Navigating AI Adoption with Splunk’s Paul Kurtz
Transcript
This is Textron tv. Hey everyone, welcome back here to Textron tv. Um, my next guest is someone I have had the pleasure of knowing for years and years, but I think this might be the first time he's on Textron TV with us in, in his role here.
Let me introduce you to my friend, Paul Kurtz. Paul is the Chief Cybersecurity Advisor and field CTO for Splunk. Paul, welcome to Tech Drunk tv, and thanks for joining us.
Great to be here. Thanks, Helan. Pleasure to have you on.
So, Paul, I, you know, I'm familiar with you and your career, but, and it's, and it's been quite a career, but, uh, people in the audience may or may not be. Why don't we start off with a little bit about the Paul, Kurt, Kurt story, if you don't mind It? Sure.
Yeah. I, I, I feel like I've had a, uh, a fairly lucky, uh, uh, career. I, I started off in, in government circles, uh, working on, uh, counter-terrorism and weapons, non-proliferation issues.
And, uh, was, uh, at the White House, uh, prior to nine 11 and, um, uh, went through the whole nine 11 experience. Uh, but then on the other side of that, uh, I was asked to pick up cybersecurity. So I've been at cybersecurity for over, uh, over 20 years now.
It's hard to, hard, hard to believe. Uh, and in that context, in cybersecurity, I've done a variety of different things. I, I ran a nonprofit, which was the first organization focused on, uh, cybersecurity policy.
Spent some time working with folks up on the hill. Uh, then I, uh, helped, uh, uh, other countries establish their cybersecurity programs, especially out in the Middle East. And then I started a company called True Star, uh, co-founded it, uh, with a friend of mine, Patrick Coghlan and, uh, uh, and True Star for several years.
And ultimately, uh, uh, Splunk acquired True Star. And so now I'm, uh, with Splunk and serving, uh, uh, doing some fun work, some very interesting work with, uh, our largest customers. Absolutely.
You know, I, I, I have to chuckle when you say I, I've had, I've had a been a bit lucky in my career. I'm reminded of, uh, you know, the quote from Branch Ricky, right? From the old, uh, Dodgers executive who said luck was, was it 80% perspiration and 20% inspiration, or, or something like that.
Right. Um, we make our own luck is, is the bottom line. And, and look, it has been a quite a ride, a distinguished career.
And, and look, the cybersecurity, I think the cybersecurity field has been lucky to have you as part of part of it as, as a leading voice in it. Now, in terms of Splunk, our, our audience is familiar with Splunk. We, we cover Splunk a bit, and they are one of the leading players here.
Of course, the recent news or the big news with Splunk has been, you know, a potential acquisition by Cisco, which is still being worked on, is unofficially closed. And that's all we're gonna say about it. But Paul, in your role as Chief Security advisor at field CTO at Splunk, what do you do actually, if you don't mind me asking?
Yeah, It, it's really interesting. It, it's, um, it's a, it, it's a terrific role because in my role, I work, uh, closely with CISOs or CTOs, and what essentially we're trying to do is make sure we're working in partnership with our customers. And so sitting down with a CISO or CTO, it's, it's understanding what their priorities and challenges are at a, at a higher level.
And, and then taking and looking at our capabilities that we can provide through Splunk and see how we might be able to, uh, assist, uh, our customers with, with really big problems. And, and I kind of look at it, it's, it's almost like being a, a, a doctor that sees a lot of patients, and you can sit down and you assess the situation, and then you can go from, if you will, patient, customer, patient, customer to patient customer, and you can begin to relay how different customers have addressed, given problems. And of course, the more customers you meet with, um, you know, the greater, you know, your capability is in order to, if you will, to offer advice or counsel, uh, to a customer.
And really where we are now, and we're gonna talk about ai, there's a lot of angst in the community. There's a lot of excitement, there's also a lot of angst. It's like, what is this gonna do to our IT infrastructure?
