Techstrong TV April 1, 2026
The AI Exfiltration Crisis: Securing Agentic Workflows
1 in 3 organizations already impacted by AI-driven data exfiltration
Agent ecosystems creating new, invisible attack surfaces
“Flight recorder” visibility for governing OAuth tokens and integrations
Featuring Amir Khayat, CEO of Vorlon
From Reactive to Preemptive Security
DDoS defense evolving to continuous, non-disruptive attack simulation
Identifying vulnerabilities before attackers exploit them
AI threats and geopolitical risk accelerating the shift
Featuring Matthew Andriani, CEO of MazeBolt
AI-Driven AppSec Auto-Remediation
Explosion of AI-generated code shifting focus from detection to remediation
Fixing vulnerabilities directly inside the developer workflow
Agentic testing enabling secure CI/CD at AI speed
Featuring Joni Klippert & Scott Gerlach, Co-founders of StackHawk
Why Kubernetes Still Needs VMs
Bare-metal complexity reinforcing the role of virtual machines
VMware Cloud Foundation enabling scalable, secure AI workloads
Dynamic GPU allocation and infrastructure efficiency
Insights from Weigue He (Broadcom)
Future of Agents & Apps (Microsoft Keynote)
Unified vision for apps, agents, and interfaces in the AI era
Power Platform enabling rapid, governed intelligent solutions
Driving enterprise automation with speed and trust
Featuring Ryan Cunningham & Daniel Newman
NVIDIA’s AI Security Ecosystem
NVIDIA emerging as a central player in AI-driven cybersecurity
Strategic partnerships with CrowdStrike, Cisco, and HPE
Implications for enterprise security architecture and strategy
Featuring insights from Security Boulevard podcast panel
Transcript
Hey everyone, welcome back here to Techstrong TV. It's been crazy with RSA season, RSAC season. I want to introduce you to Amir Khayat, and I hope I didn't mispronounce.
I should have checked. Amir is the co-founder and CEO of Vorlon. Don't worry if you don't know Vorlon, Amir's going to tell us all about them.
But before he tells us about Vorlon, let's make him tell us about himself a little bit. Let's find out, as I said, he's co-founder and CEO. Let's find out how he got here.
Amir, welcome to Techstrong TV. It's great to have you on. Thank you so much, Alan.
Great to be here today. Thank you. So let's not start with Vorlon.
Let's start with you. Share with us a little bit about your journey. Happy to.
So I'm give and take around 20 years in cybersecurity. Did pretty much every vertical, starting from building offensive system, all legal, but kind of trying and learning about the hacker mindset, which kind of what led me to help organization to protect their corporate environment. I was part of the founding team with a startup called Demisto.
And then we were acquired by Palo Alto Networks, where I led their global solution engineering. And while deploying Palo Alto products, we deployed a product called SOAR, which is orchestrating a bunch of systems to help you to respond to incident. Mm-hmm.
So the more you connect systems, basically, that's how it become more valuable for customers. And that's what kind of initiate the founding start of Vorlon. Because think about it today from a corporate environment, you have a lot of third-party tools that companies are leveraging for efficiency, which is great, but the real problem here is that it all relies on integration, that relies on OAuth and tokens.
And that's a real problem because security teams almost have no visibility for that. Got it. It's an interesting journey, Amir.
I've interviewed a lot of co-founders over the years. And I always like to hear what was the thing that kind of pushed them into saying, "I need to build a business that does this. " If you don't mind, let me, if you can, share with us what that was like for you.
Because I think every founder kind of lives that. Lives that moment where it's like, "You know what? This is a business.
This is something that we need to build. " Absolutely. And I must say, being again in the cybersecurity space for so long, it just have so many opportunities because attackers are not waiting for the vendor to catch up.
And that creates a lot of opportunity. And I think that, going back to my previous example, working with large customers, when I was at Palo, just emphasized the current gap that exists with the current security tools. And being in the startup space, moving between startups to large enterprises, always made me in a position that I want to be a problem solvers in the current problems.
And I saw that as the biggest one. The shift from the cloud and now with AI accelerating that, that was an opportunity for attackers that happened due to a gap that exists in the industry. And then talk to me about how Vorlon helps with that.
Yeah, absolutely. So again, going back to phase one, you don't know what you don't know. When today, AI obviously accelerate that because you have agent that are running autonomously.
That's basically where Vorlon is helping companies. So what we did, we've built an intelligence simulation technology that creates a living model of your AI agent ecosystem, SaaS application, MCP server communication, integration, to be able to monitor where your most sensitive data is flowing to, understand when something unusual happened, and allow security team basically to respond to it, where they don't slow the business when they shift to the AI era. I love it.
Very good. All right, Amir. You guys recently did a 2026 CISO report on agentic ecosystem security or really the agentic ecosystem security gap.
Before we get into the results of the report, share with us why did you do this report? " Yeah, that's a great question. And I think what led us to go with this survey is to get a better understanding of how different security leaders and team in different vertical are looking at the gap and the threat vector that we're trying to resolve, right?
And I think that when you run a startup, you're talking with different companies every day, different stakeholders in companies. And by surveying with a very specific question, I think that would allow us and the industry in general to understand what is the day-to-day challenges that CISOs are facing and how they rank it in their priorities. So that was kind of like the initiative that started this, so we can know if our market is already well-educated about this problem, or this is a whole new area that we need to educate more and put more effort around.
So that's kind of like what started that. And it was very interesting, in terms of the result that we received in that. Excellent.
All right. Let's jump into the report itself. You said that you said some interesting results.
Yeah, we can get into the... Well, you know what? It's a good idea, I should say this now.
For people who want to download this report and have a look at it, where should they go? So the report is up and live on our website. io, and you'll be able to download it from there.
Perfect. All right. Share with me if you can, Amir, give me two or three big key findings, the executive summary here.
Yeah, absolutely. I think that the survey was published for over 500 CISOs- Mm ... for midsize to large enterprises companies.
And we just published it this week, actually. 4% of the organization, experienced at least one SaaS or AI security incident during 2025- Hmm ... which is shocking in a way.
And I think it's, again, just emphasizing why there is a gap in the environment. I think another data point that we also learned is this is a top priority for security teams today. Again, going along with the numbers that I just shared, over 99% of them are concerned about the breaches that occurred in the industry.
And we've also learned that one out of three organizations that already deployed AI during 2025, and this is before the big wave of companies are deploying more, experience a data exfiltration through an agentic AI ecosystem. Really? Yeah.
What percentage of companies experienced that? One out of three that we surveyed. Oh, that's 33%.
Wow. Correct. Yeah.
Well, that's scary. Amir, it's interesting, right? We've got companies, they're all using AI, right?
Obviously, they all have experienced either a SaaS or some sort of security, SaaS-related, AI-related security interest, event. 33% that are using agentic had some data exfiltration. Those are significant numbers.
What, if anything, are the CISOs saying they're going to do about it, though? So you actually touched a very interesting point, which we are still trying to analyze and understand. I think that one of the data points that we've learned in the survey is that almost 90%, 89%, I think, specifically, claim that they have strong, comprehensive OAuth token governance capabilities today, which, again, doesn't go pretty well with the numbers as I just shared with you.
Yeah. And I think this is where security team have to challenge themselves around their security stack, right? If they are still acting based on old frameworks and things have changed because they did, and I think that's where we will see, obviously, early innovators are adopting new tools, because the attack vector has changed.
It's no longer a static analysis configuration checks that, to be honest, also creating more overhead for their team. It's going back to what happened also with firewalls back then. Then with endpoints, when CrowdStrike started and some of the other players around behavioral stuff, the same thing has to happen with the agentic new world.
And I think that is something that is in transition and will change this year. I love it. Amir, one last question, and that is, what came out of this report that surprised you?
Right? A lot of times, look, we do these, I've done them at companies I'veHelped. We do these reports, and we kind of expect what the answers will be.
Like, I don't think it's a surprise to find out how many companies are using AI. I don't think it's a surprise to find out that a lot of companies have had a lot of security incidents. I am surprised that 33% of agentic exfiltration things.
But what did you not see coming when you saw the results of this report? I think the level of confidence, again, going back to what I just shared, I think that the dissonance between the number of breaches that they experience versus their confidence in the tool that they have clearly surprised me there. Disconnect.
Yeah. Yeah. And- So let me ask you, is that false pride, you think?
Because the seven deadly sins, right? One of them is that false pride where you think you know how it happened, why it happened. And time and time again, I've seen that, and you know what?
Then you wind up really embarrassed when something bad does happen. Or do you think maybe they really do have a good solution? I don't know.
I would tend to think not. I think that it won't be fair to say that their confidence or overconfidence in the current tool that they have. I think that the pace is what makes all difference.
What was relevant a year ago before AI starting to explode helped them to go with a certain stack of tools. And in reality, when the attack vector change, and things has changed, I think that it's a learning curve. It helps them to understand what and how to approach it.
So I think that's why the cybersecurity space is very active. It's going to be very interesting in the next 18 months because I think things will change. That creates more opportunities.
So this is one. I think the other thing is that from a security perspective, obviously, executive and board are pushing to deploy more AI, and we've seen that because that creates more productivity. This is definitely a trend that started a few years back with automation and accelerate, and I think that, again, a lot of the decision that were made were before this era of AI, and they will change now.
So I think the level of confidence will change and will adjust through time. Excellent. Amir, we only have 15 minutes.
We're about done. io, correct? Correct.
Is the website. By the time people see this, we'll already be at RSA. I was going to say you'll be at RSA, but this will be shown during RSAC week.
And I want to wish you the best of luck with Vorlon, and keep us posted, okay? Will do, and check us out. We'll be in the startup environment in RSA.
We're also releasing some very cool stuff around AI agent, like flight recorder that should show all your agent communication together with an action center to make, again, the security team lives easier and helping them to enable the organization for this AI era. Absolutely. Thanks, Alan.
All right. Thank you. Amir Khayat, co-founder, CEO at Vorlon.
We're going to take a break. Hi, I'm John Swartz. I'm back at RSAC in San Francisco at Moscone South.
It's day one, and we hope you're off to a good start here. We're here with Matthew Andreani, who's the CEO of Maze... How do you pronounce that?
MazeBolt? MazeBolt. MazeBolt.
And Matthew, I'm going to ask you to take the floor and tell me a little bit about MazeBolt. I had a bunch of questions I want to ask you. But first, let's lay a groundwork so our audience has a better understanding of what your company does.
Thank you, John. Good to be here. Thanks.
We are in the DDoS space with Akamai, Impurva, Amazon, Cloudflare, all of these mitigation players. We don't do what they do. We augment those systems.
They've got good protection that's deployed at various enterprise organizations. What we do is we find out how attackers are able to penetrate all of those layers of protection all the time. Mm.
So that's what MazeBolt does. So you kind of enhance what those other companies do as kind of an additive. Correct.
Typically, what we see as we go in is around a 63% automated protection on average. Using our data of attack simulations ongoing, we can get that to over 98% automated protection. Wow.
So just kind of a side light, but it's important to know. I'm going to ask you a little bit about national cyber warfare and about geopolitical tensions. But you arrived in the US a few weeks ago- Yes ...
traveling from Jordan. Yes. How was that?
It was interesting. I took a taxi from where I live to the southern border in Israel, crossed the border, took another taxi to the hotel. The next morning, took a flight out to Athens, Frankfurt, and then to the US.
How long did that journey take? Left Thursday morning, got to the US, where I wanted to be in Vegas Saturday night. Oh my God.
Yeah. Well, we're glad you're here, and we're glad you're safe. Yeah.
This is kind of a terrifying, not a, kind of, it is a terrifying era we live in right now, and I'm imagining, given what's going on in the world and given the advances in AI, that we have this evolving landscape of DDoS attacks. There must be some sort of strategies that enterprises are using to stay resilient. Could you maybe explain what they're doing to keep themselves defensed?
First of all, you're right. The current landscape, even before the explosion of AI, was already a very high threat, where enterprises were deploying defenses with many layers of defense. What they are trying to do now is close those gaps before an attack comes and try and preempt.
I think this is a theme across not just DDoS. This is a theme across the industry. So before, just to be clear, it was kind of a reaction- Correct ...
reactionary approach. Now it's a preemptive defense approach. I think in general, across the cyber realm, right- Mm-hmm ...
people that are responsible, CISOs that are responsible for their organizations or government, they're trying to figure out, okay, we've got all these defenses in place. What do we do to harden all of those and augment new defenses? But your existing defenses need to be working.
