Prove Me Wrong: DevOps Everywhere | DevOps Experience 2022
At DevOps Experience 2022, Alan Shimel, Ron Gula, Thomas Krane, Suman Natarajan and Julian W. Waits Sr. discuss what the “DevOps Everywhere” mantra means to their investment strategies.
Transcript
Good morning panel. Good morning onions. So today's panel.
is proving wrong devops everywhere and there so green is the same as my screen, but on the top right corner for me. I have a friend of mine for the security world for probably longer than either too. He's the founder of tangible.
He also the founder and Guiding Light of along with his wife a cooler tech Ventures front Bula. Hey, Ron welcome. Hey, good morning.
Allen pleasure to be here. next to run between run and I am right good friend Thomas. Crane of insight Partners joining us.
I'm gonna say that background today. That's right as well. Hey Alan good to be here.
Thanks for having me. Good to have you here is always here. user always, you know part of a great battle here.
We have one two days and I was the first time she's joining us or want to introduce you name, right? Zuma not to doctor. John she's the principle of the capital group smart welcome.
Great to be here on excited. Thank you. Very my apologize.
And last but certainly not least my good friends in the security space. He always brings it where he's talking myself a part of the battle is user always interesting thing does like it is he has a really great view of the market my friend Julian Waits. Happy to be around.
Have you ever thank you? all right, let's started up I want to hit this straight talk. I actually got two requires some other media companies.
About you know, what's going on with this devops instead thing. Right. So what had Right now by sponsored article on Marvin Alexander.
Sorry. I respond to it a bunch of other people responded to it. I wonder if Thomas you probably have went down about invested.
Did anyone here? What do you think and let's take it off? Yeah, no, absolutely.
So look, I mean, we've got a number of Investments that touch that sort of software development life cycle that With an emphasis on you know developer tooling and I mean you can't really you can't really deny the secular factors that are driving, you know growth across all of these companies. I would say At the same time, they're not immune to the macroeconomic challenges that are facing many companies. And if anything they've probably have slightly more exposure to you know, the software vertical as an End Market which just can create a little bit of a little bit of short-term shakiness, but I don't think you know long term, you know the growth and the developer Community growth in complexity and heterogeneity of tooling.
I mean, it's just going to create, you know secular Tailwind for the category. You know, what whether you call it devops. Maybe there's there's a debate there and you know, I I feel I as Representing the investment team of insight.
We talked to a lot of companies. There's kind of a new trend or New Kids on the Block. There's the internal development platforms the idps.
There's a sort of it's a number of different. I mean we see these ephemeral environments as a service. We'd see sort of this reversion back to pass.
I mean again, it's kind of just new new flavors of the same. Uh sort of technology that we've been looking at and talking about for for a long time now, and so maybe you call it something different you call it IDP at its core. It's still you know, the same the same trends that are driving it which is developers needing more Tools in their toolkit to do more sophisticated.
operations around modern infrastructure there anybody on our panel wanted to jump in there? Yeah, I think one of the big things that's happening right now is that a lot of organizations are finding out that the cloud is very expensive and when they start looking at those Amazon bills and those Google bills, you know, they're starting to think about well. Hey, maybe we just can't code and throw code where we want.
We have to be a little bit more strategic about what is our business. How do we control costs? And I think that kind of can have a negative impact on, you know devops being a cost center and not a profit Center.
I don't disagree. Julian you and I have been through a few Cycles as Ron frankly and you know what money gets high people start looking where it's getting spent. And and you know, we say it really interested in.
Love you. You know Ron is it's I mean, I'm sorry Alan. What you know things work in a cycle, right?
What do we call it IDP or devops? It's really more about Automation and tehran's point. When I look at the workloads that I'm creating in the environment, where's the most cost-effective they have those work but that's at the end of the day automation is the key.
And devops is certainly not dead. It's become a core component of software development. So it's more of something that's kind of left behind in the thought process.
But it's never gonna die. It'll just get one iteration or another one in terms of his life cycle. But software development is a complex thing Cloud workloads make it much more complex and I mean, I think the whole concept of us being dead is just silly.
