Rethinking IT Operations Management with JumpCloud’s Raj Bhargava
JumpCloud CEO Raj Bhargava posits that the recent worldwide Windows outage caused by CrowdStrike might prove to be a seminal moment in the history of IT, as organizations finally revisit how IT operations are managed.
Transcript
This is Textron tv. Hey guys, thanks for the thrill. We're here with Raj Barbo, who's the CEO for Junk Cloud, and we're talking about this massive CrowdStrike windows outage that occurred last week or the week before.
Um, and arguably it should be a watershed moment, and I think maybe we will change some of our processes and behaviors, hopefully. But Raj, I gotta say I'm doing this long enough that every time someone tells me that this is a wake up call, that inevitably people just roll over and hit the snooze button after it's all over. So from your perspective, what will change?
What needs to change and why will it stick? Yeah, Mike, I've been doing this a long time too, so I'm getting old, but, um, but thanks for having me. And, and look, I, I think that you're dead on.
I mean, it's, it's a watershed moment if we want it to be a watershed moment, but if we don't, if we roll over and hit the snooze button, absolutely, uh, we're gonna let an opportunity go by. I really hope that doesn't happen. Um, I think it's not gonna happen, but, um, you know, time will tell.
Uh, and that's absolutely, totally, uh, appropriate to be skeptical about it. I think the core issue is an update went out that wasn't as thoroughly tested as it should have been. And arguably we can point fingers at CrowdStrike, but, uh, last time I checked, customers were supposed to check software before they uploaded it themselves as well.
So I think there's plenty of blame to go around. Um, from your perspective, what broke down here and, and what should we kind of take away as the, to-do item as a result? Yeah, I mean, look, I think I, I mean, the truth is these things are so complex.
There's so many different issues, variables. Um, we've had lots of these issues happen. Almost every single major provider has had an issue, right?
So they're gonna, they're gonna continue to happen. It's not, this isn't a one-time thing, so what do we do about it? I think that's the core question, right?
Uh, I think, look, I think technology is more important than ever. We got, we gotta make sure that our technology teams have a seat at the table. And what does that mean?
That means that they get allocated budget, they have real voice in where the direction of the company's going. Um, they have real access to resources, those kinds of things, right? That's probably number one.
Number two is we gotta stop talking about being a Microsoft shop, a Google shop, and AWS shop and Apple shop. I think we need to be mixed platform. We have to, you know, take advantage of, of all of what technology has to offer.
And, and that's pretty critical. I think if, if we continue down this sort of single threaded path, I think it's gonna be tough. I'd say those are two places to start.
Mike, To your point, um, I think you're right. We should assume that this is gonna happen again. Do we need to kinda revisit our incident response plans as a result?
'cause I think, uh, a lot of people woke up and they were shocked and amazed that this was happening, and it took them a long time to recover. And I can't help but wonder if they had a plan in place, or if it was just that complex and endeavor. But I think there's a little work to be done in this area.
Absolutely. So, I, I mean, I think obviously on the security side, people have been doing incident response plans, uh, tabletop exercises, those kinds of things. Those have become pretty, pretty normal.
I don't think we do that as often on the IT side, and, and we really should. So, um, clearly best in class organizations probably do do that, but the rest of us probably need to keep doing it too, right? So I think there's a lot of opportunity there.
Do you think maybe, you know, you can't walk down the street these days without somebody leaping out to tell you about their great new AI thing, but, um, can AI help here? Um, is there a role for that as we kind of think through how to make our entire IT environments more resilient? I, I mean, look, I think there's gotta be, right?
I mean, a AI has gotta be used here. Uh, there's gotta be ways to leverage all the patterns, the recognition, um, hopefully as software vendors, we're a software vendor, hopefully, you know, we can leverage it to catch defects before they escape. Um, really that's, that's an, an important, important part of it.
And then hopefully customers can start to use it for their monitoring for, you know, testing all of those things on their side as well. So, yeah, absolutely. Uh, it might, it's gonna take a while, right?
I mean, AI's still pretty new, but absolutely, it's gonna have an application here. Some folks are calling for, well, we need a chief resilience officer and somebody who's gonna take responsibility to make sure that all these platforms stay available. Is that the way to go?
Or is resilience just really part of everybody's fundamental job in the first place? And we just need to kind of double down on our accountability and what we're gonna do about it? I, I probably go with that model where it's, you know, part of, uh, part of our roles already.
Um, so, you know, adding another person on the, the staff if you will, just focused on this, is probably, I, I think, you know, probably muddies the waters, but, you know, different companies are gonna do it different ways. That's the beauty of, of this. And, and people are gonna find out, hopefully we do have some organizations go hire Chief Resiliency officers and let's see how it goes, right?
It's pretty, pretty uncharted territory. But if it works, then, then we adopt it. Some people will go out there and test it and be the canary in the coal mine, if you will.
And, and let's see what happens. But I, I, I think and know VPs of engineering, head of ops, head of security, that's job number one for them anyway. So I, I think that's probably the best, best way to go Is part of our problem that we are just too dependent upon legacy platforms.
I mean, uh, there's a lot of old stuff out there, and a lot of these issues are related to, uh, versions of Windows that have been around for a while, and, um, for a variety of reasons, we don't seem to be able to, uh, modernize them, but, um, yeah, the risks that they bring may be greater than their value reward. So do we need to have a, a real conversation about all this legacy platforms that we're supporting that may be unrealistic? Yeah, a hundred percent.
I mean, I, I think absolutely we, we have to take a look at that. Um, the cloud has changed everything. It's given us an opportunity to kind of rewrite the, the infrastructure, the technology approach.
We gotta take advantage of that. Um, you know, the industry we're in, we're in the identity industry. If you wanna talk about legacy, we've got, you know, this thing called active directory that's been around for 25 years and, and many people are still on it.