Mm-hmm. I think there's a huge focus in this area. We focus in this area in DDoS.
It's interesting because I work with a number of folks who are security experts. Right. They started companies, Alan and Mitchell, Still Secure, and they always talk about this kind of concept of security where traditionally, maybe until now- Right ...
it was more of a kind of an evolutionary industry or technology versus the revolutionary things that are happening around it. So for instance, as cloud came along, or as AI, they are quantum leaps in terms of how technology is used, and whether by design or maybe out of just habit, cybersecurity was always kind of the last consideration, and we'll get to that, we'll fix that once we have to. And that you're kind of telling me in a sense that, that attitude or that posture among CISOs and others is changing.
I think you're right. The industry's evolving very quickly, and the technologies are evolving very quickly. If you're not getting ahead of it and figuring out how to prevent damage, you're going to have the damage.
And I think visibility is critical, and figuring out how you protect your particular organization is critical across the spectrum, whether it's from the external, internal, lateral movement, whatever you're trying to protect. So, that brings me, in a sense, again, back to AI in that we get a lot of surveys, we write about a lot of surveys, a lot of studies. And what we consistently see is that there is a pressure from the top down- Right ...
to adopt AI as quickly as possible, maybe with not as much stringent governance or upskilling among employees, safeguards, guardrails, whatever you want to call them, and that has created a tension or created a very difficult situation for the CISOs because they're under pressure to put these systems in place, like agents, for instance. But they're also responsible for the consequences if something were to go awry. So I'm wondering how CISOs are kind of reconciling the pressure from the top down to adopt AI, yet still maintain safe and secure operations.
So I think AI is a huge topic. CISOs are under pressure. Some CISOs tried to block AI at the beginning.
That lasted a few days or a couple of weeks at the maximum. What if they, I mean, were there CISOs who got forced out if they were too slow or resistant? I don't know of any, but I think the internal pressure was very quick.
I think what you've seen is the smart organizations are looking at what they've got in the whole AI space, providing a singular offering to the various departments, scaling down the amount of AI tools, but still letting people fluidly work. I think that any company that isn't using AI is going to just fall far behind. They're not going to be around.
They don't have a choice, right? Yeah. They're not going to be around, and I think everyone recognizes that the speed is incredible.
When you get to the attack side, you can see, if you just use ChatGPT, you can see the speed that you're getting answers now. If you just apply that in a very limited fashion to just orchestrating attacks against organizations, you can imagine the speed that that's moving at. Any manual process that you rely on in an organization with an AI-orchestrated attack, you don't stand a chance.
Which brings us back to what we do in our company. We provide that data prior for those defensive systems to be immunized prior to that attack ever arriving because any type of reaction with a human element in it is slowly going to become redundant. And when I say slowly, I think over the next 18 months maximum.
Maybe if you could go a little bit deeper into some of the products you have and what they do and how they work in concert with some of the companies you mentioned earlier. Are there a couple that you could just highlight just for those who are unfamiliar with the technology? Sure.
So at the core of what our technology does is we are a company that figured out how to simulate non-disruptive DDoS attacks against production systems. That's the core patented technology that we developed over many years. It was released in 2021.
Through actual data So you're kind of testing, but in a non-threatening way. " So we give exact telemetry on every single layer of defense you've got, and we operate on big data sets, so we're launching thousands of simulations over a month's period. And with just a few fixes, you can de-risk many thousands of entry points for attackers in an ongoing way because of things like configuration drift in security policies.
We, in 2022, started significant research in AI because we generate what's referred to as unique data in the AI industry. We are now able to find, with a limited amount of knowledge on the targets that we see in an environment, point our simulator there, knowing where those vulnerabilities are likely going to be, and get that data as quickly as possible to the vendor responsible for that particular layer of security, so that when the customer's attacked, you prevent this initial damage or extended damage at least. Was your background always in cybersecurity, or were you- Yes.
So I'm always wondering what led you to... I'm assuming you co-founded this company? Yes.
What led you to co-found this? You saw immediate need, or you'd come across some examples of kind of high profile incidents, or...? So I was very involved in forming the team in Radware in 2011.
That was a research team that we scaled to an emergency response team that I was essentially dealing with real-time attacks against large organizations, like the New York Stock Exchange, Hong Kong Stock Exchange- Oh, God, yeah ... Vatican, all the banks in the US during large operations, coming up with solutions in real time to mitigate those threats. And I then started a services company, seeing that every one of those attacks that I saw that caused extensive damage sometimes, sometimes for months, could have been prevented relatively easily.
Mm. And when you look at these large organizations that had seemingly endless budgets, what they didn't have was the knowledge of how those systems are bypassed. So we started actually as a cyber services company, and through need, transitioned to a product company in 2021.
So I'm assuming that business is probably booming for you. Yes. Or you're getting more inquiries than ever because I'm thinking about this classic scenario of people employing AI agents.
I even read that Mark Zuckerberg's going to have his own chief of staff AI agents. Right. With access to his ideas and his information.
And I'm just wondering, that must be setting off alarm bells in a lot of these sectors, where the bad guys, they're making as much use of AI agents as the white hats are. Right. But there must be a palpable sense of anxiety, I think, within enterprises, especially as agents, of course, begin to be adopted at these companies.
Yeah. First of all, yes. And depending on what you're responsible for, if you're responsible for hosting the agent infrastructure, you've got an entirely new threat to deal with in terms of even how you inspect your traffic, right?
Agents are completely- Yeah ... new traffic. They're not traditional web traffic or API traffic that you were used to in the past.
This is different traffic. And I think that protecting these agents is going to become very complex because they're very dynamic. They're expanding and contracting.
Can I ask you really quickly? So conceivably, we're going to have security AI agents- Yes ... that defend against AI agents that are malicious.
So could we conceivably have AI agent versus AI agent duels between good and nefarious purposes and good purposes, or? I think in the enterprise space, you're going to see definitely orchestration agents operating. We've already got it in companies.
We're actually going to release later this quarter a very significant AI capability, which I can't get into too much yet. But it's going to be something that is going to validate a lot of these types of protections because we understand that very, very quickly, and we're already getting some information from vendors and customers we're working with, that AI is going to be orchestrating a significant amount of attacks. And- Do you expect, in that vein, do you expect a fair number of announcements at RSAC along those lines, like AI agent defense systems of sorts that are brought out by companies?
Yeah. They're going to have some sort of platform or architecture to address this special problem you're talking about, or? I think there's going to be companies dealing with many areas of it.
You say AI agents, but obviously AI is a large area of- Or autonomous ... LLM poisoning, finding out, for instance, all of the models that you use in AI, how contaminated are these models? Where do they come from?
Yeah. They might be open source. What's in those models?
Who made those models? How are they leaning? There's models made in China, models made in America.
What's inside those models? How do you isolate those models in an environment to make sure that you're not going to damage your environment, and have unnecessary leakage? Because you don't know what these LLMs are going to do.
Even if they're privately hosted, you don't really know, so you need to assume. Kind of like in the cloud. You send data in the cloud, if that data's not encrypted, you don't know where that data's going.
It's very similar with an LLM model, whether you're forming it locally or using a local database to maybe query external LLM models like ChatGPT or Claude or whatever it might be. To me, what's stunning or what's kind of troubling is the speed with which these new models are being pumped out. Right.
Conceivably, it seems like every other month, there's a new model from Claude. There's a new Claude model or GPT or what have you, and there's a lot more use of open source. So the speed with which things are moving and advancing- Right ...
makes this a particularly difficult time to defend your operations. I think it also opens up a lot of opportunity because, for instance, companies like us, again, we generate a lot of proprietary data, vulnerability data on environments across the spectrum. We've got millions of data points, which allows us to leverage this to better protect our customers.
And the AI allows us to get big data sets much quicker to be able to deliver to the vendor in a more organized fashion to eliminate the most amount of vulnerability in the attack surface as possible. So it does bring a lot of opportunity, but you have to have, at least as a vendor, you have to take into account what you're doing with the AI, what the threats are, make sure that everything is QA'd between results automatically. AI kind of checking AI, QA'ing the AI, so that it's reliable for your customers, that there won't be an accident.
I'm not sure if you share the names of some of your customers, but if you don't, I'm wondering which sectors are they primarily come from and what, if any, are their particular concerns? We're in the 87th percentile plus in the BFSI industry, so banks, insurance companies- Mm ... trading platforms, payment processors- Got it ...
credit card. Government also, large e-commerce, but we primarily focus on the BFSI industry. Okay.
And they're concerned about infrastructure uptime, service uptime, banking continuing, no disruption to banking services, transactions. There's a high volume of transactions happening in these environments. You can't have downtime.
So I was thinking about the landscape, in terms of the infrastructure, there's this big movement in the infrastructure towards faster, more use of data, AI, and I'm thinking about the landscape. We have these geopolitical tensions that you've experienced firsthand. We've got open claw phenomenon, which it's hitting executives within companies like Meta.
There was an incident recently there. These increasingly sophisticated AI attacks. There's a lot to digest, and I'm wondering, do you foresee more geopolitically motivated attacks or even national cyber warfare?
We talked a little bit about this before we started filming, but I'm wondering, you mentioned DDoS involving drones and others. Can you maybe go over that a little bit again? Sure.
So DDoS is used extensively in cyber warfare. We saw it in Georgia, we saw it in Ukraine, Iran. You see it all over the place when you want to cripple infrastructure, cut communications.
DDoS is a great attack tool to cause chaos. You also see DoS attacks more accurately, not DDoS attacks, for jamming drones. If you look technically, technically speaking, this is an actual DoS attack against the receptor on a drone, and this is what stops communication and drops the drone.
So this is utilized in- Have you seen instances of that in the conflict in the Middle East now? Or it's probably existed, but are you starting to see an escalation of that or maybe even infrastructure? I'm not an expert in drone warfare, but you can see that there's a lot of activity in the area.
You can see recently that the Americans even asked Ukraine for assistance in this area, so- Yeah ... definitely. I was recently in Texas in a very prestigious research institute that does a lot of research for the DoD, and they shared some very interesting findings on what's going on with drone warfare.
And what was very interesting is how much DoS attack is being used in that warfare. So definitely it's being used. Wow.
Well, that's a little something to ponder. I was going to ask you, how do organizations anticipate sudden surges in disruptions in their infrastructure? You're helping them, but are there other means that they use to kind of anticipate things before they happen?
I don't know much about your field or is this something that is especially used, I would assume, in banking, in governments, finance? Of course, the main thing any organization will do is try and have a solid architecture in their deployment and make sure that it's redundant and all these traditional concepts. I think what they're also trying to do is secure the application layer very heavily, too.
Right. So we're very focused on the application layer. Services are all over the place.
They're in the cloud, they're in DC, they're in multiple clouds. As best they can and have the redundancy to scale. But without the protection, no matter how much scalability you've got, you'll still- This is like a high-wire act in the sense there's so much going on there.
The upside is incredible. Right. And we should probably point out that the upside, for the most part, is what these companies are looking at in terms of efficiency, profitability, et cetera, but there's always that kind of a thread lingering in the background that they have to be aware of.
You can see the organizations that get hit with a cyberattack that makes headlines. You can see the immediate market cap effect, which can take- And we're seeing more of those ... 12 to 24 months- Yeah ...
and sometimes never get back to the position that they were at. So there is that imminent threat. It's not a threat for everyone.
It's not going to happen to every company, but for each company that this does happen to, it sets an entire industry kind of on alarm. Right. And I think this is going to be a story we're going to see repeatedly over and over again.
You always just wonder when it's going to reach a point where there is the defining events, and I'm not sure if we've reached that event yet. I agree. I don't think we've reached an event that says there has to be some fundamental policy- Right ...
change or something like that. And a bit of good luck to that happening. Maybe, by the way, in cyber warfare, that has happened because there's a lot of very quick targeting of targets on the ground- Yeah ...
utilizing AI and stuff like that, but that's of course not in the headlines. Yeah, that's right. So I think AI has had a tremendous impact on warfare in general, just the speed at which everything is moving.
It's in warfare. And it's only going to get quicker. Yeah.
And of course, that translates into the enterprise space. We see it already that there are AI attacks being identified, and the EU Council is doing testing on AI attacks, and other governments are checking how they're going to respond to this. So this is clear that this is happening now.
Right. It's not the future. It's happening now.
