Resilient Organizations, Teams and Partnerships – Cory Minton and Ryan Kovar, Splunk
Beyond uptime and MTR measurements, leaders look to build resiliences across the organization, their teams and partnerships. Splunk’s Cory Minton, Field CTO Americas, and Ryan Kovar, distinguished security strategist and leader of SURGe, take a people, processes and technologies approach to building organizational resilience.
Transcript
This is Textron TV Of the pleasure of being joined by Ryan Kovar. Ryan is distinguished tech security technologist and leader of Surge with Splunk and Corey Minton, who's field c t o, Americas with Splunk. Welcome guys.
Thank you. Good to be chatting with you both. You know, a a, a topic that's very top of mind for CISOs or IT leaders of course, is how do we, how do we create a resilient and dynamic organization that can keep pace with the business and the change that we see in the technology landscape, whether it's our own infrastructure, own application portfolio, cloud, et cetera, all of those things.
But also, of course, the tax services that are evolving and changing is what the, what the, uh, bad guys, the threat actors are doing. Uh, but we've also not only gotta have a great and resilient technology stack, but organizationally, process-wise, all of those things have to fit together into a cohesive strategy. So we're here to talk about that, thinking about it as a, an IT leader, whether you're in security or it, or combination of both.
And, uh, discussing, you know, you, you're all expertise experience, but also you talk to a lot of customers, um, as leaders in Splunk and the kind of things that you do. Corey, it'd be great to have you kind of kick things off. Maybe we start, should start with, if you wanna start with the people domain or maybe you want to kind of set it up a little bit differently.
I'd love to hear your initial thoughts on this. Yeah, no, people's perfect. I, I think the people process technology lens on, you know, tackling any sort of problem for, uh, leaders today is a, is an appropriate sort of framework.
So I'm happy to talk about the, the people portion of building great cybersecurity and IT organizations that, like you said, deliver resilience. Great. Corey, One part for me at least when we think about this is, you know, you said IT leaders, and I think one of the big changes I've seen across for cyber for CISOs is it's no longer IT or security, it is business leaders.
And when we start talking about people, that to me, kind of starts resonating. 'cause that is a cognitive change in how CISOs think of themselves and they think of their value, right? Which, you know, we often get stuck in the, the technology part of people process and technology because a lot of us are technologists at heart.
But I think the big change that Corey and I have seen, uh, when we start talking to CISOs and CIOs is this con convergence of skills and the need to support the business differently. Yeah. And it's, it's an interesting sort of people market too.
I think, you know, leaders have to think about the fact that there's, you know, yeah. In technology, there has been some turmoil in some of the big tech companies, but there's still a lot of really great talent out there. And I think that there's choice.
You know, when you think about with unemployment so low, right? People are, and there's, you know, what's like 16 million jobs unfilled currently in the us? You know, and a lot of those being in the tech sector, people have choice, right?
And they have a place where they can go. And I think leaders, if they're gonna build a talent pipeline and build a, you know, great organization, they have to find folks where they are and bring 'em in and connect them to a value, like a mission and a vision that they get excited about. And certainly, you know, securing, uh, you know, digital services and protecting against bad actors is exciting in and of itself for many folks.
But actually connecting, you know, those people to how it affects the, the outcomes that matter to the business. And that whole value creation process, I think is a real critical skill for folks to understand today. As they, you know, again, they're out communicating and interacting in the network building networks, you know, of talent pools.
I think that clear vision of why it matters and why the work that somebody would do with you matters is critically important. One of the, that reminds me the, you know, the cliche of course is people don't put, people don't quit jobs, they quit leaders. Mm-hmm.
And the, the, you know, the, when you flip that around, one of my mentors, Susan St. Ledger told me, you can evaluate the success of a leader by how many people follow them, uh, to another company. And I know right now in this market, what I'm finding is people are staying longer because they like the people they work for, or they like their leadership team.
