Techstrong TV December 19, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, you remember the girl who danced with everyone at the Prom, don't you? Was her name open ai? You're watching Textron Gang.
Hey everyone, it's Friday. It's the Friday before Christmas week. So it's a really good Friday.
A lot of us are hopefully already feeling that holiday cheer or just waiting to just push, you know, get get to the holiday break as we we this crazy year of 2025 starts drawing to a close. Thanks for joining us today on Textron Gang. Let me introduce you to our all star panel of gang members.
We've got, uh, Gina Rosenthal looking great. I don't know if that's a new camera or what, Gina, but that you are looking like an eight k today, my friend. Um, joining Gina, we've got, uh, Alistair Cook who's joining us from, uh, the Land of Oz, I assume getting ready to spend the holidays at home, as well as John Swartz and Mike Ard and myself.
Welcome gang members. Mike. You know, we've only got a few stories left for the year, but it's gonna go out with a bang.
Open AI is, uh, dating again. What do we got? They keep on Coming.
They sure do. Keep on coming. I'm having a hard time sorting this one out, but, you know, on the face of it, it looks like a hell of a discount for open AI to use AWS processors, but what do I know, John, you're closer to this thing.
What's going on? And can you make any sense of this one? Uh, Jesus, you know, every day I try to make sense of this stuff.
You know, there's a photo circulating on, on, on x. I don't know if you saw it, and it's funny that Alan would would mention the girl, the dances with everyone, but there is a photo of seven executives standing around each other. Sam Altman is in that group and Well, Is that the time cover?
Is that the cover of time? Yeah. Oh no, it's another one.
No, this is another one. Oh, okay. This is, yeah, this is another one where our standing one and, and you've got Su Sundar, you've got Tim Cook, you've got Zuckerberg, you've got all the usual suspects, um, Nadella and, and, and the caption is, it's your turn, Jeff Bezos, to invest in open ai.
And that's actually, it's going viral. But in any event, according to the information, which does have really great information, uh, there's a, a story that Open AI is in preliminary discussions to raise at least $10 billion from Amazon that's gonna be part of a larger fundraising round that if the information has subsequently said could reach a hundred billion dollars, which would give ultimately open AI evaluation of $750 billion. Now going back to the Amazon deal, which allegedly is, is being talked through, this would value, um, chat GPT at about $500 billion and include open AI's adoption of train.
Um, it could be in a sense, would it, it's if, if this comes to pass, Amazon would include, they would be exploring commercial opportunities and potentially selling a corporate version of chat GPT, uh, on their service. Uh, it's, it's interesting because in a sense, Amazon's competing with Nvidia in terms of a AI chip markets, and, uh, a lot of people are actually, we, I think Dave Nicholson yesterday talked about more competition for Nvidia on this front. So not only Amazon, we've got Meta and others.
And so Mike, to go back to your original question, it's, I, it's, it's, it's head spinning. I don't, I don't, I don't quite know where this is going. I think they're all going in on open AI until they turn against them and compete against them like Microsoft did.
Um, it's, it, it's, it's, it's, it's just leaves me speechless actually. Well, I think you have spot on in that the Microsoft announcement was a precursor for all these other organizations to now invest in open ai. And one way of looking at this, Alan, is to say, Hey, you know, we're just passing the hat around for open ai, tossing a couple of billions, and away we go.
That is one way of looking at it. But, but, you know, there's a method, there's a method to Sam Altman's Madness, right? And I've said this before, I think I said it on yesterday's show.
Sam Altman is the pied piper of ai. He is the closest thing to Steve Jobs we've seen in the Valley since Steve, you know, unfortunately died way too young. Um, but here's the thing about all of these open AI deals, they're not that simple.
It's not just passing the hat and throw in a couple shingle, you know, sheckles from your pocket. It don't work like that. There's always a, you give me this, I'll give you that.
The money really doesn't change hands. We just move it from one spreadsheet back to your spreadsheet, from my ledger to your ledger. It's a give and take.
So for this $10 billion investment, and, and John, I don't know the particulars, I'm sure you do, but for that $10 billion investment, OpenAI is pledging to do, you know, $20 billion in hosting with AWS on train infrastructure or something. So for the 10 billion that, uh, Amazon's investing, they're going to get 20 billion back in in revenue. OpenAI is a company, you know, you mentioned the $750 billion valuation, God bless 'em, but they're on the hook for a trillion and a half dollars guys.
Yeah, Right? The ma it's just Yes, exactly. Into one and half trillion.
They're still in the, it goes to red by a hundred percent. 4 trillion. Exactly.
So what are we, and, and you just, you add up all, uh, yeah, it's just like, it's like a kill game. This is, This is, So one of the things I was trying to think about is, okay, so like, where are the places that could be a single point of failure for organizations that are adopting ai that are trying to use the different things? So in, in one sense, you've got, okay, if OpenAI, um, does whatever the money shenanigans are with Amazon for the, um, what is it called?
Traum chips Cranium. Yeah. That gives you a choice between, supposedly between train and, um, NVIDIA's chips.
But it also Complete No, no, no, no. It's a different, no, it's different. The tra or inference chips.
Okay. And the inference chip, you got Amazon, Trane, you got Google's, uh, chips that they're making, and then of course, you're a Broadcom, Right? Right.
Those are probably the bigger inference chip competitors though. But though, what's his name, Jensen and, and Nvidia wanna get into that, but they clearly have the gpu, the training chips, But they're also like, Google's chips are made by Broadcom, so it's a little fluid, and some people will use training to train versus the other chips that AWS has. So it's a, it's, it's not that clean.
Right? And so the, but the question is, if you look at what OpenAI does and how much money they are owing, this is my question, maybe it's a dumb question, but let's see. Um, and how much they're now owing by and trying to make up with these different partnerships.
If the partnerships fall apart or if it doesn't really work, what is their, what are they trying to prove that, what, what do they have to do to shore up their business, making their open AI system better and getting more people to adopt it and use it, and then that rush to get the more adoption, does that have any impact on what it actually does, which is influences how information is derived from data? And I think there's a little bit of a danger there. So there's more than a little bit of a danger.
There's a big danger, and it's not to open ai. And I'll explain to you in a second. First of all, what OpenAI is doing here is classic business.
They're locking down territory. They, this is akin to European explorers planting flags on every shore they landed on, right? OpenAI is in a land grab trying to grab as much of this market as they can.
The problem with this model is if OpenAI, Sam Altman has put OpenAI at the center of it, if it falters 60 plus percent of, of, of booked revenue in the future from, for Oracle, for all of Oracle is OpenAI, even Microsoft with a, what is it? Two, $3 trillion valuation. A huge percentage, 30 something percent of their book data they're waiting to recognize comes from open ai, right?
There is so much open AI is on the books Core Weave, a huge percentage of core weaves revenue is, is open AI pledges. Now it's gonna be at Amazon too. And, you know, Amazon AWS is what, a 13 billion or 15 billion year business?
Something like that. You know, how much of that is going to be open ai uh, pledges. So this is, this is a setup for a classic fall where if it, I did this on Shimmy says a couple weeks ago, I had the Jenga Tower, right, with open AI's tile right in the middle.
You pull out open AI's tile, the whole Tower falls, The whole thing collapses. Yep. 4 trillion that you astutely referenced, Alan Open AI is like hemorrhaging users to, to Gemini and, and to Claude.
Absolutely. And this is created panic within the company. It, but here's the one thing I, maybe this plays into it, I'm not sure, but somehow maybe this Johnny Eye relationship with open AI involves Amazon eventually, where you have some sort of Consumery device and Amazon is 60, but Amazon's talking about business version, not a consumer Version.
No, no commercial. No. They might use it for commercial.
Yeah. So, so let's wait, let's get Alistair in here for a second, since he's our new guest for the moment. Alistair, what's your take on this whole thing?
Well, I've been looking as, as all of us have at the ridiculous amounts of money that are flowing around in, uh, this generative AI space, these chat bots, and it, it comes back to me to where the heck is all the business value that this money is supposed to generate. There's the gap for me is there's a whole chunk of money, and as you say, this is a, this is a land grab for compute capacity across the world by open AI and under them by core weave as well. But all of this compute capacity that's gotta be built for all of this spend, how the heck are we gonna actually get business value out of it?
I don't, you know, still hemorrhaging cash you say outta it. Well, that's, that's what the Krishna Armand Krisna, yeah. Armand Krishna of IBM said mm-hmm.
You know, 'cause we've talked. So forget just open AI for what they, what the, the powers that be. And it's the seven or eight people in that picture you talked about, John, or in the time man of the year, it's the architects of ai.
They have them sitting on a beam like the workers, you know, there's the eight, I don't know if you guys have seen this one. It's a great shot. Anyway, they're talking about $8 trillion in data center build out over the next three to five years, $8 trillion.
A we don't have enough power generation to generate to, to, to power those $8 trillion. B, if you are gonna have, if you're gonna invest $8 trillion, what's a reasonable return? Right?
And you're not gonna make it up in one day, even though every five years you've gotta redo these data centers with the next generation of equipment and infrastructure. But so what's a reasonable rate of return? How much money can it make?
How much money can it make to, to justify that sort of cap CapEx? And, you know, it was one thing when Google and Amazon and Meta were using the, the hordes of money they've been sitting on since COVID to invest in this. com bubble, you know, and when, when, when stuff goes south, someone's going to get left holding, you know, with a short straw here.
But that's what You started to see evidence of it already with Oracle. Yeah. I mean, well, that's what the government's doing, right?
It's they're gonna use the government money to do it. That's what the US Department of Energy is in charge of the whole, um, whatever the executive order was to build out the AI data centers in the us it's gonna be taxpayers. Are you saying, Are you saying the taxpayers are gonna get stuck with this at the end?
Is that where we're Going? I think that's a possibility. Well, we're already paying, we're gonna pay higher utility costs for it.
But, but guys, this isn't just a US problem. The EU is bought into this. Our friends in Saudi Arabia are, you know, head down into it.
This is that $8 trillion is not a US number. It's a world, I I should mention that the eight trillion's a worldwide number. I think the US number is closer to five.
So, Alan, for the people who have forgotten, how does that Pi Piper story end again? He, he leads all the children out the village, right? It doesn't end well, not, it doesn't end well.
And never to be seen, Never to be seen again. Yep. Yep.
Mm-hmm. It's, it's a scary thing. But that being said, you know what, you gotta give Sam Altman credit the same way you had to admire Steve Jobs, moxie and showmanship.
So, do you gotta admire Sam Altman too. He's, he's, he's placed them in the middle of everything, pivotal in the middle of everything, a company that doesn't even have $20 billion in revenue, hemorrhaging money, like, like a, like a, a, a cut, you know, artery. And, and, and he, but they're in the middle of everything and, and doing these deals.
10 billion here, 200 billion here. It's, it's, I mean, one day they'll do business school case studies on this And then, but to John, and they Could be either triumph or a tragedy story. I'm sorry, Mike.
I mean, look, maybe, maybe we're all, we don't see it that he does. And, and maybe ai, when you start putting it in robotics and the GenX and everything else, and it puts us all outta work and we just sit on serbo chairs and grow fat, right? And Sam Altman looks crazy as a fox Maybe, or to John's point, you know, everybody moves over to LLMs from Google and Microsoft and smaller LLMs and open AI winds up being, you know, the biggest buble in history.
That's a, that's a possibility actually. Yeah. Would discount a better, you Know, when you, there is a PT Barnum element to it, right?
So, I mean, Steve Jobs was a PT Barnum, but he, I mean, he did delivered in a sense, this one, we is yet to be known. And, and if you wanna be in the middle of everything, you also take a lot of risks by being in the middle of everything, you're, you're, something Falls, falls aside or a kilter. There's a lot of possibilities for things to go badly.
I'm not saying it will, but it just raises alarms for me at least. Absolutely. Well, it's Friday.
Let's not end on a bad note here. We got a lot of good stuff coming up on text and gang. Um, let's take a quick break, Mike.
We've got more. We've got Microsoft AI agent machinations. I love that you're watching text and gang.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions, your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back and we're talking about the latest AI announcements from Microsoft involving VS Code. And if you've been following Microsoft over the years, sometimes that M stands for Mud as in clear s and Microsoft is basically talking about how they're going to embed this kinda agent control plane into BS code in their app dev strategy. But at the same time, they're also, um, deprecating certain other AI related tools that they have created over the years.
And it seems like they're trying to make a play to be kind of the central control mechanism for all AI agents related to anything to do with software development. Gina, I know you read this story. What, I mean, what's your take on what's happening here and, and how did you read this thing?
Well, I read it and, um, it looked like it was good stuff and bad stuff. So it looked like there was really good stuff. People were happy that, um, in inte code, well, well, not the Intelli code, that the transcript seven is, it was all updated and it's great.
And it's newer model, new newer language. Everybody's happy with that. The copilot stuff is awesome, is obvious.
They just want more co-pilot, um, subscriptions. They don't want really, um, they don't wanna give anything away for free like they were doing with the Intelli code. But the, the rest of it is just like, it's such a total product market.
My product marketer went crazy because reading this, because the, the person that wrote this was just like, the messaging sucks. This is the worst messaging ever. We don't know what Agent HQ is supposed to be.
We don't know what all of these terms mean. We don't know what it's going to do. So that's why I had a bunch of questions about it.
And, and, and for a platform for agents, there have to be tons of questions about it. I mean, I'm trying to build an agent right now, and I'm totally within that 85% of what I'm trying, the agent came out is wrong, and you have to go back and, and rewrite it. And, um, there, there's so many security implications that I don't even think I've caught all of them with my dumb little agent that doesn't do anything.
Um, so I'm terrified to put it out into the real world to see if it'll, Well, welcome to tomorrow. I think everyone has, you know what Gina, everyone I speak to has a very similar experience. I tried to build an agent and it sucks, right?
I, as, as a fact, when we were at AWS on the way in, in the cab, uh, from the airport, there was a sign, or maybe it was in the airport, Databricks, our, they said, our agents don't suck, But why don't we call 'em bots? That's the thing I don't understand. So to have this, they Are bots.
Well, bots, bots have a bad connotation, security wise, right? These should have a bad connotation security wise too, because they're bots. Yeah, right?
That's all they're doing. My, my little agent is nothing, you know, it's got one little piece of, of an open AI call, but it's basically calling a, an open. Yeah, it just, it just, no, it's, it's just calling APIs.
It's not doing anything interesting. It's a freaking bot and it's full of security holes, even my little stupid agent. But I think that's, um, what the big deal if, if you're gonna put like this agent platform out, if, if the people who are going to write about it that really do understand all the Microsoft, um, um, releases and everything, and they're like, this, I have no idea what's going on.
'cause Microsoft didn't tell us what's going on, but they want you to use a platform to manage all your agents. Like how in the clear is that platform? Do you know what the platform's doing to the agents?
And there's secret agents behind it that ma that Microsoft wants you to use. And it was really confusing, Mike. Yeah.
So here's the, here's the deal. A couple of months ago at the big Microsoft Ignite conference, you know, agent HQ is a platform and a strategy, and away we go This week, agent HQ is a statement of direction. We don't know exactly what this thing is looking like.
And I got a feeling that maybe there's not a whole lot of code to go with it right now, John, this kind of feels like classic Microsoft. Oh, it just Sure does. Yeah.
That's funny. That's funny how they changed the narrative, like just a matter of of months. Yeah.
This is, this is to be expected. And you're right, it's clear as bud and it's, um, the whole thing, and I'm glad you mentioned this, Gina, the whole thing about AI agents and what, what they are bots, right? And it's just a marketing phrase.
Maybe it's skewed, maybe they think it's, it's more embraceable, but it's, it's, this is part of this larger issue that I have with AI agents and I, I belabor this, belabor this argument, but it's just, it's just too much overwhelming CIOs, CISOs, you just put, your heads must be spinning. Like, wait a second, I thought you said this was gonna be the case. Now you're saying this, it's like, how do you, how this is why the adoption of AI agents in some cases is slower than anticipated because there's just so much noise and so much spaghetti being hit against the wall.
So guys gather round, let me try to make sense of this for you. Here's the deal. Here's the deal.
First of all, in terms of AI agents as bots, today's AI agents, six months from now, a year from now, we're gonna look at them and say how quaint, how quaint they are. Because most of the things that we're calling agents today are bots or even API calls, right? They're making API call kind of things.
And that's not really what the future of AI agents are. The future of AI agents will be autonomous tools that are persistent and aren't one trick ponies. Right?
Now what we're seeing are what I'm calling one trick ponies, right? I want my AI agent to take my whole workflow and work that workflow from A to Z, not A to B, but that's the promise of AI agents, right? That they will go A to Z in terms of Microsoft, it is classic Microsoft.
Microsoft is never the first one to a party. Ever make a party? Who's the first person there?
There's always some people who come early, not me. I'm married 35 years. I've never been early to a party in 30, 40 years since I'm with my wife.
But that's another story. Microsoft's never early to a party, but they never, like, they, they hate to miss a party. And so all they're doing right now is enunciating the same broad message that Salesforce, uh, ServiceNow, Amazon, and the rest of these people are, are enunciating, which is, I wanna be the control plane for your agents.
I wanna be the garage where you park your agents. I wanna be the Kubernetes the orchestrator for your agents. And that's what this is, this is Microsoft saying, as it relates to software development, we wanna be the control plane for your agents.
We wanna be the coob, the orchestrator for your agents, you and everyone else, Microsoft. But what Microsoft is betting on is though they're never early to a party, they're always the best dressed, you know, and they come with the nicest gifts and they bear, you know, and they, and just by their sheer tenaciousness and and market presence, they're gonna make themselves one of the top three. And that's what they do.
Are you seeing that I'll not be getting a pony from Microsoft this Christmas then? Is that what you're saying? No, there's, there's no pony in that room.
But, um, but that's, that's you talk about. And it, they don't know exactly what it's gonna look like, but they'll be there. I bet you, You wanna hit something really significant in this, Ellen, about how quaint these agents will look in the future.
Currently they look terrifying. They don't look quaint. They get things so wrong.
They are so riddled with, with risks and, and dangers in them. One of the things I pulled out of this announcement was the YOLO switch. You only live once.
Turn on the agents, let them loose. 'cause you are going to get destroyed by this, right? We are not in quaint agents.
We are in the terrifying early place where it was, uh, early radiation, right? Earlier in nuclear. Your kids are playing with uranium right now.
So This is not the way that ordered The gremlins. It's not one happens. Yeah, well, but That's exactly what I thought, Mike.
But you're gonna, you know, but hopefully we'll get through this. You know, my grandmother used to tell us about raising kids. It's just a phase.
They'll get through it. This is a thing. Now, can I mention some, can I mention something really quick about, I mean, you mentioned tenacious.
That's such a great word to describe the way Microsoft tries to convey ideas. I remember as a reporter, like when I was in a, uh, mainstream publications, they would have you go up to, to Redmond and they would do these back to back meetings. I'm sure Mike went through this, these back to back to back meetings all day.
And it was a form of brainwashing. And by the end of the day, until He said yes, Yeah, until you actually were mimicking what they said, you were mouthing what they said. You go to Apple, that you have a briefing and you have five different viewpoints from five different people at Microsoft, you'd have 20 people saying exactly the same thing, and they would just drill it into you.
Eventually they would make their point. So I think the reason they call agents agents instead of bots, and I think this is actually an important thing, right? They want us to think of them as more human running off of being our coworker friend that's going digital.
Yes. The thing is, technically we're seeing what we saw with really bad malicious spots 20 years ago, right? It's just a thing that can do a thing and maybe it can pull other things.
I mean, I was writing agents to build, to put, um, Linux on servers back in the early two thousands. That's all that jumpstart kickstart was. It was something that was written with some code that said, go and do the pre-work.
Go and install this little bit after it's installed. Go and do the post work. Now do a test.
That's all that these agents are doing. They are bots. And if we talk about them, like they are pieces of software to do specific pieces of things, and we want them to start interacting with each other to be autonomous pieces of software to do it, instead of pretending that it's our coworker and we should have an agent managing the agents in a whole department of agents.
This is just stupidity. Let's say, let's talk about having the right platform and having the bots. I I, I'm done with agents.
I'm not calling with that anymore. So, so there's a method to their madness, right? And so the software companies have been banging a drum for years about getting paid based on the quote unquote business value of their software versus just selling you a license.
License. And this aging provides a mechanism to kind of start billing you for the value of the perceived software versus just saying, here's a bot that's an extension of your existing license, But isn't an agent just the extension of your license. I would agree with you, bud.
I'm just telling you. Right? This is why I can't be a big company working.
These are the arguments I bring up in meetings. But one other thing though that I don't, I want to just, I'll leave us with this, is at the same time they're doing this, they're killing awful lot of the free stuff they were giving out. And again, that's the same old story, right?
The drug dealers in New York City used to do this first one's free, right? First one's free. They gave it to you for free to get hooked, and then now they pay.
So clearly Microsoft has decided that, hey, the time for giving out the free candy is over. Now people gotta pay for the cigarettes or whatever this is, right? And, and I I, if Microsoft is doing it, Google's gonna do it too.
Metal will do it. They're all going to do it. We might be seeing the end of the, did we get, did we set the hook deep enough to start making the money here?
Because we all can't have open AI balance sheet. Something to think about. All right, let's take a break.
We're gonna come back to C Block. I think Alistair's gonna help us with this one. I can't wait.
You're watching Text and Gang. 2026 marks a turning point. Artificial intelligence is no longer just a tool.
It's shaping industries, accelerating innovation and redefining how humans build, create, and solve problems from engineering and medicine to finance infrastructure and everyday life. AI has become one of the most influential forces on the planet. That's why for 2026, we recognize AI as tech Strong's person of the year not for what it replaces, but for what it enables a future built together humans and machines predict.
2026, join us. Hey folks, we're back and continuing a little bit on a theme, but, uh, the folks at Code Rabbit put out a report this week, an analysis of 270 pull requests that were made involving open source tools and concluded that the number of software defects being generated by AI coding tools is much higher than what humans would be doing in a similar set of cases. And this goes well beyond vulnerabilities.
These are defects that essentially increase the technical debt to the point where, well, it's probably your application's gonna eventually break. But Alistair, what's your take on this whole thing? Well, I think this, this study was, was good.
It was a, a great start to look at 270 pull requests. Uh, but you know, headlines from, from a, a whole bunch of larger companies are saying that's how many pull requests we push through in a an hour or a day or whatever their headline is. Uh, AI coding tools we know are very popular.
We've seen statements from a lot of large companies saying that huge amounts of their current code bases written by ai. So it's kind of surprising then that we're also hearing stories of code quality decline. There's been a lot of anecdotal coverage of this, particularly talking about Windows 11.
Code quality was the one that I saw quite a bit. Uh, the discussion around maybe, uh, Microsoft needs to hold all of its feature development to fix all the things that have been broken recently in Windows 11. And I know correlation doesn't imply causality, but this does correlate highly with large amounts of AI generated codes.
So I'm kind of skeptical about how much of a problem we're generating here. Now, one of the perspectives is that if the A coders AI generated and it's going to be AI maintained, doesn't matter if human can't read it so much. And this comes back to what we're covering in our last story, is how much do we trust the, uh, bots, the, uh, agents that are doing this coding for us?
And how much are we just gonna hand the keys over for the entirety of our software development? Right? Do these technical debt issues that affect human coders also affect AI based coders?
But I think fundamentally we are seeing that these, uh, AI coding tools are not up to the quality of a good software developer. They are still giving us more the intern based level of, of coding. Uh, I talked about this on a recent episode of the Tech Field Day podcast as well, that the knowledge of the enterprise scale building of applications doesn't seem to be nearly as trainable in these AI coding tools.
As a, you'd hope that the very senior engineers who have vast experience haven't necessarily codified that experience in a way that can be used to train an ai. And that's why we're not seeing awesome application architecture being built by many of these coding tools. Uh, I liked also one of the commentary in this article, which was around that AI coding tools are producing greater efficiency for developers.
Uh, maybe not. There was a study conducted midyear where the developers thought they were more productive using AI coding tools. But they com the study group actually completed tasks faster if they didn't use AI coding tools.
So is this productivity and illusion, or is it that we have to use these AI coding tools? 'cause we've spent lots of money on building ai. Are we actually getting something useful out of the AI if it's taking longer and producing worse product?
Well, that was mid-year. The world's changed since then. But let me, you know, I recently did an interview with the CTO over at Veracode, right?
Veracode's, big AppSec company. And anon, you know, anonymizing the data that they gather from their hundreds, thousands of clients. They, they actually have been putting out periodic reports on the security status and vulnerability frequency of AI generated code versus humans and so forth.
Um, and you're right, uh, the AI generated code throws off a lot of security vulnera, you wanna call 'em security vulnerabilities, bugs, defects, whatever you wanna call it. However, according to Veracode, and you know, they don't, this is just what their data shows. What I said about midyear is no joke.
The quality of code that AI is generating is, is on like a, a, a, a 45 degree upward plane. And just recently, like in September or October, it actually crossed the level of human generated code in terms of vulnerabilities and security defects, right? Let us not fool ourselves.
Yes, the most senior best developers develop better code than junior developers. I don't think anyone will argue that. But when you take the totality of human generated code and baseline that to the totality of, of AI generated code, they, they're, right now they're roughly on par.
But one is at a 45 degree angle continuing to improve. And one is sino, you know, has been level for a while now. So the, the question is, what about six months from now?
What about nine months from now? But, but here's the, here's the soft white underbelly that I think gets dangerous. And it's a birds and the bees question.
Yes, our best developers are better than AI can code right now, but if we don't train and let our not best developers evolve, where's the next generation of best developers coming from? Right? We don't hatch these people in nurseries.
We, they, they learn on the job. And so that's the real issue is we can't say just let the best people develop. We've gotta, you know, we, we talk about things like human in the loop.
We've gotta keep the human in the loop for a lot of reasons. That being one of 'em. So that these developers do learn to use AI as a tool, but become better developers, right?
Otherwise, this'll be the last generation of best developers we have. I also think that we need to use AI to review the code created by ai. But there's a a tendency where I see where people are using the same AI that they used to write the code to review the code.
And that's a fundamental mistake. 'cause that's just gonna, Yeah, no best practices has to emerge where you, if you're gonna use AI to check ai, you gotta have a different AI on it. Mm-hmm.
But you still, even in that scenario, Mike, you need a human in the loop, Right? And I'm also, you know, I am not the vice president of the United States, but I will engage in a little conspiracy theory here. The AI code is, you know, extraordinarily verbose and seems to require a lot more computing capacity to run.
And, you know, that seems to play into the benefits of the cloud service providers who want you to maybe consume more infrastructure than ever. I'm not saying that's a deliberate outcome, but it sure is coincidental. I thought you were gonna tell me you're merging, merging with a fusion energy company.
Go ahead. I digressed. I think it's, Sorry.
I think it's a bigger, it's a bigger picture too, right? Like when you look at these surveys, like, like what Alistair said, it was a really small amount of, for this story, a very small amount of pull requests that they looked at. Um, and just in general, what we're talking about with the 45 degree co, uh, AI is getting better.
And we're, we're dropping off here, but well, We're not dropping off, we're not getting worse, Gina. But human coding is steady. So, so, but what I was getting at is, I, I think there's specific things that AI code is probably really, really good at.
I think the whole mainframe industry is one place, being able to go through trillions of lines of code to, to point out this is duplicated, this is duplicated, nobody knows what this means. And really help the newer generation, uh, COBOL developers that also fluent in different languages, excuse me, to help them understand what the code was to help them see where to attack. I think that's really good, even with the older code too.
But like, um, with, you don't have developers that have the, the younger developers having the knowledge of how things break and, and that puts a whole piece into us. I don't, I think that AI code, written code and checking the code, there's all sorts of places. It's really great for, like, if we're doing infrastructure as code, that changes so rapidly depending on the different pieces of hardware that are involved in an inventory of whatever an organization has.
But being able to write the basic blocks of this is a Dell server, this is a, this type of interconnect, this and that. It should be able to get to that and be easy to check and be easy to upgrade once you have, you know, what the differences are and save lots of time, maybe help people learn to code. I think that that should always be that human in the middle that you're talking about.
This is something that, that an AI is not going to identify because there's not going to be a prompt to help it identify, because the human won't know that it's a problem until they go to run. It Could be, I mean, certainly teaching people to code, I, I think AI is a great tool for teachers, especially like code, like, you know, that kind of teaching, you know, very, uh, rote kind of stuff like that. Um, I mean it, yeah, that's certainly a use case, but I think people are using it, you know, this vibe coding thing.
I, I remember the first time I heard it here on the gang and I was like, I was thinking beach boys and, um, but who knew? So, so how do you envision this working in the future? Because in my mind it might play out this way using your statement that says, you know, six months from now the AI will be a lot better.
So are we all gonna get alerts from the new AI saying that the old AI was stupid and an idiot and I gotta go fix all this code? How does that kind of play? Well, let me ask you, do you ever get an alert from a company that says, I'm sorry, one of our junior developers developed really crappy code, but we put one of our good guys on it and it's better now?
No, you're just gonna get an update. Hey, there's a new update click. It's better, it's faster improved.
It's stronger. You'll give Esoteric press release from Microsoft. Yeah.
You know, but We'll see. We've got accumulative update for you. You know, they do that.
Yeah. But There, these updates will, will also mean there's an element here of not just the individual ais get getting better, but as, as you're saying, you, you don't use the same AI to do the code review that you use to do their initial writing. You also don't use the same AI to do the optimization of the larger code base that you use to write the individual features.
And so as we see some maturity, we will see those, those ais uh, getting better at doing the more strategic element. Starting with a, describe how this should work rather than describe the single feature that you want to have, or it'll be describe the path, the, the story. If you're gonna go agile gi give me the story of the user journey through this application and, and the AI will generate from.
So when you're talking about human in the loop, it may well be that we see a very big shift from that human looking at the individual pieces of code and needing to maintain those pieces of code to ai. Looking after all of that, in which case the, the verbose code is, is great, but we're gonna want to then optimize it, do the functionality that we've previously done with a compiler. It's gonna be to optimize and, and enhance the, the code that's actually being written by the coding AI to be better at execution time and development and production execution are two completely different spaces.
You may well not do that optimization until you're getting close to that continuous deployment phase in your development pipeline. So you absolutely, we will be seeing people using different ais for different purposes at different phases of their development as you use different humans for the same thing. I think this is where that 45 degree uplift and effectiveness is gonna be useful and eventually there'll be a critical point where the AI code is better, but we're not there yet.
We're still seeing lots of that legacy code that we're going to see an improvement in sometime in the non determinant future. Right Now, I know we have a predict conference coming up, but, um, here's my prediction for the next year. We're gonna see a lot more stories that start with Company X had experienced application outage because some software updates somewhere didn't go as planned and a lot of it will be traced back to AI code.
