Techstrong TV Monday, April 6, 2026
In this episode of Techstrong TV, Alan Shimel and Mike Vizard bring together leaders across AI, cloud, and cybersecurity to examine the rapid evolution of enterprise technology. Karthik Kannan of Anvilogic explains how agentic AI is transforming SOC operations, while Himanshu Singh of Broadcom/VMware highlights the convergence of Kubernetes, VMware Cloud Foundation, and private AI.
Gregory Kurtzer of CIQ shares new approaches to AI infrastructure and edge-based agents, and Tiffany Treacy of Microsoft discusses the rise of multi-agent systems and human-in-the-loop governance.
The episode also features insights from Tom Hollingsworth and Alastair Cooke on RSA Conference trends, along with Rick Vanover and Emilee Tellez of Veeam on strengthening data resilience in the age of AI.
Transcript
Hey everyone. Welcome back here. We're continuing our afternoon coverage of this Wednesday afternoon here at RSAC Conference.
My next guest, and I hope I get this right, is Karthik Kannan. Karthik is with a company called Anvil Logic, and if you don't know about them, don't worry, you're going to after this. But first, let's hear a little bit about Karthik before we get to Anvil Logic.
Karthik, welcome to Techstrong TV. Thank you, Alan. Pleasure to be here.
So let's start with you. Give people a sense of how you came to be here, what your career has been like, what your passions are. Sure.
Again, thank you for inviting me. This may be around the 10th or 12th RSA Conference I've been at, maybe 10th. Been doing companies in this space for quite some time now.
This company, Anvil Logic, we co-founded about six and a half years ago in 2019, pre-COVID. Prior to that, my career has been mostly in the cybersecurity GRC, big data analytics space. Uh-huh.
My previous company, Caspida, was the industry's first machine learning-led user behavior analytics product company, which got acquired by Splunk. Okay. I ended up working at Splunk for three years- Mm ...
running a portion of the security analytics business, which I'm now working with or displacing now at Anvil Logic. Prior to both of these companies, I did another company called Cetus, which was a big data analytics platform company, way before the cloud data warehouse time that we are in now. It was in the days of Hadoop.
Mm. If you remember that? Yeah.
Yes, I do. Okay. Not fondly, I bet.
No, but you want to know the truth? I remember when Hadoop was spun out of Yahoo. Yeah.
That's right. Right? Exactly that.
And the other thing sort of- Yeah. Exactly right ... that's got...
Yeah. Well, we've come full circle with data warehouses now on the cloud, like Snowflake and Databricks, and- Mm-hmm. Yep ...
I'm glad to be full circle back, but working at a better time of both gen AI and cloud data warehouses. So I think in all of my companies, we were ahead of the times, and now we are squarely in the times, so I feel pretty good. Anyway, that said, Anvil Logic is a six and a half year old company.
We are venture capital funded. What we are is a SOC automation platform company. Naturally, rendering things with AI and whatnot, but really the core function of what we do is provide automation to various persona workflows in the SOC, whether it's data wrangling and data engineering, or detection engineering, hunting, tuning, et cetera, or triage and investigation.
All of that is baked into our platform. We've been spending six years building it, and now we are surfacing all of that up through AI agents. We'll talk more about that.
But that's really in a nutshell what we do, is sell the platform to automate various functions of a SOC in a large enterprise. That's who we are. I love it.
Got it. So, you mentioned Hadoop and AI. Back then, Hadoop claimed to solve the big data problem.
Yeah. That's right. I think we needed AI to help solve the big data problem, right?
Exactly. Without AI, we weren't really solving it. Yeah.
But, in prior life, I did three or four venture backed startups myself, and one of them was we had an MSSP play, and we had the SOC, and had a lot of experience doing that. And again, we didn't have AI in those days either. Running a SOC was, you could figure out how many people you needed to man the SOC on a 24/7, 365, and that was an easy formula.
The formula for what tools we had, the data we had, how to get actionable intelligence out of that data, right? This is before there was a Snowflake and before there was Hadoop. And as you said, you probably hated it.
Yeah, I had first hand experience. But the world seems so much different now. Yeah.
Right? The technology is so much better now. Now, as you said, you started six and a half years ago, 2019, the year before COVID hit here.
In 2019, though, you didn't see gen AI or agentic AI coming in here. Let's talk a little bit about what that means for you, though. It had to be change your whole mission-- Not mission, because the mission probably stays the same.
No, the mission's the same. The way we do it, how we accomplish- Right, your whole way of approaching it. Exactly right.
This reminds me, in "Iron Man," Stark Senior says in a video, that he was limited by the technology of his times. Yeah. That's exactly how we felt back in 2019.
We knew what we wanted to accomplish, but no one knew gen AI was coming. Right. But it was such an easy thing for us to adapt to it because we were building the architecture, waiting for something like that to happen.
So we were even pre-gen AI, machine learning, and predictive analytic oriented. So our job was always reconsidered to provide recommendations to the practitioners to help them do things. Not just be a technology platform.
To be something that automated workflows. So you could come in and guide on what you wanted to do, and we would do it for you, right? Because even to use gen AI today, two things have to come into place.
One is you have to know what you are looking for or seeking to build. " That doesn't work. So that's number one.
You have to know what you want. The second thing is you have to be able to have domain knowledge to verify the results and make it better and close the last mile gap. Those are the two foundational principles we've incorporated into the platform, so gen AI can work for us and not against us.
So we spent, like I said, we are six and a half, nearly seven years old. We've been spending all of this time building that system of record platform. The platform, even without gen AI, can still do the mission.
It just is helped and moves faster with gen AI. So we take a look at everything we do in three pillars. One is, like I said, the data management, the data wrangling, bringing data on board, ensuring the health of the pipelines, all of that is so integral to your detection strategy.
Yes. That's pillar number one. We've invested a lot into that, native pipelines and whatnot.
Number two is all things detection engineering, which is the one thing that was really sorely missing in all of the legacy SIEMs, and I come from that world. Most of my team comes from that world. And that's why we built this company, to make sure the art and science of detection engineering was in the platform.
That includes building detections, scaling detections, tuning and verifying, closing the loop, coming back. Hunting too is part of it. And the third pillar is what do you do when all of this surfaces up with alerts, is triage and investigate them.
And that's where we've gone into in the last year. And this is where the announcement we have announced this week comes up. I'll talk about it in a minute.
But those three pillars really constitute the platform. Now, if you think about it, there are various personas and workflows embedded in those, and that's what now we are surfacing up with AI agents, saying, "It's in the platform. " They can either be a human in the loop approach or completely autonomous.
It's up to you. And then the triage investigation piece takes us into a net new market called SOAR. Until now, everything we did was SIEM.
Mm-hmm. And we shook that up. And we took another legacy construct of SIEMs, which is an attached proprietary database in a SIEM stack.
" Sure. And that's something we did by creating that layer of abstraction. So Anvilogic is that layer where your hands on keyboard are and eyes on glass.
But really what's beneath is not one proprietary data layer or structure. It can be- It can be anything. It can be your Splunk with a Snowflake, or a Splunk, Snowflake, Databricks combination.
What- Could plug it in, it's agnostic. Exactly. Agnostic.
That's the right one. And then we'll get to the announcement we made this week. But that's really the construct.
Okay. So back to your question. The technology of our times are helping us achieve that vision much faster now and give you, the end user, a much better experience than- Absolutely ...
having to navigate 45 screens or write code or whatever. No. Someone once told me, "It's always better to be lucky than smart.
" Both is good. Right? We'll take both.
And I don't know if it was lucky or smart in this case, but- Smart people around me, for sure. Sure. Yes.
Yes. That's my management philosophy, too. Exactly.
I don't want to be the smartest one at my table. Never been. Nope.
Me either. This really is a technology that really, AI has just been able to turbocharge it. Yep.
Right? Yeah. And I think that's what it is.
So you mentioned the announcement here- Yep ... at RSA twice. You can't keep teasing us.
What's the announcement? Yeah. There we go.
I'm glad you asked. Mm-hmm. So what we announced is something called Blueprints.
Mm-hmm. Blueprints is our automation layer for the whole workflow that I just described. The first use case of Blueprints is investigations.
So today in the investigative world, what happens is a playbook is created, and it's mostly created by the smartest tier four, five analyst who's had institutional knowledge, lots of training, years of experience, and has been there and done that. Taking that and converting that into an automated playbook is really the purpose of Blueprints. Obviously, gen AI and LLMs help make it smarter, provide more recommendations.
But that's not all. All of the contextualization we bring to the table through our small language models that are built into our platform, and the transformations that come with it and the enrichment that comes with it, helps makes this a highly intelligent, autonomous, automated playbook. And that's what Blueprints is all about.
Now, while I describe this with the example of investigations, which is the last stage of this whole workflow, you can extend this concept of Blueprints into any major workflow. " The whole cycle can be automated through Blueprints. But we want to crawl, walk, run, so we're going to take investigations to be that first use case, automate that, take all of the institutional best practices that are there in large enterprises, convert them to our blueprints, and automate and make autonomous as much as possible.
While you construct a playbook, you can have a decision box in the middle that says, "Is this the right thing you want to see? And automate the whole thing. So in a nutshell, Blueprints is our way of implementing automated workflows across the product, but it also takes us into this new market called SOAR, so now we can be a SIEM and SOAR in one AI SOC platform.
Huge differentiation because we've kind of been building this over years, and now finally gotten to that last step of the vision. I love it. It's available now or now it's coming?
Available now. It is pre-GA. Okay.
We have design partners that are working with us. We will announce GA sometime in the April-May timeframe. Month or two.
But it is available for all practical purposes. You know what we did? The website, so people can go check this out.
Yeah. We made some announcements this week. com/blueprints, takes you straight there.
You can go to our homepage and see a demo video of it in action. Excellent. So you've mentioned you've been coming to RSA 10 years.
I've been coming 25 years, right? What do you think about this year's event so far? This year, of the last two to three years, I'd say, I think has been much more active.
Yeah. And I don't know if it's because of us or generally the conference has been more active because of AI, but I've almost not been able to go to the show floor. I went- Oh, I haven't ...
once for half an hour on day one. We've been booked up in meetings at the central meeting this year. I think that's the story here, is everyone is busy in meetings.
Yes. But that's always... Truthfully, look, the RSA Con, even back when I co-founded a security company in 2001, exhibiting here through 2009 or '10, this was always a conference for the security industry by the security industry, and I used to try to convince my board that it was okay.
Back then, we were spending $75,000, $100,000, which was a lot of money back then. It's a lot of money now. Even now it is.
And we weren't really getting a lot of sales leads. But, A, if you weren't here, people questioned why weren't you here? And B, again, it was for the industry by the industry.
This is where you form partnerships, relationships, deals are made, ideas are exchanged. Yeah. And so I think that stays true, right?
It is true. There's a lot of things that happen off on the side, in side rooms, in hotel areas, all over the place. That hasn't changed.
No. Has not changed. No.
I think it's partly also because of our execution this year that I feel good about RSA this year, is the conversations are great. AI's obviously changed a lot of the conversation, but the fact that we've been active in meetings means our team is working hard making those conversations possible in one-on-one settings, private settings. We are moving the ball forward.
We're meeting with a bunch of prospects between yesterday, today, and tomorrow. That's great. We've been back to back with meetings, and these are great forward-moving conversations.
So I feel particularly good about this year than I have in the last couple. Good for you. So I'm happy to be here.
Absolutely. Well, Karthik, I want to wish you well. Congratulations.
It'll be interesting to see how this plays out, right? Yeah. Because we're just, this agentic kind of revolution, and I think it is, is going to end up being bigger than generative.
And I think when people have the ability to just access their data and take actionable intelligence out of it, and because I see it in our own company. You can't imagine all of the different permutations, all the different ways they take this. Maybe ways you're not even thinking of.
Mm-hmm. But it'll be interesting to see how it comes out. That is true.
I think customers are going to push us into use cases- That you didn't think ... that we did not imagine. Exactly right.
And that is our job, is to have a platform that is extensible. That, right, that people can run with. It's not a single purpose.
Right. Yeah. Because I think in today's world, that's what people want, right?
I think that's part of the reason why open source is so popular, right? Yeah. I take the base, and I could build, I go anywhere I want with it.
" And so that's, I think, the kinds of platforms that people want to work on. Yep. You're right.
Thank you for having me. Pleasure. Al.
Karthik, one more time. com? com.
That's right. Check it out. Hey, we're going to take a break here.
We're live at RSAC. We'll be back. Hello, everybody.
We're here in Amsterdam at the KubeCon + CloudNativeCon Europe Conference, and we're having a little chat with my friend Himanshu Singh from Broadcom about, well, what's going on with VMware and Kubernetes. Welcome to the show. Thank you for having me.
