Techstrong TV Tuesday, April 14, 2026
On today’s Techstrong TV, Alan Shimel broadcasts live from RSAC with Sophos CTO John Peterson on how AI is transforming endpoint security and whether the CISO role will survive the age of machine-speed threats. Mike Vizard sits down with QuSecure CEO Rebecca Krauthamer on why Q-Day is closer than enterprises think — and why waiting for the perfect migration plan is a fatal mistake. Jon Swartz reports live from RSAC on the premiere of The Women in Security documentary, with co-producers Aarti Gadhia and Kristen Rank on why allyship is the key to fixing the broken rung. Mike Vizard also reports from KubeCon Europe with Dirk Alshuth of emma Technologies on taming multi-cloud complexity through a no-code abstraction layer. Plus, a Microsoft Copilot Studio replay with Clay Wesener, the Security Boulevard Podcast on Anthropic’s leaked debug map, and Lightyear from Tech Field Day.
Transcript
Hey everyone, we're back here live at RSA. We're in Moscone on what they call Broadcast Alley, and I'm really happy to introduce you to my next guest. It's his first time on Techstrong TV, so it's a pleasure to welcome him, John Peterson of Sophos.
Nice to be with you, Alan. Nice to be with you. Thanks for joining us.
So John, what's your position with Sophos? I'm chief technology officer at Sophos. CTO?
Yes. So I'm responsible for all the folks that build our products and support them out in the wild for our customers. Excellent.
Yep. So I always like to let people know who they're listening to. Mm.
You don't just walk in one day and become CTO of a company like Sophos. John, tell us a little bit about your journey. Absolutely.
So I've been with Sophos now for almost nine years, believe it or not, and it feels like I joined yesterday. But when I first joined, I was responsible for the cloud security group, so the group of engineers that's responsible for the Sophos Central platform. Mm-hmm.
And at the time that I joined, Sophos was going through this transition because we were one of the first endpoint security companies, in the world actually, and like many of the original endpoint security products that were out there, our original endpoint products were all kind of on-premise managed, and we were going through this transition to the cloud, right, and cloud-based management. And so there was a huge inflection point that the business was going through at the time, and I was able to help them through that and get Sophos Central to the point where today it supports over 600,000 customers, 28 million devices- Wow ... globally.
So we're processing petabytes of data every day. So the platform itself has really grown. Our business has grown, and I've been fortunate enough to be in a position where my role has grown with the company.
Love it. Yeah. You know what's an interesting thing, John, the wheel of karma goes round and round.
Mm. So Sophos was one of the original endpoint. Mm.
Then went to the perimeter, then went to the cloud. Mm. And now with the advent of AI- Mm ...
AI on the edge, AI on your devices, you're an endpoint company again, right? Yes. Yeah All of a sudden endpoints are sexy again.
Or endpoint security's sexy again. We think that endpoint has always been sexy. Okay.
Beauty is in the eye of the beholder. But that's a great story. And you know what?
We touched on it a little. So there's still the cloud security- Yep ... aspect of Sophos.
There is this big endpoint push. Yep. What's the three-letter acronym for endpoint security now?
EDR. Yeah. EDR.
Yep. Do you still make ETMs and sort of perimeter boxes, or? We still have a large and growing firewall business.
Really? It's less of a UTM business, but more just like a business enterprise edge, SMB, mid-market focused firewall product. Really?
So we see Fortinet all the time out there. Yeah. In mid-market.
They were here earlier, actually. Okay. Yeah.
But yeah, we still have a large firewall business. And people have been talking about the death of the firewall for a long time. And- From 2001 when I started- Yeah ...
they were talking about it. And the reality is that business for us continues to grow. We continue to invest in it.
But we of course also are investing heavily in our MDR business, which is actually, we believe, the largest MDR operation in the world. We have 35,000 customers. Really?
And actually, that's one of the things that's allowed us to do some pretty innovative things with AI agents for our MDR operation because we have, I think, probably more data about customer behavior and the active threat landscape, and also how to deal with that threat landscape and those active threats, than any other vendor. So as we're building agent-driven solutions for that SOC to help us with efficiencies and also with better customer outcomes, we're in a position that we think is just very, very competitive because we have this corpus of runbooks and standard protocols and procedures that our SOC uses every day to protect customers that we can use as context to make the agents better and drive better outcomes for our customers. I love it.
Yeah. It's a great story. Mm.
So we're one day in. Well, we started yesterday, so maybe there's two days in- Yeah ... to RSA, and there's clearly no mistake, this is the year of agentic AI at RSA.
Yes. I got a confession. I've been using AI for a while, but the last three weeks or so, month, I really dug in on agentics.
Mm. It's a drug. I'm telling you, this is like crack.
Because it's not only me. The people in my office who are on it- Mm ... it's very hard for them to disengage.
They're coming in on weekends. I haven't had people in the office on weekends in I don't know when. Mm.
They're staying late. They're coming in with stuff they did at home. Mm.
Because people are just like, "Holy. " Right. Right?
It's that kind of effect. Are you seeing this similarly within Sophos in the people you're managing? And more importantly- Yeah ...
we've got to help secure these people because they're running as fast as they can. Oh, 100%. Yeah.
And I think the answer is absolutely to that question. It's been remarkable even just in the last six months to see how fast the technology has- Six weeks. Yeah.
How fast the technology has progressed. 6 is- Game changing ... such a leap forward.
Yeah. One of the things that I spend a lot of my time thinking about is AI-driven engineering and- Yeah ... how can I enable the development workforce at Sophos to build our products more efficiently, and theThe AI coding tools are going to be a big part of that for us.
Sure is. And like you said, it's sort of like a drug when you get going with it and you start seeing something that used to take you days or weeks being at your fingertips in- Moments ... a matter of moments.
Yeah. Yeah. And so we're definitely seeing that in the engineering side, but also, as I mentioned, in our security operations center for MDR.
There's a huge amount of efficiency and just better outcomes that we've been able to drive with the agents that we're building. But also, I would say that the same tools that are great for us as defenders are being exploited by attackers absolutely mercilessly. And so the amount of time that it takes to actually take a vulnerability, or even discover a vulnerability, that used to be a very specialized niche thing, and that still is.
Security researchers out there every day submitting issues to our bug bounty program and every bug bounty program out there. Well, but this is a problem now. Right.
The volume of bug submissions. Right. A lot of people are shutting down their bug bounty programs.
Yeah. The Curl, for example, was one of the- Yes ... ones that I saw.
Yeah. And so that's troubling in a sense, because we have this explosion of vulnerabilities. We also have the amount of time that it takes to exploit one of those vulnerabilities successfully and then scale it massively, that used to be contained to a very small set of specialized operators.
Mm-hmm. Now it's available kind of a mass to- Anybody with AI ... any 18-year-old with an LLM.
Yeah. And so, setting ourselves up and our company up, and our customers up to deal with that new reality is a big part of what I spend my time thinking about. And the solutions that we're building into our MDR operation will help.
But, we also need to be thinking about, as we build our products, how do we engineer better code reviews into our release pipelines- Sure ... and our CIC infrastructure. Well, just to do that quickly, but- Right ...
to me, I don't know if you ever read the book "The Goal" by Goldratt. Mm-hmm. " Yeah.
"The Goal" is about manufacturing, but it's the theory of constraints and bottlenecks, and part and parcel with that is, as soon as you break through one bottleneck, you discover the next bottleneck, and then the next bottleneck. So we're moving from a world where code was the bottleneck. Right.
There's only so much code we could turn out, how many developers do you have? Yeah. How much lines of code did they do a day?
Right. To that's sky's the limit, right? Yeah.
You can turn out as much code as you want with these things. Yeah. Well, the next bottleneck then is, oh my God, how the hell are we going to govern?
We need governance here. Exactly. How are we going to put quality control in?
Yep. How are we going to security test? Yeah.
Well, we tackle those things, but then the next bottleneck will come out. Yep. Right?
Which is, okay, I've got to deploy this now. Yeah, exactly. And I've got to run it.
I've got to make sure it stays, and I've got to update it. Right. So there's always the next one and the next one, and it's just the theory of constraint.
How do you at Sophos, where you're talking scale- Yep ... at scale, these problems become a billion here, a billion there. Before you know it, you're talking real money, right?
Oh, for sure. It's the same thing. You mean in terms of the expense of the LLMs and...
Yeah. So I think the- Just keeping up. Yeah.
Well, I think the interesting thing is there's a whole series of cultural things that we're trying to do to enable our engineering staff to really lean in safely on these technologies. But one of the first things that we saw when we started introducing AI coding assistance was the amount of code being created was going like this. But when you look at some of the more traditional productivity metrics, like do you have more PRs moving through the system?
Are they moving through more quickly? Do you have more issues being resolved? Are your cycle times reducing?
Those metrics didn't initially improve because you had this top of the funnel being loaded, but the rest of the funnel wasn't set up to actually- Uh-huh ... take that input and then process it more quickly. And so one of our large focuses now is getting beyond just this AI-driven coding to true agent-driven workflow across the whole development stack, right?
So that when a PR comes in, it's being reviewed for defects by an agent. It's being scanned for vulnerabilities by an agent. And then when a human actually reviews it, they're reviewing something that's got a much larger chance of just working its way quickly through the system.
And so that all... We're on a journey. I think many companies are on that journey right now.
Absolutely. Yeah. There are going to be a lot of business school case studies- Absolutely ...
coming out of the next year and a half, two years here. Yeah. No doubt about it.
Let me ask, wrap things up a little bit about RSA. Sure. Any specific Sophos news around RSA or observations from you about this year?
Yeah. I think one of the big things that we're focusing on as a company right now is this idea of kind of making CISO level expertise available to the masses, right? And so we like to cite a statistic that there's only about 35,000 CISOs in the world, but there's over 359 million companies in the world.
009% of businesses- Has a CISO ... have access to CISO level expertise, right? And so, per our previous conversation, as agents get better and better at finding and exploiting vulnerabilities, having that access for small and medium businesses is absolutely critical.
And so, major focus for us right now is trying to build services that serve that market and- Let me ask you a question on that one. Please. Because I had this conversation with someone not on camera.
Okay. We'd be clear. But I'm going to ask you on camera.
Okay. If you don't want to answer, don't answer. Okay.
But we talk about AI making certain jobs obsolete or- Sure ... harder. Not harder, but-Superfluous- Sure ...
is the word. Yeah. What about the CISO?
Well, I think that in many cases, I look at it less as elimination of jobs, more as elimination of tasks, right? Okay. So if you think about, to the SOC, for example, which is another example that I'll keep referring back to.
The typical SOC functionality is you get a case, and then you open the case, you triage it, and then if you determine it needs to be investigated, then you go through the process of investigating it. And that's often the relatively procedural thing that you go through in a SOC. So what we're focusing on there is trying to automate as many of those steps- Absolutely ...
as possible, so that when the human actually gets involved to review the case, you're reviewing the output of that agent's analysis. It's further along, yep. Yeah.
And so I think with virtual CISO or the CISO role in general, I think that there's always going to be a need for a human-level component, the human judgment element. But I think a lot of the tasks that are associated with being a CISO are going to ultimately get easier, and they're going to be, hopefully, you'll be able to conduct them more thoroughly. But at the same time that I'm saying that, the threat landscape is also changing so- Well, that's the other thing ...
so quickly, that- It may free them up from doing that mundane- Right ... reporting stuff. Yep.
And focusing on strategy- Absolutely ... and keeping up to date with what the latest threat vectors look like. Yeah.
And I do think that as we get more and more vulnerabilities being discovered by better and better LOMs, you're going to have to be positioned to respond to those. As we, as software manufacturers, need to be ready for that. And CISOs need to be ready to put programs and processes in place to ensure that that happens, and manage it.
And I think that that role's not going away anytime soon. Yeah. Agreed.
Yeah. John, we're out of time, man. Great.
Thank you so much. Yeah, sure. I appreciate you coming in.
I hope you enjoyed it. Yep. " We're going to take a break.
I've got my friend Chenxi coming in here, so don't go anywhere. Hey, guys. Thanks for the intro.
We're here with Rebecca Krauthamer, who is the CEO of QSecure, and we're talking about, well, Quantum Day. It's today. And everybody's talking about quantum, and it always brings us back to this conversation about Q-Day.
But I'm just starting to wonder, are we going to be prepared for this? Because even when Q-Day arrives, and let's just randomly say it's 2029, well, I started working my way backwards from where we are, and I think there's roughly maybe 370 working days between now and then. And are we maybe going to be caught unawares by all of this?
Anyway, Rebecca, welcome to the show. Thanks, Mike. Thanks for having me.
