RSS
Логотип
Баннер в шапке 1
Баннер в шапке 2
2018/10/12 09:51:53

Andrey Golov, "Code of security": Our profession will be one of the most demanded in fight against the Matrix

The CEO of "The code of security" Andrey Golov in the run-up to the 10-year anniversary of the company told in an interview of TAdviser about plans and the development strategy, new products, foreign expansion and risks of total digitalization.

Andrey
of the Heads
the Information security became a part of defense capability of the country

The geopolitical situation becomes more difficult, and even more often we hear a story about spies and hackers with that and on the other hand. Whether this background affects demand of the state for solutions in information security field?

Andrey Golov: Certainly, the information security became priority for the state. The president discusses this subject at any international meetings if not the first, then second or third question. It was not several years ago. But under what corner all this is presented is interesting. The information security how many attempt of manipulations with information or with the business processes connected with its processing is discussed not so much. Actively there is a process automation, including, management of the state. These processes require protection.

Do you mean cracking, leaks?

Andrey Golov: Yes. Earlier elections it was possible to hold Elections without the state automated system system, and now they are carried out only through this system and in any way differently. And impact on a system is fraught with risks to break activity of the state. It is rather new trend.

How, in your opinion, the situation with an information security management system in the country is?

Andrey Golov: It is important that at us, unlike many other developing countries, very harmonious, imposed by nobody information security management system. We have a legislation, there are ministries and departments which execute a role of regulators. They become more owing to increase in the importance of this subject now. All activity at us licensed – the companies which create products are licensed, render cybersecurity services. Products are certified. All this system is regulated – and it is very good as there is an accurate algorithm, clear who, for what is responsible.

How does the management system look?

Andrey Golov: The information security became a part of defense capability of the country, i.e. the president is responsible for this subject, in fact. Further the reality begins. Well, for example, critical information infrastructure. For audit of observance of requirements in the state information systems FSTEC, is responsible for personal data protection – FSTEC and FSB, for military subject – the Ministry of Defence. It is very important that there was no chaos in this question.

Whether it is possible to define that moment when an end was put to chaos?

Andrey Golov: Probably, it is difficult to define a clear boundary, but the step forward was taken with changes in FSTEC and with appointment as the associate director of service of Vitaly Lyutikov in 2016. And in 2017, probably, there were changes and in FSB. The picture of the market exchanged.

In the management of FSB there were changes too?

Andrey Golov: There was a change of accents. Traditionally FSB was responsible for protection of the state secret and the supreme bodies of the state power, and confidential information for them was not in a priority. Also it is necessary to understand that their specialists have a strong examination in certain areas – in cryptography, in mathematics, in the narrow systems, in the data protection connected with a state secret. But at the same time there is no considerable experience in IT systems of mass service which work in scales of the country and have millions of users.

And there was a subject of digital economy, the term "public cryptography". And heritage on use of the same cryptography old - the instruction of FAGCI still 20-year. All this, of course, forces to revolve in the existing realities, especially so far as concerns distribution and operation of cryptomeans. It would be desirable to see them in everyones Google markets, apstor, and it is impossible. Therefore there are certain difficulties, but FSB conducts the hard laborious work now. They became much more active, they listen to opinion of the market much more now and conduct dialogue with developers.

To "Code of security" of 10 years. How did demand for your products change during this time?

Andrey Golov: When our company began the activity, we tried to convince clients that we are necessary to them. And now on the contrary – demand exceeds the offer. We are faced more by a task to make, than to sell.

Demand grows on ready-made solutions or on custom developments?

Andrey Golov: Custom developments are a deadlock way. The more the vendor goes to custom development, the more increases product cost. We refused the idea of narrow, niche solutions: the amounts of contracts there it seems impressive, but cost value is always higher. Senseless investment because the got experience over one solution cannot be transferred to another turns out. We managed to make shrink-wrapped software products in all directions. We have a pipeline and we are able to afford to develop new technologies without prejudice to existing solutions.

What structure of this growing demand?

