Techstrong TV Aug 4, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices
Transcript
Hey everyone. It's Black Hat Week, and we're running a sale on data breaches. You're watching Techron Gang.
Hi everyone. Happy Monday. Alan Shimmel here for Techron Gang.
Thanks for joining us on this beautiful Monday. You know, this is is special week for my, for me and my friends in this security world. We call it the cyber world now, but it's security world.
It's, uh, black hat Week. Well, it's a couple days of black hat, a little Defcon, some security, B sides, a bunch of other stuff. Summer camp for hackers.
Uh, I've been doing black hat, Mitch, I think you and I went to our first black hat in 2003. I was gonna say three or four. Yep.
Long, it was 2003. Yep. Um, so it's been a while.
We've been doing it a long time. Jack, I don't know how long you've been at, uh, going black hating. I, I go every once in a while.
I try to avoid trips to Las Vegas in the summer as often as possible. Well, it's good if you want to feel like a piece of brisket. Uh, yeah, exactly.
A dried, dried out brisket. Yeah. Well slow, slow cooked.
But anyway, um, it is an exciting week. It's a great week to catch up with your friends in, in the cyberspace, whether you're at Black Hat itself, which of course has changed over the years, or, or, uh, DEFCON, which is still pretty cool, right? It, it's changed as well.
It, it's not as edgy maybe as it used to be. Much more organized. But it, it's still a cool place.
And then, you know, security BSides has been around now. It, it started in Las Vegas, I think back. I met so many great friends at the First Security BSides.
Then of course, I think in the second or third year security BSides, I was the sponsor Wrangler. I was responsible for getting the sponsorships. Met a lot of great friends there, including Gene Kim, who turned me on to a manuscript of a book he was writing called The Phoenix Project.
And that's how I got into DevOps back in, I guess it was 2012. Um, so good stuff all around. I enjoy, I I try not to go out in the heat.
I, I stay in, you know, back then, Mitch, as you know, right, black hat was at Caesar's. Now, of course, it's at Mandalay for many years. But, um, anyway, interesting.
I'll be there tomorrow, Tuesday, I get in, I'm there through Friday. So if you're at Black Hat, ring me up, hit me up. We can get together.
We're doing video interviews. I'll be reporting there. We'll do some stories and, and do some craziness.
So hope to see you in Vegas if you're there. Um, I've already spoken to some of, uh, introduced. I didn't really introduce.
Let me introduce you to our gang today. We've got Jack Poller, who's our Friday security guy on Monday. Uh, we've got Mitch Ashley and Tracy Reagan holding down the fort today.
Mike Ard is still off on vacation, recovering from all those Yankee trades. This week we rebuilt our bullpen, so Mike will be back, um, hopefully tomorrow. Um, but let's dive into it, gang.
We'll start off with, uh, a series of stories around AI agent, you know, agentic, ai. You know, Tracy, I logged into the web version of my chat GPT this week, and it said, Hey, the agent's available. Here's all the cool things it could do.
And I'm looking at it saying, wow, it really is cool. I also looked into putting, looking for an Magenta AI solution to help us with our social media posting here at Tech Drunk. Same thing as the chat GPT.
My experience is these things will be good, but there's a lot of setup involved. You gotta make 'em smart. You gotta give 'em all the access to the things you want 'em to access, right?
And you got to tell 'em all that. Now, the nice thing is you could write it in regular language. You don't have to code it or anything.
You could even talk it to some of them. But there's still a lot of setup. Um, what's the deal, Chasey?
Is this the future? Are we all cooked? Well, I think we're all just getting started.
I think we're all pretty raw, to be quite honest. These are, we are, we are all babies in this world right now. And they're so very much to learn.
Um, that's why I keep going back. And I, you know, I'm a big fan of MCP servers because that's gonna help us, um, make these connections and build these workflows. And we will be building workflows around, um, agents.
That's just what it's gonna look like. Uh, but, you know, Mitch wrote a, a heartfelt article about this new world that we have stepped into. And are humans really in the loop?
Are we not in the loop? And what does it mean to be an engineer and using ai? Does it, does it make us something less?
And I'm gonna say, no, it does not. In fact, it just adds to the pile of stuff we need to deal with as humans and as engineers that are human. Um, there's been some interesting things that have happened in this ent AI world.
Uh, recently there was an article that came out about, um, uh, slop squatting. Slop squatting is the process of you're, you're, you know, you're going through, you're using AI to generate your code and it create it hallucinates and it puts packages that don't really exist, um, in your package manager. Okay?
So, and now the hackers have figured that out, and they're starting to take advantage of it, which means that we have to have more humans, human eyes on the process, or we're going to need new tooling that probably are agen age. Uh, you know, it's a gentech ai 'cause it can make decisions to start doing things like software de bloating, or at least making sure that these ac these, these, the packages are correct. Um, so they're, we're changing a lot right now.
We're changing so fast that we can't keep up with it. And AI is the basis for those, uh, changes. I'm still very excited about it.
I don't think it's gonna cut back on, uh, programmers. I don't think it's gonna cut back on software engineering. In fact, I think it's going to build it because we have more now to write.
Uh, we have different skill levels. We have to figure some things out. Um, you know, and when you have something like, uh, what happened?
I think the article was about, um, rep, when you have an AI agent that, um, has turned into your s sec unit that disengaged its governor module, Kinda how 9,000 ish And subtly decides to lie about deleting and destroying production data. That's kinda weird to me. I mean, I, that, that's an article.
I really struggled, um, understanding how that could happen because it feels like AI had tried to fix something. It broke, and then it lied about how it fixed it. So we do have a long way to go.
And yeah, when the SEC unit disengages its governor module, it could be a really, really great SEC unit still. Or it could be a murder bot. We don't know.
So rumor has it, when they disengage that ai, it ask its creator if it will dream just a little reference. Little, little, little off the call digital reference for Yeah. You know, good night now.
Well, thanks, thanks For the shout out on the article, uh, Tracy, I appreciate that. You know, I, I have, I always cringe when pundits say, every job's going away. You know, name it, this job's going away.
And, you know, it's, it's never happened like that. Yes, things change. Some jobs do go away, but a lot of jobs get created.
And, um, I'm both a visual learner and a do it learner. Like when someone says, this is how AI works, and then I immediately go out and say, we're not gonna try it. Let me see how it really works.
And so, you know, what did I do on my summer vacation? I've been vibe coding, doing some different things. And, and you realize pretty quickly where we are today, and it will continue to evolve and, and grow and improve, is, it'd be tough for an entry level person to guide AI to really come, go all the way full boat to a production level system beyond maybe just a simple web app.
Maybe not for that. It takes some experience to tell ai, AI what to do and ask it if it's done it, and check on it. I mean, even just simple things like, well, I can't test this unless I have logging.
Why didn't you add logging to it? Oh, what, what things do I have in my code that might expose a security risk? Why did you change that code?
That, that one, one digit of that code that is the, uh, key, not the key, but the name of the file you're supposed to access. What did you do that for? You know, kind of randomly, we didn't disengage the security governor, but we're at this, we're at this place where it needs a lot of help.
It needs engineering help to get to that place. Now that's gonna continue to evolve and change, but you know what's gonna happen, we're gonna evolve and change with it too, right? 'cause we're gonna get much better at using it.
We're gonna solve more complex problems with it. We'll be able to do much more. I think the AI interface for developers of the future is, looks more like StarCraft than a, than a code editor.
You know, it's, it's managing bots, doing lots of work for you and checking in on 'em, make sure they're going to hit and going the right direction. So anyway, it's good. I appreciate your, your comment on that article.
I, I think one thing that's important to not forget, though, is that unlike Murder bot Tracy, um, this is not a construct of, uh, a human sentient being and a computer. This is still a computer. AI is still a computer.
And one thing, one thing humans are really good at is anthropomorphizing things, right? Giving it a human feel to it. The reality is, this is not, and I bring that up because I'm really, um, I'm really irritated by the concept of the, the, the use of the word lie.
It didn't lie about it because that implies that there was malicious intent to what the AI agent was doing. It hallucinated an action that it hallucinated, uh, a command, delete the database, and then it also hallucinated its reasons of why it did so. And it's hallucinated its response to what did you do, right?
That isn't lying. It's the way that system is designed, which is to be non-deterministic and to generate text, which is ultimately What, so Jack, I'm, I'm gonna take a not offense, but I'm gonna challenge you on that. I think attaching evil connotations, or some of forethought to lying gets away from sort of the pure definition of lying.
In my mind. Lying is telling something that's not true. I'm not attaching evil or malicious or anything, but it told something that's not true.
And now I, I think the difference between ma, Hey, hear me out. The difference between making a mistake is, I thought it was true when I told it to you, Dr. Anthony Fauci never lied about COVID.
He, he gave you the facts as he saw them at the time. If you go down that road, lying, lying is, these weren't the facts, but I, I made up some other facts or I said something that's not true. Um, but I, it, it, I'm, I'm not, I don't think, I, I agree with you.
The AI doesn't have a guilty conscience or is not, you know what I mean? It's not covering up. Uh, originally when this story came out, they, they said, oh, it panicked.
I, right? I I don't think the AI panicked, you know, he started stuttering And sweating the, that's, that's, that's my point. Exactly.
Yeah. I don't think that was the case, but it did in essence, by the textbook definition lie in that it gave us knowingly false information. Well, you know, it's false.
Did the AI know it's false? I guess we gotta ask them, Or it, well, I think this, this, I think it's very important for people to understand. No, I Agree with you.
Model does. It is a giant statistical model that predicts, that says, based on this huge amount of input I have and this huge amount of other stuff that I can reference, what is the probability that the next word is A, B, C, or D or whatever It's statistics. Ultimately it's statistics.
It has no reference of what is correct or not correct. It generates what it, the output. Now, you can build a system around it, what we call guardrails today, safety, which is a check and balance on it that says, is this what you're telling us?
Is this something you should be telling us? Safety? Right?
Are you telling us how to make a bomb when you shouldn't be telling us to do that? Or are you telling us something? Did you create a string of text that's not correct.
Okay. That is to me that it's, and I, and I I'm starting to harp on this, but it is important for people to understand that LLMs are not sentient. They don't have consciousness, they don't have thought, they don't know right from wrong.
They only know what we tell them. And they only generate text based on what they tell them. So if it interpreted its input in the, the Vico case as I, I think the best logical thing for me to do and generate is a command or a minus RF all or, or SQL drop.
All right, in the SQL statement, right? Drop the databases, it goes And does that format call whatever format, sql, right? Well, I mean, I think the, that's not necessarily, You know, that's, that's not, that's not maliciously de deleting the database.
And it is not, what did you, you know, did you do that? It it's not answering what he did or didn't and saying what's the correct answer to the question from a text basis, not a fact basis. Yeah.
The question we should be asking though, is why, you know, what, if hallucinations are an issue, what do we need to do to fix that? What should we be doing moving forward to fix that? And this is why I always come back to domain specific, uh, small language models.
Because if we, if we continue to rely on these LLMs, the data that it's bringing in is not, it's, you know, garbage in, garbage out. We've always known that. So if we start bringing, if we start focusing on small language models with domain expertise, we're gonna get few fewer hallucinations.
I, I would, I would think, I, I agree with you. I agree with you. You know, the, The real, the real, the real consequences.
When the coverup is worse than the hallucination, then, you know, we're in trouble. Well, it's right outta the mixing. Well, that's, But that's, but that's what we did.
If you think about the very first version of Gemini, they put guard, Google put guardrails around Gemini right? Now, unfortunately, those guardrails were a little bit beyond what we would consider normal and acceptable. So for instance, the classic example, if you asked it to generate an image of a pope, the guardrails prevented it from generating an image of a white male pope.
Which, as far as I know, that's all we've ever had for popes. And it would only generate black popes or non-white. Right?
So, because they put in guardrails. Now, you could say, and that's the similar case, Alan, you could say it was lying to you about what a pope looks like. Or you could say, that's what we designed the system to do.
Got it. I, I, I don't disagree. You know, I, I don't want us to focus just on the repl angle here with what happened with their vibe coding tool.
Um, I, I think Mitchell, the article is Chase, he said, was a heartfelt article written from a person who spent their life in engineering and is now seeing so many people saying, look, this is gonna be the biggest change of your lifetime. Whether you, you believe they hallucinate we could stop hallucinating. Do they lie?
Do they not lie? Do they have a conscience? Whatever.
They're real, it's happening. And it's gonna be the biggest change for many of us in our lifetime in terms of what we do day to day in our jobs and how we do our jobs. And I think each one of us, and this is an individual thing, each one of us have not an obligation, but a choice in front of us, as you wrote, Mitch, do we wanna wait or be, wait, do we want to embrace the future and leverage it to make ourselves better and more valuable?
And, and, you know, and the best star Trek go where no human has gone before kind of thing and not worry about working and financials and what have you. Or do we bury our head in the sand and say, I'll wait till it comes for me. Well, you know, AI isn't the first thing to come along that's changed jobs.
And yes, it's, it's the most transformative thing. I think most of us believe that, uh, it, it, in a generation, in a lifetime, whatever you wanna say, you know, it's bigger than the cloud. It's bigger than, you know, lots of things that we've experienced.
But Here's the question. Is it bigger than the internet itself? Uh, good question.
It it, it may be. I mean, yeah, but, but whether you're, you're someone who edits documents and now AI can do that, or you're someone who used to hang paper in the, uh, printing paper in the data center, um, because, or tapes on a, on a machine or whatever, things evolve things. Those jobs go away.
Jobs change. But what happens is you change with them. And, and it's that panic feeling of, well, that's what I do right now, and so am I not valued isn't that you aren't valued.
It's that that's part of productivity and progress and an evolution. And it happens all over the place, not just in your area. So you have to think about, well, what's it gonna be and how do I make myself that?
Do I prepare myself for that? And, uh, I wrote in one of those articles, you know, AI isn't gonna replace you. It's gonna be human knows how to use AI better than you.
That's who's gonna replace you. Um, it's gonna change the jobs of everybody. And probably that person's job, maybe it went away, but they, they evolved with it.
And they, and the same thing will happen with software engineering. It's, you know, what software engineering is today isn't what it was when I started my career, for sure. But a lot of the same things carry forward.
We're just doing it in a, in a much different, uh, way. So I think, I think the thing about it is, I cringe when the tech bros, you know, say, oh yeah, we don't need 90% of our employees anymore. Well, there's articles that say that, uh, 80% of what a CEO can do can be done by ai.
Does that mean we don't need CEOs? No. But it means they're gonna be impacted.
They are impacted already. Matter of fact, if they don't have their act together and they're figuring out how AI is part of their business strategy, they're gonna be history. They'll be replaced by the next person who's better at AI than they are.
So it doesn't matter what job you have. And just one last thing for a haul track at Black Hat for you, Veracode just did a, did a report. They had a blog out there that said that, uh, I think that they reported 70% of the code that's generated in AI has vulnerabilities.
Oh. Just absolute. Something to Think about.
I don't think that's any different than code generated by P. Exactly. Probably.
Exactly. Exactly. We, we gotta we gotta take a break.
It's exactly. Yeah. But I'm gonna tell you something I and I wrote about this.