This is fantastic. We're super excited about being at KubeCon. It's the preeminent conference in the Kubernetes space and for the platform engineering community, so we're glad to be part of it.
As I understand it, there's been some new extensions made to VKS, and maybe you could walk us through what those are a little bit. But as it looks to meI think you've added support for the container networking interface, and you are kind of now building out an ecosystem. So what does that look like?
Yeah. And I want to kind of maybe even take a step back to bring people through kind of what are we really delivering overall, right? So of course, the primary offering we have is VMware Cloud Foundation, which is the private cloud platform, and VKS, or vSphere Kubernetes Service, is an inherent integral part of that.
And VKS delivers a CNCF-certified, fully conformant Kubernetes runtime, right? So for the platform teams to be able to use and build all applications. Now, along with VKS, we also include a variety of other building block services, VM service, volume service, network service, private AI services as well, because AI is a topic that you can't have a conversation without, right?
And so the idea is you've got all the building blocks in VCF overall to kind of build whatever modern application you are building, your AI application that you might be building. And it's fully extensible to any third-party service that is CNCF conformant as well, right? So what we're trying to do now is in addition to, for example, you talk about CNI with VKS, we ship in a built-in CNI with Antrea.
We include Calico in there as well, open source Calico. 6 release that recently came out, we're introducing the idea of bring your own CNI. So, you want to do any third party CNI.
In this particular case, you want to do Calico Enterprise maybe, you want to do Cilium, for example. Absolutely available. This actually takes the point of view we've had with our Kubernetes platform and kind of extends it.
The point of view being that we're not trying to create a highly opinionated ecosystem of our own. We want to be part of the existing community ecosystem. So the way we have built VKS, it is very, very close to the community of Kubernetes, which means that, one, it's easy to adopt, right?
There's no customizations and all that that you got to do or jump through hoops and everything. Also, it helps us release newer versions of our Kubernetes distro very, very quickly right after the community release comes out, typically within 60 days, right? So that helps.
In addition to that, we're also being able to provide support for multiple releases, like N minus 2 or more than that. We're including 24 months of support for all our Kubernetes releases as well. So what that does is it simplifies things from the platform team for the infrastructure teams, so that, one, you don't have to worry about, hey, all these different applications need to be upgraded to the newer version at the same time.
Every different team can be on their own timeline when they want to. And also by having that kind of long-term support included, it just reduces or eliminates any kind of, "Hey, we only get 12 months of support. We need to buy extra support and all that," and those kind of things.
In terms of Kubernetes, like, the community comes out with a new release three to four months. So it's just for us to be able to do that with 24 months of support, you're going to be able to upgrade within that timeframe, no problem. So it just simplifies things a lot overall.
So from a Kubernetes perspective, that's one area we're really happy about. The other thing I wanted to also call out is with the new release as well, of course, and folks might not know this, as part of the VCF platform, we are providing or entitling you to Ubuntu OS for free as included. However, if you'd rather have RHEL, for example, and you want to use that, you can bring your own RHEL license.
We support that completely as well. So it again furthers the idea of having a very open platform for you to be able to use the tools and the technologies that you really like, build it on the VCF platform, build it using VKS, whether you're modernizing an existing application, you're building new AI applications, for example. So I think that has been something that's been very core to VMware over time, and we're really excited to be able to continue to focus on that kind of mindset as we go forward.
It seems like we're starting to see more convergence. And early on, I might have seen a DevOps team or a platform engineering team managing Kubernetes in isolation on a handful of workloads. Now it looks like Kubernetes is becoming more mainstream, but it still runs on a VM most of the time.
Yeah. So it seems like we're moving to some point now where those teams can work a little more easily together because there's administrators that know all about VMware, but there's not many of them that know about Kubernetes. So how do you kind of make this team work a little more hand in glove?
Yeah. And this is a topic that's very, very common across organizations. One is about, hey, we've got people who know the platform.
Can we help them up level and upskill them to be able to expand their scope of influence, growth in their careers, for example? Then also looking at, can I do things in a more consistent way, no matter whether I'm using virtual machines or containers, or I'm trying to build a new application? Can I avoid creating these silos, right?
And so with VCF, that's been very fundamental to our cause. So one, as an admin, you can deploy VMs or containers, containers running in virtual machines, so they're getting all the security and isolation benefits that VMs get. But you can do all that with the same set of consistent operations.
So you don't have to kind of completely learn a whole new skill. You extend and build on what you already know, and you grow yourself from being an IT admin, a VI admin, to a cloud admin, to a Kubernetes admin, for example. And so that's a key benefit of that.
You get all the governance policies, all the control that you need, but you're able to then provision your infrastructure for the person wearing the platform hat at that point in time. I don't want to say a platform team because you made the exact point of this is converging, and then we're seeing the same thing. People are wearing multiple hats.
So when you're wearing that platform engineer hat, hey, because theThe VKS as a Kubernetes platform, it's CNCF certified, is extensible. It runs all your applications, right? So that worry is completely out of the question.
You get that support, et cetera, that we talked about that simplifies things. And it just comes with integrations with all these kind of common PE tools that you'd use, whether it is Argo CD, whether it is Helm charts, for example. So just to your point about, hey, how do we simplify things?
That's the idea with built-in integrations. On top of that, in fact, the other thing, what we're doing is, we're not trying to create an ecosystem of our own, right? We're trying to integrate into the existing ecosystem when the way we're doing it, we're making sure that there are validations available on VKS with a variety of other cloud native leaders in the community, in the industry.
In fact, at the conference, we announced new partnerships, or new collaborations that we've had with folks like F5, folks like Kong, Tigera, et cetera. And so that it just... When customers are looking to build on VKS, it's easy for them.
You've got reference architecture, technical guidance, et cetera, that's available to them. And this adds to all these similar kind of guidance that we have with others, like Run:ai, for example, or MuleSoft, or Cosmonic for WASM. And so I think just bringing it all together, the key idea is we want to make things simpler and easier, more consistent when it comes to the cloud admin persona or a platform engineer persona.
And if you look at it from an organizational perspective overall for the decision-maker or somebody with a P&L kind of responsibility, one, hey, all of this contributes to you being able to modernize your applications at a significantly lower TCO, while you're getting all the benefits that VMware has built into the platform over multiple decades, right? The enterprise-grade security, compliance, all the reliability that comes with fundamental VCF platform, no matter what kind of workload you're trying to build on it, right? Whether you're deploying on virtual machines, you're deploying on containers, you're trying to do an AI application.
And to your point about skill sets earlier, right? That this is extremely critical because it helps to, again, not create the silos, but also be able to make sure that your organization and the resource of the people you have are able to grow in their roles and be more productive, and not have to worry about certain things that the platform and the consistency of the platform can take care of for them as well. So I think, across those different types of roles that people play, we're super excited about how VCF and VKS are playing that role to make things easier for our customers.
Now, we're also seeing a new type of workload in the proverbial IT zoo, and it's these AI inference models that are coming through. Is that going to force this convergence conversation? Because I can't really have a third set of teams to go support that either.
So is that kind of the thing that's really going to break the proverbial camel's back and get everybody to reorganize? No, I hope not. And fundamentally, while I think there's the data scientist kind of team that typically is generally a team as well, and they're really focused on getting the best out of the model, the LLM that they're trying to do.
And as I mentioned earlier, those private AI services that VCF comes with, we've got a set of capabilities really for that persona. But the idea is, hey, you can extend the same platform, build in the same consistent way, and you're going to build it on Kubernetes, right? If you're building an AI application today, you're building it on a Kubernetes platform.
So VKS becomes that substrate that you can build your AI applications. When it comes to the infrastructure side of things, we're giving you that set of capabilities, whether it is things like being able to monitor your GPU utilization and all sorts of different metrics, having consistent dashboards in your existing VCF console to be able to get all those details in there. But also for the data scientist, you have services, for example, if you need to build an agent, there's an agent builder service.
There's things like data indexing, retrieval services. There's a full model runtime that comes in. There is something called a model gallery, which helps to make sure that one, you have a role-based access, for example, so the right people are able to access the right set of models.
But also that you have the governance to make sure that you're not just downloading a model from somewhere and starting to use in your enterprise. Because fundamentally, and unfortunately, we've seen this in the industry already, where people don't realize that they're using models that might be public, and they are using internal IP or data to query and do those kind of things, and the model ends up kind of absorbing that internal IP, which is never good for an organization. So fundamentally, we kind of put our foot down and said, "Hey, when we look at private AI, we look at AI, we're thinking of private AI in terms of privacy of data, security of data, compliance as a key piece of it, making sure that a company's internal IP is protected.
" No matter where you're deploying. You can be deploying your private cloud environment on a hyperscaler, at an edge environment, at a CSP, for example, or in-house, kind of on-prem data centers. But the same benefit setup that the VCF platform is able to provide to any workload is applicable for AI as well.
So that's kind of the way we're looking at not creating this separate silo, separate team, but bring it all together. People can specialize in the areas that they're trying to do, as a data scientist, for example, or as a platform engineer, for example, but you're building on that same consistent platform that is able to meet everybody's needs as well. As we look at this convergence and all these things coming together, will we reach a point where maybe we need to fundamentally rethink how the IT team itself is organized and is another way of thinking about this?
Yeah. That's a very interesting point of view. There's always going to be, as we kind of talk to customers, there's more and more expansion of that IT team's role and bringing those capabilities together.
I'm sure network admins are going to call out, "Hey," and we completely agree. There's going to be things that an IT admin can do on the network side to get things started, and we've introduced some of that into the platform as well. But at the same time, you will have that kind of extra kind of specialized needs for that next level.
So you can get started easily, get started faster, so that we're not creating delays in the system while you're still able to bring in that special expertise to really optimize the network, for example, or optimize your storage, or optimize your compute, for example. And so the platform is built that way, so to enable collaboration across these different teams and help them kind of see the value that they provide into the overall system, versus kind of be part of that system overall, versus be separate as a silo on their own. Mm-hmm.
It also seems, sometimes we'll talk about things in senses of extremes, but the reality is a little more nuanced. So we have a lot of cloud-native applications being deployed, and we have a lot of legacy monolithic applications, and those are still being updated as well. They're not just being put on the side per se.
And then we're going to have integrations between them. So as we kind of put all that together, does that also require the IT team to get in tune with the development team that's kind of building more complex applications than ever, and they're all connected? Yeah.
If you look at IT teams, at the end of the day, you need to be able to manage that infrastructure, provide the right SLAs to your customer team. Whether the customer is the platform team that's kind of managing certain things, or if the IT team is more extended, where you're serving the needs of developers. You need to be able to have the governance and the control and all that stuff that you need while being able to provide self-service access to the dev teams, et cetera.
Provide that sandbox environment where they have all the access and the flexibility that they need, so they can be productive, they can be creative, be innovative, and have faster time to value as they kind of build these newer applications or modernize some of those applications. But extending a monolithic application to be able to meet certain needs or being able to consume services from a third-party provider, for example. So from a platform perspective, that's a very key piece that we see VCF to be able to do.
And so the idea of the IT teams being able to serve the needs of all those kind of different personas or the internal customers is critical. So being able to manage the platform in a very consistent way so you get the governance that you need while providing the flexibility for the other personas is something that's built into VCF as a very fundamental aspect. " Well- ...
I think different teams are at different stages and different environments, so it's going to vary a lot. " We do see, to your point earlier, that convergence happening more and more. There's a lot more, I would say, collaboration across those.
And then there's organizations where they are trying to basically bring those roles a lot closer together. I think as we are seeing the evolution of this DevOps and SRE and kind of platform teams happening, IT admins that used to, for example, having a very specific role are starting to wear multiple hats, to my point earlier. And I think as that changes, as that kind of happens, there's going to be some growing pains, there's going to be some of that kind of learning that different teams will have to do.
But I think that's very specific to individual environments. And the customer, the user teams, are going to be the ones who have the best understanding of what works for them. Based on how they're organized and where they want to get to.
I think the critical piece for vendors like ourselves is to be able to provide the platform capabilities that meets all their different needs, and that flexibility needs to be in the solutions that vendors offer. And so by having the point of view that I was talking about earlier, we're not trying to create a platform and an ecosystem of our own. We're trying to make sure that we are part of the ecosystem that exists so that all the different personas are able to do what they like, do what they prefer.
And so we're meeting them where they are versus other teams trying to come to them. " Mm-hmm. I think it's the art of all teams, right?
There's only one team, but we need to figure out how to let everybody do what they need to do without getting in each other's way. Yeah. Hey, Himanshu, thanks for being on the show.
Thank you for having me. All right. And we'll be back in a minute.
