Techstrong TV April 3, 2026
In this episode of Techstrong TV, Alan Shimel brings together leading voices across AI, cloud, and cybersecurity to examine how enterprise technology is rapidly evolving. Rich Mogull of the Cloud Security Alliance shares how new AI security frameworks are helping organizations address the realities of agentic AI, while Dirk Alshuth of emma Technologies explains why multi-cloud flexibility and data sovereignty are becoming critical strategic priorities. Stéphan Donzé of AODocs outlines why document governance is emerging as a major factor in AI success, and Mitch Ashley with Brad Shimmin explore how Microsoft is building new reasoning layers for enterprise AI systems. The episode also features market analysis from Alan, along with Michael Cade and Emilee Tellez of Veeam on strengthening data security posture, visibility, and control across modern environments.
Transcript
Hi, everyone. We're back here live. Where are we?
We're at RSAC. That's where we are. We're in Broadcast Alley.
It's been 20 years. If you haven't figured it out by now- ... 25 years.
Been 25 years. If you don't know this guy, you probably don't know a lot about security. He's my friend, Rich Mogull.
Let me embarrass him a little bit. I first met Rich, he was a Gartner analyst- Yep ... covering the DLP space.
Yeah. And shortly thereafter, though, he woke up and left Gartner, and he started his own analyst firm called Securosis, and he was doing his thing there. And he ran into a guy who had just written a book about the CISO.
What was the book? " "The Pragmatic CISO," our friend, the Candy Man, Mike Rothman. And Mike joined Rich at Securosis, and this is a time where Gartner was the shizzle, right?
For security. I thought you were taking that word in a different direction. No, I didn't.
I didn't. Gartner was the shizzle for security analysts. And then maybe there was Forrester, and I think some of our friends were just getting started at 451 Group- Yep ...
and stuff like that, but that was it. There was Scott Crawford here, this one there, but Rich and Mike really redefined what an independent analyst meant to be in the security space with a totally different model of doing research and sponsored research and all of these things. I always admired them when I was on the vendor side of the house, and then when I started what became TekStrong.
Rich, in his spare time at Securosis, though, was fascinated with cloud security and developed a cloud security solution, and they spun up a company. If I get any of this wrong, just jump in. No, you're on.
I-- Yeah. Spun up a company called DisruptOps- Yeah ... which was putting guardrails on for people using cloud.
And the suitors came knocking, and Rich and Mike sold DisruptOps, as part were acquired by our friends, Jody Pressel, who just happened to be sitting here when you walked up. Randomly, as I walk up. My co-founder- Well, you know what?
Yeah ... and CEO. You know what?
" So that was, I think, a little God message there. That was a good one. Yeah.
But, anyway, got acquired by Firemon, and Rich was their VP of cloud security there for a number of years. And then, I guess was it less than a year ago? Eight months ago.
October. Oh, okay. Yeah.
So about six months. Yeah. Officially became the analyst for the Cloud Security Alliance.
Yep. " Clearly, we've known each other- Yeah ... for decades.
We've known each other for a while. Back when, what was it? Still Secure, and- Yeah ...
we did some- Doing all of that stuff ... advisory work and, yep. All of it.
So Rich, how's the new gig? It's great. " Yeah.
I remember day one. He made an announcement. " I remember that.
I remember day one and two. I was here. Yeah.
Hoff, Jim Reavis. Yep. Who was the guy also with Hoff?
It's, I think, oh- I can't even remember. Yeah. But, so I got involved early in doing research.
I built their training program. I wrote some of the research documents over there, and then Jim and I were sitting there. It was last year, right before RSA, and he had this list of stuff.
" And of course, it's my side thing because I was working full-time at Firemon for Jody, who is sitting here. Right. And I was getting ready to leave that role because Jody and I both agreed it was getting to be time, and we're still friends, to hand off what I was doing to somebody else.
" And sure enough, we pulled it off. So it took a while, and joined in October as chief analyst and- Well, this is kind of a dream job for you ... it's great.
It really is though. Right. It marries your passion to what's going on in the industry.
It gives you an important perch. Well, and I like the non-profit- Yeah ... angle.
Well, not only non-profit, non-vendor. Yeah. Right?
No offense to Jody. I love Jody, too. But it takes a little while to get that stink off of you when you leave the vendor space and come to more of a non-profit or a non-vendor kind of thing.
That's some of why I left. I was proud of the work I was doing at Firemon and the new stuff that, at some point, perhaps Jody will be able to talk about when he's ready for it, but very cool. But also, it's like that's not my wheelhouse.
No. My wheelhouse is the analyst, the work with organizations, doing advisory work, helping solve problems, and I like that I'm able to give away all my research for free. That was the model we did at Securosis.
Right. Mike and I are like, "We're going to give all our research away for free, have it be vendor-independent, and still make money doing it" Make money doing it ... which nobody thought we could do.
We did for a while, and it got time to be for us to move on. The startup distracted us, and now I get to basically do that again. I love it.
I love it. All right. Enough about you and me because we could spend all day talking about you and me.
People would say we're baby narcissists. Maybe because we are. But we've got enough narcissists in this world, don't we, Rich?
We're not going into politics. You did. I didn't.
I just said it. But anyway-You guys, every year for the last 11 years, we put on what was the DevOps Connect DevSecOps event. Yeah.
Yesterday, we kind of changed it up a little this year. It was AI Native Dev and DevOps and security, AI and everything else, with some really nice talks there. But for all these years, in the room next to us is always the Cloud Security Alliance.
Yeah. They get a bigger crowd. I'd pop in between both rooms when I wasn't working.
A lot of people do. They pick to see who's speaking on any given minute. Yeah.
But you're up there speaking now, so I popped in to say hello to you. You opened at 8:40 in the morning, which I got to tell you- ... as a brave man, because I know better, because people just don't get here on Monday at 8:40 in the morning.
Alan, it's not like I picked the schedule . I had a feeling that wasn't your choice. But you made some important announcements.
Yeah. Let's talk about that. Yeah.
So my talk was, you know me, I always like to bring content. And even though I don't feel bad about promoting CSA because of the work that we do, but at the same point, if somebody's in the audience, physically in a room, I want to give content. So I talked about basically the, so one of the problems that I encountered over my years of work is we have all these great frameworks and models and standards, and on the other side, we've got somebody clicking in consoles or writing command lines to get stuff done.
And I did a lot of advisory projects where I was pulled in, sometimes by very large organizations, where we had to actually build out the, "You know what? " And I tend to be like, people like to dog on security. No, I think we do a really good job with the resources we have.
It's hard, and the job of a security professional is very difficult, and the people doing the actual active defense work there, that's really hard. And we've gotten demonstrably better. Oh, yeah.
People can say what they want. The mission's gotten harder. Much harder.
And it was- I agree ... the stakes have gone up- Yeah ... from when we first started.
Yep. " Up here, they're also dealing with compliance issues. And so my talk was, how can you bridge from that top level all the way down in a way that's practical?
Because I think we're not like, so, standards live in spreadsheets and commands live in consoles, and how can we tie it together? So that was a talk. It's a thing I came up with years ago called the governance hierarchy.
We actually built it into CSA training like four or five years ago. And at the top level are frameworks to just help us figure out our focus. It's like the lens of what we need to do, and there's really good ones like NIST CSF.
It's very broad. It's not meant to tell you everything you need to do, but it's designed to give you that big picture of what you need to do. The problem is, when I first started doing cloud work, we didn't really have good ones for cloud.
Because cloud is a different enough, new and disruptive enough technology, you couldn't just layer in the 20 years of what we were doing in data centers and in our regular networks. And so I wrote a cloud security maturity model with CSA and with IANS, if people know who that organization is, and we co-released it between the three organizations. Now with AI, same thing.
So my talk was about building that bridge and how you can go from those high-level models. I like the maturity models because they tell me this is what the buckets of your security program need to be for cloud or for AI or for general security. Then the next level is we need control objectives, which is the, how do I define my desired security outcome?
So plain language of, what do I need to be measuring in terms of my outcomes? So I kind of walked through that. For that, at CSA, we have the cloud controls matrix, the AI controls matrix.
They're a good starting point, not the end point, starting point for those. And then how do you translate that down into the clicks? And so, big things were, in terms of the content is, I had released a draft of the AI security maturity model, got 600 comments from 60 different people from around the world.
Like, all right, clearly- Struck a nerve there somewhere ... people are really interested. Mm.
Of course, I had to use AI to go through all the feedback because it was too much even for me to go through. But categorized it, got some really good improvements on that, so getting ready to release that piece. And so that was the talk part.
The announcement part was we're expanding our membership opportunities because Jim brought me on largely, because I've got, we use the word analyst. You know I'm pretty hands-on practitioner level worker. Yes.
I'm a blue collar analyst, or I don't know. Always have been. That's kind of insulting to say to actual hardworking people.
But I try to take that perspective. And CSA's got all this great research and stuff, and people, and membership, and global participation. What the organization hasn't had a lot of was, well, how do we support people to actually implement and get this stuff working to improve their security outcomes?
So, that's a big part of what my role is. And then the big announcement was expanding our membership opportunities. So we have a structured program now that I've built, it's to adding membership for organizations to be able to support them along that journey.
So it's not just vendors, it's kind of user, practitioner-oriented things? This is all oriented, this membership is all oriented towards enterprises. Right.
And look, let's be realistic. We're non-profit. Someone's got to keep the lights on.
We still need to keep the lights on ourselves. Right. So we're like, how can we do that where we're helping improve security, improving the research, opening up opportunities for people to improve their security outcomes, and do it in a way that's vendor agnostic and helps support our mission?
I love it. And look, as an outsider-I love to see the involvement of non-vendor memberships, right? Because whether it's the Cloud Security Alliance or the Linux Foundation and CNCF and all those folks, or Eclipse or the rest of them, let's face it, a lot of them have become rich, a place for co-opetition between vendors so that they- Yeah When I was practicing law 100 years ago, there was this organization where workers' comp insurance carriers were able to share all their data collectively without violating antitrust because they gave it to a not-for-profit entity- Yeah ...
which gathered the data from all the insurance carriers- And then fed it back ... and then fed it back. Yeah.
And though it was a not-for-profit and it was an alliance, to me, that was always kind of dirty. Yeah. And it was hard.
At Securosis, we do licensed research, not sponsored. In other words- Right ... in CSA, we do a lot of work with the vendors- I know you do ...
but they don't drive. And honest, it's incredibly-- Look, I spent time on the vendor side. You've been a vendor.
Absolutely. I am not completely anti-vendor. You get it to the right people, they- Neither am I.
They keep my lights on here, too, let's face it. There's very smart and we were talking with Jody. Jody and I share the goal of wanting to actually improve things.
Right. It's like, yes, of course we want to make money in the process. We have to.
We live in a capitalist society. Absolutely. But I think credibility comes with a bigger practitioner membership.
Yeah. And that's something a lot of these not-for-profit foundations have not given-- They give lip service to it. And we have a lot of enterprise members already, but we weren't serving them as well.
So, our base membership, a lot of it was you would get training, you would get access to CSA executives and stuff to talk about things. I was their unofficial analyst. I would get on calls.
Yeah. Almost nobody ever called, though, because they just didn't know that that was- That you had it ... widely available.
And you get more basic newsletter. And it's a solid little package, particularly for the training. There's- Yeah.
No, no, the training's good. Look, you and Mike did the training? Yeah, yeah, we built it, or one of them.
There's three. I built one. Right.
And on the research side, we've done some pretty good big projects. But I agree with you, if it's only the vendors, that's a problem. It's when you get this mix- That you get the real deal ...
and then because, yeah, you're serving the community of both the vendors and the organizations using their tools and technologies. You're not just serving one side. Look, I know you don't want to talk politics, but there's a political aspect to this.
Oh, no, I'm always happy to. I know. I just don't want to get you fired.