Right. It's interesting. Well, Matthew, this was a fascinating discussion.
I'm glad you shared your expertise with us- Of course ... and let us know what's going on because things are changing faster than we could ever imagine, and it's going to make for very interesting times. I've never seen anything in the tech industry like what's happening with AI, and especially on this side of things.
Right. So, thanks again for your time, and- Thank you, John ... it was nice meeting you.
Good meeting you. And we'll be back with more interviews later today, day one of RSAC. Hey, everyone.
Welcome back here to TechstrongTV. We're continuing our Wednesday afternoon coverage from RSAC here on Broadcast Alley, and I'm reaching way back to my Boulder people for this one. Let me introduce you to the founding team of StackHawk.
We have Joni Clifford, who I found out is still Joni Clifford. You know? And- But married.
But married. Just don't call her late. But Joni Clifford, who I've known as Joni Clifford for, I don't know, 10 years, no more, probably closer to 15 years- Yeah ...
I think. Yeah. Because- I'll just stop there.
Yeah. Because there's no more time after that. Fact.
That was- Right. Let's not even get you wrecked. And Scott Gorlick.
Gorlock. Gorlock. Also co-founder, who I've also known now probably seven, eight, nine years.
Yeah, at least. When did you found StackHawk? Was it about eight years ago?
2019. Seven years ago. Yeah, almost.
All right, I wasn't that far off. Yeah, close. I remember the first time I met Scott, we were in the Foundry offices- Yep ...
in Boulder. Yeah. Right off of Pearl Street.
Yep. Yeah. Anyway, though, enough reminiscing.
Well, we're not done reminiscing, actually. Joni, I'm going to ask you to kick off. I said I knew you...
I think the first time I knew you was VictorOps. That's right. And that might may or may not be a name you remember.
A lot of my DevOps people out here, you remember VictorOps? They were actually acquired by PagerDuty. No.
Splunk. Splunk. Competitor to PagerDuty, acquired by Splunk.
Yep. I don't know why I thought PagerDuty. You know why someone from VictorOps went to PagerDuty?
Yeah. Was it Jason Hand? We can play this later.
So tell us your story. Yeah. So Joni Clifford, CEO, co-founder of StackHawk.
My background is in DevOps, so what you were just saying. Right. Largely building software for software engineers.
We just went over VictorOps. It was a competitor to PagerDuty, and that company was so important because it was really in this hyperactive, we're finally releasing, DevOps is a real thing, and we had to make sure that if there was downtime or latency or anything, we were shipping those alerts directly to the software engineers who wrote the code. And I think that kind of arc of digital transformation is really what led me here.
And so, with StackHawk, it felt like application security testing was just the next mile of digital transformation. Yep. Why are we waiting until production to actually find vulnerabilities?
How come we're not collaborating with our software engineers or automating the findings so they can actually fix these and treat them like bugs? Mm-hmm. Not like even security vulnerabilities because they found them before they deployed to production.
So that is what I wanted to work on, and in the process of really getting to know, I didn't know the cybersecurity market. Right. And it felt like a very obvious process to tackle, but I interviewed a lot of security professionals.
I remember. You interviewed me. Yes.
We wanted to know- No, I do. I remember ... what was this domain?
Right. So And Scott, tell us a little bit of your path. Yeah, definitely.
So, security operations, security engineer by background. Worked at GoDaddy, leading security teams there for about 10 years. Mm-hmm.
And from there, moved to Colorado and joined another great Colorado company, SendGrid. Sure. I was a CSO there for three years.
Techstars company. Yeah, right before Twilio acquired them, and I've been working on application security at pretty much all those roles in some sort of fashion, like either deep in it or tangential to it, those kinds of things. Mm-hmm.
And so I had a deep passion for how to fix pretty broken process, how do we empower engineers? We did some of that on transition to cloud at SendGrid, like getting engineers involved early. " Yeah.
They're the one that start the code, and then way, way later they get to know about the problems that they have to fix. " But So we had a really good conversation about how can we help empower those teams, let them know about security vulnerabilities, and build safer software. Mm-hmm.
I think back to those early heady days of DevOps- Yeah ... when VictorOps was founded. So Raj, my friend Raj, was at JumpCloud.
You guys are in the building next up on the second floor there- Yeah ... that brick building. Yeah.
And what a revelation it was. Hey, let's alert the developers, not just the help desk guy, but we're going to cut that handoff from level one, to level two, to level three, we'll get back to you in 36 or 72 hours, to one boom. That's right.
One time and it's done. Now, today we almost take that for granted that developers are part of this chain, or part of this... My code's not working, I know pretty much right away if customers have it.
It was the same thing as you said with AppSec. It was like, it's similar to observability, quite frankly. All the action was on the other side of the event horizon, the event horizon being deployed.
Deployment Deployment. Right. Right?
That's where the action was. And that was part of this whole shift left, right? We're going to- Mm-hmm ...
shift to this side of the event horizon. Now, shift left has had an interesting journey- Mm ... in the DevOps space, right?
" And we came to find out the developer wants to write quality software. He doesn't necessarily want to be a security pro either, though. And we need the security people in all these things.
So it's been a journey which you guys have actually lived through- Mm. That's right ... over these last seven years.
Right? Of, well, did we overshift? How do we keep the security team involved?
How do we empower the developer without expecting him to be, or her, to be a security pro? Mm-hmm. What about the rest of the software team, the CI/CD team, the testers, the QA folks, the SREs, everybody that's involved here along this SDLC.
And then just when we thought we figured that out, AI drops from the sky. Boom. Because life can never be easy.
Never. " Yeah, it's really interesting because how we were founded was about making this type of testing that used to happen in prod, took a really long time, making it portable, easy to run on a software engineer's machine, easy to run in CI/CD, and that's very unique. I don't know of another person or another company doing runtime testing that has the same approach, right?
They're all using these cloud-hosted scanners that can't be portable, they can't be fast. So there was this really interesting architectural decision we made early on that set us up perfectly for this period. And we're now closing customers and having our existing customers come to us and say, "I think CI/CD is too right.
" Yeah. " Yeah. And I think the AI DLC or AI-supported DLC is the place where we're really focused, which is on agentic DaaS.
Right. So yeah, with runtime, you want to kind of hit the whole gamut. You want to be able to test with AI and auto-remediate issues in Claude or in Cursor.
But you may also want to test closer to prod as the- Yeah ... secondary check from your AppSec team, and you can totally do that. So, I feel like we really have a leg up.
It was just this early decision we made that now suits us perfectly for this moment. The interview before you guys came on, I was talking to the CEO of a company called Anvil Logic. Not related to you at all.
Okay. But more of like a big data lake security company. Mm-hmm.
Same thing, founded maybe two years before you, 2017. Okay. He didn't think of AI when he founded the company.
It was this problem, though, of how do you secure, at the time, Hadoop and- Mm ... stuff like that back in the day. ButAI has made his life a lot easier because- Yeah ...
he didn't realize it back then, but he really needed that technology to really wrap your head around that kind of big data. It's the same thing here. We wanted to radically change how we look at testing code, testing applications.
Well, AI, and this is only in the last two months. With Claude, Opus, and all these things, all of a sudden, we have the ability to test- Yeah ... like as we're making the code.
That's right. Soon as we commit the code. Any time along this CICD virtually, and without manpower involved.
We just report it back to the human in the loop, or as a lot of people are saying now, the human at the helm, because we don't have enough humans to be in the loop anymore. Mm. Too many loops.
There's too many loops. There's too much code. Yeah.
And so you guys, right place, right time. I always learned that from Brad Feld. Sometimes it's better to be lucky than smart.
It's good to be both. But that's, I think, what we're dealing with here. And at the same time, though, Scott, as we just said, we have so much more code.
So much. Yeah. And so I wrote this piece about a couple of weeks ago.
We've moved, in AppSec anyway, we've moved from the question of how do I find bugs or how many bugs do I find- Yeah ... to what's governance look like here? So it's no longer enough to do the scan.
Yeah. " And ultimately, you'd get half of the people say finding, half of the people say fixing. We had great tools to find problems.
Prioritizing those fixes has always been hard. And we're just not fixing problems that are discovered in code, but the power that comes with the agent being able to understand what the problem is and be able to actually fix without wasting mental power from a dev or interrupting a cycle for delivering product, delivering value, it's just radically changed how application security is working. Look, we moved the cheese in AppSec.
That's what happened here. Yeah. We went from a focus of finding to a focus on fixing.
Because as much new code as we have, we could find vulnerabilities till the cows come home. That's right. But we got to decide what to do with them, what to fix them, not fix them.
Are they real? Are they not? Are they reachable?
All the things that you guys know. Exactly. I saw a study on this.
What was it? Claude Code found, I think it was 122 potential vulnerabilities in Firefox in an hour or two hours, whatever it was. 11 of them were actually real, call them real vulnerabilities.
Two of them were exploitable. Mm-hmm. Right?
That's a huge problem in that- And that's pretty much the ratio. Yeah. " Because the punchline to the story is always, and then we tested it in runtime to see what was actually exploitable.
Right. Which is what we've been doing for the last seven years inherently. Right.
So being able to get into that loop, be the part and the function that's doing the testing of the behavior, not just does it look like it's vulnerable- Right ... and validate, yeah, this is vulnerable, and we should fix this one thing or these two things, and get rid of the other 120 other things- Right ... that are irrelevant.
Mm-hmm. It sounds like a nothing thing if you're not into security- Right ... or you're not into development.
But if you are, you realize just how radical this is. Mm-hmm. It's a totally different focus for what an AppSec solution needs to do.
Yeah. And so all these people who develop the DAST and the SAST and the SCAs, they're all good. We've got great scanners.
But if that's what your business is today, I don't know if you got a great business if you're not dealing with the how do I fix these things- Yes ... or what should I fix- That's right ... and how to fix it, and are you going to let me fix them automatically or not?
Mm-hmm. I'm sorry, but you're the first AppSec people I've interviewed here in two days. Oh.
All right. Yeah, so I'm dumping it on your laps. Well, you're like on it.
Well, I've been, right? I know a little bit about it. And I've been writing about it because to me- Yeah ...
remember, I came from before the AppSec piece. Mitchell and I standing over there at Still Secure, we were vulnerability management. We were begging people to scan their systems once a year.
Oh, wow. And that was considered radical. What do you mean once a year?
I could do this every two years, three years. Yeah. But that's what it was back then.
It was job security because you gave them a list of vulnerabilities like a telephone book. If you don't know what a telephone book is, Google it. And they'd start on New Year's, they finish on Christmas.
Yeah. And they start again. And then you'd do another scan and give them the book back- Yep ...
a new book. New list. So this is what progress is- Yeah ...
in security. How now does- Yeah ... you go to market with this and get that message across?
It's a total sea change. Software engineering is the first job to be completely changed by AI. Yeah.
Tip of the spear. They're just using prompts. We've eight X'd software engineering in the last six months.
So everything around that's surrounding code delivery has to change, and AppSec is the next most important thing. We just closed a customer who was handwriting 25,000 lines of code a month. Could you imagine?
Yes. And they're in financial services, by the way, so a mid-market financial services company. They employed Cursor.
The next month, it was 250,000 lines of code. Wow. Next month, even more.
So literally 10 X. And they called us, and they're like, "We're sitting on a million lines of code that we can't deploy- Who's going to test it? " And they're in a regulated industry, so they needed to.
So we've been co-creating with them this new AI DLC. And to your point about static code analysis tools, we have to totally rethink it, because at 10 X, where we're just getting started, software engineering, it's called the vuln apocalypse, right? Yeah, it is.
There's just no way we can fix these things. So, our perspective is, you have to focus on what's reachable and exploitable. There's no time to focus on anything else.
You can't take a food chain. I don't know if you ever read... So Brad Feld used to give this book out to all of his founding teams, "The Goal" by Goldratt.
I forgot his first name. But it was standard MBA book in the '80s and '90s. But it introduced something called, you're probably familiar with this, the theory of constraints- Mm ...
where as soon as you undo one bottleneck, there's another bottleneck- That's right ... behind it. Another bottle- Actually, Gene Kim's Phoenix Project- Mm-hmm ...
is the IT version- Right ... " "The Goal" is about manufacturing. But similar, if you ever read "The Goal," you'll see where Gene got Phoenix Project from.
We're not familiar with the theory. We're living it. Well, we all live it.
We all live it. But that's exactly... You can't...