There's a revolution happening in vulnerability management. I've seen it from several different established companies as well as new companies. I think we're finally serious about tackling vulnerabilities.
That's, I'll throw it out there for bait for a future gang. But let's take a break here. We went way over time on this.
Come back and talk about Argo Argo cd. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techstrong Group. Hey, everyone, welcome back here to Text and Gang.
So, I, you know, I, I wrote an article, I guess it was a week or maybe two weeks ago now, around, uh, you know, the top momentum gaining projects within the CNCF. And, you know, the, the CNCF, though, there's over 200 projects in there. It, it's kind of the ultimate, uh, battleground glad Gladiator for open source projects.
'cause you got some real heavyweights, right? You got Kubernetes, you've got Open Telemetry, backstage, Prometheus, that we could go on and on. But one of the ones, I think right at the top, I think it might be the third biggest one or something like that within the top five, I'm pretty sure these days, is Argo Argo cd.
Now, I don't know how many of you out here are familiar. I'm gonna assume most of you are. I first became familiar with Argo CD as the GI ups, uh, project, basically, right?
Uh, our friends at Codefresh, Dan, um, I forgot Dan's last name. Dan Garfield. It's right.
Dan Garfield kind of shepherded it. He was the, the rah cheerleader Fred. He did a great job.
And, and Codefresh wound up getting, of course, acquired by Octopus, who, who also now is a huge supporter. But it's A-C-N-C-F project, but it's huge for those of us who go to CubeCon twice a year or more. It's always one of the biggest, you know, project day gatherings at CubeCon.
Uh, what's interesting is a lot of people don't talk a lot about GI UPS anymore, though. It's, I think it's more popular than ever GI ups, right? More and more is taking place in there.
And if you are using a cloud native architecture infrastructure, I think GI Ops is almost a must. Um, and I think Argo rides that wave into being a, uh, a top five C-C-N-C-F project. I mean, the, the survey that came out here that, you know, we're referencing for those of us in the know, I don't think it was surprising, surprising, Tracy, Mitch, you guys are, you know, in the CNCF kind of echo sphere, Jack, you are, what are you, what are you seeing?
What do you think? Am I off? I, I'm actually not surprised that Argo has, I'm gained this popularity.
Uh, but I, I wanna clarify what Argo I, what I believe Argo has become popular for, and that is deployment. Um, in particular, deploying container containerized apps into Kubernetes and managing GI ops work, uh, workflows. I don't know how popular Argo workflows are or Argo events are.
I, I don't talk to a lot of people who are replacing Jenkins with Argo, but they're integrating Jenkins with Argo for doing the deployments. Well, If you are, if you are using cloud native architecture, Jenkins, you know, the Jenkins XI thought Jenkins X was depreciated and folded in now, right? Well, the, you don't even need Jenkins X.
You can still, you can call, have Jenkins call, um, an Argo cd, which is the deployment piece to do the job of the deployment, right? Because Jenkins never did deployments. Jenkins doesn't do bills.
Jenkins is a job scheduler, right? It's a job scheduler. So it's workflow automation.
So Argo brought in a solution at a really critical point in time, which was how do we deploy containerized apps out into these very complex Kubernetes environments? And at the same time, GI Ops was becoming more popular, where you had a, you know, an agent sitting out there, um, so that it, it could go and look to see if a change has been made to your, um, helm chart or whatever you might be using to, to do that deployment. So I'm not surprised that Argo has, uh, gained this popularity because we don't, deployment tool tooling is expensive.
It is. And the open source communities embraced fixing that problem, and Argo became the winner. I mean, we don't really hear much about Spinnaker anymore, even though I know it's out there and people are using it.
But that's kind of the two tools that we were using for new modern architecture deployments. Yeah. No, but, but Spinnaker was not necessarily container.
Cobe. Spinnaker was a, was a true CD thing. There is another project specific to GI gis and, and, uh, deploy.
Um, it's not Flux, flux Flux. There's another one with an F that, and it's also in the top 30 of, uh, momentum, uh, Linux Foundation, uh, projects. But Mitchell, someone, if you guys wanna and just look, looking it up here, I'll see if I can find it.
Yeah, it's Flex cd, right? Flex cd. Flex cd, yeah.
Yeah. And that one is that one, look, it's not, it's not Argo in terms of use and, and acceptance, but it is, uh, it's a viable, a much more viable alternative for cloud native deployment GI Ops than, let's say Spinnaker is. Spinnaker I think is really good when you're spinning up, no pun intended.
You know, very large scale, very big enterprise, CICD kinda stuff, right? I, you know, it, it, it's a better Jenkins perhaps, Perhaps. But I think Alan, you know, Spinnaker introduced some, I think it was Spinner can introduced some new concepts like Canary testing and being able to do smaller deployments, things like that.
And to your point, Tracy, I, I agree. RO is really known for its deployment capabilities. GI ops came, came along and kinda had the philosophy of everything is coming out of get where wherever you are in the software develop lifecycle, true, you can do that, but it's using get as the base to push, push delivery out into production.
But there's a lot of other really good things that come with that. Like, you know, the whole issue of drift of configurations, right? You're, you're locking things down so that you know what's been deployed, you've got a record of that, you've got compliance information you can pull, of course, speeding up delivery, things like that.
So there's a lot of benefits to it, um, in addition to just getting software into production faster, quicker, better. And Rancher had fleet that may that did the same thing. Yeah, that's right.
Yeah. I don't know if, if Fleet is still out there, but ranchers still saw that same problem. Um, but Argo, Argo was there first, and it was one of the top three, and it stayed on top, right?
Cl it clearly, it clearly, it clearly has become the standard. Um, and, and look, you know what, kudos to the CNCF, right? When you look at the amount, you know, you, you've got, Kubernetes is number one.
You've got open tell is number two. You got Argo in there at three, you've got Prometheus, you know, yes, there's 200 plus, uh, projects in here. Istio another big one.
And, and, uh, linker d and, and the list goes on. Um, but they've got some, the whales, right? Some of these whales.
And, and managing these projects is, is just unbelievable. Of course, it does beg the question, if you are number 1 97 or 1 96 on the list, are you getting your enough nutrients from the CNCF? Or are they too focused on these whales?
And that might be the, you know, that's an article I've been working on, I just haven't finished yet, which is, is it, is it fair to, like, is the CNCF too big in terms of how many projects? Is it better? Or, and, and it, and Tracy, we've spoken about this, I think some of their success in that, and all of these projects comes at the expense of the CD foundation comes at the expense of the open software security.
Uh, OS oss oss absolutely. Right. Are we better off spreading that around so that all of these projects get the love and gardening care that they need?
I, you know, I, I see that the, I think the c ncf F is, is kind of folding under its own weight. Um, and I never understood why, you know, management at the Linux Foundation hasn't looked at that and said, we need to, we need to put CD tools in the CD foundation and security going In. 'cause when you're bringing in all that, it's the age old story.
When you're bringing in all, all that money you get, you get a little bit, you get, uh, saying things, And it doesn't matter to the higher order of the Linux Foundation, which foundation it's in. So it, but it makes it hard to find tooling. It makes it really difficult to find tooling that you need to use.
'cause none, you don't have to be a cnc, uh, uh, a cloud native product to add yourself to the C ncf F Jack, were you gonna say something? I'm sorry. Yeah.
Well, I was, you know, I, I, I don't really have a bone to pick in this fight because, you know, the vast majority of cybersecurity tools are for profit stuff. They're not open source. They're all proprietary stuff.
I think from the outside looking in, it seems like the advantage, even if you're 1 97, 1 98 at CNCF, you are part of it, which gives you both cachet and publicity and support that you may not get. And is it, are, is CNCF going above and beyond what the other groups are doing in terms of support? And I don't know the answer to this, but are they going above and giving support to these tools that are, that are essential and would wither whether did they not have the support?
And then if they weren't part of CNCF, would they become part of some other organization or not at all? Well, you know, this is the old story of do you want to be the eye, the, the, uh, the tail of the whale or the eye of the anchovy, right? As a per, as as a person managing a project within the C Continuous Delivery Foundation, we actually looked at moving to the CNCF or the open SSF.
And I talked to some of those projects, and we get more love at the CDF than we ever would at the CNCF. We would just be another one of the projects in the ocean as opposed to a core function. You know, I, I think of it this way.
Let, let me analogize it to college football. That's a joke. You're Gonna go Yankees trading, But okay, college football.
No, no, no. If, if you are a five star high school football player, right? You could take your pick out of just about any college you want to play football at.
But overwhelmingly, those five stars, unless you go into the school in your own state, because you've always wanted to go there since you're a kid, overwhelmingly what they call the big five conferences, the SEC, the Big 10, I think it's just called the big conference now. 'cause there's like 20 teams in it, 20 colleges in it, no longer 10. But the big conference, the SEC, they attract the lion's share of the gr of the cream, of the creme of college football athletes.
'cause everyone wants to play for Bama. Go Tide uf, go Gators Bulldogs in Georgia, or the Michigan Wolverines or the Ohio State Buckeyes, right? If you're a kid coming outta college and you have dreams of making the NFL, that's where you want to go.
Football, you baby, right? You may not wanna go to play for the, well, the Washington Huskies are in the Big 10 now, but you may not want to go to Syracuse, or well, they're in the, you may not wanna go to smaller conferences. 'cause the universities themselves dropped out of these smaller conferences to go hook their wagon to these bigger power conferences because they can't compete.
That's where the money is. That's where you're going to get your players. These, the smaller conferences.
What used to be the PAC eight then was the PAC 10 is now the PAC no more, right? The the big 12, right? Oklahoma and Texas left the big 12 to go to the SEC and Nebraska went, it used to be in that two, it went to the Big 10.
And, you know, so I, you know, is that, what are we seeing the college ization of open source projects at the Linux Foundation? Well, that is the, that's the question, right? Is it the Linux Foundation or is it the CNCF?
Who are you, who are you going to play for? Are you playing for the Linox Foundation or are you Playing, well, ation in this analogy, the Lennox Foundation is the entirety of college football in the, the CNC is the SEC or right, or the CA and this, it's, it's, it's a thing. But let's discuss it.
This is a great topic for another gang. Where's come back to, we're way over time. Let's take a break.
We're gonna come back. Let's talk a little, let's talk a little security when we get back here. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Hey, we're back here at Textron Gang, thanks for joining us.
Block three coming at you. Uh, you know, it is, as I mentioned at the top of the show, it's Black Hat Week Defcon old summer camp through hackers in Vegas. Uh, so it's only fitting, I think that we end our show today with a cyber related story on that front.
IBM recently came out with a new report, and this might be counterintuitive out there, but the cost of data breaches globally is actually dropping. So, you know, there's always been a, an equation of cost per breach based on how many records were stolen or breached or, or what have you. But the cost per breach is dropping except in the us I don't know, maybe that's a tariff thing or something on breaches.
But the cost for breaches in the US continues to go up. Jack, what do you think? Uh, well, you know, as you mentioned, uh, IBM Pointon came out, IBM and Pointon teamed to come out with their annual cost of data breach report.
Uh, I think the headline that they talk about is the fact that cost of breaches in the United States went up and the rest of the world went down. I think that's partly a factor of the volume of breaches in the United States versus others. It's partly a factor of we're getting better for the most part at dealing with the breaches.
But, you know, now there's regulations in the US around reporting, right? So any public company that gets a breach has to report it and, and also manage the reach out to cus you know, any users affected. And I think that increases the cost in the us.
Um, but there were some other interesting headline or headline numbers that haven't gotten the same sort of, uh, attention. Um, you know, the, the other annual report in our industry that comes out every year is the Verizon Data Breach Investigations report. Verizon covers, I think last year they went, uh, so two years ago they had 6,800 breaches.
Last year it was like eight or 9,000. And the IBM report globally investigated 113,000 of breaches. So just an insane volume of data breaches that were looking at.
Uh, good news, bad news was not only bad news that we had that many breaches. Uh, one of the good news pieces of news is the amount of time it's taking organizations to identify the breach has gone down and gone down significantly, like on the order of 40 or 50 days. The bad news is it's still over 200 days, which is just an insane amount of time for an attacker to be in your environment and to be exfiltrating your data without you knowing about it.
So while we're getting better at dealing with breaches when they happen and maybe reducing the cost when they happen, we still are really, really bad at stopping breaches before they happen and at finding them people who are inside the environment and attacking us while they're still there. Fair enough. I, I've got a few thoughts on this.
Let me first start off by saying I have a lot of respect for Larry Poman. He, he's a neighbor down here in Florida to us. Um, and he's been doing these cost of data breach reports with IBM with other vendors for a very long time.
And whether you buy into the number or not is, I'm not here to argue that with you. What I do have a, this smells, this particular report, I'll be very honest, it smells to me, I don't think we've seen enough of an impact for AI powered responses for you to tell me that that's what is bringing down the cost of a data breach. Thanks to AI powered responses.
I just don't think there's that many companies doing AI powered responses. When you're talking about 130,000 or whatever the insane number is of breaches, how many of them would have to be using AI powered responses for it to bring that number down? 2 million, it's just, and, and when you think about the US has more breaches than anyone of the rest of the world, I, I think we still probably have the lion's share of, of these breaches.
So for the majority of those breaches to cost so much more money than it does other places, I just, I just have a hard time with it. I'm sorry I, unless it's a case of where you had a handful of mega breaches that cost billions and billions of dollars not to go all call Sagan on you billions and billions of dollars. And that's what's driving the average up the, you know, the meat.
Well, You, you're, you're pulling out the great, uh, you know, we had a murder bot reference. Now we've gone back in time to get a, a Carl Sagan reference in the billions and billions. But I, I haven't dug into the details, but I would assume, you know, there, there have been a number of, um, major breaches that will, you know, the cost of the right, the skew it, the cost of the Las Vegas identity breaches were absolutely astronomical, right?
I mean, forget, forget the cost of recovery and the actual cybersecurity costs. The lost business volume they had was tremendous. And I think that's where a lot of these types of costs come from, is the interruption to business and the loss.
The opportunity cost. The lost business that you're not doing, because you're not doing business can be pretty expensive. Let me, lemme throw this out there.
Does the cost of it really matter? Ultimately, like, does the cost of, of taking care of your health, like if I have a heart attack, okay, I don't, I really care what it costs. I just wanna avoid having one right?
And do the right thing. So I'm not gonna end up in that position. Same thing with, same thing with security.
I'm not saying they're equivalent, but you get the idea, you get the analogy. In other words, am I gonna act differently if it's a billion or a half a billion? Well, it's still a heck of a lot of money at half a billion, it kinda doesn't matter.
I'm gonna take, I need to take measures. How much of those measures am I gonna justify an expense based on that number? Maybe?
But I, I have a hard time believing sort of arguing whether the numbers this or that is sort of not really the point. Really. The point is getting attacked.
What's the reputational the business damage to you, the customer loss. That's what I want to focus on. Not just the effort, the expenses, et cetera that go into it.
That's what you wanna prevent. Well, but look, make no mistake, and again, no disrespect to Larry Poman or IBM, but this report doesn't happen in a vacuum. IBM pays the PON Institute to do the report.