They like the culture, uh, the money, even if they're not making as much as they were last year because of inflation. Uh, the people I know who stuck around longest are the people happy with the people that they work for and work with. You know, and it's interesting when we talk about people, um, I, I've worked in, in career part of my career where the sort of the higher, the purple unicorn, right?
That, that, uh, that doesn't exist. That got eight skills, that needs 20 years of experience for things that only been around for three, right? We, we, you, we set our subs up to hire these, uh, kind of phenomenal people, of which there may only be a few in the world that are like that, but it, it's, it's about growing our people, growing our or, but also growing our organizations, developing them, right?
And it's not just hiring people, it's building a team. It's building an organization that's got the right talent at the right time, at the right place to match with the business needs. And that changes.
That means you can't always hire for it. You're partnering for it. You're, uh, working with companies like Splunk, uh, to bring in skills and expertise maybe you need for the moment, you need for a project, you need for strategy.
All of those things. Love to hear your perspective about broaden what we think about people and how we incorporate that part of it into our strategy. Yeah.
I'll, I'll say, you know, top to bottom, you know, start at the executive level down to practitioners. Everybody has a partner, right? Everybody has a consulting partner typically that they bring in to, like you said, fill those gaps where it's a new skill, it's a new technology, it's a new capability that they're trying to deploy, you know, for the reasons that they've chosen to do so.
And they're valuable. But you may not have those skills internally. And, you know, training takes time.
And oftentimes just finding that partner that can help you solve that particular problem is incredibly important. And I think, you know, as the security landscape, and frankly, the, the tools being used to deliver and develop the latest digital services continues to get more complex, um, expecting to hire that skillset completely, probably not realistic, especially as digital transformation objectives sort of have a, you know, an ebb and a flow of, uh, you know, kind of momentum and the amount of work being done on particular projects. So I, yeah, I see it as, as one of the top areas where when I'm talking to CIOs and CTOs and CISOs, when they, you know, think about, Hey, we, we wanna deploy this new capability, uh, within Splunk, or we're, you know, frankly trying to figure out how to integrate better with our observability and IT teams to, you know, derive more value from the tools we've already purchased.
It's oftentimes that people conversation of how do I actually leverage your talent to show us what good looks like and bring the experience from other companies similar to us that have already been down this path to kind of, you know, uh, call it the, it's the, it's the cheat code, right? How do, how do I do the thing that, that you guys already know how to do? How do I buy that capability?
Oftentimes it's through people. I, uh, my experience. I'll, I'll go the other side of the, the halo and horns there down to the, the pratt, just the, the nitty gritty mm-hmm.
Uh, hiring recently building out my team, uh, I intentionally carved out three slots for entry-level early career folks into, um, our team cybersecurity team, which is pretty rare for, for Splunk and pretty rare for a lot of security research teams. Um, but the way I did that was really rewriting the job description to be embracive of second career people. Um, I think I actually really dislike the term.
There's a problem with the security, the pipeline for hiring. I think that's completely false. The problem is not in the pipeline.
The problem is we have a valve on incredible talent and gatekeeping who actually gets into the pipeline. So we do see a problem with the pipeline. When I start looking for folks who are underrepresented in cyber, especially 15, 20 years down, what I don't see is a problem of the, basically the reservoir.
The reservoir is healthy, the reservoir is huge, but people either are, don't feel like they're welcome or they self-select out, especially if cybersecurity. Um, so for me, a lot of the people problems that we have, you know, if we can start working on the problems of today, we, you know, future us will be very, as a security leader, will be very happy if present me can help unlock that reservoir by turning open the valve, by creating job descriptions and roles that are less around years of experience and understanding technologies that I can Google or generative AI my way through today. Um, I think there's just a lot of flexibility, especially for folks who have critical thinking and communication skills.
Uh, I can teach you T C P I P, I can't teach you how to communicate. I can't teach you how to synthesize information. I need you to walk in the door with that.