Hi, everyone. Welcome back here to TechstrongTV. Our next guest up in the box is Gregory Kurtzer.
Greg Kurtzer, founder, CEO of CIQ. He's also the founder of Rocky Linux and Apptainer, and he's done a bunch of other things in his life. Let's hear all about it.
Hey, Greg, welcome back to Techstrong TV, man. It's good to see you. Good to see you again as well, Alan.
Mm-hmm. I gave you the big build-up there, but give people the- ... Greg Kurtzer story.
Well, let's see. My background started off in biochemistry, and ended up getting really interested in open source and Linux and whatnot. And what do you do when you're kind of stuck between science and computers?
Well, I ended up in high-performance computing. Spent a number of years working for the US Department of Energy, building up giant supercomputing systems and working with scientists to really help them with their computational workloads and resources. Absolutely.
I remember the story. But you are entrepreneurial as well, right? And I mentioned not only are you the founder of CIQ, and we're going to get into CIQ in a moment, but I feel like we should start with, let's talk about Rocky and let's talk about Apptainer.
Absolutely. So while I was at the US Department of Energy, as I said, I was really helping scientists, helping researchers do their science, and created a bunch of open source projects. The first big one that I created was a little operating system called CentOS.
And that was part of an amazing team that we built up, something that kind of completely changed the industry. And so from that, as CIQ kind of started maturing, and we were founded on the idea of building a computational platform, kind of modernizing high-performance computing and driving AI and whatnot. But while we were heads down doing that, we had CentOS that was end of lifed.
And so I raised my hand to the world, and in about six weeks, we had 10,000 new followers, new people who wanted to be part of this project, and contributors. And Rocky Linux was born. Really?
Huh. Interesting. Well, I knew this story, but it's good for people out there to hear it, right?
And of course, for my friends out there who are Linux aficionados, or maybe not- ... right, the whole idea about CentOS and Red Hat and how it works with the major cloud providers and how this led to Rocky kind of branching out for people who wanted something different than where CentOS was headed and everything else and what Red Hat was doing with it. But, and I'm not here to rehash that, in all honesty, right?
But Greg, let's fast-forward over to CIQ. So CIQ, as I mentioned, was founded on this idea of let's build a more modern computing platform. And we were founded to modernize the HPC ecosystem, which is using an architecture that's about 30 years old at this point.
And while that architecture has been incredibly impactful to science and researchers, it's getting to the point where it's a little long in the tooth, and it's- It's a little long in the tooth ... starting to hold back some newer types of applications, newer types of workloads, and holding back research in a variety of ways. Now again, I want to reiterate, it's still a very impactful architecture, but as we're looking at more modern types of doing compute, things like AI and ML and really driving things like inferencing, we're starting to see that infrastructure being a little bit not as well-equipped to handle that.
So we built a platform called FuzzBall, and FuzzBall is directly designed to be that more modern interface. So researchers, whether you're focusing on AI, whether you're focusing on data science, or you're focusing on kind of the traditional simulation and modeling, FuzzBall is a more modern and better way to implement that. And now we have it actually to the point where if you want to run any AI workflows, any computational workflows or inferencing, it's just a push button away.
Super simple. But while we were building this, we also had this change in the ecosystem, which affected us and affected the world at large. And overnight, as I mentioned, Rocky Linux was born.
And from there, we kind of became a Linux operating system vendor almost overnight. And so we had to grow our vision a little bit and make sure that we were providing all the capabilities and all the needs that our customers demanded. It's interesting, right?
Because look, this isn't about knocking anybody's Linux distro or any people who are pushing a particular flavor of Linux. The fact of the matter is, as you said, it is 30 plus years old, or coming up on 30 year-- Actually, it is 30 plus years old, Linux, now, right? When did Linux- Oh, Linux is definitely, yeah Yeah.
Yeah. It has to be closer to maybe 35 even, I bet ya. Maybe more.
But anyway- Right ... they've done a remarkable job of keeping Linux at the top of the mountain, right? And one could make the argument macOS is just another distribution of it in many ways, right?
" Yeah. And you can think about them, Red Hat and SUSE and Canonical. I have three off the top of my head, CIQ.
And there's more. But wait, there's more, right? Yeah.
And they have had a remarkable run. They have made Linux the OS of choice for enterprise servers, for high-powered computing. It never really got to the desktop as we always thought it was coming, but it never really took off at the desktop like we thought.
But for everything else, it's certainly been just a steamroller, right? But now, I think we all agree we're in a new world, Greg, right? We're in a new era.
We haven't seen this kind of disruption maybe since the internet itself went commercial, or maybe even before that. And it may take more than a few Band-Aids to keep this puppy running as fast as we need to run. And I think that's what this is really about.
The other thing about it, though, and I've written about it, is in a world where we all feel like we can build anything- Oh, you need ... why do we need your version of anything when I can make my version of anything, right? And that is something that's affecting the whole open source community.
It's affecting how we build software, how we're using repos, right? Is AI going to be net-net more open source or net-net less open source? All valid questions.
Take your pick, start, and run with them, Greg. So, you made a couple of really amazing points there. And, the first one I want to reiterate, I do also believe that AI is such a big shift on the ecosystem that it is probably the most disruptive technology we've had since the internet.
And the way LLMs now can absolutely write code from scratch. We're seeing now binaries are able to be transcribed and you can recapitulate entire software programs and platforms using AI. And we're seeing AI just completely changing the ecosystem overnight.
And so the questions that it raises for me are things like, is AI going to end up getting to the point where it's writing a new operating system? It's building custom things, custom aspects from scratch, specific for particular sites. And where it leads me to think through is, the most important thing when we're talking about core foundational technologies and infrastructure has to do with standards.
It has to do with compatibility. It has to do with meeting expectations. So, for example, Enterprise Linux is Enterprise Linux not because it's a different just version of Linux, and it's not because other Linux distributions can't operate in the enterprise.
It is a set of standards and compatibility that people can expect. And in an age where things are changing faster than ever, having that level of stability in your platform and having that ability to standardize and to ensure that things are going to work as expected are going to help not only vendors, not only software distributors, but also the users. Because they're going to want to know that their applications are going to run as best as they can.
And that's really why we developed RLC Pro. So RLC is Rocky Linux from CIQ, and RLC Pro is how we bundle in enterprise-capable features all into a single platform that users and companies and organizations can leverage and know that it's going to work. They're going to know that it has the appropriate levels of standardization going across applications as well as hardware platforms and accelerators, such that everything, again, is just going to work.
From your AI workloads, to your high-performance workloads, to your high-security needs and compliance. Everything now is included in RLC Pro. As we said before, this isn't just another enterprise Linux distro.
This is really something that's really optimized for today's workloads, for today's stack, if you will. And there's a lot of talk, right, about building the AI stack, right? Whether you're Jensen Huang at NVIDIA, using Cuder and all these things, or you're the Cloud Native Computing Foundation talking about Kubernetes.
Everyone is vying to own that AI stack, this new compute stack that we're going to be using. More for inference than training, probably, but still an AI stack. I haven't heard anyone say that should run on Windows.
And no disrespect to Windows, but I haven't heard anyone say, that should run on Windows as the OS. Yeah. I think it's a given, and if I'm wrong, correct me, right, that there's Linux under there somewhere, right, at that OS level.
But last year's, five years ago's Linux isn't going to help usAnd I think that's the issue here. With all of the innovations coming out of accelerators, coming out of chipsets and hardware platforms, we have to keep up. We have to make sure that if somebody goes out and buys hundreds of thousands of dollars or millions of dollars worth of GPUs, we have to ensure that the operating system is ready to operate those GPUs and ready to run those GPUs efficiently and de-risk that investment in such a way that the users know, they know for a fact, that it's not only going to work, but that they're going to get the performance that they're trying to buy, that they're trying to acquire.
And so RLC Pro does that. And we have partnerships with the leading GPU vendors out there. NVIDIA, we've been very public about our great relationship with NVIDIA.
We have a fantastic relationship with AMD, and we are taking the capabilities and the optimizations that we are able to develop by ourselves as well as in conjunction with these other vendors to ensure that, again, not only does everything work, but everything is de-risked, such that you can just install it and run it and it'll work. That's the key piece of it. I really do.
So is this available now, Greg, or it's coming? No, it's available. How do we get it?
com. And from there, we are building everything from a self-serve portal, so you can go and log in and get these capabilities and these Linux distributions, and optimizations for free. And/or you can reach out to us.
And if you are working at a large organization and you want to scale that up and you want to build very large resources with this, we're here to help. So just reach out to us and anything you need, we're there for you. I love it.
Hey, I got another question that just popped in my head, though. We're hearing so much of computing at the edge and AI at the edge, right? I want to host AI myself and not run the tokens up and everything else.
Is the CIQ Linux and RLC Pro AI, as well as RLC Pro, the right OS for that, AI on the edge? I got guys here running Mac Minis with OpenCore and stuff on it, right? Yeah.
So you said something earlier that I thought was fantastic, which is Linux has become pervasive. It is everywhere. Whether you're running it on the edge, whether you're running it on your cell phone, whether it's your refrigerator or microwave or car that's running it, all the way to your core enterprise infrastructure, servers, and compute requirements.
AI and Linux at this point are going to be everywhere. Well, AI's going to be everywhere. Linux is already everywhere.
So how do we help enable people that are looking to implement AI, that are looking to no longer pay for their tokens because they want to run it locally? How do we enable that? And RLC AI definitely helps with that by making sure that everything's going to run out of the box.
But this is going back now to FuzzBall and what we've built with FuzzBall. And FuzzBall is going to become your push button, just click, "I want to run my coding agents locally. I want to run my inferencing locally.
" FuzzBall is able to wrap all that up into a single interface, a single control plane, and make it super, super easy. I think we gave everyone the sites and places to go do this. Hey, man, come back and keep us posted because this stuff is changing so quickly.
I'm really looking forward to seeing what we got here. Alan, it's always great to talk with you. Great to see you again.
Thank you for having me. Good to see you. All right.
We're going to take a break here on Techstrong TV. We're going to be back in a second. Go check out Rocky Linux.
If you want cutting edge Linux of what's happening, the latest, it's always good to check out what Rocky's doing. Greg, I'll be in touch. Be well.
Hey, everyone, it's Alan Schmel from Techstrong. Welcome to our next session in our dynamic series of conversations between the select thought leaders at Microsoft, as well as some of the analysts from the Futurum Group. In this session, we have Tiffany Tracy, VP of Product Management for the Power Platform at Microsoft, as well as analyst from Futurum Group, Keith Kirkpatrick.
This session is titled Agentic Automation. In this session, Tiffany is going to lead us on a deep dive into the operational realities of agentic automation. It's a world where apps, agents, and chat are converging to reshape enterprise execution.
We hope you'll discover how AI empowers everyone with a special focus on those who need accessibility and disability support. Expect insights into multi-agent orchestration, human-in-the-loop governance, and chat-led transformation across support and product activation. So another great session.
Here's Tiffany and Keith. Thanks, Alan. I'm Keith Kirkpatrick, research director with the Futurum Group, covering enterprise software and digital workflows.
Today, we're going to be talking about agentic automation and how it is reshaping enterprise execution, where apps, agents, and chat functionalities are converging to assist across workflows, driving external engagement through the delivery of personalized, intelligent experiences and streamlining interactions. And hello, my name is Tiffany Tracy, and I'm the VP of product management for the Power Platform Core, which covers our Power Apps, Power Automate, Power Pages, RPA, and process mining. I've been with Microsoft for 25 years in a variety of product roles and looking forward to the conversation today.
As we're both aware, we really can't get away from a discussion about today's technology without talking about agentic AI. And I wanted to first start off by asking you about some of the ways in which agentic AI is changing the way customers are engaging with businesses on a day-to-day basis. Yeah.
So I think it's great if we first start with the fact that agentic AI is going to change the way we work, right? We're moving much more into these human-led, agent-operated environments. And some of the big changes that come with that are we're going to move much more from this very task-based focus to a more intent and goal-driven focus.
And we're going to move from working in a particular app to really working across apps. With that, we'll see this synergy of humans that are driving what we're going to do. They're adding business intelligence.
They're guiding. We're going to have agents that really do a lot of the execution work. We're going to have intelligent apps where these agents and humans can dock in to manage everything, and we're still going to have automations like we have today for very deterministic workflows.
When we put all of that together, what we get from a customer experience is they're going to get much more personalized and contextually relevant experiences, much faster and with a lot less effort on their part. And in fact, in many cases, we see that customers or organizations were able to expand the audiences that they can actually serve with this technology. So, a simple example of that might be I'm on a flight, turns out I'm going to miss my connecting flight.