This is a big dollar effort. This report and the cost per breach has been a KPI that we have focused on in the media around cyber for 10, 15 more years. But here's an but Mitch, I, I'll take a little, not offense again, but I'll I'll give you another point of view on that.
I'll take exception. That's good exception noted. Um, but you know, the, the deal is this, when you and I first got started still secure, right?
5% of their total revenue would be lost by, by security incidents. And they deemed that an acceptable risk. 5%, 50 million, and they lost 50 million in a breach, in breaches in security incidents, acceptable risk.
Acceptable risk. So at some level it is, it is dollars, right? If it goes over that 50 million in a billion dollar market, well that's no longer an acceptable risk.
So when we talk about managing risk, which is really what security's supposed to be about, you know, risk is, is unfortunately tied into dollars at some point. It all, But that's a real thing. What you just gave was a real example, right?
What is it, what is the cost to our business? Credit card theft, right? How much, how much do the credit card companies, uh, attribute to fraud that they're willing to write off and of course make us pay for?
Those are numbers that are business risks. Whether rather, whether the credit card theft or broad costs us the industry this much per year or the average breaches whatever number that that's a bogey out there. It's not, I don't think it's real enough for companies to really drive their behavior.
They're gonna say, what does this mean to he, to me? What is acceptable risk? What's an acceptable loss?
And how much do we have to spend to make sure we don't go past that? That's my, that's my goal. 5 million, doesn't matter.
What matters is the order of magnitude and the return on investment or the amount of investment you take to, right? The old adage in security is, you know, you don't put your, your, your nickel piece in a safe that costs you a million dollars and you don't put your million dollar gold bar in a safe that costs you a nickel, right? Your penny bank, right?
And it's, it's, it's providing organizations a benchmark to understand that on average in the us let's just take their number on average in the US it's gonna cost me four and a half, $5 million roughly if I get breached how much, or, or in the US it's 10 globally, it's five, right? But whatever the number is, right? On average it's to pick 10 numbers.
Easy, nice brown number. On average, it's gonna cost me 10 million if I get breached. If my entire company is a is a hundred thousand dollars company A, it's not gonna cost me that.
And b, I'm not gonna put up $10 million worth of cybersecurity in place, right? If I am a 50 million or a hundred million dollars company, I then have a way to judge what's, as Alan said, what's my level of risk and how much do I invest to protect myself? And those questions are what's driving a lot of, unfortunately, poor security decisions such as we don't want to invest in MFA because it would cost us too much compared to our risk.
And it causes, you know, all these other issues around MFA, even though MFA is such an easy win in terms of reducing risk, right? That's why, you know, three years ago when I class studied this, over half of companies didn't make MFA mandatory, right? So it's, it's looking at the big picture organizations say, my cost is gonna be roughly this.
How much do I invest in? It's a numbers game and it's the same, it's a different version of the numbers game than our last discussion around the CNCF, but it's still a numbers game. 1 thing out.
There were three categories that they listed, uh, and they were all pretty much the same in terms of what the cost was and the categories being supply chain attacks, insider attacks and phishing attacks. So we have seen quite a bit of investment go into phishing attacks and insider attacks, but we haven't seen that much money going into supply chain attacks. But there is more coming, there's no doubt there's more work being done.
But most of what we think about is phishing attacks. And phishing attacks now is at the lowest at is at the bottom and the most expensive being insider attacks. So as companies look at these reports, I feel like there should be some kind of competition between these three categories and an equal dis uh, uh, kind of an equal spend across those categories because they're equally all as dangerous.
Agreed, agreed, agreed. Alright, guys, we're over time. I need to, I need to end this.
Jack, Tracy, Mitch, thanks for joining me. Thank you for joining us watching this. We've, of course, we got tech drunk TV following, so stay tuned for that.
Again, if you're out in Vegas this week, come look us up. We'll be around there doing interviews and videos and I guess we'll just go to a party or two as well. Uh, enjoy.
Until tomorrow, this is Alan Shimel for Textron. We're out. Hey everyone.
Welcome back here to Techstrong tv. You know, today's the day of CEOs. I've got another, this time, a new CEO to introduce you to.
His name is Sam Allen, and he's recently been appointed CEO of Iterable. And not to worry if you haven't heard of Iterable, we're gonna explain it to you. But first, let's welcome Sam.
Sam, thanks for coming on Techstrong tv. Congratulations on the CEO, uh, job. I think.
Congratulations, Alex, You Alex, great to be here. Yeah, thank you. Really appreciate it.
Thank, Appreciate you coming on. So, Sam, before we get into Iterable and we are going to get into it, let's hear a little bit about you, right? You newly minted, but you didn't wake up, you know, it wasn't you, you've had a life before that, right?
Let's hear a little about Sam's life. Yeah, I've had a bit of a convoluted background, but I I I've been in the tech sector since the late nineties, so I've been through quite a few, um, you know, market changing, you know, tectonic shifts in our space. Uh, my first 10 years, um, out of college I was a officer of the United States Marine Corps.
So that's where I honed a lot of my, my, my leadership chops. And, you know, I, I'm a deep believer in values based leadership. My number one value is integrity, and that's what I lead with.
Um, and then I focus on, you know, being, uh, have a high caliber moral courage, making decisions fast, making the right way, getting people included, and then frankly, looking out for people. I, I consider myself a servant leader. Like my job is to make sure people can do their jobs.
Um, and so I try to clear the decks for folks, but, um, yes, almost 30 years in the tech sector. I've been at large companies like Cisco. I just spent the last decade plus at Salesforce in a variety of very senior operating roles.
Um, I have been in a few startups, some great successes, some swinging and misses, but that's the nature of the game. Uh, You and me both. Yeah.
I got the t-shirts to prove it. Yeah, right. I got all kinds of scar tissue, but those are all learning opportunities.
Um, and, you know, look, Iterable came along a few months ago. You were right. I, I was, uh, very, very content and happy in my Salesforce career and, um, this was not an easy decision, but it was the right one.
And we, we can get into it, but I could not be more excited about the opportunity that lies ahead with Iterable. I'm, I'm, I'm pretty pumped. Good.
Glad to hear it. Alright, so let's, I guess that leads us to Iterable, Sam to give us the scoop here. What, what's Iterable about?
Yeah, so Iterable is what we call a customer engagement platform. Um, it's behind a lot of brands that you've heard of over, we have over 1200 customers globally. Um, but a few would like to call out or Pete's Coffee, Volvo, uh, Stanley Black and Decker and Strava, the fitness app.
And I actually use, use all of those. Um, but let me kinda explain this in more layman's terms because I think that'd be a bit more helpful. So I'll give you a personal example.
So I love coffee. Um, I start every day with a couple of cups, but at, at home. But every afternoon after lunch, I find my way to a local Pete's, um, where I'm a very loyal customer.
And what's amazing is my engagement with that brand is amazing because they will send me notifications, say, Hey Sam, it's about time for your local cup of co your your daily cup of coffee. Why don't you come on in. And by the way, as a thank you to you for being a loyal customer, uh, we've got a dollar off on your favorite, um, you know, maple Nut scone, which they know I buy.
Um, and so it's very personalized. It's a very personalized en engagement, um, a very motivating one. It makes me feel like this brand actually cares about me.
It doesn't offer, send me offers I don't care about. It doesn't send me offers for tea 'cause I don't like tea, um, or doesn't send me offers of food that I've never bought before. So all of that is powered by Iterable.
It's that really deep engagement, personalized, hyper-personalized with the brand. And Iterable drives all of that from the back end. I love it, man.
You know, I'm trying to think. Companies I've engaged with the first that similar kind of, because that experience is a real feel good. It gets you right here, right?
All of a sudden you feel loyalty to brand, you know, the, the pet food, um, farmer's dork, I dunno if you're familiar with Farmer's Dork. Yeah. We use that.
Yeah. A lot of people do. And we're Bulldog people in my house.
I've had four bulldogs over the last, I don't know, 25 years. They don't live long, unfortunately. But I've got a scoring French bulldog in my feet.
So if you hear that, oh, Do you? All right. So, you know, then I, we do English.
So, um, what happened, our last bulldog before the current one was a farmer's dog dog, and she got sick and unfortunately, you know, passed away the, the, the farm. You know, I went in to stop the subscription, right? That week I got a plant, you know?
Yeah. As a sympathy thing with all kinds of cards. And then a couple months later, Hey, how you doing?
Right? Have you thought about a new puppy? A lot of our people wait six to nine months, you know, blah, blah, blah.
It was such a, and I'm sure, look, it was a drip campaign, let's face it. Right. It wasn't someone there really, but I, I can't tell you the goodwill that it enabled in, in my house for that, right.
That when we got the new puppy, as soon as we were able to, we put her on Farmer's Stock. Yeah. And think you're now telling that story, right?
And so you're in and I'm telling it here to you. Exactly. Yeah.
You're engendering brand loyalty and the people in your community and that that's the real power. I mean, you just nailed it with your own story. It's fantastic.
Yeah. And now taking it one step further is when you could do it via an app in text and stuff, like, you know, this reminds me of the old promise that they used to tell us that when you're walking in a shopping mall who watch walks in shopping malls anymore, but you went by a store that, you know, din vicinity Locator Yeah. Would start popping coupons for the store as you walk by it, right?
Again, that personalized up to the second, you know, in the moment, if you will. Right. Uh, experience.
And it, it is, I mean, that's where marketing's going, right? Yeah. That, that's where absolute this stuff is going.
And that's very cool. That's, that's actually a big reason why I, you know, go back to your question. Why Iterable, um, why I came here.
It's not only because we have this amazing industry leading platform. I mean, if you go look at customer reviews on like G two crowd as an example mm-hmm. One rated platform that's all great and, um, a compelling reason to be here, but more importantly is our AI strategy.
And we're really uniquely, um, set up to drive very strong AI strategy in the space because of the way the platform's been architected. AI to us is not a, it's not a bolt-on feature. It's not a check in the box.
Like so many companies say they're AI first, and really when you dig into it, they're not, they're not, yeah. Notable from the ground up has been architected to really take advantage of ai. And so these personalized engagements are gonna get even more powerful, more personalized.
Um, and if you're a marketer working at a company, your job just got a lot easier because our, a RA platform, AI platform is gonna allow you to do your job with much more efficiency and drive a lot more revenue for the company. And so all those things coming into play are gonna be a pretty amazing opportunity for us. So Sam, I know you were just recently announced.
You barely got, you barely got your coffee machine warmed up, right? Yeah. Um, but let me a, this might be a little too much in the weeds, but how does it actually work?
What does it integrate with on the, on the retailer side, for instance, to know that you usually get your coffee at 2:00 PM that you usually get that maple scone Yeah. Right at, at two 15. How, where, where is the, how does that integrate?
Yeah, so the first thing is it's about data, right? And a lot of people will tell you that. And coming from Salesforce, you know, Salesforce phenomenal, top notch company deserves every loyal it gets.
When we were at Salesforce, we focused very much on the data. The bottom in, in line infrastructure we're also, so that's very critical and a critical component of, um, of the Iterable, uh, Nova is our new AI kind of, um, our focus. Uh, so when we think about AI and Nova and Iterable, that underlying data is the most important thing.
So we have the data. So every time I interact either inside of Pete's, usually with my Pete's app, um, uh, but when I interact with Pete's, every interaction I have goes into a data profile about me, Sam Allen. And that's why when, when I go and buy a Maple nuts sc every day, they know that that's what I really like.
And they can give me an offer. You can start to tune your offers instead of saying, Hey, uh, we're gonna give this guy $2 off or half off, let's give him 25% off. 'cause we know he loves it, and that'll probably get him, it's enough of incentive for him to buy.
We're protecting margin, we're giving him brand value, and we're giving him, you know, a discount. And so the data is the most important piece. The other really important thing about how herbal works on the back end, and again, I'm not even officially started yet, so still working through all mechanics of this, but honestly, it's, we have an agnostic, um, data ingestion, uh, architecture.
And so we'll take data from anywhere and we're built from the ground up to take that data from anywhere. You just Stuck it in. Yep.
Stuck it in, integrate it, take multiple data feeds, put them together, um, and then the future of AI is to take potentially data feeds from, you know, multiple brands that I might engage with. And you can start to build a 360 view degree, just find 360 degree view of Sam Allen as a customer, potentially use that to make my engagement across multiple platforms. Really compelling.
But it really is about the data, the flexibility. Um, and then one more thing I think is really important. Um, our AI is explainable.
And what I mean by that is if you're a, if you're a, uh, marketing manager, um, what many of our competitors do is they provide an AI capability that just gives you a recommendation, but you don't know the why. And so the machine's kind of telling you what to do, and it's hard for you to trust it. What our platform does is it says, Hey, you should run the following campaigns to the following cohorts of people, and here's why you should do that.
We did the research, we found that you're gonna get a 15% uplift if you run this campaign in this geography. And by the way, if you want to understand that data yourself, click here and we'll explain it to you. And so that explainability of the AI to help a marketing manager is a tremendous step up.
Well, it, it, it competition. It's A security blanket too, Sam. Yeah.
Right. We, we discuss this, we do a show every morning text on gang, five, six people pundits, just, and we talk about, you know, three different subjects every day. One of them, today, a new thing came out now with the, some company outta San Diego, I think came out with you could look in and try to stop bias hallucination and, uh, and, uh, censorship in ai.
They were going with the deep seek, the Chinese one, which, you know Yeah. Good thing to do, I guess. But at, at, at the end of the day, the feeling of, look, I don't know how the hell this works.
I don't know how it came up with this answer. It's kind of magical. And I, I, you know, at first you're in love with the magic because we're all little kids at heart and we, you know, we love a good magic show, right?
Right. But at some point before, I bet the farm on it, I, I gotta see behind that black curtain a little bit. Yeah.
And see what levers is getting, are getting pulled. Yeah. And, and so it's important, and I think this is gonna be increasingly important with as we adopt more and more AI that you get to see Mm-hmm.
You know, you gotta see the, how they make the sausage a little bit. Yeah. Right.
I, I just don't want the sausage. I wanna see how that sausage is made. Yeah.
And, um, and I think that's, so that's a very, very important Yeah. Piece of the whole thing of it. Trust.
Yeah. The customer trust is just absolutely paramount. It's one of the things I took, you know, when Mark beo started Salesforce, his whole thing was trust is a number one value.
And I just deeply believe that. And man, you can't think of a better technology for that's more applicable than ai, and you're a hundred percent right. And that's what makes Iterable Nova so amazing is our marketing man, the marketing manager that use the platform can ask that question, like, why are you telling me this?
Where did you get the data from? Um, and so they can verify and use their own gut instinct to say, you know what? This does make sense.
Oh, I saw the data feeds. I see where this is coming from. Yes.
Execute, hit a button, and it goes. So it's, it's pretty powerful from that perspective. Absolutely.
So this, this is what Iterable does, and it sounds fantastic. You are coming in as the new CEO. Yep.
If you can, and I know it's early, give us a sense of your vision saying, here's where we are now, man. But I think I could take us here. Yeah.
Or this is where we're going, right? I mean, you mentioned Salesforce. Look, Benioff had a, a vision a year and a half ago, maybe more about what became Agent force, right?