Um, so something for me around people and these hiring gaps that we see, um, is really about being more embracive of non-traditional cybersecurity and IT roles, and then also facilitating them in ways they can succeed. Well, and it's also about hiring for what we need today, but also, you know, where the ball's gonna be downfield, right? When, when the ball lands.
So part of that is hiring people who have demonstrated, uh, their ability to learn, adapt, right? Today they were the T C P I P, you know, yesterday they have T C P I P expert today. They're the security threat landscape expert.
How they do that, how did they get there? They learned it, right? It may have been on the job, but there's also a lot of self-motivation and just skill in that learning and that repetitive learning skill is, I think, something you can harness a leverage to accelerate their career as well as what you need.
Absolutely. It's one of those things that, like we always, you know, some folks get, you know, turned off in, as Ryan said, sometimes there's a valve, and one of those valves is like, you must have a college education. And while I don't necessarily believe that a college education like is always the right thing, I think what it proves, if you have one, is that you are able to, as you said Mitch, you're able to go through a structured learning process in an organization that's institutional, understands sort of dynamics and things, and achieve an objective which was set before you that had some measurable outcomes that you had to deliver.
Which I think is something true for all of us in a corporate responsibility sort of job, is we have to operate in an institution institutional environment. We have to con consistently learn new things. We have to interact with people around us.
And so I think college is a good measure, but as Ryan said, oftentimes second career is maybe even a even more powerful measure of somebody who's done that successfully. And like Ryan said, you know, it's the skills, the technical skills are, are learnable. And frankly, the fun part is, is like some of the technical skills are actually getting obfuscated by advancements in technology.
Absolutely. As we think about things like Ryan, you mentioned like generative ai, like we can make the joke, but candidly, wouldn't you rather hire somebody who's got like incredible cybersecurity skills and understands the landscape more so than somebody who's just really good at crafting queries? Like oh, sure.
That. 'cause then if you have somebody that has the domain expertise as technologies like generative AI and other sort of assistive technologies continue to evolve, then the domain expertise becomes most important because then you start interacting on a natural language sort of way, and you don't have to have those same technical skills to get there. Um, which I think is kind of an interesting, probably one of the most interesting uses for generative AI is actually bringing out the barriers for technical ability to execute in a job like security or it Prompt engineering will be one of the most like, significant requirements for entry level and mid-level jobs by next year, in my opinion, categorically.
Mm-hmm. We've already been going through one generation, it's called search engines. Now we're doing it with generative ai.
Right? No, it, I mean, we're talking about this, but the reality is I've been doing cybersecurity and IT since 1999, Corey, there's enough gray there. I'm sure you're about the same generation.
Um, you know, when I started, there was no Google and you had to read Microsoft TechNet documentation, and then there was Google and I put 65 CD binder in the trash and said, never again. Mm-hmm. Um, and the fun thing that I always tell people that I'm mentoring or advocating for in cybersecurity is I've been doing this for 24 years, and of the 24 years, I have about four years of knowledge that's relevant.
I have 24 years of wisdom, but four years of knowledge that's relevant. 5 driven pub E D B, and I know how to defrag a Windows NT four oh server. That doesn't matter.
So that's one of the great things about cybersecurity and IT for in the general is that you can become a subject matter expert in something very quickly, um, and not have the bias of age. Well, let's turn our lens to the process part of it. And we've talked a lot about people, and we could talk a lot more about it.
There's some great conversations that we've had, uh, already about that. You know, we've gotta have processes that are well oiled to highly tuned. We can be responsive incident management when things happen, right?
And, uh, the organization now has to operate cross-functionally, the, the stove pipes, the things that we've lived with for so long. Now we have to operate cross-functionally. And so we're, we're trying to tear those down, but our processes have to work across those.
I'm interested in your, your all thoughts about how are organizations, what, what do they best do to adapt to what we need today so we can be speedier, uh, respond more quickly and more reliably to, uh, threats or incidents or needs of the business? Yeah, you go ahead, everyone. No, please.