I can't be fired, Rich. I'm All right. Game on.
No, no, but it never stopped me before. No. But no, but seriously, a representative government works best when it's representative of the people.
Yeah. The people who need cloud security are not just the vendors, it's the people who need to be defended and are in the cloud. Well, and we have so many members that they don't pay us anything.
They're- And that's always been part of it ... all the working groups. Anybody can participate in chapters and in working groups.
And since day one, by the way, they've had that, right? Oh, yeah. That's the core of CSA.
I remember early on, every two weeks was a working group phone call. Anyone could dial in. This is before we had Zoom.
Anyone could dial in, listen in, and participate in the, I guess we called them conference calls then. Well, they write most of the research- Yeah ... is the working groups.
It's not someone like me on the back end. I've done that a couple of times, and that's not common. Because we produce industry consensus research that anybody and everybody can get involved with, and it's hard to manage.
I feel for our research team because some of these working groups are really large, and the logistics of holding meetings and then getting people to actually write. But like I know, so the AI maturity model, I set it, put it out, we got 600 plus comments from 60 different people. That's going to be better than if I wrote it myself and published it like the last one.
Absolutely. Every day of the week. Every day of the week.
That already, they found stuff that I missed. It is much better research than what I wrote on my own. Now, I like being able to draft something first and get that feedback, personally.
But that also, there's other kinds of research where one person can't do that. It's just too-- Like our cloud controls matrix, AI controls matrix, those need a lot of people working on it. And these are all volunteers.
And that's another aspect of the whole not-for-profit thing, that yes, there are people who get paid who work there full time, but a lot of these not-for-profits live and die- Yeah ... with the strength of their volunteers. It's the same thing again, like in open source, the maintainers, a thankless job that now is starting to recognize they're the linchpin of this whole thing.
We've got to take care of these people. All right, so we spoke about the membership program. Yeah.
Where can people get information on that? org. It's not fully on the page yet because we just announced it.
org, or RMogle on anything but Twitter, politics, and- It's X. It's X. No, that's, man, whatever.
Yeah. Okay. It's Twitter.
So, but you- By any other name where the rose smell is sweet. Find me on LinkedIn, find me on Mastodon, find me on Blue Sky. Any of the above.
And at the CSA website. Now, you got some other stuff going on. I do.
Did we cover it? We covered the membership, the research. We've got, yeah, some I know we're going to have Jim on this week.
I don't want to spoil too much- Right ... because it's Jim's baby, but we did announce a new nonprofit arm, so it's like- Yes. But we'll go more into it.
It's a nonprofit arm. Of CSAI. Right.
It's all about AI. Yeah. And so it's a way, honestly, it's a little bit hard.
Our name's Cloud Security Alliance, and right now, the vast majority of work I'm doing is on AI. You and everyone else. Because it has to be.
And we have our AI safety initiative, and our trusted AI safety expert training, and the AIC, and all this stuff. So this is a way to, it's still CSA, but it's a way for us to better align, fund, and focus those efforts. So it's not like we're splitting or anything else, and Jim can go into the details.
And it's funny because it's like, well, it's CSAI. Is that Cloud-- No, it's just CSAI. Just CSAI.
It is what it is. Cloud Security Alliance. But look, if the Linux Foundation can have, I think it's 40 different daughter foundations, you could have CSA.
And that's exactly what this is. And it's super exciting because it gives us, a better way of... Okay, I was with a friend last year at DEF CON, a good friend of mine.
And we were talking, I was telling him because I had lined up this job, and I hadn't started it yet. " That's great. " No.
CSAI. I went through all the research we had already published. " But you know what?
I wonder how many similar stories we're going to hear because, look, just sitting here with you talking, every single person, everything they're doing, not everything, but a large part of what they're doing is all revolving around this. It is driving like nothing I've-- And I was here- Oh ... for the dotcom.
Yeah. I've been here through this all. Nothing is at this level.
So I want to give an example. Go ahead. This morning, I was running a workshop, and it was a cloud incident response workshop.
Mm-hmm. And I had a framework and stuff we set out, because I used to teach that over at Black Cat, and automation platform for live attacks and everything. So I have to spin it all up the morning of the class because it's really expensive to run.
I'm not going to run it overnight. Yeah. And spun it up, and parts of it didn't work right, weren't going right, even though I had tested everything before I left.
Well, there you go. It is. Used Claude to build a new desktop.
And this was a moment. So first of all, I know I could've debugged that, but I'm looking at the clock. You don't have time to play.
And the AI had all the context of all my code. And so I gave it, told it what was going on, told it what to look for, and it went in and found it far faster than I could. And I would've found it, and it turns out it was a weird race condition in cloud formation, which isn't supposed to happen, but does sometimes.
I was spinning up 65 accounts, nine of them borked. Didn't work right. So that was the interesting part.
All right. Put together a strategy to fix it. I had to launch all these simulated attacks.
" It didn't even have the attack code. It was able to just pull it from that project because I normally run that someplace- Right ... else in a container.
" I do it from my laptop, so it doesn't look like it came with an AWS. " Because my main desktop at home, I was remote into, doesn't have those containers. " And Claude goes to go do that, realizes that the docker image I based everything on was out of date.
Interesting. Instead of just taking the next one, finds one it knew was compatible with the software libraries I had built into my attack code, downloads that, builds new containers, deploys them, aligns them with the credentials it needed to run the attack, and everything ran. And by the time I walked from the Marriott to this building, it was done.
It was all up and running. It's amazing, isn't it? It's scary amazing.
Well, so look at the implications, though. We could talk all day on this and- We can, and I have. What does this mean for the profession?
What does this mean for the jobs? I'll tell you what, I don't think we're going to know for a few years. So look, developers are the tip of the spear when it comes to this displacement.
Yeah. But marketing is not far behind. No.
Writing is not far behind. I hate to tell you this, analyst and analysis- Oh ... are not far behind.
The tech industry, in general, is the tip of the spear. But the waves here are going to tsunami out into the general economy, only to be followed two to three years later by physical AI robots- Yeah ... doing other kinds of work.
Blue-collar, physical work. It's a very interesting world we're coming to. It amazed me at "Dune," the movie and the book.
" Because they killed the thinking machines. They- The Butlerian Jihad. Yep.
If you're a real Duner. Yep. And you know that, right?
Serena Butler and the war against the thinking machines. I did not know any of the names other than the war against the thinking machines. I'll- You have a better memory than I do.
No, I reread them all the time. Oh. I love the...
So I've not only read the Frank Herbert Dune books, but I've read the sequels and prequels- Okay ... by his son and Kevin Anderson. And at the end of the whole Dune universe, the thinking machines were there the whole time, pulling the strings.
Spoilers, dude. I'm just... Look.
I know. I gave up on book three or four because- Well, I don't think they'll ever see a movie ... they got a little weird.
Well, it did. Well, the Frank Herbert one got weird there. Yeah.
But the prequels are fascinating because it talks about the war against the machines. And then the sequels pick up from the prequels. Yeah.
So it is... Yeah. We've probably used our time and nerded out a little bit here.
Yeah, we did there. I'm sorry for the "Dune" deep dive, but whatever. Rich, it's always a pleasure, man.
Oh, man. All righty. Thank you.
Hey, we're live. We're at Techstrong. I am Techstrong.
We're at RSAC. We'll be back in a moment. Hey, everybody.
Welcome back to Amsterdam. We're here at the KubeCon + CloudNativeCon Europe Conference with my new friend, Dirk. How you doing, Dirk?
Nice to meet you. Very well. All right.
We're having a little chat about cloud operations. We're companies, Emma Technologies, they're kind of an up-and-coming player in this space. But before we get started, what is happening with cloud operations in general?
Because it used to be kind of we managed all these clouds in isolation, and maybe are we starting to unify this a little bit, and what's driving all of that? Yeah, I think it's a good starting point because when you look back in when Emma was founded in 2021, it was still clouds, different clouds. Multi-cloud very often happened by accident or by acquisition.
There was no deliberate choice. Now, fast-forward five years and multi-cloud is actually there. It's a consequence.
It's because companies need to have solutions. They need to have solutions for sovereignty. They need to have solutions for AI operations.
They need to have solutions for whatever business needs they have. And with more players next to the hyperscalers coming into the marketplace, there's more diversity, there's more complexity, there's more fragmentation, and that's also where Emma comes in as a cloud operations platform where we unify the operations across those platforms or across those players in the cloud industry, including on-prem and including the cloud industry. Mm-hmm.
And it seems like what's changed, too, is organizations are more comfortable with putting workloads in different clouds in different places, and there's also even a movement, in some cases, back to on-premise because of AI. Yes. So are we making more deliberate choices- Yeah ...
about where workloads go, and it's not just kind of this... I guess for a while there, I kind of felt like the cloud, what was the question was the AI kind of thing. Yeah.
I think cloud's a more strategic choice these days. When you look at sovereignty, for example, it's a boardroom topic. There's a lot of decisions made on boardroom level saying we need to go and be sovereign in sovereign operations.
And then, of course, the teams have to figure out what does it mean, what kind of level do we need, what providers do we need, where do we go, can we stay with hyperscalers, do we need European providers, do we need to go back on-prem with certain things? So that is the complexity that is happening, but the choices are definitely more strategic, and it's coming not only from regulatory, so sovereignty, it's coming also from cost pressure, and it's coming also from every other things. And not to the least, cloud skills.
Different providers, different skill needs, not enough experienced professionals on the marketplace, so that means also where choices happen. I always felt, too, that people didn't fully appreciate the total cost of hiring different teams to run different cloud platforms. Yeah.
Because the labor was still the most expensive part of that. Yeah. So have you seen people get a little savvier about understanding where their costs come from and how to streamline the management of multiple clouds as a result?
FinOps is one great example that's came up, and it's evolving very rapidly, going from traditional cloud operations into other sectors, including also then AI. That is quite clear. But yes, there's a lot of discussion around how do we make this happen.
The new needs of the ways organizations operate in terms also from experimentation in AI, going to production of AI, need more resources, need more orchestration of what they are doing. They need also more control over what they are doing. Cost is one part of that.
There's more cost savviness already today, and also that drives decision. Do we need to keep these kind of applications or models and data in these data centers or these providers, or are there more cost-efficient alternatives? But of course, always without having any compromises on performance.
Mm-hmm. Now we're here at the show, and as I understand it, you guys had an announcement here talking about support for brownfield environments. Yes.
So what does that mean exactly? Well, Emma was traditionally a greenfield platform, so customers came to us deploying their resources, infrastructure through Emma into providers. But the majority of companies, a large amount of companies, still have their applications and data running on-prem.
That's also what we said, you can't manage only part of your environment. You need to manage it in a unified way, coming back to the unification world. So that's why we announced brownfield onboarding, which will allow our customers and companies to bring in their accounts from GCP, Azure, and AWS, gain the full visibility without migrating their resources.
It is about discovery. It is about governing it. It's about making informed decisions and starting also to pave way into do we need to stay with certain applications with our current providers?
Can't we see where cost-effective alternatives are that don't compromise on performance? And how do we go from provider A to provider B to fulfill current needs or future needs of the business? Do you think there'll also be more migration of workloads?
I kind of feel like historically we deployed something, and we left it there because we were afraid to touch it. But I wonder if, to your point, as people evaluate the costs or the needs- Yeah ... of the application change, will there be more migrations?
Yeah, I think migration is a data cost question alsoIt's how do you move data from A to B? We see this from conversations we have with partners, is, well, if you as a neo cloud, you want to gain more business, you need to get more applications and data from others. But how do you get the data in without your customers paying too much for the egress?
Well, Emma has a solution also. We are probably the only solution in the space that has its own multi-cloud networking backbone. So we can allow customers over our backbone to transfer data at one third of standard industry prices around.