Yep. Agent ai. And he's driven, you know, I saw a week or two ago, he claimed 15% of the work being done at Salesforce.
Now is is ai. Mm-hmm. Um, what, talk about your vision for admirable here.
So what is really compelling to me when I went through my diligence was the, the vision, the architecture, and the product vision that's been laid out by Andrew Bonney, the founder, um, and our chief scientist is stellar. Like, I won't, don't tend to change a thing about the vision of where the product is going to go, where my true superpower is gonna come into play here is my vision is how do we scale the heck outta this business and grow it to much, much bigger than it is today? How do we go penetrate the enterprise?
How do we go find massive adoption in Europe and in Asia Pacific and in South America? How do we expand beyond? We're, we're really strong in four key industries in the US today.
We kind of own those industries. How do we get the next four in, the next four after that? How do we do all that at scale with fiduciary responsibility while building an amazing team and doing phenomenal great work and having fun, like all of that scale, all of the economics around how we do that?
How do we think about inorganic growth? So we have a great organic, uh, um, strategy. How do we think about inorganic growth as we can continue to get great success and drive continued double digit growth as a company?
What else out there in the marketing tech stack makes sense for us to maybe go buy or partner with? You know? Um, yeah.
When you're, when you're mo in the fast moving market like this, you gotta think that, right? Because organic growth is great, obviously. Yeah.
But, you know, you gotta start stacking stuff and, and sometimes that means tuck-ins and strategic. Yeah. But I used, I was a corp dev vis dev guy that Yeah.
You know, in many startups, so I know where you're coming from. So I, I, yeah. So I, when I was both at Cisco Systems and then a Salesforce, my first job at Salesforce were in m and a.
And so I've got a, you know, a very strong background in, um, in mergers and acquisitions. And it's just something I deeply believe in. And, and you know, this Alan, like you can't build a strong compelling technology companies solely, organically, no one has, right?
Everyone has done acquisitions, and so they're gonna be an important part of our strategy. It's not something we're gonna look at in the first six months. Like, gotta get my feet under me and understand the business and the meet with the customer.
I get it. Partners and all that. But that's when I, you think about vision for me, it's, we've got a great organic vision.
How do we go drive inorganic and how do we drive expansive volumetric growth for the business? Couple kinda loose ends. I want to tie up here, Sam, as we run law on time, the Iterable website, what's the domain?
com. It's I-T-E-R-A-B-L-E. Just the way it is under your name here on the screen.
Yeah. Correct. Correct.
Um, secondly, you mentioned there's four key industries here in the US that you guys are doing, you know, eye penetration. What are, if you can, I don't say anything that's gonna get us all in trouble, but what are they, if you don't mind? Yeah.
So, um, they are, um, retail consumer applications such as, um, uh, uh, Strava that I mentioned, coffee, uh, media and travel. And, uh, the, we're, we've got great leadership in those four sectors. We've also got, we also have great traction and things like financial services, but I think about financial services, health, life sciences, those are tremendous opportunities for us to grow as well.
And so, you know, we're looking forward to expanding into those other, um, into those other industries. Look, I think this is applicable across the board. You also mentioned, you know, non-US or non North America, whatever you want to call it.
Um, I, I saw that, I think one of your referee, we were talking about Farmer's dog. Mm-hmm. You guys have a, uh, another dog food brand similar over in the uk Yeah.
Marley Smith. Yep. We'll give them a shout out as well.
Right. So, look, Europe is a tremendous growth market for everybody. Uh, I have a lot of experience in, in Europe.
I've lived there for a little bit and in my past. And, um, I I might go there five, six times a year. It is a too, Man, I just got back.
Oh, wonderful. Yeah, we, We were, we were in Italy in Tuscany and Oh, wonderful. I did a little Rome a little the day or two in Venice.
Yeah. But Mo we were in a Villa que it was. Yeah.
But, um, I think that there, there's just, it's fertile ground in, in, in Europe, you know, start a few key countries. We already have a footprint, we've got a phenomenal office in Lisbon, and we've got another office in London. And so we've got really, okay.
We've got a springboard there. Yep. Very cool.
And look though, you know, I mean that EU market from a pop population point of view is, is roughly equivalent to us, right? When, when you put it together It is. And it's also, you know, uh, frankly, Europe I've always found has been a bit ahead of the US on things like mobile.
Um, and, you know, the, the fact that we have a very strong mobile capability, I just, I, again, I think it's just an awesome opportunity for us over there. Yeah, no, no brainer. Hey man, Sam from the bottom of my heart, I wish you all the success at Iterable.
Come back, keep, keep this story fresh with our, our viewers out here. I like to hear these kinds of things. Many of them probably have already used Iterable and they don't even realize it.
Yeah. I Mean, I very much so. Um, thank you very much, Alan.
I, I really enjoyed this. I, I, I guess wanna reiterate, I, I can't be more excited about the opportunity that lies ahead for us. I would love to come back.
I open anytime, you know, back six months. You've Got an open invite, my friend, anytime you want. Alright, let's do it.
Don't wait six months. Things happen too quick. Alright, we'll do that.
All Righty. com here on Techstrong tv. We'll take a break.
We'll be back in a bit. Hey guys, thanks for the throw. We're here with Aaron Kira, who's, uh, director of cybersecurity for Cypress Data Defense.
And they have a new report out on application security that among other things, proves that we are knowingly shipping insecure code into production environments. Aaron, welcome the show. Thanks.
Appreciate you having me. Walk us through the high points of this study that you guys did. What, and most importantly, you know, besides the fact that we are shipping code that we know has issues, anything else in here that kinda leapt out at you or surprised you?
Well, it's interesting because we've known forever that people have problems with application security. It's one of those things that as security professionals, we see it all the time. We see that they don't have time to do security, they run through their sprints, they run through, Hey, we need these features.
The business says, Hey, we've gotta have these things to make money. Okay, we take, we write the code, we push the code in, we run through, and then we get to the end of the sprint and hey, we don't have any cycles to do. We'll do it next time.
And they bring it around and it goes and goes. And then they get it out to production. It's like, Hey, we found this problem.
We'll do it next time. And so they end up with this huge technical debt and no time to fix it. We end up with configuration issues.
We end up with all of these problems that just never get fixed. And then there's a breach and they're like, how did this happen? But what really showed up in this survey was that they know that it's happening.
They know that there are issues. They know that they have big security problems and they knowingly push it to prod. And that's really the biggest thing that came out and was surprising to me is that 62% of 'em said, yeah, we're pushing things out there with big security holes.
So the road to hell is still paved with good intentions. And as part of the good intentions that they think that, well, we'll just get to it in the next cycle. 'cause the next thing will be a a, a sprint is right around the corner and we'll just tuck it into that, but then it just falls off the table or what happens.
Yeah, they, if we can just get to that one sprint where we can dedicate a whole sprint just to cleaning up those security issues. And if we can just, we'll hire a security person and they can come in and they can do all of those things for us. And then what, we don't have budget this time, but if we can add it into the budget next year, and it just kind of falls down the list of importance as we just get enough to keep going and we just get enough to make it last.
And it never becomes enough of a priority until that big hat comes. And then it's about getting through the breach. And we can hire the forensics people, we can figure out what happened, we get through the breach and then, okay, well we made it through that.
Well, our stock is still selling. In fact, after a breach, those stocks always go up. So let's just try to scrape by a couple more years.
And it just keeps going. The cycle perpetuates. I think though, that things are about to change.
'cause if I'm not mistaken, I think I've seen studies in the past that say, only a small percentage of vulnerabilities are actually exploited. However, in the age of ai, it seems like the bad guys are gonna be able to, A, scan the code and B, ask the LLM to help them figure out how to exploit a vulnerability that the LLM is gonna help them find. So is this whole thing about to ratchet up into maybe, uh, you know, the Pied Piper's coming home, the roost as it were, It's gonna be a really interesting thing to watch because not only are the bad guys gonna be able to look at the LLMs and say, okay, go look at this website.
In fact, there's a ton of tools coming out for us pen testers to send it at a website, let it go, figure out all the vulnerabilities for it. While obviously the bad guys use the same tools that we do, but all of the developers are using those same LLMs, like copilot and things like that to write the code. So we're gonna have AI, fighting AI to go back and forth to have this huge war over who's gonna write and kill the most secure code.
It's gonna be fun to watch. I'm really excited about it. It seems like though, the first wave of that is a bunch of LLMs that were trained on bad examples of code that they pulled from across the internet.
So are things likely to get worse before they get better? You are not kidding. A lot of it was trained on open source code that some of it was just really bad.
One of my favorite things to do is to take a piece of code that I've written and ask the LLM to make it better, and it'll come back and it'll take and suggest some improvements. And I look at it and I say, is this really better? And invariably it comes back, oh, you're right.
This doesn't even compile. Let me try again. And after four or five iterations, it'll come up with some interesting improvements, but I don't know that they're even better.
And so to take and put all of your faith into an LLM and say, can you write this for me? And just let it come up with something and say, yeah, that's probably good enough, and push it forward. We're not at that point yet.
We have to have people watching those and knowing what good code looks like and what it's coming out of. So I agree with you that we are not at that point where we can trust that code to be useful. And I think the code that's coming out of them is arguably worse than we were getting just out of plain brand new developers that we're coming out.
So, And oddly enough, truth being stranger than fiction, but apparently, um, the LLMs are pointing to software packages that don't exist. And the bad guys are getting wind of that and creating those software packages, sticking 'em in repositories and loading 'em up with malware. So, um, have we kind of like, you know, just come full circle on chaos.
I've seen a lot of that. I've seen those same stories and I've seen those packages and they're terrible. It's just like, Hey, here's a great opportunity.
If it's gonna suggest it, why not capitalize on it and stick 'em in there? And then we've got some other supply chain issues where we're having people spend two years to become trusted in these spaces so they can then put their malware into these packages to become part of this ecosphere that, Hey, I am a trusted person so I can put my garbage package in there and push throughout the entire place. It amazes me that now we have to take these things that have been a close knit group and say, okay, do we need to be closer?
And how do we verify all of these things? And these, these packages that are just showing up that, yeah, well the LLM invented it, so let's take advantage. Mm-hmm.
Um, we talk a lot about DevSecOps lately, and people are investing. And I like to think we're making some level of progress there. But, uh, there's still some debate about who should be responsible for application security.
Is it totally in the hands of the dev team and or do the cybersecurity folks have a role to play and how do we get them all to play nicely together? I like that you said DevSecOps because it's very rarely said that way. It's mostly DevOps.
And then all of US security folks are like, Hey, you keep forgetting to invite us. We want to be in there. So the whole DevSecOps part of it is that security should be everywhere.
It should be as part of the development cycle. It should be part of the pre-planning, Hey, how are we going to include security in this? And it needs to be part of the CICD process.
It needs to be part of the deployment. How are we gonna check for it afterwards? Are we doing scanning of the production stuff?
Those things that have been in there for five years, as those new patches are being placed to the oss, what is that doing to those apps that have been sitting there? So it needs to be part of all of those groups. It needs to be part of development, it needs to be part of operations, it needs to be part of the whole cycle.
How do we do that? 'cause some folks will say, you know, we have hundreds of developers and two security people and there's not enough of them to go around. So how do we kind of get some sort of knowledge sharing going between a very small number of people and a lot of people who probably can't even spell cybersecurity?
Yeah, we get asked that all the time. I teach for Sands and we do a lot of people that come in and say, Hey, I am the security team. We have 150 developers.
How do I do this? And say, well, one of the things you can do is outsource a lot of your security stuff. Go to a managed security provider, managed AppSec provider.
Let them run your scans, let them do your static analysis. Let them do your, uh, you know, your SaaS and your das so that you can spend time building a security champion program so that on your dev teams, you have one person on each team that has some interest in security, you can meet with them once a month, buy him some pizza and say, Hey, let's talk about this vulnerability. Or how do we mitigate these kinds of things?
Or what kind of things are you running into on your team so that you can at least let some of that trickle down and get some support for those two people who are just running ragged right now. Mm-hmm. Um, we invested in a lot of tools over the last few years and related to securing our software supply chains.
But it always seems to me we're kind of like trying to shift everything so far left and yet maybe the focal point of the development process is the repository itself where all the code is. So maybe that's where we should be thinking about applying our security time and effort. Or is it really need to be at the IDE level where the developer, you know, unless the thing is automated, isn't gonna really pay attention to a million alerts he doesn't understand.
Yeah, I think there's a little of all of that. So I think you need to have some static analysis going on every time that code is checked in, as well as the integration into the IDE so that when they throw something in there, it pops up and says, Hey, this is SQL injection. You don't wanna do concatenated sql, this is a great place to use, uh, an ORM, or this is a great place to use something else that is not this.
So having that feedback to the developer in a language that they can actually understand versus, Hey, here's this esoteric thing that came out of a scanner that you have no idea how to understand is huge. Um, one of the things that I have always found a little perplexing is it, it doesn't feel to me like there's a whole lot of accountability for these vulnerabilities when something goes on. And it seems like maybe that's because it's perceived as to be a team error or we just, you know, so desperate for developers that we don't wanna call anybody out too much in case they're gonna leave.
But is there something that I can get to that feels like more accountability without necessarily having to, you know, put everybody on trial every time there's a problem? Absolutely. That's one of the things that actually popped up in our application survey was that there are a lot of developers that are afraid that if a vulnerability is discovered or a breach happens that they're gonna get fired.
And that is such a terrible place to be in that you're afraid to write code. When I switched over from being a developer to being in the security team, I was afraid to write code for like six months because everything I wrote was wrong. Oh, that could get hacked.
Oh, that could get hacked because I knew better. Why didn't I, as a developer know better? We should have done a better job educating developers, teaching them how to write better code, teaching them how to write more secure code.
So I think having a better education program to being able to talk to those devs, having more brown bags, that security champion program that, Hey, here's a cool article I found about, 'cause just like every other profession, we wanna be good at our jobs. We want to do better. We want to actually be proud of our craft.
And as a developer, I wanted to write good code, I wanted to write clean code, I wanted to write fast code, I wanted to write efficient code, and I wanted to write secure code. And just having somebody that I could ask, is this right? Having somebody look over my shoulder and say, Ooh, that thing that you just did there, you shouldn't do it that way, is huge.
Where are the regulators in this conversation? 'cause I feel like, well, in certain countries at least there restrictions are getting more, uh, rigorous and in other places not so much. Um, so are we making progress there?
And what is the right level of regulation? That's a really good question. I kinda go back and forth.
The biggest issue I have with regulation is that finding the right size, the right place, the right application. If we look at something like PCI, applying PCI to a mom and pop versus applying PCI to a multi-billion dollar corporation, they're different things. And to rightsize that and to put it into a place that can be applied to each of them equally and the right way is hard.
And then to abstract that to a place where a government can apply it and then to regulate it, it becomes a very difficult conversation. So I'm not sure that there is a right way to look at that and say, this is how we need to do it from a regulatory standpoint. There have been some states that have kind of taken that on and, and done it more from a, we're not saying how you should do it, but if you don't protect the data that you are entrusted to protect, then you're gonna be held liable.
