Techstrong TV Friday, April 10, 2026
On today’s Techstrong TV, Alan Shimel broadcasts live from RSAC with RSAC Innovation Sandbox winner Geordie AI’s Henry Comfort on how his startup went from buying laptops a year ago to taking the crown, and Anaconda CEO David DeSanto on the coming “SaaS Apocalypse” and why AI-native development is making traditional software obsolete. Mike Vizard reports from KubeCon Europe on why VMs aren’t going anywhere, with Broadcom’s take on running containers on proven infrastructure. Plus, Commvault on the shift from disaster recovery to cyber resilience, and Signal 65 from AI Infrastructure Field Day 4.
Transcript
Hey everyone. We're back here live on our day three coverage of RSAC on Broadcast Alley. I want to introduce you to this gentleman.
He's quite the star here this year at RSA. His name's Henry Comfort, and Henry is the CEO of Jordy. You never heard of Jordy?
Let me tell you about Jordy. Jordy was this year's winner of the Innovation Sandbox contest, which is probably the most prestigious startup contest in security and cyber. Yeah.
The roster of past winners, and past finalists even, have accounted for about $50 billion, more than $50 billion, in exits and- Yeah ... and liquidity events as we saw. Henry, first of all, congratulations- Thank you very much ...
to you and the whole Jordy team- Yeah ... because it's not just a one person. It's definitely not.
There's nearly 25 of us now. So, yeah, it's a team effort to get here. And I always say I've got the easy job, right?
I rock up, and I tell people about it, and everything along those lines. And then we have an amazing team of engineers and Benji, my co-founder, Hannah, my other co-founder, who have done so much to get the product where it is. So I get to have that moment on stage and claim a little bit of credit, but they're the clever ones.
Absolutely. Well, every good leader always says that, but we'll get into it. But Henry, before there was a Jordy, there was a Henry Comfort.
Yes. Give us a little bit of your journey. I'd love to hear it.
Yeah. My journey, I would say, is pretty non-traditional for someone in cyber. So, hey, we can weave a little bit here.
I was a COO of a professional football club in the UK. Really? I built a model that helped football clubs recruit managers.
It was like "Moneyball," but for football managers. " But he did take it, and I did that for a few years. And I was in Cambridge, that was where the football club is in the UK.
Mm-hmm. And I got to know, really well, the team at Darktrace. Okay.
Who have been a big success story in cyber and certainly in European tech. " No. He wasn't empowering me as much.
But eventually, I rose up. I led global operations at Darktrace. Did a lot as we scaled the business.
Had a lot of fun. And- Who was the CEO there? Was that- Poppy.
Poppy Gustafsson. Right. Okay.
Poppy's fantastic, and had a lot of wonderful years working there and getting to know cyber, getting to know people in the industry. And really went from there and just love building. Love building and building in a space that's just incredibly impactful, right?
The impact of cyber attacks and disruption is massive for society. Anyone watching this or anyone at a conference can recount stories of real life things. And I remember it during the COVID crisis in the UK, there were a bunch of hospitals getting hacked.
My wife works in one of them. And the impact that had on cardiac arrest outcomes was massive. Mm-hmm.
All from ransomware, right? And things of that nature. And I just saw the impact that cyber disruption had in society and just grew in love with the space.
And now we're building at Jordy. We're having a lot of fun helping people really get to grips with agents, the risk they bring, but also to unlock the benefits, right? And that's where we now are.
Love it. I love it. So I've started four or five companies myself, venture backed.
Yeah. Yeah. Yeah.
Amazing. This wasn't venture backed. Yeah.
Yeah. But this was an accident. Yeah.
An accident. A good one. Yeah.
Yeah. Well, I started writing and speaking after I left my last venture backed security company. Yeah.
And it grew into this. Yeah. But I know it's one thing you could be the COO, it's another thing, someone else asks you to run their business.
Yeah. To found a company- Yeah ... and as a CEO.
Yeah. It's not something one does lightly, right? Of course not.
The commitment, there has to be a passion. Yeah. " Yeah.
" Yeah. Some way it's not a little, some way it's really a big way better. Yeah.
But we're doing something. With Jordy, what was that passion? Because- Yeah ...
you didn't foresee AI five years ago, seven years ago, right? Yeah. What was kind of that moment- Yeah ...
where you just fell in love? Yeah. Because as an entrepreneur, we fall in love.
They're like our children, right? Yeah. When was that moment?
So I think there's two sides to this question, though, right? So there's the problem that you're going to solve, and also how you go about it day to day. I'm very passionate about the team that we build.
And for me, starting a company, when you say taking it lightly, you've got this opportunity, which I take very seriously, to have a significant impact on our team's lives. Absolutely. They come to work, they can either go and work somewhere where they don't feel empowered, they don't love going to work, or they can come hopefully to us, whereby they go, "This is amazing.
I feel like I'm growing. I feel like I'm learning. " And I sincerely mean that.
That's why my biggest motivation is thatIs for the people in the team. Putting that side with the tech, though, I'm going to counter something you said. Go ahead.
We saw the impact, say, at Darktrace, of autonomous AI a long time before maybe you saw it in other spaces, because Darktrace as a piece of technology was autonomously responding to cyber threats or whatever. When you started to think about the impact that AI could have in taking autonomous action in the rest of society and operations, I got incredibly excited about the possibilities of that. I thought about parts of organizations that I had led in the past, and where agents would've been incredibly helpful, both to the teams and to the business and whatnot.
But it was when I started talking to early adopters and CISOs, security teams in those organizations, I could just see this is going to be a huge problem. Let me tell you, at the time, most people thought I was nuts. They were like: "This is way too early.
Is this going to be a thing? Is this a hype cycle? " You know, that kind of thing.
People were doubt- There are people walking around here- Yeah ... who still think that, by the way. Yeah.
And there are, right? Now, I tell you what, they should ask our customers why that's not the case. Right.
But anyway, what I'd say is, we saw, for early adopters, there's two pathways that they found themselves in. I call them the "hell no" camp, and the "cart before the horse" camp. The "hell no" camp said, "There's no way that we can operationalize agents in our organization.
How are we going to know what they're doing? " No. Then you had the other camp, which they had brought agents into the business, and now they realized they couldn't see what they were doing, what risks they were creating.
" And then they would do a board audit, cyber insurance review, and it would go the wrong way. And we looked at the potential of the technology, which by the way, with coding agents in particular, you can't doubt the impact on the nature of work. Mm-hmm.
And it's coming for lots of other spaces. It's way beyond the hype now. So if you look at it as we did, we said there's going to be a middle path.
There's going to be a way in which we can unlock this innovation for society, the benefits that come with businesses, and this is a transformational change for industry. And we just felt, as a team, this was the best problem for us to try and play a role in solving in our lifetimes. If we were to put $100, $1,000, $1 million, this would be it.
And then we started working with teams who were really trying to unlock the benefits of agents but manage the risk, and it's just been wonderful building alongside them, enabling them to enable innovation, but also do so securely. And, it's a fascinating problem to help teams solve right now. Absolutely.
Agreed with you. All right. So, there's your passion.
Yeah. There's the technological. I've got a lot of it.
Yep. Yeah. You know what, I've been involved in venture-backed- Yeah ...
companies for about 30 years, and- Yeah ... back in the dot com days. Yeah, okay.
I learned, even back then, companies where the founders aren't passionate don't succeed. Yeah. So you need that.
Yeah. But you got the passion, we got the technology, we got the problem- Yeah ... right?
That we're looking to fix. All of that comes together to form Jordy. Yeah.
Jordy. How does that kind of manifest itself though? Yeah.
Like the go to market, getting the customers. Of course. I'm not even talking about the Sandbox thing yet.
Yeah. But, you and thousands of other people are starting companies every day. How did that all come together?
When did you see, in the VC world, they call it market fit. Yeah. But when did you see, hey, people need this.
Yeah. It's not a nice to have. Yeah.
It's a must have. They need this. Yeah.
I mean, look, I've got loads of stories on this now. So I think the first thing is people don't know what's out there in terms of their agentic footprint. Yeah.
And with Jordy, you're able to understand that very quickly across your endpoint, where developers are leveraging coding agents, in your code bases, where they're building agents to help your business, and also in cloud-hosted services and SaaS services where your business is leveraging agents that maybe they've bought or built in other people's platforms. And that's really hard today to get an understanding of. Like really hard.
So when customers all of a sudden go, "Hang on, across like two calls with you guys, I've been able to understand my agentic footprint and get visibility I couldn't out of any of my existing tooling. " Those are moments where I've gone, we're adding value. They now understand risk.
They can manage that risk as a result. And then, I mean, there's so much more to the product. I mean, we deal with everything from posture-based risk, behavioral risk, governance.
Our remediation engine is innovative. I think it's one of the key reasons why we won Sandbox is we have not said, "Okay, we've got existing architecture, we've got an existing view of the world. " And agents need context, and you can influence them, kind of like humans in many ways.
And we leverage context engineering to ultimately mitigate risk. And when I've seen our customers see that in action, I'm so proud of what the team have built and the difference we make to customers, because it's like a magic moment. Right.
Where like, how the hell have you just done that? Like there's no gateway. No gateway.
There's no firewall. This wasn't a binary switch that we just turned on. And I think for us, there have been multiple moments where people have gone, "You guys are building to actually solve our problem in the agentic era.
" And we're now seeing that in how quickly we're able to get value out of it from a product perspective, beyond just visibility. And, it's been amazing and we continue to evolve weekly, daily, right, for our customers right now. It's just been amazing working with them to help them secure and govern their agentic workforce as we go into this new era.
Love itLet's pivot a little bit. Of course. That's another startup word.
Let's pivot. Yeah. Let's talk about what the Sandbox experience was like.
Yeah. Amazing, right? Literally a year ago, we were buying laptops to start the company.
We were that early, right, a year ago. I remember coming to RSA last year. We'd just signed a term sheet with General Catalyst and Ten Eleven, and you come in here, and no one knows your company, right?
" And you're having those types of conversations. " And you go, "Oh, are we going to go for Sandbox? " Yeah.
It makes companies because it crowns companies, right? Right. And then we applied for it late last year, and when we found out, oh my gosh, with my co-founders- It was huge ...
it was that elation. And we're like, "We can't tell the team for a few weeks," under embargo. Okay.
And then when we told the team, the team were... Again, everyone's like, "Oh my God. " We already knew this in terms of the customer impact and the traction we were getting.
We're like, "We're part of something big here. " And so then you get on stage, and you get the opportunity to pitch in front of, I think it was 1,500 odd people. Yeah.
Some of the best security leaders have chosen your company as a finalist and then have chosen you to win it. It's hard to think of other moments, away from winning and delighting customers every day, that signal validation more than that. So it's a very, very proud moment.
I know. And my mom even messaged me at some point, and she said, "I'm crying," and I think that is great, right? She has no idea what our technology does.
No, of course. Literally none. I've lived my whole life like this.
Yeah, but it's a very proud moment. Uh-huh. And it was like that for all of the Geordi team, right?
And I'm so proud of the team because ultimately, this has come from their work, right? It's easy for me getting up on stage and pitching to some degree, but they're the ones who put the effort in. They're the ones who stay up late on a customer call and listen, and by the next day, have delivered something to solve the problem.
And it's just a great moment for us. I love it. Couple just last little things.
Yeah. Henry, website. Yeah.
ai. How do you spell Geordi? AI.
And that's obviously the on-ramp. Yeah. Once they get there, what should they do?
There's a little button. It says Book a Demo. Get on there.
You might even be with me on the demo. I love demoing. I'm there all the time.
And just take a look at our tech and tell us how you're dealing with agents, right? " Yeah. We're not here to waste people's time or to oversell on something we can't do.
Right. We've got tech that works. You can ask our customers.
But we've got tech that works. Come and see it. See it for yourself.
And before you know it, you'll probably have a view of your agentic footprint on the next two calls. " And very quickly, you realize you can't get it from those things, or it's going to take you months to even get a picture. With us, couple calls later, you understand your agentic footprint.
I love it. Congratulations. Thank you so much for having me.
I really appreciate it. Henry Comfort, CEO of Geordi, the Innovation Sandbox winner this year at RSA right here, man, on TechstrongTV. We're going to take a break.
We'll be back in a little bit. Hey, everybody. We're back in Amsterdam at the KubeCon + CloudNativeCon Europe event, and we're talking to my friend Weigu from Broadcom about what they're doing in the open source community and all the good things that are going on there.
Starting with, there's this new project that you guys have donated to the CNCF, Valero. What exactly is that, and where does it fit in the spectrum of things you guys are working on? Of course.
