Techstrong TV Aug 1, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, did Vibe coating know what you did this summer? And in What's 25 billion amongst friends? We're gonna talk about a couple of those topics here on the Textron game.
We'll be back in a minute. Hey, thanks for joining us again on the Gang Today. We've got a number of, uh, great members that we're gonna be talking about.
Some really cool topics, you know, 25 billion if that didn't get your attention. Not sure what will, but of course, we probably know a lot about that already. Joined by John Schwartz and Lisa Martin, Fred Wilcott, and, uh, the very own, uh, IRO Winkler.
Good to have all of you here, regular gang members talking about this stuff today. Let's, let's take the teaser, the 25 billion. You'll, we'll, we'll, we'll take the hook and talk about that with, uh, Palo Alto, uh, snatching up cyber arc.
Uh, John, why don't you kick that off for us? Sure, yeah, I'll make this really brief so I can get everybody's comments, because I'm really interested in what you all think. I mean, it's just another big cyber security acquisition.
So, as you mentioned, Mitch Palo Alto Networks is, uh, announced on Wednesday. They're gonna acquire CyberArk software for 25 billion. It's the biggest deal yet for Palo Alto Networks, and they've done a lot of deals.
Um, this deals, uh, expected to close in fiscal 2026, and it comes on the heels, as it, we mentioned Google's $32 billion acquisition of Wizz. And in 2023, Cisco scooped up Splunk for 28 billion. And there is a rumor that Okta is in play, and there might be something happening with them very soon.
I, I spoke, uh, briefly with, uh, Krista case, who's the research director of Cybersecurity and Resilience at the Futurum Group yesterday. And she talked to me about the importance of, uh, identity in today's critical attack vector, which was a major reason behind this deal. Um, and I'm sure we're gonna be seeing even more consolidation.
And, uh, Alan, who is now with us, wrote an interesting analysis on, on the market. But what I wanted to do is go to Fred first and get his impressions. And then after Fred talks, I'd like to share what Lisa has to say from the marketing perspective.
So we'll kick it off with you, Fred. It's pretty amazing. I think one of the things over time that we've watched, uh, with, with Palo Alto, uh, Palo Alto, no longer Palo Alto Networks, right?
Much bigger, uh, thought and vision for the company, uh, Nikesh, uh, or is basically crazy like a fox, I think, uh, super talented. Uh, I've had the privilege of being in a couple of meetings with him in specifics, uh, but super talented operator at the helm. And I think what, uh, where he sees the, the future, you know, he skates to the puck, uh, in this particular case identity, everyone knows is a fundamental, uh, requirement for, uh, netting altogether.
All of the resources you have. I think there's inherently, it's a good decision from a product, uh, affiliation perspective, and making no bones about exactly how to go out and do that. Um, they've demonstrated a bunch of success with some of their acquisitions already.
Uh, you know, I'm not sure what we'll see out of this, but it's an incredibly powerful statement that also helps unlock, I think, a lot of the motions in the market about, uh, you know, where small, medium and larger companies in the acquisition climate can, uh, can start to move in this economy. You know, I think, um, I've sat down with Nikesh before as well to interview him. And I, I've never been more nervous.
He's so stoic. I was trying to crack him. And how about, you know, just a where are you from?
Kind of, you know, late night talk show conversation. And he was outstanding, uh, as a guest, which was a nice, pleasant surprise. But I think from Palo Alto's perspective, I was taking a look at CyberArk from a customer perspective.
They've got, they've got some great enterprise customer appeal. They've got customers like Aflac, I think also Coca-Cola, Cisco, um, what we've seen in the cybersecurity market, we were just talking about this. Alan and I, and Mitch, you were there as well, and John too at, at RSAC just a couple of months ago.
And this huge surge in data breaches and ransomware that's been really propelled by AI tools. And that's increased this urgency, I think. And we're hearing a response to that urgency and with increased interest in firms like CyberArk and consolidation.
So I think it's showing that what Alan talked about in his article was that the industry, the cybersecurity industry is at an inflection point. And Palo was responding to really strength strengthen its position in the cybersecurity market. We're seeing more consolidation, which is another theme that came out of R-S-A-C-E.
And from a a, a messaging perspective, I think what they're saying is, you know, managing identity is simply not enough. It has to be secure from the forefront. Because today's world, every identity, whether it's human or machine or coming now, AI agents is a potential target.
And I think that what they're demonstrating and saying from a marketing perspective is that this is security for the AI era that we have to address head on. Yeah. Um, oh, sorry.
Um, let me just jump in 'cause I have two observations. One, I think that more important than identity, all of a sudden being out there, I mean, to me, this is a sign of where Palo Alto intends to go as a company. 'cause I think specifically, you know, I've heard from people who know Nikesh, I don't know him.
He would ha, unlike the other two, I have not been, well, I have been in a room with him, but he would not know who I am. But basically, Palo Alto is trying to be Symantec 2005, where Symantec was buying up every possible thing to fit every possible security need. And I think this is the direction Palo Alto is going.
So yes, identity's important, let's not downplay it. And attacks are there, and everybody likes to think it's some sort of strategic move. But really it's a move for Palo Alto that they are filling in every block in a matrix.
You know, they acquired a lot of companies for a lot more money than I think they should have. But, you know, they acquired like Dig, they acquired Talen, they acquired like, you know, now them and a bunch of other ones, and they're basically filling in a hole. And in this case, I'm almost impressed because I don't think Palo Alto is spending way too much money.
I don't think this is akin to the, I'll say this is different than Wiz. 'cause Wiz was a private company and a private company with random valuation with a company that had an incredible amount of excess cash, which is essentially what, you know, Google is, you know, and they could pay more money than theoretically it's worth. Um, cyber Rock, on the other hand, is a well established public company with a well-established valuation.
They're probably giving a fair premium. I haven't looked at the stock price 'cause I think it is 25, the valuation. Yeah, it's, it's a little bit more than the valuation.
I, uh, it's, um, and CyberArk's been, uh, public for about 10 years. And just one other thing I wanna just mention really quickly, IRA, I'm sorry to interrupt, is that, I'm glad you mentioned this, this idea of, of more of a, of kind of a comprehensive solution because the word comprehensive keeps coming up in terms of cybersecurity solutions and filling gaps and filling holes. So back to you.
Yeah, I think that's probably a key concept. I mean, because the power, there's pa like for example, in the cybersecurity industry, people like the Guidepoint and Optives of the world. 'cause they can have a master contract and then buy anything they want through them, where they're, they act as the reseller.
And it makes it easy. Palo Alto, by acquiring all these different types of technologies, means you can have vendor consolidation and a buy from one person instead of going through legal contracts with lots and lots of people, which in a large company does matter. It takes time, it takes effort.
Smaller companies even more important. But I think one of the things that is gonna be a, a critical success factor at the end of the day is how well are they gonna integrate this? So it could all be managed through a single platform.
Because, for example, you look at some people like ca and they just buy everything, or I dunno, ca around still, but they just buy everything, throw it together, and try to get people to migrate to their preferred platform at the end of the day without integrating what's there. Microsoft, for example, when they acquire a company, they do a lot of work to make sure it fits well within the ecosystem. And it's gonna be a trick whether or not Palo Alto is acquiring all these different things and allows you for, for lack of a better term, manage it through a single pane of glass.
And as opposed to just being a simple contract vehicle, be a true platform. 'cause there's a difference between being a platform and just being a source for a lot of different tools that don't fit together. Kind of a product catalog versus really a platform.
You know, to your point, IRA, you know, in addition to, are they filling out the, the, the seats at the table, right? The blocks with identity. Um, I I, I've seen numbers like over 10,000 customers for CyberArk that Palo Alto now gets access to.
And since they weren't in the same markets, uh, they're in security, but not an identity with Palo, that gives them access to a whole new set of customers as well as the ones that they do overlap with. And to your point about easier to do business with, 'cause we now have one contract, and one, uh, one way of dealing business makes it a lot easier for them to both assume cu current customers, but go after a lot of others. Mm-hmm.
Yeah, I agree. Um, people don't realize large companies do have a serious problem in managing lots and lots of vendors. However, as important, when you're managing lots and lots of vendors, you also want ease of integration.
And if you're just gonna have a CyberArk out there functioning as CyberArk, and then you're gonna have your firewalls functioning as firewalls, you're gonna have your web browsers functioning as web browsers, it's gonna be a mess. But then there's also the implication. I haven't got to, uh, I just, I'll just pass the concept of zero trust.
A full zero trust platform requires identity. I'm just gonna say, IRA, to your point about integration, they did the right thing from a marketing messaging perspective. 'cause they talked about, oh, you know, we're gonna be combining CyberArk strengths with Palo strengths, and we're gonna deliver these integrated security solutions to our customers that they need to secure their digital future.
So the messaging, they talked about it, but to your point, whether that is delivered is a different story. You could also argue, Lisa, that ai, AI agents identity of AI agents and things like that are also critical to a future. And how disadvantages spell without That?
That's a good point. Ms. Beach is, this morning I got a, uh, an email from the former chair of CyberArk's board, this guy named, uh, Errol Maritz, I sorry if I butchered his name, but he, he refers to this as a complete end-to-end agent AI cybersecurity automated platform.
That was his, that was his takeaway. So it's hyperbole. What do you expect?
Yes, I love it. It's all about, it Always is. Well, We'll talk, well, I mean, big companies.
Yeah. Big companies do acquire innovations. In this case, I think it's innovation market customers, all of the above.
Right? And how well it's integrated, that's, uh, in the eye of the holder to be seen. Alright, good.
Well, you know, we'll, uh, we'll see how that, uh, 25 billion gets spent, I guess, in a lot of stockholders. Um, I think it was a four, I forget what the numbers were. It was part cash and, and stock deal as well.
Ca Yeah, it's cash and stock. Yeah. $45 a share.
Yeah. Et cetera. They typically are.
So. Well good. Hey, there's, and more to come, right?
We, I think we all probably expect more. Oh, we're just getting started. Acquisitions and consolidation seems, uh, pretty, pretty common in the cyber security market.
Alright, well we're gonna take a break here and we'll be back, uh, come back and talk about, um, are we generating secure code or are we just generating code with ai? There've been some incidents to talking about security with, uh, AI generated code. We'll be back in a minute.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way. With Textron Group. Hi, welcome back.
We're talking about security and AI generated code, vibe, coding. Now, Alan, who's now with us today, he's on the road, uh, moving his son from one city to another. Um, he had, he had lunch with, uh, Eric Cab Battis, who's the founder of, uh, includes security.
And one of the things Eric said to him that caught his attention, I think probably caught all of ours, is, uh, you know, that, uh, s stands, SS in Vibe, coding stands for security. Okay. Hmm.
Yeah. Well, does it really interesting, you know, I I there have been links to, uh, links to, you know, NY and other, uh, software security, vulnerability scanning, those kinds of things. But I, I'm really fascinated or kind of frustrated that the industry hasn't really stepped up with secure code generation through the LMS themselves.
Yes, we need it checked, but let's start with more secure code than what people can generate. And it doesn't seem, we've made that many advancements. So we've already seen some incidents where, you know, databases get dele deleted, configs are left open on the cloud, et cetera.
We'll see a lot more. I think, Brett, I'd love to hear your perspective on, uh, you know, we're generating more code, but probably more unsecure code. Yeah, no, it's, uh, I, I think when you look at the amount of models out there and the data they've been used to, to train on and the code they've been used to train on, so Veracode would say 45% of the code for more than a hundred AI models, uh, contains known vulnerabilities like, you know, SQL injection, cross site scripting, you know, all the various things that we know we root out with the O os popped in, you know, with static dynamic analysis tools that do that as a usual, uh, way of operating.
What's interesting to think about is like the, the suggestions both on the language type, the volume of these vulnerabilities or problems that we know, we sort of put in the automated checks and behaviors for, or guardrails, right? For us to, to do that with younger developers. We're seeing some other interesting parts of this where that software development lifecycle doesn't include these tools, uh, and arguably might start less secure given the fact they were a trade on insecure code to begin with.
So it's interesting, right? We had, you know, this, uh, this, this set of occurrences, the, the repli conversation that you're referring to around the sql, you know, production SQL database getting dumped. But you also have, you know, the Amazon Q extension issues around the, the version compromise where there was a GitHub PR that was submitted here that had malicious, uh, effect due to, you know, insufficient code review.
Uh, it's just sort of fraught with peril everywhere. I don't know that vibe coating's the problem here, uh, I would say this is, uh, you know, if I were channeling my inner IRA Winkler, I would say this is the problem we've had for 20 years, uh, maybe longer, but uh, now we have another permutation of it with not following any of the same rules. We already know.
Ira, you can stop stupid, right? This is your, this is your domain. So well Technically you can stop stupid and that's our job.
But I would argue it wasn't the first time I heard the joke. The s in vibe coding is not well vibe coding that, I mean, the S in IOT stands for security. The s in worldwide web stands for security because what I see is a consistent problem through the history of technology where security is an afterthought.
Like there was no security in the mosaic web browser, web servers, whatever, when they first came out. There was no security in IOT when they first came out. Now, the problem is people always want the benefits of saving money and speed to market without actually investing in any forethought, especially with regard to security like the coding alone.
Because really security vulnerabilities are essentially coding bucks, for lack of a better term. I'm oversimplifying. And if there are security vulnerabilities, there are coding bugs.
And that leads to fundamental issues where people are generating massive amounts of code that are gonna experience problems and fail both in functionality, um, resilience and security. And so I see this more as an overall problem where companies are just trying to rush out there. I mean, I remember this was a story I maybe you spoke on in another tech strong gang.
I wasn't on it, but there was an Indian company which said they had a, a, an agentic AI that wrote software, and it turned out they were just hiring lots of people. I don't understand what's wrong with that. You know, you're essentially paying a company to write software.
Do you care how it gets written? As long as it solves your requirements? There seems to be this focus like, oh gee, you didn't do it with just an ai.
I am like, does it matter? And we need to understand that if you take out the ai, the AI only does what you tell it to. And if you're taking this out and you're not, including, if you're taking people out and you don't include security in the programming of the vibe coding tools, you're gonna be screwed.
And this is a problem where people need to say, there are security requirements. This happened with Microsoft, it happens with every software technology out there. And sorry, I can go on a rant about this, but this is nothing more than everything else.
Like another mistake you just see that's gonna snowball unless people stop it and say, where's the security? Yeah, the, the, the three points that I would just make real quick, Mitch, if you look at, uh, repla AI wipe, okay, no environment gating, we know that to be a problem. For anybody that writes code, the Amazon Q hack, that's a poor PR review.
Okay? We just automated that process and didn't participate. And then, you know, a lot of the things around the vulnerabilities, well that's just, you know, the absence of A-C-I-C-D security, uh, pipeline for that process, right?
So none of this is a new problem. We just took all the governors off and decided we're gonna write a bunch of code and push it. You know, Lee, all good points.
Lisa, I, I wonder if we're exacerbating the problem with ai because we are in such a rush to move into AI to capture mind share, to, you know, move beyond just kind of saying we're doing ai, but, but bringing things to market and with that accelerated pace, the security problems could be even worse. Oh, absolutely. I I think we, we hear that constantly the speed, time to market, time to value.
And whereas what Ira was saying, I totally agree, security shouldn't be a, a feature that you tack on when something goes wrong. And companies talk about this all the time. This is a message that is consistently relayed.
It shouldn't be an afterthought, but it is. And by the time customers are asking, it's usually because something's already broken. But I think the problem is, and, and some CMOs I talk to, argue that we've gotta slow things down.
This accelerated pace, which I think is only poised to get faster, is causing a lot of problems that we could be preventing if we weren't trying to be the first to market every time and infuse AI into everything. I think that that rush mentality has got to slow down and it's gonna take some strong companies willing to do that and not be first, uh, for I think that, uh, problem to start to be reduced. I don't say mitigated, I think reduced.
It reminds me of, uh, the exuberance about going to the cloud when that was like, oh, let's get everything to the cloud. And then that got sort of quelled by Yeah, but it's not secure. I know, Fred, I, you, you, you vibe with that too.
I wonder if we're gonna hit that kind of an a moment with AI generated code. I would say, here's the issue that the cloud is actually an interesting example because in many cases what's happening now is moving to the cloud gets you more secure these days than if you did it yourself. Because an organization, let's just say an organization that's using like Google apps or whatever the case is, those organizations are fundamentally, we've managed more secure now because Google has better internal security than I would say 99% of companies can implement on their own.
Say whether, you know, same thing with my, you know, office 365. Salesforce, again would manage the CRM programs better than people would themselves and so on. And it would be nice if these, you know, vibe companies are actually writing software that has better security implemented into them in the first place.
The problem is, I don't think these people know these are people who themselves, you know, it's like Google has a lot of security engineers. These are startups that have no concept of their people have no security background, they just know how to code generative ai. And frankly, I doubt they even know how to do that.
They're just figuring out as they go along. And then trying to tack on security is almost the opposite of what's happening with cloud security because you're getting a whole bunch of people who don't have native security ability, who are then not investing in security, trying to get these applications up and running quickly to sell. And I think that's where we're gonna have more problems if I, if I'm not doing an endorsement here, but if you tell me Google, Oracle or somebody else like that is developing these vibe coding tools, I would have a lot more faith in them than just these generic startups developing them.
Interesting. John, do you, do you hear much in the market? Is anybody talking about this in terms of, I mean, one scenario would be pick your company open AI or Anthropic or whoever that's building foundational models.
Say you go get the Freds and I Winkler and other people of the world and, and software engineers who know about secure coding and build the next model that's really good at, at creating secure software. I mean, that's just one possibility. Is anybody besides just integrating with, uh, code security products, is anybody talking about solving this problem that you've Seen?
Um, not really. I, it was just like full bo full throttle ahead. I mean, when you mention open ai, it's like, I can't even keep track of all the new product announcements or releases there.
I mean, it's just like, it's dizzying, you know, they're, they're leapfrogging themselves, you know, uh, so I, I wonder we again, I, and I, I'm not gonna be a alarmist, but I'll, I'll throw this out. It's eventually, it's gonna be some sort of incident. I thought it was CloudFlare.
I, for instance, I, I I just thought it was about that a year ago that where there's gonna be some sort of caution around, uh, the lack of guardrails. I remember we talked about this yesterday, this, this idea of getting, getting full speed ahead, damn, the consequences. And I, I just, I don't see it changing unless people are, are, are forced into some sort of public relations or cybersecurity disaster to address it.