So what is your assessment of what's going on here? Because ripping out encryption schemes is non-trivial. Yeah.
" Google released a paper, Oratomic released a paper, and these are earth-shattering, groundbreaking. " And Google's moved their Q-Day to 2029 when they have to have their internal migration done. Cloudflare did the same.
And what we're seeing is a lot of organizations are following suit. And so there is this time crunch. If you do the math, right, that, yeah, it's 1,000 days total to get there, to 2029 from here, maybe.
Maybe that. Much fewer working days, as you said. But this is something that we've been thinking about.
" We've known this since 1994. And that it would likely happen in the next several years. And so when we started out, we started working with the Air Force, and it was a very clear picture of what today a typical organization looks like.
A lot of investment and legacy infrastructure, and all of it needing to be upgraded to quantum safe encryption. So yes, huge overhaul. A huge amount of work that has to be done.
And it is, I think, the biggest difference now after these papers have been released, is that people are finally understanding that this is a non-negotiable priority. So to your point about that, how are we going to get there? " So how much effort is there going to actually be in taking care of my legacy systems?
Or am I just going to replace everything with something that's a little more post-quantum friendly, shall we say? Well, that's certainly how some people think about it. And you'll see that at the government level in the US, and in many parts of the world now, the migration timelines are fixed.
The first hammer drop, like the first big mandate deadline comes at the end of this year. So, yes, a lot of people are going to be prioritizing acquisition of new systems and that those support post-quantum. But it is not responsible to be ignoring the legacy infrastructure because nobody is going to be gutting their entire infrastructure and turning it over in the next three years, right?
And that's what we focused on, where we saw the biggest part of the challenge is these systems have to stay up and running, whether it's the Air Force or anywhere. These systems cannot just be gutted in order to adopt post-quantum cryptography. And to take a step back, this problem really applies to any secure data in transit, right?
That's where the biggest problem lies. And so you think about everything that goes into facilitating data as it travels. Chances are, those come into play when you're thinking about this migration.
So that legacy infrastructure piece, that's where we spend most of our time. And how we have addressed that through the past few years is essentially control plane overlays for deploying encryption, decoupling that encryption from the asset itself, and deploying that encryption over the top in a way that does not impact performance, but gives you that control to not gut things, not throw things out with the bathwater, not have to overhaul systems, but adopt post-quantum protections immediately. So you're stopping that bleed and heading off that threat so you can get there sooner than 2029.
Is it reasonable to assume that I'm going to go in and replace the encryption schemes for all of my legacy systems? Or at this point, am I going to have to maybe start prioritizing some over others because I'm just not going to get there in time? It's a great question, and the answer is, at some point, we do have to do it all.
But the right way to do it is not think of it as you have to eat the whole elephant at once. It is the prioritization. That is the most important part.
And so there is a very interesting bill that's being proposed as an amendment to the National Quantum Initiative Reauthorization Act right now, which is the big act that funds quantum computing research. But this is an amendment that says it's a forcing function to make government agencies pick one system, one high-priority system that they need to put into production with PQC within 18 months of passing. And this is exactly how everybody, not just government, but everybody across private sector should be thinking about it is, what is that first system?
Pick one and just start moving, start migrating. And everything is interconnected, and that's why ultimately we have to do it all. It's under Chatham House rules, but on one of the recent NIST calls, one of the leaders talked about it, saying, "Yes, of course, we have to do this migration as a whole.
We have to migrate everything. We do not do things because they are easy. " That was the statement.
And it is an incredibly big problem, and I think it intimidates a lot of people, but that is why we don't have to do it all at once. Mm-hmm. So starting with those initial systems is critical.
" Ask your board member, ask your CEO, your CISO to close their eyes and imagine waking up and Q-day has happened, that cryptographically relevant quantum computer has come online. And just ask them, kind of meditate on this, what does your mind first go to? What is the biggest thing that you're personally concerned about?
Maybe it's a personal email. Maybe it's all of your online banking customers. We worked on a report with Citibank that came out from City Institute about a month back, and we referenced some good econometric modeling that shows just one successful attack on one large US bank could cause losses to the tune of $2 to $3 trillion.
And so yes, I think it's really hard for leaders to put themselves into that mindset of, "Oh, that is down the road," especially when in cybersecurity, everything kills you, right? There are so many fires burning at once. But the reality is, and I think what these new bombshell papers are forcing people to get into that mindset of this could happen under my tenure.
This likely will. " And that it's going to become too hard to ignore. So to your earlier point, we've already moved the proverbial goalpost once to 2029.
What are the odds that those goalposts are going to move again, maybe closer to 2028, and this is just the beginning of something? Because it seems like technology doesn't stand still here. No.
And to give you some bit of reference, we started working on this back in 2019, and around that time, the gold standard research said you needed something on the order of 20 million error-corrected qubits to break an RSA 2048 kind of thing. It doesn't matter what a qubit is, just 20 million of these units of quantum computing power, raw quantum computing power to break RSA 2048. Now, what these papers are saying is it's possible that under very specific circumstances and several months, you could do it with something on the order of 10,000.
So going from 20 million to something on the order of 10,000 in just about five years, that's how much we have moved forward. So to your point, it is not only likely that new research will come out that accelerates the timelines, I think it's inevitable. Well, Q-day sounds quaint, like there's going to be a party or something, but if and when this does happen, I don't think the people who are doing it or have this capability are going to stand up and necessarily announce that they have achieved this goal.
They're going to have this capability for a certain amount of time before they let us know, and we might not figure it out for, I don't know, months, maybe a year or so. So this Q-day thing, it's not like there's going to be an announcement, right? That is 100% accurate.
One of the biggest dangers is that people are waiting for certainty. When is this thing going to come online? Has it already broken?
And we can't do that here, because no, if you get this quantum computer, if you get this powerful of a tool, you do not release a press release. Just like if we think back to World War II, when Alan Turing and crew were working on breaking the German Enigma code, and they figured it out, they went as far as risking lives and sacrificing human lives to keep it a secret, so that they could continue to have the upper hand. And that is what will happen.
We won't know. And data will be broken. Someone will have that master key to our communications, and it will be too late for some organizations.
Ultimately, what's your best advice to folks then? " Well, the news is always full of doom and gloom, and again, in cybersecurity, everything is on fire at all times. It's not often that we have this big of a problem staring down at us, and we actually have a solution.
And so the first thing that I see, too many people still think there is no way to solve for this problem, that it's panic mode that we have to stay in. Post-quantum cryptography exists, it is standardized, it has the stamp of approval, go forth and adopt it, and it runs on classical infrastructure. You do not need to wait for quantum technology to fight quantum computing attacks.
So that's one big thing that we need to make sure everybody understands. We don't know when this is coming. Google is not even saying that 2029 is when it'll likely happen.
They're just saying there is a big enough threat that we know we need to migrate everything by 2029. We need to stop waiting for that certainty, because if we wait till something has gone wrong, something big has gone wrong. Something company-ending, something economy-impacting.
So getting ahead of it, and I would say the main thing that organizations really should be doing and taking seriously is putting budgets very quickly towards not just discovering and inventorying across the organization where encryption lives, but also piloting. Pilot different solutions that actually remediate, that help migrate your systems to post-quantum. And finally, not just post-quantum, but what has become the gold standard way to approach this is post-quantum via cryptographic agility.
And this is the idea that these new standards will not live forever. Whether it's the underlying math or specific implementations of these new post-quantum algorithms, they're not going to hold up forever. And so next time, as quantum moves faster and faster, as AI moves faster and faster, as threats become more dynamic, there needs to be a way to switch out the encryption that we use as quicklyAs those threats emerge.
So no longer can we live in a world where you have to go through this huge migration every single time. And that is cryptographic agility. So we see organizations spending a lot of time in the discovery phase and thinking that you have to go through this exhaustive process before you do any of the remediation.
You should be doing both at the same time. You should immediately pilot, you should put a helmet on while we're hurtling towards this brick wall, and then you can progressively put on the suit of armor, and you should start prioritizing those systems and adopting post-quantum in a crypto-agile way. Well, speaking of that hurtling, have you seen any evidence that nation-states are starting to harvest encrypted data in anticipation of all this?
Because there's been some debate about that out there. Yeah. Now, the debate about harvest now, decrypt later, and what kind of problem it actually poses to the average organization, I think it's safe to assume that if you protect something of very high value, that might be high value, especially to a nation state, that it's likely to be getting attention.
Do we know that harvest now, decrypt later is a real thing? Oh, 100%. And all advanced nations do it, right?
They collect as much as they can because that data, knowing that we'll have that quantum computer online in the coming years, it's of incredible value to stockpile that data. So is it happening? There is zero doubt.
What impact it has on any given organization, that's where there may be some hype around it, and it has to be down to the organization to know the value of their data and what's exposed. All right, folks. You heard it here.
The risks are real. And I wish you all a happy Quantum Day, but I'm not quite sure that happy is the right word here. Hey, Rebecca, thanks for being on the show.
Thanks, Mike. Thanks for having me. All right, and back to you guys in the studio.
Hey, I'm Jon Swartz, and we are at RSAC. It's day one in San Francisco. We're at the Moscone South Auditorium, so to speak, on Broadcasting Row.
So to our left and to our right, there are a number of booth setups. And we're going to start this week on a very strong note, on a very important note. We're going to talk about a documentary that is going to premiere tomorrow and be shown also Wednesday here at RSAC.
" First off, welcome to the show. Thank you. Welcome to San Francisco.
I think you came in from Sacramento. Arti, I'm not sure- I came from Vancouver, Canada. Oh, nice.
Beautiful city. Yeah. Thank you.
Beautiful city. Tell me a little bit about this documentary and when it's going to premiere and kind of the idea behind it. Yes.
Well, this documentary, first viewers, happy Women's History Month, and this documentary took us five years in the making. So just before COVID, we started. " It's been a long journey, and we're finally here after five years.
We're going to be showing this documentary, and super excited to show it here at the premiere. We've had several different premieres across different cities, and we're going to be showing it here in San Francisco at the RSA Conference. It's directed, by the way, by Yvette Freeman.
It is. Yes. And Kristen, tell me a little bit about the idea or the kind of the narrative.
So from what I understand, it involves the idea of women in this cybersecurity realm- Mm-hmm ... which unfortunately, the numbers are low. They're getting better- Yes ...
over the last decade, they have improved, but is this primarily about that challenge or that issue of women in the industry, or is it even something more than that? I think it's something more than that, but it is about women in the industry and some of the things that we face being in this industry. It's not always easy, but it's a tremendously rewarding industry to be in.
Richard and Yvette did a great job narrating the challenges and some of the interesting opportunities that we face being women in cybersecurity. So you're both... Are you both in the documentary?
Are you both on camera? I'm not in the documentary. Arti is.
Arti, I know you are- Yes ... because I saw a clip. Mm-hmm.
And are you involved in the- I've gotten- What was your involvement? more involved because of Arti. Okay.
So I've done more or less fundraising to help get the movie at the Metreon. So I've done- Okay ... the fundraising.
By the way, the Metreon, which is across- Across the street. Yep ... the street from here.
Yeah. The premiere is Tuesday at 4:00 PM. Doors open at 4:00 PM.
Yep. And also Wednesday. Yep.
At 4:00 PM. There's a red carpet, starts at- Yep ... 4:00 PM.
That's right. The screening's at 4:45. Sorry.
Yeah. How long is the documentary, and- So yeah. The documentary's 75 minutes long.
Awesome. And yeah. Again, back to what you mentioned, it shows our journey, how we started in the industry.
We also talk about some of the allies who have supported us along the journey. It's such an exciting documentary, and we've had such a big impact when viewers have watched it. " There's so much great feedback that we've gotten.
So you mentioned in, I think in the press materials, allyship. Yes. Now, I was unfamiliar.
I know what the concept is, but I was unfamiliar with the word. Is that something that has kind of picked up and is now resonating and maybe has something to do with these slowly improving numbers? Yeah.
Lots of allies have helped us across- Mm-hmm ... in our journey. A lot.
A lot of them. A lot, yeah. A lot of great men.
And really supported, not just this documentary, but supported lots of different initiatives. So that's how we're going to accelerate change, is we have 25% women in the industry, and of course, we want to accelerate that change. And the way we can accelerate that change is have more voices.
And that's where we need all the allies to join us in this mission so that we can have more women join the industry. Mm-hmm. So I'm going to ask you, I don't want to put you on the spot, but in terms of the allies, who are some of the stronger allies?
If you could point out, are there certain companies or individuals within cybersecurity who have championed? So many great men. Yeah.
There are a lot of great men who have helped us along the way. Okay. The list is long.
Yes. But from a company perspective, I think all the companies that are supporting the documentary. Yeah.