So we removed the bottleneck of humans writing code, and I can only do 25,000 lines of code. And man, I could do 250,000. I just 10 X'd my lines of code.
Yeah, but now you just discovered the next bottleneck. That's right. I can't even test this.
Let's see. But what's going to happen is, okay, now I tested it, I found out originally that, I don't know, 300 vulnerabilities are really only seven vulnerabilities. Boom, I removed another bottleneck.
I'm doing that automatically. Well, now here's the next bottleneck. I got to remediate them.
What's it going to take? All right. Maybe I'll be able to do it agentically.
So we're going to do that, but there'll be another bottleneck. Mm. Yeah.
That's the theory of constraints. But from your point of view, this is really a game-changing- Mm-hmm ... kind of new era, right?
And you have marketing people, I'm sure, right? But I think that's what the marketing message has to be here. Mm-hmm.
AppSec, this- Yeah. " The thing that I've found is a lot of engineering teams are in the same mode as the AppSec team- Yep ... where they're tinkering with AI and messing around with OpenClaw and trying to figure out what works in their environment.
And then once they figure that out, they're starting to standardize, "Here's the tools that we use. " Mm-hmm. Now's a great time to go sit with, as an AppSec person, go sit with the engineering team and watch them go through this iteration, watch how they're hooking different parts of the process so that they can actually work that into their process.
Into the SDLC. Yeah, exactly. Mm-hmm.
It is. And so- Into the chain ... knowing what's out there, what's capable, and then being able to understand the process at your business of what your engineering team is doing, and how do I fit a new AppSec process into my new engineering process?
PS, there's budget attached with that because everyone's working together to get more value to the customer. Yeah, but you know how it is with budget. Again, don't take my cheese, right?
It's my budget. You go get your own budget. That's right.
And there'll be some turf wars around that, too. Mm. Yeah, I think, from a CEO perspective, from the C-suite perspective, we're spending a lot of money on tokens, right?
And the whole point is, how do we improve efficiency- Say that again for me. We're spending a lot of money on tokens. Spending money on tokens.
You ain't kidding. Yeah. I think you're spending a lot of money on tokens.
Yeah. Yeah. " And they also want to do it securely.
Yes. So being able to say, "Hey, I want to empower this process- Mm-hmm ... and enable this process, and I'm going to need some extra budget," it's not an easy conversation, but it's a way more acceptable conversation than- Absolutely ...
" That's right. Because when did that ever work, right? Never.
That never worked. And that's been a security problem, too, for years, right? " You're saying that as you see the train pulling- That's right.
into the station. " So let me ask you the ultimate question then, Joni. If I'm a reporter, I'm not a reporter, I'm just shimmy, but is StackHawk an AI-empowered AppSec solution?
Of course. All right. In two ways, right?
We are empowered by the wave. Runtime has never been more important, and it's pretty exciting to see it... happen.
We're six, seven months or seven years. We'll pretend it's months. Yeah.
Years in. Well, the time, it seems like months. You've been having so much fun.
Yeah. Of course, of course. But also, we were talking about by using AI, what you're then able to do with your product.
We've been able to release capabilities that would've been whole companies before. We are using AI to really help bridge the gap, the knowledge gap between what an AppSec person knows about software delivery that's happening in their own organization, and how fast it's happening versus what they know today is enormous. So, beyond the testing piece, over time, we've added this lens of observability component into based on what's happening in your source code repositories, you have this many APIs, web applications, LLMs, LLMs talking to APIs that need to be tested with something like StackHawk, able to show them what contains sensitive data.
The amount that we can get out of the code base to help inform the AppSec team as to where to focus is incredible, and we've been- Yeah ... totally empowered by AI to do that. So, really exciting to use it so natively, but then also just be able to draft on- Absolutely ...
the change that's happening. What's going on. Yeah.
So I've got a CTO question for you then, Scott. Hit me. How long until you're doing remediations?
Not long. It already happens today in this agentic loop, right? There you go.
So, I don't have to make tickets, which is awesome. Those days are done. Yeah.
" Go fix it. Fix it right there before we even get anywhere near CI/CD. Yep.
It's happening, and it's crazy exciting. Mm. Mitchell and I had this discussion this morning on it.
The days of just reporting- Mm ... without doing are over. That's right.
You got to do. You got to do. It's an age of doing.
Yeah. And, look, I don't know how all this ends- Yeah ... but it's really an exciting time- It really is ...
to be doing it. You know what we haven't mentioned, guys? People want to get more information about StackHawk.
Mm. How do we do that? com.
You can learn a little bit more there. We have a ton of blogs, content, ability to learn more about this AI transition and Wave. And we're also pretty active on LinkedIn, so feel free to follow us, engage with us there- I follow you already.
Absolutely ... and- And if you're at RSA, you could play Where's Waldo with the giant guy in a purple jacket and/or his companion. Okay.
So you're there. I'm there. Yeah.
Stop us. We're at the conference. I got to tell you, I haven't even had a chance to walk down to the floor.
It's pretty calm. It's really not- I heard it was a little chill this year. Not super loud.
Not very many lights. It's pretty nice. So Monday, we put on our Dev, well, we just call it DevSecOps.
I don't even call it DevSecOps anymore- Yeah ... because I don't know what to call it. I do know what to call it.
We called it Defending AI Native Dev. Right. And because it is all about AI native dev.
And, so we were there Monday, and it was interesting, but I also snuck down to the Innovation Sandbox. Mm. And everything there was AI.
Yeah. " So it's an interesting time. They're watching this live, so they probably are not there.
Where could we see you next after RSAC? Oh. Black Hat.
Black Hat. For sure. Lots of regional events.
Lots of regional events. With some of our partners. Mm-hmm.
Guide Point and WWT and some of our great partners. We're always doing regional events, some informational, come learn something, and maybe have a good steak dinner. But our next big one is probably Black Hat.
Is Black Hat, early August. Yeah. I'll be there.
All right. I'll be on the... So there, I do go on the floor to do video.
Here, I'm on broadcast alley, so I get at least to... I'm stationary. People come to me.
In BlackHawk- That's funny ... I got to go to them. I'm the BlackHawk.
I did StackHawk and Black Hat together. BlackHawk. That's a new conference you probably haven't heard of yet.
It is. But if you do it, that's a good name for your conference, BlackHawk. Joni, it's great seeing you.
Good to see you. Scott, always a pleasure to see you. Thank you for having us.
My pleasure. We're live. We're at RSAC.
We're going to be back in a little bit. com. Yes.
Check it out. We'll be right back. Hey, everybody.
We're back in Amsterdam at the KubeCon + CloudNativeCon Europe event, and we're talking to my friend Weigu from Broadcom about what they're doing in the open source community and all the good things that are going on there. Starting with, there's this new project that you guys have donated to the CNCF, Valera. What exactly is that, and where does it fit in the spectrum of things you guys are working on?
Of course. So Valera is a software that allows you to do backup, recovery, disaster recovery as well, and also do migration. So with this tool, it allows the enterprises to plan for their data and configuration to be consistent and to be able to recover it as well.
Right? And as we always do at VMware, operations for enterprise scale is very important. You look at all the other projects we contribute to, for example, etcd, Cluster API, et cetera.
So we bring our decades and decades of experience in running and managing private cloud, and bring those operational experience into this new Kubernetes space for our customers as well. Yes. Now, historically, VMware had kind of a Kubernetes approach where you could run it natively on the VMware Cloud Foundation.
Mm-hmm. And then there was Tanzu as well as kind of a project. Are those two still kind of the main Kubernetes engagement paths for you guys?
Or what's the relationship there? So that's a great question. The only engagement in terms of VKS, that includes VKS runtime or Kubernetes runtime, as well as all the cloud services that you need to run Kubernetes, are all based on VCF and in VCF actually.
It's part of the VCF software stack. Now, Tanzu as a separate product division and they have their own product portfolio, is going to focus more and more on this PaaS platform where they use the technologies from Cloud Foundry, et cetera, to focus on this developer experience. But when all things come to Kubernetes, it's VCF.
Got you. All right. Is there something right now that you perceive that is...
If you have a wish list of things you wish the community would prioritize a little bit as it relates to Kubernetes from your perspective, what comes to mind? Well, again, going back to our heritage, in terms of infrastructure and operations, right? So we will very much like the community to continue in that space to bring all this cloud experience to the customers.
I'll give you one example. If you think about, let's say, dynamic resource allocation, DRA. It's all about GPU resource allocation and everything, and surface that up to the Kubernetes clusters.
And guess what? We have been doing this for many years at the VM level already, right? In terms of presenting the GPUs as assignable hardware and if you look at Kubernetes constructs, the device group, the device class, and the resource claim, et cetera.
We have very similar concepts in the VM space already. So it was so great to see the emergence of DRA since last year, and we think there's a great opportunity that we can marry that technology and use the constructs that we have in our stack and make the GPU and AI workloads more accessible to our customers. Of course, at the show, AI workloads has been one of the main topics, and specifically AI inference.
Yes. Are there things that organizations need to do to optimize those workloads for Kubernetes types environments and open source? And it seems to me there's a lot of projects walking around here that are related to that.
What are you guys looking at or thinking about? So we are taking two approaches, but they are very much related. The goal is to meet customers where they are, right?
So by that I mean number one, in our VCF stack with VKS, we still provide a bunch of packages and services that developers and the platform engineers will need to build their applications, the workloads to run in Kubernetes. So they have that option if they just want to simply consume out of the box that customer experience. On the other hand, we also, again, meeting customers where they are, we understand, and many of the enterprise customers also tell us that, "Hey, over the last few years, we have built up our own CI/CD pipeline," for example.
"We have our own tooling and everything. " Right? So in that case, we are working with the broad ecosystem and a lot of the partners who are at the show as well.
You probably saw the announcement earlier this week, in terms of partnership with Kong, et cetera. So we work with all these partners and the CNCF projects to validate how to make those same tooling and the platform work with VCF. So we will not only provide, let's say, reference architectures or technical validation.
In certain cases, we may even provide Git repo, for example, so that customers can sample those repo code and just basically deploy the same exact tooling that they have and make the workloads run in VKS naturally, right? So with both approaches, again, coming back, meeting the customers where they are and make sure the best outcome for them based on what they prefer. Is there more convergence now between the VMware world and the Kubernetes world?
Because historically, I can remember when Kubernetes first came out, there was this general feeling that Kubernetes would compete head-to-head with VMware. But now, in hindsight, it looks like most of these Kubernetes clusters are running on virtual machines anyway, and maybe we're starting to see some convergence. Yes, I think that's exactly what we see as well.
Essentially, regardless of whether it's a modern workload that runs in containers or running in VMs, first of all, they all need infrastructure, right? Whether that's compute, storage, networking, and there are certain characteristics that developers would expect. For example, performanceSecurity, very important.
You don't want your application to be the landing spot for security vulnerability or ransomware attack, right? And you definitely don't want your applications to go down. So the reliability and all those aspects are very important.
And vSphere has been at the center of the data centers, if you will, in the last more than two decades now. That's what we do best. Now, there's also, when you run Kubernetes and containers, I think there is a trend, and many analysts are pointing out already.
For example, IDC predicts by 2028, 85%-ish of the containers will continue running in VMs. And that's what the hyperscalers do as well, right? So what that provides is really the level of resource isolation, security, and we like to say that we provide six layers of security all the way from the hypervisors to the containers and the namespace, right?
All that provided in VM and resource consolidation and the utilization. Think of today, the hardware cost is out of control. And vSphere, what we do at best is this resource utilization and consolidation that makes sure that we can save you tremendous amount of cost by running this architecture, and that remains to be true.
And more and more customers, I think I even see some solutions on the expo today that actually gets to what we have been doing for more than two decades. So that's definitely happening, and I think that will continue. Now, it seems there's more nuance in the sense that the applications are becoming more distributed.
Yes. And there's elements in the cloud, there's elements on premise, and there's elements at the network edge. So is that changing the way we think about this infrastructure conversation because the workloads need the...
There's just a higher degree of interoperability required. Yes. So in my view, two points, right?
Number one, going back to meeting customers where they are, our infrastructure doesn't have to be in your own data center. So our software stack can be deployed on the cloud, in the data center, or on the edge. So that gives you that level of consistent infrastructure wherever you want to run your workloads.
But secondly, I think it comes back to this VKS. It's a conformant Kubernetes distribution, right? So what we do is, again as I said, we may have some opinionated offerings or packages, services that goes with the solution.