Do you think we could retroactively bring the CrowdStrike on it? That will seem like, Because look, what's that, That, that, that may seem like, you know, a mere footnote in history compared to what we might see. Okay.
I mean, it's not like it hasn't happened with humans coding that and that. Mm-hmm. You know, so, and that's a lesson there.
Should we hold AI to a different, uh, level Standard Standard than we do humans just because it's ai? Should it be perfect? 'cause certainly human code's not perfect.
I think we have done, to our credit a better job of reviewing code and kind of preventing disasters. And when there are disasters minimizing the impact of that, I think in the age of ai we may be trusting too much in the machine and not having those review cycles in place. And then we're, 'cause we're all in the name of productivity and speed and break things at all costs, maybe we're not paying enough attention.
I Think someone will have to be held accountable for it, right? Because if the, if there is revenue lost because the code was incorrect or even worse human life lost or that kind of thing, God forbid that it will have to go through, at least in the us the same courts to say you're at fault and you are required to pay this much, whether it's AI or whether it's a human. That's gonna have to happen.
Mm-hmm. It be interesting. Hey, we're about out time.
What a great discussion today gang members. Thank you so much for coming on. Uh, as Mike mentioned, we do have our predict event coming where the, the good analysts of the RUM group are gonna be leading the charge this year in our predictions for 2026.
That's on January 15th after the holidays. com right now, click on Predict. com and you could register for that event.
We've got some great, great predictions and analyst, uh, kind of look aheads. I'll also mention that later today I'm gonna be doing my yearend Shimmy says, my last shimmy says of the year where I'm gonna give kind of my look ahead, uh, for what's been an a year for the record books, that's for sure. Well, we will not forget 2025.
Um, so stay tuned for that. I also just wanna also point out, I'm, uh, shimmy says I did yesterday Thursday on should we Break Up Big Tech? I saw a debate recently, a video of a debate, uh, pro and con on this, and it's fascinating.
So check out that Shimmy says, um, a what about the next Tech field day? Are you guys off till the new year? Yes, I, I'm, uh, doing the planning and organization for the next tech field day, which will be AI Infrastructure Field Day.
Uh, that will be at the end of January 28th, the 30th. It's gonna be a nice big busier event back in Silicon Valley. Very cool.
John, I see a CES in your future. Oh, I think I'm gonna stop by for a couple days. I actually got a a, I reached out to Nvidia, just reached out to me.
They're gonna be doing a big announcement the day, two days before CES starts with Jensen. I don't know what it's gonna be, but last year he talked about physical ai, so maybe something along those lines. Very cool.
Gina, what do you have? I'll be at, um, Alistair's Tech Field Day event, the AI infrastructure next month. Very cool.
All right, Mike, I know what you've got. You are waiting for pictures and catchers to report, And I am not leaving the Tri-state area for at least another 30 days. Good for you.
This is great. Enjoy it. Well, it's not warm though.
All right. I hope wherever, whatever you are doing for the rest of this year and the holidays is, is good and enjoyable. It's a time to recharge refresh, but 2026 isn't gonna slow down, so stay tuned.
We here at Textron, at Techron Gang and all of Techron Fu Tech Field Day, we're gonna try to bring it to you. So check it out. But for now, this is Alan Schmo and we're out.
Hey everyone, welcome back here to Tech Drunk tv. My next guest is David Wang. David is the head of product management at Tet Trait.
David, welcome to Tech Drunk tv. It's great to have you on. It's Great to be here, Alan.
Thank you for having me. Yep. David, we're gonna, we're gonna talk about the AI Infrastructure Foundation, what Tetrad is doing with it, but before we jump to all of those things, let's take a minute to talk about David, if you don't mind.
I, I mentioned you head of product management over at Tetra, but I gotta assume you've done other things in your life as well. Yeah, probably too many. So I won't betray my age, but I'll, I'd love to share a few things about, you know, who I am and why.
Uh, this is a great time, um, for me to be active. Uh, you know, my, I started my career as a software engineer, um, but a lot of my career is folks around finding great use of great technology. So, uh, started in aerospace, spent all time, um, at, uh, management consulting, McKinsey, and ended up mm-hmm.
At a small company called Databricks at the time. Mm-hmm. Before eventually moving on to MuleSoft and Salesforce.
Uh, and really teates a great place for me because we started out in a very, very active area of cloud native networking security, and we've translated that expertise into now AI workloads and protecting AI workloads and AI agents. Um, so what I've learned from my career is, you know, great technology is not super useful or exciting unless you find a great use in application of it. And sometimes it's not all about just the tech, it's about, you know, how people apply it.
I, I agreed. I agreed. Wow.
That's, that's you, you've, you've made the rounds, as they say, doesn't, you're old, you know, it just, you're moving around. Um, yeah, let's talk a little bit about Tet rate. Yeah.
Yeah. So, um, Tet rate has its DNA in networking, specifically cloud native networking, meaning Kubernetes and the like. Um, our core mission was to make networking additive power like a superpower for application developers to make your applications safer, to make infrastructure safer, easier to use and better.
And that manifested itself in the early years of a company as a, uh, service mesh and API gateway product. Um, and it's still actually being, it's still in active development. It's still very much a part of a company, and we have customers who uses it primarily in the regulated industries, if it's in banking, in government, uh, pharma and the like.
Um, and the reason why people want to use, um, tetras product is really that, um, it is incredibly difficult to break the trade off between speed and security and availability when it comes to developing software. And our platform networking platform allows people to break that trade off and achieve all three more easily. Um, how we got into AI is, um, well, how can you avoid AI in the first place, but it's also with a pool from our customers.
So we're already protecting the workloads of our customers in the form of microservices and applications, and it's only natural that they kind of pull us in when AI workloads is really the latest frontier of, uh, different types of like, secure workloads that needs to be secured. Right. So, um, we started this journey about a year and a year and a half ago.
It's a natural extension of our cloud native platform. Um, but we've since made great strides around, and I'd love to tell you about it later. Uh, but today, you know, we are that definitely firing on all cylinders when it comes to ai, uh, as an extension of our core cloud native network security platform.
Excellent. You know, it was about a week ago, we reported here at Techstrong that the good folks at the Linux Foundation had started a new, I always call them daughter foundations, and if that sounds sexist, I apologize, but that's how I think of them as, you know, daughter foundations or, you know, uh, sub foundations underneath the larger LF umbrella. But they started a new one called the Egen AI Infrastructure Foundation.
And what I thought was really interesting is this wasn't just an AI foundation or an AI infrastructure foundation, but specifically Ag Agent ai, because I mean, clearly as we head into this new year, you know, uh, for the last half of this year certainly, and, and in toward the new year, agen AI seems to be where the action is. Yep. And so it's interesting that they're kind of out ahead of it here.
What, what can you tell us about the AI A A IF? Yeah. Um, well, first of all, I would say it's a natural fit for Tet Trade because we are the company who's really behind Envoy and making a lot of the major contributions and which is already part of Linux Foundation.
So, as you said, when, uh, the mothership, um, had, has this new foundation where a natural participant asked for A A IF, uh, I think it's, it's, it's a much needed focus on agents, um, because, um, vibe coding, um, initial AI use cases has migrated, has graduated into building, um, business aligned business value, added even more on autonomous programs in which we generally call, uh, agents. And some people might say, but Alan agents are just software. And sure, in a way it is like software, but it's a very particular type of software and in my view is very different than traditional software.
So if I could think about traditional software, you know, comparing agents with software is like comparing, like riding a bike to driving, like find a jet. Like traditional software, uh, is deterministic. It's kind of like riding a bike.
You, you know, build it, you certify it, you test it, there is a lifecycle. Sure. But, you know, as they say about riding bikes, you kind of like never really lose it.
You know, how to ride a bike agents is different. They're software, but they're probabilistic. So it's not like you build it once and it just keeps on working.
It's more like flying a jet. You have to keep on getting recertified to make sure that you know how to fly a jet and you can fly it safely. And that uncertainty comes from the probabilistic nature of agents.
And until we solve that as an industry how to meaning, how to make sure agents behave correctly is ready for production and delivering business value, um, we can't really reap the full benefits of AI and a foundation such as the Agent AI Foundation to focus on that aspect of ai, the agent aspect of ai and the tools around it, specifically things like model context, protocol, and infrastructure such as gateways, um, to deliver that benefit is timely and much needed. Uh, agreed. Agreed.
Um, so Tetrad is a member, I, I don't know if is the term founding member or original member here of, of the A A IF. Um, and, and certainly I think we'll be seeing bigger plans and bigger things happening with the A IIF in general and in in particular, if it's okay, David, I'd like to pivot a little bit and talk about, uh, this Agent Router Enterprise a, a new product that, uh, T rate has released. Yeah, yeah.
Lemme tell you a little bit about, you know, what, what we're building it for, right? So this is kind of going back to my analogy of riding a bike versus flying a jet. So, uh, early on, AI, a lot is focused on basically the bike riding variety, how to get people to build things fast, put things in prototype, um, and look, I can tell you if there's an ai, AI bubble or not, but I can tell you from talking to our customers, there's gonna be a sorting game that's gonna happen, which is of all the prototypes we build, which ones are ready, which are, which ones are ready for production and delivering business value and which ones are not.
Um, and that is, that distinction is crucially important because the ones that are ready to be declared ready and move on to dealer value will, will stay. And it'll be, uh, hugely beneficial for enterprises and individuals. And the ones who kind of are stuck in this, what I call prototype purgatory, will just languish and it will appear as part of a bubble.
Um, so Agent Router Enterprise is all about helping, uh, organizations, individuals, and teams to ensure that their agents that they were building is actually ready for production, ready for enterprises in real world use cases, especially in regulated industries where such proof is extremely important. Absolutely. Absolutely.
Um, you know, David, we're, we're rec, this is recorded, obviously not live. We're recording it the week before Christmas. Sure.
I can't help but feel that the, the real story here will unfold over the course of the next year, Likely. Yes. And, um, you know, if you could pull out your crystal ball here a little bit and talk about it, um, do you think we really will bring, like standardization around these AI agents and tooling?
You know, I, I've been in security a long time myself, right? And security always lags, security's never out in front. Yeah.
It just seems like, are we being too optimistic to think that this thing will mature this quickly? I do believe from a legal and security stands perspective, it will be very thorny for folks who officially align. But I would say that the pressure, the enthusiasm for leaders to realize the benefit of AI will accelerate some form of readiness, proof or some sort of standardization.
Maybe not in the form of legal, maybe not in the form of book knowledge that folks can burn universities. But, uh, it will be, uh, perhaps heuristics and practices that people will have to rally around. So if you take the example of, uh, A A IF, uh, you know, one of its main pillars is model context protocol.
It is organically emerged as an extremely popular thing, and it's organically being proved at a neck break pace, uh, because enterprises demanded. So, yeah. So I would say legally you're probably right, too fast.
Um, practices wise, probably not a moment too soon 'cause folks are already putting things into prototype and they demand some kind of a value realization. Um, I'll add the bit about legal, which is, you know, AI is not new in the broad sense. Machine learning has been around.
So where Tetrad operates in, in the form of regulated industries, there is practices of, you know, model risk management, uh, for example, in financial services. And many of them have inherited the awesome job of, uh, creating some kind of a standards and controls around agents. And whether they like it or not, whether we like it or not, there's going to be some accountability for these agents that's being built and managed by perhaps these model risk management groups and existing standards such as SR 1117.
Like they will, um, be looked at as at least a starting point. And these teams and these standards do spell out general approaches that today folks are not really ready to meet without something like Tetra Agent Router Enterprise to provide basic information about compliance and traceability and governance. Um, and aside from just the security aspect, generally as the, uh, adoption happens with ai, it's not just a security or governance problem, it's actually an adoption problem as well.
Um, the amount of new technology choices is flooding the market, and it's creating huge problems for builders and engineering teams on what's the best way to go forward. Um, as an individual. It's a, it's the best of times and the worst of times because, you know, you have all these choices and it's great, but it's bad because, um, like after that initial build, how will you create some kind of accountability or proof that what you built is lasting and impactful, especially a big problem with engineering leaders or technology leaders, that there's all this innovation happening in the teams.
Like, how can you actually translate that into provable enterprise value for your executive team? That is a huge problem that's still to be solved by innovators. Yeah.
You know, and, and it's funny because it's a, it's a bottom up, top down the top is pressuring use ai, use ai use ai. Yeah. And then at, at the same, you know, at the other side of their mouth, is this thing working?
Are we making money on this? Is this profitable? Is this, you know, Well, as an engineer, I can tell you that it's definitely working, but as a leader, I can tell you that I'm not sure if I can trust The money.
Yeah. Well, and that is a paradox right there, right? We see it over and over and Yeah.
I, you know, and this is why I say, I think in this coming year we're gonna see this play out and, and hopefully get some answers because you're not alone. Yeah, right. I, a recent survey I saw 90% of developers are using ai, 90%.
I wonder who those 8% are. I would like to meet them. Yeah.
40% don't trust it. 65% thinks it thinks that it's introducing instabilities into the code base. Mm-hmm.
But yet they still use it. Yeah. So it's, it's a bit of a paradox, but I think it will play out.
David, you know, what I didn't, uh, meant to ask you is for people who want to get more information on Tetra, what's the website? io. io.
Yes. And the a AIF f You wouldn't happen to know the website for that, would you? No, but I, I think if you just search for a Google AI foundation, it's all over the news.
And, uh, yeah, it would be a great place to follow the happenings. It's just, just new, but I'm sure there'll be lots of great things to come. That's the beauty of the internet, even before ai.
Um, you can always find this stuff. David, thanks for coming here up on Text Drug TV today. I appreciate it.
No, thank you for your time. It's a pleasure. My pleasure.
Best of luck to titrate as well as to your work with the, uh, A A IF I'm gonna have to learn how to say that better. A A IF and we'll see how this agent router, enterprise product, you know, picks up steam and followers. Yeah.
There'll be lots of more exciting things. Tell, I hope to talk to you about it again in the new year. Absolutely.
Happy holidays and new year. David, David blank, head of product management here at Tet, our tech trunk tv. We'll take a break.
We'll be right back. Hey guys, thanks for the throw. We're here with shahara.
Azule is the CEO of ground cover, and we're having a little chat about observability because, well, the game is changing. We have more, uh, bring your own cloud kind of environments. We're talking about, uh, repatriation and workloads sometimes, and even sovereign clouds are an issue.
And well, we need some way to observe it. And well, right now, that may be a little harder than we think. Welcome to the show.
Hey, Mike, thanks for, thanks for having me. So, walk us through what's changing here. We, you know, historically we go all the way back to, we had application performance management platforms, and then we saw the rise of observability, and, but we now have workloads that are kind of more distributed than ever.
So how does that change the way we should be thinking about observability? So basically we, we see that kind of as, you know, a few waves of, uh, software delivered. It's kind of changed over time.
Uh, if we, you know, roll back maybe 20 years, right? Uh, some of us, uh, you know, remember that that period of time we used to kind of consume software like a physical product, right? It ran on-prem.
We used to purchase it, maintain it. Uh, it was ours kind of, uh, in, in that sense. And, you know, suss kind of changed that, right?
Uh, we used to, we started consuming software over the internet online. It made sense. And, you know, with the boom of cloud, it kind of all connected to the fact that basically we're consuming everything online, right?
All of our services are almost third party managed. Um, this starts to make less and less sense with data rich, uh, applications like observability, security, ai, when the third party is basically holding a lot of data or consuming a lot of data from the customer side, for example, for absorbability, which ground cover, you know, that's our field. Um, we have a, you know, our, our medium customer sends a hundred terabytes of logs per day, you know, to the backend, right?
Sending that over to a suss vendor. That's where the suss architecture kind of starts failing, right? It starts consuming a lot of data.
You start to pay for it. You start to be concerned about data privacy, data residency, data security, uh, you know, while shipping all that over the internet. And that's, uh, where SS is evolving to what we call BYC or bringing on cloud.
So does that mean I need to move the observability platform into something that looks more like an on-premise environment? Or am I trying to get to something that maybe is a little more federated? How will this play out?
So, uh, we we're all used to thinking about on-prem and SUS as a binary choice, right? I'm might running everything on prem, and then, you know, I'm, I'm biting my tongue on management and, you know, maintenance, and I have a team kind of taking care of that. But I gain data ownership, I gain security, I gain, I gain control, customization, whatever I want, right?
Or I choose the other part of the binary choice and just take a SUS vendor, and then I get a managed solution. You know, headache, no headaches, you know, someone is managing it for me. But I lose that sense of, you know, budget control, data ownership data, data and all that bring around cloud is basically kind of the, both, the, the best of both worlds in one.
The data plane is OnPrem, which basically just separates the, what, what is the data? Plane control plane is us. The data plane is on-prem, like you used to thinking about on-prem.
It's yours. It's running in your cloud premises. It's secured, it's private, but the control plane basically manage the infrastructure that all this, all this data planes resides in is managed remotely through cloud primitives.
That basically allows us as a vendor to scale it back it up update features, fixed bugs like you would expect from a sus vendor, right? So you get all the benefits of suss of hands off deployment. Somebody's managing it for me, guaranteeing SLA resiliency while the data plane is OnPrem.
So I don't have to worry about, uh, data cost, data residency, data privacy, or any of these things that I lose when, you know, shipping the data to suss vendor. All right? So I get to have my cake and eat it too, as it were.
Um, we were also talking about the age of ai. And I cannot help but wonder if these AI agents that we're all trying to build will, um, also maybe provide a layer of, of abstraction for engaging with observability data that I may not know, or, well, I'm, I'm probably still gonna care, but I don't necessarily need to know where the data actually resides that I'm launching my query against. Is that fair?
Yeah. And I think, you know, it's clear where the world is going to, right? Uh, anything that is data heavy is gonna be, uh, abstracted away by ai, as they say, right?
I, not everybody can, can be a power user. Not everybody can know how to query their logs, traces, metrics, whatever it be, you know, with a proficiency of what AI can offer. Basically, we can think about it as, you know, the best SRE in your team that you just, that don't have, right?
That knows how to get insights from this data that we collect. Um, and this is exactly where, bring your own cloud, that that's our belief, right? That bring your own cloud is enabler for ai.
Because again, sus kind of wears away a lot of what AI needs to be, uh, performed. You know, one of the things that AI must have is all the data in one place, right? When it comes to sus, I'm already, you know, um, I already have a lot of friction with the vendor about the pricing model, like pay per gigabyte.
I, I'm trying to reduce the data that I sent out. And we see that the, the market is moving away from that, you know, single pane of glass dream into multiple vendors after, you know, organizations kind of optimize the pricing model for each of the verticals and observability, right? They have logs there and traces there to kind of survive the day budget wise.
So that kind of wears out what AI can do because data is distributed. And also, I'm, I'm constantly trying to reduce data volume, sample rate limit, because I don't wanna pay for all that, right? Mm-hmm.
But it comes to bring your own cloud. Suddenly we go back to the basics, right? All the data's in one place.
You can store 10 export data, which with much more cost effective choice. And you also get data privacy and the use of your AI in your cloud. For example, if you're using AWS and you're using Bedrock because you don't wanna send all the data to open ai, which makes sense, right?
You can use Bedrock on top of your, bring your own cloud and basically consume your observability data with the AI agent of your choice inside your cloud premises. So we see it as enabler of people being able to even easier con con consume, uh, data with the abstraction of AI, query data with ai, get insights with AI over the, bring your own cloud, uh, data plane if you want, Right? And if I don't do that, don't I wind up in some sort of weird paradox because I'm limiting the amount of data that I send into the observability platform, so I'm not getting as broad an analytics analytics as I should be, and therefore I'm just kind of making decisions on a narrow based set of data that's probably not helpful.
Yeah, I mean, it's, it, we're, we're, you know, entering 2026 in a second, right? And about three quarters of the world, uh, the organizations of the world, right? Don't have traces.
That's, that's the situation right now. I mean, open telemetry adoption is slow. It's hard.
People don't have traces. So say you ask your AI agent, tell me what's wrong with production, right? Um, it's a, it's only as smart as the data you fit into it, right?
So if you don't want to pay for a PM or you don't want to instrument a PM, um, you know what the AI agent can do, right? Use the data that you have, the logs that you've instrumented, the things that you put in. It's only gonna be as smart as that, right?
So we bring your own cloud with the Eeb PF agent, for example, that ground cover facilitates. It's the ability to, to collect data that that is agnostic to what your developers are doing, but also store masses of this data without being concerned about, uh, budgeting and trade off as much, right? So suddenly you can ask questions, and the AI model will now have much, much more granular data to operate on top of it with all the contextual, um, correlation that it needs to kind of get that insight.
And that where it becomes really, really powerful, because that's where I shine, right? Going through terabytes of data and, you know, getting that, uh, needle in the haystack when all that this data is, you know, granular and contextualize and collect it properly. Mm-hmm.
And I'm not sure everybody knows what EBPF is, but it basically sits in the Linux kernel and kind of gives you visibility up into everything that's running on that version of Linux, per se. Um, does EBPF eliminate the need for open telemetry agents? Or are they gonna be more complimentary to each other?
How's that gonna play out? Eventually, we see it as complimentary, but, um, the reality is that EVPF is, uh, is a, is a different way to observe the data. And the most important, uh, reason for it to be very, uh, effective is the fact that it's completely decoupled from your, what your development or developer organization is doing.
Right? Open Telemetry requires you as an r, as a v, vp, R and d or you know, as an r and d team to take that journey, right? Instrument telemetry, figure out how you wanna use it, figure out how you wanna sample it, what you wanna instrument, and then take on this journey, which again, most organization will never finish, right?
Not because they don't want to, because not everybody knows how to be proficient in something else, but the product they're building, right? It requires a different set of proficiency. EDPF is kind of decoupled, as you say, from the Linux kernel.
It's a Linux kernel capability. I can observe traces going in and out into my application without you doing anything as a developer. So suddenly I get that unbiased, um, you know, kind of layer of observability that will always be there, regardless of whether you've instrumented or not.
If there is a specific point you've worked to instrument with Open Telemetry, great. That's already opinionated. You care about it.
So we'll, we'll enrich that with EPF and make sure that the two combined. It's not, it's not to say that open telemetry isn't important, but it's so hard to get sometimes that EPF is just there to kind of, uh, you know, cast a wide net of anything you're missing, Right? 'cause otherwise, I kind of have to have a set of DevOps engineers who know how to deploy open telemetry so I can instrument my applications that the rest of the DevOps team is installing.
Right? Exactly. Which is not easy, right?
Not, not everybody can, can go through this journey and be successful at that. Hmm. Ultimately, is observability gonna become a lot more accessible?
And I'm asking this question. 'cause when I talk to people, uh, initially they were all, at least, you know, we have monitoring tools and those are predefined sets of metrics, and they're kind of like, well, that's good enough for me, because frankly, I can have an observability platform, but I don't even know what questions to ask it. So are we gonna get to the point now where the AI knows what questions to ask and therefore can really, you know, augment and help me out and make observability worth the journey?
Yeah, but I, I, I think we're definitely going there and, you know, AI is gonna help a lot. But again, I think the problem is so, so much more basic. Most organizations are, you know, in survival mode of the data that they collect, right?
Um, you know, when we, when we think about bring your own cloud from the ground cover perspective, again, you can think about it as an architectural meta method, right? To change the way data is being stored and managed. Uh, we could have stopped there and say, great, you know, the data's run running on your, uh, you know, data play right now, it's in your cloud premises.
Uh, we did our part, right? But that's where we take it to the next level to make observability more accessible. Because one of the things that are most painful right now is that observability is packaged because of that price per gigabyte.
That, you know, that data budget trade off, it's packaged with multiple different, uh, product lines. Uh, most big vendors have 20, 30 different product lines. You pay for log management, you pay for infrastructure monitoring, you pay for a PM all separately, right?
So not all organizations choose to activate all these features. And, you know, again, when AI comes, comes into the picture, if you don't pay for the data, AI is not gonna know anything. So that's where Ground Co, for example, took that choice of, if we're already doing, bring your own cloud, if we're already sa saving the data on your premises, if you're already paying for it as a customer, right?
'cause we, we've separated that equation, now we can package the product differently and we, um, provide all the verticals of observability all under the same pricing umbrella. And therefore, when it comes to ai, all of our customers will have traces, all of our customers will have logs and metrics and so on. And that's, as you say, where AI will come in and basically alleviate a lot of the, um, you know, query language barriers, how to build alerts, how to build dashboards where people kind of get stuck.
This will make everybody a power user, but the data is the most important thing on that journey, right? And once I have that level of observability, well, will I need my traditional monitoring tools? 'cause it seems to me like I could just program the observability tool to monitor things already.
Uh, well, we, we definitely imagine a world where you, you're not, you don't necessarily visualize and set alerts like today, right? It's every, everything is very structured and limited right now. You wanna visualize a specific graph, you wanna set a specific alert.
It'll definitely be much a bit more flexible than that, right? You will correspond with, you know, your observability agent to, to that sense a bit more freely, a bit more structured. And data will be, um, you know, um, much more accessible outside of these, uh, specific use cases where we, we, they're, they're definitely still gonna be there, right?
Of setting alerts, getting them into PagerDuty, you know, waking up at night and all that. Uh, but data's gonna be a bit more, um, flexible to, to access and query and engage with, uh, outside of these, you know, strict, uh, options. So what's your best advice to folks about how to get to where we want to go?
'cause I think a lot of folks are kind of overwhelmed with the, with what the piece parts and everything that has to come together. But is there a simpler way to get started and where is that? Yeah, so I, I think, I think my advice is definitely, you know, figure out if you're, if you're paying right now, is that you don't have all the data or you're limiting some of the data, uh, in, in most cases, the answer is yes.
If, if, so, I think you need to look into alternative architectures and alternative data collection methods like EVPF or Bri on Cloud. com and see that in action. But it's just an example of how the, how the market is shifting towards, uh, new data collection methods, which, which are easier and new architectures for observability that makes sense, right?
That are scalable, that allows you to store the data that you can, so that you can definitely query it, you know, with AI and with all the use cases we discussed. All right, folks, you heard it here, observability. It's really a data management problem and work backwards from there.
Hey, Shahar, thanks for being on the show. Thanks for having me, Mike. All right, and back to you guys in the studio.
Hey, everyone, welcome back here to another text on TV interview. You know, I'm happy to have my friend Scott Gerlich on. We were, we were talking before we started rolling on the cameras.
I think the last time I saw Scott was in person in Boulder. And, uh, it was years ago, years ago at the Foundry office, and you know, him and Joanie and the rest of the, uh, stock clock team. They were really, I, I think at that time, Scott, I would say you were still molding market fit.
You know what I mean? You were, yeah. You, you, you kind of had the idea of what you guys had wanted to do and, and it was about market fit.
Of course, stack Hawk has come a long way since that. But before we get into that, Scott, give people a sense of, of who Scott Gurley is. Yeah.
Awesome. Thanks. First of all, thanks Alan for having us on, having me on.
I always enjoy talking to you and the tech strong audience. Um, yeah. I'm Scott Gerlach.
Uh, I'm the co-founder and chief security officer here at Stack Hawk. Uh, my background is actually running security teams. So I ran security teams at GoDaddy for like 10 years, was the CISO at SendGrid, uh, for three years.
Uh, so in charge of, you know, running different security teams, application security happened to be one of those almost every time. Um, and when Joni was out doing some research on the space, she and I got connected and had a really good chat about things that are really screwed up in application security. Um, and we, we set out to kind of try to help fix one of the biggest problems, which is just developers are the last to know about security problems in code that they write.
And we were trying to flip that on its head a little bit. So that's, that's sort of how Stack Hawk started and, and what my background is. And this is my first foray into, uh, founder of Startup Life, which is a little bit different than Security Guy Life, but not totally different.
Well, so I, I've done that too, you know, um, I I would, I would say this about it. Scott, you didn't take off one hat to put on another hat, you just put one hat on top of the other hat. No, that's right.
Right. That's absolutely right. And, and, and, and everything that goes with it.
So basically you're working twice as hard, but you know, you, you, you don't start a company as a founder, co-founder unless you have a real lot of passion for what you do it. Yeah. And so hopefully, you know, that compensates for wearing the two hats, and, and God knows, when you first start a company, you wear more than two hats even.
I wish it was only two. That's, that was what I was thinking when you said That. Well, what, you know, what I, I've heard people say that's their philosophy to startups is as the company grows, you take less, you take hats off, and that's how you know your company's doing well, you're wearing less hats as, as the founder or co-founder.
Yeah. Um, and, and there's some, I think there's truth to that. Um, Scott, you know what?
Well, and how, just to give people a sense, how long ago was this? Yeah, 2019 is when we started. So Stack Hawk has, has been around for some really weird stuff in the history of the world, COVID and bank failures and market turns, and now AI stuff that's happening.
It's, there's some, there's some weird things. I don't know if it's Irish or Chinese people tell me all different, you know, origins. But the, the proverb is, may you live in interesting times.
Well, I think we've done that pretty well so far. Yeah. You, you have, you've only existed in interesting types.
Um, so, you know, the mission was doing AppSec better. I, you, you know, it's interesting, Scott, I interviewed, uh, last week, my friend Jody Bonzo, who's the CEO founder of Harness. Yeah.
Right. And, and harness. I mean, they just announced a huge round and a huge valuation, huge valuation.
Um, but, but he, he, he said, you know, one of the things his credits to his success was his vision has stayed center the whole time, which is, there's a better way to do cd. There was a better way to do cd. And that's what they set out at Harness.
And over the course of that, you know, they've added security, does SEC ops even to AppSec into it. They've added now AI into it. They've added, you know, as a service into it.
But the core is still do CD better. Yep. And I think it's similar, similar to in Stack Hawk, it's, it's due AppSec better.
Yeah. Stuff has happened, stuff's been added, but it's still, that's, that's the mission. Yeah.
I think, you know, when we started Stack Hawk, the whole, the whole idea was we were able to ship code because of things like Harness and CICD systems that gave us the power to get code into production at a pretty fast rate. Um, and the idea was every time at the time, security testing or application security testing was really focused on, I know about this one or two things in production, and it gets changed every now and then. And so we'll test it in production, make sure there's no problems in it.
And at the time when we were starting to ship software pretty fast where people are making changes and deploying once or twice or three, or, you know, seven times a week, that kind of methodology is just sort of broken and it, it doesn't help you stay on top of what's going on with, uh, applications and APIs that are getting published. And it doesn't enable the business, right? It doesn't help you go faster.