All- You had mentioned a few, actually. Yes. Yeah.
Most of them. Centra's supported... We work at Centra.
They've supported this documentary, in the documentary itself, and some of the premieres across the country. Yeah. So back to that, is just these sponsors all have CEOs who are also allies, and they are aligned with our mission.
Was there an event or was there kind of a tipping point where there was more of an emphasis on allyship, or is this something that kind of slowly has evolved and percolated? I think it's maybe slowly evolved- Yeah ... the allyship.
I think that once people see the documentary, and they hear about being an ally, then they're like, "I want to sign up. " Yeah. That's something I was going to ask you about.
Is there something that you think stands out that you want people to walk away after watching this to remember? You mentioned some people talking about allyships. Mm-hmm.
Are there certain points in the documentary that you think are particularly poignant or particularly important that you want to call out? Yeah. So, the stories that many women have shared that people can resonate with.
We've had, at the premiere, some people bring their daughters, so it inspires them to join this industry. From that very young age, they look at it, because growing up, I didn't know about this industry. Yeah.
And had I known about it, it would've been something I would've worked towards. I just fell into it by accident. How did you- Yeah.
So was it a friend or somebody at work? So actually, when I first moved to Canada, I was looking for a job, and I couldn't find a job. " And I'm like, "I know antivirus.
Sign me up," because the bills are going up, and I needed a job, being new in the country. And that's how I joined, and I've stayed ever since. What's the state of STEM like?
So full disclosure, 15 years ago, a couple of colleagues and me, when we were at USA Today, worked on a series of stories about DEI. Mm-hmm. This was during a totally different era.
It was during the Obama administration, and we got the ear of Jesse Jackson at the time, and he did a real push into this, in tech in general. Mm-hmm. And the companies responded- Mm-hmm ...
somewhat, I think, under pressure. And they did make moves, but then that kind of dissipated after Obama left office. Mm-hmm.
And I'm kind of wondering, that was a key tenet, was the education system was just... To even be even broader, it didn't push mathematics, engineering, tech, for either sex as hard as maybe it does now. And I'm wondering, has that education system, has it improved, maybe even from the junior high and the high school levels up through college?
Potentially. I don't have children, so I'm not- Oh, okay ... I don't know.
But I would think so. If you think about it, all the kids that are coming out of school, and they want to go to the best schools because they want to go to the best tech schools or schools for science or whatever. So, I think so.
But I'm not an expert in that field by any means. Yeah. Just to add what she said, is representation matters.
When women see other women in different roles- Yeah ... then that inspires them. And when they don't see that, I'll tell you, my niece, there was a program where she saw a female who was a pilot, and she straightaway told me she didn't see that before.
And when she doesn't see representation, she doesn't see that as a career for her. And I think now, more and more women are getting into these roles that even the next generation get inspired to see, "Well, I can do that, too," or, "That is a career for me," which is something that we didn't see years back. Yeah.
I wonder, and we talked a little bit about this before we went on air, the influence of AI- Yeah ... and how has it helped or hindered women in cybersecurity, and whether it levels the playing field. And I think you made a really interesting point about how women are much more aggressive adopters of the technology, from what you've seen.
Yes, definitely. I've done my own research within my own family and friends and network, and I see the women, including myself- Yeah ... even in the workplace- Yeah.
Yeah ... we are adopting AI at a faster rate than the men that I've seen within my own family and network and friends. And this is a skill set that we- Mm-hmm ...
as we're adopting this faster, we're now starting to get ahead of the game in terms of the skill set. And I see that change. It's a big shift.
And my hope, of course, is to make sure that employers see that shift and that increases their mindset to, "Well, let's not hire traditionally. Let's open this up and remove the traditional way of hiring," which is very much certifications, which is about all these different pieces, but let's look at all the different skills that they've gained. And women definitely, like I said, are adopting AI at a faster rate that I've seen.
And personally, how have you each adopted AI? How do you use it, or how is it helping? Oh- We use it every dayFrom- Every day ...
yeah, every day. Like, literally every, even at the workplace, even outside the workplace. So many.
Yeah, we- Every day ... definitely use it every day. Its irony is that, college graduates are having as hard a time as ever getting jobs out of college.
Yeah. Mm-hmm. And you could attribute that perhaps to AI displacing certain types of jobs.
Right. But I also think in terms of cybersecurity, there's never going to be as much demand for any people who are experts in cybersecurity, given what's going on with AI. And this conference, I think, is going to probably drive that home with, I think, the emergence of OpenClaw and just all these incidents involving companies with security breaches that are attributable in some way to AI.
So perhaps that also has an influence. Yeah. I mean, look at it.
The attackers are using AI at a fast rate, too, right? And so that, of course, we've also got to be mindful of that, that they're using it faster. They're getting smarter in their techniques, and that's where, from a defender's perspective, we have to make sure we keep up with it, right?
And remove all the barriers to entry because the attackers don't have barriers to entry, right? Right. Again, get back to your career.
So when you got into cybersecurity, when you first joined the field, what was your impression? Was there a lot of other women who worked in your company or with you at that time, or? No, I was the only person when I first joined.
I didn't see it initially, right, when I joined, but when I did see it was when I was applying for a promotion and for that next role, and I didn't get it even though I was the top performer. And that's when I started seeing, well, I don't look like what the persona is of those who go into that next level. Right.
And that's when I started realizing there is an issue here. There is an unconscious bias that we all need to address. We all have our own biases- Yeah ...
and we need to make sure we recognize them, and that's how we're going to break the issues, the systemic issues that we see today, is we have to figure out what our own bias is and start breaking out of them. Is that addressed in the documentary, like prescriptive measures that can be taken to accelerate the hiring of women in cybersecurity? Are there- It's touched upon- Yeah ...
in the documentary by a couple of different ladies who are in the documentary. Yeah. What are their ideas?
If you could share what they think might reverse course. I don't know what some of their ideas are- Yeah ... off my head.
But it's just generally just showing there's a great story, which I don't want to reveal, but it's just a great story of how someone spoke up, for example. Mm-hmm. Right?
And a lot of us, sometimes we lose our voice, but when you do see something like that, allies can come in and step in- Mm-hmm ... and make sure that it's appropriate to support or call out when something is wrong versus being silent. Yeah.
So- Yeah. It's like an interesting era that we're living in right now. We were talking about all these AI influence layoffs or job tumult, and cybersecurity, I think, might be one of the safer areas, so to speak.
I don't know if you agree with that, but in tech, it seems to be open season on most jobs. Yes. And perhaps in cybersecurity, that won't be as much the case.
We just don't know. But- No ... that also brings me to this other question.
Yeah. I'm mentioning AI because, from what I understand, there is a sequel of sorts in the works to this documentary. Yes.
There is. Yes. And it involves AI?
Yeah. Yeah. There is a sequel.
Part of the sequel is going to be still in discussions around AI because everybody's talking about it, and so there is going to be that sequel coming up. Mm-hmm. Wow.
Tell me a little bit... Oh. Yeah.
We need to promote this. So this is very important. I mean, this is a very important topic.
We've written about this at Techstrong on Security Boulevard website, and something that my colleague, Terry Robinson, is going to be writing a lot more about. And I'm sure she'll write about this if I don't. One of us will write about it, and I want to bring it up on- Thank you ...
Techstrong Gang. It's interesting, the film festivals. Can you mention some of the film festivals this appeared in?
Also, can you share with us how this will reach an even broader audience later this month, perhaps? Yeah. We've actually been doing it...
We've won several awards, too, Best Director, Best Writer, because of showing this across different cities. Right now, what we've been doing is hosting it at different cities, whether it's at a theater or at the AMC. And so we've done quite a few, actually.
We've done close to 20, I believe. All across the country. Across the country.
And Canada. And Canada, too. So we're excited about this because it's now raising more awareness.
It's getting people excited about it. And coming soon, it's going to be on a very big platform, too, that we just announced. Oh, can you- Yeah ...
share that platform? Yes, we can. So it's going to be on Prime.
We just announced it last week, that it's going to be on Prime. And stay tuned because you'll see it by April timeframe. Yeah.
What has the audience's reaction been to this? And is it a kind of split between men and women, or? 100%.
It's a split between men and women. Yeah. Yeah.
And some men will bring their daughters. Yeah. I was going to ask you- Yeah ...
a lot of daughters who go. There are. Yeah.
There have been a lot of daughters. And after the movie, that's what's been so fun is seeing all the promotion, how much they loved it, and just all the activity. They must have felt inspired by it- They have ...
and encouraged. Like, we've got so many. After each documentary screening, we've got feedback, people posting on LinkedIn- Mm-hmm ...
about it, taking pictures, and sharing their overall experience. And this is a great way to celebrate the women who have made a big impact in our industry. There's 21 of us in the film.
And it's a great way to celebrate these womenIncluding other women who are going through the same journey. " They've never thought about it. Mm.
I heard daughters saying, "I didn't think this was a career. " Mm-hmm. " Which, the one thing you also had mentioned earlier was build and retention.
Yeah. Could you maybe go a little bit into that and kind of where that state is? Yeah, definitely.
I think you were talking about the retention, I think. Yeah. So the focus has been, let's hire more women, which is fantastic.
So we've seen that change and we're seeing we're now at 25% women in this industry. We need to accelerate that change. But what happens when you bring the women in?
Let's start looking at the next step. How are you going to grow them? How are you going to promote them?
How are you going to get them into these senior executive levels? Because the numbers go down as they go into that executive level. It goes to less than 10%.
Mm. And that's where the issue is. If women find that area where they can't grow anymore, they'll leave.
And that's one of the things we've got to fix, fix that broken rung, which is help women, and champion them, so that they can go into that next stage. Give them that opportunity. Remove your own bias so you can hire more women into that next level.
That always seemed- Allyship ... Oh, sorry. I think that's what- Yeah ...
allyship with men, because mostly there's men in those roles- Yeah ... where they could help promote women. Yeah.
It'd be interesting to see how the ecosystem works as maybe more women start companies that- Yeah ... kind of they hire more women to work within those companies. I remember that dynamic playing out in tech to certain extents.
But it always came back to the numbers were specifically low in terms of the C-suite. Yeah. Yeah.
And I think they still are in tech. They still are. Yeah.
I mean, dramatically low. We do in the documentary... Not in the documentary, but we do have one of our sponsors, for the next couple of days, she's a first-time founder and CEO, female.
And so we're happy to have her company- Yeah ... Schematic, with us on the documentary, or at the sponsorship. So I don't want you two to talk on behalf of Yvette, but I'm going to ask you, what was it that prompted her to want to make this documentary?
Had she made documentaries before? So she wasn't making the documentary, she's sponsoring, right? No, he's talking about Yvette.
Oh. Oh, Yvette. Oh, Yvette.
The director, yeah. Oh, Yvette. Yeah.
So I'm wondering if this is her first documentary. And I mean, for- Yeah ... I even think about, let's go back to the Oscars.
I was kind of blown away that the lady who won Best Cinematography was the first woman to win cinematography. Yeah. Yes.
I found that almost hard to believe. Yes. And I'm wondering if that's kind of the same case in terms of documentaries and what spurred your director to make this.
Yeah. So, the producer was the one who had the connection with Yvette. Okay.
And so, she aligned with the story, and she did a phenomenal job directing this documentary. So it was aligned to what she enjoyed doing, and she's done a phenomenal job. Yeah.
So I'm going to ask you, I think we've promoted the documentary. We'll promote it again before we go off. Yeah.
Thank you. But, well, I was going to ask you about the show and what you're looking forward to at the show. Were there any type of topics or type of products or type of areas of cybersecurity that have your interest?
Yeah. I think obviously you want to hear what everybody's up to. Obviously, we're going to hear so much about AI- Mm-hmm ...
but also new product announcements, new mergers and acquisitions. That's what I'm interested in hearing about. Yeah.
It's good. Am I complimenting Stewie? Yeah.
Yeah. Is there anything in particular that you're- Yeah, no, I just want to add that's basically like with the conference here, super excited about just meeting lots of people and- Awesome ... hearing where they are.
Awesome. Yeah. " Documentary.
Tuesday and Wednesday, 24th to the 25th. 4:45 screening for each day? Yes, for each day.
Drinks and popcorn is going to be included. Oh, nice. Yeah.
Cool. So there's going to be networking from 4:00 to 4:45, so come early. Yep.
And save your seat. Make sure you register, and you can find us at our booth. At our booth.
The Centra booth, which is 4607, so you can register and secure your seat. Okay. And it's going to be at the AMC Metreon 16, which is near Moscone, you said?
Yes. Right across the street. Fourth Street.
Yes. 135. You can't miss it.
I think it's right off of- Right here. Yes. Yeah.