That would facilitate, enable the data migration. But again, that's a business decision if that needs to happen or should happen. You can't walk down the show floor without somebody leaping out to tell you about their great new AI thing.
What impact is AI going to have on cloud operations and the way we should think about this? I think as everything. As everything.
You can't do without AI anymore in your daily work. I'm a marketeer, so even in marketing, you work with your AI, your agents, you're trying to get more your productivity up, without also compromising on quality what you do. In cloud operations, it's going to be the same.
AI ops. It's not only operations for AI, but it's also how do you make your operations smarter? How do we get the algorithms predicting more?
How do we do things that we help the people who operate cloud environments with AI? So that's also, for me, the philosophy of AI, is making people smarter and do more work as they did before. And I think part of this conversation too is we're running a broader range of workloads.
Mm-hmm. We're going to have AI coding tools creating more software than ever. But this team isn't going to get any bigger, that manages the infrastructure and that environment.
So is part of this issue, the math around how do we make an existing team, enable them to manage IT at a level of scale that not too long ago would've been unimaginable? Yeah, but that's also where Emma comes in. That's where we also look at when we talk to people and platform teams, how they need to manage their infrastructure.
They have a lot of work with that. So for us, it's like, well, you do your work, you develop your application, you do your coding, and you use Emma for the deployment of the infrastructure. That's what Emma today does already automatically.
And we are also looking into how can we deploy agentic AI to make that even more smoother for the users of the platform. Nice. As we go forward, are you seeing the roles of IT people change?
Because historically, we always had like, there was a virtual machine specialist and a networking specialist and a storage specialist, and is that converging more, and what is the future of an IT organization look like to you? Difficult question. For me, always, when I look at how organizations work, and there's the future of work thinking is, you have the specialist, you have the generalists.
Emma's a no-code platform, which means also it can be used by business people with a non-engineering background. So that makes also that you can use a more diverse working population and profiles in your operations, and that is also how it should work. Democratize the technology, make sure that non-engineers can use it, but with the necessary guardrails, with the necessary governance, which comes on top of that.
Right. You of course have a platform that in my mind works horizontally across different platforms. Mm-hmm.
When I talk to IT people, they often are attached to a particular management tool because it came with the product or the service that they're using. So where is that moment where they go, "Aha, we can think about this differently"? " Yeah.
" Yeah. When somebody tells you in the organization higher up, "We need to diversify, we need to gain leverage. " Mm-hmm.
Then it starts becoming difficult, and that's also where the conversation start for us is like, we can make this happen with Emma. You can spin up the environments. You do not need the qualification skills for that second environment because that's what Emma does.
The abstraction layer that helps you to spin up the second environments, and forth. So what's next for you guys? Where are you going from here?
Where are we going from here? Well, Brownfield was our first step. I think there's going to be more and more around AI, how to make this happen, how to help customers to not only find the right resources they need, deploy what they need, and how to work this, and make sure that all of these things happen all within the sovereignty in mind.
It's data, it's running, it costs money. It is putting companies at risk. So we are going further in that direction.
We also have our own infrastructure in Luxembourg's data center because that's also required. There's scarcity and we can also help our customers with that. So we try, we want to be the most versatile platform on the market that allows cloud operations in whatever directions our customers want to go.
Mm-hmm. One of the things that we've been tracking is the rise of platform engineering, but it's one of these things where every second person that I talk to about it has a slightly different definition of what that means. Yeah.
From your perspective, what are you seeing? Are you seeing more of these teams and what are they focused on? Yes.
The internal developer platforms, a lot of companies have that, but you need your team of developers to develop it, to maintain itAnd that's not always that easy. And that's also where we say, well, you can have similar capabilities with Emma off the shelf, but platform teams, yes, they prefer to develop their own solutions internal and maintain this internally. That's how we have the conversations also where we come in as alternative to existing platforms today.
So what's the biggest challenge when you go talk to these customers that they're sharing with you in terms of their pain point? What is it that kind of is keeping them up at night? What keeps them up at night?
Cost is one. Clearly, you're in Europe, here in KubeCon for the first day, there's also sovereignty on the agenda. So for the European organizations, that is definitely a big point.
And mostly it is not one or the other. It is a combination of things. How can we do the right thing without neglecting something else?
How can we do AI without paying too much or jeopardizing on sovereignty? How can we be sovereign in our operations without losing the innovation potential that we had before? So how do we make this happen?
How do we operate this? How do we orchestrate this? All right.
Well, folks, you heard it here. Change is hard, unless of course you got the right platform. Hey, buddy, thanks for being on the show.
Thank you. All right. And we'll be back in a minute.
Hey, everyone, welcome back here to TechstrongTV. Our next guest is Stephane Danze. He's the CEO of a company called AODocs.
Don't worry if you never heard of them. We're going to tell you about them. But first, let's hear a little bit about Stephane.
Stephane, welcome to TechstrongTV. How are you? Thank you for having us.
I'm great, thanks. So Stephane, as I mentioned, you're the CEO of AODocs, and we're going to talk about AODocs in just a moment. But give people a flavor for kind of how you got here, what your journey's been like.
Sure, yeah. So I'm an engineer initially, and my first professional experience was with a company named Exalead, it was a French search engine, both on the web and on enterprise documents. And so I built the core of the search engine for a few years, from 2000 to 2006, '7.
And then I moved to the US to help commercialize it here. So that's how I got-- You can hear from my accent, I'm French originally, but I live in the US since more than 16 years. And then the company was acquired by Dassault Systems, a big PLM company.
Sure. So that's taught me for a few years how to sell business critical software in America. And it was an interesting experience because I realized that having the managed-- helping companies manage their business critical information had a lot of value, be it 3D design documents or others.
So I was there and I wanted to do my own company, but I didn't know exactly what to build. I was very concerned of the risk of having a genius idea that nobody would want to build. So I was kind of running in circle, and I ran into my previous investor, who was still in France and who had started something else in the cloud services company.
And I realized that the cloud was the architecture of the future. It was something interesting to build. And that he, with this services company, could have access to customers who would have problems, who would generate an idea.
So by grounding my nascent business in ideas coming from companies, I was like, okay, there is a chance to build a product market fit since the idea comes not from me, but from customers. And very quickly, those customers of this service company were saying that they wanted to put not only their email and calendar and so on in the cloud, but also their business documents. And there was no document management system in the cloud.
All of the document management markets till today is old on-prem technology that was not designed for the cloud. So there was all the ingredients, a business problem, something business critical, document management, new technology in the cloud. There was all ingredients to build something new, and there was a population of early adopters, the companies who had already chosen to put their email and collaboration files in the cloud.
So we took all of this, and I started AODocs associated with this service company so that we could bootstrap the whole. And to this day, AODocs has never raised money. We have built the company entirely on bootstrap revenue until AODocs was profitable in 2022.
So it's a very uncommon story of a startup. It's the old-fashioned way, right? You earned it.
Yeah, exactly. Yeah. But it gave us some, let's say, a down to earth approach that I think our customers appreciate.
They appreciate that we always-- We don't BS them, so to speak. We always down to earth, including on AI, what works, what doesn't work. We're very reliable and very trustable people.
And for the business we do, taking care of the business critical documents of our customers, it's very important to build trust. We work with companies like Airbus, like Google for their data center construction plans, with Veolia for building water treatment plants. So the documents we manage for our customersAre the most important documents of the company.
We help them ensure that they use the right version of the right document. We help them put these documents in process, put traceability everywhere, and of course, add AI on top of it in a reliable manner, which I think is in line with your next questions. Excellent.
I love it. Hey, just quickly though, the website? Yeah.
com, A-O-D-O-C-S. And if you wonder what it means, Ao is the Polynesian god of the daylight, and by extension, it's the god of the cloud. So docs like documents, Ao like the god of the clouds, documents in the clouds.
Well, I meant. Love it. Excellent.
That's one of the nice things about interviewing founders and stuff like this because, and CEOs, because you get these little backstories, where'd the name- Yeah ... come from and so forth. All right.
When you started the company, you didn't think you'd be out here talking about AI and its effect, though, right? That's right, yeah. Not this quickly anyway.
But it's changing everything. I just got back, I was out in San Francisco last week at the RSAC Conference for Security, and it was all AI and agentic AI all the time. The whole plane ride home, I'm playing in my own agentic AI, playing, working in my own agentic AI- Yep ...
platform, doing things. What has this meant for AODocs? Yeah.
I think there's been two big moments, right? And people don't realize that... Everybody knows about the ChatGPT moment.
Okay, 2022, all of a sudden, we can chat with something that looks intelligent, and all of a sudden, there's a machine that understands text. So for us, it was a first revolution, and frankly, that's something I've been waiting for all my career, because even back in my search days in Exalead, we were trying to get some semantic from the text, right? It was understanding the difference between orange the color and Orange the company, and all of that kind of stuff.
So all of a sudden, AI was able to understand a text, summarize a text, and it changed. It was a first revolution for us as a document management because instead of asking humans to tag documents manually, to put it in the right folder, and in a huge amount of manual work, which was forever the biggest hurdle of adoption of our kind of product. All of a sudden, we can tell people, "Hey, just put the document there.
" So first revolution, the ChatGPT moment, AI computers are able to understand text and do something with it instead of only work on structured data. But then there's a second revolution, and I don't think people realize that it's as big as the first one. 6, and Claude.
It's OpenAI Codex. It's the ability of agents to really start doing things for a long period of time. Before the end of last year, an AI agent was able to do a single task.
Do this, 10 seconds later, you have to give another instruction, 10 seconds later, another instruction. And now they've reached a point where you can give an agent a mission. "Okay.
" And it works alone for 10 minutes. " And it works for two hours, and you come back, and it's done. It's not perfect.
It's still junior level work. But you can give missions to an agent to work for a long period of time. So it changes really everything because now you can treat agents like end users.
And that's what's provoked the SaaSpocalypse issue with the valuation of SaaS software, right? The actions that are usually done by humans can be delegated to agents. So maybe now I need 10 users instead of 20 users to do a certain operation in a certain software.
For us, I think it's beneficial in the sense that those agents to work correctly, they need a solid foundation. They need to work on the right documents. They need to be able to put their work with traceability somewhere.
So we provide, let's say, the concrete slab on top of which you build your things. If you write code a business application and you let the agent decide itself what is the storage, how the documents are managed and so on, you're in for a lot of trouble because you're asking a junior developer to make all of the hard choices regarding how you manipulate business critical documents. But on the other hand, if you ask an AI agent to build an application, let's say, to manage your maintenance work request in your hospital, right, something that you shouldn't mess up with.
But you ask the agent to put everything in a specific document management workflow in this AODocs system that is reliable and so on. You know the documents will be taken care of, then your agent can focus on the user interface, on the mobile app, on all of the things that matter to your business users while you protect the company by putting the data somewhere solid. So we enable the use of vibe coding business applications.
We enableThe autonomous agents that will run in your company do stuff because you know that they will not mess up with the data as long as they are putting it in a safe, centralized system. And you can have 20 different agents, 200 different agents, and vibe coded applications all relying on the same centralized system. If you don't have this, you fragment everything into 200 different databases with lots of poetry and improvisation on how the data is handled.
But if you put those 200 applications on a single solid foundation, now you have something that can scale in number of applications and remain compliant and traceable and all the good stuff that you need for your business documents. So we position ourselves in this era of vibe coding and autonomous agents as the foundation on which we can build things that manipulate business critical documents. I got it.
But, I can't help but I'm listening to you, Stephane. So, they talk about replacing all the junior people. Yep.
Right? And I understand why one would say that. But until our AIs can have a little more common sense, you know what I mean?
Yes. Can distinguish between certain things, because even a junior person can do that. And, so this goes to something...
And as a CEO myself, much like you, I'm learning, we're all learning as we're going here, right? We're making it up. Very sense.
Right. Yep. We're seeing what works.