Right. But by and large, it's open source, it's very conformant with Kubernetes. So that allows the customers to move workloads to any Kubernetes conformant clusters if they choose to do so.
Mm-hmm. And that's tremendous benefit to our customers, as you can see. And there's a benefit to obviously being conformant that gives us agility or time to speed us to production for our customers.
By that, I mean when a new Kubernetes release comes out, typically within two months, we will be able to validate and certify that our VKS cluster will be able to allow customers to consume the latest and greatest Kubernetes release, right? Mm-hmm. That's on par with all the hyperscalers out there.
That level of agility allows our customers to consume the latest and greatest features. But again, if the customers so choose, they can move those workloads to another conformant certified Kubernetes distribution as well. So it's an open ecosystem out there.
Right. I have yet to meet anybody who's standardized on one particular type of distribution- Exactly ... of Kubernetes or much less the version number, right?
Exactly. And I would also add, in addition to the agility and speed, we also support multiple Kubernetes releases for our customers. So architecturally, we allow customers to deploy multiple VKS clusters.
It's not just one single cluster. So with this, it comes the benefit of isolation, security, et cetera, but also different teams may want to consume different features that's offered by different releases. That level of flexibility is there.
And on top of that, with 24 months enterprise support of all those releases gives the customers a great level of confidence with us. Now, we live in a world where there's greater sensitivity about cost, but if I look at the architecture and as I understand what you guys are trying to do, is the total cost of your approach going to be ultimately less because more of the components are integrated? No, I think ultimately what determines that is the value that customers get out of the solution, right?
So not only from the compute storage networking perspective, what we put together in terms of cloud operations and cloud automation, it's very important and essential to our customers operating their private cloud, right? And listen, we didn't invent some new infrastructure or things in that nature for Kubernetes world. We basically put a control plane on top of the same exact infrastructure, the same stack.
This integration creates the value not only in that sense, but also the single unified APIs for customers to run their and manage their both their container workloads and VM workloads. That's tremendous value. So I think over time, that value will make the solution moreresonate with our customers.
So does anybody at Broadcom keep track of how big the contributions are to the open source community? Because I think everybody thinks of a lot of other companies out there, but it's not clear to me that anybody knows what Broadcom's doing. That's a great point.
We don't talk about it enough. We are starting to, right? org website that tracks the contributions.
If you look at the dashboard, VMware actually has been a top five contributor to CNCF over the last decade. Yeah. And there are a lot of projects that we have contributed to.
In addition to the Valero we announced earlier this week, there were projects like Contour. There were projects like Harbor Registry. Of course, we contribute heavily to etcd, Cluster API, and all these different projects, right?
So a top five, and we should talk about more. And obviously, at this conference, we are starting to make a lot more communication to our customers about where we are and the future that we intend to go in contribution to CNCF. Is there any particular thing you have at the top of your wish list for the open source community that you just wish as a group we would all focus on a little bit more?
That's a great question. AI is top of mind for everyone. Obviously, I saw some announcements about open sourcing some of the GPO drivers, things in that nature.
I think we can benefit from those as well, right? And then from the whole platform engineering landscape, if you look at it, there are a lot of things that's happening. org, right?
If you look at that reference architecture, what's interesting is, in addition to the developer side and obviously the CI/CD side, there are more planes that are being added to that reference architecture, including observability, security, and of course, infrastructure and the resources. So I think we play very well in those planes in terms of security observability. We have our own solutions.
But again, going back to the open ecosystem point of view, we would welcome CNCF contributions and projects that can benefit customers in those spaces, and we would love to integrate and validate some of those solutions, right? Give customers the choice. So as we see more and more of those projects mature, we will try to give customers more guidance and at some point, as integration is needed, we'll try to do that as well.
All right. " I mean, I still see a lot of things managed in isolation on my side, but what are you seeing? Yes.
So at enterprise scale, cluster management, for example, is a big thing in terms of life cycle, right, from deployment to update, upgrade, patching, and all that. So at that scale, you need multi-cluster management and multi-cluster life cycle management capabilities to go with it, operationally to be excellent at it. So I think some of the customers, I should say, may see Kubernetes as a simple platform, which it's not.
It's very complex. So I think customers will realize, in addition to the broad ecosystem and all the projects they have to stitch together just to run Kubernetes, they will need to start thinking about the scale that Kubernetes needs to be run and the scale the Kubernetes clusters need to be managed, et cetera. And more and more of that will need enterprise level features and capabilities, not only coming from vendors, but also from the CNCF projects, right?
So I think customers will realize over time. All right. Folks, you heard it here.
Hey, no matter how complicated things get, at the end of the day, when it comes to IT infrastructure, there's a good rule. It's called keep it simple. Hey, Wingu, thanks for being on the show.
Thank you, Michael. All right. Thank you.
And we'll be back in a minute. Hey, everyone. This is Alan Schimmel, CEO of Techstrong.
Welcome. Welcome to this very special virtual event that we are producing in partnership with our friends at Microsoft. The event is titled "Unlocking the Future of Agentic Experiences," and it's going to be a series of videos in this virtual event that you're going to be able to take a look at and interact maybe with some of the analysts and speakers here.
I really think you're going to enjoy and get a lot out of these videos and this event, and look forward to hearing your feedback. I'd like to kick things off with our keynote, and it's our keynote because I think we've got two terrific ... speakers in this one, and it's around the future of apps.
Right? And it features Futurum CEO and principal analyst, Daniel Newman. If you've ever seen Daniel on any of the many TV shows or conferences that he keynotes, you know what a dynamic thought leader he is.
I think you'll enjoy it. And Daniel is going to be speaking with none other than Ryan Cunningham. Ryan, of course, is corporate VP for the Power Platform at Microsoft.
And Ryan is going to share with Daniel and with you the all-up vision, the all-around vision for Power Platform. We're going to connect the dots between apps, agents, and interfaces. Right?
Ryan, and with Daniel, are going to illustrate how Microsoft is leading automation in this AI era. He's going to articulate how Microsoft is enabling every organization to build, govern, and scale intelligent solutions with unmatched speed and trust, driving the future of agentic apps. It's a great discussion, and I think it's a great learning experience.
So here's Daniel Newman and Ryan Cunningham. Alan, thanks so much for that introduction. And to introduce myself, I'm Daniel Newman, CEO of Futurum.
Very excited to be here today with all of you and even more excited to introduce my guest for this conversation, Ryan Cunningham from Microsoft. Ryan, why don't you say hello to everybody and give a little bit of background on the work you do at Microsoft? Thank you, Daniel.
It's awesome to be here with everybody today. So I'm Ryan. I'm the corporate vice president for Power Platform here at Microsoft.
So look after all the teams of product people and engineers and designers that are building really our low-code application platform and the future of where that is going. Really excited to talk to you about that today. Ryan, I've been working with and around your team for many years.
As an analyst, it's been great to follow. Mm-hmm. Of course, the change that's been going on in this market is extraordinary, and I think that everyone out there is going to leave this conversation knowing a little bit more.
And hopefully, maybe you'll give us a little bit of that secret sauce about all the stuff Microsoft's doing. Nothing too secret, though. You know how that goes.
Oh, I know. So let's start big. When we talk about the future of apps, connecting agents, interfaces, applications, what is the north star for Microsoft?
What are you guys heading towards here? Yeah. Look, it's a crazy time to be alive in a business application platform environment, right?
Because this whole world is being turned upside down in actually two dimensions at the same time. One is how we build software, radically changing in a world of agents and vibe coding and everything that is filling up our LinkedIn feeds as technology professionals. What's really interesting right now is the dramatic expansion in efficacy of what I can build, and the dramatic expansion of who can participate at the same time.
You have to be evolving the platform even more and even more quickly to- Right ... to get them what they need and what they're trying to do to accomplish the future that they're trying to build. Yeah, 100%.
And I would say to even build on your last comment because it's relevant here. It's not just an opportunity for more people to tinker and build things. It's actually really an imperative.
If we're really going to accept the premise that every company that wasn't born yesterday is operating inefficiently and needs to rapidly advance in a world of agents, then the expertise you need is not just the AI technology expertise. You actually need to go get all of the process expertise. All the humans who know what it really means to run a more efficient HR department or finance department or whatever it is, they're sitting with a real job in that department today.
You've got to go figure out, how do I harness that expertise and bring those tools right to the point where the process is actually happening today? And that's where you need a higher abstraction platform that has agents built into it that help do the coding, that help do the work. Microsoft does have some really unique approaches in this space, and particularly if you look at this broader world of how software is getting built and code generation and agent swarms, and every other term we're coming up with right now.
Where we're really focused right now, particularly in the space of business applications and productivity, is really make that relevant to the way companies run and operate. We're not out there to serve any possible whim of any possible developer on the planet. There's lots of great tools for that.
Microsoft makes some of them in other places. But here, we're really focused on the core operating system of a company. And by that, I don't mean Windows.
I mean sort of all the business applications, business processes, specialist teams of people that today make a company tick. We're seeing consolidation in this era. Customers have a ton of choice.
Yeah. " Right. What we're going to want to see is the orchestration is going to be super important, and then, of course, the speed, flexibility, access to all the tools, data, cloud, and of course, Microsoft's in a very small group- Right ...
of companies that has pretty much all of those things. Right. Not the only, but one of a very small number.
Yeah. And I think that makes you competitive. I want to go to the pragmatic side because a lot of the viewers here are probably thinking about, how do I do this?
How do we do this in our firm? We hear some of those stats about AI ROI in the enterprise, and let's just say that I'm an absolute believer, but I do think there's some hurdles. What are those key enablersYou're seeing fundamental enablers that enterprises need to get right now- Right ...
to make sure that those POCs and those production AI projects start to work and really show value. Yeah. We're seeing customers adopt exactly the mentality you're talking about.
Not just, how do I run the current process faster, but what if I fundamentally changed the process itself to really great effect? We've shared some stories of retailers that are starting to use agents and apps and automation together to totally change how they do things like fraud detection and even refunds and returns management. If I go contact an online retailer and say I want a refund, traditionally, that's a human going and vetting, is that a real customer?
Did they buy something or is this fraud? Does it meet our return policy? Which is, by the way, usually a 50-page PDF that changes once a quarter.
And then do I want to issue the refund or can I save them as a customer? And that's super slow, and it's super inefficient, and it's really expensive, and often it's outsourced to vendors. Can I go implement an agent that does that instantaneously or at least does major parts of it instantaneously?
Really starts to change my operating and my risk profile and my customer relationships. And so even in use cases like that, starting to see millions of dollars of value unlocked really quickly and just better customer satisfaction. Actually, the balance of value is really shifting towards that process expertise.
" That's just not a thing that happens to most regular people. But a whole lot of people woke up this morning and said, "Man, this part of my job sucks. That could be better.
" Right? And really harnessing that energy, that value, those skills and those people, and bringing great tools to them, that's part of the whole thesis behind why a platform is critical right now. What does it mean to totally change that interface into a human and agent collaboration space?
What does it mean to go see the activity of what agents are doing on your behalf when they need your input? Let's talk a little bit about Plan Designer. Yeah.
We're seeing we go from manual to automated to agentic level orchestration, which is great. One of the key things, too, is going to be trust. We got to trust our systems.
We got to be sure that the agent workflows we're building, that they're inspected- Yeah ... that they're constantly modified to be sure that they're right, that they're traceable. Talk a little bit about how Plan Designer can help companies, because that's a lot of work, by the way.
Yeah. That's a lot of work- Yeah ... you can automate or- Yeah ...
streamline some of that out of the process. Yeah. Well, look, for folks out there listening that haven't experienced Plans in Power Apps, it's worth trying out.
com. You can try it today. But what it really is, is a different kind of AI-centric development experience.
You go type into that box a business problem. We do not assume that you just want us to spit out 1,000 lines of JavaScript that you need an app, like a lot of vibe coding platforms today. We actually do what a real software team would do.
In fact, we've built in a digital software team. We've trained a requirements agent, a process agent, a data agent, a solution architect agent. It's a highly collaborative environment.
This is not a sort of throw a paragraph over the fence and watch magic happen. It's really sort of training and teaching people with process expertise how to think like software architects and solution architects so that they can know up ahead of time, why do I want AI to do certain things? Where do I want it to work?
How do I want it to interface with humans? And that's really the foundation of that trust in a system. Have you seen some examples out there of Plan Designer being sort of delivering promise?
