Techstrong TV December 16, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
You know, there are some days, no matter what Broadcom does, it seems like the market just doesn't like it. You're watching Textron Gang. Hey everyone, happy Tuesday.
It's Alan Hummel here. You know, we've got a, we've got a small but mighty gang to go talk about, to talk about things today. We've got a bunch of people out.
It's Christmas coming, other people are at conferences. And I'm really happy though, to have Kate Scarsella and Hope Lynch with me on the gang today. You know, it's not an orphan gang where we have more women than men.
So mark this down, and that's a good thing. Um, it's Tuesday. I guess it's, is it the week before Christmas at this point?
Yeah, by the time this week's over next week will be Christmas. So it's the week before Christmas, but the news is not slowing down. Um, we've got a lot to go over, ladies.
So wanted to start off with, uh, Broadcom, you know, they, they reported what to me. I mean, they beat the estimates. They upped their, uh, their guidance.
They announced, you know, who the big mystery customer of a new $21 billion chip order came in. You know, uh, their CEO gave an impassioned speech on why, you know, people want custom ASIC and so forth, but yet their stock got punished. I, you know, I, this is why I'm not good.
I good stock investor makes no sense to me. Kate, can you make sense of this? No, I can't either.
So, just to review here, Broadcom made headlines this week by this massive 21 billion custom chip order. Um, and at the same time, um, they were, you know, Broadcom, CEO push back on the idea that only Nvidia can win in AI calling Google's TPU strategy, a transactional move. So for me, um, gosh, I always feel like we're writing off, uh, Broadcom generally, and I think Broadcom as a whole has always been across the board, even with their, you know, raspberry pies.
I mean, they are a phenomenal, phenomenal group, Broadcom. And so I wouldn't write them out just yet. So, you know, custom, you know, who would've thought a custom chip when chips were first made?
Who would've thought right now that we would be talking about custom chips? I mean, that is, you know, this is why I think we will continue to go down custom chips, um, path and Broadcom is, is, you know, definitely moving in the right direction here. Yeah.
Um, I have a little bit, there's a little insight though about, um, Broadcom's performance and what, and what's going on. I think, um, based on the reading I did, wall Street basically feels that it's a little bit of a shell game, because Broadcom is basically acting as a pass through manufacturer. So they're taking Google's TPU designs, they're manufacturing them, and they're delivering full racks to anthropic with no markup.
So they're passing the cost directly through. So even though they beat earnings, their stock dropped because the investors are concerned. They're saying, well, you're not adding any markup.
You beat earnings. So, you know, is it, is it evening out? So are you actually doing as well as you thought?
Their margins are still great, but, um, it, it seems that they are being punished for the benefit that they're passing along to anthro. So, I, I think there's a few things at play here. Hope, I think you hit on some of them.
Number one, they are overly dependent right now today on Google as a customer. 'cause Google, they are the manufacturer of choice for Google's TPUs. And anytime your business is dependent on just one customer, you know, it's a single point of failure.
And, and so people are gonna be cautious. Number two, I, I think you're right. They are serving as a pass through distro, if you will, operating on razor thin margin there, uh, in this particular anthropic order.
Um, I think that's why, and I always forget his name now, uh, the CEO of Broadcom, uh, hang, hang HK HK HK 10, it comes to me. You guys will be this old soon, one day too, don't worry. H 10.
Um, I think this is why Hakan was saying that this Google TPU thing is a transaction, a transactional move. But what he's really saying is he's pushing clients to custom chip destiny, because no one wants to put their fortune on someone else's stack, if you will. Everybody.
He thinks everybody's gonna want to design their own chips that are customized for their unique use cases. And that Broadcom is happy to be the manufacturer of choice for these custom chips that you design. But using someone else's custom chips may be, you know, okay, for now, but it is not where you wanna be as this AI race, you know, explodes and, and, and continues to move forward.
And so what he's looking to do there is broaden the base, not just Google. Now, they already have a huge deal with open ai. I, I forget for how many hundreds of billions of dollars over the next X years.
But of course, that's contingent on open AI spending one and a half trillion dollars that they don't have, um, today. Anyway, so I I, I do think that that is a, um, part of, of what, what, what's going on here. The other thing though, in Broadcom's defense, look, they went out, they bought ca, they bought Semantic, they bought VMware.
These are software, not hardware software companies where you have better margins generally than you do on hardware. And they're basically cash cows, right? They are, um, books of business that kind of just, they're cash cows, and that should really help with their cash flow and their margins.
So I'm not quite sure in light of all this why they still deserve to, you know, be lower. But it, and the funny thing is, I, I'm not, I'm not a finance guy, and I didn't sleep at a Holiday Inn Express last night, but if you, you know, from what I read, if you look at what the, you know, the experts on the streets say they all have it as a buy long term, or most of them have it as a buy long term, but yet the stock still got hit. One, one other, um, bit of nuance for this that I think could work long term in Broadcom's favor is for the past five years, everyone's been talking about GPUs and building out for models, right?
A lot of the models now are built, what they now need is, uh, performance per dollar on inference, workloads, inference is the future. Inference is everything at the moment. And these TPUs, um, are optimized for the architecture that models like Claude, No doubt.
I mean, would Amazon, Amazon has train. That's their inference. Google has theirs.
Rumor is Microsoft's gonna have theirs. And I think that's where, where he htan is going, that everyone, that inference is gonna be the battleground, right? Video has a stranglehold on the GPU training market, if you will, but everyone's gonna want their own inference to be a player, because that is where the action's gonna be, Right?
And they're, they're betting on the idea that, um, ai, it, it won't be like one size fits all. And I think that Broadcom is really well positioned for that at the end of the day. So, You know, I, I agree.
I mean, they, they seem to be the inference chip maker of choice or the, or the inference chip manufacturer of choice. I do think that long term, that's where Intel has to be playing too, right? But there are others.
We're not finance. I I'm not a finance person either, but hey, I'd go out and buy Broadcom. Yeah, I mean, I, I think it's a good idea.
Well, hey, we're not giving investment advice though. Please, you at your own risk. Uh, the last thing we did, but, you know, there, there are some other plays in that inference.
The Marvel is one Micro, I forgot Micro something is another, but certainly Broadcom is, is a major, major player there. And, um, it'll be interesting. But here, here's just one other thing I wanna throw out at y'all as, so this $21 billion order from, uh, anthropic, all right, it's 21 billion.
I think Anthropic could probably cover it, but there's a lot of deals on the books, especially, and now we've spoken about this before, the open AI deals, you know, they, they pledged one and a half trillion dollars between AI data centers and AI chips that, like in the case of Oracle, and in the case of Broadcom, represent a significant amount of their booked revenue out there in the future. And if that doesn't happen, if there's a hiccup in the market or something doesn't work out right, that could come back and be a real, that could drive these stock prices really Yeah. Into the ground.
It's, uh, it's the, the AI angst. Yeah. Right?
It's because Anthropic, oh, go ahead. No, no, I was gonna say it's a big bet. Yeah.
But Anthropic commits $21 billion of Broadcom for TPUs. Anthropic has raised around $33 billion in funding. They're evaluated at around $180 billion.
And this is from Google, Amazon, sovereign Wealth funds, others, right? But Google is also anthropics cloud infrastructure provider, and they're manufacturing TPU through Broad No, but think about they're buying, so basically They're all in bed together. They Really, no, it's, it's a circle of money.
com days, we were in a really bad contract with World Cup MCI, world Cup for Bandwidth. I think I was paying, not me personally, the, I had helped a company grow called Inter Reliant. We were public company, big A SPI think we were paying like $1,200 for a t one line worth of bandwidth back in the day.
And the going market now was six or 700. So we were paying twice what, but it was a contract we had signed a couple years before, at the time, it seemed good. And, and this company came to us and said they were setting up a broadband trading commodity desk, and that they would buy our, uh, broad, uh, WorldCom.
It's funny, Broadcom WorldCom, they would buy a WorldCom bandwidth at $1,200 and through the magic of arbitrage and, and commodity sell us back, in essence, the same amount of bandwidth for 700. And they, you know, and they could do it all day long as much as we had. And I, I was the, I was the, uh, VP or SVP of biz Dev Corp dev, we went down with my CEO and COO to, um, actually it was to Houston, to a company called Enron, because that, that, that, that, that was the company that promised us they could do it.
And, um, the full Spectrum of, of, Uh, yeah. You know, and I'll never forget, right? I sat here, the three of us were sitting, and there were these all Enron people around us.
And this one would buy it from us, trade it to this one, trade it to that one, give it to this one. That one would cohere this one, and then this person would sell it back to me. I said, how do you do that?
They said, we've been doing this in the commodities markets for a generation. We know how to do this. I said, okay.
I mean, you know, it's Enron. They're big company. They get the big E downstairs at the, and I, I'll never forget, I walked out of there, I asked the CEO of our company, herb Rebar, who was an old cell phone guy, telecommunication guy.
I said, herb, how did they do that? I, I just, you know, I feel stupid. He said, either they're the smartest people in the house, or they're the biggest crooks.
And, uh, as it turned out, right, yeah, that's how that turned out. So, you know, this thing will implode upon itself, or it won't, I guess we'll have to see. Yeah.
But hey, Broadcom, I mean, having all the different, you know, other Broadcom's a solid business. Yeah. I mean, between the software, and they still don't forget most, even the big public cloud providers, as well as most data center providers, it's still Broadcom that is powering a lot of that infrastructure.
Not the CPUs or GPUs in a particular server, mind you. But the networking, uh, gear and everything, it's, you know, it's a fantastic, I mean, I feel like they're everywhere. Every time I turn around, it's something Broadcom and No doubt about it.
All right. I'll be happy to hear you say that. Well, Look, I, and I, I, I'll just end this with, as I said before, Kate, hope and I, we're not, we don't have a horse in the race.
We're not here touting stocks or telling you what to buy, or you do what you think is best. But we're gonna take a break here on the gang. We're gonna come back and talk about, I call it data center nimby.
You're watching Textron Gang. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included, that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
Hey, everyone, we're back here on the gang. So interesting. You know, a admit amid the 5 trillion to $8 trillion plan data center, AI data center, AI factories, as you may call 'em, build out over the next couple years, we're now seeing some pushback.
Some of the pushback is, is very kinda local. You know, the typical kind of NIMBY stuff. Oh, you didn't say you were building it in my backyard, right?
Go put it over there, where those people are, where those people aren't, you know, in the woods, in space under sea, just not anywhere near me. Um, and we're seeing more and more of this, the latest being a, a city over in Arizona, um, rejected, uh, a plant data center because of that local pushback. Um, and there's, there's other reasons for it too.
The fact of the matter is, a lot of these AI data centers aren't bringing the jobs. Yes, there's initial jobs in construction and bringing it online, but once they are online, these are not labor intensive. Uh, you know, these not manufacturing plants or something like that, that you have a lot of workers.
But on top of that, now, uh, an environmental group has asked, uh, Congress for a pause on these projects because the, the environmental potential for, for, for catastrophe is they claim not something that's trivial, right? It's primarily around, well, what, what are you using for energy? Are we, are we gonna rush nuclear on all of a sudden because we, we need it desperately?
Are we diverting water? Are we, are we gonna fire up coal plants to do these things? Um, you know, what are we doing?
What are we, what are we doing for cooling if we're not using water to cool, are we using chemicals? Are those chemicals being disposed of properly? There's all kinds of, you know, love canal scenarios here that they, they're forcing on Congress, you know, generally, you know, we're, we're past the spotted owl phase, I think of, of the government stepping in on these things.
But, and, and, and look, the government has a stake in it too. So I, I don't know what the likelihood, I mean, ultimately, I guess it winds up in courts, but I mean, our Congress doesn't really show much of a backbone to get involved in these things. Hope.
Kate, what do you think? Uh, speaking of government and speaking of the courts, um, there was an executive order on December 11th that is setting up a showdown over data centers. It is ai, the, the AI litigation task force at the Justice Department that will sue states and directs, um, commerce to potentially withhold federal broadband funding from states that don't comply.
So this is them saying, uh, you know, this is a, the new version of eminent domain, I guess, right? So Kirsten Sinema, she is the person who went to Chand Arizona to basically tell them, Hey, um, you need to approve this now while you still have local control, because if you don't, we're gonna override you anyway. So this is a, this is a big fight.
And one of the other interesting things about this fight is it's become very bipartisan, um, because it's unified, not over ideology, but utility bills. So residents in these areas are probably gonna see their power pills jump, uh, anywhere from 15 to 20% over a few years when they're not gonna get any of the benefits. Really no direct benefits from it.
And I still don't understand, I mean, and help me here, I don't understand why it is that, that it's passed on to consumers, the, the expense at the end of the day. I can someone help explain that to me, like the cost for, for energy. I like, why don't we pass it back on to the company.
I, Uh, well, one of the reasons is because it's, it's part of the grid, right? So this is not something that is just localized to the data center. So where I live, it's, it's Duke energy, right?
If Duke Energy has to build out, um, those build out costs are not necessarily directly built back to what caused the build out, but they are peanut better spread across a whole region. So it's definitely a spatial mismatch in, uh, distribution of benefit and burden. And that's part of what's driving the, the backlash.
Yeah. It, it's not like this is a dedicated circuit that you flip on for a data center, right? What, you know, what the utility looks, looks at, and, you know, from what I've been told, what the utility looks at is what is its total, uh, capacity to generate power.
And then the, you know, the, the, the cost per watt, megawatt, gigawatt, what have you, is based upon that, right? How much are they totally generating versus, and so what do we charge? Now, there are some of these data centers that are, or factories or whatever you wanna call them, that are, are supposedly being designed to have their own contained nuclear reactors in a container or something, right?
So that they don't go on The grid they want in their backyard. Well, yes. You know, no.
Who wants those in your backyard is right. But for the most part, these, these monster data centers are gonna be on the power grid and, and consumers will pay their share. And, you know, in another era with another congress, you might see legislation that says, Hey, for the good of America, we're making these companies, these data center companies, bear the cost of that.
And everybody's electric bills go down as a result. But in today's bizarro world, where corporate greed is king, we all bear the cost for these data center companies to be able to come on, you know, and the, the, the flip side is, oh, they're bringing you jobs. They're bringing you this, they're bringing you that, and they're not.
And that's why like the city in Arizona said, you know, when you, when you do this, it, it doesn't add up. It's not weighed out. Um, so, so it, it, and, you know, and then there's the whole environmental factor to Even with water.
I mean, water for this is, you know, gosh, that's really a, a critical commodity, especially in Arizona. I, you know, I remember when Intel was there and the big fight with Intel in Arizona. So I mean, you look, look at where they're building these Arizona, west Texas, right out Abilene way, not that way.
It's, it's, um, you know, in, in the Midwest, generally, like Ohio and, and some of the places where they're building there, they have a little bit more water resources. It makes more sense, but that's also why they're looking at building 'em in the bottom of the sea and up in space and everywhere else, because, you know, of the, of the heat issue or temperatures issue. Um, but you, you know, here's another, from a legal point of view, hope you, you're right, this is coming to a showdown, right?
States rights versus federal, federal government does have, uh, rights over interstate commerce. And they'll probably say that these data centers are part of interstate commerce, because, you know, they transmit data across state lines. But the issue is, can this be done by executive order without an act of Congress?
And that underlies a lot of what the Trump administration has done. Congress has actually done very little to approve a lot of these executive orders. And again, there have been a lot of the courts that say, no, this, this is, this is an action that is reserved for Congress, and it would absent a congressional order.
It can't be done by fiat. Um, now, to date, the Supreme Court has not come down on this the way many thought, um, though under the previous administration, they were very clear about it. But I guess the previous administration didn't appoint three or four of the judges on the panel.
So, but you know, this is, this is not the way the system was designed. I just, at the end of the day, I mean, I hate that. Again, we seem to be flipping the bill for ai, like we are per, and, and we are personally flipping the bill over and over again.
And it just, you know, forget about even the monstrosity that's going up in our backyards, but we're paying for it. And it just, it, it's not right. So, in my opinion, No, as they're saying in a lot of places, it's not what we voted for, right?
Um, and, and so we'll, we'll see how this plays out. Ultimately, it, I, I think, look, these, i, these AI data centers gotta pay for themselves. And if the, if the every man is gonna be footing the bills in, in, in, you know, in the form of higher electric and higher utility bills, I, that's gonna make for a real problem.
You know, Houston, we got a problem. Anyway. We'll, we'll see how it plays out.
It's gonna be interesting. 'cause $8 trillion is a lot of money, guys. Yep.
Not to mention that the I-B-M-C-E-O says that even you look at that $8 trillion buyout, uh, the 8 trillion, trillion dollars build out, and there's just no way it could be profitable, right? Given money's generated and everything. But who am I to argue?
Let's take a break. We'll come back and we're gonna talk about Alice Unchain. That's right.
Our first Textron Gang concert. No, it's not. Stay tuned.
Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, everyone, we're back. No, we're not really doing a concert, but I just wanted to get an idea of how many of you out there remember Alice Unchained?
Truth be told, it was a little before my time, or a little after my time, excuse me, But I remember. But yeah, I would imagine Kate might be your time. Uh, but we're not really talking about music.
We're talking about something called Alice from IBM. Don't ask me what Alice means, but hope you may know and tell us more. Yes.
So, IBM research announced Project Alice at newer IPS 2025. And Alice is a agentic logic for incident and code bug elimination. So, uh, it's part of IT operations, and the estimate is it outages cost over $14,000 a minute.
So finding the bug, finding the problem, um, is, is a big deal. So what is interesting about Alice and different from how others have approached the problem is they are using sequential multi-agent approach. So instead of, um, one AI trying to handle everything, there are three specialized agents, and they're working like a relay team.
So one is incident analysis, another is code context that, um, builds a graph to show how microservices connect. It's, it's basically giving you the landscape, and then a code analysis agent comes in. Um, and this is powered by IBM, that shows you where the bug is in the code base and gives you an issue in GitHub.
So the major point about this though, is this is still, this is still basically in a lab. This is still being tested. This is not in the wild, this is not available for purchase.
And with some of the caveats around it, it probably could be, let's say two to three years before it's, it's publicly available, but it is an interesting way of attacking the problem. So companies like Datadog, PagerDuty, um, they're gonna be sitting up and paying attention because this is gonna offer them potentially some competition. Competition.
Oh, I, I would think so. You know, just a silly question. I I was never, I never made up, uh, names like this.
Do you think they started with Alice or they, they said, what is, what are we doing? How can we make it smell, spell something cool? I think somebody probably, They said, oh, I need an EN No grandma.
For me, when, when I saw the name Alice, um, I thought immediately of Bob, Alice, and Bob. So now we just need Bob Alice for networking security. Alice used to hold the private key.
Bob held the public Key Eve was for eavesdropping. I, I mean, there was, and so when I thought, oh, project Alice, my first thought was, oh, we just need Bob. I, I mean, I, I literally thought it was, um, it was a shot back or quantum theory, Bob and Alice.
Alice and Bob. Um, but yeah, so I am sure they didn't intend that, but that's where my head went. Mm-hmm.
Mm-hmm. Um, and for me, you know, when I think about this, I, I personally think it's going to, I, I think just like vibe that we thought would take a heck of a lot longer. I think ag agentic AI for the win, I think this is gonna come around a heck of a lot sooner, especially if IBM is already announcing it as a person who worked for IBM for over 20 years, um, that they are already announcing it is, is really, really cool.
They're announcing how it's, how it's going around it, it goes out to GitHub. And this is phenomenal. And, and, and a person who had to design, you know, socks, not system on shift, but security operation centers, you know, when we started bringing in network logs, and I don't, you know, it, it became, it just was unmanageable from a human perspective.
Now, we started to add applications, database, blah, blah, blah, endpoints. All of a sudden it was like, oh my goodness, what the heck? We're never, you know, we couldn't detect an anomaly if, regardless, I mean, we had a hundred people on our team.
So this is a really smart way, I think it's, it's, Hey, I love Alice. So she's, she's not around yet, but I love her, right? And, but one smart thing that I think they're doing, it feels like a, a strategic bet on, um, long-term interoperability, is they are using the MCP from Anthro.
So once it's built, once it's in the enterprise, it should be able to connect with any external models and tools that support MCP. So they are, you know, it's, it's proprietary tech, but it plays, supposedly it will play well with everything. And for it to go into GitHub and for MCP, I mean, it, that's, you know, hello IO ot, right?
I mean, MCP uses iot. Um, I mean, yeah. Anyway, you know what I'm saying?
So, yes. Sorry, I do. So, you know, in my mind though, and Kate, no disrespect to, to your time at IBM and the Big Blue, but I, I-B-M-I-B-M has a way of announcing these things, and they're visionary and cool as heck and exciting.
And it's like, wow. And then a funny thing happens on the way to market It. It, it's true.
I mean, we, we had a whole Watson for QRadar and yeah. And yeah, no, we, it, you, I, I'll give you that al it didn't go. Yeah, but I mean, but I, you know it, but I love the idea of it and what, what they're trying to do here is the right thing.
I I think another aspect of it is this whole multi-agent thing, right? This is the world we're gonna live in, right? To go all call Sagan on you.
We're gonna have billions and billions of agents, right? And so our platforms, us as, you know, people are going to need to learn to live in this multi-agent system where, um, we're gonna have multiple agents, agents, some of them overlapping, right? Some not.
They're all gonna talk to each other, whether it's through, uh, MCP or A to a or, or what have you. Um, but that's the world we're gonna live in. They're digital coworkers, and it's not just one of them.
And I think wrapping our heads around that, you know, because, and again, we've discussed this on shows here before, are these agents ephemeral? They do one thing and then die and go away and get recycled? Are they perpetual persistent?
Well, if you watch Murder Bot from Apple, that would be a no. Yes. Well, I didn't watch that yet, but now I will.
Um, but I mean, so this to me is sort of the great unknown as we, as we move into this multi-agent world. And I, I do agree with you. I think Agen AI is coming fast.
Um, it, it, One, one other point, sort of a counterpoint. So Google also released a research study this week, and they tested 180 configurations across five different multi-agent architectures. And they found more agents don't necessarily mean better performance.
And for sequential reasoning tasks, the very same scenario, the very thing Alice does with the Relay race architecture, all multi-agent variants degraded performance by 39 to 70% compare it to single agents. Now, one other thing to consider, you have these agents, these three agents working in sequence. What if the first agent makes a wrong assumption?
The other agents, as they are currently designed, are not made to validate or correct assumptions. It just magnifies. So now it gets to the SRE, they're junior, SRE, they take it at face value, and they chase this until they find that, you know, it's, it's bogus.
A senior SRE is going to spend time validating it. Are you really, you know, how much, how much do you gain? So, so basically this whole, um, you know, the whole false, false positive is affecting a gen gain as well.
That's good to know. That's great to know. It's not just with humans.
So I I, it Does not escape. I I view that as growing pains, though. We'll, we'll figure that out.
Yes, I think they will Factor first. You gotta get the, a single agent working, then start thinking of it in this multi-agent world, they'll put kind of the rules there in place. Um, but the, you know, the question is how fast do you figure it out?
And, and reiterate, right? It's just like DevOps on steroids, deploy feedback loop reiterate, deploy feedback. You know, if you have sort of ephemeral agents, you could do that really quickly.
Yeah. So, so Alice is not out of the game yet. Alice is not outta the game.
Now, I didn't think of Alice on change, nor did I think of, wasn't it Ted and Alice and Bob and someone else? It was, it was Alice and Bob and Eve. And if you think about it, Eve was Eve's dropping, so that was cute.
Mallory, you had, um, uh, you, I mean, they do, uh, Carol became identity. Uh, they, they actually had the whole alphabet of characters as we grew the stack. Yeah.
So you are remembering correctly. But Alice and Bob were the first. There you go.
So, but I thought of Alice, the waitress, the TV show. Oh, I thought of the Brady Bunch Alice Too. Oh, she was one of my favorites.
Alice on the Brady Bunch, for those of you who may not remember, but you're a real Gen Xer, huh? Kate? Yes, I am.
I am. Okay. Hey, I look, I look, you know, I, I'll admit I was, I was a big Marsha Crush.
Hey, and so was I Really? I think we like March. She was cool, except when she got that thing with her nose and she didn't like it.
Anyway, I could see we're degrading here. Let's pull this back. Um, it, it's gonna be an interesting, but you know what, we're about out of time.
Hope. Kate, thank you so much for coming on today. As always, I thank you so much for watching.
We hope you enjoy your Tuesday. As usual. We've got a lot of text on TV and it's the week before Christmas, everyone, things could be worse.
You're watching Textron Gang. Hey everyone, welcome back here to another text on tv. I am happy to introduce you to Anthony Richie.
Anthony, welcome to Tech Drunk tv. It's great to have you on. Thank you, Alan.
I appreciate you giving the opportunity To kind of talk to you today. It's my pleasure, Anthony. Yeah, I didn't even mention you're from DigiCert, but we're going to get into that.
Um, let's, let's start off though, before we talk about DigiCert, let's talk about you a bit. Give us an idea of, you know, what your position at DigiCert is and, and maybe a little background on how you came to, to be there. Absolutely.
Yeah. So I'm, uh, the VP of Global Solutions Engineering and really kind of focused on the technical resources that we have within our organization, working with all of our customers in, in a pre and post sales capacity. So we have a lot of interaction with a lot of our top, um, top org top organizations that we do business with on day, day in and day out basis.
My personal experience, I've been in cybersecurity since around 2007. I actually ran my own organization. I was A-S-S-L-T-L-S aggregator back in the day, integrating with all the different public T lss and prior to that, just in it, in a variety of capacities for 32 years.
I hate to say that. So you, so you just broke into the business, you tell Me, right? Yeah, yesterday.
What behind the, Yeah, you and me both. Um, so, and that, and that's actually a great background for, to, to bring, to dig sota as we were talking off camera. Anthony, I think DigiCert has some of the rightest minds in the industry when it comes to quantum cryptography, when it comes to certificate technology and, and PKI and these kinds of things.
I mean, really, like PHD, smartest hap mm-hmm. Absolutely. Like rocket scientist kind of people.
So it's, you know, but you'd need people who also have that real go to market who understand what, what, what, what the market wants, what people need, where, where are the, where's the pain? And, and that, that's an important part of it. You know, I'm record realizing though maybe not everyone is familiar with DigiCert out here.
Anthony, if you wouldn't mind, give people a, a sense of, well, in your own, you know, from where you sit, what's DigiCert about? So, DigiCert's about public trust and increasing our capacity to help with cryptography, uh, from a public and private perspective in a variety of different organizations. And we're about kind of building that trust factor.
It's not just about the encryption, it's about the verification and validation of the different identities that you're either, you're, you're proving authenticating, you know, from a non PD perspective or, you know, signing and understanding kind of the different artifacts that are deployed within an organization. So we do a variety of different capacities, but, you know, foundationally, you know, PKI kind of sits there as our, um, our foundation for a variety of different use cases and workflows that we support for our, uh, or organizations across the globe. And you mentioned it, you know, and I think it's a, it's a testament, you know, in terms of the things that we do as thought leadership within the marketplace, you know, the people that we have globally, that the footprint of the operations of DigiCert, it's second to none.
You know, the, we, I'm always amazed at the people that we have and contribute to our customers to help them kind of build, uh, a better security posture within their organizations. Yeah, I, I agree. And, you know, part of that, of course is staying, uh, on top of the latest developments in, in the space.
And, you know, for, for DigiCert, one of the big ones is this whole post quantum cryptography issue and algorithms. And, you know, Digi, I remember interviewing people from DigiCert three to five years ago that were working with NIST as we were developing these post quantum cryptography algorithms that now we're available way before QJ way before everything else. You know, we've got this available.
I see. Almost obligated. I should mention we're working really closely with DigiCert on something called, I think it's the Quantum 25.
If I miss if I have it wrong, I apologize. But it's the, it's nominations are open right now for the top 25 folks in the, uh, quantum field because DigiCert is, is and will continue to be a leader in that space. And, and they're really, you know, forging ahead with this.
We're partnering with them, we're excited by it. And I'll just mention to anyone out there who knows someone who they think qualifies as a leader in the quantum space. Go, go check that out.
You can get through it on Techstrong as well as on DigiCert. Yeah. And Alan, to, to that point, go ahead.
Quantum Security 25 is an important aspect of kind of building that momentum within the post quantum space. And, and certainly we we're, I think they, we have until January 28th or to, you know, when there's are gonna be announced, but we want people that are gonna move the needle in the p qc space and be able to kind of support and help us have a better public interaction between different organizations. From a crypto cryptographic perspective, p QC is a big deal.
And Ellen, I've been talking to, I mean, a number of customers and surprisingly, like I'm immersed in it every day in day out, you know, from PKI perspective. But when I go talk to organizations that haven't even really moved the needle or understand what's going on, and believe it or not, there are organizations, large ones that aren't ready, right? They're still, they're kind of, you know, putting their head in the ground, if you will, and not seeing some of the things that they need to do from a security perspective.
So we as thought leaders within the industry need to be able to kind of, you know, enlighten them, educate them, and then bring them to a place where they can get ready. Alan, you made a point. You know, they, you know, NIST did approve some of those, um, standards, but, you know, NIST is, was US based, right?
So other governing bodies within the eu, you know, they're looking at other encryption algorithms as well, like classic I mees, for example, as being something that, that the EMEA region is looking at as well. So at DigiCert, we have that visibility across the globe to kind of support our customers wherever they're doing business, whether it's, you know, stateside or in near region or in a PJ. Love it.
Excellent. Anthony, I didn't want to turn this into a, a post quantum cryptography interview. I know you are not the expert there.
We've got other things you and I need to talk about. Recently, DigiCert announced couple of key strategic relationships, partnerships, and developments. If you wouldn't mind, make our audience smart a little bit on what, what's been going on.
Absolutely. You know, as we go into this, uh, you know, like, uh, certificate, uh, validity periods are starting to shorten as well as some of the validations that have to happen from an organization perspective as well as a, a domain control perspective. And the challenge for organizations is they're still doing things manually, right?
Being able, you have like, uh, IT operations folks that go into a server generate CSR, and people that don't know what A CSR is, a certificate sign or request. It's basically the request for a certificate, and then they upload it into the system. But in a day where we have cloud native technologies, Kubernetes based deployments, you know, cross built in the cloud on premises, the proliferation of certificates is, is incredible.
It's not just one or two, it's thousands and tens of thousands. And as we shorten these validity periods, we're now, they're about a year for public TLS, they're gonna get down to 47 days by 2029. So we need to ensure that we help our customers build these agility processes or velocity in terms of the enrollment and deployment and the binding.
So what we've done is we've made some strategic partnerships with, uh, Citrix and F five to kind of help support that velocity and help, you know, identify, uh, organizations that are using their technologies and then building solutions for them to be able to kind of push those certificates, support them, discover and certainly renew those when needed. So organizations can focus on what they're best at, whether their service or, um, products that they're building for their customers, not necessarily worried about the, uh, security aspect of it, I mean, worry about it, but bring in the right people to kind of help support that. And with these partnerships, you know, DigiCert with, uh, you know, certainly Citrix in this case and F five, we can kind of build that model to kind of help them support their businesses.
Absolutely. Look, Citrix F five, to me, those are natural partners of DigiCert because of the natures of their business and where they sit in the IAM uh, kind of food chain, if you will. So, Anthony, I'm recording this.
We're recording this while I'm out here in Vegas at, uh, AWS reinvent. And I gotta tell you, to me, the theme out here is ai, all AI all the time, it seems, right. How is AI specifically like with these partnerships with Citrix and F five and Digi Digi Cert, how, how is, how's AI impacting that?
You know, AI is everywhere, like we were talking about earlier, and I'm surprised it's not in my ketchup bottle yet, but it will be there share, right? It might be that just haven't told you forget, But, you know, I think, I think the, the, um, the worry, you know, from the, the space or worry in the market is like, how do we control ai? How do we validate AI and X 5 0 9 certificates?
And digital certificates are that capability to kind of drive that non repudiated identity of these agents, AI agents in particular, and DigiCert. And, and we didn't mention it, but you know, we, we actually have not only PKI cyber, you know, PKI foundational products, but we are a DNS player too. We're one of the largest DNS players within the nation.
So we have our altered DNS solutions that give you the capabilities to do and, and to do a variety of different identity management or validation of identities. Most people probably listening to this, um, interview will understand, you know, DNS sec, uh, operations for, you know, fq DNS or websites, that same type of solution. And of course, we have, there's different standards.
Uh, the A two A standards that are being, uh, formulated kind of support the AI model. And we as DigiCert can support that through DNS as well as some of our PKI solutions that we have. So what's happening is, is that we're taking, you know, we're, we're on the forefront of building different models and trust models for organizations and helping them deploy these within their organizations to ensure they have the proper AI or proper models that they're supporting within their organization to support their businesses.
Let me throw you one outta left field, and if you're not prepared to answer this, it's okay. We didn't, I'm Luck handed, so I'm good. Okay.
So the, the, uh, CEO of AWS yesterday said, you know, in the very near term future, like within two to three years, let's call it, um, there's gonna be billions. I don't wanna go call Sagan on you, but billions and billions of AI agents out there mm-hmm. To me, I'm ready to call my DigiCert people and say, Hey, how do we, how do we certificate these AI agents?
