IBM’s Nataraj Nagaratnam on Sovereign Cloud Capabilities
Nataraj Nagaratnam explores how sovereign cloud capabilities can help enterprises navigate geographic requirements around data privacy, data residency and more in the age of artificial intelligence (AI).
Transcript
This is Textron tv. Hey everyone, welcome to another Techron TV interview. I am really, uh, happy to introduce you to Naraj Nagar, and I hope I got it right.
Naraj. I, I know I got that right, nanu. I think I did.
Okay. Naraj, welcome. I hope I didn't mangle your name too badly and your family won't be upset with me.
Not at all. Uh, Alan, thank you for the opportunity and glad to be here and, uh, looking forward to the discussion. Okay.
Naraj, you are, well, you're an IBM fellow, and I happen to know what that means, and I think there are people out here who do as well. But really, it is quite a, an accomplishment, if you will, to become a fellow at IBM. You're also the CTO for cloud security.
Before we jump into that role, for those maybe who aren't familiar with what it means to be a fellow, right, um, uh, uh, at i, a company like IBM, why don't you give 'em a little history if you can? Um, sure. It's a, it's an honor and, uh, privilege to be, um, appointed an IBM fellow.
Uh, what that means is it's a reflection of the technical and business impact that an individual would've had over the years, um, to the IBM business and to the industry, not just to the company. Um, started in, uh, sixties or so, uh, over the last, um, um, so many decades. There are less around 300 fellows that have been nominated.
So you can kind of out of 300,000 employee range, and there are less than a hundred fellows that, uh, are in IBM today. So it's the highest technical, um, uh, appointment, and it is personally made by the CEO, uh, and a reflection of an individual's contribution. So I've been honored, privileged to be at IBM and, um, to be, uh, appointed an IBM fellow.
Congratulations on that. One thing I always get confused though. D distinguished engineer, then fellow, right?
Yes, fellows above distinguished engineer. Okay. And then, of course, as I mentioned, you're also the CTO for cloud security.
Why don't we, if you don't mind explaining to our audience a little bit what, you know, what, what exactly do you do in that role? Yeah. Um, in my role as a CTO, um, in that context, I work daily with our customers and across the industry, um, on few trends, right?
One is, uh, as the industry trends, the customers are failing, facing certain challenges and problems. For example, as they look to adopt ai, um, how does, should they approach in terms of security and compliance, working with them, understanding the landscape, building, providing solutions, which make it into our products. So driving our technical strategy and offering strategy that we can deliver to our clients.
So I work with our customers on one side, on a daily basis. I work with our development teams so that we bring these together. At the same time, I also work with industry through consortiums and collaboration because one size doesn't fit all.
Now, one, one vendor solves all problem. So, as IBM, from an open strategy perspective and ecosystem perspective, work with other vendors and partners to solve problems. So solving real problems with innovative solution that differentiates us and helps customer adopt new technologies is where, is what, uh, motivates me and inspires me every day.
Absolutely. Um, just congratulations, really. I mean, what a, because being a fellow is a great accomplishment, and, and, you know, you don't reach the level of A CTO at IBM for CTO for anything without that passion that I think comes through loud and clear with you.
So, uh, congratulations and, and thank you. Um, let's jump into our topic of discussion, which today we're gonna talk about navigating some of the unique country requirements in this, you know, as we talk about sovereign cloud, and of course, AI affects everything today. So how's AI gonna play into that?
And I guess in order to discuss that, people have gotta realize, and, and I'm, I think most of our audience does, right? That when it comes to cloud, different countries, different states, different entities, different verticals have different requirements about where data is stored, where processing is done, who is, who else is on that particular node, who, you know, who, how it can be accessed, what have you. Um, and, but that's always been relatively true of the cloud, right?
We had GovCloud and, you know, all of these different things be because of that. And it's also why some of the big cloud providers set up specific regions where, Hey, you just want to be in North America. All your stuff is in North America or the US or maybe all your stuff's in EU countries.
Um, but it's gotten a little bit more complicated than that. And with AI and, and some of the other things, I don't know this, like you do not, Raj, why don't you, you could probably do a better job than me, I'm hoping and expecting. Um, sure, Alan.
So, um, you step back a bit, um, and in my experience over the last 25 plus years here in the industry, when web came along, that's when I rolled up my sleeve, a sleeve to solve the security aspects of a new spin up application servers. At the time, it was a network centric view of security. Anything, um, behind the firewall is trusted.
Anything outside the firewall and the internet is untrusted simple, but we all know like breaking, like breaches happen, attacks happen, et cetera. So there's a lot of things that we have learned from that network security world over the time as it moved to mobile and cloud. And now to ai, I fundamentally believe we are onto a data centric world because data is the, um, uh, it's all about natural.