Because it sounds- Yeah ... super optimistic. Are people using this?
Oh, 100%. We have started to see really interesting sort of challenges thrown at it. " In a way where traditionally going and turning all that old stuff into full stack software was just incredibly costly and cost-prohibitive.
Starting to bring those things into Plans and generate a more robust plan for modern software, moving much faster. We've even seen huge extremes of that. I've seen a customer take 50-year-old COBOL code and just paste it into Plan Designer and say, "What the heck is this program doing?
" And actually, the results were pretty promising. So people are getting really creative with bring the problem, bring the challenge, bring the business area that you want to improve, and then start working with these agents and on this digital software team to design a solution. So we're doing all this work.
We are trying to train people to think differently, remove constraints, whatever's possible. But the UI is it that seems to be the next frontier. Like the old enterprise software, it's like these are the things you can move, and these are the things you can't, and what you can customize, and here's what you can't, and here's your dashboard.
It's like, great, but in the future- Right ... I might just want to say, "Hey, Microsoft," whatever. Yeah.
" Right. And then I want it to obviously learn based on my behavior over time, what I want to know. Right.
Then I want it to continuously, things like that. Right. How do you see being in this space so much, the kind of UI evolving?
Yeah. I thinkSpecifically chat as a UI is super compelling and natural for a lot of things. I do not believe that we're going to go regress 40 years of UI innovation and go all back to chat in the command line, though.
There's a lot of things for which text is actually a terrible modality, in which just paragraphs are not great. And I think there's a more underlying thing here that you're touching on, which is a lot of traditional experiences, whether it's text-based or visual, assume a human shows up knowing an intent, right? As opposed to an agent being really proactive and taking care of something for me or pushing me an update or a notification when I need to know it.
And so I think those experiences start to evolve a lot. What gets really interesting is where they meet. And we really see a lot of this task-based data entry, repetitive stuff, increasingly getting delegated to agents on your team.
But that means you'll need to work with that team in a totally different way, right? And where a traditional CRM system or HR system or whatever, pick your business application, was previously, like we talked about, people typing into boxes and then other people viewing reports. What does it mean to totally change that interface into a human and agent collaboration space?
What does it mean to go see the activity of what agents are doing on your behalf when they need your input, when they're blocked on something, or they've noticed a trend, or there's a form they tried to fill out but didn't complete? Then that's an important meeting space to go have experiences and user experiences. And a lot of times, those do need to be structured in a visual way.
A lot of times they could happen ephemerally or with a chat message. But how do you route people to the right place at the right time? We're working across all of those fronts.
That's why we have a robust set of tools in Copilot Studio for building the agent part of all of those things. It's why we have a ton of evolution in Power Apps, sort of becoming this new agent-centric experience where I can see a feed of that activity. I can have agents help me do the work in the applications.
And those two worlds will just continue to evolve together as we start to bring things into the future. So you heard me talk a little bit earlier, Ryan, about governance. Governance is part of the critical constraint and one of the things that differentiates software, right?
The reason we can't just use OpenAI for everything would be because it doesn't know how to handle the data. Be like, "Oh, let me talk. Help me do a job offer, or help me do a-" Yeah ...
compliant healthcare notice- Right ... " It doesn't know how to do that. Right.
So building applications that do know how to do that is the key. You got to build it. And of course, we want to go fast.
Right. Fast is the new rule. Right.
But the trust and scale are the other words. I know you often use these words. Yeah.
But what are you thinking, where are companies sort of struggling with governance and scale here with automation and how do you think what you're building in Agent Oversight can help them? Yeah. So I'd say there's a couple dimensions to governance and scale.
There's the breadth dimension. We have a whole lot more people who now can build a whole lot more things. How do I make sure that all that stays on the straight and narrow when I can't centrally top-down code review every single thing that every single person and agent is doing?
And then there's sort of depth scale. When I do want to roll out a mission-critical solution to 100,000 employees that has AI in it, how do I make sure that that AI is not just functioning, but actually continuing to get better every single day? And the good news is we're not inventing any of that from scratch.
Breadth scale and depth scale were a challenge in the first generation of Power Platform. And something that we've built a ton of capability into the platform over the last couple of years to really tackle at huge scale, and we call that the managed platform set of capabilities. And within it, there is managed governance, managed security, managed operations for life cycle, ALM management, stuff like that.
And managed availability even. How do I go ensure high availability, run disaster recovery drills for critical workloads? All of that is built into solutions baked on the Power Platform.
And all of that value accrues to this next generation of components being built as well. An agent built in Copilot Studio benefits from all of those managed capabilities. A new app built in Power Apps with intelligent capabilities in it benefits from that entire stack.
And so that's why you start to see even highly regulated financial services firms, government agencies, et cetera, really trusting Microsoft here as opposed to a 20-person startup that was founded yesterday, to really take the bet on standardizing for this segment of software. Then you get into the operational oversight. Okay, I have agents doing work.
How do I have humans managing the work of those agents? That's not a developer role anymore. That's really an operational role.
What does it mean to be an agent manager or an agent boss in a claims department at an insurance company or in a supply chain operation? That's where we need these new interfaces, and that's what Power Apps is building in with concepts like the agent feed. How do I build a purpose-built oversight experience for really high volume activity of agents?
This is one of those things that there's so much doubt across the industry about being able to do this in a sort of when you give up the human in the loop or even just have one maybe guiding, but you're moving so fast. Are they auditable? Because when you're in a business, everything you do has to be traceable and trackable.
Yep. Is it predictable, the outcome? Right.
Like, hey, you're going to have an agent interfacing with your customers, or you're going to have an agent- Right ... doing a bunch of accounting work, which, by the way, it's like a spiral. One mistake- Sure ...
and then it's just how that goes. Yep. How are you guys overcoming that doubt through the guardrails you're putting up, through the oversight, the accountability that you're kind of baking into your platform?
Because I think if you get over that hurdle, Ryan, we move a lot faster. I think what's interesting here is actually a lot of our customers have had to build these systems already. A lot of our customers already operate critical processes across massive employee bases and even larger vendor teams that operate at arm's length already today.
Right? And we've already had to go build in a world of a whole lot of variability of who's doing a task. How do you create an audit trail?
How do you create rules? How do you create data policies? How do you create oversight?
A lot of those concepts exist today because there is variability in the human system, right? And so a lot of the way we approach this, okay, how do you adapt those existing concepts, policies, features, capabilities? How do you adapt that to a world where it's humans and agents doing the work?
And what are the sort of incremental 10% shifts that you need to make in those systems to accommodate agents, but not completely pave them and rebuild them from scratch, right? Because a lot of these sort of trust concepts, or zero trust concepts in a security concept, are already built into the system. And so there's a ton of work we're doing there in the managed platform, in a lot of the ways that a lot of the Microsoft security governance and oversight concepts apply to agents.
And that's, again, one of the benefits of building on a mature platform and a mature system in Microsoft is we're not having to recreate all that stuff from scratch like a point solution startup would have to do. Yeah. So the last thing just specifically on security.
Yeah. Security is a super hot topic. Yep.
What do you, the customers, how do you want them to think about the approach? Because in the end, you can get it all governed and right, but you have to keep your doors closed, locked. Right.
And that's an increasingly large problem. AI is as much- Yeah ... enabling it as it is fixing it.
Right. Well, look, I mean, we could probably spend an entire hour on security and threat model approaches in the AI era. It is absolutely critical.
And like any security challenge, there is no silver bullet. Every customer needs to have a defense in depth strategy, and needs to think about: What am I doing from a data security perspective? What am I doing from an exfiltration perspective?
What am I doing from an access perspective? The good news is we have a lot of that built into the platform today. Even a customer building their first Copilot Studio agent and using the managed Power Platform to roll it out will see a security score in the Power Platform admin center, will see AI-driven recommendations about what to do to improve that security score.
It has a whole bunch of capabilities in there that go all the way to operate this in the cloud, but with a private VNet, with your own managed encryption keys. Again, we have a lot of highly regulated, very security-conscious customers that are working with the platform today. I would say, though, to zoom way out and look at that, and maybe connect it to some of the rest of the conversation we've had, it is absolutely risky to go too fast.
It is also very risky to go too slow. And the rest of the world is evolving, including threat actors and competitors, right? And so the cost of standing still is probably the most costly position to be in.
So let me, as an analyst- Yeah ... I have to ask you, because I've got a few things. But what kind of in this whole evolution, this exciting moment for the future of apps and automation, and agents, what's kind of keeping you up at night?
The biggest concerns that you see out there, and then what are the kind of upsides for you? Yeah. What do you most kind of think could be the biggest surprise into the future?
Give us that big- Yeah ... visionary moment here, Ryan, to take us home. Look, I think, I'll do that in reverse order.
I think there's a ton to be excited about right now. And I think there's just so much potential and creativity that we can still unlock. NET code in their life.
What unites that community is this sense of, we can make something better. This can be better. Let's do it better.
And I feel like we're at the precipice of just blowing a huge lid off of the ceiling of what you can do there. And there's a whole lot to be excited about. You joke about a night job.
I stayed up last night vibing a Power App that's just a Tetris game because it was awesome and fun, and so much faster to create it than it would have been in the last generation of the technology. And I think that's a tiny, tiny microcosm of go take that creative energy and apply it to everything that's inefficient about every aspect of every customer organization today. We're really standing on the precipice of completely rewiring how companies work, and doing it with people who have deep expertise in that process and a deep desire to make it better.
And that's just incredibly exciting to me in this moment. It really is all about speed and pace of iteration. And really, it's about time to wrong.
There's so much that we need to go invent and co-invent with customers and experiment with and try, and nobody out there is perfect right now. What will define winners and losers for technology companies, for customers, for operations is how fast can you be wrong, and then how fast can you get less wrong and more right? So that's the journey we're on, that's the hill we're climbing.
But it's just a super exciting time to go think about what the top of the mountain can be. Ryan, this was a lot of fun. It was a great conversation.
Appreciate you sharing a little bit about where all of this is heading. There's so much potential for companies to really start reimagining- Yeah ... and realize just how big of a leap forward we are having right now with AI, with agentic, and the work that you're doing in Power Platform.
So Ryan, thank you so much. 100%. Really, really enjoyed the conversation, Daniel.
Thank you for the time. Everything about the way we work is changing very quickly, thanks to the advancements in applications, and of course, agents, automation, and what interfaces may look like in the future are all going to continue to change, and they're going to enable, and they're going to power businesses to be more efficient and, of course, to be more productive. It was a great conversation over the last hour.
We really did reflect across not just Power Platform and how they are thinking, how Microsoft is thinking about building its future, but really about how businesses should be thinking about developing their future, removing constraints, being able to look at problems in new ways, and then being able to apply software, and then being able to utilize resources in new ways that can deliver more value to your business and, of course, to the customers that you serve. And this is not going to be easy. It's going to take some time.
There's going to be some effort, but it is something that can be done today, and companies can start to extract value right now. And moving quickly is going to be more and more important. That's something I'm seeing as an analyst, and that was clearly something that Ryan had seen as well.
We talk a lot about that is the customers that are moving fast are going to be the customers that get the biggest results and, of course, are able to benefit the most from those efforts. And lastly, we still have to keep all of those considerations that have existed with enterprise applications, with software that runs our businesses, and that's going to be the governance, that's going to be the controls, that's going to be security. And that, of course, is going to be putting people in the right roles and enabling them to do the work.
All those things remain similar but, of course, with a new bend. We're going to upskill the talent. We're going to think about problems in new ways.
We're going to move more efficiently, and together, we're going to drive the future. Great conversation. Appreciate everybody spending the hour with me.
See you all soon. Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group. Each episode explores a variety of topics within cybersecurity and the technologies behind it.
com, the Security Boulevard YouTube channel, Techstrong TV, and all of your favorite podcast platforms. Before we jump into today's fun topic, let's meet the guests, starting with our good friend, Alan. Alan, it's good to see you again.
Tom, it's always great to see you, especially right after RSA. What a great gathering of the industry, and I'm looking forward to talking about the industry today, Tom. Absolutely.
My feet still hurt, so that's why I'm sitting down today. But joining us also is our good friend, Mitch Ashley. Mitch, as always, a pleasure.
I'm a little hoarse from RSA, actually. No, I'm fine. I'm good.
But I do need a little rest. What a week. It's RSA.
What can you say? Exactly. And of course, I'm Tom Hollingsworth.