Um, I think right now the obsession is just to, is to get out there as fast as possible and, and especially if you're larger companies and overspend, as I had pointed out, which I agree with and gobble up as much as you can. But I think it's also, we're also tilting in the direction with the larger companies are just, are, are at a huge advantage versus the startup community. You know, I've done a, a fair amount of my own kind of working with these vibe coding, if you wanna call 'em that tools.
And, and I think it makes the case for a more experience developer because it doesn't generate code that's that's more secure. You have to ask it or tell it what you want it to do. You can ask it to exam and examine my code.
Find where you think there are security flaws in the design as well as scan it and may find something, may say, Hey, here's a constant that you've defined, probably shouldn't be in your code. Let's pull that out. But you, you have to ask it or tell it to go do things.
It's not gonna naturally, oh, I need logging for that. I need to know when something happened. I need, I need to, uh, apply this approach as opposed to, you know, leaving something, something open where I'm gonna violate an O os top 10, I guess you could say, make sure my code doesn't, but then who's gonna verify that, right, Fred?
Just to verify, I think the, the easy steps are the ones we know already for guardrails, right? It's not hard to separate environments. It's not hard to implement A-C-I-C-D pipeline with approvals, right?
It's not hard to, you know, put branch protection on things. Like, there's just a lot of things that we know that aren't hard. So those are easy things we can do.
The fixing vulnerabilities, I mean, okay. I don't know. Yeah.
But I would also have to add that you can take away, you know, it's like easy to put the blame on the companies writing these vibe tools or whatever. You really have to blame the customers at the end of the day because just 'cause you get code from a tool, it doesn't mean you take away the ver verification of this code. You know, it's almost like, oh, well it's the developer's fault.
It's like, no, it's kind of your fault because you're taking stuff, you want it cheap and you're not investing in quality assurance in any way, shape, or form. 'cause again, if security vulnerabilities are slipping through, that is a specialty, I admit. But functional quality problems are also gonna be slipping through as well.
I think the interesting thing we're gonna have to wrestle with here is a, a company may get around their environment pretty well and understand the guardrails, but, um, third party risk. Uh, we don't know whether or not your code is secure. We don't know whether or not all of these other, uh, processes have been followed appropriately.
I mean, it's hard enough to figure that out within ours, but if you look at sort of the Amazon problem and, you know, some of the provider problems, these are significant that customers had no action. I think it's a, I mean, it's a, it's a good segue into one of our other things we're gonna talk about. Yeah, it's a good point.
Especially with the innovation cycles being so short with these tools, you know, coming out with the new plugins, new models, new everything. You know, i i is the proper security testing happening in the, in the product end of things. And then back to your point, it, IRA, it's kind of what were you thinking when you left all those good security practices on the table to try this new coding tool?
You know, was that really a good decision? Probably not. Well, all good points.
Yeah, I would say there's an issue though. The question is in the first place, and this goes back to one of my other comments, did they have good sec coding, coding practices, coding, especially coding security practices in the first place, which is number one, and then at some point, much like all these other, you know, rush to the cloud and everything else, do they have contractual, um, obligations built into the contracts with the providers to ensure that these good security practices are then embedded in the acquisi, the acqui, the acquisition of software that they're essentially making? Frankly, I think, I don't, most of the companies who are being hit, I doubt had good security practices in the first place where they would have verification of any of these things going into production.
But that maybe have to look on, on case by case basis. All right, well, we're gonna get into some more security issues around AI on our next segment. So we're gonna take a break right here and we'll be right back.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
We're back at, um, Textron Gang, and this segment is called Passwords, please, and I cannot wait to hear what I and Fred think about this one. Uh, Clorox is accusing it services firm cog cognizant of letting hackers into their corporate systems simply by giving them the passwords when asked multinational. Uh, Clorox is suing Cognizant and Superior Court in California for $380 million for its role in a cyber attack by the scattered Spider threat group nearly three years ago.
It's also seeking punitive damages. I'm just gonna tee it up and say, what do you think, IRA, about this one? Alright, so I've been in security like so long, like nothing has come to surprise me.
I have however, developed what I call a church lady scale. You know, the church lady scale is hopefully people get this is isn't that special? And then could it be Satan, you know?
And oh my God, you make a good data car, by the way, you know, Harry and I live. Yeah, God, that's it. That's old school.
And then for this one, I almost, I had to add like the Deadpool scale where Deadpool has like his, um, uh, what's the name? Home alone face, like, you know, a hopeful maybe you saw like, you know, like that because I'm like sitting there thinking one of the major providers has, and and they, they claim to have audio of this, you know, one of the major providers has no identity verification, you know, going back to the first block discussion of like, you know, multifactor authentication. And they're even saying where there was multifactor authentication, they could just change the phone number by calling up and asking for the change.
And, uh, I mean, when you look at fundamentals of a help desk, this is like one of, I, like, literally more than a decade ago, I was writing help desks, actually two decades ago. I'll mention this because there was a case where Microsoft, hopefully Microsoft's not mad for something that happened more than two decades ago where I was like paid to go through Microsoft's authentication procedures to verify like a decision tree. Like if somebody calls up and says, I want my password changed, how do you go ahead and, you know, do this?
So I went through a decision tree. Okay, well what if they say this? What if they say that?
What if they say this? And so the people know, like from a security perspective, how do you do that? And that's without the technology in place like caller ID and everything that we have now.
And so we would, and the reason I did this was there were account takeovers where people were calling up the Microsoft help desk on their gaming systems and saying, oh, I forgot my password. And the agents would change it, and then people would like sell off all their like magic unicorn hammers or whatever it was. So there was a lot of money to compromising this.
And Microsoft decades ago realized there was a problem and took proactive steps to putting in like this whole protection mechanism from an operational security perspective. And that doesn't include, for example, you know, like the technology caller id, multifactor, authentication, everything, you know, to the extent we have now. And so when I look at this, and this happened, what, 2, 2, 3 years ago, I guess, you know, this was kind of like horrifying because people, you know, I do social engineering simulations where I call up a help desk and get them to try to do things and people are like, gee, that's not nice, that's unfair and all that stuff.
And, you know, somebody should have, honestly, it's not a standard practice, but this is beginning to an incident like this says all large companies should implement it as a standard practice to try to see how hard is it to get their help desk providers to change things like this. Because if any of this is halfway true, this is horrifying where you are, you are paying somebody to implement processes, which supposedly there were that were just not followed appropriately. And to the extent they say, look, I am no doubt Cognizant is strong in security in many, many ways, but there has to be an acknowledgement if, if this is true, if as alleged, you know, people could call up and just say, Hey, please change my password or gimme a new one or change the cell phone.
That's a problem. And that's an operational problem because a lot of people are relying on technology and they need to make sure they have the appropriate operational procedures. Like I said, I helped Microsoft with decades ago of step by step by step, what's the right way if you don't have the technology?
There was supposedly, if the articles were correct, a process to at least verify with the manager or at least inform the manager that this was done. And so, yes, a CyberArk is critical, but you can't ignore the operational procedures you need to build in. And a, I'm sorry, I like, this is just like I said, Deadpool level, you know, horrifying, you know, like, you know, like that.
And so hopefully, um, anyway, I will leave it at that. My rent temporarily over. Yeah.
Hey, you know, Lisa, you, you, we've talked before about sort of the incident management from a brand company perspective in these kind of situations. And, you know, sometimes you think something fatal has happened, you know, maybe it's a CrowdStrike, but you know, CrowdStrike had a great reputation before that, I'm sure Cognizant did too. What, what do they, what do companies have to do to, to fall back and recover from this?
And is there any really big financial impact when something like this happens or we kind of desensitized to it now and we just don't wanna be Clorox? I think, well, we don't wanna be Clorox, but, uh, it's funny, IRA got a, um, an OG church lady vibe. I got a Lloyd Christmas vibe with these folks on the set of Cognizant go.
Sure. Because he was, you know, Lloyd Christmas, he could do anything. I'm so happy.
But I think one you mentioned CrowdStrike and I praised them recently on Schwab about being a company to watch, but also one that was completely transparent last year when this huge breach occurred, not breach, um, uh, issue happened, security incident happened. Their CEO came out, I think same day, acknowledged what was going on, took the blame, and they've come out really well. I think they've really done a great job because they were so honest with customers and transparent about being able to preserve their, their brand reputation.
Nobody wants to be the next, in this case, cognizant. But what Cogni what what I read in this article was, it's a, he said, she said, Clorox is saying this. Cognizant is saying, no, we did this instead.
But what what they need to do is acknowledge where they had missteps on both sides to be able to salvage the trust that com customers of all types have in both brands. I think that transparency, um, is not, it, it's a, it's an imperative to be able to maintain that customer trust and then to continue earning trust from perspective customer. So that he said, she said, mentality is not gonna help in this case.
Well, I think also you have to look at how other companies did. There was an incident, JP Morgan Chase lost 80 million records. And the 80 million records was due to the fact that one system did not have multifactor authentication on it.
That was like a failing, it might not have been the only failing, but, you know, people were saying, Hey, there's this issue. And they were, and there were some other major incidents happened that were on a smaller scope at about the same time. J at the time, JP Morgan basically came out and said, yeah, we screwed up.
There should have been multifactor authentication on the system. There was not, we will deal with it. And everybody just said, I have nothing to yell at them for.
Everybody was just like, there's nothing to dig in. They put out information, they said they were wrong, they said they're gonna fix it, and the story was over. But then you have all the other stories where people are pointing fingers and that creates more of a story.
It's always the co it's so, I mean, I hate to say that it's always the co not the, I'm not saying that there's a coverup, but when you're transparent and up upfront, say, look, we made a mistake in the case of CrowdStrike or JP Morgan. The what this issue about cognizant, this interesting to me is you wonder if there were other similar problems with other customers. I don't know if this is a one-off.
So therefore, I mean, with Iram a little bit, um, aware, I'm not wary of what what was written, but it says again, if it's a he said she said story that's difficult to weed through. Yeah. I mean, if they would just frankly say, look, we, there are deficiencies in the thing that might have gone ahead and cr you know, added to this.
We're investigating this. If there are deficiencies found, we will address them. That would make it more of a non-issue.
Because frankly, the more Clorox has to drag it out the way these cases are gonna work, they're gonna go ahead. They're gonna dig into all of cognizant security to find every possible flaw that Cognizant has in there that could theoretically come out in court. They will almost a hundred percent settle out of court where, you know, cognizant admits nothing wrong, but gives them money.
The reality though, is if they would just say, there seems to be a deficiency that we're looking into and have addressed since that time, it would make people feel so much better. Because I don't think anybody expects perfect security from any vendor out there. And, and yeah, but Let me interrupt you 'cause I think, let me put the, you put your CISO hat back on.
I'm gonna put my former identity provider CISO hat on and say two things. There's this notion of implied security and around third party relationships, right? So as a identity provider, right, I might outsource to another organization or health or help desk function or support function.
That organization may also, uh, be sourced for five other organizations, right? So if we go back to the Okta breach, this is what happened there, uh, at the same time, right? I called Dave that time was like, Hey, exactly what happened.
Why? Because some of those same environments at that time, we also used some of the same people. So one of the challenges with this particular exercise is transparency is one thing, but accountability is another.
And so if you've outsourced your third party risk to an organization that is a industry known Titan for doing this kind of work, and it becomes a problem, there has to be some accountability there. The cyber resiliency part, Clorox has to own that too. It's a shared responsibility problem.
But the, the bottom line here is like if you trusted Cognizant to do your endpoint and identity management and this particular thing happens, happens, is that not akin right to a violation of your third party trust agreement? And are they not accountable for it? Well, I'm not disagreeing at all with any of this responsibility.
I'm saying from Cognizant's perspective, they need to just say something clearly happened. We're looking into it. Even if they would just say, yes, there was a problem.
It appears to be an isolated attack from what they could tell, we haven't heard others. If there are others, the more they fight this, the more public, the more it will come out. But I'm just saying from a response, a PR response capability, they should do what JP Morgan or Tylenol did.
And I don't, sorry, I saw the Tylenol. Yeah, I was thinking back to a year ago with CrowdStrike. CrowdStrike was pretty transparent, I think about the way Delta reacted.
They threatened to sue and they, they, they spoke way too loudly. 'cause I know Ed Baskin and his, his whole idea was we are gonna be as advanced technology as technologically as anybody else. And they immediately pushed that.
And you know, in a sense they, I think they had some sort of reputational damage and then Microsoft just put his head in the standard in the sand and pretended like nothing had happened. So I think about that and, and, and the, there are consequences, right? The public forum.
There, there are, um, I mean, at the end of the day, it depends who's out there telling a better story. But I think when you look at this story, 'cause is Clorox, see, the thing is that, you know, it goes back to my church lady scale, you know, isn't that special? And now adding Deadpool in this case, the fact Deadpool is involved in the identity portion, does it alleviate the problem in theory of the internal resiliency?
I would have to say I don't think so. That's one issue, you know, but the issue here, I mean, as we're addressing, you know, you know, if you are outsourcing your help desk, support your technology infrastructure for Somebo to somebody who allegedly changed passwords negligently and let the bad people in. The question is, is there liability there?
That's the answer should be probably yes, because there's an expectation of what they're doing. There were clearly standard operating procedures that were not followed. You know, does that alleviate Clorox not having more resilient infrastructure?
You know, at one level, I have to find out more, and I, I will say this and caveat this. At one level, I have to find out how much was the identity access management tied into this? In other words, like what in the resiliency, how much revolved around, for example, access to tool sets that were given out that allow, for example, manipulation of log data that allow for overriding of operating procedures and stuff, or, or sorry, permissions and things like that.
And that's potentially a mitigating factor for Clorox. Is it to say the whole thing should have crumbled to the point where it did impact cause outside of, you know, cause $300 million worth of damage. You know, I don't know enough about the internal incident.
I would have to think, yeah, it could have been a bit more resilient, but the whole thing changes things, and I'll leave it at that. Well, I guess the, gonna close this topic. One thing I would also add to this is when you aren't transparent and you just point fingers at the customer, guess how your other customers feel about working with you?
That there's, there's some consequences to getting into the he that you said, without that transparency. So I'm sure we'll have another conversation about another breach or some, uh, some fault in a security incident to, uh, to examine and maybe you'll learn from. I mean, that's what this is all about.
So, well thank you to all of our gang members, IRA, Fred, Lisa, John, it's been, uh, wonderful. We had a great conversation today. Kinda hit a lot of areas and, uh, there's some ties in between 'em as well.
We thank everybody for joining us here on The Gang today. Please stay tuned for some great content. It's coming up on Textron tv.
com, security Boulevard, cloud native, now, tech Strong, ai, et cetera, et cetera. com, another new one that we have. So thanks to you all for joining us.
We'll see you on the next game. Welcome to another edition of techron tv. I'm John Swartz, Techron Group's senior content writer in Silicon Valley.
And with me today is John Herma, chief Product Officer at Absolute Security, where he's responsible for leading the company's product organization and driving the strategic direction of the evolving portfolio to extend cyber resilience capabilities to global enterprises. John has spent more than two decades focused on enterprise mobility and security. John, welcome to the, uh, segment today.
John, thank you for having me. I really appreciate it. Sure, and sure, my pleasure.
Hey, I understand you're here to discuss how absolute security, which is a, a valid leader in enterprise resilience, has announced some new advancements in AI that's been added to the absolute resilience platform. Can you tell me a little bit about what those are and, um, maybe where you're gonna be announcing or elucidating more about these announcements? Well, hopefully we'll skip the hallucination bar, but yeah, we're really excited.
So in our, uh, secure endpoint at 10 Edition, um, we've introduced kind of our first foray into, um, uh, artificial intelligence in terms of having, uh, an AI assistant embedded into the product, um, to help our administrators more easily, um, generate insights, reporting, understand their risk and, and, and compliance posture, and just do that in a much more rapid, natural, simple way. Um, that doesn't involve, you know, having to do complex queries, complex report generation. You can just have an interaction with that assistant, um, and it will reveal the insights to you, um, based on the questions you're asking it, and then allow you to turn those into customized dashboards, trending and reporting so that there's something that you're looking to track over time.
Um, it will automatically do that for you. Is, is, are you gonna be talking more about this at Black Hat and under what type of context? Yeah, for sure.
So we're, uh, we're gonna be a black cat and, uh, I'd be remiss if I didn't say Booth 46 0 5, so definitely come see us there. And so we're gonna be demonstrating, um, that, that product as well as our, our full, uh, full portfolio and some other, uh, interesting capabilities that we've, uh, launched recently. For example, our rehydrate capability, um, our AI threat insights, um, capability, uh, as part of our secure access portfolio.
So we're, uh, really excited to be showing off everything we do, uh, as absolute, you know, one thing that I wanted to ask you about and kind of just kind of stepping back in the cybersecurity realm, for example, are you seeing, uh, especially among enterprise adoption, is there more of a, of a cognizant, uh, acknowledgement of having guardrails or the necessity of guardrails, especially now recently as AI starts to take off and drives demand? No, absolutely. So I think it's, it's this classic tension where folks absolutely wanna embrace the technology, use it for all the, the wonderful, uh, things it can do for us, uh, but are taking, you know, measured approaches and making sure that they have policy in place, um, in terms of what can be used, what types of tools can be used and what modes.
So that's really important. Uh, I would say is, is making sure that you start with that, uh, policy side of things so it's clear, uh, you know, that it can be used, but then also how it should be used, uh, but then also being able to couple that with tools, um, that make sure that those policies are being enforced. So within our own portfolio and others are doing similar things, um, we have the ability, for example, to see, for example, uh, whether there are local models running on the endpoint and which types of local models and, you know, the ability to apply controls if you didn't want to, particular models running locally.
And then with our secure access product, we can actually also monitor the flow of traffic from that, uh, endpoint and that user interaction out into any cloud-based models as well. So you can kind of have that full visibility into terms of what is going on either on the endpoint itself or in conjunction with a cloud-based, uh, large language model. And make sure that you have the visibility to ensure that, uh, your policies are actually being complied with, um, and then as needed to remediate, um, and control that where something might be being used in a way that is not consistent with policy.
You know, it's interesting, there's this been this classic narrative, and I know it's been discussed at blackhead or RSA, any number of conferences where security was always kind of thought of as like this evolutionary technology that slowly developed. But given what's going on with AI and it's revolutionary nature, it seems to me increasingly that cybersecurity is becoming more of a, uh, a priority. It's not the last thing considered, or one of, one of the, among the last things considered, it's, it's raised in terms of, uh, it's importance, especially as AI is, is kind of seeping its way through all these organizations.
Is that kind of an you see a change in that narrative happening at all? Well, as you say, it's been evolution. It's really interesting.