How do I, how do I make sure this is the real AI agent and not some rogue AI agent or a a, an evil clone or something else? Man, that's a scary proposition, right? With billions of these agents running around the, it just seems like the, the potential for chaos is, and, and for e you know, for mal malware, I don't wanna call, I don't know if you call it malware, do you call that malware?
Um, it could, Right? I mean, training it inter inappropriately for to do nefarious acts. Yeah, absolutely.
Uh, you know, where do you see Digi and, and you're gonna need the f fives and the, and the Citrix's of the world, 'cause this is, is probably is bigger than any one company. Yeah. Right.
So I think when we look at, uh, the validation of the, the authenticity of the agings certificates become that, um, that model to kind of help deploy that and deploy and, you know, so I look at it as agent is another aspect of, um, control that we need to support. So, you know, we talk about different appliances, applications, you know, we deploy within the clouds. We have, you know, Kubernetes based deployments with microservices where we need to, what we call mutual authenticate, and we use certificates for that.
Like I have a certificate that says, I'm Anthony Ricci. You have one that says you're Alan Shimmel. And then we have a trust, a a, a root of trust, which in this case is DigiCert or an organization's, um, root certificate that we're supporting on their behalf to prove that trust.
So if we both trust the root, we can trust who we're talking to. So if we were AI agents like your Alan AI and Anthony ai, we'd certainly be a lot, probably smarter. You and I, if we had AI agents talking on our behalf, we can have identities associated with it.
So it's not only just an identity for a person or an appliance or applications. We can do identities for AI agents. And the deployment and management is all around the protocols and industry standards that we are participating in to ensure that we have a safe deployment of those technologies.
I don't know, it sounds kind of Mr. Smith out of the matrix, right? Bill Bluefield to me in There.
Oh Yeah. Anthony, I wanna, we gotta kinda wrap up. So I wanna bring it back to Citrix and F five.
Where can people get more information about these partnerships? com and, uh, look up our partners, and then you'll see we have the different press releases within our website. Please add a request and certainly we'll have a team and a, a very seasoned team kind of work with you through some of those, uh, different questions that they have.
Absolutely. Um, look, two good companies we work with, you know, we obviously cover both of them, so sounds like three good companies here going, going to to market together. What could go wrong?
Anthony, thanks for coming up here on Tech Trunk TV with us today while we're out in Vegas. I appreciate it. Come back, maybe we'll do something actually the, I know DigiCert has a bunch of their trust, uh, events going on worldwide.
Maybe we'll catch you in person at one of those. That'd be great. I usually have, I usually do some different talks about implementation and how we, I'm all about helping the customer, but thank you for having us spending the time with me today.
My pleasure. I appreciate you getting on here early with us. Anthony Ricci, uh, DigiCert here on text on tv.
We're gonna take a break. We've got more Stay tuned. Hello and welcome the latest edition of the Textron AI Leadership Insight series.
I'm your host, Mike Bazar today with Mike Lynch, who's the head of the AI transformation Services for auditoria. And we're talking about, well, how AI is impacting the financial services sector. Mike, welcome to show.
Thank you Mike, for having me. I think everybody out there is grasping for some way to understand, well, just how are we using ai? What impact is it having and where is that elusive ROI?
But you guys do a lot of work in the financial services sector and they're usually at the forefront of these things. So what are you seeing? Yeah, no, it's a great question, Mike, and uh, again, thanks for having me.
So really, when we talk about AI and where we've been over the past, really six to seven years, as the office of the CFO has really tried to transform forward, it's, it's not a question of if we're gonna in integrate AI into our processes anymore. It's really a matter of how fast and in what areas. And so at auditoria, what we've seen most of the offices of the CFOs start with is areas of the office of the controllership, so mostly in their accounts payable and accounts receivable space.
And we actually run an annual report where we look at the state of AI transformation in the office of the CFO. And, and it's really interesting to watch those trends over the past six years as we've done the report to, to think about where things were before. And then of course, when you have the advent of chat GBT just a few years ago, what has kind of, uh, like a hockey stick accelerant of, of what's happening there.
And so what we're primarily seeing is that a lot of customers and a lot of companies are trying to find value in automating those repetitive tasks that they're doing on a regular basis in a, with, with AI that is auditable, transparent, and understandable so that they don't necessarily have to go, well, we sent it into a black box and some other stuff came out on the other end, and they, and then they don't know what happened and where it went. So, uh, we're seeing that that actually really transform. Yeah, it's, we're talking about about an 85% reduction in manual things like reading email boxes and responding to supplier inquiries or responding to customer inquiries where you have to go in and, and grab a copy of a bill or a copy of an invoice and send it back to somebody.
So that's a significant ROI where, where companies can choose to say, okay, we wanna realize actualized cost savings, or in many cases what we're seeing is they're saying, we wanna take those people from a, a menial non-value add task to strategic level tasks that such as supplier relationship management, such as chasing discounts on, on payments. The other area that we're seeing is significant amount of value is, is companies being able to reduce their day sales outstanding, their DSO, which really is a, it, it's a, it's a key way for them to be able to put their money back in their pockets instead of having their money in their customer's pockets. And so it's a, it's a great opportunity.
So when you talk about, you know, the, the ch biggest challenge with ai, especially in the office of the CFO, has been how do I actually see ROI, these are some areas that our customers are seeing some, some very significant ROI in those spaces. Mm-hmm. I think one of the issues that I keep hearing a lot about is the process matters and what you're using AI for, especially with Gen ai, and are people starting to understand that, you know, the more deterministic that process is, the more challenging it becomes to apply AI to it.
It's not impossible, but there's a lot more work because, well, deterministic means, you know, it's gonna be done the same way every time and AI never does the same thing the same way twice. Yeah, no, it's a great question. And I think that's where, when you, when you think about your processes, and, and this is actually why I think controllership becomes the, the forefront of opportunities is because in many cases there, there are processes that are driven by some pretty standardized processes at, at organizations.
So they have rules about how they process invoices, they have rules about how they send out bills, how they do Dunning processes. And so the, because there's some clear rules and regulations within those companies, they provide really fertile soil for automation. And so when you talk about how to apply AI in that space, that's where, especially when you see some of the companies, when they try and kind of go it alone and figure it out, they get into a little bit of trouble because you can't just claw or chat GPT up some automation in your, in your finance space.
Because while those are great models, they do a lot of things and everybody uses 'em probably daily at this point. They're not gonna be specific to the office of the CFO. And so what, what we do is we'll bring in our specialized reasoning model, which is a, a specially trained small language model to sit on top of the large language models, which help it do from doing what you're talking about, right?
So it's not just a, I come up with a new rule, I come up with a new thing every time because it's kind of generating on the fly. This is where it really helps them dial in those processes and repeat them in, in that fashion. And so that's where they're able to see it.
And I think that's, that's where, you know, when, when we do these with, and when I work with customers to kind of align their, their processes, that's a big part of it. They need to make sure that they have a good sense of what data looks like for their organization. They need to make sure they have good processes.
Where does the data reside? What are the flows? Where do we go and what do I really want my people to be doing, uh, going forward?
And so that, that really helps avoid the, the AI churn in the office of the CFO. And I think that's, that's where a lot of, a lot of finance teams are starting to see some value. Mm-hmm.
Um, early on, everybody was talking about how AI would, you know, replace people and everything would be highly automated. I think maybe as we've gotten into it and understand some of the limitations is, is that viable a little less out there these days and people are more realistic about what, what the benefits are? I think so we we're strong believers in the, in the concept of human in the loop ai.
And, and that's really that AI is not just gonna turn on and it's not a fire and forget type of type of activity. It's really an opportunity for them to turn it on and, and they get to be the strategic storytellers with it. They get to be essentially the supervisors of these new digital coworkers, these agents that are now working alongside them and, and so the, the humans, you know, are, are upskilling to not necessarily be the ones to process an invoice, for example, they're letting the AI process the invoice, work on the coding, get everything teed up to move into their ERP systems.
And then the humans are reviewing that work. Essentially. They've now become the supervisors of these digital coworkers, kind of a junior accountant, if you will, that's now on their team.
And so they get to then say, yes, that's great. Go ahead and write that into our system. And so it's not eliminating the humans, it's reducing a lot of manual time.
And so I think there's a luxury that, that folks in finance now have to, to really think about it. And then they've never had this luxury before. It's what would I do if I had some extra time?
And, and it's, they've always been buried underneath paperwork, buried underneath emails. And so now because they have this opportunity to let the digital coworkers kind of go and do a lot of processing at, at high speed, they now get to think about what's next and, and what other value can we provide for our organization. Many of these of these groups are, are running a shared services function, they're responsible to the organization.
And so now they get to talk about insights and data storytelling and analytics, whereas before they were just kind of treading water to keep up with the, the pace of, of the transactions that they were trying to make. So moving, you know, it, it sounds kind of cliche, but from transactional to transformational is really kind of where we want to get them. What is their reaction from people that you've talked to about this?
Because on the one hand, I mean, I'm not a finance person and I look over there and sometimes to me I see a lot of what I recall, you know, mind numbing, soul crushing work, but then there are other people who love that stuff. So, you know, they're kind of heavily into it. Um, when they look at ai, what do you hear from those folks?
Yeah, no, and, and you know, there was a saying, um, actually a colleague of ours uses all the time. He goes, you know, finance people aren't boring people. We just like boring stuff.
And, and so, because they kind of like the boring stuff. Uh, it's interesting because the finance folks have a really analytical mind, and so they really want to dig in and figure out how AI works. And, and so I think for them, in some instances it's kind of a new challenge, right?
It's kind of a new, the new crossword puzzle or a new thing for them to kind of figure out how this thing is working for them. So there was definitely some initial trepidation. And I think especially to, to your earlier point, they were worried about things not being exact.
Now in many cases, you have senior level finance folks that say, look, get it within 5%. I don't need everything to be exact. I need everything to be directionally correct, mostly complete, mostly accurate.
But most of those senior leaders weren't demanding 100% every single time. And so, but the people wanted to produce it at a hundred percent. And so I think when you talked about the early stages of AI and how they were adopting it, that was a big concern for them is, is it's not 100% accurate or they couldn't, they couldn't prove that it was 100% accurate.
Now, over time, they've seen the results of it and they realize that, oh yeah, this is, this is processing what I'm asking to do. It's, it's moving forward. It is not a silver bullet though.
That that's, it is one of the big misconceptions that I think folks had initially of AI is that it was gonna come in and do everything for me. Like CFOs will be able to kind of kick back in the nice leather chair and go, uh, tell me about this, or do something about that, or what happens if this, and, and while it does great at pulling data together, it it's getting better at, at being able to ate it together, put those analytics together. And I think really the next over the horizon a little bit, but not too far out of the way, not too far out there, is what we're gonna talk about in terms of causal ai, which is actually AI that's gonna help understand the root cause analysis of something.
So really, when they're getting down to the root cause of why did my numbers go up by 10%, that causal AI is gonna be able to kind of do some of that recursive searching back through the data, understand what are some of the, maybe some, some micro things that happen at my company as well as macroeconomic things that may have happened writ large, and then be able to deliver those insights. And, and I don't think we're too far away from that. We're not there yet.
But again, it's not a, it's not a bullet magic bullet. So it's, it's kind of an opportunity to, to understand what can AI do. And so the finance teams are kind of now, now gelling around that fact and saying, okay, it's really great at information extraction out of documents.
It's really great at automating some of these rote tasks. But again, it's, it's not magic. And, and so, you know, there now at the rate of change of technology and the rate of change of how people are, are developing this, uh, there's probably some stuff we're not even envisioning today that a year from now might look like magic to us today that's gonna be, uh, really impactful for the office for the C ffo.
So we're getting a little more agile than we used to be in the finance space. 'cause we were pretty, you know, you could take Excel when you pry it outta my cold dead hands type of thing. Right.
You know, Excel just turned 40 this year, and I think many of the folks that work in finance were there from the beginning. And, and so it's, it's really, uh, you know, it, it's a unique opportunity to see this, this, this back office function that, um, while, while it's rife with data and, and has all of the other information that's great for automating, uh, we're kind of, they weren't the ones that were getting all the shine, but now they're really able to to accelerate forward. Well explain that a little bit, if you don't mind, because there is generative and there's causal and there's predictive ai and all these things are a spectrum of tools that we'll be using, right?
That's right. And, and I think, you know, most of the finance teams, I, I by and large are, are generally staying away from generative AI because again, they, you know, you worry about model hallucination or something else where, uh, or to your point to your question earlier, it's coming up with a different answer every single time. And that's not what I want.
I want something that's you kind of, you know, taking a consistent approach. And so some of that, that predictive ai that that's looking at information helping to make insights and dri and driving that forward, um, that's, I think where people are gonna really wanna be. I think, you know, Gartner's Gartner did some research and they had said that causal AI is probably only impacting maybe two to 3% of companies today.
And that's really at a very nascent, almost an infancy stage at this point. And so I think that'll, that'll start to grow over time. They, they envision it's gonna be a huge impact to, to teams, but it's just, we're just not there yet.
What I think is, what I think is, is going to be the, the, the next wave that's really gonna impact the finance teams is the ability to pull data together better than we are today. So instead of having to go build a bunch of reports in your ERP or in a data lake, or however you've set it up within your organizations, they're gonna be able to use AI to basically go grab information out of their data stores and then provide those analytics using natural language processing. So being able to start having those conversations of, you know, create a report for me that's telling me about my sales over the last three quarters, lay it up against this type of information and, and AI is gonna start to be able to do that for you.
So there's some players in that space that are starting to get there. We're one of them, uh, with our smart research tool that, that I think is gonna be an opportunity for, for, you know, the finance teams to really start moving forward in that space, which starts to pick up other parts of finance, right? We talked about, you know, the office of the controllership, but this is areas where, uh, your FP and a teams, your GL teams, your financial reporting teams are, are gonna start to see oppor more opportunities for them to take advantage of AI in their space without having to kind of build everything from the ground up.
Because in many cases, for, for those teams to see a lot of value, they're having to create large data repositories and then stack analytics on top of it today. But I think there, there are tools that are gonna start coming out to help them do that in a much more rapid pa rapid pace than they can today. Um, they say that, you know, the thing about AI is that the AI we have today is the worst we're ever gonna have.
So as you look into 2026, what are you looking forward to? What do you think's gonna happen? Yeah, I mean, if, if, if the worst that we have today is something that could automate 75 to 80% of my manual tasks, um, I would say I'll take it.
But at the same time, I think, I think so. So the causal ai, I'm excited to see that. Are we gonna see it in 26?
I, I hope so. Um, I think that would be great to, to have those opportunities. I think other opportunities to continue to refine language models to be more trained for finance is gonna be key for people to see that value.
So not trying to go with some, you know, giant LLM to, to use against that data, but really starting to find those, those specialized models, which of course means you have to find specialized data to go train them on. And, and so I think, I think that's where we're gonna see a lot of value is, is those smaller models, those reasoning models, helping them move forward in that space because it just understands finance, uh, better than just, you know, pulling up my chat GPT on my phone and saying, Hey, tell me about my, you know, DSO. And it's like, I have no idea what you're talking about.
You know, I can define it for me, but it has no idea how to go grab my data. So I think that's gonna be the big piece, is being able to take those tools and apply them more directly into the finance space. So it almost seems to me, and I think we're kind of trying to figure this out, is, are people just gonna consume this using some sort of AI agent that's built into the software, or are they actually gonna go to the trouble of building their own AI agents that are unique for their business?
Yeah, and that's a great question. And there's a lot of companies that are kind of going through that build by, uh, conversation today. There, there are a lot of great commercially available tools that are out there that can help them accelerate and see time to value today.
And so I think when you have customers and, and, and companies who are, are really struggling really underneath it today, that, or, or they're under a mandate, you know, the, the CEO, the CFO, somebody says, the CTO says we need to do AI now. And so in some instances, they may not have the luxury of time to truly figure out how to line everything up internally to go kind of build it. Um, I get to building a second, but I think, you know, there, it's, it's actually never been easier to build your own agents, uh, within your ecosystem.
So I think, but I think a lot of those companies, because they're under a time crunch, they're under a huge amount of pressure to actually just do their d do their day-to-day job. I think many of them are, are pursuing kind of commercial solutions that are out there to move forward. As far as the building goes, you know, all of the ERP systems are starting to create essentially the opportunities to build agents within their ecosystems.
A number of organizations, and we're one of them. We'll use Claude internally to build smaller agents to kind of help us manage work to, to help with project workflow. Um, you know, you'll at Microsoft copilot in organizations, I know a couple of our customers that have, that have figured out ways to some kind of nifty ways to use Microsoft copilot to build some agents internally.
And so I think what we were thinking about and maybe three years ago in terms of a citizen data scientist, I think that's almost been overcome by this concept of kind of almost like a citizen agent builder, if you will. Um, I, you know, I'm sure somebody has a better name for it than that, but it, it, it's essentially, you know, these people are kind of going, alright, what if I could do X? And they're basically just kind of going and figuring it out.
They, they're not experts in the data, but they're using the tools that exist within their ecosystems to kind of go build it. And so I do think you're gonna see a proliferation of agents both commercially available as well as self-built, um, really, really over the next kind of year, year and a half. I, I think, and, and I talked to this about our customers because when they talk about where we're at in this space and really this transformative, you know, changes over the past number of years, I, I tell them, I said, we are the last generation that will hire exclusively humans into our organizations.
At this point. You're hiring humans and digital coworkers and, and that's not going to change. We're gonna continue to move forward in that space.
And so, uh, I think the future is gonna be a hybrid workforce and it's gonna look that way. Uh, we, you know, five years ago during the pandemic, we talked about a hybrid workforce as, uh, some people working from home, some people in the office. I think in this case, we're now talking about who's actually doing the work.
And in this case, it'll be both hybrid, uh, human and, and digital agent. All right, folks, you heard it here. The finance teams are gonna be at the forefront of this transition.
There's no doubt about it. And we're all gonna watch and see what happens. 'cause hopefully we're gonna learn from their adventures.
Hey Mike, thanks for being on the show. I appreciate it, Mike. Thanks for having me.
And thank you all for watching the latest episode of the Techstrong AI Leadership Insight series. You find this episode and others on our website, we invite you to check all those out. Until then, we'll see you next time.
Hey, everyone, we're back here with our day three last day coverage of, uh, our time at AWS Reinvent. Uh, this guy's no stranger to our tech strong audience. He's always either on a webinar showing you how to use Kubernetes, trying to make Kubernetes easy.
Some say that's an impossible dream. Um, or on text, drunk TV, talking cloud native and Coob with me. He's my friend Andy Suman of Fairwinds.
Andy, it's great to see you. Good to see you. Thanks for having Me.
You know, for people who haven't caught you before on either Techstrong TV or any of the webinars, give 'em a little bit of your background. Yeah, Sure. So I'm a long time infrastructure guy.
I've spent, well, my entire career working in infrastructure. I spent the last nine years working exclusively with Kubernetes. Uh, now I'm the CTO at Fairwinds, and we help people run Kubernetes.
We try to make it easy, like you said, And like I said, in some cases it could be a bit of an impossible task. But, you know, it's, it's funny, Andy, we, you know, we're, we're sponsored by Suitor. Uh, you are s Suman we're sponsored by suse here at, it's the last day.
I'm getting a little punchy. It's, uh, it's a long, uh, you know, we're sponsored by Susa at, at at here at AWS reinvent, and we've been spending a lot of time talking to the, uh, rancher guys about multi cluster Gotcha. Kubernetes management.
I'm sure that's something that's near and dear to you. Yeah, I mean, we manage quite a few clusters for all of our customers. We're familiar with rancher, lots of, um, lots of multi cluster stuff.
I think, you know, the one question we all have to ask is, um, where's the data live, right? Yeah. Everybody was say like, we wanna go multi-region, we wanna go multi cluster.
And I say, that's great. Where's your data gonna live? Because that's the thing that's harder to move between clusters.
I, I agree with you, and especially in a world of data sovereignty and, and all of those things that you're dealing with, right? Absolutely. But you know, what I found, and, and maybe, and I might be wrong 'cause I'm not the expert you are, but a lot of time multi cluster Kubernetes happens quite by accident, right?
You're, you are doing the Kubernetes project over here and you spin up a cluster. I'm, we're in the same company, we just don't talk. Yeah.
I spin one up over here. Jill spins one up there, Bob and Harry over there, and before you know it, damn, we got four Kubernetes clusters we're managing, but they're all kind of standalone. But you know, okay, now we gotta get efficient and we wanna bring 'em together.
Yep. So I I call that like the accidental multiple Kubernetes cluster. Yeah.
We have a name for it. Uh, our sales team knows this term. It's cluster proliferation problem.
Uh, CPP. Yeah. Yeah.
So, okay. We run into a lot of folks that have that, mostly large companies, lots of teams, different business units. They end up with a vast number of clusters.
The cost gets outta control. Um, and usually when we work with those folks, we work with them to consolidate into a platform. And so their end goal is let's get down to a manageable number of clusters managed by us at Fairwinds, hopefully, um, and build a platform on top of that so that all of these developers aren't managing all of their own clusters.
And the goal is let's make it easy for them while also getting control and governance and policy in place. Um, it's a lofty goal, but, uh, it's can be very successful for Folks. Absolutely.
Wow. Um, you know what, this was a good way though of introducing what Fairwinds does. And, and that You took me right up.
I did not even realizing it, but, but that is the kind of the, the bread and butter of Fairwinds, right? You've got people who have these, uh, proliferating clusters Yep. And you have people who are saying, Hey, I wanna modernize and move over, you know, from to a mo you know, maybe I'm going from VMware and I'm, I'm moving to another virtualized environment, but I want to go cloud native.
I Yep. You know, I want to go to a microservices architecture. Yeah, yeah.
Any architecture really, but yeah, microservices one, one way. Um, I had something I was gonna say and I lost it. It's okay.
We're live, so we just gotta keep rolling. So I'm gonna come up with something here for you then. Um, you know, I just recorded or played our shim, my shimmy says that I do every week, a little 10 minute video on LinkedIn and X.
But one of the, the, the theme of this week was, Hey man, DevOps cloud native and platform engineering are alive and well here at AWS reinvent. And, and my thought was, you know, when I first got out here, I was just like, bowled over with all the agentic AI announcements. It seemed like all AI all the time, right?
Yeah. And, um, but in talking to people and having conversations, you know, I'm hearing, well, one of the agen AI agents, Amazon came outwards with the DevOps, they're calling it a DevOps agent. Mm-hmm.
I don't know if I'd call it a DevOps agent just yet, but, but they have plans. They have big plans for it. Yeah.
But hearing a lot about DevOps, a lot about cloud native, right? Cloud native is the choice. If you are looking for transformation modernization, you wanna move maybe from on-prem to the cloud.
Not all the way you wanna do a hybrid, you want to, you know, um, cloud native has had a strong showing here at the show. And, and platform engineering is no longer a fad or a niche. It's, it, I think it's taken its place alongside the other two in, Hey, this, this is how we build software.
Yeah. How we run software. Absolutely.
Absolutely. You know, I, I would think at Cube Gun we talked about, we've launched a product to help people build those internal platforms, and it's entirely based on cloud native software. Yeah.
Because we really believe that is the future of platform and where it's going. And I think we could see it from Amazon as well with the announcement of the managed ar o CD and Crow Yeah. Act or a CK, um, you know, they're doubling down on Cloud native as well.
And so it's not going anywhere. It's here to stay. And it will be, you know, the future of platform and DevOps engineering as we as we know it.
You know, thinking back to the rancher announcement, what you just said is, is manage cloud native, the future, I mean, you guys manage for your clients, but you are also, you could come in, set 'em up and parachute back out, right? Yeah, Absolutely. Um, now, I, I had a similar experience in the cyber.
We didn't call it cyber the InfoSec space when I was there, which was after about 15 years, 10, 12 years, I realized that most organizations just weren't capable of managing their own security. It was, they didn't have the, they didn't have the budget, they didn't have the expertise. And quite frankly, they didn't have the stomach for it.
Uh, are we at the same place in Cloud native? I think so. With the larger companies, that's absolutely true.
You know, a lot of our customers, it's, it's one of one or two of those three things. It's either they don't have the time or the budget or the people that all generally rolls back to budget or they could do it, but they don't want to because they'd rather focus on business impacting things. And that's what we enable is, you know, let us do the things that you don't have the stomach for or don't care about, or don't have the time for, uh, and you can focus on your business.
Right. Always have that philosophy of, you know, outsource what isn't your core competency. Yeah.
I learned, I also learned that the hard way, the dot coms, I had helped start a company. We wound up going public. Uh, we were what they call an A SP application search.
So there's no cloud, there's no like T three lines of your in. That's meow internet. I remember that.
And, um, we're, we're offering hosted Lotus Notes, Oracle, PeopleSoft. And, and the lesson we learned is if it's not core and critical, those are the two things, right? Yeah.
Something could be core to your, to your DNA, in your case, Kubernetes expertise, cloud native expertise or critical. Your business can't run without it. It, you don't give up things that are core and critical.
Right. If it's core or critical, you might give it up. Right.
If it's not core or critical, you absolutely should give it up. Yeah, absolutely. Right?
Because otherwise you're just wasting money. Yeah. And I think for a lot of companies, the, the intricacies of managing a cloud native environment, managing any IT environment, if you're not an IT company, you know, it, it's hard.
But Cloud native in particular, because, you know, Kubernetes really never came with a chimey uneasy kind of button. No. No.
Batteries were never included. No batteries. Security never, never included.
There never included. No. Uh, crazy defaults was never included.
So what, what kind of, uh, you, you guys have a presence on the floor and everything. Yep. Yep.
What, what kind of, what are you hearing from people? You know, one of the biggest surprises to me, um, this is the first time we've had a booth at Reinvent. Mm-hmm.
Um, and, uh, in the past it's always been, you know, I always just kind of assumed that we'd get about 10, 15% of people using Kubernetes. That has changed, um, in, at absolutely this show. It's 85 90% of people really, you Think it's that hot that I talked to are using Kubernetes.
And maybe that's 'cause they're stopping by a booth that says Kubernetes on it. But, uh, go figure. But I'm talking to so many more people that are using Kubernetes or planning to move to it from some other container orchestration or something like that.
So it's a huge number. Uh, it's, it's good to see That is, that is, you know, I, so now you got me curious. I'm gonna have to ask everyone I talk to.
85 sounds really high. Yeah. Uh, like I said, confirmation bias on my part.
Yeah, No, but you know, the big picture number I always am told is that about 15% of payloads on the cloud are cloud native. Hmm. Now, a lot of that is because it's legacy stuff, right?
Yeah. Yeah. I'm sure there's quite a lot still that, you know, people aren't talking about.
Um, and it's also that, you know, I've said this in the past is that they're probably using Kubernetes, the company is, but what percentage of their workloads are running Are running it. That's a smaller, You're right. Absolutely.
That's a, that's a real distinction. Yeah. Because I think what it is, is Greenfield products very well may be 85%.
Cool. Yeah, absolutely. I think so Brownfield, again, people may not have the stomach to do that transformation.
Right. Or the need, I mean Right. Don't break what's not, If it's not broken, don't fix it.
Yeah. Don't fix what's not broken. Yeah, exactly.
Absolutely. Um, So this was your FI didn't realize this. This was fair One's first time exhibiting here.
Yeah. Yeah. Coming back next year Probably.
Yeah. Yeah. Worth it.
Good. Good conversations. Good customers.
Yep. Yeah. Good show for you.
All The right people are here. Yeah. Really good, good conversations.
And, you know, the parties are fun too. The part, you know. Yeah.
We did a, uh, a thing at the Sphere last night with you. A wizard of ours was pretty cool. That's Cool.
Yep. Um, wanted to talk to you a little bit about forget, uh, AWS for a second. Fair Winds.
Yeah. Anything new coming down the pike you want to share? Um, nothing that we didn't talk about at CubeCon, but I'd love to share, you know, our new product, IDP Quickstart.
So we are, I talked about a little bit a minute ago, but we are putting together with AWS um, they've built an app mod blueprints repository that helps you build a platform from open source. Uh, they did a couple of sessions on it this week, A couple of workshops. Yeah.
We're gonna be running another one with them, uh, next week, I believe. com if anybody's looking. Um, and we will show you the, the product that we're going to be building, which is get you started with a platform faster than you could probably build it yourself.
'cause the biggest problem with platforms is that people spend two, three years building a platform because it's such a complex task. And so AWS and Us together have made that much simpler, uh, kind of prepackaged it up for you, and then we can customize it to your business needs, and then you can build on top of that to, to serve your developers. So, I love it.
Yeah. Anything else you wanna share? No, it's all right.
Come to reinvent. It's a long week. It's fun.
But, uh, it Is a long week, but I, uh, it's worth it. You, you're heading home today? Tomorrow.
Tomorrow. Good for you. Yeah, me too.
Yeah. All right. Hey, you know what we did mention Fairwinds website.
com. There you go. Andy.
It's always good to see you, man. I don't know when I, well, I'm not doing you, you guys don't do K Con in Europe, do you? Uh, we will sometimes we'll have a person there, but we won't have a booth.
No, I'm actually, I'm not. Mike ards gonna cover Q Con Europe first. It's the same week as the R Rs a conference, so I'm out in San Francisco that week.
Gotcha. But we'll talk, and you guys are always on with your webinars and everything else around. We'll do something.
All right. Sounds good. Hey, we're live, we're at AWS reinvent on day three.
We still got some great content coming up for you. Great interviews. Stay tuned.
Hey everyone. Welcome back here to Our Tech Drunk TV coverage of AWS Reinvent for 2025. I promised you two more analysts, and here are two more analysts, both, both of my colleagues with the Future Group.
Let me introduce you quickly to them to the far right. He's no stranger to you. If you watch Techstrong, it's my good friend Mitch Ashley and the man in the middle.
Actually, you've been on a text Drunk TV once before. Yeah, I remember. But if you don't know Nick Patience, he is, Nick is our AI coverage specialist, but he's also, Nick is one of the founders, co-founders of the 4 5 1 group.
If you follow the tech analyst scene, widely, widely respected. Nick, it's great to have you here. Live with us.
Great to be here, Mitch, as always. You bet. Um, I didn't mean to embarrass you, but did I leave anything out that you want to mention about yourself?
My lifetime's a accomplishment. No, that's Good. Stay Right.
That's a good salesperson. Stop it. Yes.
Mitch, what about you? Just in terms of coverage, you know, I do kind of all things software development, um, AI agent development. Nick and I collaborate on the AI side of it.
I collaborate with, with Brad and, uh, Fernando in respective areas. So it's, it's a good team here at Futurum. Absolutely.
So guys, let's dive in. It was an exciting day. A lot of announcements in that keynote.
Um, you must be happy 'cause every it was ai, all AI all the time. It seemed for a lot. Everything is Every, every con, every conference is, so, yeah, it's good.
So I'm not, you know, let's say I've been around the block more than was Mitchell once taught me a saying from Nebraska. I may have been born that night, but it wasn't last. Right.
But it wasn't last night I learned all these Midwest Nebraska sayings from maybe well enough to turn up. We didn't have those sayings in New York, but Mitch, but Nick, how much of this is PR announcements that shows, and how much of it is rubber meeting the road? Well, I guess for these guys, for AWS they used to, um, leave everything to reinvent, so everything to this, this, this time, straight after Thanksgiving.
And they, they realized, um, yeah, the world doesn't work like that anymore. Um, so yeah, I think they, they had some really interesting stuff, uh, but it wasn't, yeah, some, some of the years you come here and it's completely like every, there's a list and it's so, so, so long. I think it, I think it's, it, yeah.
The stuff is, the stuff is real. I think you, you, you probably already talked about it, I'm not sure what you talked about, but, you know, the Nova Forge thing Yes. I think is really interesting.
That's the kind of the Yeah. Sort of industrialization of the AI process. And I, I know perhaps digging into that, um, pretty deeply.
Um, but I think that that's a really, um, interesting thing. It's not to say you couldn't do that with any other provider, um, but it's more like they wrap it up as a service and make it easier. Um, then I think it is a, you know, I think that that is a, um, yeah, it's real.
I mean, there's stuff, you know, most of the stuff is real. Um, I mean, some of it's in public preview, so it's very, very early. Um, but I, but I think, you know, AWS has, um, is having to work hard.
It's obviously the dominant cloud provider, but it's having to work hard to reestablish its AI credentials somewhat. Um, you know, I've had many discussions with, with the company about that, you know, with the current thinking, obviously is of the three hyperscalers, that that kind of Google has an edge. Um, but AWS has a market share and have, you know, hundreds of thousands of SageMaker customers and things like that.
So they're not exactly, um, you know, flailing away, not knowing what's going on. Yeah. Um, and, but, but I think, you know, the, you know, the models, um, the Nova Forge stuff, the chips, um, it's like, like all the hyperscalers, it's, it's, it's the ability these days for them to have everything from, from the chips to the applications and, and all bits.
No, It's a vertical integration for sure. We used to call it back in the day ke suits, right? Mm-hmm.
Where you had that whole family. But how much of this, I wonder, is AWS pivoting to AI in a big way, because maybe they were a little bit, or at least perceived to be a little bit behind Google and Microsoft, right? Even in the Futurum signal report, they weren't in the top two.
Mm-hmm. Correct. Not, not that the Futurum signal is the source, but it's a source.
Yes. It it is. It's, yes.
