Brad Shimmin & Fernando Montenegro on AI, Cybersecurity, and Cloud Innovations | AWS re:Invent 2025
Analysts Brad Shimmin and Fernando Montenegro discuss key takeaways from AWS re:Invent, including cloud technology advancements, AI evolution, and cybersecurity practices. They highlight new tools, frameworks, and the importance of responsible AI implementation while addressing challenges in security and adoption.
Transcript
Hey, everyone. Welcome back here to Techstrong TV and our continuing coverage of AWS Reinvent. You know, one of the great things about Techstrong being part of FU is we get to kind of pick the brains of some of the FU analysts, you know, the industry, well-known analysts, uh, about what's going on in the world of tech.
And especially when we're at an event like this. We're gonna do two segments here, each with two of the Futurum analysts. The first segment is gonna feature Brad Shiman and Fernando Montenegro, uh, of fu I'm gonna give, I'm gonna let each of them kind of introduce themselves though.
Brad, if you wouldn't mind, why don't you kick it off? Introduce yourself. Yeah, Thanks, Alan.
Hi, everybody. Brad Shiman. I am an analyst with futurum, as you noted.
Uh, I, I look at data intelligence, analytics, and infrastructure. And I, I'm a software guy. I love software developments and all things databases, so I'm hoping we can, we can chat about that a little bit today.
Absolutely. And I'm Fernando Montenegro. I lead our cybersecurity and resilience practice and, uh, the gray hair comes from being around cybersecurity for many, many, many years.
There Was a time I had gray hair in cybersecurity too, when I had hair Fernando's just outta high School. Yes. Oh Yeah, exactly.
Yeah, exactly. And, and, and, yeah, I've been covering cloud security for a long time and, and, and it's been a pleasure to come to AWS reinvent for, for a few years. Not the, the full 14 that they've had it, but, uh, It's a good show.
It's a, it's an amazing show. Yep. Well, you know, an observation.
I'm glad you brought it up. Well, let's just jump in, of course. Sure.
An observation I had today, and I wrote about it in an article I put up on one of the text drunk sites. Think about coming to AWS reinvent five years ago. Mm.
What would you be talking about? S3 Lambda serverless? You'd still be talking about security bit, but you would be talking about cloud.
Yeah. Cloud nitty gritty, cloud native, managing my Kubernetes EKS. Right.
Securing that stack. How much of that do you spend about here today? So if I transported you from five years ago to today Yeah.
Would you believe it's still the same company, the same industry, the same? Uh, absolutely. I, I feel, I feel like we're still in that era because honestly, all of those concerns are still here.
They all inform what AWS is doing. They are all, they are still all in in the cloud. And you can hear that in Matt Garmin's, uh, keynote today.
'cause he, he did, did not mention when he said, if you wanna get the most out of ai, you're going to need to bring data to the ai and to do that properly, you need to bring it to the cloud. You know, that's Loud and clear everything. Yeah.
Yeah. No, I mean, it's kind of funny in that we haven't, I just feel like there's less of an emphasis on cloud or it's abstracting behind the ai. That's it.
So, so, so here's the thing. So point of order, five years ago, we were in the middle of the COVID pandemic. Yes.
So we're Right. So we, we would not be doing maybe Four. Yeah.
But, but, but point taken. Uh, I think that, um, to, to, to Brad's point, the cloud is foundational to do this. Yes.
And it's funny that you brought up abstraction. I have a, I have a thing that I talk about that, uh, go back to high school calculus, like high school maths. Mm-hmm.
The limit, like the limit for cybersecurity as time goes to infinity, to me, is anti-fraud. Mm-hmm. And what I mean by this is that we abstract away technology.
We abstract away a lot of this, and then we help businesses and buyers and sellers and whatnot talk about higher level, uh, constructs. Right. And what, and it's kind of what we're doing here.
It just so happens that I'll be, am I the first one to bring up the AI words? I think I am right. So, uh, uh, Dance won't be the last I, but, but, but that's the point.
I think that we are abstracting away some of it, but to Brad's point, it is always there. And actually, one of the security announcements had to do with, uh, uh, ECS, not the agenda points. Oh.
Had to do with ECS and E two. Right. Which was the, the, the, the, the, the guard duty, uh, support.
Right. So it, I agree with you that that's not what we're talking about as much, but it's here, it's always, it's always there. It's, it's always there.