So Valero is a software that allows you to do backup, recovery, disaster recovery as well, and also do migration. So with this tool, it allows the enterprises to plan for their data and configuration to be consistent and to be able to recover it as well, right? And if you look at Valero, it's really placed in this enterprise space where we focus on operations.
And as we always do at VMware, operations for enterprise scale is very important. You look at all the other projects we contribute to, for example, ETCD, Cluster API, et cetera. So we bring our decades and decades of experience in running and managing private cloud and bring those operational experience into this new Kubernetes space for our customers as well.
Nice. Now, historically, VMware had kind of a Kubernetes approach where you could run it natively on the VMware Cloud Foundation. Mm-hmm.
And then there was Tanzu as well as kind of a project. Are those two still kind of the main Kubernetes engagement paths for you guys, or what's the relationship there? So that's a great question.
The only engagement in terms of VKS, that includes VKS runtime or Kubernetes runtime, as well as all the cloud services that you need to run Kubernetes, are all based on VCF, and in VCF, actually. It's part of the VCF software stack. Now, Tanzu, as a separate product division, and they have their own product portfolio, is going to focus more and more on this PaSS platform where they use the technologies from Cloud Foundry, et cetera, to focus on this developer experience.
But when all things come to Kubernetes, it's VCF. Gotcha. All right.
Yeah. Is there something right now that you perceive that is... If you have a wish list of things you wish the community would prioritize a little bit as it relates to Kubernetes from your perspective, what comes to mind?
Well, again, going back to our heritage, in terms of infrastructure and operations, right? So we will very much like the community to continue in that space to bring all this cloud experience to the customers. I'll give you one example.
If you think about, let's say, dynamic resource allocation, DRA. It's all about GPU resource allocation and everything, and surface that up to the Kubernetes clusters. And guess what?
We have been doing this for many years at the VM level already, right, in terms of presenting the GPUs as assignable hardware and if you look at Kubernetes constructs, the device group, the device class, and the resource claim, et cetera. We have very similar concepts in the VM space already. So it was so great to see the emergence of DRA since last year, and we think there's a great opportunity that we can marry that technology and use the constructs that we have in our stack and make the GPU and AI workloads more accessible to our customers.
Of course, at the show, AI workloads has been one of the main topics, and specifically AI inference. Yes. Are there things that organizations need to do to optimize those workloads for Kubernetes types environments and open source?
And it seems to me there's a lot of projects walking around here that are related to that. What are you guys looking at or thinking about? So we are taking two approaches, but they are very much related.
The goal is to meet customers where they are, right? So by that I mean, number one, in our VCF stack with VKS, we still provide a bunch of packages and services that developers and the platform engineers will need to build their applications, the workloads to run in Kubernetes. So they have that option if they just want to simply consume out of the box that customer experience.
On the other hand, we also, again, meeting customers where they are, we understand, and many of the enterprise customers also tell us that, "Hey, over the last few years, we have built up our own CI/CD pipeline," for example. We have our own tooling and everything. I don't want to deploy VCF and then retool everything, right?
So in that case, we are working with the broad ecosystem and a lot of the partners who are at the show as well. You probably saw the announcement earlier this week, in terms of partnership with Kong, et cetera. So we work with all these partners and the CNCF projects to validate how to make those same tooling and the platform work with VCF.
So we will not only provide, let's say, reference architectures or technical validation. In certain cases, we may even provide Git repo, for example, so that customers can sample those repo code and just basically deploy the same exact tooling that they have and make the workloads run in EKS naturally, right? So with both approaches, again, coming back, meeting the customers where they are, and make sure the best outcome for them based on what they prefer.
Is there more convergence now between the VMware world and the Kubernetes world? Because historically, I can remember when Kubernetes first came out, there was this general feeling that Kubernetes would compete head-to-head with VMware. But now, in hindsight, it looks like most of these Kubernetes clusters are running on virtual machines anyway, and maybe we're starting to see some convergence.
Yes, I think that's exactly what we see as well. Essentially, regardless of whether it's a modern workload that runs in containers or running in VMs, first of all, they all need infrastructure, right? Whether that's compute, storage, networking, and there are certain characteristics that developers would expect.
For example, performance, security, very important. You don't want your application to be the landing spot for security vulnerability or ransomware attack, right? And you definitely don't want your applications to go down.
So the reliability and all those aspects are very important. And vSphere has been at the center of the data centers, if you will, in the last more than two decades now. That's what we do best.
Now, there's also, when you run Kubernetes and containers, I think there's a trend, and many analysts are pointing out already. For example, IDC predicts by 2028, 85%-ish of the containers will continue running in VMs. And that's what the hyperscalers do as well, right?
So what that provides is really the level of resource isolation, security, and we like to say that we provide six layers of security, all the way from the hypervisors to the containers and the namespace, right? All that provided in VM, and resource consolidation and the utilization. Think of today, the hardware cost is out of control.
And vSphere, what we do at best is this resource utilization and consolidation that makes sure thatWe can save you tremendous amount of cost by running this architecture and that remains to be true. And more and more customers, I think I even see some solutions on the expo today that actually gets to what we have been doing for more than two decades. So that's definitely happening, and I think that will continue.
Now seems there's more nuance in the sense that the applications are becoming more distributed. Yes. And there's elements in the cloud, there's elements on-premise, and there's elements at the network edge.
So is that changing the way we think about this infrastructure conversation because the workloads need the... There's just a higher degree of interoperability required. Yes.
So in my view, two points, right? Number one, going back to meeting customers where they are, our infrastructure doesn't have to be in your own data center. So, our software stack can be deployed on the cloud, in the data center, or on the edge.
So that gives you that level of consistent infrastructure wherever you want to run your workloads. But secondly, I think it comes back to this VKS. It's a conformant Kubernetes distribution, right?
So what we do is, again, as I said, we may have some opinionated offerings or packages, services, that goes with the solution. Right. But by and large, it's open source, it's very conformant with Kubernetes.
So that allows the customers to move workloads to any Kubernetes conformance clusters if they choose to do so. Mm-hmm. And that's tremendous benefit to our customers, as you can see.
And there's the benefits, obviously, being conformant, that gives us agility or time to speed us to production for our customers. By that, I mean when a new Kubernetes release comes out, typically within two months, we will be able to validate and certify that our VKS cluster will be able to allow customers to consume the latest and greatest Kubernetes release, right? Mm-hmm.
That's on par with all the hyperscalers out there. That level of agility allows our customers to consume the latest and greatest features. But again, if the customers so choose, they can move those workloads to another conformant certified Kubernetes distribution as well.
So it's an open ecosystem out there. Right. I have yet to meet anybody who's standardized on one particular type of distribution- Exactly ...
of Kubernetes or much less the version number. Exactly. And I would also add, in addition to the agility and the speed, we also support multiple Kubernetes releases for our customers.
So architecturally, we allow customers to deploy multiple VKS clusters. It's not just one single cluster. So with this, here comes the benefit of isolation, security, et cetera, but also different teams may want to consume different features that's offered by different releases.
That level of flexibility is there. And on top of that, with 24 months enterprise support of all those releases, gives the customers a great level of confidence with us. Now, we live in a world where there's greater sensitivity about cost, but if I look at the architecture and as I understand what you guys are trying to do, is the total cost of your approach going to be ultimately less because more of the components are integrated?
No, I think ultimately what determines that is the value that customers get out of the solution, right? So not only from the compute storage networking perspective, what we put together in terms of cloud operations and cloud automation, it's very important and essential to our customers operating their private cloud, right? And listen, we didn't invent some new infrastructure or things in that nature for Kubernetes world.
We basically put a control plane on top of the same exact infrastructure, the same stack. This integration creates the value not only in that sense, but also, the single unified APIs for customers to run their and manage their, both their container workloads and VM workloads. That's tremendous value.
So I think over time, that value will make the solution more resonate with our customers. So does anybody at Broadcom keep track of how big the contributions are to the open source community? Because I think everybody thinks of a lot of other companies out there, but it's not clear to me that anybody knows what Broadcom's doing.
That's a great point. We don't talk about enough. We are starting to, right?
org website that tracks the contributions. If you look at the dashboard, VMware actually has been a top five contributor to CNCF over the last decade. Wow.
And there are a lot of projects that we have contributed to. In addition to the Valero we announced earlier this week, there were projects like Contour, there were projects like Harbor Registry. Of course, we contribute heavily to etcd, Cluster API, and all these different projects, right?
So a top five, and we should talk about more. And obviously, at this conference, we are starting to make a lot of more communication to our customers about where we are and the future that we intend to go in contribution to CNCF. Is there any particular thing you have at the top of your wish list for the open source community that you just wish as a group we would all focus on a little bit more?
That's a great question. AI is top of mind for everyone. Obviously, I saw some announcements about open sourcing some of the GPO drivers, things in that nature.
I think we can benefit from those as well, right? And then from the whole platform engineering landscape, if you look at it, there are a lot of things that's happening. org, right?
If you look at that reference architecture, what's interesting is, in addition to the developer side and obviously the CI/CD side, there are more planes that are being added to that reference architecture, including observability, security, and of course, infrastructure and the resources. So I think we play very well in those planes, in terms of security, observability. We have our own solutions, but again, going back to the open ecosystem point of view, we would welcome CNCF contributions and the projects that can benefit customers in those spaces, and we would love to integrate and validate some of those solutions, right?
Give customers the choice. So as we see more and more of those projects mature, we will try to give customers more guidance and, at some point, as integration is needed, we'll try to do that as well. All right.
" I mean, I still see a lot of things managed in isolation on my side, but what are you seeing? Yes. So at enterprise scale, cluster management, for example, is a big thing in terms of life cycle, right?
From deployment to update, upgrade, patching and all that. So at that scale, you need multi-cluster management and the multi-cluster life cycle management capabilities to go with it, to operationally to be excellent at it. So I think some of the customers, I should say, may see Kubernetes as a simple platform, which it's not.
It's very complex. So I think customers will realize, in addition to the broad ecosystem and all the projects they have to stitch together just to run Kubernetes, they will need to start thinking about the scale that Kubernetes needs to be run and the scale the Kubernetes clusters need to be managed, et cetera. And more and more of that will need enterprise level features and capabilities, not only coming from vendors, but also from the CNCF projects, right?
So I think customers will realize over time. All right. Folks, you heard it here.
Hey, no matter how complicated things get, at the end of the day, when it comes to IT infrastructure, there's a good rule. It's called keep it simple. Hey, Wingu, thanks for being on the show.
Thank you, Michael. All right. My pleasure.
And we'll be back in a minute. Hey, everyone. Welcome back here to our day three coverage of RSA Conference.
If you've been watching our feed, we just finished up Techstrong Gang, and it was a rip-roaring Techstrong Gang episode with some of my friends here at RSA. But speaking of friends at RSA, let me introduce you to my next guest. It's David DeSanto.
David is the CEO of Anaconda. We last spoke at, I guess, it was December. Yeah, it was at re:Invent.
Yeah, at re:Invent. But David reminded me of something. The first time I met David was about six years ago, which puts us squarely into COVID time, right?
It was right before the lockdown. That was the COVID. Yeah, that was COVID year.
And, at the time, David was the chief product officer at GitLab, and I said, "David, I love having you here. " And he said, "Alan, GitLab is a security company, right? We're about DevSecOps.
" Interestingly, I was walking on the street yesterday, David, I see a coffee- Yeah ... cart, CloudBees. Oh.
Who I haven't heard from also in a very long time. CloudBees giving out free coffee at the security conference. So there you go.
Yeah. But David, why does this have anything to do with Anaconda? Yeah, it's a great question.
So Anaconda historically is about secure Python packages for AI and data science. Uh-huh. And a lot of customers around the world, 95% of the Fortune 500- Yes ...
use that to build secure AI applications. And for Anaconda, a combination of my security background and the mission that we've set to help organizations out, we're going to be releasing some more security capabilities this year. Like a AI model security scanner and helping with guardrails within production environments.
And ultimately, Anaconda, as the company we are today, focused on AI native development, we're all about reproducibility and at scale, and that's also important with security. If you're training a model, you want to make sure it's operating as you expect. You deploy it, you want to know if there's drift, has there been manipulation of it, and so forth.
And so we're looking forward to helping move into that production side of our story, where we've traditionally only focused on the development side. I love itI love it. Now, but you threw some new terms at me there that I haven't associated with Anaconda previously.
Yes. But I know you guys also recently went through a, not a reorg, that's not the word I'm looking for, but you freshened up the messaging. Yeah.
Fine-tuned the mission and all of this. And who doesn't in today's world where things are moving so quickly? Talk to us about that a little bit.