I am related to all things security here at Tech Field Day. So let's jump into today's topic. But spoiler alert, we're not going to be talking about RSA, because the week before RSA, there was an even bigger conference, and that was GTC.
And you're probably thinking to yourself, but RSA is the biggest thing out there. I would say that maybe GTC has started becoming the destination for people to talk about a lot of other things in the industry. But as luck would have it, GTC was filled with a lot of discussion around security, and that's the topic for today's episode, because it looks like NVIDIA is building a security ecosystem inside of their world domination plans for AI.
And it's honestly not surprising given the amount of conversation we've had about AI over the last couple of years, that while a lot of press has been going to companies like Anthropic or OpenAI or Google for creating models and creating images of people with multiple fingers and things like that, the real dark horse in this for a while was NVIDIA because they were the, well, let's call it what it is, they were the arms dealer for all of those people, providing GPUs, providing networking infrastructure, providing all of the things necessary to generate AI everything. And now, Jensen Huang in his leather jacket, and yes, his leather jacket is a sentient being at this point. It has been imbued with the power of AI.
They are both- It's the Steve Jobs black shirt. Exactly. It is ...
turtleneck. It is. They are teaming up to create these new ecosystems.
And we saw a lot of announcements from companies that we work closely with, like CrowdStrike and HPE and Cisco and many more. So I want to let the two statesmen of the industry talk about this because we've seen this before, especially when cloud was brand new. There were a lot of companies that were racing out there to talk about how they were partnering with different cloud providers to offer these services, but it felt scattershot back then.
It really feels like everybody is coming to NVIDIA this time. Well, I'll kick off, Alan. First of all, I just give you the Steve Jobs reference.
It really has become the new Apple Steve Jobs conference, where everything else tends to stop, oxygen leaves, and the event horizon is at the edge of the GTC conference until that's over. " Now, that's actually true, but not in that sense. What's the big issue for getting AI into production?
He spent an hour and a half talking about software and applications before he really got into the hardware side of things. So, somebody gave him the memo about software eating the world. So he knows that they've got to have outcomes out of all this investment in equipment and data centers, et cetera.
So, one of the big ones is securing it, control planes, observability, all of those things. And guess what? All of those companies are trying to figure out, how do we play in this market, not just ourselves, but partner with the big companies like Nvidia.
So I think it makes a lot of sense that I think that it's happening, natural evolution. You compare it to RSAC, which is more of a kind of inward-looking conference. I don't know if I say that in criticism or not.
RSAC could be like GTC. It just doesn't have a Jensen Huang to kind of ramp them. Alan could do it, but he's busy these days.
Yeah. Look, I think RSAC still gets more people than GTC. Oh, yeah.
They definitely do. 5,000 people there this past week. But here's the thing, Mitch, I think you're onto something with what you said.
This has become the new Apple, black turtleneck, I got the world in my palm with this phone kind of thing. Right? I'm throwing a hammer into the glitches.
But you got to give Jensen and his leather jacket credit, because what they do well over there, they're a great learner of history. They've seen the Jobs script. They've seen the Apple script.
They've also, though, seen, and I firmly believe this, they've seen the cloud roll-out. Mm-hmm. Remember, right, Nvidia was the gamer and then the crypto chip.
So they're very familiar with those communities. And so they're being really smart. Jensen also knows that as big as a lead they have in GPUs, as we move to inference, they don't have that M word, that monopoly or that big a lead on the rest of the audience.
And he realizes that as much as we think Nvidia and we think chips, it's all about software. Mm-hmm. It's about owning the software stack for inference and AI use.
And that's what this year's GTC was about, right? Exactly what it was about. We got the stack.
The stack, and by the way, the stack is headed up by, or at the pinnacle, at the top of the stack is the agent that does all of these things. And we're going to own the agent all the way down that stack. But learning from the cloud industry roll-out, A, he can't go it alone.
As big as the $5 trillion he has in market cap is, he can't do it alone. And they did an amazing job in rolling out a full ecosystem, of which cyber is a good piece of it, as it should be. But let's be clear, Tom, you racked off some big names, right?
Mitch, you got it, too, right? Some big names. From cyber, the two biggest ones for me were the CrowdStrike, JFrog, which is now a DevSecOps or security company as well.
Fortinet, Cohesity, there were a number of folks that had direct announcements with them. And then, Cisco was there, and HPE was there, and the usual suspects. So you got to give them credit for assembling this ecosystem.
Not just cyber, but the whole package, right? This is what Apple did. When I launched that iPhone, how many apps are you going to have, Steve?
Tens of thousands. We have three now, but there will be tens of thousands. Tens of thousands, right?
And Mitch, remember our friend Andrew Greeley, who's over at Armis now. By the way, Armis had something at this GTC. Oh, they did?
Okay. " Right? He has an Australian accent, and he was a big iPhone.
Yeah. Australian dude. That's the key here, guys.
But let's dig in, if you don't mind, Tom and Mitch. Let's talk a little bit about, well, what are you going to do to secure this stuff? What exactly is CrowdStrike and JFrog and HPE and all these folks doing?
And I think that's important. It's coupled too with, because I want to get into that, but they made their own announcements. They announced Open Shell, which is an open-source environment to run your on-premise or in the cloud, wherever the GPUs are, to secure if you want to run OpenClang or run anything else, right?
It's this kind of, I want to say containerized, but it's this walled garden. The goal is it meets enough security requirements of enterprises to get them comfortable to put this into production. So you stack onto that, right?
Announcements with CrowdStrike, announcements with Cohesity, Fortinet. But like CrowdStrike especially, who has Fortune 500 wrapped up, they do, right? They're in every one of those companies.
So it's about not just lining up the technology. I think it's lining up who has the customers that they want to make sure their software is playing on Jensen's hardware. So- That's the strategy So what's a customer in this case?
Because I find it kind of fascinating that, like you said, we had a lot of announcements of partnerships from companies like CrowdStrike, JFrog, HPE, Fortinet. But how much bandwidth of that two hours of keynote, that wasn't just them talking about how Nvidia is going to make an eleventy trillion dollars, was related to OpenCLAW? Because they had quite a few announcements around OpenCLAW, creating architectures to run it, creating their own system to accelerate it into what I saw online as Super OpenCLAW.
And that to me is one of the most fascinating parts about this whole thing, is a lot of companies that are out there, in a way, it's when you get any kind of vendor-branded conference, there are a lot of companies that sign up because they want to be seen near the proximity of a successful company, right? Whether it's HPE Discover, whether it's Cisco Live, whether it's RSAC, whether it's Fortinet Accelerate or the Extreme User Conference, whatever it is. We want you to know that we work with these people that you came to see.
But with OpenCLAW, I don't think there was an OpenCLAW booth. I don't think that there was any kind of, like, we're going to invite the guy up on stage to talk about it. It was, oh, we see that you're using this, and there's a lot of chaos in the industry.
Did you know that we're going to work with it, too? So in a way, OpenCLAW brought Muhammad to the mountain. Like that's the thing, is why did Nvidia suddenly want to tell everybody-- Actually, it would've been bring the mountain to Muhammad in this case.
Why did Nvidia want to tell everybody- Because the- ... that they worked with OpenCLAW? This was the coronation of OpenCLAW as the de facto standard for your agent- Yeah ...
infrastructure. And this is something Mitch and I have dealt with for 25 years. This is classic open source, right?
Classic open source. OpenCLAW itself, I don't know if you've tried to play with it. We've got a few people here running it on Mac Minis.
Yeah. It's a b***h. No doubt about it.
You got- It's got a lot of claws. It's not just two. There's a lot.
It's unwieldy. You've got to be... You're going to be working in your CLI.
Typical open source kind of stuff. However, once it's up and running, and we'll leave security out of it for a second, just a microsecond. Once it's up and running, it's that eureka moment of, oh my God, I could build anything.
And so we've seen this, you saw it with Linux, what it did to Unix, right? It's probably a great example. You saw it with the, for as big as VMware was, it wasn't the default hypervisor for the cloud, was it?
For private cloud, but the public hyperscalers, they didn't use VMware, they used open source. KVM, Linux. Yeah.
Here come in Linux again. Same thing as Linux. Exactly.
So this is a classic. " The whole observability industry is built on OTel, on OpenTelemetry, under the cover, right? Jensen saw this and said, "We're going to build this stack, this agentic stack," and he called it a five-layer stack.
We're going to build it on this open source. And for people like me who still have a good place in their heart for open source, I all of a sudden now have a good feeling about Nvidia for building on open source and supporting open source. And a lot of the companies you mentioned, Tom, and Mitch and I mentioned, they also at least give lip service to supporting open source.
So again, brilliant move here. But open source is the agent that we're going to build on. And the good news is it's so raw and so insecure that there's so much to do in terms of these guardrails and the security we're going to need to lock it down, as well as non-security things.
Well, what does open source address, Alan? It addresses the number one concern of vendor lock-in. Yeah.
Now, if I'm running this on open source, albeit it may be the Neoclaw or Nemoclaw version of OpenClaw, which they've wrangled some of those claws into packaging it into a little easier environment to install and operate on top of their AI toolkit, which is that open shell, AIQ, and there was another component to it as well. But they're trying to build the environment to run that. So yeah.
And to your point, though, I want to really emphasize one more thing that you nailed, and that is, it was more than a coronation. 7 Richter scale event. Like, whoa, oh s**t, what happened?
Did stuff fall off the shelf, or do I need to go check my house, make sure it's okay? If you want a more recent example, it's the MCP of 2026. MCP caught fire And was a big thing, and it's this really tiny, little thing.
It's not a big thing, but it was the can opener to everyone who had a can that didn't own a can opener. It was just like, now everybody could get to access their agents, their models, get access to tools and data. That's what OpenClaw is.
And you wrote a nice piece. I appreciate you quoting me on the piece about there will be 1,000 recreations of, or innovations of OpenClaw. It will spawn generations of new things, and that's exactly what Jensen announced.
That's the hammer that hit the sabotage into the gears of the 1984 won't be like 1984. Right. Won't be a walled garden.
Mitch, but to MCP or not, that is the question. That's ano- Oh, that's another. A joint article.
You can check that out. com. Yeah.
But let's peel the onion back a few layers here, get into some details for our listeners. I want to talk specifically about JFrog for a second. So they announced something called the JFrog Agent Skills Registry, which is- Mm-hmm ...
designed to provide a secure trust layer for AI workflows in development. And that JFrog Agent Skills Registry actually integrates into the NVIDIA Open Shell Runtime, which NVIDIA announced at GTC. So it's an important part there.
They have an AIQ NVIDIA, certified NVIDIA AIQ blueprint, as well as automated security scanning now for that. And one other thing in regards to the MPC, they actually announced the first MPC registry, Mitch, where you can now download and check what MPC you have and what it's going on there. So JFrog was certainly very, very busy here.
Let's talk a little bit about CrowdStrike too, though. They announced a major partnership embedding Falcon, the Falcon platform, right, in directly into NVIDIA's Agent Toolkit as well. So, this Agent Toolkit is the Swiss Army knife of using, in this case, OpenClaw.
But any, there's going to be OpenClaw compatible agents built off the open source. Right? So Alan, let me talk about that real quick, because I think that that's a brilliant move by NVIDIA.
Oh, yeah. Because, well, but for the reason of it opens a new market for them, because one of the problems that we have to deal with a lot in the security space is authorization and risk management, right? How many times have we heard or seen something in the news about a company that did something and then it turns out, oh, well, you weren't actually supposed to do that.
Like, I mean, shadow AI, shadow IT, we've heard that for years. A lot of organizations, especially heavily regulated ones like finance or government or healthcare, they only buy off the approved vendor list. How many times have we heard you never got fired for buying company X, whoever that company is, IBM, Cisco, whoever.
By embedding Falcon in their toolkits, what they're basically saying to companies that are very on the Herman Cain, nobody jumps out of an airplane because it might crash kind of thing, risk factor of zero. If Falcon is embedded in here and you're already approved to use Falcon as your scanning tool or your prevention tool, well, you're already approved to use Falcon, why can't you just use our stuff because it works with Falcon? They're trying to open themselves up to those markets that would not have even given AI a second look or a first look in some cases because they don't feel that the security controls are mature enough.
By having something that is integrated tightly with an industry-recognized name and that kerfuffle a couple of years ago notwithstanding, CrowdStrike is trusted. " Because, I mean, for, what was it my friend Keith Townsend pointed out like on the small business line, it's only $155,000 for the entry level rack to do this. Yeah, no, but that's an enterprise solution, Tom.