Day by day, week by week, things change. But I still believe in my heart, whether you're a junior or a senior worker, if you embrace this technology, but don't think it's replacing you or just let it run amok or run wild. But if you channel it, use it correctly, you 10X yourself.
You can 10X yourself- Yep ... and make you, I don't care whether you're a junior, senior, or post senior, you make yourself much more valuable in the market to your employer, to your next employer, and everything else, right? Yeah, absolutely.
I think the multiplier depends on your seniority. Juniors will 2X themselves. Yes.
Senior can 10X themselves, but it doesn't matter. It's a new skill to learn, like I said. To me, the first step, and I had that conversation with some junior staff in our company, before asking the AI to produce stuff, use it to review your stuff.
You build something, you ask AI to review, give you ideas of improvements and so on, and then it speeds up, it increases the quality of your work. And then once you start to understand how the AI, where the AI is good, where it fails, then you can upgrade little by little and make it do stuff. But it's a learning curve, and I think there's a shock right now because everybody is discovering the technology and adjusting their hiring plans based on that.
But once we pass the shock, we get into a new normal where, okay, onboarding a junior is no longer let them do the boring work to learn the trade. Is that you take them directly to more advanced work and learn to use the AI as a sidekick. But if you stop hiring juniors, who are going to be your seniors in five years, right?
So I think there's a temporary turbulence. There are positions that disappears. It's a fact.
You don't need people to translate text anymore, so that kind of specific tasks will disappear. But the new equilibrium between humans and AI will settle, and then it will be the new normal. But right now it's very turbulent because everything is changing so fast.
Like I said, in the last six months, it's a complete revolution. And I'm very surprised talking to people. I was at a conference last week in Chicago.
Most of the people in the room, meaning CIOs and IT leaders, were not aware of the fact that everything changed between, let's say, November and February this year. They still- Absolutely ... have not integrated.
I agree with you. So as I said, I was at RSA C, Security Conference. I actually gave a talk, Mitchell Ashley and I, about developing and security, and it's to this exact point.
The whole AppSec, application security market, was based on finding bugs. We scanned, we tested, we fuzzed, and we found bugs, and we gave you bugs and say, "Fix the code. " So the emphasis was on finding those bugs.
Now with Claude Opus, Claude Security, and not just Claude, they all. With AI, we can find so many bugs. Not all of them are critical, but we find so many bugs that it overwhelms you.
Yep. So the cheese has moved. The emphasis is no longer on finding bugs.
It's on governance of code. The bottleneck used to be an average developer, what did he make? A couple of dozen, maybe a couple of hundred lines of code a day at most.
Oh. A really good. Oh, yeah.
Now you've got these machines that are turning out thousands of lines of code a day. What does that mean for the world of security? We couldn't secure the amount of code coming out before.
How are we possibly going to secure the amount of code that we're turning out now? Not without AI, not without autonomy and autonomous scalability. Yep.
And I think that's exactly what you're talking about as well. Governance is the new- Yep ... problem.
I think there's an aspect, and going back to what you were saying about common sense, an aspect we didn't cover is using AI to find information, right? When you plug your AI on your company's file, right? " No, because AI assumes that everything you give it is- Is equal ...
reliable. Is equal, exactly. Exactly.
And AI is very good at semantic matching. I have a question, I will find all the documents that relate to that question, contain a potential answer to that question. But what if the document in question is 20 years old, right?
It's the N minus five version of the maintenance manual of your industrial robot, and everything has changed because now it's not this button first and this button second, it has reversed. And if you don't follow the right procedure, boom, or you lose your arm or whatever. So AI is unable to distinguish between something obsolete, something not validated, something bluntly incorrect.
" Nobody raised their hand. " Two, three hands in the room. It's 90+ percent temporary files or whatever.
Right. So if you ask critical question, if you want reliable answer, your banker answering about an interest rate, your maintenance technician asking about what should I do with this or that error code, right? If you are asking questions where you cannot afford to make a mistake, you need to make sure that your AI is working only with the golden copy, the correct version of the documents, and for this, you need governance.
AI is not smart enough to find the right document. Why? Because the information's not there.
xls. Which one is the correct one? If you don't have the tag, if you don't have the metadata that tells you this is the price applicable today because the end of your discount is over, and we're in such and such region and so on and so forth, all of this contextual information is not in the file somewhere.
You need to give it to the chatbot. Otherwise, it will pick one randomly because all five spreadsheets have the same semantic score in terms of relevance to your question. Yeah.
" It has very hard... So how it's the best? You know how it always suggests- How do I decide best?
Right ... it doesn't have a criteria. It tells you it picked...
Well, that's a whole nother discussion we could have. Exactly. That's where the common sense comes into question.
Yeah. As a human person, if you see five files that have exactly the same name, you're like, "Whoa, danger. " Who wins?
Not the AI. So I wrote an article. When I was a kid, there used to be a StarKist tuna commercial, right?
Charlie the Tuna was always trying to get picked by StarKist by showing them he had good taste. Yeah. " And AI, that's the problem we have here.
My taste was bad. We want AI that tastes good, not good taste, but we need it to learn good taste. Stephane, we're over time.
I got to end this one up, but great conversation. Appreciate it. Good luck with AODocs.
Come back, keep us posted on what's going on. Yeah, of course. Thank you for having me.
Bye. All right. Thank you.
It's our pleasure. Stephane Dantozy, CEO, AODocs, here on Tectron TV. We're going to take a break.
We'll be back. Control, this is Agent Dev. I'm in position.
Copy that, Dev. Standby for go. Standing by.
Hey, everybody. Welcome. You've joined us for another episode of Agents of Dev.
I'm Mitch Ashley. I lead the software lifecycle engineering practice with Futurum Group, co-hosting this podcast with Brad Shimmen. Welcome, Brad.
You are practice lead of... Data integration. Sorry.
Data engineering. Sorry. Data intelligence, analytics, and infrastructure.
I'm trying to grow beyond the basics because apparently, we're moving past all of those mundane use cases and job roles now. Everything is engineering. We're all builders.
We're all... That's what we're becoming. Oh, no, we're just intent shepherd.
We're just shepherding intent. Yes, there's a lot of truth to that. It is fascinating how, just my mind getting around what this change really is about, and I feel like I'm just starting to really grok it.
And graph it- I think you're ahead of the class then, sir, because I- Oh, I don't know that ... this week, I'm at Microsoft Fabcon and the first-ever SQL Con, which- Uh-huh ... I love the fact that we're actually starting up a conference in 2026 about SQL.
Oh, Renaissance Week. Okay. It's brand new.
Never been seen or tried before. Anyway, it is amazing to me just how much energy continues in our little industry around AI and in the midst of a complete lack of understanding of how it actually works. Yes.
I don't know, but it's going to be great, right? Exactly right. When we get there, we'll know it.
Something like that. Will we? I don't know.
Will we? Well, the target will have moved. That's the challenging part.
That's exactly it. That was the target. Zeno's paradox where you never get to the finish line.
Mm-hmm. Because you're always just partly there. It's a journey.
It's the journey. For sure. Well, hey, let's do the call-out segment.
You want to kick that off? Yeah, sure. So, I try to keep my eye on the news while I'm on the road, which is never easy, but it did capture my attention, a small release by a certain data warehousing company called Snowflake.
They rolled out a new product called Snow Work, which may sound somewhat familiar if you're familiar with Anthropic Claude Cowork. There you go. Because it is literally the same idea, but envisioned and delivered within the ecosystem of Snowflake.
And what's great about it, I think that you and I talk about this quite a bit, is agentic software development is really a bellwether and a pointer for where other markets are going to go. Mm-hmm. And I think that the things that we've learned about agentic development are now trickling into or avalanching, snow, get it, into other aspects of data practitioners.
And so Snowflake is really taking the idea from Anthropic and applying it to things like having a conversation with your data that can take action, that can do things, and do things with much more trust and belief in the data that you're actually looking at, because- Mm-hmm ... for those of you following at home, within the data space for quite some time now, we've been trying to be able to talk to data and have conversations with data, and that was through NLP and other type technologies which forced you to know exactly the names of the columns and whatnot when you typed your question, or it would be wrong. And we are apparently, hopefully moving beyond that, and this is what we're seeing from Snowflake with their Snow Work.
Ah, the semantic layer. I know that's where you were going eventually. It is exactly.
Yeah. That is big time at this conference, at the Microsoft conference that I'm at this week. Do you sense just kind of a change in tenor, tone, where it's headed?
It's starting into something definitely different. Yeah. I think that many of the problems that we used to face, such as building and maintaining data integration pipelines as but one of many examples, we're starting to think of AI as a means to a layer of abstraction above that- Mm-hmm ...
such that it's not just being able to automate it, because we could do that before, but it was brittle. These things were always breaking. And you would be perhaps not shocked to know how many companies currently rely on nightly secure FTP uploads of CSV files to get stuff done.
Yes. Yeah. They aren't going away anytime soon, but they may have agents doing it.
Well, they might not have to. Maybe it doesn't matter. Maybe- Mm ...
if you can have a nondeterministic system that can see the context that it's operating in and take action, as we talk about so often in the stuff we're working on, maybe you don't need to have somebody that's dedicated to keeping that thing running. Maybe it can be self-correcting. Maybe it can be preemptive in alerting me to a problem that I might not even know is happening.
Mm-hmm. I had not heard about Snow Work. Sounds like- Snow Work ...
what they do in the Colorado mountains when we do have snow. They have some snow work to do. Unless it's yellow, and then you don't.
Yes. No, stay away from that. But there's enough territory there you can usually avoid that.
This was NVIDIA GTC week, and- Yeah ... Nick and I had a chance, Nick Patience and I had a chance to do a report on that. But you couldn't cover it.
NVIDIA GTC is now the Steve Jobs announcement equivalent, where- Yeah ... all the oxygen left out of the room. It was the event horizon of which nothing else was happening.
But I think in this case, the difference is, and everyone else and their brother, sister, mother, and uncle are announcing something with that NVIDIA at the same time. Right. They're riding the coattails.
Riding those coattails. Yeah. And a big time.
It was really fascinating. But what caught my eye was, well, my ear, was Jensen spent, I don't know, the first 45 minutes, maybe an hour, talking about software. He didn't talk hardware.
That is really weird. Yeah. That's- He talked about software ...
freaking me out. Yeah. And applications, and it's like, he got the memo about software's eating the world .
Like, hey, that's very, in 19 whatever, was it 12? That is still, yes. But still relevant.
Still relevant. And he went, of course, he went into the whole Neo cloud. We'll get into that.
But what jumped out to you about GTC? Yeah, I mean, the couple things, the first one I think you and Nick probably wrote about, and I think, if those of you who sort of know of our little ecosystem perhaps watched one of our "Utilizing AI" podcasts recently where Nick and I chatted about the show. And he made note of the fact that Jensen sat down with a good number of very influential open source model makers.
And it is something that we, as analysts have chided Nvidia about in the past, mostly with regards to the software layer that sits between the GPU and the operating system. Mm-hmm. That's not always been the most open, but you can see in what Jensen's prioritization from this conference and this panel I'm talking about, just how critical the open source ecosystem is to Nvidia.
And how they want to support it. They see, for instance, that in the United States anyway, there's a bit of a pullback right now away from open source. And I should say actually, perhaps that same thing is happening elsewhere in China, and we can chat about that in some detail.
But, for Nvidia, they live and breathe with developers and data scientists and those people that work with software. So they need to not just honor, but support that community that's driving so much innovation in AI. Well, developers, you can spread that out too, are the tip of the spear.
I've said that for a long time. It's like this is where the highest degree of innovation- Yep ... and the application of AI and the transformation of what that work looks like.
That isn't happening in other areas, but developers are just wired differently. They seek this stuff. They figure out what they can do with it.
They're excited about it. They don't mind changing their jobs because they don't want to do the same boring stuff. They want to.
