Techstrong TV August 22, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. There's something rotten in the cybersecurity business, and we're gonna talk about it here today. Ciso Paola on Textron Gang.
Hi everyone. Happy Friday. It's Alan Shiel and we're here to do Techron Gang.
And man, I've got a loaded, a loaded gang handpick people because we've got some important stuff to talk about today. I, I mentioned the CSO Paola issue. I think it's, there's a stench rising from the cyber industry that we need to address and we need to address it head on, and I've got some great cyber friends to talk about it with, but we, we've got more than that to talk about as usual.
Let me introduce you to my, it's, it's a lo I feel like we're loading the Supreme Court, our loaded gang for today. We've got, uh, returning, she's been away a few weeks from us, but our friend Lisa Martin, our cyber triumvirate of Fred Wilmot, Jack Poller, IRA Winkler, welcome gentlemen, and our editorial team, crackerjack editorial team, John Swartz, Mike Ard, the, the Bernstein. And, uh, I forgot Bernstein's call wood word, Woodward wood word of of, of the tech world.
So, so lady and guys, I wrote about this last week. I, you know, it, it's been the, the stench has been wafting through the cyber channels for a while now. I saw it, a lot of black hat though.
I've spoken to a bunch of people about it. I've seen a lot of LinkedIn posts around it. Not a lot, but enough.
And it's something that I, I think we knew was always has been there. I just think that somehow along the way, and maybe it's because of our present situation where we, you know, we used to worry and think bribe bribery was wrong, and we used to have like ethics rules and, and ethics seems to be gone way along with the diversity inclusion and all of that stuff. But in cybersecurity, we got a, we got a CISO payola problem.
We've got different levels of stench and wrong. And here's how I, I look at it. First of all, there's just a flat out what I call bribe.
I'm a CISO at a global 2000 company, and this extends all the way up, by the way. But I'm the CISO at the Global 2000 company, and you are a security vendor and you spend a good chunk of your marketing outreach dollars trying to reach CISOs. And you say, you know what?
I got a ciso, I don't wanna lose them, Mr. Ciso, what do I gotta do to have my product selected for your company? And it may not be flat out cash, though.
I think sometimes it is, it may be a bribe in the form of can you be on our, our advisory panel and you know, we're going to, uh, give you some stock options. We're going to give you some, we'll pay you for being on the advisory panel. We'll, we'll give you some other perks, right?
Yeah. How, Sorry, Hear me out. So that, that's, that's almost benign, right?
Then worse than just someone giving you pure money. But then there's other flavors of this. There's CISOs themselves who have said, let's cut out the middleman.
We don't need someone to give us an advisory panel. We'll form our own CISO group and we'll have vendors who wanna come pitch us and we'll charge those vendors 25 grand, 50 grand, a hundred grand, depending how many CISOs I got. And for that a hundred thousand dollars, they're in our club and they can tell us about their products and do their companies know if I picked that product or not?
Well, that's wrong too, right? It's just another kind of wrong. And then there's different variations up and down this, this whole thing.
We need a code of ethics for ciso. And it's not just the CISOs. I don't blame just the CISOs.
First of all, it extends beyond CISOs, up and down. It goes to CIOs, it goes to people below the sea level, anyone who has decision making. But I blame the vendors too.
The vendors are so desperate to get these accounts, and they all want to meet the CISOs. And once they meet the ciso, they wanna land that fish in the boat. And sometimes you gotta put out a lot of chump.
I'll throw it to the panel ira. I know you want to go first. Well, yeah, and let me be very clear, and I will be, you know, disclosed.
I am on advisory, um, panels for companies. None of those companies, by the way, I use as a vendor, just to be upfront with you. You know, I hope, and I was approached by one, a company recently, and it's like, well, we went to as an advisor, but our advisors are limited to customers.
I'm like, no way in hell. And that is a problem in this industry where people think it's the Silicon Valley way for the most part, that you have a Silicon Valley company and what do you do? You throw them stock options for mm-hmm.
Something like this. If you happen to be there, there are ethical ways to do this, you know. And again, for example, when I, I will, again disclosing I will, I'm on the advisory board for CSafe, an awareness related company.
And when my company was looking for awareness, I basically said, here are four vendors, which were legitimately the four, four vendors. And I abdicated any decision making responsibilities to the head of GRC and said, I'm staying out of the evaluation process. I'm staying what?
You know, all that sort of stuff. And they made a decision. It was the decision I frankly liked.
I didn't tell them what my decision was or whatever. But that's how it is. The outright bribes, there's no, I mean, I think it's a crime, frankly.
If you are, if you are an executive of a public company and you throw business to someone and get a, that, I think there's SECI Think it Used to be, it used to be a crime. I don't know. I'll Leave it there.
I can go on for so many different ways. But, um, you know, I, I'll, I'll leave it there. 'cause I've been asked that I turn down in some because of implications.
But at the same time, if you do it right and you're hands off, I will only be, uh, on an advisory board that I do not have decision making ability over. And if I have, I abdicate my responsibility for that. Jack, some other folks in here.
Jack, how much of this are you seeing or hearing, or can you confirm what Alan's talking about? Yes, and this, this gets my, you know, this is one of those topics that I think gets a lot of people's chili on fire. Mine, particularly, uh, as an industry analyst, I talk to a lot of vendors and customers, and I hear it from both sides.
And as Alan said, there is a big stench. And for me, it, it really ranks wrong because for many years, the industry analyst industry has also been accused of being paid to play in order to get ranked in, in a vendor competitive match quadrant wave or whatever. There is this perception that it is paid to play when it is very clearly not.
And, uh, you know, one of my mentors, Steve Dusi, the founder of ESG, said, if you wanna get ranked higher, upper, and the right, build a better product, right? It's not about paying the, the analysts. And the same thing from the vendor perspective.
If you really need to get attention of the, the users build a really good product. The CISOs that are soliciting, and I've heard this, uh, as Alan said on LinkedIn, and in a couple of private back channel conversations, the CISOs that are doing this are violating their employment contracts by soliciting business, right? That means that they have dual loyalty.
So you have a loyalty to their main employer and to whoever's paying them for business. And that typically violates your employment contracts at a C level, if not a regular employee. So there's a, you know, aside from the broad, broad aspect, there's a whole lot of legal and ethical implications that really bother me.
And it's eroding the trust of buyers and the cybersecurity industry. And I think that's the really big challenge, is the origin of trust overall. Agree.
Yep. Fred, you're a, you're a c you were a ciso, right? You've been on both sides of this way in here.
So I think this started from a good place. Um, you know, and the YL venture sort of, uh, approach, which is if you wanna really get a good understanding about product market fit and product validation, you surround yourself with a bunch of people that understand the problem clearly. And what that, as an example, has evolved into is sort of, uh, you know, ciso super groups, which, you know, in Avan, um, you know, status of access and, and gatekeeping, right?
Provides a vehicle for people to take other opportunities aside from just the access part of this problem. And the, there are little title pools of this all over the place. Um, and talking with some good friends this week, actually, this is a topic that, you know, high integrity CISOs, you know, vehemently have an issue with.
Because ultimately, if you want a seat at the table, right? And every CISO wants a seat at the table, uh, this will quickly as an industry remove the access of CISOs to have seats at the table because of it. And, you know, the, the conversation about where CISOs fit with respect to CIOs is also, you know, relatively, uh, impacted here.
So, uh, on the vendor side, um, you know, a, as a startup, right, how do you maintain your integrity when you're trying to get something that you believe is useful as a product or valuable in the market or what have you. If you don't know the secret knock, if you don't have the funding or the wherewithal to, to grease skids, to influence, to, you know, go to Iceland to have these, you know, a cool CISO outing to talk about whatever war stories and as this glitter associated with it, you know, it's, it's a tough spot. So, you know, when you think about the best product doesn't always win.
You know, now an organization has to have some realization that their best product may not be winning in that particular case. And that organization that, you know, that CISO may represent is possibly losing some sort of quantitative value that helps reduce their risk. So, I mean, it's pretty rotten.
And I think that some of the folks that are at the top of this echelon see this as a potential and a significantly influencing damage to the industry reputation for the role itself, and has implications across the market segmentation for the best products winning today. I think that been here, I'm sorry, what? Mike?
I said, Lisa, you wanna jump in here? You keep nodding your head. Yeah.
Yes, yes, yes. So, so I, I totally agree. I think, I think that that Jack and front hit it on the head.
What I was thinking about this is that you wrote in trust factors. Jack talked about when relationships are cloudy, no pun intended or, or not clear, that can lead to skepticism and mistrust. And that can make it challenging for other ethical vendors to build credibility, to establish meaningful relationships.
Another thing, Fred, you had talked about was damaged brand reputation for those unethical vendors. And that can lead to negative publicity, lost credibility, but it also helps to, or not helps, but it also can overall, even for the good guys, decrease credibility of marketing messages. When, when those CISO vendor relationships are cloudy or opaque marketing messages from vendors, even the good ones can be viewed with skepticism or they simply won't land.
So if that payola comes to light, CISO's organizations may question the validity of claims of accuracy of data from other vendors and question their motivation. So I think, and I also think ultimately this can have a negative impact on sales and revenue, which is critical for organizations. So I think that, um, from a messaging perspective, from a marketing lens, that's what I saw with this.
Would, Would that a, Alan, I, Ellen, go ahead. Um, can I ask you a quick question? Sure.
Um, so this has Been around, or it's been lurking in the shadows, and I'm wondering now that we're hearing more about it and we're talking about it, is this a byproduct of social media exposing things that used to go under the radar? Or are we just normalizing scandalous behavior given the circumstances? I mean, I think if I were to answer that, because we're not the, like Fred touched upon this, but we're, there's the VC element to it.
He mentioned YL Ventures in starting that. Now, YLI know them, I'm not on their board. I think they're an ethical group of people.
Knight Dragon, for example, also has this, you know, my company was in the process of raising funding and Knight and, sorry, so one of the VCs was put trying to figure out, and they put us in front of a group, one of their, you know, a group of their advisors. And essentially what happened was, yeah, they took a look and they had, they gave feedback. The issue though is how are these people being rewarded?
Because the most valuable thing a CISO has is their time. And I'm not saying rewarded, like, you know, I want, I demand money. But what happens is, like, so companies like YL, like Night Dragon, like teammate and others for their villages or whatever they call them, they have events that are frankly not sponsored by the vendors, but are sponsored in some level of reward.
And it's kind of, I don't know if you say it's murky to be part of this, but you don't get any direct compensation. Like apparently other groups were accused of in the VC world. I had one CISO who once wanted, when I said, do you wanna look at my company's stuff?
The guy sent me a link for, I think it was $2,500, but it was for a charity. 'cause he appreciated the fact his time was valuable and he wasn't taking the money himself. Now, is that questionable?
I, you know, I understand the intent, but you know, at the same time, we're paying to get in front of him, you know, for a way that's whatever. He didn't get it directly, but it, there, there is the, I do recognize the fact his time was valuable. Was that the right way to approach it?
I'm not sure. But again, there's a difference between, I would have to say a group of CISOs saying, pay us to come in front of our group, which is, I mean, I don't know where that money goes, which is a big question, but, you know, you have to look at the time factor for CISOs, the reward, direct compensation, indirect and so on. And it's a very complicated issue to do it right, and even do it along, like just stay kind of, sort of off the line.
And, you know, and again, to Fred's aspect, how do companies, I mean, I get like literally 30 messages a week saying, we'd love to run our product by you. Like entrepreneurs are doing this. Like, Hey, if I gave 30 minutes to everybody, it'd be a full-time job at this point.
Yeah, It, it would be. And that, and that's a dilemma. It's a legitimate ira, the legitimate thing that you're talking about.
But let me, John, let me go back to your point about why now. Why now, I will tell you that historically, I know people, friends of mine who were CISOs at large companies, Yahoo, other companies who were tainted with Scandal in that they got pitched, they got buy buyback for picking a particular product, and they kinda left. And they had to go, you know, in the finest US tradition of the time they had to go into rehab and, and rehabilitate themselves.
And they came out fine on the other end of eventually, but it used to be a, a pretty clear line of what was wrong. It's been eroded. YL Ventures is a upstanding group.
I I know the guys, you know, Jo and the rest of the team there, they're good people. The Night Dragon is, what's his name, Dave de Walton them. Yes.
Good people. Mm-hmm. But what you've set up is a system where vendors will literally do anything to reach CISOs in the cyberspace.
And, and I don't think this is just confined to cyber. I think the same goes for CIOs. It may even go for CMOs.
Right. Well, let me just say, sorry, my, I I need to go on this rant just for a quick sec. Go ahead.
I think there's too much. So there is, there are some CISOs who are their bulk of their entire cybersecurity program. But I think the biggest problem is vendors need to understand that they need to become magnets and be able to pull people in and not just go for CISOs, but go for the people in the middle.
Because when I was chief security architect at Walmart, I'm the wrong person to come to, even though everybody was harassing me. Because it's the people at the lower levels who understand the needs. And you gotta find those people, people you won't give a squishy toy to are gonna be the most valuable people, let alone the CISO you're gonna give cash to.
And so you need to un they need to understand really a legitimate company, lets the bottom, you know, have pushes vendors from the bottom up. Yep. So we Wait, wait.
We all get the, that there's an issue here, but now the thing I'm not hearing is what's the fix? What do we need? So I I I, what I think we need is some sort of ethics code for C-level people.
And we used to have these things that I didn't get a chance to finish my thought. I'm sorry, sorry about My thought is, is that we, I as a society, as a civilization, especially here in the us, have seen a tearing down of our ethics, a tearing down of what is acceptable. People used to be civil.
There was, there was a code of, of, of conduct a moral clause, if you will, of how one does business and what's right and wrong. And this has, this hu this whole, that's all been torn down. It's all been torn down.
And just go on your, your favorite social media thing and, and say whatever the hell you want. And whether it's right, wrong, a lie or not. And that contributes to the moral turpitude of our whole situation here.
Right? We need a code of ethics for CISOs, Alan. There's a, there's a hell of a lot more money involved now too.
I being Well, There is, there is. That's what I was gonna say. This, this, this goes beyond the CSOs.
I think we also need that code of contact for conduct, excuse me, for ance. Yep. One big issues here.
And you know, you guys asked about why now, why now is because the cost of doing business is getting more expensive to show up. Ira mentioned squishy twice to show up at RSA among 650 or 750 other vendors, vendors on the convention floors at a minimum 50 k for a small startup, if you're, you know, if you got, you know, it's 50 k just to, to show up on the show floor, a hundred to 150 K for the event. If you can get in front of five or 10 key vendors for 20 for, sorry, customers for 20 k, that's an easy ROI question for the vendors, right?