Today when I land, I might get a text message that I've missed my connecting flight. But you see very quickly, I'll land, the airlines has already rebooked me with an agent. They're going to let me know what my new flight is, and then if that doesn't work for me, they're going to give me a human to escalate.
That's going to change in these kind of customer experiences. Can you talk to me a little bit about how we're going to see all of this intelligent automation be managed? So one of the powers of this agentic transformation is you begin to get intelligence on tap.
So you have these different agents that you can leverage for different business functions. A level one agent, I think most of us have probably experienced in this point, and that is AI is maybe we're asking it questions, or it's giving us a set of information. And then you have level two, where the human is actually directing the agent to conduct some sort of task, and then the business rules dictate when the human will get involved, and it may be just giving the human information so they can make a better decision.
And then level three is where you see these agents actually taking action aligned to the business rules, and the human being in the loop aligned to whatever business rules you set. So what you'll find is that the goal of how we're thinking about agentic AI is we want humans to continue to work in the way they do today. We want them to have a personal assistant that transcends with them throughout their day, whether in their business data, their productivity data, whatever task they're doing.
And then they will have intelligent apps that let them manage some of these autonomous agents. But those agents can dock into their personal assistant. They can dock into their agents.
So we really want the humans continue to work the way they do today, that this AI will sort of collaborate seamlessly with them, and that's why you see that using both intelligent apps and kind of Copilot in this chat interface have their place, depending on what the human's trying to accomplish. And so we want this all to kind of slot in more seamlessly versus thinking about it as they have to change as much the way they work. Right.
That makes sense. But I guess one thing that I'm particularly curious about is as we move into this world where we have agents that work alongside of humans, and there are obviously going to be agents that work sort of autonomously, obviously still with a human in the loop to make sure that they don't go off the rails. How do you actually coordinate multiple AI agents across a platform to make sure that the agents do what they're supposed to do when they're supposed to do it?
Yeah, it's an excellent question. It's very inherent in the platform we're building across both Copilot Studio and Power Platform and, of course, some of the pieces in Azure. But it is very straightforward to design for a particular agent, what its rules are, what it's allowed to do, what knowledge it has, what memory it has, what kind of guardrails it needs to follow.
Mm-hmm. And what we see as customers are moving to these level three agents is they're really thinking through their business processes and chunking those up into reusable components. So maybe, for instance, you interact to gather information from an external company, and you do that for several business processes.
You might build a dedicated agent that does that and gathers that information. That will have a set of business rules that you set for that agent. It will have a set of points where you escalate to a human or where the agent can actually take action.
And then that agent may talk to another agent. Again, you define what that communication is and the business rules. So it's very configurable to what your business policies are, what your risk tolerance is, depending on the impact.
The other piece is it's quite straightforward to evolve those business rules. So maybe, for instance, you start with an agent that makes recommendations on approving insurance claims or approving purchase orders. You might say that when you start, every single one of those has to be validated by a human.
" If it's under such amount, $1,000, the agent can auto-approve. If it's over that, the human still has to make that decision. And then you keep ratcheting that up as you build confidence in the agentic system you've created.
And those things are very straightforward to configure and continuing to evolve. Actually, how does Power Platform help to sort of manage that, as you're talking about multi-agent orchestration across different modalities, whether we're talking about chats, applications, and back-end systems, because that seems like that's going to be a core requirement as organizations, whether they're dealing with regulated industries or not. Absolutely.
So when you think about the Power Platform, one, we have a tremendous amount of line-of-business, large-scale apps running on the platform today. And I think it's really important to note, for those customers, we are going to bring AI to where they're working today and let them use AI to add even more value to the applications they have today. Then we're introducing new tools for building agents and some of these intelligent apps that will dock the agents in.
All of that will still run on the Power Platform managed environments. So all of the governance that you're used to in the Power Platform will extend to this agentic transformation so that customers have confidence that they are running in a managed environment, that they have the ability to set the policies, to manage it, to audit it, to understand RAI, all of the different components they need. But that will be within the core platform that they have come to trust in managed environments.
Tiffany, you just mentioned something that's really interesting, and you've been talking about it throughout our conversation, about the idea of human-in-the-loop governance. I'm curious, how do you actually embed that into agentic workflows without sort of slowing down automations or creating unnecessary bottlenecks? So human-in-the-loop can be orchestrated at any milestone in the process that makes sense for that process or that business.
This is one of the places that we think intelligent Power Apps is going to play a large role. So you can imagine that I might have 1,000 automations or 1,000 agents that are running, and I have this intelligent app that lets me go through and quickly approve, guide, change, whatever needs to happen to ensure that the human is guiding but not slowing down the process. And I think this is one of the roles we see for intelligent apps as we go forward.
What about-- The other thing I've heard about is the use of adaptive risk models and how that might help ensure that agents just remain compliant with any kind of regulatory or even business guidelines. Can you talk to me a little bit about that? So for every agentic solution, the organization really needs to think through a concept we call evals.
And those evals are what are letting you know that the quality, the functionality, the reliability is all within your guidelines. And so it depends on the agentic solution, but you're going to have metrics that tell you the functionality and the reliability. It's going to let you know the quality of the response.
If it's an agent that's creating some sort of UX or interface, you're going to have metrics that let you test if that is high quality and functional. And then, of course, you're going to have evals around responsible AI. And so depending on the solution, one of the first things you want to do as you get started is define for the type of solution you have, what are the areas that will be key, and what are the metrics and tests you want to use, and then there'll be multiple ways to ensure that those metrics are on track.
So we've heard a lot about agentic AI, but one of the things that I hear from talking with companies is that there's still a little bit of fuzziness or confusion around what sets agentic AI apart from sort of the chatbots or assistants that we become accustomed to dealing with in our everyday lives. There's a number of things. One is that an agent, if you give it to them, has memory.
So they can remember previous conversations with you. They can remember previous context. The second is that the agent can learn.
You can continue to train it on knowledge, and it can continue to learn and be more and more helpful as it goes along. It also has not just the initial knowledge that you trained it on, but it has generative AI, which helps it to fill in the knowledge that you've given it. So you can think of it as all the power of the orchestration and the LLM, or the large language model, with your specific information on top to personalize it.
All of those are things that chatbots could not do. Chatbots also cannot take action. So chatbot was really great at the time, but it's really more of a Q&A with very curated answers.
When we get to LLM, it has all of these richer capabilities, and so it's not only quicker to get the information back to the human, but it also can do more of that on its own because of the context, the shared memory, the knowledge, and the fact it can take actions. Well, one of the things I think that agentic AI is really sort of building on is that chat modality where you're able to use natural language to interact with it. Do you see that as being another sort of real selling point for using agentic AI?
Because anyone can interact with it. You don't need to program. You don't need to remember specific terms or anything like that.
Natural language interfaces are going to have a large role in agentic AI because as humans, that's an interface that we like, we enjoy, and has a much lower barrier for people to participate in. So I think natural language and being able to type what you want an app to do or what you want an agent to do for you and be able to go create that will absolutely have a large role in that. Again, I think it will depend on the business solution.
We also know that humans are more comfortable in sort of like a personal assistant, like a Copilot realm, talking back and forth because that's how they interact with their other coworkers. And so we really want, as much as possible, to have the humans still work in the way that they're accustomed to working. So they might ping a coworker to ask a question.
Now they might ping their personal assistant to ask that question. There will be places where they'll actually go into an intelligent app because that's the best interface for them. And then they may continue to ask their personal assistant questions about that app.
So they will be much quicker to learn about that app and what they're doing. But the natural language interface is definitely going to play a key role because of the way it lowers the barrier and allows humans to continue to interact with the technology in a way that they're most comfortable. So it sounds like what you're describing is sort of an agent first or assistant first approach to interacting with systems.
Is that kind of what we're moving toward? I would kind of flip it around. I think it's a human first, a human-led.
I think the human is going to have a personal assistant like Copilot that transcends their day with them, understands their productivity context, their business context, how they like to communicate, how they don't like to communicate. It's going to be more kind of, I'll call it, connected with the human and their personality. And then I think there's going to be a set of intelligent apps and agents that dock into those places.
Agents may dock into your apps. Agents may dock into your personal assistant, depending on what they do. All that together will build kind of the new tapestry of how we work and how we move forward.
But I think it's the human at the center with these technologies helping to make them more productive and giving them more time to think strategically, to be creative, and to think about what they can do next. We know from all kinds of studies that 80% of people in organizations say they don't have enough time to do what they want to do, to think about the things they want to think. So we're thinking about how we empower that human and how they now have more time for those strategic, creative things.
And then this technology is really helping them along the way. Tiffany, one thing you mentioned is that AI should be for everyone, and I'm curious if you could talk a little bit about how agentic automation can help ensure that people with disabilities aren't just included but actively empowered as they're working and using enterprise workflows. Yeah.
This is an area I feel extremely passionate about what we've seen so far with particularly Copilot and some of the automations that have been done in Teams and some other places. So-There's lots of different situations that people with disabilities face. You may have someone who has hearing loss, and now with the transcript on a meeting, they can fill in where something wasn't quite clear to them.
You may have someone who has ADHD, who focusing on the meeting and the notes, they feel like they miss out on both fronts. I think that's a human experience across the board. Now, with meeting notes and the transcription, you can stay 100% focused on the conversation in the meeting and know the rest of that is going to be there for you.
You could flip this over to other environments like schools or education, where the concept of meeting notes can help students take notes in lectures, and they can have it all there, so they're focused on their learning in the moment. Amit, a lot of these agentic AI pieces are going to help humans be fully present in the moment and know all this other stuff is there for them to use later, but they're not having to multitask in the moment. And the numbers are showing people see the real impact to that.
They feel like the quality of their work is better. They feel like they are more included. They feel like they have better performance, and they feel like the meaning of their work has actually gone up.
We're just seeing the beginning of all the impact that this is going to have for us. Tiffany, can you give me an example where agentic AI has provided an outsized impact above and beyond what you either might have expected or what we could have previously done? Yes.
We see many times that the spark for starting with AI is around efficiency or productivity. But what we're hearing from customers is they're seeing a number of other vectors of impact. Accessibility and inclusion has been a really strong one, which I'll talk about.
Being able to upskill and learn has been another one that's come up quite strongly. In fact, EY, Ernst & Young, recently did a study where they interviewed over 300 people who had been using Microsoft Copilot, asking them how did it impact their work. All of these 300 people identified as having a disability.
Mm-hmm. And over 75% of them said they felt like Copilot had made them more productive at work. They kind of laid that along three lines.
One was removing barriers. 88% said they were doing better communications by using Copilot than they had in the past. They also talked about feeling more included and feeling like the quality of their work had gone up.
That was over 85%. And they also talked about feeling like they were getting more meaning out of their work because of their productivity and the quality. So that is just a tremendous additional benefit that we're seeing from AI, where organizations are able to ensure that every team member is bringing their best selves to work and doing the best role that they can.
And I think we will just see more and more of this as we move forward. Because as Copilot and some of the other AI continues to learn even more and more and becomes more personalized, it can even help in other ways that will be very valuable for people. So Tiffany, I was wondering if you could share some examples about how agentic technology is being designed with accessibility in mind.
Yeah. So as you know, Microsoft's had a long history of thinking about accessibility features in our products, whether that's been sort of in Xbox and assistive controllers or Office a- and the many accessibility features we provide there. That same sort of mission is moving into agentic AI.
So we can think about what are the new accessibility features that maybe in the past weren't as feasible that now we can bring to the forefront. Some of them are already out. You think about Teams meetings, Teams transcripts.
You think about things like Copilot being able to ask questions across all of your graph data. As we move forward, we see even new opportunities. For example, the Teams team is thinking about how today in a Teams transcript, you have whatever has been said verbally.
Might be another language, might be in English, might be in multiple languages, but it's what was spoken. In the future, what they want to do is include what was signed in the meeting into the transcript. So everybody has a complete transcript, whether that was spoken or whether that was signed.
And that's just one example of the many type of agentic AI features that we feel like is now feasible that we're exploring. So I was wondering if you could tell me about how agentic automation has really streamlined very personal or sensitive processes and procedures. One of the areas that would be a great example of this might be human onboarding.
So we each come to a new role or a new set of work with various backgrounds, with strengths in places, things we know nothing about, and agentic AI can really personalize helping that human onboard in a way that they feel completely comfortable. They can ask many questions. They can get access to many resources.
They can get recommendationsAnd guidance that will help them learn at a much quicker pace, but not something whereas in the past they would've had to share very broadly with their new team that they didn't understand a concept, or they didn't have this experience, or maybe it's very difficult in a large conference room to hear the voices. And so agentic AI has a opportunity to really help speed up that onboarding, personalize that onboarding, and do it in a way that is really taking the human into account and helping them do that in the best way possible, in a way that's sensitive to things and very positive and productive. Thank you very much, Tiffany, for a great conversation and real insight into the world of agentic technology.