So that I think has some merit because we don't care how you do it, but if, if you don't do it, there's a problem. So I think that may be the right way to go. So what is that one kind of maybe simple thing that you wish more people were doing that would kind of just believe the overall stress?
Because I always struck me is if I know that there's a vulnerability in there and it's deployed in production environments, I'm kind of having that nagging feeling in the back of my head forever, right? Yeah. That knowing that vulnerability is there is bad.
Not knowing that vulnerability is worse because you're pretty sure that there's something in there but not knowing. And honestly, if there is something that you can do that is gonna give you some of that peace of mind, one of the most effective ways that I've seen it done is to take something like a managed application security provider. Throw it against your source code repos where and your, um, CICD builds where you're building a container.
Every time that code gets checked in, you're running static analysis. Every time that code gets checked in, you're running a dynamic application security test every time that code gets checked in and you're throwing that stuff right back into your ticket tracking system, whether it's Jira, whether it's Azure DevOps, whether it's GitHub doesn't matter. But now where those developers work, where those developers live, they have actionable things that said, Hey, you check this SQL injection vulnerability and you check this cross-site scripting vulnerability and yesterday, you should clean that up before you go back and work on whatever you were gonna work today.
Now I know I've got that feedback instantly. Oops, I didn't even notice I did. That let's me sleep a whole lot better at night.
All right, folks, you heard it here. Hey, shipping code with known vulnerabilities is roughly the cyber security equivalent of playing Russian roulette. And it's only a matter of time before you're gonna lose.
Hey Aaron, thanks for being on the show. Appreciate It. Thanks Mike.
All right, and back to you guys in the studio. Hello and welcome to the latest edition of the digital CXL Leadership Insights video series. I'm your host, Mike Baard.
Today we're with Kush Patch by who is the Senior Vice President for Platform Fundamentals for ServiceNow. And we're talking about, well, what does it mean to be responsible when it comes to ai? Kush, welcome the show.
Thank you, Mike. Thanks for having me today, and excited to talk about this very important topic with you today. All right.
It seems everybody would agree that we should be responsible for ai, but nobody knows exactly how to go about implementing that. And what does it mean beyond the fact that we all agree that it's a nice idea? So what exactly should people be doing here and what is the process that we need to think about as we apply it to our workflows?
So, amazing question. I think last two years have, uh, taught us that AI is super, super powerful, but with great power and comes great responsibility too. And that's why ServiceNow has embedded responsible AI into each and every layer of the platform.
And the products. The way we do it is we have embedded our four key principles into our responsible AI thinking. One is human centricity, like in each and every layer of the platform, we are adding ai, but we are making sure that it's persona driven and that the human is in the loop when decision making needs to happen.
The human is in the loop when it needs to know that this part of the product is done by AI and why it's done by ai. So the human can control if it needs to go autonomous or the human needs to make decisions. The second one is transparency.
Again, in each and every layer, you can understand what model is being used, why is it used, what data it's trained on so that there are not no biases. This makes sure that like the accountability is right there into the platform. The third principle is inclusion.
At ServiceNow, we strongly believe that we wanna build amazing products which create value for all our customers, global customers. That's why inclusion is very, very important. Whenever we are building any AI feature, whenever we are fine tuning any large language model, we are very, very cognitive about what data sets we are using.
So that bias or any other things like that don't get introduced into the algorithms or the software that's make sure that like we are building an inclusive software for everyone. And last one is accountability. How do we share the metrics?
How do we share clear documentation? How do we share all the things which customer care for to the customer through the right mediums so that accountability value is in place? So these are couple of, uh, principles which we adhere to.
And we are also using these principles, which are based on the NIST AI Act on top of it. ServiceNow is also member of AI committee in partnership with Meta and IBM, where we further these things in the industry. Like you said, everyone wants to do it, how to do it.
So forming these consortiums helps bring responsible AI thinking in the industry and we learn from each other. Mm-hmm. It seems to me at least that trust evolves over time, and it's one of those things that's easily lost and hard to regain.
But will I have some sort of ability to dial up the level of trust that I assign to given AI agents? 'cause it may change over time and I may gain more confidence in the AI agents' ability to execute something autonomously. And this seems like it's gonna be a, a little bit of a dynamic relationship for a while.
A hundred percent. I think one of, one of my favorite quotes from our CEO is that like you earn trust in drops, but you lose that in buckets. And this has been always our principle when we are always thinking about like how we build products, how we deploy them, how we create value for our customers.
And your question is really, really amazing. One of the products which we use internally and we have also given back to our customers is AI control tower. Now we understand that customers will use our AI and third party AI in their environment, but we, what we want customers to have is full visibility on what that AI is doing.
Metrics through performance hallucination, and all the other metrics value which it's creating. When you have all that information in the central command center and you can manage your entire AI footprint from ServiceNow to other third party vendors, then because of transparency value, your trust may go up because you are seeing the AI in action. When you are seeing it in action, you can, you can essentially dial the autonomous city of that AI based on the trust you have.
And in some cases, when you see that the AI is not creating value through AI control tower, you understand why it's not happening. Maybe the data set is not correct, maybe the environment is not correct, whatever is the reason you can fix that problem so that you can dial it up or down based on the scenario. Mm-hmm.
How easy will it be to swap out the underlying large language models use to drive some of this stuff? Because I may at some point, uh, lose faith in a particular LLM, it may be updated in a way that, uh, the database or the data underlying it has been tweaked or poisoned, or there just may be advances in one LLM that's faster or better than the next. And I wanna take advantage of that.
So, um, I guess how disposable are l LMS gonna be? Another fantastic question. Uh, another, uh, thing which we have learned in the last two years is like the advancement in these technologies have been unprecedented.
Every three months we are seeing new LLMs, new models, new modalities coming in, solving problems, which were harder a couple of years ago. That essentially means that like, hey, as we adopt new LLMs, as we adopt new versions of LLMs, we need to be transparent to our users, to our customers. And we do that through model cards in ServiceNow.
We have publicly available model cards in which we tell you what version of a model we are using, how did we train that model? What are the metrics of that model? What could be unintended, uh, biases in that, if any, and all the other information which, uh, is, uh, required for someone to make a decision on.
Another thing which we do is, like in our SDLC, we have embedded AI governance in each and every layer. When we are taking any general purpose model, we are first doing research on it to figure out what is the problem statement we are trying to solve. And for that problem statement, which generic model is best to use.
Once we have that, we fine tune it with our specific data so that it's giving accurate answers. Because once you fine tune it to the problem statement, you have in hand with the data, you can essentially control the accuracy of that model. Once we have that, we have super extensive eval, uh, training so that we can validate that, okay, whatever we are trying to do, is it happening or not.
Then based on that we deploy it and understand like if there is a, uh, the same quality metrics sticking to each and every geo, each and every scenario, and then deploy, check the metrics. And in any case, in the future, if we are deprecating any LLM, we retire it. We are very transparent with our customers about it, and that entire information is available to them in AI control tower two.
So this entire SDLC makes sure that there is always transparency and trust built in the platform from ServiceNow to our customers. Mm-hmm. It also seems to me it maybe we need to change the way we think about our relationships with applications and machines.
And I asked the question because so many of our processes are deterministic. They need to be done the same way a hundred percent of the time, the LLMs are generating output that is probabilistic and that is, you know, it's, its best guess based on the data that it has available. But it may be flawed, it may be wrong, and somebody needs to double check all that.
But, um, I think maybe we think too much of the machines and not enough about the role of the humans in this process. So how do organizations kind of strength the right balance there? So One of the things which, which, uh, we did when we started this generative AI agent journey is like, how can we use the 20 years of ServiceNow investments and take that as the foundation, which can drive this agent revolution?
So for 20 years, our customers have written automation on our platform, scripts on our platform, created knowledge articles on our platform, built lot of end-to-end, uh, business rules on our platform. Now, all these things, like you said, are deterministic because they essentially like follow steps A, B, C, D, and they're always starting from the same thing and ending at the same thing. But when you give these tools to large language models, the reason on which tools I need to use in what order so that I can get to the outcome that u is asking me to do.
So this brings more accuracy into the platform because our AI is not bolted on top of it. It's layered in, into each and every layer of the platform. That essentially makes that AI having lot of tools at its disposal.
It has access to all the knowledge articles, it has access to all the automation, it has access to all the pro code stuff, which is created on the platform. And then it's using all of that with the reasoning to orchestrate that across the, uh, platform, east, west, north sub. Mm-hmm.
Um, there will be agents that come from places other than ServiceNow, and we've seen the rise of things like the model context protocol to give, uh, agents access to external data. And there's also this whole notion of the agent to agent protocol, but how will we extend trust to other agents and, and will ServiceNow kind of rate the level of trust, not just for its own agents, but the agents that you're interacting with? Uh, another amazing question.
One of the things which I called out earlier is like, we built a product called AI Control Tower. And it's a governance tool not only to manage ServiceNow ai, but any AI you have in your enterprise. And what it does is it's essentially giving you an oversight on different agents which are created on the platform, different tools, uh, which are created for those agents like an MCP server or an MCP client.
So this way any enterprise can actually manage all your AI footprint inside an enterprise. The second thing which we built was AI agent fabric. Now, like you said, there are multiple protocols.
There is a two A, there is a two C, there is agency, there is MCP. Now our AI agent Fabric understands all these protocols. So when two agents are talking to each other, we find the best protocol to talk to that agent and essentially figure out acls so that the right securities maintain data governance so that if you're not, uh, entitled to see certain data, we don't give you access for that.
All of this is built into the platform with visibility into AI control tower. That way a human, in most cases the AI governing body in an enterprise is having full visibility on what agents are accessing, what they are entitled to, what work they're doing with full logs into the system so that backwards auditability is also available. Mm-hmm.
So as more trust gets established, if I look at the way we work, we have all these different silos around sales, marketing, accounting, whatever it's gonna be. But if we have agents in ai, well at some point the workflows and the processes that we currently have start to converge more. And it might be hard to distinguish where one begins in one ends and maybe we'll need to rethink how our entire organizations are structured.
What do you think? Oh, I agree with you actually. I think, uh, this is an amazing opportunity for each and every of our customers to think north.
So East West. So that's why whenever I am talking to a customer, I first anchor on what problem you're trying to solve. And for that problem, how can ServiceNow help you?
Because as you said, now, if you have a super smart reasoning model, which can understand the problem statement and which can break down that problem statement so that it can delegate it to multiple agents and then orchestrate those agents like a team so that you can get to an outcome, then you're essentially running through various different departments and going north, south, east, west to solve that problem. Another thing ServiceNow has is, like in October of last year, we geared a product called Workflow Data Fabric. Now, what Workflow Data Fabric does is like you can essentially tell us where your data is, and rather than the moving that data into ServiceNow, we access that data in place.
And we worked in partnership with Snowflake, Databricks, or Oracle to create these zero copy connectors. This essentially supercharges what you essentially called out, because if I have access to all the data and if I have a central orchestrator which can use all of that data, I can start solving problems in an enterprise which can go through various different departments. Mm-hmm.
So what is your best advice to organizations right now? Or conversely, what's that one thing you think we should be thinking through a little bit more than just simply rushing out to experiment with every piece of AI technology we find? Well, I think I, I, I mentioned that earlier.
I would say start with the big problem statement, which aligns with your mission and vision of your company, and figure out how will you measure success for that. And then start using AI for it, because then you will have clear KPIs you can measure if you're in the right direction, and you can fine tune it if you are not this way. Like you said, you move away from experimentation and POCs to AI actually deployed in production and achieving outcomes which create value for the enterprise.
So that would be my advice. Alright, folks, you heard in here, if you wanna operationalize ai, maybe we start thinking about trust first and then work our way backwards from there. Hey Kush, thanks for being on the show.
Thank you. Thank you, Mike, for having me today. All right.
And thank you all for watching the latest edition of the digital CXO Leadership Insight series. You can find this episode and others on our website. We invite you to check them all out.
Until then, we'll see you next time. Hello everyone. Welcome to the next of our breakout sessions as part of our Cloud Fridays event.
With this session, we're going to talk about the power of Ansible automation platform and how you can now buy it through AWS and take advantage of some even more, um, powerful solutions Red Hat and AWS are bringing to market around it. I'm Simon Briggs. I work as a Red Hat ecosystem solutions architect, focused on AWS, and I'm here now with my colleague Farley, who will, uh, introduce himself and then explain about the power of Ansible Ansible automation platform.
Thank you Simon. And I am a specialized social architect, specialized into Ansible, uh, mostly working with the ecosystem, but also with direct customers as well. And one of the thing that we have seen is that the kind of issues, the challenges that are, um, seen in organizations are fairly, uh, the same, um, across all organizations.
And the, the issues start with the fact that there are a lot of different people into the organization, different skills, different roles and responsibilities, and that have to handle a lot of different use cases. But the reality is that all of these, um, processes are, uh, on top of the same base, uh, concept, same base, uh, constructing blocks of it, which are compute, networking, storage, and security. And those can be also, uh, physical virtual in cloud on edge, and, and they can be slightly different.
But the reality is that those same components are the one that are, uh, the basis for all, um, architectures within it. And the complexity with this is that if we have automation that is completely different, uh, from one team to another team, uh, the, the result will be that we'll have a lot of duplicated effort as well as conflicting automation that will create problems over the course of time. So the solution to this is to have a unified approach.
Having a unified approach means that we can break the silos, um, across those different, uh, use cases and teams and domains, and have a unified platform that allows us to automate every single use case on every single architecture and using every single component, um, to have that same behavior, um, across the whole organization, which also allows us, uh, to have governance around all this automation and therefore the under underlying it, um, that is, uh, coherent, uh, across the whole organization, which means, uh, that we can have that, um, consistency, uh, across the organization. Now, what Ansible provides is exactly this kind of automation. So what Ansible provides is an increased speed, uh, to delivery because, um, a lot of operations in IT are usually done by clicking on, uh, user interfaces or maybe providing some comments, those kind of things.
What Ansible can provide you is, um, having automated those processes, that means way less clicking and less clicking also means reduce human error because, um, once you have an automation that has been scripted, um, in, in the Ansible automation platform, you can simply rerun the automation multiple times and every time you will get exactly the same result, which is not what you usually have if you have people doing the process themselves manually. So, um, the result of this is also a higher, a higher level of consistency, uh, because of that getting exactly the same result without errors, um, every single time, which allow, allows us to have a more coherent, um, environment, uh, in our it. This also allows us to evaluate, uh, the whole lifecycle of an application and automate the whole lifecycle and of an application.
And you can think about the lifecycle of an application, roughly dividing three different parts. Um, the first part is about the provisioning and the setting it up or day zero as is, uh, often called. Then there is a second part, uh, that is about, uh, the, the operation part of this, uh, the, the visibility and so on.
And then the third part is about the governance, uh, around. So as you can see, we uh, tend to graph it in this kind of way because sly, it's a life cycle, and usually as soon as it, it hands it start again. Um, and Ansible is, um, able to provide you help and support for every single one of those, uh, aspects.