From a, a marketing and a, and a sales lead perspective. So we need the vendors to take on some ownership and responsibility and say, we are not going to participate in any play to play activities as well. That, Yeah.
Let me challenge you there, Jack. I think that's you, you can't ask vendors who are solely, uh, focused on generating revenue, have investors that are solely focused on generating revenue, have scale problems that require generating revenue to take an ethical approach to how they sell when, you know, the other side of the fence is not ethically, uh, consuming. It's a really hard, it's a bitter pill to swallow to make that statement.
But I would agree. I I think it has to be both. I don't think, I don't think it can be one or the other, both sides of all sides of the problem, right?
Yeah. I mean, but the fact is, a lot of this is criminal. I mean, we're sitting here arguing ethics.
We shouldn't have to argue ethics when essentially bribing somebody of bribing an executive of a fortune of a publicly traded company, let alone fortune ranked, is there. And even in private companies, it's still technically bribery and it's still kind of borderline criminal if we're even talking border. I don't think we need a code of ethics.
You know, it's wrong to approach someone and say, well, let's kind of sort of do hide the money or whatever. You know, it's, it, it, sorry, I'm just, I just don't accept the debate that it's ethics. I, I argue it's kind of criminal in some of the cases.
Are there, I I agree with you. It is criminal. If you had a criminal system that was gonna pursue that kind of thing.
But when, when you have a Congress that does inside a trading based upon insider, not insider, when you have a Congress that trades stocks based upon perhaps confidential government information, and it's not just Congress, it extends to all of government. You know, again, this is all, none of this happens in a vacuum. Mm-hmm.
It's a societal issue. We live in a, there are no rules laissez-faire, you know, this is, this is the proverbial give the capitalist enough rope, they'll hang themselves. Well, I mean, there are other choices for people.
Like, for example, one business model is cresting way former CIO of Blackstone, and he gets CISOs together. And much like, it's kind of in a similar vein to CISO society or mer uh, Merlin's thing where they have panels of CISOs, they together not compensated, and then they bring the vendors to present to whichever CISOs are there. And then their model, this third party vendor is essentially taking the profit, doing the matching the companies have to pay.
There are legal models for doing this. Yeah. No, there are legal ethical ways of doing it, but who's the policeman here is my question.
I mean, in, in theory, yes, there should be a policeman for doing this. The reality is these crimes are hard to detect. They're not in many cases above the line crimes, which is unfortunate.
But, you know, I mean, these products should be shunned. Like, if a vendor has said, Hey, take it, you know, we'll make sure we send you on a trip or something. I'd be like, hell no.
And then I would blacklist the vendor. You know, it's, We used to do things like that. Guys.
We're counting up on the 25 minute block here on this a block disturb. Alright. You know what?
We, we will, we will discuss this more. Ira, Fred, Jack, I, I've, look, you know what? I'll be honest with you.
I think it takes a set to come out here and talk about this openly. And I appreciate the three of you coming out here and talking about this openly, right? Because all four of us, we, we live in that, we live in this community and we all have friends who, who are on both sides of this, probably, unfortunately.
And, and, you know, physician heal thyself. As an industry, we need to heal thyself with this. I am going to, and I, I know you are hooked in with the good folks at RSAI am as well.
I'm gonna ask them if we can't do something at RSA next year about this. Hmm. Well, deadline is Monday, I guess so.
Well, I'll, I'll they always extend, you know, but I'll, I'll call, I'm, I'm gonna write to our friends there today because this isn't done. You're watching techron Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back.
And the next block is, well, cybersecurity related as well. But the UK government has said is it's no longer interested, I guess in getting a backdoor into the Apple iCloud. And this has also been an issue here in the United States where government officials are saying Nvidia should have some back doors and a kill switch.
And this conversation comes up almost every two or three years, I feel like. But Fred, um, what's going on here from your perspective? Is this kind of a serious conversation or is this kind of noise in the system?
Um, great question. I think it is pretty much noise in the system. You know, in, in 2018, we had a huge upheaval about, uh, super micro devices that had, uh, erroneous chips on the motherboards that Apple and Amazon had to answer for to the federal government.
Uh, you know, we know about Huawei, we understand that there are a number of vendors and chip manufacturers that have questions and are issues and backdoors are in essence, you know, something that I think ha have political fervor depending who's in, um, who's in, who's in the o uh, the Oval Office. But the additional part of that is the assertions of things like, uh, terrorism and, and, and, uh, sexual abuse and things like this are the reasons for having that. We already have full transparency as part of the five eyes amongst the organizations who would be concerned about it.
So I think there's a little bit of saber rattling. Also, we've created some distance, uh, with England, unfortunately. And so this is one of those, you know, do we or do we not sort of press the buttons here?
And I think that's really sort of a political sentiment more than anything else. Mike. Hmm.
Jim, what's your take here? Because, um, we also hear concerns that, you know, gear come outta China has unknown back doors in it, and we don't know what goes on with that. And, um, is this gonna be one of those, everybody's gonna want their own backdoor because well, it's and cyber espionage savvy to do so.
I think the a, everybody wants their backdoor. They've always wanted their backdoor. We have as, as Fred mentioned, we have mandated backdoors in our telecom industry for five eyes.
And that was what was exploited by salt typhoon. So the, the concept that a backdoor is just for the government is false. A backdoor is a back door that anybody can access, not just the government.
I think the concern, the big concern I have and a lot of people have is that the, the British government's desire was to get access to WhatsApp and Signal and, you know, apple iMessages, quote unquote for terrorism. But once you mandate a destruction of end-to-end encryption on a messaging platform, you've mandated destruction to end-to-end encryption for every platform everywhere. Which means now all of your cloud end-to-end platforms are no longer end-to-end.
They all will have back doors in them. They have to, because that's where the data for iMessage or whatever is stored, right? And all these things is on the cloud platform.
So now all your business requirements to have end-to-end encryption and not have the cloud service provider have access to your encryption keys is gone. So does that mean the end of cloud services for England? And I would venture to say that if, if Amazon and Microsoft were, and Google were aware of this, you know, were serious about this, they would say so that they would come out and put a stake in the ground and say, Hey, you, you implement this stuff.
We just won't have hot services for you guys, particularly for the government services. And I think that would help put an end to this. Well, I don't think that's ever gonna happen.
Nobody's gonna say, I'm sorry, Mr. Government who potentially gives us billions of dollars a year. We are going to exclude you from doing business with us, or we're gonna give up an area of the world.
The reality of the situation is, from my past perspective, how I, I worked for NSA, let me disclose that. And how many people remember the clipper chip arguments in all this where I would originally started. I mean, I remember like, you know, like everybody arguing about the clipper, we do have, fundamentally, here's the issue.
We do have legitimate concerns that everybody wants to hear about getting into terrorist communications. And the reality is, everybody is up in arms in general. There's the pendulum.
Everybody's up in arms until there's a terrorist attack. Then everybody's like, why didn't you do something? And it's like, well, we didn't have this.
It's like, why don't you, it seems like law enforcement should have that capability and everybody swings the other way. 999% of the people just don't care if people have a back door. And so the government wants it, the government's probably gonna get it because they have the finances and they have the ability to put restrictions on a company.
And that is gonna drive the company to make decisions as long as it's somehow defensible by, have never seen a company actually put their stake down and keep with it and still be in business to this day without changing that. You know, IRA, the only people I ever heard b****y moan about back doors was the government themselves, right? When I first started selling to the federal government, you know, the, this was security stuff.
The, the rumor, you know, the, the, the u this, the US federal government, especially the DOD would not buy Checkpoint, would not buy Checkpoint, and Checkpoint was kind of the first big Israeli cyber company security company. They wouldn't buy Checkpoint. 'cause the rumor was the Mosad had a back door into Checkpoint, and so they wouldn't buy it yet, didn't stop Checkpoint from being, you know, the second most popular security company at one point out there, right?
And, you know, and, and, and really setting the mark in the firewall market. Um, but other than the government, no one seemed to care. You know, and I think I was right.
You, you know, you'll get some privacy people who get their panties tied around their necks about it until something bad happens. And then you go the other way. And you know, like after nine 11, for instance, and, and allow, you know, Leo to do whatever they want.
Is it not caring or is it just not knowing? Because Lisa, I can imagine a conversation that goes something like, well, suddenly some buddy in Italy wakes up and says, wait, let me understand this. Trump has a kill switch for our IT environment.
I think what's really important here from a reputation management perspective is transparency. And that's one of the things that we're not getting because transparency demonstrates a commitment to addressing the concerns, to maintaining a positive brand reputation. We talked about trust in the earlier segment, and I think by openly addressing allegations, providing reassurance, these companies have to build trust with customers and partners.
They have trust with customers and partners. It can be eroded with this and stakeholders. So I think what they need to be doing is really approaching and addressing security concerns that can differentiate them from competitors, help them maintain the trust they've already earned with customers, with existing customers, and help them earn trust with prospective customers.
But it always goes in marketing and, and for really across any organization, I think that transparency is currency these days. And that's one of the things that we're not seeing. Well, Lisa, can I ask you a, you know, legitimate, what I think is a legitimate question.
How is a company saying we adhere to British law? You know, not being transparent, not eroding trust. I mean, saying we are going to snub British law would, I think, be more of an erosion than the other way around.
I agree with you. I understand what you're saying there. I think that, but from an, from an end-to-end encryption perspective, if companies are saying, we're not gonna do this, you guys can have it.
You guys can't have it. It's, it's undermining trust globally. And I think that's where reputation damage, branch damage can happen for an organization.
It needs to be blanket and where it can be so that that trust is maintained. And people understand, like the, the, those of us, like me, your data's protected. It's not gonna be shared with the UK government.
It's not gonna be shared with this organization. I can't hack into your iCloud and get your information. That's what people need to feel secure about.
Yeah, I wanna, I want to come back to some, I really wanna touch on some of the stuff that Jack talked about, but Lisa, what you're talking about is piercing a veil that isn't really, I mean, there's a lot of artificial sentiment about what that actually is versus what it's, and I think you're right, but you know, if, if you told everybody the world was ending tomorrow, right? Um, what happens, right? Chaos disorder, mayhem, whatever, the world may end tomorrow, right?
Or, you know, as my mom loves to say, everybody wants to go to heaven, no one wants to go to tomorrow. In this particular situation, everybody probably has some understanding of what it means to compromise, you know, their, their privacy. Uh, we have a whole set of infrastructure set up in the EU now that really makes it hard to do business.
The cost of doing business is as much a factor here as anything else. But something that Jack said that is really important to talk about here, this stuff exists, right? And whether or not it's, it it's accessible to different organizations or to different governments.
If you look at what's going on in the CHIPS Act right now, if you look at the potential investment in Intel, if you look at the potential, you know, requests by, by our government for Nvidia, there are many more things at play here about global territory. And I think that's the piece, right? Jack touched on this briefly about what that means, but the integrity of who's doing what type of, of, uh, trade craft, uh, and analysis on that data is something that we've already established a collective to, to support, uh, as a, as a country.
Everything that is outside of that is literally outside of that. So when we have conversations about whether or not you can put something in Telegram, which we don't own, right? That's a conversation.
When we have a conversation about Zuck and his AI premises and the things that go with it, that's a conversation. What are we allowing China to do as a result of that, which we've talked about before. Um, but I, I think there are several things here, and every time we talk about how do we think about the transparency, super good call out, Lisa.
That's what every American or every citizen wants to know. There are just some things that are never going to be true in those terms that we will never understand. And that's why I say it's piercing the veil.
Yeah. Randall, Um, one more question thing, Alan, which is the, the regulations in the EU that exist today, like GDPR and particularly on data sovereignty regulations were inspired by the US Patriot Act after nine 11, which gave the US basically the ability to pierce encryption and get access to European company company data stored in US cloud service provider services because it was owned by US cloud service provider. And so the reaction was, well, we need data sovereignty and we need to have that stuff stored outside of the US in the EU so that the US government can't get to it.
The irony here is now they want to get to that very same data themselves. Yeah, it is ironic. Guys, I, we gotta, we went too far and too long in the first session.
I gotta add this one, I apologize. But we, we've got one more, uh, block coming up here. We're gonna talk about AI misfire.
We can't have a show without ai. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of Security Bloggers Network. Hey folks, we're back. And is Anna alluded to, we are talking about AI misfires as a much talked about report this week from MIT talking about how nearly all the AI projects, at least the internal ones that they tracked felt, and people are saying, well, is this another indication that this AI stuff maybe is not just over hype, but maybe, uh, just not quite.
It is the promise and the vision. John, you covered this. What's your take?
You know, so I have mixed feelings about this. You know, the 95% gets your attention, of course. So MIT has this report, which has since had metastasized it kind of into, uh, roiling the markets.
It prompted Sam Altman of all people to warn of an AI bubble. There's even some naysayers, or some would say short sellers referring that NVIDIA's results are gonna fall short when it reports next week. Um, this, this report basically says that 95% of generative AI pilot programs that companies have little or no impact on the bottom line, but there's a lot of nuance to the reports.
An issue isn't really the quality of the AI models, but this learning gap for tools and organizations, in particular, these flawed enterprise integration. There's talk of the impact, the negative impact of shadow AI and the ongoing challenge of measuring AI's impact on product and productivity. It, it's, in a sense, it, it, one executive I talked to, um, a gentleman from Sitecore said, the high failure rate isn't a sign that Gen AI doesn't work.
It's a sign to most organizations that's still learning how to make it work. There's also some sentiment of thought that the areas the money's going into or the projects that are going into are the wrong areas to invest in and to get products or productivity from. So we've got this, this whole kind of report kind of overtaking and creating a new narrative.
And I, I spoke, uh, yesterday to Daniel Newman, our, our fearless leader. And he, um, he has very strong opinions and I think it, it's, it, his opinion is that this, this report basically has had far too much influence. Again, you know, it'll probably be forgotten within two days and the Marcus will correct themselves.
But I think there, there still is some doubt about ai. There's a lot of murmuring still about this AI bubble since so much money's being put into it and being invested in it by big tech in particular. It's an, it's an interesting touchstone.
The timing of the report was really good in terms of maximizing, uh, coverage of it and, and raising some issues. Hey, Lisa, what's your think here? Because it did royal in the markets and all the marketing people are probably flipping out.
You know, guys, I'm gonna come at you from a marketing perspective. I have the luxury of talking to CMOs every week. I've spoken with about 20 recently.
I had 10 of them over for dinner last week. They're marketing is a great use case. We have, we have, we have A CMO Kola problem with Lisa.
No one paid, I wanted entire thing, Alan, no Paola here, sorry, I'm your girl. But basically everybody's adopted AI and marketing, not just to improve productivity, but another thing that I'm seeing is enabling sales. A lot of CMOs are now owning the SDR function.