And, uh, whether it's, whether you're figuring out instances that you need, whether you're figuring out what kind of database do you need, there were announcements around S3. There were announcements around S3 tables, I think. Right.
Uh, and so yes, you are correct that, that the topic has shifted, but the technology is Underlying, I always, The thing that powers our, our little market is that Race to Zero, trying to beat Zeno's paradox to, to always go a little bit further closer to getting there. And we never get there. And that's why it works, because we're always inventing new ways to abstract away problems.
Yeah. And to find new, interesting ways of applying this technology to solving problems. And I, I feel like that was really, um, on display today when we talked about Amazon Nova Forge.
Yes. Which I would love to spend some time talking wrote. We, we've spoken about it a bunch today.
I'd love to hear your thoughts on it. Yeah. I, I have some thoughts.
It's, it's a renaissance era for, for the, you know, more traditional foundational, large language model. It's like a re a return to form. I'm calling it.
Because instead of, like, we, we've spent so much time over the last year in investing in frontier scale models, uh, like Gemini, like Claude, et cetera, and, you know, they do a wonderful job. And when they first came out, if, if everyone will recall, we used them for POCs, and that was about it, because they were very flexible. They could do a lot of different things.
They had a great knowledge, basic work from, um, but you, for production, you went with an actual model that you fine tuned that you built. Yes. And we kind of went away from that, and we said, let's just make them do it all.
And, and I think what we learned is that that costs a lot of money. Yeah. And so, you know, if you're gonna do ai, right, like, like Matt said, you want to bring the data to the ai, and that's what they're doing with Nova Forge, is they're really trying to make it so that we actually do what we started doing a few years back in fine tuning these models to bring the data to the ai.
So I, I think it's a, it's a return to forum and I, I applaud them for focusing on it. No, I, I, so it's not anything I've seen before, which is interesting. Yeah.
And, but I'll tell you something. Two, two and a half years ago, we're gonna have Mitch Ashley on, in the next group. Mitch came to a hackathon.
We did down at Techstrong around what we called operationalizing ai. Yeah. Yeah.
And we had people like Patrick dubois, who's founded the DevOps, who came up with the word DevOps, uh, uh, John Willis. Oh, he's great. We had a lot of great people who were very, you know, early on in the DevOps movement and they were working back then Yeah.
On, on Rag and on Vector databases and S SLMs and stuff like that. And to me, it be, I'm not an analyst, but I did stay at a Holiday Inn Express last night. To me, it was obvious that not every job in AI required a, a truly frontier size LLM No.
As a matter of fact, it might be the wrong tool In a lot of Cases for a lot of jobs. It's The wrong tool. I need.
Yeah. I need a scalpel or a, or a rifle, not a shotgun. And I, I, I, I'll, I'll go one deeper.
And that's one of the things that I was looking forward to coming here and having conversations and, and we are having those, if that, I would argue that the, the lms Right. The language models in many cases, fine tuned or not right, may not be what people need. And this is one of the areas that Yeah.
Uh, this is one of the areas where like, I I, I, I was really excited, I'm really excited about the field of neuros symbolic ai mm-hmm. Which is the, you're, you're bringing the, the, the neural component that, that from the LLMs with the symbolic reasoning. Right.
And, and AWS has been doing a lot of work on that. So it was really interesting to come here and see that. But anyway, but the, the, the point being that the way that we are going to, to improve those models is by the fine tuning, and in some cases, by using these more neuros, symbolic components.
And so one of the things that I was excited about, the announcements that that, that they now have a, uh, a verifiable policy language on the agent core stuff. Yeah. Right.
That's a step in the right direction. I really like that It's responsible AI and ML lops as you're, you're talking about. Yes, yes, yes.
It's part and parcel to that. And so I, I feel like they have to, they have to do that. And if you look at all the components of Agent Core, you can see it starting to look like an ML ops platform more and more.
That's for agents, not just for select models here and there, but for orchestrated, Let me, let me ask you a question on this. Have you guys seen the letter that was circulated last week? Like a thousand AWS employees signed on to calling for responsible Really moral Yeah.
Ai. Wait, this was Amazon? Or was it meta?
No, I believe it was AWS Okay. Interesting. Interesting.