Thank you, Keith. I really enjoyed our conversation today. It's always fun to talk about the transformation that's ahead of us and how agentic AI is going to help all of us move forward.
Today we heard a lot about agents, and I think some of the things that really resonated with me was the fact that ultimately, to have success, you need to start with humans, looking at processes and goals, and then bring in the technology. Now, of course, there's a need for platforms that can really provide an orchestrated agent experience across intelligent apps, agents, and of course, all of the workflows that are integral to really driving real business benefits. And ultimately, the other thing that really, really sort of resonated for me is the ability of agentic technology to improve the experience of people who may have disabilities, and to do it in a way that really takes into account how they're feeling, and not really kind of separating them from the rest of the employee base or other customers, but to do it in a way that's empathetic, and again, can really drive outcomes.
Get in, losers, we're going to space. Cisco is shielding AI agents. Boom goes the cloud spend.
Email attacks cash in. SAP snags Reltio for agentic AI. " It is April 1st.
No, I am not Tom Foolery. I am Tom Hollingsworth, your host for this wonderful episode. And before I say anything else, we are bringing you the straight news this week, because I'm not going to play around with any of that foolishness, as our friend Stephen Foskett loves to say.
This should be a serious discussion with as much snark as we can fit into the half hour that we have. And joining me, of course, is my good friend, Mr. Alistair Cook.
Al, welcome back to the show. It's always a pleasure to be here with you, Tom, and I will endeavor to get at least 50% of your snark level into our conversation here on National Child Help Day, something to be taken quite seriously. Yeah, that should be taken quite seriously.
And let's be fair, some of these people in the news stories probably could use a child to help them figure things out, because they have some pretty interesting ideas. We're going to go ahead and start off with a company called Starcloud, because they have raised $170 million in their Series A round. 1 billion to develop the world's first orbital data centers.
The company has already launched a satellite with an NVIDIA H100 GPU, and plans to deploy more powerful spacecraft equipped with multiple GPUs and even Bitcoin mining computers. Starcloud aims to make space-based computing cost competitive with Earth-based data centers, once reusable heavy lift rockets, like SpaceX's Starship, are operational and not blowing up in flight. The startup plans to sell processing power to other satellites now, with full-scale distributed orbital data centers becoming viable as soon as launch costs drop in the coming years.
Al, I know that I've decried this many, many, many times, but have our friends over at Starcloud figured out how physics work? You know, it seems like they have. One of the nice things that Starcloud has done is actually written up a white paper outlining their math on power.
So I was having a read of it, and our usual objection to this is heat. How do you get rid of heat in space? And that's a very common challenge to all satellites, all spacecraft.
That radiated heat from the sun is pretty hot out there, and taking in that heat and then re-emitting it rather than getting very hot. So although space is very cold, it's not cold in the way that a cup of water is cold. You can't stick your finger in space and have it cool down at great speed.
What happens is you work with radiative cooling. So the white paper that I was reading from Starcloud suggested that their target is a five gigawatt data center. It's going to have solar panels that are four kilometers square.
For those who can't do the conversion, that's two and a half miles on each side. And their math is that the radiators that they need to get rid of the excess heat, basically almost all of that five gigawatts of power, and they need to cover about half of the area behind the solar panels. So here's an interesting thought, right?
The solar panels are absorbing the heat, and then they're also screening the radiatorsFrom absorbing further solar heat. You're getting your most efficiency if you're capturing all of that solar heat in the panels, and then radiating it all behind in the radiators. There's some interesting pieces in there.
One of the challenges, I think, is the superficial math that was in the white paper doesn't account for the fact that you're sitting right next to the Earth, and the Earth is not minus 270 degrees. And so your radiative effects will be much less. But they were still forecasting needing less than the half of the surface area that the solar panels will cover for their radiators.
And of course, the radiator probably makes sense to have it at a right angle to the solar panel so it gets minimum heat from those solar panels and can radiate away from them. So I'm less skeptical than I was, other than that when they start talking about two and a half mile square solar panels in space, and the requirement for these heavy lift spacecraft to be cost-effective and not self-destructive, as you say. So yeah, there's definitely some challenges along the way.
I think StartLab is pretty well-placed because they currently have that NVIDIA H100 GPU in space, and they've used it. They've run model training there. They have run Gemini AI models there.
And then the white paper also discusses some challenges around getting data to and from there, from the actual satellites. So they talk about both sending physical ship of data up, as well as potentially doing repair of failed elements of the data center by launching satellites up there with maintenance. And that addresses some of the things that I think are going to be huge challenges.
But it still comes on the presumption that the cost of massive amounts of lift to orbit is going to go down, and that it's something that's actually not going to be destructive to the planet in the way that, well, current lift to orbit is quite environmentally destructive. The chemicals involved are pretty nasty, and there's large volumes of them. Also strikes me that recent challenges with some of the Starlink satellites, where they're having failures and leading to fragmentation and shrapnel shooting around in low Earth orbit, that's not going to be reduced by sending thousands more of these satellites up into low Earth orbit.
Yeah. Maybe I'm still skeptical about the capability of actually doing anything meaningful with these data centers. By the way, we're not even sure what we're going to do with the ones we're planning on the ground for all of this massive AI.
But what if the AI running your business got hacked? At RSAC on March 23rd, 2026, Cisco announced new security tools to protect AI agents before they can be exploited. While most companies are testing AI, very few have fully launched it because of trust gaps.
Cisco's Defend Claw framework and duo identity tools let security teams give AI agents temporary, precise permissions and check their code for vulnerabilities. Treating AI like human employees, as unreliable as some humans can be, Cisco aims to make AI safe enough for real business use. Is this going to be another AI checking the AI, Tom?
We're going to cover some of this a little bit more in-depth in the closer look, but I thought it was interesting that Cisco has taken this approach because one of the things that you think about when you think about AI is, oh, it's completely infallible, and it never screws anything up, and it does exactly what it's told every time. You know, like an intern. My interns know exactly what they're supposed to do, and they're completely infallible, even though they have absolutely no experience in what I'm doing.
And every time I give them explicit instructions, they follow them to the letter every time, right? Everybody's at home is nodding their heads because they know that their interns are 100% reliable, right? Why are you not nodding your heads with me?
Come on. Oh, yeah. That's right.
Because we've already solved this problem. We have figured out how to contain the damage from people who are not intimately familiar with the way the systems work. How do we do that?
We limit the scope of what they're capable of doing. And yes, as I will mention in a little bit, OpenClaw has scared the crap out of everybody because it has shown what will happen when an agent starts doing things without being prompted to do them. " That is what we're adding in here.
We are limiting the scope of what these systems can see, and that limits their blast radius. And you're darn right that these things have trust gaps, as we had on a big Futurum group call last week. Some people brought up the fact that if you launch OpenClaw on a system that is managed by your work system, you could be fired on the spot because OpenClaw and agents like it have a very limited trust boundary right now.
People really don't know how far to throw them. And look, I could bring up the Meta chief of security email problem. " So I think what we're going to see is more companies like Cisco coming out with these solutions that are creating boundaries, zero trust boundaries, around AI agents where we can leak what they need to have access to and limit the horizon of their ability to cause other problems.
So the good news is that companies are already thinking about this. 9 billion in late 2025, mostly due to the rising demand for AI systems. Major providers like AWS, Microsoft Azure, and Google Cloud all saw strong growth as companies moved AI projects from testing into the real world.
The growth of AI agents and more complex AI systems is increasing demand for computing power, storage, and networking, which is pushing companies to build even more data centers. Cloud platforms are now becoming the foundation for enterprise AI, and spending is expected to keep growing through 2026. Al, is this good news for cloud providers that they're actually not going to get left behind by the AI wave after all?
Well, the interesting question is whether the cloud revenue matches up with this cloud spending. I was unclear whether this was a spend on building out or actually income. Maybe this actually is income for the cloud providers who have been spending billions to build out for their AI agents.
Yeah. I mean, we do see growth in revenue. We see growth in revenue of being maybe 32% shown for AWS, and similar kinds of levels, a little lower levels for both Azure and Google Cloud.
Oh, no. Sorry. I apologize.
I misread on Google Cloud. They are up 50% growth. Maybe Google is getting the big leg up here.
Now, that would make sense that this growth is driven by AI. DeepMind team at Google has been one of the leading teams for turning AI into something commercial for a long time. So yeah, I'm definitely seeing this increase in revenues matching up with the increase in spending.
So there's definitely been a large investment in more data centers to accommodate AI workloads. There's been a lot of talk about AI agents as we maybe been discussing a little bit. There's still a lot to be written about making AI agents successful and useful.
But that's not stopping people from going out and testing this. And the cloud is an awesome place to test things that are going to use a lot of resources. So yeah, good news overall.
Cloud revenues are great. Cloud spend, cloud build-outs are all happening, but of course, those data centers have to exist somewhere, and we know there's been some pushback about where those data centers are going to be built and when they're going to be built as well. And there's always some challenges around making sure that there's actually equipment in those data centers for these AI agents that presumably are going to be business transformational and awesome in the very near future.
Iran's been in the news, and Iran-linked hackers have reportedly broken into Kash Patel's personal email. And they posted some private photos and those emails online. The group behind the attack, the Hindela Hack Team, claimed responsibility.
Somebody's claimed responsibility and released hundreds of messages and images. Although the officials from the US government are saying there's no classified government data exposed, and that this hack is part of an ongoing attack against anybody in the US in a position of public power, and that they're really more psychological than actually having any other element. Is this really just grandstand hacking going on, Tom?
In a way, it is. And I mean, first of all, if I was the director of the FBI, you can better believe I'd have multi-factor authentication turned on on my private email address. I'll be honest with you.
I was rather shocked that we didn't find any classified or sensitive materials in there. We found a lot of pictures of cars and cigars. So at least there's consistency there.
But I think that this shows another side to activism hacking. So we've talked a lot, not only here, but on the "Security Boulevard" podcast, about nation-states taking down certain individuals or certain companies using their muscle and flexing it to knock things offline, right? It could be an oil processing terminal, or it could be a nuclear plant, or it could be a lot of things.
But here, they have a very specific aim. You can't hide from us, and we're going to find things you don't want us to find. And we've seen that being a source of embarrassment for certain individuals in the administration over the last, let's say a year and a half or so, where your name appearing in a group of emails could potentially cause a lot of problems.
Well, now I'm going to dump your whole email account. I'm not going to dump your government one because that's a big problem, right? That's going to get Cyber Command and CISA and a whole bunch of other people trying to track me down.
No, I just hacked in and stole your vacation photos, and I don't know, maybe your bank account information or anything like that. And boy, isn't it embarrassing whenever I release all this stuff online, and it's your fault that I did this, and all you have to do to make all this stuff go away is just stop bombing our country. I don't think that this was the only company or only person that got hacked.
I'm pretty sure a lot of others did. We just don't know about it because this was the first shot across the bow. Honestly, this was probably a proof point that we know more than you think we do, and we're going to release the stuff that isn't embarrassing or compromising right now as a way for you to realize we could make it a lot worse.
We probably have a lot of fun things that we could share with people, and if you leave now, you won't have to endure the worst of it. So to the government officials who listen to this, and I know several people in cabinets for the last 15 years have listened to this podcast, and we appreciate your patronage because it's a wonderful thing. Please turn on multi-factor authentication.
Please turn on all systems that you can use to prevent people from logging into your accounts. Please don't just randomly send that six-digit code to somebody who texts you saying they need to do that to have access to something. SAP SE has announced plans to acquire Reltio to improve how enterprise data is organized and used for AI.
The deal focuses on solving one of the biggest challenges in AI adoption, that's fragmented data across different systems. Reltio's technology creates unified golden records for customers, producers, and suppliers, giving AI systems reliable data to work with. SAP plans to integrate Reltio into its business data cloud to support agentic AI systems that can analyze data, make decisions, and trigger actions in real time across business applications.
The acquisition is expected to close later in 2026, and it is, of course, pending that pesky regulatory approval. Al, do you think having a system that will allow them to unify all of these disparate records is going to help SAP pull ahead in the agentic AI race? That's certainly what they're hoping for, and definitely Reltio has historically positioned itself as a foundation for an agentic AI future as a way of bringing together multiple disparate pieces of data.