Um, so it's improving alignment with sales. It's creating more compelling content that converts. They're overhauling web pages, they're overhauling microsites, they're delivering marketing generated pipeline faster, which impacts revenue.
I had the CMOs of Snowflake, Dynatrace, Nutanix next week, my episode with CrowdStrike Drops, and they talk about how they're leveraging AI as a force multiplier. It's helping marketing and sales move faster. It's helping them focus on more strategic tasks.
What they need to do and what they're responsible for doing is elevating the ROI impact of that pipeline and revenue to the C-suite, to the board, to really clarify where from a marketing lens perspective, these AI marketing councils that a lot of, a lot of CMOs are, uh, leading, are leading to a richer audience targeting. It's more effective marketing, and that contributes to pipe and it contributes to revenue. Could I So Yeah, go ahead, Alan.
Sorry. Well, I was, I just wanna make a clear point. The clear point is we're talking generative ai.
People are saying ai, and the problem is that AI has, I hate the word ai, but algorithm AI models have made vast improvements across organizations all over the place. And what we're talking about is a very specific branch of AI being generative ai, which is the unique building of content. And there people are just playing, and I'll leave it at that, but we need to make that clear distinction.
Yeah, generative ai. Look, I was on a webinar last week where people were talking about generative AI in the past tense that we've moved on, you know, to agent. But I, I've written a few articles about this.
One. One is in the notes here about ai, or you're fired through CEOs through different approaches. I wrote another one last week and I, I remember it ended with Keep calm and keep, you know, and AI on, uh, McKinsey had a very similar survey, not quite 95% failure already.
I think they only had an 80% failure. It was 80% Yes, at McKinsey. So clearly were there, smoke this fire.
But, uh, you know, I, I get a shimmy says yesterday on this where I said, you know, quack, quack. If it quacks like one, it's one. I've seen bubbles before.
There's a bubble. No doubt there's a bubble. com era in terms of internet companies and, and internet, you know, ways of doing things.
I think think what we have is an extremely overhyped overheated situation where I don't give a crap how good this stuff is, and I don't care whether it's generative or ml or or agent. It cannot live up to the hype. It can't, you Can't certainly, I mean, we just, There's this ai and so there, there's gonna be people disappointed.
There's it happened, right? Wasted, It's Gonna be fallouts, there's This, yes, it's a bubble. Those Are meetings.
You know, there's two things to think about here. One, particularly for the studies, and one is the way we present 'em. When you look at the studies, the real question is what is the definition of success for the MIT study?
It was simply a, a revenue contribution, right? Bottom line. Bottom line.
But a whole lot of what AI and gen AI is doing is not directly immediately measurable by the bottom line, because what it's doing is changing the way you do business, the way you operate, particularly the way marketing teams operate, right? When you implement, when we went to an implemented, um, automated marketing, right? And with market, uh, with all the different marketing tools, we didn't see a bottom line contribution for a while.
It takes a while for that stuff to show up because it's changing the way you do business. The second thing is, with all of these types of studies, as it goes back to the old news adage, if it bleeds, it leads, right? And, you know, shoot for a 94, 5% number structured study.
So you get a big headline grabbing number. And that's what we did. And I take that all with a grain of salt as somebody who creates these studies, right?
Is you really gotta understand the size of the study, what it was targeted at, what they were seeking to figure out. And the one thing I think the study pointed out, which John mentioned, is the applicability of generative AI and other forms of AI to different business functions. And what it can do is very hard for people to understand right now because it's revolutionary, not evolutionary, right?
com was, and as the transition to the cloud was, it takes a while for people to figure out how to apply this revolutionary new way of thinking about doing business. So the report about AI being overhyped is overhyped, is that what you're saying? Absolutely.
Imagine that. Absolutely. Hey guys, I gotta pull the plug, man.
We're way over time. What a, what a fantastic panel. What a fantastic discussion Panel.
Thank you, Fred, Jack, IRA, Lisa, thank you. Thank you. Of course, John and Mike as always, thank you.
Thank you for watching. Hey, if you're, if you're p****d off about this Cecil Paola thing, do something about it. Say something.
Um, we'll be covering it more here. But we've got a full Textron gang coming at you. Uh, excuse me, A few text, full text on TV coming at you immediately following.
Enjoy your Friday. Have a great weekend. You know, summer's almost over.
Don't let these last couple weekends go to waste. We'll see you here Monday on the Gang. Hey everyone, we're back here on Tech Drunk tv.
It's been a while since we checked in with Ox Security, so I'm really happy to have our next guest on here. His name is Tson Nisan. Ziv Nisan, welcome to Text Junk tv.
It's great to have you on. Thank you. It's, it's been a while, so it's, it's great to be, uh, back.
Yes. So Nisan, you're coming at us from your new house in New Jersey. Congratulations.
Before we even get into OX and everything, give us, give us the neat sense, Larry. Well, before starting Ox with my partner Leor, um, we were both working for Checkpoint leading the cyber security business unit. It's one of, uh, the best places I've ever worked for.
Amazing people really enjoy there. And it gave us the opportunity to look on how things are done at scale. And really, we grew from that place trying to understand product in a really, really deep understanding.
The go to market, how do you scale business? Um, and then we grew to actually say, Hey, you know what? We are starting to understand that while the firewall was always the middle, the protection, the gap between the internal and the external.
And we started seeing a movement towards the sides, towards things that are going towards the endpoint security and things that are going towards the cloud security. And we said, okay, what's what's next? And we started seeing that next is going to be security, security, the code.
This is the future. And especially now that we've seen that everything goes to Gen AI and security is done from the source, uh, I think it's one of the best positions to be in right now. Oh, absolutely.
Well, it's where the action is, right? And anybody in security wants to be where the action is. You don't wanna be in some, you know, old town with tumbleweeds growing by and no one's there.
Um, of course now we we have the actions in the cloud. It's on the edge, it's on the endpoint. I mean, the fact of the matter is the action is is everywhere.
Um, what about before Checkpoint? Give us a little more of your kind of story. So before Checkpoint, uh, another startup for seven years in the endpoint business, um, it was a very, very fun time where the entire industry was, uh, shaping up.
And I was telling this to a few friends that are a bit younger, and I was trying to explain the ecosystem back in two or 20 or five and try to explain that there was no such thing as a cloud. You wanted to have a server connected to the internet. You actually had to buy a server, go to a hosting farm, connected, deploy.
It's a, it was a different world back then. It's like, uh, you wanted more scale, you had to order more boxes from HP or Dell, whatever you used, and it would take you time and they would ship it to you. You would need to install it.
It's, it's a process. Yes, it was. And you'd have a toolbox with your screwdrivers and you, you would, you know, rack literally rack mounting servers.
Um, I, I remember it well, I remember it well. Yeah. You know, I, uh, I start, well, I, I started in technology and what became a hosting business, I had found it, of course, at the time we didn't call it hosting.
I thought I was a digital landlord. And then, um, sold that and went into what we call an a SP application service provider, where we had data centers, you know, in, in Virginia and Atlanta and out in Silicon Valley and France and England. And, um, there, you're right, there was no cloud.
We were host, you'll repre, you'll appreciate this needs. And we were hosting Lotus Notes in data centers, Lotus Notes people, so PeopleSoft and Oracle apps. No cloud, no hypervisors, T Three bare metal, yes.
Yeah. Bare metal with T three lines, right? Which were 45 megabits a second, which back then was, oh my God, T three line and or DS three.
And then, um, you know, and then the cloud came on, right? It changed, it kinda changed everything, didn't it? Well, this and the cost of internet, meaning Yeah, we, we used to pay back then T one lines, I'm talking about T three, like T one, you would pay like a thousand dollars.
And, and now I'm getting like from, um, I've got Optimum for $30 for a gig. Yeah. Crazy.
And you saying, oh yeah, I can, I've got more bandwidth right now than the entire IPI work with. Well, When I see you in person next say whether at RSA or wherever, I'll talk to you about it. I, um, yes, I remember we used to buy a bandwidth from a company called WorldCom, and we were paying also about a thousand a T one line and a a DS three, which was the top of the mountain that I forgot it was 20,000, something like that.
But, and then we went to a company named Enron who said they could give us Oh yeah, cheap, cheaper. V analyst is a whole story. But yeah, it was, it was a different time.
The cloud really changed everything, but it also make no mistake, changed security too. So I think this is where things became interesting. So let's say in, in those time, all he wanted is to have some indication about what's wrong with your software.
So the entire industry of application security was built from run a tool, get a long list of issues, and there you go. You've got indication where you might search for, for gold. The challenge is that people took this to developers and developers say, Hey, this is a million lime long list.
What do you want me to do with it? Meaning even if we cure all development, it's like zero new features for a year will never crunch through this. What do you want me to do with it?
And I think that, uh, at that point people started to understand that be worried with what you want. You might get it. You wanted the long list of issues.
You got it. Now the next question is what I do with it, and you've got actually two things you need to do with it. One is you need to prove to the auditors that what you decided that is not a risk is actually not a risk, and they need to accept it.
The other is, if you say something is true and you, you're asking your developers to actually fix it, you kind of need to get to the point that they trust what you say and say, I understand why this is important, why this is real and and more important. What do you want me to do with it? And we find ourself right now in a situation where everything changed.
Gen AI changed the entire world in a speed like never before. And what we're seeing in this industry is if up until now we had X amount of vulnerabilities coming to the industry, every year this number is accelerating. It's like every day we've got roughly a hundred new vulnerabilities being disclosed.
Yeah. Now I rate the threat actors on the other end are saying, Hey, I don't want to do the hard work anymore. Uh, chatt pt, can you take the recent patch that, uh, they announced on this product and try to reverse engineer and exploit from it?
So instead of having like three weeks and from the moment that the disclosure is out, up until there's an exploit, this is now ours. So, so this is also insane. Now we're coming out of a very strange economic downturn where the resources for security has not increased for a very long time.
It's unlike what we had in the good old bubble days. So now you've got this ecosystem saying more vulnerabilities, less time to patch. And on top of it, we've got developers starting to use gen AI to write code that nobody understand what's written inside it.
Well, we generated twice as much code as before. So think about the, the guys that need to do product security that we're saying, Hey, all the KPIs right now stacked against me. What OX is trying to do is something different saying, Hey, if we can focus you on the 5% of risks that matter and show the auditors, those 95% are meaningless, here are the evidence developers here, the 5% that matter, here are the evidence.
And more than that we've created for you an agentic remediation that actually takes you from, you have no idea what it means to, here's a suggest fix. Just review makes sense for you. Click here, we'll do the rest for you.
So we're trying to change the industry from the inside to do something that is drastically better. I love it. And adoption is, is so far has been amazing.
Absolutely. Were you at a black hat, uh, week or two ago As a company? We were there.
I was not there personally, unfortunately. I think this is the first time I'm missing black hat for good 10 years. Yeah.
No, I mean, I, I've been going to Black hat since like 2003. But, um, an interesting, I was in an interesting conversation with some very smart people and v around vulnerability and, and AppSec and so forth. And they made an interest very similar to what you said, for all the hundreds of thousands.
And there are hundreds of thousands of CVEs and, and you know, vulnerabilities really when you boil it down, there's about a thousand vulnerabilities that are responsible for almost every breach. If you look at every breach, every incident that we've seen over the last X years, it's really about a thousand vulnerabilities that you're seeing over and over again. And if somehow we could focus in on those thousand vulnerabilities, you're probably going to take off the table 90 plus percent of, of, of the, of the exploits.
It sounds like you're saying a similar thing. Is that true? It is, uh, with two caveats.
One, the vulnerability management space is about fixing what is known. Unfortunately, application security has another element, which is you're writing your own code. Yes, you're using other components, open source and so on, which has intelligence, vulnerability management, but you also have your own developers doing mistakes.
Like what are common mistakes? They don't sanitize inputs to your database or it's stupid things like you, you add a password to the code and by mistake, make the repo and open source. Right.
So are a lot of those mistakes Oh, not, It's very Hard. It's very, very hard to know Whats right now and also seeing it, you know, you mentioned ai, look, AI's changing this whole game, you know, they're estimating now something like over 70% of the code being generated is got AI generating it, or, and some, if not, AI didn't generate the whole thing. Somehow it's involved in it.
And out of that code that's being generated, well, it gets better every day. So I don't want to say it's terrible, right? But like for instance, they used to have a lot of syntax problems, but now they've kind of gotten better with syntax.
But just pure bugs, vulnerabilities, bad code, they're estimating 60%, somewhere between 40 and 60% depending, may in fact have vulnerabilities or, you know, bugs in there. This very quickly outstrips the ability of humans, right? So we're generating twice as much code with a lot more vulnerabilities.
So twice as much bad code, if we could call it that. How does OX help? So let's go to understand what are we actually saying?
Okay, so when you think about ai, it learned from something Agreed, agreed. No one to blame, but ourself We did. Exactly.
So you give the bad code and then you blame it. It's like telling your child, right? I get it.
So yeah, you, you learn from something with X amount of statistical probability for a vulnerability in code. And, uh, this probability remains. And actually we're going to publish a very interesting research, uh, I think it's coming in the coming weeks.
It actually said, Hey, we've done this research about all the code base that we have, and here are the findings, like X amount of new code, what's inside this unique code versus human written code. And it's a very interesting research because you, I can actually see the fabric of AI on the broad scale. It's what's interesting inside of it, what's unique, where are the flaws?
And you see it's flawed, just like humans, just different angles. Um, which is super cool to see this, um, especially the amount of, uh, problems that you see that are just like humans. You, you tell a human write something, they will get it done.
You try to say, Hey, I need to add this and this and this. And by the 10th attempt that you're changing and tweaking AI, for example, loses the original planning and just goes and do wild things. And you, you basically get to the place saying, how is this related to what I ask you to do?
Mm-hmm. Yes. There are a lot of places inside the code that still require adjustment and security just deteriorates faster as more ations you do.
Agreed. Agreed. Um, by the way, this report's coming out in a few weeks.
In a few weeks. Yes. Well, we'll, when that's out, I'd love to have you back on.
Maybe we could go over some of this. Oh, yeah, I'll be happy to. Um, so, you know, needs, and here at Textron we serve a lot of different communities.
Cybersecurity, our biggest DevOps platform, engineering, digital, uh, transformation leadership. Uh, IT in general, it's almost like I feel you almost gotta feel sorry for developers today for not, and not just the developers, all the people on that side of the house, the DevOps engineer and the platform engineer, right? Because it wasn't an easy job to do, to develop code and to develop secure code to begin with.
All of these things we're talking about with AI and, and all of, all of this stuff is making their job harder. I think what we've seen though is that a lot of security companies are maybe tone deaf, right? Because they're security people.