It, it is a definitive source. No Source. And, and they weren't in the top two.
No, they won't. And, and look, Google does have an inherent advant advantage here. They do have that true vertical integration up and down the, the, the stack.
Um, is, is, is that maybe at play here? Yeah. Yeah, I think so.
West feel like they had to play a little catch up. Yeah. And that's, that's an uncomfortable situation for them.
They're the 800 pound gorilla. Yeah, I think so. I mean, the reason we put them in that situation, you know, there's many reasons.
I'm not gonna go through all of 'em, but there's many reasons. But I mean, when you look at the, you know, Google invented transformers, you know, and, and so, you know, they, they kind of were there at the beginning of, of, of the, of this whole thing. And then many other things that are going on.
It has been a bit of a, you know, a race to the, um, you know, the, who's got the best model thing. And that's, you know, who's got the best model today. And there'll be somebody along tomorrow with a, with a newer one.
And until really reinvent last year, Amazon, you know, AWS really wasn't playing in that, um, in that, in that, that way at all. They announced Nova a year ago. Um, and now we've got the, the new ones, which I think you've already, you've already talked about.
Um, that's not the only measure though of, of success in ai. Um, you know, certainly from the end user point of view, it's not, it's just 'cause it's, it's, a lot of it is kind of f and confusion and say the, you know, today's benchmarks are, you know, our old hat by tomorrow. But I think it's, yes, they are.
They are. Um, they weren't as prominent in that, that kind of model race. Um, that may end up being a good thing for them, I dunno, um, in terms of, um, you know, have the resources you have to spend to, to get, you know, to the top of that, that that tree.
Um, and then obviously Microsoft was kind of outsourcing everything to open AI and now is obviously playing a more pragmatic game. Um, so it's, it's kind of, you know, they're right up there because of open their open AI relationship, which gradually is gonna be get diluted both from a kind of financial point of view, but also, um, from a kind of, you know, product, you know, development point of view as they can hedge their bets, uh, with, with other model companies. So I think it's, it's, um, it's certainly, I don't really believe it's a race that only one company.
It's not a zero sum game. No. You know, not one company's gonna win and every else, you know, loses.
Um, and, you know, maybe in a year's time we'll be look thinking back and saying, you know, look at AWS they've caught up. You know, because I think there's the user, the customer base is so vast. Um, No, they still have, look, they still have a lot of cards Yeah.
That are worth playing. Let me pause it. Something else at you, Nick.
Tremendous amount of attention on the train and processors. And this follows, I think it was last week or the week before Google's announcement a around, uh, chips. Is this the, the signal that we're moving, that the real action is moving from GPUs to other kinds of chips from, so in other words, from training to inference, I'm not taking up any collections or playing any death nails for Nvidia.
Mind you, but are we moving towards, not towards but a more multipolar world where GPU isn't the only chip we need Yeah. Use for ai. I mean, organizations have wanted silicon diversity for, for, for years.
And they haven't got it at the moment. I think it's baby steps, you know, very, very, very, very baby steps. This is, you know, this, uh, Nvidia has, you know, it's, you know, dominant market share and will do for quite a long time to come.
Um, and will it eventually slip, slip from 90% to 85% to 80%? Yes, it probably will. And that's got as much to do with a MD as it has got to do with AWS and Google.
But I think, yeah, the train stuff was interesting. It was completely predictable. 'cause they said they were gonna do it last year and they did it, so that's good.
Uh, they training two last year, train three this year, and now they're talking about training four. Um, Six X is powerful. It's Free.
Yeah. And then you have these kind of train, um, the ultra service things, which is kind of, it's a sovereignty play. It's like, you know, you get out our chips plus, you know, all the, all the interconnects and everything else in, in, in the stack and, and shove it in your data center.
And I think that's, um, something they had not really talked about much. I've had outposts for years and it went through a period of time, um, in 24 and in early 25 of like ignoring the fact that on premises matter at all. And you, the old ad ad is once you move everything to the cloud, X, y, Z will happen.
Well, people don't move everything to the cloud. So that, that's that. I thought that was really interesting as well.
Yeah. Um, and I think, yeah, I think that is a, um, you're gonna hear more sovereignty stuff from, from AWS, um, in, you know, new Year as well. And that's, and that's gone from being, uh, an, you know, as a lot of people in the US thinking of obsession of Germany and France and countries like that to more or less every single country in the world.
So, no, You know what, so our, our whole presence here is sponsored by our friends at suse. Alright. And, you know, they've gone into digital sovereignty in a big way.
They've actually started a whole division around it. Now granted, they are a Luxembourg, European based company. And, and so maybe that feeds into the narrative you're talking about.
Mm-hmm. But I'll go one better. I think we may see a world in the US where you have state to state sovereignty issues, right.
I'm a, I'm a, for lack of a better word, a blue state versus a red state. And I don't want abortion data available to the red state. Right.
And just so I, I want to know if it's hosted in my state, and I want to make sure that they get their heads on this pretty close. Yeah. Right.
So when we talk about data sovereignty, it's not just a nation state thing, it's a, it's, it's a territory to territory thing. It's, it's a big, it's a big issue that's gonna get bigger. Mm.
Nick walked around today, you had a lot of meetings, spoke to a lot of people. What, what surprised you? Um, what surprised me?
Um, that's a difficult question to answer off the top of my head. Um, I guess, I guess, yeah, the few people I've, I've spoken to so far, the, uh, the show floor can be a bit intimidating. Um, yeah.
Um, I think, I think it, I think it is the, you know, the, the progress of the gen stuff, um, which may be, you know, people want to say they're further along than they actually are because yeah, we're incredibly early as we, that's, that's also become a bit of a cliche saying we are incredibly early. Um, but it's, I think, yeah, I think some of that, the, um, the claimed, um, progress in that is, uh, somewhat surprising, probably, therefore maybe not entirely true. Um, so, so I can, so that's a, that might be a bit of a sort of a surprise, sort of a kind Of, it's a very UK proper way of saying don't believe it.
Polite. Yeah. Yeah.
Right, Right. We're a very, very polite nation. Um, but it's, but yeah, I think, I think it's, yeah, I think that's, that's, that's probably the case, I guess.
I mean, from the AWS point of view, I think the, I think the kind of, um, the sovereignty stuff we were just talking about, I think, yeah, the, the amount of emphasis I've, I've seen on that and heard from them on that was, um, you know, it was probably a bit higher than I thought it was gonna be. Yeah. I, I don't disagree there, Nick.
I know you have to run out to another appointment. That's why I wanted to focus on your earlier without going to Mitchell. Um, you recently, I think the, the, uh, the signal report that you had done on AI had come out, um, where can people keep up with what you're, I mean, not just the signal reports, but you, you're constantly putting out Yeah.
com. That's where, that's where all, all our stuff goes. Um, you know, on the socials at, on on, on Twitter X anic patients, but not very often, um, on LinkedIn more often.
Yeah. Um, but yeah, the signal stuff is available, um, for everybody to, to look at. And so that was the first one of, of the AI platforms.
And I think we had nine vendors in the, in the signal. Um, and obviously of which AWS was, was certainly one. And there will be, there'll be others along in Q1, Q2 of, of, of next year.
I'm sure I'm not gonna commit to a specific date, but, you know, there's more, it's been a really interesting exercise and, and we've had some sort of validation that the way we've done it and the how we quickly we can turn these around, um, and get results, which, um, actually make sense and resonate in the market, I think has been really encouraging. Absolutely. Nick, I'm gonna let you go.
Cool. Thank you so much. Thanks, Nick.
Patience. Check him out. Another one of the great Futurum analysts.
We're gonna take just a quick three second break as we unhook Nick from his tether here on the microphone. And I'll continue our conversation with Mitchell. You're watching Text Drunk tv.
Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platforms.
Before we jump into today's topic, let's meet the panel starting with Alan. Alan, it's good to see you again. Tom, it's nice to see you.
I've, I've been, I've been on the road a lot. It's conference season, so happy to be here in the office and able to jump on today. Well, we're very happy to have you.
And, uh, joining us is also someone who's been on the road quite a bit recently. Uh, Mitch, it's good to see you again as well. I'm back in Guitar Central where I belong.
Exactly. You know what? I think, think I like your decor better than the hotel rooms in Las Vegas.
Uh, you definitely have an eye for, uh, you know, things that are interesting. I'm in, I'm in my, my, my man cave. You know, I got my stuff around me.
Oh, well, that's awesome. I, of course, I'm in the formalist void of my office because let's be fair, you guys are more interesting than me. But let's jump into today's topic because it is something that's actually very interesting.
And I think that, you know, Mitch, uh, you highlighted something I think that we all should be keeping an eye on. We've been talking about age agentic AI a lot recently. We've had several episodes about it here.
We've been covering it a lot of other areas. But of course, you know, the s and age AGENTIC stands for security. So one of the things we've gotta figure out is how are we going to secure agentic ai?
Now, before we even got started on this, we, we had to make sure that we were clear on this. We're not talking about using agents to do security on this episode. That's an entirely different conversation had.
We wanna talk about how we're going to secure the agents themselves, because as we know, with all things related to ai, those particular pieces of code have a lot of access. And if something were to figure out a way to confuse them or jailbreak them, or potentially turn them against us, we could have a big problem on our hands. Mitch, I'm gonna let you kinda lay things out since you brought this topic up.
What is it about agentic security, meaning securing those agents that kind of has piqued your interest? Well, the, the main thing is that we have been seeing announcements from vendors, you know, the large vendors, the Microsofts and Googles, uh, GitHubs even, uh, and even folks that are kind of farther down the food chain around doing some different kinds of security with agents while they're rolling out agents. And why that's notable to me.
You know, Alan and I have been preaching the gospel of, uh, DevSecOps and shifting left or whatever, however, you get software secure and always questioning like, are we making progress? Are we ever gonna get there? And of course, I think beginning of the year, I would say, we're in the hope mode.
Well, we hope we do it right this time. It appears that something, I'm not saying we're, we're fixing everything, but there are a lot of products that are coming out for agent identity, security guardrails, um, control some oversight. There's even talk around behavior and compliance.
Uh, a little bit of that coming out. I mean, I've got a whole list of rash of vendor announcements. Again, none of this is complete solving all the problems, but I have to believe that in the interest of, we wanna be part of AI too, the security and other companies security part of these product companies are saying, we better get our act together now and start working on security of AI and agents.
Let's get products out the door. You know, Mitch, not to disagree with you, but I, I gotta disagree with you. I, I think right now, just like every other tech company out here, security executive security vendors are under tremendous amount of pressure from their board, their investors, the VCs, to say, what are you doing with ai?
What's your AI story? And for most of them, for most of them, what they're doing, what's their AI story, is how they're using ai, how they're using AI to be, to provide better security, to do better AppSec, to do better endpoint, to do better data. DLP or what cloud security or what have you, it's how do they use security?
It's just a subset of these vendors who are gonna say, well, how do we defend, how do we secure an AI future? And there's gonna be a lot of them whose lips move, but I think you gotta watch for the ones who, who are putting their hands in their pocket and, and coming out with it. I, I've seen a lot of talk about it, but it pales in comparison to the companies who are saying, we're going to use AI to give you better security.
And, and this is an old story. Here's where you and I would, would differ. Yes.
I think the, the market's very large for using AI for security, the market for wanting to get AI into production. Meaning I want my agents to go into, go into production. Enterprises are not gonna let AI into production, into, you're gonna be super cautious because the data issues that market is, you know, pick a, pick a multiple that's much bigger than the security market using ai.
Both of 'em are important, but I think that's, I think the enterprise is what's driving. If you really want these deployed into production, you have to secure ai. Mitch, I appreciate your point of view.
When has that ever actually been the truth? I was waiting. I heard, Hey, wait, lemme take you back on a little trip down memory lake.
Let's go to 2000 award. 2002. We don't use open source in the enterprise.
It's not secure. Who, whose throat are we gonna choke? Everyone was using open source.
We don't use white wifi in the enterprise. It's not secure. It's wide open as people, you and I were, as people are tossing the WAPs under their desk when their bosses work, work by, we don't use the cloud.
It's insecure cloud. The biggest inhibitor to cloud adoption is cloud security. As every developer and their mother whipped out a credit card and spun up instances.
What makes you think this time's any different? It's, it's not different in the, in what you're saying in that way. I agree with what you're saying.
What's different is we see companies coming out with security solutions earlier in the maturation of AI and agents in the cycle I see is different. And I'm, I'm not claiming any, uh, any clairvoyant that suddenly we're all gonna get religions and secure all of our ai. But I do think the market, everyone wanting it, it's happening in observability too.
You see companies like, okay, I want, uh, I want observability of my agents. How do we Dynatrace, Datadog, new Relic be part of the Microsoft announcement, right? Um, for DevOps agent, the other companies that aren't AI companies that wanna be part of the AI era are moving, some of them are moving in a fast mover way.
Not all of them. There's a lot that aren't. But so, so you are gonna have some security products for some of this ai.
Maybe we're gonna see some better security. Not, not, not the kind of, you know, what was the Eden was the Star Trek episode when they were all all headed to Eden. Mm-hmm.
You know, we're probably not gonna go there. 'cause that turned out not to be a good place anyway. Yeah.
Well, if I remember correctly, the guy with the ears, so Tom, you gonna, I I think, uh, Mitch, you kind of stumbled across something that I think blends what Alan was saying. The reason why I feel like people are moving a hundred miles an hour is not because there's any hesitancy on their part to implement ai. Like they know that there are risks associated with it, but the bigger risk is the board and the investors coming down from on high saying, you have to have a strategy.
You have to adopt something. You have to do something now, or we're gonna unseat you. We're gonna, would've put somebody in that can do that.
But the observability piece, I think is maybe kind of the, the trick to get this in here because what's the one thing that they want to know above and beyond? We have an AI strategy. They wanna see the data points proving that it's actually happening, right?
How much, um, agentic workload have you deployed? How utilized are these agents? And maybe by selling this as an observability platform and saying, oh, well, you know, we can tell that we're using these agents in their max to 85% capacity or whatever.
Oh, by the way, we can also see what workloads they're doing. We can see if something jail breaks that we can see if things are, are doing behavioral stuff that they shouldn't. I feel like that's a way to back into the security conversation as kind of an afterthought that will also allow you to bring that up to the board in three more months when it becomes relevant.
Oh, by the way, we, we prevented like all of the board, uh, members, uh, salaries from being leaked through an AI prompt injection attack. Oh, I didn't know that that was possible. Well, good thing that I was thinking about this while you guys were worried about whether or not we had enough agents deployed.
I think that's a very good point. And especially if the vendor you're already using for observability or security or both are moving, uh, making moves to introduce those products. Now I think you're in a better position.
Y you know, again, experience leads me to say we will have security for agent AI when customers put their foot down and demand security for agent ai. Yeah, for sure. Mm-hmm.
But to Tom's point, when you've got the board and the C level, what's your AI story? What's your AI story? How fast can we get this?
How fast can we, can we, can we lay some people off and replace them with ai? Right? That kind of pressure doesn't bode d well for, for it.
But here's an interesting thing too, Mitch, ultimately, who's responsible for the security of this ent ai for these agents? Is it the people designing the agents? Are we, in other words, are we gonna have a secure by design sort of standard for, uh, uh, agents, for AI agents?
Or are we gonna see the rise of a, at first the cottage industry, hopefully growing into a, you know, big part of the, not a big part, but a significant industry of security companies, you know, cyber companies that secure ag agent ais, maybe even robotic AI as well. But, you know, so in other words, ultimately who's the, who's responsible here? Is it a security company that's solely focused on the security of your agents?
Or is it the developers of the agents themselves who have security as part of their mission? I think it's, at least right now, what we're seeing is the pu the companies that are creating the platforms for agents to operate within. So the, uh, agent hq, Microsoft, the agent hub at, at, um, at GitHub, that what they're building in the framework for, you heard at AWS last week, Allen, about their A AWS security agent, their AWS DevOps agent, and coupled right in that announcement and is, and here's the vendors who are integrating with that agent so they can connect into it.
So the framework of security and observability are starting to be put in place, at least in those cases, um, it certainly isn't across the board. Will there be a, a WHI or as somebody that, you know, pops up as the agent security company or AI security company? Probably.
I think, we'll, we'll see some of those come up, but the other folks are not gonna miss out. They're, they're gonna go after this market and they, and some of 'em already are. So the framework ones sounded very much to me, like the early cloud security.
Remember, we build it into the platform, right? We don't have to show you everything, but AWS was pretty good about giving, uh, vendors a, a window in into the security of that foundation, if you will. And, and I think that what we saw at AWS last week and what we've heard from Microsoft very much kind of fits that cloud security mm-hmm.
Model where, Hey, we're responsible for the, for the platform and, and we're gonna partner with you. We're gonna do some of that security, and then we're gonna make APIs or, or MCP servers or whatever available for you to supplement that with more. But I do think you're right.
I think we're gonna have a category buster, like a wiz or, or, you know, in the last cycle that, and I don't know what FU or Gartner or whoever will name it, but it's gonna be a category of security companies that secure AI wherever it may be. And, and there will be some winners there. Very much like we, I think on a much bigger scale, like we saw with microservices in Kubernetes, right?
We see a synap rise as a product category. And there's, that's exactly what I'm referring to. Like, see now, right?
And, and you know, the funny thing is usually the analysts come up with a name for it after it's, they saw it in the wild, you know what I mean? And now, okay, we gotta name that, but I, I do think we're gonna see in the, while a security, as I said, it'll start as a cottage industry and grow, but a, uh, uh, another silo in the cyber market for companies that specialize in, in securing, uh, uh, gentech or agents, AI agents, that doesn't let the AI agent developers off the hook though. No.
We need some sort of best practices to emerge about, you wanna call it the law of agent AI or something, right? These are the three rules and the zero law of how an agent behaves or should behave from a security point of view. I agree with you, Alan, But here's the problem.
We don't know how agents behave until we see them in the wild. And that's one of the things that we're, we're running into right now, is the, just the absolute sheer amount of creativity that people are throwing at these problems to try to bust them up. I mean, last week we saw the Icaro Labs paper where you can jailbreak an LLM by writing your prompt injection in poetry, because someone somewhere was like, why would anybody ever wanna write hacking instructions and poetry?
Well, Before that, you could do it with calculus, right? You could do your prompts in math and, and break it as well. Um, yes.
But you also gotta remember, Tom, right now we're in a Cambrian explosion era of AI where we're making all kinds of funky animals with six eyes, eight legs, 12 guts, and, and, you know, and everything else at, at some point, I I, I'm hoping we're gonna have, and, and some point soon we'll have standardization and best practices come out, right? We, we don't have best practices yet. We don't need, We, we don't have best practices because we haven't seen a best solution yet.
Like, like you said, what, why does an animal have four legs and not five or 12? Because we found out that through trial and error, through evolution, 12 legs doesn't work there. There's Evolution's slow.
We can't afford, we can't afford ev you know, we've, evolution Can be slow, but there's also this theory of punctuated evolution where you have a rapid number of changes that quickly fall out, and then we iterate on the best model. And we're seeing that now with a lot of companies who are like, no, no, no, no, that's not gonna work. We need to move on and do something different over here because that doesn't scale the way we want it to.
But the problem is, is that when we jump to that next, uh, shift, if you will, it's almost like, just like a neural learning model. We've forgotten all the lessons we learned over here. We're starting fresh.
Well, what if we do it this way? Or what if we have it that way? And unfortunately, from my perspective, developers don't do themselves any favors because they're so focused on doing the job that they forget what happens when people try to do the job wrong, right?
Like, think about anyone who like used to check for cross site scripting. It's like, well, what happens if I type the wrong thing into this dialogue box or causing an overflow condition or something like that? Well, why would you do that?
Well, why wouldn't you think about that? Like, I, I think about any, any number of like software development things like, you know, uh, video games are actually a really good example. If you look at the people, it's like, okay, we deployed this patch, but there's a bug in it.
If you wanna know if there's a bug, make it something that's useful to the users. Like if it's a way to get infinite money or something like that, they'll find ways to, to test it quickly and get the outcome that they want. And then you'll have to go back and go, oh yeah, we probably should patch that out.
'cause that's not an, an intended side effect. And I think that we've gotta get to a point where we can do that rapidly. Because unfortunately, as much as I would like to say that I would love that the value of adding security happens before the thing is released until you release it.
You won't know what kind of attacks you're gonna face against it. Well, it's like, this is very much where, again, back to microservices, right? When we first started working with microservices, like, how many, are we gonna have a a dozen or two dozen, uh, hundreds, may thousands.
Really? How am I gonna manage that? How am I gonna know what they're all doing?
And if they're doing what they're supposed to be doing? You say the same thing for agents, right? And that's where, you know, Kubernetes came from.
That's where telemetry really took off from. Um, and this, we're seeing the same things start to happen here where, uh, vendors are coming out with picture your product name, but it's a agent control plane someplace where you have some observability or a place to manage what agents are running, what tasks that they're doing. We don't know what the best framework of the best model.
I think it looks like a, a video game or a PC game like StarCraft, that that's what I hope the interface looks like someday. But that aside, you know, it, it's being defined or will be defined. I don't think the solution is there yet.
com, I feel it, I feel compelled to say, this isn't the developer's problem. Let's not throw this on the shoulders of developers and say, oh, the developer has to think this way. The developer has to do these things.
Developers have a bid on their plate, right? We need this is, this is all of our, this is the whole stack. The whole team's problem.
It's the DevOps engineers problem. It's the security guy's problem. It's the tester's problem.
It's the AI's problem. It's the platform engineers problem. And it's the SREs problem.
It's all of our problem, right? Don't, don't throw it on the developer that he should be, you know, because that's a recipe for failure. The developer's not a security professional developer may not have written the code.
AI wrote it. AI might have written the code, but here's, here's where I think there's good news. I think using AI technology, we could do things like digital twinning and, and, and, and stuff like this where we can see kinda what's out there and fuzzing and everything else.
And, you know, I would, I, and I've seen this just in the last year or two, what I used to think of is after the event horizon security, in other words, post-deployment security measures being deployed, pre-deployment, right? We, we've seen, uh, what we used to consider vulnerability management move into AppSec, right? And, and, and things like this.
So I, I think given the, the, uh, capabilities of ai, we can have higher confidence in the software we release in our software supply chain, which will result in hopefully fewer, not eliminating, but fewer security issues post-deployment. And, and that's why I think we do need to spend a lot of effort and a lot of resources in harnessing AI to make our, you know, uh, the announcement within with anthropic buying bun, the job JavaScript runtime environment of yes, I can imagine that for production use. I can also imagine that for setting up sandboxes and testing ai, doing those tasks and actually running it is maybe part, even part of the code generation process before it says, here's your code.
I've got your code for you it, doing some testing, doing it, running it in an environment, at least for that particular programming language. You know, we're, we can do things a bit differently in how we create software. It doesn't mean we're changing all of it, but I think folks are kind of thinking out of the box now with ai.
I think. So what, lemme lemme, lemme switch gears a little bit. Um, also one of the early questions about agents was, well, what, what permissions does it have?
And the first company that I ran into that had made a decision about that, and may may not have been, probably weren't the first company to do it, was to treat a AI agents as a teammate, as a user in the system to give them their own id, their own, uh, credentials if you will, security, but also their own permission structure and set up and actually show up in the list of kind of users you can select to, uh, perform tasks and things like that. And that te seems to be what the approach people are taking is build on our identity, our IM systems for agents. Now, is that enough?
Will we need more? I don't know, but that seems to be the prevailing win. You guys think that's, is that gonna solve the problem long enough for us to get AI into production or we got some more hills to climb for Hamburger Hill there, Alan, We're not there yet.
Because the problem with limiting the agent's horizon as far as what it can do is what happens if those controls are breached? And, and we've seen that time and again with your average user, right? Well, I'm not gonna give them admin rights.
Okay, that's great. What happens if they get them? Oh, crap, now they have visibility into the entire infrastructure and they can do whatever.
Like, like how many times have we seen like backup operators get breached and Oh look, it can read everything. I think you're gonna have to take an agentic AI approach with a combination of zero trust, where even if the agent itself is limited, I have a se a separate set of controls on top of it that hides things that it doesn't need to see. So even if someone does manage to break out of the security controls, they are basically in a, in a prison cell.
And, and we've learned that over the years with users, right? Like, like even the most well-meaning user can accidentally do things without realizing it. I go all the way back to my internship when I was at IBM and someone obliterated about 50 gigs worth of backup data in 2001 off of a tape robot because he accidentally removed the wrong directory.
Because when he, when he, uh, changed users, he didn't do PWD to figure out he was on the tape robot and not an attempt directory. And to this day, 25 years later, I still do PWD anytime I change user focus at all because of that. Because I don't want to be in an area where I can cause a massive amount of damage.
And that's the whole heart behind zero trust, right? If, if I can't control what the users do, I'm gonna control what the users can see. And I think we have to have that, we have to put an extra set of guardrails above the agents to prevent the kinds of attacks that could potentially cause them to do harm.
Yes. Um, you said the, the, the, the thing about this though is we've got, at some point we're gonna start thinking of these agents and, and we've seen this written already, digital coworker, digital workforce. Yep.
It's a digital workforce and they're your digital coworkers. And again, you know, we're gonna need best practices to emerge, but these digital coworkers are gonna have, I, I hesitate to use the word identity. They're gonna have an identity and access management, right?
An IAM for your digital workforce, right? And I, I, I bet you some of the IAM vendors are already working on this and, and included in that, I I think zero, you know, zero, don't leave your zero trust at the door when you're dealing with agen, right? All of the policies and best practices we've developed around IAM should, should apply to our agents.
Now you've got MCP servers and, and, and, uh, you know, these kinds of things. Very similar. Mitch and Tom, if you remember just three or four years ago, there was this whole move towards, uh, AI security.
There was a whole bunch of AI security companies mm-hmm. Api you mean traceable, right? Yeah.
API, yeah. Yep. A, I'm sorry, API security.
And, um, and now all of a sudden it kind of got subsumed. It went away pretty quick. I I think we're gonna see a similar thing around MPC, excuse me.
MC Yeah, no, I do that. Get my initials mixed up. MCP servers and, and the security built around those kinds of interactions.
But they all fall within the broader category of IAM for agents. That's my, I think that's the likely outcome here. No, I was just gonna kind of wrap with, I think o one of the things that is happening is we are building on some good things that we've done because you see policy as code.
Now that's policy guardrails, right? You see, even see behavior behavioral because of the unpredictable nature of generative ai, um, behavioral and outcome based. There's different names people have for this, for the output to make sure that it's accurate.
Um, the others, I spent some time that with a company that's taking the output of AI and then putting into, into structured languages, traditional languages for further execution. So you aren't using the same resources, but also getting more predictable results. Kind of a hybrid approach of AI plus structured code.
We're we're building on things we've, we've done including identity management. Not saying it's solving the problem, but, but we're not starting from scratch either. Like how are we gonna secure those APIs?
I don't know, maybe we should like put a, put an account on there, et cetera. So I'm, I'm, uh, cautiously optimistic, mostly hopeful that we'll do better this time. Even if it's marginal, it's better.
I love the hope, Mitch. I, I appreciate it, but I also appreciate having Alan here to remind me that we've had hope before. Yeah, keep hope alive.
Keep hope alive. Alright, I think we'll go ahead and wrap up the episode today. On that note, um, you know, we've got a lot of things in the air right now.
I know it's the end of the year for most everyone listening to this podcast. I'm sure you probably hopefully have implemented change freeze December so that you're not dealing with any other craziness, but we've got a lot of stuff coming out. Uh, Mitch, what's something you've got coming up that people definitely wanna be checking out?
I definitely want folks to check out the agent of Cha, agent of dev podcast that I'm doing with Brad Shiman. It's all about sort of what's real and what's happening in AI agent and agent development, you know, across the SDLC. So that, and both of us are coming at it as analyst and folks that have a practitioner background.
And, and I've got a number of reports. We just did our a WS report, uh, combined with a bunch of analysts. Uh, right now we're kind of tuning the practices.
So there'll be some information coming out about what I'm gonna be doing with the software lifecycle engineering. So keep watching, watch LinkedIn, 'cause that's what's where I post everything. Great.
Alan, what have you got coming up? 'cause I know you've been a really busy man. Yeah, I mean you can keep up with me on LinkedIn or text on tv, but what I really would like to call the people's attention is coming up after the first of the year.
I think it's Jan, the week of January 9th, something like that is our annual virtual event called Predict. This year, of course it's Predict 2026 starring our FU analyst team. And each one of the analysts will be doing sessions on, uh, what they think is the big story, what they think you need to know for 2026.
And, uh, it's always a great event. I think this year with the FU team it's gonna be even better. com and look up predict, but it's free to register and attend and ask questions and it's gonna be a great event and I'm really looking forward to that.
And we thank you all for listening to this episode of Security Boulevard podcast. Remember, if you enjoyed this conversation, we would love it if you would subscribe on YouTube, make sure you hit the notification bell and, uh, get all those updates. Or you can also subscribe to us in your favorite podcast application choice because we don't want you to miss any of these episodes.
Do us a favor, leave a rating and a review and a comment. All of those things really help us get noticed by a lot of other people out there. And if you have somebody that really needs to understand security, this is the best place to do it.
So send it to a friend. com and the Futurum group. com, the tech strong TV website or the Techstrong TV app, which runs on Apple tv, Roku, any kind of smart device that has a screen, that app runs on it and you're gonna want to check it out.
We also want you to check out our socials because we are on X, Twitter and LinkedIn as security BLVD. And there's a lot more content out there that you're gonna wanna check out. We thank you very much for tuning in for this episode.
We'll see everybody next week. Hi, my name is Matthew Flug and I'm a research manager at IDC and I cover application deployment platforms. First, thank you for choosing to watch my session today.
One of my favorite comedians once said, it's a lot easier to not do something than it is to do something. And I appreciate all of you for taking the time to tune in to me today. And then during this session we'll talk about some quantifiable metrics that you can use to measure the impact of your application platform, whether you purchased it from a vendor or built it in-house.
But before we dive into the metrics, I just wanna set the stage and provide some context for our conversation today. So application platforms, internal developer platforms, whatever you call them, they've become a table stakes technology. Recent IDC research from earlier this year found that over 80% of organizations have one, um, and they've had one for more than two years.
So the upfront investment has been made with people time and money to implement these platforms into your organization's IT ecosystem. So hopefully your organization is embracing a platform as a product mindset because this platform does serve customers. It's just that those customers are your developers and the rest of the software development lifecycle personas at your organization.
While all four of the pillars on the screen right now, um, are crucial to a platform at a a as a product mindset, uh, and we can have a entire webinar on that concept alone. Uh, during this session, we will focus specifically on the role that metrics play in assessing and driving platform success. So again, whether built or bought, we already talked about how application platforms require significant investments of time, money, and people.
However, not all of the benefits that come with an application platform can be directly tied to ROI or revenue. That means that measuring the impact of a platform across various areas is crucial to get the full scope of the impact that the platform is having on your organization as well as where it can be improved. And because it can't be tied directly to ROI or revenue all the time, it makes it difficult.
Business teams need to understand the value of the platform brings to justify the likely not so insignificant investment that they made in the platform. And for the users, there will need to be some level of standardization among tools, but personal preferences are easier to overcome when you have data to back up why they should go with what the platform says. It's also easier to drive adoption when you can show hard stats.
I love data and you'll see some of it in this, uh, in this presentation. Hard stats of how the platform is improving other users' daily lives. Lastly, to truly continuously innovate the platform, platform engineering teams need to understand where platform users experience pain points.
So some hard data. In that recent survey I mentioned, 78% of respondents said that their application platform is meeting or exceeding their return on investment goals. And while ROI is an important if not crucial metric, when it comes to measuring the impact of anything including an application platform, there is more to measure.
And one of the key takeaways from this presentation should be that one size doesn't fit all when it comes to measuring the success of a platform. The metrics organizations choose to track should align with the business and developer goals that the black, that the organizations set out for the platform. And they should help answer the following questions, what are the goals the organization is trying to achieve with the platform?
And is the platform helping to meet those goals? Second, does the platform ease the burden of building, deploying and managing software? So with that in mind, I like to classify application platform metrics into three categories, business metrics, technology metrics and people metrics.
Business teams want to understand how the application platform is impacting the overall business. Is the platform driving ROI or reducing costs or produ or generating new revenues? And we'll dive into those in a bit.
Technology metrics should measure the platform's impact on an application performance and resiliency and the processes involved to build, deploy, and manage applications. They should also measure their performance and resiliency of the platform itself. Platforms inherently touch a lot of systems within the organization, which make them a prime target for security threats.
People metrics are another key factor, and success is built on driving adoption. People. Metrics should measure things like usage, developer satisfaction, and time to onboard for any metric an organization decides to track.
Comparing with the baseline before the implementation of an application platform is crucial to understanding the impact the platform has on the software development life lifecycle. So let's dive into some business metrics. Again, we talked about revenue.
It's crucial for measuring platform success and really anything that a business does and financial metrics in general are a top priority for business teams. That same survey that I've been referencing found that nearly half of organizations cite higher revenue enabled by the platform as a top factor that influenced the organization's decision to adopt an application platform in the first place. So speaking the language of business teams is therefore an important step for platform teams, improving the value of the platform to business teams.