So the whole idea was how can we, how can we pull that in to be part of the development life cycle so that as we're publishing stuff, we have high confidence that there's not security vulnerabilities in it. That problem got exponentially worse when we started introducing LLMs and, uh, coding agents that can help you not only ship code, but write code at an insanely fast rate. So I know a ton of engineering teams that are, you know, eight x 10 x more efficient at writing code and delivering value to production and are application security programs largely haven't evolved anywhere near that speed.
Um, and so our problem has just gotten worse along the lines of, can I keep up with what's going on? So that's, that's where Stock Stack Hawk started out. And what we were trying to help, uh, application security teams do is just, you know, understand what's out there.
First of all, what's my, what's my inventory? Second of all, how safe is it? Are we testing at a, at a reasonable cadence and are we putting safe software out in the world and enabling the business to go faster?
I always, when I talk to some of our customers, I always say, my goal is so that when someone comes to you, whether it's the CISO or the CEO to say, how's our security posture, I want you to be able to say it's great, go faster. Instead of what kind of happens today, which is like, uh, I'm kind of keeping up by the hair of my teeth. Uh, we're Okay.
I'm by my fingernails. Yeah, exactly. Um, so that's, that's where we're, that's what we started out to do, and we're, that's what we're still doing and we're, we're helping a lot of customers do that today.
Very cool. Um, look, we only have 15 minutes. I'd love to dive in more and go, you know, through a lot of recent stuff with you, but we could, but we'll see each other and hopefully in person in RSA and we'll go dive deeper.
But I love that. But I wanted to get to, um, news you guys recently kind of in Yeah. And we wanna leave time for us to discuss that.
Why don't, if you don't mind, share it with our audience. Yeah, it was super exciting stuff that's coming, uh, from, from our engineering team, specifically business logic testing. And the thing that's really exciting about it is not that the problem is new, it's that the solution is new.
Uh, and so, you know, business logic testing has been around forever where people are like, okay, if I add an item to the cart, how many times can I apply a coupon and then make you send me the item and money? That's been business logic testing forever. The problem has gotten worse because of this code, um, code explosion and API explosion where 37% I think of recent breaches have been due to authorization issues or kind of this business logic problem that exists in APIs.
Um, that's a, a wasp stat recently. And the ability to, you know, do business logic testing inherently was upon the AppSec team or the security team. Like they have to understand how things are supposed to work and then be able to write tests to do that work, really expensive process.
The really cool thing, as scary as AI is for an AppSec person, it's also this huge opportunity to be able to do a bunch of, was impossible stuff. And this is kind of one of them, which is use AI to do its probabilistic, uh, action and kind of understand how an API was intended to be written by looking at it, looking at the API, kind of decomposing it and being able to go, I understand how they intended this API to be used like with some certain, with some certainty. And then use that information to then test the API for some of that business logic problem.
And that business logic problem could be authorization issues, whether it's cross user, cross tenant, like this company shouldn't be able, company A should not be able to see company B's data, user A, user B, those kinds of things. But then also stuff like, can I change Alan's, uh, password via the via the API itself? And so those, those are some of the authorization issues that exist.
But the cool thing is, um, a couple of things. One, uh, the Stack Hawk dynamic testing engine, the Hawk scan, um, are dast, for lack of a better term now, has this intelligence built into it around APIs. It can look at an API and go, I understand how this is supposed to be used.
Then exercise it that way and gather, capture all the data that the API is returning while you're making calls. So if I have to register a user and it returns a user ID and I need that in the rest of the API, we can now do that very, very simply without other user interaction. That's the first part that's really cool.
It's called the Smart, smart Crawler, uh, smart Crawl plan. The second part of that is then using that information to look at the API and go, okay, this looks a little fishy. I should go test this with a user or multiple users to make sure that we don't have those authorization issues.
Um, and so that's, that's the stuff that we've released today. But the really, really cool thing, those are very cool as well. I'm super excited about that because it's the foundation of being able to do, take the AI and look at the API and come up with test scenarios that we wouldn't normally have done ever.
Uh, and then be able to build more deeper business logic testing across an API or across many APIs in the organization. Uh, today we started with that Smart Crawl Pro plan and some of those authorization, uh, detections, but there's a ton more that we're continuing to work on and deliver, um, for, for the customers out there. So business logic testing is what we're doing.
Absolutely. Now. So I'm really proud of ourselves, Scott, here we are.
It's the, we're we're more than 10 minutes in. We really didn't talk a lot about ai. Right.
Which is unusual. Unusual. But you, you did mention how much more code is being generated.
Yeah. And a lot of that code, you know, face it is AI generated code. You know, we had a discussion on Text gang this morning.
Have we reached the point where AI generated code probably has as many vulnerabilities, so human generated code versus a, a human written code, AI written code. What, what's more insecure? What's more, you know, that's more, and yeah, I saw a, a actually a survey from Veracode that actually it's approaching parody.
Mm-hmm. It 'cause it keeps getting better, but nevertheless, there's also a lot more code if we need to, you know, you know what the bane of all testing is. There's never enough enough time, never enough time to finish my test, uh, you know, scheduled.
How scalable is this business process testing? Yeah. Uh, I think it's pretty scalable.
The, the testing is not as fast as a normal testing, but it's less destructive. So when I say that, I mean our normal kind of what we do is, uh, specifically kind of behavior testing, right? We're checking how that written code is behaving while it's running, whether that's in production or in test environments or whatever that is.
And I would actually say that, um, the how a, how an API behaves is probably more important than, is it spelled correctly for lack of a better term? Because I agree that parody is happening with AI written code and human written code. Um, and there's just some things you can't find without testing the behavior.
Yeah. So the, the thing that's super interesting about, um, what's happening with this business logic testing is it can be very focused where you want it to be focused. And we're trying to help teams understand where the most important things to test are, whether that's, um, what APIs are handling PII data or PCI data or PHI data, um, as well as how frequently are they changing.
So the rate of change that's happening in the code base is equal to how risky a thing is. So helping people understand where should I be testing to get the most bang for my buck? Because to your point, I can't test everything and get all of the alerts because that's not gonna get me anywhere.
I have to be pretty focused and intelligent about where I'm testing and what I should be fixing. Um, so scalability wise, I think it's, I think it's pretty, pretty good because we always advocate people test on smaller microservices as part of CICD systems, those kinds of things. So wiring it into the, the release process for most of the code really enables that kind of testing to be super scalable and it's very focused and it's very much real when it pops a thing, when it pops an issue and says, Hey, there's a problem.
Agreed. Agreed, agreed, agreed. Um, Scott, it, it, so is this like part of the, the whole Stack Hawk system, is this a separate module that people are just interested in this can buy?
What, what's, you know, how is it, how is it going to market if you will? Yeah, so it's part of the Stack Hawk system. Um, it's part of, uh, there's a couple of, there's basically three things that are part of the Stack Hawk system.
One is discovery, and it's part of discovery. So we can, as a dynamic testing, uh, company, we can actually look at code and help you understand what APIs you're building, how often they're changing, which ones you should be testing, where, what code is building those APIs. Then obviously the testing part is really important, making sure that we're surfacing the right things, helping developers understand those problems so that they can fix them as part of the development cycle.
And then the oversight of what's going on across those different pillars, uh, of the program. So it's actually part of, uh, discovery and also testing because we can not only look at that code and go, Hey, there's an API here, but in open API land, we can build an API spec out of that code and then we use that API spec to do the testing. So those two things are, are part of this program.
Um, you can do the testing without the discovery part, but most people that I talk to don't have open API specs. So that's why we built that for them, uh, to enable, you know, not only the visibility, but enable stuff like this kind of testing. Absolutely.
You know, it's interesting, there was a time a couple years ago where API security was its own category. Yeah. Companies just API security companies.
And you know, like the lesson I learned in my still secure years was, especially in security, a lot of programs or a lot of products become features. Mm-hmm. And, and the whole API security thing has become features.
Right. Yeah. And it is a great example of it as well.
Scott, we, we are about outta time for people who want to get more information from Starhawk and specifically about this business logic testing. What, what's your advice kind of, where should they go? What should they do?
Yeah, if you want to come check out what Stack Hawk is doing, you can always visit our website and get ahold of us there. com. Um, and then I know we've got a bunch of stuff going out on our LinkedIn channels.
Oh, our LinkedIn page is obviously Stack Hawk, maybe not obviously, but hopefully, obviously Stack Hawk. We keep posting a bunch of stuff about business logic testing, some of the new stuff that's coming out of the company as well. So you can always give us a follow on LinkedIn.
Um, those are two of the many channels that we're putting in information out. Uh, and you can, you can follow along with us. Alright.
Hey, say hello to Joni and Casey and the rest of the gang out, out there in Boulder. I do hope to see you in person a few months at RSA. Same Good man.
Have a great holiday and happy New Year. Very Quick. Thanks Ellen.
Do you do the same? Have a great weekend. Alrightyy Scott Garlock, uh, co-founder at Stack Hawk.
Go check them out. Business logic testing. It's another thing we're solving Delicious BLT sandwich.
Yeah, That's one way. Um, it's about lunchtime. Anyway, we're enjoy, stay tuned for more text on tv.
Hey guys, thanks to the throw. We are here with Karen Oli, who's the CEO for Leo Stream. And we're having a little chat about well, vendor privileged access management.
It's a problem out there because we have so many people that we're trying to partner with, but we don't know exactly what they're doing once they get into our environments. Karen, welcome the show. Thank you very much, Mike.
It's always a pleasure speaking with you. Thanks for having me. This has been an issue for some time, but I feel like it's getting worse because the bad guys have kind of figured out how to attack our supply chains and they, they navigate and start to move laterally and all kinds of bad things happen.
But, um, do we grant too much access to these other vendors out there and how often are we actually managing what they're doing on our networks and our systems? Yeah, I think that's the problem is historically we have been, I don't wanna call it lax, but it is just simple to wrap vendors into the same systems that we use to manage access to our employees. So maybe that means, um, adding them into our VPN or whatever other remote access solution that we have, but the way that we manage employees but needs to be fundamentally different from how we manage vendors because these are outside people who we are giving carte blanche access to our network to.
And that is just becoming, as you pointed out, more and more problematic over time. And we don't seem to know exactly what kind of defenses they have in place. So for all we know, once we let them in our network, they've already been compromised.
But how do I make some sort of assessment of what somebody's actual cybersecurity posture is, um, without just sending 'em a form and hoping that they my scouts on or tell me the truth. Well, that's the thing is, and, and I've gotten these as a vendor for some of the people that we work with, is they send us forms to say, what's your cybersecurity stance? But even though we do have a good cybersecurity stance, you shouldn't trust me when I tell you that and I shouldn't trust you when you tell me that instead of relying on these forms and questionnaires, you need to put an actual plan and solution in place to essentially force them to adhere to what your cybersecurity policies are.
So making sure that people ensure MFA when they're accessing your systems and enforcing that. A vendor can tell me they do that, but I need to make sure that they really are. And I do that by implementing services and solutions and my network that they have to use.
How much of this is also part of the human condition where we just get attached to other people and they work for other companies, but we kind of start to treat them like they work for us and the next thing you know, something bad happens. Yeah, there's definitely some of that. When you've worked with a vendor for a long time, it, it can become difficult to say, well now I need you to use this different solution.
And I I I am kind of telling you that I don't trust you. And it's not necessarily that I don't trust the vendor, it's just that people, people make mistakes. I may accidentally click on a phishing link and now if I have credentials for your systems and I've become compromised purely by accident, well that compromises you and you need to make sure that you're not, you're just protecting yourself from situations like that.
Mm-hmm. Of course I would just tell people, well, I trust you, but Karen, she doesn't, so we have, I don't trust anybody. Not anymore.
Not these days, man. And well, to be honest though, you can't always be sure that somebody is who they say they are because there's now digital fakes and all kinds of interesting things that are going on out there. So even if somebody kinda looks and acts like somebody, you know, they might not be right.
That that is very true validation. You have to validate people's identity usually using more than one factor. It's, yeah, it's a scary world.
Right. And will it get worse with the rise of these AI agents because theoretically they are quote unquote digital employees that are now accessing things on behalf of my vendors and, um, god knows what they're doing. Right.
Yeah, no, that is a very interesting point. And a good, a good thing for people to think about is, you know, we talk about managing vendors when it comes to third parties who we assume are people, but at some point in time, yes, you need to take those policies out and expand them to include these AI entities as well. So what am I supposed to do about all this?
Because there are some legacy technologies out there, but I imagine they were created for a different era. But is there another way of thinking about, you know, vendor privilege access management? There definitely is, and I think the, the key is to, again, not treat them like employees.
Think of them as vendors. You may like them, you may trust them, but you d do need to put different solutions in place that, um, basically allow you to adhere to zero trust policies. So only give them access to the limited number of things that they really need instead of giving them a full VPN connection to your network.
So use some sort of zero trust architecture that not only auth, authorizes them to trust the right resources, but also has a time bound policy associated with that. So they can request access and you have to approve it and that approval is for a certain period of time and when it expires, they can't come back in that way. Even if they're compromised later, well their session has expired, it's enforced through the services that you're using to control their access.
They can't get in anymore. So who's in charge of these kinds of issues? Because I sometimes feel like, well, the cybersecurity people are generally aware of it, but they have no idea how many vendors they are and who's in charge of what.
And then there's the business folks who, um, you know, they have a handle on how many vendors they're working with, but cybersecurity is never top of mind for them. So where does this fall in the, in in terms of who's responsible? It really is kind of interdepartmental.
'cause I know, I know me as the CEOI have a vendor spreadsheet. We know who our vendors are, but now I need to make sure I'm talking with it to say, okay, now you need to put policies in place and actually implement plans based on those policies that control the access that these different vendors have. So it really is, again, cross department and communication as it is in many cases is, is the key there to make sure vendors don't fall through the cracks and policies get put into action.
Mm-hmm. Do you think that the auditors and the regulators are starting to figure all this out and starting to ask tougher questions about this stuff? Oh, I think that's definitely true.
I think there's, there's more accountability now. So you need to not only, again, it's not just good enough to have the policy, you have to have the plan that backs it up and then implement that plan. And people are looking at that now too.
It used to be you could say, look, we have this policy, but now you have to prove that you're putting the policy in place. Do you think also that maybe we're getting to the point where, you know, companies will fire vendors for the lack of security controls and governance issues and this will become something that, you know, there'll be a little teeth in these evaluations? Oh, absolutely.
I mean, we even, we have cases where we've had to invoke our incident response plan because we've had a vendor who's done something that was, uh, not, we didn't have a, a hacking type incident, but it's still, you have to hold your vendors accountable. And if they aren't resolving issues that they have and proving to you that they can be better, then, then yeah, they're gonna be put on notice. We talked about AI being used by the bad guys, but it occurs to me that, well, maybe I can use AI to kind of evaluate the security of my vendors and make some assessments of that, because otherwise it's kind of a hard job to do and don't really have the time and capability.
So will this get easier for folks to do? Maybe, hopefully, You know, that's an interesting question. We're actually just starting to adopt AI into our business workflows and look for ways that we can implement it.
So maybe I'll look at that one. Uh, think about how we can leverage AI to manage our vendors a little better. Alright, I think so what's your best advice to folks?
Because honestly, I think some of them look at this and they go, I understand the issues, but it's a daunting task and it's so overwhelming that they just don't get started. Well, I think that's the key is to look at a little problem that you can solve and then expand from there. So when we talk about vendor access, it's really about, okay, can I find a simple solution that'll make it easy for me?
If I have a vendor who's doing maintenance on a couple operating systems or just needs to maintain my database or install some patches on a server, can I take this one little use case and make it very simple to secure that better than I am right now by finding some sort of vendor privilege access management solution? And so that, that's the key is just, you know, the world is big. Can you find a little problem and start from there?
And I think the, the concept of just securing third party access to a particular server or a particular application, that's a pretty small little problem to solve. And then you can kind of expand out, Is there an a to this? Because inevitably someone will complain about whatever security measures you put in there because they added friction to a process.
But I mean, what is the tolerance for additional friction? And how far can I go before everybody starts to rebel? Uh, I think that's gonna depend on the person.
Some people are so security focused that they're okay with a little friction, but some end users don't like any kind of change in any sort of experience that they have. So some of it's gonna be case by case, and then some of it's gonna be mandated by what your organization requires that people essentially put up with. But again, the key is to find that balance.
Can I find something that's simple enough for it to implement and simple enough for end users to use that if there's some friction in the fact that, you know, they have to do MFA now they're okay with it because otherwise it's, it's simplifying other aspects of their life. So ultimately, what's your best advice to folks then as you kind of think this through for a minute, um, you know, should I have a big meeting and convene everybody and kind of make it a giant corporate wide initiative? Or, you know, to your earlier point, do I just kind of like go after it one at a time until eventually I get my arms around it?
Again, you've got the cross departmental, so there's somebody on top that's kind of thinking of it from the overarching, oh my God, here's everything we need to do standpoint. But when it comes to actually implementing the solution, yeah, narrow it down. Find some simple use cases that you can tackle and then expand out from there.
Because if you try, as they say, if you try to boil the ocean, you're not gonna get there. All right, well folks, you're heard in here, zero trust. Even if you know them, it's a good idea because well, vendors change, people change.
You don't know who's on the other side of that contract anyway, but eventually something probably is gonna go wrong. So better to be forwar and forearmed than to suffer the consequences. Karen, thanks for being on the show.
Thank you very much. Thanks for having me. All right.
And back to you guys in the studio. Hey everyone, welcome back here to Techstrong tv. I'm so excited to have my next guest on, you know, we were talking for way too long in the green room before we got on, but the first time I, I interviewed my friend Andreas Prince.
It was at a, I I'm not even sure if it was a DevOps world or a Jenkins world still, but it was in nice France way before COVID. Good times. And, uh, you know, we've been talking pretty regularly ever since then.
So let me introduce you if you don't know to my friend Andreas, and Andreas is the head of sovereign solutions at SUSE now, but, and Andreas is, oh man, he's had a storied career and Andreas welcome. Thank you. Thank you for coming on.
You know, I, I hope I didn't embarrass you, but give people a sense of your journey. Yeah. So our journey, right, started indeed in nice, I do think it was the first year they left Jenkins world and called it DevOps world, right?
They were really trying to bridge, uh, but I started very much in, um, in actually in digital transformation. So helping organizations to pivot to more agile phos pace ways of working. Did a lot of CICD automation, release automation type of companies.
Uh, and then the last startup was all about observability. And that was acquired tech state by Susan. And then I joined the bigger family, which is really, really interesting, uh, because all of a sudden there's much more power, right?
Than rather having a single product you all of a sudden, uh, can influence platform polio. Um, mm-hmm. So I'm now global head sovereign solutions and building actually our proposition around sovereignty, taking our products to markets, finding new partnerships, and, uh, yeah, really helping out Europe, middle East, Africa to become more sovereign and more autonomous, if you like, from a IT perspective.
Yep. Thanks for that, Andreas. And, and congratulations to you on this role.
I, I couldn't think of a better person for it. You know, Andres, the whole idea of, uh, it sovereignty, uh, sovereignty, data sovereignty, cloud sovereignty is really come to the forefront over the last year or two. We are living in, you know, I wasn't alive then, but in the, in the lead up to World War I, and let's hope this isn't a lead up to another war.
But in the lead up to World War I, we saw sort of old empires dying out, new nations, emerging new alliances, new new ways of doing business, you know, because there was a bit of an industrial revolution going on there too. You know, the Austria-Hungary empire, the Ottoman Empire, they were breaking up countries like Italy and Germany, you know, were new, new countries back then as modern countries. We, we look around today and we see a little, not exactly that, but we see similar kinds of things the EU arising as, as a, as a power in this multipolar world, right?
It's not just the two superpowers that you and I grew up in the world of. Um, technology is just changing our lives and, and the promise of AI and what it can bring. Yep.
At the same time, we're also seeing, we're seeing a lot more violence. We're seeing authoritarianism, we're seeing, you know, uh, different factions fighting for freedom, freedom of the press, freedom of speech, freedom of information. It really is a pivotal moment, I think, in history when we look back at 2025.
Yeah. In many ways, 2025 is gonna be the first year of this new century. I think for the first 24 years we were still living in a 20th century world.
Yeah. It's been changing, but now clearly we're not in the 20th century anymore. We're in the 21st century.
And sovereignty is, is part of that. How do you think, how do you feel about that? Well, I, couple, couple reflections on that.
So, one of them, right, is I do think the first 25 years has helped us to accelerate when it comes down to an innovation perspective, right? So all the cloud native, uh, application landscape, et cetera, right? Help us now to run AI workloads in a very controlled way, right?
So the first few years have been needed to accelerate and innovate where we are right now. So there's definitely a connection. But I do think we're also entering a very interesting phase, because you could argue the entire sovereignty thinking from an innovation perspective is a bad thing, right?
Because Europe is a kind of closing Middle East Africa, right? So we're making the world smaller because all of us are focusing on our own geographical, jurisdictional region, and sometimes even down to a country. And when you think about innovation, right, where you need mass to really accelerate and experiment and whatever, I do think sovereignty as such might be a bad thing when we look back.
However, I do think where it's a really good thing, and that's also what we see happening at our customers is companies, executives, leaders, they all of a sudden, well wake up, if you like, to understand their dependencies, their dependencies on hyperscalers, their dependencies on the chips. They use their dependencies on the entire software supply chain. And I do think that awareness is a really good one because A, you need to determine your levels of business resilience.
And it obviously contributes big time to that. So the positive side in my mind of the entire sovereignty movement is that we see a reassessment of risk. Um, right?
No longer is a data center, below C-level, um, a threat, but it's an opportunity compared to an American hyperscaler. For some companies, they were in the past, we would've made a different choice. Um, so bottom line, right?
I do think it's just the next transformation that we'll go through in our thinking, and then also followed by our IT choices and implementation in, uh, in engineering. I love it. And I don't disagree with you at all here.
Um, it, some of it makes me sad because I do think, you know, as, as a, not even a child of the internet, I was already an adult when the internet, you know, went public, went commercial. But as, as someone who spent their career in the internet, let's say, um, I love the i the global nature of it Yeah. That we're all one, one community.
Yeah. And, and this sort of thing, you know, building walls, I always like tearing down walls. Yeah.
But you know, this, this is the world we find ourselves in. Yeah. Andreas SUSE has a, an aggressive sovereign solution product line, if you will, or vision, right?
Yeah. It transcends just Linux or rancher, Kubernetes or SUSE software. Yeah.
It, it goes to the heart of the data center and support sovereign in every sense of the word. Yeah. Expand on that for us, if you don't mind.
Well, if you, if you think about right, that the world becomes or gets smaller, right? Or people start to look at their, at their, uh, continents, if you like. Um, then the question is, what is still helping you to cross, uh, to, to, to, to step aside, right?
Cloud Act or Cyber Resilience Act here in Europe. And then I do think there are only a very few elements that are still helping us to build software that can be used across the world. And that's open source, right?
So the direct effect of using open source is it gives you the freedom, right? To build it yourself, to create it yourself, to enhance it, and to, to, to use that to your own, um, needs. And I, what we see happening here at, at SUSE is air opensource was obviously always our top, our top lever.
Uh, but today, fascinating enough, all of a sudden, the market is also requesting IT proprietary software, right? Where they don't, or are not able to assess the risk is no longer suitable for governments, uh, for public sector, for healthcare, for mission critical, um, industries. So the fact that suse, right, as a firm believer of open source has that at the core of their DNA well, is really beneficial for us.
So what we're doing is we're not only have bringing our existing products to the market, but we're also rethinking is, hey, but what does it mean that we have features like, for example, reproducible builds, right? That you can build anywhere across the world in any data center. You still get the same version of the software out.
What does that mean from a sovereignty perspective? Um, and we see and start to learn and have learned in recent months that we have a lot of diamonds in our portfolio that are perfectly suitable and powerful for a, for a sovereign solution. Um, and then we start announcing that with sovereign support, eh, as an example where we say, Hey, for Europe, if you wanna use open source, but you still want to get enterprise support, we have a solution for you as well, which is sovereign premium support.
So that's really what we have. And then we're adding on top new features, new services, uh, new partnerships to, um, to expand. We're gonna, we're gonna dive into that in a moment.
I, I think there's a, there's an interesting or an ironic kind of piece to this, which is at the same time, as you say, we're making smaller, we're putting up these walls, we're also relying on open source, which is the ultimate wall buster, right? The ultimate uniter. It unites us all.
We all can, everybody can use open source. We're using open source to build this sovereign, uh, offering. And, and that, you know, there's a, there's like a, I forgot, not a dichotomy, but there's a, an interesting paradox there.
We're using open to do sovereign, yeah. Closed, yeah, yeah, yeah. Make Closed.
Well, and I, I would re I would not use the word closed, I would say to gain control, right? Because ultimately it's about control, right? Knowing what is the software used, what are the packages in there, uh, what are the libraries being used, the vulnerabilities, the license types, right?
And open source helps you to assess that very quickly and very clearly. Absolutely. Andreas Souse recently announced a partnership and alliance with evoc.
So I don't know if everyone in our audience is familiar with evoc and certainly with this recent announcement, why, if you don't mind, give us a little evoc background. Yeah, definitely. So EVOC is a brand new, um, M-S-P-C-S-P really focused on helping governments, public sector, mission critical companies in Europe to increase the level of sovereignty by providing an infrastructure, a modern AI platform that is entirely European.
And when we speak about entirely European, the data centers, uh, the personnel, the type of support that is delivered, um, and that's then bundled with lots of open source software that they can support or are supported by companies like suse to build a stack on top where, um, companies can actually make use of, so imagine right. Governments, um, that say, Hey, I want to decrease my dependencies for my crown jewels, my mission critical applications on an hyperscaler, not for all workloads, but for a few, are there alternatives in Europe, right? Where I can put skill, um, and, and, and put my workloads on.
And that's actually what froc is doing. So they have data centers across Europe. Uh, they're continuously expanding, um, but they're really, really sovereign.
So they're founded pretty recently, only a few years ago. So they start building it with sovereignty in mind and with a modern approach in mind. And, um, yeah, that's what goes really well together with, uh, with suse, if you like.
I love it. Um, talk more about the strategic alliance. Yeah.
So imagine, right, a customer who would pick a company like SUSE to say, Hey, I would like to have a, a full stack from a software perspective, Linux virtualization, uh, cloud native rancher management on top, um, without sovereign infrastructure, right? You are a sovereign as the infrastructure, you run it on, on the EVOC side, right? They could argue saying, Hey, we have a very sovereign infrastructure, but if, uh, the sovereign on top isn't sovereign, you're still a sovereign as the sovereign that runs there.
And that's really what we would like to achieve and have achieved by merging the two, using the infrastructure from froc, and then the software from SUSE on top, the Linux layer, the cloud native layer is really enabling customers to pick an entire sovereign stack and start migrating workloads, uh, head containers or virtual machines towards that stack. And that's then combined, and that's also the strategic element here with sovereign support from both parties. And because that truly makes the solution, uh, sovereign.
So it's infra software and service from both parties combined, which is our sovereign offering that we've brought to the market together with avo. We love it. Now, look, I get that a lot of this is aimed primarily at Europe, but you mentioned the Middle East and Africa.
Yeah. Um, are there plans for data centers in the Middle East and Africa, people based there, or will they use Europe sovereignty, if you will? Well, so, um, so the couple, couple very interesting moves going on.
So Europe is definitely a trusted body place, country, right? So when software comes from there, it's very often what we see happening, accepted, for example, in Africa as well, right? So software created here, um, is very useful when it's open source in the other two regions, middle East, Africa, but also countries like Japan, right?
So that's, that's why it's really, really global. Now, from a data center perspective, right? There's another challenge you need to solve, and that is what is your vision or where your data from a jurisdictional, uh, perspective needs to be?
And what we see happening is that data centers in Europe, right, are not sufficient to host, for example, a South African bank or, uh, whatever bank or insurance company that is out there. So they still pick, um, local data providers. And same to Middle East, right?
Middle East is not a single region, right? Multiple countries with all their own rules and their own philosophy when it comes down to where the data needs to reside. So although, right, our ever partnership is absolutely the first one, right?
That, that tick all the boxes from a sovereignty perspective, obviously, right? We have partnerships across the world when it comes down to, uh, to data centers. But what we want to do is really help them to increase the levels of sovereignty, um, as such, right?
By, by software and by support that we could, uh, that we could deliver. Yeah, Absolutely. An important element, a lot of people think, right, that it's that sovereignty is, is black and white.
So they say, yeah, we now need to leave. All of us need to leave the hyperscaler and move to a party like EVOC or whatever data center here in Europe. And I do think that's a wrong philosophy.
You first need to assess what are the most important crown jewels or the mission critical applications. These are the ones you need to consider and probably still conclude, right? That you can run them on an, on an American hyperscaler because your business simply runs and in the US and runs in Europe, right?
So you de-risk Europe, but there's, there's no reason for doing that. Um, so governments, for example, they can take a bit more an aggressive approach, um, and they're moving, right? Or they're at least decoupling their hard dependencies to the, to the hyperscalers.
But I do think people really shouldn't see it as a black and white. Uh, but really as a nuanced approach, some ordinary workloads, well let them easily scale up and down at an hyperscaler, right? Versus some mission critical ones that you would like to protect with data and whatever you could run on a European data center.
And I do think we're quickly losing that balance. Um, but that's a very important one to, uh, to add to the, to the conversation. I, I agree.
A lot of it is about data, right? Yeah. And, and, because that's really, now, yeah.
The, the question may become, if that data ran on this application and this application's not in a sovereign, uh, uh, stack, do I have stickiness to go get that data? 'cause it was in that, you know, it ran on this application, and that's where bifurcating data from, from the app really, I think will, will come in. You know, there's something else I want to state on here.
For those of you watching this, this isn't about EU versus us or US versus China, or, or, you know, just nation states like that. Even here in the US and js, you know, we have, we have some states where certain medical procedures are illegal, and in other states they're legal and doctors can prescribe medications and so forth that they may not be able to prescribe in a different state. Yeah.
And so some states in the US are looking to have sovereign data that is not subject to the, the, the prying or discovery by a different state. Yeah. And those are states within the US even.
Yeah. So, you know, this is kind of a worldwide trend that we're seeing where people are saying, Hey, I want to keep my data Private. Well, I, I, I do think for the US it's certainly the data conversation.
Um, right? So when we have conversations on ai, the data security, um, right, is a very, very old topic. So we barely in the US speak about digital sovereignty, but we speak a lot about data security.
So the data perspective is an important one. If you go to, uh, Africa, they speak much more about autonomy. If you come to a few European countries, they would speak about business resilience, right?
So all different angles, autonomy, resilience, sovereignty, data security, that articulate ownership and control of that. What is most precious to you as a company, right? Because ultimately, why do you wanna protect the data?