So they look at it from a very kind of cut and dry security perspective. But as you said, giving a developer a phone book full of who remembers what a phone book looks like anymore, giving a developer a, you know, a big fat book full of, of, of potential vulnerabilities of, of, you know, back doors, et cetera, that doesn't help him or her, that doesn't help them. What can we do to make their life better?
I think that there are two, two major things that, um, the industry is trying to help with. I, I think if we've seen it in all the graphs of, um, I would say developer advisory forums without naming them, that used to be a major, major thing up until two years ago. And now when I'm talking with, uh, the developers that we've got, we've got roughly a hundred developers, uh, talks.
So when we think about our developers, they stopped going to those forms and they're just saying, Hey, whatever AI you're using, just write me an example of such and such. And so that's something that is reducing the burden a lot. Yeah.
Now, writing complex logic, that is something that AI is still not great at. It's definitely improving, but not there yet in terms of security. I think that the new interfaces like MCP is definitely going to change drastically the equation.
It enables you to insert security and validation and quality during co-generation time, which I think is going to be huge. And part of the outcomes of the research that we, I just talked about is that developers are going to move from becoming a developer to a developer manager because you'll be instructing somebody else what to do, reviewing it, saying, does it make sense? So you, you'll be putting the head of a manager and you'll have subcontractors doing the work for you, and it's going to be very Exciting work.
Maybe those subcontractors may be digital workers. Exactly. It's gen subcontractor, Right?
Genix, I, I don't disagree at all. Um, we're running outta time. And I, I just wanna pivot a little bit.
How can people get OX to help them with this, right? How, what, what's the on ramp to working with ox As easy as, uh, contacting us and just, um, seeing where we can accelerate alignment with the business? Um, just go to access security and just check it out.
Contact us. Uh, we'll be happy to do education sessions. We're constantly in events and so on.
We constantly have webinars and seminars of, uh, how can things be happening? And it's really about making sure that developers and security can find ways to collaborate that is based on a common ground that can accelerate the business goals. That's once you get there, everything becomes easy Once you're a hundred percent right.
OX security. OX security. Yes.
Yeah, exactly. All right, MI and I want to thank you. Hey, you, you stepped in it.
You told us you're gonna have this report in a few weeks. I expect to see you back here. Go and we'll be talking about es.
Amazing. I will do that. Alright.
Congratulations on your new house. Enjoy the rest of summer. Thank you very Much, Anne.
Good luck with Ox. We'll be in touch. Neat.
Thank you. Neat and Z here on Textron tv. We're gonna take a break.
We'll be back. Hello and welcome to the latest edition of the Techstrong AI Leadership series. I'm your host, Mike Bizzo today with Michael Dominic, who's head of AI for user testing.
And well, we're gonna have a little chat about why most of these AI projects seem to be failing, or at least floundering. Michael, welcome to show. Thanks, Mike.
It's great to be here. A lot of enthusiasm for ai. A lot of projects get started, but they don't seem to quite find their way into production environments.
And I suspect that there are some common causes for all of this, but what's your take on what's going on here? Are we just overly enthusiastic without thinking it through, or are there other issues that work that we're just not seeing? Yeah, it's a great question, Mike.
I think there's a lot to unpack there. Um, I think the enthusiasm is in the right place. Um, I think the execution is where things get a little bit murky.
Um, you know, certainly AI projects could mean a lot of different things for a lot of different companies. Um, there are projects that companies are launching internally. There's projects that they're obviously launching externally designed to be used by customers and products.
Um, but yeah, like I, I think at the end of the day, um, they mean different things. Like depending on what those two things are, if we're looking at products that we're building with AI capabilities, um, I think a lot of companies are maybe taking that enthusiasm and pushing it forward a little bit too fast, and maybe not being as methodical as they perhaps should be. Um, I think there's a lot of, a lot of companies are developing, um, AI solutions in their products to be quote unquote ai cool, right?
So like, there's some of that. Um, but look, I think what we talk to our customers about at user testing is if you're gonna build, uh, AI into your product, that's not gonna look that much different from any other product solution that you might be building. You know, there's a product discovery lifecycle, product building lifecycle that's gonna happen.
Uh, you wanna start with discovery, like figuring out what is it that you're, what problem are you actually trying to solve by bringing AI to your customers, um, and then making sure that you're building the solution that actually fits that problem, building that solution in the right way. And I just, I don't know that a lot of companies are doing that. I think they're trying to maybe move a little bit too fast.
Some of that sounds like to me that we're not thinking through the use case well enough, because what's the point in spending $2 million to eliminate a job function currently handled by two people making $50,000 a year? And I think a lot of folks kinda look at some of the end results of these projects, and they're a little underwhelmed because the initiative itself didn't seem to, um, have enough of a big of a return for the business. Yeah, I, I think that's part of it.
Sure. Again, like there's so much to unpack here, but yeah, at the end of the day, it's really understanding what problem are you trying to solve? And is, is AI even the right solution to that problem?
Right. Is it even worth us, you know, going through a massive development cycle in order to execute that solution that may not actually be the right solution in the first place. Mm-hmm.
Doing also, maybe as humans need to come the terms with the whole issue of testing in the first place. Even before ai, we would tell ourselves that we didn't have enough time to test. So we didn't test because we ran up against deadlines and then we pushed something out and we basically tested it on human beings live, right?
All that going on on ai. And of course, you know, AI folks are like, you know, it's cool just to go ahead and break things and see what happens. But, um, do we, if we're gonna start building more software than ever and start rolling out more things than ever need to come to terms with the need for testing in a different way.
'cause, uh, historically I think as humans we're just kind of predisposed to not wanna test. 'cause that's just not the fun stuff. You're right.
I mean, we do see a lot of that at user testing, right? Um, typically companies are coming to us because they've done exactly what you just described, right? Is they had a hypothesis, uh, around building a product that, you know, answered a solu or answered a problem, a solution to our problem, um, and maybe didn't get any feedback at all about, about how big that problem was.
Is this, is this the right solution? Are we building this product the right way to be a solution? And then they launch it into market, and then they recognize like, oh, okay, like, maybe we should have gotten feedback.
So they often come to us at that stage and say, okay, like, it's time to get a little bit more methodical about the way that we're building our product. We need to test, we need to get human insight. We need to figure out, you know, what are the things that we're doing well?
What are the things that we're not, what needs to be augmented? Um, and it's ver very difficult to do that without, without actually getting real feedback. Mm-hmm.
Can we make it easier to do the testing? I think one of the problems we have is a lot of folks are, well, there's different types of testing, and it's an art in its own sense, or maybe a science depending on how you look at it. But the whole workflow of testing and the relationships between different tests, it seems like, uh, a lot of folks are overwhelmed by that.
Can we just make it easier? Uh, well, that is what we are hyper-focused on at user testing is making this as easy as possible for companies to do something that we all recognize is really important. Um, you know, I think it's, I think it's two things.
One, it's speed and, uh, and, and again, like what you said, like making it easier, right? So we, again, like that's something that we think about all the time when we're augmenting our product, as it were. AI is a, becoming a little bit of a solution there.
Um, you know, so like, I think a lot of times, like companies, they're thinking about maybe not so much is this easy or is this difficult? But a lot of times what they're thinking about is, is this just gonna take, uh, too much time? Right?
And, you know, again, at user testing, we make it really easy for teams building product to find the right individuals to test with very quickly, get rapid feedback on the thing that they're doing. Um, often maybe like the biggest challenge as far as speed goes is understanding where all the insights are that you're actually getting if you're gonna, you know, do some of that testing. I think that's, that's kinda like the interesting AI layer there is, you know, we know that large language models are actually really good at synthesizing large volumes of data.
Um, so that's, you know, we're building features in our product that help our customers do this a lot faster. Mm-hmm. Um, when we do the actual testing, do we really understand the results or we kind of maybe suffering a little bit from, um, uh, our own biases or bias confirmation.
And so we don't objectively look at the test results either. Yeah. So I mean, traditionally that has more or less been the role of like a UX researcher, right?
Like, those are people who are really well trained to be able to understand insights that you're, that you're capturing around a thing that you're building and removing bias, right? Like removing whatever it is that we think might be good or bad. And just listening to what a customer is saying about the experience that you're providing them.
Um, so that's traditionally been the role of like a, of a UX reacher researcher. Now, not everybody, not every company has a UX researcher, right? Like, not every company has that level of expertise.
Um, I think this is actually another interesting area where AI could be, um, a solution that helps companies, you know, do this a little bit better, do this with less bias. Um, you know, user testing has built in, into our product as we've, we've built in AI layers that help you understand feedback that you're getting, again, removing that bias, trained in a way that a UX researcher would be able to pull those insights out and then help give a product team the right feedback to make the right decisions about what they need to be doing with that product. Mm-hmm.
One of the things that I think we suffer from, and especially in software development, is we're kind of in the notion that, well, we'll fix it next time we update it and we think we're gonna update something a lot faster. And we constantly do that. Our end users less patient with that.
They're not standing around waiting for that, oh boy, send me that minimally viable product so I can go mess with it. I think their tolerance for bad software is dropping the near zero, and they're starting to realize that they can just swap out another app for another app, and the one they're currently using doesn't do what it's doing. So is the whole relationship between end users and their, uh, notion of what's good software changing, Uh, everything is changing.
So, um, you're absolutely right. Like there are a lot of companies that say, well, hey, we'll just wait for the next update cycle to fix some of these problems. Um, I mean, I would maybe, or we would recommend maybe not doing that, right?
Like, maybe you want to be a little bit more responsive to the things that actually matter in the experience that you're providing with your customers. You know, it's, it's interesting, like we're living in a time now where it's never been easier to build software, right? We could do this a lot faster, we can get the feedback a lot faster.
Um, and I think a lot of companies are now rethinking what does, what does a product sprint even look like? Um, is that changing? Right?
Are we able to do this a lot faster? Uh, so I think, I do think the companies that are providing their customers with the best experience are being a little bit more adaptive to these new possibilities. Mm-hmm.
Um, will we just have AI agents to do the testing of the code created by other AI agents or any other kind of testing for that matter? But how automated will all this get? Yeah.
Well, I mean, there's code, right? And, and yeah, I think that there's a strong opportunity to bring agents in to help with debugging and, you know, help making sure that you're, the software that you're writing is actually, uh, the, the, the, the product that you want to ship. Um, and there's probably like a really strong opportunity for agents there.
I think what user testing is a little bit more focused on is making sure that you're providing the right experience, right? So like, you could ship perfect software with no bugs, but if it's not the right experience that delivers value for your customer, then that's kind of pointless. That's a pointless exercise.
Um, and our agents, so to you go to your question, like, our agents gonna be able to do that. I don't know. I I think we're still nibbling around the edges right now.
I do think that there is no replacement for human insight. You know, a lot of people in our industry are now talking about, um, you know, like AI generated feedback, synthetic feedback that's often called. Um, I think that there's been a pretty allergic reaction for most of this industry about that, because we all recognize that humans, uh, are gonna respond in very unpredictable, unpredictable ways, right?
Like, we're just unpredictable beings. Um, and it's gonna be really difficult, I think, for AI to be able to give us any, any kind of, uh, you know, insights or, or that we're really confident in, um, that might replace an actual real human insight. Um, so that is, that is a big part of what we're focused on at user testing.
But we also recognize that maybe there's a role for AI to play in giving us an estimate of what a specific demographic might need, or what problems, uh, you know, is that demographic currently struggling with that there are no solutions for, right? Like, I think that AI might play a role there, but at the end of the day, I think human insight is far more valuable. Mm-hmm.
I also wonder if as we go build applications, maybe there'll be more versions of that applications that are tailored for specific Yeah. Types of end users, or even specific people themselves. 'cause part of the problem, and I I feel for the people who build the applications is if you're trying to build something that's, uh, gonna be of use to, you know, a couple hundred thousand people, they don't all think the same way.
And so you're trying to make some optimization decisions around a hundred thousand people, but maybe we can get to more granular sets of software that are customized for more, uh, unique individuals such as, you know, myself probably. And my question then becomes, you know, does that also kind of increase the testing complexity if we do that? Uh, that's a great question.
Um, I, I mean, in short, like, I don't know, I don't, I don't think anyone knows that yet, right? I think that that is a possibility for the future as we, uh, you know, as, as we get deeper and deeper into the capabilities of ai, uh, this kind of like massively proliferating space, uh, yeah, it, it, it, there might actually be software that's immediately adaptive to the needs of the user. Um, one way that that could actually play out is in accessibility, right?
So when we're building software, we want to think a lot about the accessibility of that software for people with different needs. Um, you know, some people struggle to see a screen more than others, and maybe those individuals need a completely different interface than someone with very good vision. Um, and, and maybe that software is immediately adaptable to those individuals, but different needs, are we there yet?
No, I don't, I don't think we're there yet. I think that's a possibility for the future. Um, yeah.
I mean, I mean, that would be cool, right? I think it would increase some of the complexity, but yeah, sure. Like if that's something that at the end of the day will deliver a better experience for the customer and for the user, I, I think I'd be all for that.
So what's your best advice to folks as they kind of go on these journeys? I mean, you've seen this a few thousand times. What, what makes you shake your head a little bit?
I think my advice is, you know, I, so we're having a conversation around ai, right? And how AI's changing all of this. Um, at the beginning of this conversation, you asked me about hype.
Like my conversation, my advice to individuals is kind of cut through that hype and focus on what we can do today. Um, and what we can do today is we could start to develop software at a much faster rate aided by ai. But at the end of the day, you are developing products, you're developing software for people to use, usually people to use, right?
And make sure that you're, to make sure that you're building that in the way that's gonna be super valuable for your customer. Get their feedback at every stage of the product development lifecycle. Make sure that even before you write a line of code, even before you have any versions of a prototype of the thing that you're building, get pe, get feedback from the people that matter.
Make sure that you're solving the right problems, solving those problems in the right way, and you're building a thing that actually is valuable for your customers. All right, folks, you heard it here. I think it was Ben Franklin who once said, you know, uh, failing to plan is, uh, planning to fail.
And I think the planning part of that assumed testing too. Hey, Michael. Thanks.
I wanna agree. Yeah. Thank you, Mike.
It, it was a pleasure. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership series.
You can find this episode and others on our website. We invite you to check them all out. Until then, we'll see you next time.
Hey, everyone, welcome back. You know, we made it up from the show floor of Black Hat to our suite here in, in Las Vegas to do something a little bit quieter. Hopefully the quality will be better for you.
Um, I'm really happy to introduce you to Dave Crot Hammerer. Fair enough. Fair enough.
You say it for me. K er, cr hammerer. Either way.
Dave is here with us. And, uh, Dave, the company's called Q Secure. Yeah, Q Secure.