Corey, go ahead. I'm, I, I was actually gonna say it's all good. I was gonna say the, the, you know, it's actually not even an option anymore.
Like we talk about that they need to do it. It's not an option. If you look at some of the SEC's, recent rulings on the disclosure of material inci and incidents that happen, you know, for publicly traded companies in the us, you know, you have to report now you have to have that cross-functional view of how did, if a cybers, you know, security incident happens or an IT sort of incident outage or, you know, uh, you know, breach any of these sort of categorical things that happen, if they have a material impact on operations that would affect shareholder value, then you must disclose those things.
And so now the impetus is on every publicly traded company to get this figured out really well. And it's got executive sort of buy-in now that we're going to tear down the walls between security and IT operations and our engineering teams developing our next, you know, digital capabilities. Because anywhere across that spectrum that we have a, a process breakdown, whether it's externally caused or internally caused, if it's material, we better report it.
And these are no longer, like, you know, hey, it's a good idea. This is like test that theory and report the results kind of stuff that the S E C will send somebody to jail over. And we've already seen some, you know, some convictions on, you know, previously publicly traded companies on, you know, misreporting things.
It's no longer a game. Like, we're serious about this. So I think from a process perspective, one of the things I'm seeing is, you know, reaching across the aisle, CISOs are talking to CIOs and CTOs more so now than I've seen in the last couple of years, because they have to understand those impacts.
And they're looking to organizations that actually already do some of them within the company, right? That are already being trusted by different pockets of the organization. They're looking externally for that guidance and help, whether it's from consulting partners that are, you know, hey, advising on security operations or advising on, you know, software development capabilities or technology partners.
I mean, even the cisa, you know, the cloud infrastructure security agency, like their recent strategy update talked about one of the key pillars of their, like their annual strategy for resilience included, like technology partners that were going to help them achieve that resilience. So I think we have the impetus, the measurement is required now. There's no longer a game.
And I think executives are starting to understand it, and they're looking external to say, who can help me, uh, deal with this, right? No matter where we land on what is material and some of the legal questions on how it's implement implemented, we still have to respond and we still have to report some of those capabilities. And so now's the time to start reaching across the aisle and starting to ask questions of your, you know, your partnerships that you have in the org on how can you help us solve this problem?
I look at things like DevOps, which still today has a little bit of a carve out separate than in a lot of organizations, DevOps is a slightly different place than maybe traditional security and certainly, well, certainly than security, and then possibly even different than traditional IT engineering or infrastructure. But in today's society or today's, you know, world of technology, a lot of the security issues that organizations are facing are in their DevOps, DevOps pipeline. And so I find it fascinating what Corey said.
The s e c has this, this term material finding, right? Like you have to report a material finding. Now, I, as a security professional, may very well know what that is, uh, but frankly, the DevOps world has gone feral to a point where the security organizations are not a part of it.
And so the DevOps team are the only ones who understand what the security implications are. They're the ones finding it. And because they're in a DevOps mind frame, they're not stopping and saying, let's create a, uh, let's create an incident.
Let's walk this through. Let's, well, let's see if we, no, they're just fixing it and they're moving it on. That's how the cloud works.
That's how DevOps works. So, you know, there is this essential need for us as us, you know, as an, as an industry to really start reaching more across, because we are being outpaced by DevOps home, growing their own dev SecOps without oversight, without the wisdom of the security world. But we can't say in the way of the business, which is why that's so important for us to kind of go across and understand this, because now there's regulatory requirements and the real world is people are gonna move forward whether they like it or not.
So get on that train. Yeah. It's funny, Ryan, you say that the, I I was reading the, uh, the, the s e c reports from, uh, JP Morgan Chase, Jamie Diamond, their c e o said in the letter to shareholders, he had two sort of funny, uh, juxtaposed statements that used the same, um, the same phrasing, which I found interesting.
And he said two things he could not overemphasize. One was, I cannot overemphasize the need for cybersecurity in our organization. Everything must be secure.