Well, because right. You run your, your company on it. Uh, one fun fact, I do think not a lot of people know, uh, but the US was the first and foremost country that introduced sovereignty.
Um, yes. Right? If you think about FedRAMP for the military, for the cloud, Cloud FedRAMP, Yep.
Um, Suzu started, or Rancher started Rancher government services, which is an entirely separate legal entity disconnected from Suzu owned, owned by suse, but Right. We don't know what's happening there. Um, that is, that is sovereignty to the next extreme level.
Um, so to us as a company, it's very known, how will you bring that to the most extreme? And funny enough, that started in, in the us. So, um, yeah.
Yeah. It's ironic, isn't it? It Is.
It's funny stuff. Hey, and Andreas, for people out here, maybe they're in Europe watching this or wherever they are, how can they get more information? How could they get started?
Well, when it comes down to, um, understanding, uh, digital sovereignty, um, right, there's, there's a lot to do when you are in Europe. And you want to inform yourself on where do I need to look at when it comes down to sovereignty? The EU published only a six page document.
It's the Cloud sovereignty framework. It's amazing to, to read and to, it gives a really broad perspective. So that's definitely recommended to familiarize yourself with that concept, obviously, right?
com/digital sovereignty, uh, is a lot of information to find on products, on services, how suse can help you out getting more sovereign, um, and understanding what needs to happen in this transition. I love it. Um, and Andreas, best of luck in this new, uh, role.
I hope to see you. Well, we're gonna hopefully be at Scon in Prague Oh. Meet in Prague in March.
Absolutely. Uh, or excuse me, that's in April, in March. CubeCon is in Amsterdam.
I unfortunately won't be at Cube Con. I'm gonna be at the RSA conference in San Francisco that week. But Mike Ard on our, and our team hopefully will be there.
Nice. So, we'll, we'll, we'll talk more about that then. Um, but look, don't be a stranger.
Come on here and keep us posted on this. I, I think this whole i, it sovereignty thing is, is a subject that we're gonna really see come into its own next year. Yep.
Yep. And there's a lot in the pipeline here at suse. So, uh, stay tuned.
We'll definitely come back. I love it. Andreas Prince Head Sovereign Solutions at SUSE here on text on tv.
We're gonna take a break. We'll be right back. Hey, everyone, it's Alan Hummel.
We're back here with our continuing live coverage of AWS Reinvent 2025, um, another month. We won't be saying 2025. It's hard to believe.
But anyway, it's day two. We've been having a great time interviewing some really great folks here. This is a, a, this is probably the biggest panel we've done so far this week, and I'm really excited to introduce you to them.
Uh, I'm going to ask actually, folks to introduce themselves so I don't mess up names and everything, but we'll start at the far right with Ali. Yeah. My name is Ollie Reese, and I'm VP of Product Strategy at suse Ali.
Thank you. And thanks for being here with me. Next to Ali is Mani.
I'm Mani Jata, I manage strategic alliances at AWS Mani. Thank you for coming on. I appreciate it.
And this young lady is Christine, Christine cio, and I'm VP of our AWS Growth Strategy at suse. I love it. So I think just the fact that we have someone who's in charge of the AWS growth strategy at SUSE is a statement about how you view your relationship with AWS.
Correct, yeah. Especially a senior person. So, um, we're gonna dive into that.
Uh, good. I'm, I hope we do. Absolutely.
Um, but Mony, if it's okay, I'd like to start with you. It's a great title. You deal with a lot of the Linux providers, right?
And, and look, we all know Linux, it's open source. There's, there's some great companies in the Linux space. Sus is one of them.
Um, what, what does AWS want from their Linux partners? So, great. Uh, question Alan.
Uh, let me start with where this journey started, right? Like SUSE and, uh, AWS have been partnering for more than a decade, right? For context.
Uh, one of the first Army listings on the AWS marketplace back in the day, 10 years ago, was suse, right? Like, we started there. So from there, this journey has grown.
So to answer your question about, hey, like how do AWS and SUSE add value to each other? I feel like we've grown the partnership from day one, right? Like we've added value to each other from a open source perspective, right?
Like AWS has leaned on SUSE for so many, so many big initiatives, which we'll dive into. So, um, really excited to be here to talk about all the work we are doing today. Absolutely.
Absolutely. Um, Christina, I'm gonna ask you, how do you know, obviously it's a strategic relationship to suse. How do you view this?
And not just you, but how does Souse look at this relationship? Why is it strategic? How is it strategic?
You know, I'm not even ready to jump into product or re announcements that we've done here this week, but historically, that strategic relationship Relationship, well, going back to what Monty said, it's a a very strong relationship. It's been there for 15 years. I joined the company actually as a consultant.
Um, and that was in April of 23. And at that time, they were just looking to get Marketplace off the ground. And I was working with the product teams and the engineering teams, and also sales.
And it became very evident of the flexibility that AWS brought to the table in order to get a company like suse, who is now taking the products that they had that were traditionally on-prem and how we were going to deliver them through marketplace. We had our, what we call first party, which is more like a, an omni based model that Monty talked about. But we had to look at how are we looking at operations?
How are we looking at the way that we, um, stood up our listings and all that. And I think from then in working with AWS, they provided the most flexibility to meet suse where they're at, at that point in time. And about a few months later, I was hired in as the VP of Cloud and then managed the, uh, global cloud team.
And then we started looking at where the investments were being made within the partnership, who was really making and leaning into that investment. And hands down it was AWS So, um, working with our executive team, um, they said, we really wanna double down on AWS and said, Christine, we would like you to go do that. So I started working with our office of the CEO and our strategy office, and I started putting down what that longer vision would be with AWS.
And there were a couple things that we were working on at the time, um, that we just announced, which was, um, SUSE providing, um, additional packages in Amazon Linux. One thing I really love about the company is choice and flexibility and customers are going to use of, uh, various amounts of different technology. And SUSE's very, very open to supporting that.
So we, we doubled down on that, uh, project. And then we said, well, what if, what if we took, um, our rancher platform and we looked at in providing a SaaS? And then, um, Ollie came in and helped me really shape and define, uh, how that would look.
And a year later, here we are. So from a strategy perspective, you know, AWS has been, uh, a leader in the market, period, hands down. And yeah, with marketplace, they have just innovated and, and the amount of innovation that they do that we will never be able to, to do that on our own.
And that was another reason why we really wanted to partner with somebody who had that depth and that breadth in the market. And we had the technology on the other hand. So it just became a really nice union.
I love it. So you mentioned there's a lot packed in, there is a lot, no pun intended. We had to unpack it starting maybe with sp the, the secure packet for Amazon Secure packets for Amazon Linux.
Spoke a little bit about that actually, uh, earlier with, with Margaret. Mm-hmm. Mm-hmm.
But Ali, you are the, you are the product guy. What are we talking about here? So, from a product perspective, what I'm really excited about is like the launch, um, that we've pulled off together with the help from Amazon for suse, rancher, for AWS, um, that's been the products in conception and like being developed for over a year.
We've done a lot of user research and know, had a lot of good help from, from our friends and partners at AWS understanding what it means to be a product led strategy. Um, you know, how we operationalize SaaS products. 'cause if you think of what SUSE's been doing, right?
Like we're SaaS is not necessarily in our DNA yet, if you look back at what we were doing. And so, like that, that modernization right, is super exciting for me personally, um, to help bring this to the company. And, you know, I couldn't have done it without the help from AWS.
Um, and so the product in itself is Rancher is our multi-cloud, multi cluster Kubernetes management platform, right? And, um, SUSE acquired it five years or so ago, and we've, um, have tremendous success. It's highly regarded.
We're guarding our and, uh, forest a leader, you know, in multi-cloud, uh, multi-class management. Um, but it's, that's an on-prem product, and that fits our traditional customer profile of enterprise customers where they like to just have, you know, things on their estate. Um, but, you know, we want to, you know, using some of the AWS technology meeting customers where they are and meeting new customers.
And so with, um, scuse Rancho for AWS we're actually tapping into, um, customer profiles that are EKS users, right? And there's, there's plenty of them. EKS is wildly successful.
It's a great platform, um, for, for any Kubernetes, um, workloads. Sure. Um, and so what we are doing is we're bringing the capabilities from rancher to EKS to their customers.
And one of the feedback that we've heard is that, um, for example, multi-class management, if you have larger state, you know that that's where customers, um, wish they had additional help. And this is one of the strengths of, of Rancher. Mm-hmm.
Um, where we have heterogeneity and we support, you know, many clusters across many, um, providers. Now being a AWS and EKS opinionated product, we've then taken, um, rancher and, and really added additional user experience to it. So, for example, um, identity management is often a problem, you know, for, for enterprises.
'cause there's multiple accounts and different setups and orgs. And, you know, IAM is just, it's very complex because it's a very important topic. And so we take this very serious, but we've implemented features that make it really easy for our customers of SUSE Ranch of AWS to import identities in a safe way by delegating roles so there's no more copy and pasting of passwords and whatnot.
So we do this all through off delegation, um, on the IAM side. And then with, with that in mind, then we all have of a sudden have insights into the whole estate that is being managed or run on EKS. And from there on, we, um, allow our customers to selectively import specific clusters, or all of them create new clusters and use the capabilities that Rancher Manager provides.
And then, um, another part of the portfolio that we've baked into suse Rancho for AWS is observability. That's super critical, right? Like, we need to know and understand what's running, where, you know, how well it is performing are the bottlenecks.
And so that, that's another key feature that's available in suse Ranch for AWS. Love it. Alan, if I may add to what, uh, Ollie is saying, I think this has been a long time in the making, right?
Like, we meet the customers where they are. So AWS customers and rancher customers, uh, have been using both products separately, right? Like, and for us to basically complete the puzzle by saying, Hey, you have a one-stop shop, go to the marketplace.
You know, you get observability, you get cost optimization, all of that in one package. Uh, I think that's a huge value add for customers. And it's, it's, uh, it's a long time in the making.
Yeah. Because customers have asked for it, And we have a, wait, there's one more. Um, so in, so this is just getting out the basic product, right?
And then super exciting. E everybody's talking about AI here, right? You can't walk across the floor, Not just here, everywhere, but Billboard.
It's, it's very, um, omnipresent, right? And, and so with the help from, from, um, the AWS teams, we've been able to actually implement one of the first, um, AI agents in the platform, um, within suse within our portfolio to help customers actually ease their SRE burden, right? So Kubernetes is complex.
Um, rancher helps already like to, to lower that complexity and make it more accessible. But now all of a sudden you have a, um, a wingman that helps you understand, you know, what a specific error code or whatever means, and you can actually chat with the system to identify, you know, is this intrinsic? Is this a invasive problem?
What are remediation steps? And we've built this on top of Bedrock and q and the, the way to get there was amazing. And like, the value that it's providing for customers is really astounding.
It, it really is. Again, a lot, a lot of stuff covered there. Ali.
Let, let's, you know, rancher, I, I'm Shang the founder of Rancher. Mm-hmm. It was, I know him, he's a friend.
I know him for many years. Rancher in my mind, was the best multi cluster Kubernetes manager that in the market, right? I mean, look, I, you, you know, you could go out onto the floor here at AWS reinvent and say, how many of you think Kubernetes management is easy?
No one's raising their hands. Right? It, it's a known thing.
This is hard. Yeah. Multi cluster Kubernetes management is even harder.
And that's what made Rancher well, one of the things that made rancher as, as unique as it was, and of course, since it's become part of the Sousa family, you know, the K threes and everything else, we, we added into it. And now AI and, and what that means to it is, has, has made a a huge difference. I should mention when we say multi cluster, don't be confused with multi-cloud.
Yeah. Mm-hmm. Right?
It doesn't necessarily mean you're on different clouds, though. We can, what happens is, is at the enterprise level, right, the average enterprise is running multiple clusters of Kubernetes, right? I don't know mony if you would have metrics on that, but, Uh, more than metrics, I feel like the customer journey, right?
Like they start with a few clusters and very quickly it expands across regions, across accounts. So the complexity increases so quickly that something like rancher is super critical, uh, for somebody to scale, right? Like for an enterprise customer to scale that happens, that ramp happens very quickly.
To your point. Absolutely. Now, I just wanna make sure I got it straight.
For the people watching this offering with AWS is a SaaS based offering, SaaS based offering, and it's focusing on AWS and D-E-A-W-S ecosystem and EKS specifically. So as a customer, you won't be able to manage, um, Azure or GCP for example, at this point, because we're targeting, um, that segment of customers that are getting started in, in EKS that are, you know, seeing the increasing complexity and just single cloud strategy at this point, right? But as, as those customers mature, right?
Like, then we might see a multi-cloud strategy, you know, in, in enterprises. Yeah. Um, but for right now, this is, you know, we're focusing on EKS.
I love it. I wanna come back. So I'm a security guy at heart.
I've been in security, I was in security a very long time. I didn't want to tell you how long, but we, we didn't call it cyber, I'll tell you that. Um, secure packages for Amazon Linux, I want to come back to this.
This is a major thing, right? We've seen over the last month or two, uh, you know, the NPM ude, the, the worm self propagating malware into packages. It's a problem, right?
When, when, when 80% of the software inside of the applications we develop are pre-existing components, scripts, packages that we download in, gets into our software supply chain, and then God knows what happens. It's important and increasingly important that we know that we have confidence. If I'm on Amazon and I'm getting a package from an Amazon partner or a repo, I wanna know that that's not, I'm not downloading malware.
I'm not injecting malware into my thing. And that is, you know, SUSE announced this, I guess it was at Seus Con last year. I think Ali, we might have spoken.
Mm-hmm. Um, there. And that's an important thing, right?
Yes. We have SBOs, right? That's, everybody wants to know, you know, bill of materials.
That's great. It's like the tag on your mattress, right? That you don't tear off.
It's good to have there, but we, we wanna have confidence in the packages we're putting into play that they're secure. And that's an important piece of this. It Is important.
And I think, you know, just even going back to, we talked about complexity. We're talking about security, um, and we, we, we, um, kind of touched upon the voice of the customer. This, this whole solution started as a concept.
It was a concept document. And we actually talked to over 50 customers. The number one and number two, uh, issue that we were solving for was complexity security.
Yeah. Those are the top two. Uh, we see it too.
I mean, you know, we see it across the board. That's what people are concerned about. And when, and when we did that research, it actually kind of parlayed a little bit into what we were doing with Sal, the supplemental packages.
Yeah. Because now AWS can offer their customers a safe environment to create applications without having to pick their own packages that they need. It's all built in that repository.
And that's what's really critical. And that does leak into cluster management and, you know, everything else containerizing applications. But It's a, it's a question of confidence.
Mm-hmm. I, I need to be confident that the software I'm getting from you is, is, is secure that it's not gonna come back to bite me. Right?
Because this is where, this is where incidents are happening. Third party components into the software supply chain. Um, and if we're, and if developers are our audience, that's very much on top, as you say, it's on top of their minds.
One of the top two that and complexity. Um, if you don't mind, I'd like to come back a little to ai. We touched on it a bit.
Certainly this show is all about ai, right? AWS has re has come out guns blazing, right? About agent, and it was started with the keynote yesterday, right?
Magenta ai developing their own ai, developing their own AI processors, right? The creating an AI stack, that's really what we're talking about, right? From hardware to software.
I know AI is something I've spoken to suer about over the last month's year. How, how is that manifesting itself in these announcements and partnerships that we've made this week? Well, we did sign a strategic collaboration agreement.
Mm-hmm. And that really was the first kind of thinking of us leaning into the technology that AWS has. And as Ali pointed out earlier, we in incorporated that into the platform itself.
Yes. Into the SaaS platform. Um, that's our first step.
And we actually are looking at it right now, now of looking at what we're doing around MCP and seeing how we can actually make the correlation between Amazon q, um, to look at how do we, how do we incorporate these two technologies? 'cause right now Q is predominantly for SaaS. Yes.
Not necessarily on-prem, but there's a lot of data there that actually is beneficial, um, for AWS customers as well. Sure. Is.
So we're, so we're in the infancy of that. So it's kind of, it, we, we signed the strategic agreement really thinking that, okay, we're gonna be using it for this, for this SaaS platform. And then as we started deepening the relationship, other product teams, and you'll talk to Rick.
I don't know if you've talked to Rick already. No, I have not. Uh, you, you'll talk to him I think later today.
Yes. He'll tell you a little bit about SLES 16 and all of the, um, all the press and news that we're getting about the operating system because of all the work that we're doing around ai. And he's looking at incorporating that into the platform as well.
So it's, uh, and, and we've done our own, we have our own stack, um, for ai. And so does, so does, um, suse Rancher. Um, and so we're just now trying to look at how do we marry these, both these worlds?
Let's talk suse rancher's, AI stack a little bit, Ali. So we in, in suse rancher for AWS, right? We have, um, our agent that I, that I mentioned, right?
Um, build on Bedrock and q and that helps from an SAE perspective. Um, but then if you think about it like being the infrastructure for workloads, right? Like there's a lot of intelligence that we actually get through the observability solution, right?
Like, so that helps feed and make agents and AI smarter about the, the infrastructure that, that we're operating. Um, but oftentimes there's, um, not just a Kubernetes estate. And so going back to what Christine said, our, one of our, our products is, um, Linux manager, right?
And so all of a sudden now when we have systems that can talk to each other in intelligently, um, right? Like, it helps enterprises, it helps customers to better understand their whole estate, not just compartmentalized, you know, by, by the execution platform that's Kubernetes or VMs or whatever. And so I think that's the true power, like getting all those different data sources in and then combining them to, for, you know, to provide meaningful outcome.
And, um, on the rancher side, we have, um, the stack that Christine mentioned earlier. Um, it's called suse ai. Um, and that helps customers to securely run AI LLMs models and whatnot on-prem, right?
Because there's a lot of risk right now that we have to manage, um, you know, with this new technology, uh, in terms of IP and like being, making sure that no data leaks and that models are not tampered with, or that we don't have drift and suse, I helps customers actually to manage that complexity and those risk vectors. Love it. Nancy, I wanna, from the AWS perspective, you guys have been sort of like the Candyman this week announcing all of these great gifts for, for developers and for partners like Cuse to develop on and build on top of expectations of, you know, Ali mentioned QI didn't hear a lot about Q this year, a lot more last year, I think.
Mm-hmm. But we've heard about, about Bedrock, but we've, we've heard about other, uh, agentic AI programs that a, uh, that, uh, AWS is, is working on that they're either in pre-release or they're released already, but, you know, imminent. What's the, you know, this thing is moving so fast.
What's the timeframe you got a company like suse? Is it gonna be next year that we're using, you know, some of the stuff that we're, we're doing? That's a great question, Alan.
Um, you know, for instance, I'd love to talk about the mental model around how we build with partners like suse, especially from an AI perspective. So Ollie, you can vouch for this, right? Like integrating q the agent into, uh, the suse rancher solution, I think it takes a matter of a few days mm-hmm.
Versus what it would take earlier, a few months, right? Like for the teams to come together, say, let's go innovate, right? Like figure out the architecture now that's out of the window, right?
Like we say we are doing this, and then it happens within days. And then to your question, where is this heading? I would say the days will be cut down into, right, like a few hours, right?
Like that's the speed at which we are moving. And that is, uh, we are seeing the benefits of that across the organization, right? Like from an efficiency perspective, uh, across the board, right?
Like, this is the model we follow with all the partners. We jointly say, Hey, these are the three customer problems we are trying to solve jointly. How can we insert all the AI innovation we are building at the services team, right?
And then we kind of figure out how do, are we solving a real customer problem through this, right? Like, what is the use case? That way it becomes very easy to scale.
And that's how we solve for, uh, you know, a lot of the problems that, uh, suse is atan. I think the, the length of time there for us to get this out was a few things, right? Understanding the customer, looking at a concept document, soliciting that.
Then we actually had, um, folks from AWS come in and do a workshop about how to look at personas in a different way. We were tapping into different personas, a developer persona, right? We we're used to the more of the platform engineer, but how are we going to tailor this offering to a developer, right?
So that took some time. Then we went to, um, work with the PLG team, um, with AWS so getting it, getting the product in a MVP stage. And now we're looking at how do we get better with automation through marketplace.
That's another, that's kind of the next, but now that we have this baseline for the offering, it helps us now go back in and just now, you know, incorporate newer technologies or get, get a more, uh, feature rich roadmap moving forward. So, to the bottom of your question, like time to market mm-hmm. And time to adopt.
Um, there's been a lot of announcements around quick and quick suite, right? Yes. We've been in conversations with the teams already for months.
Um, and you know, that's something that we have on the roadmap. 'cause that helps, you know, having a in place in product chat bot is fine, but it's table stakes these days, right? Yes, it is.
Um, but like lifting this to the next level where, you know, you have agents facilitated through quick Suite, like talk to each other and actually automate business processes, right? Even down to the infrastructure. Like that's, I think where a lot of innovation can happen.
And I'm confident we'll be able to really quickly adopt that with the help from our AWS counterpart. Absolutely. Um, I wanna make sure if we hit anything I've left out announcement wise, It's on marketplace trial.
Is there, uh, just a little plug there. Okay. Well, no.
Hey, this is the place to do it checking out on marketplace. Let me ask this then. What's next here?
Vacation. No, no, but I, you and me both, but actually it's gonna be almost Christmas. But, um, no, but in terms of a strategic relationship, where do you see, let's ask the AWS point of view where, you know, where, where can, where's this headed?
So going back to the journey where we started, we started with Army based products. Now, uh, to Christine and Ollie's Point, we are almost experts at SaaS building SaaS. So now the next transition is right, like we scale, right?
Like, that's why we see our, uh, I think 2026 is gonna be the inflection point where the, uh, the SSA AWS uh, you know, relationship scales because we have so many products on the cart and we are solving real customer problems. Agreed. Christine, this is your baby now.
Yeah, I mean, if I looking into, you know, what we do next, I think automation is really important because the go-to-market aspect of it, engaging with the field and, um, getting feedback from not just the customer, but from AWS themselves, um, and looking at how we're incorporating that into the roadmap, I think will be critical in order to get the scale. So how do we, how do we make the user experience, you know, just a few clicks away, you know, to get access to the Yeah. To the product.
You know, one of the themes that came up in our talk today was, look, suer is undergoing a bit of a transformation from a company where enterprises primarily used it OnPrem to this new world that we're all living in now, where, you know, the hyperscalers, the clouds, you know, no one, no one is all in on any one, it seems right. We live in a hybrid world, and, and this is a major focus shift a little bit for suse, right? Because you have to have your AWS offering has to be as good or better than the on-prem offering.
But I think increasingly customers say, look, where I house my stuff, my infrastructure, my data, what have you, is not important. I want a solution that runs, right? I don't want a solution for on-prem and a different solution for AWS and a different solution for somewhere else or what have you.
I want a solution. How Ali as a, as a product guy, even at the rancher level, right? This is multi cluster at its, you know, take it to the Yeah.
Logical end. So you, you threw me a good bone because what you described is really like one of our key value props to our customers, which is choice, right? And we are not opinionated of where you run, or if you're running, you know, a red stack or a green stack or whatever color, right?
Like you want to use there. Um, we'll support you where you are. And I think that's, that's one of our strengths.
And that we've, throughout years, what we hear from customers is like, we don't lock customers in. And so that, that value prop or that corporate value really like, reflects into our portfolio. Um, you see it with Linux manager, we support 15 plus operating systems with, um, on the rancher side, right?
Multi-cloud heterogeneity, right? Like is key, is a key driver for us. And so that's where we provide customers.
That's what customers really enjoy, you know, given, um, recent, um, market trends that we've seen and, and movements, you know, with customer, uh, with, with other acquisitions, right? Like, customers feel locked in and we're here like to just, you know, cut those shackles and, and give them the freedom that they need. Last question.
This is, I don't know, 60,000 people here or something, right? Running around that show floor and around the area. What are you hearing from real life people about this relationship?
About the announcements, you know, feedback. I don't know if you've had a chance to go talk to real people yet, but I was, well, it was interesting 'cause I was talking to Barry earlier, right? Yes.
So, um, he understands the, he, he was really excited to see the, um, the agreement with the SAL packages and Right, because he understood from an AWS viewpoint, like they, they, they have their skillset, we have our skillset, and customers want to build applications. They don't wanna kind of pick and choose what libraries that they're gonna put into their application. They want it, they want it easy.
Mm-hmm. So I think the excitement that I'm hearing about the relationship is, um, wow, you guys have really done a lot with AWS in this past year, because I think last year we were talking about what we're gonna do, and I think now we're talking about what we are doing, and I think that's the biggest difference. Um, and I, our customers, you know, in the field, you know, with, uh, EKS and then also rancher, we get a lot of questions, uh, from the customer saying, well, I'm, I'm moving to EKS, or I'm an EKS customer, now we have something there to offer that is specific and opinionated for that customer.
We don't have to, you know, kind of juggle around that answer. So that is from true customer feedback. Excellent.
You'd have it. I mean, uh, Alan, the energy here, 60,000 people, the number of meetings, the number of customers we meet, uh, the mental model that I think about at reinvent is you come here, you talk to your customers and get six months of work done in one week because you get all that feedback and then you go back into the hog wheel and bend. Mm-hmm.
Yeah. Yeah. And that is, it's, it's, you get your, your, your, you know, you got your paddles out here now.
Yeah. 10 is then you go home, you take this all back, internalize it, and move. Yeah.
Holly, I'm gonna give you last word. So From the show floor, what we hear is just amazing feedback about, you know, not so much new AI features. Again, like that's, that's a commodity already, but like the choice part that I described earlier, like, a lot of people are like, oh, so you're not just managing suse, oh, you're also managing, you know, other Kubernetes, other operating systems.
Like, that's been overwhelming feedback at the booth mm-hmm. This week. Mm-hmm.
They want one solution. Rules 'em all. Yep.
Absolutely. Hey, thank you all. Thank all three of you for coming on here.
I know you're all busy too. All of us are busy at this show, but thank you for taking time out to come on here. I hope everyone at home has enjoyed this.
Uh, if you're watching this live, you're probably not here. So I hope you brought a little bit of what's going on at Reinvent too. If you're watching this on demand later, good for you.
I, I hope as well that you enjoyed it. To mimic Christina, go to the marketplace, check out what's there. And, and you can see a lot of this for yourself.
We're gonna be back. We've got more SUSE coverage, more AWS coverage. We've got a lot of things going on all day today.
You're watching Text Drunk tv. Hey everyone, we are live here at AWS Reinvent, continuing our coverage of Day One Lot going on a lot of ai, a lot of agentic ai. You know what?
I don't hear a lot about Cloud. AWS Reinvent used to be all about cloud. Now we're talking ai, but we're gonna talk some security.
One of my favorite topics, I want to introduce you two and make, I'm gonna mess up his name, but we practiced it 12 times and I still didn't get it right. Sne, Ben Shimo, Shimo. I almost, I wanna say Shlomo and I keep Schmo, but he likes to be called Ben.
Ben, what's, thank you for coming on to Text Drug tv. It's great to have you on here, man. Thank you for having me.
So from the name, I'm gonna guess you, maybe you have some Israeli roots. Yeah. But You live, you're a New Yorker, New Jersey, like me.
So I guess that makes us kind of almost related, but, um, tell us about your journey. How, how did you come here? Yeah, definitely.
So currently based in New York, almost in the past 10 years, uh, been in cybersecurity for many years, as you all know. Uh, I'm Israeli originally. So we started a journey in the military.
Uh, I'm not 8,200. You're not 82? No, my 1200 Is the few, not 8,200, But actually 8,200 is quite big.
Yes. To the place that I used to serve. I used to serve in more of a secret service.
Okay. The Prime Minister office, which is, uh, more boutique, more unique, uh, harder to get into if you're 8,200. Don't hate me, but we're better.
Okay. Hey, he said it. Not me, but go ahead.
So, yeah, we, um, basically moved to the states after, um, managing a lot of cybersecurity, public company research division, building from scratch. Really, really passionate about research, anything related to vulnerabilities, attacks, offensive security defense. And, uh, I found myself in, in New York as like one of the big companies.
I build their product, they couldn't sell their product to the ciso. And I was blown away because such a great product, we need to explain the value. And when I moved to the states, uh, I was really kind of exposed to, no matter how good product you're building, you need to be close to the customer.
You need to be really close to the team, you need to close to the security executives and explain to them what's going to come next. Mm-hmm. The thing with security is like check if you're playing, if you're trying to survive the next week or maybe the next year, you're probably going to fail in year two.
In year three. So when I moved to the states, one of my biggest goal was to educate them, right? And like, what's coming up next to build a strategy in the right way.
I used to be a CISO as well, and managing security organization over 100 people. Um, um, very quickly, um, after that build a startup, a couple of really good friends, uh, named Cider Security very quickly was sold. I know them well.
Sure. Yeah. So really quickly, uh, we had a huge success.
We sold it to Palo Alto Network. Mm-hmm. Spot of Prisma Cloud.
And, um, I ended up loving the cyber, uh, security and startup. I'm like, wow, I can do, I can build, I can do whatever I want versus enterprise. That was a little bit slower.
Yeah. So I decided to take some time off after the exit, and my co-founder, eh, who I didn't know is going to be my co-founder, called me. His name is ly based in Boston.
And he's like, Hey, so I have something interesting for you. I got to a point you manage vulnerability management and cloud security for Akamai from Cambridge. Sure.
And he is like, Hey, I got to zero vulnerabilities in three of the massive Akamai environment. I'm like, great, Julie, you accepted the risk. Everyone can accept risk.
It's like, no, no, no, no. Actually remediate it. Actually.
It's like, excuse me. Look, vulnerability management is never happened, never happened, never happened. Vulnerability management is a list of problems everyone have.
And you just wait for, you know, s****y defense and bad things will happen, but it is what it is, right? And he's like, no, no. I was able to do something about it.
Uh, it sounds very promising. I opened a plane, went to Boston, and I spent a few days with Uwe. And what he showed me, I was blown away because I couldn't achieve it with the best team in the world of security people for all the decade I'm in cybersecurity.
And this is where I realized that vulnerability management, the dead market of vulnerability management, exposure management is, can be solved. We can actually win the vulnerability battle. Call me skeptical, but okay, I'm listening.
You got my intention. So after a long journey of speaking to over 100 good friends, CISOs and large enterprises, and also smaller one, everyone were, we're skeptical. What we ask him is like, Hey, if we can come in and take your, of backlog, your vulnerability backlog, and all these vulnerabilities that you're getting from Tenable, from w from AWS inspector for, and we'll talk about AWS later on while we are here, but all these crazy vulnerability data from on-prem, from the cloud, take all this vulnerability data.