But there are other financial metrics that influence R-N-I-R-O-I and revenue, excuse me, including resource allocation efficiency. Our developers allocating too many resources to their applications and that results in waste. That's gonna become more and more important with AI and agentic applications, which are resource intensive time to market.
How long does it take to go from idea to general availability, cost of ongoing software development, lifecycle operations. And then really important, especially in large enterprises, is the reduction in technical debt. This could, this slide could really go anywhere in my presentation, I decided to put it here, but this is gonna be a theme throughout all of these metrics.
Ultimately, time is money and developer productivity is an area where an application platform can have a tangible impact on the organization. This will, again, this will bleed into the technology metrics section two, frequency and time to market kind of span all three business technology and people metrics organizations can be more agile and better capitalize on market trends. When developers are enabled to move faster, they can pivot effectively to meet those unforeseen market opportunities.
Kind of the way AgTech has kind of just exploded us, right? Self-service capabilities empower developers to build innovative applications without needing to rely on operations teams to allocate resources or spin up environments. And when developers spend less time on tasks like configuring deployments and allocating resources, they'll spend more time building innovative features, which is going to increase innovation while decreasing the taxing tasks developers have become responsible for.
And more than that increase innovation, it's going to increase innovation on tasks that have an actual high impact on the organization. So let's talk about technology metrics. While business teams focus on ROI and revenue and financial metrics engineering leadership, we'll look to technology metrics to assess an application platform's effectiveness.
They need to ensure that teams can build, deploy, and manage better applications faster while maintaining security performance and operational efficiency. Security and performance are really non-negotiables. No organization is going to want to sacrifice those.
So your platform needs to maintain those while making a developer's life easier. The key is finding the right balance between enabling developer self-service and standardizing around best practices. Too much standardization will stifle developer creativity, but golden paths abstract away, mundane tasks, speeding up time to market and providing consistency for tasks that often lead to security vulnerabilities and performance issues.
So where to start? I say start with door metrics. They provide a well-defined and understandable framework to measure the impact of an application platform.
However, there is one fatal flaw, uh, which we will get to in a minute. First, successful application platforms enable teams to deploy daily, if not multiple times per day. Application platforms help improve deployment frequency with increased developer, automated CICD pipelines and built in security and compliance via golden paths.
Shorter lead times indicate more efficient development processes and application platforms often provide automated code, code builds testing and deployment to reduce manual in intervention. And they also provide developers with self-service environments that we've talked so much about. And resource allocation, pre-configured bill packs and templates and automated scheduling and scaling for those deployments.
Lower rates typically suggest higher quality and stability and application platforms enforce standardization of best practices around infrastructure, security, compliance and governance. And that again, serves to limit vulnerabilities, misconfigurations and human errors to lower change failure rates faster recovery times indicate strong incident response and resilience and application, uh, a key function of application platforms and the platforms provide developers with insights into their applications' behavior, enabling faster root cause analysis and recovery actions. They can also provide a centralized repository for documentation and best practices to help troubleshoot and resolve issues quickly.
So I mentioned that fatal f flaw at the beginning. Um, there's not a lot of security in here, and again, that is a key non-negotiable for folks looking to purchase an an application deployment platform. So let's talk about some security metrics.
Again, that's IDC research that I've been referencing, found that almost two thirds of organizations consider security a top criteria, both business and technical criteria. When purchasing application platforms, the security of the platform and the security of the applications deployed via the platform are essential, especially now in the age of AI and agent. This will only continue to grow in importance and application platforms will have a key role in fostering trust in those agentic systems.
So the top metrics to count here include the number of vulnerabilities that are caught and resolved before production. And that shows that the platform is helping the organization become more proactive versus reactive. The number of vulnerabilities that actually still make it into production.
Again, an organization is never gonna be perfect, but you want your application platform to help you close that gap. And then lastly, the average time for developers to fix security issues. The shorter time it takes, the less vulnerable and organization is the less downtime you may have.
And all of those things are crucial tasks for an application platform. So one thing we haven't talked about is it's is the measurement of the performance, the measurement and performance of the application platform itself. If an organization's application platform is not working well, those organizations will encounter operational risks, lower levels of developer productivity, and an inefficient software development lifecycle.
By measuring the platform performance organizations can understand exactly where their application platform works well and where it falls short and try to close those gaps. Ultimately, application platforms need to be available, they need to respond quickly to requests and they need to scale efficiently and effectively. And then again, what it's a theme throughout this, they need to be secure.
So availability and uptime measures how often the application platform is available for developers to use. If developers go to use the platform and it is not ready for use, that creates a bad experience, which could result in developers abandoning a platform. Again, they are customers the same way we are consumers of, let's say Uber.
If I go to use Uber and my app isn't working, maybe I'll go use Lyft or vice versa. Latency and response time measures how quickly the application platform responds to requests. The quicker the platform responds to developers, the more they will use it to ease the burden of their daily tasks.
If it saves them time, they will use it. Research resource utilization and scaling measures. The resources, the application platform allocates to applications when deploying those applications.
And when auto scaling under dynamic loads, the platform should help developers allocate the appropriate amount of memory storage and compute without over or under provisioning. If you overprovision resources, you're gonna wi throw money away. And if you underprovision resources, your app is not going to perform.
And that will lead to developer dissatisfaction. And developer dissatisfaction is exactly why we wanna measure people metrics. The value of an application platform increases as developer adoption grows and adoption and retention metrics are crucial to gauging the platform's impact and whether it is successful in reducing developer friction and improving productivity.
Furthermore, the better the adoption, the more impactful an application platform will be. So when deciding which pain points and application platform should solve platform teams need to take a second before they implement this platform and ask developers. And frankly, I know we haven't talked, we've only been talking about developers, but I wanna also throw in here security teams, platform teams.
You should ask all stakeholders how they're being evaluated and where their pain points are in meeting their goals and identify where they're falling. Short metrics should then be aligned to track the platform's effectiveness in solving those issues across all the personas, ensuring the platform delivers meaningful improvements to developer experience. So let's dive into some people, uh, metrics.
And again, for all of these, there are more, these are just a few to consider right off the bat, adoption and retention rates. Developers should be naturally inclined to use the platform because it makes the right way, the easy way and the wrong way, the difficult way. Starting an application pla uh, platform pilot program at the outset with a handpicked group of developers, security team members and platform engineers will help drive adoption as developers see the pilot, uh, program's accomplishments, trek onboarding to first commit time.
This metric directly reflects how well the platform enables users to be productive. In that survey that I've been referencing, uh, we asked respondents whether they exceeded, met or fell short of their revenue goals in the prior calendar year. And the survey found that organizations that exceeded their goals were 10% more likely than those that fell short of their goals To track this metric, time to onboard new users and time to access, time to access needed resources and environments.
The, again, the easier it is for developers to access the tools, resources, environments they need to complete their tasks on their own, the more likely they will be to use a platform. They don't wanna submit a ticket to have platform engineering teams stand up an environment or, you know, get authorization from a security team to use a specific tool. So lowering the time to access the needed resources and environments will fuel developer velocity and productivity and it'll drive adoption and retention of the application platform itself.
This metric is more difficult to track. Um, and organizations can collect this from developer satisfaction surveys, which I highly, highly recommend doing. So those are just a few, but I've got a bunch of key takeaways here.
Um, finding the right balance between enabling developer creativity and standardization can be tricky, but consistency in environment security and compliance tends to be important drivers in implementing application platforms and they're crucial to the platform success. Getting developers to buy into that is also a tricky, uh, undertaking here. The first key takeaway, understand your baseline before the platform.
Uh, understanding your baseline before the platform is critical to understanding how the platform is impacting your organization. To use a cliche term here, in order to understand where you're going, you need to understand where you've been and where developers deviate from golden paths, they do so because it is easier to do what they need to do when devi, when deviating, again, I'm gonna reference that survey because I love data. Uh, we found that organizations that exceeded their goals are 11% more likely than those that, than those that fell short of their goals to track consistency in infrastructure and security.
So that's a huge driver of platform success, is that consistency in infrastructure and security among all the deployments. The next thing, and I, again, I can use a cliche term here, don't try to boil the ocean. It sounds simplistic, but far too often I hear organizations who are trying to build a platform that does everything right from the get go.
You will be spread too thin, especially if you've built this platform on your own. Pick a few high impact pain points and address those first. Align the metrics you choose to track with those pain points to understand how impactful the platform is at solving those specific challenges.
As you address those challenges, again, you're gonna continuously iterate. This is not a set it and forget it exercise, but then you can slowly start to expand the scope of the platform and eventually maybe you can boil the ocean. And I speak to a good amount of platform engineers and they are awesome.
They really can do some amazing things. But here is the most important thing. Don't just build cool stuff.
I wanted to say a bad word here, but I'm gonna go with stuff. Don't just build cool stuff for the sake of building cool stuff. Everything that is built for the platform should make a stakeholder's life easier.
And that's why all departments with stakeholders in the platform should have a seat on the platform team. However you do that. My favorite way I've seen it done is a rotating seat for each department, developers, security line of business folks, so that those people don't become full-time platform team members, but they still get a permanent voice at the table to improve and innovate on the platform however you do it.
Include those folks. Now, there was a ton of focus on developers in the industry in this presentation, um, and the term developer enablement is all the rage even among my colleagues. We, if you go to IDC research, we're talking all the time, including myself about developer enablement.
But what I wanna make sure that an application platform team does is address the other personas. Personas, what about the rest of the software development lifecycle folks? Application platforms should align all of those personas to common goals and enable them to fil fulfill their responsibilities in achieving them.
And I just want to end on a quick story, uh, about enablement. I attended an event in New York City called Platform Con. Um, and while speaking to a bunch of platform engineers, the conferences for platform engineers, I use the term developer enablement when talking to one of these platform engineers.
And they looked at me and they just said, what about platform engineer enablement? One, I had never heard of that term. And two, they were absolutely right.
And it got me thinking, what is platform engineer enablement? What is security team enablement? What does it look like?
And obviously it is a way more simple, uh, than what I'm, it is way more complex than what I'm about to say, but I believe when you boil it down, it's about enabling platform engineers and security teams to say yes to developer requests. And the best application platforms will not only enable developers, but they will enable platform engineers, security teams, line of business personas, and anyone else involved far too often. And a key theme at that platform com conference was the tension between the security teams, the platform teams, and the developers.
Developers are tasked with moving fast and getting things done quickly, getting things to market quickly while platform engineers and security teams are tasked with keeping things secure, keeping things compliant. And in the case of platform engineers making sure that everything works well, there's a tension there because developers will do whatever it takes to go fast. And platform engineers will say, Hey, hey, hey, if you, you can't do this 'cause this is a threat, right?
To our performance or to our security. So enabling them to say yes to developers and now everyone's working towards the same goals, that is what an application platform should do. So again, thank you everyone for your time today.
I'm honored that you chose to, uh, listen to my survey or, uh, to my, to my presentation. Um, feel free to reach out on LinkedIn. I've got a QR code there at the bottom, um, as well as a link to, uh, my profile page and we can keep the conversation going.
Um, yeah, this has been great. Thank you. Welcome to New York and Commvault Shift.
I'm Steven Foskett here with the tech field, a crew, and we are on site with Commvault learning a little bit more about where they're going, but more importantly learning a little bit more about the industry and the state of, of course ai. So we have brought together a panel of independent delegates here along with, uh, one of our friends from Convault to talk a little bit more about what's happening in the industry, what was announced this week and what we think of it. Before we get started, let's meet who's, uh, around the table here physically in New York.
Hi, I'm Karen Lopez, uh, at Info Advisors. com. I'm Tom Hollingsworth, I'm the event lead for all things security here at Tech Field Day, but I also do a lot of security analyst research work and I'm also networking nerd pretty much everywhere online.
Michael stem, vice President product experience at Copal, Jade Kro. org. I'm also the Chief Product Officer at Nexus Tech and a consultant for Kro Consulting.
Hi, I am Shala, Minnie may know Mele across social media. I am also a DevOps engineer and a cloud solutions architect. And as I said, I'm Steven Foskett, I'm in charge of the tech field day business unit for the Futurum group, and I focus on artificial intelligence and other new technologies.
So this event has been particularly relevant to me because we've got data, we've got ai, we've got the evolution of data protection, uh, something called res ops, which I think we're gonna get to. Uh, let's start things off with just a little bit of a, a reaction to this whole event. Jay.
Thank you Steven. I, I think I'll start with the res ops. Um, it's only been a few months.
I think we need a new Portman to, so we've, we've got DevOps, we've got DevSecOps, we've got finops, we've got Green Ops. And I think in the world of resilience, it's time to embrace thinking about res ops. So when we unpack what we saw on stage, from my perspective, it was a convergence of things.
So it wasn't a separate security discussion or a specific threat intelligence or tools, techniques, processes, discussion as much as it was, how could we have combined efforts in, in the sense of if it was cloud operations, if it was security, if it was resilience, what if they actually kind of all sort of combined forces like a vultron, if you will, and emerged from this as this res ops thing. So it seems like you could get more accomplished through that interlock. Um, so if it's a recovery time and point objective, could you get there faster, safer, with known best well-known backup as now this is restored.
That's what I think what I heard on stage. I saw multiple integrations that will speak to most enterprise buyers. There was an AWS logo, there was an Azure logo, there was a ServiceNow logo, there was a Snowflake logo, and the list goes on and on.
So it seems like, again, that convergence of all the things that would normally be happening in more complex environments that are doing AI workloads, machine learning, it sounds like resilience is coming to that arena. So, So what I liked about it, of course, is that we're now talking about data, not just being files and blocks. We're, we're talking about what's in those things and understanding it so that we can, you know, triage and prioritize by knowing what our most sensitive data is, to know more about it, to be able to inventory what we have.
I loved all the dashboards I saw, of course, because it told me what, what assets do we have? Are they being protected? How are they being protected?
Are they being protected the best way? And that's where I see a good fit for AI because it's probably better at doing that than I am. I would say.
Um, one thing that's sticking out for me, especially as a cloud solutions architect and for my DevOps engineering lens is the concept of, let's say a cyber attack happens and then you need to actually roll back. So what is really sticking out to me is being able to roll back but not reinfect or reintroduce the ransomware. And so you have to be able to roll back to a clean state before it happens.
And so I really wanna get hands on with that and dig into that more. Um, and again, this is why I love coming to these type of events because the last time I was doing a cloud fill day, I got to learn about a nice concept called, uh, recovery as code. So now I wanna fit that type of concept into recovery as code and using Terra Fort to stand that up quickly and things like that and create run books and playbooks.
And I do remember hearing something about AI being able to automate the run books. I definitely wanna hear more about that. For me, I think the exciting thing to hear from Commvault is they're identifying attack vectors that people might overlook to prevent those from becoming problems.
For me, the big announcement was about the fact that they're gonna be doing this with active directory because when's the last time you guys did an audit of your active directory to figure out if people had created a, a persistence in there? And even if you did know about that, how long ago was it? Because if you roll back, you could very well reinfect yourself and, and it doesn't sound exciting to most people, but to security people, it sounds amazing.
Uh, there was even talk of things like post quantum cryptography. I know we're, we're not there yet, but we need to be there soon. And so being able to put these things in place as we start moving towards that future where we need to think about all of these things means that they're just taking care of and I don't have to like dedicate resources to this when I'm focused on other threats.
Yeah, and I think another thing that is important to think about that I really appreciate out of, uh, the messages earlier today is not if we get ransomware attack, but how many times, like is going to happen. It is happening, it's going to speed up because yes, AI is here and it's kind of just being unleashed everywhere. So yeah.
Yeah, if you look at it, you know, the average recovery time after a cyber attack is 24 days. Universally people will talk about that. And now people are getting hit, you know, 4, 6, 8 times a year, 24 days times four times a year.
Can your company be down for four months at a time? And you know, we thought, we thought for years we, we were on the right track, right? We were doing disaster recovery.
Everything was RTOR peel. We had it down to a science, we practice it quarterly. In fact, we've gotten so lazy 'cause we had it down so good, we just flipped flop our data centers back and forth nowadays, right?
And it works great. But now with the realm of cyber resiliency, I mean R-T-O-R-P-O has no meaning anymore, right? It's not about how fast you come back, it's what's the meantime to clean recovery.
Can I have clean data come back? 'cause if I just go super fast, I'm gonna just reinfect everything. Yeah.
And, and that was actually one of the things I wanna call out as well. Um, amid some of the more technical aspects of the announcements that were made was one that caught my ear, which was this idea of a synthetic restore and, um, being in storage and data protection for a long time. I'm used to thinking of synthetic full backups.
Uh, that's a, um, essentially where you only back up the changes, but you create a full image by the all, all the history of all those changes. And so, you know, it speeds things up. But you actually do have a current state of, of data on whatever media you're using.
Uh, synthetic Restore is something that's new to me, but I love the idea essentially that, um, typically when you have to do a recovery from ransomware or basically anything, you have to recover all of the data to one point in time. The idea with a synthetic restore is that you can recover most of the data to whatever the most recent point in time is and the infected data to wherever that went back to. So you don't have to go back necessarily 2, 3, 4 days at when the, when the ransomware hit you for the entire environment.
You can go back only that one application or only the that one directory, even though that one file. Um, and the fact that it's got some intelligence in there to, to detect those changes and to help you find that point in time, it really could help to make sure that, that you have a useful and a clean, as you said, uh, restore. Yeah, it's one of the key ways that you're gonna drive down that 24 day time limit and get that shorter is, uh, you know, if I had a hundred machines infected, I can maybe get a blast radius report that says this is kind of where it should be.
But you get into a manual process, I have to restore each machine, check it, do forensic analysis, make sure it's good, and that's an iterative state. I have to keep doing it over and over until I, this at least guides me to the most probable point in time that I could do a recovery from eliminating po potentially days of recovering just to see if I can find that, that bad apple And days of lost data. Absolutely.
Well I stared at that in the face we did at our table. We had store one of many and, uh, you watch me waste how much time, you know, it was not 24 minutes, I wasted 24 minutes, you know, going like, maybe this is the one. Nope, that's not it.
Nope, it's still there. It's still. And so then you would see on the left hand menu, Hey, here's, here's clean room available to you.
Here's a way to do one of these restorations to a known good stay. That's actually part of that story at the synthetics. One thing that did occur to me is that that was only possible 'cause you had specific key integrations.
You had CrowdStrike coming in, sharing bidirectionally, you also had Splunk for those that are in that kind of world, had Splunk, there could have been probably Palo Alto there, there probably could have been other elements. But, um, bringing that all together, converging in one place, that was a, it was a total story as opposed to a piece of the story. And so I think the ability to, again, cross over interlock amongst teams is really what gets you much, much closer to a realistic recovery outcome as opposed to a, I don't know, boss.
Uh, we're working as hard as we can. I think we were talking about Star Trek earlier, so I got Scotty in my brain. But I, I think that we are probably going to see AI also attacking us differently.
So I think there's gonna be some spy versus spy like the old cracked cartoon that that is gonna, that's gonna also, uh, mean that the product experience will also have to keep up with that asymmetric warfare that is cyber, you know, threat. I'm so glad you mentioned that, Jay, because when we were in that recovery range lab, um, one of the things I saw was exactly that. So when I work with people who have run books or have automated things, it's typically a responsibility group or a team has written these automated scripts or something, but it's just for their part and they pretty much just automated enough to take care of their keystrokes.
Not all the other things that come with it. Like what are all the other systems saying, what, what vectors am I seeing from everywhere? What are the end users reporting?
Like all of that really goes into making a better decision and therefore a better recovery. I think it's important that this illustrates what I think is one of the biggest important shifts in the industry is this idea that we're no longer looking at this from the perspective of just having a bad day, right? Like backup and recovery is the data center caught on fire, A tornado knocked something out, we deleted some things we weren't supposed to.
It does not assume adversarial relationships. We have to assume that now we're not just thinking that the data went bad, it's that someone was purposefully trying to make it bad and keep it that way for the purposes of a ransom or theft or denial of service. And moving to that idea of I'm not fighting against nature or accidents, I'm fighting against another person or people who are actively trying to combat my countermeasures is critical.
Because only when we start thinking that, do we start coming up with these suggestions like synthetic recovery where it's like, what if I don't need to get all of the data back on this date when the fire happened? I need to see how far back I have to go. When did they start corrupting my transaction files, my active directory?
When did they start poisoning the models that I've been training? Those kinds of things. Dalicious intent.
Exactly. And that's giving me something like you just made a light bulb thought go off in my head. Yeah.
So there is the piece of now is thinking about, you know, having to protect against other people, but also we're starting to have more AI agents and them getting to that loose into production. So it could also be us having to do protections against AI itself, like just going off and doing its own thing because it can, now that one's really creepy, but Yeah. Well we don't have a three laws of robotics for AI right now.
Even if we did, it's not that hard to convince an ai, well don't, don't tell me how to make this evil thing, but let's just assume that you were gonna hypothetically make an evil thing. What would it look like? Oh, well I'll help you with that.
Well, and, and that's the other thing is like, again, just going back to that integration that that that bidirectional uh, CrowdStrike example where, you know, if it says, and I'm just gonna make thumb up 'cause I don't know what it's gonna be in the future, but it's maybe it's like emo panda has like gotten into here and now we have to worry about like Sge Spider is going to, you know, somehow cause this, but it it's gonna increasingly be fully agentic attack vector and it will be not set and forget, but there will probably be wider democratization of this to the bad guy community. And so I go back again, like I just, I feel like there's gonna be just jockeying back and forth trying to stay one step ahead. But that story of I see what multiple teams have to work together and interlock meaningfully.
That's the only combat available. And then the agentic part of this will be is your agentic team members and your human team members working together. That human in the loop that we heard from the Yeah, we, we, so you know, when you look at DR, which we've done For years, uh, you know, whoever the backup person was when, when there was a DR test or a true DR happening, that person was a God, nobody messed with them.
It was this one person who could do the entire thing. And now you've said it a couple times, it's the teaming, right? We call it a team sport.
Cyber resiliency is a team sport because you have to bring in everybody that cybersecurity guys can't do something without the IT guys. The IT guys shouldn't restore anything until they get buy off from general counsel and security. IT everybody has to learn to play together, which, let's be honest, these teams usually the only time they saw each other was on the baseball field twice a year at some corporate event and they played against each other, or they're fighting For budget.
So that was, so that was the other thing too, is during that, uh, onscreen sequence, there was literally, and just to put another one, it was like porting into it's finops. There was literally a description of, based on what I see, this is what your cost, your return on investment would be if you did this in this environment versus another environment. And I think by putting that in the tooling, perhaps not, not a guarantee, but perhaps you actually offset a potential like individual team to other individual team kerfluffle over the budget and how it should be allocated and where it would go.
Uh, 22 years ago, if you went to a tech symposium for hp, you had HPO on stage, they were the people that would always get the fastest network because the backup had to complete in this, you know, you know, timeframe. And so everyone's going like, wait, wait, why? Why are they getting the why is the backup team getting all the resources?
So I, I do feel that that was a, um, an interesting interface to show on. I was very fast. I'm not sure if you caught it, but showing finops on screen after a res ops conversation.
That's another example of some of the convergence I saw. So I want to just ask sort of the, the elephant in the room question here. Um, one of the challenges that many companies have is how do they break out of their niche?
And we've just talked about the importance of this being a team sport. Uh, that came through very clear in all of my conversations with folks from Commvault, not just at this shift, but even the last two shift events that I've been to and Commvault go before, that the company wants to be treated as not a purveyor of storage related products, right? This is a company that is trying to blaze new territory and deliver resilience, uh, resilience in the face of cyber attacks, resilience in the face of ai challenges for the business.
So my question for all of you is, to what extent now do you find that credible? Because they were making that case two years ago when we were here, um, in New York, they were making that case last year that this is a new company with a new strategy. And we're really serious about this.
We're serious about working with security people, with the business, with applications, with ai, with data. And is that credible to you? And I wanna throw this to Karen because she's my favorite, uh, data.
Uh, what about the data? You know, So of course, what about the data? Everyone should, data's the most important thing.
Okay. Maybe not everyone agrees, but, um, like this just reiterates. I like, since you're talking about over time, like a lot of these events everywhere I went to it is just so focused on optimizing backups.
And I have said for a long time, facetiously, no one needs backups. We only need recovery. That's all we need.
Backups are just the way we make that happen. And so I love that the conversation has shift to how do we get our data back up and running. Um, even if the, the outage wasn't a malicious thing, it was just an incompetent or overly curious inside person, we still need to recover from those things as well.
I think that one of the ways that Convault has extended, this was on stage when Sanjay mentioned that they have MCP server integration. Now, because think about the interface that most of our, uh, incoming knowledge workers are using. They're not jumping on a command line.
They're not going to a gui. They would prefer to do ChatOps. They want to ask a question, they want to make something happen.
It's a lot like the way your executives work, right? Tell someone in IT to make this happen. And the way that that works is with MCP server, they can use whatever interface they're comfortable with, whether it's Clot or Chad g PT or whatever, tell the infrastructure to protect this, tell the infrastructure to do that.
The MCP server knows intelligent enough to go, okay, well that is a function that is handled by this platform, and that's gonna be asked there. And eventually those lines blur enough that it doesn't really matter if this is the backup program because the system knows where to send those requests. And I think that that's how you eventually kind of become that critical piece of the infrastructure, is that you effectively melt into it.
Yeah. It's not about storage and backups, and it's never been about backups. You're absolutely right.
But they're even going further than restore, they're saying resilience. Absolutely. And I think the end element was, um, when the CEO of, uh, humane Intelligence was presenting, there was a Harvard Business Review study, and I went and found that, you know, this, this notion, the cybernetic, you know, contributor to your team.
And what happens, and it literally follows what you said is if a single individual can be empowered to run that, you know, I have to run the report because it's time to run the report. And if they can do that through a natural language interface on A GPT, you get back what, 20, 30 minutes of your day right there. If the team embraces that based on the projections that the Harvard Business Review study shows a team outcome may not necessarily be faster, but it would actually be 10% easily in the top 10% of all possible solutions that could come back in terms of quality.
And so I think another important point you go, resilience is what is the quality measure of that resilience? And can we do that on a programmatic basis and improve upon it? Just like you said before, we narrowed and narrowed and narrowed our time bound, and then AI disrupted it.
So it seems like we have to keep kind of running like a, I I, I'm, I'm envisioning like a rodent on a wheel in some ways, but I think there is a payoff in that the team will be better for the adoption of the AI than have they not, Uh, to me. And, and, and I don't think he gets enough press is, you know, we can bring technology in all day long, but you also have the process and the people that you have to look at along with that technology. And Commvault has invested heavily in what we call ready verse, which is our educational arm, which is, you know, when you talk to people, you know, one of the, what we call our four pillars of being cyber resilient is you gotta have a cyber recovery plan, which is so different than a disaster recovery plan, but nobody has them because nobody knows how to do 'em.
You can't even find 'em on Google. Right? You can't even search for 'em.
And so we have an entire, uh, services offering and, uh, enablement that teaches you how to do cyber recovery plans, how to bring your teams together, do proper tabletop exercises. Mm-hmm. You know, I always love that I've been through hundreds of tabletops and, you know, it's a two hour event.
They have donuts, they have coffee, you know, it's gonna be a couple easy hours. And, you know, I like to go in there and shake it up, you know, uh, one of the things that we like to do is bring chaos into that testing. Yeah.
And people don't know how to organically do that, right? I'm like, it's pretty easy. You know, you can't go with these 12 servers.
Let's, let's write the names of all your servers on the back of cards and throw 'em against the wall. And whichever ones are face out, that's the ones we, that's chaos. And so people don't organically go there.
And so we're trying to educate them on how to be more chaotic. Just like ransomware attacks are. Like, we should all be er doctors before we become resiliency people.
So we can deal with lots of information coming at you, needing more information and having to make a decision. But it's important that we get that because one of the things that AI needs is context, and it needs guardrails, right? Uh, think about like, go to any, go to any prompt and say, draw me a picture of a bear, right?
Well, it doesn't have any context, so it's just gonna spit out the first thing you think of. But if you tell it, you know, imagine you're a children's, children's illustrator and I need you to draw me a picture of a brown bear that's not wearing a shirt. In this setting, you've created context for the things that you're gonna get better results.
And we need to do that because a lot of what you, you've said you like the chaoticness of it is partially because that institutional knowledge isn't recorded anywhere. And we need to put that down because if we're ever gonna try to automate that or enhance it with ai, those things work on logical systems that require tagging, that require, uh, context. If we don't give it to 'em, we're never gonna figure out how to do it.
So, uh, you said it, I mean, we've been talking about AI a little bit here too. Uh, one thing I think we need to talk about before we wrap is, um, the applicability of this to ai, uh, to new workloads, because, um, one of the highlights of the CEO, uh, keynote was talking about that we're not just cyber resilience, we are AI resilience. Um, I'll ask the same question.
Is that credible to you? Do you feel that Commvault has a credible AI story, Jay? So again, just going back to the recovery range experience that we had, it was a storefront demo.
You're, you're, you're in e-commerce example. I think by the time we get back to this again next year, we would expect to see like, okay, here's your vector database pine cone. Here's what's happened.
Someone went in and changed material pricing information that's used as a core instruction set that someone uses as a part of a knowledge base or a chat that's gonna give a customer a fictitious price, and that causes a PR problem. You know what, whatever that set up a scenario is, and I do believe it will be a very specific, how do we recover to, to our known good state for our data? And, um, that's super down in the weeds, but I do believe they have all the essential pieces to put that together.
And, uh, I look forward to that demo. And the offshoot of that is like, in my experience, I've seen companies that are really worried about their customer database, their web website database, but they never think of what I call their IT databases. So, uh, you know, active directory, their dev environment, their training data.
So what I'm seeing is people are thinking of training data as test data, even though by definition it's usually got a mix of synthetic data and production data, and they're not protecting it, it's just data sitting out on a file share on somebody's laptop. So that's why I'm a big fan of all these inventory tools that can find stuff, because we don't even know, we can't protect what we don't know, and we can't recover data that we don't know about. True.
Yeah. And it's making me think back to something that I've been talking to, talking about a lot more and more is in the realm of vibe coding, because what's happening is, in respect to that, people are going out using things like windsurf or, you know, there's, there's so many, but let's take Windsurf for example, and using that to like code up some new application or maybe make new Terraform configs or whatever, and they could be injecting some of that synthetic data as well as production data and not paying attention to that, potentially causing leaks. And so, yeah, that's something I'm always thinking about more and more within my space of how we protect against that.
And like you said, going out and even one knowing if it's out there in the first place, I think that the story that Commvault is telling, it's a lot more credible if you think about something as mundane as Office 365. Like they, the well, and the reason for that is because there's an agent that hooks into 365 and Google Workspace to back up your documents. That's because that's where we store documents.
Now, we don't store them on a hard drive. We don't store them in our documents folder on our laptop. Everything's in the cloud, and the cloud never goes down.
Right? You, you moved off of US East one. Right?
But, but more importantly, the Commvault skating to where the puck is going to quote Wayne Gretzky, they are looking forward to AI as the place where all that data is gonna be very soon. Yeah. So how do I protect that?
Because AI is a container just like Microsoft 365, there's no file structure inside of there, and I have to figure out how to make sure that that becomes readily available so that in the event of one bad day, how do I get all of my AI data back the way that it was? Because we all know that if we send something to the prompt three or four times, we're gonna get slightly different answers three or four times. And I might need to reconstruct that thought process to get my widget off the ground or something like that.
Yeah. So do you think we, we, we got the message. I think you got the message.
I think, uh, what you're gonna find is we actually break it into two main categories, right? Um, uh, AI for Commvault. So how do we organically take in AI to make things easier?
We talked earlier about the cloud interface and, and just, you know, people wanna talk, they want to, they wanna express themselves instead of sit there and typing all day. So having that, so bringing AI into Convault, but then also Convault for ai, being able to protect that AI where it is, you know, there's poisoning attacks, there's all types of things that are going on, and we're at the, at the beginning of where these bad actors are gonna be attacking these things. And so being able to get back to a good state or law, I have to go back to the state for a lawsuit, or I have to get this back to the state for governance compliancy.
These are things that haven't been tested in the courts yet, and so we've gotta get in there early and be prepared for 'em where there's gonna be some hefty fines. Well, you know, overall though, it was, it was a great event. Uh, I really enjoyed getting out here.
Uh, Commvault did a nice job of organizing this. Um, I absolutely love the keynote by, uh, Dr. Chadri from, uh, humane Intelligence, um, just great and, um, worth watching.
Uh, if you watch this round table, if you're interested in what's going on here, uh, you can see the Convault presentations for yourself, uh, on the Commvault website. You can also learn more about much of what they're doing over there. And of course, you can, uh, find our delegates wherever they're writing and speaking and so on, and connect with them, uh, to hear their opinions as well.
Uh, also, we will be having, uh, many more tech field day presentations, tech field day sessions, and so on, uh, in the coming years. Just check the Tech Field Day website, go to YouTube slash tech field day, or follow us on social media as Tech Field day. So thank you very much, uh, for watching.
Thank you all for giving some precious days of your lives to come to New York and, uh, and attend all this and, and, and pay attention so well. And, uh, and I, uh, really appreciate the, the whole experience. You know, there are some days, no matter what Broadcom does, it seems like the market just doesn't like it.