I think one of the interesting elements about current AI is that it works much better with unstructured or semi-structured data than it does with the kind of structured data that you have in your SAP system. And so bringing in that unstructured data to sit alongside all of the ERP data that you have in your SAP, that's going to be beneficial. Getting that full context of who a customer is or who a supplier is will be useful for these agentic AI systems that are going to replace whoever's previously been trying to work out what product we last sold to this company, and why are they calling in for support on a product we've never sold them, or at least we don't think we ever sold them.
So bring that kind of data together into a single place to allow agentic AI systems or AI systems in general to work with this collection of data. Now, one of the challenges is we don't really want to move all of the data to a single central place. The idea of moving everything into the data lake comes with a lot of delay in getting the data into that lake.
And that's not really acceptable for agentic systems to be successful. They need to have current, up-to-date information. So the Reltio story is very much about providing access to the data where it resides and providing things like a Model Context Protocol, an MCP gateway, into different sets of your data.
I think that's a great thing. I think the idea that we would want to copy all of our business data into a single place to make it available to AI is going to be problematic as we move to production, where some AI is going to run in the cloud and some is going to run on premises, and apparently some's going to run in space. So having to move all of your data to all of these locations will be very problematic for running agentic AI at scale.
Having access to the data without moving it around I think is something we will see a lot more around, and that transition towards agents are everything and software licensing is less of a concern for us. That's something we saw last week from another large company. Botnets are back in the news as US and international authorities have taken down four major IoT botnets.
The ISURU, Kim Wolf, JackSkid, and Mossad botnets, which were controlling millions of devices like security cameras, DVRs, routers, and using them to launch massive DDoS attacks worldwide. These attacks caused financial losses and supported cybercrime as a service operations. The coordinated effort involved the FBI, DOJ, and partners in Canada and Germany, and it seized the command and control systems.
This is the way that commands are being sent to all of these tiny little devices, and stopping those commands being sent is vital. The operation shows the importance of global cooperation fighting large-scale cybercrime. Are these cybercriminals going to stop anytime soon, Tom?
Probably not. They're probably going to fire back up and start this all over again because one of the things that we've seen is that low-cost IoT devices that have things like compromised credential chains are not easily or quickly replaced, and it can lead to problems. Mirai was probably the most famous botnet that we've talked about in the last five or six years, where a bunch of security cameras had a hard-coded root password, which means now anybody who knows that password can use them as a botnet, as an amplification system.
And one of the things that you see in these kinds of operations, of which there were four that were using very similar systems, is that they were selling these services. So everybody knows that this wasn't just me knocking kids off of World of Warcraft or jamming up the scoreboard at Dodger Stadium for the heck of it. No, this was you pay me a certain amount of money per hour, and I knock these systems offline.
And we've seen these kinds of things in the past, but we've never seen it at the scale where it has effectively become an extortion business, right? " And this is creating massive problems for people. When you think about the amount of infrastructure that has to sit in the middle of these traffic patterns to drop all of this traffic.
Cloudflare, every time there is a story about a botnet that they've blocked, it's the biggest botnet they've ever blocked. Every time. So, the Guinness World Record for botnet just keeps climbing because as they get more and more access to these IoT devices, it's becoming more and moreefficient for them to be able to launch these kinds of attacks, because when you compromise a phone or a tablet or a desktop, those things can get patched out fairly easily, right?
Or I can create enterprise security policies or even home security policies that prevent these kinds of outbound traffic, or your home ISP is going to go, "Wait a minute. You're not supposed to be sending this amount of traffic. " I know because they'll email you if you do.
But for IoT, is anybody really looking at it that much? If a camera is sending 10 times the normal amount of traffic, doesn't sound like a whole lot of traffic, right? Because it's probably only a meg or two.
Times how many cameras are in your environment? Yeah, there's your problem. All of these things, cameras, DVRs, compromised routers, thermostats, sensors, these things can add up really fast, and when they turn that ion cannon on whoever they're going to be attacking, it can cause a lot of problems.
So I'm glad that they were able to shut this down, but more importantly, this is something that the device manufacturers need to be made aware of, and they either need to patch those systems out, or they need to provide a way for the customers of these systems to purchase new sensors, devices, at a reduced cost to replace known compromised devices. Because I'm sorry, but if you're paying $30 for a camera, and the company said, "Well, you're going to have to pay $30 for a new camera," can you not give it to them for 15 and then take the old camera back and wipe the firmware and get the passwords out of it? Because you've already said you can't do that from a firmware release.
So take it back, rehabilitate it, and sell it on the market again. If you want to talk to me for more business tips, I'm always happy to do so. Okay.
Let's take a closer look at some awesome stuff that was happening last week. You were probably aware that I was out at RSAC, and there was a lot of talk at the event around artificial intelligence. And there was a shift from what we've been seeing a lot of hype about to more of a concrete, grounded reality.
There were a lot of security professionals that felt a sense of urgency around AI's rapid growth, but there was also some fatigue mixed with that urgency. While AI agents, automation, and AI native deployment were major themes, the biggest concerns centered around governance, security risk, non-human identities, and attacks that were targeting trusted systems like SaaS integrations and credentials. A lot of the experts that were out there emphasized that organizations really have to focus less on AI hype and more on practical issues like identity management, intent validation, and security controls as AI systems start to gain more autonomy.
The overall message that I heard at RSAC was pretty clear. AI is now operational, and companies are going to have to build secure, governed systems that can move fast without losing control. Al, do any of these themes hit home for you when it comes to thinking about how AI is being deployed and what we need to be watching for?
I think we're seeing some pretty consistent themes in here, that there's a lot of innovation in AI. A lot of the people who are making these innovations are our scientists are working out what they can do. They're not asking whether they should do it.
They're not asking whether they're doing it safely. So yes, I think these are absolutely consistent themes in the industry. We're seeing AI being injected into everything, every product, every business, every business process.
AI is being shoved in there, whether it fits or not. And the urgency of putting AI into everything means that we're allowed to run fast and break stuff. The only problem is we're breaking really significant things, and that's where the fatigue is coming in, that this pattern of moving very fast and particularly in RSAC, it's all about security controls, doing things safely in your business.
The tooling to move at this speed and continue to be safe, or to be safe, is just not there yet. I think this is one of the things we need to be looking at more. Where's the governance and security around the use of these AI tools?
We saw OpenClaw release earlier this year as one of those classic elements of, yes, you can do this, but should you ever do this? Should you have these uncontrolled autonomous agents doing whatever the heck it is the autonomous agent decides to do with no idea of the consequences? And that's a wake-up call.
As you mentioned on an earlier topic, there are companies where simply running OpenClaw on a corporate asset is grounds for being walked to the door, and that's a great start to the governance, but it doesn't actually address the real problem. It addresses a symptom. The real problem is not having had good governance baked into these AI products from the beginning, because we're simply allowing ourselves to move too fast.
And Tom, I think that this is all driven by the vast amounts of money that people think that they're going to make or save from these AI and these agents. Is that an unfair judgment? That's not an unfair judgment.
A lot of companies are talking about the fact that AI agents are available 24/7, and they don't require healthcare, and they can be fired, or in this case, dismissed, and reconfigured at will, right? That's one of the value that corporations are seeing out of this. We've seen it for the last few years with this idea of these online chatbots, right?
I don't have to have somebody manning the support desk 24/7 if there's a chatbot that can triage some of my case and then maybe hand it off to a human so I have smaller groups of people running around. Because companies are very worried about what happens when the deployment of these agents gets out of hand quickly. And we learned that from OpenClaw.
Like say what you will about what they developed and how quickly it went up, and look, we've had so much fun talking about this on "The Rundown" about what you're going to call it and losing control of the domain and all that other stuff. But the fact of the matter is that for a solution that was released in late 2025 but really only caught steam in 2026, the fact that NVIDIA mentioned it at GTC and so many companies were using it as a reference point at RSAC tells me that the developer of OpenClaw found a weakness in the system that most people were not ready to talk about. So when we finished with our Field Day stuff out there last week, Tuesday afternoon, I had some meetings that I set up.
And I met with three different companies and had four different conversations about non-human agentic AI identity. And everybody is approaching it from a different perspective. And I think this is one of the things that I took away from it.
Some of you are old enough to remember when zero trust networking was still kind of coming to the forefront, or when SD-WAN, sorry, SDN was becoming a forefront, and that's firmly tongue in cheek, kids. Like that was not that long ago. But everybody had a different way of doing it, right?
So I talked to Okta, and they are very set on using browser plugins to kind of control instantiation of agentic AI and being able to control what it can communicate with. I talked to Delinea and StrongDM, and they're using a network proxy layer to intercept calls that are being sent to off-property AI systems. And then I had a meeting with a company called Akeyless, which is doing something even radically different from that, using some of the technology that they've built on.
It's interesting for me to hear how so many people are attacking the same problem from different perspectives, but what it makes kind of an interesting sense to me is that not everything is going to pan out, right? Go all the way back to high school genetics. Like, we try a bunch of different things to see what's actually going to work, knowing that some of these things are going to be dead ends, but we have to go down that road anyway to see how far it can go.
But the ultimate goal is the same. We have to treat non-human identities like we treat humans. We have to give them the ability to do their job but control their ability to not cause problems.
The term we always use is limiting their blast radius, right? But think about all of the people in your organization that you have to keep tabs of. Now imagine if they could do dumb things instantly and won't listen.
I mean, I've seen a lot of commentary over just the last week, where some talking heads on social media are starting to wonder, is AI starting to kind of ignore humans? " And I always go back to that because interns very much are AI. They're untrained, they're eager, and if you don't give them proper boundaries, they will blow everything up because sometimes they do things without asking that you didn't want them to do because they're trying to be efficient.
And there was this massive split at RSAC. There were people who were very much on the AI fatigue, like please don't say that. Like let's talk about literally anything else.
And then there were people who just couldn't get enough of it. It's like, tell me more about how you're going to secure these agents, and my company is going to be deploying these things. And it just felt like it was reaching a fever pitch, and I don't know how that's going to fall out because I know that the fatigue people are just so tired of companies slapping AI on their product so they can get an extra $10 million in funding.
And then the AI pundits are absolutely 100% head over heels happy that AI is here, and any form of restriction on it feels wrong to them because they've never blown up their email. Because a lot of those people are also the ones that are running OpenClaw on a Mac Mini that's walled off in a section of their office with a thermite flower pot poised overhead so that if it becomes self-aware, they can kill it. But that's a possibility.
So I mean, Al, does it feel like that on the outside to you guys, where it's like there's this fatigue kind of matched up against this zealousness when it comes to AI? Yeah, I think we see it in the people that you and I talk to at Techfieldday events as well. " And as usual, the reality will fit somewhere in between, but probably in a place that we're unable to predict right now.
This is the thing about innovation is, once you see it, it's obvious. Until it turns up, it's impenetrable. So yeah, I think we will see a place where that sort of reality of how to get value from AI, how to use it properly, and how to not throw the baby out with the bathwater.
So when we've had a problem with an AI tool, not saying all AI tools are terrible and we should never touch them, but saying, well, we need to learn something from the mistakes we've made because that's part of what makes us human. I want to circle back on one of the comments you made about AI being like an intern and having no idea of the consequences and no self-awarenessNo self-awareness that I might make a mistake, and so I need to be careful and check this with somebody else. Time and again, we see people using AI agents or AI coding tools, and the coding tool is questioned by the human operator, and the AI comes back and said, "I've been a bad boy.
" There is no ability that I've seen for AI tools to do that introspection, to think about themselves as, "I'm being asked to do something I'm not good at," or, "I'm being asked to do a task that I shouldn't be asked to do because I'm just not authorized to do that scale of change, or that scale of operation. " Yeah. There's still lots for us to learn about how to actually use AI to achieve real business good, and let's be careful that we don't let the headline stories of people being reckless and being burnt by their recklessness lead us to not actually doing useful things.
Speaking of doing useful things, Tom, you're going to be doing useful things again next week. You're heading back out to California for the 40th edition of Network Field Day. Looks like you've got a pretty awesome lineup of delegates and sponsors for this event.
Yeah, we are going to be very busy Wednesday, Thursday, and Friday of next week. We've got lots of presentations from companies who are going to be talking about all forms of networking, whether it's your traditional AI network build-outs or monitoring, or even just some billing and management systems. You never know.
We're going to have a pretty interesting mix, and we have some new delegates who will be joining us, so we're very happy to have them. com for all of the fun, and don't forget, we're streaming live on YouTube Live right now. And then Al, I think Steven's going to be doing something the week after on the other side of the country.
He is. Steven and a few of the delegates will be across at Qlik Connect, which will be in Orlando in Florida, the far side of the country. That's a state I have not yet been to, so I'm a little disappointed they didn't invite me for that one.
I think I'd like being surrounded by tornadoes sometime. Is it tornado season? Hopefully not.