You can sift through it. You don't have enough people in the team to review it. And then you have workflows.
But you cannot automate vulnerability management because it's deterministic. Every CV is different, every vulnerability is different and the environment is different. So how can you automate?
You can't. This is why we're failing. And I ask him, it's like, if I can take this problem and automatically reduce 90% of that backlog automatically without any human touch, just eliminate it and leave you with that 10 or maybe 5% to actually handle.
It's like, that sounds good. That sounds great. That's great prioritization.
And then I, then they told me, what about remediation? I was like, okay. So once we have that 10 or 5%, I know and we practice that, then we identify it, take that five to 10% and simulate remediation and give you that one, two, or three steps that you need in order to reduce Back to the Buck.
Exactly. That's exactly what we're saying in our website. Mm-hmm.
And they say like, that's amazing. If I have something like that, I will, I will buy it. We, uh, close the seed round in a month really quickly.
We just took the money, great investors, and we built Zes security, which is the current company we're at today. Very excited about it. So that's basically the story of, of You and Security.
Yeah. And Uwe, So lemme give you a little background. I, I've been inside, but we didn't call it cyber, we called it security.
I've been in security 30 Years. Information security info InfoSec. Yep, exactly.
And, um, I actually, I've co-founded a couple companies, one of which was called Still Secure back in 2001. And we in 2003 came out with a vulnerability management product. And back then it was very different.
Back then you had to convince people to do a scan once a year. Mm-hmm. It was like pulling teeth.
But when you, but it was job security for the security guy. 'cause you would do the scan, you'd deliver like a telephone book of vulnerabilities. Let's say I give it to 'em for Christmas or New Year's, you know, you are from New York.
It was like painting the Veno Bridge. You know how they paint it? Theno Bridge.
Amazing. They start on one end, it takes 'em a whole year To finish, To finish. And then when they're done, you know what they do?
They go back and start again on the other Best job security ever. That was vulnerability management. It was almost by design that you didn't get to zero vulnerabilities.
So then people got smarter. They said, look, we don't need to get to zero vulnerabilities. We should only worry about the vulnerabilities that are exploitable, reachable real.
You know, I had, I had a friend, I don't know if you ever heard of this guy, giddy Cohen, Skybox Security. Yeah, of course. Giddy just started a new company too.
I know. Um, you know, and that was one of, when I first saw his attack maps is what he called them, right? Mm-hmm.
I was a revelation. I was like, wow, this is great. Now I only have to worry about 20%, 25%, Which is a couple of millions.
It's Still a couple of still job security. Yeah. But unfortunately, it's been almost by design that we never get to zero vulnerabilities.
A as a matter of fact, even you mentioned, we were talking off camera about black hat. I was a black hat in August. I was talking to a friend of my, uh, two friends who actually just, uh, just starting a new company.
They just raised money now. And, um, their, their thing is, look, forget all these vulnerabilities. There's only a handful that are real mm-hmm.
That are responsible for incidents and just focus in on those. That's good. If I knew exactly which ones to focus in on, you know, that's like the old, old joke.
A plumber comes and says, the lady says, I don't have heat. A plumber says, let me look. He takes out his pipe and he, he bangs the, he takes out his wrench and he bangs the pipe with the wrench and the heat starts working.
And the lady says, oh my God, what do I owe you? He says, $250. She says, $250.
All you did was bang your wrench on the pipe. He said, oh, no. That was free.
Knowing where to bang my wrench on the pipe is $250. I love that. I I'm going to use that.
Tell you got it. This is yours. Wow.
But that's the thing about vulnerabilities, right? If you know, which of the ones that are exploitable are dangerous, you can mitigate. But to get to zero, I'm not gonna ask you to give away secrets here, but what is the secret to getting to zero vulnerabilities?
So what we, and, um, I don't know if we want to get to zero. Okay. I don't think we need to get to zero.
Yeah. But we definitely need, like, why do the, the world need is important since you start talking about scanning. Today's scanning is mandatory.
Yes. You have requirements, right? You have continuous regulators.
You have auditors. More than that, if you want to provide services as a SaaS company to customers, you need to have an SLA. Yep.
And what happened in 2025, these regulators, uh, re requirements are stop asking you for visibility. Because visibility, everyone knows everyone have that list of vulnerabilities, right? Mm-hmm.
Everyone can scan. Everyone's scanning today, even SMBs. Yeah.
They're required to. Yeah. But now the regulators starting to ask, because again, I will, I'll give some more information because I think it's important.
Over 60% of incidents today, and this is vouch number, are related directly to vulnerabilities that were known to the organization. Absolutely. I think it's higher than 60.
I think it's close to 80. I'm, I'm just basing on ENT report and Verizon report. Yep.
The time to exploit this vulnerability. Were reducing the past three years in 19%. Now it's less than a day.
Last year in 2024 was less than three days before that it was five. So we got to less than A day. I remember it was 30, 45 days.
Exactly. It keeps going down. So regulators, cyber insurance, your customers want, if you have something critical, they want you to commit to an SLA and God forbid something happened.
You miss your SLA, your regulators will come after you, especially if you're highly regulated environment. Yep. Most of our customers are biotech, financial services, health, and even SaaS company that provides services to this healthcare Today.
Look, it's, it's about who your third parties are. Yeah. Right?
It's not who you are. It's who they are. So, you know, and further down The list, and they want to get these deals.
It's like, yeah, I cannot get these deals because I cannot commit. Or they're committing. But now they need to deliver a seven days or six days critical vulnerability in production remediation.
Absolutely. It's the whole SOC two, all of these other Yeah. Audits.
And, and what we actually realize is there is a need like not in zero vulnerability. There is a need in remediation. Yeah.
And how we do what we do is basically, you cannot automate, but you can AI it. So we using different type of LLA models, we acting as an army of security engineers that going one by one of these vulnerabilities. And it doesn't matter if they have high score or low score.
It doesn't matter if they're being exploited in the wild or not exploited in the wild, they're in your environment. Yeah. And what I need to tell you, if in your environment this vulnerability is actually risky or not, and you'll be surprised how the more, the most advanced scanners, these tools that you paying million dollars to, they're giving you this list of vulnerabilities with attack path with mm-hmm.
What will happen if, but they're not correlating that with your environment. No. So you have an open SSH vulnerabilities, right.
That open SSH vulnerability have requirements for exploitation. You need to run the service with specific permission. That asset that is vulnerable need to live in specific environment, environment terms.
Without them, this vulnerability can never be exploited. And to understand that you need to send someone to do this test. Yeah.
That's exactly what our agent ai, uh, uh, capabilities are. Wait, I needed to say it. You You said it.
We but you made a long time till you mentioned it. Look, exactly. We're here at AWS reinvent.
I don't hear them talking about cloud. I hear them talking about AgTech ai. So talk to me about how your agent is working to do this.
Uh, we actually announced, uh, we are going to have an announcement, uh, early next year. But in, uh, reinvent, we doing a private preview of a new capability that was very, very interesting to all of our AWS enterprise customers. AWS investing a lot in security.
Yes, they are. And we call it Native security controls. So they're allowing today DevOps and, and platform teams and engineering teams that build a cloud to build a cloud in a secure by default way.
And they have a lot of native capabilities around resources. You can build policies around services. You can have security policies without paying money, just using the native capabilities of the cloud.
If you will look in these native security capabilities, and you will correlate that information, the, that your cloud architect actually infuse into your cloud, correlate that with your vulnerability backlog that you need to solve. You will realize very fast that many of these native security controls basically reducing 50 to 60 to sometimes 70% of your attack surface. But because you're not marrying these two together, you, you don't know.
That means that you can focus on vulnerabilities that were already diffused and solved by and mitigated by this amazing AWS cloud native controls that you have. So one of the capabilities of our agenda AI is to look and understand your policies around services, resources, encryptions, VPCs, microsegmentation in your cloud, and understand if this remote code execution vulnerability can actually exist. Even if you take into consideration these policies, most of them are not exploitable.
Right. That's the idea. I love it.
It's great. You already, you, you don't have a problem. You already solved the problem.
Right. And you don't know that you solved it. You know, some, some part of me sits here and says, did it take AI agents agent AI to reach this level?
Like, it's always bothered me to tell you the truth, why we didn't do better with this problem. Right. I I was working on it 2003 22 years ago.
It's a technology limitation. It's not a need limitation. We always have that need.
I think we've always had the need. I I always thought we didn't have the will. Right.
People, people talk a good game, but their hands don't reach their pockets when it comes time to, to really prioritize. But this makes it easier, more, it's, I don't wanna say automated, but it, it's just, it's easier to, to do this. You can win.
I love it. Yeah. I, I agree.
We, we are giving a lot of, I I, I'm really proud of it, but we are giving more life years to our security engineering. Yeah. Every time we talk to a team and the team sounds tired and unmotivated, this is the team we want to work with.
The teams that have these backlog of vulnerabilities that every day of their life is chasing down this Vulnerability. Look, this is a whole big problem. You, you've been in security long enough, you know this.
Right? The, the depression of, because for those of us who've been in security a long time, we have a lot of people in security who are, they suffer from depression. They, it, the, the, the, the issue is, it's like what does winning look like in security is I didn't get breached today.
Mm-hmm. Right? Did I neck got breached 'cause I was the zebra in the herd and the lion ain't someone else today.
Or because I did a good job, or I convinced my CISO and the board how to manage risk, what, you know, what's acceptable risk or not. And, and so anything that I think Im improves that is, is an amazing thing. I was gonna ask you what Zest security's doing here at AWS, but you already answered that Ben, so that's fantastic.
Um, what has been, so there are security people here, but there's everyone here, there's CIOs, CSOs, there's that. Do people understand, like the security people obviously do, but does the CIO do the cloud engineers understand what a, a load this is off of their chest, right off of their shoulders? Mm-hmm.
I don't think they care. No. I think at the end of the day it's part of The problem Too.
I like, it's not part of the problem as much as, you know, we, me managing over 100 people, I knew everyone personally and I cared. Right. When you walk in a large enterprise, you like many times you can't do that.
You don't know what the security team in the trenches actually going through. Even not the ciso. Yeah.
Not talking about the CEO and the CO what I, what I actually, um, what what what I like to surface is if your security team, if your vulnerability management team that in charge of prioritizing vulnerabilities and fight the vulnerabilities are drowning, which they are, it's going to bubble up into management problem. Yeah. It's going to bubble up in audits.
It's going to bubble up the way you look in front of your customers that asking you about what you do about this, what do you do about that? It's going to bubble up when you have a red team or penetration test. It's going to look bad when you have a customer that's saying like, Hey, I asked you about this couple of days ago, what's going on?
And we're getting these emails, right? So the management team needs to look good and needs to act good. And it start from the vulnerability.
It start from the team. So what I'm, I'm basically telling this COO and CIO is like, today you have a backlog of, or do you have vulnerabilities? It's like, yes.
Do you want to eliminate a and at least 90% of these vulnerabilities without spending money and asking favors from the CTO and engineering team without asking and pushing tickets into teams that need to build your business? It's like, yes, of course. It's like I can guarantee you that with agent AI infuse into your exposure management program, your program, you don't need to hire 200 security engineers.
You can walk with your existing team, maybe add some more people if you want to, but you can win. If you infuse AI into that operation, you can open less ticket. But each and every ticket you give to your engineering team, that ticket was 20 or 30% of your risk reduction.
Got it. And that's what they like, they, they sync numbers. Right.
But at the end of the day, I'm helping the vulnerability management team. Yeah. And if they do a better job, the COO, the CFO even will be happier.
They don't understand that. But it's okay. That's my job to make sure that both sides agree to embrace our technology.
This will get, like, these guys will get their executive report and the vulnerability management will get an amazing, amazing tool that will make them survive the holidays. We need to survive the holidays, right? Yeah.
Always. But then there's always another holiday. You know, Um, Ben, we're running low on time.
I want to just make sure we hit a couple of things for people out there who, like what they're hearing, what's the website to go to here? io. We're very ZT Zs T zes, like Lemon Ze.
Yeah. io. And we're very transparent about what we do and about our technology, and we have our customers use cases there.
Everything you need to know. It's in the website if you want to see it live. If you don't believe what you're reading, which is okay, we have a dedicated security team that can show you a 30 demo, 30 minutes demo and actually to see it by yourself.
And we also have, um, um, a free, we just announced a few months ago, a free remediation assessment, really, which is not a risk assessment. We're not showing you your problems. Right.
Uh, we are basically showing you, uh, the probability of your remediation operation. How can you remediate more with less? And it, it takes, I think, seven days of the platform to run, analyze, and get you everything you need without having any sales calls during that time.
So Absolutely. Yeah. Just That security io.
Yeah. Hey, I think you're onto something, man. Good for you.
Thank you so much. I really enjoyed the Conversation. I enjoyed having you on here.
We'll have you on again, Z Security io. Go check it out. Look, this is, this is, uh, this is kind of a holy grail a little bit if you've been in vulnerability management and security like I have.
So go check it out for yourselves. I'd love to hear what you say about it. Enjoy the rest of reinvent.
I will. Thank you. All right.
We're live. We'll be back with more. Stay tuned.
Hey, you remember the girl who danced with everyone at the Prom? Don't you? Was her name open ai?
You're watching Textron Gang. Hey everyone, it's Friday. It's the Friday before Christmas week.
So it's a really good Friday. A lot of us are hopefully already feeling that holiday cheer or just waiting to just push, you know, get get to the holiday break as we we this crazy year of 2025 starts drawing to a close. Thanks for joining us today on Textron Gang.
Let me introduce you to our all-star panel of gang members. We've got, uh, Gina Rosenthal looking great. I don't know if that's a new camera or watch Gina, but that you are looking like in eight K today, my friend.
Um, joining Gina, we've got, uh, Alistair Cook who's joining us from, uh, the Land of Oz, I assume getting ready to spend the holidays at home, as well as John Schwartz and Mike Ard and myself. Welcome gang members. Mike.
You know, we've only got a few stories left for the year, but it's gonna go out with a bang. Open AI is, uh, dating again. What do we got?
They keep on Coming. They sure do. Keep on coming.
I'm having a hard time sorting this one out, but, you know, on the face of it, it looks like a hell of a discount for open AI to use AWS processors. But what do I know, John, you're closer to this thing. What's going on?
And can you make any sense of this one? Uh, Jesus, you know, every day I try to make sense of this stuff. You know, there's a photo circulating on, on, on x.
I don't know if you saw it, and it's funny that Alan would would mention the girl, the dances with everyone. But there is a photo of seven executives standing around each other. Sam Altman is in that group, and Well, is that the time cover?
Is that the cover of time? Yeah. Oh, No, that's another one.
No, this is another one. Oh, okay. This is there.
Yeah, this is another one where they're standing one and, and you've got Sundar, you've got Tim Cook, you've got Zuckerberg, you've got all the usual suspects, um, Nadela and, and, and the caption is, it's your turn, Jeff Bezos, to invest in open ai. And that's actually, it is going viral. But in any event, according to the information, which does have really great information, uh, there's a, a story that open ais and preliminary discussions to raise at least $10 billion from Amazon that's gonna be part of a larger fundraising round that if the information has subsequently said could reach a hundred billion dollars, which would give ultimately open AI evaluation of $750 billion.
Now going back to the Amazon deal, which allegedly is, is being talked through, this would value, um, chat GPT at about $500 billion and include open AI's adoption of Tanium. Um, it could be, in a sense, would, and it's, if, if this comes to pass, Amazon would include, it would be exploring commercial opportunities and potentially selling a corporate version of chat GPT, uh, on their service. Uh, it's, it's interesting because in a sense, Amazon's competing with Nvidia in terms of a AI chip markets.
And, uh, a lot of people are actually, we, I think Dave Nicholson yesterday talked about more competition for Nvidia on this front. So not only Amazon, we've got Meta and others. And so, Mike, to go back to your original question, it's, I, it's, it's, it's head spinning.
I don't, I don't, I don't quite know where this is going. I think they're all going in on open AI until they turn against them and compete against them like Microsoft did. Um, it's, it, it's, it's, it's, it's just leaves me speechless actually.
Well, I think you have it spot on in that the Microsoft announcement was a precursor for all these other organizations to now invest in open ai. And one way of looking at this, Alan, is to say, Hey, you know, we're just passing the hat around for open ai, tossing a couple of billions, and away we go. That is one way of looking at it.
But, but, you know, there's a method, there's a method to Sam Altman's Madness, right? And I've said this before, I think I said it on yesterday's show. Sam Altman is the pied piper of ai.
He is the closest thing to Steve Jobs we've seen in the Valley since Steve, you know, unfortunately died way too young. Um, but here's the thing about all of these open AI deals, they're not that simple. It's not just passing the hat and throw in a couple shingle, you know, shekels from your pocket.
It don't work like that. It, there's always a, you give me this, I'll give you that. The money really doesn't change hands.
We just move it from one spreadsheet back to your spreadsheet, from my ledger to your ledger. It's a give and take. So for this $10 billion investment, and, and John, I don't know the particulars, I'm sure you do, but for that $10 billion investment open AI is pledging to do, you know, $20 billion in hosting with AWS on Traum infrastructure or something.
So for the 10 billion that, uh, Amazon's investing, they're gonna get 20 billion back in, in revenue. OpenAI is a company, you know, you mentioned the $750 billion valuation, God bless 'em, but they're on the hook for a trillion and a half dollars guys. Yeah, Right?
The ma it's just Yes, exactly. You don't go into one and a half trillion, they're still in the red by a hundred percent. 4 trillion.
Exactly. So what, and, and you just, you add up all Yeah. It's just like, there's like a chill game.
This is, So one of the things I was trying to think about is, okay, so like, where are the places that could be a single point of failure for organizations that are adopting ai that are trying to use the different things? So in, in one sense, you've got, okay, if Open ai, um, does whatever the money shenanigans are with Amazon for the, um, what is it called? Traum chips Cranium chip, that gives you a choice between, supposedly between Traum and um, NVIDIA's chips.
But it also No, No, no, no. It's a different, it's different. The Trane are inference chips.
Okay. And the inference chip, you got Amazon tra, you got Google's, uh, chips that they're making, and then of course, you're a Broadcom. Right?
Right. Those are probably the bigger inference chip competitors though. But though, what's his name, Jensen and, and Nvidia wanna get into that, but they clearly have the GPU of training chips, But they're also, like, Google's chips are made by Broadcom.
So it's a little fluid, and some people will use TRA to train versus the other chips that AWS has. So it's a, it's, it's not that clean. Right?
And so the, but the question is, if you look at what OpenAI does and how much money they're owing, this is my question, maybe it's a dumb question, but let's see. Um, and how much they're now owing by and trying to make up with these different partnerships. If the partnerships fall apart or if it doesn't really work, what is their, what are they trying to prove that, what, what do they have to do to shore up their business, making their open AI system better and getting more people to adopt it and use it, and then that rush to get the more adoption, does that have any impact on what it actually does, which is influences how information is derived from data?
And I think there's a little bit of a danger there. So there's more than a little bit of a danger. There's a big danger, and it's not to open ai.
And I'll explain to you in a second. First of all, what Open AI is doing here is classic business. They're locking down territory.
Th this is akin to European explorers planting flags on every shore they landed on. Right? OpenAI is in a land grab trying to grab as much of this market as they can.
The problem with this model is if OpenAI F Sam Altman has put open AI at the center of it, if it falters 60 plus percent of, of, of booked revenue in the future from, for Oracle, for all of Oracle is OpenAI, even Microsoft with a, what is it? Two $3 trillion valuation. A huge percentage, 30 something percent of their book data they're waiting to recognize comes from open ai, right?
There is so much open AI is on the books Core Weave, a huge percentage of core weaves revenue is, is open AI pledges. Now it's gonna be at Amazon too. And, you know, Amazon AWS is what, a 13 billion or 15 billion year business?
Something like that. You know, how much of that is going to be open ai uh, pledges. So this is, this is a setup for a classic fall where if I did this on Shimmy says a couple weeks ago, I had the Jenga Tower, right, with open AI's tile right in the middle.
You pull out open AI's tile, the whole Tower falls, The whole thing collapses. Yep. 4 trillion that you astutely referenced Alan Open AI's like hemorrhaging users to, to Gemini and, and to Claude.
Absolutely. And this is created panic within the company. But here's the one thing I, maybe this plays into it, I'm not sure, but somehow maybe this Johnny AI relationship with OpenAI involves Amazon eventually, where you have some sort of Consumery device.
And Amazon is, wait, Amazon's talking about business version, not a consumer Version? No, no commercial. No.
They might use it for commercial. Yeah. So, so let's wait, let's get Alistair in here for a second, since he's our new guest for the moment.
Alistair, what's your take on this whole thing? Well, I've been looking as, as all of us have the ridiculous amounts of money that are flowing around in, uh, this generative AI space, these chat bots, and it, it comes back to me to where the heck is all the business value that this money is supposed to generate. There's the gap for me is there's a whole chunk of money, and as you say, this is a, this is a land grab for compute capacity across the world by open AI and under them by core weave as well.
But all of this compute capacity that's gotta be built for all of the spend, how the heck are we gonna actually get business value out of it? I don't, you know, still hemorrhaging cash, you say, well, That's, that's what the Krishna Armand Krishna, yeah. Avan Krishna of IBM said.
Mm-hmm. Yeah. 'cause we've talked.
So forget just open AI for what they, what the, the powers that be. And it's the seven or eight people in that picture you talked about, John, or in the time man of the year, it's the architects of ai. They have them sitting on a beam, like the workers, you know, there's the eight, I don't know if you guys have seen this one.
It's a great shot. Anyway, they're talking about $8 trillion in data center build out over the next three to five years, $8 trillion. A we don't have enough power generation to generate to, to, to power those $8 trillion.
B, if you are gonna have, if you're gonna invest $8 trillion, what's a reasonable return? Right? And you're not gonna make it up in one day, even though every five years you've gotta redo these data centers with the next generation of equipment and infrastructure.
But so what's a reasonable rate of return? How much money can it make? How much money can it make to, to justify that sort of cap CapEx?
And, you know, it was one thing when Google and Amazon and Meta were using the hos of money they've been sitting on since COVID to invest in this. com bubble, you know, and when, when, when stuff goes south, someone's going to get left holding, you know, with a short straw here. But that's what You're starting to see evidence of it already with Oracle.
Yeah. I mean, well, that's what the government's doing, right? It's they're gonna use the government money to do it.
That's what the US Department of Energy is in charge of the whole, um, whatever the executive order was to build out the AI data centers in the us it's gonna be taxpayers. Are you saying, are you saying the taxpayers are gonna get stuck with this at the end? Is that where we're Going?
I think that's a possibility. Well, we're already paying, we're gonna pay higher utility costs for it. But, but guys, this isn't just a US problem.
The EU is bought into this. Our friends in Saudi Arabia are, you know, head down into it. This is that $8 trillion is not a US number.
It's a world, I I should mention that the eight trillion's a worldwide number. I think the US number's closer to five. So Alan, for the people who have forgotten, how does that Pi Piper story end again?
He, he leads all the, the children out of the village, right? It doesn't end well, not, it doesn't end well and never to be seen, Never to be seen again. Yep.
Yep. Mm-hmm. It's, it's a scary thing.
But that being said, you know what, you gotta give Sam Altman credit the same way you had to admire Steve Jobs, moxie and showmanship. So, do you gotta admire Sam Altman too. He's, he's, he's placed them in the middle of everything, pivotal in the middle of everything, a company that doesn't even have $20 billion in revenue, hemorrhaging money, like, like a, like a, a, a cut, you know, artery.
And, and, and he, but they're in the middle of everything and, and doing these deals. 10 billion here, 200 billion here. It's, it's, I mean, one day they'll do business school case studies on this And then, but to general, and they could Be either triumph or a tragedy story.
I'm sorry, Mike. I mean, look, maybe, maybe we're all, we don't see it that he does. And, and maybe ai, when you start putting it in robotics and GenX and everything else, and it puts us all outta work and, and we just sit on SBO chairs and grow fat, right?
And Sam Altman looks crazy as a fox Maybe, or to John's point, you know, everybody moves over to LLMs from Google and Microsoft and smaller LLMs and open AI winds up being, you know, the biggest bubble in history. That's a, that's a possibility actually. Yeah.
I would discount that you, there is, you Know, when you, there is a PT Barnum element to it, right? So, I mean, Steve Jobs was a PT Barnum, but he, I mean, he d delivered in a sense. This one, we is yet to be known.
And, and if you wanna be in the middle of everything, you also take a lot of risks by being in the middle of everything, you're, you're, something Falls, falls aside or a kilter. There's a lot of possibilities for things to go badly. I'm not saying it will, but it just raises alarms for me at least.
Absolutely. Well, it's Friday. Let's not end on a bad note here.
We got a lot of good stuff coming up on Textron Gang. Um, let's take a quick break, Mike. We've got more.
We've got Microsoft AI agent machinations. I love that you're watching text and gang. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions. Your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black cloak, digital executive protection, defending the new attack surface your personal life.
Hey folks, we're back and we're talking about the latest AI announcements from Microsoft involving VS Code. And if you've been following Microsoft over the years, sometimes that M stands for Mud as in clear s and Microsoft is basically talking about how they're going to embed this kinda agent control plane into BS code and their app dev strategy. But at the same time, they're also, um, deprecating certain other AI related tools that they have created over the years.
And it seems like they're trying to make a play to be kind of the central control mechanism for all AI agents related to anything to do with software development. Gina, I know you read this story. What, I mean, what's your take on what's happening here and, and how did you read this thing?
Well, I read it and, um, it looked like it was good stuff and bad stuff. So it looked like there was really good stuff. People were happy that, um, Intelli code, well, well, not the Intelli code, that the transcript seven is, it was all updated and it's great.
And it's newer model, new newer language. Everybody's happy with that. The copilot stuff is, o is obvious.
They just want more copilot, um, subscriptions. They don't want really, um, they don't wanna give anything away for free like they were doing with the Intelli code. But the, the rest of it is just like, it's such a total product market.
My product marketer went crazy because reading this, because the, the person that wrote this was just like, the messaging sucks. This is the worst messaging ever. We don't know what Agent HQ is supposed to be.
We don't know what all of these terms mean. We don't know what it's going to do. So that's why I had a bunch of questions about it.
And, and, and for a platform for agents, there have to be tons of questions about it. I mean, I'm trying to build an agent right now, and I'm totally within that 85% of what I'm trying, the agent came out is wrong, and you have to go back and, and rewrite it. And, um, there, there's so many security implications that I don't even think I've caught all of them with my dumb little agent that doesn't do anything.
Um, so I'm terrified to put it out into the real world to see If it'll, well, tomorrow I think everyone has, you know what Gina, everyone I speak to has a very similar experience. I tried to build an agent and it sucks, right? I, as, as a rabbi, when we were at AWS on the way in, in the cab, uh, from the airport, there was a sign, or maybe it was in the airport, Databricks, our, they said, our agents don't suck, But why don't we call 'em bots?
That's the thing I don't understand. So to have this, well, Bot bots, bots have a bad connotation, security wise, right? These would have a bad connotation security wise too, because they are bots.
Yeah, right? That's all they're doing. My, my little agent is nothing.
You know, it's got one little piece of, of an open AI call, but it's basically calling a, a open. Yeah. It just, it just, no, it's, it's just calling APIs.
It's not doing anything interesting. It's a freaking bot and it's full of security holes, even my little stupid agent. But I think that's, um, what the big deal if, if you're gonna put like this agent platform out, if, if the people who are going to write about it that really do understand all the Microsoft, um, um, releases and everything, and they're like, this, I have no idea what's going on.
'cause Microsoft didn't tell us what's going on, but they want you to use a platform to manage all your agents. Like how in the clear is that platform? Do you know what the platform's doing to the agents?
And there's secret agents behind it that ma that Microsoft wants you to use. And it was really confusing, Mike. Yeah.
So here's the, here's the deal. A couple of months ago at the big Microsoft Ignite conference, you know, and HQ is a platform and a strategy, and away we go this week and HQ is a statement of direction. We don't know exactly what this thing is looking like.
And I got a feeling that maybe there's not a whole lot of code to go with it right now, John, this kind of feels like classic Microsoft. Oh, it just Sure does. Yeah.
That's funny. That's funny how they changed the narrative, like just a matter of of months. Yeah.
This is, this is to be expected. And you're right, it's clear as bud and it's, um, the, the whole thing, and I'm glad you mentioned this, Gina, the whole thing about AI agents and why they are bots, right? And it's just a marketing phrase.
Maybe it's skewed, maybe they think it's, it's more embraceable, but it's, it's, this is part of this larger issue that I have with AI agents and I, I belabor this, belabor this argument, but it's just, it's just too much overwhelming CIOs, CISOs just put, your heads must be spinning. Like, wait a second, I thought you said this was gonna be the case. Now you're saying this is like, how do you, how this is why the adoption of AI agents in some cases is slower than anticipated because there's just so much noise and so much spaghetti being hit against the wall.
So guys gather round, let me try to make sense of this for you. Here's the deal. Here's the deal.
First of all, in terms of AI agents as bots, today's AI agents, six months from now, a year from now, we're gonna look at them and say how quaint, how quaint they are. Because most of the things that we're calling agents today are bots or even API calls, right? They're making API call kind of things.
And that's not really what the future of AI agents are. The future of AI agents will be autonomous tools that are persistent and aren't one trick ponies. Right?
Now what we're seeing are what I'm calling one trick ponies, right? I want my AI agent to take my whole workflow and work that workflow from A to Z, not A to B, but that's the promise of AI agents, right? That they will go A to Z in terms of Microsoft, it is classic Microsoft.
Microsoft is never the first one to a party. Ever make a party? Who's the first person there?
There's always some people who come early, not me. I'm married 35 years. I've never been early to a party in 30, 40 years since I'm with my wife.
But that's another story. Microsoft's never early to a party, but they never, like, they, they hate to miss a party. And so all they're doing right now is enunciating the same broad message that Salesforce, uh, ServiceNow, Amazon, and the rest of these people are, are enunciating, which is, I wanna be the control plane for your agents.
I wanna be the garage where you park your agents. I wanna be the Kubernetes the orchestrator for your agents. And that's what this is, this is Microsoft saying as it relates to software development, we wanna be the control plane for your agents.
We want to be the kube, the orchestrator for your agents, you and everyone else, Microsoft. But what Microsoft is betting on is though they're never early to a party, they're always the best dressed, you know, and they come with the nicest gifts and they bear, you know, and they, and just by their sheer tenaciousness and and market presents, they're gonna make themselves one of the top three. And that's what they'll do.
Are you saying that I'll not be getting a pony from Microsoft this Christmas then? Is that what you're saying? No, that's, there's no pony in that room.