That's Q like Quantum, QU Secure. Yeah. Yep.
Quantum secure. And, um, well, we're going to hear all about the company, Dave, but first let's hear a little bit about you. Sure.
Um, so again, Dave Coffer. I have a computer science background from before there were computers long, long time ago, and I kind of spent a lot of time in it, became a Chief Information Officer in telecom, and then I founded what became the Oracle's largest cloud partner services partner. So grew up in that kind of enterprise software realm.
And I grew up in a very nerdy Caltech family, JPL family, and was always really fascinated with physics. Um, although I didn't have a physics background. So we founded a company that was really focused on quantum computing, quantum algorithms, and quantum development, and then pivoted into this quantum security paradigm that we've been doing since, um, roughly 18, 19, 20 19.
And just in having a really fun time. But, um, just focusing in on creating new layers of security to protect us from current and future attacks. Un un that's fantastic.
If you don't mind me asking. Sure. What, what possessed you to this was what, about four or five years ago?
Yeah. What possessed you four or five years ago to jump into quantum computing? Uh, as a, as a great question Al Alan.
So, you know, like I said, I, I, I grew up in a very nerdy, you know, family. My mom was a college professor, and I was always really just fascinated with future, next things, really exciting things that were occurring. And they were kind of on the cusp of quantum computing becoming a real thing and what do you do with it?
And so I've had some exits and I was in a good position to kind of do something really fun. Um, I founded the company with my daughter, uh, who's now the CEO. That's Fantastic.
And it was just really a wonderful opportunity to focus on some really future cool stuff, make it a now thing, you know, work with my daughter and just do some cool things. Love it. You know, it, it's funny, Dave, we're about the same age Yeah.
And we've seen waves of technology, as you said, come and go in our time, not just go. 'cause technology never leaves, it doesn't fade away. Right?
Like Douglas MacArthur says about, you know, old generals. Um, it, it gets built into the foundation, and then we build on top of it and on top of it and on top of it. Yeah.
Now, quantum, I, I have to admit, when I first became aware about quantum computing, it sounded Star Trek to me. Yeah. You know what I mean?
Yeah. And, um, I didn't think I would see it in my lifetime, let alone in my working career. Yeah.
But then again, I didn't think I'd see artificial intelligence In your career. Yeah. In my career either.
In here we are, um, there's so many aspects to quantum computing. I was actually talking to a friend of my John Willis day. He was doing a book on quantum computing.
He's telling me he's about 150 pages into this book. And he said, Alan, you don't realize how long this has been sort of a, a holy grail, if you will, because it could do everything and nothing all at the same time, so to speak. Absolutely.
Um, I think for a lot of our audience out here, they don't, they don't understand Yeah. What quantum really brings. Sure.
I I think probably the easiest use case is the security post quantum encryption that we hear about and stuff like that. But Dave, if you don't mind, let's pick your brain a little bit Sure. With our audience, when we talk about quantum computing.
Yeah. You know, we toss around terms like qubits Yeah. We, you know, and, and the whole non-binary kind of being both a one and a zero at the same time kind of thing.
Yeah. But what are we really, what does it really mean? Where does the rubber meet the road for our Audience?
That's a great question. So when we talk about conventional computing, conventional computing processes, a, a transaction or a word really fast, and these transactions are like 64 bits, you've heard of a 64 bit computer. So I process 64 bit bits worth of information at a time, which is great.
We figured out how to do that really fast. But it's linear in nature, meaning it goes from step to step to step, which is good for a lot of problems. But, you know, in the Venn diagram of problems, there's all these problems out here that you can't solve linearly.
Um, hacking RSA is one of them because it's prime or refactor, right? So just if the quantum thing is, computing is really simple, it takes that word of 64 bits and a qubit, which is like a quantum bit. It's basically an atom.
A qubit is an atom. Mm-hmm. And when I create a word of 64 bit word out of 64 qubits, instead of being 64 bits, it's 64 2 to the 64th.
So the word size of 64 qubits is equivalent to like all the data stored in the world in the last year in one transaction. So instead of like, linearly going from step A to step B with one instruction, that's such a massive amount of volume and capability, I can solve these problems. That, like, one good example is like, if I go into a maze with a conventional computer, I turn right, I go left, I do this.
If you go in with that quantum surrogate, I can take every path simultaneously all at once. So really, if you boil down quantum computing, it's just the word size is really, really big. And, um, and it lets us do kind of amazing things with significant amounts of data in an instant.
You know, I've never heard it explained that simply, eloquently good work. It's really actually a simple concept that they use some fundamental natures and the bit, because it can be one zero anything. It's, it's not just on and off.
It's, and I put 'em together and it's just really a lot of capability. But it's two to the 64th power, two To the 64th power, which is equal to a Yoda bit of data, which is equal to all the data stored in the world in the last year. It's a lot of data about Transactions.
Crazy. Now you understand why it's so hard to develop Now, as hard as it is though, I, I don't want to be, I, I, I think we owe it to the audience to tell. We've been making tremendous progress Yeah.
In the quantum field, in the quantum, uh, computing field. Talk to us a little bit about the state of the art today in quantum computing. Yeah.
So, so this quantum bit, which is just an atom, right? Different kinds of atoms for different, for different applications. Um, the, the quantum bit that the whole issue is error correction.
They're very noisy. So measuring the quantum bit is really hard. So there's been really significant improvements in the noise of these bits.
So, to crack, RSA, which is what we're here to talk about, RSA, is the encryption used on most devices. It's a prime number 20 thou 2048 bits long. Um, you need about 4,000 quantum bits, but high quality noise reduced bits.
So what happened in the past two, three years ago, if you had a million qubits, which you didn't, it would reduce down to, you know, a hundred clean bits. Now they're improving the error correction to where, you know, you can have one qubit that's error corrected. And, uh, once you have error corrected qubits, which we're raising towards really fast, you mentioned it Yeah.
That the power of what you can do is, you know, is unimaginable. We're gonna have, you know, instead of ai, we're gonna have convolutional neural nets that can parse your whole complex neural nets at once. So instead of like going, well, I'll do this, put something in a bucket, they'll be like, they'll be able, you have about 400 billion neurons in your brain, and it's highly parallel.
So with quantum, you could actually understand the whole state of the system. Error corrections is the key. We're making monumental strides in error correction.
It's really exciting time. Yeah. The other thing I've heard, and look, I'm no quantum expert, I'll say that up, up front, is we used to say, well, we had to reach a thousand qubits to have sort of a working quantum computer model.
But now they're saying, well, no, we may not truly need a thousand qubit machine. We could do these in parallel. Yeah.
And we get away with a lot less to have functional quantum. Yeah, yeah. Yeah.
So, um, you know, the, the, the holy grail is getting to 4,000 qubits to crack RSA and when that happens, we'll talk about it in a minute, but every device is vulnerable. Your camera, your, Anything that's encrypted, Anything that's encrypted is vulnerable. It's kind of like the new malware.
Um, so, um, you know, there, there lies, the, the challenge State of the art RSA is 2048. Yeah. But there's a lot of legacy stuff out there that's 1 0 2 4.
Yeah. And that needs half 4,000. You say you need 4,000 for 2 48, you probably need 2000.
Right. And in parallel, you could get almost in spinning distance of that right now, from what I understand. Yeah.
And there's, you know, in large corporations, um, they'll have thousands of applications that have embedded cryptography. Some of this is from companies that have gone outta business. Sure.
Some of it's, you know, des triple des old, old encryption that's already been hacked. So we already have this cryptographic debt is a term I was a CIO in my old days. We have this cryptographic debt, and as I said, only about 25% of the companies actually monitor what cryptography they have.
So the networks are strewn with older stuff mis implementations, and we don't even know what debt we have. So it's really, yeah. It's not just cracking RSA, it's, there's just a vast array of stuff out there that we don't even know what it is.
You know, RSA might be the gold standard, but there's a lot of silver, bronze, and copper. Yeah. It's in plague here that, that's highly Vulnerable.
Um, now look, I've, I've had the pleasure over the years of, of working with a few companies in the quantum encryption field, one of which, or post quantum Yeah. Encryption, I think is the right term. One of which is DigiCert, which is probably the worldwide, worldwide leader in digital certificates.
Web certificates. Yeah. You know, and of course NIST has been involved in this Yeah.
Mitre, you know, quasi-governmental agencies and, and we have come out with post quantum algorithm. Yeah. That is supposedly quantum proof.
Yes. Now, the adoption of the, you, you know how security is. We don't, do we have what we call just in time security.
Yes. They don't do it until it's probably a little too late. Then they all of a sudden everybody gets religion.
Yeah. But what, what about, what's the state of post quantum cryptography for these kinds of Sure. Digital certificates?
Um, great question. Just I wanna be really clear that post quantum is just better math. So RSA prime refactored post quantum is just lattice math.
It's just better math. So I like to equate it with RSA. If I wanted to have tea with the queen, I go to Windsor Castle, there's one guard I push 'em over and go have tea with the lattice based math or post quantum, it's like every inch of that palace is filled with a guard, so I'm just not gonna get through it.
So I think the term post quantum is a little confusing and deceptive. It's just a better math algorithm that can withstand these quantum attacks because they're just not prone to the large word size in a quantum computer. Sure.
So I think, um, you know, when it comes to post quantum, so we've established, NIST is established basically with crypto. You're starting to see a lot of compliance regiments mandating, um, post quantum, but more important than post quantum. And post quantum is just the next algorithm is this concept of crypto agility.
And that is, you know, now that, uh, we have a new algorithm, what if that fails tomorrow? How do I swap that out? So in the past, you know, these implementations of cryptography have been very static.
You can't change them. But this move to crypto modernization is really about crypto agility. Meaning if I have a million cell phones and I need to swap out the algorithm, I can say, I've got a threat.
I can press a button and upgrade to post quantum two, or whatever it might be. Um, so that's the field we are in at q secure is basically crypto agility and orchestrating this new cryptography to any endpoint when the threat occurs, and monitoring and understanding where we're at. And so I'd like to demystify post quantum better math, um, quantum computing, bigger word size.
You know, the concepts are pretty straightforward, but how do you swap it out in real time? That's the question. Yep.
So, look, I feel like we gave everyone out here a terrific, uh, you know, quick cursory, cursory course on quantum Yeah. No charge. Um, but let's now turn to Q secure.
Sure. Yeah. So you said you, you started the company, it was about four or five years ago.
Yeah. Uh, your daughter is now the CEO I'm gonna assume she has a little bit of a background in quantum and computers. She does.
Well, she does. Yeah. Um, well first let me do proud Papa with you.
Tell us about your daughter, who's the CEO of background. Yeah. So, uh, our, my daughter Rebecca, who's the CEO, she was a Stanford artificial intelligence.
Um, so she focused on AI and kind of went into the quantum field because the promise of AI when you have a quantum capability, right. So, just really exciting. Um, she was, uh, Forbes 30 and a 30 in quantum physics, in quantum computing.
She's on the World Economic Forum, the board for AI and quantum, and just really has carved out a really cool position for herself. Um, and so she's, you know, and by the way, she's just a phenomenal leader. She's taken over the company and just a visionary and really leading us into kind of this AI driven, quantum crypto, agile world.
And so, uh, You must be very proud and you should be very proud. Terrific story. Um, so let's talk Q secure.
Yeah. What, what's the mission? What are you guys doing exactly here in quantum and security?
Yeah. So, you know, I've had some exits. My ethos is really to create a safer future for everybody.
We're at kind of this pivotal time when, you know, the internet was built with kind of no walls. It was built to trust everyone. Scientist, scientist.
It was. But, so we're going through a transition where, you know, we've got to, we've gotta rebuild it in the image of that, you know, Alan's, Allen, we can guarantee Alan's Allen, we can guarantee, you know, Alan's talking to Dave and, and, um, so we've gotta rethink it. And so the future should be safe.
We should be afforded, it should be a human right, that you're afforded a degree of privacy and control. So income's Q secure. So what Q Secure does, um, we have an orchestration platform, fancy word for the software that basically orchestrates this cryptography and keys to any point.
It can live in the cloud, it can live on a server, it can live in a air gapped environment if you're high security zone. And then it orchestrates this crypto to any endpoint, and you can manage it one single pane of grass glass. And, um, so that's what we do.
In essence, we enforce, um, policy and then let you swap out broad slots of your network in real time. Really easy to deploy. We've done like post quantum 5G, uh, in a couple hours.
And, um, so it's a really easy way to set the stage for crypto agile networks. Um, if you're in the networking space, there's a concept of sd-wan, which is a network orchestrated. Sure.
Think of us as SD-WAN for cryptography, and that we can orchestrate it across the network in real time. All in software. Really.
Yeah. That's fantastic. Now there are customers that are more, uh, attuned Sure.
I think is a good word. Customers that are more attuned to this kind of solution. Talk to us about Sure.
You know, the target customer personas for Q Secure. Great. Um, yeah, we, we kind of cut our teeth, um, working with the government.
Um, there's been a number of executive orders. One just came out a couple weeks ago, mandating post quantum cryptography and the path there that, you know, the deadline when they think that's gonna be a quantum computer that can hack RSA, it's coming in towards us quickly. It was 2035, it's now 2030.
Um, and this journey closing quick and closing quick. And so, um, it, it's a governmental mandate. And, um, so there's real, if you're working with DOD or working with the government in that supply chain, it's mandated.
Now what we're starting to see by verticals, and this is pharma banking, a lot of telco energy is now, there's a compliance regimen coming out where they're saying you have to deploy crypto agility. Like PCI, which is the credit card standards now has a requirement for crypto agility. Um, we were working with a banking customer, and they had the regulators in, and they said, the regulators have never mentioned post quantum.
And the last time they were in, they were like, you Know, You gotta be, you've gotta get this done. You, you. And so they were like, boy, this is really creeping up.
So I think what's happened is n certified crypto, all these compliance regimens, Dora Fido, they're all saying you need crypto agility. And now there's kind of a mad rush in the verticals like pharma, energy banking, kinda The usual suspects for this, but for good reason, right? Yeah.
Uh, either mission critical or highly, highly, uh, regulated kinds of industries where you can't afford to have, you know, kind of New York Times headline kind of, uh, incidents happening. Right? Yeah, Absolutely.
I'll tell you something else, Jessica, my opinion. Yeah. I think the speed that AI Yeah.
Has tsunamis, for lack of a better word, the tech industry Yeah. Has made people quantum shy. If that's, that's, Hey, I said that word first.
Quantum shy. Quantum shy call it. Because they, they, if, if AI can come on like that, so can quantum and though the government, you know, it's like secretariat coming around the bend for the Belmont stakes and pulling away from the field, they're saying 2030, it could very well be 2028.
It could be. It could be. And it's not the kind of thing you can turn on.