We just came back from our company kickoff in our own as, uh, uh, CIO Harold, uh, Revis actually gave a really great talk about, you know, how has the role evolved over the years. And I think what's interesting there is that it's, it definitely evolved, but in some place it is still evolving. So I think depending on the type of company where you might be in the world, um, what we think of this as a role today, uh, for example, north America, if you're working at a financial services institution, it might look a little bit different than it does in some other industries, some other, um, locale, but certainly, um, it's moving and, and a lot of places is now, you know, more level visibility.
Um, and there's, there's accountability all the way up to the board, um, for that risk management and cybersecurity posture management, um, aspect of that role. So it has certainly evolved, um, from really being almost kind of an IT EO function many, many years ago, or an adjunct to IT, to really its own board level, um, visibility in many organizations and certainly our own. Yeah, they knew that.
There's a, uh, some couple of research reports that came out, including one from the Futurum group this week that indicate that, uh, CIOs, almost all of them, all of them actually, there were 203 they talked to, and all of them talked about this kind of transitionary period in terms of IT experience and the use of AI absolutely necessary, uh, a critical part of what they're doing, uh, especially, uh, given the number of data breaches and, and ransomware incidences that we keep hearing about. So it's definitely become in, again, even adding in, in the, uh, growth of a AI agents, it's become an absolute necessity. Um, hey, Fs, that brings me to my next question.
What threats are causing the biggest problems for organizations today in cybersecurity? Well, I think this is the, the, the place in the conversation, right, to use the, it's probably the two words that are used most often these days, so certainly ransomware. Um, the increasing sophistication of those, those attacks, the notion of ransomware as a service where these ransomware organizations are operating as businesses and, and offering best in class services to their, their customer group, so to speak.
It's a bit frightening when you think about how well organized that's, uh, that's becoming. Um, and then coupling that with ai, uh, both on the, you know, for good and for bad side of things because, you know, for example, with ai, uh, on the bad side of things, we have the opportunity to craft much more sophisticated phishing attacks and so on, um, uh, have them adapt in novel ways to, in, in and in, in tune and improve their behavior. But on the flip side, when we're using it for, for good, um, I think one of the big stressors on, uh, A CIO or CIO organization is just staffing and having enough people to keep up with, um, all of the patching, configuration management, all the things that need to be happen, make sure you have what we call shields up in the first place.
Um, and so being able to leverage AI and agentic AI to not just identify where you have those weak spots, but then to actually automatically be able to apply, you know, configuration, patching other forms of automation. So at least that part of the job, um, is simplified, operating more at scale, um, is, is a wonderful opportunity. I think the other great opportunity for good for AI is that, you know, when you can use AI to model, you know, how data is flowing throughout the organization and being able to, uh, identify cases where, for example, a legitimate process may have been hijacked and is now starting to operate in unusual ways and, and move data, for example, low and slow exfiltration things that are very hard to catch, you know, at the macro level.
Um, AI can certainly be a tool, um, to kind of root out those sort of instances of anomalous behavior and again, at that very, very nuanced level, um, because increasingly attackers are trying to, you know, impersonate and sit on top of otherwise legitimate processes and people and identities, um, so they can execute that live off the land. And that low and slow data exfiltration, um, type of model, just just the proliferation of AI agents from so many different vendors, does that actually help or hinder, um, security efforts within companies. I'm wondering what the impact you think will be, I know it's early in the game, but I'm wondering where you think that's going.
Yeah, well, I think it's, look, it's always when something new comes around, um, there's gonna be many, many, many vendors and options to choose from. But I think when we see any of these sort of, you know, hype curves and things, things, you know, you go through that inflated expectations, maybe that disillusionment, then you start to come out as things sort of start to normalize. So I think we will see that, um, that similar type of pattern.
I think what we're gonna see in this case, however, is a very compressed, uh, pattern because the nature of them tools themselves will probably allow that, that cycle to, to progress more quickly. So, um, there's always a bit of, uh, norming and storming involved, but, uh, I think we'll, we'll, we'll get through that. So, so I wanna ask you about, uh, absolute security and how, how specifically if from your, your product viewpoint, how it's helping organizations in the modern threat environments.
Yeah, so I I, yeah, I'll preface that by saying one of the big shifts that we're seeing overall is this, this notion of, you know, certainly I have to continue to focus on protection and detection, but we're seeing a general shift where a lot of folks are recognizing that, look, you, you have to do your absolute best in, in those areas. And I'll, I'll talk a little bit about that, but increasingly a focus towards, okay, but what if I do have the bad day? And maybe not even what if, but when I have the bad day, uh, how am I actually gonna be able to recover recover rapidly and to full production and productivity for, you know, all of my users.
So I think there is kind of an understanding there that if you're not, you know, assuming that you're gonna have the bad day and preparing for that, that when that day comes, it's gonna be worse than it, than it otherwise would be. And so at absolute, um, we kinda look at that, that resilience journey, um, across sort of four, four steps. And, and there's different capabilities we have in our portfolio to address that.
The first one I call just get the hygiene right. And so, uh, one of the really interesting things, and a bit alarming is that, uh, you know, depending on whose statistics you look at, maybe 40% or more, um, of successful ransomware attacks were traceable back to, uh, a vulnerability that was actually already known and could have been, could have been patched. So one of the things that, um, we, we focus on there, uh, with our, our patching and vulnerability remediation capabilities backed up by our, our firmware, uh, persistence, is that you, you just have to make sure those processes are running, running in an automated way, running rapidly, and running to completion so you can get that basic hygiene right and take care of all the vulnerabilities that you already knew about and, and should have been fixing.
Um, so that's the first step. You have to get the hygiene right. Uh, the next part is you have to make sure that the tools you're using for things like endpoint protection, um, and XDR actually deployed, um, fully updated and operational at all times.
And we call that kind of shields up. Get the hygiene right and make sure that your shields are up and stay up. And so we have a capability called application resilience, um, that we can use to monitor and make sure that all the different security management controls that you need to be deployed on that endpoint are always deployed, operational, running, and fully updated.
And so that kind of protects you against things that you, you, you don't yet know about. The third step in that is that if you, if you have the hygiene right, you have your shields up, now you're ready to start interacting with the world and, and moving data in and outta your organization. And so, uh, at that point, applying zero trust principles and doing that universally, um, a lot of times folks, when they think about Zero trust, they think about it as something that, well, I'm gonna apply that maybe when the user's remote and trying to connect, you know, into the organization.
But, uh, we're seeing that organizations that are more mature on that cycle are, are looking at, at zero Trust is something that need, need to be doing every user, every device, um, all the time, regardless of whether you're remote on premises, whether you're accessing internal resources or accessing externally. And one of the key parts of that is that a lot of times folks end up compromising between the policy they wanna apply and doing universal Z 10 A because the impact on user is too great. So one of the great things are secure access solution, which supports universal.
ZTA also, um, optimizes the experience of a user just from a connectivity, uh, perspective. Because if you have bad user experience when you're trying to apply your security policies and controls, you're creating this kind of, you know, tension between the two. So if you can get that part right, um, then you're really doing everything you, you, you possibly can on that sort of preventative side of things.
And then the last step is, uh, number four, you can still have the bad day. So you have to have a set of tools in your kit that are allow you to recover, uh, and bring yourself back to a fully operational and productive state, even if, uh, all of your attempts to prevent, um, you know, your best, uh, level attempts, uh, don't succeed. And I think that's the part where again, we're starting to see more focus, um, on that with folks understanding that being ready for that day is as critical as those first parts.
Well this is, uh, very, very interesting stuff, John. I know that you will be at black half of these announcements and you're also gonna be releasing a cyber resilience risk index for 2025. Um, I appreciate your time.
Thank you for being on, uh, Techron tv. Um, we wish you the, the best of luck and we look forward to the news that's coming out that has come out and, and what you care to share with us at Black Hat. Thanks Sean, really appreciate it.
We hope to see folks there and, uh, appreciate the time today. Welcome everyone to season two of Investing with the Boys. We are back powered by Futurum Equities here.
We got your boy Logical thesis. We got Stock savvy shy, also known as Shy. I don't know, maybe that's shy, who knows?
And you and host the shy, the shy, the Shy, the shy, and the third host, Sam, solid Sam bed. How are you guys doing? We, we have a lot to catch up on.
The last time we had one of these episodes was months ago during the tariff tantrum and now we're here back at all time highs again every single day all time high. We had big earnings this week. We're gonna do a little bit of recap what we have so far.
We had FOMC report, of course, unchanged rates, but a lot under the radar there. Lots to talk about. Guys, let's kick it off.
How's it going, Shai? It's going well. I mean, when was the last, what was the date of our last episode when season one ended?
It was, it pre is March. I think it's kind of crazy. It feels like a year ago, but, uh, yeah, it's only been a couple months.
That's what it's like in a Trump presidency. Uh, things are just up and down, but it's been great. Uh, I think we can all agree our portfolios are an all time high, uh, which is always a great sign.
And I think that's in the past couple months. I mean, I started a new role. I I made it across the walls.
I'm on the street, I'm on the institution side. I work at Futureum Equities with a great team and d uh, Dana Newman as a partner, learning a lot from him and the people we interacted with. Like just last week alone, I was in the ServiceNow in IBM, uh, room.
And that's something I would not think I would say a couple months ago. And other than that, yeah, things are, things are really looking great in the market. Uh, I feel like we keep having gut punches and we keep coming out stronger.
And that's something that proves the durability of this bull market where if it was flimsy, like I think that we probably would maintain a bear market, maybe test, uh, no multi-year lows, but we didn't. We v-shaped why is that? AI is still the main event and it's going to continue to do so there's gonna be a high flow in any kind of pullback.
There's gonna be a v-shape recovery type of behavior because knowing that we're in the earlier side than the later side of this AI theme, things are gonna be okay just because we're in that AI infrastructure spend that's going to be touching so many different sectors. And, uh, whether Powell, ems, it or not, we just came off from this FMC meeting where he was just teetering on like Dubbish. Um, are they gonna cut rates, increase rates, like he's playing, playing it right down the middle?
Uh, I don't think it matters 'cause we are fr like, doesn't matter if the Fed is gonna cut rates, the mar market's moving ahead of it, knowing it's coming regardless. So I think that we're in a good spot and now we have some seasonality weakness, but, uh, I wanna pass it to Sako 'cause I mean logical, uh, because I think he is probably the, i I wanna speak for Sam, but I think he's, he's two xing my performance this year. I don't know if he's two Xing your Sam, but he is killing it triple digits, right?
You're over a hundred percent year day. It's connecting me, Man. It's crazy.
Yeah, man, I just hit, I just hit a new all time high today, uh, feeling pretty good off the back of a couple really big earnings. I've been sizing my positions really well. I've been, you know, basically digging deep into that conviction and, you know, finding the names that I feel are mispriced right now.
And so yeah, it's been a great run. I think we got a very big, uh, opportunity with the tariff selloff. If you remember on the show months ago, we talked about how, look, if the economy is really gonna go into some tariff induced in, uh, recession, then we're gonna see a lot of these names in ad tech, et cetera, get hit the hardest, which they did.
Um, but if it turns out that the recession is really not gonna happen, then those are potentially gonna be some of the biggest winners in the market. And that's exactly what we've seen. You know, I've talked about mite a lot on this show.
That's been a huge winner for me. I still look forward to a couple other names in the space like PubMatic. Uh, we had that huge Google News, which I had discussed in the past.
I still think that is yet to be priced into some of these stocks. Uh, but you know, today I had, um, uh, lending Club is a name that I've talked about for a long time, you know, and a lot of these positions I'm sitting in, uh, with a good amount of calls to add leverage to my, uh, you know, exposure, uh, Tedy, which seemed like a kind of a dying giant up 20% today on earnings. Um, that one also in calls given, you know, the low iv, it just made sense, uh, to position to trade that way.
And, you know, the stock was getting constantly downgraded. Uh, meanwhile there was a lot of research out saying that they were the supplier for Amazon's robotics. And I think today we got some of that hints on the earnings call and the, and the stock went from plus 5% to plus 20%.
So, you know, I, I think there's a lot of sleepers in this market. And while, you know, the market's pushing all time highs, really we're just only a few percent above what we were at the pre tariff, uh, tantrum days. So, you know, the market's not as stretched as people wanna believe.
You know, they're anchoring to the lows. But if we didn't have the tariffs then, you know, we wouldn't really, um, you know, if we didn't have the tariffs and we didn't have the fall off, then we wouldn't be up so much. So I think people are just price anchoring to those lows rather than maybe price anchoring to before, uh, the sell off.
And so I think that this market still has legs. I think that we've seen that breadth hasn't truly participated. And I'm looking forward to the breadth expansion I'm looking for.
You know, there's a lot of opportunities that we look at and, you know, we just got some numbers from Microsoft Meta you guys were mentioning. They're up a lot after hours, uh, on really good earnings, which is fantastic for this market to ch along. Obviously the core there is, you know, AI compute, et cetera, which is fantastic.
Shai mentioned, you know, that's what's, you know, really driving this bull run. That's fantastic stuff and you know, it's gonna continue to fuel this market. That said, there's still a lot of froth in this market and we're still kind of getting through some of these momentum names, some of them losing momentum in the last couple weeks.
And so it would, it would be nice to see some of these more fundamental stories play out. There's still a lot of good relative valuations out there in the market, and that's where I'm focused. I have my fundamental hat on.
Uh, you know, I do put some credence to technicals a good amount. Uh, but right now I'm, I'm in my bottom fishing phase and I'm telling you, there's a lot of bottom fishing. I know we'll get into software at some point, but there's some mid-cap software trading for real cheap.
We've talked about it. Uh, you know, Sam and I, you know, are aligned on GitLab and a couple others. So, you know, we had that big news with Palo Alto Networks, uh, acquiring cyber.
Um, so you know, there's names like Okta out, they're still trading for really cheap. And so you know what's gonna happen when some of these mid-cap software names start to rerate closer to what I believe should be fair valuation. There's, there's a lot of opportunity in this market anyways, I've talked a lot.
Lemme pass it to Sam. Let us know what you've been up to, man. Uh, yeah, I mean for me, I think all three of us were just dumping loads of cash on the market in April.
That that was quite an opportunity. Getting a lot of names, a lot of companies at, I wouldn't say very compressed valuations, but some of them were pr pretty, were pretty low in terms of their median and average valuations. When we think about companies that were obviously set up for the AI narrative, they were one of the first ones to recover.
Uh, one of them was Palantir, of course had all time highs, probably a month and a half before the entire market did. On top of that, you also had meta basically leading the race for the max seven in addition to Netflix and of course Nvidia leading the wave. And then you had a lot of late bloomers come in there and just start to outperform as they had been laggers months before that you had a MD now getting close, I think it's above 180, probably one 90 after hours with the, uh, massive, massive, uh, cloud growth and probably heightened CapEx spend for a lot of these mega cap companies for Microsoft for meta and recorded this Wednesday.
So on Thursday we'd be getting numbers for Amazon, uh, to see what's happening with that. Google did raise their CapEx by $10 billion last week on their earnings. And that was great to see.
And a lot of these data center companies have really led the wave, the upward wave in the market momentum and they will continue to do so in my opinion. And data center expansion continues to re-accelerate. And on top of that, you also have the chip restriction or chip export restriction being lifted.
Uh, now Nvidia can sell the H 20 chips, which is basically an under or down, down clocked version of the, uh, B two hundreds and H two hundreds. And then you also have a MD, they could continue selling the MI 3 0 8 series chips to China as well. So you also have all of these large hyperscalers in China, which has the second largest number of gigawatt, aggregated number of, uh, gigawatt data centers in the entire world.
Of course, the US is number one, and then you also have Europe as well. But when you think about the amount of spend that's really going toward bringing compute as close to the consumer as possible, you also have other plays as well that are hitting all time highs, which I know HAI is a big fan of it as well. CloudFlare ha it was always known as the DNS protector grabbing about 20% of all the DNS traffic around the entire world.
And up to, I think it was about like 80% of the traffic does go through CloudFlare, but able to bring that compute closer to the clients and consumers using their edge computing. But now they're tapping into, they're also tapping into a cybersecurity TAM as well that has, I think now their tam probably was like a threefold after they started announcing that a couple years back. And it's sitting at basically near all time highs.
Not all time highs back from 2021, but at least 52 week highs, day after day valuations. I think we all can kind of agree they're getting a little stretched at this point. 01 or something percent last quarter.
And then on top of that, you also have the AI disinflation backdrop as well. As you continue to push out this more efficient technology, and as you continue to cut the headcount workers, you reduce the opex, you reduce the CapEx and the long term for these companies. But they're bringing all that forward today.
It's just showing the positive momentum in terms of how the country's gonna perform. Bringing jobs onshore, bringing a lot of manufacturing onshore. That's just gonna be the upper momentum for the entire economy, which helps the whole theme of paying down the debt at the beginning of the year.
And during Trump's nomination or during Trump's running, he was going for, Hey, let's cut the government spending and pay down our debt and increase tariffs. But then now that narrative has switched from paying down the debt to outgrowing the pace of the debt. And he is full force on this saving, what was it like $800 billion of taxes?
Sorry, $800 billion of debt. If we do decrease the rates by about 2%, if we continue these figures, we're gonna continue this Goldilock state. And I could see the market just continuing to push all time highs for a prolonged period of time.
Yeah. So I mean, Sam mentioned CloudFlare, that's a name that we've been talking about for a long time. And it's also been a kind of polarizing name because it's never been cheap.
It's been very expensive. And this, this is like one of the instances where my philosophy as a thematic investor caring all about Moat has played out where you guys hear me talking about the AI tsunami coming all the time, and it's coming for everyone, but especially coming for a lot of software companies, CloudFlare is, I wouldn't classify them as a software company. Like what's, uh, Sam was mentioning this was a CDN, now it's be essentially building, it's becoming the gatekeeper of the modern internet.
So I'll, I'll get back to why that is in a little. But they always had this monopoly where 20% of the internet essentially runs through their own network, like 20% of all websites that are used globally, think about that runs through them. That's something that protects them as a lifeboat from that AI tsunami that combined with a founder-led CEO, who I believe is one of the best out there when they, when you're thinking about wartime CEOs, when you think about carb musk, zuck, you have to think about Prince at CloudFlare and knowing that he can probably leverage the monopoly that they have in that internet presence as that CDN network to become that gatekeeper of the new modern internet.
'cause guess what guys? AI is changing everything for the whole world. It's going to change the internet.
You're gonna see browsers essentially become the distribution of all these LLM models you're already seeing firsthand right now with open ai, what they're doing, and that's also why people are throwing law of FUD on Google, is because the browser go browser's gonna change and that's gonna affect Google search. Uh, we're talking about Google probably another episode. 'cause right now we are just talking about the latest and greatest, and I think we gotta talk about Cloudflare's latest, um, product release that validates everything I'm saying right now where it was the crawler platform.