Andrey Golov: We are engaged in purely infrastructure security. So we - the base only. Kind of it is wild sounded, but it is possible to refuse an antivirus, and it is impossible to refuse a computer network, authentication it is impossible to refuse, the uniform directory, it is impossible to refuse separation of flows of networks. Therefore our advantage that we - a basis, we are between IT infrastructure and applications. We ensure safety of network, workstations, virtualizations, mobility.

In what does our product evolution consist? Five years ago all fought for the certificate. The main thing was to provide compliance to requirements of the legislation. And even solutions were not always implemented: something was purchased and right there put on the shelf. So security was "paper".

About three years ago the information security became a part of IT infrastructure. We began to work with Chief information officers very closely. "The code of security" had a product revolution, alternation of generations of products – we grew up from vendor of SMB solutions in Enterprise - it is when you have tens of thousands of users, thousands of network devices through the whole country. And now not to frighten us the big project: at us behind shoulders of Plato, NSCP, FIFA and many others. All projects for such customers are socially important, and failures are simply inadmissible there.

Then again the accent in product development exchanged. If it was necessary to solve infrastructure problems earlier – that the network worked that it was monitored, controlled, then there was about one and a half years ago a requirement that all this was also it is safe. Kind of wildly it sounded, but 20 years later on security demanded security from products.

How does demand from the point of view of industry structure change?

Andrey Golov: Earlier federal agencies were generators of demand. Their final quantity and they have a final budget. Then there was demand from state corporations, such as, for example, Roskosmos or Rostec. They have an automation of key business processes, management of finance, etc. There is a single budget system which needs to be secured within, for example, 600 enterprises.

And then also commercial customers began to be brought up. Though in connection with changes of our economy I cannot unambiguously tell any more who commercial and who monarchic. To what category, for example, to refer VTB Bank? Such customers have business processes and IT infrastructure are much stronger developed in comparison with FOIVAMI. It is geographically distributed, there is a set of departments, a large number of people works. Nevertheless, we managed to get up in a basis of their IT infrastructure and to ensure safety.

There are also customers who traditionally were guided by western vendors – such as, for example, Rosneft. Also I can tell that there migration happens not for the sake of "paper" security. We really compete quality of solutions. Yes, we did not catch up with foreign competitors yet. Probably, if to speak about networks – 4-5 years of a difference between us. But for those problems which are solved by our customers our functionality quite is enough. For example, we do not support 1 terabits of a fayervoling, but we can make 80 gigabits that more than it is enough for the existing networks. And the main thing - we are the only Russian cybersecurity vendors capable to make.

Andrey Golov: You know, there was no it that the kind uncle came and told: "To importozamestitsya by all!". Customers always did and do competitive comparison. All the same they are always interested in functionality and stability. We, probably, take the any more origin, and to those that we are closer to customers - we can lend a shoulder, listen to their requests, make functional completions which foreigners will do three years at their request. Even our Rosneft for foreign vendors is rather small customer, and the market of Russia for them is 2-3% of world turnover.

Who your foreign competitors?

Andrey Golov: In network security – Check Point, Fortinet. And they are competitors not here, and there. So now we aim in the competition abroad. I think that here we all the same will win certain areas in the next three years. And further we want to develop due to quality, functionality and reliability of our solutions, but not due to compliance.

What strategic steps for strengthening of the market positions do you take?

Andrey Golov: We do not aim to expand the product lines yet, we are not engaged in Internet of Things or a blockchain, and we want to make the best network solution in Russia. Our strategy - to go not in breadth, and deep into. A task – to make the best solution which will successfully compete with western. I do not speak about high end, we very much want to get to an average segment. For this purpose we densely interact with Gartner, to opinion of their experts foreign customers very attentively listen. We are advised first of all in questions of ensuring compliance of our products to recognized universal standards, we should get to their templates of thinking, to their product templates.

The Platon project is implemented, there took place the World Cup, the NSCP is started. What, in your opinion, will be the following megaproject?