But, um, but that's, that's, you talk about it and it, they don't know exactly what it's gonna look like, but they'll be there. I bet You You wanna hit something really significant in this, Alan, about how quaint these agents will look in the future. Currently they look terrifying.
They don't look quaint. They get things so wrong. They are so riddled with, with risks and, and dangers in them.
One of the things I pulled out of this announcement was the YOLO switch. You only live once. Turn on the agents, let them loose.
'cause you're going to get destroyed by this, right? We are not in quaint agents. We are in the terrifying early place where it was, uh, early radiation, right?
Earlier nuclear, your kids are playing with uranium right now. So is this, this is not the way the, The gremlins. Isn't that what happens?
Yeah. Well, but That's exactly what I thought, Mike. But you're gonna, you know, but hopefully we'll get through this.
You know, my grandmother used to tell us about raising kids. It's just a phase. They'll get through it.
This is, now Can I mention some, can I mention something really quick about, I mean, you mentioned tenacious. That's such a great word to describe the way Microsoft tries to convey ideas. I remember it as a reporter of like, when I was in, uh, mainstream publications, they would have you go up to, to Redmond and they would do these back to back meetings.
I'm sure Mike went through this, these back to back to back meetings all day. And it was a form of brainwashing. And by the end of the day, until you Said gifts, Yeah.
Until you actually were mimicking what they said, you were mouthing what they said. You go to Apple, that you have a briefing and you have five different viewpoints from five different people. If Microsoft, you'd have 20 people saying exactly the same thing and they would just drill it into you.
Eventually they would make their point. So I think the reason they call agents agents instead of bots, and I think this is actually an important thing, right? They want us to think of them as more human running off of being our coworker friend that's going out.
Digital Coworker. Yes. The thing is, technically we're seeing what we saw with really bad malicious bot 20 years ago, right?
It's just a thing that can do a thing and maybe it can pull other things. I mean, I was writing agents to build, to put, um, Linux on servers back in the early two thousands. That's all that jumpstart kickstart was.
It was something that was written with some code that said, go and do the pre-work. Go and install this little bit after it's installed. Go and do the post work.
Now do a test. That's all that these agents are doing. They are bots.
And if we talk about them like they are, they pieces of software to do specific pieces of things, and we want them to start interacting with each other to be autonomous pieces of software to do it instead of pretending that it's our coworker and we should have an agent managing the agents and a whole department of agents. This is just stupidity. Let's say, let's talk about having the right platform and having the bots.
I I'm done with agents. I'm not calling with that anymore. So, so there's a method to their madness, right?
And so the software company's been banging a drum for years about getting paid based on the quote unquote business value of their software versus just selling you a license. And this quantum aging provides a mechanism to kind of start billing you for the value of the perceived software versus just saying, here's a bot that's an extension of your existing license, But isn't an agent just the extension of your license. I would agree with you, bud.
I'm just telling you. Right? This is why I keep being a big company working.
These are the arguments I bring up in meetings. But one other thing though that I don't, I want to just, I'll leave us with this, is at the same time they're doing this, they're killing off a lot of the free stuff they were giving out. And again, that's the same old story, right?
The drug dealers in New York City used to do this first one's free, right? First one's free. They gave it to you for free to get hooked, and then now they pay.
So clearly Microsoft has decided that, hey, the time for giving out the free candy is over. Now people gotta pay for the cigarettes or whatever this is, right? And, and I I, if Microsoft is doing it, Google's gonna do it too.
Uh, meta will do it. They're all going to do it. We might be seeing the end of the, did we get, did we set the hook deep enough to start making the money here?
Because we all can't have open AI balance sheet. Something to think about. All right, let's take a break.
We're gonna come back to Sea Block. I think Alistair's gonna help us with this one. I can't wait.
You're watching Texture and Gang. 2026 marks a turning point. Artificial intelligence is no longer just a tool.
It's shaping industries, accelerating innovation and redefining how humans build, create, and solve problems from engineering and medicine to finance infrastructure and everyday life. AI has become one of the most influential forces on the planet. That's why for 2026, we recognize AI as tech Strong's person of the year not for what it replaces, but for what it enables a future built together humans and machines predict.
2026, join us. Hey folks, we're back and continuing a little bit on a theme, but, uh, the folks at Code Rabbit put out a report this week, an analysis of 270 poll requests that were made involving open source tools and concluded that the number of software defects being generated by AI coding tools is much higher than what humans would be doing in a similar set of cases. And this goes well beyond vulnerabilities.
These are defects that essentially increase the technical debt to the point where while it's probable, your applications gonna eventually break. But Alistair, what's your take on this whole thing? Well, I think this, this study was, was good.
It was a, a great start to look at 270 pull requests. Uh, but you know, headlines from from a whole bunch of larger companies are saying that's how many pull requests we push through in a an hour or a day or whatever their headline is. Uh, AI co coding tools we know are very popular.
We've seen statements from a lot of large companies saying that huge amounts of their current code bases written by ai. So it's kind of surprising then that we're also hearing stories of code quality decline. There's been a lot of anecdotal coverage of this, particularly talking about Windows 11.
Code quality was the one that I saw quite a bit. Uh, the discussion around maybe, uh, Microsoft needs to hold all of its feature development to fix all the things that have been broken recently in Windows 11. And I know correlation doesn't imply causality, but this does correlate highly with large amounts of AI generated code.
So I am kind of skeptical about how much of a problem we're generating here. Now, one of the perspectives is that if the coders AI generated and it's going to be AI maintained, doesn't matter if a human can't read it so much. And this comes back to what we're covering in our last story, is how much do we trust the, uh, bots, the uh, agents that are doing this coding for us?
And how much are we just gonna hand the keys over for the entirety of our software development? Uh, do these technical debt issues that affect human coders also affect AI based coders? But I think fundamentally we are seeing that these, uh, AI coding tools are not up to the quality of a good software developer.
They are still giving us more the intern based level of, of coding. Uh, I talked about this on a recent episode of the Tech Field Day podcast as well, that the knowledge of the enterprise scale building of applications doesn't seem to be nearly as trainable in these AI coding tools as, uh, you'd hope that the very senior engineers who have vast experience haven't necessarily codified that experience in a way that can be used to train an ai. And that's why we're not seeing awesome application architecture being built by many of these coding tools.
Uh, I liked also one of the commentary in this article, which was around that AI coding tools are producing greater efficiency for developers. Uh, maybe not. There was a study conducted mid-year where the developers thought they were more productive using AI coding tools, but they com the study group actually completed tasks faster if they didn't use AI coding tools.
So is this productivity an illusion or is it that we have to use these AI coding tools? 'cause we spent lots of money on building ai. Are we actually getting something useful out of the AI if it's taking longer and producing worse product?
Well, that was mid-year. The world's changed since then. But let me, you know, I recently did an interview with the CTO over at Veracode, right?
Veracode's, big AppSec company. And anon, you know, anonymizing the data that they gather from their hundreds, thousands of clients. They, they actually have been putting out periodic reports on the security status and vulnerability frequency of AI generated code versus humans and so forth.
Um, and you're right, uh, the AI generated code throws off a lot of security vulnera, you wanna call 'em security vulnerabilities, bugs, defects, whatever you wanna call it. However, according to Veracode, and you know, they don't, this is just what their data shows. What I said about midyear is no joke.
The quality of code that AI is generating is, is on like a, a, a, a 45 degree upward plane. And just recently, like in September, October, it actually crossed the level of human generated code in terms of vulnerabilities and security defects, right? Let us not fool ourselves.
Yes, the most senior best developers develop better code than junior developers. I don't think anyone will argue that. But when you take the totality of human generated code and baseline that to the totality of, of AI generated code, they're, they're, right now they're roughly on par.
But one is at a 45 degree angle continuing to improve. And one is sino, you know, has been level for a while now. So the, the question is, what about six months from now?
What about nine months from now? But, but here's the, here's the soft white underbelly that I think gets dangerous. And it's a birds and the bees question.
Yes, our best developers are better than AI can code right now, but if we don't train and let our not best developers evolve, where's the next generation of best developers coming from? Right? We don't hatch these people in nurseries.
We, they, they learn on the job. And so that's the real issue is we can't say just let the best people develop. We've gotta, you know, we, we talk about things like human in the loop.
We gotta keep the human in the loop for a lot of reasons. That being one of 'em. So that these developers do learn to use AI as a tool, but become better developers, right?
Otherwise, this'll be the last generation of best developers we have. I also think that we need to use AI to review the code created by ai. But there's a a tendency where I see where people are using the same AI that they used to write the code to review the code.
And that's a fundamental mistake. 'cause that's just gonna Reinforce. Yeah, no best practices has to emerge where you, if you're going to use AI to check ai, you gotta have a different AI on it.
Mm-hmm. But you still, even in that scenario, Mike, you need a human in the loop, Right? And I'm also, you know, I am not the vice president of the United States, but I will engage in a little conspiracy theory here.
The AI code is, you know, extraordinarily verbose and seems to require a lot more computing capacity to run. And, you know, that seems to play into the benefits of the cloud service providers who want you to maybe consume more infrastructure than ever. I'm not saying that's a deliberate outcome, but it sure is coincidental.
I thought you were gonna tell me you're merging, merging with a fusion energy company. Okay, go ahead. I digress.
I think it's, I think it's a bigger, it's a bigger picture too, right? Like when you look at these surveys, like, like what Alistair said, it was a really small amount of, for this story, a very small amount of pull requests that they looked at. Um, and just in general, what we're talking about with the 45 degree co, uh, ai, AI's getting better and we're, we're dropping off here, but well, We're not dropping off, we're not getting worse Gina.
But human coding is steady. So, so, but what I was getting at is, I, I think there's specific things that AI code is probably really, really good at. I think the whole mainframe industry is one place, being able to go through trillions of lines of code to, to point out this is duplicated, this is duplicated, nobody knows what this means.
And really help the newer generation of COBOL developers that also fluent in different languages that, excuse me, to help them understand what the code was to help them see where to attack. I think that's really good, even with the older code too. But like, um, w with, you don't have developers that have the, the younger developers having the knowledge of how things break and, and that puts a whole piece into it.
I don't, I think that AI code, written code and checking the code, there's all sorts of places. It's really great for, like, if we're doing infrastructure as code, that changes so rapidly depending on the different pieces of hardware that are involved in an inventory of whatever an organization has. But being able to write the basic blocks of this is a Dell server, this is a, this type of interconnect, this and that.
It should be able to get to that and be easy to check and be easy to upgrade once you have, you know, what the differences are and save lots of time, maybe help people learn to code. I think that that should always be that human in the middle that you're talking about. This is something that, that an AI is not going to identify because there's not going to be a prompt to help it identify, because the human won't know that it's a problem until they go to run.
It Could be, I mean, certainly teaching people to code, I, I think AI is a great tool for teachers, especially like code, like, you know, that kind of teaching, you know, very, uh, rote kind of stuff like that. Um, I mean it, yeah, that's certainly a use case, but I think people are using it, you know, this vibe coding thing. I, I remember the first time I heard it here on the gang and I was like, I was thinking beach boys and, um, but who knew?
So, so how do you envision this working in the future? 'cause in my mind it might play out this way using your statement that says, you know, six months from now the AI will be a lot better. So are we all gonna get alerts from the new AI saying that the old AI was stupid and an idiot and I gotta go fix all this code?
How does that kind of play? Well, let me ask you, do you ever get an alert from a company that says, I'm sorry, one of our junior developers developed really crappy code, but we put one of our good guys on it and it's better now? No, you're just gonna get an update.
Hey, there's a new update click, It's bitter, it's stronger, Esoteric press release from Microsoft. Yeah. You know, But we'll see.
We've got accumulative update for you. You know, they do that. Yeah.
But These updates will, will also, I mean there's an element here of not just the individual AI get getting better, but as, as you're saying, you, you don't use the same AI to do the code review that you use to do the initial writing. You also don't use the same AI to do the optimization of the larger code base that you use to write the individual features. Mm-hmm.
And so as we see some maturity, we will see those, those ais uh, getting better at doing the more strategic element. Starting with a, describe how this should work, rather than describe the single feature that you want to have, or it'll be describe the path, the, the story. If you're gonna go agile, get, give me the story of the user journey through this application and, and the AI will generate from.
So when you're talking about human in the loop, it may well be that we see a very big shift from that human looking at the individual pieces of code and needing to maintain those pieces of code to ai. Looking after all of that, in which case the, the verbose code is, is great, but we're gonna want to then optimize it. Do the functionality that we've previously done with the compiler is gonna be to optimize and, and enhance the, the code that's actually being written by the coding AI to be better at execution time and development and production execution are two completely different spaces.
You may well not do that optimization until you're getting close to that continuous deployment phase in your development pipeline. So you absolutely, we will be seeing people using different ais for different purposes at different phases of their development as you use different humans for the same thing. I think this is where that 45 degree uplift and effectiveness is gonna be useful.
Eventually, there'll be a critical point where the AI code is better, but we're not there yet. We're still seeing lots of that legacy code that we're going to see an improvement in sometime in the non determinant future. Right.
Now, I know we have a predict conference coming up, but, um, here's my prediction for the next year. We're gonna see a lot more stories that start with Company X had experienced application outage because some software updates somewhere didn't go as planned, and a lot of it will be traced back to AI code. Do you think we could retroactively bring the CrowdStrike on it?
That will seem like it. Or Is that because look, what's that, That, that, that may seem like, you know, a mere footnote in history compared to what we might see. Okay.
I mean, it's not like it hasn't happened with humans coding that and that. Mm-hmm. You know, so, and that's a lesson there.
Should we hold AI to a different, uh, level, Standard Standard than we do humans Just because it's ai? Should it be perfect? 'cause certainly human code's not perfect.
I think we have done, to our credit, a better job of reviewing code and kind of preventing disasters. And when there are disasters minimizing the impact of that, I think in the age of ai, we may be trusting too much in the machine and not having those review cycles in place. And then we're, 'cause we're all in the name of productivity and speed and break things at all costs, maybe we're not paying enough attention.
I think someone will have to be held accountable for it, right? Because if the, if there is revenue lost because the code was incorrect, or even worse, human life lost or that kind of thing, God forbid that we will have to go through, at least in the us the same courts to say, you're at fault and you are required to pay this much, whether it's AI or whether it's a human. That's gonna have to happen.
Mm-hmm. Be interesting. Hey, we're about outta time.
What a great discussion today gang members. Thank you so much for coming on. Uh, as Mike mentioned, we do have our predict event coming where the, the good analysts of the Futurum group are gonna be leading the charge this year in our predictions for 2026.
That's on January 15th after the holidays. com right now. Click on Predict.
com and you could register for that event. We've got some great, great predictions and analysts, uh, kind of look ahead. I'll also mention that later today I'm gonna be doing my year end Shimmy says, my last shimmy says of the year where I'm gonna give kind of my look ahead, uh, for what's been an a year for the record books, that's for sure.
Well, we will not forget 2025. Um, so stay tuned for that. I also just wanna also point out, I'm, uh, shimmy says I did yesterday Thursday on should we break up Big Tech?
I saw a debate recently, a video of a debate, uh, pro and con on this, and it's fascinating. So check out that Shimmy says, um, ALIST, what about the next Tech field day? Are you guys off till the new year?
Yes, I, I'm, uh, doing the planning and organization for the next tech field day, which will be AI Infrastructure Field Day. Uh, that will be at the end of January 28th, the 30th. It's gonna be a nice big busy event back in Silicon Valley.
Very cool. John, I see a CES in your future. Oh, I think I'm gonna stop by for a couple days.
I actually got a, a reached out to Nvidia just to reach out to me. They're gonna be doing a big announcement the day, two days before CES starts with Jensen. I don't know what it's gonna be, but last year he talked about physical ai, so maybe something along those lines.
Very cool. Gina, what do you have? I'll be at, um, Alistair's Tech Field Day event, the AI infrastructure next month.
Very cool. All right, Mike, I know what you've got. You are waiting for pictures and catchers to report, And I am not leaving the Tri-State area for at least another 30 days.
Good for you. This is great. Enjoy it.
Well, it's not warm though. Warm. Alright.
I hope wherever, whatever you are doing for the rest of this year and the holidays is, is good and enjoyable. It's a time to recharge refresh, but 2026 isn't gonna slow down. So stay tuned.
We here at Techstrong at Techron Gang and all of Techron Ur Tech Field Day, we're gonna try to bring it to you. So check it out. But for now, this is Alan Hummel and we're out.
Hey, everyone. Welcome back here to Techstrong tv. My next guest is David Wang.
David is the head of product management at Tetra. David, welcome to Tech Drug tv. It's great to have you on.
It's great to be here, Alan. Thank you for having me. Yep.
David, we're gonna, we're gonna talk about the AI Infrastructure Foundation, what Tetra is doing with it. But before we jump to all of those things, let's take a minute to talk about David, if you don't mind. I, I mentioned you a head of product management over at Tera, but I gotta assume you've done other things in your life as well.
Yeah, probably too many. So I won't betray my age, but I'll, I'd love to share a few things about, you know, who I am and why. Uh, this is a great time, um, for me to be active.
Uh, you know, my, I started my career as a software engineer, um, but a lot of my career is folks around finding great use of great technology. So, uh, started in aerospace, spent all time, um, at, uh, management consulting, McKinsey, and ended up mm-hmm. At a small company called Databricks at the time.
Mm-hmm. Before eventually moving on to MuleSoft and Salesforce. Uh, and really tetras a great place for me because we started out in a very, very active area of cloud native networking security.
And we've translated that expertise into now AI workloads and protecting AI workloads and AI agents. Um, so what I've learned from my career is, you know, great technology is not super useful or exciting unless you find a great use and application of it. And sometimes it's not all about just the tech, it's about, you know, how people apply it.
I, I agreed. I agreed. Wow.
That's, that's you, you've, you've made the rounds, as they say, doesn't meanly you're old, you know, it just, you're moving around. Um, yeah, let's talk a little bit about Tet rate. Yeah.
Yeah. So, um, Tet rate has its DNA in networking, specifically cloud native networking, meaning Kubernetes and the like. Um, our core mission was to make networking an additive power, like a superpower for application developers to make your applications safer, to make infrastructure safer, easier to use and better.
And that manifested itself in the early years of a company as a, uh, service mesh and API gateway product. Um, and it's still actually being, it's still in active development. It's still very much a part of a company.
And we have customers who uses it primarily in the regulated industries, if it's in banking, in government, uh, pharma and the like. Um, and the reason why people want to use, um, Tetris product is really that, um, it is incredibly difficult to break the trade off between speed and security and availability when it comes to developing software. And our platform networking platform allows people to break that trade off and achieve all three more easily.
Um, how we got into AI is, um, well, how can you avoid AI in the first place, but it's also with a pool from our customers. So we're already protecting the workloads of our customers in the form of microservices and applications. And it's only natural that they kind of pull us in when AI workloads is really the latest frontier of, uh, different types of like, secure workloads that need to be secured.
Right. So, um, we started this journey about a year and a year and a half ago. It's a natural extension of our cloud native platform.
Um, but we've since made great strides around and love to tell you about it later. Uh, but today, you know, we are that definitely firing on all cylinders when it comes to ai, uh, as an extension of our core cloud native network security platform. Excellent.
You know, it was about a week ago, we reported here at Techstrong that the good folks at the Linux Foundation had started a new, I always call them daughter foundations, and if that sounds sexist, I apologize, but that's how I think of them. As, you know, daughter foundations or sub, you know, a sub foundations underneath the larger LF umbrella, but they started a new one called the Agent AI Infrastructure Foundation. And what I thought was really interesting is this wasn't just an AI foundation or an AI infrastructure foundation, but specifically AgTech ai.
Because I mean, clearly as we head into this new year, you know, uh, for the last half of this year, certainly, and, and toward the New year, AG AI seems to be where the action is. And so it's interesting that they're kind of out ahead of it here. What, what can you tell us about the A-I-A-A-I-F?
Yeah. Um, well, first of all, I would say it's a natural fit for Tet Trade because we are the company who's really behind AMLO in making a lot of the major contributions and which is already part of Linux Foundation. So, as you said, when, uh, the mothership, um, had, has this new foundation where a natural participant asked for A A IF, uh, I think it's, it's, it's a much needed focus on agents, um, because, um, vibe coding, um, initial AI use cases has migrated, has graduated into building, um, business aligned, business value, added even more business autonomous programs in which we generally call, uh, agents.
And some people might say, but Alan agents are just software. And sure, in a way it is like software, but it's a very particular type of software and in my view is very different than traditional software. So, if I were to think about traditional software, you know, comparing agents with softwares like comparing, like riding a bike to driving, like find a jet, like traditional software, uh, is deterministic.
It's kind of like riding a bike. You, you know, build it, you certify it, you test it, there is a lifecycle. Sure.
But, you know, as they say about riding bikes, you kind of like never really lose it. You know, how to ride a bike agents is different, their software, but they're probabilistic. So it's not like you build it once and it just keeps on working.
It's more like flying a jet. You have to keep on getting recertified to make sure that you know how to fly a jet and you can fly it safely. And that uncertainty comes from the probabilistic nature of agents.
And, uh, until we solve that as an industry how to meaning, how to make sure agents behave correctly is ready for production and delivering business value, um, we can't really reap the full benefits of AI and a foundation such as the Agent AI Foundation to focus on that aspect of ai, the aspect of AI and the tools around it, specifically things like model context, protocol, and infrastructure such as gateways, um, to deliver that benefit is timely and much needed. Uh, agreed. Agreed.
Um, so Tetrad is a member, I, I don't know if is the term founding member or original member here of, of the A A IF. Um, and, and certainly I think we'll be seeing bigger plans and bigger things happening with the A IIF in general. And then in particular, if it's okay, David, I'd like to pivot a little bit and talk about, uh, this Agent Router Enterprise a, a new product that, uh, titrate has released.
Yeah, yeah. Let me tell you a little bit about, you know, what, what we're building it for. Right?
So this is kind of going back to my analogy of riding a bike versus flying a jet. So, uh, early on, AI, a lot is focused on basically the bike riding variety, how to get people to build things fast, put things in prototype. Um, and look, I can't tell you if there's an ai AI bubble or not, but I can tell you from talking to our customers, there's gonna be a sorting game that's gonna happen, which is, of all the prototypes we build, which ones are ready, which are which ones are ready for production and delivering business value, and which ones are not.
Um, and that is, that distinction is crucially important because the ones that are ready to be declared ready and move on to deliver value will, will stay. And it'll be, uh, hugely beneficial for enterprises and individuals. And the ones who kind of are stuck in this, what I call prototype purgatory, will just languish and it will appear as part of a bubble.
Um, so Agent Router Enterprise is all about helping, uh, organizations, individuals, and teams to ensure that their agents that they were building is actually ready for production, ready for enterprises in real world use cases, especially in regulated industries where such proof is extremely important. Absolutely. Absolutely.
Um, you know, David, we're we're, this is recorded, obviously not live, we recording it the week before Christmas. Sure. I can't help but feel that the, the real story here will unfold over the course of the next year, Likely.
Yes. And, um, you know, if you could pull out your crystal ball here a little bit and talk about it, um, do you think we really will bring, like, standardization around these AI agents and tooling? You know, I, I've been in security a long time myself, right?
And security always lacks and security's never out in front. Yeah. It just seems like, are we being too optimistic to think that this thing will mature this quickly?
I do believe from a legal and security stance perspective, it will be very thorny for folks who officially align. But I would say that the pressure, the enthusiasm for leaders to realize the benefit of AI will accelerate some form of readiness, proof or some sort of standardization. Maybe not in the form of legal, maybe not in the form of book knowledge that folks can learn in universities, but, uh, it will be, uh, perhaps heuristics and practices that people will have to rally around.
So if you take the example of, uh, A A IF, uh, you know, one of its main pillars is model context protocol. It is organically emerged as an extremely popular thing, and it's organically being proved at a neck break pace, uh, because enterprises demand it. So yeah, I would say legally you're probably right, too fast.
Um, practices wise, probably not a moment too soon 'cause folks are already putting things into prototype and they demand some kind of a value realization. Um, I'll add the bit about ego, which is, you know, AI is not new in the broad sense. Machine learning has been around.
So where Tetrad operates in, in the form of regulated industries, there is practices of, you know, model risk management, uh, for example, in financial services. And many of them have inherited the awesome job of, uh, creating some kind of a standards and controls around agents. And whether they like or not, whether we like it or not, there's going to be some accountability for these agents that's being built and managed by perhaps these model risk management groups and existing standards such as SR 11 certain thing.
Like they will, um, be looked at as at least the starting point. And these teams and these standards do spell out general approaches that today folks are not really ready to meet without something like Tetras Agent Router Enterprise to provide basic information about compliance and traceability and governance. Um, and aside from just the security aspect, generally as the, uh, adoption happens with ai, it's not just a security or governance problem, it's actually an adoption problem as well.
Um, the amount of new technology choices is flooding the market, and it's creating huge problems for builders and engineering teams on what's the best way to go forward. Um, as an individual. It's a, it's the best of times and the worst of times because, you know, you have all these choices and it's great, but it's bad because, um, like after that initial build, how will you create some kind of accountability or proof that what you built is lasting and impactful, especially a big problem with engineering leaders or technology leaders.
There's all this innovation happening in the teams. Like, how can you actually translate that into provable enterprise value for your executive team? That is a huge problem that's still to be solved by innovators.
Yeah. You know, and, and it's funny because it's a, it's a bottom up, top down the top is pressuring use ai, use ai use ai. Yeah.
And then at, at the same top, you know, at the other side of their mouth, is this thing working? Are we making money on this? Is this profitable?
Is this, you know, Well, as an engineer, I can tell you that it's definitely working, but as a leader, I can tell you that I'm not sure if I can trust What the money. Yeah. Well, and that is a paradox right there, right.
We see it over and over. And I, you know, and this is why I say, I think in this coming year, we're gonna see this play out and, and hopefully get some answers because you're not alone. Yeah, right.
I, a recent survey I saw 90% of developers are using ai, ah, 90%. I Wonder who those 8% are. I would like to meet them.
Yeah. 40% don't trust it. 65% thinks it thinks that it's introducing instabilities into the code base.
Mm-hmm. But yet they still use it. Yeah.
So it's, it's a bit of a paradox, but I think it will play out. David, you know what I didn't, uh, meant ask you is for people who want to get more information on Tetra, what's the website? io.
io. Yes. And the A A IF.
You wouldn't happen to know the website for that, would you? No, but I, I think if you just search for ai, AI foundation, it's all over the news. And, uh, yeah, it would be a great place to follow the happenings.
It's just, just new. But I'm sure there'll be lots of great things to come. That's the beauty of the internet, even before ai.
Um, you can always find this stuff. David, thanks for coming here up on Tech Truck TV today. I appreciate it.
No, thank you for your time. It's a pleasure. My pleasure.
Best of luck to titrate as well as to your work with the, uh, A A IF I'm gonna have to learn how to say that better. A A IF and we'll see how this agent router, enterprise product, you know, picks up steam in followers. Yeah.
There'll be lots of more exciting things to, I hope to talk to you about it again in the new year. Absolutely. Happy holidays in New Year.
David David Wang, head of product management here at Tet Trade, our tech trunk tv. We'll take a break. We'll be right back.
Hey guys, thanks for the throw. We're here with shahara. Azule is the CEO of ground cover, and we're having a little chat about observability because, well, the game is changing.
We have more, uh, bring your own cloud kind of environments. We're talking about, uh, repatriation and workloads sometimes, and even sovereign clouds are an issue. And well, we need some way to observe it.
And well, right now that may be a little harder than we think. Shahara, welcome to the show. Hey, Mike, thanks for, thanks for having me.
So, walk us through what's changing here. We, you know, historically we go all the way back to, we had application performance management platforms, and then we saw the rise of observability, and, but we now have workloads that are kind of more distributed than ever. So how does that change the way we should be thinking about observability?
So basically, we, we see that kind of as, you know, a few waves of, uh, software delivered that's kind of changed over time. Uh, if we, you know, roll back maybe 20 years, right? Uh, some of us, uh, you know, remember that that period of time we used to kind of consume software like a physical product, right?
It ran OnPrem. We used to purchase it, maintain it, uh, it was ours kind of, uh, in a, in that sense. And, you know, suss kind of changed that, right?
Uh, we used to, we started consuming software over the internet online. It made sense. And, you know, with the boom of cloud, it kind of all connected to the fact that basically we're consuming everything online, right?
All of our services are almost third party managed. Um, this starts to make less and less sense with data rich, uh, applications like observability, security, ai, when the third party is basically holding a lot of data or consuming a lot of data from the customer side, for example, for observability, which ground cover, you know, that's our field. Um, we have a, you know, our, our medium customer sends a hundred terabytes of logs per day, you know, to the backend, right?
Sending that over to a SUS vendor. That's where the SUS architecture kind of starts failing, right? It starts consuming a lot of data is start to pay for it.
You start to be concerned about data privacy, data residency, data security, uh, you know, while shipping all, all that over the internet. And that's, uh, where SS is evolving to what we call BYC or bring your own cloud. So does that mean I need to move the observability platform into something that looks more like an on-premise environment?
Or am I trying to get to something that maybe is a little more federated? How will this play out? So, uh, we we're all used to thinking about on-prem and SUS as a binary choice, right?
I'm I running everything OnPrem, and then, you know, I'm, I'm biting my tongue on management and, you know, maintenance, and I have a team kind of taking care of that. But I gain data ownership, I gain security, I gain, I gain control, customization, whatever I want, right? Or I choose the other part of the binary choice and just take a SUS vendor, and then I get a managed solution.
You know, headache, no headaches, you know, someone piece managing it for me. But I lose that sense of, you know, budget control, data ownership data, data and all that bring on cloud is basically kind of the, both, the, the best of both worlds in one. The data plane is on-prem, which basically just separates the, what, what is the data plan control plane in sas?
The data plane is OnPrem, like you used to thinking about OnPrem, it's yours. It's running in your cloud premises. It's secured, it's private, but the control plane basically manage the infrastructure that all this, all this database resides in is managed remotely through cloud primitives.
That basically allows us as a vendor to scale it, back it up, update features, fix bugs like you would expect from a SAS vendor, right? So you get all the benefits of sass of hands off deployments. Some is managing it for me, guaranteeing SLA resiliency while the data plane is OnPrem.
So I don't have to worry about, uh, data cost, data residency, data privacy, or any of these things that I lose when, you know, shipping the data to sus vendor. All right? So I get to have my cake and eat it too, as it were.
I'm, we were also talking about the age of ai. And I cannot help but wonder if these AI agents that we're all trying to build will, um, also maybe provide a layer of, of abstraction for engaging with observability data that I may not know, or, well, I'm, I'm probably still gonna care, but I don't necessarily need to know where the data actually resides that I'm launching my query against. Is that fair?