Correct me if I'm wrong, Sam if I'm misusing it, but I think it's, uh, this couple weeks ago they announced a pay per crawl feature or like a metering product where I think is a perfect example of how they're gonna position themselves in the new digital economy where if you're not unaware about this, LMS are going to be scraping and summarizing the internet. And that's what feeds into all these model qualities. Spoiler alert, we don't want that.
A lot of companies don't want that. So how do they protect themselves from that via the CloudFlare crawler? And essentially what this means is whenever these LMS try to scrape, uh, the information from the internet, the internet internet's gonna send them a bill, a k, CloudFlare, and they're not gonna be waiting for permission from all these bigger players like the open ais, philanthropics, Googles to do that because what do they have their own network and how much of that own network's being used in the world?
20%. That right there is a great example on why CloudFlare is leveraging their monopoly in order to capitalize on this AI wave. And it's something that I think it's going to allow them to compound it at 30% clip for a very long time.
It looks very expensive right now, but if you think about enterprise value as a whole, it's what, it's 70. What's your market cap right now? Uh, their market cap is around 70 billion.
That's still like, ugh, that's kind of pricey. It's at the Times sales. Hey, what's anthropics, uh, valuation?
Oh, it's 170. Uh, yeah, it's over a hundred. Yeah.
See, like I, I think there, there's an weird environment where valuation's taking a backseat, it's because a lot of these private companies are getting ridiculous valuations, but it's because they're proving themselves that they're going to belong in this new digital economy where nobody knows the ceiling on ai. It's gonna be one of those themes that has, is going to have an indefinite demand. And because of that, nobody knows what a ceiling's going to be and it could just be a ridiculous amount of money that's gonna be made.
And I think that if you're proving that you're gonna belong and thrive at $70 billion with a $10 trillion tam, it's signed to ai, it's pennies. And I think that that's why it's showing a lot of relative strength. And I think that's a classic example.
I wanted to bring that up because of when you have a monopoly and there's a supercycle going on, you can leverage your monopoly to catch the latest tide. And another good example actually, I I went over a lot, uh, ki what you think about that, Sam on, uh, the CloudFlare piece? Yeah, it was actually pretty interesting.
'cause I agree with you Matt Prince, CEO of CloudFlare is one of the greatest CEOs alive. I I really put him up there with a lot of other great CEOs like Frank Sluman, uh, bill McDermott, and obviously we have, I think it another great CEO is probably gonna end up being, um, Riha Swami with just how he's able to turn the ship around with, uh, snowflake. But, uh, a lot of his software companies out there have really good CEOs and they're very, I wouldn't say underappreciated.
When you look at the valuation of the company, you had an all-star CEO like Alex Karp basically he, he know, he knows how to market the company as well, but he knows how to land very big contracts with very recurring revenue, and that includes govern governmental revenue. And, uh, they also know how to attack the private side as well. Like they know how to really represent their company and make the company very relevant.
But also you have, uh, you also have Val lad 10 off from, uh, from Robinhood as well, amazing CEOs. And I feel like these companies need to have these really good CEOs that can be the face of the company and they're usually founder led too. If you, uh, you guys probably have noticed too, like usually the really good CEOs tend to be founder led and the us the companies that are really usually, usually are founder led also, if you think about, um, CrowdStrike as well, uh, you have the CEO there, founder and uh, chief executive officer of the company and director of the board leading the company, the general direction that he wanted.
And we were talking about also earlier, uh, logical brought it up with, uh, Nkechi, who's the CEO of Palo Alto recently announced that they're having a $25 billion acquisition of, uh, CyberArk. And a lot of people didn't really know what CyberArk was before this acquisition happened, but that's another sector of cyber cybersecurity in privilege access management, mostly with identity lockdown and, and protecting your credentials and certificates, whatever it is, this is all becoming very important in this entire AI wave. And when we think about the AI wave, it's not just about data center and comp compute, it's not just about software with data as well.
It's about protecting that data at all costs. 'cause with the amount of data that gets scraped on the worldwide web, uh, who knows, honestly, I'm just gonna assume that my information's already out there, but I don't have information that's tied to myself that costs billions and maybe even trillions of dollars. But these large enterprises do they need the best of breed protecting all of their data?
And that was something that was a narrative that, uh, that wasn't appreciated as much I would say in 2023 and beginning of 2024. And now it really is getting that appreciation, even though CloudFlare only did guide for about $4 billion this year, this fiscal year trading at, uh, about what is that like 19, 20 times their, uh, valuation in a forward ET NTM basis. I think it's rightfully so to have that kind of valuation.
My only thing is that, is this valuation gonna expand? Is my return on equity gonna be in a positive direction for some time? Well, you know what?
I think that as long as the market stays bullish, companies like this with leaders and with wide moats in their own industries expanding their tam as these era, as this era unfolds itself, I think that it'll probably continue expanding as long as we stay in this bullish market. 'cause leaders tend to lead the whole way and laggards tend to continue lagging unless there's some sort of narrative shift in terms of their inflection when it comes to their technology or their financials. And we've seen that happen, but the tide does raise a lot of boats.
When we think about CyberArk basically getting acquired and being a sector that's looked at for cybersecurity, that puts into question as well with Okta, which is something that logical, I know he's bullish on with a compressed valuation. Could this be a turnaround story for them as well? We've seen it happen many times.
A lot of companies, especially in the data sector, it's probably gonna happen in cybersecurity as well. What are your thoughts about that? Logical Look, I am a data scientist by trade, so I have studied, you know, computational mathematics, machine learning models, you know, all that kind of stuff.
Um, so I'm very well versed in the technology that we're talking about that's sweeping the world right now. And I can say pretty confidently that I think most people who are bearish on AI don't truly comprehend what's going on, don't understand the level at which it's being implemented today, the speed at which it's being implemented, like the most cutting edge technology that's being released is immediately being implemented because we already have that infrastructure today. com, it's like, dude, Amazon iPod in 2020 and, or sorry, 20 in, in 2000 or 1999.
I didn't order my first package until 19, uh, until 2012, right? So 13 years after the IPO today, you're getting, you know, chat GPT or anthropic and obviously the private equity mar market is popping more, uh, than the, uh, public equity markets in terms of some of these up and coming companies. But all of those companies, their LLMs are being implemented today immediately.
And so those are seeing efficiency gains at the corporate level at all of these large companies. And that's leading to efficiency gains. Um, it's gonna lead to sadly, uh, head, head a headcount reduction, and that's gonna basically flow right through to companies bottoms, line, bottom lines, and it's also going to increase, uh, revenues because, uh, you're able to develop products at a faster speed and get them to market quicker.
So all of a sudden you're able to, uh, offer better products quicker, which means that you can probably increase your pricing, you can outpace that inflation, so you're getting top line growth, you're getting, uh, operating expense, uh, reduction, that's a huge margin expansion opportunity. And so that also extends the runway of a lot of these companies. So I think, you know, I've been posing this question to myself and you know, as my followers of like one, you know, people keep trying to say, this is 2000, what if it's 1998?
What if it's 1996? What if it's 1994? Tough to say, and I would argue that we're not really at crazy bubbly valuations.
Sure, there are pockets of froth agree to all. I'm not a big fan of like pre-revenue companies and some of these sectors fine, but a lot of the companies that are leading AI are real businesses. They're making real impacts in other businesses today, like the Microsofts, the metas, the Amazons, et cetera, the the clouds, um, you know, these LLM companies that that's all reaching efficiencies today.
So forget about if it's 19 98, 96, whatever, you know, I would still say that right now we're not in the realm of bubbly valuations whatsoever. The runways of these revenues and growth is getting extended and the profits as well. So now I gotta ask myself, we develop technology today and implement it way faster than we did in the past.
What happens if the fundamentals outpace this bubble? Right? And so that's kind of what I'm thinking about is like, what if we never bubble?
Because it just ends up being, we just keep out, you know, implementing and outpacing and, and then new things come out and AI agents. And you know, I think the one thing is probably like that's a realistic fear, uh, on a societal level is what happens if we have too much head force, uh, or headcount, uh, workforce reduction, right? And so that's for sure something that's a little troubling.
But yeah, I mean, I think people underestimate the impact that AI is making today. Um, you know, maybe some of these applications are still not profitable or whatever, but I can tell you from a workflow standpoint, um, at many, uh, corporate jobs, it's speeding up the work that's going on. Um, you're able to develop something that used to take two weeks and two days.
Um, what else? I mean, I'm, I'm reading reports that first to third year law students or law associates are, you know, not needed as much because basically you can get better reports from a chat GPT, like, um, LLM, uh, than you would get from a, you know, first year associate in a week, right? You can do that in an hour basically.
So I think we talked about this on actually like probably one of our first episodes Shy where we talked about how like workforce reduces, you go from five engineers to two, but all of a sudden compute just goes to the moon and you're getting like, you know, queries are doubling and tripling, et cetera. So I I know you got some comments on that. Go for bro.
No, I think the PE first off we're so early. I think a lot of people realize there's multiple generations that they don't even use AI still, they don't realize they don't use chat gp, but let's ignore that. That's the easy low hanging fruit.
Let's talk specifics literally just 30 minutes ago as your numbers at 39% of year over year growth. That's mind-boggling at that scale. 3 billion alone this past quarter.
That's more than two x the previous record that Azure's ever done in his company history. I think this is the moment where AI's going to start being reflected in an aggressive pace for all these first stage winners, and it's going to result in a productivity boom like we've seen, we've never seen before. The logical is a data scientist, I'm sure now with ai, he's able to do five x the amount of stuff he was used to be able to before because, and now for his employer, there's a better ROI now for logical keeping him on, not just because he is got a charming smile, he is a genius, but he can actually do a lot more with that one seat count.
I mean, even, even things, sorry, just to even No, continue. Yeah, No, yeah, I mean, like there are things that maybe I'm not like the best power user of a specific software, like let's say Tableau or something like that. And I need to make some pretty complicated charts in terms of like, you know, these data visualizations for upper level management to like kind of monitor metrics, et cetera.
I can like develop these dashboards on the fly without being an expert myself, but just being, you know, co competent enough to be like, Hey, how do I do this? What's the best way to do this? And the solutions it comes up with are so elegant and so quick and efficient and it's like, wow, that probably would've taken me days, uh, without these tools just because like how would I do that?
That's so complicated. And it's like, oh, easy like this and no, yeah, sorry, go, It removes the trow and no, it removes the trow and error and that takes the lump sum of a lot of these kind of data analysis. And, and not even that, but like, let's even take it further like nowadays.
I mean, why would you even write code Yourself? Like, it's so ridiculous. And, and obviously there's companies like Cursor that literally do a lot of the code writing for you, which if you have the tools, like we're we're past the point, it's almost like think about like, you know, I was thinking about it, I was like, oh, well what happens to kids now who never learned coding and blah, blah blah.
And I was like, well dude, I don't know how electricity works, but I still use my lights at my house, right? So like, I don't need to know how everything works. I mean, I think to a certain extent it's good to know.
Um, but you don't really need to anymore if these tools exist. So if I need to like run a machine, like I have a data set and I need to run a machine learning model to determine like, hey, you know, I can just ask basically, hey, you know, write me some a Python script that will, you know, read in this data, clean it for me, um, try out, you know, do some K fold cross validation for several different classification models, compare the results of all these different models. Pick me the best one, you know, spit out the a z curve.
Well let, let All that, let me, let me pause you there. Do you use Mosaic and Databricks? Uh, I don't think I've used that yet.
We use a lot of, so Do you use, do, do you use Cortex and snowflake then, or what, what's your usual like I use Databricks nowadays. Uh, I've used Snowflake in the past, but, uh, I don't know. Okay, maybe I'm just not familiar with the words.
I'm not on the data data engineering side, but then again, uh, I don't know. Uh, lemme look it up. Oh yeah, No, no worries.
I mean, but Yeah, I also agree with that. I, I think there's gonna be a lot of a contraction when we think about headcount in multiple companies. We already saw a lot of the mega cap companies, including Microsoft, came out and said 40% of their code is really generated by ai, which I think it was like half a trillion dollars they're able to save, uh, in terms of headcount and operating efficiency just by that benefit.
And that, that this is like second year maybe, if you wanna say year three of chat GBT. Um, I, this is gonna last for a long time. If you think about the massive S-curve that people have been talking about with, uh, AI hype and so on, you know, Gartner's AI hype cycle, they expect it to be a huge hype into a runup and then kind of fall off a little bit there.
But the actual realization of the technology is gonna get better as it increases over time. I think it's actually a little bit different. 0 and whatever.
At a certain point they stopped talking about it because it was no longer relevant to, to say the clock and speed. This is actually something that Sam Almond was saying in a recent interview that he had, was that it's no longer relevant anymore. And at a certain point, hard dis usage was important at cer at a certain point, memory size was important and now it's come to the point where it's no longer about that.
It's no longer constraint on the actual compute. It's more of a constraint on the energy and the power that we're able to get to power. All of these new systems going to that are gonna be running basically at a hundred percent capacity until we come out with the newer generation.
And that newer line of compute that gets invented and created every single year is gonna be twice as good as the previous year, not linear exponential. We can think of the same thing with the stock market in that perspective. People thought valuations were egregious when they were trading at five or 10 times sales.
Now today we're seeing Palantir at a hundred times. Not saying that that's the norm or anything, but as long as we continue staying at a bull market, this can consistently, this can continue, this can continue on an exponential basis and think about the amount of money that's being printed around the world as far as possibly making cryptocurrency the stable coin of the entire world. If that happens, it's no longer about how much money you're printing, it's just about the expansion of valuation that people are pumping up these coins to the point where we no longer have to worry about dollars anymore.
It's more about whatever stable coin that we're using around the entire world, whether that's tether, whether that's, uh, USDC or so on. I don't wanna read the future of speculate into that, but there's a reason why the world is changing this quickly and at an exponential basis versus a linear basis because as a society as a whole, technology just gets that much better every single year. I mean, I know you guys got a lot to say about that, but I think that that, I think that wraps up great for our first episode of season two.
Uh, we're definitely have many more installments of this. We're in the midst of earning season right now. There's gonna be a lot more ahead still at the time we're recording this episode.
Amazon and Apple are gonna be reporting tomorrow at the market close. That's an additional $6 trillion of market cap being reported. I mean, who knows, maybe, uh, at this point I think Microsoft's gonna be head to head with Nvidia in terms of market cap.
NVIDIA's probably still ahead even though we got that 10% or was it like 7% increase on the, uh, Microsoft market cap? I mean, hey, what if Apple is up about 10% after hours? That might come pretty close, right?
So it's gonna be a very exciting week. Lots of new information to go through. I know for myself, and I know for you guys, earning season is just a really busy season, but it was great bringing this back to you guys with the boys.
We got logical, we have Shai and myself, Sam, great to see y'all guys and see you guys in the next one. Hello again, thanks for joining us on the next installment of the cloud Fridays with AWS, um, event that we are running. This is a breakout session and today we're gonna focus on maximizing your marketplace spend with AWS I'm Simon Briggs, a solutions architect at Red Hat, focused on the AWS partnership partner, and I'm here with my two great colleagues who will help us explore this topic.
Thanos, do you wanna introduce yourself? Good morning to everyone. I'm super excited to be here.
My name is Anos Ententes, uh, I'm a partner business development manager for Red Hat at AWS And Dolly. Hi everyone, I'm Oliver Reed, the cloud Marketplace sales leader for ea. Thanks a lot for joining us today.
So as described, what we'll do today is first of all, touch on the AWS marketplace and who would be better than to talk about that topic with you. Then our team member from AWS himself, Thanos. Uh, then I'll dig into some of the offerings that we have, uh, available to you from Red Hat on the AWS marketplace today.
Um, then, uh, Ollie will bring us home by talking about, uh, the solutions and why Red Hat really loves the marketplace. Over to you, Thanos Super. So, uh, as part of this, uh, red Hat Cloud Fridays today, I'm super excited, uh, to introduce you to a WS marketplace.
Really, I'd like to show you something exciting that can make your life easier when it comes to getting the software and services your business needs to serve your customers better. So, uh, let me start with the simple truth. Running a business today is complex on one side, you need to move fast.
Try new technologies, keep everything secure, and watch your budget all at the same time. It's like trying to build a plane while flying it. Facing a perfect storm of challenges and opportunities with new and cloud technologies, artificial intelligence, uh, machine learning, and an expanding developer ecosystem of solution, uh, there is a plethora of new possibilities for innovation, yet many business feel pushed to move quickly while still keeping things secure and costs under control.
On one side, there is an intense pressure to accelerate digital transformation and deploying new technologies quickly. On the other side, there is the reality of managing costs, maintaining security, and ensuring proper governance. We've seen, uh, mainstream enterprises often struggle with legacy contracts that cost too much or find it hard to check if new tools are safe to use, some try to build new customer experiences, but are getting held back by complex buying processes and tight budgets.
This is where AWS marketplace comes in. AWS marketplace can help you in this business race of serving your customers better, offering a solution that bridges the gap between innovation and control. AWS marketplace can help you solve these challenges and navigate the digital transformation journey more effectively to modernize your business and serve your customers better.
AWS uh, marketplace helps you find, buy, deploy, and manage the software, data, and professional services you need, allowing you to transform your software supply chain to foster digital growth and innovation. You can give your teams, your agile teams access to the new tools and products from AWS marketplace, sellers that they need to accelerate innovation while enabling, uh, procurement leaders to control purchasing, provisioning and budgets. In short, AWS marketplace can help you find the right products you need with a broad selection of products from different sellers.
It's really like having the world's best, uh, text store at your fingertips. Uh, you can access everything you need all in one place. And the best part, you can also get to read, uh, real customer reviews, product recommendations, and even try many of the products, uh, before you buy.
No more guessing if a tool is right for you. That's built right in with fast access to products from sellers and streamline the valuation, you can more quickly innovate to transform AWS marketplace. Streamlines procurement and deployment, allowing you to migrate and modernize faster with less effort.
You can accelerate migration with modern approaches to procurement, such as negotiating custom terms and pricing through AWS or using standardized contracts to speed up negotiations. With access to different deployment options and interoperability across AWS service consoles, you can quickly purchase and start using the products you need. With AWS marketplace, you can consolidate and optimize costs with flexible pricing options that allow you to ease into commitments and test out software before a long-term contract.
Keep track of all spending and get detailed insights at all times. Instead of dealing with dozens of different vendors and bills, everything goes into one bill, making it easier to manage your software budgets. This detailed visibility and pricing flexibility allows you to invest in what drives your business forward.