They seek that out because- Exactly ... they don't want to write code or document it. And they want to show their friends.
They want to like go, "Hey, look at this. " Put it up there as open source, as whatever. Yep.
So it- Yep ... still is, and I think it's going to be that way for quite some time. Now the builder- Thankfully ...
builder community will expand. And I think that- Yeah ... as you can see, I was just talking to a salesperson this afternoon, and he was talking about, "I like to make my job more efficient, and I'm not really a technical person, but, I do think about ways I could do...
" It's like, yeah, you're a builder. You have the tools to do this. We're all builders now.
If you're not already there, and if you want to do a download OpenClaw, you could. Well, because speaking of that, can we talk about OpenClaw? Can we talk about Malt Book and OpenClaw?
Malt Book, yes. What happened? So I don't- Don't enjoy that work?
Mm. I am still trying to wrap my head around why Meta would acquire, hire acquire, that asset. Because anyone who followed what was going on with that would certainly tip their head like a dog trying to hear and understand better, to say, "Well, wait a minute.
" Mm-hmm. Wasn't this really just people trying to drive this unrealistic vision of AGI? That these Claude bots at the time were all having a conversation on their own, and it wasn't actually happening.
So, don't know. But maybe we should put that aside and just talk about Nvidia, who is jumping on the OpenClaw bandwagon pretty heavily with GTC, and their Nemotron and OpenClaw announcement. Yeah.
" And by realistic, I mean something that isn't going to cause immediate and irreparable harm to whoever uses it. That's what they're doing. They're going to bring down the internet?
Or your MacBook, or not MacBook, sorry, your- Mini ... Mini, your Mac Mini. Yeah.
Right. So, here's what I think is interesting. One thing is I think, Jensen definitely got right, and he gets a lot of things right too.
Of course, he tends to create his own reality. But, is last year MCP was the thing that was the viral- Yeah ... changed everything, right?
Yeah. Because it just opened up what you could do with agents. Solved the problem everybody had, is everybody had tin can vegetables, but nobody had a can opener.
And suddenly here's the can opener. Everybody jumped onto it, right? To make a really poor analogy.
This year, it's OpenClaw, and I think it's OpenClaw because what it's done is shown... It's dropped the barrier to get into the agent creation and management and do stuff with AI. Now, maybe it's not safe all the time or done well and enterprise has a little different requirements, which is what Jensen went after- Yes ...
with their offering. But everybody's dropping in OpenClaw.... offering, right?
Or they're dropping something like it. So you talked about the work, Snow Work. Yeah.
Right. That can be seen- Complexity computer ... as very similar.
For complexity computer, and- Yeah ... they're going to come out with personal computer version of it. So I think- Or anyone using Ralph to have their agentic tooling do work on problems till they're done.
That's the same thing. We've gone into this... What was the utility knife everybody had to have?
If you remember that. Not the Swiss Army knife, but what came after that, the Leatherman multi-tool. The Leatherman, that's what it was.
Yeah. Everybody's got to have the Leatherman, right? You got to have my tool kit.
And I think that's what this year is about, is everybody being able to start to exercise what this means to use it and create agents. I think the other part of it too, you didn't say it this way, but the edge is the new cloud. When did we rush out to buy Mac Minis for anything, or the latest edge computer, for what?
Maybe to- Yeah ... do a LAN party, to do gaming. But really, the fact that we have run on hardware to be able to do this stuff locally on your own, you don't need the cloud.
It is amazing. Do you know why that it actually works? Is because of software.
Well, yeah, there's that little thing called software. And it's successful- I don't mean just possible. I mean, the reason why it's actually feasible is- Oh, okay ...
good software. You're being real. You're making a real comment, not a funny.
I am. I am, seriously. You think of OpenClaus built on one of-- I think we were chatting about this a week ago, about the pie of this rifle is mine, but in the form of an agentic harness.
Mm-hmm. And OpenClaus built on top of it. It's built on other ideas.
It's built on the work of many people. It is. That's kind of that shoulder of giants.
Maybe they're small giants, but a lot of small giants. They were all- Absolutely ... a few big ones along the way.
Yeah. Exactly. So I think the kimonos open or the barn door is open and all the animals are running out and having fun in the pasture, right?
It is a good time, and what's been exciting for me is just in my own work, so you'll love this, I've been saying this to you before. Mm-hmm. So I developed this framework, observability native, all around the premise that observability can't be an operations thing.
If agents are going to build agents, and agents are part of all that workflow happening from spec plan, all the way through deployment and beyond, whatever is beyond. It's everywhere. You can't just observe agents when they get into production.
You have to observe the agents that are creating agents that are part of the- Yeah ... underlying fabric. And so I created these seven pillars and four steps in an agent operating cycle, and had folks like you and Fernando review it.
So I gave my write-up. It's not a spec, but it's kind of a definitional, foundational document. It is very thorough, which to me is kind of a spec.
Thank you. I guess we can call it a spec. " So I gave it to my agentic operating environment that I do development with, and it said, "Yeah, we're doing some of these things.
We're doing one, three, and five already, and here's the ones we need to address. Here's two, four, and six. We can do those really easy.
Here's what we need to go change, and now what we need to fix about it. " In an hour and a half, the whole thing was instrumented and implemented, all of it. Now, there was a lot of things built, so your shoulder of giants.
There were a lot of things already in place. But if I was- Yeah. Right ...
going to start from scratch as a fundamental architecture or requirement or spec, I wouldn't have had to do any of that. It would just be built in. That's the environment we're working in.
That is heady. There are a lot of downsides to agentic work, of course. Mm-hmm.
We've talked about many of them here. But when I think about what it means to be a builder, meaning somebody who creates something, and it could be anything, not just a piece of software even, but just an idea. Mm-hmm.
Remember when you used to sit down with your trusted friend and say, "Hey, I got an idea. " And you would work through it and poke holes in it and whatnot. That took time and opportunity, and it was not fast, but we have literally sort of collapsed the time to value, if you will- Mm-hmm ...
from idea to value to almost nil with these tools. And what that means, I don't know. Well, so I think about these like you do.
I think about these things a lot, and I was on a panel the day before yesterday, and we were talking about so the first mover advantage is shrinking, right? Yeah. Because people quickly come out- Yeah ...
with their own version of OpenClau or whatever kind of in their product. Call it the 10-day mover advantage. Yeah.
It's that. What we're talking about with Claude Open. That's going to be I think that's going to get shorter.
Also, I think we're going to get to, maybe this isn't that far away, of, "Well, do I really need to maintain that code? " Ooh, yeah. When I want something Just rebuild it.
Don't take the time to go and fix it, just rebuild it. Because we get better and better at building it. It's not like our skills are staying the same, or we're gradually incrementing and our skills increasing.
If you follow the curve of models and how quickly they're improving, just how much Clod code has improved in, I say Clod, Cloud code in six months is just not even the same tool. It's not, no. It's not.
I think we're going to be at a point where software is just like mixing up a new batch of whatever. Okay, cool. We're good.
Maybe it's not even what we knew software to be. Maybe. There's a paper I would love us to dig into and talk about- Okay ...
that came out recently that talks about using a directional acyclical graph, a DAG, to define basically an intent to outcome map, if you will. Mm-hmm. And the idea behind it is to make that a deterministic system that uses a non-deterministic system, meaning a generative agentic system, to actually implement.
So you have a fixed route and a fixed outcome, but the way that you get there is up to the agents and the models. Mm-hmm. " Make it so number one.
Yeah. Well, so you're pointing to something too that also I had a bit of aha this week is, there's the model of request response- Right ... linear interaction with AI.
Do this. Yeah. Create that.
No, don't do that, do this instead. Right? This sort of what I thought originally vibe coding was.
And I don't know if vibe coding is a thing anymore, but I think the model really is about, it's not a linear process anymore. It's letting AI figure out what to do. You might want to ask it.
The tools that I work with I say is, there's a relationship we have here. My goal is to get to agentic and understand how you're going to do agentic. Yeah.
So I don't want it to be opaque, I want to understand, right? Yeah. And what it caused me to do is realize that, oh, that work was over there, but I forced it down a linear path here because I made it go do an assessment- Right, I didn't give it the freedom to choose a better route.
Yeah. It said, "This is a table lookup. We don't need to do it.
" So how do we make it agentic? So I had to really step back and say, "I'm not going to tell you how to do it anymore. " Yeah, yeah.
" If I need to do it at some point- ... I don't have to re-review that part of it. Yeah, yes you do for security and other reasons, but it's a change in how we work and interface with AI.
It's pretty drastic. It is. And it's fairly recent.
You remember how we were talking about prompt engineers as a job a couple of years ago. And this year, and then over the last year, we've been talking about context engineering, which is still highly relevant. Mm-hmm.
In the day, a year or so ago, if you worked with a model, you had to be very prescriptive, and you would use techniques like chain of thought, for instance, to help guide the model to an output. And what I've found experientially is that the less data I give it, the less instruction I give it, sometimes the better the result, because I give it that freedom- Mm-hmm ... to wander a bit as you're talking about.
There's an old Zen koan, or actually a saying, not a koan, sorry, but it is a Zen Buddhist saying about if you really want to keep your cattle, horse, or cows or whatever, don't watch them constantly. Just keep an eye on them every so often. You don't have to chain them up.
You don't have to do anything, just let them roam in the field and they'll be okay. They're not stupid, mostly. Mm-hmm.
Yeah, they may wander off the land here once in a while, but then go get them and bring them back and- That's right ... they're not going to stay there forever. But if you're holding the cow constantly, then you're not doing anything else.
Why don't we jump to our last segment? Okay, it's time for the drop. You had suggested the drop for this one, too.
Unsloth Studio. Yes. That sounds like a prompt too, another great name.
What is Unsloth Studio? Yeah. It's yet another ML Studio and yet another Ollama.
Do we need another one? Yes, we do. Absolutely, we do.
These are for those who don't use those tools, means for interacting with AI locally. And with Ollama and ML Studio, you have a lot of great capabilities, a lot of control. You can use the LLM or Llama CCP to do your inferencing, for example.
Or if you're on a Mac, you can use MLX inside of ML StudioAnd run your models quite rapidly. But what those really kind of focus on are basically interacting with models as you would if you were logging into Gemini or Claude or whomever as a chatbot. What Unsloth is known for, for those of you who perhaps aren't familiar with them, they have been an early sort of proprietor of fine-tunes, and the tools that you would need to fine-tune a model.
And not just fine-tune, but do all kinds of work, like distillations and whatnot. And they put together a ML Studio style interface that focuses on or really elevates some of the work you might be doing with models, such as fine-tuning. It's just one of many.
And one of them, for instance, I'm quite anxious to try out, is being able to... They'll have what they call recipes, where you would have a recipe for creating triads for unstructured data. So I could feed it a whole bunch of PDFs, like the presentations that we get from vendors, for instance.
Mm-hmm. And I would be able to have it basically create a knowledge graph or just a property graph out of that with all the nodes and edges that are represented in that text from those PDFs. And there's a lot you can do with that, such as use that to fine-tune models and generate refined data to do more work with that.
And so for folks who are in the AI and data fields, this Unsloth Studio is just awesome, and I encourage everyone listening to check it out if you haven't. It's just a UV pip install away for everyone. Another example of taking what took massive resources and, in this case, data sciences to do, now making its way into everyone's hands, right?
It'll become more and more accessible. Yeah. And more and more people, you too, can train a model.
Like you can train your dragon. Here, train your model. Right.
Train your dragon. Yeah. Frontier models are critical.
But they're not the only game in town. Mm-hmm. And we have seen research from early on that indicated that for more task-specific duties, like name density extraction, you would be absolutely wasting resources to throw that at Gemini or Claude.
5 is free. It may be rate limited or whatever, but it's free. Yeah.