Yeah. So when I started in October, I wanted to just talk to customers and understand why Anaconda from their point of view. And over the course of a couple of months, I started realizing Anaconda focuses on the story that has been our legacy around secure open source packages.
But customers were using us for other things. Not just traditional data science, but they're actually building AI applications using Anaconda. And so we then asked ourselves what is the future for Anaconda?
And we realized that base of our customers were now focused on AI native development. And for those not familiar with the term, there's two types of development you can do today. There's traditional software development, and then you have AI native.
Traditional software development, the application code is a thing you version and release, and the AI model is an artifact. Right. In AI native, that's been reversed.
So if you look at applications like Claude, OpenCode, even our Anaconda desktop that's coming out, the AI model is the thing that is important, and everything versions off of that, and the code is now the artifact. And I think it's just a sign of how fast things are moving. Well, but before AI, yeah, we thought things moved fast.
Correct. What you've got here, what you just described, is 180 degree, right? It is.
Yeah. If you would've told me this three years ago, I'd say you're putting the cart before the horse. Yeah.
But now that's the world we live in, the cart before the horse. It is. So I'm a huge fan of Lego.
Mm-hmm. I think we've probably talked about it in the past. But using like a Lego analogy, AI native development is you want to build the engine first, and think about it like if you're building a robot.
Then build the car around it or- Yeah. Or let's say you're building a robot. You want to get the engine configured, built, and you know it's working, and then you add the arms and legs and head.
If you did a different way, you'd be like shoving the engine in or having to rebuild stuff. Right. And that's why now that's becoming the trend.
I love it. And, as we were talking off camera, this was... Not to be an I told you so or a visionary or anything else you want to call me, but we saw this happening when we were getting ready.
Every year here on Monday we did the DevSecOps event. " It's this, I think the community, and not necessarily even the security community- Mm ... but the broader community, the developers community as well, the ops, the DevOps, they're coalescing around this notion of AI native dev.
Yeah. And because we're at RSA, we made it sort of securing AI native dev. Yeah.
And that was our theme. So I'm in violent agreement with you. I do think that is the way forward.
What's interesting is what we take from that legacy stack- Yeah ... from that legacy way of doing, and cloud native, for instance. Does cloud native go with this AI native dev?
Yeah. So actually, what I'll say is that I found interesting, and then I'll answer the question, is there's a new breed of cloud provider available. Yeah.
And like Nebius is an example. Yes. They are what they call an AI native data center.
Yeah. And getting to know them over the last several weeks, they are the opposite of a traditional cloud provider. And so what I think is going to happen, so here's like my prediction, and then maybe a year or so we can say we told you so.
I think cloud native is going to become the AI native. And the reason for that is when you look at what Anaconda does with helping people deploy models securely, we're putting it into a container that's hardened, and it gets deployed via cloud native practices like GitOps or standard Kubernetes configurations. And so when looking at it, I think what we're going to see is this continual shift.
Traditional software will start to shrink down, especially as more and more agents are able to do what they need to do. And then we're going to start to see this everyone's a builder, and everyone now has to worry about what they're doing. And to your point, you end up in now a new cloud native, like rebranded AI native, where it's just completely different than a traditional experience.
And I would say that the thing that's most exciting for me in all of that, whether it's my time at previous companies or just things I enjoy, it's really truly incredible to see the unlock. We updated the company's vision to be deliver AI innovation at the speed of imagination. I love it.
Because today, if you think about it, you can have an idea and two hours later you have a running app. You don't know the half of it. Two hours?
Yeah. I was giving some time there some padding. Yeah, you could have coffee in two hours.
We've been on a bit of a mission ourselves at Techstrong, adopting agentics and doing stuff. I saw a mistake on our homepage this morning, and I wrote to our marketing team and said, "Hey, this mistake's got to be here a long time. Why hasn't anyone caught it?
" Yeah. " Mm-hmm. No.
I went into Perplexity Computer. I fed it the old URL. I gave it some thoughts of what I want.
" I then sent the zip file to put into WordPress. Yeah. Fixed.
Yeah. New hero image, the right logos and names. That's the world we live in today.
Yeah. It's instant. You said something-- I have a lot of friends, David, who are serial entrepreneurs- Mm-hmm ...
who have been multi-time, but they started as developers. Yeah. Same with me.
Very similar to your thing. Yeah. When I talk-- And some of them haven't done real development in 20 years, right?
" And that's the world we're in right now, where- Yeah ... I could build anything. And it doesn't need dozens of engineers, it doesn't need a whole bunch of designers.
Yeah. You could take a skeleton team, three to five people, and God knows what you could build. Yeah.
So I'll tell you about a little fun side project. Go ahead. Because it fits into it.
So we have a really good partnership with Nvidia. Oh. We provide all the CUDA packages so people can build their applications on top of Nvidia.
Very cool. And so Nvidia launched a box called DGX Spark. Yes, the Spark.
Yeah. I'd love-- Could you get me one? I can't commit to getting you one.
Okay. What I- If you did, you'd be my friend forever. Oh, okay.
Well- Go ahead ... we'll have to work on that. I don't want to lose the friendship.
But- Oh ... what I decided to do is like, how fast can I get to being up and running? And Anaconda, we have a new desktop app coming out in May.
It's in alpha. We've- Very cool ... launched a couple of people.
But it can control the DGX Spark box. And so all I did was open up the new Anaconda desktop on my Mac, gave it the IP address of the DGX Spark, and then I could start to select models from the Anaconda platform to deploy there. And when I was done deploying, I decided, well, I want to do some vibe coding.
So I could use what was in the Anaconda desktop app. I decided to play with open code because it was the current popular AI- Yeah, the hot thing right now. And we're an OpenCore company.
We support open source. " Well, I had a fully working application three hours from when I opened the boxes. Yeah.
It's crazy. " Yeah. And it was this moment of like, it's- I could build- ...
very polished ... anything. Right?
It's very polished. I've not written code full-time in 15 years. " Right?
I think that's why they talk about the SaaS apocalypse. Yes. Right?
No doubt. If you're not an AI native company where you're helping build those sort of applications, that's why traditional software is dying. And so the way I look at it is, there are going to be two, maybe three types of applications in the future.
You'll have the traditional ones, and those are slowly shrinking. The last two years, we had AI wrapper- Yeah ... applications.
But now you've got to do AI native. Yeah. And I describe that middle one, the AI wrapper, as like, do you remember the Intel commercials that were like, Intel Inside?
Uh-huh. I look at those applications as, and now with AI. Right.
Because the application itself really hasn't changed. It's just bolted on. And all that is, is really an intermediary.
Yeah. Right? It's a missing link.
And they serve their purpose, right? We all- Well ... got to understand AI better and whatnot, but they can't be the future because they're still doing it the old way.
I tell you something. " Yeah. And he sent a laundry list of things he's using AI for.
I didn't write this on the corporate Slack because I didn't want to knock him in front of everyone. Yeah. But he's using the same applications he was before, but now those applications are empowered with AI.
They're the same applications, David. Yeah. They're not doing anything different.
That's not the AI use we're looking for. Go find- Correct ... some other droids.
Yeah. You know what I mean? Yeah.
And I'm going to wait till I talk to him privately to tell him that's not really AI use. I'm sorry. Yeah.
But I think you're dead on. Let's bring it back to Anaconda- Yeah ... now, though.
You gave up-- I don't want to get you in trouble, so let's just... May, which is just two months. Yeah.
So in May, it's- We've got Anaconda desktop. Yeah, the new desktop. So we currently have two desktop applications, two separate things.
It's all pulled together, plus all the power of our platform, which we shipped last year. And when we talked at re:Invent, we announced a second module, which is AI Catalyst, which is the curated open source models that we've security tested and performance tested and made available. That comes out in May.
Similarly, we're also doing another release of secure AI packages. We'll have 40,000 new wheels packages available to- Wow ... Anaconda customers.
We will- Also May? Also in May. Okay.
Also in May. And there's a couple other small things that will probably come out, too, but those are the two big things we're excited about. And then around the fall, we'll be bringing out some of the security capabilities I mentioned, the AI model security scanning.
We're looking at securing production AI in that AI native development world. Uh-huh. And then we're deepening our relationship with some of the cloud providers and with Nvidia, of course, and so there'll be some things around that as well.
To give people the sense of the reach of Anaconda, and I did not fully understand or appreciate this initially, and now that I've been with the company six months, we have 50 million users worldwide, two million contributors to our open source projects, and one of the most healthy open source communities I've ever seen. And I've done a lot of open source over my career. Yeah.
And so the power of all of them has really gotten Anaconda, we'll say, marketed across their companies, across teams. They've got user groupsBut the things that sometimes just don't jump out to people is Anaconda also provides an analytics engine for Microsoft Excel. And so if you're in Excel and you want to do scripting and do some functional calls, that's Anaconda.
Right? And so Anaconda is really, truly the foundation of modern AI, and our goal is to help everyone be able to achieve their goals. That imagination, speed of innovation.
Yeah. It's... No.
Yeah. It's innovation at the speed of- Speed of imagination ... yeah.
Which is, if you think about it, innovation is your imagination realized. Right? And so- And it's powerful.
Yeah. Really powerful. It's a very powerful statement.
Yeah. And as we- It's very good ... keep on pushing and expanding our platform, it'll only get more exciting for users all over the world.
You know what I always tell people, Dave, is you can tell how successful a company is by the passion that their leaders speak about it, and I hear the passion in your voice, and that's a great thing, man. Yeah. It is.
Yeah, no. Thank you. Yeah.
For everyone who's not super familiar with Anaconda, it checks all the boxes of all the things that have been important in my life, open source, broad community, security, and like I said, we're doing more of that. It's also... Look, you've heard of Python.
If you've heard of Python, you've probably done something with Anaconda, right? That- Almost definitely. Yeah.
Right. And I'm going to tell you, so I've been on my own little- Yeah ... island doing things.
And I'm not a Python, I'm not a coder, I'm a business. But this Vibe company is crazy, and I am amazed. Even when I call out agents, and you know- Yeah.
Yeah ... the great thing about these agents, they tell you what they're doing, and you- Yeah ... they're all just spinning a Python script.
Correct. And that is the underpinning of the whole damn thing. Yeah.
It's great. You didn't mention the website, though. Yeah.
I was going to give a couple plugs for things. Go ahead. com and you'll see everything we're doing and a lot of good customer use case stories.
Zimpler Bank just did one where they said they've reduced fraud by 90% leveraging- Really? Anaconda's AI platform. Right?
That's amazing. So those are there. Read those.
One last other one that's a favorite, and I think you'll love this one, too. McGill University researchers- Sure ... found a drug replacement for a drug that costs $10,000 a month, one pill, $10,000 a month, $10 alternative- Wow ...
leveraging Anaconda. That research, so- So that's where stuff gets real. Yeah.
And so I'll say check out the website, look at what we're doing, read the use cases. There's way more than those two. Please go check out our blog.
We've been posting what we're working on. Sometimes we're also posting some videos of it. The Anaconda desktop app will start showing up there as we get closer to the release, and it's just a great way to kind of stay on top of everything.
And of course, also follow us on social media. The DGX Spark stuff I actually posted on LinkedIn. Good.
Actually, you've reacted to it. I follow you, yeah. Yeah.
But you can really see what we're doing because as much as Anaconda is a 472 person company, our reach is so broad- Spoken like a real CEO there. Really broad. And to your point, this is a great way to end it, and the plugging components, everyone meets Anaconda in some sort of way in their life.
You mentioned- Right ... one way. If you've had to do a report in high school.
A friend's daughter just used Anaconda to finish her econ class in high school. Really? There's people who do their research.
Friends who've done their PhD, they used Anaconda to get that done. So it's very wide, very big. But we are truly making a big difference for enterprises and organizations around the world.
I love it, man. I love it. David, congratulations.
Thank you. Keep up the great work. And you are a security company, too.
Yes. We'll go with that. And what I'll say is we don't necessarily want to be the big security player, but we want you to be secure by default.
So- Well, because security needs to be built into everything, and that's something we've preached for a long time- Yeah ... anyway. Anyway, hey, man, always a pleasure seeing you.
Great catching up. Go check out Anaconda. David's like this, I know from his past experiences.
He's got so many things going on. Don't blink. We're going to take a break.
We're here live all day. We'll see you soon. You're watching Techstrong TV.
So we've done a couple of these, and we usually start it with a market trend. But because I have Bevill here, who is a recovering CISO, I thought we'd hear some words from not only his past experiences, but also what he's doing at Commvault, talking to security teams, CISOs alike, and even some of the AI folks. So we'll use that to kind of ground the conversation today, and then we'll talk about all the new recent things that we've recently released, and then we'll close the session with a hardcore demo on what is going on with threat detection and response.