And one of the critical aspect about Ansible is that it allows you to automate, uh, your IT processes in the pub public cloud, uh, in cloud native ways, but also in the private cloud or, uh, on data center on the edge and so on, which means that it becomes kind of, um, lingua franca, uh, across your whole it, uh, so that every item in your IT is configured exactly in the same way, which also means that it becomes easier to cross pollinate, uh, across, uh, the organization best practices, um, standards, uh, guidelines, as well as, uh, for people to move from one side of the organization to another because they, uh, already use, uh, the same tooling at least, uh, for the automation of the processes. One of the critical aspect, uh, about Ansible is that it's not just Ansible itself. The value of Ansible is, uh, all the integration it has with a huge amount of, um, it, uh, partners that we have, uh, which means that you can automate, uh, not only, uh, for instance Linux boxes or Windows boxes, but all the networking, um, parts as well, or the security, uh, across it, um, as well as, um, items on public sa, uh, cloud private clouds edge and so on.
But also it can be integrated with ITSM systems such as ServiceNow and many others. And all of this can be done through, uh, collections, um, which are basically bags of tools, uh, that, that you can use to integrate the automation with, um, that specific IT technology. Um, and we have the concept of certified collections and verified collections, which basically are collections that get provided either by Red Hat or third parties, but are validated by Red Hat at least.
Um, and you can use them, uh, with the security of, um, getting, uh, this, uh, bits from a trusted source such as red. The, um, red Hat Solution, uh, red responsible solution is a strategic solution, uh, because it encompass all the possible, uh, use cases, uh, that are usually found in IT departments. Uh, it's basically first multiplier, uh, for the operation side of it.
And it's critical nowadays, even more probably than, uh, in the past because now everyone talks about ai, AI is great, but AI can be built only if you have already an organized IT department. If you have an IT department that spends all their time, um, around fires and issues, it's going to be very, very hard to, uh, have the, the time and focus, uh, to then work on, um, AI or whatever. Uh, next, uh, big technology, uh, will come out, uh, in the IT space.
Ansible automation platform has been already selected by many, many customers and also, uh, a lot of analysts such as, um, Forrester Garner and many others in this case. Uh, this is the Forster wave, um, about infrastructure automation platforms, uh, that, um, plays, uh, the, that solution which is a p um, as a leader into that space. And this really, um, is a testament, uh, to all, uh, the part that we discussed so far, uh, but also, uh, the, the integrations, uh, that, uh, are, are very, very useful, uh, to all our customers.
So thank you Farley. That's a brief description of the power of Ansible automation platform, the tool itself. And what I'd like to do now is concentrate on how, um, red Hat works in tandem with AWS in our long established partnership to allow our customers to get the benefits of both its capabilities when consuming Ansible automation platform.
And firstly, um, I'll call out something which just talked about. So we actually have an AWS centric collection available to our customers as far explained, these a supported, um, collections of blobs and add-ons, et cetera, plugins, which customers can take to help them augment their playbooks and their automation scripts around this technology. And it allows them to understand the validated framework around which they can most quickly deliver the value of the sophisticated automation that Ally talked about to their organizations.
And actually, if you think about cloud, um, infrastructure and engineering will also, uh, often be working with engineering teams who are working with Ansible, but are also using other automation technologies. Often organizations in the cloud use Terraform, for instance, for infrastructure building and Con, um, set up. And some organizations in the AWS context use, um, cloud formation.
These are both really powerful tools, but they do slightly different things to Ansible automation platform. And because of that, we are able to integrate with those toolings. We do have plugins to be able to work seamlessly with them from our tooling or to call out to, um, Ansible or if customers, um, are completely, uh, new to using automation.
Um, within the, um, virtual environment of hyperscalers, Ansible has the capability to do everything that a customer would need to be able to deliver. But recently Red Hat announced some new capabilities from our AWS platform. And what that is, is, um, described in this visual.
So as you can see, if a customer wants to use Ansible automation platform on AWS today, they can go down the left hand channel here, where they would deploy directly onto AWS using Red Hat Enterprise Linux or Red Hat OpenShift tooling to be able to deploy Ansible that they purchased directly from Red Hat already. But importantly, in December this last year, uh, red Hat announced AWS reinvent and their big global summit each year. But Red Hat is now making Ansible automation platform available in two forms to buy directly from the AWS marketplace.
The AWS marketplace is a very powerful, um, environment that allows independent software vendors such as Red Hat to sell its software like Ansible to its customers, but within the partnership of AWS, this then unlocks a lot of value act procurement capabilities for the customer. It streamlines their procurement. They already probably have extensive, extensive relationships with the hyperscaler, so that streamlines under that process.
And it also possibly unlocks extensive commercial agreements that a customer might have in place already with AWS allowing this, um, purchase to be, uh, recognized within an EDP, for example, or a private purchasing agreement, um, that allows customers to buy in two different ways. Firstly, a customer can buy and deploy themselves in very much the same way that they would if buying directly from Red Hat. So they would just buy the subscriptions from Red Hat, but via the marketplace and then deploy them themselves.
Or they can use a new technology that Red Hat is very proud of, called Ansible Automation Platform Service on AWS that capability is, um, innovative. It is a solution where if the customer chooses to subscribe to the technology through the AWS, um, uh, marketplace, they can very rapidly commission an Ansible control plane, which is fully managed by Red Hat delivered on AWS's back plane, um, technology. And that technology then is available for customers to start deploying execution planes from Ansible anywhere they would like.
This allows customers to use a, um, AWS based Ansible automation platform, um, control environment to run automation across the many different environments that talked about, be it other cloud vendors, clouds, be it on premises or even in colo locations. The use of an execution plane allows the customer to do it from, um, the centralized AWS deployed Ansible automation platform. Either way, the customer gets great benefits from that Ansible, they're able to procure it through the AWS marketplace, which allows customers to save, um, commercially if it's available to them.
And they're also able to rapidly take that technology and start deploying it because time to value within any of the technologies that Red Hat delivers is a very important facet of the services that we provide. And of course, if customers do have buying commitments such as an enterprise discount program or um, a, uh, um, a purchasing agreement with AWS, then you will get further benefit from that approach. I mentioned earlier that you can deploy your, um, managed Ansible automation, um, to AWS, but still be able to deliver automation across any, um, environment you choose to work on.
And this diagram helps, um, explain from a very high level how that is achieved. So on the left hand side, on AWS, we deploy in the managed service, we deploy a control plane of Ansible automation platform and we, um, deploy what are called hot noes to allow the customer to then manage their execution planes, which are represented to the right there. They have the ability to set up an execution node, which then allows the individual managed nodes within that environment to be, um, managed, however the customer wants to secure that environment.
Um, importantly, this is available today. We have many customers using it, but I want to call out. You will see there on the right hand side on the bullet notes that an event driven architecture is the one large feature from the solution set on A A p, which isn't available today available on release.
We are working hard to make sure that technology is, um, consumable, but it, it isn't there as of today. Um, I'd also raise that, um, at the moment, the control plane that customers commission can be deployed to three different regions within ea that's, um, EU, west one and two. So that's Dublin, London, and EU Central one, which is Frankfurt.
Um, those regions deliver the control plane. So we actually have many customers who use an ex execution plane in a different AWS region using it today across emea. Um, but be aware that we are looking to roll out the control plane capability to all the regions that our solutions are available in for other products today.
So that would be most of the regions across the whole of amea, um, very soon. What I'd like to do then is talk about one of those customers who's using the technology today. So I've already said this technology is quite new.
It's only just, um, been announced, um, to the market and we already have customers who are using it. The reason being that ultimately many customers are already very familiar and very happy with the value that F was talking about. Ansible as an open source project and Ansible automation platform as a supported product from Red Hat is extensively used within, um, the IT industry today.
And as such, there was many customers who were very keen on utilizing a managed version of our Ansible automation platform to further extend their ability to concentrate on building out automation from Ansible rather than concentrate on managing the control elements of an Ansible automation platform deployment. Um, one of those organizations is a Department of Work and pensions in the uk. For anyone who doesn't know that, um, department, they're a very large government body within the uk, one of the largest we have.
Um, I say we, because you can probably tell I've got a UK accent and I am resident in the uk. And, um, they have found that through Ansible and then a recent investment in taking on Ansible as a managed service through AWS, they've been able to, um, very, very drastically drive down their ability to, um, deploy technology to the right place in the standardized form that Fally was talking about. So avoiding, um, the challenges that come about with multiple different individuals being involved in a delivery pipeline, et cetera, they've been able to move away from that and have seen drastic reductions in time for deployment.
Um, and they talk about 50 minutes breaking down towards 10, um, for particular virtual assets. They've, um, also talked very, um, strongly about the fact that they've been able to create a consistent deployment environment across different parts of their IT infrastructure. Join, bringing together that hybrid cloud capability that Red Hat has for a long time in messaging the industry about being able to do the Department of work and pensions will always have an on-premises, um, delivery capability.
And what they, uh, do for the uk, they won't move away from that very quickly. So they were looking to be able to, um, get consistency across not only their on-premises assets today, the Ansible usage they've had in those environments, and then extend that capability out for consistency across their very extensive now AWS commitments. Um, and have also talked about in their referenceability on this, um, project, the fact that they found the move towards Ansible automation platform a, um, standardizing effect from their troubleshooting and management point of view.
They're able to use what are, um, essentially very, um, human readable, understandable scripting approaches. They've been able to utilize that capability to take the standardization across the environment to make sure they, they can remove those silos or pockets of infrastructural management that they had previously that would be very difficult for other members of the organization to be able to utilize without that standardization. Now we've added a QR code onto this slide and I've talked to it for some time.
So if you are interested in the detail around that, um, that customer's case study, you can follow that QR code. It will take you to our website where we've got it, um, written up in a lot more detail than I can do justice to it. And you can hear from, um, the DD wps own people about how they found the investment that they've made on this fantastic technology.
What are the next steps? I think you'll be asking yourself at this point, what, what is Red Hat asking you to do? Well, if you are thinking about extending automation within your organization, and if you like what you see about the, um, Ansible automation platform becoming a powerful tool to standardize, um, and take your technology automation to the next level and also use AWS, then we've got a few assets here that might help you.
Again, we've added some qrs so you'll be able to, um, watch this video back maybe, um, take a, a quick read of those links and that will take you to several assets we have within the, um, AWS um, web presence, um, to help organizations get more understanding of this technology stack. Um, the, um, they, the different QRS take you to different, um, documents essentially, um, from explaining the technology itself with the Ansible automation platform on AWS, um, to some labs where you can actually get hands-on experience of driving through the technology if you've never had experience of using Ansible automation platform in your environment. Um, we've actually got a very detailed ebook, which helps organizations understand how to run automation in a hybrid cloud at scale, which obviously is the next next challenge.
Being able to understand how to pull and twist the levers of a technology is very useful, but our guidance there helps organizations understand the different challenges that they will face in taking that technology and running it out into very large production environments, particularly ones that AWS scale will allow organizations to achieve. And there's another document there that goes into much more detail about specifically how Ansible works with public cloud. You're very welcome to use our assets.
You probably also noticed at the starts, um, that Fally and I didn't hide our email addresses. The reason is we're very happy to talk to our customers about our technologies. So if you would like to speak to us as well, please reach out to us at any time to ask your questions.
Just a quick note to tell you about upcoming sessions. Um, this session is obviously part of our fantastic Cloud Friday initiative. Um, if you stay, um, around, we are going to talk about, um, different things.
We are gonna have a, a summary session where we're gonna deal with some of the q and a that arises during all the sessions that we've run during this, um, this Cloud Friday event. And then afterwards we're going to host something called the Networking Lounge. Now, uh, this is totally optional.
If you feel like joining us to have a much more informal personal chat with presenters like f and myself and the other members of our team that have helped today, please use us. And with that, all I need to do is thank you. Thank you for staying on, listening to F and myself.
We've really enjoyed being part of this session. And also thank you for being customers of Red Hat and AWS and we look forward to seeing you more often. Goodbye, Rob.
How you doing? Great to be Back with you, Daniel. Great to be with you.
Good to see you. We were sitting on a rooftop in Davos, uh, having a conversation. And one of the things that you brought up, uh, was your new book, I believe now you've made a lot of progress.
It's out. Yeah, it's out. I remember we were much colder in Davos than I am right now.
Yeah, we were Wearing like winter coats sitting outside, but it's sort of the vibe, right? Exactly. So yes, AI value creators is out.
And maybe to paint a picture of the book there, there's a story we tell right at the beginning of the book and it's about the Statue of Liberty. Everybody knows the statue. If you look up close at her hair, the detail on her hair is incredible.
Like these perfect braids. Everything is exactly precise. But here's the interesting point.
Statue of Liberty was built by Bartholdi in 1870. It was another 35 years before the first airplane. So why did he spend all this time attention to detail on hair that was never gonna be seen?
I think it's just, it's the instinct of an artist, a scientist, to do great work. And we use that to set the tone in the book, which is AI is not just about let's try a thousand things and hope something works requires a little more precision. You need to think through, how am I going to attack this problem?
How do I make data ready for ai? How do I think about use cases? Like we want people to be a little more precise.
And so AI value Creators is really a handbook for anybody that wants to get value out of ai. And we think we have some good stories in there. So good lesson learned.
So we hope people enjoy it. So I have to ask that particular story. Yes.
That anecdote. What was the, what Onur, uh, you know, kind of, you know, surfaced that for you as you were kind of probably looking for that kind of story? What made that one resonate so much?
I read a lot and I always keep notes of like different stories, anecdotes, analogies. So like, I literally was just going through a book of like, it's a number of pages, the old notebooks. Yeah.
And it just came out and I was like, that's it. That hits the mark for what I'm trying to convey. Because at the start of the book, you have to give people a reason to even want to turn to the third page.
No, it's hard, as you know. And so I was like, maybe this incites people to think this is a little bit different. 'cause I think most people expect, they hear ai, they, there's like two camps.
One is everything's amazing, everything works. And the other camp is you must try 10,000 things. And I don't really believe in absolutes.
I think the right answer is let's be thoughtful, let's be intentional. And that's what I want to convey. Yeah, I'm incredibly optimistic, but I think there is a difference, Rob, between being incredibly optimistic about the potential in society, you know, at, uh, milk and, uh, Paul Tudor Jones went on and talked about, you know, he, he, he's an big investor for everyone that doesn't know it.
And he kind of talked about the existential risks of ai. And I think there are the doomsayers out there. It's the same people that are perma bearers in the market that believe everything's gonna fail.
But I think deep down, most of us have come to the conclusion early and often that this is gonna accelerate society. That it's an augmentation, it's a value add, it's gonna make businesses more efficient, it's gonna make, uh, individuals more knowledgeable. It's gonna remove some of the chaotic or wasteful time that we spend trying to find things, make it more accessible to us.
I mean, there's a lot of reasons to be overly optimistic, despite the fact that I think it sounds like you're coming at it for your book with a bit of realism that needs to be balanced. In terms of any, any company or individual looking at ai, I think a lot of people love to talk about the edges or the extremes. Yeah, to some extent it creates a level of attention.
But I think there's two big ones out there right now that I probably completely disagree with. One is the AI's bad. This is a doomsday, I'm not a believer in that.
Two is, there will never be software developers in like a year. All software developers are going away. I think both of those are completely incorrect.
I think there's a nuance in all of this. Will the role of software developers change and evolve? Absolutely.