Or you can run Gemma on your own hardware. Yeah, right. Pick your model, whatever it may be.
NeoClaude, if you got the right hardware. But that's- Nemotron- Nemotron ... speaking of Nvidia.
Yes. Nemotron, exactly. So here's my drop for the week, and it's sort of a collection of drops that form a rainstorm.
It's many drops, huh? It's many drops. I wouldn't say I'm inundated, but every day I get either a briefing or multiple emails or signals from the stuff that find out what's happening out in the world, letting me know about it, is you reviewed, and I'll be issuing the agent control plane framework document- Mm ...
this week. Probably come out the end of this week, maybe first part of next week. And everyone is coming out with their, just like their studio or their claw or their whatever for building and operating agents.
Now vendors are also starting to lay claim to, well, here's the agent control surface, control plane that has things like observability built into it- Yep ... security, governance, accountability, et cetera. So you know how you can not only manage it, but you know what your agents are doing, and are they sitting within the guardrails, and are they compliant?
Can you do governance on that? Tricentis announced theirs for... They're a testing company.
"Okay, here's the agent control plane- Ah ... " Yeah. That's brilliant.
And I can name a dozen that I think I've gotten hit with in the last week of people coming out with parts of that functionality, which I think is good. But the sort of great sorting, maybe the clone wars of the future are agent control planes fight for dominance and who's going to control the control planes. We'll see what path that takes.
Yet they all just get along. That's the way the sky is. Isn't there like a open semantic interchange idea for agent control planes?
That's- There should be. Somebody should make that. We need an agent control plane semantic layer.
There you are. Well, the OSI could actually work for that. It could, actually.
But they're not actively promoting it to do that, but it definitely could. It is a model to build from to be able to do that. Mm-hmm.
Sure. So I think the effect of that is you need that to be able to get AI into production. Enterprises won't let you take anything significant into production at scale unless you can govern it, control it- Yeah ...
have accountability around it, secure it. So everybody is naturally doing that for their part of it, so their products and tools can get into production. But I think it is going to create some forcing function to sort that out.
I maybe could have five to 10. Maybe I'd like one or two or three. Where is that balance?
Oh, boy. Maybe it's 20 because you have agents controlling control planes. I don't know what the- Don't say that.
That's way too many. It's a little circular. There's a recursive programming example.
Yep. Maybe it's a model that we're not thinking about yet, but that seems to be what's on the next horizon of, okay, I'm being overrun by control planes, folks. Help me out.
What do we do here? It's like you have catalogs of catalogs. We need control planes of control planes.
Parts are made of parts. Yes. The old- It's all an abstraction game.
Oh, boy. It's turtles all the way up. Well, next week is RSAC, the week this'll drop.
So I will be there doing some live Textron game videos there. What are you up to next week? Oh, next week I'm recovering from FabCon and getting ready to visit with people in their conference at the end of the month.
Mm-hmm. Google Cloud Next. Yep.
Yep. That's coming up. I'll be going to SUSECON in July.
That should be interesting. Yeah. With all the talk of operating systems being required to capture age verification.
Yeah, verification, lack of TSA people. Can you get back in the country? Hey, it's an adventure.
Who knows? But I'll be somewhere I can join by digitally to say hello and see what we're doing. I'm also going to the MCP Dev Summit.
Oh, I'm jealous. Which is hosted by the- Yeah ... Agentic AI Foundation, part of the Links Foundation.
Yeah, I didn't even know it was happening and they reached out, and I'm sure they'll be reaching out to you for the next one. But- Do you think they'll have a session about what comes after MCP because we all over-rotated on MCP? Well, that's my main thing is, is MCP going to stay this or is it going to become what?
What is it? Right. What is it next?
I don't know. Yeah. I've got to believe- And if it's just a lookup, maybe it's already past its sell by date, could've been something else that it hasn't grown into yet.
Is it SMP version two waiting for version three? Or is it like, no, we're going open telemetry here, full out. Let's kind of rethink this problem.
Mm-hmm. We'll see. I'm really excited to see what happens there, so.
And we'll get to do the next one together. There's another one in the fall. I forget what it is.
But I think that's in San Diego, so we'll find out what's happening there. So that's on the horizon, too. So lots of great things happening.
Agreed. Well, safe travels, my friend. Enjoy the rest of the FabCon SQL crunch- SQL Con.
Don't say that. Oh, so sorry. Sequel Quan.
Enjoy your time. Rathbon. Yes.
And safe travels this week- Same to you ... as you get ready to go and head into Google Next, and while I'm heading out to San Francisco myself. So, well, thanks everybody.
You survived another episode of Agents of Dev. Congratulations, everyone, and thank you. And it is an accomplishment, so, we have participation awards for everybody.
You'll get your prize soon. No, seriously, thanks for being with us for part of this discussion. Please reach out, follow, share.
We appreciate everything you do to be part of this community, and we'll look forward to talking with you soon. Control, this is Agent Dev. I'm in position.
Copy that, Dev. Stand by for go. Standing by.
Hey, everyone. You know, they killed Sora on us, so we got to find something else to do our videos with. But we will.
There'll be something else. Anyway, welcome to this week's Shimmy Says. I got to ask you all something, because I know me, people I know, are feeling a bit of this.
Does the world feel just a little bit crazy to you right now? I'm not talking about regular crazy. I mean, like, really crazy.
There are forces at play here beyond our control that it's just crazy. Not even the normal news cycle. Yeah, that's crazy.
Politics, beyond crazy. But it just seems like everything is going crazy. We're living in a pressure pot.
There's so many things going on day to day, hour to hour. How do you keep up with it? This one's out.
This one's in. We're doing this. We're doing that.
It's crazy. Most of all, our technology, for those of us in tech, it's moving faster than many of us can even process. We got companies laying people off.
Oracle laid off a good chunk of their whole workforce this week. Not because they're being replaced by AI. They're doing it so they could take that money to spend into their AI infrastructure product or into their AI infrastructure.
Companies are laying off people at the same time they're spending hundreds of billions of dollars. And it's not just companies. Countries are racing each other for AI dominance.
And it's not just China and the US, it's every country is trying to get their share of this AI pie. It just feels our economy, one day the stock market's crazy. The next day it's crazy down.
It's back up. It's down. It ping pongs up and down because it moves with every announcement, every earning, and everything else.
It's not every few months, it's every dayFor a lot of us, this is really unsettling. You look around and you think, "What exactly is going on here? " Some days it feels like we're heading into the biggest, greatest boom period of humanity, of human history.
Or are we walking down into Dante's Inferno's fourth layer of hell with one of the most disruptive tranches we've ever been in? Look, honestly, I think the answer's probably a little bit of both, and that's what I want to talk to you about today. Because if you're trying to make sense of the world right now, my friends, you're not alone.
We all are. On one hand, as I said, we're standing on this edge of what we think is something extraordinary, right? " Artificial AI is advancing faster than many of us even predicted.
Physical AI, or robotics, as most of us call it, is right behind it, following real quickly. And right in that rear view mirror is quantum computing. New breakthroughs every week, it seems.
It's moving from labs into real-life systems, and we've got to deal with it. But when you put those three things together, this next, the rest of the '20s, early part of the '30s, could be the most definitive things happening to humanity ever. This is akin to maybe fire, the wheel, the Industrial Revolution, and the internet.
It's going to lead, or it could lead to things like better medicine, better healthcare, better quality of life, longer life, new scientific discoveries all around, productivity gains, entirely new businesses and job occupations that didn't even exist a couple of years ago. When historians look back at this period, they may very well call it one of the biggest turning points in human civilization, and I honestly believe this. But there's another side to disruption.
They don't call it disruption for no reason. They call it disruption because it disrupts. And that disruption is already here.
And I'm sure you realize it. As I mentioned before, the news coming out of Oracle, tens of thousands of jobs cut, a huge percentage of their workforce, but not because their jobs are being replaced by AI. Don't jump to that conclusion.
That's not what happened. They took the money from laying those people off, and they're investing it back into their AI infrastructures that they're building. It's complicated.
This massive infrastructure build-out required to power AI, data centers, GPUs, networking, energy infrastructure, cooling systems, the very people to build them, electricians and so forth, HVAC people. This is one of the largest capital investment cycles that we've ever seen in the tech industry. It's not even hundreds of billions of dollars, it's trillions.
$8 trillion, maybe more. And someone has to pay for that. And when there's nowhere else to go, they're taking that money out of payroll.
So think about that. They are firing people to build these AI temples. That's what I call them, temples to AI.
The infrastructure. People talk about AI like it lives in the cloud. No, it lives somewhere.
It's not just floating up in the cloud like the grandma in the IBM commercial used to point to. AI infrastructure is very physical. It lives in these town, citywide physical facilities, enormous facilities.
And we call them data centers, but that doesn't even do it justice. You got to really think of them just like the Egyptians built temples back in the old days. We're building temples to AI.
They require unbelievable resources, electricity, as I mentioned, water, steel, concrete, specialized chips, networking. And then what we've seen, people don't really talk about it, but we saw it come out today, tradesmen. We need electricians and pipe fitters and construction workers.
And you know what? We don't have enough of those trained people, and a lot of them that were, were immigrants that we just kicked out. So there are places, believe it or not, right now, where data center projects are being delayed because we just don't have enough skilled workers to build them, even if we had the power, the water, the chips, and everything else.
Power itself is one of the biggest bottlenecks. We've got to build out our whole electric grid, and none of us want to pay for it. Let the people on the data center pay for it.
The energy demand from AI data centers is just skyrocketing, and our utilities are doing everything they can to scramble and keep up. Communities are pushing back because of their water usage and their land consumption and the noise it makes. But yet it's not slowing down.
The race continues. Because whoever builds the most capable AI infrastructure may end up controlling the future of technology, and with that, end up controlling the future of mankind. Here's another issue to think about, the debt question.
It's another layer to this. When we first started this build-out, all these Mag 7 tech bro companies were sitting on billions, tens, even hundreds of billions of dollars. But that money went up like in the first wave.
Now we're seeing massive debt to finance these AI build-outs because how many people can you lay offAnd how much money is that going to get you towards building out these data centers? So huge amount of debt being accumulated. The US government's no different.
We're in this up to our ears. We're financing enormous technology transitions. At the same time, we're carrying historic levels of national debt and adding to it every day.
Our debt exceeds our GDP, and no one can tell us how bad this balance sheet's going to look like 10 years from now. But we're all betting on the same things, that investing this enormous amount of money right now will result in the gains that AI eventually will eventually justify this investment. My friends, that's a really big bet.
I'm not saying it's a bad bet. I'm not saying it won't come true, but we're living on the edge. It's a really big bet.
But let me come from that and make it personal to you. The craziness you're feeling, a lot of it is insecurity about your own future. Let's get away from the global level.
It's you, it's your job, it's your career, it's your family. If you haven't thought about how AI might affect what you're doing for a living yet, then one of two things. Either you're lying to yourself and me, or you're just walking around with blinders on, waiting for something to fall on you.
But for the overwhelming majority of us, this should be a real concern. You got to be thinking about it. Whether you're thinking about it late at night laying in bed, or during your commute into the office, for those of you who go into an office, maybe when you see another headline about this company's layoffs or that company's layoffs, it's got to strike home to you.
And you know what? You're not alone. It's a fair question.
And in fact, it's the right question you should be asking. What does it mean to me? So what should you do with all of this?
Well, I wish I knew definitively, I tell you, but my advice is really simple. You don't retreat. You don't freeze.
You got to dive into this. You got to dive in headfirst. You got to learn how to use these tools, experiment with them.
Upskill yourself. Don't wait for it to bite you. Every company on Earth right now is asking the same question: How do we do more, better, for less?
AI, that's the whole point of this AI thing. It's forcing organizations to rethink how work gets done and how our workers work in it. I guarantee you, your employer's thinking about it.