And, and we think that that's crazy. Uh, there's, there's so much new innovation in the identity space related to security, ease of use, um, resiliency, gotta take advantage of it. Having an on-prem server that, you know, was created in 1999, I, you know, uh, we, we've, we've evolved.
We, we should be taking advantage of new stuff. What's your best advice to business folks who I feel like, and to your earlier point, maybe are taking it for granted, and they kind of assume that this is now a utility that will always be available, and so there's surprised when things happen, but, um, what would be your best advice to them about how to kind of wrap their heads around this? Well, you said the key word utility, right?
So I, I think that's, um, that's how we gotta treat it. This is a utility and utilities are almost always on, never go down. They're, you know, highly safe, highly secure, tested, monitored, um, you know, all those things happen.
So I think that's the mentality that we should have. And what does that mean ultimately, as a business leader? That means funding, that means resources.
That means having a seat at the table. So until leaders, business leaders treat the IT organization, the security organization, the operations organization, by putting them at the, at the table with them, and they're funding them appropriately, I, I think, you know, these kinds of things are gonna continue to happen. What is the core problem with funding?
And I go back in time and people would say, you know, we're gonna allocate, uh, 2% of revenue it, and they have that whole methodology, and yet the business is more dependent upon IT than ever. And it seems like the, there's an antiquated way of thinking about finance as it relates to IT, versus what the modern reality is of our dependency on IT for driving revenue. Yeah, a hundred percent.
So when it was 2% of revenue, how much of that revenue was driven through technology, or how much of the business dependent on technology, totally different than it is today? The whole business is, is dependent on technology. And by the way, you're probably driving a lot of revenue from that technology infrastructure.
So why is it 2%? It's gotta be much more, right? And so, yeah, I think it's an antiquated way to think about it, and it's not calibrated to how we think about the, the revenue potential, the revenue opportunity, the cost savings, all of those things.
So until we do that, you know, I, I don't think we're gonna fund it enough. Where do we have that conversation? Do we need to go sit down with CFOs, CEOs, the board who kinda has to come to this aha moment?
I think it's gotta be the senior leadership table. So, you know, at the end of the day, obviously the CFO is in charge of controlling the dollars, but you know, the dollars aren't allocated by the C ffo, they're allocated by the CEO, right? So they're allocated by the team saying, look, this is, this is where we want the business to head.
Here's how we wanna, you know, carve out different investments and dollars. So I, I think that's done at the, in, in good organizations. I think that's done at the senior leadership table.
Gotta have it and security at that table. So Do we need somebody to write kind of the Harvard Business Review case study for this whole incident and it becomes part of the, uh, business school curriculum? Yeah, I think, well, I think there's gonna be a lot written on this.
So, you know, let's see what happens six months, 12 months from now, you know, I really hope, you know, what we started the conversation with doesn't happen where we hit the SNOO button and kind of, you know, roll over and, and go back to sleep. You know, I, I really do hope there's, there's a lot written about it, how people really take it seriously and, and kind of use it as an opportunity to kind of rewrite some of the playbooks that, that they have. There were, of course, a lot of finger pointing and a lot of, uh, calls for accountability emanating from everywhere from Washington to probably, you know, the local data center.
But, um, should we really be that aggressive about accountability or should we kind of just admit to ourselves that, you know, it was a group failure and we should learn from it? And, you know, in, in the land of DevOps, we have this notion of empathy. Um, do we need to just take a moment and take a breath here and just go, all right, this wasn't the best day for all of us, but we can do better, Mike?
I, I really wish that would happen, right? I wish we'd all have a lot of empathy, you know, the world we live in these days. So, um, you know, un unfortunately, and I have a huge amount of respect, uh, for the CrowdStrike team and, and, um, I have a lot of empathy for them.
They're investors in JumpCloud, so, you know, we have a lot of, a lot of, uh, support for them. And, you know, unfortunately they're gonna get dragged through a lot of stuff here. And, you know, that's, that's gonna be unfortunate.
But it, I mean, truthfully, this could happen to anybody. Um, and it has happened to a lot of us. And so, you know, uh, it's, it's part of the game, unfortunately.
I think, you know, there is gonna be accountability. There is gonna be, you know, uh, hearings in Washington and, you know, all kinds of other hearings all around the world. And that's part of the, the world that we live in these days.
And, you know, unfortunately that probably impedes a lot of progress, but that, I think we just sort of have to take it. That's, that's life today. If you were an IT leader at one of the companies that was impacted and you were having these difficult conversations, what would you tell these people?
How do, how should they be talking to the board and how should they kinda, uh, approach that in a way that kind of gets this maybe closer to this sense of empathy? Yeah, I mean, look, I, hopefully, everybody knows mistakes happen. You know, we've all had mistakes happen in our careers, in our organizations, all kinds of things.
So, you know, at the end of the day, that's what we gotta rely on is, you know, we all make mistakes. Things happen. You know, how do we, how do we go from here?
That's the, that's the key. All right, folks. Well, somewhere in, uh, our legacy, uh, teachings, there's a phrase about something about me who cast the first stone.
So no matter what religion you are, you get the basic idea. But, um, I'm hoping that we can all look at this maybe in a year and go, wow, that was the moment when we all changed our behavior. But cross your fingers.
But who knows? I hope, Raj, that we're not having the same conversation a year from now. Raj, thanks.
I, I Really, I really hope we're not, but thank you, Mike, for let me, let me chat with you about it. You know, maybe, uh, maybe we're a little too optimistic here, but you know, I, I do really think that people are gonna make some changes. All right, Raj, thanks for being on the show.
Thanks for having me, Mike. All right. And back to you guys in the studio.