AWS marketplace enhances the governance and control as you are managing a growing cloud infrastructure and wanna minimize your risk exposure while adopting new products from, uh, from sellers. Have you ever, uh, seen how challenging it can be to get software approved from your security team? From we provide all the security information upfront.
We've also made, uh, security and compliance straightforward. Plus you can set up rules about who can buy what, so you maintain control while still moving quickly. Access security and compliance information directly in AWS marketplace to evaluate the security posture of the solutions faster.
We commissioned a study by Forrester to demonstrate how AWS marketplace can help accelerate time to value. The study found that customers who started using AWS marketplace experienced a 70% time saving in product discovery and 60% time savings. Uh, due to streamlined procurement customers also experienced a 30% faster time to market with streamlined deployment on AWS.
So now that I've shown you how AWS marketplace can drive tangible outcomes, lemme walk you through a WS marketplace in more detail, starting with finding products to drive innovation. We've invested in a broad community of AWS marketplace sellers to help you transform and modernize your organization. These sellers, including independent software vendors and channel partners at both speed and agility to customer transformations, because their solutions and services are built for the cloud in AWS marketplace, we can discover thousands of products and professional services from leading AWS marketplace sellers in one place.
Same as you can find Red Hat Solutions overall, with a breadth of software, data and services from sellers that span across over 70 categories, you can find the solutions to help drive innovation like millions of active subscribers have already done. You can find listings across key domains like artificial intelligence and machine learning and DevOps and over and observability. You can discover key business applications and industry offerings.
AWS marketplace includes thousands of software listings across specific industries such as healthcare and life sciences, financial services, energy and industrial and more. Or you can also navigate on a MI based server products, docker containers, data products and machine learning products, professional services, which include services to assess, migrate, support, manage, and even train others in how to use AWS services and products in AWS marketplace. And of course, we have softwares as a service products where sellers deploy software hosted on AWS infrastructure and they are responsible sharing the benefits to your, to you as customers starting May 1st, 2025.
AWS marketplace is also enabling all SaaS products regardless of where they are hosted to be and sold in AWS MA marketplace, making things even more simpler for you. Simpler with a wide product selection. AWS marketplace helps you narrow down your consideration set and evaluate whether a product meets your needs.
AWS marketplace for offers an AI powered, uh, comparisons features that allows you to compare similar SaaS products across key decision criteria, helping you find the product you need faster. You can also access, of course, customer reviews and product recommendations on popular product pages to help you guide through that decision. We can quickly conduct a proof of concept and get hands-on experience with three trials and free products to further simplify product evaluation.
And most importantly, for more informa information or pricing inquiries, you can connect the, uh, you can connect directly with sellers, request a demo or custom pricing, uh, from their existing product page. AWS marketplace allows you to find and buy the right solutions when and where you need them. You can access the full breadth of ca of the catalog in AWS marketplace itself on the web and find curated sets of solutions while you work in AWS service consoles that are integrated with AWS marketplace, like the Amazon Bedrock marketplace.
With buy, uh, with AWS feature, you can find and buy products directly available, uh, in AWS marketplace through the AWS partner websites like, for example, the Red Hat websites. Today AWS marketplace offers streamlined procurement and deployment that helps reduce the administrative burden of purchasing and launching products from sellers, allowing you to accelerate your cloud migration and start realizing benefits sooner. You can review the standard contract of AWS marketplace, uh, frequently called SCMP, uh, once and reduce the need to negotiate contracts for thousands of products that are also offered with the SCMP.
Instead of managing separate vendor relationship, you can onboard vendors to AWS marketplace using your existing AWS account. AWS marketplace has integrations with over 10 AWS service consoles allowing you to subscribe to seller products through AWS marketplace and quickly launch them using AWS service consults themselves and SaaS products are now bused as deployed on AWS. These are products that you, you can deploy directly and quickly on AWS and leverage the strong security posture and operation and excellence of AWS infrastructure.
While these may also qualify for additional AWS customer benefits to help you maintain existing procurement processes, AWS marketplace supports multiple ways to purchase, purchase a product directly from the AWS Marketplace catalog. Using the self-service option, you can negotiate custom pricing with the ISV through a private offer, or if you need you and if you have a preferred channel partner, you can continue to purchase products or professional services from your channel partners themselves. I've mentioned earlier consolidation and cost optimization.
AWS marketplace offers you detailed visibility into spend and pricing flexibility. You can centrally manage your AWS purchases, including AWS marketplace purchases from one dashboard where you can access and process invoices for your organization. AWS purchases with ease.
Separate AWS marketplace transactions from your AWS infrastructure, pos and allocate spend across different cost centers with purchase order management, making it easier to track and manage your transactions. You can access the Procurement Insights dashboards in the AWS Marketplace console to help you identify licensing consolidation opportunities and provide detailed visibility into spend and usage. And you can also spread out payments for your AWS marketplace purchases with financing, and choose from a wide variety of pricing models that give you more control over your spend overall.
AWS marketplace offers pricing flexibility to all customers. To get started, you can access free trials or bring your own license. To simplify migration of legacy software commitments to AWS, you can choose a usage based subscription.
So you only pay for what you use when you are ready. Set contract durations to meet your exact needs from early to multi-year contracts with many long-term contracts, offering discounts for commitment for high higher value purchases. Negotiate with sellers to secure preferred pricing and terms through private offers.
Agree on custom being frequency with your seller, using flexible payment scheduler, which enables you to have tailored payment schedules through private offers. The centralized management of AWS marketplace helps you enhance governance while you scale your cloud infrastructure. For starters, AWS marketplace manages the catalog and scans 24 7 for vulnerabilities allow you to purchase with confidence.
Vendor Insights allow you to access the security and compliance information of participating sellers in a unified dashboard, helping you evaluate and procure software that meets your industry standards to further scale your governance. Managed entitlements for AWS marketplace allows you to automate the distribution and activation of software entitlements across accounts in your AWS organization. Private marketplace lets you customize a catalog of pre-approved seller products that users in your organization can purchase, allowing your team to move fast while maintaining purchase control as from coming to a closing.
I already referred, uh, to the findings of this Forrester Consulting Total Economic Impact study before, but I just wanted to offer you the chance to download and read this at your own pace and discover the time and cost savings achieved when our organizations utilize AWS marketplace to find, try, buy, deploy, and manage software, data, and professional services from AWS marketplace. Ultimately, it's all about transforming your experience to enable your business to innovate with the software it needs. Before I hand it over to our, my colleagues, let me share one last thought.
AWS marketplace isn't just a catalog, it's a way to transform how your business meets customers demand, helping you move faster while staying secure and cost effective. So to let us know how to use the leading open source and hybrid enterprise trade solutions through a simplified buying experience with flexible billing as secure tailored usage, let me pass it on to Simon. With our new strategical collaboration agreement, we are significantly expanding availability of Red Hat offerings in AWS marketplace, accelerating cloud modernization through virtualization and ai.
Thank you for your time. And Simon, over to you. Thank you very much, Thanos.
That's a great description of why marketplace is so essential for AWS customers, but how does Red Hat meet that demand? Well, ultimately we make our software available. Thanos talked about different, um, capabilities or different listings that are available through AWS marketplace, and Red Hat has followed that logic.
We have made sure our software portfolio, when it is applicable to usage on a public cloud, is available for you via our marketplace. And you, you can rest assured that we have capability to deliver our key products such as Red Hat Enterprise Linux in different ways such as HA or built specific to AI or SAP application usage are available from this platform. We have middleware technologies at Red Hat such as JBoss, um, enterprise Application platform, um, which is available.
We also have automation tooling, which is very powerful in Ansible automation platform that can be purchased, um, via a managed service on this platform. But as you can see here, I've detailed those listings we have today that are, um, Amazon machine image listings, where as a customer you subscribe and then use a image of a server delivered by Red Hat and AWS to then consume your subscriptions or a SaaS listing, which is where a customer takes that, um, service and, and subscribes to that service, and then they can, um, grow that capability directly from the service as it's delivered. And you can see here that we've got the ability to also deliver Red Hat Enterprise xenex, um, virtually all the Red Hat subscriptions you might be interested in, such as Advanced Cluster Manager, advanced cluster security, satellite management.
All these subscriptions become available under this very flexible SaaS listing model. I'll also quickly call out, there is a special rail listing available, red Hat Enterprise Linux available, and that's for organizations that have found they've been using, um, open source, uh, derivative distributions of Linux based on Red Hat Enterprise Linux. But they're now in a situation where there's no longer support available such as customers who've been using CentOS operating system where customers have been doing.
So, red Hat recognizes that they, um, will often want to get full support as they would get from Red Hat Enterprise nux for those servers in a seamless lifecycle upgrade. And that's what that real extended lifecycle supports and third party Linux management listing allows our customers to do. They can take that, uh, derivative Linux distribution as long as it's RPM based and migrate that across to become a Red Hat Enterprise Linux version, and they will be able to then move forward with the standard rail lifecycle.
We have many managed services that I touched on earlier. Um, the key ones are Red Hat OpenShift service on AWS. So although through the a MI listings, you can buy OpenShift if you want to manage it yourself as an engineering operation that's perfectly, um, valid and available to you.
The roads are option is slightly different. That is where you commission Red Hat and AWS to jointly deliver that OpenShift service on your behalf. We have very similar services available for managed Ansible automation platform and Red Hat Advanced Cluster Cloud service as well.
Um, so those services are available to you on the marketplace today. But how do they look if you are searching for Red Hat software in AWS marketplace today from Europe, middle Eastern and Africa, what you will be looking for is all the Red Hat listings that carry the wording sold by Red Hat Limited. The listings that have this sold by Red Hat Limited are the ones that will be available to your EMEA based AWS accounts.
There is often some confusion with the fact that in North America you see something slightly different when it's a North American AWS account that is registered. They would be looking to subscribe to the Red Hat listings sold by Red Hat themselves is just a nuance of the fact that a slightly different operating business works in the EMEA region than the rest of the world. But sometimes customers have fallen foul of this and found they're trying to subscribe to the wrong listing from the wrong region.
Just so you're aware, also, you may come across some Red Hat Enterprise Linux list, Linux listings that are actually sold by AWS themselves. These are available through the marketplace, but they're actually sold as part of AWS's console EC2 services. So when a customer would like to buy this software, it's slightly different from the marketplace proposition that Thanos so eloquently described.
Thank you for your time. I'm now gonna pass over to Ollie who's gonna walk you through why customers great, get great value outta buying through this route. Thanks A lot Simon and Thanos for that brilliant introduction and for also talking about what the Red Hat products are that are available through the marketplace.
I'm gonna take a slightly different spin on it and talk about how you as a Red Hat and AWS customer can benefit from this and why it's important for both of us and our partnership together. So we are fully aware that customers love AWS. We know a lot of customers out there, including yourselves, have made a strategic choice to have AWS as your cloud platform.
So we are looking to provide that choice and that flexibility to you if you want to deploy your workloads, whether a mix of on-premise cloud, hybrid cloud, that we can support you on that journey in whatever phase you are at and also support that migration plan for you. So yes, it's a lot of the messages that fan has landed. It's streamlining your procurement, enabling your governance around how you manage that, but it's also about supporting you on that journey of having your deployment wherever it best suits you.
I think it's really important to call out as well that we use a co-sell program. So essentially that's between our, our team. So you've got, um, somebody to look after you as a customer from Red Hat and obviously the same equivalent from AWS, but behind the scenes it's all about aligning on where are you as a customer going, what are your objectives and your goals, and how can we ensure we're working in sync rather than selling you individual propositions.
So we find that really useful so that we turn up and talk about the things that are most important for you as a customer. And also I want to touch on pricing. So we're fully aware that when people were first, you know, experimenting with the cloud, using Pay as you go type models that yes give you the flexibility to turn on and off, but also then can come as a premium.
So initially I think when some of the customers were looking at, you know, how do we first deploy Rell, for example, so our our Linux platform, they potentially would've looked at a cost comparison between what are they procuring, either on-prem, um, or through, you know, direct resell or through a partner. Um, and that comparison might have seen a little bit out of sync. However, now with the introduction of marketplace and private offers, it no longer has to be the case that you could be paying more for that.
So if you go down the private offer route and you work with us, we can help support that continuity of pricing that you're used to and give you the same discounts you we getting. Um, and obviously then you get that second benefit of being able to decrement your committed spend with um, AWS. So what else can we do?
So buying through the marketplace also helps us with that continuity of support relationship. So that customer experience they're used to having with Red Hat directly, that can stay the same as it is, it can maintain that level of support that you get from us directly. So customers often see that as a benefit that they don't have to change their Red Hat experience.
And also it's really important to call out, there's funding and migration programs that support you. So you might be aware of mop, but if you are not, essentially that's a program that if you are doing your first private offer through the marketplace for Red Hat, you're entitled to either one or 2% of that funding back. And that's essentially free money for you in the form of AWS credits.
So paying for that infrastructure that you'll be running on, and obviously that's something we wanna call out for you to take benefit of. There's also map, which is essentially around the migration part. So sometimes one of the customer challenges is understanding, okay, we want to be on AWS but we appreciate there's a, a cost and a time and a services effort to get there.
So AWS have taken that away by providing the ability to leverage map funding, which can help you, whether that's with Red Hat, whether that's with your trusted partner, um, to essentially migrate those workloads onto AWS without having to face the cost that comes with that. So please do reach out if you want to know more about any of those programs. So there are multiple ways to buy, as I've mentioned.
Obviously you've still got the flexibility if you want to subscribe directly. So if you want the pay as you go, um, the ability to turn off on or off flex up and down as your requirements need it. Um, or if you are committed to the platform and you know that you're going to be keeping that on as a a constant workload, you can commit upfront for a discount.
However, we've also talked about today, obviously the marketplace and private offers and how they play a route. So there's three ways you can leverage that. You can either do it direct, so essentially that would mean through AWS directly or you can do it through a partner.
So that could be a trusted partner you already use or, or an alternative partner. Um, and then you've also got the ability to include a distributor in that transaction, which will still end up coming through your partner, but just multiple ways for you to leverage that without having to change partners that you might have that are providing trusted guidance and support and could be providing that services to help you migrate toward AWS. So again, just touching on the fact that's gonna help you leverage your committed spend, um, and maintain your relationship with Red Hat and the discounts you're used to.
So in summary, so we wanted to provide some useful resources and some potential next steps if you're liking what you hear today. So there's a variety of QR codes. Obviously you'll have access to the slides and the resources, but these are some things that might help you if you need to share with other colleagues internally that want to understand a little bit more about how does that work.
So that's gonna be covering topics like maximizing your cloud spend combined with obviously AWS and Red Hat, but also what does that look like in terms of marketplace. If you want an overview and you need to help explain some colleagues, we've got some short videos in there and some blogs that will help really get into how do we help you on that journey, why are our Red Hat solutions better on AWS marketplace and what solutions are available for you? But if you are early on in that journey, I'd just encourage you to reach out and because we're so in sync with our ecosystem in AWS, you can do that at any point.
You can do that through Red Hat directly, you can do that through AWS or you can do it for a trusted partner. And behind the scenes we'll be aligning to make sure that experience looks great for you. So do it at whatever entry point is best for you and we can help you shape what funding programs can you leverage, what migration support do you need, what's your phased approach and how can we help you ultimately satisfy your goals and your strategic commitment to AWS.
Next slide please. And I just wanted to call out a few extra upcoming sessions so you'll be aware. Obviously Simon called out earlier, that is part of our Cloud Fridays, um, in conjunction with AWS.
So that's gonna be covering obviously Marketplace, which you are in the session for now, but it's also gonna be covering Red Hat Enterprise Linux or Rail, um, Ansible, our IT automation platform, and also Rosa, our joy managed service for OpenShift, um, in combination with AWS. So thanks so much for your time, really appreciate it, and we'd love to hear from you and see how we can support you on that journey. Thanks very much.
Thank You all. Hey guys, thanks for the throw. We're here with Dr.
Tim Curry, who's CEO of Nova and author of a book called Swic Trust. And we're talking about, well, the trouble with remote computing these days because it may not just be a technical issue, it might be cultural. Dr.
Tim, welcome to the show. Thanks Mike. Great to be here.
We've seen this kinda rush where everybody said we're gonna work remotely and some people even move clear across the country. And now there's this whole push to bring everybody back in the office, at least in some organizations. And it seems to be that the leadership doesn't always believe that the folks who are working remotely are actually working.
What's going on here and, and, and how did we get to this situation? Yeah, it's a, it's a pervasive question that everyone seems to be talking about these days and uh, I don't know that there's really one simple answer to it, but, uh, a few things, uh, that I've seen both in my experience in the tech industry and in my research, um, is that the, the move, the, the sort of drastic remove, we all sort of got kicked off the limb during the pandemic and, and everybody started working remotely. And I think in many cases, people's, uh, people started to compartmentalize their work life in some cases, um, which isn't necessarily a bad thing, right?
Home life, family, you know, uh, your, your personal life are very important too, and should be. But, but some dynamics did change, right? And I think, you know, especially larger, larger, more traditional organizations struggled, I think to, you know, whether to get the productivity or the same results or provide a similar enriching work experience for their employees.
Um, smaller, more agile companies, uh, organizations dealt with it, I think a little better. 'cause a lot of them may have already been hybrid or, or used to being remote or cloud native already. But certainly the, the, the world changed very quickly.
And I think, uh, now people are trying to come to terms with, okay, do we come back to the office? Do we come back to the office? If we do, is it, is it all the time?
Is it hybrid? You know, what are the exceptions? Or do we at the other end of the spectrum, do we build and found completely remote organizations from the beginning?
One thing that's one thing that I think is true is that the, the, the answer to it isn't to have HR send out the same satisfaction survey from 2019 to find out what's going on. You know, it requires a new, a new method of engagement and thinking that I think a lot of these bigger organizations aren't, aren't coming around soon yet. Mm-hmm.
I feel like sometimes, and there's probably fault on both ends, right? Um, the remote worker might get disengaged and we haven't quite figured out how to keep them engaged. And I, that leads to management complaining that, well, I can't manage by walking around and make sure everybody's engaged in the mission at hand.
And, and they get frustrated. And, uh, logging, you know, keeping track of who's logging in on their keyboard isn't really a good metric in the first place. But, um, right.
How are there ways to keep people engaged who are working remotely? Because, well, you know, even people working in the office are working at home on projects and remotely too. Yeah.
Yeah. I mean, I think, so you bring up a very good word, engagement. Um, you know, there are different kinds of engagement, right?