And so having a partnership with our customers is, is really critical. And I, I spend most of my time doing that. Do some, uh, thought leadership pieces.
I do some writing, uh, for, you know, internal use and for external use, uh, as well. Excellent. Excellent.
Well, that's a great role for you too, Paul, if you don't mind, I want to turn to what kind of is our main topic of discussion, which is, uh, recently Splunk did a survey on AI priorities, obstacles, and its impact on cybersecurity. Now look in the tech, not only in the tech world, in the whole world in general, these days, it seems you can't walk more than three feet without tripping over ai. People say it's either gonna be the greatest thing ever to happen to mankind, or it could be the unleashing of, uh, of, you know, all hell breaking loose.
But the truth probably, as it often does, lie somewhere in between. Tell us a little bit about this survey, if you don't mind. Why, why did you know, why did Splunk do it?
And let's discuss maybe some of the findings. Yeah, I, I think the reason why to do it is kind of coming back to what I talked about before. It's like, you know, understanding where your customers are coming from, what are they looking at, what are they thinking, uh, what are they feeling, what are their, what are their concerns?
And trying to get an initial assessment, is there how they're thinking about ai? Uh, I'm a big fan of not operating in a vacuum. Yeah.
We have to do our part. We have to, we have to talk to our customers about how we seek to, uh, help them, um, with, with ai. But it's, it's getting that feeling of what we're where're, where are the customers looking.
And, and what I think is fascinating about the results of the survey is, you know, a lot of it is leveraging AI to bring more automation into the space. 5 or four coming out, uh, uh, last year, or excuse me now I have to say, the year before in, in, in 22, late 22, um, we were already seeing a push to automate more, uh, there an understanding inside enterprises that we're never gonna have enough humans to look at the volume and pace of attacks and, and or, or the, the general telemetry from security to, uh, observability, uh, to DevOps. We just, we, we don't have enough humans to, to, to, to do that.
So we have to automate well with ai now we have a, a, a capability to, you know, get in the fast lane of, of automation and, you know, there's AI and there's, uh, a GI, and I think really now what we're talking about is really, um, uh, the ai, uh, not that if you will, putting together new information, uh, right. We're, we're not there quite yet, but at least leveraging AI to improve automation, uh, to make, uh, tools easier to use in the context of Splunk. One of the things we've done, which is really simple is, you know, can you use an LP natural language processing to structure Splunk queries, um, make life easier for your customers?
That's a very simple thing to do, but it in the impact is important because you get customers now that don't have to spend the time as much time on the trainee in order to use a product, if that makes sense. Absolutely. So Paul, I always like to try to undo the alphabet spaghetti for customers because I, I think, uh, people understand AI stands for artificial intelligence.
But when you say a gi, what are you referring to? Yeah, artificial intelligence is basically being able to draw conclusions off of an existing data set. Uh, Dixie, uh, uh, an existing large language model, a GI gets you into, um, um, uh, producing new information, new insights, uh, say, you know, an understanding of it's a new understanding or new ideas and nuances that, um, could be brought to light.
And so that's where we, the, the difference is they're, they're, they both involve automation clearly, but one is looking at existing information. And the other one in a GI is, is being able to draw different conclusions that cure to four we didn't have. And so a GI is artificially generated, or it's not generative AI anymore?
Or, or, Or, or where does This all come Together to call? You could call it generative ai, uh, too is a GI. Yeah, they, they're, if you will, uh, it, it's one and the same.
Yeah. Just wanted to make sure we're talking. No, it's, it is alphabet, you know, because When you go into a new area, we, if we got it, it, it starts with the language, right?
If we're, if we're not all, if it means something different than it to you, then it means to me or to someone else watching this, right? This is where we get into, people don't understand. Alright, so let's jump in.
What, what did we find out in the survey? Well, within the context of the survey, uh, as I, as I mentioned before, a lot of it is about automation. So, okay, well with automation, what, what are we actually doing?