It's like a natural resource. It's the economy that drives, um, asset, that drives a business economy, or for that matter, even in a, a country's economy and so on and so forth. At the same time, the lessons learned over the years also reflects that the data is not about the, not only about the business data or the government, but it's also about each and every citizen, the consumer.
And so the interest of the consumer, individuals like us, when we log into a bank, and if our ID gets, uh, stolen, we are impacted. Therefore, it's the responsibilities of the governments and regions to look after us. And that data, therefore, in the context of a data-centric world, regulations have started to emerge over the last decades, as, you know, like GDPR came along with Europe, in Europe, but more and more as you look at it, it's not only about security, it's about how do you provide regulatory oversight?
How do you mitigate risk from a business and an individual data perspective? And how they come together. This is where the continued focus is.
There are global level standards, like industry level standards on how do you protect data and, and, and your applications and your network and all of the good, um, uh, good things At the same time, based on the geopolitical aspects of a region, they introduce new regulations and requirements in the interest of their citizens and countries. Therefore, over the last two, three years, the, um, increased focus in every region, not only in Europe and US, but Asia and, um, many other, um, regions and countries. There are specific regulations and laws that have evolved, much more savvy of the technology, not just about a process, but into the technology.
Therefore, in the context of AI and hybrid cloud, the regulatory aspects, compliance requirements that is focused on mitigating the risk of like losing individual data or the economy of the country, um, or even resiliency in which a utility like critical workloads that run on clouds, uh, have come into forefront of these discussions. This is where the discussion around sovereignty come into play. Because even if your network outside your country gets cla, uh, cut, if you kind of simply think about it that way, can the applications, your banks, your infrastructure, your utilities, your power grid, can it run and be secure are kind of the focus.
Because more and more critical workloads, mission critical workloads are moving to cloud. And AI is just opening up, opening it up even more in terms of what of the possible, I I couldn't agree more with you. Agree.
You know, I, I just came off another recording for our text on gang, and we were talking about AI all, you know, with elections coming up, AI and maintaining LLMs and so forth, there's another side to the AI conundrum, and that is people seeking to circumvent country requirements. How do they use AI or, or, you know, some of these things to, to circumvent the requirements, basically, right? I mean, there's, there's a dark side to it, and one has to ask themselves, in a world with AI in a world that's drawing together in a more and more interconnected world, can we really continue to have sort of these unique requirements and, and have faith that they they are what they are, what we think they are?
Yeah. Yeah. Um, you're absolutely right.
Um, so if you think of that journey, uh, from hybrid cloud to ai, like you're pointing out, and if you take a look at it from even industry perspective, right? Even, uh, a general practice of how do you secure your data or your applications, but then when it comes to specific industry like financial services or healthcare, they're much more risk hub, right? I mean, they're looking at their dealing with sensitive data and the mission critical, uh, uh, application.
So we work with industries, regulated industries, and we focus from an IBM cloud perspective to build the best and breed of secure compliant and resilient cloud infrastructure, hybrid cloud infrastructure for those regulated industries. So that's our focus on enterprise cloud. Now, as AI has come along, the focus on that kind of regulatory aspects and, uh, mitigating the risk as an enterprise cloud is increasing multi-fold, because now we are infusing data, especially with generative ai.
The order of the possible in imagination is what if, if you, you infuse and mix all the data together so that you can get the best outcome. Well, if you mix it, it's a grinder, you put it in, you don't know what comes out because it depends on the data lineage, what went in for it to respond, right? So the focus is increasingly the transparency to what really went in to make that what are called models, generative AI models.
And then when you use it, have the level of confidence and transparency and assurance on how to use them. How do you build applications? So this is a journey.
We are at the cusp of, um, imagination and what could be done at the same time, the risk is high i in, in terms of understanding it, especially if you don't use it correctly. Therefore, we are working with the industry on what are all the best practices to build secure and trusted ai, um, and in, and building them and deploying them on IBM cloud as well as our watsonx services so that it has the trust from a watsonx perspective on governance privacy. And as it, as you kind of infuse them together from AI and hybrid cloud technologies, it can then start to address the sovereignty requirement.
Because if you deploy, if you, going back to your sovereignty question, let's say in Europe, we worked with customers like BNP Paraba, uh, it's the largest bank there, and they have global presence, and they, they needed the level of assurance, technical assurance that they have full control of the data. Because even from a critical, uh, application perspective, data is important from a sovereignty perspective, data sovereignty, which deals with privacy and residency become important is the data. Does it stay in country?
Who has access to it? Do you have full, um, control of the data, the key so that even the operator cannot access it? So we solve that problem for them and customers like them, and Isha and others in other countries have started to, um, use this infrastructure to address that data aspect given the sovereignty, regional requirements, et cetera.