Right across. I can literally see it. Literally walking distance.
You can get right there. So if you can get to Moscone South, you can find the theater. Yeah.
Totally. Thank you so much for your time. Thank you.
Yeah. You guys were great. And I look forward to seeing it.
Yeah. Good luck. Hope you can make it.
Yeah. I'm going to make it. Yeah.
Yeah. You should. Yeah.
Definitely. I was part of a... I told you this earlier.
I shouldn't say this, but I will. Who cares? Okay.
I was part of a documentary about cybersecurity a long time ago, and I was one of the talking heads, and I am ashamed to tell you that there were maybe 20 talking heads in that documentary, and there was maybe one woman. One woman. I know.
So- Yeah ... hopefully we've kind of reversed course and flipped the switch. Yeah.
Yeah. No, I'm excited. Yeah.
I'm super excited about it. All right. It's going to be good.
All right, thanks. So we're going to have more interviews coming up later today, and very soon, actually. I'm Jon Swartz with Tekstron Group, and thank you for watching.
Hey, everybody. Welcome back to Amsterdam. We're here at the KubeCon + CloudNativeCon Europe Conference with my new friend, Dirk.
How you doing, Dirk? Nice to meet you. Very well.
All right. We're having a little chat about cloud operations. We're at company's emma technologies.
They're an up and coming player in this space. But before we get started, what is happening with cloud operations in general? Because it used to be kind of we managed all these clouds in isolation, and maybe are we starting to unify this a little bit, and what's driving all of that?
Yeah, I think it's a good starting point because when you look back in when emma was founded in 2021, it was still different clouds. Multi-cloud very often happened by accident or by acquisition. There was no deliberate choice.
Now fast-forward five years and multi-cloud is actually there. It's a consequence. It's because companies need to have solutions.
They need to have solutions for sovereignty. They need to have solutions for AI operations. They need to have solutions for whatever business needs they have.
And with more players next to the hyperscalers coming into the marketplace, there's more diversity, there's more complexity, there's more fragmentation. And that's also where emma comes in as a cloud operations platform where we unify the operations across those platforms or across those players in the cloud industry, including on-prem and including the cloud industry. Mm-hmm.
And it seems like what's changed too is organizations are more comfortable with putting workloads in different clouds in different places, and there's also even a movement in some cases back to on-premise because of AI. Yes. So are we making more deliberate choices about where workloads go, and it's not just kind of this...
I guess for a while there, I felt like the cloud, what was the question? It was the AI kind of thing. Yeah.
I think cloud's a more strategic choice these days. When you look at sovereignty, for example, it's a boardroom topic. " And then, of course, the teams have to figure out what does it mean, what kind of level do we need, what providers do we need?
Where do we go? Can we stay with hyperscalers? Do we need European providers?
Do we need to go back on-prem with certain things? So that is the complexity that is happening, but the choices are definitely more strategic, and it's coming not only from regulatory, so sovereignty, it's coming also from cost pressure, and it's coming also from every other things and not to the least, cloud skills. Different providers, different skill needs, not enough experienced professionals on the marketplace.
So that means also where choices happen. I always felt, too, that people didn't fully appreciate the total cost of hiring different teams to run different cloud platforms because the labor was still the most expensive part of that. Yes.
So have you seen people get a little savvier about understanding where their costs come from and how to streamline the management of multiple clouds as a result? FinOps is one great example that's came up, and it's evolving very rapidly, going from traditional cloud operations into other sectors, including also then AI. That is quite clear.
But, yes, there's a lot of discussion around how do we make this happen. The new needs of the ways organizations operate in terms also from experimentation in AI, going into production of AI, need more resources, need more orchestration of what they are doing. They need also more control over what they are doing.
Cost is one part of that. There's more cost savviness already today, and also that drives decision. Do we need to keep these kind of applications or models and data in these data centers or these providers or are there more cost-efficient alternatives?
But of course, always without having any compromises on performance. Mm-hmm. Now we're here at the show, and as I understand it, you guys had an announcement here talking about support for brownfield environments.
Yes. So what does that mean exactly? Well, emma was traditionally a greenfield platform, so customers came to us deploying their resources infrastructure through emma into providers.
But the majority of companies, a large amount of companies, still have their applications and data running on-prem. That's also what we said, you can't manage only part of your environment. You need to manage it in a unified way, coming back to the unification world.
So that's why we announced brownfield onboarding, which will allow our customers and companies to bring in their accounts from GCP, Azure, and AWS, gain the full visibility without migrating their resources. It is about discovery. It is about governing it.
It's about making informed decisions and starting also to pave way into do we need to stay with certain applications with our current providers? Can't we see where cost-effective alternatives are that don't compromise on performance? And how do we go from provider A to provider B to fulfill current needs or future needs of the business?
Do you think there'll also be more migration of workloads? I feel like historically we deployed something, and we left it there because we were afraid to touch it. But I wonder if, to your point, as people evaluate the costs or the needs of- Yeah ...
the application change, will there be more migrations? Yeah. I think migration is a data cost question also.
It's how do you move data from A to B? We see this from conversations we have with partners is, well, if you as a neo cloud, you want to gain more business, you need to get more applications and data from others. But how do you get the data in without your customers paying too much for the egress?
Well, emma has a solution also. We are probably the only solution in the space that has its own multi-cloud networking backbone. So we can allow customers over our backbone to transfer data at one third of standard industry prices around.
That would facilitate, enable... the data migration, but again, that's a business decision if that needs to happen or should happen. You can't walk down the show floor without somebody leaping out to tell you about their great new AI thing.
What impact is AI going to have on cloud operations and the way we should think about this? I think as everything. As everything.
You can't do without AI anymore in your daily work. I'm a marketeer, so even in marketing, you work with your AI, your agents, you're trying to get more your productivity up, without also compromising on quality of what you do. In cloud operations, it's going to be the same.
AI ops. It's not only operations for AI, but it's also how do you make your operations smarter? How do we get the algorithms predicting more?
How do we do things that we help the people who operate cloud environments with AI? So that's also for me, the philosophy of AI is making people smarter and do more work as they did before. And I think part of this conversation too is we're running a broader range of workloads.
Mm-hmm. We're going to have AI coding tools creating more software than ever, but this team isn't going to get any bigger that manages the infrastructure in that environment. So is part of this issue, the math around how do we make an existing team, enable them to manage IT at a level of scale that not too long ago would've been unimaginable?
Yeah, but that's also where Emma comes in. That's where we also look at when we talk to people on platform teams, how they need to manage their infrastructure. They have a lot of work with that.
So for us, it's like, well, you do your need to work, you develop your application, you do your coding, and you use Emma for the deployment of the infrastructure. That's what Emma today does already automatically. And we are also looking into how can we deploy agentic AI to make that even more smoother for the users of the platform.
Nice. As we go forward, are you seeing the roles of IT people change? Because historically, we always had like, there was a virtual machine specialist and a networking specialist and a storage specialist, and is that converging more and what is the future of an IT organization look like to you?
Difficult question. For me, always when I look at how organizations work and there's the future of work thinking is, you have the specialists, you have the generalists. Emma is a no-code platform, which means also it can be used by business people with a non-engineering background.
So that makes also that you can use a more diverse working population and profiles in your operations, and that is how also how it should work. Democratize the technology, make sure that non-engineers can use it, but with the necessary guardrails, with the necessary governance, which comes on top of that. Right.
You of course, have a platform that in my mind works horizontally across different platforms. Mm-hmm. When I talk to IT people, they often are attached to a particular management tool because it came with the product or the service that they're using.
" Yeah. " Yeah. " Mm-hmm.
" You can spin up the environments. You do not need the qualification skills for that second environment because that's what Emma does, the abstraction layer that helps you to spin up the second environments, and forth. So what's next for you guys?
Where are you going from here? Where are we going from here? Well, Brownfield was our first step.
I think there's going to be more and more around AI, how to make this happen, how to help customers to not only find the right resources they need, deploy what they need, and how to work this, and make sure that all of these things happen all within the sovereignty in mind. It's data, it's running, it costs money, it is putting companies at risk. So we are going further in that direction.
We also have our own infrastructure in Luxembourg's data center because that's also required. There's scarcity and we can also help our customers with that. So we try, we want to be the most versatile platform on the market that allows cloud operations in whatever directions our customers want to go.
Mm-hmm. One of the things that we've been tracking is the rise of platform engineering, but it's one of these things where every second person that I talk to about it has a slightly different definition of what that means. Yeah.
From your perspective, what are you seeing? Are you seeing more of these teams and what are they focused on? Yes.
The internal developer platforms, a lot of companies have that, but you need your team of developers to develop it, to maintain it, and that's not always that easy. And that's also where we say, "Well, you can have similar capabilities with Emma off the shelf," but platform teams, yes, they prefer to develop their own solutions internal and maintain this internally. That's how we have the conversations also where we come in as alternative to existing platforms today.
So what's the biggest challenge that when you go talk to these customers, that they're sharing with you in terms of their pain point? What is it that kind of is keeping them up at night? What keeps them up at night?
Cost is oneClearly, you in Europe, here in KubeCon, for the first day, there's also sovereignty on the agenda. Yes. So for the European organizations, that is definitely a big point.
And mostly it is not one or the other, it is a combination of things. How can we do the right thing without neglecting something else? How can we do AI without paying too much or jeopardizing on sovereignty?
How can we be sovereign in our operations without losing the innovation potential that we had before? So how do we make this happen? How do we operate this?
How do we orchestrate this? All right. Well, folks, you heard it here.
Change is hard, unless, of course, you got the right platform. Hey, buddy, thanks for being on the show. Thank you.
All right. And we'll be back in a minute. Hey, everyone, it's Alan Shimel from Techstrong.
We're going to continue with this fantastic series we're doing of sessions between some of the leaders at Microsoft, as well as analysts from the Futurum Group. In this next session, we're lucky to have Clay Wesener. Clay is the Partner for GPM Power Apps Studios at Microsoft, and Futurum analyst, Keith Kirkpatrick.
In today's session, it's really a customer success story where Clay, joined by Keith, are going to delve into a real-world customer story, in this case, Wells Fargo, offering a blueprint for leaders ready to scale success in the age of intelligent apps. You're going to see how Power Platform is being used to modernize complex, regulated workflows with Copilot Studio agents and Power Apps. This session will highlight architecture, business impact, and lessons learned from deploying intelligent apps at scale.
I think it's really a great session you're going to enjoy. Let's go to Clay and Keith. Hi, I'm Keith Kirkpatrick, Research Director with the Futurum Group.
I cover enterprise software and digital workflows. Hi, my name is Clay Wesener. I look after our low-code developer experiences on the Power Platform.
Well, thanks for joining me today, Clay. Maybe, Clay, you could talk to me, though, a little bit how Power Platform can actually help these organizations balance that agility to handle these types of scenarios with their compliance needs that often come up when you're dealing with things like banking or insurance or any one of these regulated types of processes. Yeah, absolutely.
And within the product, we sort of refer to this as managed platform because it is very much a feature of the platform of how you can govern at this scale. And this has come from not just us deciding exactly what's going to be in there, but really folks and customers leveraging low code over the last 10 years and evolving to have a really, really strong governance. Because I think we learned very early on in the journey that if those guardrails are not there, people are just inclined to want to turn it off.
And I use the word guardrails deliberately, and a lot of the things we do in a managed platform is focused around how do we give you the right controls so you can still enable these types of tools, whether it be building apps, building automations out at scale, but do it in a way with the right sort of controls and guardrails on it. And so examples are things like data loss prevention. So I can set rules around what connectors and what data you can access versus someone else.
And so I can also say how many people you can share an app or a workflow or something with. So I can sort of mitigate the risk that you might be able to have working in low code versus someone that's received more training or onboarded to the platform. And so typically what we see customers do is sort of implement this zoned approach of their zone one is everyone in the organization, and they say, "You can build apps for personal productivity, you can connect to your office data, you can sort of work with those well-known sources, and you can go and share apps and flows and agents with up to 10 people," as an example.
"But once you want to go beyond that, we want you to engage a little more with IT. We want to make sure things are supported. " And then what typically happens is we'll then have a zone two, which is potentially some more sensitive data, potentially ability to share with more people within the organization.
" And then that final zone would be your IT, your dev center, who's working with your really critical data around things like finance and HR. powerautomate, and start building, and they're not going to fall into a trap there. They're going to fall into the pit of success because we've put those right guardrails on what they can access and what they can do.
If you look at not just if we're talking about, let's say, agentic technology, but just everything. If you look at-The development of the smartphone, everyone expects sort of a consumer-grade experience throughout all facets of their life. And I guess that, do you see that sort of pushing or helping to evolve kind of what customer success might look like, not just now but into the future?