And then he, later in the letter, he said, I cannot overemphasize our need to deploy and to deploy innovative technology, which is like, it's exactly what you said, right? If my C I C D pipeline is continuing to push updates, but I'm not applying those cybersecurity principles that, like you said, was incident review and forensics and actually looking into it, then we've missed the boat on this. Like one of the key parts of this s e C filing is you not only have to report the outage, but you actually have to, from an annual reporting perspective, talk about your processes that you're using to ensure cybersecurity in those areas.
Mm-hmm. And so that's one of those that's like the c e o is saying this to shareholders, the ceo, A bank that touches 20% of every dollar in the world. Yeah.
Right. It's, you know, what Jamie said, We cannot overemphasize. I, I love that example because I, I look at DevOps as a perfect world where I have no, no fear at all, that the DevOps team will identify and remediate security issues very quickly mm-hmm.
And then continue to do so because they're not looking at the larger picture. Why did this get ingested? Why do we have this happening?
Why is this C oh, it's a threat actor. You may not know anything about a threat actor. You may not understand that, you know, tempest strawberry as per Microsoft has a really significant interest in your organization.
And one of their TTPs is actually moving up the chain and actually jumping ahead for software supply chain like that is something that I would not expect a DevSecOps engineer to understand. But that is where the context of a larger security world, and that's why this resiliency message, this is why it's working across aisles, becomes so important for the process. I honestly think the technology is usually the easiest part of this.
The people and the process to implement and secure the technology way harder, way less interesting than most people except nerd like me, but much harder. Well, and, and what you, what you really bring to light is that the security specialists are gonna understand the threat landscape much better, right? DevOps developers, et cetera, are, are know their environment, focused on the things that they are, but it's, it's, you know, you mentioned Jamie Diamond, those two things.
He's expecting us that our CEOs are expecting us to figure out how we bring that together, how we make that happen. So we don't have feral organizations, so we don't have processes that are brittle when things really fall apart or, or our com our environments get more complex. I mean, that's sort of an obvious thing, right?
It, they, they are complex and they're getting more complex and no one understands the whole thing. So we've all got to pull together and say, there are three dimensions to this problem, not one. And here's the steps.
We together figure out how we fix this. Great. Well, let's talk about the technology perspective then.
Obviously Splunk, Splunk being a great technology company, been around for a long time. Remember finding Splunk on the showroom floor in the early days, still doing, you know, doing black t-shirts then just like they are today. Uh, great company that you all work for.
Yeah. So let, let's talk about some of the kind of technology side of what's important. Um, and again, thinking about not just internal people and, and processes, but also, you know, third parties that we're using like the Splunks of the world in, in our organizations and how you can help with this, uh, with this challenge.
I'll, I'll start really easily on this one, and then Corey will actually say something much better. But, uh, people buy software to solve their problems. That's it.
That's the easiest way, you know, when I pay people, you know, I didn't come from a sales background. I was operational. I was a threat hunter for the government, threat intelligence at darpa, places like this.
And I didn't think about why I bought software until I worked for a software vendor. And it's very easy, you buy software to make your life easier to solve a problem faster or to solve it better. And so when I look at what Splunk does, a lot of our recent efforts are really around this incremental growth of just making people's lives better, making people's lives easier, cutting down the barriers to do their job faster.
Because that's what people need, whether it be security, whether it be observability, whether it be traditional, IT engineering, that to me is really what we focus on here at Splunk, which is why I'm still here after nine years. Uh, we make people's lives better and we allow them to fulfill the mission that they're actually being paid for rather than fighting the software that they're buying and paying money for. So that, that to me really is at the chart of what we do.
Yeah. And I think the, one of the things that we've, you know, if anybody's seen some of the Splunk, uh, messaging in the market, we've really rallied behind this idea of resilience. And I think it actually sums up nicely the things that we do, which I think based on the conversation we've just had about the people and process, things that are challenging organizations, I think we're in a really unique place to be a partner, to be one of those partner organizations and be the software that people buy to make their lives easier.