So hopefully they will have an awesome time out in Orlando with Qlik, and that's going to be a great one to drill a little further into. It's good that you get a couple of weeks off as well. So Network Field Day is April 8th and 10th, people tuning in there.
But people should also tune in for you again, April 29th and 30th, because you're back out for Security Field Day. Yeah, that's right. We're going to have some great presentations from some longtime friends of Field Day out there.
We're going to be hearing from Fortinet, we're going to be hearing from Dell, and we have some more companies that are actually ready to tune in. Now that RSAC is over, I can't wait to hear a lot of these companies that are coming in to kind of further some of those conversations and talk to some experts in the security field, honestly, because we know that these things aren't going to secure themselves no matter how much we want them to. And so we're going to have some great conversations and probably a roundtable or two discussing the impact of this.
I can't wait to get a whole bunch of security experts in the room and get them ranting about things. It's one of my favorite parts, because that's what I do every week here on "The Rundown" when I'm here. When I'm not, Al and another co-host do it.
We rant about things every Wednesday on YouTube or on your favorite podcast application. Whatever it is. As long as you're listening to us, that's what we want.
Don't forget, we also stream it on Techstrong TV, and then we show up on a lot of other Techstrong and Future in Group programs, podcasts, Techstrong Gang, you name it. Sometimes I just get roped in. " But we'll be back next Wednesday to talk about all the IT news in the week that was.
Well, I won't be, because I'll be busy doing other stuff, but Al will be here with a new co-host, and then they can figure it out. And then when I get back, who knows what might happen. But until then, for Tom Hollingsworth, for Al Cook, and for everybody else here at Field Day, no fooling, we wish you a great day, and we hope to see you next week.
Welcome to this Tech Field Day section, the heart of our presentation here at Tech Field Day Extra RSAC 2026. We're going to talk about resilience. I'm Rick Vanover from Veeam.
And I'm Emily Taas from Veeam. All right. So we're on a journey today.
We're walking through the new segments of the Veeam capabilities, but the part that I think is the heart of what we do is resilience, and that's what people have gotten to know Veeam from, but we want to walk you through a few of those things today. So this is that part of the journey, so we're on our journey, and this is, A, part of where our products in market have brought Veeam to this conversation, but again, all this work of understanding, securing, and more, who are you going to call upon should things not go as expected? So we brought this up earlier, but Emily, you want to give your perspective to the different generations of disasters that are out there?
Yeah. So, we've been on this long journey of resilience, right? And we can say that in the beginning, it started with operational resilience, the fire, flood, and blood days of Mr.
Rickatron here, right? There was a disaster. There was some type of event from an operational standpoint.
We knew that we had to have a plan, and this was pretty straightforward. We knew that we could just recover to the latest or most recent restore point. We knew it had to be at most instant as possible because we wanted to reduce our RPO, essentially, in that data loss perspective.
Preparation time generally took days or weeks. We had to build different playbooks. We had to test those.
Hopefully, we were testing those more than once a year. But I know for some, it was probably being tested every once a year, and the first part of that test was them updating everything that they should have updated throughout the year. And then the probability of that not working was low.
And it all related to humans. You had a human at the wheel that was driving these orchestrated responses. And there was little to no concern around exfiltration, and there was little to no concern around data sprawl.
But then we entered this world of cyber, and now we had an external factor that was working against us, and it was a targeted cyberattack, whether that was a ransomware incident or just an exfiltration event, some type of cyber threat. Our recovery point became unknown. Depending on when that threat actor gained access into the system, depending on the type of infection that they had correlated, there was a lot that we had to do in terms of to understand what is going to be a clean recovery for us to go through.
And this significantly impacted the recovery time. It was longer now because now we had to think about reinfection. If we try to rush to recovery, then all of a sudden, our secondary DR site that was maybe a blind spot to the threat actor is now front and center and stage, and they're going to cripple our operational resilience in order to get a playbook or a ransom.
And your preparation time, for some organizations, it was random. For some, they thought that, "Well, ransomware would never hit us. We're a K through 12 school district.
We don't have any money. " But it happens. Some of those organizations that just didn't think that they would be a high target ended up being one of those.
And your probability of this happening to you is very high, medium to high in most cases. And with this new world of AI, we also have identities that can be human, but also non-human identities. The same AI that's driving some of our internal operations and making us better in terms of overall resiliency is also making those threat actors maybe a little bit better when it comes to building malicious code or doing additional reconnaissance or discovery once they gain access into the environment.
And then on top of that, exfiltration becomes very high because we've actually seen this in the own data that we have from Cover by Veeam that works on ransomware incidents cases where they see more exfiltration events happen versus pure encryption because threat actors, they want a payday. And one of the ways that they can secure a payday is if they threaten you to release information that they've taken. So your data sprawl concern becomes very high, because if you have data that's being released onto the dark web, well, how do you own that?
How do you control that? You don't. And then we enter this world of AI resilience.
You have overprivileged agents. You have people that are not coders or not engineers that are building their own AI agents. They're giving it access to everything.
They're giving it rights to go do certain things. And when they make mistakes, we got to make sure that we're recovering those mistakes very surgically because the last thing we want to do is recover good data from bad things when that bad thing wasn't an intent or a harm on that pace. And this has to be fast recovery time.
Your preparation time can be random from it, and your probability of this actually happening now is high. I think from some reports, we see from a human to AI agent perspective, it's going to be ten to one from some of these different reports that we're seeing. I know I met with an organization last year.
They have over 10,000 AI agents that have already been deployed within their organization. Another one just got Claude code for each one of their employees. They're like, "We don't care if they're in IT or engineering or if they're in sales.
" So we're going to start seeing a lot of this take place, especially here at RSAC. And then from an identity perspective, now you have to think about the AI agents as well as non-human identities, the APIs that they have access to. What are they doing with those APIs?
And then on top of that, your exfiltration becomes a high concern because what are they doing with that data, where are they putting it becomes a big case. So these threats are evolving. The sad thing is that it's not just because we fixed one, we can go to the other.
No, we still, from an IT and security team, we need to still be prepared for all three and maybe for all three to be taking place at once. Bold claim. I think this far column, we're going maybe ahead of the current state of the challenges.
Column one, column two, I think we all agree are real challenges in the market. We're looking ahead to column three. Check my thought here.
Do you see this as an upcoming emerging risk? I've done some AI agent things that luckily, sometimes there's safeguards, sometimes there's not. And just curious if you think we're ahead of our skis or where the market is.
Tom? How would you... And it's going to be a little tongue in cheek example, but how do you deal with, I don't know, the head of security and risk for your organization unleashing a claw on top of her email system?
Because I think that that's one of the problems that people are having struggles with is not so much that they know that there are things they need to watch out for. It's that, to quote my good friend Ivan Pepelnjak, automation, in this case AI, allows me to do stupid things faster than I could've ever imagined possible. " I think that that's where people are going to find challenges.
So I think that the struggle that they're going to have with a data protection company is how quickly can I triage the problem but then get back to a running state? Because who amongst us has not blown away a mailbox or a server ... or more.
But if we know we're working with a safety net, I can get that back. We need tools as fast as the problem. Right.
And that's where we live. And to one of Shala's points earlier, I think that the key there also is detection and information about it, because sometimes we don't know that that's happening. " before I get the next text message.
"Hey, we boiled the claw and served it with some roasted butter, and we've quarantined it so that it can't do this anymore. " Well, I think that the expectation is that there's a high risk, and then the thought is the people who own the data, chief information security officers, chief data officers, data scientists, and then sideways to directors and management, depends on who the company is. They'll need to...
I don't know the right word, but overlord just comes to mind in the sense that they need to oversee all these things. Because there is really no practical way to know what the organization is doing with the tooling they've been given. " It's grim, but the way that I've always described with automation before is with all this tooling that we've developed, you're giving toddlers dynamite and hoping that they figure it out.
Yes, there is a perfect path to that, but there's a lot of ways that things can get really messy. And there have been a few headliners of it going wrong, the dynamite exploding. Right.
We didn't bring those and prepare those examples, but they're out there. Yeah. And I think we're going to only see more of that.
So I guess maybe coming back to that, what does Veeam offer from a controls perspective? Because obviously we know that your bread and butter is if it got blown away, we can get it back. But I also know that that is a resource question with money and time spent doing a restoration, even as good as you guys are.
Yeah. Shameless plug. But how do I prevent that from happening in the first place so that I don't have to use the other things that you guys have spent so many years working on?
Dynamic pivot AC. Mm-hmm. All right.
So what we're going to do is I'm going to show you something that we... Where's my mouse? I'm going to show you something, Tom, that we didn't have in the script, which was, I want to talk about something called Agent Commander.
And this was an announcement a few months ago. As to Michael's point of 100-some days into the acquisition of these two companies, SecurityAI, the thought is Agent Commander is going to bring in three main pillars, detect, protect, and undo AI. These three primitives will be the first integration of our portfolio, so Data Command Center and the Data Command Graph that Michael was talking about, and the well-known recovery capabilities from Veeam.
Okay. Agent Commander is a marketecture. I'm going to just say it right now, but it is going to have an integration of these two things.
Now, marketecture isn't the right word. They want to call it a solution, but the reality is this will walk organizations through that. No, sorry, I should've closed that one.
But the thought here is this is Agent Commander going to be the one that bridges that gap from the AI agent discovery, permissioning, and more to the undo mistakes with precision thought here. So it's Agent Commander. It was big news at Veeam maybe three weeks ago or so, and it's the first directional integration of our platform.
But the reason why I called it a marketecture or broadly a solution is because it actually works right now with Data Command Center and the recovery capabilities we have. Just by way of analogy, the way that I think about it is I know that spray and wash will get drawn butter out of my shirt. But the solution is to wear a bib when I'm eating.
I've got to prevent- Okay ... the problem before because I have a lot of ways to restore it, and I like that, that we're lording over that, to use your terminology. Yeah.
Which is honestly is kind of a good way to look at it- Yeah ... because AI is honestly, it's a bunch of automated interns running around doing things that I really don't want them to do. Yeah.
Well, I think I like the bib part. But I just think there's trade-offs with velocity and innovation. Oh, well, move fast and break things doesn't work if- Yeah ...
the fast is hyper speed. Yeah. But anything to add to that, Emily?
No. So you're onto kind of the vision, and we're early on in this journey. Make no mistake, these three generations of potential things to go wrong will pivot.
There'll be surprises. The AI space will change and give us new phenomena, and then we'll have to make new connectors, and we'll have to make new discoveries, and we have to make new things backed up, and we have to make new things recovered. We're on a journey.
This right now is a brief look at part of our product portfolio. And the reality is we back up so much. We're more than just virtual machines, to what I started with.
There are some things we don't yet, but there will be a time. We get requests all the time for XYZ service. But the big services that are out there, chances are we protect already.
And that's what I really wanted to convey here. And then I guess we'll stop here for any questions on what we back up. I'd hope that when we think about the core of resilience, backup and recovery, replication and failover, storage snapshots, orchestration, some of the things that Emily spoke aboutI would like to call us successful there, but I realize not everybody here or online calls data protection their primary skill.
But do we have any questions on resilience? Yes. Shala from Gifted Link.
Yes, Shala. Shala. Sorry.
You're good. My name comes from a song, so no one knows how to say it. Oh, I get it.
But yeah. To piggyback off, I guess just to clear up, is there any monitoring of AI agents so that it could be detected if they have overprivileged access? Oh, yeah.
That's the heart of the data command graph and the data command center for Veeam. And Michael Cade is in the next session, we're going to hit the unleash pillar with AI agents, and so he's going to talk through that for everybody. Yeah.
And the only practical way to visualize all of this is with AI, honestly. Mm-hmm. So that's where this all comes together.
But any other questions on core of resilience? A couple zingers I'll throw out. I joined Veeam 16 years ago.
I saw technology that flipped backup and recovery on its head. I don't want to say I'm lazy, but I saw something that let me be lazy, and that was instant recovery. To take your backup and actually put it to work immediately rather than moving all that data back, so just to run in just moments, it was wild at the time.
It imitated, duplicated in the industry plenty of other times. But that changed the game. It changed the currency.
It introduced the data labs. It really changed our portability story. One thing we didn't talk about is moving off of VMware and stuff like that.
We can help with that because of this portability stuff. But anyways, this is the heart of our business. This is the bulk of our revenue.
This is what a lot of people know us for, but it's not really what we're trying to tell now. We're trying to tell this additional story. And fun fact about that, William, there's an organization that used Veeam to migrate 8,000 virtual machines- Yeah ...
off of VMware into HyperV. Yeah. Happens every day.