Again, earlier in the low-code journey, it was always IT departments, development teams that were looking at the low-code platform. And more and more these days as we're talking to customers, it'll be their employee experience team. It will be folks responsible for actually healthy and productive employee experiences.
And that's what I mean. It's not just about cost saving, but it's about bringing the right tools in. There's the SNCF, the French railway, are actually a really good example.
They run Power School, which is an onboarding school for the whole Power Platform when any new employee starts. And this is becoming a really, really common practice that more and more folks are, as they join an organization, they're getting training on these tools, not as something they have to use to do their job, but as a benefit to them to be able to do their job in a more productive way. And I think, again, the consumer push and acceleration of AI is just accelerating that within the enterprise as well.
Right. When you're talking about human in the loop, you raise a really good point because ultimately this is still new technology and you want to make sure that particularly in, you're dealing in a commercial environment, that you don't want this agentic technology to sort of run wild or unchecked. So I'm just curious if you could talk a little bit about, have you seen other examples where customers have actually deployed their sort of checks and balances to make sure that their technology does what it's supposed to?
Yeah, absolutely. And there's a couple of ways we're seeing folks doing that. One is just in how we define and build the agents and the tools themself.
While that agent has the ability to issue refunds, it can only do them up to 100 pounds. So it has very specific guidelines built into it that once it goes over certain criteria, loop in a human, send them an approval workflow so that they can approve this, review the details. So that first one is just very structured, giving the agent details.
The other side, and this is where we've sort of really seen how apps have evolved in the last couple of years. If you've been looking at what we've done with Power Apps, we've introduced this concept of an agent feed, which is really about in the same UI that you would come into the app and do your day-to-day work, you start getting this feed of activity from the agents that are in your digital team, effectively. And so you can start seeing where they're completing actions, where they might need assistance, or where they're getting blocked.
And so what we're starting to see there is even our UI patterns of what we traditionally thought an app was, is starting to bring in this agentic behavior to give, you know what I mean, that human in a loop and that oversight capabilities. So I still want someone to have a really clear view of what tasks are being completed by the agents, what's being completed by AI. And in that view, be able to get into the reasoning, understand the logic, and sort of the thought process that the agent followed behind it.
So it's not a mystery of why something progressed or why an action was performed. But as the human responsible managing that team of agents, I can effectively go in and see why it did something that might be then come a teaching moment for the agent where we correct that behavior or change it for future cases as well. Well, it's really interesting you mentioned sort of the generational shifts that are going on.
We're seeing the entry of these, I guess you'd call them AI natives, coming into the workforce where they don't know anything other than a world with AI. And I guess that kind of begs the question, we've heard so much about AI in the past, particularly the last couple of years. Can you talk to me a little bit about what role can AI actually play within customer success?
Because it's a wide, AI has so many capabilities, but I'd just be curious to see if we could boil it down to this function. Yeah. And I think it honestly depends on the customer and how they're approaching it.
One of my favorite examples of, I think, sort of scale and pace, PG&E here in the United States, they're a big Power Platform user, and we talk about scale. I think they estimate since they started their journey in 2021, along the lines of, like, $38 million in savings that they accrue to the Power Platform, like, huge in terms of scale. But so much of actually what they've implemented is not just cost efficiencies.
They introduced an agent called Peggy, and they actually have a nice little avatar for Peggy that they introduced across the organization. And Peggy now handles, it's between 30% to 40% of their IT help desk calls. So built in Copilot Studio, Peggy has access to their knowledge base, all their policies and documentation.
And just Peggy, one agent, they estimate saves them about $800,000 a year. And it's- Wow ... it's absolutely transformational.
And so even with the savings they were getting on the Power Platform between apps and automation, there is a limit. Mm-hmm. There's a limit to how much productivity that that can drive.
And you look at, again, someone like PG and E, when they implemented Peggy, it was very simple, looking over knowledge bases, access to information. It helped a large volume of sort of tickets that would come through the help desk that used to be a human replying to an email or replying to an IM. Those humans now are actually providing much higher quality support on more technical cases.
They're not helping someone log into Citrix for the first time or point them to something that's really well-documented. Peggy's able to do that. But then they've also continued to evolve it over time.
And so again, one of my favorites that Peggy can do is getting folks that get locked out of their SAP accounts. One of the most common things that IT, apparently happens thousands of times. And now Peggy, using an integration between Copilot Studio and Power Automate, can actually open up SAP and go and unblock that person's account for them after they interact with her on Teams.
And so this was something that was critical to an end user to get unblocked really, really quickly. Peggy's able to do that for them fast. But it wasn't high value from an IT support team and what they were really providing, them going and opening up an account and unchecking a blocked checkbox.
And so I feel it's a really good example of where they started simple. They focused over sort of knowledge base examples. They evolved it into actions, but it's something where they've gone for a high volume, cost-inefficient area.
They've applied agentic AI to it, and that's something that go back three or four years ago, would've been an extremely expensive tool to go and implement. Leveraging LLMs and leveraging Copilot Studio, they've been able to do all that in low code, which is super impressive. I'm curious, one thing, Clay, that you alluded to earlier is if we think about how apps were previously developed and rolled out, it was IT who kind of managed that.
Now, what it sounds like what you're saying is we're getting to the point where business leaders or even folks who are working within departments may be able to actually launch apps or launch agents, obviously, with that human in the loop and with those specific guardrails. Are you seeing any kind of patterns emerging in terms of customers who've successfully scaled this agentic automation for more of a grassroots approach as opposed to springing from IT? Yeah, you're absolutely right.
We sort of see an approach from both directions and some customers very deliberately approach it from one or the other to start with. I actually feel like all the examples I've sort of talked about today do quite well balancing both ends of the spectrum. And I think that's where you start getting the real value multipliers.
PG and E, great example. I talked about Peggy earlier. That's an IT or centrally led tool.
It was about optimizing a process within the IT team. But at the same time, they have thousands of developers across their organizations. And when I say developers, I mean low-code citizen developers that are enabled to go and build apps, to go and build agents, to go and build automation across their team.
And they've sort of very deliberately focused their center of excellence, their digital transformation team, on a few core objectives. So that's the team that sets their governance policies, makes sure it's scalable, and then they also support and train those different sort of divisional leads across the company. PG and E actually, again, I think they're on the end of the spectrum where they're doing this in a really amazing way.
They have a conference every year called Level Up Now, where they actually get together all their citizen developers and those divisional leads from across the company to come together, share stories, share learnings, and sort of explain new technology. But it starts becoming a real cultural tool in that they're enabling people to go and solve these problems, make themselves and their teams more efficient, and there's reward that comes from that. They're getting folks together, they're getting a lot of learning.
And so I think, while lots of companies are enabling citizen development, the ones where we see it's truly being successful, they're bringing this level of evangelism to it. Well, Clay, maybe you can talk a little bit about some of these platform features that are kind of critical for managing customer success initiatives, because it really seems like, obviously, you have the human component, but there's also the technology side in terms of making sure there are the right tools in place to help organizations address all of these issues. There's obviously the human, the technology component.
I would also say there's just the practices and sort of learnings. We actually have some good documented platform guidance out there of what are the best practices in thinking about this zoned approach that I was talking about and in how people can sort of apply different levels of control to different parts of the organization. I would say then we start looking at the specific technology.
One, a lot of those guardrails just light up directly in the product. So as a new citizen developer, as a maker, when I go land at any one of the power platform tools, I can get welcome guidance with links to internal learning, explanations of where I can go to support. I get routed to my own personal developer environment.
So I actually have a sort of controlled, dedicated environment for me to go explore in, to experiment in. I'm not sort of working in prod. I have the ability to be controlled.
Pipelines, which effectively are a low-code ALM tool, so that once I do build something, I can either use it for myself and my personal environment, but if it gets to the point where it does make sense for it to be deployed somewhere centrally leveraged by others, I can go through an automated deployment process where the right checks go. I have an AI advisor that reviews my code, makes sure my apps are secure and performant and accessible, and then get the right approvals before that gets deployed. And it's really that mix of we want to democratize, we want to make these things available to everyone across the organization, but then have these right built-in tools so that you don't have to go read a wiki to find out what's the process that you should follow.
It's built-in to the developer tool. So I kind of just, as I start building, get guided to the right environment, I get guided to use the right data, I get guided to share it and deploy it in the right way. And all of that we bundle up and sort of leverage within that managed environment, which gives the admins, the IT, the central digital teams that control centrally to sort of set up those tools and that content that they want available across the organization.
It sounds like all of these tools really underscore what you were talking about before, which is this culture of trying to utilize technology in a way where it's deployed at the right time, in the right space, and with the appropriate guardrails, but while still fostering a culture of experimentation and ensuring that people feel empowered to use these new tools. You're absolutely right. I think when we talk about your first question about what's the new definition of customer success, I think it's the customers that have implemented the right culture and it feeling like it is a culture of empowerment and experimentation, you know what I mean, not something that they have to fight really hard to get access to.
Because that's where a lot of these examples where we have customers turn around, they've built something that's ended up saving them millions of dollars, it came from the expert that was involved in the business process. It didn't come from a central team. And to get that creativity and get that ideation, you need to give people access to these tools.
" And I think so will users, so will makers, they will find a way. And to restrict these tools, to hide them, folks will go find a tool on the web that can help them be more efficient in their job. The companies that are doing this right are making it part of their culture to provide those tools and just really enable people from the get-go.
The technology is probably going to be more accurate over time if you're talking about trying to really assess images and differences between them. But one of the other things I'm really curious about is how can agentic AI and all of this technology be used in regulated industries? I'm thinking in particular financial services, banking, insurance, where there's a lot of complex process, but you also have to be mindful of all of the regulations that are attached to those industries.
Yeah. And it's actually quite surprising, I think, in this technology shift with AI compared to when we moved to the cloud, compared to internet, compared to a lot of the others, I think actually the regulated industries have actually been quite a lot of the front runners on this. EY, for example, built PowerPost, which helped them with their financial processing, sort of end-of-month processing.
They built this as a sort of typical low-code application. They're already looking at how they bring agentic checks into it to make sure that things are being posted in the right period, that they have the right information. Again, time-consuming sort of manual checks.
Wells Fargo have rolled out agents to more than 4,000 branches. You know what I mean? A huge, huge number.
And they targeted a process that was around their branch forms and procedure management. And this is something that was particularly time-consuming, so if you went into a branch and said, "I need to set a power of attorney," or, "I need to open an account," under maybe a non-traditional circumstance, there's a huge amount of internal documentation around those procedures, the right forms, the right information to collect. And before, that would mean as a customer is standing there with the branch member, they're looking up that information, trying to go find the right procedure, going to find the right form.
So a heavily regulated scenario, but also really impacting a customer who's literally standing in front of you waiting, maybe on their lunch break, trying to get through the bank really quickly. And so they rolled out an agent across all their branches to actually manage that forms and procedure scenarios. And so that now in the branches, those employees are jumping straight onto an agent, talking about the scenario that the customer has, and working with this agentic AI to basically get guidance on the right forms, the right procedures to follow.
Even in these regulated industries, they're seeing the value in AI, and I think it's more about how they do it, making sure they have the right checks in place, making sure they have the right guardrails, rather than what they probably would have done five years ago, where they just tried to turn it off. We talked a little bit about potential friction there, but are there any other sort of potential hurdles that organizations need to be wary of? And what's sort of your take on a solution?
Like most things, we talked about human in the loop. Making sure you introduce this technology in the right way to organizations is really, really important. I mentioned EY earlier.
They were really, really successful in after building PowerPost, which helps them manage their sort of end-of-month financial processing. It simplified it. It brought in some agentic behavior to validate quality.
And they had huge gains in efficiencies in both. I think it was 70% in sort of the time, or 95% in lead time to get things posted, and about a 35% cost saving for them. So real sort of impact to the efficiencies of their users.
But what they did really well was once they built that tool, they told that story. They evangelized it. And so they helped people understand that this is how this technology was helping them.
This is how it was implemented. And that not only made, obviously, people a lot more receptive to onboard and leverage the technology, but it also started driving this ideation of other things to go improve within the organization and using similar technology. A lot of these companies are not coming in and doing a full low-code approach of apps and agents and automation and reports all on day one.
Where we're seeing folks be really successful is they're leveraging the composability of the platform. They're starting with, for example, they might have a legacy application that's inefficient for a user. So they go and use an app.
They build more efficient, streamlined UI over the top of that. That's an incremental solution they can deploy, they can get out to their users and start seeing benefits. Then on that same app, they can go and add automation.