Yeah. Well, you know, it's, it's, uh, it's very much, and we saw it actually the beginning of the keynote this morning. The very first words on the screen were why, and the, the response was, why not?
And that's the era I feel like we're in right now, is, well, let's just dam the torpedoes and see what happens. And I, I don't think we can do that. No, it's, it's, we should not be doing that and yet have been because it's all about time to value.
And we've found with transformer models in particular, that we can shortcut that time to value, but we can't shortcut the hard work. And that's why things like fine tuning are so important because it's another tool in the toolbox. It gives you, at the end of the day, a model that actually, as you said, has a scalpel to do what you wanna do, do it performance, do it in a secure, safe manner, and do it in a way that you can actually make some money.
Absolutely. Lemme bring up another thing. You know, coming in yesterday at the airport, I was reading all the, the electronic billboards.
Yeah. I'm a sucker for them, but I saw one from Databricks that really caught my eye. I don't know if you saw this one.
Our A AI agents don't suck. Remind me of the old, you know, we suck less, Suck less software is alive and well today, today suck. Yes.
Yeah. Well, now it's called Suck Less Agent ai, maybe. Oh, come On.
That's never gonna happen. But okay. It's like agentic ai.
It's the antithesis of Suckus software. It's like whatever you want it to do, it'll Just, it'll do it for you. Yeah.
Just do it for you until it doesn't. Yeah. Until it doesn't, until you check clears.
Anyway. Um, but you know, we, we certainly are in this, Brad, you're right. You want, we could, we you want an agent?
I got an agent right? In New York. It's like that.
But you, I got an agent for you, but we're also seeings a kind of a, a Cambrian explosion, if you will. Sure. Right.
Like, I, I had a, a fellow we interviewed up here this week or today rather, who comes from, um, uh, SE Agentic AI. For S se not for SEO. For SRE.
Okay. Yeah. Sounds great.
What a great idea. We need that, that's something we could do. Of course, he's one of six agent AI for SREs that are here.
Uh, may I say seven? Because, Because you know of what too? No, no.
Because one of the announcements today, It was AWS themselves, AWS themselves. Right. And now check Your watch, because we might have another one.
Another one. But, but, you know, but that's not unusual for, that's their model. Look, we're gonna give you 80% for 20%.
Yes, that's right. That's a lot of the AWS model. But I, I do think we are in a, you know, a Cambrian explosion of life, if you will, of ai that some will, some will make sense three to five years from now.
Yeah. And some will say, what were we thinking about 12 eyes and six legs? It just, you know.
Well, a lot of it's gonna disappear because as we saw early on when we had a lot of wrappers, as you'd call them, around chat, GPT, are they in business anymore? No, because you don't need them. I'll tell you what else I think might disappear.
Mm. Everybody and their mother has an MPC server. I have one right now.
Yeah. Yeah. I mean, do we, why can't we have an open source one that we all kinda standardize on?
Kind. And this is the open source model, right. And then build on top of that, build functionality.
Like, but that's on top of Yeah. But that's what MCP is, right? MCP is by itself, like an open, It will evolve into what you're talking about, Alan.
Yeah. I I think we don't need 10 different MCP service. No, there's an X-K-D-E-C.
Sorry. XKCD. Yes, I know exactly.
We need a standard next panel. We have another standard for Yeah, yeah, Yeah. We have 13 standards.
We can't do it. We need another one. We need a one single one.
Now there's 14. That, that is the way it goes, isn't it? Yeah.
I, Fernando, I gotta talk security with you a little bit. Of course. So I had another fellow I interview today, smart guy, zest security.
Okay. I don't know if you heard of these guys. The founder there came out of, uh, oh, they sold to Palo Alto Cider, remember cider Yes.
Security. Yes, Yes, yes. He claims zero.
They could get you down to zero vulnerabilities using ai, agentic ai. That's Bold. I, I I I, I told him, I I said, say that again for the people in the back.
Don't hear Me. Yeah. I think that there are, um, there's multiple ways to interpret zero vulnerabilities.
Right? Okay. In the context, like when we have conversations about vulnerability and security, the first question I want to ask is, okay, am I talking to an ops team or am I talking to a dev team?
Very different measures. If I'm talking to a dev team, zero vulnerabilities means one thing. If I'm talking to an ops team, zero vulnerabilities means something else.