I know just here. Look to paraphrase an old General. old Technologies never die right away, but here's an interesting thing that I see that you know the mission to keep on this military kind of thing the mission of devops.
Has has grown so much right when we first when I first saw that I come. It was dead Ops that I just had an officer work together. You know five six years ago.
security and huge part of his dad Stack Up Julian you and I spoke about it Ron and times we both spoken about it. But tomorrow I mean, this is an area where you place well, right. Absolutely.
Yeah. I mean I've invested in a number of devops and devsecocks companies across, you know with Intel Capital City Ventures. And now at the capital, I think the notion of devops is dead is you know is supposed to be provocative to kind of encourage conversations like this but out in the real world.
I think the thing that a comment like that ignores is that people are still just starting their Journey with devops. It's it's a broad continuum. Many organizations are kind of a different stages.
And so to kind of only talk about maybe a tip of the spear experience and you know within our maybe VC bubble. We like to fixate on some of those spots a little bit more is kind of not maybe seeing kind of the full picture of the ecosystem at large but I mean devops is all about, you know, supporting velocity and supporting reliability and trying to find you know, technology approaches process approaches collaboration approaches that facilitate that and just how people are working together the technologies that are available I think continue to change and I think as Thomas and and Ron have spotted from a resourcing perspective, you know, given the macro some of the you know, we might want to lean more on technology. I you know giving that current challenge, but it's certainly not it's not special environment run you you frankly really well, right?
Used to having security too. This is not the cost center. Or is it help it make us more efficient.
It actually saved right? It's a generate by your prosperous money. Yeah devops certainly enables a lot of cost savings and you know, I'm trying to put myself in somebody who's in in the audience watching.
This is maybe a brand new developer trying to figure out the lay of the land. If I describe devops as taking, you know 95% of it, you know written by somebody else right? Whether it's open source code or you know Amazon's microservices or or whatnot, you know, you can see devops is basically saying, you know, I'm gonna take a little bit of code.
I'm writing and getting maximum, you know value out of that. There's Security benefits to using other people's code, especially if it's been tested and infrastructure so you don't need to go out and buy as much security stuff is as you know, you would think the Cyber industry, you know once wants to invest in them, but at the end of the day, I think if if you look at other Industries, like, you know Automotive iot devices that you know for manufacturing and whatnot. We're starting to get into this phase where people are expecting new features to kind of come for free, you know in things that they buy and and sometimes that's a little frightening because if you're you know, you're flying anywhere, you know, Really don't want to hear on take off the pilot saying hey, you know, we just upgrade to the wings last night, you know, if it goes, well, you know, the whole fleet's gonna get them right, but if it doesn't, you know, we're gonna roll back real quick, you know, the devops is one of the only Industries where you can constantly get value out of that but you know some customers and industries are very much, you know.
Hey, my features are good. I don't need new features. You know, I wanted the way it was before so you have this constant tug back and forth.
a great degree so Thomas up I'm gonna throw the same kind of thing at you, but I wanted you said in give it macroeconomic condition for all we'll use the sanitizer back or economic conditions, right? We're headed for a recession. Potential, you know pretty likely here.
What is this? What does this mean for your investment now? What does it mean?
Not only for president portfolio companies but professions you're looking at. Yeah look Alan. I mean there's a lot of Doom and Gloom out there.
But again, you look at penetration of cloud workloads relative to on-premise it look at growth and number of developers and just a lot of the underlying trends that I think fuel sort of the long-term growth that the software sector and certainly things are only getting more and more complex. And as Ron pointed out. Yeah, I mean folks are starting to realize that their Cloud bills are a little bit out of control.
But what does that mean? It means to push toward hybrid infrastructure and that means more complexity and you know that that creates an opportunity for emerging Technologies to help navigate that opportunity. I mean you look at how you know, the introduction of devops and really that ubiquity of it's adoption has created New Market opportunities.
Look at microservices architectures and the criticality of apis. You know as a building block of any application and what that means from a cybersecurity perspective as we see more API breaches happening and no name security being one of the highest growth, you know companies in our portfolio, you know, you see those kinds of opportunities being created, of course, as you know, also is Ron mentioned new component, you know software development just being cobbling together existing third party components. Well that software supply chain creates a lot of Downstream risk, if it's not and a lot of interdependency as we saw with with some of these recent software vulnerabilities that that creates again more opportunities.