They can start getting approval workflows. Then they can start bringing in agentic AI, getting that automation and that AI behavior incrementally building these solutions over time. And it's very much intentionally how we've designed the platform in that these are not all or nothing solutions.
And back to our earlier conversation, pace is extremely important these days. And people don't want to go do a 12-month waterfall project of every requirement met. They want to find ways to incrementally build.
And by leveraging a platform that has common governance, these tools are designed to work together, apps with automation, with agentic behavior integrated into Copilot with that unified platform. So essentially, you're setting up a framework to enable organizations to really drive these best practices in terms of making sure that, yes, you are implementing new technology, but you're doing it in a thoughtful way where you have the right checks in place and you really are making sure there's other things that you need there. You need the audit trails.
You need to make sure that when you do a project, you're going back and you're actually assessing, does the technology achieve the goals that we set out to when we deployed it? Exactly. And I think it's that there's two parts to it.
One is that being proactive. So as you're releasing a new app or a new agent to the organization, do you have the right controls around it, the right guardrails from the beginning? And again, our goal is let's have the right framework, the right tools, the right guidance to go really enable that and let an organization tailor those guardrails to sort of accommodate their level of risk, what they're comfortable with doing.
But then on the flip is make sure we just have the right visibility, the right auditability, so that as you're leveraging AI more and more within the organization, it's really transparent about what it's doing. I think one of my favorite things with Copilot Studio, and Pets at Home is a great example of this, as it's interacting with customers on customer service. You can go into any step through any sort of run or action the agent has performed and understand its thought process.
Why did it do this particular step? What were the inputs? What were the outputs?
What were the reasoning? And not just understand it, but then also help teach it to handle sort of moments in a different way in the future. And I think having those sort of tools from a governance perspective just built in, again, we talk about it being unified for the developer, unified for the end user, but also for the admin, so that they're doing in this sort of a central and controlled way.
And even then, whether you're building an app, an automation, an agent, you've got that composability across the platform. But I don't think admins really want a super composable admin story. They want that to be a lot more unified and controlled.
So, it's bringing the blend of those worlds of let's bring together multiple technology, multiple tools, but make sure then you sort of have one central view of how it's all coming together. If you want to really drive the use of new technology, you need to do it in a very stepwise fashion using a platform that allows you to unify people, processes, technology. It doesn't make any sense to try to do it in a very disjointed way.
You won't have the governance required to do it safely. You'll confuse people in terms of which tool should I use, which approach should I use. Ultimately, it really does matter to make sure that you have a unified way of approaching the implementation of new technology.
It's also really critical to make sure that as you go about your journey, whether it's implementing low-code processes, implementing agentic technology, to have a clear understanding of your business goals. How are you going to measure them? And then how are you going to take all of these different learnings and then streamline it so you can actually apply it and scale it over the enterprise, not just for today, not just for tomorrow, but well into the future.
And finally, I think the most important thing that kind of resonated with me today is you need to look for a trusted partner, trusted technology partner, to help you through this journey. Agentic technology is very new. Low code, yes, it's been around for a while, but there are still quite a few pitfalls that can be out there.
To go it on your own can be very challenging because you have all of that risk of potentially opening yourself up for errors, missteps, and of course, there's that, we talked about it a little bit today, regulatory concerns. It makes a lot of sense to partner with a company that has experience working with other enterprises to deliver these types of benefits using that new technology. Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group.
Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard YouTube channel, Techstrong TV, and every one of your favorite podcast platforms. Let's meet today's panel before we jump in.
They're my favorites. They're the people that you know and love from this podcast, starting with Mitch Ashley. Mitch, it's good to see you again.
Always good to be on. Just recouping, uncompressing from RSAC, so I'm not quite as tall as I used to be, but I'm working on it. I swear that process takes more and more time.
It couldn't have anything to do with the fact that I'm getting older. It must be that RSA is just getting bigger and bigger every year, right? Could be us, yeah.
Well, we need a third opinion. So Fernando, it's good to have you back. Are we getting old or is RSA getting bigger?
And don't say both. Por qué no los dos? Good answer.
The little meme. Yes, and RSAC is, I think size-wise, so on that happy note, as we record this, Mitch and I just published last week our event note on RSAC and a lot of Futurum's research is public, so that's one of those pieces. So our full note is out.
And to answer your question, I think that we've been, you ask are we getting old or are we getting bigger? A little of both, and I would say that as far as event notes are concerned, this one was the one where I wrote that I was probably the most old man yelling at cloud vibe for what I wrote. Mitch did a great job, but I was the one basically complaining about AI and agentic and all those things.
" Exactly. To be fair, I'm a huge proponent of the technology, but people, let's use it properly. But the other thing is that on the getting old and whatnot, I had a very embarrassing flat fall, bum, on the sidewalk running from meeting to meeting to RSAC.
That can be dangerous, too. Yeah. Basically, I tripped on the curb, and I didn't fall face first.
I know how to fall kind of stuff, and that was okay, but it was so embarrassing. " So that's your martial arts training. Yes, exactly.
You know how to fall. I know how to fall. But yeah, it was just bad.
Unfortunately, bruises to your pride take a little bit longer to heal, as we'll talk about in just a minute. Yes. Anyway, but to answer your question, I think it's a combination.
Por qué no los dos? But it was an amazing week. I'm happy to have worked with both of you gentlemen in there, so it was lovely.
Well, my name is Tom Hollingsworth, as always. I am the host of Security Field Day, as well as many other things around here. And we had a fun topic that we wanted to jump into today, because I don't know if you guys realized this last week, but in the US and many other countries over the world, it was April Fools' Day.
April 1st, the time when you can trust no news on the internet, save for the Gmail launch, which was the greatest April Fools' joke of all time. I will not be taking questions. However, some people over at Anthropic were not so happy about the April Fools' holiday because they had a little bit of a problem that came up, and we're still going to be dealing with the fallout from this for a while.
It involves a new intersection of cybersecurity and AI and the human interaction between all of it, and some good old-fashioned data leakage. Mitch, I'm going to toss this to you to kind of give us a quick overview. What exactly happened to our good friend Claude, and why has it got everybody so crazy right now?
Well, it's interesting. It is a data leakage problem. It actually happened on the day before April Fools', on the 31st, and that was some of the confusion is like, is this notice about this event real?
And some of them were, and some of them were jokes, but actually turned out to be real. So essentially what happened was Anthropic accidentally shipped a debug source file, it's called a map file, in their Claude code NPM update on the 31st. Now, what's a map file?
A map file is something gets produced when you build code that helps you debug it when you're testing. It's kind of an internal document, but it has a lot of very useful information in it, like feature flags that you can turn on, things like that. And that map file actually pointed to a public Cloudflare bucketThat contained the full code base, half a million lines of code.
About 2,000 TypeScript files were exposed. So in other words, the crown jewels are laying out there for the whole thing, right? The current version of what this is, sitting out on a Cloudflare instance that gives that away.
So, everybody's NPM did their nice little jobs of downloading, updating their Claude code, and not everyone, but certainly a hefty number of them. So all of a sudden now we have source files out there. And an intern at Solair Labs, I don't know them, but posted it to X and mirrored it globally.
So they had 41,000 GitHub forks before the takedown notice came. So, that's internet speed, right? P**f, all of a sudden everybody's got this code.
So it's permanently in the wild. Once it's out there, once it's on the internet, it's like those photos in college or whatever you put on Facebook. Once it's there, it's always out there.
It's exposed. So the full Claude code architecture is fair game now for attackers to tear apart, understand, figure out ways to attack it, hack it, insert bad stuff and malware, whatever it might be, Trojans, et cetera. So it's more than a black eye.
It's more than a oopsie. It's a, hmm, I can't use this word on our podcast, or I could, but I won't. But I'll let you use the word.
" Yeah. It is a big oh s**t moment. Because when your entire code base gets released, that's a tough thing to defend against.
And, so I'll leave it at that. Lots of places we can take this, but this is the ultimate supply chain attack when you essentially open your kimono on the supply chain. And they did.
And people raced to download these files to get a peek at what was going on. Stephen Foskett, who is another part of Tech Field Day, but also heavily involved in Techstrong Gang, was telling me that he saw dozens of projects that had sprouted up that were using that code as a base to do a lot of different things. Which leads me into my first point of, there's some questions around what this really means.
Because the first thing that happens is anybody knows that if a closed-source project's code gets leaked, one of the immediate things that happens is that people have to figure out exactly where that code came from and what kind of liability they can get. Because, I don't know if you guys know this or not, but intellectual property is something you can sue for. I kid, but this is actually a really famous case from companies like Nintendo, where parts of their internal source code were leaked, and they were incorporated into emulation projects on the internet that were then forced to be taken down because that code taints every release afterwards if you can prove that there was any of that code in there, because Nintendo owns the copyright for that code.
But where this gets a little interesting, and this is the first point I want to talk about, is the assertion from Anthropic that large portions of Claude's code base were written by Claude itself, the inevitable vibe coding, if you will. But one of the things that we've seen, and Mitch, you brought this up during the pre-event pregame that we did, US copyright law requires the copyright to be assigned to a person, not a agent, if you will. So are we going to be in a really weird legal situation for at least a little while, where Claude may not be able to have copyrighted...
Or, I'm sorry, Anthropic may not have been able to copyright Claude's code because it was written by Claude and not a guy named Claude? " So it's actually in the source code in a lot of the documents that it produces. So it certainly creates a gray area, and also sort of the worst case could be somebody uses, and probably will, one of these 41,000 or more downloads or forks of the code, in something they're building, and then the scenario you talked about, Tom, which is they put a cease and desist.
" Sort of the irony of where do they train their models from? Probably a lot of uncopyrighted code. So it definitely is a I would be careful about using it until seeing what happens with some lawsuits and stuff.
Or go for it and take the risk. It's up to you. Yeah, as I like to say, I come from a family of lawyers.
I'm not one. You do, that's right. And, so I'm tiptoeing my way around, but I think that, yeah, this highlights one of the challenges that we all should be concerned about is, okay, when this hits the fan, societally, right, what is possible?
What is not possible? And I think that I don't have an answer for vibe coded copyright, but, I think that if your company is doing that significantly, you should talk to lawyers and sort this out. But yeah, the incident itself was interesting in many ways, and we'll get to them in a second, but I just wanted to comment on the copyright and the intellectual property law both runs the gamut.
Some things may be copyrighted, some things may be trade secrets, some things... So very gray area there. I'll take an interesting angle on this, because one of the things I brought up in the post or in the pre-event thing was, if everybody remembers, there was this case a few years ago where a chimpanzee took a selfie with a photographer's camera.
And then when the picture got published, a court ruled that the chimpanzee owns the copyright to its own photo because of the weirdness of US copyright law. " But that's the way the law is written. And I think that that is what we're going to get out of this, is a clarification in the law, but also clarification on the part of the companies involved in creating this stuff.
Because when these things happen, everyone in the room kind of understands the common sense of Anthropic owns the copyright to the code that was written, whether it was written by a person or a collection of shell scripts. But it's not the way the law is specifically written. And then everyone kind of has to stop and step back and go, "Wait a minute.
This doesn't make sense legally. We have to create law here. We have to have a judge who's willing to take a look at this and go, 'Yeah, you're right.
The person owns the code. It's not just freely available. '" And that's what's going to move this case along.
I think ultimately what's going to happen is that those projects that are borrowing Claude's code will either have to purge themselves of it, or probably what more likely will happen is they'll probably work out an agreement with Anthropic where they get to use certain sections of it, but not these sections or things like that. And it's going to be messy for a while, but that's what you do when you have a rat's nest of cables, right? Is you have to pick out all of the pieces, and some of them are harder than other.
Anybody that has ever had to work the knot out of a jewelry chain knows how infuriating that can be. And that's kind of the point we're at right now. But I think the other thing we want to-- Oh, go ahead, Fernando.
What were you going to say? I was just going to add two more things to it. One of them is that when we talked about how this was forked 41,000 times and tying back to my old man in the cloud kind of stuff, my mind immediately went to, do you remember when people were trying to get around the DVD encryption, and we had the DCFF?
Mm-hmm. People were printing T-shirts with the algorithm for the DVD. Anyway, sorry, my mind-- For people who are old enough, go look at what we were doing.
I had one of those shirts. So yeah. But it's the idea that knowledge is free, right?
Once I have put knowledge into the world, I can't unmake that knowledge. That's one of the problems we run into with things like classified documents and stuff like that. Once I have said what the content of that document is, I can't make people forget.
Yeah. So anyway, so that's one thing. And the other thing is that we can go back to the Claude code example itself, but there's other things going on around legal aspects of AI that we should track, that security professionals should track.