Like the, the walking around and looking over the cubicle, uh, or, or the virtual version of that, right? If we're just looking at eyeballs and whether you're, whether you're online or not, uh, engagement is, is one of the number one, uh, activities or dynamics that came out of, uh, the research that I did, uh, on remote on a hundred percent remote organizations. And what I found was that authentic enga, what what had decreased with the move to remote work was authentic engagement.
And what had increased was task oriented, get the work done, very transactional type of engagement. So when you talk about what is it, what, what is it that we need to do? Um, it's, uh, leadership and management and to some cases peer to peer, they need to ensure that they are doing authentic engagement, both work related and non-work related.
Because if we're taking away all of the interpersonal relationships and all the interpersonal interaction that used to happen in an in-office environment, not that it all was perfect, good, bad or indifferent, there was a lot of ways to waste time walking around talking to the water cooler. But those things meant something, they were part of the fabric of how people developed organizational trust. It's how people developed identity and the place that they worked.
Um, and given the amount of time they, they spent in a given, in a given, um, workday, it was a big part of their wellbeing, um, over time. So what we found is that good leaders, uh, that, that where their remote employees felt like there was good leadership, they cared, they were, they were, they could be trusted, was when they engaged authentically, both in, meaning if it's task related or work related, they do what they say they're gonna do, they're transparent as they can be, and they deliver on, deliver on their promises, or they stay consistent to, to, to their talk track. But they also engaged in non non-work related channels, right?
The Taylor Swift channel or, you know, the sports team channel or you know, wherever you're sharing pictures of your kids. 'cause you don't have picture of your kids on the desk anymore for people to see, for you to reveal layers of yourself over time, they want to see you engage in those remote channels. And that was, that was a big part of, you know, engagement.
Meaning, I, I don't want, I don't need eng, I don't need micromanagement from you. That's not engagement. I need meaningful engagement.
Are you, are you helping me do my job better? Are you giving me the resources I need? Are you helping to drive the company that I'm rely reliance on, uh, for my, for my wellbeing and my livelihood?
And then, you know, are you human? Uh, do you engage with us in something that isn't just task related? So it's, it's, it's a lot of work for a leader though, uh, to, to, to work that way.
It's a very different mode, uh, from just like working the room, you know, walking the halls. Well, And I think you maybe come to the next big crux of the issue. I think, you know, there's a whole generations of managers who do not know how to manage remotely and therefore they just can't handle it.
So it's not really the fault of the employees, per se, for not being able to work remotely. They'll tell you they're doing just fine. Made me even happier than ever.
It seems that to have a generation of managers who don't know how to manage folks remotely, and, and I would po the fact that a lot of people were being managed remotely years, decades, even before COVID. So what's the problem with the management squad? Well, I, I think what you say is absolutely true.
And in fact, there's a, it's be, it's started to become a rather famous study that Microsoft did during the, uh, during the pandemic. Um, and 87%, I think it was across 250,000 employees, 87% of them said they were highly productive working remotely. 12% of management agreed that their employees were even productive working remotely.
So that's a huge perception gap. It's a huge trust gap. It's also a huge sort of operating like impedance mismatch on the, the organizational design, right?
And then this gets to your point, everything, yes, a lot of people worked remotely, especially those of us in the tech industry. We've all been remote for a good, a good portion of our careers, but hybrid. And there was always a, I would, I would argue that there was always a satellite office or headquarters or a regional place or uh, a briefing center where, where people worked every day and things got done.
And that's where the, the corporate culture was hatched and reinforced. But that being said, yes, there, there are a lot more people who never, surprisingly enough, there are a lot more people who never worked remotely and many more who never managed remotely. And I think, uh, I, I think that we are three dimensional animals.
And if my, if my success is dependent on a group of people that work for me, I'm gonna manage them in a particular way. Um, and I think my, this isn't based on any of the research I've done, but I suspect that you had a lot of managers that worked in places that had amazing cultures and were amazing brands where people thrived on being either there in the office or part of, you know, whatever, call it Google, Google or Amazon or Unicorns pit you pit. And though they, they might have had a very antiquated management style, they kind of had to operate within this, within this very, um, you know, very supportive, uh, very energetic, you know, kind of modern workplace.
And when that got pushed out into being more fully remote, they couldn't rely on that this sort of operating in this happy place. And all it was was really that them and their, them and their, and their directs and, and I think things got, things got a lot more tactical, things got a lot more task oriented, a lot more outcome based and maybe a little more transactional than it ever had been before. Once everyone's just on 10, 10 hours of zoom every day.
Uh, and, and you're seeing the effects of that. Like no one was ever retrained, you know, and, and they didn't, they didn't, they couldn't operate. They didn't have all the other, you know, sort of backstop to work, work, work within.
Yeah. But I'm not sure, like, just because people are showing up in an office that they're any more productive. And to your point about those cultures, they spend an inordinate amount of time going out for lunch and sitting around the water cooler BSing about, you know, what happened in the NFL Sunday.
And it's not always a hundred percent clear to me that being in the office is more productive than being remote. And it may just come down to the people. 'cause vice versa, being remote doesn't always mean you're more productive either.
'cause you as a person may get caught up on Gilligans Island every three o'clock in the afternoon. Hey, there's nothing wrong with Gilligans Island. Everybody needs, needs a break every now and then, right?
Escapism. Um, I I would say that all things being equal, yes. Uh, which is, I think I kind of feel like this is one of the biggest misleading statistics of remote work.
And again, I'm not saying, uh, we should all go back into the offices, right? I'm just saying that the world has changed and we haven't figured out the new operating system yet based on everything I'm seeing, right? Um, but if you think about, okay, so you take a per, let's say you get eight hours of, you get eight hours of somebody, right?
For a given workday, which is probably a stretch, uh, in some cases, uh, in the tech industry, you probably got a lot more than that on a given workday. Um, but there's still, there's, we are three dimensional beings and we are social animals. And so people are gonna find a, they're gonna find a replacement for the water cooler.
They're gonna find a replacement for talking about the NFL, you know, their, their fancy football outcomes. The, the, the difference is they're gonna do it where there's, where they're gonna do it in their home office when there's, there isn't any other of the, of, of the reinforcing infrastructure of being in the office with a bunch of other people that have a job to do. Right.
That rely on you to get things done. Um, and I would take it one step further, and that is, um, I was traveling and stayed at a friend's house, um, recently, you know, of course, you know, he's, I'm traveling. I'm actually, this is one was a great opportunity to actually go to see a customer who's actually in their office like, like in the before times.
Um, but I stayed with him and he's working remotely. He's on a Zoom. I, I happen to notice is he's on a Zoom with the camera off.
He's got something on the, he's got his phone and he is scrolling. And when I left, that's what he was doing. And when I got back, that's what he was doing.
And he is like, yeah, I just got done with 10 hours of Zoom. I'm like, yeah, you were probably on your, you know, you, you talk about like attention distraction now. I mean, you have to compete with so much just to have a meeting, right?
Because everybody's, I think that he's probably not that unusual in that, you know, whether it could be the kids or it could be the UPS guy, you know, and the dog barking. 'cause the UPS guy's at the front, I, I once had an employee, almost every meeting I had with him, something happened and his dog barked, right? Like, and that just becomes normalized, right?
It wasn't anything we would ever have have accepted, you know, years ago. But it becomes like, that's just, that's the work mode, right? It's a, so I think there are plenty of opportunities for us to get distracted in the remote world.
Uh, some of us are better than others and locking it down and focusing when we need to, um, and being productive. But I think, I think the danger is that many corporate cultures have reacted by just stacking, stacking. I had a meeting the other day that had four people on it and five AI note takers.
And I'm like, are we, are we productive? Are we, is this, is this what productivity looks like? I don't think so.
And I did what you did earlier. I kicked, I kicked the note takers out. I said, if you want to be in this meeting, be I, I've got a note taker.
Okay? So, you know, whatever. But, um, I, I, I think the whole productivity thing is kind of a misnomer because I think we're viewing it purely from a task oriented, task completion, you know, Gantt chart view of the world.
And I think that isn't what made Google and Amazon successful, right? Or the unicorns successful, or the disrupt or uber successful, right? It's, it's something that as at least for a very long time, resided inside of a corporate culture of innovation.
And I'm not sure how you get that. I, you know, there are certainly customers absolutely thriving in a hundred percent remote environment. I, I interviewed some of them and, and they're part of my research, but they weren't the bigger customers.
I weren't, they weren't the bigger organizations. They were usually very specialized groups who had known each other for years and can finish each other's sentences. They have a lot of trust and, you know, interpersonal stuff built up from the before times, right?
So, um, I, I think, I think that there is something lost. I don't know how to get it back. So the thing that you're describing as lost is what we might have referred to as esprit de corps back in the day.
Yeah. Yeah. And, And, and some execs will say that that manifests itself because, you know, cross departmental teams are not talking about the customer and having a conversation that sparks some great new idea because it's too hard to do remotely.
And that's a possibility. But at the other end of it, I would say that having worked in those office buildings, um, they go for four or five floors, and I might not have ever been on three of them. And so it's true.
So the level of it's true collaboration that exists there may be exaggerated as well. So to your point about needing a new operating system, which I don't disagree with, we need to, it seems like rethink how we're gonna create something that feels like esprit de core in a remote environment. And that's the challenge.
It is the challenge. It is the challenge. And, and it's certainly, uh, a combination of, it's a combination of recognizing, you know, each, maybe not each individual employee's positionality, but yet I think every organization has to ask themselves some hard, some hard questions.
Um, you know, this idea of swift trust just, uh, which we talked about earlier is, is something it's, it's not, it's not mine. It's a common research term, and it means a very transactional, provisional level of trust. It means I trust you to do the job I asked you to do.
Uh, you trust me to pay you if you do the job. And I interviewed some people that that's what they were looking for out of their workplace. And there might be a lot of workplaces that that's maybe all they're looking for outta their employees.
And that's okay, as long as everybody understands upfront that that's the, that's the arrangement. Remote workers can compartmentalize their workplace knowing that they're responsible for the outcomes. And employers can understand that.
That's a, that's a very transactional relationship. That's likely not to last very long. Um, but most of o overwhelmingly, most of the people I talked to wanted everything else.
They loved the autonomy of working remotely, um, and also wanted to be part of something special, wanted to have interpersonal relationships at work. They wanted all the things that they might've gotten, you know, in the past, um, you know, prior to the pandemic, one third of all, some, somewhere close to one third of all marriages originated in the workplace. You know, either with coworkers or friends of coworkers, or, you know, what have you.
Um, as we all know, that's drastically changed. Uh, it's shifting to, you know, online and dating apps and so on. Um, the, there's, there's a, there's a big piece there that's gonna be very hard to, you know, and maybe that'll never be the case again.
And that's okay. Um, but I think you've gotta have some combination of understanding that what people generally want from their workplace hasn't changed that much, even though the situation has, they still want to be part of something. They still wanna identify with something.
They still want interpersonal relationships that, that they can rely on and build over time. And that's what builds organizational trust. Organizational trust is what helps organizations through the hard times, the big pivot shifts the bad years.
Um, and there's, you know, if I segue into ai, like there's gonna be a lot of organizations that are disrupted by, um, by Gen AI and, and Agent ai and understanding, you know, how they still maintain what the, not just how they operate their organization, but how they reimagine what they need to do now. Um, and that organizational trust is the kind of the sinew that holds it all together. Mm-hmm.
I think to your point, there is no substitute for, uh, personal interaction. And that occurs face to face. But I also noticed in the age of remote work that we tended to stop inviting people into the office.
We didn't wanna fly them in 'cause that was cost, and managers didn't wanna go see the remote workers. So maybe part of this issue for building the esprit to corps is just, you know, old fashioned, get on a plane and go see somebody. I absolutely, um, almost everyone I talked to in my research said that, you know, that I had one, I had one person I talked to who had worked remotely a hundred percent for three years and never met anyone.
And they were fine. You know, it was, it was, you know, good days and bad days. And a lot of the things that I, you know, that we talked about, but one of their coworkers was going to a wedding that was six hours away, and, and she got in a car and drove six hours.
She was so desperate to see one of their cowork, one of her coworkers face to face, you know, and people want that. People need it. And they need to see that that leadership wants it too.
Um, the c ffo, the CFOs have not forgotten, right? Like, they're like, no, no, no, we, we got rid of all those expenses. It's like, okay, yes, but that was a reason we got rid of those expenses.
They have to, the world has to come back, come back. Um, I mean, think about it from a, from a, like, I'm, I've spent most of my career in the consulting world, consulting and sales. I mean, so little of what you do that what you used, what used to determine how well you did with a customer, how well what you delivered was how much time you spent on site in their environment, how well you got to know them, their organizational structure.
Like, I remember a time was like, if you could get someone on the softball team, oh, you knew you had, you had a good client, right? Because you, you knew what they needed. And you also had built, uh, a trusted relationship.
And, and you did that through going through authentic experiences together, right? If you, that doesn't ha that that doesn't happen as much anymore. It's really hard to have those, um, both in the sales role and in a consulting role.
So yeah, I think leadership has a huge responsibility to, to make it clear, you know, again, when and where they, they wanna make it happen. They have to make both the resources and the expense, uh, expense, uh, available. All right, well, folks, it's clear we need a new playbook.
And I spoke if you wanna run a company and everybody you want there to work is within two hours of a commute, that's possible. And you can make that work. But you might also not be making available the best talent you possibly can because there could be somebody sitting four states away who's actually the best at that particular task and anybody's seen, and you're never gonna hire them.
So think about it. Hey Tim, thanks for being on the chair. Great to be here, Mike.
Appreciate the conversation. All right. And back to you guys in the studio.
Hello and welcome to the latest edition of the techron AI Leadership Insight series. I'm your host, Mike Bazar. Today we're with KJ Kush, who's global field CTO for Wfme.
That's an unit of SAP that focuses on optimizing the end user experience with a framework they developed. And we're gonna be talking about that in the context of artificial intelligence. 'cause it's the age of AI agents.
Kj, welcome to the show. Thank you, Michael. So I'm not sure everybody watching this knows exactly what WalkMe is.
So maybe let's start at the beginning and describe what is this end user framework and how come we need it? Because well, we've been accessing applications for better or worse for years. Yeah.
Which is true, right? And if you think about it, everybody shows up with a large ecosystem with lots of applications. And what we've seen over the years is best intent on billing applications, users have to use it.
And that point of friction is where adoption comes in. So we did training and then we went to the application and used it WalkMe, combine those. So what we're really focused on is actually helping users navigate, adopt, and execute process.
What's interesting in the age of AI is how much AI is working its way into process. So our worlds are now combining AI with basically adoption of that technology. We are also on the cusp of the age of AI agents and SAP has juul, but there's a bunch of other ones that are out there.
How will AI agents kind of get streamlined into that user experience process? Because I don't think AI agents will be doing everything and somebody's gotta orchestrate these things. The one thing I could tell you about working with so many customers is they have a hybrid environment.
They use multiple technologies. And really AI needs to be orchestrated, not just enabled, just not just turned on per application. And that's what we're finding with the users because we focus on that.
So if somebody is guiding, and I'll, and I'll give you an example. Assistant to me has a system process. SAP wants you to use S four hana, SuccessFactors in a certain way.
Then my customers, everybody out there in the universe says, here's really my standard operating procedure. Here's how I go across eight applications to do that. And now I have a Gemini and I have a, you know, jewel all trying to tell users what to do.
But it's disconnecting more and more that what the user is trying to do by giving spurts of AI information. And so now when we look at where WalkMe is really sitting in a day in a life, it's more of orchestrating that ai. So we are right, unlike SAP focused on the SAP environment, right?
Or Watson on the IBM or Gemini in, in its own, is we look at it across all of those and not from the viewpoint of that application or right, or that, that ecosystem, it's really agnostic. And that's where we stand out. It's not being a competitor against those, it's being a force multiplier for those so that users can start orchestrating across them contextually based on where the user's at.
'cause ultimately companies just need to get work done. That's how they make money. So to your point, I might be using two different applications that have two different sets of agents, and I'm asking them to perform a task.
How will they negotiate with each other to divvy up that task and have that conversation amongst themselves and what happens when they get in an argument? Yeah. So I don't think it's necessarily going to be like two suggestions provided at one time.
And here's why I say that because truly, right? The underlying application knows its business object and its data. And it's going to say at this point, I'll just give an example, you're doing a purchase order, right?
And based on what I know from what you put in the value of say, this order in these line items, it's gonna suggest discounting. So nobody's going to argue with the discounting that comes from that core app. What's gonna truly happen for that user says, sounds great, except my internal company policy, right?
Might conflict with that. And so in their brain, not on the screen, there's a point of friction. And so what we see at WalkMe is we're watching and there's a long pause, and the next thing you know, there's a workaround.
They go look at their knowledge article and they come back. So now what you have to think about is how can WalkMe help? Well, right?
It, it is a matter of, now I need to integrate, right? This, this what I would call a rag. But it's really a point over to that customer's, right?
What I would call standard operating procedure to say, yes, this is correct or not. If I have to do, say shipping right inside of S four hana, how do I know it's written and regulatory of this country, this location, right? That call off to another source of information is literally should be sequenced correctly for the customer, which is why WalkMe is the right orchestrator for that.
Because what's happening is there is the system process combined with the customer's, right? What they call their user flow or their workflow. And then WalkMe combines those to sequence them and bring in the source.
So the decision point that's needed. So we're not gonna, right, if a user's not frustrated and they can follow the process and, and a JUUL or a Watson or anybody can do it, we're not gonna insert. But if we see frustration or we see slowdowns or cycle time, right?
We wanna start proactively prompting or prompting, right? Hey, I have an idea, or I see a frustration or I've seen on the screen you've gotten it wrong three times and it pops up the right source to answer that point of friction versus trying to reorchestrate the whole process. Mm-hmm.
Dual is orchestrating the process. We're literally facilitating the user workflow. Will there be more of these bottlenecks in the age of ai?
Because we will, I'll have say, my set of AI agents and I may have optimized that to, for example, sell something and we'll be engaging with customers who probably will have AI agents that are optimized to procure things. And these two things will have to kind of negotiate with each other. But one, I wanna surface something when they're just basically kind of grounding each other to a halt because they're so well optimized against each other that some human intervention may be required.
Yeah. And it's a great question. So I think, right, AI had this really high swing where everybody felt like it was very productive.
And then I, I know the whole entire AI community is now saying, yeah, but let's step back and ask, are we hallucinating? How valid is the source of data, right? And, and so what's interesting to me, the trend over the last probably three years is while at first we thought it was great, now customers are questioning it.