I know some people that are using our free conversion technology to take either their clients' or their own infrastructure from one hypervisor and move it to another completely for free with Veeam. And now they're even entertaining going to KubeVirt containerization platforms, such as Red Hat OpenShift or a couple others, Morpheus and more, right? So yeah.
So it's like Veeam can be part of that conversation, and what's interesting to Emily's example, a lot of times they're like, "We're only going to go there if we can protect it- Mm-hmm ... " So let's talk a little bit about if we remember the middle column of potential problems and cyber resiliency, and specifically ransomware resiliency. A couple questions came up in the earlier segments.
com. But a couple of other segments we asked questions about when can we detect potentially some of the problems. But I'll let Emily walk through this really powerful grid of what we do, but I want to set the scene when it comes to ransomware cyber incident preparedness.
In first quarter of 2023, we acquired a company called Coveware. Coveware previously did in-house incident response of their own and had a couple of software toolings that would help build data pipelines and help with recovery. They were really an expert in incident response.
com, incredible visibility into some of their threat actor behavior, some of the modes of entry, some of the TTPs that are in use by threat actors. But anyways, Bill likes to say that we can tell in the first 15 minutes of a conversation how well or how poorly an incident response is going to progress just based on how prepared an organization presents themselves during the initial phone call. That probably checks out, and if you think about the preparation of what do we do when bad things happen to good data, we are in the business of working left of the boom, everything from cyber incidents to the AI era to fire, flood, and blood, all three of them.
And when it comes to ransomware resiliency, I know, Emily, you live in this world here. Mm-hmm. Walk us through the before, the during, the recovery, and some of the zingers that Veeam brings along the way.
Yeah. " So before the backup even takes place, right, we have different ways in which we can correlate and contextualize data. So first being that Veeam Incident API that Cade spoke about earlier.
Right? This is a public API that different types of security platforms can write to. So essentially if they're finding something from an EDR perspective, that endpoint detection response tool, they can go ahead and they can flag that inside of Veeam and say, "Hey, we just identified a potential suspicious activity that's happening within production.
We have traced this back to being close to 48 hours old. There's a good chance that your backups that have taken place within the last 48 hours could potentially include this. " Or let's say we're seeing encryption happening during that time of production machine.
So that machine itself is in the process of being encrypted by some type of malicious strain, and that EDR tool sees that. They could also send a notice or an action to Veeam to say, "Take a quick backup ad hoc," so that way we could try to save as much data as possible during this encryption period, so that way we have those blocks of data that we can go ahead and roll back to. So this is, again, before a backup even takes place.
Another bit of information that was captured from our Coveware acquisition was this recon scanner capability. So recon scanner is what they utilize to help them build and track what has happened withinThat timeline of the incident. So it lives off the production machines itself.
It captures logs, and then from there, all of the actions and that information is formulated and based through the MITRE ATT&CK framework. So we can see things like brute force attempts. We can see things like changes within credentials.
We could see when tools were installed or downloaded that are living outside of that machine that probably shouldn't be there. So that recon scanner capability is actually showing us these types of techniques or tactics that those threat actors are utilizing and forwarding those over into production. So that way, we can be more informed to that overall risk mitigation that we can provide before backup, again, takes place.
And then during a backup, you have a whole line of different things that Veeam's able to do, right? Inline detection from a malware perspective, file system activity analysis, meaning we can go and look at the files itself and see if there's any encryption or any changes or anything like that that has happened to the file systems that we could flag as either suspicious or malicious. And then we have those IOC tool scanner, meaning we're seeing remnants that were left behind from a threat actor where they might have tried to perform some type of exfiltration tactic.
And then during the recovery response, you have the items like secure restore, meaning let me go ahead and pull this back up, isolate it inside of the sandbox, and do a restore. But let's go ahead and do some additional checks. Let's run a YARA rule against it.
Let's leverage Veeam Threat Hunter, which is Veeam's own AV detection engine that we formulated specifically to work with Veeam backups that can actually provide a better output for customers. So they could run Veeam Threat Hunter to do this AV signature-based detection, and then they could also run their own internal AV signature-based detection and get two lines of outcomes sent back to them. So they could see what Veeam pulled up and then what does their own in-house AV signature look like.
And then, of course, that could all be fully orchestrated and set up to work within a clean room. So we'll support other customers' clean room environments. I have a customer that leverages a separate subscription within Azure, and that is their quarantine network that they will recover to, that they'll test to validate and do some scanning.
And then, again, at the end of the day, we have this incident response or cyber extortion readiness responsibility that's available via Cover, where number one, if we're doing all these things, hopefully you're not calling, right, to get that incident because that means that there was a failure or there was a breakdown. But the one beauty, the fact that Cover could do is that they could see when everything had went bad from an organization standpoint, and they formulate that into proactive readiness assessments. So they go in quarterly to different customer environments, and they can show them, "Hey, these are new techniques that threat actors are utilizing.
" And they actually publish this online. You can actually find it on their quarterly reports. Top 10 threat actors, most used techniques, tactics, procedures that they've utilized to gain access into systems.
Did they exfiltrate? Did they encrypt? Et cetera.
So they have all of that information, but they provide that back to organizations so that way they can be proactive. But then on top of that, they ride alongside that legal perspective and regulation perspective that if you are in an incident, they can help provide some additional information and clarity based off of what is happening. So they'll ride alongside the Mandiants and the Unit 42s that are doing containment and eradication, but they'll just be providing some additional services on top of that.
And also intelligence sharing with cybersecurity law enforcement. Ah, yes. CISA.
Which is a big, it's actually a critical point of engagement. One thing I'll say about this end-to-end resilience claim, our claim in specifically in the data protection industry, we are claiming going to analysts, going to customers, that we have the most comprehensive end-to-end resilience. And we're not getting pushback on that.
This is a bold claim, and I'll give you one, every one of these tiles have their own amazing stories, okay? Mm-hmm. Customer examples.
I'm going to give you one right here. We have probably close to 70 different ways that we can store data immutably on an immutable media. I'm based in central Ohio.
I talk a lot to our tech support team. We have over half a million customers. I have been telling this story for a few years now, and it's still true to this day.
If we have our customers' backup data in an immutable target and they have their encryption password, very important and, we don't have a case on record of someone unable to recover data in a ransomware incident. That's really powerful if you think about the sheer volume. Every one of these have a story of saving the customer from potential bad things.
You're in the right place. Veeam's end-to-end resilience is by far the most comprehensive in the market. So it's a bold claim.
But the thought here is we innovate, and then we have our ecosystem partners that you were talking about. Yeah. So all of those capabilities that you're seeing there, those all be sent up to the SIEM providers and to our providers, right?
Yeah. " Yeah. " So bringing in those security teams and IT ops teams together.
And then I have a couple of things I want to go through a little bit different. I want to myth bust, right? I think you talk about a lot of established brands in the space.
There's a perception. I even started with that. than what someone may first know about Veeam.
Let's start with this one. Veeam as an enterprise. Doesn't scale.
Only a small business. Now, I showed you some of the revenue numbers. Those are big adult numbers, which is great.
But my proof point here, and this is something that the audience watching online, you can go to this, I think this is a really bold move because we share designs, like sizing all the different componentry to deliver a solution, no login required. We don't hide this information at all. One of them is, I'll just say, it was a large bank, the one that's 10,000 VMs, two data center, that one was a large bank.
The one that was 26,000 VMs was a retail operation. These are field-proven designs and validated by our product management team. Now, I don't think any one of us necessarily needs this, but I think it's a proof point that we have this out publicly on the market.
Mm-hmm. Another myth I want to bust is that it's not secure. Veeam's only runs on Windows.
So, I want to say it was November of last year, the version 13 went GA with the Veeam software appliance, and I know that some of those in the room here were at the Security Field Day 13. We were in kind of a preview of that. And now since that's gone fully generally available, that really dispels some of the biggest myths that we have.
Oh, absolutely. Yeah, 90% of the code actually was rewritten, so that way it runs on a secure Linux deployment for customers. Yeah.
Yeah. It's Rocky Linux, so if you all are familiar with that. And what's interesting, another bold claim that Rick drops on Monday mornings is the Veeam software appliance that Veeam offers in version 13, as far as we know, is the only commercial software, especially in the data protection backup space, is the only commercial software prepackaged with the DISA STIG hardening profile applied at no additional cost.
That's a big claim. DISA STIG doesn't play. That is a very serious security profile.
And to have that built into the Veeam software appliance, I think that saves a client an incredible amount of time. And so when we talk about that Veeam software appliance, pre-built, pre-hardened, and predictable operations, that's really the heart of it. I'm going to talk a little bit about the pre-hardened part, but anything you want to add, Emily, to these two other tiles?
No. No? There we go.
Okay. We got time. We got time.
Yeah. But it is a packaged appliance. That's a big benefit.
It's a consumption model. Now, we still have the Windows environment. It's hard to be absolutely prescriptive to customers, but we've gotten feedback.
We need an appliance. We need not Windows. Okay, done.
Sorted. And so the other thought of having it predictable, there's kind of this great day one view or day zero view, hey, it's pre-built, pre-installed, pre-hardened, and predictable, but what about day two when we have to do an update? All software needs to take an update.
So I've embedded a video here of how the individual componentry, so this is a view of the individual Veeam host management. So this could be a proxy, it could be a repository, or it could be the Veeam server. It's got quite the long password, trust me on that, and it has OTP, MFA required, and I've put that in.
And the thought here, just a quick view of this host management, this is different than the day-to-day backup administration. This is the actual infrastructure of it. And so things like setting the network time, changing passwords, et cetera, potential remote access for SSH off by default.
If you turn it on, it turns off at 24 hours, by the way, or some number of hours. But what I want to draw your attention to is this notion of updates, and I did this Friday before we came. So Friday was the 22nd, or 20th, if I remember right, and we're live here on the 23rd, but look here.
Updates to install. Note it says it checked an hour ago, but it says they will be installed automatically. It would've been, I guess, Sunday night- Mm-hmm ...
if I didn't do this. I went ahead and did it now, but these updates are mandatory. So I personally spin this as a benefit.
Hey, XYZ customer, this is all this time you don't have to go do updates. And I can just have this done. I can look at the history, and should I want to see specifically what happened when packages were updated, of course, we can accelerate that and take a look.
But the thought here is I'm going to do these packages, updates. It's pretty straightforward. It downloads, it updates, it goes, and then it's updated.
All right, so I think that that's just a quick example of mandatory... Yeah, Michael? So I was going to say about the- Oh, come on up here.
Yeah. Be on camera. That's the rule.
The rule. Yeah. So I was going to just say- Sorry ...
so I know Rick alluded to it, all those updates are from the operating system level up as well as Veeam. Yeah. So we're looking after...
So the Rocky Linux mentioned is actually a Rocky Linux distribution that we've engineered with a partner that is hardened, so it provides that. No one can SSH into a Rocky Linux shell and start installing other packages. It's completely hardened.
It's our Veeam distribution that is used for all of the components that we have. And those automatic updates are from the operating system up to the application. Yeah.
So cool. Thank you for that, Michael. And then the thought here is that the core resilience, we're making it easy to run, to protect, easy to recover as well.
I like to say that nothing in Veeam is more than seven clicks of a wizard. Mm-hmm. I still think-Even with data command graph, I'd say most things would still be in that rule.
But when it comes to resilience, any questions or comments that we can talk to? Jack Palmer here. I have a quick technical question on the updates.
Do the updates happen in the middle of a backup? So will it stop a backup, update, reboot, continue? Or does it try to find a window?
Because I'm thinking it might have a problem finding a window. Great question, Jack. It's configurable to the window.
The default time is not the default time of a backup. So I would recommend people just explicitly set a time so that they know when it would be. Yeah.
Like flip it around to be middle of the day versus middle of the night. Well, you could schedule it. Yeah.
So you could schedule. Take it out of the box, it's 3:00 AM. Mm-hmm.
Yeah. But yeah, it's a manual change, so it's not dynamic. If you've set a backup job at that point as well, remember this is just the control plane, so that can be bounced at any point.
Okay. But the proxies that are lifting and shifting data, yeah, you definitely don't want them updating and rebooting- Yeah ... when they're lifting and shifting data.
So- Yeah ... those guardrails in place, that that won't happen. The backup will take priority to get that over.
And if the control plane bounces, the backup will continue. Yes. Yes.
Worst case, retry. Yeah. And there's visibility on that.
It rolls up to consoles, emails, and the like. And I'll just give you one last example as we wrap. I had one in my lab, many deployments of the Veeam Software Appliance.
I forgot about one, but that's okay. It updated automatically and it was ready to go. All right.
So I'm Rick Vanover. Thanks for watching this segment of Tech Field Day Extra from RSAC 2026 on resilience. Thank you.