So so look, I mean, there's going to be there's gonna be some short-term I think choppiness in terms of performance, but with with the long term macro very much in our favor and maybe whole periods get extended by a year or two could be a compression on IR, but fundamentally, I don't see a massive reduction in terms of in terms of performance or or a retreading in terms of adoption. In fact, I only see more new companies getting started this year than ever before. Absolutely, you know what?
It's been my experience and shop yet Economic Times. com bubble. Think about all the great companies that were founded in that in that period of time again in 2007 in 2008.
So, you know, yeah, I think I think there's definitely companies being created now that could be iconic companies of the future and we've had a lot of great companies in cyber for the last, you know, 10 years or so, but they've been you know, as to to Tom's point the complexities kind of increase so these products become very Niche, you know database, you know activity monitoring for you know, for example, you need it but it's not hugely, you know strategic like a Cisco or or a checkpoint. I also think that if we hopefully have, you know, peaceful conclusion to the war and Ukraine, you're actually going to see a lot of cyber talent and cyber companies including in the this devops Tech developers come out of Ukraine. Amen to that And you all want peace I think as quickly as possible that for more than just even factors here, but that certainly will help.
You know speaking of side without one of the things that's not my heart good over these years. is to see how security has really integrating the last time this old devops movie times. She spoke that software supply chain.
You can't say software supply chain without attaching security to the end. And S bombs and all of this sausage, really? Are securities Main Street security is top priority opening around.
Julian you've got a bunch of years here. This this industry, Woody. What do you think about that?
Well again it to your point Alan and I think that point to everyone is making the scale at which we're needing to build software. Is driving a need for more and more security and more and more automation. I mean it's unfortunate but even in this day and age most developers don't understand security.
Not that they don't want to have security. They just don't understand it. And so more tools have to be built to support it one counter to what runs that earlier because I'm a basketball owner.
I actually love when I get new updates. But just think what it takes to support the development process between Tesla's Cloud to the CP is in the stores that run in my car and now magnified at towards thousands of cars. And God forbid if somebody found a way to get in that Pipeline and all the sudden the car turns off the cliff or the breaks don't work.
So, you know, the one question you have to ask yourself is or we're gonna have more and more code written every day. Are they gonna be more developers coming into the market every day and certainly a CPU is continue to move forward and clout workloads become more efficient again having a concept like devops to me is it's more of a process than the thing. It's just a component of the way you do things.
I absolutely agree. Smart, what would from where you said though? I mean security is really in the fabric Now, isn't it?
I mean, that's the that's the hope. I think it's still, you know, evolving more into kind of being embedded within the sdlc more. So I previously invested in companies like sneak and styrod that I think were doing a great job of trying to one Embrace kind of the developer experience than to kind of Leverage the new reality of the stlc.
It will change in Cloud native infrastructure. So it is moving in that direction, but I think the kind of load and kind of shift shift left kind of process I think is part of maybe one of the reasons why this notion of devops is dead and let's move to platform engineering idea is a rising as well and that it's really putting a lot of burden and strain on the developers to Julian's point, right developers don't know security and I don't know if the expectation is for them to become Security Experts, but Possibly. It's just helping them embed security earlier in the process to ensure greater reliability and you know more Downstream.
So I think it is still evolving but we're you know, we're not quite there yet. It's the hope would be to have it fully embedded. And that's the opportunity.
Alright, so shift left is the topic of discussion we've had. You have we gone too far left. We need shift, right?
there's various parts of it, but I want to say about that much for this panel and You know, you mentioned styrofer that's right there the people behind all over so small is the agent but they're clearly in the cloud native space. I'm actually doing the live Roundtable agent this afternoon. She have Cloud native without devons.
And when we talk about devops everywhere, this is the kind of thing. We're talking about that about so bad in the way. We're doing things.
Yeah, a lot of people who you know moving over the cougar Daddy's facts. It's all new stack Cloud native stack. that I any one of anybody can jump in and just Kind of fun.