Bevill? Awesome. Thanks, Michael.
So good morning, everybody, and really appreciate the opportunity. Again, my name is Chris Bevil. As you can tell, we went from the far northeast down to the south in Knoxville, Tennessee, which I want to make sure everybody knows.
It's the home of the real UT, so I have to make sure that everybody understands that for all my Texans out there. No. He talked about being a recovering CISO.
What does that mean, actually? It means that I got to go on July 4th to have a vacation with my family, and I didn't have to worry as much about the phone ringing. Did somebody click a link?
Did something happen? What are we doing? And had the opportunity to join Commvault, where I think I can make a bigger difference, and that is talking to my peers, talking to folks like you, and really talking across the board to our salespeople, our sales engineers, and really across the board of what is important today.
Because that is where we're at. And it's all becomeKind of a transitional to it's about trust. I know many of you in here, we got a compliance person in here, and trust is what we live every day.
So that's really what we're trying to talk about and really why I came to Commvault. As we get into it, some of the stuff that we really want to talk about is what's happening in the organizations today. What are we trying to do?
When we think about it as a whole, this has become a board-level problem. I used to go to the board, and I was giving them, "This is how we patch. This is what we did.
" And the reality is they didn't want to hear that. What they really want to hear is: what is the business objectives? Can we recover sooner, faster, safer, and with trust?
Can we really get there? There's a discussion of really whether we talk to about does the CISO report to the CIO? Does it report to the board?
Does it report to the CEO? And there's a number of things that you look at. When you look at this slide here, as far as 75% of CIOs self-report, they begin to start thinking about it.
But their overall thinking from a IT perspective is kind of more holistic and global. Then you get the CISO who self-reports a little bit, but their thinking is now having to transition more into that CIO role. They're having to start thinking about who owns it.
So when we begin to think about our organizations in a whole, it's everybody working together. It's a resilience operation that we start from the beginning and we have to test. If the one thing that I say the whole time I'm up here is testing is critical.
If we don't test and we don't know where we are and what we're going to do, we're going to be in a very, very difficult situation. And that leads us to this. So many times we have disaster recovery.
Hurricanes come in, and I can tell you there's an organization in Hawaii, they can do disaster recovery better than anybody else. I tried to trip them with every tabletop exercise known to man. I threw the kitchen sink at them.
They were good to go. But we transition into the cyber recovery. How are you going to recover cleanly?
How are you going to know that your data is trusted when things occur? And that's where we have to begin to start thinking about things. Disaster recovery today does not equal cyber recovery.
It doesn't equal cyber resilience. There's a lot of things that are occurring and have to be accounted for when we look at it. And that is why Commvault, we're beginning now to talk about this thing called resilience operations.
And that is where we begin to work as an entire organization. I can tell you a quick story. I was working with a major retailer.
I was asked to come in and talk to them about security as a CISO, and it was the VP and CIO of the IT infrastructure. " Guys, I about fell out of my chair. How is my CIO and my VP of infrastructure asking me if their organization should have an incident response plan?
Why are they not working with their cloud people, their cyber people, and all working together and coming together as one to really understand? And that's what this is all about. When you hear Commvault talking about Res Ops, this is a new methodology that we think about.
One, we all know we have to now assume compromise, but whose responsibility is it? Are we talking to each other? Are we having that conversation that is so critical that we understand where we're going to do and what we're going to do when that first 30 minutes hit?
You got to expect loss of trust. Look, the bottom line is this. If you look at healthcare and finance, as soon as you say ransomware or the word breach, trust is gone.
Trust is now what happened? What happened from an exfiltration perspective? What are we going to do?
How are we going to do it, and where are we going to go? So we have to expect that our reputation is going to be damaged. How are we going to minimize that?
And part of that is how do we get back to becoming a minimum viable company and get our lights on so we can function, but how do we do that in a methodology that we can trust the data? " But the reality is, where's the trust? I'll give you another story on that.
I was at a major conference two weeks ago, and an organization was presenting how they had partnered with another company where they had their pipe going to an air-gapped copy, and that air-gapped copy then, if something happened, they could spin up an IRE in about two hours. " Great idea. I love the fact that they were going to the air-gapped copy, then they were going to the IRE.
My problem was, how do they know that that was clean data? How did they know that what went through that pipe to that air-gapped copy was clean? What were they doing to try to address that?
And there were many conversations after that that I had with them to talk about where's the trust, where's the clean room, where's the different things that you're going to do? So you have to design with clean recovery. You've got to understand that's what this is all about.
And that goes to testing. Again, good tabletop testing, not just at the executive level, but at the technical level as well. Again, I talk about compliance.
We address that. I was a PCI QSA. I was a high trust assessor.
I've been in that world, and I've talked about it, and we have to have these people understand it. And then finally, automate where humans cannot scale. Gosh, wonder what that kind of ties to.
Maybe there's two letters, AI. I don't know if we've ever heard of that or not. When you start thinking about AI, what that does is that doesn't mean that that's going to replace humans.
What that means is we're going to use the tools to compete against those attackers, and we're going to be able to find those things that we're looking for more importantly. And if you think about it in healthcare, they use AI now to look at X-rays to determine what a doctor may not be able to see on that X-ray. That's what we're doing here.
But it starts with IT. It starts with security. It starts with the cloud people.
It really starts at the C-suite, and it starts at the board as well. It all has to work together, and that's what ResOps is all about. We're holistically working together to really get to where we're trying to go.
And that leads me to my next slide. When you look at it, why does it matter to leadership? Let's be realistic.
I could go through every one of these on this board up here, but the reality is this. When you're sitting there and the board is trying to say, "Can we recover our data? Can we recover it cleanly?
Can we trust it? " That's what it's all about. I'll leave you with one last story.
2021, I got my very own letter from the Conti Group. It was exciting, let me tell you. Nothing like getting your own letter sent to you from that perspective, where I was actually the incident commander supporting another organization.
From that organization, this had nothing to do with Commvault, but the story really resonates. If they had practiced and done the things that they were supposed to do, it would not have taken them 284 days to recover. Now, here's the kicker.
284 days to totally recover, and six months later, because they didn't know whether the data was clean or not, they got hit again. And this was a cash cow for a Major League Baseball organization's owner. That's what this is all about.
That's ResOps. That's what the board needs to know, and that's what Commvault is here to do today. Turn it back over to Michael and let him take you through cyber resilience.
Awesome. Thanks. So I'll use this as kind of a frame to discuss many of the elements that Chris had just covered.
And there's a lot of subtle nuance in there that I think is really important for us to uncover because a lot goes behind the sheets. So sure, we're going to talk about features and functions, but more importantly, we're going to talk about how all these pieces are interlaced together to make sure that we can provide high-fidelity signals or extremely clean recovery, or making sure that the data's secured in the back end. So it all starts with our cyber resilience layer at the very, very top, right?
That's our entire platform. Recently, we released Commvault Cloud Unity, where we span across SaaS, cloud, on-prem, and everything, so there's no exceptions. There's no compromise there that you need.
We then have this anomaly and threat detection layer. This is a complete substrate across the entire platform. So whether you're doing backups, active directory, files, user logins, deduplication, storage, there's anomalies across the entire system, and they're very mature.
I think it was probably a dozen, probably 10 to 12 years ago, we started down the machine learning path, and we've constantly refined our ability to do anomaly detection. And anomaly detection is really important for us to also provide scale and clean recovery. The second part to that is our data discovery, and we've been doing that for probably 15 years.
And that's on primary and secondary data. So it's not just what we back up. We can actually do it on primary data, and we do it across structured and unstructured data.
And then when we talk about some of the DSPM-like capabilities a little later, we'll talk about some of the new add-ons that we added to the product to make sure we have the entire sweep. But data discovery is really important because we need to know what's going on with the data. First, we got to find it, and then we got to know about it, and then we can apply the proper controls and policies that we do, either through our particular engine or what we'll talk about with Satori in just a bit.
As we get to the middle stack, all of these things work in concert to Bevil's point about how do we detect threats rapidly, how do we do it accurately, and then obviously, we want to provide confident recovery. So all of these things work together in unison to deliver that outcome, and David's going to show you that from beginning to end in the demo. So he'll walk you through that entire sweep, and we'll talk about the products and things that make that happen.
And as Bevil said, going into an organization, they don't even have an incident response plan. What's better than an incident response plan? Something that you can do over and over again that's not manual.
So we'll look at capabilities that allow us to have one-book automation that you can completely customize for your environment. We'll talk about a couple examples that we do with Active Directory or Clean Recovery, and you can see how we can use these motions over and over again to provide predictable outcomes. And because we can do it in the clean room, we can do it without impacting production.
So as we were talking about before with testing and testing and testing, how do we do that efficiently? How do we do it without low cost, and how do we do it consistently without impacting production? Those are the things that we're going to talk about.
And then obviously, the complete substrate of the platform is highly secured. We have CIS level one hardened OVAs. These things work in unison together, whether you're on-prem or in the cloud.
And then, we provide these capabilities within the product to make sure that your data is always immutable, indelible, and obviously resilient against all types of threats, whether they're DR or cyber. So here's a quick flow chart, and we'll step through this level, and then we'll talk about the thing in the very middle in detail. But from where we were just now to where we are, this is our makeup of how the products and outcomes fit together.
So on the left side, we always talk about readiness. This is all left-of-bang stuff. And we have these configurations and policies that we apply consistently across all your different workloads, all your different data silos.
So that's the bread and butter of how we do things consistently across. And then we use capabilities like our threat scanning product to allow us to detect threats and make sure that our backups can always be recovered cleanly, and we can flag these things accordingly. And then obviously, we have the ability to do recovery testing, and we use clean room to do that.
Then we get to this rapid and clean data detection area of the product, and this is where a lot of our new capabilities are. And we have a multitude of defense in-depth type capabilities that allow us to not only have anomalies, but also third-party signals that come in. And we take all of these things together to provide a high-fidelity viewpoint of what is going on in an environment, and then how do we react accordingly to it, whether that is account compromise, which we'll talk about in a little bit, clean recovery, how do I empower my SecOps team with signals that are generated out of Commvault?
So we have a lot of third-party integrations that are bi-directional. So any signals that we get within the product, we can send them into a SIEM and SOAR that exists outside of our product so that the security teams and the admins can actually have a single pane of truth that they can go through incident response with. So here's just a laundry list of some of the stuff that we do there.
And then some of the new stuff is embedded in that middle layer where we talk about AI, YARA rules, signatures, and hashes. So that's our really quick way that we can detect what's going on in a machine. We give the SecOps team the ability to go use YARA rules, or if they have custom rules that they want to add, you can now add that to the product.
And again, we'll talk about that in a little bit, and then Cunningham will show it to you in the demo. But all of these layers allow us to build that confidence. So when Bevil's talking about trust, how do we do that?
We constantly have these signals that pile onto each other. They're high fidelity. They're not noise.
And as we get them and we can paint that picture, we allow you to have that really high-fidelity understanding of what's happening so you can respond accordingly and accurately. And then, of course, we allow you to use those signals to cleanly recover. And that's not a manual process.
And we'll show you how we've automated all those bits and pieces. And that brings us to our next bit, which is really how do we do clean recovery? And our new capability, synthetic recovery, allows us to take all these rich signals and understanding of what's going on on a machine automatically and provide a composite of your latest restore point so that you can recover only clean data.
And again, I'll show you a visualization in just a second. But uniquely, you don't have to do stepped restores anymore. You don't have to hunt through all of your different backups to find the latest copy of that data.
We do it all automatically, and we provide you with statistics right up front to tell you how clean that latest point recovery is going to be. So that only becomes one click away, which is truly unique from our standpoint. Then we get to the optimal recovery side of the fence, and that's really where a combination of these tools allow us to validate what's going on, provide forensic capabilities, test the recoveries, and make sure that all of these things can happen together.
And what's important about that is with the capabilities that we have with something like Active Directory forest level recovery, we can go lift and shift that forest into a clean room. You can then restore your apps adjacent to it. So if you have dependent apps on Active Directory, you don't have to guess if you could actually recover that if something was really bad to happen.
You can simulate that entire thing into a clean room. So it's a really powerful way that we can reconstruct an environment and make sure that we can build trustworthy, confident recovery, even in a clean room, so that you can be very confident that you can recover that data. And then obviously, at some point, you're going to have to bring it back to production.
So again, by going through these testing workflows, you can have confidence that you can recover that data accordingly. Just curious about a couple of things. One of the things is when it comes to detecting the compromise in the backups, is it just signature-based?
Is it behavioral? Yeah. So if you look into the threat detection box under Threat Detection and Response, there's several engines that we use, and I think we're up to about 13 different anomalies that we could detect in addition to using YARA rules, hashes, signatures, and then we do have a deep scanning engine as part of the product, and that will detect polymorphic and even zero days.