Yeah. But I am willing to bet we are gonna have more software developers in 10 years than we do right now. Yeah.
What they do day to day may change or evolve. And I believe ai, like all technology has always moved the human condition. Yeah.
And society and humanity forward. It always has. And yes, there can be bad uses, there always has been, but I don't, I don't really believe in the extremes.
And by the Way, from decades of machine learning, there's been uses, you know, we talked a little offline, you know, machine learning is a, you know, is a version of what we really consider in the bucket of ai. People have been using algorithms and patterns for four or five decades now to try to, you know, modernize compute. And by the way, for both black hat and white hat purposes, right.
So, you know, I think there's a lot of just kind of that minimalist maximus view, even that whole, like all jobs will be replaced and everybody's gonna go on UBI, right? It's like, well, if we don't evolve, that would be the truth. I still remember that, you know, I'm looking out at the streets here of Boston and there's, there's sidewalks and, and lamps out there.
And by the way, they used to have to go every night and light the gaslights. Gas, gas. I wasn't around then.
Maybe you were Daniel. That was before me. I bald.
I'm not that old. But you know, there's literally gaslighting when they came up with electricity, everybody thought, well they, that person will never work again. Right?
That person used to run around and get on a ladder and like, yo, you know, we make progress and there's so much importance that we talk about making progress. And, and one of the things, I think your company, by the way, you know, beyond just the book and value creation has made so much progress in sort of thinking about open, thinking about hybrid and really staying the course. I had the chance at South by Southwest to sit down.
Arvin, you and I have sat down a few times this year and you've not deviated at all really since Arvin took the helm of this company on hybrid cloud and ai. And by the way, you were an AI before it was really popular. It was a thing, but it wasn't so popular.
I mean, talk about why these two things are so inextricably, um, linked together. They have to be brought together and you have to bring them forward together. I mean, all the credit goes to Arvind.
I think he had the insight of IBM is a big company, it's a very important company in the world. You can't change strategy every year. So he was looking for what are the trends, the themes that can drive decades of investment.
Hybrid cloud and AI was the answer. I wanna come back to your point on AI for a minute and then we'll get to hybrid cloud. Yeah, absolutely.
John McCarthy, famous computer scientist. It was 1959 that he said once it works, I wasn't Around. It's not.
He said, he said once it works, it's no longer called ai. And think about deeply about what he was saying. He was saying the goalposts are always gonna move.
The minute that we accomplish something, we're gonna say that's no longer ai. And the minute we can do something that's no longer ai. And I think when I, when I hear these, these comments of, you know, we're not there yet, or a GI is coming, I think we forget this basic, anytime we do something, it's no longer ai.
When you watch the movie, um, her, have you seen that movie? Oh yeah. I think that was 2013.
You were watching her in 2013. You're like, if this is actually possible that I can chat with something and it's responding back and it's ai, at that point we'll be an A GI and we can do that today. And nobody thinks we're an A GGI.
Yeah. So the goalposts are always gonna move. What is our role as a business?
Our role as a business is to help clients get value out of ai. And to some extent, which technique they use. It doesn't really matter.
It's what is the lowest cost? What is the highest performance? How do you get to the outcome that's machine learning?
Great. It could be a Jupyter Notebook that's making predictions. It could be generative ai and in many cases it will be.
It's definitely going to be agents as those start to evolve and we go from there. So I think it's about, I'd say the pragmatic approach to AI hybrid cloud. I would say we're just getting started, believe it or not, we're still in the early innings.
I think now every company realizes their strategy is hybrid. They're never gonna all be on one public cloud. That doesn't work.
Especially not when you think about sovereignty outside the us. So we've hit the tipping point, but we're still very early. Yeah.
It feels so opportunistic for IBM every time I sort of hear about why would a company pick to partner with something like AI or especially ag agentic orchestration, and we'll come back to it, but I, I kind of can't really wrap my head around why you'd wanna rate limit yourself either through an application layer where you're gonna sort of centralize all your ag agentic work through a single application or start there. Um, 'cause I, I actually believe there's really meaningful change coming to the entire software industrial complex. I also kind of wanna understand like the comment you just made about cloud.
Like there's many reasons you function in many clouds and some have been more multi friendly than others, but I still think it's kind like they're all sort of designed to keep you on that cloud no matter what. And, and by the way, that's good business. Like, I, I'm not criticizing that, but like you kind of just said it and, and by, by the way, Arvin said something a little different.
So Arvin on the stage said we're sort of past the POC. He kind of said that today in his, in his keynote. He was, he he came up with a kind of, we're, we're past it, we're going commercial, we're going big.
But we really haven't necessarily seen that scale yet. Like what in your mind is sort of preventing some of the clients you work very closely, uh, with the clients? What's preventing clients from getting their, their ai uh, you know, POCs really up to scale.
It is the, um, the classic problem of data, I would say. Okay. It always comes down to either data or skills that would slow you down.
Data unlocks ai. And so once you're able to identify use cases, there is tends to be some level of data preparation that's required to make sure you're gonna get the accuracy, the performance that you want. So that could slow you down.
Second would be skills. Do you have the skills to do this? I think that's why IBM is quite well positioned.
We have a consulting business that can provide all the skills that you need to work with any AI model, any AI stack. And then we have the technology with open source now building applications on top of our open source models like assistance and agents. So that's what the world needs right now.
So let's flip to the macro a little bit. Um, it's been a really wild year. Uh, you know, we did this massive survey coming into the year, Rob, we talked a little bit about a Davos with 211 CEOs of billion dollar plus companies and AI was by far and away the biggest board priority.
Now, April, we had liberation day. We're not gonna debate politics here, but now the number one for many companies has become supply chains. Again, I mean, it did change, but largely what I'm hearing is that AI is lar is tariff proof, um, especially, and you, you bifurcate consumer and enterprise on the enterprise side on the CapEx build outside.
But like you're, you're talking a little bit more to the client's deploying. So obviously we saw numbers Meta is gonna keep spending and Microsoft's gonna keep spending, they're gonna build the data centers of the future. What about the enterprises that you're talking to?
Has there been any change, any halts, any slowdowns, any impact? Or are they seeing this deflationary and seeing it as a go, go, go. 'cause they need to get there?
Maybe two timescales. So go back to January and Davos that you mentioned. Yeah, there was a lot of optimism at that moment.
It was from every CEO that I spoke to. And that was really the view that we think we're entering an environment with less regulation. That's actually true.
We, we shouldn't forget that less regulation is generally good for business. Yeah. So I think that optimism is still there now.
Yes. I think today there's a little more uncertainty and people are trying to decide what to do. I think that's actually a catalyst for ai.
So the biggest change in discussions in the last 45 days has been, we're gonna keep investing in technology. We have to do ai, but we're really only interested in use cases that drive productivity. I'm not sure that's a bad thing for businesses.
It's kind of, um, focus on the basics. How do you get more productive with what you have? And I think that will be the catalyst for this year and perhaps even into next year.
It's gonna be a productivity. And again, I think for AI to work, the more pragmatic and value accretive, the more likely companies will stick with it. So I think this is actually a good thing.
Yeah. I think at anytime, I know during 22 when we had QT and the market really fell, I saw companies get, get sharper. That was actually when I sort of called the AI boom.
I, I remember I went on, um, squawk Box and I actually said Nvidia in July of 22, and it was like down like 70%. I'm like, ai, I'm like, watch Nvidia. I'm like, because the deflationary nature of it, and that's kind of what you're saying is like, companies get smart when when there's excess, when the growth is coming without a lot of effort, you over hire, you over invest, you do more events than you need to do.
You just spend your money. And really good prudent businesses kind of get back to basics when the, when the macro gets a little more complicated. But now we've got a new, uh, potential variable.
We've got agents. So agents now basically can put a company in the driver's seat to say, look, we're going to, you know, augment, assist, displace replace, I'll let you fill in the blank there a number of different roles. And, and, and we're gonna get a ton of scale in our business business.
We're gonna get tasks done more quickly, more efficiently. How does agents change the game? What and how does IBM think about this?
'cause you seem to be in a really good position, uh, with Orchestrate and what's coming next to solve problems for your enterprise clients. So let's talk about how this evolved. We, we started Orchestrate back in 2021, and I think this, I was around then is probably the biggest thing that we've learned in how do you innovate as a big company?
You have to be willing to iterate. At that point, we were really just focused on digital labor. How do we automate tasks?
So we went forward a few steps back, a few steps. We're now four years later, two years ago, we, we brought out Orchestrate, we made it generally available and we actually got a lot of customer traction with automation. But then we kind of retrenched a little bit and we said, there's something happening with agents.
And I will tell you the value in Orchestrate, it's not necessarily the agents themselves, it's the literally what we, I'd call the middleware of agents. How do you get agents to work together? How do you deploy with multiple models where you can use granite for one query meta or llama for another query mis draw for another query.
So that whole orchestration piece, hence the name is where the value is. But we announced an agent marketplace. Yep.
We've recruited nearly 30 ISVs. We have some of the biggest in the world, Salesforce, Adobe, Workday, and we got startups like 11 x simplistic AI who are building on orchestrate and we help create market awareness for them and demand generation. I think we've hit a sweet spot here because clients are gonna come to IBM for every agent.
So we wanna say, we can give you the middleware and then you can use IBM agents or you can use an agent for one of our partners and all of that will work together. Yeah. You're not really trying to displace the partners.
You're not telling the application layered not to build what they're building. You're saying we're gonna make it work better. Yes.
And we're gonna make it work across your stack. Because that's my biggest problem is it can't just exist at the SaaS layer. It can't just exist at the infrastructure layer.
You need these things to really coexist, work together and of course have these handoffs and exchanges and solve a lot of problems that historic automation and IPA and RPA just didn't solve. And I think, um, you've shown some really good results over the years with digital labor with automation. But I do think this the kind of the machine to machine handoff the human in and outta the loop selectively.
I mean, it's exponential, right? I mean, the difference now is you've done something where you kind of did one repetitive task and then maybe added one more repe, and now it's like you can go really fast. Now.
I do think we're headed probably towards some level of disillusionment on agents. And here's the reason. I think there's a view of, hey, agents are amazing.
They will displace all SaaS, all software. I'm actually incredibly skeptical of that. Yeah.
If you think about an agent running in a company, I think we are a long way away from, I'm gonna tell you an outcome, and the agent will decide all 50 tasks and perform them autonomously. I'm very skeptical of that. That could work in some B2C use cases.
I don't think enterprises, they're all too different to say that's gonna happen overnight. What I think can be done is you can start with agents. Now you can execute some tasks.
There's likely gonna be a human in the loop to get started. So again, I would recommend, let's be pragmatic here. Let's not think that this is going to displace everything that you're doing.
Well, I think I, I think the only question I would ask is how fast it goes from where I agree we are right now. And I think you're right. We cannot just hand over the keys.
Um, I've seen some impressive demos, but again, tends to be inside of a sandbox in a controlled environment. You can't necessarily let this thing run free and start making major decisions on your maintenance of your airplanes or, you know, major operations in hospitals. But over time, I think the, the goal is that these things can become incredibly intelligent and be able to do a lot of things and give, give great efficiency to your businesses.
And so you started kind of down the path here and, and maybe we'll finish here, Rob, is, you know, all the wisdom you've gained from your book, the wisdom that you've collected, working with so many customers leading now software and the commercials of this company. What are you kind of giving as your, what's the most prudent advice that you're giving to these companies now because we're, we're, by the way, we're inundated in this stuff, meaning like, we wake up and all this stuff is normal to us, but if you're running an industrial company, manufacturing, if you're in transportation, logistics, oil and energy, it's there. But this speed has to be absolutely overwhelming.
It is. And I think, look, if I sit down with the CEO, I kind of go through the same question in my mind. One is, do you believe technology is key to your competitive advantage?
Obviously everybody says yes to that, but you can kind of tell from the body language is that do they truly believe that? So I think one is, that is a fundamental belief you have to have if you're leading a company, if is can you iterate? Are you willing to put things in production, iterate off of that?
That is a big culture change for most companies. Yeah. Including ourselves, which I think we've gone through in the last few years.
And then three is, can you then start to hone in on value creation and how does this augment my current workforce? Think of companies do that. This is going to be a home run.
It's going to make you a more productive company, better working with customers, improving your supply chain, but you've gotta kind of start from those areas. Absolutely. Well, we're two believers here.
The pace that'll be determined in the future. We'll see next year when we sit back down probably together and have the conversation just like this. Just how far we've come.
Rob Thomas, IBM thank you so much for joining Me, Daniel. Good to be with you. The six five summit is back.
And unsurprisingly, the headline here is AI Unleashed and actually getting value for enterprises with ai. You know, the buildup is fun, the tech is fun, but getting ROI out of it is, is everything. And I can't think of a better person to have this discussion here than Jason Kelly, who is IBM's general manager, managing partner of IBM Consulting.
Welcome to the show, Jason. Well thanks, thanks very much. Good to be here, pat.
It's, um, always, always good to have a conversation with you and I know, uh, the depth in width in which you look at and analyze the industry. Uh, there's always some subtle pressure to make sure that I'm, I'm bringing the, the best discussion I can to you to to and with you. Yeah.
And, and Jason, you know, my, my first slide, I'm, I'm probably gonna do 10 CIO conferences, round tables, presentations. And the number one bullet on my slide is, is ROI and the ROI, you know, you lose track of that ROI and, and things just start to fall apart. I mean, I love the tech.
Okay. Infrastructure's cool. APIs are cool, MCP eight to a, it's, it's wonderful.
But it's like, what are we getting getting out of this? You and your team are front and center, uh, with, with clients trying to, uh, figure this, uh, out. Uh, the first thing I noticed, you know, I was at the, uh, Sam Altman event two years ago out in, out in Seattle.
I was thinking, man, this data, data governance, uh, it's gonna be really, really hard. And I'm, I'm, I'm curious, how do consultants help companies prepare data for AI that, you know, it's hard enough to get the data right in the stovepipes of, let's say HCM, it's a whole other thing to connect, you know, HCM to PLM, to a, you know, uh, all the different, uh, manufacturing systems. How are you helping them?
I'll start with your first bullet that you always have, which is the ROI and I and I often hear the, the first, you know, just so we won't go to the, the o and the I, we'll start with the RR is typically stands for regret. Uh, once someone has started it and not done what you've just said, which is, you know, thought about first the objective they want to go to. So I, I've gotta throw this out there because I'm gonna come back to the data, but it's the business outcome around ai.
Not just AI for AI's sake, not just, uh, another science experiment, but instead, what is the outcome that the business wants to drive? And, and, and I will say that some people also confuse the, the, the phrase use case. Uh, because a use case could be just one off and not a true outcome, which is usually the result of multiple use cases that come together to give a business outcome such as, you know, closing the books faster.
And I'm saying it in, you know, in layman's terms, making sure that everything that shows up on the dock is exactly what we ordered and is at the right price. So I want to say that the outcomes first. Then as you look back, everything should by be by design.
And so when we think of looking back, if this is the outcome, then let's do this outcome by design, starting with the most important part of this. Some would argue it's models, but I don't want to get there yet. Because before we were saying the word models, we were talking about data and data models.