Yeah, I can comment on that. So when you talk about, you know data in the cloud in the US we tend to view data from a regulatory point of view, you know as a pii is it something to PCI? Is it gdpr and and and and and whatnot but we sort of don't have sort of the safety hat, you know caution.
This is contaminated radioactive don't ever give this to anybody sort of mentality when it comes to data and unlike, you know countries like Astonia which have like, you know, one use data retention policies and policies of you want to code against this data. When are you gonna get it? Who's gonna get it?
There's authorization that goes with access. We just don't have that mentality here in the states. We tend to focus more on is the code secure.
Is it resilient is it you know, is it is it delivering the features people want and until we have that change that data is the resource that drives things. We're not going to I think ever really get away from from managing that stuff. Okay, here's the goodness.
All right companies that are involved in it that off. That experience Thomas look you you probably see many companies as anyone obviously. What do you think about data they discerning?
I'm looking I think Ron makes some great points that this does kind of have to start top down and there's From the perspective of Regulation we're sort of in that early phase where it is more of a compliance driven sale and exercise in terms of the early adopters and it is security or actual the operational side of it. I mean same could be said that the vulnerability Market back in the day you kind of did it so you could check the box on PCI compliance, but now, you know you use tenable to to measure continuously your cyber exposure and I think that's gonna be true with data. We're still in that.
Okay, let's make sure we get all of our cookie settings and and oh, you know user user permissions set properly, but at some point they're actually has to be a reckoning around. You know, how do we actually think about the security risk of the data and how we use it? Agree, Julian is your area next or one of your areas of expertise wondering what you think?
So actually think people do think about data what they don't think about is the care of the data and I think that's where wrong was going since we've actually had this discussion before the big issue, right? It's you know that rapid 7 or any other company. I've worked for in the past people and others and operational security.
The issue is still always focuses around security for what or devops what again? If you look at security as a processing you look at devops as a process. The way everything should be built is around the data that's most critical to your environment that you're trying to protect.
But today we all the infrastructure to drive how we care for our data versus the way it should be done. And until we think about it differently. We're going to continue to have all the security issues we have continually.
But more importantly right what makes devops so important and I think Thomas made a good point. When he talked about hybrid environments because I actually hate when people say cloud native. I think that's a that's a great buzz word to use with when you're trying to sell to a customer or something like that.
But very few applications are fully Cloud native. Cicd pipelines and being able to secure the processes and the steps in between will always be critical to what we do and and it still comes back to why are we doing it? And why are we doing it is to protect the data, but you know It's a suman's point, you know, we're a long way away from being able to control all of them.
Can I just jump in and I think you the inertia to on-prem has historically been more Tech debt one, but also the data the data security question and regulation. I think there's gonna be a push back toward on Prem to Ron's point on and and I think our team Casado at Andresen has written about this but this idea of actually You know folks moving away from the public Cloud because of the response to the cost side and and there's no proof that the cost equation of renting a workload is necessarily better long-term than you know, the capex equation. So again, and we're going back the pendulum is swinging right and and maybe it's it's a little I'm trying to be a little bit provocative with it.
But there may be that's a sort of a headwind to the Microsoft Azure and AWS growth that is really been kind of unencumbered up until now. Devops that she's our premises in cloud in the edge. It's all about speeding.
Oh, yeah, I I totally agree. I think that as infrastructure continues to evolve like the the knowledge base and kind of optionality, you know continues to grow and you need kind of a subject matter expert who can consume that and take advantage of that for like the needs and requirements of your organization and the applications that you're building and delivering and so I think as a function it's not going away. It's certainly evolving and I think some some folks have you mentioned that in the comments as well?
And then I think I I really love the kind of Conversation of you know moving to cloud and then moving back to on-prem again. I think that's like a very tip of the sphere kind of experience for people to start a non-trivial process of migrating workloads and data off Cloud onto Prem and you know, it's you're gonna have kind of a similar data gravity inertia issues. We invested in a company that's actually helping on the cloud cost optimization side called zesty, but the kind of hope there is that you can stay in the cloud and only pay for what you're actually using just to kind of optimize that cloud bill, but the flexibility that public Cloud offers is just so much greater.