I mean, the, the, there's so much embedded infrastructure that would need to be updated. Upgraded. Yeah, quantified.
That's a good word. Um, you know, that we, we, we do need now is the time to get outta ahead. Right.
We could, yeah. Don't, don't let you know, for those people who, you know, AI came on and was almost the auto magical. Right.
Wow. What It is crazy. It's fun, you know?
Unbelievable. Um, yet it, it's not magic for those of us who are into neural nets and, and understand how AI does what it does. Yeah.
Really putting one word in front of the other. Yeah. It wor it's the same thing with quantum.
I think we're seeing inch by inch, step by step. You, how do you eat an elephant? One spoonful at a time.
Yeah. And we're eating the quantum elephant one spoonful at a time. Yeah.
So I, I, I do think people are starting to now feel the, uh, the, the, the, uh, the weight of it, you know, breathing down our necks a bit. Um, I've always asked friends of mine who are into the quantum field, what's the killer app? Is, is it the cryptography piece of it?
Yeah. But what are some of the other Sure. Killer apps out there that you think quantum may unlock for us?
Yeah, I think, I think at the top of the pyramid for me, um, is like molecular simulation. Because right now, if, if I wanna simulate a molecule, you know, we don't have the math or the computing capable to do it. So if you think about the future where I can just engineer materials, I can engineer pharma, um, and I like to proteins, um, it, it, it's just fascinating what we're gonna be able to do.
Um, there's quantum sensing, which is really hitting hard. And that's the, the ability to sense your environment at the atomic level. 'cause when you can kind of come down to the atomic level, it's amazing what you can do.
It's almost subatomic, right? Subatomic. Yeah.
Yeah. And it, it is, it opens, you know, no, no pun intended, but it opens a whole new world, right? It Opens whole New world of, of, of, And another thing on the, on the security side, one of the big threats we face right now is steel.
Now to crypt later, our data's already being harvested. So, um, they're harvesting the encrypted data, and in the past they've been like, if you have encrypted data, we don't care, but we should care because no more nation states are, they're taking our encrypted data. They're ordering the, what do they call 'em?
Hash hash balls or whatever. Uh, yeah, I got the name for it. There's One for nation state that's speculated how, versus to 25% of the global encrypted data, when they have enough qubits to crack it, they can crack that data.
And if it's health records, if it's credit card data, if it's banking data, um, that point's a little scary. The other big thing about quantum computers can be revolutionary is quantum neural nets. And this concept of being able to understand the state of a neural net instantaneously, it's gonna open up this kind of super intelligence, this gateway to super intelligence NPI and super intelligence.
Yeah. Yeah. So I mean, your, your brain, your neurons function at very slow speed.
It's like four bits. But if you had a quantum neural net, the, the capabilities for artificial intelligence, it's really the real thing. A little, a little scary.
Yeah. Let me give you another kind of pulled right at it. Sci-fi out of a Hollywood movie, once you have the ability to create a neural net that exceeds the capacity of our brain.
Yeah, Yeah, yeah. You know, immortality has been a, a dream. If you look at it, it drives, it drives religion, right?
Yeah. The thought of being able to live forever. We have this whole class of billionaires.
It's not about the money for the, I mean, they have more money than their children's, children's, children's children will use, but their mortality is, is, you know, a a sure. It's the holy grail. Is it possible with a neural net to like download someone's mind?
Yeah. So we, I don't know if you've heard of Ray Kurt's wheel. Sure.
You know, the singularity. So right. Google.
Um, so this concept of yeah. Creating a, creating a neural net that, you know, when it's a quantum neural net, you know, right now the challenge with AI is it can only resolve the next word in a really sophisticated way. But when you add these quantum capabilities, it can then create things outside of the known knowledge that, so I'm a, I'm a, I'm a believer in the singularity, which is the nerdy side of me.
Right. And that they will develop this capability that, um, you know, you can transcend into that. There's a joke about the singularity is that if you don't have a lot of money, you'll have ads in the sky when you're in the singularity.
And Yeah. Well, you'll have to pay for, right? You gotta pay for it one way or The other.
But the other, the interesting thing about Singularity is that, you know, it was usually, Ray said it was 2050. Now it's like supposed to be 20, 29. People are saying, we may already be reaching it somewhere.
We may Already be reaching it somewhere. Last thing. And then we gotta go.
'cause we're way over time. I apologize, but I, I actually like this stuff. Um, marrying AI and Quantum.
Sure. We talked a little bit about it. It maybe it brings on the singularity, maybe it brings on a GI super intelligence, but you, you marry that along with what we're calling physical AI robotics.
Yeah, Yeah, yeah. Super smart machines that have quantum capability and ai. Yeah.
Do we have to be afraid? Wow, that was a, I wasn't expecting that. Um, obviously that's a big topic right now.
There's a lot of thought concern, optimism, pessimism around that. Um, you know, I, I, I personally, so my personal belief is that, you know, the trajectory bends towards morality. Martin Luther King.
Right. Um, and, uh, absolutely. We definitely need to be concerned, um, because uncontrolled, where it leads us is once it exceeds our capacity to understand, then, you know, it just, it's, it's an interesting thing.
But I think, I think, you know, our, our ambition is to create a safer future. I think if the ethos we bring to things, to collectively is that we wanna create a good outcome with this, then we'll bring that ethos to this discussion and create technology that really has a moral arc to it. And there will be a lot of problems along the way.
There. There certainly will, there'll be growing things. But I, I agree with you.
I, I, I believe in the goodness of, of humanity at a core level, and I think we will build in those guardrails. I love it So far. I think there's an opportunity to build an imaginably beautiful things.
Absolutely. And that's why you're doing it. You know what we didn't mention though, Dave?
What's Q Secure? What's the website? com.
My email is Dave at Q Secure. And feel free to reach out. It's a really fascinating topic, and it is really appreciate.
We're, we're planning on doing a, uh, a virtual event on Quantum either later this year, early next year, virtually. We're gonna call it Quantum Leap of all things Quantum. But, um, we'd love to have you come talk about, maybe we'll have Rebecca come on too.
Yeah, she's really, really good. Like she would, would Love to talk about Quantum. It's a pleasure meeting you.
Great hanging out with you Too. Secure here on Text Drunk tv. Go check 'em out.
We're gonna be continuing our black Hat coverage, uh, in a little bit. So stay tuned. You're watching Text Drunk tv.
Hey guys, thanks for the throw. We're here with Chi Jin, who's president of engineering and product for Observe, and we're talking about how software development is changing in the AI era. You welcome the show.
Thank you. Thank you for having me. I think we all agree that it's changing, but I feel like it's kind of like a traffic accident in the sense that no witnesses seem to be seeing the same thing.
And I get a call entirely different reports as to what's happening. And it will range everywhere from developers are saying it's nice. I can have something to explain something to me, and it writes some code, but I still gotta figure out how to vet it to CEOs who think that, you know, the entire economics of software development is fundamentally changing in ways that will allow them to cut the SAP by, I don't know, 80% depending on who you talk to, somewhere between those two extremes is probably some sense of reality.
But what's going on here, my friend? What are you seeing? Uh, well, uh, thank you Mike.
I, I think, I mean, uh, you know, if you look at Avidity, right? Uh, let's say you are the head of engineering. I, I think with all the technologies your basic needs doesn't change, right?
So what, what is the basic needs in the engineering organization? Um, or, you know, a leader of the, uh, engineering organization. You, you kind of look at it saying, okay, one, your software need to solve customer, uh, issues and then needs thing need to be reliable, stay up.
So sort of really deliver a customer outcome. So that's sort of a more like reliability, right? And then the second thing is just like you, typically the productivity, like your engineer typically spends 30% time, uh, on calls and charge incidents, all all these things.
Uh, so that's sort of more productivity. The third thing is, you know, you're gonna running, uh, you know, C-P-U-A-W-S and Gulf forbid and GPUs. Now, uh, that's typically took, um, you know, in a, in typical SaaS, took somewhere between 15 to 30% your total bill.
So that's like how my infrastructure should be efficient. Lastly, it'll be like, uh, if you can do all three, well, you'll be like, okay, well, is there any other thing I can look at it, my customer base, how they use my product? It's more like a product behavior, customer analysis.
So with all these where observability, uh, need to solve, uh, didn't change before and after ai. Now, uh, if, if we just put that aside to say, uh, with ai, what changes? So, uh, I, I think if you look at them, the in the space, who is the player, right?
One is, uh, the engineers in the engineer side. I think the coding, uh, the creation side, you now have a strong assistant and take out all the body code, and they can write a code much faster, can debugging what, uh, these all this cogent tool is. Great.
The only, the thing that is missing from a cogent tool is it, it it only goes to dev environment as soon as you go to production, none of the cursor, you know, winder and, and can actually tell you what's going on in a production. So that's, I think that's gonna happen next is the, the cogent tool. What takes you all the way through to debugging the project production incidents and reliability, all this.
Uh, so that's sort of from the, the, the, the coding tools. The other side, which is, uh, the availability tool ability to lets you essentially solve these problem and I efficient, can I reduce instance, can I reduce toil? The problem is they're rich is only always on the production.
They cannot go to the dev side, say, Hey, listen, you know, you are, um, you write a wrong code on this way. You could do, you could do that way. I think they were actually going to the cogent space to say, okay, if I had this log problem, how can I, um, uh, how can I, um, you know, uh, doing better code to, to do production.
I think eventually this, the coding side and the observability side is gonna, uh, integrate, become one process in my view, uh, which is sort of end-to-end developer focused flow. Uh, we call a vibe loop, which is from sort of a, uh, coding all the way to production as one, two versus a separate markets. So, Hmm.
And how will we bridge that divide? Because today you'll hear people talk about the coding tool that they used, created a bunch of code, but it wasn't really aware of the runtime environment, so the code didn't really run. Um, so how do I get to the point now where that ei coding tool was smart enough to create something that is optimized for my production environment, which is often a snowflake in its own right?
Yeah, yeah, totally. Um, that's a, that's a, uh, you know, I, I give you a couple example, right? What, what happened in the production.
Ultimately you have an incident, you come in, you look at metrics, uh, the metrics may all look screen, but you know, the customer didn't run. You are like, Hey, I wish I instrument the customer field so I can see which customer have a problem. Uh, so, uh, so how do you do that?
Now you have to go find a code who actually, uh, admitted the metrics at that customer field, and then when you add it, you take another site to shore up. And so that's actually a very laboratory process. Uh, so that's number one.
The, the second thing is, in the past people say, oh, I, I, I, I should be able to add this instrumentation, but the problem is the volumes so high that they couldn't afford to do that. Right. Um, so I think to solve that problem, uh, my opinion is, you know, every developer want the signal, uh, on the log metric and traces, but none of them actually want to write it and point to the code.
This is the last thing you want to do is adding log statement. I think, uh, uh, giving the, the advancement of the tool, uh, you know, the, the code generation tool, understand your advocacy context. They could add a lot of the instrumentation automatically either using auto instrumentation or using understanding code logic.
So you're adding these things. It's almost like how you generate business insight. And that thing with the continued deployment will flow to the production, and you can see this thing very quickly.
So that's, that's a, that's a big thing, uh, to do, which is let, uh, let the more insight generated from the code generation to the wrong time. The reverse side is very interesting. If you look at all the code generation, they have a context.
They'll say what application you want to generate. You're like, Hey, you know, I, I wanna generate a website, you know, I wanna, I wanna do this and that. The thing is, when you run in the wrong time, it actually had a lot of insight too, like, what's the services, which cluster you are running?
What's traffic? If these contents can send to the coding tool, it can say, oh, you know, you run a lot of limits. I I actually need to increase your resources.
I actually need to put, put in a protection. So the other side is the, the, all the context from the run time become part of the knowledge graph you can ingest in the coding time, which actually will make your quality much better. Hopefully, I, I expand it.
Yeah. Will that ultimately lead to more efficient code? 'cause I think one of the dirty secrets of it is that a lot of the code currently right, is inefficient and we wind up spending a lot more money on infrastructure to run it.
However, also, people will say that the code that the AI coding tools are currently generating is even messier. So, totally, how do we kinda, you know, close that loop. Uh, I really, uh, like how you, how you frame it, right?
You know, when you close the loop, the first loop you close is based on the, uh, instrumentation best practices. You do wanna send enough right signal to the wrong time. So you sort essentially recall your, uh, I, I'll call that, uh, business intelligence on your code, right?
So when you write this thing down, uh, couple things will happen. One is, uh, how do you deal with, with basically incidents and errors? So to close the loop, uh, in the past what happened is you, you have a arrow, you have a log, you have traces, you, the people would take a copy of that thing, you know, copy that log, try to go search in your code base to search these things.
Uh, nowadays to close loop, you can have MCP server, uh, essentially, you know, mc server is just a protocol for, for AI to understand each other, right? So, uh, mc server of your availability system, and then the, the coding tool can directly create that. Uh, for example, ask very simple question, you know, which server has the most logs, arrows?
And then you are like, oh, I have a 4 0 4, you know, in my case, right? And it will say, I searched the 4 0 4, there are three places in your code have this thing. And by the way, the the last one was someone changed it, do you wanna roll it back?
And you, and so, so that's actually one sets which is reduce, uh, reliability. The other thing, uh, just, uh, on efficiency, I feel like you really spot on. Then people said, listen, you could actually write a very efficient code.
The issue is you don't want like a micro optimize, because every line is of code. You can optimize the thing. But the, the point is like, you wanna optimize the thing, get caught a million times, not a one time.
So how do you know a code got caught a million times? Well, you only know that in the wrong time. So if you look at the wrong time and say, oh, you know, this thing got caught a million times, this take a huge latency.
They take a lot of efficient, uh, uh, issues. You can take this signal and go back to the code and ask a cogen saying, Hey, listen, the memory usage is not, not good. I mean, can you think about shutting it?
Can you think about reduce it and whatnot? Uh, I think then you can write it efficiently, code, uh, uh, you know, get going. Uh, ultimately the efficiency, the quality come from the creation side.
You know, I think visibility at the end of the day are still like, if you can impact on the most left side of the process, which is creation side, it will be the most efficient way to do it. We also somehow magically expect that we're gonna be building more applications than ever. But when I look at the DevOps workflows that are out there, they're brittle.
And I don't think I can keep just throwing more pipelines at that. So how will I manage all this additional code and application development projects that I assume are gonna be happening more in parallel, but how do I kind of get that to be workable in a way that doesn't overwhelm me or just break everything as I have it? Yeah.
Yeah. I love it. I obviously, everyone have a, a lot of different perspective.
How do you do, uh, the best practices, right? And I, uh, if you mind, I, you know, I'll give you one example. So, uh, so I walked in the Google search, right?