Yeah. And I think, you know, it's clear where the world is going to, right? Uh, anything that is data heavy is gonna be, uh, abstracted away by ai, as they say, right?
I, not everybody can, can be a power user. Not everybody can know how to query their logs, traces, metrics, whatever it be, you know, with a proficiency of what AI can offer. Basically, we can think about it as, you know, the best SRE in your team that you just, that don't have, right?
That knows how to get insights from this data that we collect. Um, and this is exactly where, bring your own cloud, that that's our belief, right? That bring your own cloud is enabler for ai.
Because again, sus kind of wears away a lot of what AI needs to be, uh, performance. You know, one of the things that AI must have is all the data in one place, right? When it comes to sus, I'm already, you know, um, I already have a lot of friction with the vendor about the pricing model, like pay per gigabyte.
I, I'm trying to reduce the data that I sent out. And we see that the, the market is moving away from that, you know, single pane of glass dream into multiple vendors after, you know, organizations kind of optimize the pricing model for each of the verticals and observability, right? They have logs there and traces there to kind of survive the day budget wise.
So that kind of wears out what AI can do because data is distributed. And also, I'm, I'm constantly trying to reduce data volume, sample rate limit, because I don't wanna pay for all that, right? Mm-hmm.
But it comes to bring your own cloud. Suddenly we go back to the basics, right? All the data is in one place.
You can store export data, which with much more cost effective choice. And you also get data privacy and the use of your AI in your cloud. For example, if you're using AWS and you're using Bedrock because you don't wanna send all the data to open ai, which makes sense, right?
You can use Bedrock on top of your, bring your own cloud and basically consume your observability data with the AI agent of your choice inside your cloud premises. So we see it as enabler of people being able to even easier con con consume, uh, data with the abstraction of AI, query data with ai, get insights with AI over the bring on cloud, uh, data plane if you want. Right?
And if I don't do that, don't I wind up in some sort of weird paradox because I'm limiting the amount of data that I send into the observability platform, so I'm not getting as broad an analytics analytics as I should be, and therefore I'm just kind of making decisions on a narrow based set of data that's probably not helpful. Yeah, I mean, it's, it, we're, we're, you know, entering 2026 in a second, right? And about three quarters of the world, uh, the organizations of the world, right?
Don't have traces. That's, that's the situation right now. I mean, open telemetry adoption is slow.
It's hard. People don't have traces. So say you ask your AI agent, tell me what's wrong with production, right?
Um, it's a, it's only as smart as a data feed into it, right? So if you don't wanna pay for a PM or you don't want to instrument a PM, um, you know what the AI agent can do, right? Use the data that you have, the logs that you've instrumented and the things that you put in.
It's only gonna be as smart as that, right? So with bring your own cloud, with the EVPF agent, for example, that ground cover facilitates, it's the ability to, to collect data that that is agnostic to what your developers are doing, but also store masses of this data without being concerned about, uh, budgeting and trade off as much, right? So suddenly you can ask questions, and the AI model will now have much, much more granular data to operate on top of it with all the contextual, um, correlation that it needs to kind of get that insight.
And that where it becomes really, really powerful, because that's where I shines, right? Going through terabytes of data and, you know, getting that, uh, needle in the haystack when all that this data is, you know, granular and contextualized and collected properly. Mm-hmm.
And I'm not sure everybody knows what EBPF is, but it basically sits in the Linux kernel and kind of gives you visibility up into everything that's running on that version of Linux, per se. Um, does EBPF eliminate the need for open telemetry agents? Or are they gonna be more complimentary to each other?
How's that gonna play out? Eventually, we see that as complimentary, but, um, the reality is that EVPF is, uh, is a, is a different way to observe the data. And the most important, uh, reason for it to be very, uh, effective is the fact that it's completely decoupled from your, what your development or developer organization is doing.
Right? Open Telemetry requires you as an, as a vp, R and d or you know, as an r and d team to take that journey, right? Instrument telemetry, figure out how you wanna use it, figure out how you wanna sample it, what you wanna instrument, and then take on this journey, which again, most organization will never finish, right?
Not because they don't want to, because not everybody knows how to be proficient in something else, but the product they're building, right? It requires a different set of proficiency. EDPF is kind of decoupled, as you say, from the Linux kernel.
It's a Linux kernel capability. I can observe traces going in and out into my application without you doing anything as a developer. So suddenly I get that unbiased, um, you know, kind of layer of observability that will always be there, regardless of whether you've instrumented or not.
If there is a specific point you've worked to instrument with open Telemetry, great. That's already opinionated. You care about it.
So we'll, we'll enrich that with eeb PF and make sure that the two combined. It's not, it's not to say that open telemetry isn't important, but it's so hard to get sometimes that Eeb PF is just there to kind of, uh, you know, cast a wide net of anything you're missing, Right? 'cause otherwise, I kind of have to have a set of DevOps engineers who know how to deploy open telemetry so I can instrument my applications that the rest of the DevOps team is installing.
Right? Exactly. Which is not easy, right?
Not, not everybody can, can go through this journey and be successful at that. Hmm. Ultimately, is observability gonna become a lot more accessible?
And I'm asking this question. 'cause when I talk to people, uh, initially they were all, at least, you know, we have monitoring tools and those are predefined sets of metrics, and they're kind of like, well, that's good enough for me, because frankly, I can have an observability platform, but I don't even know what questions to ask it. So are we gonna get to the point now where the AI knows what questions to ask and therefore can really, you know, augment and help me out and make observability worth the journey?
Yeah, but I, I, I think we're definitely going there and, you know, AI is gonna help a lot. But again, I think the problem is so, so much more basic, most organization are, you know, in survival mode of the data that they collect, right? Um, you know, when we, when we think about bring your own cloud from the ground cover perspective, again, you can think about it as an architectural meta method, right?
To change the way data is being stored and managed. Uh, we could have stopped there and say, great, you know, the data's ran running on your, uh, you know, data play right now, it's in your cloud premises. Uh, we did our part, right?
But that's where we take it to the next level to make observability more accessible. Because one of the things that are most painful right now is that observability is packaged because of that price per gigabyte. That's, you know, that data budget trade off, it's packaged with multiple different, uh, product lines.
Uh, most big vendors have 20, 30 different product lines. You pay for log management, you pay for infrastructure monitoring, you pay for a PM all separately, right? So not all organizations choose to activate all these features.
And, you know, again, when AI comes, comes into the picture, if you don't pay for the data, AI is not gonna know anything. So that's where Corp, for example, took that choice of, if we're already doing, bring your own cloud, if we're already sa saving the data on your premises, if you're already paying for it as a customer, right? 'cause we, we've separated that equation, now we can package the product differently.
And we, um, provide all the ver verticals, observability all under the same pricing umbrella. Therefore, when it comes to ai, all of our customers will have traces. All of our customers will have logs and metrics and so on.
And that's, as you say, where AI will come in and basically alleviate a lot of the, you know, query language barriers, how to build alerts, how to build dashboards where people kind of get stuck. This will make everybody a power user, but the data is the most important thing on that journey, right? Mm-hmm.
And once I have that level of observability, what I need, my traditional monitoring tools, 'cause it seems to me like I could just program the observability tool to monitor things already. Uh, well, we, we definitely imagine a world where you, you're not, you don't necessarily visualize and set alerts like today, right? It's every, everything is very structured and limited right now.
You wanna visualize a specific graph, you wanna set a specific alert. It'll definitely be much a bit more flexible than that, right? You will correspond with, you know, your observability agent to, to that sense a bit more freely, a bit more unstructured.
And data will be, um, you know, um, much more accessible outside of these, uh, specific use cases where we, we there, they're definitely still gonna be there, right? Of setting alerts, getting them into PagerDuty, you know, waking up at night and all that. Uh, but data's gonna be a bit more, um, flexible to, to access and query and engage with, uh, outside of these, you know, strict, uh, options.
So, what's your best advice to folks about how to get to where we want to go? 'cause I think a lot of folks are kind of overwhelmed with the, with what the piece parts and everything that has to come together. But is there a simpler way to get started?
And where is that? Yeah, so I, I think, I think my advice is definitely, you know, figure out if you're, if you're paying right now, is that you don't have all the data or you're limiting some of the data, uh, in, in most cases, the answer is yes. If, if, so, I think you need to look into alternative architectures and alternative data collection methods like EVPF or BRI Cloud.
com and see that in action. But it's just an example of how the, how the market is shifting towards, uh, new data collection methods, which, which are easier and new architectures for observability that makes sense, right? That are scalable, that allows you to store the data that you can, so that you can definitely query it, you know, with AI and with all the use cases we discussed.
All right, folks, you heard in here observability. It's really a data management problem and work backwards from there. Hey, Shahar, thanks for being on the show.
Thanks for having me, Mike. All right, and back to you guys in studio. Hey, everyone, welcome back here to Techstrong tv.
I'm so excited to have my next guest on, you know, we were talking for way too long in the green room before we got on, but the first time I, I interviewed my friend Andreas Prince. It was at a, I, I'm not even sure if it was a DevOps world or a Jenkins world still, but it was in nice France way before COVID. Good times.
And, uh, you know, we've been talking pretty regularly ever since then. So let me introduce you. If you don't know, to my friend Andreas, and Andreas is the head of sovereign solutions at SUSE now, but, and Andreas is, oh man, he's had a storied career.
And Andreas welcome. Thank You. Thank you for coming on.
You know, I, I hope I didn't embarrass you, but give people a sense of your journey. Yeah. So our journey, right?
Started indeed in nice, I do think it was the first year they left Jenkins world and called it DevOps world, right? They were really trying to bridge. Uh, but I started very much in, um, in actually in digital transformation.
So helping organizations to pivot to more agile phos pace ways of working. Did a lot of CICD automation, release automation type of companies. Uh, and then the last startup was all about observability.
And that was acquired tech state by Susan. And then I joined the bigger family, which is really, really interesting, uh, because all of a sudden there's much more power, right? Than rather having a single product you all of a sudden, uh, can influence platform polio.
Um, mm-hmm. So I'm now global head sovereign solutions and building actually our proposition around sovereignty, taking our products to markets, finding new partnerships, and, uh, yeah, really helping out Europe, middle East, Africa, to become more sovereign and more autonomous, if you like, from a IT perspective. Yep.
Thanks for that, Andreas. And, and congratulations to you on this role. I, I couldn't think of a better person for it.
You know, Andreas, the whole idea of, uh, it sovereign, uh, sovereignty, data sovereignty, cloud sovereignty is really come to the forefront over the last year or two. We are living in, you know, I wasn't alive then, but in the, in the lead up to World War I, and let's hope, uh, this isn't a lead up to another war. But in the lead up to a World War I, we saw sort of old empires dying out, new nations, emerging new alliances, new new ways of doing business, you know, because there was a bit of an industrial revolution going on there too.
You know, the Austria-Hungary empire, the Ottoman Empire, they were breaking up countries like Italy and Germany, you know, were new, new countries back then as modern countries. We, we look around today and we see a little, not exactly that, but we see similar kinds of things the EU arising as, as a, as a power in this multipolar world, right? It's not just the two superpowers that you and I grew up in the world of, um, technology is just changing our lives and, and the promise of AI and what it can bring.
Yep. At the same time, we're also seeing, I, we're seeing a lot more violence. We're seeing authoritarianism, we're seeing, you know, uh, different factions fighting for freedom, freedom of the press, freedom of speech, freedom of information.
It really is a pivotal moment, I think in history. I, when we look back at 2025, yeah, in many ways, 2025 is gonna be the first year of this new century. I think for the first 24 years we were still living in a 20th century world.
Yeah, It's been changing, but now clearly we're not in the 20th century anymore. We're in the 21st century. And sovereignty is, is part of that.
How do you think, how do you feel about that? Well, I, couple, couple reflections on that. So one of them, right, is I do think the first 25 years has helped us to accelerate when it comes down to an innovation perspective, right?
So all the cloud native, uh, application landscape, et cetera, right? Help us now to run AI workloads in a very controlled way, right? So the first few years have been needed to accelerate and innovate where we are right now.
So there's definitely a connection. But I do think we're also entering a very interesting phase, because you could argue the entire sovereignty thinking from an innovation perspective is a bad thing, right? Because Europe is a kind of closing Middle East Africa, right?
So we're making the world smaller because all of us are focusing on our own geographical, jurisdictional region, and sometimes even down to a country. And when you think about innovation, right? Where you need muscles to really accelerate and experiment and whatever, I do think sovereignty as such might be a bad thing when we look back.
However, I do think where it's a really good thing, and that's also what we see happening at our customers, is companies, executives, leaders, they all of a sudden, well wake up, if you like, to understand their dependencies, their dependencies on hyperscalers, their dependencies on the chips. They use their dependencies on the entire software supply chain. And I do think that awareness is a really good one, because hey, you need to determine your levels of business resilience.
And it obviously contributes big time to that. So the positive side in my mind of the entire sovereignty movement is that we see a reassessment of risk, um, right? No longer is a data center below sea level, um, a threat, but it's an opportunity compared to an American hyperscaler.
For some companies, they were in the past, we would've made a different choice. Um, so bottom line, right? I do think it's just the next transformation that we'll go through in our thinking, and then also followed by our IT choices and implementation in, uh, in engineering.
I love it. And I don't disagree with you at all here. Um, it, some of it makes me sad because I do think, you know, as, as a, not even a child of the internet, I was already an adult when the internet, you know, went public, went commercial.
But as, as someone who spent their career in the internet, let's say, um, I loved the i the global nature of it Yeah. That we're all one, one community. Yeah.
And, and this sort of thing, you know, building walls, I always like tearing down walls. Yeah. But you know, this, this, this is the world we find ourselves in.
Yeah. Andreas suse has a, an aggressive sovereign solution product line, if you will, or vision, right? It transcends just Linux or rancher, Kubernetes or SUSE software.
Yeah. It, it goes to the heart of the data center and support sovereign in every sense of the word. Yeah.
Expand on that for us, if you don't mind. Well, If you, if you think about it, right? That the world becomes or gets smaller, right?
Or people start to look at their, at their, uh, continents, if you like. Um, then the question is, what is still helping you to cross, uh, to, to, to, to step aside, right? Cloud Act or Cyber Resilience Act here in Europe.
And then I do think there are only a very few elements that are still helping us to build software that can be used across the world. And that's open source, right? So that direct effect of using open source is, it gives you the freedom, right?
To build it yourself, to create it yourself, to enhance it, and to, to, to use that to your own, um, needs. And I, what we see happening here at, at SUSE is air open source was obviously always our top, our top lever. Uh, but today, fascinating enough, all of a sudden, the market is also requesting a proprietary software, right?
Where they don't, or not able to assess the risk is no longer suitable for governments, uh, for public sector, for healthcare, for mission critical, um, industries. So the fact that suse, right, as a firm believer of open source has that at the core of their DNA while, it's really beneficial for us. So what we're doing is we're not only bringing our existing products to the market, but we're also rethinking is, hey, but what does it mean that we have features, like, for example, reproducible builds, right?
That you can build anywhere across the world in any data center. You still get the same version of the software out. What does that mean from a sovereignty perspective?
Um, and we see and start to learn and have learned in recent months that we have a lot of diamonds in our portfolio that are perfectly suitable and powerful for a, for a sovereign solution. Um, and then we start announcing that with sovereign support, eh, as an example where we say, Hey, for Europe, if you want to use open source, but you still want to get enterprise support, we have a solution for you as well, which is sovereign premium support. So that's really what we have.
And then we're adding on top new features, new services, uh, new partnerships to, um, to expand. We're gonna, we're gonna dive into that in a moment. I, I think there's a, there's an interesting or an ironic kind of piece to this, which is at the same time, as you say, we're making smaller, we're putting up these walls, we're also relying on open source, which is the ultimate wall buster, right?
The ultimate uniter. It unites us all. We all can, everybody can use open source.
We're using open source to build this sovereign, uh, offering. And, and that, you know, there's a, there's like a, I forgot, not a dichotomy, but there's a, an interesting paradox there. We're using open to do Sovereign, yeah.
Closed, yeah, yeah, yeah. Make close. Well, and I, I would re I would not use the word closed, I would say to gain control, right?
Because ultimately it's about control, right? Knowing what is the software used, what are the packages in there, uh, what are the libraries being used, the vulnerabilities, the license types, right? And open Source helps you to assess that very quickly and very clearly.
Absolutely. And Andreas Souse recently announced a partnership and alliance with evoc. So I don't know if everyone in our audience is familiar with EVOC and certainly with this recent announcement, why, if you don't mind, give us a little evoc background.
Yeah, definitely. So EVOC is a brand new, um, M-S-P-C-S-P really focused on helping governments, public sector, mission critical companies in Europe to increase the level of sovereignty by providing an infrastructure, a modern AI platform that is entirely European. And when we speak about entirely European, the data centers, uh, the personnel, the type of support that is delivered, um, and that's then bundled with lots of open source software that they can support or are supported by companies like suse to build a stack on top where, um, companies can actually make use of, so imagine, right?
Governments, um, that say, Hey, I wanna decrease my dependencies for my crown jewels, my mission critical applications on an hyperscaler, not for all workloads, but for a few, are there alternatives in Europe, right? Where I can put skill, um, and, and, and put my workloads on. And that's actually what froc is doing.
So they have data centers across Europe. Uh, they're continuously expanding, um, but they're really, really sovereign. So they're founded pretty recently, only a few years ago.
So they start building it with sovereignty in mind and with a modern approach in mind. And, um, yeah, that's what goes really well together with, uh, with suse, if you like. I love it.
Um, talk more about the strategic alliance. Yeah. So imagine, right, a customer who would pick a company like SUSE to say, Hey, I would like to have a, a full stack from a software perspective, Linux virtualization, uh, cloud native rancher management on top, um, without sovereign infrastructure, right?
You are as sovereign as the infrastructure. You run it on, on the EVOC side, right? They could argue saying, Hey, we have a very sovereign infrastructure, but if, uh, the sovereign on top isn't sovereign, you're still as sovereign as the sovereign that runs there.
And that's really what we would like to achieve and have achieved by merging the two, using the infrastructure from froc, and then the software from SUSE on top, the Linux layer, the cloud native layer is really enabling customers to pick an entire sovereign stack and start migrating workloads, uh, head containers or virtual machines towards that stack. And that's then combined, and that's also the strategic element here with sovereign support from both parties. And because that truly makes the solution, uh, sovereign.
So it's infra software and services from both parties combined, which is our sovereign offering that we've brought to the market together with avo. We love it. Now, look, I get that a lot of this is aimed primarily at Europe, but you mentioned the Middle East and Africa.
Yeah. Um, are there plans for data centers in the Middle East and Africa, people based there, or will they use Europe sovereignty, if you will? Well, so, um, so a couple, couple very interesting moves going on.
So Europe is definitely a trusted body place, country, right? So when software comes from there, it's very often what we see happening, accepted, for example, in Africa as well, right? So software created here, um, is very useful when it's open source in the other two regions, middle East, Africa, but also countries like Japan, right?
So that's, that's why it's really, really global. Now, from a data center perspective, right? There's another challenge you need to solve, and that is what is your vision or where your data from a jurisdictional, um, perspective needs to be?
And what we see happening is that data centers in Europe, right, are not sufficient to host, for example, a South African bank or, uh, whatever bank or insurance company that is out there. So they still pick, um, local data providers and the same to Middle East, right? Middle East is not a single region, right?
There are multiple countries with all their own rules and their own philosophy when it comes down to where the data needs to reside. So although, right, our ever partnership is absolutely the first one, right? That, that tick all the boxes from a sovereignty perspective, obviously, right?
We have partnerships across the world when it comes down to, uh, to data centers. But what we want to do is really help them to increase the levels of sovereignty, um, as such, right? By, by software and by support that we could, uh, that we could deliver.
Yeah, Absolutely. And We also, an important element, a lot of people think, right, that it's that sovereignty is, is black and white. So they say, yeah, we now need to leave, all of us need to leave the hyperscaler and move to a party like Evro or whatever data center here in Europe.
And I do think that's the wrong philosophy. You first need to assess what are the most important crown jewels or the mission critical applications. These are the ones you need to consider and probably still conclude, right?
That you can run them on an, on an American hyperscaler because your business simply runs and in the US and runs in Europe, right? So you de-risk Europe, but there's, there's no reason for doing that. Um, so governments, for example, they can take a bit more an aggressive approach, um, and they're moving, right?
Or they're at least decoupling their hard dependencies to the, to the hyperscalers. But I do think people really shouldn't see it as a black and white. Uh, but really as a nuanced approach, some ordinary workloads, well let them easily scale up and down at an hyperscaler, right?
Versus some mission critical ones that you would like to protect with data and whatever you could run on a European data center. And I do think we're quickly losing that balance. Um, but it's a very important one to, uh, to add to the, to the conversation.
I, I agree. A lot of it is about data, right? Yeah.
And, and because that's really, now, yeah, the, the question may become, if that data ran on this application and this application's not in a sovereign, uh, uh, stack, do I have stickiness to go get that data? 'cause it was in that, you know, it ran on this application, and that's where bifurcating data from, from the app really, I think will, will come in. You know, there's something else I want to state on here.
For those of you watching this, this isn't about EU versus us or US versus China, or, or you know, just nation states like that. Even here in the US and js you know, we have, we have some states where certain medical procedures are illegal, and in other states they're legal and doctors can prescribe medications and so forth that they may not be able to prescribe in a different state. Yeah.
And so some states in the US are looking to have sovereign data that is not subject to the, the, the prying or discovery by a different state. Yeah. And those are states within the US even.
Yeah. So, you know, this is kind of a worldwide trend that we're seeing where people are saying, Hey, I want to keep my data private. Well, I, I, I do think for the US it's certainly the data conversation.
Um, right? So when we have conversations on ai, the data security, um, right, is a very, very old topic. So we barely in the US speak about digital sovereignty, but we speak a lot about data security.
So the data perspective is an important one. If you go to, uh, Africa, they speak much more about autonomy. If you come to a few European countries, they would speak about business resilience, right?
So all different angles, autonomy, resilience, sovereignty, data security, that articulate ownership and control of that. What is most precious to you as a company, right? Because ultimately, why do you wanna protect the data?
Well, because right. You run your, your company on it. Uh, one fun fact, I do think not a lot of people know, uh, but the US was the first and foremost country that introduced sovereignty.
Um, yes. Right? If you think about FedRAMP for the military, for the cloud, Cloud FedRAMP, Yep.
Um, Suzu started, or Rancher started Rancher government services, which is an entirely separate legal entity disconnected from Suzu, owner owned by Souse, but Right. We don't know what's happening there. Um, that is, that is sovereignty to the next extreme level.
Um, so to us as a company, it's very known. How will you bring that to the most extreme? And funny enough, that started in, in the us so, um, yeah.
Yeah. It's ironic, isn't it? It Is funny stuff.
Hey, and Andrea, it's for people out here, maybe they're in Europe watching this or wherever they are, how can they get more information? How could they get started? Well, when it comes down to, um, understanding, uh, digital sovereignty, um, right, there's, there's a lot to do when you're in Europe and you want to inform yourself on where do I need to look at when it comes down to sovereignty.
The EU published only a six page document. It's the Cloud Sovereignty Framework. It's amazing to, to read and to, it gives a really broad perspective.
So that's definitely recommended to familiarize yourself with that concept, obviously, right? com/digital sovereignty, uh, is a lot of information to find on products, on services, how SUSE can help you out getting more sovereign, um, and understanding what needs to happen in this transition. I love it.
Um, and Andrea, it's best of luck in this new, uh, role. I hope to see you. Well, we're gonna hopefully be at scon in Prague Oh.
Meet in Prague In March. Absolutely. Uh, or excuse me, that's in April in March.
CubeCon is in Amsterdam. I unfortunately won't be at Q Con. I'm gonna be at the RSA conference in San Francisco that week.
But Mike Ard on our, and our team hopefully will be there. Nice. So, we'll, we'll, we'll talk more about that then.
Um, but look, don't be a stranger. Come on here and keep us posted on this. I, I think this whole it sovereignty thing is, is a subject that we're gonna really see come into its own next year.
Yep. Yep. And there's a lot in the pipeline here at suse, so, uh, stay tuned.
We'll definitely come back. I love it. Andreas Prince head Sovereign Solutions at SUSE here on text on tv.
We're gonna take a break. We'll be right back. Hey guys, thanks to the throw.
We are here with Karen Oli, who's the CEO for Leo Stream, and we're having a little chat about, well, vendor privileged access management. It's a problem out there because we have so many people that we're trying to partner with, but we don't know exactly what they're doing once they get in our environments. Karen, welcome the show.
Thank you very much, Mike. It's always a pleasure speaking with you. Thanks for having me.
This has been an issue for some time, but I feel like it's getting worse because the bad guys have kind of figured out how to attack our supply chains, and they, they navigate and start to move laterally and all kinds of bad things happen. But, um, do we grant too much access to these other vendors out there? And how often are we actually managing what they're doing on our networks and our systems?
Yeah, I think that's the problem is historically we have been, I don't wanna call it lax, but it is just simple to wrap vendors into the same systems that we use to manage access to our employees. So maybe that means, um, adding them into our VPN or whatever other remote access solution that we have, but the way that we manage employees, but needs to be fundamentally different from how we manage vendors, because these are outside people who we are giving carte blanche access to our network to. And that is just becoming, as you pointed out, more and more problematic over time.
And we don't seem to know exactly what kind of defenses they have in place. So for all we know, once we let them in our network, they've already been compromised. But how do I make some sort of assessment of what somebody's actual cybersecurity posture is, um, without just sending him a form and hoping that they my scouts on or tell me the truth.
Well, that's the thing is, and, and I've gotten these as a vendor for some of the people that we work with, is they send us forms to say, what is your cybersecurity stance? But even though we do have a good cybersecurity stance, you shouldn't trust me when I tell you that, and I shouldn't trust you. When you tell me that.
Instead of relying on these forms and questionnaires, you need to put an actual plan and solution in place to essentially force them to adhere to what your cybersecurity policies are. So making sure that people ensure MFA when they're accessing your systems and enforcing that. A vendor can tell me they do that, but I need to make sure that they really are, and I do that by implementing services and solutions in my network that they have to use.
How much of this is also part of the human condition where we just get attached to other people and they work for other companies, but we kind of start to treat them like they work for us. And the next thing you know, something bad happens. Yeah, there's definitely some of that.
When you've worked with a vendor for a long time, it, it can become difficult to say, well, now I need you to use this different solution. And I, I, I am kind of telling you that I don't trust you. And it's not necessarily that I don't trust the vendor, it's just that people, people make mistakes.
I may accidentally click on a phishing link, and now if I have credentials for your systems and I've become compromised purely by accident, well, that compromises you, and you need to make sure that you're not, you're just protecting yourself from situations like that. Mm-hmm. Of course, I would just tell people, well, I trust you, but Karen, she doesn't, so we have, I don't trust anybody.
Not anymore. Not these days, man. And Well, to be honest though, you can't always be sure that somebody is who they say they are because there's now digital fakes and all kinds of interesting things that are going on out there.
So even if somebody kind of looks and acts like somebody, you know, they might not be right. That that is very true validation. You have to validate people's identity, usually using more than one factor.
It's, yeah, it's a scary world. Right. And will it get worse with the rise of these AI agents because theoretically they are, quote unquote digital employees that are now accessing things on behalf of my vendors and, um, god knows what they're doing.
Right. Yeah, no, that is a very interesting point. And a good, a good thing for people to think about is, you know, we talk about managing vendors when it comes to third parties who we assume are people, but at some point in time, yes, you need to take those policies out and expand them to include these AI entities as well.
So what am I supposed to do about all this? Because there are some legacy technologies out there, but I imagine they were created for a different era. But is there another way of thinking about, you know, vendor privilege access management?
There definitely is, and I think the, the key is to, again, not treatment like employees. Think of them as vendors. You may like them, you may trust them, but you d do need to put different solutions in place that, um, basically allow you to adhere to zero trust policies.
So only give them access to the limited number of things that they really need instead of giving them a full VPN connection to your network. So use some sort of zero trust architecture that not only authorizes them to trust the right resources, but also has a time bound policy associated with that. So they can request access and you have to approve it, and that approval is for a certain period of time, and when it expires, they can't come back in that way.
Even if they're compromised later, well, their session has expired, it's enforced through the services that you're using to control their access. They can't get in anymore. So who's in charge of these kinds of issues?
Because I sometimes feel like, well, the cybersecurity people are generally aware of it, but they have no idea how many vendors they are and who's in charge of what. And then there's the business folks who, um, you know, they have a handle on how many vendors they're working with, but cybersecurity is never top of mind for them. So where does this fall in the, in, in terms of who's responsible?
It really is kind of interdepartmental. 'cause I know I, you know, me as the CEO, I have a vendor spreadsheet. We know who our vendors are, but now I need to make sure I'm talking with it to say, okay, now you need to put policies in place and actually implement plans based on those policies that control the access that these different vendors have.
So it really is, again, cross department and communication as it is in many cases is, is the key there to make sure vendors don't fall through the cracks and policies get put into action. Mm-hmm. Do you think that the auditors and the regulators are starting to figure all this out and starting to ask tougher questions about this stuff?
Oh, I think that's definitely true. I think there's, there's more accountability now. So you need to not only, again, it's not just good enough to have the policy.
You have to have the plan that backs it up and then implement that plan. And people are looking at that now too. It used to be you could say, look, we have this policy, but now you have to prove that you're putting the policy in place.
Do you think also that maybe we're getting to the point where, you know, companies will fire vendors for the lack of security controls and governance issues, and this will become something that, you know, there'll be a little teeth in these evaluations? Oh, absolutely. I mean, we, even, we have cases where we've had to invoke our incident response plan because we've had a vendor who's done something that was, uh, not, we didn't have a, a hacking type incident, but it's still, you have to hold your vendors accountable.
And if they aren't resolving issues that they have and proving to you that they can be better, then, then yeah, they're gonna be put on notice. We talked about AI being used by the bad guys, but it occurs to me that, well, maybe I can use AI to kind of evaluate the security of my vendors and make some assessments of that, because otherwise it's kind of a hard job to do and don't really have the time and capability. So well let get easier for folks to do maybe, hopefully, You know, that's an interesting question.
We're actually just starting to adopt AI into our business workflows and look for ways that we can implement it. So maybe I'll look at that one. Uh, think about how we can leverage AI to manage our vendors a little better.
Alright, I think, so what's your best advice to folks? Because honestly, I think some of them look at this and they go, I understand the issues, but it's a daunting task and it's so overwhelming that they just don't get started. Well, I think that's the key, is to look at a little problem that you can solve and then expand from there.