You're watching Textron Gang. Hey, everyone, happy Tuesday. It's Alan Shimmel here.
You know, we've got a, we've got a small but mighty gang to go talk about, to talk about things today. Got a bunch of people out. It's Christmas coming, other people are at conferences.
And I'm really happy though, to have Kate Scarsella and Hope Lynch with me on the gang today. You know, it's not an orphan gang where we have more women than men. So mark this down, and that's a good thing.
Um, it's Tuesday, I guess it's, is it the week before Christmas at this point? Yeah, by the time this week's over next week will be Christmas. So it's the week before Christmas, but the news is not slowing down.
Um, we've got a lot to go over, ladies. So wanted to start off with, uh, Broadcom, you know, they, they reported what to me. I mean, they beat the estimates.
They upped their, uh, their guidance. They announced, you know, who the big mystery customer of a new $21 billion chip order came in, you know, uh, their CEO gave an impassioned speech on why, you know, people want customer AIC and so forth, but yet their stock got punished. I, you know, I, this is why I'm not good.
A good stock investor makes no sense to me. Kate, can you make sense of this? Uh, no, I can't either.
So, just to review here, Broadcom made headlines this week by this massive 21 billion custom chip order. Um, and at the same time, um, they were, you know, Broadcom, CEO pushed back on the idea that only Nvidia can win in AI calling Google's TPU strategy, a transactional move. So for me, um, gosh, I always feel like we're writing off, uh, Broadcom generally, and I think Broadcom as a whole has always been across the board, even with their, you know, raspberry pies.
I mean, they are a phenomenal, phenomenal group, Broadcom. And so I wouldn't write them out just yet. So, you know, custom, you know, who would've thought a custom chip when chips were first made?
Who would've thought right now that we would be talking about custom chips? I mean, that is, you know, this is why I think we will continue to go down custom chips, um, path and Broadcom is, is, you know, definitely moving in the right direction here. Yeah.
Um, I have a little bit, there's a little insight though about, um, Broadcom's performance and what, and what's going on. I think, um, based on the reading I did, wall Street basically feels that it's a little bit of a shell game, because Broadcom is basically acting as a pass through manufacturer. So they're taking Google's TPU designs, they're manufacturing them, and they're delivering full racks to anthropic with no markup.
So they're passing the cost directly through. So even though they beat earnings, they're stock dropped because the investors are concerned. They're saying, well, you're not adding any markup.
You beat earnings. So, you know, is it, is it evening out? So are you actually doing as well as you thought?
Their margins are still great, but, um, it, it seems that they are being punished for the benefit that they're passing along to ant. So, I, I think there's a few things at play here. Hope, I think you hit on some of them.
Number one, they are overly dependent right now today on Google as a customer. 'cause Google, they are the manufacturer of choice for Google's TPUs. And anytime your business is dependent on just one customer, you know, it's a single point of failure.
And, and so people are gonna be cautious. Number two, I, I think you're right. They are serving as a pass through distro, if you will, operating on razor thin margin there, uh, in this particular anthropic order.
Um, I think that's why, and I always forget his name now, uh, the CEO of Broadcom, uh, hang, hang, hock, hock, Hak, hakan, it comes to me. You guys will be this old soon, one day too, don't worry. H 10.
Um, I think this is why Hakan was saying that this Google TPU thing is a transaction or transactional move. But what he's really saying is he's pushing clients to custom chip destiny, because no one wants to put their fortune on someone else's stack, if you will. Everybody.
He thinks everybody's gonna want to design their own chips that are customized for their unique use cases. And that Broadcom is happy to be the manufacturer of choice for these custom chips that you design. But using someone else's custom chips may be, you know, okay, for now, but is not where you want to be as this AI race, you know, explodes and, and, and continues to move forward.
And so what he's looking to do there is broaden the base, not just Google. Now, they already have a huge deal with open ai. I, I forget for how many hundreds of billions of dollars over the next X years.
But of course, that's contingent on open AI spending one and a half trillion dollars that they don't have, um, today. Anyway, so I I, I do think that that is a, um, part of, of what, what, what's going on here. The other thing though, in Broadcom's defense, look, they went out, they bought ca, they bought Semantic, they bought VMware.
These are software, not hardware, software companies where you have better margins generally than you do on hardware. And they're basically cash cows, right? They are, um, books of business that kind of just, they're cash cows, and that should really help with their cash flow and their margins.
So I'm not quite sure in light of all this why they still deserve to, you know, be lower. But it, and the funny thing is, I, I'm not, I'm not a finance guy, and I didn't sleep at a Holiday Inn Express last night, but if you, you know, from what I read, if you look at what the, you know, the experts on the streets say they all have it as a buy long term, or most of them have it as a buy long term, but yet the stock still got hit. One, one other, um, bit of nuance for this that I think could work long term in Broadcom's favor is for the past five years, everyone's been talking about GPUs and building out for models, right?
A lot of the models now are built, what they now need is, uh, performance per dollar on inference, workloads, inference is the future. Inference is everything at the moment. And these TPUs, um, are optimized for the architecture that helps models like Claude, No doubt.
I mean, but Amazon, Amazon has train. That's their inference. Google has theirs.
Rumor is Microsoft's gonna have theirs. And I think that's where, where he htan is going, that everyone, that inference is gonna be the battleground, right? Vidia has a stranglehold on the GPU training market, if you will, but everyone's gonna want their own inference to be a player, because that is where the action's gonna be, Right?
And they're, they're betting on the idea that, um, ai, it, it won't be like one size fits all. And I think that Broadcom is really well positioned for that at the end of the day. So, You know, I, I agree.
I mean, they, they seem to be the inference chip maker of choice, or the, or the inference chip manufacturer of choice. I do think that long term, that's where Intel has to be playing too, right? But there are others.
We're not finance. I I'm not a finance person either, but hey, I'd go out and buy Broadcom. Yeah, I mean, I, well, I think it's a good idea.
We're not giving investment advice, though. Please. Advice at your own risk.
Um, the last thing we did, but you know, there, there are some other players in that internship. The Marvel is one Micro, I forget, micro something is another, but certainly Broadcom is, is a major, major player there. And, um, it'll be interesting.
But here, here's just one other thing I wanna throw out at y'all as, so this $21 billion order from, uh, anthropic, all right, it's 21 billion. I think Anthropic could probably cover it, but there's a lot of deals on the books, especially, and we've spoken about this before, the open AI deals, you know, they, they pledged one and a half trillion dollars between AI data centers and AI chips that, like in the case of Oracle, and in the case of Broadcom, represent a significant amount of their booked revenue out there in the future. And if that doesn't happen, if there's a hiccup in the market or something doesn't work out, right, that could come back and be a real, that could drive these stock prices really Yeah.
Into the ground. It's, uh, it's the, the AI angst. Yeah.
Right? It's because Anthropic, oh, go ahead. No, no, I was gonna say it's a big bet.
Yeah. But Anthropic commits $21 billion of Broadcom for TPUs. Anthropic has raised around $33 billion in funding.
They're evaluated at around $180 billion. And this is from Google, Amazon, sovereign Wealth Funds, others, right? But Google is also anthropics cloud infrastructure provider, and they're manufacturing TPUs through Broad Talk.
No, but think about it. They're buying, so Basically they're all in bed together. They Really, but no, it's, it's a circle of money.
com days, we were in a really bad contract with World Cup MCI, world Cup for Bandwidth. I think I was paying, not me personally, the, I had helped a company grow called Inter Reliant. We were public company, big A SPI think we were paying like $1,200 for a t one line worth of bandwidth back in the day.
And the going market now was six or 700. So we were paying twice what, but it was a contract we had signed a couple years before, at the time, it seemed good. And, and this company came to us and said they were sending up a broadband trading commodity desk, and that they would buy our, uh, broad, uh, WorldCom.
It's funny, Broadcom WorldCom, they would buy our WorldCom bandwidth at $1,200 and through the magic of arbitrage and, and commodity sell us back, in essence, the same amount of bandwidth for 700. And they, you know, and they could do it all day long as much as we had. And I, I was the, I was the, uh, VP or SVP of biz Dev Corp dev, we went down with my CEO and COO to, um, actually it was to Houston, to a company called Enron, because that, that, that, that, that was the company that promised us they could do it.
And, uh, the full Spectrum of, of, uh, You know, and I'll never forget, right? I sat here, the three of us were sitting, and there were these all Enron people around us. And this one would buy it from us, trade it to this one, trade it to that one, give it to this one, that one would go here, this one, and then this person would sell it back to me.
I said, how do you do that? They said, we've been doing this in the commodities markets for generation. We know how to do this.
I said, okay. I mean, you know, it's Enron. They're a big company.
They get the big E downstairs. And I, I'll never forget, I walked out of there, I asked the CEO of our company, herb Rebar, who was an old cell phone guy, telecommunication guy. I said, herb, how did he do that?
I, I just, you know, I feel stupid. He said, either they're the smartest people in the house, or they're the biggest crooks. And, uh, as it turned out, right, yeah, that's how that turned out.
So, you know, this thing will implode upon itself, or it won't, I guess we'll have to see. Yeah. But hey, Broadcom, I mean, having all the different, you know, other Broadcom's a solid business.
Yeah. I mean, between the software, and they still don't forget most, even the big public cloud providers, as well as most data center providers, it's still Broadcom that is powering a lot of that infrastructure. Not the CPUs or GPUs in a particular server, mind you.
But the networking, uh, gear and everything, it's, you know, it's a fantastic Business. I mean, I feel like they're everywhere. Every time I turn around, it's something Broadcom and No doubt about it.
All Right, I'll be happy to hear you say that. Say that. Well, look, I, and I, I'll, I'll just end this with, as I said before, Kate, hope and I, we're not, we don't have a horse in the race.
We're not here touting stocks or telling you what to buy, or you do what you think is best. But we're gonna take a break here on the gang. We're gonna come back and talk about, I call it data center nimby.
You're watching Textron Gang. You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included, that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life.
Hey, everyone, we're back here on the gang. So interesting. You know, a admit amid the 5 trillion to $8 trillion plan data center, uh, AI data center, AI factories, as you may call 'em, build out over the next couple years.
We're now seeing some pushback. Some of the pushback is, is very kinda local. You know, the typical kind of NIMBY stuff.
Oh, you didn't say you were building it in my backyard, right? Go put it over there, where those people are, where those people aren't, you know, in the woods, in space under sea, just not anywhere near me. Um, and we're seeing more and more of this, the latest being a, a city over in Arizona, um, rejected, uh, a plant data center because of that local pushback.
Um, and there's, there's other reasons for it too. The fact of the matter is, a lot of these AI data centers aren't bringing the jobs. Yes, there's initial jobs in construction and bringing it online, but once they are online, these are not labor intensive.
Uh, you know, there's not manufacturing plants or something like that, that you have a lot of workers. But on top of that, now, uh, an environmental group has asked, uh, Congress for a pause on these projects because the, the environmental potential for, for, for catastrophe is they claim not something that's trivial, right? It's primarily around, well, what, what are you using for energy?
Are we, are we gonna rush nuclear on all of a sudden because we, we need it desperately? Are we diverting water? Are we, are we gonna fire up coal plants to do these things?
Um, you know, what are we doing? What are we, what are we doing for cooling if we're not using water to cool, are we using chemicals? Are those chemicals being disposed of properly?
There's all kinds of, you know, love canal scenarios here that they, they're forcing on Congress, you know, generally, you know, we're, we're past the spotted owl phase, I think of, of the government stepping in on these things. But, and, and, and look, the government has a stake in it too. So I, I don't know what the likelihood, I mean, ultimately, I guess it winds up in courts, but I mean, our Congress doesn't really show much of a backbone to get involved in these things.
Hope. Kate, what do you think? Uh, speaking of government and speaking of the courts, um, there was an executive order on December 11th that is setting up a showdown over data centers.
It is ai, the, the AI litigation task force at the Justice Department that will sue states and directs, um, commerce to potentially withhold federal broadband funding from states that don't comply. So this is them saying, uh, you know, this is a, the new version of Emmin domain, I guess, right? So Kirsten Sinema, she is the person who went to Chandler, Arizona to basically tell them, Hey, um, you need to approve this now while you still have local control, because if you don't, we're gonna override you anyway.
So this is a, this is a big fight. And one of the other interesting things about this fight is it's become very bipartisan, um, because it's unified, not over ideology, but utility bills. So residents in these areas are probably gonna see their power bills jump, uh, anywhere from 15 to 20% over a few years when they're not gonna get any of the benefits.
Really no direct benefits from it. And I still don't understand, I mean, and help me here, I don't understand why it is that, that it's passed on to consumers, the, the expense at the end of the day. I can someone help explain that to me, like the cost for, for energy.
I like, why don't we pass it back onto the company? I, Uh, well, one of the reasons is because it's, it's part of the grid, right? So this is not something that is just localized to the data center.
So where I live, it's, it's Duke energy, right? If Duke Energy has to build out, um, those build out costs are not necessarily directly built back to what caused the build out, but they are peanut better spread across a whole region. So it's definitely a spatial mismatch in, uh, distribution of benefit and burden.
And that's part of what's driving the, the backlash. Yeah. It, it's not like this is a dedicated circuit that you flip on for a data center, right?
What, you know, what the utility looks, looks at, and, you know, from what I've been told, what the utility looks at is what is its total, uh, capacity to generate power. And then the, you know, the, the, the cost per watt, megawatt, gigawatt, what have you, is based upon that, right? How much are they totally generating versus, and so what do we charge?
Now, there are some of these data centers that are, or factories or whatever you wanna call them, that are, are supposedly being designed to have their own contained nuclear reactors in a container or something, right? So that they don't go on The grid, those in their backyard. Well, yes.
You know, no. Who wants those in your backyard is right. But for the most part, these, these monster data centers are gonna be on the power grid and, and consumers will pay their share.
And, you know, in another era with another congress, you might see legislation that says, Hey, for the good of America, we're making these companies, these data center companies, bear the cost of that. And everybody's electric bills go down as a result. But in today's bizarro world, where corporate greed is king, we all bear the cost for these data center companies to be able to come on, you know, and the, the, the flip side is, oh, they're bringing you jobs.
They're bringing you this, they're bringing you that, and they're not. And that's why like the city in Arizona said, you know, when you, when you do this, it, it doesn't add up. It's not weighed out.
Um, so, so it, it is, and you know, and then there's the whole environmental factor to it, Even with water. I mean, water for this is, you know, gosh, that's really a, a critical commodity, especially in Arizona. I, you know, I remember when Intel was there in the big fight with Intel in Arizona.
So I mean, you look, look at where they're building these Arizona, west Texas, right out Abilene way and out that way. It's, it's, um, you know, in, in the Midwest, generally, like Ohio and, and some of the places where they're building there, they have a little bit more water resources. It makes more sense, but that's also why they're looking at building them in the bottom of the sea and up in space and everywhere else, because, you know, of the, of the heat issue or temperatures issue.
Um, but you, you know, here's another, from a legal point of view, hope you, you're right, this is coming to a showdown, right? States rights versus federal, federal government does have, uh, rights over interstate commerce. And they'll probably say that these data centers are part of interstate commerce, because, you know, they transmit data across state lines.
But the issue is, can this be done by executive order without an act of Congress? And that underlies a lot of what the Trump administration has done. Congress has actually done very little to approve a lot of these executive orders.
And again, there have been a lot of the courts that say, no, this, this is, this is an action that is reserved for Congress, and it would absent a congressional order. It can't be done by fiat. Um, now, to date, the Supreme Court has not come down on this the way many thought, um, though under the previous administration, they were very clear about it.
But I guess the previous administration didn't appoint three or four of the judges on the panel. So, but, you know, this is, is not the way the system was designed. I just, at the end of the day, I mean, I hate that.
Again, we seem to be flipping the bill for ai, like we are per and, and we are personally flipping the bill over and over again. And it just, you know, forget about even the monstrosity that's going up in our backyards, but we're paying for it. And it just, it, it's not right.
So in my opinion, No. As, as they're saying in a lot of places, it's not what we voted for, right? Um, and, and so we'll, we'll see how this plays out.
Ultimately, it, I, I think, look, these, i, these AI data centers gotta pay for themselves. And if the, if the every man is gonna be footing the bills in, in, in, you know, in the form of higher electric and higher utility bills, I, that's gonna make for a real problem. You know, Houston, we got a problem.
Anyway. We'll, we'll see how it plays out. It's gonna be interesting.
'cause $8 trillion is a lot of money, guys. Yep. Not to mention that the I-B-M-C-E-O says that even you look at that $8 trillion buyout, uh, the 8 trillion, trillion dollar build out, and there's just no way it could be profitable, right?
Given money's generated and everything. But who am I to argue? Let's take a break.
We'll come back and we're gonna talk about Alice Unchain. That's right. Our first Textron Gang concert.
No, it's not. Stay tuned. Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group.
All right, everyone, we're back. No, we're not really doing a concert, but I just wanted to get an idea of how many of you out there remember Alice Unchained? Truth be told, it was a little before my time, or a little after my time, excuse me, But I remember.
But yeah, I would imagine Kate might be your time. Uh, but we're not really talking about music. We're talking about something called Alice from IBM.
Don't ask me what Alice means, but hope you may know and tell us more. Yes. So, IBM research announced Project Alice at newer IPS 2025.
And Alice is Agent Logic for incident and code bug elimination. So, uh, it's part of IT operations, and the estimate is it outages cost over $14,000 a minute. So finding the bug, finding the problem, um, is, is a big deal.
So what is interesting about Alice and different from how others have approached the problem is they are using sequential multi-agent approach. So instead of, um, one AI trying to handle everything, there are three specialized agents and they're working like a relay team. So one is incident analysis, another is code context that, um, builds a graph to show how microservices connect.
It's, it's basically giving you a landscape and then a code analysis agent comes in. Um, and this is powered by IBM that shows you where the bug is in the code base and gives you an issue in GitHub. So the major point about this though, is this is still, this is still basically in a lab.
This is still being tested. This is not in the wild, this is not available to purchase. And with some of the caveats around it, it probably could be, let's say two to three years before it's, it's publicly available, but it is an interesting way of attacking the problem.
So companies like Datadog, PagerDuty, um, they're gonna be sitting up and paying attention 'cause this is gonna offer them potentially some competition. Competition. Oh, I, I would think so.
You know, just a silly question. I I was never, I never made up, uh, names like this. Do you think they started with Alice or they, they said, what is, what are we doing?
How can we make it smell, spell something cool? I think somebody probably Said, oh, I need EN No, Grandma. For me, when, when I saw the name Alice, um, I thought immediately of Bob, Alice, and Bob.
So now we just need Bob Alice for networking security. Alice used to hold the private key. Bob held the public Key Eve was for eavesdropping.
I, I mean, there was, and so when I thought, oh, project Alice, my first thought was, oh, we just need Bob. I, I mean, I, I literally thought it was, um, it was a shot back or quantum theory, Bob and Alice. Alice and Bob.
Um, so I am sure they didn't intend that, but that's where my head went. Mm-hmm. Mm-hmm.
Um, and for me, you know, when I think about this, I, I personally think it's going to, I, I think just like vibe that we thought would take a heck of a lot longer. I think ag agentic AI for the win, I think this is gonna come around a heck of a lot sooner, especially if IBM is already announcing it as a person who worked for IBM for over 20 years, um, that they are already announcing it is, is really, really cool. They're announcing how it's, how it's going around it, it goes out to GitHub.
And this is phenomenal. And, and, and a person who had to design, you know, socks not system on shift, but security operation centers, you know, when we started bringing in network logs, and I don't, you know, it, it became, it just was unmanageable from a human perspective. Now, we started to add applications, database, blah, blah, blah, endpoints.
All of a sudden it was like, oh my goodness, what the heck? We're never, you know, we couldn't detect an anomaly if, regardless, I mean, we had a hundred people on our team. So this is a really smart way.
I think it's, it's, Hey, I love Alice. So she's, she's not around yet, but I love her, right? And, but one smart thing that I think they're doing, it feels like a, a strategic bet on, um, long-term interoperability, is they are using the MCP from Anthropic.
So once it's built, once it's in the enterprise, it should be able to connect with any external models and tools that support MCP. So they are, you know, it's, it's proprietary tech, but it plays, supposedly it will play well with everything. And for it to going to GitHub and for MCP, I mean, it, that's, you know, hello IOT, right?
I mean, MCP uses iot, um, protocol. I mean, yeah. Anyway, you know what I'm saying?
So yes. Sorry, I do. So, you know, in my mind though, and Kate, no disrespect to, to your time at IBM in the Big Blue, but I, I-B-M-I-B-M has a way of announcing these things, and they're visionary and cool as heck and exciting.
And it's like, wow. And then a funny thing happens on the way to market It. It, it's true.
I mean, we, we had a whole Watson for QRadar and yeah. And yeah, no, we, it, I'll give you that, Alan, it didn't go. Yeah, but I mean, but I, you know, it, I, but, but I love the idea of it and what, what they're trying to do here is the right thing.
I I think another aspect of it is this whole multi-agent thing, right? This is the world we're gonna live in, right? To go all call Sagan on you.
We're gonna have billions and billions of agents, right? And so our platforms, us as you know, people are going to need to learn to live in this multi-agent system where, um, we're gonna have multiple agents, agents, some of them overlapping, right? Some not.
They're all gonna talk to each other, whether it's through, uh, MCP or A to a or, or what have you. Um, but that's the world we're gonna live in. They're digital coworkers and it's not just one of them.
And I think wrapping our heads around that, you know, because, and again, we've discussed this on shows here before, are these agents ephemeral? They do one thing and then die and go away and get recycled? Are they perpetual persistent?
Well, if you watch Murder Bot from Apple, that would be a no. Yes. Well, I didn't watch that yet, but now I will.
Um, but I mean, so this to me is sort of the great unknown as we, as we move into this multi-agent world. And I, I do agree with you. I think ag agentic AI is coming fast.
Um, it it, One, one other point, sort of a counterpoint. So Google also released a research study this week, and they tested 180 configurations across five different multi-agent architectures. And they found, or agents don't necessarily mean better performance.
And for sequential reasoning tasks, the very same scenario, the very thing Alice does with the relay race architecture, all multi-agent variants degraded performance by 39 to 70% compare it to single agents. Now, one other thing to consider, you have these agents, these three agents working in sequence. What if the first agent makes a wrong assumption?
The other agents, as they are currently designed, are not made to validate or correct assumptions. It just magnifies. So now it gets to the SRE, their junior SRE, they take it at face value, and they chase this until they find that, you know, it's, it's bogus.
A senior SRE is going to spend time validating it. Are you really, you know, how much, how much do you gain? So, so basically this whole, um, you know, the whole false, false positive is affecting gen GA as well.
That's good to know. That's great to know. Not just with humans.
So I, I, it Does not escape. I I view that as growing pains though. We'll, we'll figure that out.
Yes, I think they will Factor first. You gotta get the, a single agent working, then start thinking of it in this multi-agent world, they'll put kind of the rules there in place. Um, but the, you know, the question is how fast do you figure it out?
And, and reiterate, right? This is like DevOps on steroids, deploy feedback loop reiterate, deploy feedback. You know, if you have sort of ephemeral agents, you could do that really quickly.
Yeah. So, so Alice is not out of the game yet. Alice is not outta the game.
Now, I didn't think of Alice unchanged, nor did I think of, wasn't it Ted and Alice and Bob and someone else? It was, it was Alice and Bob and Eve. And if you think about it, Eve was Eve's dropping.
So that was cute. Mallory, you had, um, uh, you, I mean, they do, uh, Carol became identity. Uh, they, they actually had the whole alphabet of characters as we grew the stack.
Yeah. So you are remembering correctly. But Alice and Bob were the first.
There you go. So, but I thought of Alice, the waitress, the TV show. Oh, I thought of the Brady Bunch Alice Too.
Oh, she was one of my favorites. Alice on the Brady Bunch, for those of you who may not remember, but you're a real gen Xer. Heck, hey.
Yes, I am. I am. Okay.
Hey, I look, I look, you know, I, I'll admit I was, I was a big Marsha Crush. Hey, and so was I really? I think we really like Marsha.
She was cool, except when she got that thing with her nose and she didn't like it. Anyway, I could see we're degrading here. Let's pull this back.
Um, it, it's gonna be an interesting, but you know what, we're about outta time. Hope. Kate, thank you so much for coming on today.
As always, I thank you so much for watching. We hope you enjoy your Tuesday. As usual, we've got a lot of text on TV and it's the week before Christmas, everyone, things could be worse.
You're watching Textron Gang. Hey everyone, welcome back here to another TechOne tv. I am happy to introduce you to Anthony Richie.
Anthony, welcome to techron tv. It's great to have you on. Thank you, Alan.
I appreciate you giving the opportunity to kind of talk to you today. It's my pleasure, Anthony. Yeah, I didn't even mention you're from DigiCert, but we're gonna get into that.
Um, let's, let's start off though, before we talk about DigiCert, let's talk about you a bit. Sure. Give us an idea of, you know, what your position at DigiCert is and, and maybe a little background on how you came to, to be there.
Absolutely. Yeah. So I'm, uh, the VP of Global Solutions Engineering and really kind of focused on the technical resources that we have within our organization, working with all of our customers in, in a pre and post-sales capacity.
So we have a lot of interaction with a lot of our top, um, top org top organizations that we do business with on day, day in and day out basis. My personal experience, I've been in cybersecurity since around 2007. I actually ran my own organization.
I, it was A-S-S-L-T-L-S aggregator back in the day, integrating with all the different public tls. And prior to that, just in it, in a variety of capacities for 32 years. I hate to say that.
So You, so you just broke into the business, you tell, right? Yeah. Yesterday.
What behind You and me both. Uh, so, and that, and that's actually a great background for, to, to bring to DigiCert as we were talking off camera, Anthony, I think DigiCert has some of the rightest minds in the industry when it comes to quantum cryptography, when it comes to certificate technology and, and PKI and these kinds of things. I mean, really like PhD smart as heck.
Mm-hmm. Absolutely. Like rocket scientist kind of people.
So it's, you know, but you'd need people who also have that real go to market who understand what, what, what, what the market wants, what people need, where, where are the, where's the pain? And, and that, that's an important part of it. You know, I'm record realizing though maybe not everyone is familiar with DigiCert out here.
Anthony, if you wouldn't mind, give people a, a sense of, well, in your own, you know, from where you sit, what's DigiCert about? So, DigiCert's about public trust and increasing our capacity to help with cryptography, uh, from a public and private perspective in a variety of different organizations. And we're about kind of building that trust factor.
It's not just about the encryption, it's about the verification and validation of the different identities that you're either, you're, you're proving authenticating, you know, from a non p perspective or, you know, signing and understanding kind of the different artifacts that are deployed within an organization. So we do a variety of different capacities, but, you know, foundationally, you know, PKI kind of sits there as our, um, our foundation for a variety of different use cases and workflows that we support for our, uh, organizations across the globe. And you mentioned it, you know, and I think it's a, it's an a testament, you know, in terms of the things that we do as thought leadership within the marketplace, you know, the people that we have globally, that the footprint of the operations of DigiCert, it's second to none.
You know, the, we, I'm always amazed at the people that we have and contribute to our customers to help them kind of build a, a better security posture within their organizations. Yeah, I, I agree. And you know, part of that, of course is staying, uh, on top of the latest developments in, in the space.
And, you know, for, for DigiCert, one of the big ones is this whole post quantum cryptography issue and algorithms. And, you know, did you, I remember interviewing people from DigiCert three to five years ago that were working with NIST as we were developing these post quantum cryptography algorithms that now are available way before qj, way before everything else. You know, we've got this available.
I feel almost obligated. I should mention we're working really closely with DigiCert on something called, I think it's the Quantum 25. If I miss if I have it wrong, I apologize.
But it's the, it's nominations are open right now for the top 25 folks in the, uh, quantum field because DigiCert is, is and will continue to be a leader in that space. And, and they're really, you know, forging ahead with this. We're partnering with them, we're excited by it.
And I'll just mention to anyone out there who knows someone who they think qualifies as a leader in the quantum space. Go, go check that out. You can get through it on Techstrong as well as on DigiCert.
Yeah. And Alan, to, to that point, quantum Security 25 is an important aspect of kind of building that momentum within the post quantum space. And, and certainly we we're, I think they, we have until January 28th for to, you know, when there's are gonna be announced.
But we want people that are gonna move the needle in the p qc space and be able to kind of support and help us have a better public interaction between different organizations. From a crypto cryptographic perspective, p QC is a big deal. And Ellen, I've been talking to a, a number of customers and surprisingly, like I'm immersed in it every day in day out, you know, from PKI perspective.
But when I go talk to organizations that haven't even really moved the needle or understand what's going on, and believe it or not, there are organizations, large ones that aren't ready, right? They're still, they're kind of, you know, putting their head in the ground, if you will, and not seeing some of the things that they need to do from a security perspective. So we as thought leaders within the industry need to be able to kind, you know, enlighten them, educate them, and then bring them to a place where they can get ready.
Alan, you made a a point, you know, they, you know, NIST did approve some of those, um, standards, but, you know, NIST is, was US based, right? So other governing bodies within the eu, you know, they're looking at other encryption algorithms as well, like classic mees, for example, as being something that, that the EMEA region is looking at as well. So at DigiCert, we have that visibility across the globe to kind of support our customers wherever they're doing business, whether it's, you know, stateside or in near region or in a PJ.
Love it. Excellent. Anthony, I didn't want to turn this into a, a post quantum cryptography interview.
I know you are not the expert there. We've got other things you and I need to talk about. Recently, DigiCert announced couple of key strategic relationships, partnerships, and developments.
If you wouldn't mind, make our audience smart a little bit on what, what's been going on. Absolutely. You know, as we go into this, uh, you know, like, uh, certificate, uh, validity periods are starting to shorten as well as some of the validations that have to happen from an organization perspective as well as a, a domain control perspective.
And the challenge for organizations is they're still doing things manually, right? Being able, you have like a IT operations folks that go into a server generate CSR, and people that don't know what A CSR is, a certificate sign a request, it's basically the request for a certificate, and then they upload it into the system. But in a day where we have cloud native technologies, Kubernetes based deployments, you know, cross built in the cloud on-premises, the proliferation of certificates is, is incredible.
It's not just one or two, it's thousands and tens of thousands. And as we shorten these validity periods, we're now, they're about a year for public TLS, they're gonna get down to 47 days by 2029. So we need to ensure that we help our customers build these agility processes or velocity in terms of the enrollment and deployment in the binding.
So what we've done is we've made some strategic partnerships with, uh, Citrix and F five to kind of help support that velocity and help, you know, identify, uh, organizations that are using their technologies and then building solutions for them to be able to kind of push those certificates, support them, discover, and certainly renew those when needed. So organizations can focus on what they're best at, what are their service or, um, products that they're building for their customers. Not necessarily worried about the, uh, security aspect of it.
I mean, worry about it, but bring in the right people to kind of help support that. And with these partnerships, you know, DigiCert with, uh, you know, certainly Citrix in this case and F five, we can kind of build that model to kind of help them support their businesses. Absolutely.
Look, Citrix F five, to me, those are natural partners of DigiCert because of the natures of their business and where they sit in the IAM, uh, kind of food chain, if you will. Mm-hmm. So, Anthony, I'm recording this.
We're recording this while I'm out here in Vegas at, uh, AWS reinvent. And I gotta tell you, to me, the theme out here is ai, ai all ai all the time, it seems, right. How is AI specifically like with these partnerships with Citrix and F five and Digi Digi Cert, how, how is, how's AI impacting that?
You know, AI is everywhere, like we were talking about earlier, and I'm surprised it's not in my ketchup bottle yet, but it will be there For sure. Right? It might be they just haven't told you forget.
But, you know, I think, I think the, the, um, the worry, you know, from the, the space or worry in the market is like, how do we control ai? How do we validate AI and X 5 0 9 certificates? And digital certificates are that capability to kind of drive that non repudiated identity of these agents, AI agents in particular, and DigiCert.
And, and we didn't mention it, but, you know, we, we actually have not only PKI cyber, you know, PKI foundational products, but we are a DNS player too. We're one of the largest DNS players within the, so we have our alter DNS solutions that give you the capabilities to do and, and to do a variety of different identity management or validation of identities. Most people probably listening to this, um, interview, we will understand, you know, DNS sec, uh, operations for, you know, fqdn or websites, that same type of solution.
And of course, we have, there's different standards. Uh, the A two A standards that are being, uh, formulated kind of support the AI model. And we as DigiCert can support that through DNS as well as some of our PKI solutions that we have.
So what's happening is, is that we're taking, you know, we're, we're on the forefront of building different models and trust models for organizations and helping them deploy these within their organizations to ensure they have the proper AI or proper models that they're supporting within their organization to support their businesses. Let me throw you one outta left field, and if you're not prepared to answer this, it's okay. We didn't, I'm lucky.
And so I'm good. Okay. So the, the, uh, CEO of AWS yesterday said, you know, in the very near term future, like within two to three years, let's call it, um, there's gonna be billions.
I don't wanna gonna call Sagan on you, but billions and billions of AI agents out there. Mm-hmm. To me, I'm ready to call my digit cert people and say, Hey, how do we, how do we certificate these AI agents?