So in the context of I think they learn more on the developments. No, he, so I agree with you. I mean, you and I both know.
Yeah. I have a security background. He was talking about the security team in ops, like tra not AppSec vulnerabilities.
Like true, True vulnerabilities. And, and, and, and, and that, and that is, uh, um, like, again, I, I applaud the, the, the, the, the, the gusto. But I, I struggle with it because this is the trick that, that security teams are learning the hard way.
There are vulnerabilities that you don't fix because it's too expensive. Yep. Right.
Because given the risk, Well, it's a manage, it's a risk management. It's A, it's a risk management conversation. And then like, like here, for example, here we are having a wonderful conversation.
Uh, some of these doors are open. That open door is a vulnerability. Right?
Should Say Windows 10 at the moment. Should we talk about that? Yeah.
We talk Windows 10. We might as well talk Windows 98. That's a whole nother story.
But, but, but, but I think, but you know what your reaction, he said, that's exactly what we hear from CIOs and CISOs. And then we show them. I'm going to introduce you to this gentle, I'm happy to chat and I'd love to hear you talk.
I'm happy to. Yeah. Guys, I gotta wrap this little portion up 'cause we've got more analysts waiting.
Sure. Hate to keep analysts waiting. But let me, let me pose question to each of you and, and, and we will go with that.
Brad, if I had to ask you for one story, that's the big story at Reinvent this year. And we've, we've skirted on all of them. Yeah.
But for you, what, what's the, what's the, you know, the key takeaway? Well, for me, uh, I would say that it is, you know, the, um, Nova. Um, but I'm not, I I, I want to actually instead pre pre, you know, get ahead of what I know Mitch is gonna talk about, uh, when it comes on.
And, and that is Kiro and that is age Agentic development. And the fact that on stage today we heard from Matt that the company has committed itself to using this platform to develop their software in-house. That is very much, you know, a bold statement.
Yeah. Because I, I, I feel like a lot of these companies try to sell us on you yet another agentic, IDE, blah, blah, blah, blah. But they really put their money where their mouth is.
Well, AWS is trying to do that. So, we'll, I wish them luck, and I, I think it's, it's gonna be interesting to watch. One last thing for you.
What wasn't on your Bingo card coming out here? Uh, well, you know, I wanted to hear more about data, honestly. Uh, and, uh, we, we didn't have a lot of of announcements about that.
So my Bingo card was all filled with, with like slots about what's happening with their various databases. I didn't get too much Of that. No, I haven't, I actually haven't heard much at all.
No. I would've loved to have heard something about a semantic layer, for example, because every other vendor, we mentioned a couple of them with Databricks, and, uh, right now, if you're gonna do a lot with ai, you're investing in a semantic layer. Yeah.
But we're not really hearing that from AWS So I, I would encourage them to, to really kind of rethink that in their go to market coming up in the next couple of months. Fair. I wonder, well, I don't want to be Doctor Evil, but I wonder if that means AWS is working on their own semantic data layer.
They have been known to build internally. Yeah. Yep.
Fernando, let me come to you. What's your big story? My big story comes in two pieces.
Uh, you know how we always talk about security for AI and AI for security, yeah. Third one being security from ai. Uh, I think that we saw the announcements today, the security for Agentic and the agentic for, for security.
And the big story for me is that on the security for Agentic, it's how they've woven the conversation of Bedrock has security, bedrock has it built in, bedrock has it, and, and then, and then you take the policy agents from, uh, the, the, the policy language. Now an Asian core. So I think that I, I encourage my security colleagues to, as you are thinking about Gentech, you are, you have to look into what security is coming from the platform.
Yeah. And the other big story is ag gentech for a security. So just like the DevOps agent there, there is now an announcement for a preview for a security agent that is going to be doing a lot of the, Hey, let me fix that code for you.
Now the devil is in the details, right? Uh, but what kind of things is it going to fix and what kind of things is it not going to fix? But importantly, what's the, the, what's the play the interplay between a true security, uh, uh, professional doing a pen because it's going to automate pen testing.
The theoretically, theoretically, sorry, forgetting English. Uh, where do you draw the line? So if you're, if you're a developer and I'm a security, uh, engineer, what have you, and then do I now code my policy at my company to say, look, as a developer, you are, um, uh, you're going to do multiple things for security, and you are going to already run a pen test, and then I'm just going to test the results of the, of that pen test.