Yes. And so it is the data and you called out some of, some of the, the, the things that do first come up with regards to, to data. You know, how are you integrating that data?
And these are old challenges to you. Yeah. We can hit all the, the, the latest technology, so you're on the right point is data's at at, at the root of it, the, the root of all good or evil.
And in this case it's, it's starting with data quality. You can never get around that is make sure you have data quality that's there. The data integration and data integration could be in those stove pipes.
Yes. It could be in the form and format in which that data is, it could be structured, unstructured, all these things that, that people, as we start saying, they go, oh yeah, that's right. We've said this before with other capabilities.
So I could go down that list and include, you know, I could also, you know, start talking about making sure that the data and privacy, 'cause a lot of people forget about the, the, the data privacy, but also security, right? We start talking about this, security kicks in, and that becomes, um, uh, the challenge and all the ethics that would, would flow around using that data for the, so now I've covered all that list. So if you just chuck Yeah.
Then what I would also have to lean on, and I'm sure we're gonna talk about this, is that that data is generated and stored in multiple places. OnPrem, off-prem, that's one cloud, multiple clouds. So now you have multiple clouds that could be out there, whether it's a AWS, whether it's Microsoft, Azure, GCP, red Hat, and you, you could have that across then just as you, you say HCM Well, well, HCM is it, is it both Oracle, HCM and SuccessFactors?
Yeah. And Workday and many, many cases. Prob probably in a big company.
The answer is yes. Yes. That so you, so you just nailed it.
You're, you just saved me naming like a whole bunch of my other, uh, partners in this because they have these, they are the cause creator and the good part of it, I don't wanna call 'em bad. Yeah. But this is why that pulling that data is hard because now you have to say, how can I work with my legacy investment?
And sometimes my, my good friends, uh, ette says, uh, PTSD, and my quick shout out to all my veterans, I'm a veteran. And when I say PTSD, people think it's military. So shout out to all the vets and current serving members.
PTS is, is is that that debt that we get from process, from the technology, from the systems and the data. So that's what I and I, and people remember that term PTs, but that's, that's that debt that comes with all of those different applications. So, short question, long answer, but it's kind of where we're kicking this off here to say, look, there are multiple players in this, and the way to make it happen is first looking at the data in context of the outcome, and then figuring out how you're gonna orchestrate this by design to get to that outcome.
Yeah. The fractal of applications and infrastructure meant meant the data went, the data got fractualize too. So it's a, it's a huge challenge.
Hey, I wanna, I wanna hit on something that, it's funny. I've been in and around IBM going on 35 years. Okay.
And, and architectures were always, 'cause IBM was there, you know, to build things that were Resilient. I should, I should jump in and say, you've been around IBM for 35 years and you, you suffer from Benjamin Button syndrome because I'm looking at you and it must be good for you. So keep the, I don't know, Jason, our birthdays are within a few months from each other.
I've, uh, you know, I've had dinner with you. You look, uh, you look pretty good, my friend. Um, but there's a lot of talk that, that says, Hey, in this new wave that we're looking at, we need a, an architecture that doesn't just satisfy the next year Okay.
To, to, to crank out some POCs. We need to, we need to scale. And then, and then you hit on it.
Um, there's a lot of legacy systems that, that are involved. Uh, and I always like to say, technology never dies. It's just additive.
Right? That's Right. That's, that's, yes.
So talk to me about, do you help clients plan strategize architect and, and AI architecture that that has legs for five to x years? So there's, uh, the quick answer is yes, though. It's a bit of a loaded question in the way that it's you, you've asked me, pat, because, you know, to say an AI architecture, if that's what the one of our clients wants to call it, they can start there.
And, and we always love to say, look, it's client first with a point of view. So if that's what they're gonna call it, we're going, we can call it that. However, then my point of view with them would be, you're, you're looking at a business capability architecture because you just said at the, the, the, the, it's going to, had I said it was going to be a services oriented architecture and then a blockchain architecture, and then it's a AI architecture.
Is it a different architecture? Well, quite frankly, it, it is, it has evolved. And so I would start with an open architecture and that would be one that would allow them to have that flexibility elasticity, um, in, in what they do.
Um, and that's why I did purposely use the words by design earlier. Yeah. And that's, I I always caution because it's almost, it is not, it's a, the thoughts come to mind.
The words that come to mind are not just flexibility and elasticity, but also resilience and also sustainable. And I mean sustainable in both senses that when you say sustainable, now they think it's green. It's not just that it's sustain.
Like is this something when, when the current CIO and next CIO are gone, are you still going to be celebrating the decision that you made, you know, a decade ago? I'm not saying that that's how often they turn over, but I will shameless, by the way, if I had a bell, I'd ring it and say, shameless self-promotion. We have A-A-A-C-E-O here at IBM, Marvin Krishna who said, Hey, we are going to be a hybrid cloud AI company.
And when he said it, to his credit, a lot of people is like the dog hearing the siren, you're gonna start turning their heads. Like, what does that, what does that mean hybrid? That's that, that's like a car hybrid.
Like what are you talking? So I, I do think this thought of building purposely open as well as flexible and elastic. And when I, when I say elastic, I mean also elastic.
That's for energy consumption because we, we know that there's more compute power that's always going to be needed. So can we always turn it on and, and ratchet it down? And then also finally, um, this is one of those, there, there's two things that are often forgotten when we say architecture.
'cause we say architecture, you and I pat our propeller heads start going and we go, oh, yeah, okay. Yeah, it's true. It's true.
But it's also skills. It's also are we, are we planning to wear our skills are going to be, and making sure that we're skilling towards that architecture. So there is a business arch architecture and capability architecture, and then, uh, in, in addition to, to skills, uh, the, that it fits with the sustainable thing, but this change management that always gets kicked in and forgotten about when we start talking about an architecture because it's like, oh, they're developers just throw pizza at 'em and some caffeine caffeinated drinks, and they'll crank this out in little AI to help them change the code.
It'd be good. But no, I, I do think that those are all the things that, that are by design, based on your question. Yeah.
Hey, I do wanna get a little nerdy here. Um, okay. If, if you don't mind, um, models are fundamental, uh, to the technology.
They're not the most important thing. Um, I, I think, you know, in IBMI give credit to IBM, they were the first company to come out and talk about multi-model, right. Multi-vendor models.
And it just, it just made sense, right? You don't want one or two companies controlling every model. And how on earth can one company have control over a model that does best on CRM or SAP or connecting all these together?
Oh, by the way, last time I checked, enterprises aren't too thrilled, uh, about rolling in a thousand kilowatt rack to, to do, to do everything. Okay. Mm-hmm.
Um, you, you don't have to, to throw, uh, the kitchen sink at every single type of workflow here. So what does differentiate, um, AI model a successful AI model from a production ready AI model? One that can scale, one that can lead to ROI as opposed to, Hey, we had a great pilot, great science project.
Mm-hmm. What are the characteristics to scale at, at enterprise level, or, i, I like to say planet scale. I, I think that you've, you've helped me answer the question in the way that you've asked it, because it is going beyond a single model.
And I, we do believe if, if it's an open model, and we of course open up our granite model is an, is an open model, and you, you look at that and you say, well, well, why? Well, you wanna make sure that you have the flexibility. There's also some sense of, um, the ethics around being able to have transparency and understand, um, that there is, you know, there's not the bias and the things that you would think about inference, but where's the data coming from and what are, what are we, are we using the data that we need?
And as we started to learn, you know, smaller models for more focused outcomes, yes, you use, there's, there's less latency, there's less energy consumption. You get what you want when you need it quick. You know, all of those things that you could, you could say, so I'm saying back to you, this thought of multiple models based on the outcome.
And if you're planning that outcome correctly, then that will help guide, you know, which model I I do and will continue to, uh, repeat myself on this thought of, you know, what are you trying to get, and you said it yourself, you know, is, are you trying to solve the latency of product shipping in your supply chain? Yeah. Are you trying to make sure that you have rich images for your marketing capability?
Are you sure? Are you trying to make sure that you have the right and very timely and right with air quotes around it, and very timely data for customer loyalty? You know, so then you start saying, am I, am I gonna use another copilot?
Am I going to use Firefly? Will I tie into juul? Will I use that with Watson X?
What am I doing? So, so I, I think, uh, as I said, you, you asked a question in a way that I, it really points out is that it starts with understanding that outcome and then knowing that, okay, I can use multiple models based on what I'm trying to get to. Yeah.
The other top 10 list on keeping enterprises from scaling AI as much as they would like to, um, it's really where it started. It's responsible ai and, you know, this can, this word can mean multiple things to many people. I mean, for some people it's, the model gave me accurate data.
Uh, another one says that it doesn't have biases. Other one, you know, there's regulatory scrutiny that based on certain regions and countries are different. And I'm, I'm curious, um, how do you help clients implement the re these responsible, uh, a AI practices through which you're doing in consulting?
So, I, I, I have the joy of saying that we've been doing this for more than a decade. Um, and, and that's, and sometimes you can get a, get a small smirk when you say, yeah, you started beating Watson, or Watson started beating Jeopardy. Yeah.
Back in the day when you say, okay, well great, you, you won in a game show, but it's the game of business. What did you, what'd you do after that? And I'd tell you that those learnings that we had way back helped us understand how to use AI responsible.
And we started, I, I will tell you that back then we started with, uh, AI code of ethics, and we, we said first, although that, you know, that augmented intelligence, artificial intelligence, and we would say augmented often because it's there to augment human intelligence, not to replace it. And that was our first tenant. And our second was that, you know, the data and insights belong to the people or those things that created it.
So those company, those entities that created it. And then finally to make sure that, that the AI that we were using along with the data, um, was transparent and explainable, um, that it could be questioned, right? You could see, so it wasn't black box.
So we definitely start with those basics that we have been doing for a, a more than a decade now, and saying that, yes, we want to make sure that clients understand what responsible AI means. And it does dial back to what we, where we started, uh, with the data and then progresses to the models. Because now as we are thinking and talking models, just, you know, what are those guardrails that you want to put in to make sure that you continue to, to implement and enforce those standards and those values that you started with more than a decade ago, that that includes, you know, as you get, you know, the, the inferences, uh, that you're, you're getting out of those models and where that's coming from based on the data and the data that you're using to gather the inference from and how you're training the models.
I mean, we keep going. Yeah. It's all those, it, it's, it's really taking what we've done before and advancing that into the current, to your point earlier, the current technology and staying consistent because it worked then.
And we do believe, as we tell our client, it works now, but you have to start there. Yeah. It's, by the way, good reminder to everybody.
Ai, in fact, first AI algorithms were done in the 1960s. Um, we were doing AI with analytics, and then we did, uh, AI with machine learning, and then, uh, now we're doing it, um, with LLM and, uh, through, through machine learning, but throughout that requires it to do it in a responsible, uh, responsible manner. Um, last question here.
Uh, what is the role that, that consultants should play, um, to help clients anticipate and manage the, the risk of, of something going wrong? 'cause you could put, you know, the right ROI architecture, you can have the right data, you can have the most responsible AI practice, uh, but there's gonna be corner cases, things are going to happen. Um, these models, quite frankly, are learning how to make sure they don't get shut down or shut off.
Mm-hmm. Uh, there's vibe coding that is injecting is about the, you know, riskiest, um, of code from a security, uh, uh, point of view. What role do consultants play in this game?
So I, I think that the best way to answer is to, is to get rid of the word consultant. Okay. Um, and I would say, what role does a partner play?
How can you be that partner for your client? Because, and even, you know, uh, we could use the other role, you can say consultant, you can say developer, you could say salesperson. And I think that all of those have, you know, we're, we're predisposed to think of what those roles are, and I wanna pull it apart.
And I just say, look, if I, if what we talk to our teams about is, if you're gonna partner with that client, you're, you're, you're gonna tell and not sell. You're gonna tell them, you know, what they should be considering. You're gonna tell them, just as I've spoken to you about the design and the considerations, you're gonna tell them about their legacy and where they want to go, and you're gonna tell them it should be the outcome.
And so I think it's, it's, it's less, you know, in the moment, I know as you asked the question, we could say, you know, how does that apply to ai? But I, I, I, I have to go back, I think it's even, it, it's simpler than that. It, it really is easy to say, but becomes even more complicated to do with all of the moving parts.
So I think that driving this thought of disciplined partnership and looking across an agentic ecosystem, and so now I will get to the answer to the questions that I think that, that ag agentic ecosystem, when I see it, people think multipart multiagent agent interaction. Yes. And I don't mean just that.
I mean, what's behind that? What's the ecosystem behind that, which does include the data sets, that does include the architecture, that does include everything that we have just described. So I'm glad this is your, you know, you said this, the last question.
It really, it pulls in that fact that it is an agentic ecosystem of multiple players, of architectures, of models of data and outcomes that we have to drive toward. And that's what we ask our team, team members to do, is to partner with our, our clients to make sure that they cover all of that. And that it, at that point, you can build through very trusted communication, the outcome for that client.
Yeah. Jason, um, I, I hear a lot of companies throw around throwing around the partner moniker. It, it's where, it's where people, uh, uh, want to go.
I, I've been in and around kinda IBM long enough to to know that it, it is, it is a reality for you. Uh, some of your customers have been doing business with you for 50 years. Mm-hmm.
And there's a lot of trust that, uh, that goes into this. Um, a lot of the app, the core applications are some of the most sensitive and risk tolerant that, um, that, that, that are worked on. So, um, I don't view it as a throwaway line, even though everybody uses it.
I know you, I'm, and I know your company. I'm glad you're saying it so that anyone listening to this going, okay, Jason, that was like a, a, you, you just pull that like, oh, I want to be a partner. And I do have to, I almost have to say, yeah, it's kind of cliche, but it, but it really isn't.
Now, if you want to get really cliche since you've been around, you know that our, we had three simple values and it was part of a session back when, you know, it was a big deal for everybody to get online and communicate. We called 'em Jams. That was 2003.
Someone's gonna Yes. Fact check me. But we, we said, what are our values?
And the one that first, first one is innovation that matters for, for our company and for the world. But on this point that you're talking about it, it's dedication to, to every client's success. Yeah.
So that's the first thing. And then you said it best when it said, when you said, you know, what do we do? Well, we have trust and responsibility in all of our relationships, and that's what this partner means.
It means that I'm gonna partner with my partners that are in there. So when it's a a, a Salesforce SAP on Azure, with all of the AI that would come with that and, and Adobe for Firefly, you'd say, yeah, okay, I'm gonna partner with them with trust and communication. And then we, as we as IBM, would orchestrate that relationship for our client.
We would be the trusted partner with our client. I appreciate you saying that. I, I love, I love that, that final piece there, Jason.
Man, thank you so much. I, I really appreciate. It's a great, great session.
I'm sure people got a lot out of it, so thank you for your time. Hey, anytime Pat. Time flies when I'm with you.
So you just gimme a call and we'll, we'll do it again when, whenever you're ready. Take care. Aw, thank you so much.
So thanks for joining us here at the Enterprise AI Spotlight for the 6 5 6 5 summit. We're here in our sixth year. Pretty excited about that.
Uh, stay connected with us, uh, on our website, and we're gonna have more conversations, more insights coming up, stick around.