How do I, how do I make sure this is the real AI agent and not some rogue AI agent or a a, an evil clone or something else? Man, that's a scary proposition, right? With billions of these agents running around the, it just seems like the, the potential for chaos is, and, and for e you know, for mal malware, I don't call, I don't know if you call it malware, do you call that malware?
Um, good, Right? I mean, training it inter inappropriately for to do nefarious acts. Yeah, absolutely.
You know, where do you see Digi and, and you're gonna need the f fives and the, and the Citrix's of the world. 'cause this is, is probably is bigger than any one company. Yeah.
Right. So I think when we look at, uh, the validation, the, the authenticity of the agents certificates become that, um, that model to kind of help deploy that. And the, and, you know, so I look at it as agent is another aspect of, um, control that we need to support.
So, you know, we talk about different appliances, applications, you know, we deploy within the clouds. We have, you know, Kubernetes based deployments with microservices where we need to, what we call mutual authenticate, and we use certificates for that. Like, I have a certificate that says, I'm Anthony Richi.
You have one that says you're Alan Shimmel. And then we have a trust, a a, a root of trust, which in this case is DigiCert or an organization's, um, root certificate that we're supporting on their behalf to prove that trust. So if we both trust the root, we can trust who we're talking to.
So if we were AI agents like your Alan AI and Anthony ai, we'd certainly be a lot, probably smarter. You and I, if we had AI agents talking on our behalf, we can have identities associated with it. So it's not only just an identity for a person or an appliance or applications.
We can do identities for AI agents and the deployment and management is all around the protocols and industry standards then we are participating in to ensure that we have a safe deployment of those technologies. I don't know, it sounds kind of Mr. Smith out of the matrix, right?
Bill Bluefield to me in There. Oh yeah. Anthony, I want to, we gotta kind wrap up.
So I wanna bring it back to Citrix and F five. Where can people get more information about these partnerships? com and, uh, look up our partners, and then you'll see we have the different press releases within our website.
Please add a request and certainly we'll have a team and a a very seasoned team kind of work with you through some of those, uh, different questions that they have. Absolutely. Um, look, two good companies we work with, you know, we obviously cover both of them, so sounds like three good companies here go go into to market together.
What could go wrong? Anthony, thanks for coming up here on Techstrong TV with us today while we're out in Vegas. I appreciate it.
Come back, maybe we'll do something actually, the, I know DigiCert has a bunch of their trust, uh, events going on worldwide. Maybe we'll catch you in person at one of those. That'd Be great.
I usually have, I usually do some different talks about implementation and how we, I'm all about helping the customer, but thank you for having us spending the time with me today. My pleasure. I appreciate you getting on here early with us.
Anthony Ricci, uh, DigiCert here on text on tv. We're gonna take a break. We've got more stay tuned.
Hello and welcome to the latest edition of the Textron AI Leadership Insight series. I'm your host, Mike Bazar today with Mike Lynch, who's the head of the AI Transformation Services for auditoria. And we're talking about, well, how AI is impacting the financial services sector.
Mike, welcome the show. Thank you, Mike, for having me. I think everybody out there is grasping for some way to understand, well, just how are we using ai?
What impact is it having, and where is that elusive ROI? But you guys do a lot of work in the financial services sector, and they're usually at the forefront of these things. So what are you seeing?
Yeah, no, it's great question, Mike. And, uh, again, thanks for having me. So it really, when we talk about AI and where we've been over the past, really six to seven years, as the office of the CFO has really tried to transform forward, it's, it's not a question of if we're gonna in integrate AI into our processes anymore.
It's really a matter of how fast and in what areas. And so at auditoria, what we've seen most of the offices of the CFO start with is areas of the office of the controllership, so mostly in their accounts payable and accounts receivable space. And we actually run an annual report where we look at the state of AI transformation in the office of the CFO.
And, and it's really interesting to watch those trends over the past six years as we've done the report to, to think about where things were before. And then of course, when you have the advent of chat g bt just a few years ago, what has kind of, uh, like a hockey stick accelerant of, of what's happening there. And so what we're primarily seeing is that a lot of customers and a lot of companies are trying to find value in automating those repetitive tasks that they're doing on a regular basis in a, with, with AI that is auditable, transparent, and understandable, so that they don't necessarily have to go, well, we sent it into a black box and some other stuff came out on the other end, and they, and then they don't know what happened and where it went.
So, uh, we're seeing that that actually really transform. It's, we're talking about about an 85% reduction in manual things like reading email boxes and responding to supplier inquiries or responding to customer inquiries where you have to go in and, and grab a copy of a bill or a copy of an invoice and send it back to somebody. So that's a significant ROI where, where companies can choose to say, okay, we wanna realize actualized cost savings, or in many cases what we're seeing is they're saying, we wanna take those people from a, a menial non-value add task to strategic level tasks that such as supplier relationship management, such as chasing discounts on, on payments.
The other area that we're seeing a significant amount of value is, is companies being able to reduce their day sales outstanding, their DSO, which really is a, it, it's a, it's a key way for them to be able to put their money back in their pockets instead of having their money in their customer's pockets. And so it's a, it's a great opportunity. So when you talk about, you know, the, the ch biggest challenge with ai, especially in the office of the CFO, has been, how do I actually see ROI, these are some areas that our customers are seeing some, some very significant ROI in those spaces.
Mm-hmm. I think one of the issues that I keep hearing a lot about is the process matters and what you're using AI for, especially with Gen ai, and are people starting to understand that, you know, the more deterministic that process is, the more challenging it becomes to apply AI to it. It's not impossible, but there's a lot more work because, well, deterministic means, you know, it's gonna be done the same way every time, and AI never does the same thing the same way twice.
Yeah, no, it's a great question. And I think that's where, when you, when you think about your processes, and, and this is actually why I think controllership becomes the, the forefront of opportunities is because in many cases there, they're processes that are driven by some pretty standardized processes at, at organizations. So they have rules about how they process invoices, they have rules about how they send out bills, how they do dunning processes.
And so the, because there's some clear rules and regulations within those companies, they provide really fertile soil for automation. And so when you talk about how to apply AI in that space, that's where, especially when you see some of the companies, when they try and kind of go it alone and figure it out, they get into a little bit of trouble because you can't just claw or chat GPT up some automation in your, in your finance space. Because while those are great models, they do a lot of things and everybody uses 'em probably daily at this point.
They're not gonna be specific to the office of the CFO. And so what, what we do is we'll bring in our specialized reasoning model, which is a, a specially trained small language model to sit on top of the large language models, which help it do from doing what you're talking about, right? So it's not just a, I come up with a new rule, I come up with a new thing every time because it's kind of generating on the fly.
This is where it really helps them dial in those processes and repeat them in, in that fashion. And so that's where they're able to see it. And I think that's, that's where, you know, when, when we do these with, and when I work with customers to kind of align their, their processes, that's a big part of it.
They need to make sure that they have a good sense of what data looks like for their organization. They need to make sure they have good processes. Where does the data reside?
What are the flows? Where do we go? And what do I really want my people to be doing, uh, going forward?
And so that, that really helps avoid the, the AI churn in the office of the CFO. And I think that's, that's where a lot of, a lot of finance teams are starting to see some value. Mm-hmm.
Um, early on, everybody was talking about how AI would, you know, replace people and everything would be highly automated. I think maybe as we've gotten into it and understand some of the limitations is, is that vibe a a little less out there these days and people are more realistic about what, what the benefits are? I think, so we we're strong believers in the, in the concept of human in the loop ai.
And, and that's really that AI is not just gonna turn on and it's not a fire and forget type of type of activity. It's really an opportunity for them to turn it on. And, and they get to be the strategic storytellers with it.
They get to be essentially the supervisors of these new digital coworkers, these agents that are now working alongside them. And, and so the, the humans, you know, are, are upskilling to not necessarily be the ones to process an invoice, for example. They're letting the AI process the invoice, work on the coding, get everything teed up to move into their ERP systems, and then the humans are reviewing that work.
Essentially. They've now become the supervisors of these digital coworkers, kind of a junior accountant, if you will, that's now on their team. And so they get to then say, yes, that's great.
Go ahead and write that into our system. And so it's not eliminating the humans, it's reducing a lot of manual time. And so I think there's a luxury that, that folks in finance now have to, to really think about it.
It, and then they've never had this luxury before. It's, what would I do if I had some extra time? And, and, and it's, they've always been buried underneath paperwork, buried underneath emails.
And so now because they have this opportunity to let the digital coworkers kind of go and do a lot of processing at, at high speed, they now get to think about what's next and, and what other value can we provide for our organization. Many of these of these groups are, are running a shared services function, they're responsible to the organization. And so now they get to talk about insights and data storytelling and analytics, whereas before they were just kind of treading water to keep up with the, the pace of, of the transactions that they were trying to make.
So moving, you know, it, it sounds kind of cliche, but from transactional to transformational is really kind of where we want to get them. What is their reaction from people that you've talked to about this? 'cause on the one hand, man, I'm not a finance person, and I look over there and sometimes to me I see a lot of what I would call, you know, mind numbing, soul crushing work, but then there are other people who love that stuff.
So, you know, they're kind of heavily into it. Um, when they look at ai, what do you hear from those folks? Yeah, no, and you know, there was a saying, um, actually a colleague of ours uses all the time.
He goes, you know, finance people aren't boring people. We just like boring stuff. And, and so, because they kind of like the boring stuff, uh, it's interesting because the finance folks have a really analytical mind.
And so they, they really want to dig in and figure out how AI works. And, and so I think for them, in some instances it's kind of a new challenge, right? It's kind of a new, the new crossword puzzle or a new thing for them to kind of figure out how this thing is working for them.
So there was definitely some initial trepidation. And I think especially to, to your earlier point, they were worried about things not being exact. Now in many cases, you have senior level finance folks that say, look, get it within 5%.
I don't need everything to be exact. I need everything to be directionally correct, mostly complete, mostly accurate. But most of those senior leaders weren't demanding 100% every single time.
And so, but the people wanted to produce it at a hundred percent. And so I think when you talked about the early stages of AI and how they were adopting it, that was a big concern for them is, is it's not 100% accurate, or they couldn't, they couldn't prove that it was 100% accurate. Now, over time, they've seen the results of it and they realize that, oh yeah, this is, this is processing what I'm asking to do.
It's, it's moving forward. It is not a silver bullet though. That that's, it is one of the big misconceptions that I think folks had initially of AI is that it was gonna come in and do everything for me.
Like CFOs will be able to kind of kick back in the nice leather chair and go, uh, tell me about this, or do something about that, or, what happens if this, and, and while it does great at pulling data together, it it's getting better at, at being able to pul data together, put those analytics together. And I think really the next over the horizon a little bit, but not too far out of the way, uh, not too far out there, is what we're gonna talk about in terms of causal ai, which is actually AI that's gonna help understand the root cause analysis of something. So really, when they're getting down to the root cause of why did my numbers go up by 10%, that causal AI is gonna be able to kind of do some of that recursive searching back through the data, understand what are some of the, maybe some, some micro things that happened at my company as well as macroeconomic things that may have happened writ large, and then be able to deliver those insights.
And, and I don't think we're too far away from that. We're not there yet. But again, it's not a, it's not a bullet magic bullet.
So it's, it's kind of an opportunity to, to understand what can AI do. And so the finance teams are kind of now, now gelling around that fact and saying, okay, it's really great at information extraction out of documents. It's really great at automating some of these rote tasks.
But again, it's, it's not magic. And, and so, you know, there now at the rate of change of technology and the rate of change of how people are, are developing this, uh, there's probably some stuff we're not even envisioning today that a year from now might look like magic to us today that's gonna be, uh, really impactful for the office of the CFO. So we're getting a little more agile than we used to be in the finance space.
'cause we were pretty, you know, you could take excel when you pry outta my cold dead hands type of thing. Right. You know, Excel just turned 40 this year, and I think many of the folks that work in finance were there from the beginning.
And, and so it's, it's really, uh, you know, it's a unique opportunity to see this, this, this back office function that, um, while, while it's rife with data and, and has all of the other information that's great for automating, uh, we're kind of, they weren't the ones that were getting all the shine, but now they're really able to to accelerate forward. Well explain that a little bit, if you don't mind, because there is generative and there's causal and there's predictive ai and all these things are a spectrum of tools that we'll be using, right? That's right.
And, and I think, you know, most of the finance teams, I, I by and large are, are generally staying away from generative ai. Uh, because again, they, you know, you worry about model hallucination or something else where, uh, or to your point to your question earlier, it's coming up with a different answer every single time. And that's not what I want.
I want something that's, you kind of, you know, taking a consistent approach. And so some of that, that predictive ai that that's looking at information helping to make insights and drive and driving that forward, um, that's, I think where people are gonna really wanna be. I think, you know, Gartner's Gartner did some research and they had said that causal AI is probably only impacting maybe two to 3% of companies today.
And that's really at a very nascent, almost an infancy stage at this point. And so I think that'll, that'll start to grow over time. They, they envision it's gonna be a huge impact to, to teams, but it's just, we're just not there yet.
What I think is, what I think is, is going to be the, the, the next wave that's really gonna impact the finance teams is the ability to pull data together better than we are today. So instead of having to go build a bunch of reports in your ERP or in a data lake, or however you've set it up within your organizations, they're gonna be able to use AI to basically go grab information out of their data stores and then provide those analytics using natural language processing. So being able to start having those conversations of, you know, create a report for me that's telling me about my sales over the last three quarters, lay it up against this type of information and, and AI is gonna start to be able to do that for you.
So there's some players in that space that are starting to get there. We're one of them, uh, with our smart research tool that, that I think is gonna be an opportunity for, for, you know, the finance teams to really start moving forward in that space, which starts to pick up other parts of finance, right? We talked about, you know, the office of the controllership, but this is areas where, uh, your FP and a teams, your GL teams, your financial reporting teams are, are gonna start to see oppor more opportunities for them to take advantage of AI in their space without having to kind of build everything from the ground up.
Because in many cases, for, for those teams to see a lot of value, they're having to create large data repositories and then stack analytics on top of it today. But I think there, there are tools that are gonna start coming out to help them do that in a much more rapid pa rapid pace than they can today. Mm-hmm.
Um, they say that, you know, the thing about AI is that the AI we have today is the worst we're ever gonna have. So as you look into 2026, what are you looking forward to? What do you think's gonna happen?
Yeah, I mean, if, if, if the worst that we have today is something that could automate 75 to 80% of my manual tasks, um, I would say I'll take it. But at the same time, I think, I think so. So the causal ai, I'm excited to see that.
Are we gonna see it in 26? I, I hope so. Um, I think that would be great to, to have those opportunities.
I think other opportunities to continue to refine language models to be more trained for finance is gonna be key for people to see that value. So not trying to go with some, you know, giant LLM to, to use against that data, but really starting to find those, those specialized models, which of course means you have to find specialized data to go train them on. And, and so I think, I think that's where we're gonna see a lot of value is, is those smaller models, those reasoning models, helping them move forward in that space because it just understands finance, uh, better than just, you know, pulling up my chat GPT on my phone and saying, Hey, tell me about my, you know, DSO.
And it's like, I have no idea what you're talking about. You know, it can define it for me, but it has no idea how to go grab my data. So I think that's gonna be the big piece, is being able to take those tools and apply them more directly into the finance space.
So it almost seems to me, and I think we're kind of trying to figure this out, is, are people just gonna consume this using some sort of AI agent that's built into the software? Are they actually gonna go to the trouble of building their own AI agents that are unique for their business? Yeah, And it's a great question.
And there's a lot of companies that are kind of going through that build by, uh, conversation today. There, there are a lot of great commercially available tools that are out there that can help them accelerate and see time to value today. And so I think when you have customers and, and, and companies who are, are really struggling really underneath it today, that, or, or they're under a mandate, you know, the, the CEO, the CFO, somebody says, the CTO says we need to do AI now.
And so in some instances, they may not have the luxury of time to truly figure out how to line everything up internally to go kind of build it. Um, I get to building a second, but I think, you know, there, it's, it's actually never been easier to build your own agents, uh, within your ecosystem. So I think, but I think a lot of those companies, because they're under a time crunch, they're under a huge amount of pressure to actually just do their d do their day-to-day job.
I think many of them are, are pursuing kind of commercial solutions that are out there to move forward. As far as the building goes, you know, all of the ERP systems are starting to create essentially the opportunities to build agents within their ecosystems. A number of organizations, and we're one of them.
We will use Claude internally to build smaller agents to kind of help us manage work to, to help with project workflow. Um, you know, you look at Microsoft copilot in organizations, I know a couple of our customers that have, that have figured out ways to some kind of nifty ways to use Microsoft copilot to build some agents internally. And so I think what we were thinking about and maybe three years ago in terms of a citizen data scientist, I think that's almost been overcome by this concept of kind of almost like a citizen agent builder, if you will.
Um, I, you know, I'm sure somebody has a better name for it than that, but it, it, it's essentially, you know, these people are kind of going, alright, what if I could do X? And they're basically just kind of going and figuring it out. They, they're not experts in the data, but they're using the tools that exist within their ecosystems to kind of go build it.
And so I do think you're gonna see a proliferation of agents both commercially available as well as self-built, um, really, really over the next kind of year, year and a half. I, I think, and, and I talked to this about our customers because when they talk about where we're at in this space and really this transformative, you know, changes over the past number of years, I, I tell them, I said, we are the last generation that will hire exclusively humans into our organizations. At this point.
You're hiring humans and digital coworkers and, and that's not going to change. We're gonna continue to move forward in that space. And so, uh, I think the future is gonna be a hybrid workforce and it's gonna look that way.
Uh, we, you know, five years ago during the pandemic, we talked about a hybrid workforce as a, some people working from home, some people in the office. I think in this case, we're now talking about who's actually doing the work. And in this case, it'll be both hybrid, uh, human and, and digital agent.
All right, folks, you heard it here. The finance teams are gonna be at the forefront of this transition. There's no doubt about it.
And we're all gonna watch and see what happens. 'cause hopefully we're gonna learn from their adventures. Hey Mike, thanks for being on the show.
I appreciate it, Mike. Thanks for having me. And thank you all for watching the latest episode of the Techstrong AI Leadership Insight series.
You find this episode and others on our website, we invite you to check all those out. Until then, we'll see you next time. Hey, everyone, we're back here with our day three last day coverage of, uh, our time at AWS reinvent.
Uh, this guy's no stranger to our tech strong audience. He's always either on a webinar showing him how to use Kubernetes, trying to make Kubernetes easy. Some say that's an impossible dream.
Um, or on Techstrong TV talking cloud native and KU with me, he's my friend Andy Suman of Fairwinds. Andy, it's great to see you. Good to see you.
Thanks for having me. You know, for people who haven't caught you before on either tech drunk TV or any of the webinars, give 'em a little bit of your background. Yeah, Sure.
So I'm a longtime infrastructure guy. I've spent, well, my entire career working in infrastructure. I spent the last nine years working exclusively with Kubernetes.
Uh, now I'm the CTO at Fairwinds, and we help people run Kubernetes. We try to make it easy, like you said, And like I said, in some cases it could be a bit of an impossible task. But, you know, it's, it's funny, Andy, we, you know, we're, we're sponsored by suor.
Uh, you're pseudo man. We're sponsored by SUSE here at, it's the last day. I'm getting a little punchy.
It's, it's a long, Uh, You know, we're sponsored by suse at, at, at here at AWS reinvent, and we've been spending a lot of time talking to the, uh, rancher guys about multi cluster Gotcha. Kubernetes management. I'm sure that's something that's near and dear to you.
Yeah, I mean, we manage quite a few clusters for all of our customers. We've familiar with rancher, lots of, um, lots of multi cluster stuff. I think, you know, the one question we all have to ask is, um, where's the data live, right?
Yeah. Everybody would say like, we wanna go multi-region, we wanna go multi cluster. And I say, that's great.
Where's your data gonna live? Because that's the thing that's harder to move between clusters. I, I agree with you, and especially in a world of data sovereignty and, and all of those things that you're dealing with, right?
Absolutely. But you know, what I found, and, and maybe, and I might be wrong 'cause I'm not the expert you are, but a lot of time multi cluster Kubernetes happens quite by accident, right? You're, you're doing a Kubernetes project over here and you spin up a cluster.
I'm, we're in the same company, we just don't talk. Yeah. I spin one up over here.
Jill spins one up there, Bob and Harry over there, and before you know it, damn, we got four Kubernetes clusters we're managing, but they're all kind standalone, but you know, okay, now we gotta get efficient and we wanna bring 'em together. Yep. So I I call that like the accidental multiple Kubernetes cluster.
Yeah. We have a name for it. Uh, our sales team knows this term.
It's cluster proliferation problem. Uh, CPP. Yeah.
Yeah. So, okay. We run into a lot of folks that have that, mostly large companies, lots of teams, different business units.
They end up with a vast number of clusters. The cost gets outta control. Um, and usually when we work with those folks, we work with them to consolidate into a platform.
And so their end goal is let's get down to a manageable number of clusters managed by us at Fairwinds, hopefully, um, and build a platform on top of that so that all of these developers aren't managing all of their own clusters. And the goal is let's make it easy for them while also getting control and governance and policy in place. Um, it's a lofty goal, but, uh, it's can be very successful for folks.
Absolutely. Wow. Um, you know what, this was a good way though of introducing what Fairwinds does.
And, and that You took me right up. I I did not even realizing it, but, but that is the kind of the, the bread and butter of Fairwinds, right? You've got people who have these, uh, proliferating clusters Yep.
And you have people who are saying, Hey, I wanna modernize and move over, you know, from to a mar, you know, maybe I'm going from VMware and I'm, I'm moving to another virtualized environment, but I want to go cloud native. Yep. You know, I want to go to a microservices architecture.
Yeah, yeah. Any architecture really, but yeah, microservices one, one way. Um, I had something I was gonna say and I lost It.
It's okay. We're live, so we just gotta keep rolling. So I'm gonna come up with something here for you then.
Um, you know, I just recorded or played our shim, my shimmy says that I do every week, a little 10 minute video on LinkedIn and X. But one of the, the, the theme of this week was, Hey man, DevOps cloud native and platform engineering are alive and well here at AWS reinvent. And, and my thought was, you know, when I first got out here, I was just like, bowled over with all the agentic AI announcements.
It seemed like all AI all the time, right? Yeah. And, um, but in talking to people and having conversations, you know, I'm hearing, well, one of the agen AI agents, Amazon came outwards with the DevOps, they're calling it a DevOps agent.
Mm-hmm. I don't know if I'd call it a DevOps agent just yet, but, but they have plans. They have big plans for it.
Yeah. But hearing a lot about DevOps, a lot about cloud native, right? Cloud native is the choice.
If you're looking for transformation modernization, you wanna move maybe from on-prem to the cloud. Not all the way you wanna do a hybrid, you want to, you know, um, cloud native has had a strong showing here at the show. Absolutely.
And, and platform engineering is no longer a fad or a niche. It's, it, I think it's taken its place alongside the other two in, Hey, this, this is how we build software. Yeah.
How we run software. Absolutely. Absolutely.
You know, I, I think at Cube Gun we talked about, we've launched a product to help people build those internal platforms, and it's entirely based on cloud native software. Yeah. Because we really believe that is the future of platform and where it's going.
And I think we could see it from Amazon as well with the announcement of the managed AR OCD and Crow Yeah. Act or a CK, um, you know, they're doubling down on Cloud native as well. And so it's not going anywhere.
It's here to stay. And it will be, you know, the future of platform and DevOps engineering as we as we know it. You know, thinking back to the rancher announcement, what you just said is, is managed cloud native, the future, I mean, you guys manage for your clients, but you are also, you could come in, set 'em up and parachute back out, right?
Yeah, absolutely. Um, now, I, I had had a similar experience in the cyber. We didn't call it cyber the InfoSec space when I was there, which was after about 15 years, 10, 12 years, I realized that most organizations just weren't capable of managing their own security.
It was, they didn't have the, they didn't have the budget, they didn't have the expertise. And quite frankly, they didn't have the stomach for it. Uh, are we at the same place in Cloud native?
I think so. With the larger companies, that's absolutely true. You know, a lot of our customers, it's, it's one of one or two of those three things.
It's either they don't have the time or the budget or the people that all generally rolls back to budget or they could do it, but they don't want to because they'd rather focus on business impacting things. And that's what we enable is, you know, let us do the things that you don't have the stomach for or don't care about, or don't have the time for, uh, and you can focus on your business. Right.
You've always had that philosophy of, you know, outsource what isn't your core competency. Yeah. I learned, I also learned that the hard way, the dot coms I had helped start a company that wound up going public.
Uh, we were what they call an A SP application search. So there's no cloud, there's no like t three lines of your in the guts meow internet. I remember this.
And, um, we're, we're offering hosted Lotus Notes, Oracle, PeopleSoft. And, and the lesson we learned is if it's not core and critical, those are the two things, right? Yeah.
So I'm thinking be core to your, to your DNA, in your case, Kubernetes expertise, cloud native expertise or critical, your business can't run without it. You don't give up things that are core and critical. Right.
If it's core or critical, you might give it up. Right? If it's not core or critical, you absolutely should give it up.
Yeah, absolutely. Right? Because otherwise you're just wasting money.
Yeah. And I think for a lot of companies, the, the intricacies of managing a cloud native environment, managing any IT environment, if you're not an IT company, you know, it, it's hard. But Cloud native in particular, because, you know, Kubernetes really never came with a chimey uneasy kinda of button.
No. No. Batteries were never included.
No batteries. Security was never included. There included.
No. Uh, crazy defaults was never included. So what, what kind of, uh, you, you guys have a presence on the floor and everything.
Yep. Yep. What, what kind of, what are you hearing from people?
You know, one of the biggest surprises to me, um, this is the first time we've had a booth at Reinvent. Mm-hmm. Um, and uh, in the past it's always been, you know, I always just kind of assumed that we'd get about 10, 15% of people using Kubernetes.
That has changed. Um, in, at, oh, LY show is 85, 90% of people really, You think it's that high that I talked to are using Kubernetes. And maybe that's 'cause they're stopping by a booth that says Kubernetes on it.
But, uh, go figure. But I'm talking to so many more people that are using Kubernetes or planning to move to it from some other container orchestration or something like that. So it's a huge number.
Uh, it's, it's good to see That is that is, you know, I, so now you got me curious. I'm gonna have to ask everyone I talk to. 85 sounds really high.
Yeah. Uh, like I said, confirmation bias on my part. Yeah, no, But you know, the big picture number I always am told is that about 15% of payloads on the cloud are cloud native.
Hmm. Now a lot of that is because it's legacy stuff, right? Yeah.
Yeah. I'm sure there's quite a lot still that, you know, people aren't talking about. Um, and it's also that, you know, I've said this in the past is that they're probably using Kubernetes, the company is, but what percentage of their workloads Are running are running it.
That's a smaller number. You're right. Absolutely.
That's a, that's a real distinction. Yeah. Because I think what it is is Greenfield products very well may be 85% cou.
Yeah, absolutely. I think so. Brownfield, again, people may not have the stomach to do that transformation.
Right. Or the need, I mean Right. Don't break what's not, If it's not broken, don't fix it.
Yeah. Don't fix what's not broken. Yeah, exactly.
Absolutely. Um, So this was your, I didn't realize this, this was fair. When's first time exhibiting here?
Yeah. Yeah. Coming back next year Probably.
Yeah. Yeah. Worth it.
Good. Good conversations. Good customers.
Yep. Yeah. Good show for you.
All The right people are here. Yep. Really good, good conversations.
And, you know, the parties are fun too. The par, you know. Yeah.
We did a, uh, a thing at the Sphere last night with you. A wizard of ours was pretty cool. That's cool.
Yep. Um, wanted to talk to you a little bit about forget, uh, AWS for a second. Fairwinds.
Yeah. Anything new coming down the pike you want to share? Um, nothing that we didn't talk about at cube com, but I'd love to share, you know, our new product to IDP Quick start.
So we are, I talked about a little bit a minute ago, but we are putting together with AWS, um, they've built an appm mod blueprints repository that helps you build a platform from open source. Uh, they did a couple of sessions on it this week, A couple of workshops. Yeah.
We're gonna be running another one with them, uh, next week, I believe. com if anybody's looking. Um, and we will show you the, the product that we're going to be building, which is get you started with a platform faster than you could probably build it yourself.
'cause the biggest problem with platforms is that people spend two, three years building a platform because it's such a complex task. And so AWS and Us together have made that much simpler, uh, kind of prepackaged it up for you, and then we can customize it to your business needs and then you can build on top of that to, to serve your developers. So, I love it.
Yeah. Anything else you wanna share? No, it's alright.
Come to reinvent. It's a long week. It's fun.
It is A long week, but I, uh, it's worth it. You're heading home today? Tomorrow.
Tomorrow. Good for you. Yeah, me too.
Yeah. All right. Hey, you know what?
We didn't mention Fairwinds website. com. There you go.
Andy. It's always good to see you, man. I don't know when I, well, I'm not doing you, you guys don't do co con in Europe, do you?
Uh, we will sometimes we'll have a person there, but we won't have a booth. No, I'm actually, I'm not. Mike ards gonna cover Q Conn.
You're at first. It's the same week as the RSA conference. Oh.
So I'm out in San Francisco that week. Gotcha. But we'll talk and you guys are always on with your webinars and everything else around.
We'll do something. All right. It sounds good.
Hey, We're live. We're at AWS reinvent on day three. We still got some great content coming up for you.
Great interviews. Stay tuned. Hey everyone.
Welcome back here to our Tech Drunk TV coverage of AWS Re Invent for 2025. I promised you two more analysts and here are two more analysts, both both of my colleagues with the Future Group. Let me introduce you quickly to them to the far right.
He's no stranger to you. If you watch Text Strong, it's my good friend Mitch Ashley and the man in the middle. Actually, you've been on a text Strong TV once before.
Yeah, I remember. But if you don't know Nick Patience, he is, Nick is our AI coverage specialist, but he's also, Nick is one of the founders, co-founders of the 4 5 1 group. If you follow the tech analyst scene, widely, widely respected.
Nick, it's great to have you here. Live with us. Great to be here, Mitch, as always.
You bet. Um, I didn't mean to embarrass you, but did I leave anything out that you wanted to mention about yourself? My Lifetime's a accomplishment.
No, that's good. Stay right. You.
That's a good salesperson. Stop it. Yes.
Mitch, what about you? Just in terms of coverage, you know, I do kinda all things software development, um, AI agent development. Nick and I collaborate on the AI side of it.
I collaborate with, with Brad and, uh, Fernando and respective areas. So it's, it's a good team here at fu. Absolutely.
So guys, let's d dive in. It was an exciting day. A lot of announcements in that keynote.
Um, you must be happy 'cause every it was ai, all AI all the time. It seemed for a lot. Everything is every, every con, every conference is so yeah, it's good.
So I'm not, you know, let's say I've been around the block more than was Mitchell once taught me a saying from Nebraska. I may have been born that night, but it wasn't last night. Right.
But it wasn't last night I learned all these Midwest Nebraska sayings from maybe well enough to turn up. We didn't have those sayings in New York, but Mitch, but Nick, how much of this is PR announcements that shows, and how much of it is rubber meeting the road? Well, I guess for these guys, for AWS they used to, um, leave everything to reinvent.
So everything to this, this, you know, time straight after Thanksgiving. And they, they realized, um, yeah, the world doesn't work like that anymore. Um, so yeah, I think they, they had some really interesting stuff, uh, but it wasn't, yeah, sometimes some of the years you come here and it's completely like every, just, there's a list and it's so, so, so long.
I think it, I think it's, you know, the stuff is, the stuff is real. I think you, you probably already talked about it, I'm not sure what you talked about, but, you know, the Nova Forge thing Yes. I think is really interesting.
That's a kind of the Yeah. Sort of industrialization of the AI process. And I, I know perhaps digging into that, um, pretty deeply.
Um, but I think that that's a really, um, interesting thing. It's not to say you couldn't do that with any other provider, um, but it's more like they wrap it up as a service and make it easier. Um, then I think it is a, you know, I think that that is a, um, yeah, it's real.
I mean, there's stuff, yeah, most of the stuff is real. Um, I mean, some of it's in public preview, so it's very, very early. Um, but I, but I think, you know, AWS has, um, is having to work hard.
It's obviously the dominant cloud provider, but it's having to work hard to reestablish its AI credentials somewhat. Um, you know, I've had many discussions with, with the company about that, you know, with the current thinking obviously is of the three hyperscalers, that that kind of Google has an edge. Um, but AWS has a market share and have, you know, hundreds of thousands of SageMaker customers and things like that.
So they're not exactly, um, you know, flailing away not knowing what's going on. Yeah. Um, and, but, but I think, you know, the, the, you know, the models, um, the Nova Forge stuff, the chips, um, it's like, like all the hyperscalers, it's, it's, it's the ability these days for them to have everything from, from the chips to the applications and, and all bits.
No, It's a vertical integration for sure. We used to call it back in the day KET suits, right? Mm-hmm.
Yeah. Where you had that whole family. But how much of this, I wonder is AWS pivoting to AI in a big way, because maybe they were a little bit, or at least perceived to be a little bit behind Google and Microsoft, right?
Even in the Futurum signal report, they weren't in the top two. Mm-hmm. Not, not that the Futurum signal is the source, but it's a source.
Yes. It it is. It's Yes, it is, it is a definitive source.
Good Source. And, and they weren't in the top two. No, they weren't.