So it does do that deep scan. It's a third-party engine that we use. So if you think about all these different layers, you have medium fidelity signals on anomalies and things, and those are your hints.
Then when we cover the threat scanning part, we'll talk about how we provide hyper threat hunting, which is our quick way to determine, okay, we have these signals. Can you give me a little more fidelity on, is this really a problem and a threat? And then we have the deeper scan, which really gives us the checkbox that, yes, there's something really going on.
And then we take all those signals, and we provide almost like a score of, yeah, we're very confident that these are threats, and we provide that capability. And then what we did add was YARA recently. So if you do have a security team that wants to use YARA rules, and we'll demo it for you, we provide that option also.
So we have all these different tactics, and one of the important things to your point is we provide these capabilities because we don't want to make any assumptions. Right. We have customers that are all over a broad spectrum.
Some have really mature security teams, some don't. Some have just Commvault admins that wear lots of hats. So by us having the flexibility in the platform and how all these tools are integrated together, we provide all of the different broad spectrum personas that we play to the ability to go do incident response and threat hunt and the things that they need to do to make sure that they can optimally clean.
And that's really one of our main principles about meeting customers where they are. And when we talk about some of the third-party stuff later in the presentation, that really applies to not only the organizations and the integrations that we do, but also the personas that actually use our product. So we look at it from both of those.
We really want to facilitate the flexibility of the platform and make no assumptions so that there's no compromisesSo again, the magic of synthetic recovery and why it's different than some of the other solutions in the market. Again, this all becomes automated, and we'll show you what it actually looks like in the product when David gets to the demo. But basically, what happens in the visualization that we have today, we have three backups.
Ransomware hit at backup two. We automatically flag that, and then we flag all the encrypted files. During backup three, that malware is still on the machine.
We still have some changes to some of the files that are there, and then other ones got encrypted. So with our synthetic recovery, what we do is we surgically flag the malware and then all the encrypted files, and then we restore automatically all of the clean versions of those files across the entire backup cycle. So that's a single button that's completely automated.
So as we're detecting anomalies, as we're doing fit scans on the machine, when the admin's like, "I got to go do a recovery," we do this entire process all automatically for them. In the past, what you would do is you would do a stepped restore, or you would go back to the one that was probably the least compromised. You don't need to do that anymore with our synthetic recovery.
So this minimizes data loss. This provides you with the cleanest possible recovery based on the latest data across the entire machine. I've got a question about that.
Does it go back to find a known good copy of the file, or does it clean the infection from the file before restoration? It will look at the last known good version of that file. Okay.
And so it's using file hashes or other secondary indicators to make sure that it's a good, clean copy? Yep, and it's based off of our index. So we're not physically and surgically removing anything from our back end because, again, it's immutable, it's indelible.
So because we have an indexing layer that exists here, we can do all of that surgery in there, and then when we need to go do the recovery, it will find the last known good version of that file. That's correct. Awesome.
So cool. Hopefully, this lands. And like I said, it's different than the other solutions that are in the market that are either moving back in time completely and then trying to do some post-surgery, or other methodologies to just go back to the last cleanest version.
We avoid all of that, and we really minimize data loss with this technology, and I think we have patents for it, too, so it's very cool. All right, so I talked a little bit about some of the changes that we made to threat hunting, and what we've done is divided it into almost two phases. And this is more of a logical division, not a physical division.
And Threat Scan has evolved over time to make sure that we can provide that really high-fidelity set of signals and a wide variety of signals, because threats come in all flavors and shapes, and we never know how these are going to evolve. So the hyper threat hunting is really your first line defense that you're going to run consistently and constantly. It's going to give you pretty good indications that there's something going on on the machine.
And again, that's using hashes, that's using YARA, that's using signatures. We could look at all of these signals and use them to make sure that either the data's clean or we're finding some signals that there's a compromise. And then we have the deep one, which is what I was talking about before, which really allows us to do file-level analytics on these files.
And it's deep, and it will tell us if there's a compromise, if there's encryption, if there's polymorphic threats, if there's zero-days that kind of look like other threats that are in the market that maybe there's no signatures for. This is our tool to do that. And we've had several customers call us up that their EDR didn't pick it up, but we picked it up in the backup with our deep threat scanning.
So we've seen many proof cases out in the wild with our customer base that there was some infection, and before their EDR or XDR platforms even picked it up, we were able to find it in the backup. And because we're using these methodologies consistently across the board, we're able to almost augment. We're not going to replace those tools.
They're still very necessary. But when it comes to backup and clean recovery, these are very important. And what's good about these tools working in unison with recovery is that all of these signals can be used both to drive clean recovery and also to provide deep information about what's going on in the environment to SOC analysts and other people.
So, us taking these risk signals and putting them into other systems, we're finding really provides that ground truth for people to really go through incident response beyond just what we're going to do from a backup perspective, because the world is much bigger than just clean recovery, but it's a absolute critical portion of how we play into this particular space. I have a question. Does that integrate with any other threat detection solutions?
So can that-- Is there a way to point in time something else detects a threat to trigger additional scanning or any additional- Yes, absolutely. So I wish I had the slide, actually. Maybe if we have some time, I'll dig it up.
We have a plethora of third parties' integrations that are bidirectional. So we can-- The demo video has CrowdStrike, right? So if we're getting CrowdStrike signals into Commvault through our bidirectional communication, that can absolutely orchestrate these types of deeper scans.
It could orchestrate a recovery. And for a lot of the SIEM platforms, we have embedded recovery runbooks so that if you need to act fast, you could actually do it through that. So we provide those different methodologies, but absolutely.
Third-party signals have their own characteristics within our product, and you can run all of this different type of automation, clean room, forensic recovery, synthetic recovery based off those signals. So signals are super important for us, and we look at incident response as a team sport. Cyber is a team sport, and we can't do it alone, and we shouldn't be doing it alone.
So, I hope we have time so that I can flash the slide, but we really have a lot of deep integrations... with many, many different platforms. And sharing those signals, again, really provides that ground truth for both traditional Commvault folks and the security team to really act when there's an incident.
Great question. Okay, so that's all the threat scanning stuff. We'll talk about identity because identity's been the hot topic for the last couple of months.
I think all of our traditional folks in our space have been talking about identity. We all see the big bosses that talk about identity resilience. And when we think about identity resilience, this is the flowchart of all the different things that we're doing.
And what's important about this is you'll see lots of similarities between what we just talked about, from responding to incidents and identifying threats and identifying these things, and how it's going to work in concert with clean recovery. Right? So we look at identity as just another vector of things that we need to understand so that we can provide next generation recovery methodologies, and then ultimately clean recovery and making sure that it's not as friction full as we all know identity could be.
Because recovering an active directory forest requires a PhD, and it's like 200 steps or something. So, we'll talk about how we resolve some of that. What's important is probably our most recent announcement, which is now we support Okta.
So, Okta came out of nowhere based on how long Active Directory and even Entra ID have been in market. And we had a significant amount of signal that people have been resorting to Okta for identity purposes. So we wanted to extend that capability.
And hopefully it's clear about when we talk about the product, doing things in a very consistent way is super important, because again, we make no assumptions on who's going to be using the product. So Okta is going to function just like our Active Directory or Entra backups. It's going to function just like our virtual machine or database backups.
Right? The flows are very, very similar, and of course, there's going to be some subtle nuance. But at the end of the day, it becomes a very familiar flow for people to respond to.
And then even the signals that get generated from our identity resilience pieces of our product being sent into SIEM and SOAR will, again, look familiar so that you don't have all of this custom, like, how do I respond based on these signals that may not look like the other signals that we're getting out of the platform? So very purposefully designed so that it looks like everything else that we built, so that as people need to respond to incidents or even just run regular backups or recoveries, the flows are very consistent. So what we found with Okta, admin error, some type of mistake, just like Active Directory or Entra, maybe not to the extreme, but recovering is really hard.
It's not as surgical. And then in identity systems that are very complex, where you have a multitude of these products, we found that administrators have a really hard time with point solutions trying to figure out how recovery is going to happen across these things. And that's not just identity.
That also applies to everything else that's happening in an environment. So again, that consistency that we build in the platform is super important, and we want to make sure that as people are onboarding these new pieces of the products, whether they're identity or AI workloads, we want to have that familiar look and feel, whether it's going to be the admin or it's going to be someone reading signals that we get out of the product. So we built immutable protection for Okta.
We're providing point-in-time recovery for Okta, and then it happens all under the same umbrella under Commvault Cloud Unity. So baking that consistency in. And again, this is not just about us providing a brand new workload, right?
This is another area of the product that allows us to generate really high fidelity signals that are happening inside the identity space, and I'll talk about that in just a second. Quick question. Sure.
It's Shalik again. So speaking about workloads and adding all the different things you can add, going back to the deep inspection. So at scale, how long is it taking to run a deep scan?
Deep scan, can you answer that? The time it takes for a deep scan. Yes.
Dave here. So deep scanning, it would depend on how much data you're scanning, obviously, and there's filters we have in. But you can look at, I think some of the numbers we were looking at was, in some of the simulations was 200 VMs in about 10 hours for a deep level scan.
However, Mike touched on the hyper threat hunting capability where we can do an index only hash lookup, and that's super quick. We can look up millions and millions of files and hash, check them against known threat hashes in a very quick amount of time. So that's where the layers to the approach come in.
It's like the quick approach is good for that initial do you have a threat? And then the deep scan is when you need that extra level of assurance. And then, so are you able to prioritize workloads by chance, or?
Yeah. So you do. It's a plan based configuration, so you can definitely prioritize workloads or you can...
We actually, generally to make it easier, we recommend just putting all the workloads in one plan because it's automatic the way we scan things. It's just a background incremental scan. So just for the protection of the data, we just make it easy to onboard into one plan.
But you can certainly stagger it. And then we have our standard blackout windows and things like that to prioritize when you want scanning operations to run. Yeah.
Cool. Thank you. Yeah, I look at it as the quick scan is almost like your litmus testAnd then the platform itself, he was talking about plans.
They do support tagging, both Commvault-based tagging and cloud-based tagging. So if you do have a really sophisticated tag and taxonomy, we could use that as another indicator on how we prioritize and scale things so that they can happen at the rate in which you need them to happen, like tier zero apps or your AI apps or whatever. So, we do have all of that kind of minutia that sits in the platform that we commonly don't talk about.
But when you think about building a highly effective and efficient system, all those capabilities do exist as part of the platform. And we do encourage folks that do have a tag and taxonomy to just marry that into Commvault so that it provides very good predictability on how the platform is going to respond, especially when we're doing auto-scaling and scaling of resources to do things like scanning. I do have a quick question on the Okta integrations.
So obviously this is the identity engine side, so your identities. Does it also support recovery of the customer identity that they bought when they bought Auth0? I do not know.
We will need to take that question, but I'll get you an answer on that. That's a great question. Cool.
So that's Okta. And, as we've been talking about that this is a team sport, we made an investment in CloudSEK because we really believed in their technology. And there's a lot of different pieces that are part of CloudSEK, so this is just one example.
But when CloudSEK detects that a external identity has been compromised, again, talking about how we collect rich signals and action on them, we take those signals from CloudSEK. We're able to identify the impact of those identities, and then we can action on them directly in the product and start to kick off workflows that can force MFA. You could reset the credentials, you could revoke the credentials, you can kill the tokens.
It provides us a very high fidelity signal, and it does dark web scanning and the traditional methods of, hey, this credential may have been compromised. And that allows us to action on that in almost real time. Right?
So we get the signal in, that's a really high fidelity, high severity signal. And if that credential's being used in the product or we see it being used, in other areas, we can then action on them. And for those that are here, feel free to look at any of these things that we're talking about today, with the exception of the last thing that I'll talk about with Microsoft.
All these things are available in the booth as demos. So if you want to actually see these things operating in the product, including the CloudSEK piece, I absolutely encourage anyone who's at RSAC, this week to certainly check those out. Because it's one thing for me to stand up here and say it, it's another that we can prove that these things all happen as I'm describing them.
So, please check me. We're really proud of a lot of these innovations and thinking about new ways that we can provide signals and incident response so that we can minimize blast radius and ultimately cleanly recover, and understand how threats are evolving. So, certainly check them out.
So after identification, we can do those particular things. And again, us understanding through backups, understanding the identity, being entrenched in Entra and Okta and AD, and looking at the applications that we support, it almost allows us to build a timeline attack chain, right? So we can put a bunch of pieces together, again, through what we know in Commvault, and we can send those signals out so that we can almost provide a mock report of, hey, we know that these signals are here.