Andrey Golov: First, total informatization continues. We as the country already learned to automate quickly enough standard processes – management of finance, logistics. Only earlier it was on the basis of foreign ERP systems, for example, SAP or Oracle. Now slowly there is a migration on the Russian solutions – databases pass to Postgres, for example. What's next? And further the terminal equipment will begin to be tightened. First of all, it will be a question of Internet of Things, of automation of the lowest layer. It will generate the huge jump in amounts of data. And those methods which we apply to increase in controllability now, unfortunately, will cease to work. So the person will not manage to manage all this, and he will be come to the rescue by artificial intelligence and machine learning. A lot of things will be assigned to the machine, algorithms owing to what there will be a new big problem – kind of this Matrix did not absorb us. And security issues will be at the head of a corner. Information will become information weapon, and tanks rockets will end. It will be necessary to learn to cope with all these trends.

Do you predict what, roughly speaking, Rostec will connect all machines in Internet of Things, and the Russian Railway is each wheel of each car? In this direction the following megaprojects will appear?

Andrey Golov: Yes. Life it is total will change in the next 10 years. Robotization will quickly develop. Everywhere we will be surrounded by information systems. According to my wife, soon all life will turn into one button. It is actually serious trouble for intelligence of the person.

But the biggest trouble is personal data. Earlier this expression was just a stamp from area of compliance. And now you understand what is personal data when there comes time to prolong the CMTPL - and you each seller of insurance services begins to call to sell the policy. And you never gave them any permissions to use of the personal data, and nobody knows from where this information at them appeared! It comes to our life, and personal data begin to be perceived absolutely in a different way.

And here, for example, we never worked in B2C, and, frankly speaking, very much we do not want it to do because it is other business, other distribution, other products, other type of support. But we think of the project of anonymization of the person in network.

As an online service?

Andrey Golov: Yes, it is the service bound with infrastructure. Well, for example, you do not want to use the cash card - you have one virtual card on one purchase. You want to call somewhere – the proxy server is provided to you. And that only the service provider knew about you, and for all others you would be an anonymous author. Such service could dissolve you in network because if not to make it - the network slowly begins to know about you more, than you are.

I watch how much children leave in social networks. But they will mature. What will be in 20 years with it children when the network tells about them what they smoked that they said where they went? There is a digital array of the person, and it is very much a dangerous subject. We consider, it is necessary to fight against it. Our profession will be one of the most demanded in fight against the Matrix.

It is dangerous to the person, but, maybe, it is useful for the state...

Andrey Golov: For what? For us it can be useful, for Americans - it seems as angrily. On condition of the fact that we are completely surrounded with the American infrastructure it is a huge problem from which it will be necessary to be protected. There was, in fact, a digital colonization, and we did not notice it. You perfectly use WhatsApp on phone of production Apple through infrastructure of Microsoft. And you do not even think of it. And what it means? It means that and all your data took away you there...

Your digital double lives there …

Andrey Golov: The first – they collect knowledge of you. The second – they will analyze and systematize this knowledge. The third – they will foresee at first your behavior and to manipulate these data. So they will unostentatiously force you to do what will be necessary for them. It is the whole problem. And you will notice nothing again. It happens surely, and the most unpleasant that we have no still uniform body which would estimate these risks. Take the same problem of "blue whales" - a children's suicide through social networks. We investigated it and understood that there is no department where it would be possible to address to solve this problem. The State Office of Public Prosecutor goes about the own business, investigators - the, FSB - the. And so that someone stopped all this – it is absent. There is a strong wish to hope that the digital economy will allow to build interaction between departments. But on it time is necessary.

Let's talk about strategy. For a start there is a wish to understand dynamics of your revenue for the last few years. How did it exchange?

Andrey Golov: For the last five years revenue grew almost three times. In 2017 it made 4.3 billion rubles if to consider in the prices which were paid for our products by clients.

And marginality, probably, high?

Andrey Golov: Behind marginality we attentively look, it at us very good: true profitability about 25%. Financial system of the company absolutely transparent.

What your forecast for 2018?

Andrey Golov: We expect to reach a mark of 5 billion rubles.

What part of this money will be earned in Russia what abroad?