And Google infrastructure for eight years. And I was actually always surprised, at least inside Google, um, actually the dashboard and, and the metrics wasn't really a big thing, but we, we have some stuff, but you, you would, you would imagine if you do search, you would have hundred thousand dashboard, a hundred thousand pipeline. The truth is not, we actually, I have several dashboard, and it's all I could, and I'm kind of, uh, reflecting on is like, why?
So there's a couple things. The first thing is obviously being a single company, uh, they, they have the best infrastructure. There's a best practice.
It was enforced. So in that way, you, you do have lots of, lots of code, but, uh, in our case, the, the monitor dashboard, the, the metrics, the middleware, uh, the, the, the pipeline, they were actually all standardized. So in some way, you, if you standardize and if you really, really hone on externalization, then it will be better.
So, uh, in country to everyone was thinking, you know, look, we have a lot of, uh, cogen tools. That's not gonna be mass. I do think, um, there's a chance for this cogen tool to take the best practices and take the sort of cookie cutter standard way.
And, and in that way, uh, you actually have a less profit. You might have a more and more volume of applications, but because they all like does this thing very, very standard way, it actually, uh, will be, uh, more efficient. And so that, that will be sort of a, and I have an example, right?
Um, let me give you one example. I used to do knowledge graph. It, it runs like a 50% Google search.
When we did, uh, its backend server, we used a, uh, internal Google tool called Block It. It basically generate all the dashboard and, uh, you know, it generate the debugging flow, it ed deployment flow. Um, none of our guy actually need to worry about this thing.
It's all standard. And I log in, I got all that things, I only need to do a few customization. So that the, the source I had is, you know, if you can get that standardization into, uh, the, the, the vibe coding tool or into the visibility, then you actually had a better way to solve this problem.
The hope, hopefully, and I see the same works, uh, even in the scale, uh, the the key thing, standardization, uh, and, uh, and the best practice in the, in the get go in, in the code, not actually to say, oh, I already a mess. How do I curate it? Right?
Mm-hmm. So, And does that lead to better observability and monitoring because, um, able to identify things that are deviating from standards, AK anomalies, and those are the things that are worth investigating? Yeah.
Yeah. You, you're, you're spot on. You know, for example, you know, we have, uh, we have, uh, the standard called O Hotel, right?
We do metrics, logs, traces. And if you look at some of the issue with hotel is they have a thing called a cementing convention, which basically gives the fields the different, uh, you know, what the database called what the request really called. Uh, it's good, everyone understands good, but, but the thing is, if, if you want every developer to follow that thing, there's a hundred thousand names to track and everyone create different names.
Now, the issue is, if you call this a, you call this b in, in, in, in, in the wrong time site, you don't even know which is which. But if you standardize in, it's almost like visibility is built in. You're not even aware.
All you're gonna do is you run a code interpretation is already building. Uh, you go there, you just ask four questions like, what do I have? Um, are they running?
Uh, uh, if anything fail, can you tell me why? And then can you fix it? And, and then developers should spend more of their time on the creation, not on these sets of things.
And then the best way to do that is try to make the whole thing standardized, you know, generated. And, and then with AI sort of manage that, uh, versus sort of a, you know, training more and more people try to do observability. So What does the future of the software engineering team look like?
And I'm asking the question because will each member have their own small army of AI agents, or will there be kind one AI agent that is trained to handle a task on behalf of everybody, or some combination thereof In my way? You know, I, I think, I think ai, uh, in some way, we already had, all of us have a small server army working for us, right? We, you know, we will de charge GBT, which is a question answer bot or do Gong, which is a sales bot, right?
We'll do, um, you know, in the, in the, in the document search or another bot, I think what happens in the coding space, uh, you will have some coding agent really good at the, at the, at the UI there, there's some coding agent, really good at understand your specific domain, like a payments, you know, you have some coding, really, you look at it debugging. Um, you would just leverage them, you know, sort of calling them to, to your, uh, to on your call. And that's actually not that different from, uh, if you, if you, if you step back, look at what's going on today, right?
So today, every one of us would run hundreds of thousands of machines on the AWS. Now that's basically, we summon all the machines with different jobs, and they coordinate all this stuff. Compared to 10 years ago, every one of us have a desktop.
We just run it. And then we just, we just gonna scale to these things. I think it's gonna happen that way too.
Like today, we're only running one code agent. I think in the future, we just gonna have lots, lots of power. Everyone will still collaborate with other, other developer.
We could do a hundred, a thousand times of productivity. Um, I think, uh, I think that's how you would work with, with coding agent. Obviously you still work with your coworkers.
We all have a different domain expertise. That's fine. But that, that's how I see it.
Hmm. Every time there's a new innovation, we, we've seem to see the same patterns. We use it to do what we're currently doing, slightly faster, but you can't help but wonder if maybe we should just reinvent what it is we're doing in the first place.
So as you kind of think about software engineering in the future, what's it gonna look like? Um, I totally agree with you. I mean, uh, if you, uh, this happened with every, uh, every innovation, right?
When, you know, I'm just thinking out when mobile happened, people said, it's a smaller desktop, let me carry around and let me click. Right? And towards then it's become news feeds.
It's become Uber. And, and I think, uh, it's a pattern that everyone, when the new technology come, everyone is gonna sync their flow and fits to it. Um, I, I, I don't have a match wand, but I would say for, uh, I think, I think software engineer will, um, in some ways a liberation.
'cause if you think about it, uh, software engineering, uh, today, it's much more like a manufacturing process. Means you spend most time coding, you spend most of time fixing and debugging, uh, you don't really spend that much time creation. You, you do have a little bit creation, I think, I think eventually because the manufacturing process become so fast, software engineers almost become like a crater.
Uh, like if you think about how creative created videos, if you think about people who manufacturing and produce shoes or whatnot, they, their main thing now is the design and not fit together. The taste. I think the software engineering will be like that.
They can wielding the AI coding much better, but majority, however, they're not on the TBI typing forever. They're just gonna waiting the, the agent to, to, to perform doing this thing they wanted to do. So that, I think software engineering was much more close to a creation process versus sort of a manufacturing process like today.
Ultimately, then, what's your best advice for your fellow software engineers who are looking at these issues and trying to sort it out themselves? Because I think everybody's having the same thought process. Maybe not at the exact same time, but eventually they're coming around to the same issues.
Exactly. Um, okay, so, you know, I'm part of software engineering too. I've been in the block vault for quite a long time, right?
So, you know, initially it was, uh, you know, on-prem software, and then there's internet, right? And there's, uh, uh, then there's sort of a cloud and there's a mobile, right? There's AI in every, uh, aspect.
I, I sort of went through this process of like, okay, that thing wouldn't work, right? And then, and if you, if you, if you try to look at it from your perspective, right? You, you, you're sitting at the place today, you look at the, you're always like, that thing wouldn't work.
And my recommendation is like, you, you first change your recommendation, it should say, if you really believe AI will work, you say, well, the AI will work. How does that work? I don't really know.
How would you, how would you then make sure you're part of AI wave, you should be staying in it. Like I would, uh, uh, I would refresh the technology. I would use ai, I would get into the company with Marcos, that space, and then, and think about like, I want AI work.
Now, once that happen, I think you will be part of that evolution. You'll learn all the things along the way versus to say, okay, is there safe spots that AI wouldn't touch it? I, I think it's very hard every time when you see this technology innovation, uh, it will start with small, it will start with boutique use cases, but eventually it will be prevalent.
And you're gonna know these things, you know, it's gonna change, uh, everyone's life, right? It's like a cloud data, like a mobile data, like internet data. I think just sort of embrace it and try to say, you know, I'm part of a, you know, AI movement, how do I learn, how do I adapt?
Uh, and then you'll find, you know, the, the, the, the path even brighter. So, All right, well, folks, you heard it here. Even in the age of ai, there's still no substitute for hands-on experience.
Hey, gee, welcome. Thanks for being on the show. Thank you very much.
Cheers. Point And back to you guys. And Steve.
Hi everyone. Thanks for joining us again in this breakout session of the Red Hat Cloud Fridays with AWS event where you get real talk about real solutions. This session is going to focus on Red Hat Enterprise Linux, and our title tells you that we are looking at how to go beyond standard and take, unlock the real value of RL to get value on AWS.
I'm Simon Briggs, I'm the ecosystem sa focused on AWS across Europe, million Africa at Red Hat, and I brought a special guest with me today who will introduce him in a second, but it'll become plain that he's a real expert on the power of Rel and will present the majority of this session. So if you'd like to introduce yourself. Yeah, Good, good day, everyone.
My name is John Regan. I'm a, um, specialist solution architect looking after our Relapse Enterprise Linux platform. And thank you for having me on this panel today.
It's good to have me on board. Let's dig into what we're gonna talk about in this session. So we're gonna talk about why AWS cloud is important, um, as a channel for customers to be able to get to Red Hat, um, software.
Um, then we're gonna talk about the different ways that you could buy Red Hat Enterprise in, I sent some of the other software. I'll just, um, mention it in passing, and then we'll get to the meat of this presentation where, uh, Yuan, who I can never pronounce his name properly, so I do apologize. Uh, we'll go through the power of Red Hat Linux.
Now I have, um, mentioned that q and a is encouraged, and you can use the chat section to enter questions throughout our session, but we are actually going to answer any questions in our conclusion session after this one, which will run as part of the, um, cloud Friday event. So please ask away. We encourage you.
So why is AWS really important? Well, the fact is, red Hat understand that our customers love to work with AWS. And of course, when our customers need to do things, red Hat listens, and this has been backed up with research.
So, um, last year, 2024 Red Hat, uh, worked with canals, another name I can hardly pronounce, um, and produced a report when we were analyzing how important ISV or third party products are, um, when being purchased via the hyperscale clouds. And this is an absolutely massive, uh, market that has essentially grown up in only 10 years since AWS brought out the first genuine, um, hyperscale marketplace. Um, it's looking at, in 2023, it was around $16 billion.
The forecast for this year, extrapolated from that research goes through to $45 billion. And as you can see, the expectation is that we'll only keep growing. So in fact, 2028, we are moving towards $85 billion.
And in my personal experience, I joined Red Hat to work on, um, hyperscale cloud partnerships because I know that any of the analysts expectations are conservative when you look at the explosion of interest within the industry about utilizing the services the hyperscalers can provide. Importantly on the right hand side, there was a couple of findings in this report that I wanted to bring to your attention. First of all, um, many organizations are looking to use a hyperscale marketplaces to involve third parties trusted advisors, effectively in that procurement process for software.
And that actually is an interesting capability that we've now got available if you are looking at buying r through one of your partner organizations. And also, sometimes we found that organizations didn't get the best commercial, um, arrangements wrapped around their investment on third party software coming through this route. Obviously this is a survey from a year ago, and organizations are maturing all the time, so things will have improved.
But back then we saw there was lots of dollars being, um, left behind by customers that they could have accessed through buying programs and funding. And certainly some of the capabilities we have in offering Rail to you will help you access better buying conditions. So saying that, how do customers buy r on AWS Well, there's multiple options for you, but at the core of all the options is Red Hat's understanding that when customers are wanting to buy through AWS they're looking for a cloud experience.
That first of all gives them flexibility. Our customers constantly tell us that they want to be able to buy efficiently where they need when they need it, but at the same time, there needs to be quality in the stability of the service that they're purchasing, the capability that they're purchasing needs to be solid, to be able to drive the critical business applications they deliver on them. And also they need to be confident that there's a secure wrap around that technology.
Of course, security has always been pri primary factor in customers understanding of how they should procure software for their businesses, even when they've been working solely on, um, on premises delivered platforms. But in the modern world, extending into cloud services as well as including those, um, on-premise platforms, um, means security is even more critical to organizations. And certainly we will touch on that in our discussion about how powerful Red Hat Enterprise inex is.
And then also touching on that affordability piece where we mentioned that in our analysis some organizations are not getting the best buying conditions, we understand that we need to make that available to customers. And because of that, we have several options available to you as an organization looking to buy Red Hat Enterprise Linux today. So there's four different motions that you can, um, use to be able to procure the software.
And let me, um, describe them in this way. The two outer options here, the two pillars on the far left and the far right, um, are, um, route to procure software that have been available for many years on AWS cloud. Um, the one on the left has always been available, so customers have always been able to buy Red Hat Enterprise it for all the powerful reasons that we will discuss later in this session from Red Hat and our partners.
Um, and then take it themselves and utilize the subscription they've purchased on AWS cloud. The right hand column, the console column, describes another buying motion that came about a few years after. Um, EC2 became a standard service from AWS, and that was where Red Hat and AWS were together to turn AWS into a Red Hat certified cloud service provider.
And in that case, AWS sells Red Hat Enterprise Linux baked on top of EC2 images to customers on our behalf as a cloud service provider. In that scenario, the customer is able to procure in a pago fashion from AWS. But a couple of things, um, are, um, important to understand when customers buy that route, buy from that route.
First of all, AWS has a fixed price in that model. We work with our cloud service providers and, um, those service providers provide royalty back to Red Hat in the background for the software that's used, that is ours. Because of that, our pricing is quite fixed and there's no scope to be able to buy, provide any special pricing to our customers.
Um, although importantly, when customers do buy PayGo via the console, they are buying through a cloud, um, motion. So therefore it is via AWS as a partnership and it's recognized to spend against any spend agreement the customer has, whether it's an EDP or a private purchasing agreement with AWS. The spend on the Red Hat software on top of the EC2 is recognized.
As I say, it's a cloud-based transaction, but you don't see that this is, um, channel friendly. So where we were discussing, um, earlier our research about the use of, um, uh, independent software vendors services on AWS many organizations were using partner organizations to, um, e exploit the value of those services. Um, in the case of the console procurement route route via AWS, the um, channel has no place.
And that's why the two offerings in the middle have been created and recently announced. So Red Hat now has the ability to sell Red Hat Enterprise Linux via the AWS marketplace. Importantly, you see at the bottom that, um, that opens up a channel friendly route for our customers.
Um, the, uh, business value adding partners that they work with can, um, help in that procurement decision for the customer. There is a place for them in that, um, procurement route whilst it is still a cloud-based transaction. And the spend is recognized in a, um, against a committed spend with AWS as well.
There's two pillars 'cause there's two forms of consumption from a customer point of view. They can, um, either, um, subscribe to a committed term with Red Hat via, um, a marketplace offer, or they can commit to a wider consumption deal with Red Hat that covers multiple Red Hat software products. If you are interested in the consumption model, please speak to your Red Hat representatives or our sales later on in the Cloud Friday event, and we'll be able to explain more detail about what, uh, a consumption agreement with Red Hat will look like.