This account compromise was here. This is what it has access to. This is where it was being used in Okta or whatever, through understanding through the different backups, and we allow you to roll back those changes.
So, if an account was compromised, there was lateral movement, they were added to the domain admins group, we'll see how those bits and pieces unfolded by looking at that account and the backups that we have across those identity servers and provide the ability to roll them back. So no more having to do a full recovery of these objects. We can surgically do that.
So again, these themes of looking at how we take signals and do surgery upon things so that you could do nice clean recovery without having to bring everything back, you can see how all of these things are kind of working together. So, we use CloudSEK signals for that. So again, we'll pull signals from any third party.
In this particular case in CloudSEK has a really good way to detect these things, and this is what we're bringing in so that we can provide those responses. And then just like every other signal that we get, we can go send that to a SIEM and SOAR, and if the SEC team needs to do something or we need to bring it into the clean room and understand what's going on, we can have all those as options too. Similar to the question I asked earlier about signal sharing, do you listen for if somebody's deployed ITDR solutions like honey accounts and honey tokens for those getting touched?
Yeah. And use and trigger any of this through that? Yeah.
So we recommend that those configurations are purposefully built so that we can get those signals, and then obviously action against them. So, our recommendation is always understand that we're not going to randomly discover it, but we do want to have that configuration so it's like, hey, we know that this thing is happening or may happen, and then we can action on it appropriately. Awesome.
And then as I said, it's not just about we're protecting Okta now. We look at all of these bits and pieces as ways that we can identify what is going on in these systems, so that if there is account compromise,If there's back doors being built, if there's other things that are going on that are anomalous, we can detect them, understand them, and then provide quick rollback capabilities so that we can do the surgery and do all of the heavy lift on our end and not have to burden admins with staging it somewhere else, extracting only the changes, and then pushing it back in, which is what we've seen historically. So, these things are much bigger than just backup.
This is all about really understanding what's happening in these systems. And in this particular case, we're talking about identity, but these are principles that we're building across the infrastructure and our platform to make sure that whether it's a database, identity, files, VMs, that we can provide a very consistent path to recover from traditional DR scenarios or cyber, or any of the other threats as they evolve, especially with AI looming behind the scenes. Cool.
20 minutes? Okay. I think we're making some good progress.
So another investment of ours, but this one was an acquisition. A couple of months ago, we bought Satori Cyber. And Satori Cyber was a awesome piece of technology that we added to the platform, and there's bits of that thing already baked into the core platform of Combo Cloud Unity.
So that was a very quick acquisition to be merged into the main product. And what that provided us was the ability to augment our risk analysis product, which is what we talked about earlier, which allows us to do deep data discovery and classification and add all the new workloads that it does data discovery and classification on. These are the Snowflakes, these are the Amazon RDS databases, structured data.
So we take what we had with unstructured and structured data, we added the structured data from Satori, and now we have an AI-heavy product that we can understand where the data is and what's going on with that data so that if we need to provide data risk analysis, if we need to provide just even visibility of things, it allows us to have a much wider sweep of what's going on, especially as these applications are starting to be used by AI, and that's what we're seeing as the hotspot. So this filled a really important gap in the risk analysis product, so that we could provide that across the scenes. And again, this allows us to do just deep understanding of where there's PII, passwords, and secrets.
And look, these things leak in. They just happen. And although we have a policy that we could apply across all of the different applications, that provides us, again, this consistency across the platform that you understand we're looking for these particular things.
It doesn't matter what workload it is, it doesn't matter what database it is, it doesn't matter if it's Databricks or Snowflake or Amazon or an old school Oracle database. We do it consistently across the board. So we're finding a lot of customers are starting to, especially with RAG workflow pipelines, they want to better understand what is going on and what's going into these systems so that they can remove any PII or sensitive data, so that they don't get inadvertently surfaced.
And there's lots of other controls that we've seen out in the market and anyone who walked the floor in the last day or so can see there's a huge amount of startups that are trying to solve these particular problems. But again, we're doing this in a very unified way with our platform and with all the support of the databases that we've traditionally done. So you get the best of both worlds that it's not only AI focused from our end, it's also traditionally focused.
And as we think about the wide breadth of customers that we have, that allows it to be really full service for them. So if there's any consolidation with all these point solutions, our platform becomes pretty key for them to do that consolidation with a very robust platform. And there's all these awesome charts and things that you can see.
And like I said, if you go downstairs to our booth, you can certainly see how we put all of these threat signals together so that you really have a wide understanding of what's going on inside of your infrastructure, whether it's structured or unstructured data, primary or secondary data, to really have good data-driven decisions on what's going on from a risk profile standpoint with your data, especially if you're doing stuff like RAG. A quick question. Sure.
Good morning. Sky Fugate. So with getting those data insights, how are you gathering that?
Is that based off of the data that I'm already protecting and you're just pulling those insights out of that? Or is this something else that I have to go put as an overlay across the rest of my environment? Yep.
So we provide optionality, just like everything else. You can use a process that will sweep it on the live data. So if you don't want to protect it, say you have a massive database that you just don't want to protect it and do this on, we can do it on your live data.
And then the alternative is, if you do want to do it on your backup, we can facilitate that too. So we provide that optionality and, as we've seen, again, it's a mature product. We've seen over the years that customers are pretty split.
Some like to do it on primary data, so they're not doing massive data movements. Others are like, "I don't want you to touch production. If you could do it off of the backup as a secondary data use case," we provide that facility to do that too.
And does this also give me the ability, if I wanted to see... Let's say it's PII. Can I see that there was still this record in all of these backups, and then this is when that rolled off?
Yes, absolutely. So, the product not only is a detection capability, but it also allows you to remediate it. And we could also do redaction as part of that.
So if we do discover some data that we find some PII in it, and you still want to use that for RAG or whatever your data use cases are, we could redact just that sensitive data and then serve it into these systems. And there's a whole another thing that we're not going to talk about today. It is downstairs, though.
And that's how we serve data up into AI applications. We can do all the data discovery and redaction, and then provide the redacted data into these systems so that you don't have to worry about those things. If you want to use the rest of the data that's around it and just obfuscate the redacted data.
So we do provide all those capabilities, too. Thank you. Awesome.
And then that gets us to the final part. So now we've done all this deep data discovery and classification, and now it's like we have to do something with that data. So Satori also brings to us data access governance.
And I'll give you an example where I think it's a really strong case, especially with the AI as the frame. What it does allow us to do is, the Satori data access governance capability allows it to sit in an AI workflow, both in the beginning and at the end of the workflow. And why that's important is you don't want PII going into the LLM, and you don't want the data to be returned out of the LLM.
So Satori can sit on both sides of that fence. Not only will it block the PII from escaping, it also provides a signal for us to then push back into the thing we just talked about with the DSPM-like capabilities so that we can refine the policies on how that data got in there to begin with. So again, same type of theme.
How do we start generating high fidelity signals to action on and improve your security posture, and then ultimately drive to clean recovery? These things all start to work in unison together. So, these capabilities allow us to generate really high fidelity signals, and then we push it back into these policies.
Why these policies live in Commvault? Because we can apply them to across all of your workloads consistently. So we get questions all the time, "Hey, I can go do this through Unity Catalog.
I can go do this in Snowflake. " Because I could apply that policy to all of these different workloads that we support instead of just Databricks. Because we all know that not all of your data that you're using for all these things live in Databricks, right?
It's just the reality of how people are building applications today. So the big advantage for us is really we could apply that consistently across the board, and then as we start to take in these signals, we could then refine the policies and make sure, and we can clean these things up so that they don't continue moving forward. So it's a self-reinforcing loop on how we prevent data leakage and things, especially when we start talking about AI and GenAI.
But just quickly, is that a real-time redaction? So is that- Yes ... basically in real time while it's being pulled in through RAG or whatever it leans into?
Yeah. So you send the query, the DAG will pick it up. It will immediately redact that data that you set the policy for, and then it'll go hit the LLM.
So it doesn't require time to have- Nope ... scanned and identified that previously as- No ... PII or something sensitive?
No. And that's why that use case is really important because when that generates the signal that someone actually tried to put PII in it, it's like, how do I prevent that from happening moving forward? Does it also integrate with data classification?
So could we say instead of just looking purely at the content of what's in the file or in the data, can it be data that's classified, restricted, or something like that? Absolutely. So that's why the deep data discovery and classification is part one.
It doesn't have to just be sensitive data. You can say, "Hey, these are always going to be token files," or they're YAMLS or something where they're high risk all the time. " I guess more specifically, does it tie into data classification policies that might already exist?
com or something like that with their data classifications, does it tie into that? Yes, with exceptions. Not everything, but I know we do it with Fabric, Microsoft Fabric.
Cool. Okay. Very last thing.
Super awesome. So I mentioned before, we have lots of rich partners for how we go about incident response because, again, it's a team sport. Cyber's a team sport.
And this is our latest integration that we extended. So we used the Microsoft Sentinel part one, using some older technology on their end. We had an integration that was bidirectional.
We had recovery runbooks. That was all good. Microsoft came to us as one of our favorite partners, and they said, "Hey, we're making updates to Sentinel.
It's going to have a data lake backend. " We reconstructed the integration, and then we added all the ability to have a Copilot run on top of it, Security Copilot specifically. So that allows us, again, to break down these silos of, hey, we're generating alerts and things in our platform.
We're going to send them over into Sentinel Data Lake, and then we want to make sure that we use all the tools at our disposal that now are bolted onto Sentinel Data Lake so we can remove all of that churn from all of these different signals that are coming from all these places. We can send our high fidelity signals into this, and then you can carry on with incident response. And again, these threat signals can be third party.
They could be from risk analysis. They could be from Satori. They could be from Threat Scan.
They could just be from the platform's anomalies. So, this allows us to have really high fidelity data to go into Sentinel Data Lake and then provide that recovery layer, again, through a runbook that someone sitting in Sentinel can go, "Yep, there's a problem here. I need to kick off a forensic recovery.
I need to kick off a synthetic recovery. " We provide those capabilities for them through the runbook. So again, bridging that gap and allowing everyone to move in unison.
So, really cool. And this is one of the many announcements we're going to make with Microsoft this year. There's a lot of cool stuff coming and stay tuned because lots of exciting stuff coming with Microsoft specifically.
Okay. Me again. My name is Dave Cunningham, the product manager team at Commvault.
I work on our cybersecurity solutions at Commvault, including our integrations. So what I'm going to do here is I'm going to show you a demonstration of our cyber resiliency solution, and I'll give you the gist of what we're going to do. I'm going to simulate a malware...
event where there's going to have some data corruption, encryption, and I'm going to show you how you can investigate that within our dashboard, and then ultimately hunt for threats using hashes, and then ultimately get to a clean recovery. One thing I want to point out, this is a simulation. Everything's real that I'm showing you in the demo, but cyber incidents come in all different shapes and sizes.
We've had customers and organizations that had to rebuild entire environments, and some that had to put pieces together here and there when a cyber incident occurs. Ultimately, what we want to be able to do is help our organizations get to clean recovery as fast as possible while minimizing the data loss and rollback. So I'm sitting on a file system, and what I'm going to do is I'm just going to show that I have some data here that you can open up and read, some security documents.
This is being protected by Commvault. We're already backing it up, and I'm going to run this script, and it's going to encrypt the data. So like I was saying before, you can look at the data, you can use a lot of different sources to look at dwell time, how long it takes to detect cyber threats.
The numbers are all over the place. I like to use the Verizon data breach report. Nonetheless, if it takes days, if it takes weeks to detect a threat within an environment, there's a risk of data being protected from a data protection perspective, right?
We're continuously protecting the data. We're making copies of the data in the backup repository, and this data is going to get protected. So I'm going to move over into our threat scan dashboard, where we'll start the investigation.
So let me pause it right here and talk through this a little bit. So number one, I was briefly talking about this before with the question how long it takes to scan data, to do deep analysis, whatnot. So let me explain this a little bit.
So the default capability in the product is make it easy as possible for customers to scan their data and protect it. So we incrementally do this in the background. You onboard your resources into a plan.
We will incrementally scan it using various different scanning methods, signature-based. We have a machine learning engine for detecting encryption, hashes, YARA. There's a lot of different signals.
We'll dig deeper into it. So we make it as hands-off as possible. Now, keeping in mind the persona that's using this dashboard may or may not be a security persona, right?
So right now we're talking about cyber recovery, and this dashboard is helping the persona that's going to do the recovery process, find the clean data, get to that clean data, and recover as quickly as possible. So number one, what we wanted to do on the left side is make it super easy to understand what you need to look at. We do this by correlating the signals.