And I think where we're, where we're seeing, uh, it started to play out is in the context of monitoring, uh, compliance is, uh, is always going to be with us. It's a very tedious, uh, operation and, and, and, uh, AI helps us address compliance issues with, uh, less tedium. Absolutely.
Now, as, as you know, coming full circle to what we were talking about earlier, yes, there's a tremendous potential for good to automate, to make jobs less tedious to, to do all these things, but there are obstacles in, in adopting this a GI as well as ai, um, you know, from an observability and cyber point of view. And then there's also the whole idea of being able to secure some of what we're doing around ai. Um, what, if any, did the survey touch on that, any findings from the survey that may be irrelevant to that?
Yeah, well, certainly, you know, once again, I, I feel like a broken record, but I'm gonna go back to the issue of automation. How can you, um, leverage AI to automate vulnerability identification? Uh, how do you, how do you expedite that process?
How do you expect expedite the mitigation process? So there's identifying the vulnerability, mitigating the vulner vulnerability. Um, and this is where I think, you know, uh, AI's particularly beneficial when you develop a store of, of data, uh, of, um, if you will, uh, whether it be existing vulnerabilities, uh, or the means to, um, uh, attack those vulnerabilities of being able to le leverage those type of data sets in real time in order to improve security.
I, I think that's, I mean, it's, it's fairly, um, well, much easier said than done, but it, it is fairly straightforward to those two, uh, those two pieces are, are, are, are quite significant. How do we more rapidly address vulnerabilities and how do we mitigate those vulnerabilities? Okay.
Um, you know, I'm, I'm reminded Paul Beck, when I was a company, I had co-founded Still secure when we first started coming out with our vulnerability management and network access control tools. A a lesson I learned when it comes to security is just because you can't, doesn't mean you should. Right?
Especially when it comes to remediations and or blocking traffic or, or what have you. I'm wondering if anything in the survey popped up about people sort of hesitant to go full bore into this, taking more of a kind, well, let's see, a wait and see approach to things. Look, I don't think people are, um, um, operators are not jumping into the DeepEnd pool.
Uh, they, they are, they're waiting in at, at the shallow end and, and, uh, doing things that, that make sense that, that they can understand. I think a lot of the problem with AI or a GI both is, um, alright, what's my, what's my level of control? You know, how do I actually understand that or what the output I'm getting from AI is, is, is true, it's solid.
We've all heard about hallucinations, uh, those kind of things. And so it is definitely wa into the pool at a slow pla at a slow pace, um, you know, taking on very particular tasks. And, and that's what we're hearing from customers too.
They, they do want to, they no doubt they see huge potential in the adoption of ai. There's, you know, surveys out there like McKinsey and Company have done, it's like, you know, the, the, the potential for, uh, uh, AI to streamline operations, having nothing to do with what's fun has done in their survey. And, and, but they, they testing going forward, testing going forward.
Um, and, and that to me seems to be a very reasonable thing to do it. Once again, it's really important for, you know, vendors like Splunk, uh, to, you know, step hand in hand with our customers in partnership as they begin to explore ai. And it's up to us to explain how we're gonna leverage AI to their benefit.
Makes sense. Paul, we're just about out time for people who wanna maybe dive into the survey a little bit, see the report, find out kind of what, what, uh, came out of it. Is there a place on the Splunk site people can get to this?
Yeah, it, it's, it's available, uh, on our website. Paul, first of all, happy New year, my friend. It's a pleasure to have you on here.
Here's to a great 2024. Keep up the great work. Thanks for being here.
Say hello to all our friends at Splunk. Okay. Hey, thank you Alan.
Pleasure being here. Alrighty. Paul Kurtz, chief Cybersecurity Advisor and Field CTO at Splunk here on Techstrong tv, talking about Splunk's survey on AI priorities, obstacles, and its impact on cybersecurity.
We're gonna take a break. We'll be back in a second with more text on tv.