And, and look, Google does have an inherent advant advantage here. They do have that true vertical integration up and down the, the, the stack. Um, is, is, is that maybe at play here?
Yeah, I think so. West feel like they had to play a little catch. Yeah.
And that's, that's an uncomfortable situation for them. They're the 800 pound gorilla. Yeah, I think so.
I mean, the reason we put them in that situation, you know, there's many reasons. I'm not gonna go through all of 'em, but there's many reasons. But I mean, when you, you look at the, you know, Google invented transformers, you know, and, and so, you know, they, they kind of were there at the beginning of, of, of the, of this whole thing.
And then many other things that are going on. It has been a bit of a, you know, a race to the, um, you know, the, who's got the best model thing and that's, you know, who's got the best model today. And there'll be somebody along tomorrow with a, who, a newer one.
And until really reinvent last year, Amazon, yeah. AWS really wasn't playing in that, um, in that, in that, that way at all. They announced Nova a year ago.
Um, and now we've got the, the new ones, which I think you've already, you've already talked about. Um, that's not the only measure though of, of success in ai. Um, you know, certainly from the end user point of view, it's not, it's just 'cause it's, it's a lot of it is kind of f and confusion and say the, you know, today's benchmarks are, you know, are old hat by tomorrow.
But I think it's, yes, they are, they are. Um, they weren't as prominent in that, that kind of model race. Um, that may end up being a good thing for them, I dunno.
Um, in terms of, um, you know, had the resources you have to spend to, to get, you know, to the top of that, that that tree, um, and then obviously Microsoft was kind of outsourcing everything to open AI and now is obviously playing a more pragmatic game. Um, so it's, it's kind of, you know, they're right up there because of open their open AI relationship, which gradually is gonna be get diluted both from a kind of financial point of view, but also, um, from a kind of, you know, product, you know, development point of view as they can hedge their bets, um, with, with other model companies. So I think it's, it's, um, it's certainly, I don't really believe it's a race that only one company.
It's not a zero sum game. No. You know, not one company's gonna win and every else, you know, loses.
Um, and you know, maybe in a year's time we'll be thinking back and saying, you know, look at AWS they've caught up. You know, because I think there's the user, their customer base is so vast. Um, No, they still have, look, they still have a lot of cards Yeah.
That are worth playing. Let me posit something else at you, Nick. Tremendous amount of attention on the train and processors.
And this follows, I think it was last week or the week before Google's announcement a around, uh, chips. Is this the, the signal that we're moving, that the real action is moving from GPUs to other kinds of chips from, so in other words, from training to inference, I'm not taking up any collections or playing any death nails for Nvidia. Mind you, but are we moving towards, not towards but a more multipolar world where GPU isn't the only chip we need?
Yeah. We use for ai. I mean, organizations have wanted silicon diversity for, for, for years.
And they haven't got it at the moment. I think it's baby steps, you know, very, very, very, very baby steps. This is, you know, it's this, uh, Nvidia has, you know, it's, you know, dominant market share and we will do for quite a long time to come.
Um, and will it eventually slip, slip from 90% to 85% to 80%? Yes, it probably will. And that's got as much to do with a MD as it has got to do with AWS and Google.
But I think, yeah, the tra stuff was interesting. It was completely predictable. 'cause they said they were gonna do it last year and they did it, so that's good.
Uh, they train two last year, train three this year, and now they're talking about training four. Um, Six X is powerful. It's three.
Yeah. And then you have these kind of train, um, the ultra service things, which is kind of, it's the sovereignty play. It's like, you know, you get out our chips plus, you know, all the, all the interconnects and everything else and in, in the stack and, and shove it in your data center.
And I think that's, um, something they had not really talked about much. They've had outposts for years and it went through a period of time, um, in 24 and in early 25 of like ignoring the fact that on premises matter at all. And yeah, the old ad adage, once you move everything to the cloud, X, y, Z will happen.
Well people don't move everything to the cloud. So that, that's, I thought that was really interesting as well. Yeah.
Um, and I think, yeah, I think that is a, um, you're gonna hear more sovereignty stuff from, from AWS um, in, you know, new Year as well. And that's, and that's gone from being, uh, an, you know, as a lot of, uh, people in the US thinking of obsession of Germany and France and countries like that to more or less every single country in the world. Um, so no, You know what, so our, our whole presence here is sponsored by our friends at suse.
Alright. And, you know, they've gone into digital sovereignty in a big way. They've actually started a whole division around it.
Now granted, they are a Luxembourg, European based company. And, and so maybe that feeds into the narrative you're talking about. Mm-hmm.
But I'll go one better. I think we may see a world in the US where you have state to state sovereignty issues. Right.
I'm a, I'm a, for lack of a better word, a blue state versus a red state. And I don't want abortion data available to the red state. Right.
And just so I, I want to know if it's hosted in my state, and I want to make sure they can get their heads on this pretty close. Yeah. Right.
So when we talk about data sovereignty, it's not just a nation state thing, it's a, it's, it's a territory to territory thing. It's, it's a big, it's a big issue that's gonna get bigger. Mm.
Nick walked around today, you had a lot of meetings, spoke to a lot of people. What, what surprised you? Um, what surprised me?
Um, that's a difficult question to answer off the top of my head. Um, I guess, I guess, yeah, the few people I've I've spoken to so far, the, uh, the show floor can be a bit intimidating. Um, yeah, I think, I think it, I think it is the, you know, the, the progress of the Gentech stuff, uh, which may be, you know, people want to say they're further along than they actually are, because yeah, we're incredibly early as we, that's, that itself has become a bit of a cliche saying we are incredibly early.
Um, but it's, I think, yeah, I think some of that, the, um, the claimed, um, progress in that is, uh, somewhat surprising, probably, therefore maybe not entirely true. Um, so, so that's a, that might be a bit of a, it's sort, sort of a surprise, sort of, It's a very UK proper way of saying, I, I don't believe it. Yeah.
Yeah. We're a very, very polite nation. Um, but it's, but yeah, I think, I think it's, yeah, I think that's, that's, that's probably the case, I guess.
I mean, from the AWS point of view, I think the, I think the kind of, um, the sovereignty stuff we were just talking about, I think, yeah, the amount of emphasis I've, I've seen on that and heard from them on that was, um, you know, was probably a bit higher than I thought it was gonna be. Yeah. I, I don't disagree there, Nick.
I know you have to run out to another appointment. That's why I wanted to focus on you earlier without our going to Mitchell. Um, you recently, I think the, the, uh, the signal report that you had done on AI had come out.
Um, where can people keep up with what your, I mean, not just the signal reports, but you, you're constantly putting out Yeah. com. That's where, that's where all, all our stuff goes, um, you know, on the socials at, on on, on Twitter X ethnic patients, but not very often, um, on LinkedIn more often.
Yeah. Um, but yeah, the signal stuff is available, um, for everybody to, to look at. And so that was the first one of, of the AI platforms, and I think we had nine vendors in the, in the signal.
Um, and obviously of which AWS was, was certainly one. And there will be, there will be others along in Q1, Q2 of, of, of next year. I'm sure I'm not gonna commit to a specific date, but the, you know, there's more, it's been a really interesting exercise and, and we've had some sort of validation that the way we've done it and the how we quickly we can turn these around, um, and get results, which, um, actually make sense and resonate in the market, I think has been really encouraging.
Absolutely. Nick, I'm gonna let you go. Cool.
Thank you so much. Thanks, Nick. Patience.
Check him out. Another one of the great future room analyst. We're gonna take just a quick three second break as we unhook Nick from his tether here on the microphone, and I'll continue our conversation with Mitchell.
You're watching Text Drunk tv. Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it.
com, the Security Boulevard, YouTube channel, tech Strong tv, and all of your favorite podcast platforms. Before we jump into today's topic, let's meet the panel starting with Alan. Alan, it's good to see you again, Tom, it's nice to see you.
I've, I've been, I've been on the road a lot. It's conference season, so happy to be here in the office and able to jump on today. Well, we're very happy to have you.
And, uh, joining us is also someone who's been on the road quite a bit recently. Uh, Mitch, it's good to see you again as well. I'm back in Guitar Central where I belong.
Exactly. You know what? I think I like your decor better than the hotel rooms in Las Vegas.
Uh, you definitely have an eye for, uh, you know, things that are interesting. I'm in, I'm in my, my, my man cave, and I got my stuff around me. Oh, well, that's awesome.
I, of course, am in the formalist void of my office because let's be fair, you guys are more interesting than me. But let's jump into today's topic because it is something that's actually very interesting. And I think that, you know, Mitch, uh, you highlighted something I think that we all should be keeping an eye on.
We've been talking about age agentic AI a lot recently. We've had several episodes about it here. We've been covering it a lot of other areas, but of course, you know, the s and AG agentic stands for security.
So one of the things we've gotta figure out is how are we going to secure ag agentic ai? Now, before we even got started on this, we, we had to make sure that we were clear on this. We're not talking about using agents to do security on this episode.
That's an entirely different conversation to have. We wanna talk about how we're going to secure the agents themselves, because as we know, with all things related to ai, those particular pieces of code have a lot of access. And if something were to figure out a way to confuse them or jailbreak them, or potentially turn them against us, we could have a big problem on our hands.
Mitch, I'm gonna let you kinda lay things out since you brought this topic up. What is it about a genix security, meaning securing those agents that kind of has piqued your interest? Well, I, the, the main thing is that we have been seeing announcements from vendors, you know, the large vendors, the Microsofts and Googles, uh, GitHubs even, uh, and even folks that are kind of farther down the food chain around doing some different kinds of security with agents while they're rolling out agents.
And why that's notable to me. You know, Alan and I have been preaching the gospel of, uh, DevSecOps and shifting left or whatever, however, you get software secure and always questioning like, are we making progress? Are we ever gonna get there?
And of course, I think beginning of the year, I would say, we're in the hope mode. Well, we hope we do it right this time. Well appears that something.
I'm not saying we're, we're fixing everything, but there are a lot of products that are coming out for agent identity, security guardrails, um, control some oversight. There's even talk around behavior and compliance. Uh, a little bit of that coming out.
I mean, I've got a whole list of rash of vendor announcements. Again, none of this is complete solving all the problems, but I have to believe that in the interest of, we wanna be part of AI too, the security and other companies security part of these product companies are saying, we better get our act together now and start working on security of AI and agents. Let's get products out the door.
You know, Mitch, not to disagree with you, but I, I gotta disagree with you. I, I think right now, just like every other tech company out here, security executive security vendors are under tremendous amount of pressure from their board, their investors, the VCs, to say, what are you doing with ai? What's your AI story?
And for most of them, for most of them, what they're doing, what's their AI story, is how they're using ai, how they're using AI to be, to provide better security, to do better AppSec, to do better endpoint, to do better data. DLP or what cloud security or what have you, it's how do they use security? It's just a subset of these vendors who are gonna say, well, how do we defend, how do we secure an AI future?
And there's gonna be a lot of them whose lips move, but I think you gotta watch for the ones who, who are putting their hands in their pocket and, and coming out with it. I, I've seen a lot of talk about it, but it pal in comparison to the companies who are saying, we're gonna use AI to give you better security. And, and this is an old story.
Here's where you and I would, would differ. Yes. I think the, the market's very large for using AI for security, the market for wanting to get AI into production.
Meaning I want my agents to go into, go into production. Enterprises are not gonna let AI into production. They're gonna be super cautious because of the data issues that market is, you know, pick, pick a multiple that's much bigger than the security market using ai.
Both of 'em are important, but I think that's, I think the enterprise is what's driving. If you really want these deployed into production, you have to secure ai. Mitch, I appreciate your points of view.
When has that ever actually been the truth? I was waiting. Hey, don't do open was waiting, waiting.
Wait, wait. Lemme take you back on a little trip down memory lake. Let, let's go to 2000 award.
2002. We don't use open source in the enterprise. It's not secure.
Who, whose throat are we gonna choke? Everyone was using open source. We don't use wifi in the enterprise.
It's not secure. It's wide open as people, you and I were, as people are tossing the WAPs under their desk when their bosses work, work by, we don't use the cloud. It's insecure cloud.
The biggest inhibitor to cloud adoption is cloud security. As every developer and their mother whipped out a credit card and spun up instances. What makes you think this time's any different?
It's, it's not different in the, in what you're saying in that way. I agree with what you're saying. What's different is we see companies coming out with security solutions earlier in the maturation of AI and agents in the cycle.
That's I see, is different. And I'm, I'm not claiming any, uh, any clairvoyant that suddenly we're all gonna get religions and secure all of our ai. But I do think the market, everyone wanting it, it's happening in observability too.
You see companies like, okay, I want, uh, I want the observability of my agents. How do we Dynatrace, Datadog, new Relic be part of the Microsoft announcement, right? Um, for DevOps agent, the other companies that aren't AI companies that want to be part of the AI era are moving, some of them are moving in a fast mover way.
Not all of them. There's a lot that aren't. But so, so you are gonna have some security products for some of this ai.
Maybe we're gonna see some better security. Not, not, not the kind of, you know, who is the Eden was the Star Trek episode when they're all all headed to Eden. Mm-hmm.
You know, we're probably not gonna go there because that turned out not to be a good place anyway. Yeah. Well, if I remember correctly, the guy with the ears, so Tom, you get a sense, I, I think, uh, Mitch, you kind of stumbled across something that I think blends what Alan was saying.
The reason why I feel like people are moving a hundred miles an hour is not because there's any hesitancy on their part to implement ai. Like they know that there are risks associated with it, but the bigger risk is the board and the investors coming down from on high saying, you have to have a strategy. You have to adopt something.
You have to do something now, or we're gonna unseat you. We're gonna, would put somebody in that can do that. But the observability piece, I think is maybe kind of the, the trick to get this in here, because what's the one thing that they want to know above and beyond?
We have an AI strategy. They wanna see the data points proving that it's actually happening, right? How much, um, a gentech workload have you deployed?
How utilized are these agents? And maybe by selling this as an observability platform and saying, oh, well, you know, we can tell that we're using these agents in their max to 85% capacity or whatever. Oh, by the way, we can also see what workloads they're doing.
We can see if something jail breaks that we can see if things are, are doing behavioral stuff that they shouldn't. I feel like that's a way to back into the security conversation as kind of an afterthought that will also allow you to bring that up to the board in three more months when it becomes relevant. Oh, by the way, we, we prevented like all of the board, uh, members, uh, salaries from being leaked through an AI prompt injection attack.
Oh, I didn't know that that was possible. Well, good thing that I was thinking about this while you guys were worried about whether or not we had enough agents deployed. I think that's a very good point.
And especially if the vendor you're already using for observability or security or both are moving, uh, making moves to introduce those products. Now, I think you're in a better position. You, you know, again, experience leads me to say we will have security for agent AI when customers put their foot down and demand security for agent ai.
Yeah, for sure. Mm-hmm. But to Tom's point, when you've got the board and the C level, what's your AI story?
What's your AI story? How fast can we get this? How fast can we, we, can we lay some people off and replace them with ai?
Right? That kind of pressure doesn't bode d well, for, for it. But here's an interesting thing too, Mitch, ultimately, who's responsible for the security of the Syngen AI for these agents?
Is it the people designing the agents? Are we, in other words, are we gonna have a secure by design sort of standard for, uh, uh, agents, for AI agents? Or are we gonna see the rise of a, at first the cottage industry, hopefully growing into a, you know, big part of the, not a big part, but a, a significant industry of security companies or, you know, cyber companies that secure ag agent ais, maybe even robotic AI as well.
But, you know, so in other words, ultimately who's the, who's responsible here? Is it a security company that's solely focused on the security of your agents? Or is it the developers of the agents themselves who have security as part of their mission?
I think it's, at least right now, what we're seeing is the, the companies that are creating the platforms for agents to operate within. So the, uh, agent hq, Microsoft, the agent hub at, at, um, at GitHub, that what they're building in the framework for you here at AWS last week, Allen, about their A AWS security agent, their AWS DevOps agent, and coupled right in that announcement and is, and here's the vendors who are integrating with that agent so they can connect into it. So the framework of security and observability are starting to be put in place, at least in those cases.
Uh, um, it certainly isn't across the board. Will there be a, a whiz or a somebody that, you know, pops up as the agent security company or AI security company? Probably.
I think, we'll, we'll see some of those come up, but the other folks are not gonna miss out. They're, they're gonna go after this market and they, and some of 'em already are. So the framework ones sounded very much to me, like the early cloud security.
Remember we built it into the platform, right? We don't have to show you everything, but AWS was pretty good about giving a vendors a, a window in into the security of that foundation, if you'll, and, and I think that what we saw at AWS last week and what we've heard from Microsoft very much kind of fits that cloud security mm-hmm. Model where, Hey, we're responsible for the, for the platform and, and we're gonna partner with you.
We're gonna do some of that security, and then we're gonna make APIs or, or MCP servers or whatever available for you to supplement that with more. But I do think you're right. I think we're gonna have a category buster, like a wiz or, or, you know, in the last cycle that, and I don't know what Futurum or Gartner or whoever will name it, but it's gonna be a category of security companies that secure agentic ai, wherever it may be.
And, and there will be some winners there. Very much like we, I think on a much bigger scale, like we saw with microservices and Kubernetes, right? We see a CAPP rise as a product category.
And there's, that's exactly what I'm referring to, like CA, right? And, and you know, the funny thing is, usually the analysts come up with a name for it after it's, they saw it in the wild, you know what I mean? And now, okay, we gotta name that, but I, I do think we're gonna see in the wild a security, as I said, it'll start as a cottage industry and grow, but a, uh, uh, another silo in the cyber market for companies that specialize in, in securing, uh, ag agentic or agents AI agents, that doesn't let the AI agent developers off the hook though.
No. Uh, we need some sort of best practices to emerge about, you wanna call it the law of Ag agentic AI or something, right? These are the three rules and the zero law of how an agent behaves or should behave from a security point of view.
We agree with you, Alan, But here's the problem. We don't know how agents behave until we see them in the wild. And that's one of the things that we're, we're running into right now, is the, just the absolute sheer amount of creativity that people are throwing at these problems to try to bust them up.
I mean, last week we saw the Icaro Labs paper where you can jailbreak an LLM by writing your prompt injection in poetry, because someone somewhere was like, why would anybody ever wanna write hacking instructions in poetry? Well, Before that, you could do it with calculus, right? You could do your prompts in math and, and break it as well.
Um, yes. But you also gotta remember, Tom, right now we're in a Cambrian explosion era of AI where we're making all kinds of funky animals with six eyes, eight legs, 12 guts, and, and, you know, and everything else at, at some point, I I, I'm hoping we're gonna have, and at some point soon we'll have standardization and best practices come out, right? We, we don't have best practices yet.
We don't, We, we don't have best practices because we haven't seen a best solution yet. Like, like you said, why, why does an animal have four legs and not five or 12? Because we found out that through trial and error, through evolution, 12 legs doesn't work there.
There's E evolution's slow. We can't afford, we can't afford e you know, we've got, evolution Can be slow, but there's also this theory of punctuated evolution where you have a rapid number of changes that quickly fall out, and then we iterate on the best model. And we're seeing that now with a lot of companies who are like, no, no, no, no, that's not gonna work.
We need to move on and do something different over here because that doesn't scale the way we want it to. But the problem is, is that when we jump to that next, uh, shift, if you will, it's almost like, just like a neural learning model. We've forgotten all the lessons we learned over here.
We're starting fresh. Well, what if we do it this way? Or what if we have it that way?
And unfortunately, from my perspective, developers don't do themselves any favors because they're so focused on doing the job that they forget what happens when people try to do the job wrong, right? Like, think about anyone who like used to check for cross site scripting. It's like, well, what happens if I type the wrong thing into this dialogue box or causing an overflow condition or something like that?
Well, why would you do that? Well, why wouldn't you think about that? Like, I, I think about any, any number of like software development things like, you know, uh, video games are actually a really good example.
If you look at the people, it's like, okay, we deployed this patch, but there's a bug in it. If you wanna know if there's a bug, make it something that's useful to the users. Like if it's a way to get infinite money or something like that, they'll find ways to, to test it quickly and get the outcome that they want.
And then you'll have to go back and go, oh yeah, we probably should patch that out. 'cause that's not an, an intended side effect. And I think that we've gotta get to a point where we can do that rapidly.
Because unfortunately, as much as I would like to say that I would love that the value of adding security happens before the thing is released until you release it. You won't know what kind of attacks you're gonna face against it. Well, it's like, this is very much where, again, back to microservices, right?
When we first started working with microservices, like, how many, are we gonna have a a dozen or two dozen, uh, hundreds, may thousands. Really? How am I gonna manage that?
How am I gonna know what they're all doing? And if they're doing what they're supposed to be doing? You say the same thing for agents, right?
And that's where, you know, Kubernetes came from. That's where Open Telemetry really took off from. Um, and the, we're seeing the same things start to happen here where, uh, vendors are coming out with pictured product name, but it's a agent control plane someplace where you have some observability or a place to manage what agents are running, what tasks that they're doing.
We don't know what the best framework of the best model. I think it looks like a, a video game or a PC game like StarCraft, that that's what I hope the interface looks like someday. But that aside, you know, it, it's being defined or will be defined.
I don't think the solution is there yet. com, I feel it, I feel compelled to say, this isn't the developer's problem. Let's not throw this on the shoulders of developers and say, oh, the developer has to think this way.
The developer has to do these things. Developers have a bit on their plate, right? We need this is, this is all of our, this is the whole stack.
The whole team's problem. It's the DevOps engineer's problem. It's the security guy's problem.
It's the tester's problem. It's the AI's problem. It's the platform engineer's problem.
And it's the SREs problem. It's all of our problem, right? Don't, don't throw it on the developer that he should be, you know, because that's a recipe for failure.
The developer's not a security professional developer may not have written the code. AI wrote it. AI might have written the code, but here's, here's where I think there's good news.
I think using AI technology, we could do things like digital twinning and, and, and, and stuff like this where we can see kinda what's out there and fuzzing and everything else. And, you know, I would, I, and I've seen this just in the last year or two, what I used to think of is after the event horizon security, in other words, post-deployment security measures being deployed, pre-deployment, right? We, we've seen, uh, what we used to consider vulnerability management move into AppSec, right?
And, and, and things like this. So I, I think given the, the, uh, capabilities of ai, we can have higher confidence in the software we release in our software supply chain, which will result in hopefully fewer, not eliminating, but fewer security issues post-deployment. And, and that's why I think we do need to spend a lot of effort and a lot of resources in harnessing AI to make our security better.
You know, the, I think this also ties into things like, uh, the announcement within, within anthropic buying bun, the job JavaScript runtime environment of yes, I can imagine that for production use. I can also imagine that for setting up sandboxes and testing ai, doing those tasks and actually running it as maybe part, even part of the code generation process before it says, here's your code. I've got your code for you doing some testing, doing it, running it in an environment, at least for that particular programming language.
You know, we're, we can do things bit differently in how we create software. It doesn't mean we're changing all of it, but I think folks are kind of thinking out of the box now with ai. I think.
So what, lemme lemme, lemme switch gears a little bit. Um, also one of the early questions about agents was, well, what, what permissions does it have? And the first company that I ran into that had made a decision about that, and may may not have been, probably weren't the first company to do it, was to treat a AI agents as a teammate, as a user in the system to give them their own id, their own, uh, credentials if you will, security, but also their own permission structure and setup and actually show up in the list of kind of users you can select to, uh, perform tasks and things like that.
And that seems to be what the approach people are taking is build on our identity, our IM systems for agents. Now, is that enough? Will we need more?
I don't know, but that seems to be the prevailing win. You guys think that's, is that gonna solve the problem long enough for us? Get AI into production where we got some more hills to climb for Hamburger Hill there, Alan, We're not there yet.
Because the problem with limiting the agent's horizon as far as what it can do is what happens if those controls are breached? And, and we've seen that time and again with your average user, right? Well, I'm not gonna give them admin rights.
Okay, that's great. What happens if they get them? Oh, crap, now they have visibility into the entire infrastructure and they can do whatever.
Like, like how many times have we seen like backup operators get breached and Oh, look, it can read everything. I think you're gonna have to take an agentic AI approach with a combination of zero trust, where even if the agent itself is limited, I have a se a separate set of controls on top of it that hides things that it doesn't need to see. So even if someone does manage to break out of the security controls, they are basically in a, in a prison cell.
And, and we've learned that over the years with users, right? Like, like even the most well-meaning user can accidentally do things without realizing it. I go all the way back to my internship when I was at IBM and someone obliterated about 50 gigs worth of backup data in 2001 off of a tape robot because he accidentally removed the wrong directory.
Because when he, when he, uh, changed users, he didn't do PWD to figure out he was on the tape robot and not an attempt directory. And to this day, 25 years later, I still do PWD anytime I change user focus at all because of that. Because I don't want to be in an area where I can cause a massive amount of damage.
And that's the whole heart behind zero trust, right? If, if I can't control what the users do, I'm gonna control what the users can see. And I think we have to have that, we have to put an extra set of guardrails above the agents to prevent the kinds of attacks that could potentially cause them to do harm.
Yes. Um, so the, the, the thing about this though is we've got, at some point we're gonna start thinking of these agents and, and we've seen this written already, digital coworkers, digital workforce. Yep.
So digital workforce, and they're your digital coworkers. And again, you know, we're gonna need best practices to emerge, but we, digital coworkers are gonna have, I I I hesitate to use the word identity. They're gonna have an identity and access management, right?
An IAM for your digital workforce, right? And I, I, I bet you some of the IAM vendors are already working on this and, and included in that, I I think zero, you know, zero, don't leave your zero trust at the door when you're dealing with agen, right? All of the policies and best practices we've developed around IAM should, should apply to our agents.
Now you've got MCP servers and, and, and, uh, you know, these kinds of things. Very similar. Mitch and Tom, if you remember just three or four years ago, there was this whole move towards, uh, AI security.
There was a whole bunch of AI security companies mm-hmm. Api, I you mean traceable, right? Yeah.
Api, yeah. Yep. A I'm sorry, API I security.
And, um, and now all of a sudden it kind of got subsumed. It went away pretty quick. I I think we were gonna see a similar thing around MPC, excuse me, ccp Yeah, no, I do that.
Get my initials mixed up. CCP servers and, and the security built around those kinds of interactions. But they all fall within the broader category of IAM for agents.
That's my, I think that's the likely outcome here. No, I was just gonna kind of wrap with, I think o one of the things that is happening is we are building on some good things that we've done. Because you see policy as code.
Now that's policy guardrails, right? You see, even see behavioral, behavioral because of the unpredictable nature of generative ai, um, behavioral and outcome based. There's different names people have for this, for the output to make sure that it's accurate.
Um, the others, I spent some time that with a company that's taking the output of AI and then putting into, into structured languages, traditional languages for further execution. So you aren't using the same resources, but also getting more predictable results. Kind of a hybrid approach of AI plus structured code.
We're we're building on things we've, we've done, including identity management. Not saying it's solving the problem, but we're, but we're not starting from scratch either. Like how are we gonna secure those APIs?
I don't know, maybe we should like put a, put an account on there, et cetera. So I'm, I'm, uh, cautiously optimistic, mostly helpful that we'll do better this time. Even if it's marginal, it's better.
I love the hope, Mitch. I, I appreciate it, but I also appreciate having Alan here to remind me that we've had hope before. Yeah, keep hope alive.
Keep hope alive. All right, I think we'll go ahead and wrap up the episode today. On that note, um, you know, we've got a lot of things in the air right now.
I know it's the end of the year for most everyone listening to this podcast. I'm sure you probably hopefully have implemented change freeze December so that you're not dealing with any other craziness, but we've got a lot of stuff coming out. Uh, Mitch, what's something you've got coming up that people definitely wanna be checking out, But definitely want folks to check out?
The agent of Cha, agent of dev podcast that I'm doing with Brad Shiman, it's all about sort of what's real and what's happening in AI agent and agentic development, you know, across the SDLC. So that, and both of us are coming at it as analyst and folks that have a practitioner background. And I, and I've got a number of reports.
We just did our a Ws report, uh, combined with a bunch of analysts. Um, right now we're kind of tuning the practices, so there'll be some information coming out about what I'm gonna be doing with the software lifecycle engineering. So keep watching, watch LinkedIn, 'cause that's what's where I post everything.
Great. Alan, what have you got coming up? 'cause I know you've been a really busy man.
Yeah, I mean, you can keep up with me on LinkedIn or text junk tv, but what I really would like to call the people's attention is coming up after the first of the year. I think it's January the week of January 9th, something like that is our annual virtual event called Predict. This year, of course it's Predict 2026 starring our FU analyst team.
And each one of the analysts will be doing sessions on, uh, what they think is the big story, what they think you need to know for 2026. And, uh, it's always a great event. I think this year with the FU team.
com and look up predict. But it's free to register and attend and ask questions and it's gonna be a great event and I'm really looking forward to that. And we thank you all for listening to this episode of Security Boulevard podcast.
Remember, if you enjoyed this conversation, we would love it if you would subscribe on YouTube, make sure you hit the notification bell and, uh, get all those updates. Or you can also subscribe to us in your favorite podcast application choice because we don't want you to miss any of these episodes. Do us a favor, leave a rating and a review and a comment.
All of those things really help us get noticed by a lot of other people out there. And if you have somebody that really needs to understand security, this is the best place to do it. So send it to a friend.
com and the Futurum group. com, the tech strong TV website or the Techstrong TV app, which runs on Apple tv, Roku, any kind of smart device that has a screen, that app runs on it and you're gonna want to check it out. We also want you to check out our socials because we are on X, Twitter and LinkedIn as security BLVD.
And there's a lot more content out there that you're gonna wanna check out. We thank you very much for tuning in for this episode. We'll see everybody next week.
Hi, my name is Matthew Flug and I'm a research manager at IDC and I cover application deployment platforms. First, thank you for choosing to watch my session today. One of my favorite comedians once said, it's a lot easier to not do something than it is to do something.
And I appreciate all of you for taking the time to tune in to me today. And then during this session we'll talk about some quantifiable metrics that you can use to measure the impact of your application platform, whether you purchased it from a vendor or built it in-house. But before we dive into the metrics, I just wanna set the stage and provide some context for our conversation today.
So application platforms, internal developer platforms, whatever you call them, they've become a table stakes technology. Recent IDC research from earlier this year found that over 80% of organizations have one, um, and they've had one for more than two years. So the upfront investment has been made with people time and money to implement these platforms into your organization's IT ecosystem.
So hopefully your organization is embracing a platform as a product mindset because this platform does serve customers. It's just that those customers are your developers and the rest of the software development lifecycle personas at your organization. While all four of the pillars on the screen right now, um, are crucial to a platform at a, uh, as a product mindset, uh, and we can have a entire webinar on that concept alone.
Uh, during this session, we will focus specifically on the role that metrics play in assessing and driving platform success. So again, whether built or bought, we already talked about how application platforms require significant investments of time, money, and people. However, not all of the benefits that come with an application platform can be directly tied to ROI or revenue.
That means that measuring the impact of a platform across various areas is crucial to get the full scope of the impact that the platform is having on your organization as well as where it can be improved. And because it can't be tied directly to ROI or revenue all the time, it makes it difficult. Business teams need to understand the value of the platform brings to justify the likely not so insignificant investment that they made in the platform.
And for the users, there will need to be some level of standardization among tools, but personal preferences are easier to overcome when you have data to back up why they should go with what the platform says. It's also easier to drive adoption when you can show hard stats. I love data and you'll see some of it in this, uh, in this presentation.
Hard stats of how the platform is improving other users' daily lives. Lastly, to truly continuously innovate the platform platform engineering teams need to understand where platform users experience pain points. So some hard data.
In that recent survey I mentioned, 78% of respondents said that their application platform is meeting or exceeding their return on investment goals. And while ROI is an important if not crucial metric, when it comes to measuring the impact of anything including an application platform, there is more to measure. And one of the key takeaways from this presentation should be that one size doesn't fit all when it comes to measuring the success of a platform.
The metrics organizations choose to track should align with the business and developer goals that the black, that the organization set out for the platform. And they should help answer the following questions, what are the goals the organization is trying to achieve with the platform? And is the platform helping to meet those goals?
Second, does the platform ease the burden of building, deploying and managing software? So with that in mind, I like to classify application platform metrics into three categories, business metrics, technology metrics and people metrics. Business teams want to understand how the application platform is impacting the overall business.
Is the platform driving ROI or reducing costs or produ or generating new revenues? And we'll dive into those in a bit. Technology metrics should measure the platform's impact on an application performance and resiliency and the processes involved to build, deploy, and manage applications.
They should also measure their performance and resiliency of the platform itself. Platforms inherently touch a lot of systems within the organization, which make them a prime target for security threats. People metrics are another key factor, and success is built on driving adoption.
People. Metrics should measure things like usage, developer satisfaction, and time to onboard for any metric an organization decides to track. Comparing with the baseline before the implementation of an application platform is crucial to understanding the impact the platform has on the software development life lifecycle.
So let's dive into some business metrics. Again, we talked about revenue. It's crucial for measuring platform success and really anything that a business does and financial metrics in general are a top priority for business teams.
That same survey that I've been referencing found that nearly half of organizations site higher revenue enabled by the platform as a top factor that influenced the organization's decision to adopt an application platform in the first place. So speaking the language of business teams is therefore an important step for platform teams, improving the value of the platform to business teams. But there are other financial metrics that influence R-N-I-R-O-I in revenue, excuse me, including resource allocation efficiency.