NVIDIA does have... Mitch, what do they call their little box that looks like a Mac Mini? And they have- And they announced a new one.
I don't remember the name of it. The new one's like this massive thing. But yeah, it's- Oh, the new one, yeah, is 150 or 170 grand, and I'm not- No, this is like two grand or something like that.
Yeah, no, Keith Townsend has it. Oh, the Jetson. No, it was- The Jetson's the one he had, but I think you're right, they did announce a new one.
Yeah. And that's the Mac Mini. But you know what, Tom?
That's a whole another show we could get into is- ... how Apple, which we thought was an AI laggard, actually is making a very serious play to own the edge in terms of- Yep ... being the AI computer.
They already do own the edge, Alan. Right. Well, yeah.
I mean, that's the default choice is your Mac Mini- Yeah ... to run OpenClaw. That's what our folks are using here.
Yeah. Now, but, and this is again, you got to give to Jensen and that team. They've got everything from this little Mac Mini-looking box that's, I forget what they called it, but whatever.
This Mac Mini-looking box all the way up to this mid-range $170,000 behemoth, and then you get into their real stuff, right? But here's the thing. They said this stack, this stack with the security, with everything, is going to generate a trillion, $1 trillion in revenue in the next year or twoHow do you justify a $5 trillion company?
Well, when you got a trillion dollars in revenue coming out of this stack, that might justify a $10 trillion company. I'm not a stockbroker. Don't take my advice.
But this seems to be a real boon to NVIDIA's thing. Here's another play, though. Tom, you mentioned this as part of this agent toolkit.
And Mitch, I'll throw it out at you, too. Is the agent toolkit another name for a marketplace? Maybe we should get Alex Smith from Futurum in here on this.
Mm-hmm. Agent toolkit become a marketplace. Because it seems like everyone's putting their stuff into the agent toolkit, and they'll probably be competing things, right?
You could use this for that or that for that. So I'll let Mitch go first, because I bet you I know what he's going to say, and I bet mine is the opposite. I think it's the start of the marketplace, and it's the open source start.
But you think about where they're going to go next. It all depends on what the channel strategy is, and this is where Alex would kick my butt on it because he knows so much more about it. But do you go to NVIDIA to buy your CrowdStrike software?
Mm, I don't know. Maybe it comes out over time, but I think what I said before, the whole channel strategy of go to the vendors who already have the customers that will get you in, and you're not some startup company, you're NVIDIA. So it's a pretty easy move, I think, for that.
But to your point, it is the start of a huge ecosystem, and you were saying this before, Alan. Everybody already wants to be part of running on NVIDIA's stuff. They want to be part of NVIDIA's announcements.
So I think there's a natural sales channel, partner channel, ecosystem there, for sure. I just don't know enough about how to set one up. I actually wasn't that much different than Mitch's response.
So I don't think this is the marketplace. I think this is effectively GitHub for the AI integration. " Yeah, for us.
GitHub is easy for people who know the difference between a pull request and a push request. But your grandmother doesn't. The people who run boardrooms, by and large, don't.
That's who the marketplace is for. To make it to an app store level, it has to be so simple that it is one or two clicks to do the installation. What will kill their marketplace, and you guys brought this up, is how do the customers approach this?
Is it that I am already in the NVIDIA ecosystem, and I want to install this piece of software, à la AWS Marketplace, I'm already here, and I'm just going to pick and choose the parts that I want off of the shelf? Or am I looking for something very specific? And how much is NVIDIA charging me to be in that marketplace?
Because we know what the answer is. 30% is too much. 30% cut of everything you get is far too much.
That's what Apple gets. And we have seen massive amounts of pushback because it's not just 30% of the app cost, it's 30% of the subscription cost. It's 30% of any in-app purchases.
And in 2009, 2010, there was no other option because Apple created that market. Now, I think what NVIDIA is going to have to do is they're going to have to give back a lot of percentage points for people to want to list themselves in some kind of a marketplace, and it's going to have to be valuable enough to those providers, and they're going to have to see enough attach rate in order to want to list themselves there. Because if you start buying your software directly from NVIDIA, then that means that I don't need to open a storefront anywhere else, unless I'm selling to the 18 people who are still running Tensor Cores.
There's one thing that Jensen announced or said that I strongly disagreed with, and he made it sound like we've got it sewed up. We've figured out how to secure this for the enterprise because we have the AI toolkit. It has AIQ.
The third component was actually NeMo-CLA. Yeah, NeMo-CLA. And they have NeMo-Trime, the model.
And that's the typical response we've lived with for years, which is, well, let's talk about when it gets into production. That's where we'll secure it. Well, the world has changed.
We use AI to build AI. We use agents to build AI. So guess what?
They're just as vulnerable in the development, in the planning, in the product ideation, in the CICD process, all the way. The whole pipeline is now AI. That has to be secured.
It has to use the same kind of controls, guardrails, governance, all of that throughout the life cycle. It's why I created this concept of observability native. It's got seven pillars.
One of them is that, it's throughout the life cycle. And it also examines, you have to understand the agent's behavior about what it was trying to do, how it decided to do it, what it did, and what was the consequence. " So I'll give you the prompt to start to do it.
And we'll send out the link to be able to download that. I'll have a paper as well describing what it does. I did this to my own environment, dropped it in, and the answer back was, well, we do one, three, and five pretty well.
Got those covered. These other ones, not so much. What do we do for those?
Okay, great. Now, it also implemented an instrumented OTel, Alan, in the beginning, in the development environment. Oh my God, what a difference.
Those are the things we've talked about securing the supply chain. A huge step. So that's what Prompted me, no pun intended, to say, "Look, I'm going to give this away.
" And of course, they'll improve it. Very cool. It's very cool.
Guys, in all of the talk, and we've kind of danced on the head of this pin. Let's just re-emphasize. " Right?
And that seems to be their go-to-market. We're going to give it to you securely. They didn't talk about walled gardens a la Apple, though it may in fact be a walled garden.
We'll have to see how this plays out. And by grabbing the partners they did, they grabbed by the throat the security aspect or the security angle of using OpenClaw, which much like when cloud first came out, security was one of the biggest inhibitors to adoption. And we're hearing the same thing around OpenClaw, and NVIDIA is looking to own that.
" Well done. Ditto. Well, I agree that agentic is going to happen, and it needs to be secured.
Just like LLMs are going to happen and dominate, and they need to be secured. The problem that a company like NVIDIA faces is that even though they are the behemoth, the mega behemoth in this market, that we've seen some mega behemoths before. Ask Lit Bhutan how it feels to miss skating where the puck is going.
Because that's NVIDIA's problem now is can I pivot fast enough to go where the next advance in AI is? Because while the rapid development of using AI to build AI and coming up with these new paradigms and it's the race for AGI is very important, and we know how important it is to secure that, you cannot bet $5 trillion of company on making the wrong decision. Because the first mistake will not be a huge problem, but mistakes beget mistakes, and that's how Intel ended up where they are, which, if I'm not mistaken, doesn't NVIDIA own 5% of Intel right now?
That's the situation that you find yourself in. One day, you are making graphics cards for nerds that want to run Quake a little bit prettier, and the next thing you know, you are on the cusp of a massive revolution, and if you make the wrong decision and freeze or don't freeze, you can find yourself in a world of hurt. So I think NVIDIA needs to be seen as the dominant player in those markets, whether it's LLMs or agents or whatever comes next.
But they have to play speed versus certainty. I need to be fast to react to these things, but I need to make sure that it's going to be a thing if I'm going to pour millions of dollars of resources in there. Because remember, the other thing that you have to understand, this is a problem that we started hearing about a couple of years ago, you have a company full of multimillionaires doing this job for you.
Every one of the people that owns NVIDIA stock is a multimillionaire right now. " And that's one of the things that they have to be careful of is the potential for brain drain where someone's going to be, I'm going to spin out, I'm going to take the three people in my department that agree with me, and we've got funding cash that we can use to start a startup to fix this problem, maybe with the hope that we turn it into a business and maybe the hope that NVIDIA buys us later. Because obviously, they're too big to understand the real problem around here.
Agreed. You know what, though? They've bought themselves $5 trillion buys you a lot of things, Tom.
Buys you a lot of friends, too. Yeah, it buys you a lot of friends. You're the popular guy, big man on campus.
It does also buy you a little bit of breathing room, let's call it, that maybe the guy chasing open AI, the Avis of the AI world, if you will, who has to try harder, doesn't have. But look, and I wasn't there, right? I've spoken to Daniel Newman, who was there, and we had a chat about it.
From everything I see, there was no fumble here. No fumble here, right? This was damn near flawless, unless two-hour plus keynotes are not your thing.
It was Disneyland. There was something for everybody. You wanted robots.
You wanted one of the Disney characters. Even where the keynote was held. The keynote was held in the arena where the San Jose Sharks play.
This wasn't like your average sort of keynote stage. Conference center, yeah. It's like where rock stars play, where rock bands play kind of thing.
So, look, at least for right now, and as far as I could see, which is 12 months, maybe at best six months, they are the reigning past, present, and possibly future heavyweight champions of the world. It's theirs to lose, right? Get ready to rumble.
But security has a way of coming up and biting you in the butt too. Don't forget that. If you start seeing a lot of security things, especially even on the NVIDIA stackIt doesn't prove to be appreciably more secure than some of the other open source kind of methods out there.
Every plan is great until you get punched in the face, right? Until you get punched in the face for the first time, you never know how that knock might react, right? And considering who that quote came from, Mitch, we are always on the lookout for the Buster Douglass of the world.
So Mitch, what are some things that you're working on that people should check out? Well, with coming out of RSAC, it's a ton of follow-up that I have because people had so many announcements, but announcements aren't as important to me as much as it where it signals where people are going, and control planes, governance, agent behavior, agent accountability, and trust, AI trust is the big thing. " And I'm going to be launching a framework around agent control plane so you can kind of see where are the pieces, what is Jensen talking about, where does that fit into this?
When I'm talking to this vendor, how does that work? Give you kind of a reference architecture to talk about agents and agent control planes. Alan, what about you?
You know, Tom, no rest for the weary. I put in a few miles myself working at RSA, though I do have to admit I did go up to Napa Valley after RSA for a weekend and did some whining. So, drinking, not whining like Karen was.
A little bit of both. But anyway, I'm home for about two weeks keeping Techstrong perking, and then I'm heading to Prague, where I'll be there at SUSECON. I think, Mitchell, you're going to be- I will be there too.
Yes, I will be there I'm really looking forward. I think the whole digital sovereignty thing is going to blow up because this is in Europe. SUSE is a big proponent of it.
I'm really looking forward to how that plays out. It's going to be interesting, especially given world events and everything. So I'm looking forward to that, Tom.
But we're also, guys, we are eating our own dog food here at Techstrong in terms of adopting AI and agentics and everything else, and I am so damn excited by how fast I'd want us to move. And the team, Mitch knows this because Mitchell was our CTO for 12 years, 10 years, and he's still intimately involved in everything we do at Techstrong. And we are ready to run and run fast, so- You are Watch out.
You're becoming an AI native agentic company. We are an AI native tech media company. Go figure.
Yeah. So that's what's going on here, my friend. And I'll point out that we have just posted a lot of videos from RSAC, especially around data protection with companies like Veeam, Object First, and Commvault.
com or the Techfield Day YouTube channel to check that out. We'd love it if you'd leave us a like and maybe a comment because we love to hear those. " And of course, if you enjoy listening to Alan and I rant and rave about things and Mitch trying to figure out who to agree with, please subscribe on YouTube if you're not already, or in your favorite podcast application of choice so you don't miss any episodes when you're out riding your bike or mowing your yard.
We would love it if you would share this episode with others because that's what helps the show grow. A good recommendation from a friend is the best kind of podcast recommendation there is. com and the Futurum Group.
com, the Techstrong TV website. Or if you haven't already downloaded the Techstrong TV app, you should because I am watching your downloads. I can do that.
I'm a security guy. It's available on Apple TV, Roku, or pretty much any smart device. If you are still on social media, may God have mercy on your soul, but you can check us out over on X, Twitter, and LinkedIn.
Just look for Security Boulevard, that's Security B-L-V-D because vowels are for losers. And we have a lot more content out there for you. Thank you very much for tuning in and we'll check you out next week.