So we have different layers of signals, anomalies, higher fidelity signals such as detecting the malware. And depending on how many signals are being detected and what level of signal is being detected, we can classify them in these different risk levels. So first of all, critical resources will be ones that have malware detected.
" But any resources that have multiple signals being triggered at the same time, like maybe you have an anomaly, or maybe you have partner signals telling you something's happening on the resource, we'll designate that as high. And then moderate would be one signal, like an anomaly, right? Our anomaly detection is detecting changes as we're protecting the data.
It may not necessarily mean there's a threat, but it means that something has changed in an unusual way, and you should look at it, but that's a moderate risk. Combine that with another signal, now you have a higher level risk. So number one is identifying which resources you want to focus your attention to.
Then you got the right side, which is our outcomes. So we're continuously scanning the data, and we can tell you that we detected this amount of data is clean. We can detect how much is malware infected, how much is encrypted, so on and so forth.
So we're providing you with the results on the left side. And if I scroll further down, these are operational type components on the dashboard, so you can see where your scanning gaps are. Do you have resources you're not scanning?
You can true it up. You can get it onboarded as quickly as possible. So let's dig a little bit deeper in here, and I'm going to take one step further, double-click here, and we're going to go to the critical resource list.
So these are the resources that are in critical status. And you can see from the columns that are multiple different signals being triggered. I got some anomalies.
I got partner signals. I have threats. I'm going to dig into each one of these in more depth, so don't worry.
But the first thing I'm going to do is demonstrate to you how you can bring your own IoCs into the scanning methods. You could do a threat hunt using a hash. You can use YARA rule.
So the first thing I'm going to do is show you how you can do that. And what I'm going to do is I'm going to modify the plan. And so the plan is basically a set of rules that you're going to set up.
You're going to associate all your resources to the plan, and it's going to tell you what the scanning schedule's going to look like, if it's automatic, what intelligence you're going to use. And then you could also provide your own IoCs. And you can see here I have a list of IoCs, like YARAs and hashes, and I'm going to bring over my Google Threat Intelligence platform just to get some more IoCs.
So I'm just going to look up LockBit as an example, and I'm going to look at the LockBit campaign here. Of course, Google provides a whole bunch of information. But for this demonstration, I'm just going to grab some hashes here and download this, and I'm going to inject it into the plan.
So what I'm showing you is how you can manually do this. We've had customers tell us before that their security teams would come to them, like as a backup admin, their security teams would come to them with a list of hashes, scan the backups using these hashes, or scan the backups using these YARA rules. That would be the process here.
In addition to doing it manually like this, we also have SecOp APIs, where you can automate this. So your SOC analyst can automate the import of these IoCs into the plan so it's more streamlined. So you can see here, I imported the hash, and now here's my hash list.
It's a JSON with a bunch of hashes in it. I also have YARA rule in here for a different threat, Brick Storm, YARA with the various different rules in hereSo now that I've imported these IoCs in rules into my plan, my regular scheduled base scanning will use these IoCs as part of the scanning intelligence, or any threat hunting operation or on-demand scan will also use this. So if I go back over to my dashboard, what I'm going to do is I'm going to rescan my resource, essentially perform a threat hunt operation.
And when I do this, I have an option of doing full and incremental. So I could incrementally scan this resource, meaning that only the data that's changed since my last backup, that's the only thing I'll scan. Or I can go all the way back in time, scan all the backups for that resource, which is particularly useful if I have new IoCs, new hashes, new YARA rules, where I need to go back in time just to make sure that the backup is safe.
So these are my two options here, and I'm going to run a full, and I'll submit this. And I'll pause after I do this just to see if there's questions. Okay, I'll pause up to this point.
So I submitted a threat hunt. It'll use everything I have configured in my plan, including the new IoCs, and it's going to look through all the backup data, for that full cycle. Any questions up to this point?
Self-explanatory? Okay, good. So let's move along here.
And what I'll do now is I'll show you the details of what was picked up from a threat perspective on the resource. So what's interesting is, we have a mix of personas here. So typically, the user that's using this dashboard, they may not understand all this data.
But then we have security teams, CISOs, management that want to see the details of what's happening in the backups. They need to see the threat details that we detect. So we have these various different trends and charts on here.
So you can kind of see when the threat first started. You can see the list of anomalies that occurred, and this will give you a full list of files, which is great for an investigation, and for understanding what your impact is. These are all the anomalous files that were protected, and you can see what type of anomaly occurred on it, such as they were modified, or if there was unusual amount of deletes, or a MIME mismatch on the file, or even a change in the dedupe ratio in the size of the backup itself, which could indicate that there was some sort of a mass encryption that occurred on that system.
Next is the Threats tab. So the Threats tab is really interesting because this is a culmination of our quick hyperscanning, where we're looking at the hashes on the backups, or this is also a combination of the signature-based scanning, the machine learning-based scanning, as well as the encryption-based detection as well. So what we have here is a list of files that were detected by our machine learning engine that they were encrypted.
Now we have a model that we've built that will actually look at the file and it'll determine whether that file is encrypted or not encrypted. Right? And we've trained it against encrypted data, like real ransomware samples and things like that.
So we can detect that with a relatively high level of accuracy. So you can see here I have a bunch of files that are encrypted, and then I have a malware threat detected. And you'll notice that my executable was detected here.
So I'm going to click on this, and number one, you're going to notice that on the right side, our generative AI solution, we call it Arli, which is, I think it's OpenAI-based on the back end of it. And this is our gen AI assistant that's going to give you context, which is super important for this persona, because making the data really easy to consume for a person that may not be so adept to security is very important. So I'm going to go ahead and scroll down.
You can see a little bit more context below. We have the hash of the threat itself, so you can use that for additional threats. I'll move along to the partner signals, which is another insight that we have, and this is where you can see CrowdStrike providing us input from the CrowdStrike XDR platform.
They're one of the partners that we integrate with. Any unusual behaviors we detect on the live system, we correlate it to the backup, and we use that as a signal for correlation purposes and to give you a higher level of indication that something is happening on that system. And if you don't understand the CrowdStrike info, you can use Arli once again.
So Arli is on every page of Threat Scan dashboard. All right, so now I'm going to get to the outcome here, which is going to be recovery. So two things I'm going to show you here.
Number one is the calendar view. So we have a threat-aware recovery that we've implemented into the product, meaning that all these recovery points you see on the calendar here, we will tell you if there was threats detected across those recovery points. So it makes it super easy for the user to see which recovery points were impacted across the period of time.
You can see I have quite a bit of impact here. I could recover off this. I could go pick a time date on here and just do a recovery, but the one thing that it's not going to do for me, it's not going to intelligently roll back my data in an intelligent way and get the latest version of my data.
I'm literally going to pick a point in time and roll back to that point in time. That's where the synthetic recovery option comes in. So if I scroll down, the synthetic recovery option is the automated clean option.
And you can see here, I think as Mike explained before, we will programmatically look at the files, because every threat that we detect, we track it in our index. We'll programmatically look at the files, we'll find the last good version of that file across all the backups, build that curated recovery point, and send it off for the recovery. So you can see here, we're also telling you the level of impact as well.
5% of the files coming from the latest backup set, but then some of the files are being pulled from previous ones. Below that is forensic recovery, which is like the inverse. It's like the opposite.
This is for security use cases where maybe you want to recover the infected data, but in a controlled way. If you pick that option, you could only go to our clean room solution, which is our isolated recovery environment to pass off to a security team. So it's a secure way of doing an investigation.
So I'm going to pick the synthetic recovery option, and I'm going to click Next. And one of the new options we added into our product is integrated clean room recovery destination. So in place would be I want to recover back into production directly.
Out of place would be I would want to recover to not the same production system, but another production system. And then clean room is our isolated recovery environment. And that's a great way to test your data before putting it back into production, just to do that one last bit of validation.
So I'll pick that option, and then I'll submit this recovery into the clean room, and then it rebuilds the operating system using a clean image. It puts the data back on, and then I can remote into the system and look at my files back in the recovered state. So that's the end-to-end process of detecting threats using the layered solution that we have, going threat hunting for specific things, specific IOCs, getting all the way to clean recovery while minimizing rollback.
In that recovery scenario, did it recover the entire VM itself, and was that a downtime hit, or was that actually just going in and putting those back on the file system? Yeah, that was a full system recovery. So the synthetic recovery is meant to be simple.
So in Cobalt, you can be very granular with your recovery. You can pick certain things you want to recover. Synthetic recovery is meant to be like, I want to recover this whole system, figure out how to roll my files back, and put it back in place.
So in this example, I put it out of place into the clean room. I didn't go right to production first. I could do that if I wanted to, though.
Yeah. So I'm kind of curious about Arlo's integration. Does that extend into any of the partnerships that you have with other tools as far as the data that you're bringing in there, or is it really just going to show you what's on system and in your environment?
Ask me in three weeks. Okay. It intelligently pulls the data off of some threat sources on the back end.
So it does do that pull. It's more of like an internet pull, and we curate that. Got it.
That's kind of how it works. Yeah. Right.
Okay. In other words, we're not training the model to pull back the information. It's doing a search.
Perfect. Thank you. It's AI Infrastructure Field Day.
It continues. We are here trying to close out our second day. In fact, we are going to be very successful with closing out our second day because one of my colleagues here at Futurum Group is going to be presenting for us, and that's always a win.
We really enjoy having members of the wider family within Futurum here. Great to have particularly some of the research analysts, some of the people with odd titles within the organization sitting around the table and joining our delegates. So leaping up from the table today is going to be Brian Martin.
He's going to be talking about some of the work he's been involved in recently, which is very much aligned to the important topics we have here for AI Infrastructure Field Day. Follow us along on your favorite social media. Remember the hashtag of #AIIFD4.
Also, remember that 8:00 tomorrow morning we'll restart, and so you need to have your... In New Zealand, it'd be the Weetabix, but I believe in Britain it'd be the Weetabix. I have no idea what the equivalent terrible breakfast cereal is in this country.
But make sure you've eaten, make sure you've had breakfast and some coffee. Join us tomorrow morning when you are finished with joining us tonight. I think I've raved for far long enough today, so I'm going to hand straight across to Brian for him to do some raving.
All right. Thank you, Alistair. As he said, I am Brian Martin, with Signal 65, VP of AI Data Center, AI and Data Center Performance.
I want to talk today a little bit about Signal 65, what we're doing over there, and share some of the results from a recent POC we just did. So as our president likes to say, Signal 65 got its name from the concept of attempting to be the signal through the noise. How do you make a difference?
How do we figure out what's actually true, find ground truth, in the work we do? And that squarely puts us into the lower right of this Futurum circle, which is the assess. Get our hands on equipment in the lab, test things for real, see how they behave, and then write it up and talk about it.
I have the privilege of working in and with the AI lab in Colorado. This is sponsored by Dell Technologies, and we have quite a collection of AI infrastructure, so being here at AI Infrastructure Field Day feels spot on. And we all have a mission to accelerate innovation, and do real-world impact tests of AI workloads and on AI equipment.
This is part of the AI testing lab. This is our air-cooled section for now. Primarily for these demonstrations of solutions technology built around Dell XE9680s, XE7745s, GPUs from our favorite vendorsUp through and including the RTX Pro 6000 Blackwell, and soon later this year, B200, B300, as well as MI355X.
And again, I couldn't ask for a better playground in this day and age with AI, being able to run these model solutions locally. And we do this for Dell, with Dell, for customers, and some of our own investigations. The lab itself has a monitoring infrastructure that we set up to keep track of utilization.
The systems being used, how heavily the GPU's being used, how hot are they running? Utilization is the only one that's red if it's on the left, so if it's below 50% utilized, it goes red. Everything else goes red when it gets high.
These, as we know, are not cheap components. This is expensive infrastructure. We want to keep it busy, we want to keep it running, doing meaningful work wherever we can.
Also very interested in power consumption. So power, cooling. Later this year, we're also going to add acoustic, as we start to compare air-cooled servers with liquid-cooled servers.
Be nice to know how that impacts the acoustic footprint. Some of these servers with the smaller fans get very loud. We're clocking some 120 decibel sound levels in the AI lab today.
Looking forward, one of the things we've heard a bit about today, a couple of times at Infrastructure Field Day, is digital twins. We did a similar thing for the AI lab, and my team constructed a digital twin in the lab for the lab, which allows us not only to explore the build-out and creation, but also allows us to do a little what if modeling. So we can take new servers, put them into the rack.
We went all the way to VR with this solution, so Meta Quest headset, fully immersive. Why did we do that? Going from blueprints to models to fully immersive gave us and some of the lab operators the opportunity to feel the space in three dimensions.