Because we, we sit in this, we sit in this unique place of being one of the few organizations that actually unify, tear down the walls between, you know, security IT operations, and those feral DevOps teams that are out there building, you know, the next digital services. Because our corporate mission is around resilience. And that's, we think of that as a simple statement of how do you keep all this digital, you know, this digital business secure and up and running, right?
Simple statement, but secure, not a simple thing to do. And up and running oftentimes equally on simple things to do. And, and Sometimes at loggerheads Yeah, exactly.
Apparel of either, you know, sort of objective, but I think it's one of those, like there used to be this term we called, um, a mom, right? We all love mom, but I mean, monitor of monitors, right? It sits above, you know, uh, it sits at a, at an enterprise level, at a higher level to give you visibility.
I think that's what, you know, folks have maybe, you know, struggled with that we see is like hybrid cloud is a reality right there. There's lots of clouds. No one cloud is one.
Clearly there's leaders in terms of revenue, and each quarter they grow at different paces. But candidly, like even Michael Dell said some years ago, the cloud is not a place, it's more of an operating model. And as you see, like SAS comp, SaaS being part of cloud, you know, journeys, yes.
Data centers are still run by organizations. They just are run now in a much more sort of orchestration pattern similar to cloud providers. And that reality of lots of silos across different landscapes is creating challenges.
And if you use one tool that's provided by said, you know, provider, then yes, you can secure and keep up and running that one particular cloud real estate. But what about how it's connected across the organization? How about the, the ways that applications traverse, you know, sort of deployment centers.
And so I think that's what we really see as interesting is, you know, organizations are leaning on Splunk, especially in the kind of macroeconomic conditions where everybody's focused less on growth and more on profitability. So they're looking at like, Hey, how do I reduce the number of tools More out of less? Yeah, exactly.
Like do more with less. They're looking at going, wait a second. So I have this, I have this network, I have this networking environment, this router, so my data center, I'm sending the logs from that thing to nine different tools.
Why am I doing that? Like, that's nine times I'm paying for that bit of data to be stored and processed and analyzed by, you know, some number of tools, right? And organizations are looking at going, maybe that's not smart.
Maybe that same piece of data has like nine questions being asked of it, and is there may be a fewer number of tools that could answer those nine questions effectively to give me the outcome without having to have all this sprawl. So it's a unique conversation that we're in today. I've candidly, the tools consolidation, that rationalization of tools is one, looking at data, like the data deluge hasn't stopped, right?
We're, as we talk about sending data to nine different places, well, as that data becomes richer, it's no longer just logs. Now we're looking at, you know, metrics for real time. We're looking at traces for, you know, spanning, how does an application actually impact, you know, multiple sort of environments, but data's getting rich and large.
Is it all equal? Like, should we all be sending it to the same place? Should we be treating it with some valuation, right?
And those are conversations that I'm having today that technology is helping solve. And Splunk's doing some really interesting work in the data rationalization and in that tools consolidation area that's making it easier for customers to do more. And as Rocket said, like you bought, you bought a piece of software to make your life easier.
We're trying to go out and help folks figure out how to make more lives easier with the software they already bought. I find this, uh, I'm just required to hit all the buzzwords. So I'll say ransomware now, uh, when, when people, it's fascinating to me, resilience as in the concept of business leaders and cybersecurity ciso, leaders having to come together, I think partly is really being driven by this threat of ransomware.
Because the first time a cybersecurity threat has consistently and continually impacted every aspect of a business where 10 years ago, 15 years ago, oh, a p t one from China, exfil data, well, that was the big issue. Well, by the time you heard about in the news, it's already done. Um, and it's actually relatively small scale.
The impact is we were compromised, there was a breach, and now we have to deal with the public relations fallout, the stock drop. And also we have to, to make sure this doesn't happen again with ransomware, it's actually, we've encrypted your critical business systems and you can no longer do business. And now you have questions of do we pay the ransom?