Andrey Golov: Abroad we, generally so far have pilots. There we expect no more than 200 thousand dollars at the end of year.

What countries or regions for you are priority?

Andrey Golov: For the Russian company, in principle, it is possible to sell only in three regions. It is Latin America (Peru, Chile, Argentina, Uruguay and Colombia), the Middle East and Southeast Asia. We do not go to Southeast Asia yet because not really we understand this market, there everything is difficult. In Latin America, in Uruguay we created joint venture. In local products our engines are used. Partners on their basis created the new interface, new products.

Why Uruguay?

Andrey Golov: It is the neutral country, a peculiar Switzerland in the region. It has equal relations both with Peru, and with Chile. It is necessary to understand that in Latin America there are several camps. There are pro-American countries, there are more neutral. It would be heavy to purely Russian company to sell something, especially to customers in B2B and B2G, including in power bodies.

With whom it is possible to pilot products in Latin America?

Andrey Golov: Generally it is the power sector. Our products are very well perceived by military.

So it is the same sector which at us used these products five years ago?

Andrey Golov: Yes, because at military very well with security in respect of business processes. They accurately know what can be done and that it is impossible. There is no gray zone. And products just under it are also ground.

Do you go on the Middle East through the joint venture too?

Andrey Golov: We develop business in Dubai, but there we go as the Russian company. There is a partner who was one of the largest local partners of Kaspersky Lab. Now there is a study of the legal scheme. First of all, we define who will possess the intellectual rights. Because they would like that it was written "is made in the UAE", and we would like that IP products remained at us.

It became more difficult to Russians to work abroad?

Andrey Golov: Certainly. There is an example: our partner in Dubai received the official letter from the state regulator that is not strongly recommended to work with the Russian companies. And the regulator refers to the English government which prohibits the UAE to work with Kaspersky Lab. At the same time in the letter of the regulator of the UAE it is already about all Russian companies from the sphere of information security.

Natalya Kasperskaya made the company there too …

Andrey Golov: Yes, but so far all this private initiatives, we should spend for it the money. At the western countries other approach. At them initial communications are built by the state, and already then there come businessmen and on the plowed field sow and reap a crop. And in our case we should arrive for the money, dig up this field, sow, then tell our regulators that everything passed well, exported grain, put. We do always contrary to.

What your forecast for the next years for revenue from the foreign markets?

Andrey Golov: In our strategy it is written that in five years revenue from the Russian and foreign clients will be divided in a proportion 50 into 50.

And the total amount of revenue will be what in five years?

Andrey Golov: About 150 million dollars.

So on 75 million, roughly speaking?

Andrey Golov: Yes.

At the expense of two regions?

Andrey Golov: Perhaps, Southeast Asia will be added. There we try to leave in a different way. Now we in a contract signature stage about global partnership with one of local vendors. But in more detail I will tell about it next time.

Why I am confident in quality of our products? Because we often go the way OEM-integration and we use spare parts of the western production. It is Intel, it the solutions developed by our technology partners in France, in Germany, in Israel.

Of course, sanctions for us — it is bad, it slows down progress. We will not manage to catch up with foreign competitors in present conditions. Very big difference. They have a number of developers many times more, and they do it much longer, than we. And the product is people, hours and nothing else.

And assembly at you where?

Andrey Golov: Assembly in Russia.

It does not affect quality?

Andrey Golov: We try, we pay much attention to monitoring, management, integration. The more you put devices, the more widely at you installation, - the better at you fitbek. Than better fitbek - that high quality. If you invest money in service, in development - products become better and better. We have a test base - it is 89 regions of Russia. Very few people can brag of it. Very few people are able to afford it to himself. Therefore we are sure that we will be competitive abroad.

In terms of new products what your plans?

Andrey Golov: We are focused on the available product groups. But in them constantly there are new technologies which we began to patent. For example, we made the most highly productive fayeyrvol. It is quite competitive in comparison with medium models of Check Point, and at cost is many times cheaper. We are competitive in those niches where not megaresources, and megabrains are necessary. We have these megabrains.