We only get one chance to design these labs. This particular build-out is slab on grade, overhead water. It's as scary as it sounds.
And in conversation with Dell, just within the last 12 months, there has been a huge uptick in questions from customers about slab on grade. In the past, it's always been raised floor, water under the floor. We're really starting to see companies trying to take advantage of existing space.
As we heard earlier, this equipment can be incredibly heavy. 3,000, 4,000 pounds for a rack is not unusual in these AI servers. So slab on grade is good for that, but we have to be very careful.
So now we're looking at routing water overhead, power overhead, network cables overhead. Where do you fit that? How do you fit that?
Having VR and the ability for the lab techs and the designers to put on the headset, walk through the lab, get on a ladder. Can they fit their head over the rack, under the pipes to reach the network cables? We made a few design changes early on based on these models, design changes that would have been very expensive to do later on in the project.
So not only was it fun, entertaining, and enlightening, it was also helpful with a positive ROI almost immediately. All right. What do we do in the lab?
I mentioned some projects we've got going, with partners, customers, Dell. We publish that on the Signal 65 website. There's a dedicated page for insights from the AI lab.
I'm going to talk about one of the projects we recently completed around data preparation. This seems to dovetail well with talks we've heard earlier today, about the importance of the data we feed into AI models for the results we hope to get back from those models. So Brian, you mentioned Dell servers.
Do you have NVIDIA DGXs and those sorts of things, or? Well, we do have access to NVIDIA DGX. Those are in a different lab.
Not in this lab? Not this lab. They're much smaller.
They fit into the Kentucky lab. Thanks for asking. All right.
I think I heard this earlier today. You can't just dump huge amounts of raw data into an LLM and expect reasonable results. Our friends at Forward Network shared that and talked about their solution and why.
This turns out to be the exact same problem Gadget Software is addressing in this engagement we did. So garbage in, garbage out. In this case, it's very expensive garbage out when you're running on systems that cost well north of a million dollars per cluster.
And this gap we get, between AI capability, the models we have are incredibly powerfulWhat we can do with them, given clean data, clean instructions, clean context, is very impressive. But when we don't have data that they can consume or they have too much data, they struggle. Why do they struggle?
They struggle for a number of reasons. They're going to struggle with quality. In a typical RAG environment, we start with data ingestion, and that starts with chunking.
And often we overlap the chunks we ingest so we don't lose context on the gaps between the data, but we're still doing it blindly. So we don't have continuity through a given thought or topic. And then at the back end, we have a vector DB, we have our data, and when we're trying to retrieve that data, the LLM has to rebuild the context.
It has to re-thread those topics together, it has to understand what's related to what, pull that back out of the vector database, reassemble it. Generative process, you're likely to get different answers every time. Not always what we want when we're trying to have strong attribution or if we have strong security requirements.
Going through this process, we discovered something interesting, and that is, really, that the documents we're feeding in, even though they're the most commonly uploaded things into the LLMs, they're not the best format for them to make good decisions. PDFs and the PDF format, PDFs are for people. They're the last stage of publication pipeline, and it's really a publication format.
It wasn't meant to be computer consumed. It's meant to be person consumed. Computers and AI especially need something else.
And what we think they need, and what Gadget is offering, is this concept of compute-ready data or compute-ready documents. How do we give a computer system something a computer system understands? And for those of you who've been in and around the storage industry for years like I have, you're going to hear a very familiar term, and we've also heard earlier today, and that's metadata.
And metadata can be a lot of different things. Metadata can be about where the data lives, what file system it's in, what container it's in, what its properties are. Metadata can also be about what's in the file itself, about the contents.
And this is what we're looking at here. The metadata that we build up, that Gadget builds up in this solution, is about what's inside. And they do that in four steps.
They start by decomposing the document in something they call semantic decomposition. How do they pull apart a document while retaining topics and concepts and holding those together, feeding those into an LLM that takes those topics and enriches that data with useful things? And those useful things are summaries, descriptions, keywords.
If you configure or derive sentiment or intent. Relocating silver to gold. Go ahead.
You're not doing vectorization of the documents, or? Not yet. Well, or should I say, also yes.
Vectorization also happens, and vectorization of the metadata can happen. But the challenge we found with pure vectorization is you get proximity results. Like this concept is close to that concept.
And what gets lost in that process often is attribution. Attribution or providence, whether it's security or the ability to simply cite your source. Quick question.
Yeah. When we're talking about compute-ready documents, the legal industry has document management systems that are quite large, quite large vaults of documents. Are they working with you in collaboration on how to do some of the decomposition?
Because they also have some AI tooling around document manager decomposition. I was just curious if they're involved in any way or anybody is. Not yet.
We expect soon. Okay. I don't know if it's in the slides or not, but we're looking at some grants specifically around this topic- Mm-hmm ...
which we hope they'll participate in. Maybe get a DMS involved. Okay.
Yeah, definitely. Gadget goes so far as to even create sample Q&A pairs based on the data. Like given this data, what's a reasonable question that might be asked, and how would that be answered?
That can be a starting template. If anyone's done prompt engineering, one of the parts of a prompt that are often helpful are examples, and this starts with some ready-made examples. What kind of documents are they doing this for?
Ah, fantastic. Hold that thought if you would. I wasn't sure where to put that slide, but we do have a use case, a very specific use case, with one of the world's largest publishers.
Then, as I mentioned, governance and security is a key point. All right. So what does that look like?
It looks like a machine. It's a conveyor belt. Data comes in.
Interestingly enough, in both the use case we're going to look at and a large portion of the publishing industry, the data phase immediately before conversion to PDF is actually semi-structured data, often XML or something similar. Being able to tap in at that point in the stream helps text parsing and assembling that, but we also have charts, tables. The next project we're looking at is basically finding a large volume of data that's literally just scanned documents that are brought in as images.
So there's zero text content to start with. That's when the vision models really kick in to help process those on ingest. The other interesting thing is when this is created.
So there's this concept of write once, read many for this data ingestion. Bringing the data in, validating the data, so this is part of the pipeline, making sure that the data we brought in accurately reflects the source data. Once we've got that finished, we basically write lock it.
Now it's got an ID, it's persisted, and subsequent processes, whether they're chatbots or agents or Power BI as an example, BI tools, can access that same data, have the same responses, which bring back for a set of keywords, a set of topics, brings back cited references, and then the LLM can do what it does best, which is embellish that for final return. I have a question. You can tell me to wait till later on this one, too.
It's fine. But I'm looking at this pipeline here. The ingestion, it's data, so does it have to be a Word doc, a spreadsheet, an email?
Can it be text? What are the data- It can be anything. Okay.
Anything an LLM can interpret, it can be. Okay. So anything from a picture.
Doesn't have to be in a specific language. Okay. What we've done in this use case is predominantly English text with pictures- Okay ...
for the starting point. So the process of summary, description, topic-specific keywords, sample Q&A, sentiment intent, topic boundaries, segmentation is done through LLMs, or is that something that Gadget has created themselves or what? That is an agentic process similar to what we saw with Forward Networks in the previous presentation.
That is a pile of code the agent, that Gadget has written in communication with an LLM to process it. Great question. The question I have, I just want to add some context, because I'm thinking about use cases of how people would use this.
Mm-hmm. And how people create data- Mm-hmm ... is so sporadic, right?
Yeah. So I'm thinking of, even if you have a document that's been... all the comments from editing it down, some of those comments are sometimes really- Valuable ...
informant and good things to know, especially if you're going to ingest it into this type of thing. Mm-hmm. So I was wondering how much they thought about how people actually create data- Mm-hmm ...
and did that go into consideration of how to make this pipeline? Absolutely. Okay.
So those comments, I think of those as comments in the margins. Yeah. We write in our books, scribble things, highlight things.
And if those are captured electronically because you took notes, that's one way. These documents that are photos, a lot of them do have scribbling on them. Okay.
That gets captured as well. And the vision models are getting extremely good these days, so they can tell when something is in the margins, what it belongs to, and then how it relates to a keyword or a topic. Okay, cool.
All right. Here's the answer to your question. So the use case we looked at was the United States Federal Register.
This is an enormous pile of data that gets generated daily. They set a record in 2024. Over 107,000 pages generated.
This also includes final rules, which include a lot of dense legal text, which has to be parsed carefully and has to be referenced accurately if you're trying to make decisions based on this. So this is a large amount of data, in this case, in a relatively friendly structure coming in, but with pretty dense content and requirements around it. And at the end of the day, the threshold we set is that the tools will have the ability to trace all responses.
Anything can be cited back to a document. And that becomes crucial when you think about governance and security. To block those from going out so they don't come back.
Whereas in a vector database, that often gets lost. I'd go so far to say always, but that won't be true tomorrow. So does the- But it often does.
gov or whatever, that you can access the federal registry- Yes ... by asking a- PubWell, our system is not running there. This system is running there.
Anyone can go to that site and download it. Oh, I understand. But you've got more semantics, summarization, description, keywords, all that other stuff.
Correct. That's not part of this system. Not part of this system.
But- Where's your system- ... this is an overlay ... to access that?
Look in the notes in the video when it gets posted. Okay. No.
It is from time to time made publicly available for this. So getting to the fun performancy stuff of this. So in the lab, one of the first things we did was compare the solution running in the cloud or running locally, but accessing LLMs in the cloud.
So we want access to the best models to do this work sometimes. But getting from on-prem to off-prem and back again, managing this data, results in pretty spiky latency. So this is a graph of hundreds of thousands of data points run across each or the entire processing of a month's worth of data from last year.
So we brought in each document that comes in, generates... There are some dots around zero. Generates a little to over 6,000 what are called artifacts.
An artifact is anything that gets generated from the system, a keyword, a Q&A pair, a summary, a topic. Some of the larger documents generate a lot of those, and with pretty predictable correlation, the larger the document, the more you're doing with it, the longer it takes. What surprised us running on-prem, with both L40S GPUs and RTX Pros, is how flat that other line was.
Consistently spot on, doesn't really care in the overall measurement. And this is just the ingestion process. It's not the actual query process.
This is the ingestion and enrichment process. Correct. When you do these sorts of comparisons, the question I would have is, is the hardware similar in both the cloud environment as well as local, or is it different?
Are you using RTX 6000s versus the cloud might be using L40s or whatever? So in this particular test, this is cloud API against local GPU, so we don't actually know what the system is inferencing on. Could be anything.
Could be H100, could be A100, could be- Yeah ... H200. We don't know what the back end is running.
Could be sharing some slice of something. Yeah. Correct.
So shared system problems. Once we have all this data, what can we do with it? " And one of the things they discovered in conversations with customers is the first question they ask is, "What should I ask?
" It's like, "What can this data set tell me? Am I looking at something about environmental law, or am I looking at after-school activities? " And we don't always know that, even in our own companies, when we're looking at a data set.
So one of the things that they did as a demonstrator, this is a Power BI dashboard, with a lot of stuff packed into one screen. Analyst's dream here. But before any question gets asked, this is a breakdown of the data that's in the repository.
So this is range of topics or departments in the government or areas of the world that are impacted. And it's meant to show different ways to bring a customer or a user into working with the data. So there's a lot of different topics, people, places, impacts that can be looked at and drawn through here.
So watch for more updates as we do more engagements. Again, Signal 65, Insights from the AI Lab. This is the digital twin for the liquid-cooled portion of the lab, which is being built out as we speak.
Questions? Is this the actual representation of the data center? Or is this- It is the actual representation.
It's a big place. Yes. 8,000 square feet, I believe.
Oh, wow. Yeah. This is the actual design, the actual layout, the plumbing, rack spacing.
A couple interesting things about this, you may notice here, there's no hot aisle, cold aisle. Every system in this is room neutral for temperature. I see a fire alarm pole on the wall.
Are you modeling fire suppression? Not yet. That was it.
That's it. That's it. I was reminding him to go back and do that.
We do have it. All right. Thank you.
Cool. Thank you, Brian, and I know the build-out of that data center has been an incredibly exciting project for a whole bunch of time. It's occupied Brian for a very long time, and will continue to occupy Brian for quite a while yet.
So, it's a really cool project, and we're really glad to get that underway too. Mm-hmm. So thank you, Brian, for sharing with us.
Thank you all for joining us. It's been our pleasure to bring you here into this meeting room in Santa Clara, and particularly to bring all of my delegates and the presenting companies into this meeting room as well. Thank you for joining us on LinkedIn Live, TechStrongTV, YouTube, whatever your favorite flavor of location is, and I hope you'll join us tomorrow morning at 8:00 for the final day of AI Infrastructure Field Day 4.
We're going to go off and have some drinks and some dinner, maybe do something fun. You have some fun tonight too. Primotion Media, please shut down the stream for me.