So I think what's gonna happen is companies are starting to become aware of the data results that come from ai. And so that is a point of friction. It's actually you're watching users slow down and question.
Now some AI sources the data, some doesn't, right? And even sourcing the data is interesting because, is it my company's right answer or is it the general from an LLM or a PLM or an industry LLM, right? And so what's truly happening is, I think friction points.
Like I think what's happening is people are gonna want that really fast cycle time that comes from ai and then they're gonna start looking at the visibility, the quality results of what they're doing is doing it, you know, 90 times faster, better than doing it 85 times with better quality. So is right, is the audit results of what's the audit results of machine learning AI versus humans. And how many times do I interject?
I suspect we're gonna see another bump, which is in this cycle of ai, which says, okay, I need to insert, I am seeing, you know, incorrect errors, I'm going to insert some ai, right? I'm going to see AI insert and the results come back wrong. And we're gonna see interjections of the right AI for the right moment.
And then maybe in three to four years it's gonna be smooth again. So I think we're gonna have a couple bumps when we think about, you know, what's the right data? How do I source it?
Is it frustrating the user? I think we're gonna have some, let's try this. Let's not, let's check the quality of data.
And over time companies will figure it out. That's how they're gonna get to the ROI for, for truly for ai, it can't just be fast. It has to be right.
You know, I'm old enough to remember good computer science and we used to separate the presentation layer from the outline code. And um, and somehow I feel like we got away from that over the years and we wound up customizing things and tying things too closely together. So are we now gonna revisit all that?
Because we're starting to understand that we need to separate the workflows and the presentations from the underlying code. I think you're correct, right? Because we, I'm, I'm old enough to say, right?
We had a couple apps and then we bought a whole lot of apps and then we said, oh, we gotta do apps consolidation, right? If I just have to say it's like for, like, it pretty much is like for like where, right? It may not be just the number of apps, but the user experience and as well tended as the best technologies can be.
If users have to use more than one application, and we know that's true most of the time, then we have to really start talking about that user experience layer. Can it really be controlled by individual, you know, companies like SAP or do I need to walk me to really drive that? And of course I'm at WalkMe.
So I believe we need that common experience because, you know, as well, I, I mean I've been a developer in my lifetime and I thought I did it right. Like, it, it, I think it was easier to say, I developed my technology, I'm good to go. And I never had to consider humans.
I think humans are the reason we have to start looking at that whole presentation layer, right? And does it truly need to be one app at a time or can I make it universal? And with ai, now we have this whole new debate.
Is it really a, you know, let's commonize the screen so that people can get through different screens. Or is AI now the common presentation layer? Can I have fact turn everything in the backend to just a database and everything can be ai.
Maybe it's just a matter of when, right? And what that experience is like and how are users really gonna become prompters instead of followers of applications mean We've built applications for so long, that's what we're doing. So I think there's a lot of human factors, education factors, training factors, right?
Is this for the young generation, not the new generation? Can I afford to do both in parallel? Um, I think people are gonna play around with all options.
Is there an opportunity to maybe consolidate a lot of these applications that we've had? And that's become a more pressing issue in my mind in the post COVID era. 'cause during COVID, we seem to go out and buy a SaaS app for every little workflow function we needed.
And we were just like, you know, maybe a little bit like drunken sailors, but we wanted to get things done and devil be damn what it costs. And now I walk around and I'll talk to people and they have hundreds of SaaS apps with overlapping workflows and stitching that all together has become somewhat problematic. So are we on the cusp of some other wave of consolidation and rethinking workflows?
I think we are. So let's just, just talk about, right, how data has changed that ecosystem. So for the most part, like in my history, I've bought a lot of software and the reason that I bought software is 'cause it served a niche, right?
It, it was my industry focus, it really drove my workflow. And instead of having one application where it did one thing well and, and nine things kind of well, right? We, we bought the big one, the, the Gartner leader, and then I bought nine ancillaries.
But now with ai, the way data and AI and machine learning is happening, I don't know that I need the application as much as I need the data and the smarts that I got from it. And then I can, I can bring it back to less applications. That's how I see tying it together.
If the data, the objects and the machine learning can give me the niche process I need to make my company unique, then I don't need the whole application, right? I just need what AI can produce from those right. Custom experiences and the reason I bought.
So absolutely. I also think, right with WalkMe, we're very fortunate that we have a tool called Discovery. And what we're seeing is, are people really using all of these applications we bought?
And what I mean using, I don't mean, right? There's a lot of discovery tools that can log in, say somebody used it and log back out. What I really care about is how they're using it.
Are they logging in? How long are they staying in? Right?
Are they doing five minutes of work and then logging out, right? Are they taking that work from that niche application back to a bigger application? Is this supposed to supplement or is it supposed to be standalone?
Right? And I think how people use all of those applications is driving the need to just, I don't need them anymore. Right?
You said you needed this, I'll just say a fancy project tool and in fact you're not doing anything different than the license we have over here, right? You're, you what you said you wanted it for, you're not actually using it for, I can tell, I can look at the screens and tell you you're not, it's going away, right? I think a lot of business cases never got traced and we don't use the reasons I bought 'em.
I think WalkMe's gonna help really downsize that ecosystem by saying here's what people really are doing, right? It's an answer we never had in the past. What's that one thing that you see organizations doing that just still makes you shake your head a little bit and goes, you know, folks, maybe we could be a little bit smarter.
So I think a lot of people are still heavily reliable on manual work. I'm really, really amazed, right? That, um, they haven't even used AI to automate manual tasks.
I, I look at like, and not in it, I think it users and back office can, but when I really look at what's business critical, like I am, I'm manufacturing, I have to get stuff out, right? Um, I'm surprised how much people are still documenting. They're still using, like even on their phone, right?
There's no AI on simple transactions. They're not even starting small on some of the business critical parts of their company. I'm like, that part of AI is safe.
I believe that data, that machine learning, like I can predict what a delivery code's gonna be. I can tell you how you're gonna have to pick and pack. They're still manually entering everything, right?
So I think I'm, I'm more amazed that people aren't starting small and then all of a sudden customers are getting this pressure and I, I look at customers, they're like, okay, now I need to solve world hunger with ai. And they haven't even done a tiny project. So the leaders started with tiny projects, right?
The the innovators and the thinkers. And now I think everybody thinks that's easy, right? And they're gonna take the lessons learned from those leaders.
And now, now all the followers are trying to do Big Bang. I think followers, people who are not natural innovators, um, also need to start small in this, in this space. Alright, well folks, you heard it here.
The user experience is changing and hopefully from the better in the age of ai. But you gotta take a minute to think about it 'cause it's just not naturally gonna happen without some actual effort and a plan. There you have it.
Hey kj, thanks for being on the show. Yeah, Great. All right.
Take care. And thank you all for watching the latest episode of the Techstrong AI leadership series. You can find this episode and others on our website.
We invite you to check all those out. Until then, we'll see you next time. Daniel, how You doing, my friend?
Yeah, good morning. This new flagship location is great. Been here a couple of times since it opened up Pat, and it's got that kind of, not only that new smell, but it really has that kind of new growing, exciting transformational company that is IBMI mean, we saw a few years ago, Arvin came in, said it's gonna be about hybrid cloud, it's gonna be about ai.
We're seeing it start to kind of, you know, transcend, transform this business, this industry. Uh, and it's been exciting. So it's good to be here.
And yes, pat, um, you are an old historic product guy. How are you Ross? I'm great, Patrick.
Thank you very much. Thanks for coming on the show again. Absolutely.
I'm excited to be here. A lot of, uh, innovation and effort by my team went over many years Yes. To get to this day.
And so that's why it's so exciting for all of us and what we're about to unveil for our clients for Sure. With Z 17. There's a lot happening.
But let's take a little walk down history, a walk down memory lane. You know, you've been here for several z launches now. Mainframe still are something like 70% of all the transactions, um, you know, in, in the, in the world right now.
Talk a little bit the history, the buildup to Z 17. Well, I, I'm not gonna go back all the way in history. Come On.
Come on, start with one. Kidding. We have an hour.
We have an hour. I just think that, you know, if you just look at the past five years, right? 15 and 16 here, the world has changed, right?
The pandemic changed things, but digital transformation is what really changed businesses and consumers, you know, I would say experiences, right? And now we've got AI on the scene and so we've just, we've been putting out mainframes that have really met our client's needs. They need super secure, super scalable transaction and data systems.
I mean, it's just that basic super secure being very important, right? Powerful, scalable, yeah. Able to take, you know, stock market spikes or black Fridays that occur on Thursday in the wrong month or whatever, right?
So the idea that we're building these systems to, to suit our customers needs, the banking needs, the insurance needs, retailers, airline reservation systems, governments, central banks. We've been meeting their needs. But what to me has really changed is this digital re revolution, this digital transformation, this driving up of transactions has really allowed the mainframe to flourish.
And now with ai, I think it's a real game changer. Yeah, I mean, I think we first met Z 14, Z 13, I, I forget the exact time. You know, sometimes, you know, you can, uh, 40, 50 years Ago manage, manage time with uh, z launches here.
But, um, at your investor day, you talked a lot about the design principles and the success of Z 16. And it is funny, you know, probably five, I mean actually not five years ago, there was always this, we're gonna replace the mainframe thing. Mm-hmm.
Okay. But can you talk about the design principles that go into it that really explains its longevity of, of, of value? You talked a little bit about, um, uh, two or three things, and maybe do the double click on that.
Sure. I I think that, so the basics are high performance at high scale, because these workloads are incredible. I mean, you think about a credit card company or a bank, bank payment system, they could be doing 20, 30, 40, 50,000 transactions per second.
It's a lot of people, right? You doing a lot, doing a lot of shopping or whatever they're doing right? But these transaction rates are real and are sustained.
We have many banks that do well over a billion transactions a day in 24 hours. So scalability and performance is key. What's the next thing?
Security. Keep the data secure. Keep the system secure.
Right? Right. Keep everything about it secure.
I mean, it's the country's economy flowing through our systems, not just our country, right? Many countries around the world, their economies are flowing through. Our systems have to keep it secure.
Those are like table stakes, high availability. I mean, things happen. There are power outages, there are natural disasters.
People make mistakes. I mean, all kinds of things happen. Systems have to keep running.
So high availability is key. What we've, what we've now moved into though in, in my sense is some of these illities, um, are really coming to the forefront. And so with the notion that AI has come out, that to me is creating this ability to take all this data that's captured through all this transaction processing and do things with it that couldn't be done before.
That's the difference. And I think Z 16, you mentioned investor day. I am glad you went to investor day.
I am glad that Arvin highlighted Z 16. Uh, it is the most successful program in, in IBM's history from a, from a mainframe point of view. Glad to be a part of that.
Glad that our clients were so thrilled that they're expanding their capabilities. And what's changed, I mean, the cloud's been around for more than a decade now, and as you said, people have been kind of writing off the mainframe for a couple decades now, right? And who would've thought that in the era of cloud, with cloud growing like this shouldn't mainframes just being disappearing?
Well, mainframe growth is phenomenal, right? Yeah. I mean it's, it's five x growth, right?
Is that's going on here. And it's, and it's ZOS workloads, it's Linux workloads that are growing again. So why our customers are highly intelligent, very big corporations that again, have to spend their shareholder money wisely.
It's because these systems are rock solid and they do fit for purpose computing like nothing else in terms of transaction processing and data. So we're building on all those principles. I talked to the ilities, as you like to call them, um, injecting AI now, and I know we're gonna talk a little bit more about that.
To me, that's been the game changer these past three years. We kind of surprised the world that we embedded an AI inference accelerator in the microprocessor. Sure.
And people are like, what are we gonna do with that? And then we said, well, here's what you can do with it. And now they're like, oh, I like that and I want a lot more.
Yeah. I'm, I'm gonna hit you up on that in just a second. Yeah.
I do wanna say having, you know, come to investor day. It was really good to see this highlighted. Both Pat and I have talked endlessly on after various earnings about just the significant contributions that Z make every quarter, especially during launch periods.
But one of the things that did change during the Z 16 was you created a bit more of a longer term scalable impact to revenue, where it wasn't kind of that big wave and then fall off, which has been, you know, transformational when you talk about a company, you know, has certain growth profile, certain profit profile, and of course, uh, the way your investors invest in the company. So that's been really, really good. Now, as you pivot to ai, you know, you sort of started teasing.
Pat and I are both, you know, we both love chips, so we love the fact that you're, you're doing something there. But again, in the end, it's, it's about the use. I mean, that's right.
We really take for granted, Ross, that um, this stuff just works all the time. I mean, when we go swipe our car to get put gas in the car to buy dinner or breakfast, whatever, it's, we just expect it to work behind the scenes. There's a lot going on there.
So where does AI sort of start to create new use cases and how are your clients sort of reacting to the power of the possibility of what you can do with Z 17? So let's just start with Z 16 quickly, because what they, what we put out there was we, when we launched Z 16, we had about 10 use cases, right? Our clients now have identified in, are using more than 250 use cases.
So we had a little bit of an idea of what clients could do. They adopted the technology. Why did we have sustained growth throughout the cycle?
And not just a bump like, like it used to be. There's a bump in the cycle. More demand, it's demand based, right?
It's growth based, right? It's for higher resilience and it's for more transactions and more clients around the world. So that's what's, that's been part of the difference here.
Now, as we get into 17 and the use cases, the use cases are all over the place in terms of from healthcare to, you know, banking and credit card fraud, right there, there's a very, very wide range of use cases. Our sweet spot is banking, which is, that's where, that's where our sweet spot is. Over 30% of the use cases are actually fraud.
When you say the word fraud, it's a short five letter word. There's hundreds of different types of fraud detection that needs to go into all the business processes within a bank, within a credit card processor, a payment processor, a claims adjudicator. And so it's these use cases for fraud detection and prevention that are saving banks now hundreds of millions of dollars, right?
That's across an industry. And so that to them was a big game changer. They could, they could go from doing partial fraud detection, um, and maybe catching, maybe catching mm-hmm.
A small percentage to doing a hundred percent of their transactions regardless of how high the transaction rate is. And doing a pretty good job of fraud. I mean, you know, getting maybe 85, 90, 90 5% of the fraud out of the system, letting those transactions run and just grabbing the ones, or most of the ones that they thought were fraudulent.
Now with Z 17, and we'll talk a little bit about the technology, but from a use case point of view, we're allowing something called multi-model AI to occur. So you can run multiple different types of models mm-hmm. Against a fraud case in a transaction and make that determination close that window to such a small point that, you know, something's fraudulent or you don't because it's that gray case in the middle Yeah.
That the banks are still toying with. So there's lots of use cases we pick on fraud just 'cause it's easy for everyone to understand. Yeah.
And again, there's a lot of demand for it. So really quickly, um, when you talk about these fraud detection and multiple models mm-hmm. You're, you're talking about something that happens in almost zero latency too.
And I think that's really important for everyone out there to understand is you're basically running multiple models against transactions so that, you know, that time that I accidentally clicked that wrong link and I give my debit card and make a payment on fake PayPal, it's able to quickly see that this is happening. And by the way, thousands, tens of thousands per se of these types of transactions are happening per second and have to be detected. That's pretty, pretty big.
I mean, So the, the news E 17 can do 450 billion inferences a day, one 50 billion. So you start, just do the math and break it down. A transaction takes four to six milliseconds, right?
So you have to do the full fraud and all the other processing might be multiple reads, could be multiple rights all within that transaction. So all of our AI inferencing has to go on within one millisecond to make that whole window. Oh, there's even legal, uh, requirements.
Yes, there are For that, that a lot of people just kind of paper, paper over and availability. Yes. Yeah, absolutely.
So I think the power of say taking, doing a machine learning inference for fraud and then backing it up with a large language model, right? And encoder, large mag model like Bert or something like, or Bert Large, or Roberta or one of those, one of those large language models and basically doing the fraud two different ways and then comparing the results. That's what the banks are looking for us Now, we've worked with a number of enterprises around the world that have guided the requirements that drove this into Z 17, and we've got over a hundred clients right now waiting for us to come out with this multi-model support Kind of getting at it.
But, uh, I want to ask about Z 17 in the context of, of cloud, and we talked about hybrid cloud and ai. Uh, I think when, you know, the, the, the most people in tech, right, when they think of, of a mainframe, they may not know its hybrid cloud, uh, capabilities and really how it fits into this overall, uh, uh, IBM strategy of hybrid cloud and ai. Can you do the double click on that for us?
I can try. So hybrid cloud means a couple different things. Let me just try to parse it up a little bit.
So if you're, lots of people think hybrid cloud means containerized system like Kubernetes and maybe Red Hat OpenShift, right? So you have a containerized based application development where the containers can be transported and run in different systems in different environments depending on the workload characteristics. Full player in an OpenShift world, right?
Sure. So the Z is a full player there. So some people, hybrid cloud means ensuring that you can share data between clouds.
So we've got a whole API strategy and APIs up and down the system software stack so that you can kick off transactions, you can gather data, and you can do it in a very high speed and efficient way. Mm-hmm. To connect with the cloud.
In fact, we've got six patterns that our clients use to connect with the hyperscalers make it very easy to connect with a hyperscaler to share data back and forth. So it's, it's kind of one big long processing engine if you would, mainframe and hyperscaler working together in unison. Then some people think hybrid cloud means application development and moving into a modern application DevOps environment with A-C-I-C-D pipeline.
All of that software is available for use on the mainframe where you can develop elsewhere and bring your applications in. All of that software is available. So, and then the final thing would be operations observability, right?
Right. Performance management done across the enterprise's. Full infrastructure, hyperscaler, public cloud, private cloud Z, cloud, right?
All those things together. We have that software as well. So we participate in the hybrid cloud at all levels.
And I, I went to those four kind of spaces, Patrick, because people say hybrid cloud and then their minds, they usually go to one of 'em. Listen, I'm glad you did replay in all of 'em. Yeah, I'm glad you did because it is the first, I usually caveat with here's my definition of it, what I mean, but I'm glad you expanded the definition to pretty much everybody's definition of hybrid cloud.
And I think it's still, uh, people are amazed that that Z runs Linux, it runs containers, and you can leverage a lot of the work that you've done throughout the enterprise, uh, with transportability that's right in there. And that, you know, by the way, that's my definition of hybrid cloud. So, uh, I'm glad you hit that first.
Yeah. It's really, it, it's interesting. When I started this, I kind of talked about how everything, and you know, how Arvin brought everything back to hybrid cloud and ai and it's great that you kind of explained that.