It's vastly greater than what you can actually achieve on Prem. So I feel like while there might be this kind of push back on cloud. I don't know if it will be sufficient enough to actually drive kind of that big change unless you're a large Tech hyperscaler.
Organization where you need to kind of man manage your your workloads in a more efficient way. and you get that control, but that's I I would just like to add on that thing. I know.
If you don't want to use the word cloud native don't use the word cloud native, but one of the nice things about kubernetes based architecture is you can run cool on privacy, right? I'm gonna metal. And in the cloud and it really represents for this distributed architecture.
that I you know the market we would something for 20 plus years that ground true distribution of your applications of your data the distributed architecture. Hey, Alice like it jump on it. No, no you when you run, you know kubernetes, you know on Linux in in something like Equinox and one of your own data centers, you know, you probably bought the hardware.
There's a chance the hard work could have a you know, a back door and implant on it whatnot. But but most most likely it it doesn't right you control the operating system you control the code that goes on there. You probably can control the cryptography that goes in and out soon as you move that to a virtualized system and somebody else's cloud.
They can take screenshots of your memory. Basically, they can copy your hard drive images and a lot of people who do incident response in the cloud. You actually have full native images of the not only the containers but the VMS that are there.
So this is really, you know, halted a lot of banks from going all in with the cloud because they have to do multiple layers of cryptography and key control just to run a VM, you know securely from their point of view. So it's actually a lot more work for some people who care about security to go to the cloud versus on-prem. But there's always been right that's always been the argument with the card right?
You control not responsibility. But but if the customer requires it and it's the fastest way to get there. I mean, you know, if if I'm competing with Tesla, I know that the standard is I need to be able to update the software.
I'm on my car Fleet and my customers expect that and I may not be equipped to to. Build that on my own or in my own existing infrastructure, and I I have no choice but to go to the public Cloud if I want to stay alive. So there is that aspect of just trying to keep up with the with the more Innovative companies out there that have kind of necessitated that No, I think Thomas phrase is a really good point because it's really a trade-off, you know across Enterprises.
Are you security lead or are you velocity lead and I would I would add Security in your liability LED and I think the you know what you're optimizing for and the process that kind of facts that up is going to vary based on how you decide to make that trade off. And so, you know to Thomas's point if you are, you know a software company that needs to compete and needs to kind of get your software out there as quickly as efficiently as possible. Then you're going to embrace kind of different different kind of architectures and then require security to adapt to that versus, you know, organizations like Banks and and so forth and my experience at City too, I totally understand the the risks that they're taking and moving to Cloud but I think there are opportunities to kind of improve upon the security posture as well as they're making that migration and kind of is forcing function to kind of maybe rethink older standards and controls that they've maybe leaned on for years as well.
So I also think that it's I mean The concept of digital transformation is an evolving concept right meaning, you know initially when we first started using it it was it was the it was the move to the cloud. But the kind of go back to some of the things we started on earlier. I think we're software development and certainly in the security World.
We're having to think about it from a reliability standpoint and availability. It's still optimizing whether workloads. Run best to optimize what it is.
The outcomes are that I'm trying to achieve. So I honestly believe there's going to be a lot more hybrid applications written moving forward, especially when you're looking at situations where I have no access to the cloud, but I still need to have availability to my workloads. I still need to have availability to many of the outcomes that I expect from the software.
It's it's gonna force it. And I think a lot of banks are looking at that now run. That they are, you know one we've a lot of experience with companies who have commercial offerings containers for commercial customers and the military the US military is asking them.
Hey deploy your stuff on our cloud and even with big contracts a lot of commercial companies, like look, we don't want to go through that. We can't make that investment to kind of re-architect this to do to do security. It's really really rough on.
I mean really classic example, there's no on-prem version of slack, right? There's no on-prem version of Salesforce. It's absolutely not even something that you can buy you throw all the money in the world that these at these companies and you're gonna find that as you look at all the different apis out there and all the different types of you know, middle layers for running Cloud.