Well, now you need to involve the finance sort. You need to involve your chief legal officer. Oh, it's publicly out there that we have this security issue.
You have to involve the PR team, the public relations team. Oh, it's actually knocked out our core business. Oh, well now you're involving the sales org, now you're involving the IT org.
And so it's coming across all these different places. So it's kind of builds back into the what tools do you have that facilitate this? And then going back to the people part that we touched on earlier, uh, this is where someone needs to be across all of them because they need to understand the impact and actually drive those changes that are needed.
And because of ransomware, we actually have to deal with it. You know, we can't just pretend it doesn't exist. CISOs can't just be nerds in the closet playing cyber.
They actually have to be able to speak eloquently to their business leaders, to the board of directors and others. Yeah. It's one, you know, gonna jump on the bandwagon of, uh, buzzword bingo.
Uh, you know, one of the things we're, we're seeing a ton of too, is like, you know, we talk about new digital workloads constantly being brought in, right? New innovation, right? We're hiring consultants to bring in and actually help generative AI get real in our organizations, right?
There's a lot of conversation about like, is generative AI threat versus risk? And there's a whole kind of conversation there, but one that actually as we're moving past, like the, the hype and the AI washing nonsense that's happened in the market once we're getting to real, a lot of CISOs have been talking about are, or talking to, are trying to figure out how do I deploy those technologies internally? How do I go find, you know, the models that I can train against my data sets that would actually go help my teams do their jobs better?
And what I, what I would say is, is that's, that's another one of those areas where as you're innovating and bringing in new technology, treat it like another dig digital workload, right? You're still gonna have to detect when something goes wrong. You're still gonna have to investigate, right?
When something goes wrong in that generative, generative AI hallucinates, it has an outage, whatever. And you're still gonna have to respond to those outages and take those learnings and put it back into the operational process of how do you run that system more effectively. And I think people, you know, need help oftentimes finding those consistent patterns that we have to deploy, just keep things securely up and running regardless of the work, what the workload is under the covers.
And I candidly see that is one of the greatest areas for, you know, leaders that are looking to, you know, partner with a professional services organization or a, you know, an si, those kinds of outside consultancies. There's a lot of value there. And having them, yeah, help bring in the patterns, uh, especially on proven technologies to, you know, short cycle, you know, increase your time to value, or excuse me, shorten your time to value when thinking about those digital new digital workloads and making sure that they're secure and up and running.
I, I, I like where you're taking this, which is one I wanted to wrap with, which is our organizations are expecting us to, to innovate is not just our ourselves innovate, but also support the rest of the organization to be able to innovate. Mm-hmm. So you talked about ransomware, right?
The, the newest thing is they're not encrypting your data anymore. They're just threatening to release it. So it's not a matter of losing the data, it's losing control.
Oh, control over it. AI is sort of the next, maybe it's the next boon to phishing. You know, we may not be able to tell the difference between an email from a generative AI L l M that's been trained on how, you know, our c e o talks versus, you know, a well-scripted, predefined email.
The, these new kind of threat models as well as new technologies sort of force us to innovate and find ways new, new ways to do things. We have to help our people with tools, technologies, processes. I'd love to hear some more thoughts about, um, what do we do to set ourselves up for success, to be able to, in innovate in a way that's gonna help support where the organization is today and where it's going.
Well, I'll make a slightly controversial opinion here. Uh, I don't think there's ever been a single technology that outweighs the benefits for the offense or defense. Um, I look at generative AI as something that is going to liberate, uh, security organizations from the shackles of mundanity.
Uh, it'll demo democratize what we can do in terms of analysis. It will also do the same for the adversaries. And so the only people who will lose are those who are not taking advantage of this technology on either side.
Um, I really do believe that we can all uplevel as we go through with different technologies, just as the adversaries are, you know, when we invented a trench or trench warfare in World War I, they invented a tank. You know, when we invented an airplane, they invented anti-aircraft. Um, like this is a tip for tat sort of thing.