How many at you developers?

Andrey Golov: For the last five years the company grew from 170 people to 500.

From them how many engineers?

Andrey Golov: From them R&D about 350-370 people. The main part works in Moscow and in St. Petersburg. In general, with the personnel very big problem. They just are absent in the market. To us it is difficult because the developers having highly specialized knowledge in the field of the high-loaded server platform, a kernel of operating systems are required, and people generally write Java toy or design systems from ready blocks.

How do you solve a problem?

Andrey Golov: We cooperate with universities: with MEPhI, MSU, - all at us more than 40 partner universities. We invite students to practice and a training, we leave the most successful. Among 500 employees about 35 are students whom we pump over. We managed to adjust process of knowledge transfer. Earlier it was very big problem: our gurus were closed as a shell. But we managed to break this situation. Now we have many talented children who already began to teach younger colleagues. And with some we went further away. We are ready to pay them interest from sale of new products.

Developers draw interest?

Andrey Golov: Yes, they are patentees. The patent is made out on the company, but they are authors. And via the mechanism of SP they can receive money.

If to speak about any largest developer and the holder of patents how many percentage of his income can make these assignments? How serious money?

Andrey Golov: It is many times more salary.

Such model at someone was spotted?

Andrey Golov: It occurred instinctively. Children geniuses very hard get on in collectives. They have other thinking style. Therefore it happened that they left. And their talents are rather hard applicable in the market because they do not write, for example, a toy. They know very highly specialized things. Therefore they came back, but already via the mechanism of SP.

We counted, and it turns out that they receive money more, and for the company of costs did not change.

How many people so work?

Andrey Golov: So far they are not enough, less than five.

So super-geniuses?

Andrey Golov: Super-geniuses. But in addition to them to eat simply geniuses. We completely changed approach to work and now we just have no concept "work". We it live, we try to erase as much as possible an edge between work and normal life.

Private life at people remains at such approach?

Andrey Golov: We also start families directly in the company. If to look on sales, then I do not understand at all when they work and when have a rest. The same at developers. They play before one o'clock in the morning in the evenings, and after an hour begin to write the code. When there work begins when comes to an end, I do not know. For them product development is just a way of life.

How much is Code of Security company?

Andrey Golov: At least 150 million dollars.

In 2017-2018 several Russian IT companies - IBS, Aplana and others – considered entry into the exchange, carrying out the IPO. They estimate the cost of the companies in the amount of annual revenues. And your assessment considerably exceeds revenue. Why?

Andrey Golov: Yes, many times exceeds. Because we have a capital which integrators do not have. They have services, and we are property - it is products which are installed at customers.

So it is an opportunity to gain regular service income?

Andrey Golov: Not only service. This development of products, it aprgreyd versions. These are not services. It as "the real real estate" across all Russia. And it will not disappear, it is a core infrastructure. It is possible to refuse custom development. And from us as from a core infrastructure it is impossible. We can disappear only together with Russia. Therefore we also cost much. And it not only our assessment.

What should occur that you suddenly seriously began to think of the IPO?

Andrey Golov: Well, the IPO for us, unfortunately, is impossible. There is a law on restrictions of the foreign investments. We do not know who will be an investor, the Russian citizen or not.

Not to limit it even at the Moscow Exchange in any way?

Andrey Golov: And how? The foreigner can buy at second hand. We the strategic company for the country according to the legislation, and makes the decision on it the government commission. Therefore the IPO is impracticable.

It turns out, you can attract investments only from the Russian players?

Andrey Golov: The Russian investments are possible. We realized it, and we know that it is a good stock.

What your long-term plans, say, for the next 10 years?

Andrey Golov: We have an extensive experience, the huge test platform. We have shrink-wrapped software products to which it is a lot of years, and we know how to do them. We have a pipeline with absolutely predicted cost value. We can accurately predict expenses. We need to be engaged only in expansion of the market of sales. There are people who are able to do it. We even have no doubts that we will make it. A question only, in what time frame in connection with a present geopolitical situation.