There's different levels of what you can actually control to be secure because sometimes security just wasn't the number one thing in these designs fair enough Hey guys. You got a lot of questions from the audience and I I asked people to ask questions. I feel obligated to respond.
One of the question was hey kubernetes has been kind. Dominant is the organization. Layer of this one piece of this for a while now.
We can see something else. Is there another? orchestration a tool or something that allows us maybe accomplished some of the things around security around some of the other things we're talking about.
tomorrow you have your here to their new South Africa we often and everyone else. follow up Yeah, I think I think technology-wise an architecture-wise they're probably are better orchestration layers out there. I think they've probably come and gone.
I think what what kind of makes kubernetes dominant is just that it's the most popular given, you know, even with all its faults and you know, the kind of architectures and standards that are able to get that kind of mind share. I think ultimately dominate it's very hard to kind of compete on kind of, you know, small features. But I agree.
I think the kind of opportunity to build on kubernetes is pretty large one. I think adopting it is a non-trivial and so there are a lot of companies that I have, you know emerged to help kind of manage kubernetes more easily both in the open source, and as kind of commercial offerings and then again, I think there's a lot of cyber companies that are also kind of recognizing. Hey, this is the standard let's build to kind of work within the constraints of kubernetes to offer more policies more controls as well.
So I don't think kubernetes is going away. I think how we interact with kubernetes might continue to change. I would agree with that.
I think it's it's gonna continue to dominate but there's ways to optimize around the edges. You know, I think deployment is where there's I think a lot of innovation happening and deployment management deployment automation, you know, the founder of Docker and mentor of it Solomon Heights has a new company dagger. It's all about you know, how do you rethink almost like a container containerization of deployment for example, right and so and we've seen certainly tremendous growth in, you know, companies like harness and those that make the deployment side of and the kind of continuous deployment side of this easier.
So, but I don't see kubernetes going anywhere. And if you're if you're selling into the federal government kubernetes is the standard. I mean the dod and now many civilian agencies are dictating if you're doing fedramp.
Or if you disag into DOD gun Cloud environments, you can't even get certified without kubernetes now, so it's just it's just the way things are. So if you're trying to sell in both environments, why would you have more than one orchestration technology? I think I don't think you're gonna see a lot of things that are going to disrupt How We Do kubernetes regardless if you're hybrid Cloud, you know all in on Google or whatnot, but I think the biggest thing is gonna affect the industry.
If you can talk to an AI and say draw me a picture of heaven and have this amazing picture of Heaven given to you instantly you're gonna be able to go to an AI very soon and say I want some code and some infrastructure that does this and the AI is going to write it for you. And I think that's gonna be more disruptive to our industry than anything else coming down the pipe right now. And I shared back.
Especially even if you're right. They're using AI just try your articles and it's getting harder and harder to tell. Whether human body or an AI wrote it, I started AI PR agency.
That patches your stories automatically. You know what again? Thomas with the United field flow and companies you see running through you.
How where are we with AI in that? I mean it gets a it's it's hotter than web 3 I'll say that these days. Uh, yeah, look, I mean we said we just invested in this company Jasper in the generative AI space.
It's in facilitating some of these kinds of AI writing and and AI marketing agency types of approaches. I mean, it is truly remarkable the growth is there for a reason again at Insight? We don't Sit back and just try to be so super theoretical about you know, where we want to invest.
We really just try to get a pulse on Market directly to form investment decisions. And you know, I I Jasper's definitely one where you you could just you know, you could hear the the demand the suck at the vacuum of just we this is there's a huge market for this and so I think what what Ron was talking about, you know, in terms of that application of Jennifer AI to to devops and to you know new application development. It's pretty it's pretty mind-blowing how you secure that that's just a whole other whole time right you Yeah, I do think that it is very early days, but you are starting to see some startups that I think are trying to pull in AI to enable kind of a better collaboration experience between develop devops and developers.