Your competitors are thinking about it. Every startup founder on this planet is thinking about it. And you should be thinking about it, too.
If you're not, you're going to miss the boat here, and it's not going to end well. There's a global race going on, everyone. You zoom out further from the personal to the organization, to the national level, and every nation is trying to figure out where they stand in this new world.
How do they remain competitive? How do they remain sovereign and not dependent on another country? How do we make sure the next generation of technology is not controlled somewhere else?
Whether it's the US, China, Europe, the Middle East, even South America and Africa, and of course, Australia, we're all investing heavily. Semiconductor supply chains are ready-- Well, it's not much of a supply chain. It goes from Taiwan to everywhere else.
It's under intense pressure. AI infrastructure, national AI strategies. Should we have them?
Should we not? Some people compare this moment to the Cold War and the space race that took place then. In some ways, this is even much bigger than the space race because this competition touches every part of the global economy: technology, defense, manufacturing, healthcare, finance, everything.
It's big. But here's the opportunity, and that's the good news. Here's the good news.
Hidden inside of all this chaos that you're feeling, of all that's swirling around us, is something still really incredible, and that's the opportunity. Because the opportunity here is the greatest I've ever seen as an entrepreneur. The greatest entrepreneurial opportunity of our lifetimes is sitting in front of us.
I was an entrepreneur before the dot-com, and I was an entrepreneur during the dot-com and after the dot-com and all the way through today. I spent decades building companies, and I got to honestly tell you something. My brain and my heart are racing every day in seeing what's possible with AI, with agentics, with everything going on now.
Because the opportunities, the possibilities are endless. Literally, one person, a laptop, and a powerful pipe into one AI system, you could build things that once required teams of dozens of peoples and engineers and months and years with departments and companies and capital. No more.
History shows us something interesting. A lot of the greatest companies in the world get started during periods of disruption. When big orgs are reorganizing, when people are leaving these large companies with real training, skill, and know-how, when the old rules stop working, we may be heading into another one of these moments right now.
So I fully expect to see a huge wave, maybe like we've never seen before, of new entrepreneurs, people starting their own businesses, building new products, solving problems that didn't even exist five years ago, coming up with novel ways of solving problems that did. But here's the reality. I'm not going to sugarcoat it.
Not everyone's going to see it this way, because there's always people who stay behind, the laggards, people who refuse to believe what their own eyes and ears are telling them. We see it in so much of our society today. They think their opinions matter more than facts because everyone should have an opinion regardless of the facts.
But we see that, right? It's part of the problem in our society. But my friends, the writing is on the wall.
The world is changing, and it's changing a lot faster than you may realize. So if you're trying to make sense of this crazy world and period that we're living through right now, let me leave you with this. Yes, it's really disruptive.
Yes, it's quite unsettling. Yes, it raises real questions about jobs, our future careers, and the future in general, our children, our countries, our planet. But it's also the greatest technological adventure humanity has ever embarked on.
And adventures are not meant to be watched from the sideline. They're meant to be lived through. So get in the game, learn the tools, build something, start something, push yourself, because the future's not going to fall on your head.
And if it does, it's going to kill you. It's out there waiting for people who have the imagination and the fire to go get it. And that, my friends, is how you make sense of this crazy world right now.
I'm Shimmy. I'm out. I'll see you next week.
Shimmy says, Shimmy says, Shimmy, Shimmy, Shimmy says, Ask me almost anything Okay, so our next section is going to be talking about the securing of data. So last we spoke about the understanding. This is really a follow-on to that around how do we help our customers not only have an understanding of that data, but how do we enable them to secure or see the flow of that data, the lineage of that data as it moves through the life cycle management of that, but then equally coupling it with what Veeam's been doing to what Emily said in the last session as well around our security story from an integration point of view, but also what we've built into the platform already.
So I'm Michael Cade, Field CTO at Veeam. I'm Emily Taas, Field CTO at Veeam. Okay, so this is really about how do we mitigate risk, how do we reduce that exposure of good data?
And generally speaking, in that last section was many of our customers or many companies out there today haven't got a good grasp on the data that they've got anyway. So they haven't even got to this secure. They might have bits and pieces across their estate, but ultimately they don't have...
The analogy I use internationally is the garage at home, right? We store everything in our garage. We move house, bigger garage, hopefully, if we're doing good, and then we move all of that stuff, and we just, "Oh, we've got a bigger garage.
" And that's my analogy. There you go, Tom. But the analogy fits for enterprise data as well, right?
We just store everything because we're humans, right? We love to store it. And that's fine if you want to keep on buying the storage, whatever that storage may be, in the public cloud, on prem.
Storage companies will sell you more storage. No worries. From a security point of view, though, who has access to that?
Because that posture is what's going to stop, or it's going to be the difference between someone taking that data, encrypting that data, or doing bad things with that data. So having a good grasp or a good posture against that is really where we're focusing on this, and then we'll go into how does that feed into the Veeam story as well. So I mentioned around security being a data security posture management tool, but put a plus on the end around governance, compliance, and regulation.
But from a security posture rule, who has access to what? Who does what? What is the data?
Is it an AWS 3 bucket that's open? What data does it contain? And almost wrapping those policies, those frameworks around that data set so that you can protect it better, but also just have visibility of it.
Like if you have an AWS S3, and this is just an example of a best practice in the public cloud that is very topical, S3 buckets being exposed to the world. Let's flag that so that you can at least do something about it. So it's almost, I would say, a lightweight ticketing system.
However, it does link into the likes of ServiceNow as well to be able to say, "That S3 bucket that you've got over there is open to the public. " But equally, it could be about data moving from one country to another. From a, again, as a Brit on tour in the US, data sovereignty is a massive thing.
It's not just where your data is located, it's actually the legal jurisdiction of that data and who has access to that. If you're moving data from the UK to Germany, and you're meant to be in that, you're adhering to data sovereignty rules, that data from a legal jurisdiction, if someone's got access it from Germany, it doesn't matter where it's stored. So there's a lot of different posture to consider there.
Quick question. Charlotte here, known as Gifted Lane. So what I'm starting to think about now is like when, say, something like that happens, is there like an alert or something that goes off and is it email?
Can you do text? Is it Slack or Teams? So yeah.
Great question. So yes, it can be. It can be any of those.
It can feed into ServiceNow or SIEM platforms. Also from a dashboard point of view. Now, I don't expect people to just live it...
We're not just going to have a DSPM... human to look at this dashboard all day, every day, but it will be flagged up and visualized there, as well as the reactive reporting as well. So really, this is about having a good grasp on what that data is, where it's going, who has access to it.
Also being able to get those reports or having visibility of when people have too much access into those data systems as well. It's very easy. We've all been through the you get god mode, you get god mode, and domain admin here, there, and everywhere.
And it seems like potentially with agents, identity is going to be a massive thing that we're going to have to deal with from a resilience point of view, but also in enterprise IT. Who has access to what? That agent has access to everything because it makes my life easier.
I'm just going to unlock the world to it. No. We have to have a good control plane for that.
Let's say someone has god mode or an agent has god mode or something like that. Is it weekly reports or something where maybe it gets flagged to say, hey, you may want to rectify this? Or how is the customer notified?
So, it's all based on a policy. So if you want it to be real-time, whenever we're picking up that change, then we can see that and feed that into those systems to be able to get that. Feeding off Shala's question.
Sky Fugate. I know that you mentioned agentic identity or AI identity, and finding what has access to the resources across your environment. How are you making those determinations?
How are you saying, "You should have access to this. You shouldn't have access to this"? So that comes down to the policy.
So we can bring in policies, frameworks, but we're not deterministic to who should have access to that. So we're just going to flag up who has access to it, and then it's down to the data system owner, the app owner, to determine, actually, they shouldn't have access. That group shouldn't have access.
So we're not doing anything to say you shouldn't, but you can be quite granular. I'll bring up the sovereignty story again, is that if you've got a user that is based in Germany that's accessing data in the UK, then we can flag that. Again, the user is going to put that logic into the system, because in some companies, Germany to the UK, accessing data is going to be absolutely fine.
In financials, that's not going to be fine, or another industry. So a lot of it, the building blocks are going to be put in place from us, as out of the box, and new ones can be built as well. So if you've got your own regulations or compliance rules that you want to bring, then you can create custom ones.
But out of the box, we're going to provide these ones, and you choose what ones you want to use. So this gives me a framework that I can then go enforce my own policies and internal memos. Correct.
Okay. Exactly. So if a country doesn't maybe have to adhere to GDPR, but they like the idea of GDPR, but they like the idea of the EU AI Act, they might merge those and create their own custom regulation that they want to adhere to, to be more hygienic from a data perspective.
Yeah. I think about it in a way that we can, even here in the States, we could take an AI policy that's highly recommended, like the Colorado AI Act. But then if we're doing business in different states, and each state is rolling out their own regulation, well, now it's an opportunity for those businesses to go and say, "Okay.
" And so from our perspective, it's more just providing that contextualization piece and pulling in all of those different types of frameworks that an organization can utilize. But then up to them to take action on the actual ownership of that data. " It's more so we can make sure that they're fully informed of everything that's happening within that environment.
Thank you. Mm-hmm. You- Was there another...
Well, I was just curious if you partner with any IAM providers, companies, things like that, that actually can do remediation. So in other words, you do the reporting. You say this is, okay, HIPAA, you've got a bunch of HIPAA violations, and then your partner product, you can feed them, and they'll do the remediation?
Because there are products out there that'll do that. Yeah. From a remediation side better.
I don't know off the top of my head. We integrate into the Entra IDs, the Optas, the et cetera. Okay.
I just don't know whether we integrate enough to tell it to revoke access. Sure. That would be a very good follow-up to come back to.
I mentioned about this as well, about redundant, obsolete, and trivial, or if I've mentioned ROT data, that's the acronym that I'm using. And there's two areas that this is important to, and it resonates with our customer scope at the moment, is one about reducing cost. There's not a company out there that doesn't want to reduce cost or mitigate risk.
That's number one bullet point. If you can help them do that, then we're always going to have a conversation. But reducing cost of...
To that garage analogy that I used, you've moved all of that data from garage one to garage two to garage three, enterprise storage, enterprise storage, and you're just adding more data to it. If we can help the customer understand duplication of data, but also just old data. What's not been touched in the last six months?
Is it sensitive? Do we need it? Make that decision tree so that they can reduce the cost.
Now, I'm not saying delete it. That might be an outcome of that. We're not going to delete it.
We're just going to flag that up. We're just going to visualize that for them so they can make that decision. But equally, how can we help them tier that off into a cheaper, deeper type storage plane as well?
And on top of that, from a security point of view, if we get rid of six-year-old data, six-year-old sensitive data, we're just reducing the attack surface. But also we're not muddying the water. If you've got the same document repeated every year that contains the same data, or differing data, like reports, et cetera, then you're getting rid of that muddy garbage that could be influencing what we're going to get to later around being able to leverage and use and unleash that data.
So there's two folds to redundant, obsolete, and trivial. One is being able to reduce the cost, but also mitigate the risk. If you don't need it, let's get it out of that.
Oh, and bricks. But yeah, what does that look like? In terms of visualization, how do we show that?
But that's across all of your data systems as well. So I keep on referring to the Data Command Graph as a social network of data. So you've added in all of your data systems, structured, unstructured, databases, NAS, et cetera, and your identity systems and your cloud, and all of this is building up this social network of all of the data that you have.
And you can then run a policy against all of that data to tell you what's old, what is redundant, based on the characteristics that you want it to be. Everything has been fed into this graph database, the Data Command Graph. So you can then run queries against that data to be able to give you an outcome of that, whatever you want.
Maybe you just want to see what that looks like. How much data do we have that's six years old? So this is where I want to marry up the two between what Veeam's done over the last, feels like 10 years, of security integrations and security advancements within the Veeam product, but then also that access suspension that I touched on.