For example, I think that there's a brewing controversy around legal terms used in the pilots, right? So, for example, when the pilots, I mean, like, so there's something going on around Microsoft saying that Copilot's for entertainment purpose only. Of course not.
I mean, this is going to eventually sort itself out in terms of, as Tom said, legal considerations, but it's a further reminder that we need to have more awareness of what's going on on the legal framework. So the legal path of this is one awesome big path, right? It's hugely complex, has its own complexities and things to unwind of that jewelry chain.
I totally get that analogy. There are so many security implications to this because when you have access to the full code base, okay, you have access to things like how are security controls done, how is sandboxing done, how are permissions granted, what things is Claude code allowed to do or not allowed to do, which might be up to change. You essentially have access to everything about how the system operates.
It isn't just a great architectural document. It is the system. And of course, immediately, right, you're seeing spawns like typo squatting versions of this, so people are downloading unofficial versions, even though they're not thinking they're getting a fork, but they're getting something like it through their NPM, which by the way, if you're updating Claude code through NPM, use the official installer because you're not going to be typo squatting.
But that's just one of hundreds of things that are happening with this. So now customers, users of Claude code are in the position, security teams, scanning products, that lights that whole process up of how do we make sure the code that we're generating is not going to be tainted because of what happened with Claude code? , the supply chain internally, as well as the supply chain we get externally.
Make sure it's officially from Anthropic. But what about all the things you got created downstream, and that we want AI in production, but this is a big speed bump, maybe a brick wall for some folks that they're going to hit. So this is more than reputational damage and in addition to the legalsystem that they've got to work through.
I know you're itching to say something, Fernando. I know you- No, no ... have thoughts on this.
I agree with you that we can go back to the more technology-centric and security-centric aspects of this. But yes, so the bow tie around the legal is go talk to your general counsel, go make friends with your neighborhood lawyers, and understand where this thing lands. The thing that I- They'll be happy to talk to you, right?
They want to talk to you about this. Yeah. Anyway.
But the thing that this is interesting in many, many ways is that I think it calls in to remind people that there is, from a software engineering perspective, and Mitchell know this much better than I, there is this thing about there is only so many things you can trust client-side code for. Again, I feel like an old man, that there was the thing about the programming Satan's computer back in the late '80s, early '90s. How difficult it is to secure client-side anything.
And here we have, now that we have the Claude code source code, we see how many things they were trying to look at from as a client-side component. And I feel like, of course, it makes sense from a performance angle, of course, it makes sense that we don't want to deal with the latency of sending something all the way upstream, and costs, and whatnot. This is the consequence.
How do you balance what goes client side, what goes server side? Not to mention the fact that we're all-- Some of the commentary I saw, people were more excited about what does the development version of Claude code tells us about the near future. So people had code names for new versions, for new models.
I think that there were versions for Opus and Sonnet, and a bunch of other things built in there, new features that-- So there is the, "Oh my goodness. " I think that's a good point, Fernando, because there is quite literally a cottage industry in the client device market around Apple and the beta test versions of iOS and macOS that they release that have references to MacBooks that haven't been released yet. And if you've ever looked at a MacBook release, they're all pretty generic and boring.
It's like MacBook 14,2, but it can betray, like if you have a 14,1, 2, and 3, you know there are going to be three different versions of that MacBook that have all these different things. " And more than half of them are fake. So you don't actually know which ones are going to be release versions.
And that's not something that a company's ever had to deal with before in the space because, well, the code's never leaked, and nothing's ever leaked until the first time it happens. And so are we going to start seeing them kind of going on the offensive to start hiding some of the stuff? Because downloading patch notes and pulling them apart to find what new releases look like is nothing new.
It's been done in the operating system game, in the video game space, in all kinds of client architectures for years. Sure. But you have to have that balance of do I run this as an app, like a full app on somebody's machine and do all the things that I want with it, or do I run it like an electron app, where it's basically a web browser?
And there's pros and cons to both. I tend to fall on the side of the app because it's better performance, and it's a more complete solution that doesn't involve me having to worry about is this the 14th time that Slack has had to reload today because of a helper problem. But I don't think that the companies are ready to expose that.
And how many times have we said on this podcast and in many other things that we've done, you always have to assume that you're being breached. You always have to assume that people are pulling your code apart and analyzing it. Because if you don't, you are going to have a process that would allow something like this to be left in there.
" Oh, that's probably, at least right now, tough to know whether it was a decision error. But it certainly was a process error. How did this happen that this gets externally both distributed through NPM, but also to the Cloudflare bucket that had this source code?
That's the ultimate big oops. Not just that it had this map file inside of it. I think to me, the biggest gap here is we're trying to build trust in AI, and we're trying to build trust in the code that AI generates.
And now one of the major, many people think of one of the best at writing code with Claude Code, has not only had a breach, but the response to it was, let's say, less than full-throated. I wouldn't say-- Their response were things like, "Well, it was human error. This wasn't a security breach.
There's no sensitive data credentials that were involved and exposed. The model itself was not exposed," the weightings and that kind of stuff. They're rolling out measures to prevent it, of course.
They recommend switching to native installer andAs far as I know, there's no dedicated communication to what you should be doing, not just what they're doing to fix their problem, but the users of their technology should be doing. So let's take CrowdStrike. That was a great example of the right way to handle it, right?
They were a model. If you could say if there's a company you want to do what you should do in an event of a breach, it was fantastic. I'm sure there's even flaws in what they did in their disclosure and things that they can do better, but you don't see too many that were done that well.
And so leaving this gap, where there is a vacuum, other things will fill the void, whether they're truth or rumor or false or whatever. So we're going to hear a lot of false narratives or unconfirmed narratives about what's really going on with this when Anthropic should take the bull by the horns and not only fall on their sword and say, "Whoops, we screwed up and we're fixing it," but communicate with their customers what you should be doing, what you can do to help protect yourself given the situation. Yeah.
No, I don't have much to add there. Thank you for calling out the CrowdStrike incident. It's one more thing where it's the reminder that you want to be able to-- We have to move this entire industry.
We have to move from one flaw and you're dead kind of, oh, I caught you kind of thing. This has become that much more strategic, where you work with your strategic partners to, okay, something went wrong. What are we going to do about this, right?
And I think that some of the narratives that we have within the cybersecurity bubble, sometimes it's a little bit too much true or false. Either you're great or you're crap kind of thing, and any little thing can blow up. No, the world doesn't work like that.
The world is more, okay, this happened. Let's make sure it doesn't happen again. What are you doing to-- And so if we can take one thing of this is like Mitch said, let's watch what Anthropic is doing for remediation and disclosure and sorry.
And I think that's a good point, Fernando, because there's two schools of thought on security. It's keep things out that shouldn't be in here or limit the amount of damage it can do if it does happen to get in. And I think a lot of people for years have been focused on the first thing, right, where it's like we need to keep things out as much as possible, and that's the whole idea behind bastion hosts and perimeter security and stuff like that.
But we also know that no perimeter security is completely impenetrable. And what you have to do is you have to create a scenario inside of your organization where when things go wrong, that either the blast radius is minimized or the likelihood that the blast can spread quickly is basically marginalized to the point where I can put defenses in place. And that does not necessarily have to be an attacker.
It can be something like this that happens because effectively when you share or inadvertently publish a file that contains sensitive information, you have breached your own perimeter, so to speak. Mm-hmm. So how can you slow that process down?
And there's any one of a number of tools out there that can do it, but a lot of it comes down to policies and procedures, right? So next time, if you're going to publish a build, it has to be desk-checked by a second person, or we're going to look for certain files in there that are not supposed to be there or grant certain exceptions if they do need to be there, or there needs to be a framework and a process. Because this is the way that human beings react to these problems.
We can't imagine every conceivable thing that could happen that could blow something up or expose things. " And we've built that over the years, layer on top of layer on top of layer of security. " And then you realize that 10 years ago, somebody instantly published a build to the whatever repo, and there was something in there that shouldn't have been there, and that 24-hour cooling off period is so that people can go in and look at it and make sure that it's valid or not.
And you're like, "But that's dumb. " And neither did the guy who thought that that happened 10 years ago until it did happen, and now that's why we have the policies in place. I think the danger here is the blast radius is so big.
Let me draw an analogy. Pick your favorite electric car company, anybody. Let's say the source code for all of the software that runs that car, because it is essentially a computer on wheels, right?
That's what's driving that car is the software, much more than any other kind of vehicle. If all of the source code for that was released, you would question, "Well, can I get in this car? Is it safe?
Is somebody going to take over driving from it? Is somebody going to turn on a camera or microphone somewhere and record me? " Yeah, and I don't mean to be hyperbolic about that, but when you have access to all the source code, it's not just the crown jewels.
The blast radius, the attack surface is massive because anything can be attacked. Like I said, just the quarantining, the sandboxing of how you do that. Now, of course, if I was at Anthropic and this happened, or a company that happened, I'd immediately be thinking about, well, what are the biggest attack surfaces that we need to lock down?
Maybe we need to re-architect some of our sandboxing. Maybe we need to change how we're doing some permissions or security protections. Mm-hmm.
Maybe some of the things we had on the roadmap we move up sooner, either to make a change in it or to make it more secure. SoIt really changes from your thinking as a product leader, product developer, whatever role that you're playing. Your work plan is going to change pretty quick.
If it doesn't, you're in big trouble, I think. Yeah. So many things.
I see your point. Still, I think there's a couple of nuances here. One of them is that there is, we go back to cryptography, von Kerckhoff's principle, right?
That the security of the system shouldn't be relied on obscurity. It's the old argument against security through obscurity. Obscurity absolutely helps, but it shouldn't be what you depend on.
And this was a perfect example of what just happened, right? We have just seen that, personally, I don't like the expression open the kimono. But we've shown the light on how a very popular piece of client-side code runs and what guardrails it has to do things.
So if you are an attacker, you are now able to understand what those guardrails are. So what changes in your threat model knowing this? Oh, okay, I know that, as an example, the Claude code prompt for protecting against injecting security vulnerabilities is out there.
It's relatively long. Please don't inject security vulnerabilities. Please only report vulnerabilities that are very high.
And that's interesting on its own, right? But it's the kind of thing, okay, you have to think through, okay, if an attacker knows this, what changes in my environment? And honestly, it may not be that much, right?
Because if you are, what is your threat model for running Claude code in your environment, right? Oh, somebody is going to subvert Claude code to do something else. The likelihood of that happening increases by a bit because now people know how Claude code is built.
It doesn't mean that it will necessarily happen, but the likelihood of that increased a little bit. But we will compensate. We'll build other controls around it.
" Right? So this will be an interesting point. But as Tom was mentioning something as well, in terms of we get better at this little by little, and so on and so forth, reverting back to the episode we had last week, Tom, I'm losing track, on risk, right?
How do you account for the overall risk to the organization of something like this happening? And yes, we're building a discipline together, but this is a teachable moment for many, many people, right? It's a teachable moment for be careful about what you share.
It's a teachable moment for understand where constraints are being run or where controls are being run, maybe not run so many client side. And yes, this is what the pace of change is on modern AI frontier model development kind of stuff. Yeah, I totally agree.
This moves the conversation to a different spot that the people at Anthropic didn't think they were going to have to have prior to April the 1st. But if there's anything from this that you can take away as a listener of this podcast, is that the best time to have that conversation is right now before something happens. As was mentioned, make friends with your legal team because they would rather talk to you beforehand than have to interview you afterwards for a deposition or something else.
And the more in front of it you can get, the less likely this is to become a huge show-stopping moment for you or your team. This is the planning part of doing security. We're going to go ahead and wrap it here, I think.
Can I have a parting thought, Tom? Just one thing. Go ahead, Mitch.
Yeah. I'm not in the advice of giving people, or job of giving people advice about how to write code or manage your systems, but it is pretty straightforward to switch from an NPM-installed Claude code to a Anthropic installer. You basically can install the native, because they live in different libraries, native while you're running the current one and then uninstall the current one, and it doesn't affect your Claude MD file and not the other artifacts that you're keeping.
So fortunately, those things are separate if you want to, I would recommend go back to the native. Now, it's assuming that's not compromised, but I think that's a prudent thing to do. So end of advice.
All right. And with that, we'll go ahead and wrap it up here. Mitch, what have you got working on that people should be checking out?
Well, I just released the agent control plane framework that I've been talking about for a few weeks. Again, held off while all of the ta-da was happening with RSA, and didn't want to compete with all of that news. So be sure to check it out.
Again, this framework is, there's so many vendors talking about agent control planes or talking about governance and control, all of it important things, but it's happening all over... kind of the product life cycle, in development tools and platforms, in operations, in observability platforms, in security tools. So we're entering an era where there's a lot of innovation happening in this.