I think mostly you know one I've seen is a company called kubia, which is basically providing a better way to in, you know, natural language just request Services requests can provisioning of resources and I think it is kind of a it's a nice kind of opportunity especially in that kind of enablement. I think you're also probably seeing it in kind of optimization of you know, workloads and so forth and I think that probably is you know has kind of more of an ml need versus baby like a full generative AI kind of capacity. But yeah, it is starting to get kind of inserted into kind of these Nice little you know problem areas across kind of the devopsin sdlc process.
So but still I want to jump into that awesome things iot, but before we do one more question from the audience, and that is Mac. What friends will you recommend for new devops out of the focus on going forward, especially provide better and more attractive value customers. Thomas and want to go to the well again, but ask you.
Look, I mean again you just have to cater to the the developer, which is a very fickle. User buyer Persona, and you know, I I see a lot of companies with very exciting technology with a ton of potential a ton of potential but you know commercializing it and the change management required or even just getting a developer to pay attention to you. Let alone pay you is is quite challenging.
I think the new vendors tend to underestimate that challenge so sort of what I'm seeing in the market. Fair I would I would tell people to focus on controlling cost if you're if you're designing an offering and 95, if not, 99% of what you're using is somebody else's resources or code. You know, you have to think about managing that and we've had a couple companies sort of recompile and refactor to use the Amazon chipset for example, and they've dramatically reduced their CPU uses cost.
And that was literally one of those things we're going to spend two quarters doing this and then we're going to you know, save money forever, you know at these rates Beyond and that's the kind of conversation people who are doing managing devops need to think about with their businesses. How can they save money and be more efficient? Great.
All right you what I used to call iot, right and to me iot used to be stated devices that were simple devices on off. But today we'll talk about some things. Whether it's pacemakers and planted in your chest.
The chips in your Tesla or other cars every car has literally hundreds of chips now. Filming baby critical infrastructure controls, but it sensors in space sensors at the top of mountain sensors at the bottom of the sea. There's going to be 55 billion.
devices connected to the internet including your refrigerator They all run software now it they have more Headroom you put more software on them. That has a role in developing that software. And security is probably going to be tested once again.
devops of things Julian if you don't mind, I'm gonna ask you to kick this one off. Yeah, that's a big one. So obviously OT is it certainly for corporate Enterprises has become front and center because of what you're saying even many new devices not just Legacy devices that are that are ot-oriented control more and more things, you know.
Recently, I was involved in an opportunity where we're selling to a water municipality. And and they wouldn't allow their air conditioning in this case. I shouldn't say air conditioning.
They're cooling equipment detects the internet because if you change the temperature of the water before it goes through the full process. You can make somebody sick or you can kill just by changing the temperature and so There was a there was a lot of adversity and constellation about putting him on and after. Working with them what a lot of solutions that didn't have anything to do at rapid 7.
Actually, they finally got to the point where there are a lot more comfortable with it. But the big issue is is in this case. They won't say the the company but the largest refrigeration company in the world in collaboration with them.
It's amazing to see how they're trying to change their development processes to get their customers specifically these industrial customers much more comfortable with having this equipment internet face. It's it's a big problem. It's only gonna get worse and companies like tenable and Rapid or responding to it in time.
Sure. panel I mean there's a hair on fire moment just in terms of the inventory of what do I have that's attached to my network. From a device perspective and what is the risk associated with that device could be an IT device.
It could be an OT device. And so, you know, I'd be remiss if I didn't mention Armistice, I mean they are the clear leader in the space board device and asset security and you know the hair on fire moment is what do I have but there's the deeper question of what are the behavioral elements that indicate? There's an issue and certainly geopolitical.
Uh factors and tensions and the the jumping of cyber risk into the Physical Realm with you know, utilities being affected and impact on actual, you know, human populations. It becomes a pretty profound issue and and source of demand as well. Yeah, I I mean just as kind of a concept I am so excited about the idea.
I just take another view of this. I'm really excited about kind of the opportunity, you know devops across the edge one. I think the you know, there's huge kind of opportunity to actually standardize the support development process to match more of the traditional application experience.