Our developers allocating too many resources to their applications and that results in waste. That's gonna become more and more important with AI and agent applications, which are resource intensive time to market. How long does it take to go from idea to general availability, cost of ongoing software development, lifecycle operations.
And then really important, especially in large enterprises, is the reduction in technical debt. This could, this slide could really go anywhere in my presentation. I decided to put it here, but this is gonna be a theme throughout all of these metrics.
Ultimately, time is money and developer productivity is an area where an application platform can have a tangible impact on the organization. This will, again, this will bleed into the technology metrics section two, frequency and time to market kind of span all three business technology and people metrics organizations can be more agile and better capitalize on market trends. When developers are enabled to move faster, they can pivot effectively to meet those unforeseen market opportunities.
Kind of the way Agentic has kind of just exploded us, right? Self-service capabilities empower developers to build innovative applications without needing to rely on operations teams to allocate resources or spin up environments. And when developers spend less time on tasks like configuring deployments and allocating resources, they'll spend more time building innovative features, which is going to increase innovation while decreasing the taxing tasks developers have become responsible for.
And more than that increased innovation, it's going to increase innovation on tasks that have an actual high impact on the organization. So let's talk about technology metrics while business teams focus on ROI and revenue and financial metrics, engineering leadership will look to technology metrics to assess an application platform's effectiveness. They need to ensure that teams can build, deploy, and manage better applications faster while maintaining security performance and operational efficiency.
Security and performance are really non-negotiables. No organization is going to want to sacrifice those. So your platform needs to maintain those while making a developer's life easier.
The key is finding the right balance between enabling developer self-service and standardizing around best practices. Too much standardization will stifle developer creativity, but golden paths abstract away, mundane tasks, speeding up time to market and providing consistency for tasks that often lead to security vulnerabilities and performance issues. So where to start?
I say start with door metrics. They provide a well-defined and understandable framework to measure the impact of an application platform. However, there is one fatal flaw, uh, which we will get to in a minute.
First, successful application platforms enable teams to deploy daily, if not multiple times per day. Application platforms help improve deployment frequency with increased developer self-service, automated CICD pipelines and built-in security and compliance via golden paths. Shorter lead times indicate more efficient development processes and application platforms often provide automated code, code builds testing and deployment to reduce manual in intervention.
And they also provide developers with self-service environments that we've talked so much about. And resource allocation, pre-configured bill packs and templates and automated scheduling and scaling for those deployments. Lower rates typically suggest higher quality and stability and application platforms enforce standardization of best practices around infrastructure, security, compliance and governance.
And that ser again, serves to limit vulnerabilities, misconfigurations and human errors to lower change failure rates faster recovery times indicate strong incident response and resilience and application, uh, a key function of application platforms and the platforms provide developers with insights into their application's behavior, enabling faster root cause analysis and recovery actions. They can also provide a centralized repository for documentation and best practices to help troubleshoot and resolve issues quickly. So I mentioned that fatal fo flaw at the beginning.
Um, there's not a lot of security in here, and again, that is a key non-negotiable for folks looking to purchase an an application deployment platform. So let's talk about some security metrics. Again, that's IDC research that I've been referencing, found that almost two thirds of organizations consider security a top criteria, both business and technical criteria.
When purchasing application platforms, the security of the platform and the security of the applications deployed via the platform are essential, especially now in the age of AI and agentic. This will only continue to grow in importance and application platforms will have a key role in fostering trust in those agentic systems. So the top metrics to count here include the number of vulnerabilities that are caught and resolved before production.
And that shows that the platform is helping the organization become more proactive versus reactive. The number of vulnerabilities that actually still make it into production, again, an organization is never gonna be perfect, but you want your application platform to help you close that gap. And then lastly, the average time for developers to fix security issues.
The shorter time it takes, the less vulnerable an organization is, the less downtime you may have. And all of those things are crucial tasks for an application platform. So one thing we haven't talked about is it's is the measurement of the performance, the measurement and performance of the application platform itself.
If an organization's application platform is not working well, those organizations will encounter operational risks, lower levels of developer productivity, and an inefficient software development lifecycle. By measuring the platform performance organizations can understand exactly where their application platform works well and where it falls short and try to close those gaps. Ultimately, application platforms need to be available, they need to respond quickly to requests and they need to scale efficiently and effectively.
And then again, what it's a theme throughout this, they need to be secure. So availability and uptime measures how often the application platform is available for developers to use. If developers go to use the platform and it is not ready for use, that creates a bad experience, which could result in developers abandoning a platform.
Again, they are customers the same way we are consumers of, let's say Uber. If I go to use Uber and my app isn't working, maybe I'll go use Lyft or vice versa. Latency and response time measures how quickly the application platform responds to requests.
The quicker the platform responds to developers, the more they will use it to ease the burden of their daily tasks. If it saves them time, they will use it. Research resource utilization and scaling measures.
The resources, the application platform allocates to applications when deploying those applications. And when auto scaling under dynamic loads, the platform should help developers allocate the appropriate amount of memory storage and compute without over or under provisioning. If you overprovision resources, you're gonna wi throw money away, and if you underprovision resources, your app is not going to perform.
And that will lead to developer dissatisfaction. And developer dissatisfaction is exactly why we wanna measure people metrics. The value of an application platform increases as developer adoption grows and adoption and retention metrics are crucial to gauging the platform's impact and whether it is successful in reducing developer friction and improving productivity.
Furthermore, the better the adoption, the more impactful an application platform will be. So when deciding which pain points an application platform should solve, platform teams need to take a second before they implement this platform and ask developers. And frankly, I know we haven't talked, we've only been talking about developers, but I wanna also throw in here security teams, platform teams.
You should ask all stakeholders how they're being evaluated and where their pain points are in meeting their goals and identify where they're falling. Short metrics should then be aligned to track the platform's effectiveness and solving those issues across all the personas, ensuring the platform delivers meaningful improvements to developer experience. So let's dive into some people, uh, metrics.
And again, for all of these, there are more, these are just a few to consider right off the bat, adoption and retention rates. Developers should be naturally inclined to use the platform because it makes the right way, the easy way and the wrong way, the difficult way. Starting an application pla uh, platform pilot program at the outset with a handpicked group of developers, security team members and platform engineers will help drive adoption as developers see the pilot, uh, programs accomplishments, trek onboarding to first commit time.
This metric directly reflects how well the platform enables users to be productive. In that survey that I've been referencing, uh, we asked respondents whether they exceeded, met or fell short of their revenue goals in the prior calendar year. And the survey found that organizations that exceeded their goals were 10% more likely than those that fell short of their goals To track this metric, time to onboard new users and time to access, time to access needed resources and environments.
The, again, the easier it is for developers to access the tools, resources, environments they need to complete their tasks on their own, the more likely they will be to use a platform. They don't wanna submit a ticket to have platform engineering teams stand up an environment or, you know, get authorization from a security team to use a specific tool. So lowering the time to access the needed resources and environments will fuel developer velocity and productivity and it'll drive adoption and retention of the application platform itself.
This metric is more difficult to track. Um, and organizations can collect this from developer satisfaction surveys, which I highly, highly recommend doing. So those are just a few, but I've got a bunch of key takeaways here.
Um, finding the right balance between enabling developer creativity and standardization can be tricky, but consistency in environment security and compliance tends to be important drivers in implementing application platforms and they're crucial to the platform success. Getting developers to buy into that is also a tricky, uh, undertaking here. The first key takeaway, understand your baseline before the platform.
Uh, understanding your baseline before the platform is critical to understanding how the platform is impacting your organization. To use a cliche term here, in order to understand where you're going, you need to understand where you've been and where developers deviate from golden paths, they do so because it is easier to do what they need to do when devi, when deviating, again, I'm gonna reference that survey because I love data. Uh, we found that organizations that exceeded their goals are 11% more likely than those that, than those that fell short of their goals to track consistency in infrastructure and security.
So that's a huge driver of platform success is that consistency in infrastructure and security among all the deployments. The next thing, and I, again, I'm gonna use a cliche term here, don't try to boil the ocean. It sounds simplistic, but far too often I hear organizations who are trying to build a platform that does everything right from the get go.
You will be spread too thin, especially if you've built this platform on your own. Pick a few high impact pain points and address those first. Align the metrics you choose to track with those pain points to understand how impactful the platform is at solving those specific challenges.
As you address those challenges, again, you're gonna continuously iterate. This is not a set it and forget it exercise, but then you can slowly start to expand the scope of the platform and eventually maybe you can boil the ocean. And I speak to a good amount of platform engineers and they are awesome.
They really can do some amazing things. But here is the most important thing. Don't just build cool stuff.
I wanted to say a bad word here, but I'm gonna go with stuff. Don't just build cool stuff for the sake of building cool stuff. Everything that is built for the platform should make a stakeholder's life easier.
And that's why all departments with stakeholders in the platform should have a seat on the platform team. However you do that. My favorite way I've seen it done is a rotating seat for each department, developers, security line of business folks so that those people don't become full-time platform team members, but they still get a permanent voice at the table to improve and innovate on the platform however you do it.
Include those folks. Now, there was a ton of focus on developers in the industry in this presentation, um, and the term developer enablement is all the rage even among my colleagues. We, if you go to IDC research, we're talking all the time, including myself about developer enablement.
But what I wanna make sure that an application platform team does is address the other personas. Personas, what about the rest of the software development lifecycle folks? Application platforms should align all of those personas to common goals and enable them to fil fulfill their responsibilities in achieving them.
And I just want to end on a quick story, uh, about enablement. I attended an event in New York City called Platform Con. Um, and while speaking to a bunch of platform engineers, the conference is for platform engineers.
I use the term developer enablement when talking to one of these platform engineers. And they looked at me and they just said, what about platform engineer enablement? One, I had never heard of that term.
And two, they were absolutely right. And it got me thinking, what is platform engineer enablement? What is security team enablement?
What does it look like? And obviously it is a way more simple, uh, than what I'm, it is way more complex than what I'm about to say, but I believe when you boil it down, it's about enabling platform engineers and security teams to say yes to developer requests. And the best application platforms will not only enable developers, but they will enable platform engineers, security teams, line of business personas, and anyone else involved far too often.
And a key theme at that platform com conference was the tension between the security teams, the platform teams, and the developers. Developers are tasked with moving fast and getting things done quickly, getting things to market quickly while platform engineers and security teams are tasked with keeping things secure, keeping things compliant. And in the case of platform engineers making sure that everything works well, there's a tension there because developers will do whatever it takes to go fast and platform engineers will say, Hey, hey, hey, if you, you can't do this 'cause this is a threat, right?
To our performance or to our security. So enabling them to say yes to developers and now everyone's working towards the same goals, that is what an application platform should do. So again, thank you everyone for your time today.
I'm honored that you chose to, uh, listen to my survey or uh, to my, to my presentation. Um, feel free to reach out on LinkedIn. I've got a QR code there at the bottom, um, as well as a link to, uh, my profile page and we can keep the conversation going.
Um, yeah, this has been great. Thank you. Welcome to New York and Commvault Shift.
I'm Steven Foskett here with the tech field, a crew, and we are on site with Commvault learning a little bit more about where they're going, but more importantly learning a little bit more about the industry and the state of, of course ai. So we have brought together a panel of independent delegates here along with, uh, one of our friends from Convault to talk a little bit more about what's happening in the industry, what was announced this week and what we think of it. Before we get started, let's meet who's, uh, around the table here physically in New York.
Hi, I'm Karen Lopez, uh, at Info Advisors. com. I'm Tom Hollingsworth, I'm the event lead for all things security here at Tech Field A but I also do a lot of security analyst research work and I'm also networking nerd pretty much everywhere online.
Michael stem, vice President product experience at Kawell. Jay Kro. org.
I'm also the Chief Product Officer at Nexus Tech and a consultant for Kro Consulting. Hi, I am Shaah Minnie, may no me de lane across social media. I am also a DevOps engineer and a cloud solutions architect.
And as I said, I'm Steven FoST, I'm in charge of the tech field day business unit for the Futurum group, and I focus on artificial intelligence and other new technologies. So this event has been particularly relevant to me because we've got data, we've got ai, we've got the evolution of data protection, uh, something called res ops, which I think we're gonna get to. Uh, let's start things off with just a little bit of a, a reaction to this whole event.
Jay. Thank you Steven. I, I think I'll start with the res ops.
Um, it's only been a few months. I think we need a new portamento. So we've, we've got DevOps, we've got DevSecOps, we've got finops, we've got Green Ops.
And I think in the world of resilience, it's time to embrace thinking about res ops. So when we unpack what we saw on stage, from my perspective, it was a convergence of things. So it wasn't a separate security discussion or a specific threat intelligence or tools, techniques, processes, discussion as much as it was, how could we have combined efforts in, in the sense of if it was cloud operations, if it was security, if it was resilience, what if they actually kind of all sort of combined forces like a Voltron, if you will, and emerge from this is this res ops thing.
So it seems like you could get more accomplished through that interlock. Um, so if it's a recovery time and point objective, could you get there faster, safer, with known best, well-known backup as now this is restored. That's what I think what I heard on stage.
I saw multiple integrations that will speak to most enterprise buyers. There was an AWS logo, there was an Azure logo, there was a ServiceNow logo, there was a Snowflake logo, and the list goes on and on. So it seems like, again, that convergence of all the things that would normally be happening in more complex environments that are doing AI workloads, machine learning, it sounds like resilience is coming to that arena.
So, so What I liked about it, of course, is that we're now talking about data, not just being files and blocks. We're, we're talking about what's in those things and understanding it so that we can, you know, triage and prioritize by knowing what our most sensitive data is, to know more about it, to be able to inventory what we have. I loved all the dashboards I saw, of course, because it told me what, what assets do we have?
Are they being protected? How are they being protected? Are they being protected the best way?
And that's where I see a good fit for ai, because it's probably better at doing that than I am. I would say. Um, one thing that's sticking out for me, especially as a cloud solutions architect and for my DevOps engineering lens, is the concept of, let's say a cyber attack happens, and then you need to actually roll back.
So what is really sticking out to me is being able to roll back but not reinfect or reintroduce the ransomware. And so you have to be able to roll back to a clean state before it happens. And so I really wanna get hands on with that and dig into that more.
Um, and again, this is why I love coming to these type of events because the last time I was doing a cloud fill day, I got to learn about a nice concept called, uh, recovery as code. So now I wanna fit that type of concept into recovery as code and using Terra Fort to stand that up quickly and things like that, and create run books and playbooks. And I do remember hearing something about AI being able to automate the REM books.
I definitely wanna hear more about that. For me, I think the exciting thing to hear from Commvault is they're identifying attack vectors that people might overlook to prevent those from becoming problems. For me, the big announcement was about the fact that they're gonna be doing this at active directory, because when's the last time you guys did an audit of your active directory to figure out if people had created a, a persistence in there?
And even if you did know about that, how long ago was it? Because if you roll back, you could very well reinfect yourself. And, and it doesn't sound exciting to most people, but to security people, it sounds amazing.
Uh, there was even talk of things like post quantum cryptography. I know we're, we're not there yet, but we need to be there soon. And so being able to put these things in place as we start moving towards that future where we need to think about all of these things means that they're just taken care of.
And I don't have to like dedicate resources to this when I'm focused on other threats. Yeah, and I think another thing that is important to think about that I really appreciate out of, uh, the messages earlier today is not if we get ransomware attack, but how many times like it is going to happen. It is happening, it's going to speed up because yes, AI is here and it's kind of just being unleashed everywhere.
So yeah. Yeah. If you look at it, you know, the average recovery time after a cyber attack is 24 days.
Universally people will talk about that. And now people are getting hit, you know, 4, 6, 8 times a year, 24 days times four times a year. Can your company be down for four months at a time?
And you know, we thought, we thought for years we, we were on the right track, right? We were doing disaster recovery. Everything was RTOR peel.
We had it down to a science. We practice it quarterly. In fact, we've gotten so lazy 'cause we had it down so good.
We just flip flop our data centers back and forth nowadays, right? And it works great. But now with the realm of cyber resiliency, I mean, R-T-O-R-P-O has no meaning anymore, right?
It's not about how fast you come back. It's what's the meantime to clean recovery? Can I have clean data come back?
'cause if I just go super fast, I'm gonna just reinfect everything. Yeah. And, and that was actually one of the things I wanna call out as well.
Um, amid some of the more technical aspects of the announcements that were made was one that caught my ear, which was this idea of a synthetic restore and, um, being in storage and data protection for a long time. I'm used to thinking of synthetic full backups. Uh, that's a, um, essentially where you only back up the changes, but you create a full image by the, all, all the history of all those changes.
And so, you know, it speeds things up. But you actually do have a current state of, of data on whatever media you're using. A synthetic restore is something that's new to me, but I love the idea essentially that, um, typically when you have to do a recovery from ransomware or basically anything, you have to recover all of the data to one point in time.
The idea with the synthetic Restore is that you can recover most of the data to whatever the most recent point in time is and the infected data to wherever that went back to. So you don't have to go back necessarily to three, four days at when the, when the ransomware hit you for the entire environment. You can go back only that one application or only the that one directory, even though that one file.
Um, and the fact that it's got some intelligence in there to, to detect those changes and to help you find that point in time, it really could help to make sure that, that you have a useful and a clean, as you said, uh, restore. Yeah. It's one of the key ways that you're gonna drive down that 24 day time limit and get that shorter is, uh, you know, if, if I had a hundred machines infected, I can maybe get a blast radius report that says, this is kind of where it should be.
But you get into a manual process, I have to restore each machine, check it, do forensic analysis, make sure it's good, and that's an iterative state. I have to keep doing it over and over until I, this at least guides me to the most probable point in time that I could do a recovery from eliminating po potentially days of recovering just to see if I can find that, that bad apple And days of lost data. Absolutely.
Well, I stared that in the face we did at our table. We had store one of many. And, uh, you watch me waste how much time, you know, it was now 24 minutes.
I wasted 24 minutes, you know, going like, maybe this is the one. Nope, that's not it. Nope.
It's still there. It's still. And so then you would see on the left hand menu, Hey, here's, here's clean room available to you.
Here's a way to do one of these restorations to a known good state. That's actually part of that story at the synthetics. One thing that did occur to me is that that was only possible 'cause you had specific key integrations.
You had CrowdStrike coming in, sharing bidirectionally, you also had Splunk. For those that are in that kind of world, had Splunk, there could have been probably Palo Alto there, there probably could have been other elements. But, um, bringing it all together, converging in one place, there was a, it was a total story as opposed to a piece of the story.
And so I think the ability to, again, cross over interlock amongst teams is really what gets you much, much closer to a realistic recovery, uh, outcome as opposed to, uh, I don't know, boss. Uh, we're working as far as we can. I think we were talking about Star Trek earlier, so I got Scotty in my brain.
But I, I think that we are probably going to see AI also attacking us differently. So I think there's gonna be some spy versus spy, like the old cracked cartoon that that is gonna, that's gonna also, uh, mean that that product experience will also have to keep up with that asymmetric warfare that is cyber, you know, threat. I'm so glad you mentioned that, Jay, because when we were in that recovery range lab, um, one of the things I saw was exactly that.
So when I work with people who have run books or have automated things, it's typically a responsibility group or a team has written these automated scripts or something, but it's just for their part and they pretty much just automated enough to take care of their keystrokes. Not all the other things that come with it. Like what are all the other systems saying, what, what vectors am I seeing from everywhere?
What are the end users reporting? Like, all of that really goes into making a better decision and therefore a better recovery. I think it's important that this illustrates what I think is one of the biggest important shifts in the industry, is this idea that we're no longer looking at this from the perspective of just having a bad day, right?
Like backup and recovery is the data center caught on fire, A tornado knocked something out, we deleted some things we weren't supposed to. It does not assume adversarial relationships. We have to assume that now we're not just thinking that the data went bad, it's that someone was purposefully trying to make it bad and keep it that way for the purposes of a ransom or theft or denial of service.
And moving to that idea of I'm not fighting against nature or accidents, I'm fighting against another person or people who are actively trying to combat my countermeasures is critical. Because only when we start thinking that, do we start coming up with these suggestions like synthetic recovery where it's like, what if I don't need to get all of the data back on this date when the fire happened? I need to see how far back I have to go.
When did they start corrupting my transaction files, my active directory? When did they start poisoning the models that I've been training? Those kinds of things.
Delicious intent. Exactly. And that's giving me something like, you just made a light bulb thought go off in my head.
Yes. So there is the piece of now is thinking about, you know, having to protect against other people, but also we're starting to have more AI agents and them getting set loose into production. So it could also be us having to do protections against AI itself, like just going off and doing its own thing because it can, now that one's really creepy, but Yeah.
Well, we don't have a three laws of robotics for AI right now. Even if we did, it's not that hard to convince an ai, well don't, don't tell me how to make this evil thing, but let's just assume that you were gonna hypothetically make an evil thing. What would it look like?
Oh, well I'll help you with that. Well, and that's the other thing is like, again, just going back to that integration that, that that bidirectional, uh, CrowdStrike example where, you know, if it says, and I'm just gonna make them up 'cause I don't know what it's gonna be in the future, but it's maybe it's like emo panda has like gotten into here and now we have to worry about like Shuga Spider is going to, you know, somehow cause this, but it it's gonna increasingly be fully agentic attack vector and it will be not set and forget, but there will probably be wider democratization of this to the bad guy community. And so I go back again, like, I just, I feel like there's gonna be just jockeying back and forth trying to stay one step ahead.
But that story of I see what multiple teams have to work together and interlock meaningfully. That's the only combat available. And then the agentic part of this will be is your agentic team members and your human team members working together.
That human in the loop that we heard from the Yeah, We, we, so, you know, when you look at dr, which we've done for years, uh, you know, whoever the backup person was when, when there was a DR test or a true DR happening, that person was a God, nobody messed with them. It was this one person who could do the entire thing. And now you've said it a couple times, it's the teaming, right?
We call it a a team sport. Cyber resiliency is a team sport because you have to bring in everybody. The cybersecurity guys can't do something without the IT guys.
The IT guys shouldn't restore anything until they get buy off from general counsel and security. IT everybody has to learn to play together, which, let's be honest, these teams usually the only time they saw each other was on the baseball field twice a year at some corporate event, and they played against each other, or they're Fighting for budget. So that was, so that was the other thing too, is during that, uh, onscreen sequence, there was literally, and just to put another one, it was like Portman to it's finops.
There was literally a description of, based on what I see, this is what your cost, your return on investment would be if you did this in this environment versus another environment. And I think by putting that in the tooling, perhaps not, not a guarantee, but perhaps you actually offset a potential like individual team to other individual team kerfluffle over the budget and how it should be allocated and where it would go. Uh, 22 years ago, if you went to a tech symposium for hp, you had HPO on stage, they were the people that would always get the fastest network because the backup had to complete in this, you know, you know, timeframe.
And so everyone's going like, wait, wait, why? Why are they getting the, why is the backup team getting all the resources? So I, I do feel that that was a, um, an interesting interface to show I was very fast.
I'm not sure if you caught it, but showing finops on screen after a res ops conversation. That's another example of some of the convergence I saw. So I want to just ask sort of the, the elephant in the room question here.
Um, one of the challenges that many companies have is how do they break out of their niche? And we've just talked about the importance of this being a team sport. Uh, that came through very clear in all of my conversations with folks from Commvault, not just at this shift, but even the last two shift events that I've been to and Commvault go before, that the company wants to be treated as not a purveyor of storage related products, right?
This is a company that is trying to blaze new territory and deliver resilience, uh, resilience in the face of cyber attacks, resilience in the face of AI challenges for the business. So my question for all of you is, to what extent now do you find that credible? Because they were making that case two years ago when we were here, um, in New York, they were making that case last year that this is a new company with a new strategy.
And we're really serious about this. We're serious about working with security people, with the business, with applications, with ai, with data. And is that credible to you?
And I wanna throw this to Karen because she's my favorite, uh, data. Uh, what about the data? You know, So of course, what about the data?
Everyone should, data's the most important thing. Okay. Maybe not everyone agrees, but, um, like this just reiterates.
I like, since you're talking about over time, like a lot of these events everywhere I went to is just so focused on optimizing backups. And I have said for a long time, facetiously, no one needs backups. We only need recovery.
That's all we need. Backups are just the way we make that happen. And so I love that the conversation has shift to how do we get our data backup and running.
Um, even if the, the outage wasn't a malicious thing, it was just an incompetent or overly curious inside person, we still need to recover from those things as well. I think that one of the ways that Convault has extended, this was on stage when Sanjay mentioned that they have MCP server integration. Now because think about the interface that most of our, uh, incoming knowledge workers are using.
They're not jumping on a command line. They're not going to a gui. They would prefer to do ChatOps.
They want to ask a question, they want to make something happen. It's a lot like the way your executives work, right? Tell someone in IT to make this happen.
And the way that that works is with MCP server, they can use whatever interface they're comfortable with, whether it's Clot or Chad GPT or whatever, tell the infrastructure to protect this, tell the infrastructure to do that. The MCP server knows intelligent enough to go, okay, well that is a function that is handled by this platform, and that's gonna be asked there. And eventually those lines blur enough that it doesn't really matter if this is the backup program because the system knows where to send those requests.
And I think that that's how you eventually kind of become that critical piece of the infrastructure is that you effectively melt into it. Yeah. It's not about storage and backups and it's never been about backups.
You're absolutely right. But they're even going further than restore, they're saying resilience. Absolutely.
And I think the other element was, um, when the CEO of, uh, humane Intelligence was presenting, there was a Harvard Business Review study, and I went and found that, you know, this, this notion, the cybernetic, you know, contributor to your team and what happens, and it literally follows what you said is if a single individual can be empowered to run that, you know, I have to run the report because it's time to run the report. And if they can do that through a natural language interface on A GPT, you get back what, 20, 30 minutes of your day right there. If the team embraces that based on the projections that the Harvard Business Review study shows a team outcome may not necessarily be faster, but it'll actually be 10% easily in the top 10% of all possible solutions that could come back in terms of quality.
And so I think another important point you go to resilience is what is the quality measure of that resilience? And can we do that on a programmatic basis and improve upon it? Just like you said before, we narrowed and narrowed and narrowed our time bound, and then AI disrupted it.
So it seems like we have to keep kind of running like a, I I, I'm, I'm envisioning like a rodent on a wheel in some ways, but I think there is a payoff in that the team will be better for the adoption of the AI than have they not. Uh, to me, and, and, and I don't think it gets enough press is, you know, we can bring technology in all day long, but you also have the process and the people that you have to look at along with that technology. And Commvault has invested heavily in what we call ready verse, which is our educational arm, which is, you know, when you talk to people, you know, one of the, what we call our four pillars of being cyber resilient is you gotta have a cyber recovery plan, which is so different than a disaster recovery plan, but nobody has them because nobody knows how to do 'em.
You can't even find 'em on Google. Right. You can't even search for 'em.
And so we have an entire, uh, services offering and, uh, enablement that teaches you how to do cyber recovery plans, how to bring your teams together, do proper tabletop exercises. Mm-hmm. You know, I always love that I've been through hundreds of tabletops and you know, it's a two hour event.
They have donuts, they have coffee, you know, it's gonna be a couple easy hours. And you know, I like to go in there and shake it up, you know, uh, one of the things that we like to do is bring chaos into that testing. Yeah.
And people don't know how to organically do that, right? I'm like, it's pretty easy. You know, you can't go with these 12 servers.
Let's, let's write the names of all your servers on the back of cards and throw 'em against the wall. And whichever ones are face out, that's the ones we, that's chaos. And so people don't organically go there.
And so we're trying to educate them on how to be more chaotic. Just like ransomware attacks are. Like, we should all be er doctors before we become resiliency people.
So we can deal with lots of information coming at you, needing more information and having to make a decision. But It's important that we get that because one of the things that AI needs is context and it needs guardrails, right? Uh, think about like, go to any, go to any prompt and say, draw me a picture of a bear, right?
Well, it doesn't have any context, so it's just gonna spit out the first thing you think of. But if you tell it, you know, imagine you're a children's children's illustrator and I need you to draw me a picture of a brown bear that's not wearing a shirt. In this setting, you've created context for the thing that you're gonna get better results.
And we need to do that because a lot of what you, you've said, you are like, the chaoticness of it is partially because that institutional knowledge isn't recorded anywhere. And we need to put that down because if we're ever gonna try to automate that or enhance it with ai, those things work on logical systems that require tagging, that require, uh, context. If we don't give it to 'em, we're never gonna figure out how to do it.
So, uh, you said a, I mean, we've been talking about AI a little bit here too. Uh, one thing I think we need to talk about before we wrap is, um, the applicability of this to ai, uh, to new workloads because, um, one of the highlights of the CEO, uh, keynote was talking about that we're not just cyber resilience, we are AI resilience. Um, I'll ask the same question.
Is that credible to you? Do you feel that Commvault has a credible AI story, Jay? So again, just going back to the recovery range experience that we had, it was a storefront demo.
You're, you're, you're an e-commerce example. I think by the time we get back to this again next year, we would expect to see like, okay, here's your vector database pine cone. Here's what's happened.
Someone went in and changed material pricing information that's used as a core instruction set that someone uses as part of a knowledge base or a chat that's gonna give a customer a fictitious price, and that causes a PR problem. You know what, whatever that set up a scenario is, and I do believe it will be a very specific, how do we recover to, to our known good state for our data? And, um, that's super down in the weeds, but I do believe they have all the essential pieces to put that together.
And, uh, I look forward to that demo. And the offshoot of that is like, in my experience, I've seen companies that are really worried about their customer database, their web website database, but they never think of what I call their IT databases. So, uh, you know, active directory, their dev environment, their training data.
So what I'm seeing is people are thinking of training data as test data, even though by definition it's usually got a mix of synthetic data and production data, and they're not protecting it, it's just data sitting out on a file share on somebody's laptop. So that's why I'm a big fan of all these inventory tools that can find stuff because we don't even know, we can't protect what we don't know, and we can't recover data that we don't know about. True.
Yeah. And it's making me think back to something that I've been talking to, talking about a lot more and more is in the realm of vibe coating, because what's happening is, in respect to that, people are going out using things like windsurf or, you know, there's, there's so many, but let's take Windsurf for example, and using that to like code up some new application or maybe make new Terraform configs or whatever, and they could be injecting some of that synthetic data as well as production data and not paying attention to that, potentially causing leaks. And so, yeah, that's something I'm always thinking about more and more within MySpace of how we protect against that.
And like you said, going out and even one knowing if it's out there in the first place, I think that the story that Commvault is telling, it's a lot more credible if you think about something as mundane as Office 365. Like they, the well, and the reason for that is because there's an agent that hooks into 365 and Google Workspace to back up your documents. That's because that's where we store documents.
Now, we don't store them on a hard drive, we don't store them in our documents folder on our laptop. Everything's in the cloud, and the cloud never goes down. Right?
You, you moved off of US East one. Right? But, but more importantly, the Commvault skating to where the puck is going to quote Wayne Gretzky, they are looking forward to AI as the place where all that data is gonna be very soon.
Yeah. So how do I protect that? Because AI is a container just like Microsoft 365, there's no file structure inside of there, and I have to figure out how to make sure that that becomes readily available so that in the event of one bad day, how do I get all of my AI data back the way that it was?
Because we all know that if we send something to the prompt three or four times, we're gonna get slightly different answers three or four times. And I might need to reconstruct that thought process to get my widget off the ground or something like that. Yeah.
So do you think we, we, we got the message. I Think you got the message. I think, uh, what you're gonna find is we actually break it into two main categories, right?
Um, uh, AI for Commvault. So how do we organically take in AI to make things easier? We talked earlier about the Claude interface and, and just, you know, people wanna talk, they want, they wanna express themselves instead of sit there and typing all day.
So having that, so bringing AI into Convault and then also Convault for ai, being able to protect that AI where it is, you know, there's poisoning attacks, there's all types of things that are going on, and we're at the, at the beginning of where these bad actors are gonna be attacking these things. And so being able to get back to a good state or law, I have to get back to the state for a lawsuit, or I have to get this back to the state for governance compliancy. These are things that haven't been tested in the courts yet, and so we've gotta get in there early and be prepared for where there's gonna be some hefty fines.
Well, You know, overall though, it was, it was a great event. Uh, I really enjoyed getting out here. Uh, Commvault did a nice job of organizing this.
Um, I absolutely love the keynote by, uh, Dr. Chadri from, uh, humane Intelligence, um, just great and, um, worth watching. Uh, if you watch this round table, if you're interested in what's going on here, uh, you can see the Convault presentations for yourself, uh, on the Convault website.
You can also learn more about much of what they're doing over there. And of course you can, uh, find our delegates wherever they're writing and speaking and so on, and connect with them, uh, to hear their opinions as well. Uh, also, we will be having, uh, many more tech field day presentations, tech field day sessions, and so on, uh, in the coming years.
Just check the Tech Field Day website, go to YouTube slash tech field day, or follow us on social media as tech field day. So thank you very much, uh, for watching. Thank you all for giving some precious days of your lives to come to New York and, uh, and attend all this and, and, and pay attention so well, and, uh, and, and I, uh, really appreciate the, the whole experience.