But rest assured there are different options for organizations, importantly with the marketplace offers that are available because Red Hat is the organization selling to you, you are actually buying via Red Hat, but procuring through the AWS marketplace, we can offer through private offers, um, extended pricing, um, agreements, which would recognize longer term commitments to the software packages, and also the amount of commitment you spend with Red Hat, um, in entirety rather than the PayGo model I mentioned earlier. So what actually are we talking about when we are talking about those different options? The option, when I talked about console is represented in this AWS slide.
So you can see there that many of the Red Hat Enterprise Linux server derivatives are available today through that route. But when buying through that route, you are buying directly with AWS. We have the ability to, uh, deliver SAP with ha.
Uh, we have the ability to just deliver Linux server with ha you can deliver, um, across many of the instance types that A-W-A-W-S support, be it graviton instances, uh, outpost instances, arm instances. And we do have special builds for application types such as SAP or Microsoft sql. But, um, on the right hand side, we've got a more extended list of the software you can procure on the AWS marketplace.
You can still buy the types of software I've discussed as being available on the console. It's just different buying motion. So you can still buy Red Hat Enterprise zenex in the forms we've discussed for console.
But importantly, there's one extra, um, uh, type of rail offering in that marketplace list. The Red Hat Linux, including third party Linux migration and extended lifecycle support. That's a special kind of listing that Red Hat has made available via AWS.
You can buy it direct from Red Hat yourself or you can buy it via the AWS marketplace. But that, um, subscription allows organizations to take any derivative, um, operating system that they have today that maybe is out at support such as CentOS and migrated across to be a fully fledged Red Hat Enterprise Xanax instance to get full support and migration supported from that subscription. Um, I'll also highlight the, recently we're very proud, we released the Red Hat Enterprise UX AI listing on the AWS marketplace.
That's a Red Hat enterprise ux, um, instance, which is specifically curated to give value for organizations who are looking to build trial and deploy their initial AI workloads. So if you are looking to build agents or bots, which will add benefit and features to your organization, but are not yet at the point of wanting to deliver highly sophisticated collaborative ai, um, infrastructure across a much wider platform, then Red Hat Enterprise Xenex Server is a fantastic solution to help you access those capabilities. It gives you access to GPUs and also a curated version of the Instructor Lab's open source project, which allows you as an organization to augment your large language model with your specific, uh, intellectual property and data sources to be able to deliver a particularly customized AI solution to your organization.
So that's a quick high level description of what Red Hat Enterprise UX services are available today through AWS. And at this point we'll change gears and allow our specialists to talk to you about the power of Red Hat Linux and how it works on AWS as a cloud. Thank you, Simon.
So you've explained, you know, the options you have in terms of getting Red Enterprise Linux or RES is more commonly known in, into AWS, but Red Enterprise Linux is probably the most well known Linux distribution out there, and we have thousands of customers that's using it within the cloud environment, but also on-prem. And one of the key things that we've trying to find is that very few customers only run in an environment such as AWS typically have, um, that on premise, they may have it in some of the other cloud environments, they might even have it in edge devices. So Simon, one of the key things that we're looking at is that customers aren't just running the environments singly on a AWS environment.
I have very few customers. It's sort of in that scenario. Most of them have been migrating from the on-premise environment into cloud environments.
They may have some edge devices and so forth. So this is becoming a very complex environment for them to be able to manage and look after, and how do they get that flexibility back into it to be able to see what is going on, to be able to quickly deploy fixes and being able to see, um, you know, analyze and access and remediate any of the vulnerabilities they have into the space. And being able to do updates fairly quickly from a single point of view, whether it's sitting in a cloud or whether it's sitting on-prem.
Now, the probably the best way is to bring in a little bit of analogy in terms of why did is low cost carriers so successful? Where did they come from? How did they manage to do this?
How do they break this into the, the, the market? Um, similar probably to how we see our client providers doing something very similar. A few years ago, you know, 10 or 12 years ago, they've done also sort of a similar change within the market.
And one of the key things that they really achieved is through cost savings. And that is using a standard aircraft across the range, same parts, same maintenance crews, same engineering that they need. But also if we take it a little bit further, so that is sort of analogy to our operators, but we take it a little bit further to the pilots, the pilots need to be trained on the same aircraft.
So again, some developers, again, need to understand the same operating system, improve security. Inevitably their cabin crews know exactly what is the standards and features on these aircraft. They have one training module they have to go through to be able to stand this.
And this is why we're trying to bring this back to our operating system and why we're saying why do you need, want a single operating environment within your, um, landscape. So some of the common deployment challenges that we see a lot of customers having in terms of deploying it is that they have to deploy at scale. And it becomes, when it comes at that scale, it becomes more and more complex.
Do I manage a different Linux sitting in the cloud? Do I as to what I'm having on-prem? Do I use a different Linux again at my point of sale systems that's sitting at the edge that I'm having to use for my accounting systems and so forth?
So we're trying to find a way that we can com we can manage this, uh, very complex at scale environment consistently, and be able to have a standard operating environment as they have standard aircraft, a standard operating system within our environments that the Linux operators know and love, the application developers know and love, and everybody can be able to be very quickly in terms of provisioning and updating, managing this environment. But why a single operating environment? And it comes down to efficiency.
And I'll show you in next few slides where Rail has done real work and, and we as reta done real work with AWS to be able to very quickly be able to help customers to provision new environments out there, to have standards, um, deliveries of the operating system to be able to simplify the, the, to support the onboarding that we have. Security is always such a key concept, and it's not just being able to have the environment secure, but these patches and fixes need to be deployed very quickly. And if you have one single operating system that you need to, to manage and deploy this, these fixes to, whether it's sitting again in your on-premise environment and the different cloud environments and AWS very quickly, it can then be able to be compliant and be able to fix those security things.
And then just having healthy patterns to sustain your automation. And again, when we start looking at how do I manage automation the same way as I would manage, um, it within my standard operating system in on the premise, I can use the same automation methodology sitting in the cloud. So what do we mean with standard operating in terms of red enterprise Linux?
Well, first of all, rail runs in almost anywhere you can think of that an operating system is required. And in the most majority environment it's the physical bare metal environment. It's our virtual machine sitting in on-premise environment.
We can have a private cloud where we want to run this in, we do it in the public cloud, for example, in AWS we can even have it in edge devices, like I said, point of sale systems. But I've seen rail being used in wind turbines in the North Sea. How do I manage it?
How do I actually have that capability of having all of this disparate systems under one pane of glass that I can actually see what's happening, understand what's the vulnerabilities, what patches needs to be applied, um, what is the analysis behind it? Well, red Hat satellite is the tool that we do in all of this. So all I do is extend my Red Hat satellite manageability to the pro the, to the my a s environment and at the same time then group them, whether that system is running on a s or on prem, they can be part of the same group being able to manage them, complete lifecycle management behind it, being able to do updates and patches and so forth.
I also have Ansible automation platform. That's another tool on our arsenal. Again, the same automation tools that I'm using on, on-premise environments I can use for the same row environment sitting my, uh, cloud environment.
It's the same Linux, the same applications can run the, the same playbooks can be executed in the different environments. And again, single team that can manage both my cloud and my on-prem and my edge devices. And finally we have Red Air Insights, our SaaS solution that is the capability of being able to look at the cloud environments, including your on-prem environments.
Again, but the beauty behind this, we have the advisory level behind within that. So it will actually scan and look at the current environment you have, not the applications, not the data, just the operating system and advise you on how to fix certain things, how to improve security, what fixes needs to be applied according to these things. What is the best packages to deploy?
And within an example I have a little bit later I'll show you how to do those deployments into that environment. And that sort of creates a whole ecosystem around, well for us in a cloud environment, on-prem environment, edge devices and so forth. And if we look at a bigger picture of where Red Hat Enterprise Linux really plays, I've spoken about the management side, I've spoken a little bit about the deployment and we'll go into that, but we are really strengthening in, in terms of security and compliance, making sure that you can harden the system environment.
Quite often customers, especially financial institutions, governments come to us and say, I need to have a hardened environment, CIS level two or Ansys Gap or P-C-I-D-S-S for the financial institutions. And again, we can do and help with the security compliance to be able to level up with those developers. We still have a huge amount of developers out there that needs to develop and deploy in this environment.
We have a broad ecosystem to be able to help developers. And again, that can be deployed within your a s environments. And then just in terms of the consistent performance you have, if you run rail on premise, you run rail on your, uh, uh, cloud environment, you know exactly what you need, you know exactly how to manage and migrate it.
And then migrations going back and forth. If you want to migrate from on-prem into the cloud, same operating system, same application, same management styles you need to do, if you need to do upgrades on-prem and in the cloud space, same upgrades applied to the same operating system. So again, strengthen the real reason why you want tore have r in your cloud environment similar to what you have in your on-premise environment.
Now, one of the key great features that we've announced with R 10 coming, um, out of our uh, um, summit event last, uh, two weeks ago, is that we have worked very closely with our cloud providers to provide an optimized Red Hat enterprise Linux for each cloud provider and especially with AWS as well. So benefit from the seamless integration that's designed to work with that cloud provider environment, making sure that the tools are working, that the telemetry and the information you're getting from that. And again, that those specific, um, environments for the cloud providers is being pushed into the marketplaces.
And for the AWS environment, this is the red it will now find within the marketplace. Again, close integration with CloudWatch, using the Open telemetry tools, making sure that the network performance is part of the Elastic network adapter and have it all the AWS two CLI tools within the operating system itself. And those are available now from Marketplace specifically strengthened, applied, and made sure that they're optimize with AWS working very closely between Red Hat and AWS to create you the best operating system that we can deliver.
But also if you don't want to go with the marketplace, there's a different way of doing that as well. And again, we're trying to help our customers to make better decisions when they actually want to build these things. And again, from the operating system point of view, our system operators, how do we do that?
And within the Red Hat insights, even if you don't want to use the telemetry and you don't want to use the application tools, I suggest go and have a look at the tool, which is called Image Builder. And that is the ability to be able to create an AWS image that I deploy from scratch, but it's taking the latest packages, the latest details that I have, I can harden that, I can add additional repo repositories, additional applications, create the whole blueprint. This is not the final product.
This is a blueprint. It's almost like a recipe, you know, if you get a recipe for your good amisu putting, you want to dessert, but you only do that once you just before the guests arrive, but you don't want to steal all one out there. Similar with the blueprint in Image Builder, I tell it exactly what I want in that image, but it only gets to point when I need it.
And then we'll pick the latest and greatest RPMs, the latest updates from the packages, the fixes, the fixes, and we push that out into the environment. So lemme quick go through a few just, um, examples of this. This is, um, from the image builder.
com. I've re-added all my details in terms of a AWS, um, details. I've added some magician repositories and so forth in this instance.
Then I'm gonna select that I want to deploy this specific image to the AWS, but I can pick any of the others and I can also have on premise environments like VMware and so forth. So the same package, the same blueprint I'm using here. I can push into other cloud providers, not just AWS and also to my VMware or my um, KBM environments.
One of the key things, of course, like I said, is that I can then pick the specific, um, uh, uh, AWS account I want to use that is getting immediately in there. It sort of defaults to the region that I typically associate with that, um, account. And then the next step is that I can then the, the, the side of I want to do hardening.
Now this is one of the things I really want to highlight with our users in AWS in the past we've seen some red out images being floating around that has hardening in that it doesn't come from red out. So please, I i I just wanna portion our users about that. Rather use this tool that we have of here, we have about 25 different levels of hardening.
You can pick in there with a specific to your PCI, whether in, um, for example, that I have this CSI level two or level one server. And we will create the hardening right at the bolt time for you for that specific image and that you can then push into your AWS environment. The next step is where we do AWS package selection.
I've just brought up there that I'm picking the AWS um, uh, CLI tools in there you of course can add all the other tools that we typically put in the, uh, AWS environment for our marketplace images such as the telemetry and so forth as well. And again, you can add in your own repositories into this tool as well with additional packages that you want to deploy into that specific image. And then finally, I can deploy this finished built image into my environment.
The blueprint will be ready and I can redeploys over and over again and again, each time I deploy it will build it from scratch with latest RPMs and latest fixes in there. I can select the size of the image I want the count of the image, I can add additional information, a few screens I didn't show, but I can add in my SSH keys into that. I can add in additional users time zones.
There's a whole RAF of tools that I can use this for my deployment if I want to do my own deployments in AWS. And again, this is where Red Hat really comes into play, where we're trying to make your enterprise Linux deployments that you want to put into this environment as easy and as quickly as possible. Whether you want to bring your own licenses as Simon has described, or you want to pick it from the marketplace, the offerings are both the, and you can be able to pick and choose between the two of them.
And then we've announced Route 10, as I said, uh, a few weeks ago. This is a really a significant release for us. And I just wanna highlight four key things that, um, we've brought into this specific release.
The first one is image mode. Um, this is a container technologies that is being brought into your, um, operating system so that the operating system, the virtual machine, the BareMetal deployment, the a WS deployment is behaving more like a container than previously it did with, uh, an operating system. And again, we can, you can, we can discuss this more in the summary section, the QA section afterwards, we have command line assistant, um, that is an AI engine that's within the command line itself.
So if you forgot how to do a certain command, I certainly do because, um, you know, uh, we do forget things that we've done two years ago. I can ask the command line assistant exactly how do I actually execute that command or even write me a little bash script and so forth. One of the key things that we are looking at is, um, when quantum computers come online, we are really worried about how quickly and possibly it's ability to be able to decrypt our current encryption keys that we have if we get to quantum computing.
So again, we're starting to apply a lot of post quantum encryption algorithms into the keys for L 10 to to, to be preemptive to that going forward. And then finally, within the satellite I mentioned this is one tool that be able to manage both your on-prem and your and your um, AWS environment altogether in one single environment. We're now bringing that advisor label that we have an insights into your satellite environment as well to be able to help you very quickly with those.
And finally, back to you Simon. Yeah, so thanks, thanks for that detail about RL as was called out. We can talk about the, um, new features of RL 10 in the summary session.
We've got after the breakouts from Cloud Fridays, just to say we've quickly added some QRS here so you'll be able to go if you interested, is speak peaked and do some more research on the technology. And of course we've got upcoming sessions. We've got, um, sessions where you can pick, um, the session to talk about automation through and small automation platform on AWS or how you should maximize, um, spend through marketplace on AWS.
Um, but all these resources are recorded and will be available for you to catch up on if you had to choose one, but you'd like to understand both. And we do encourage you to watch all these sessions we think are very valuable for our customers. And that leaves us with just saying thank you.
Thank you to my fantastic, um, counterpart here. Jan, thank you very much for your session today. It's great to hear the detail you bring and thank you from us to you as customers for sitting through this session and joining us on Cloud Fridays.
Simon, thanks so much for inviting me and thanks to everybody who joined us.