It's also really important to note that you've done all this with security in mind. And I think, you know, not to circle back to that 'cause you sort of, you know, you were sort of made that point earlier, but I think a lot of times when people start to go, oh, you're connecting your mainframe to the cloud, doesn't that sort of, you know, isn't that sort of breaking the whole purpose of the mainframe kind of, and, but there's been a lot of work that's gone into building the right encryptions that's to being able to move data to and from. So you, what you're really doing is you're creating a modern cloud environment in many ways.
Yes. That runs and has all the security and, and kind of, uh, scalability profiles that mainframe had. That's that which is, which is incredible.
And I mean that's why 70%, that's why people aren't moving off and that's why, what are they, those, those titles that they love to use in, in articles is something like the mainframe is dead long Live the mainframe. Exactly. We're in one of those moments.
Oh, I've seen some hyperscalers take a few runs at it to now They've all, they're all friends. They all face planted. It just doesn't Oh, I know.
It does not work. Like you can't move off of it. Ross, we got just a minute left.
Sure. You know, uh, thank you so much for spending the time and covering this with us. Um, just kind of a takeaway for everybody out in the audience right now is kind of what are the one or two things that you know, you really think, you know, they should be most excited about as they look to this opportunity to move and to upgrade and to, to buy advance and continue their partnership with ZII think the, the biggest thing is we, we mentioned machine learning and predictive ai, but, but on this mainframe there is also going to be generative AI for assistance and assistance running agents.
So think of chatbots the most, adv of the most advanced kind. So not only will we be doing on the mainframe with its security and its robustness, right? And its RAs traditional machine learning, but we'll be doing generative AI things like Watson Code Assistant Watson X code assistant for Z, or now the new Watson X Assistant.
A whole new way for a system program or system administrator to be able to deal with the mainframe, to be able to set it up through a fully modern interface. And, you know, the old system programmers like me, you know, gray hair, but especially for the new generation that wants to come in, that learns differently, wants to get on board in different ways than perhaps I did in the eighties. They want to do it in a much more online, ask questions, do things manner, um, they can do that.
So I think the power of AI in generative ai, again with, with with assistance and agents, is going to be fully unleashed. And we've got some specialized hardware now in the mainframe to enable that at performance scale and with security. Yeah.
Well, Ross, I wanna thank you so much for joining us. T-shirt on. Yes.
You know, I might tell 'em toot, I want, I want one of these. Yeah, We're gonna, we're gonna get one of these. I'll get you one.
You know silicon nerds, right? Yes. Hey, it's good.
Hardware's cool again. It is, it's great to be infrastructure infrastructure's cool. I Always thought it was, I always thought chefs were cool.
Just didn't get the rest of the industry to come, uh, come along Well. Well, you know, we called the semiconductors would eat the world. And here we are.
I know. Ross Moy, thank you so much for joining us. My pleasure.
Thank you Daniel. Thank you Patrick. Thanks.
And thank you everybody for tuning into this episode of the six Fives and of course all of the six five. We appreciate you being part of our community. We'll see you all later.
Hi everyone, and welcome to the six five Summit AI unleashed for this channel ecosystem spotlight. I'm joined by Dr. Kareem Yusef, SVP Ecosystems Strategic Partnerships and initiatives at IBM on powering AI transformation through ecosystem partnerships.
Welcome to the show, Kareem, Thank you ever so much for having me. I'm so excited to have this conversation because I think you've got such a unique perspective, not only within obviously IBM's ecosystem, but just from your experience, uh, running and leading products at IBM m as well. And so I'd love to just understand from you, at least from your perspective, what are the key drivers for enterprises turning to partners to implement all that ai, uh, is now bringing to bear the solutions and the outcomes that, that you are, uh, developing at IBM?
Well, I think if you think about how AI gets consumed, there's what I would call two main vectors. There's the actual implementation of an AI project, uh, typically embedded in some kind of business process that might lead one to then consider what I would call here AI platform tools, right? In our context that would be something like what's next orchestrate?
And you're building agents and the like and embedding them and integrating them with business processes. And then the other vector is you're just consuming software or technology that in itself embeds ai. Um, so I'll just use another IBM product just to give that for a context.
Think about something like IBM concert, which is all around, uh, application resiliency. It uses an AI engine to figure out what's going on with applications within the IT space. So you take those two vectors and you think about it from a partner perspective.
We have partners, what are called service partners who are doing work and implementation around these kind of platform AI platform technologies. And we also have partners who are building new solutions where they're embedding AI engines within them such that that AI is powering new capabilities that, uh, a client is then consuming. So that's really the two vectors in my mind of consumption, or at least the two major ones and how that kind of manifests.
Yeah, and I think there's gaps in AI readiness at the customer level, right? Or the end user level that that partners are uniquely positioned to solve, especially as everyone you know, is struggling with the fact that there isn't people out there with 10 years of ag agentic AI experience that they could go and hire, right? So, you know, the investments IBM is making to help the ecosystem be ready for these AI transitions and capabilities, uh, because customers are, uh, a little bit, uh, light on the capabilities internally.
Yeah, I think of kind of three kind of like primary threads you could pull there. Um, when you think about AI projects, this first world is the base statement of skill. So as you said, partners, the ecosystem, everybody getting skilled up and being able to provide skilled resources is important.
When you think about AI in and of itself, a big conversation is around data and data readiness. So there's a lot of focus with partners, um, working on the data problem. Is it data cleansing, data quality, data aggregation within data lakes, that kind of stuff.
That's obviously a, a big vector of work. And then of course you've got the AI applications or solutions themselves. And I think a particularly unique aspect to that that intrigues us a lot is all around being able to take partner created content and flow that into the solution context itself.
That's why in our world, we've uh, announced, as you well know a couple of weeks ago, our what's next kind of, uh, agent connect program where agents that partners are building can be carried within our Orchestrate catalog and linked into solutions. So yeah, you're right. That's just how partners find different ways to begin to engage and build through always starting with skills.
It can you walk us through a real w world, uh, AI use case where the collaboration between an ecosystem partner and a provider, um, really led to some good, I don't wanna say good demonstratable, ROII should say. Well, I mean a nice easy one to use. You'll hear us talk a lot about the realm of HR or the realm of, uh, procurement as, uh, great domains for looking for these kind of outcomes.
But the way I would baseline it is often what is the core outcome that folks are looking for? I would contend it's really all around productivity, right? It really is around efficiency in terms of execution of key processes and what therefore that speaks to how much work can get done with how many people, right?
So you can easily scale up and stuff. That's why you often find examples of AI projects sit in the realm of customer service, uh, or HR or procurement because they all respect critical business processes that could obviously benefit from this. But if I was to walk you through it, any one of these projects, uh, stick in the realm of, uh, HR or the involves a couple of systems, right?
You've got, um, the systems of engagement. Where is the actual work occurring from? Is it from a webpage?
Is it from your productivity tool of choice, your email inbox? You've got, um, systems of record read those as various HR systems, right? Um, whether it's employee systems, whether it's job hiring systems, and you've got what I would call the plethora of additional supporting data sources and environments that might be relevant to the process.
Think about, uh, hiring in HR and think about integrations with things like a LinkedIn, for example. So when you think about these processes, and I always like to use the word processes because you're really talking about steps of execution that are required to do real work. All real work involves a number of tasks coming together with decision points being made as you move from task to task.
And so these tasks typically span as I just illustrated, multiple systems. And so when you think about it from a partnering perspective, there's lots of integration points. There's the big partners who own some of these big endpoint systems and what are they doing around AI and what agents are they embedding within their systems?
And how might these agents interact with each other or interoperate? There's what data do you need to access, how do you connect to them and how do you bring and orchestrate this all within context? There's the clear understanding of the core professional themselves, the domain, what work are they trying to do, what brings value to that work?
Sometimes it's aiding the decision points. Sometimes it's rapidly automating a set of tasks so that they're done quicker, right? And allow them to move on to the next and the next.
And so that is really how I think about it when I bring it to life. Now for some of, um, those listening or watching at the moment, you'll find this kind of familiar, these are the discussions we had back in the days when we were talking about application integration, business process management, business process reengineering, business process automation. These are all still the same context of doing work.
It's why you hear us talk about putting AI to work, AI for business because it's really just taking these technologies and leveraging them to really allow us to evolve and advance key critical processes Because of that. Do you think that there's a opportunity for a new, and I know you're a big proponent of this, a new partner type or persona because of what you just walked through, right? It's a little systems integration, ISV, professional service systems integrator.
I mean, we could go on and on and on, right? Of the various ecosystem partners that you pay attention to from a persona standpoint, do you feel like there is a new partner type that may potentially become a, a offshoot of a current, you know, persona, a combination of one or two of them, or sort of net new? Think back to that kind of born in the cloud partner that popped up, right?
Wasn't someone who was a resale partner historically that now has sort of moved to the cloud. It was someone who just started a business from scratch, you know, a new partner who is agentic or AI driven and born from versus learning it, if you will, as part of their other business. Uh, the traditionalist in me would actually quantify that as I see instantiation of new partners coming from new backgrounds and emerging from existing and emerging and, and, and creating, you know, new, you know, conglomerates.
I don't know whether I really think about it as new partner types as in completely different archetypes. Because when you actually baseline it, the work becomes familiar and similar, right? But what I do think we're going to be seeing is the combination of these tasks within what might have been siloed partners, or I just do service systems integration.
No, they're gonna be actually acting as ISV partners or build partners as they generate these critical assets, these agents themselves, and try to repurpose and leverage these agents across multiple projects or encapsulate critical value that they can now begin to resell. I do see a kind of emerging of the, if you like, ISV from many more quarters than how you would've traditionally thought about it. So yes, I do see the service partner going in that direction.
I see the ISVs themselves beginning to really think much more deeply around what does an ecosystem look like, especially when you're talking about an ecosystem of interacting applications. If you like, I'll use the word applications here to reflect agents, right? It's typical sidebar conversation I was in this week.
When you think about integrating and APIs, right? We have all these notions of what we know how to call these various applications and you know, we've got this data structures and the stuff that we use, you know, the good old gopi IT stuff. When you think about interoperability within agents, it's not quite the same.
You actually are more actually probably talking to the agent more like you're talking to a human being because think about interacting with an LLM, the notion of prompts, right? Uh, it's actually kind of conversational set pieces. So what does implementing that in today's world look like?
And what does that mean for the kind of ecosystem you build? And as you said, the skills that make it up and how do we actually govern and ensure we understand what is happening in this kind of world where agents are speaking to other agents to leverage tools and trigger off. It's quite, um, I would say heady stuff.
Yeah. And I, I get all excited about it, right? Because I feel like for the ecosystem partners primarily, I always try to, uh, inspire them, if you will, or nudge them along to become client zero on their own.
Like how are they gonna deploy AgTech and some of these capabilities you were just outlining in their own business so that they can learn where those handoffs happen and the opportunities for them to maximize the return, the ROI and then even potentially what KPIs that they're using in their own business to say, are we doing better because of this? Right? Have we over complicated things, um, is it allowing us to scale faster?
Which I know you're a huge fan of the term scale. Mm-hmm. And so if, if, if a, if a partner, you know, um, is listening to this and is like, you know, yeah, I'm all in.
Where do you think you would suggest they start maybe on their own internal client zero journey so that they can start to become more familiar to how do they apply this to customers? I think it's really important to emphasize that point you just made. I fundamentally believe that you can participate meaningfully in the world of ag agentic AI without being a user of ag agentic AI yourself.
It's not like, you know, the the other days where you could master a tool but never really had to implement the tool within your own, um, enterprise or company or environment. It's just not the case. You are going to have to be a user.
And so back to your point of where do people start, right? Or a partner starting, I think there's some obvious entry points. Clearly in the world of software development or writing code, we're seeing a lot of adoption of AI assistance, right?
Code assistance of various ilks and, and forms. And so as a productivity boost, which by the way, I will be honest with you, when this journey began, I thought developers would be the ones to first push back and go, oh, no, I I'm crafting this code. What do you mean?
Uh, LLM or AI can help me with that? But they actually are some of the biggest adopters and embraces of the technology, especially in terms of the way it helps them take away some of the, what I would call the mundane and allow them to really fixate on the creativity that they're trying to do. Right?
And so clearly developers using ai, uh, tools to improve their productivity and efficiency is key and central. That's a great starting point. And many a partner, I would always encourage them if they've got like, you know, it stuff, that's an obvious one.
The other one I would add into then is back to your, what I call self-help, right? There's a reason why you hear people talk about Ask hr, employee self-service as an example, is one of the, what I would call lowest hanging fruits, right? For leveraging AI to have a meaningful impact.
And, and benefit. And I may have used this example with you before, but let me just pick on one very basic illustration of what kind of value can be given for which I have personally experienced as an employee. Um, the good old favorite, uh, employee verification, salary verification.
Now, in truth, I personally have not had to do salary verification for a very long time until my son college age needed to rent an apartment and I'm co-signing on an apartment. And so while I'm like, oh, I have to verify my employment and my salary, I mean, how do I even do this? Because of what we've implemented on our technology in IBMI literally just logged into the website, typed neither my employee verification, it asked me for who needed it, um, where else might I needed it.
It eventually generated the whole document, shipped it off to the realtor, put a copy in my own inbox, I'm talking about two minutes and make that two minutes me type in. This is the kind of productivity on lock where you just totally change how employees interact. So I just picked two there.
You know how your developers work with code assistant looking at employee, um, service, self-service, great places to start and get engaged with that technology. Yeah. And if I were to start a partner company, well, let me, let me say that differently.
If you were gonna start a partner company today, and then I'll tell you what I would do, but if you were gonna start a partner company today, what, knowing all, you know, right? Like if you're like Kareem's, you know, magical partner company, right? What would that look like?
Well, uh, I was gonna, I was gonna adjust and say it would be all properly, it all be built on ai, but um, obviously we all have our bias. My company would probably be going down the world of building and deploying agents that interoperate with each other. I mean, I'm a product guy at my core.
The notion of, you know, these agents and how they can interoperate and do meaningful work always sits close to my heart. So I'd probably be working on, on, on creating agentic content. I'd be signing up for the watsonx, uh, agent Connect partner program.
I'll be building agents on Orchestrate, and I'll be getting out there to embed them in business processes. That will probably be the direction I Kareem would go. Yeah.
And I, I would say sign me up, right? I agree. Because it's, you know, there's the next a hundred million or 50 million or 5 million, right?
Partner company, one person, not a hundred or not 50. Now, I, I, you know, I, I don't want people hearing me say, ah, we're, you know, it's not about people. No, it's about humans and technology, not human alone, not technology and designs.
How can you maximize individual productivity and impact using all we now have at our disposal? Like, I, I remember 15 years ago, I stood in front of, you know, back then, IBM still had much more hardware than it, than it has today. But if I was standing in a room full of hardware partners, and I'd be like, if you were gonna start a business today, how many of you would resell hardware?
It was interesting. Not many hands went up, but yet they were knee deep in it, right? But, but you know what they might do?
They might focus on solutions that integrated hardware. You know, my other favorite phrase of the moment is, um, uh, I call it storage with a purpose, right? You think about storage boxes, they, they don't just go hang out to store stuff.
They're doing it with a purpose. Is it backup and restore? Is it an AI workload environment?
Is it to support a data lake? And so you can begin to think, for example, of our hardware vendor could evolve themselves by just thinking about the purpose of some of that hardware to be more of a solution vendor. But I do wanna double click on your point about humans, because as someone who has been steeped in technology for a long time, and in particular in ai, in all its forms, I actually walk away with, you know, kind of always in awe of how amazing the human mind is, right?
Um, because people seem to forget that the creativity that one enables this stuff and then exploits this AI is actually human. And when you think about any major technology shift that has occurred in society, it is actually always, and go back whether you want the steam revolution, you know, you know, first time we did fire, you know, go industrial revolution. It's all given us the ability to be more creative and bring new and interesting value to the market.
So I actually think that this is about to unlock a next level sta change, right? In what we can do as individuals, as we leverage and embrace and collaborate with these technologies, which by the way, we create, they're not creating themselves. Absolutely.
And, and it's, if you could do anything, I mean, that sort of beginner's mind, if you will, right? Not the expert's mind of, uh, we've been here before, like you said, oh, this is not just a replication of what we've seen in transitions, maybe to the cloud from on-prem. You know, and this is not a normal, uh, transition.
Most definitely, in my opinion anyway, on the acceleration, how quickly things are happening. Like, we saw each other four weeks ago, what we talked about is almost not even relevant, right? Because it's moved so fast.
The, The models that were tough of the leaderboards four weeks ago are not the models today. So yes, you're right, Right? And so, so, so much partners can take advantage of, um, I if, if someone's listening and going, you know, I, well, I have reservation, or I'm a little hesitant, or maybe I'm a little nervous or afraid, right?
Uh, of what, what this transition means to me and my people and my teams and my organization, um, leaning in, I I always say start with the customer, to your point, like, what is the purpose? What is their outcome? What are they trying to solve for?
How can you do that in a more efficient way? Leveraging now all that, you know, AI and technology brings to bear. Mm-hmm.
I, I would agree with you. Look, and I, I think there's a reason why we've both been picking on that word efficient or productive. It's one vector.
Are there others? Probably. But it's a very tangible vector, and it's a good way to get focused on driving towards meaningful outcomes.
There is absolutely nothing to be afraid of in my mind there, there really isn't. But, you know, lack of fear or addressing your fear comes with familiarity. Get stuck in, right?
Play around with these tools, figure out how to use them collaboratively, right? To benefit, as you say, your own work, and then the work of what you're going to deliver for others. I think that's just core and, uh, essential to it.
These things often in my mind reduce themselves back to some pretty basic patterns. But I would echo your words. This is really an exciting and fast moving time, and I don't think we've actually figured out all the ways we're gonna leverage this stuff for real meaningful advantage.
We're, we're really at the early innings. W well said. And, and look, as we wrap up our time together, I'm gonna, I'm gonna end on two kind of rapid fire ones, if you don't mind.
But the first one is, uh, what's one misperception about, uh, AI ROI that you'd love to bust? Ooh, ai. ROII like to bust, um, misconception.
Oh geez. Now you caught me off guard on that one. I don't know what that call is.
A misconception. I think the thing that people do not understand about ai, ROI, is that it actually boils down to very meaningful, simple, um, metrics. Can you do something faster, better, quicker than you could before?
And so I think the misconception in my mind is people overcomplicate ar ROI, they rarely do, they overcomplicate it and they shouldn't. Alright, and the last one in one sentence, this might be hard, but in one sentence, what makes a great AI partner Knowledge, skill, domain and understanding That is just, I think that's great. Not a sentence, but three great words.
I love that, Kareem. Well, thank you so much for joining us for this channel ecosystem spotlight at the six five Summit. com slash summit.
More insights coming up next.