So if you think about the production side and all of those different data systems, let's understand the entropy of that data. What is that data? What data is contained in there?
Sensitivity of that data. We're going to have a good understanding of that data, which then allows us to flag up anomalies, who's accessing it from that country, but then two hours later, they're in New York, and that is not possible, and they're making changes. It is possible for VPN, but yeah.
But you get my point, is that it gives us a good understanding of the data, the securing of that data, the flagging of when bad things could potentially be happening, and feeding that into other systems to be able to act upon that. Which then leads us into some of the stuff that Emily just touched on, but then more so going into the security integrations that we have. Right.
So when we thought about building a lot of our security-based integrations from a Veeam standard, we thought about it in terms of, okay, well, we have access to the data as it lives in a backup. So really when we think about this, we're marrying the two of what can we do with the primary data and where it lives at source, and then what can we utilize that to make better decisions on the secondary data or your backup data itself. And a lot of the tools that we've integrated into the backup data portion of it is really what helps us to create those better outcomes.
So if we think about it in terms of threat scanning, well, now I have the capability to do inline-based malware detection. Now I have the ability to leverage ER rules that are provided for me from my security team. Now I have a capability to search for indicators of compromise and what those tools possibly look like.
We could do file system activity analysis, understanding when data becomes encrypted or when there's large changes that are made that are symptoms of encryption. And then we can also leverage our security partners or that broad ecosystem to pull in what it is that they're seeing from a production side and be able to flag that data that could be seen as malicious inside of the backup data, so that way our teams, from an IT operations standpoint, know that that data is not going to be ready or clean or verified to be able to perform a recovery. It makes them do an extra level of due diligence.
So our ecosystem is pretty large. We add a new vendor, or a new sticker I would like to say, almost every couple of months. Actually, our head of product management is here at RSAC, and we have probably 16 different meetings set up with all of these broad vendors.
So when we can talk to organizations and integrate into their SOAR platforms, we can leverage SIM, we can integrate with ITSM, we could do things around KMS, and then even storage integration. I think I will say that from a storage perspective, I think that's my next one, this is brand new. This just GA'd a few weeks ago.
So this is actually with Pure Storage. So essentially we have this capability here where essentially what Pure is doing is that they're understanding from a storage perspective of where those virtual machines are living. They've identified a potential anomaly that is happening within the production environment.
So you can see here, like even from an ecosystem perspective, those companies that weren't in the business of security are making some very large strides to provide additional information around risk mitigation for customers, right? And so this anomaly and awareness workflow is one of those next frontiers that you're seeing from a production storage use case. But now just think, if we have all these different signals, if you have signals from your storage or ASV, you have signals from your DXPM-based solution, if you have signals from your EDR tools, and now you have signals from your backup tools, how much easier does it get for that security analyst to sit back and say, "Okay, I can actually see a pattern here, and I can understand what this pattern is, and I can understand what that full risk assessment looks like.
" It's all about just creating those signals, so that way the security teams that are in charge can actually make more informed decisions. Just on the Veeam incident API, so that's a public API that is exposed from a Veeam perspective. Just because that previous slide has loads of logos, if there's something that can trigger an event to say something bad is happening, weather's come in, it can hit that API, and it can enforce that backup, that point in time copy of that data.
Yep. And so even on top of that, so we have purpose-built applications that are built within each one of these security vendors' marketplaces. So they could go and you could download a specific Veeam app for Palo Alto, for CrowdStrike, for Splunk, for Sophos, whatever it may be.
But Veeam still integrates through just standard Syslog. So if there's a platform out there that a customer is utilizing, if you're an SMB customer that's not paying an arm and a leg for a specific SIM or SOAR tool, and you're leveraging something like Adios or one of those others, you could still forward these events that Veeam is capturing from an inline or from a before an incident takes place, or an after an incident takes place, still capture those events and forward those to a SIEM tool of your choosing. The beauty is, is that you have both options to kind of leverage this.
And then what you're seeing that's being scrolled over on that slide next to me is these are all the different types of events that Veeam is actually categorizing. So we sit down and we look at, okay, well, before backup happens, this is what generally happens, and this is the information that you should be aware of. That document was actually generated with working with a cyber lead defense architect for a customer of ours in which she said, "Hey, I don't actually want to know your guys' platform.
" So I said, "Fair. Fair point. Let's get you an actual documentation of every single event, how we're categorizing it, how we're mapping that to the MITRE ATT&CK framework, and then also we'll provide you guys with some outcomes.
" So she actually took that information, she integrated it with her Splunk environment that she has. She built an app that'll correlate all the rules from everything else that's being fed into Splunk, and then she forwards that as a SEV 1 alert into Palo Alto Networks XSOAR. So if everything flags as a SEV 1, meaning we see some anomalous activity, we're seeing from a data perspective from the backups that we're flagging this as suspicious or malicious.
She has an incident response playbook that runs inside of Palo Alto Networks that creates a war room. It highlights all of the application owners for that specific machine that has been flagged, and it starts what we call as an incident recovery. And it starts to run that inside of an isolated sandbox.
It starts performing regular scanning, even if it's just AV signature scans. And then it puts everybody inside of a Teams chat and says, "Go start investigating this particular application, because we're seeing EDR tools flag it, we're seeing Veeam flag it. " And so she actually built that as part of a community project, so if anybody is a Splunk, Palo user, and Veeam user, you can actually find that information available today.
Quick question. So this is making me think back to, so with like the RIT reduction, is the sentiment that is helping make recovery, like improving recovery confidence or speed? What are your thoughts about that?
I will say that-- Oh, so I'll let you answer from a POP perspective. Yeah. You go, and then I'll- Okay.
So for us, it's not about speed, especially from like a ransomware or like a cyber breach incident. Speed used to be the biggest factor from like an operational resilience guideline, right? We had data center failure, we had hardware failure, need to recover fast.
Right. Cyber, you don't want to recover fast, right? We want to recover and make sure that we actually know the data that's there, it exists, that we're recovering the right data, that we're not risking reinfection, right?
It's a lot more of a staged response. This particular integration with what we're trying to do with bringing all of these components together is trying to make that more informed decision on how do you correlate an effective response without impacting a speed of performance. Meaning that, well, once we have all the things in place, we can click Go, and we know all the teams are going to be doing what they need to do.
And then how do we actually validate that it's going to be clean recovery? So for us, it's more about making sure that we're providing all of those essential elements, so that way they can make a more informed decision. But from a ROP perspective, it's probably more so leaning into that understanding and contextualizing the information first.
Yeah. But if we think about the understand and the secure side, if we've got a good grasp on that data, our customers have got a good grasp on that data, and they can tier that. I'll simplify it into like gold, silver, bronze.
We can protect that data. We know that that's been impacted, or maybe it's just silver. You know you've got a better idea on what needs to be recovered as well.
So it comes down to, it depends how fast that needs to be, but also how can it be safe. But equally, if we know where the gold data is, we can bring that back faster. We can get that up and running, get it scanned so that we're not reintroducing bad things into the environment.
But at the moment, we're just backing up everything, and we're just going to bring back everything, because every app owner's going to tell you that their app is the most important and their data set is, right? So this is about the understand and secure on top of what Emily said is going to give you a good viewpoint of what's the most important, what absolutely needs to be clean when it comes back into the business. I think that would be my answer on that.
That's plain. Yeah. So, this is just a quick show and tell of one of the integrations.
So this is one of our latest ones with Microsoft Sentinel. So customers that are leveraging the Sentinel platform, right? We built two purpose-built dashboards, right?
One that actually does data platform monitoring, meaning now you can actually be informed on what IT operations look like. Do we have backups that are running? Are they hitting SLAs?
Do we have missing backups? Do we have failed backups? So this provides that additional context for those that are sitting inside of the security space to know, okay, what does our backups actually look like?
And then from a security activity side, we can pull all that information that we're contextualizing, right? So meaning we see potential backups that are seen as malicious or suspicious, and we've marked them as possibly infected. So that way they need to take a secondary look before they just go and run to recover them, right?
So this is very important from a security point of view, because again, we're providing information of something that maybe used to be a black box that didn't exist inside of their world. " Well, now they could actually see that in the platform that they utilize, that they know, that they trust, and they can see that information in here, and they can take additional looks without having to go and drive directly into the platform itself. " Well, now I have these automated playbooks that I can create, that I can generate.
We have ones that we built for some of those customers already, so they have a standard template that they can utilize and that they can go ahead and clone and make changes to. But these are some of the ways that we look at customers that have already invested inside of their SIEM or SOAR tools. " No, we just want to plug into your multimillion-dollar investment that you've already made and make sure that your teams have all the right information so they can make better decisions.
I just want to make a comment. Shala was onto something about ROT data, and it makes other things better, like disaster recovery. Just like that much to the garage analogy.
A lot of orgs struggle to keep just basic blocking and tackling. Imagine if it was the correct set of data, and then people end up understanding, and explainability- Mm-hmm ... of what they have is a kind of a hidden benefit downstream of ROT analysis.
Yeah. And I give a perfect customer example, right? There's a customer I worked with that has their dev environment alone was over 10,000 machines.
And they're like, "How do we even start with an orchestrated response? " Right? " So the fact that they'll be able to leverage some of these tools to get that contextualization first, so that way they can make those informed decisions about building out those workflows, is pretty large from a customer standpoint.
That makes me think of another question. So are customers able to, whether it's set up a cleaning room or whatever, do a dry run of their DR, like what they think they're going to do, so they can actually test it and not test it on the day that something actually happens? Absolutely.
So in some of the sessions, well, we didn't get a chance to really get into it too deep, but we could do three different types of reporting, but also three different types of testing. One of those is the readiness check of just saying, is all the underlying infrastructure and what we've actually put out in this plan actually going to work? Meaning, do we have backups that are meeting the RTOs and RPOs that we've already set up and that we've classified from the customer standpoint or from the business?
Does the infrastructure that we're writing to, meaning if we're sending it to VMware, if we're sending it to HyperV, we're sending it to Azure, do we have the right access credentials in there? Do we have the right CPU, RAM, storage space that's needed in order for us to perform these restores, or is it going to fail? Do we have the right network or credential access as well if there's specific applications?
And then on top of that, we can even inject different types of scripts as well as steps. So my example just showed performing a restore of that virtual machine into another hypervisor platform. But we could also take it a step further and say, this is a SQL database.
So we could run those readiness checks to validate that that underlying area is going to work, and then we could also run it inside of a test, which is with our data labs that we've had for close to 10 plus years. Run it inside of the data lab, validate, see it come online, send out a report to say, "This is what we have," and knowing that it didn't actually run inside of production. So Jack Palmer here from Paradigm Technical.
So for things like the readiness checks, are you requiring the user to tell you what needs to be done or are you inferring that from your knowledge of the environment? Both. So we're pulling in from the backup policies that they've already created.
So that's how we're creating based off of the RPO and RTO. But if a customer goes in and they're creating their runbook and they put, "Well, our RPO is 24 hours and our RTO is one day," and then we go and look at the backup policy and we say, "Well, you just put a machine in there that doesn't get backed up once a week. " So we're using the intelligence of what they've already put in from a backup policy perspective, and then we're referencing that back based off of whatever the customer put as what they think their RTO and RPO should be, and we're showing them discrepancies there.
So I'm thinking more of the example that you said, which was, this is a database server, so it needs to come up before the client machines that are going to access it. So are you also requiring that level of input from the user, or are you able to infer that from the data graphs that you have? We can infer from the data graphs of us pulling in that information.
Actually, that would be more of a where we're seeing these integrations going, of taking in with this newest acquisition and pulling that information in. " So right now it's more of a manual process, but with our integration of this piece of the data graph, it'll make us do more informed base policies. So thank you everybody.
With that, that ends our session for the secure pillar. Stay tuned, we're going to click on resilient next.