Right. Or am I going to it? It's great that you ran a pen test, but you know, like trust, verify, Verify, trust.
Good. Verify, verify. I'm gonna do it.
I'm going to do it too. So I think that that's the next level of conversation. So I, I think there'll be a human in the loop conversation there.
Lemme play devil's advocate a little bit though. Sure. The DevOps agent to me is an alert monitoring tool.
That's what it sounded like from what I heard. Oh, I don't know. The, the advertisement we saw The advertisement was one thing, but when you read, when you read, yeah.
It sounded like alert logic to me. But, okay, we'll, we'll go with that. Well, actually, let me ask, lemme tell you, uh, what I feel that is going on there is that they're not gonna deliver it today.
'cause they're gonna build for The preview. It's A preview. Yeah, exactly.
And, and what we do see them doing is working on long running ag agentic processes. They talked about that a lot today, as a matter of fact. Yep.
And what else is, you know, building safe software then a long running process of monitoring your code base, testing your code base. That seems like what it ought to do. Yes.
That is what it ought to do. You know, there's an old saying, I learned in law school about what you do do and what you ought to do. That's the difference.
You Do, you're Not gonna get caught doing Your comment on security there. I gotta tell you the truth. I had a deja vu to 2007, the cloud, I can't put my stuff in the cloud.
It's not secure. Don't worry. We built security into the platform.
We keep, We didn't buy it then. I don't know if we buy it now. Yeah.
We keep moving the layers up. I think It depends who you are, right? If you're a big company, maybe you question that.
If you're a small company, you're never going to have provide That until, until, well, that, and then it Gets a little bit better. And, and, and, and I go back to my thing about abstractions, right? We've now given developers more capability to do more things.
So instead of, you know what, that budget for a pen test that was going to find 50 vulnerabilities, and out of those 50 vulnerabilities, 35 of them could have been found mm-hmm. Automated in an automated fashion. Now, perhaps that same budget can focus on more critical vulnerability.
Just those 15. Yeah, Exactly. Because we've asked you to do this.
I'm optimistic, Always the optimist. I, I'm, I'm, I'm, I'm optimistic. We, we are.
It's, it doesn't have to be perfect, right? It doesn't have to be zero. Nothing is Perfect.
It's never, we're never gonna get to zero. We're never gonna get Know that. Right?
That's risk Management. Risk Management and said zero. I almost fell outta my chair.
Yeah. Anyway, Brad, Fernando, thank you so much for coming up here on Tech Drug tv. Thanks for Having us.
Appreciate A pleasure. We'd love to have you. You know, we do these remote, you don't have to come to Vegas to see us.
And, and may I remind you that we are kind of halfway through, so there's, there's still, There's still, still. And we'll be here tomorrow and the next day At least six more keynotes. Yes, There Are.
Yes. And, and, and there are, and, and, uh, just, just to, uh, sidetrack a little bit, one of the things that I was really interested in is this whole agent and, and, and, uh, and, uh, neuros symbolic stuff. But coming alongside that, there's other things going on.
Like, one of the areas that's super interesting is like confidential computing, right? Yeah. Mm-hmm.
Oh, that's, we we're seeing from a AWS do some interesting things there. So let's keep talking about this and, and, well, Now, now you invited yourself. You know where we are.
I have no excuse. We can do this remote. Yeah.
Alright. Hey guys, let me just remind you all Futurum does a thing called the Futurum signal. It's, it's the report that we've put out in, in different practice areas.
Fernando's done one. Brad's done one. The next two folks that we're gonna have on have done what, unlike a lot of other analyst firms, these reports are available to you.
You could go see the whole, I think, virtually the whole report, right? Yes. Yeah, yeah, yeah.
Sign Up. And it's an amazing look at using ai. If you looked at our life coverage earlier, Daniel Newman and I had a great discussion on this.
I encourage you to all go look at Futurum signals, check out what's in there. This isn't last year's information given to you six months after the fact, right? It's, it's the, it it, I don't want to say it's up to the minute.
It's not continuous yet, but it's a lot more current than the 18 month old stuff you may have been used to. So go check out FU Signals. These are the guys behind it.
We're here at AWS Reinvent for Text trunk tv. We'll be right back. We've got two more great analysts.
I want to introduce you to.