What's not clear about the end result of where are we going to land. Are we going to live in a world with 25 different agent control planes that don't talk to each other? Are we headed down a path of building some kind of integration?
Yeah, I see you shaking your head, Fernando. That's like we have 25 different policy servers to satisfy every different edge use case in the world. So that's sort of the next mountain to climb on this as vendors start to issue this, and I think there'll be some winners and losers in the market in terms of control planes.
That doesn't mean it's all going to be sorted out. So I think that's something you'll be seeing me talk a lot about. Oh, I look forward to having those conversations.
Fernando, what about you? From my end, I sometimes help peer reviewers on Mitch's stuff and whatnot, and he does phenomenal work. I will be controlling myself not to include XKCD references in his- ...
there are 14 standards. Oh, look, one to rule them all. Now there's 15 standards, right?
So- Brushed, yeah. Both that and the one piece, the one about everything depends on one little open source. But, so other than that, Tom, you and I have our FASHY paper out imminently, so that'll be very interesting.
Of course, AI affects everything, but there is more to life than AI, and so we have a paper out on secure access service edge. Also on the influenced by AI, but more than AI, here at Futurum we have a robust quantitative research program that goes on as well, and I am right now starting to review the incoming data from the cybersecurity decision maker survey that we run. I'm collecting early shield data now.
I think it'll be published in about six, eight weeks, perhaps a little bit longer. But, yeah, I'm really looking forward to that. As we're recording this, we're starting the spring season for conferences, right?
So our SAC just wrapped up. We have a robust presence across the many conferences, whether it's Google Cloud Next, whether it's Cisco Live, and some of those others. So I'm looking forward to that, and I'm already thinking about what's happening, besides Las Vegas, Black Hat, and DEF CON in early autumn.
So let's start thinking about that. Yes, indeed, and I hope that you check out some of the stuff that I've been working on. com for that.
Also, we are going to be at Black Hat and DEF CON this year, and we are going to be doing some exciting stuff, so make sure you stay tuned to our brand new Tech Field Day website for more details on that. Thank you very much for listening to this episode of the Security Boulevard podcast. If you enjoyed this conversation, you know what to do.
Head over to YouTube and subscribe, or you can do it in your favorite podcast app. Whatever it takes, we want you to listen to what we're doing. We also appreciate if you'd leave a rating and a review because we want to reach all of the people out there that are interested in cybersecurity.
com and the Futurum Group. com, the Techstrong TV website, or your Techstrong TV app. I hope that you've downloaded it by now.
You really should go download it. Download it on your TV, on your tablet, on the little calendar that you have on the wall that tells all the kids what their upcoming appointments are. Whatever it can run, we want to run on it.
Follow Security Boulevard on X, Twitter, and LinkedIn using SecurityBLVD as the tag, and there's lots more content out there. Thank you all for tuning in. We'll see everyone next week.
Dennis Donguchen here, CEO and co-founder of Lightyear, and I'm excited to give you a platform demo of Lightyear. So as a reminder, Lightyear is the telecom operating system, which aims to automate and digitize the full life cycle for your telecom services. So in this demo, I'll take you through the life cycle of an individual service with Lightyear through our procurement product, our network inventory manager, and our expense management product.
It's worth noting that every aspect of this product is somewhat customizable based on your vendor constraints, quoting workflows, objectives, et cetera. So don't view this as overly rigid as I walk through it, but basically, this is the homepage you'd see upon login. There's this left side navigation pane that can take you to different components of the product, procurement, inventory, expense management.
In the middle, you have some action items that may require attention, installs where you may need to confirm acceptance, ongoing installs that have action items that may require your attention, and pending installs. We also have this global search function where I can maybe type in site details and so maybe here I want to go to my Albany site right from the top, and on the right-hand side, you can start a new service request if you would like. So, let's go ahead and visualize a new service request with Lightyear.
And via Lightyear procurement, you can create a service RFP quite quickly. So here you can basically configure any form of telecom service, internet, broadband and voice, wave, point to point, colo, et cetera, et cetera. You can do one or many sites.
We have a bulkQuestionnaire if you want to configure services for, call it, 100 sites at a time. But let's configure an internet circuit for a single site here, and you can also utilize a templatized site configuration if you'd like. So let's get an internet connection for our Albany site.
Let's say we need a /30 over fiber with 100 megs, no managed router or BGP, and contract term of three years with a preferred install date, and the option to sort of either allow or negate providers if you have particular provider constraints, and then you can submit your request. And via procurement, you can submit a request for redundant 10 gig waves or something like that within 60 seconds. And what happens here is actually more exciting than what you see visually, in the sense that basically, I just submitted a request, and effectively that request is then going to go to our back end, where we're going to use location intelligence from a variety of sources to dictate basically what vendors have the highest probability of being on-net or near-net at a given site, bidding out to those vendors for the best potential pricing.
They will submit back pricing via workflows that we've built that tie in with the vendors. And then from there, there may be a negotiation step that goes on if the pricing they submit doesn't fall in line with existing data for effectively what's a good price here. And then you'll get pricing back, and you'll have the opportunity to evaluate it, and you'll get a notification saying you've got price quote.
So here's what a hypothetical price quote would look like. So here's a Toronto site, so you can see some Canadian providers quoted, Rogers, Shaw, Bell, et cetera. And you'll see here the price points on all of the services in CAD or USD, any install costs.
We'll also denote the estimated install interval, the contract term, the transport type, last mile provider, is the vendor reselling a different provider, capacity on the transport AS number, and the delivery point. So, you can see here Bell will actually deliver to the suite, which may be something that you want, as well as an availability SLA if there's an SLA associated with the service of some type. You can select quotes here, primary, secondary, et cetera, and then move to sign contracts.
Another interesting point is if you're sort of architecting diversity, we can also gather KMZs on your behalf. So here are some 10 gig waves. Or actually these ones don't have KMZs.
Let me pull up here. These ones should. So here's some 10 gig waves quoted from a variety of vendors here, and here you can see we actually got KMZs from the Crown and Lumen routes, and we can go ahead and compare the KMZs and see that there are two points of intersection along the route.
And you can actually leverage our network engineering team to work with you as well as the vendors to augment the routes and get rid of either overlapping points of entry or overlapping points within the route. And then once you buy the services, we will store all of those KMZs in your inventory, and you can visualize the KMZs in whatever form that you'd like. Once you sign orders for a service, that takes us to installations, and we know that everyone here who's managed a network before knows that installations are the bane of a network manager's existence.
So we've built fulsome install project management software that basically aims to operate as a squeaky wheel, keeping you organized on all of your installs, escalating issues on your behalf, and leaving the pain of managing those threads end-to-end as much off your plate as possible. So here you can see a bunch of different ongoing installs for an enterprise with a bunch of different vendors. And if I click into an individual install, I can see all the job steps, what's completed, and the estimated completion dates for all those various job steps going into that install.
So here's a Zayo circuit getting installed in London, and I can click in and see detailed project updates as they occur and what is expected to occur next. I can see my provider install manager, my billing contact, et cetera, all in one place. And this system will do two things.
If you have an action item associated with the install, it'll flag it for you and make sure that that action item doesn't hold up the install if you need to submit a permit, have someone on-site, schedule a site survey, that sort of thing. And also on the other end, if things are not occurring at pace, we have an implementations teams that's monitoring all of these and utilizing proprietary exploration paths with the carriers to get to better outcomes. Once an install is completed, you have the opportunity to verify whether or not the install is substantially complete.
Meaning the vendor can sometimes say that an install is complete, but you'll need to confirm that the circuit's actually activated and working as it's supposed to on your end, and that is something that we can help with, because sometimes a vendor will say something is installed, and it's not actually installed. So coming next to our network inventory manager. Here, I'll actually start with the map view.
This is effectively a system of record for your network that tracks-Everything in your network in detail and automates a bunch of workflows for you like MACD ticketing, reshopping service prior to renewal, and more. So you're set up for continuous cost optimization. And as asked in one of the questions earlier, you can also use this for existing network that's not been sort of migrated or purchased via Lightyear.
We can basically build this system up on your behalf. So here you can see a hypothetical enterprise network with a bunch of sites and services. You can see KMZ routes sort of live and visible on the map, and I can sort of show or hide those as I like.
These routes represent either point-to-points or waves running between sites, and in red, services expiring within six months. Or in blue are sites that have services getting active installs. And I can click into any individual site and pull up my circuit details.
And so here's a one gig Zayo DIA. And here you can see basically over 30 unique data points that are relevant to the service, the delivery point for the service, the install details, the carrier info, the SLAs, static IPs associated with the service, or any custom fields that I'd like to create. We can actually facilitate and track custom fields for you.
Prior to renewal for an individual service, you can sort of dictate settings. Do I want it to cancel at expiration? Do I want it to auto-renew?
Do I want it to auto re-shop? And we can also do that in bulk for services that come up for expiration in bulk on your network as well. And at least just to keep you reminded that I can open a MACD ticket.
So let's say I want to upgrade a service, I want to disconnect the service, I want to move a service mid-contract from one site to another. You can facilitate that with clicks rather than phone calls or emails. And as anyone who's gone through these workflows before is well aware, these are quite painful.
You can track all of your service change logs in here. You can store things like your contract files, KMZs, et cetera, in here, and take any notes that you'd like on an individual service. You can create custom views and filters over here and export your inventory in whatever way you'd like, and also via API.
You can keep this up to date and push and pull information from other enterprise systems. And you can manage your MACD tickets through to completion here as well. So here's a disconnect ticket that's hypothetically been moving.
And finally, we also have this dashboard that'll give you a variety of holistic, overall aggregated views on your network, your spend over time, spend by service, spend by vendor, your opportunities for cost savings year over year based on when things come due. And you also can actively re-shop services prior to renewal. So here you can see a circuit that is month to month, where our service indicates that market pricing is far lower than you're paying for the service today, and you can simply click to request a re-shop on that service.
And then finally, we get to our expense management offering. So this is really what I'd call AI native invoicing software or invoice management software for your telecom expenses. Basically, it automates invoice management, it automates payments, it standardizes invoice receipt and processing, regardless of the format in which invoices are received, and we use LLMs effectively to extract data and bucket all of the line items on your invoices as they're received to actual inventoried services.
So you know what you're paying per service and what line items are in that invoice. For example, what is a tax and fee versus a government surcharge versus the actual service cost. And we also automate variance analysis as well.
So here we have reporting and a dashboard view that offers you a couple of high-level views into your actual services and invoices. Here you can see consolidated bills as they're received as well, if you're using us to pay basically one consolidated bill per month and see what sort of items are on those bills. And if I pull up the actual individual provider invoices here, this is where some of the magic happens.
So, again, we're using AI that is optimized via RAG on a bunch of telecom data to ensure that we're able to extract all the line items in the right way for every single telecom invoice. And here you can see basically this invoice from Lumen being itemized and tied to actual inventoried services, and then bucketed based on where the charges are supposed to go. And then over here, you can see what is the actual total service charge by inventory service on this invoice, which will be exportable in any which way you would like from a reporting perspective to the extent your finance team wants that.
And if something on here causes an issue, we will sort of tag that. So here you can see some variances that may show up on here. For example, something that has a dispute open, something that has a dispute closed, depending on what the actual source of the variance is.
And we will go and chase that down and close that out for you. Over here, you can basically configure what services are enrolled in the expense management services. Here's the top-level variances view, where you can actually see what the individual variances are, what's been accepted, what needs review.
So here is a variance in taxes and fees, perhaps in advance of when they were supposed to be charged. So that caused a flag, and then you can choose to accept that or notHere are some settings that you can utilize on reporting that gets sent to your AP or finance team as they'd like to see it. You can configure basically what fields are included in billing reporting as it's shared, how bills are delivered, and also what's tracked from a variances perspective.
Some example variances that we track are services that are higher than what they're supposed to be from a contracted basis, higher than a previous month's charge, taxes and fees that are larger than expected, or inactive services billing. And basically, the endpoint of these three services combined, procurement, inventory, and expense management, is that you have your entire telecom lifecycle from end to end tracked in one singular system from basically service RFP to service deprecation when that happens. And finally, it's worth noting we have this calendar system as well that can track all of your various service deadlines, install dates, BOC dates, notice deadlines, et cetera, as they come due.
And we also have a message center where you can message us, tag any individual service, or request support with us live. So, let's say I have a question on an individual service. I can tag that service, ask about it, and our team will come to help answer whatever it may be, or even ask how to perform an action or create an action within the platform that I'm struggling with.
And that is the end of the demo. So hopefully that gives you a good vantage point into how Lightyear works and edifies some of the points I noted about having a system to manage your telecom lifecycle and how that can result in material time and cost savings.