And there's always a leap. You know, at some point people created a star fortress and that steamed invasions until someone invented a cannon. So sometimes defense beats offense and sometimes offense beats off defense, but it kind of goes back and forth as you go.
So I don't necessarily see anything that's a semantic change in how organizations will defend. But I do believe if you're not paying attention, if you're not innovating, if you're not selecting vendors, um, if you're a, so, you know, if you're buying software, if you're not buying vendors who aren't innovating, uh, you're going to have a very difficult time in the next five years because your adversaries absolutely are. Yeah.
And I, I would, I would go maybe less, uh, digital and say, we as leaders cannot underestimate and cannot undervalue investments that we make in our people and our business culture today. That creates space for the learning and the development and the skills that, you know, attainment that Ryan talked about, being critical, like leaders must create space for technologists, for practitioners, for leaders to go learn and to go study and have a mantra of spending some amount, large amount of time on a regular basis, on a cadence basis, you know, investigating whether that's going and attending conferences and networking and starting to understand what's happening in the industry. Or it's partnering with a technology organization and doing more hands-on workshops and learnings, or it's going next.
You know, when you've got a consultant in spending time with those folks in the office picking their brain on what are the skills that they're paying you for? Why are you here? What is so unique about what you're doing?
And how do I learn more of that? But it comes from leaders making that a priority. And if we're gonna have an organization that has people, process and technology that's actually going to be resilient and that's going to be able to survive in this kind of next epoch of technology innovation, it's gonna have to be led by the best intelligence, which is still human intelligence.
And that requires investment. And I think you gotta put a stake in the ground and make that a priority today. I, I love that part because kinda going back to our previous discussions about leaders who often have 10, 20, 30 years of experience, none of it's relevant.
So, you know, when I started my career a ciso, my only half, well, first off, CISOs didn't exist. Second, uh, you know, the C T O or the, the person in charge of technology at that company had to like pay attention to desktops, printers, and servers on-prem. And then 10 years ago, 15 years ago, it was laptops, desktops, printers on-prem, printers in the home offices, a data center that they co-located to in this little cloud thing that they're trying out.
And then five or 10 years ago, it was all those plus software as a service. And now it's, okay, well we have a C I C D pipeline and we're driving APIs and our entire business is dependent upon this one piece of open source software that's maintained by three guys in a former Yugoslavian Republic. And if it has an issue, we're gonna be done.
Also, we've emanated a company out of China every time they develop a VUL vulnerability that has to go to the Chinese government along with us. It's a lot more complex. And for those who are just resting on their laurels of, I've been doing this for a while and not upleveling their own education and hiring people who are subject matter levels as direct lieutenants, you're gonna have a bad day.
Yeah. Kind of bringing it back to, uh, the thinking that got us here is not the thinking that will get us to the next place. Kind of paraphrasing Einstein here, but it's also also our own thinking, right?
That's the value of bringing in perspectives like yours, you know, with your partners, your suppliers, companies like Splunk, professional Services. There are a lot of ways, and I think we're at the same junction point where we were with the cloud, where we're like, here's the cloud. Is it just somebody else's computer or is it a new way of doing things?
But what is that new way? We're kind of that, that place today with ai. Okay.
Right? We know we can do generative AI stuff, but what does it really mean? How do we leverage it?
To your point Yeah, Ryan, and, and you have to be a participant on the field to really figure that out. You don't have to go spend crazy money on the latest thing just 'cause it's, you know, that's what was in the airline magazine, right? It it, but it is about figuring out and learning what you can do with it and what, what's possible.
Learning from by yourself, but also with others. Yeah. Well, thank you both, uh, to both of you, uh, to Corey Minton and Ryan Kozar for, uh, joining us.
And thanks to the Splunk team for, uh, bringing us together to have this conversation. And we hope it's been really beneficial to everybody who's listening in. I know.
It's been great for me as well. Thank you.