At the same time, when you look at, um, more emerging aspects of ai, going back to your question on ai, how do you ensure the AI models, the AI system, the data resides in a particular country and in infrastructure control? Another pattern that we have seen is it's not only on a public cloud infrastructure, IBM cloud, we are with our hybrid cloud mission. You can deploy these capabilities in an infrastructure and a provider of your choice.
Imagine that cloud comes to you, right? Therefore we, for example, recently we announced in working with a Phoenix system, um, if you look their webpage, they will call themselves the Swiss sovereign cloud in Switzerland, right? Mm-Hmm.
Now they have the infrastructure powered by IBM infrastructure technologies like ZP and other, um, uh, vendor hardware and system technologies, but we deliver platform services like watsonx on top of it so that they can provide AI services to the regional companies and, um, governments that they need, and they announce an ai, um, set of capabilities based on what we, uh, provided. So from cloud and data sovereignty is evolving into even AI sovereignty. That's the beauty of how these technologies evolve.
Yeah. And we are being proactive and prepared for it. That's a fantastic story.
You know, so I agree, right? Data, data has become paramount. It was always paramount, but somehow we forgot we got focused on applications.
But it's all about the data, right? It was always about the data. And now though, you're right, this last piece of it is, okay, once we set all of our sovereign kind of protocols and we're in compliance and all of that, now we're gonna run AI on it, right?
And, and because we need, not we, but certain customers, certain entities need that certainty of, of, of what it is there on and, and who could access it and when, and everything else. I mean, look, just the last few weeks, the headlines of the last few weeks remind us that everyone's a target. Everyone is a target.
We've had so many huge breaches in the last three, four weeks. Again, it's, you know, it's funny, whenever RSA season starts, it seems we have more breaches in the news. I don't know if there's a connection there or not, but, but nevertheless, we've seen some big breaches this last couple weeks.
Um, so you mentioned a ai IBM is, excuse me, IBM is, is helping customers with this, and it's not necessarily in a public cloud. It could be private cloud, it could even be, you know, kind of on-prem and or hybrids the right word. Yeah.
Um, you mentioned Z systems, right? Mainframes and so forth. Uh, they're all that, that's the thing about the world we live in today.
It's is it's not, everything's not discreetly packaged, right? These things all blend in together into a modern solution. And, you know, especially at the enterprise level, that's what, that's what these enterprises need.
They can't afford to be siloed. They can't afford, you know, to have that, that kind of isolation, if you will. Um, where do you see this go?
We're almost outta time, but where do you see this now evolving course, AI's gonna continue to have a outsized effect here, but what else do you see coming down? Um, I think there's a lot to be done in the space of AI itself over the next few years as a maturity, the use cases become concrete. Um, that's why, yeah, for example, the recent announcement that we did of IBM cloud's presence in Montreal, because mm-hmm, from a sovereignty perspective, it's not only data sovereignty, but it's also operational sovereignty.
Can you have resilience? So with what we already had with Toronto, no, we have with Montreal, customers can deploy within two MDRs and deploy that, and they can deploy AI workloads that addresses some of the sovereignty aspects of it. At the same time, to your question on ai, um, in terms of driving, um, very, uh, focused efforts, working with the industry, working with the governments on, uh, precise regulations and, um, best practices as we build these out is important.
So we have been pioneering in that building our models with very much transparency. For example, IBM's granite model, we publish, think of it as a nutrition label on where the data is coming in and what data we have used, et cetera, et cetera. Because when you consume something today, when you, um, get some a food and want to eat, then we look at the nutrition label many times and said, what is in it?
I'm a, I'm a vegetarian, so I look at to make sure that I can consume it. Similarly in ai, you need to look at the nutrition label of the AI system and the model to understand does it apply to your use case? How do you use it?
Then as you use that model, does it run in a infrastructure and environment that provides you technical assurance in terms of the protection of your data, the privacy and operational sovereignty, which we do with our IBM cloud and enabling with what's next. So these patterns are going to evolve much more. And another thing you mentioned in terms of how this is like coming together, productivity in, in the industry at this time is paramount, therefore more automation needs to happen.
So how do you automate these patterns of deployment of AI use cases and hybrid cloud use cases? And that's where we are focused on as a strategy across hybrid cloud and AI to solve this for enterprise customers. Agreed.
Agreed. Um, you know, there's that old saying, may you live in interesting times. It certainly is interesting times right now.
Naraj, I appreciate you coming here on text Drunk TV and, and talking with us. Hope to have you back soon. Keep up what you're doing and, and please keep us posted.
Thank you so much for hosting and for this is a wonderful discussion, Alan. Um, have a good day. Thank you.
Thank you. Naraj Nagar, IBM fellow CTO for cloud security here on Tech Trunk tv. We're gonna take a break.
We'll be right back.