And I think that's a huge opportunity. And then too I think from a security innovation side, maybe not security experience and management side. It also represents it huge kind of opportunity to tackle a new problem and I think companies like armis are kind of helping with the certainly with the hygiene side of things but then understanding kind of the you know, Network segmentation that you might need to do in this world being able to do vulnerability Discovery looking at the firmware, you know security here I think is a lot of really interesting, you know companies can be you know form just to start tackling some of these these issues so On that side of things as an investor.
I see it as you know good good fertile ground for investing so Yeah number of number of comments here. I think it's really good to bring up OT at a at a devops conversation because there's a lot of a lot of analogies like you can imagine if I'm I'm in the hardware widget making business. I've got a bunch of apis in the cloud and just some of those apis also run out that endpoint.
So it's all part of a synchronize, you know devops point of view. So in other way, you know, you probably take code you you strip it down to run in a container. It's a very similar process, you know, we don't ship full Lenox operating systems, you know for these OT devices we have to kind of strip it down and do that.
It's very very similar processes that go on and and whatnot. I think a lot of the new OT devices. I have better security but you know, a lot of them come from China A lot of them come from overseas and they might not have you know, as much robust standards as we as we think we do where they host the data, where's what's the quality of that going on but there's still a huge problem with old OT devices that are on how do you Find them they might have fragile tcp/ip Stacks.
They might not respond well to vulnerability scanning and asset Discovery and they might not even you know, make any really Network traffic for you to go find it. So it's a really really hard issue. But I think the future is definitely more optimistic than the past if you look if you consider no T device like an iPhone or an iPad those things are really really hardened compared to like like a Windows Surface even like a Google Android phone is is a much more lockdown system.
So a future if that's your, you know primary Computing device, even though that's kind of an OT thing. It's actually probably gonna be more secure than a traditional, you know modern complex operating system. What scares me though is that I don't see.
standards Right. Look software software application is applications today connected devices have much more Headroom. Than skated switches or something.
So I guess you know the same way we developed software for for a phone is the same way we can develop software. For your toaster or your or your pacemaker, right? I don't see standards around security involving there.
I don't see standards around, you know, we talk about software supply chain and stuff like this and that's what kind of can keep me up at night. See you got a good point there. Alan not only are they're not standards.
But there's some great social issues that we haven't really answered yet. Julian talks about he likes getting his updates to his test level. What if I have a Tesla and I want to make my own updates, you know, if you have BMW for example, and you want to just change the battery you have to take it into a deal and get them to recalibrate that for you.
So so what is mine, what is a service who can do those things if we can't even answer that? How can we answer what's secure and and where did this data goes in the first place? Julian sounds like you.
Well, I think you have to look at the whole ecosystem right again. This is a journey and an evolution. The way I see OT devices going.
What is two sizes. The one side is just operational and looking at it from a security perspective like you look at any other device on the network that that you're you're looking for vulnerability and you're looking for behaviors that are not characteristics. But the flip side is is from a standards perspective.
There are a couple of flagelling. You know, ICS is starting to pick up some steam, but the real issue is until we start to look at it as an ecosystem. It's still going to be a place for I think great opportunity to summons point.
For lots of startups to really come in and try and provide some Synergy here. The lack of standardization is is in you know lack of efficiency is what leads to more opportunity for companies to to provide value here Yeah, and I just add I think that something to maybe kind of look out for is you know in the iot OT world. They're really isn't kind of an open source ecosystem.
And I think we do look to open sources in devops and devtools to kind of feed that origin point for new standards. And so I think you know, maybe there will be kind of an open source approach to kind of helping kind of iterate on what those standards could be that can be adopted more broadly to kind of get to some convergence across the devops process, but also kind of some of the Cyber practices as well. I agree.
Hey guys, we are we we started early and we were coming right up on time here. I need to wrap it up. summon Julien Thomas, Ron I'm so great to be able to call on people like you and we have a panel like this and subject like this you had you had to bring so much to it.
Thank you so much. We appreciate it. And To our audience.
We have a full day of great. I'm hearing an echo. I apologize.
We have a full great day of great content. I think I am due back out at around 12:30. We're gonna have a live Zoom with the audience for question and answers aren't anything devops and I'll be as part of that note to see you then.
But for now, that's it. Thank you panelist. Enjoy the rest of devops experience everyone.