So when we talk about vendor access, it's really about, okay, can I find a simple solution that'll make it easy for me? If I have a vendor who's doing maintenance on a couple operating systems, or just needs to maintain my database or install some patches on a server, can I take this one little use case and make it very simple to secure that better than I am right now by finding some sort of vendor privilege access management solution? And so that, that's the key, is just, you know, the world is big.
Can you find a little problem and start from there? And I think the, the concept of just securing third party access to a particular server or a particular application, that's a pretty small little problem to solve. And then you can kind of expand out, Is there an aren't to this?
Because inevitably someone will complain about whatever security measures you put in there because they added friction to a process. But I mean, what is the tolerance for additional friction? And how far can I go before everybody starts to rebel?
Uh, I think that's gonna depend on the person. Some people are so security focused that they're okay with a little friction, but some end users don't like any kind of change in any sort of experience that they have. So some of it's gonna be case by case, and then some of it's gonna be mandated by what your organization requires that people essentially put up with.
But again, the key is to find that balance. Can I find something that's simple enough for it to implement and simple enough for end users to use that if there's some friction in the fact that, you know, they have to do MFA now they're okay with it, because otherwise it's, it's simplifying other aspects of their life. So ultimately, what's your best advice to folks?
Then, as you kind of think this through for a minute, um, you know, should I have a big meeting and convene everybody and kind of make it a giant corporate wide initiative? Or, you know, to your earlier point, do I just kind of like go after it one at a time until eventually I get my arms around it? Again, you've got the cross departmental, so there's somebody on top that's kind of thinking of it from the overarching, oh my God, here's everything we need to do standpoint.
But when it comes to actually implementing the solution, yeah, narrow it down. Find some simple use cases that you can tackle and then expand out from there. Because if you try, as they say, if you try to boil the ocean, you're not gonna get there.
All right. Well, folks, you're heard it here. Zero trust.
Even if you know them, it's a good idea because well, vendors change, people change. You don't know who's on the other side of that contract anyway. But eventually something probably is gonna go wrong.
So better to be forewarned and forearmed than to suffer the consequences. Karen, thanks for being on the show. Thank you very much.
Thanks for having me. All right. And back to you guys in the studio.
Hey everyone, it's Alan Hummel. We're back here with our continuing live coverage of AWS Reinvent 2025, um, another month. We won't be saying 2025.
It's hard to believe. But anyway, it's day two. We've been having a great time interviewing some really great folks here.
This is a a, this is probably the biggest panel we've done so far this week, and I'm really excited to introduce you to them. Uh, I'm going to ask actually folks to introduce themselves so I don't mess up names and everything, but we'll start at the far right with Ali. Yeah, My name is Ali Re and I'm VP of Product Strategy at suse Ali.
Thank you. And thanks for being here with me. Next to Ali is Mancy.
I'm Mancy Jata, I manage strategic alliances at AWS Mancy. Thank you for coming on. I appreciate it.
And this young lady is Christine, Christine eo, and I'm VP of our AWS growth Strategy at suse. I love it. So I think just the fact that we have someone who's in charge of the AWS growth strategy at SUSE is a statement about how you view your relationship with AWS.
Correct, yeah. Especially a senior person. So, um, we're gonna dive into that.
Uh, good, I'm, I hope we do. Absolutely. Um, but Mony, if it's okay, I'd like to start with you.
It's a great title. You deal with a lot of the Linux providers, right? And, and look, we all know Linux, it's open source.
There's, there's some great companies in the Linux space. Sus is one of them. Um, what, what does AWS want from their Linux partners?
So, great. Uh, question Alan. Uh, let me start with where this journey started, right?
Like SUSE and, uh, AWS have been partnering for more than a decade, right? For context. Uh, one of the first Army listings on the AWS marketplace back in the day 10 years ago, was suse, right?
Like we started there. So from there, this journey has grown. So to answer your question about, hey, like how do AWS and SUSE add value to each other?
I feel like we've grown the partnership from day one, right? Like we've added value to each other from a open source perspective, right? Like AWS has leaned on SUSE for so many, so many big initiatives, which we'll dive into.
So, um, really excited to be here to talk about all the work we are doing today. Absolutely. Absolutely.
Um, Christina, I'm gonna ask you, how do you, you know, obviously it's a strategic relationship to suse. How do you view this, and not just you, but how does Souse look at this relationship? Why is it strategic?
How is it strategic? You know, I'm not even ready to jump into product or re announcements that we've done here this week, but historically, that strategic relationship, Well, going back to what Cy said, it's a a very strong relationship. It's been there for 15 years.
I joined the company actually as a consultant. Um, and that was in April of 23. And at that time, they were just looking to get Marketplace off the ground.
And I was working with the product teams and the engineering teams, and also sales. And it became very evident of the flexibility that AWS brought to the table in order to get a company like suse, who is now taking the products that they had that were traditionally on-prem and how we were going to deliver them through marketplace. We had our, what we call first party, which is more like a, an omni based model that Mony talked about.
But we had to look at how are we looking at operations? How are we looking at the way that we, um, stood up our listings and all that. And I think from then in working with AWS, they provided the most flexibility to meet Susa where they're at, at that point in time.
And about a few months later, I was hired in as the VP of Cloud and then managed the, uh, global cloud team. And then we started looking at where the investments were being made within the partnership, who was really making and leaning into that investment. And hands down it was AWS So, um, working with our executive team, um, they said, we really wanna double down on AWS and said, Christine, we would like you to go do that.
So I started working with, um, our office of the CEO and our strategy office, and I started putting down what that longer vision would be with AWS. And there were a couple things that we were working on at the time, um, that we just announced, which was, um, SUSE providing, um, additional packages in Amazon Linux. One thing I really love about the company is choice and flexibility and customers are going to use of, uh, various amounts of different technology.
And SUSE's very, very open to supporting that. So we, we doubled down on that, uh, project. And then we said, well, what if, what if we took, um, our rancher platform and we looked at in providing a SaaS?
And then, um, Ollie came in and helped me really shape and define, uh, how that would look. And a year later, here we are. So from a strategy perspective, you know, AWS has been, uh, a leader in the market, period, hands down.
Yeah. And with marketplace, they have just innovated and, and the amount of innovation that they do that we will never be able to, to do that on our own. And that was another reason why we really wanted to partner with somebody who had that depth and that breadth in the market.
And we had the technology on the other hand. So it just became a really nice union. I love it.
So you mentioned there's a lot packed in, there is a Lot, No pun intended. We had to unpack it starting maybe with sp the, the secure packet for Amazon Secure packets for Amazon Linux. Spoke a little bit about that actually, uh, earlier with, with Margaret.
Mm-hmm. But Ali, you are the, you are the product guy. What are we talking about here?
So, from a product perspective, what I'm really excited about is like the launch, um, that we've pulled off together with the help from Amazon, for Suzy Rancher for AWS, um, that's been the products in conception and like being developed for over a year. We've done a lot of user research and know, had a lot of good help from, from our friends and partners at AWS understanding what it means to be a product led strategy. Um, you know, how we operationalize SaaS products.
'cause if you think of what SUSE's been doing, right? Like we're SaaS is not necessarily in our DNA yet, if you look back at what we were doing. And so like that, that modernization right, is super exciting for me personally, um, to help bring this to the company.
And, you know, I couldn't have done it without the help from AWS. Um, and so the product in itself is Rancher, our multi-cloud, multi cluster Kubernetes management platform, right? And, um, SUSE acquired it five years or so ago.
And we've, um, have tremendous success. It's highly regarded. We're guarding and, uh, forest a leader, you know, in multi-cloud, uh, multi-class management.
Um, but it's, that's an on-prem product, and that fits our traditional customer profile of enterprise customers where they like to just have, you know, things on their estate. Um, but, you know, we want to, you know, using some of the AWS technology and meeting customers where they are and meeting new customers. And so with, um, scuse Rancho for AWS we're actually tapping into, um, customer profiles that are EKS users, right?
And there's, there's plenty of them. EKS as well is successful. It's a great platform, um, for, for any Kubernetes, um, workloads.
Sure. Um, and so what we are doing is we're bringing the capabilities from rancher to EKS to their customers. And one of the feedback that we've heard is that, um, for example, multi-class management, if you have larger state, you know that that's where customers, um, wish they had additional help.
And this is one of the strengths of, of Rancher. Mm-hmm. Um, where we have heterogeneity and we support, you know, many clusters across many, um, providers.
Now being a AWS and EKS opinionated product, we've then taken, um, rancher and, and really added additional user experience to it. So, for example, um, identity management is often a problem, you know, for, for enterprises. 'cause there's multiple accounts and different setups and orgs.
And, you know, IAM is just, it's very complex because it's a very important topic. And so we take this very serious, but we've implemented features that make it really easy for our customers of SUSE Ranch, of for AWS to import identities in a safe way by delegating roles so there's no more copy and pasting of passwords and whatnot. So we do this all through off delegation, um, on the IAM side.
And then with, with that in mind, then we all of a sudden have insights into the whole estate that is being managed or run on EKS. And from there on we, um, allow our customers to selectively import specific clusters or all of them create new clusters and use the capabilities that Rancher Manager provides. And then, um, another part of the portfolio that we've baked into Suse Rancher for AWS is observability.
That's super critical, right? Like, we need to know and understand what's running, where, you know, how well it is performing are the bottlenecks. And so that, that's another key feature that's available in suse Rancho for AWS.
Love it. Alan, if I may add to what, uh, Ollie is saying, I think this has been a long time in the making, right? Like, we meet the customers where they are.
So AWS customers and rancher customers, uh, have been using both products separately, right? Like, and for us to basically complete the puzzle by saying, Hey, you have a one stop shop, go to the marketplace. You know, you get observability, you get cost optimization, all of that in one package.
Uh, I think that's a huge value add for customers. And it's, it's, uh, it's a long time in the making. Yeah.
Because customers have asked for it, And we have a, wait, there's one more. Um, so in, so this is just getting out the basic product, right? And then super exciting.
E everybody's talking about AI here, right? You can't walk across the floor, not just here, everywhere, but Billboard. It's, it's very, um, omnipresent, right?
And, and so with the help from, from, um, the AWS teams, we've been able to actually implement one of the first, um, AI agents in the platform, um, within suse within our portfolio to help customers actually ease their SRE burden, right? So Kubernetes is complex. Um, rancher helps already like to, to lower that complexity and make it more accessible.
But now all of a sudden you have a, um, a wingman that helps you understand, you know, what a specific error code or whatever it means, and you can actually chat with the system to identify, you know, is this intrinsic? Is this a invasive problem? What are remediation steps?
And we've built this on top of Bedrock and q and the, the way to get there was amazing. And like, the value that it's providing for customers is really astounding. It, it really is.
Again, a lot, a lot of stuff covered there. Ali. Let, let's, you know, rancher, I, I'm angling the founder of Rancher.
Mm-hmm. It was, I know him, he's a friend. I known know him for many years.
Rancher in my mind, was the best multi cluster Kubernetes manager that in the market, right? I mean, and look, I, you, you, you could go out onto the floor here at AWS reinvent and say, how many of you think Kubernetes management is easy? No one's raising their hands.
Right? It, it's a known thing. This it is hard.
Yeah. Multi cluster Kubernetes management is even harder. And that's what made Rancher, or one of the things that made Rancher is, is unique as it was.
And of course, since it's become part of the Sousa family, you know, the K threes and everything else, we, we added into it. And now AI and, and what that means to it is, has, has made a a huge difference. I should mention when we say multi cluster, don't be confused with multi-cloud.
Mm-hmm. Right? It doesn't necessarily mean you're on different clouds, though.
We can, what happens is at the enterprise level, right, the average enterprise is running multiple clusters of Kubernetes, right? I don't know mony if you would have metrics on that, but, Uh, more than metrics, I feel like the customer journey, right? Like they start with a few clusters and very quickly it expands across regions, across accounts.
So the complexity increases so quickly that something like rancher is super critical, uh, for somebody to scale, right? Like for an enterprise customer to scale that happens, that ramp happens very quickly. To your point.
Absolutely. Now, I just wanna make sure I got it straight. For the people watching this offering with AWS is a SaaS based Offering, SaaS based offering, and it's focusing on AWS and DAWS ecosystem and EKS specifically.
So as a customer, you won't be able to manage, um, Azure or GCP for example, at this point, because we're targeting, um, that segment of customers that are getting started in, in EKS that are, you know, seeing the increasing complexity. And that's just single cloud strategy at this point, right? But as, as those customers mature, right?
Like, then we might see a multi-cloud strategy, you know, in, in enterprises. Yeah. Um, but for right now, this is, you know, we're focusing on EKS.
I love it. I wanna come back. So I'm a security guy at heart.
I've been in security, I was in security a very long time. I didn't want to tell you how long, but we, we didn't call it cyber, I'll tell you that. Um, secure packages for Amazon Linux.
I want to come back to this. This is a major thing, right? We've seen over the last month or two, uh, you know, the NPM ude, the, the worm self propagating malware into packages.
It's a problem, right? When, when, when 80% of the software inside of the applications we develop are preexisting components, scripts, packages that we download in, gets into our software supply chain, and then God knows what happens. It's important and increasingly important that we know that we have confidence.
If I'm on Amazon and I'm getting a package from an Amazon partner or a repo, I wanna know that that's not, I'm not downloading malware. I'm not injecting malware into my thing. And that is, you know, SUSE announced this, I guess it was at Seuss Con last year, I think Ali, we might have spoken.
Mm-hmm. Um, there. And that's an important thing, right?
Yes. We have SBOs, right? That's, everybody wants to know, you know, bill of materials.
That's great. It's like the tag on your mattress, right? That you don't tear off.
It's good to have there, but we, we wanna have confidence in the packages we're putting into play that they're secure. And that's an important piece of this. It is important.
And I think, you know, just even going back to, we talked about complexity. We're talking about security, um, and we, we, we, um, kind of touched upon the voice of the customer. This, this whole solution started as a concept.
It was a concept document. And we actually talked to over 50 customers. The number one and number two, uh, issue that we were solving for was complexity security.
Yeah. Those are the top two. Uh, we see it too.
I mean, you know, we see it across the board. That's what people are concerned about. And when, and when we did that research, it actually kind of parlayed a little bit into what we were doing with Sal, the supplemental packages.
Yeah. Because now AWS can offer their customers a safe environment to create applications without having to pick their own packages that they need. It's all built in that repository.
And that's what's really critical. And that does leak into cluster management and, you know, everything else containerizing applications. But It's a, it's a question of confidence.
Mm-hmm. I, I need to be confident that the software I'm getting from you is, is, is secure that it's not gonna come back to bite me. Right?
Because this is where, this is where incidents are happening. Third party components into the software supply chain. Um, and if we're, and if developers are our audience, that's very much on top, as you say, it's on top of their minds.
One of the top two that and complexity. Um, if you don't mind, I'd like to come back a little to ai. We touched on it a bit.
Certainly this show is all about ai, right? AWS has re has come out guns blazing, right? About Ag Agent, and it was started with the keynote yesterday, right?
Agentic AI developing their own ai, developing their own AI processors, right? The creating an AI stack, that's really what we're talking about, right? From hardware to software.
I know AI is something I've spoken to suer about over the last month's year. How, how is that manifesting itself in these announcements and partnerships that we've made this week? Well, we did sign a strategic collaboration agreement.
Mm-hmm. And that really was the first kind of thinking of us leaning into the technology that AWS has. And as Ali pointed out earlier, we in incorporated that into the platform itself.
Yes. Into the SaaS platform. Um, that's our first step.
And we actually are looking at it right now of looking at what we're doing around MCP and seeing how we can actually make the correlation between Amazon q, um, to look at how do we, how do we incorporate these two technologies? 'cause right now Q is predominantly for SaaS. Yes.
Not necessarily on-prem, but there's a lot of data there that actually is beneficial, um, for AWS customers as well. Sure. Is.
So we're, so we're in the infancy of that. So it's kind of, it, we, we signed the strategic agreement really thinking that, okay, we're gonna be using it for this, for this SaaS platform. And then as we started deepening the relationship, other product teams, and you'll talk to Rick.
I don't know if you've talked to Rick already. No, I have not. Uh, you, you'll talk to him I think later today.
Yes. He'll tell you a little bit about SLES 16 and all of the, um, all the press and news that we're getting about the operating system because of all the work that we're doing around ai. And he's looking at incorporating that into the platform as well.
So it's, uh, and, and we've done our own, we have our own stack, um, for ai. And so does, so does, um, suse rancher. Um, and so we're just now trying to look at how do we marry these, both these worlds.
Let's talk suse rancher's, AI stack a little bit, Ali. So we in, in suse rancher for AWS, right? We have, um, our agent that I, that I mentioned, right?
Um, build on Bedrock and q and that helps from an SAE perspective. Um, but then if you think about it like being the infrastructure for workloads, right? Like there's a lot of intelligence that we actually get through the observability solution, right?
Like, so that helps feed and make agents and AI smarter about the, the infrastructure that, that we're operating. Um, but oftentimes there's, um, not just a Kubernetes estate. And so going back to what Christine said, our, one of our, our products is, um, multi Linux manager, right?
And so all of a sudden now when we have systems that can talk to each other in intelligently, um, right? Like, it helps enterprises, it helps customers to better understand their whole estate, not just compartmentalized, you know, by, by the execution platform that's Kubernetes or VMs or whatever. And so I think that's the true power, like getting all those different data sources in and then combining them to, for, you know, to provide meaningful outcome.
And, um, on the rancher side, we have, um, the stack that Christine mentioned earlier. Um, it's called suse ai. Um, and that helps customers to securely run AI LLMs models and whatnot on-prem, right?
Because there's a lot of risk right now that we have to manage, um, you know, with this new technology, uh, in terms of IP and like being, making sure that no data leaks and that models are not tampered with for that we don't have Drift and suse, I helps customers actually to manage that complexity and those risk factors. Love it. Nancy, I want to, from the AWS perspective, you guys have been sort of like the Candy man this week announcing all of these great gifts for, for developers and for partners like Cuse to develop on and build on top of expectations of, you know, Ali mentioned QI didn't hear a lot about Q this year, a lot more last year, I think.
Mm-hmm. But we've heard about, about Bedrock, but we've, we've heard about other, uh, agentic AI programs that a, uh, that, uh, AWS is, is working on that we're, they're either in pre-release or they're released already, but, you know, imminent. What's the, you know, this thing is moving so fast.
What's the timeframe you got a company like suse? Is it gonna be next year that we're using, you know, some of the stuff that we're, we're doing? That's a great question, Alan.
Um, you know, for instance, I'd love to talk about the mental model around how we build with partners like suse, especially from an AI perspective. So Ollie, you can vouch for this, right? Like integrating q the agent into, uh, the suse rancher solution.
I think it takes a matter of a few days mm-hmm. Versus what it would take earlier, a few months, right? Like for the teams to come together, say, let's go innovate, right?
Like figure out the architecture now that's out of the window, right? Like we say we are doing this, and then it happens within days. And then to your question, where is this heading?
I would say the days will be cut down into, right, like a few hours, right? Like that's the speed at which we are moving. And that is, uh, we are seeing the benefits of that across the organization, right?
Like from an efficiency perspective, uh, across the board, right? Like, this is the model we follow with all the partners. We jointly say, Hey, these are the three customer problems we're trying to solve jointly.
How can we insert all the AI innovation we are building at the services team, right? And then we kind of figure out how do, are we solving a real customer problem through this, right? Like, what is the use case?
That way it becomes very easy to scale. And that's how we solve for, uh, you know, a lot of the problems that, uh, suse is atan. I think the, the length of time there for us to get this out was a few things, right?
Understanding the customer, looking at a concept document, soliciting that. Then we actually had, um, folks from AWS come in and do a workshop about how to look at personas in a different way. We were tapping into different personas, a developer persona, right?
We we're used to the more of the platform engineer, but how are we going to tailor this offering to a developer, right? So that took some time. Then we went to, um, work with the PLG team, um, with AWS so getting it, getting the product in a MVP stage.
And now we're looking at how do we get better with automation through marketplace. That's another, that's kind of the next, but now that we have this baseline for the offering, it helps us now go back in and just now, you know, incorporate newer technologies or get, get a more, uh, feature rich roadmap moving forward. So, to the bottom of your question, like time to market mm-hmm.
And time to adopt. Um, there's been a lot of announcements around quick and quick suite, right? Yes.
You've been in conversations with the teams already for months. Um, and you know, that's something that we have on the roadmap. 'cause that helps, you know, having a in place in product chat bot is fine, but it's table stakes these days, right?
Yes, it is. Um, but like lifting this to the next level where, you know, you have agents facilitated through click suite, like talk to each other and actually automate business processes and even down to the infrastructure, like that's, I think where a lot of innovation can happen. And I'm confident we'll be able to really quickly adopt that with the help from our AWS counterpart.
Absolutely. Um, I wanna make sure if we hit anything I've left out announcement wise, It's on marketplace trial market is there, and, uh, just a little plug there. Okay.
Well, no, hey, this is the place to do it. Check it out on marketplace. Let me ask this then.
What's next here? Vacation. No, no, but I, you and me both, but actually it's gonna be almost Christmas.
But, um, no, but in terms of a strategic relationship, where do you see, let's ask the AWS point of view where, you know, where, where can, where's this headed? So going back to the journey where we started, we started with Army based products. Now, uh, to Christine and Ollie's Point, we are almost experts at SaaS building SaaS.
So now the next transition is right, like we scale, right? Like, that's why we see our, uh, I think 2026 is gonna be the inflection point where the, uh, the suse AWS uh, you know, relationships scales because we have so many products on the cart and we are solving real customer problems. Agreed.
Christine, this is your baby now. Yeah, I mean, if I looking into, you know, what we do next, I think automation is really important because the go-to market aspect of it, engaging with the field and, um, getting feedback from not just the customer, but from AWS themselves, um, and looking at how we're incorporating that into the roadmap, I think will be critical in order to get the scale. So how do we, how do we make the user experience, you know, just a few clicks away, you know, to get access to the Yeah.
To the Product. You know, one of the themes that came up in our talk today was, look, Cuse is undergoing a bit of a transformation from a company where enterprises primarily used it on Preem to this new world that we're all living in now, where, you know, the hyperscalers, the clouds, you know, no one, no one is all in on any one, it seems right. We live in a hybrid world, and, and this is a major focus shift a little bit for suse, right?
Because you have to have your AWS offering has to be as good or better than the on-prem offering. But I think increasingly customers say, look, where I house my stuff, my infrastructure, my data, what have you, is not important. I want a solution that runs, right?
I don't want a solution for on-prem and a different solution for AWS and a different solution for somewhere else or what have you. I want a solution. How Ali as a, as a product guy, even at the rancher level, right?
This is multi cluster at its, you know, take it to the Yeah. Logical end. So you, you threw me a good bone because what you described is really like one of our key value props to our customers, which is choice, right?
And we are not opinionated of where you run, or if you're running, you know, a red stack or a green stack or whatever color, right? Like you want to use there. Um, we'll support you where you are.
And I think that's, that's one of our strengths. And that we've, throughout years, what we hear from customers is like, we don't lock customers in. And so that, that value prop or that corporate value really like, reflects into our portfolio.
Um, you see it with multi Linux manager, we support 15 plus operating systems with, um, on the rancher side, right? Multi-cloud heterogeneity, right? Like is key, is a key driver for us.
And so that's where we provide customers. That's what customers really enjoy, you know, given, um, recent, um, market trends that we've seen and, and movements, you know, with customer, uh, with, with other acquisitions, right? Like, customers feel locked in and we're here like to just, you know, cut those shackles and, and give them the freedom that they need.
Last question. This is, I don't know, 60,000 people here or something run running around that show floor and around the area. What are you hearing from real life people about this relationship?
About the announcements, you know, feedback. I don't know if you've had a chance to go talk to 'em, real people yet, but I was, well, it was interesting 'cause I was talking to Barry earlier, right? Yes.
So, um, he understands the, he, he was really excited to see the, um, the agreement with the SAL packages and Right, because he understood from an AWS viewpoint, like they, they, they have their skillset, we have our skillset, and customers want to build applications. They don't wanna kind of pick and choose what libraries that they're gonna put into their application. They want it, they want it easy.
Mm-hmm. So I think the excitement that I'm hearing about the relationship is, um, wow, you guys have really done a lot with AWS in this past year. 'cause I think last year we were talking about what we're gonna do, and I think now we're talking about what we are doing.
And I think that's the biggest difference. Um, and I, our customers, you know, in the field, you know, with, uh, EKS and then also rancher, we get a lot of questions, uh, from the saying, well, I'm, I'm moving to EKS, or I'm an EKS customer. Now we have something there to offer that is specific and opinionated for that customer.
We don't have to, you know, kind of juggle around that answer. So that is from true customer feedback. Excellent.
How? No, you'd have it. I mean, uh, Alan, the energy here, 60,000 people, the number of meetings, the number of customers we meet, uh, the mental model that I think about at reinvent is you come here, you talk to your customers and get six months of work done in one week because you get all that feedback and then you go back into the hog wheel and bend.
Mm-hmm. Yeah. Yeah.
And that is, it's, it's, you get your, your, your, you know, you got your paddles out here now. Yeah. 10 is then you go home, you take this all back, internalize it, and move.
Yeah. Holly, I'm gonna give you last word. So From the show floor, what we hear is just amazing feedback about not so much new AI features.
Again, like that's, that's a commodity already, but like the choice part that I described earlier, like, a lot of people are like, oh, so you're not just managing suse, oh, you're also managing, you know, other Kubernetes, other operating systems. Like, that's been overwhelming feedback at the Booth to this week. Mm-hmm.
They want one solution rules 'em all. Yep. Absolutely.
Hey, thank you all. Thank all three of you for coming on here. I know you're all busy.
All of us are busy at this show, but thank you for taking time out to come on here. I hope everyone at home has enjoyed this. Uh, if you're watching this live, you're probably not here.
So I hope it brought a little bit of what's going on at Reinvent too. If you're watching this on demand later, good for you. I, I hope as well that you enjoyed it.
To mimic Christina, go to the marketplace, check out what's there. And, and you can see a lot of this for yourself. We're gonna be back.
We've got more SUSE coverage, more EWS coverage. We've got a lot of things going on all day today. You're watching Text Drunk tv.
Hey everyone, we are live here at AWS Reinvent, continuing our coverage of Day One Lot going on a lot of ai, a lot of agentic ai. You know what? I don't hear a lot about Cloud.
AWS Reinvent used to be all about cloud. Now we're talking ai, but we're gonna talk some security. One of my favorite topics, I want to introduce you two and make, I'm gonna mess up his name, but we practiced it 12 times and I still didn't get it right.
Sne, Ben Shimo, Shimo. I almost, I wanna say Shlomo and I keep Shimo, but he likes to be called Ben. Ben, what's, thank you for coming on to Text Drug tv.
It's great to have you on here, man. Thank you for having me. So from the name, I'm gonna guess you, maybe you have some Israeli roots.
Yeah. But You live, you're a New Yorker, New Jersey, like me. So I guess that makes us kind of almost related, but, um, tell us about your journey.
How, how did you come here? Yeah, definitely. So currently based in New York, almost in the past 10 years, uh, been in cybersecurity for many years, as you all know.
Uh, I'm Israeli originally. So we started a journey in the military. Uh, I'm not 8,200.
You're Not 82? No, my 1200 Is what, a few, not 8,200, But actually 8,200 is quite big. Yes.
To the place that I used to serve. I used to serve in more of a secret service. Okay.
The Prime Minister office, which is, uh, more boutique, more unique, uh, harder to get into if you're 8,200. Don't hate me, but we're better. Okay.
Hey, he said it. Not me, but go ahead. So, yeah, we, um, basically moved to the states after, um, managing a lot of cybersecurity, public company research division, building from scratch.
Really, really passionate about research, anything related to vulnerabilities, attacks, offensive security defense. And, uh, I found myself in, in New York as like one of the big companies. I build their product.
They couldn't sell their product to the ciso. And I was blown away because such a great product, we need to explain the value. And when I moved to the states, uh, I was really kind of exposed to, no matter how good product you're building, you need to be close to the customer.
You need to be really close to the team, you need to close to the security executives and explain to them what's going to come next. Mm-hmm. The thing with securities, like check, if you're playing, if you're trying to survive the next week or maybe the next year, you're probably going to fail in year two and year three.
So when I moved to the states, one of my biggest goal was to educate them right? In like, what's coming up next to build a strategy in the right way. I used to be a CISO as well, and managing security organization.
Mm-hmm. Over 100 people. Um, um, very quickly, um, after that built a startup, a a couple of really good friends, uh, named Cider Security very quickly sold it.
I know them Well. Sure. Yeah.
So really quickly, uh, we had a huge success. We sold it to Palo Alto Network. Mm-hmm.
Part of Prisma Cloud. And, um, I ended up loving the cyber, uh, security and startup. I'm like, wow.
I can do, I can build, I can do whatever I want versus enterprise. That was a little bit slower. Yeah.
So I decided to take some time off after the exit, and my co-founder, eh, who I didn't know was going to be my co-founder, called me. His name is Uri based in Boston. And he's like, Hey, so I have something interesting for you.
I got to a point, he manage vulnerability management and cloud security for Akamai from Cambridge. Sure. And he is like, Hey, I got to zero vulnerabilities in three of the massive Akamai environment.
I'm like, great, Julie, you accepted the risk. Everyone can accept risk. It's like, no, no, no, no.
Actually remediate it. Actually. It's like, excuse me.
Look, vulnerability management is never happened, never happened, never happened. Vulnerability management is a list of problems everyone have. And you just wait for, you know, s****y defense and bad things will happen, but it is what it is, right?
And he's like, no, no. I was able to do something about it. Uh, it sounds very promising.
I opened a plane, went to Boston, and I spent a few days with Uwe. And what he showed me, I was blown away because I couldn't achieve it with the best team in the world of security people for all the decade I'm in cybersecurity. And this is where I realized that vulnerability management, the dead market of vulnerability management, exposure management is, can be solved.
We can actually win the vulnerability battle. Call me skeptical, but okay. I'm listening.
I got my attention. So, so after a long journey of speaking to over 100 good friends, CISOs and large enterprises, and also smaller one, everyone were, we're skeptical. What we ask him, it's like, Hey, if we can come in and take your backlog, your vulnerability backlog, and all these vulnerabilities that you're getting from Tenable, from Wiz, from AWS inspector for, and we'll talk about AWS later on while we here, but all these crazy vulnerability data from on-prem, from the cloud, take all this vulnerability data.
You can sift through it. You don't have enough people in the team to review it. And then you have work workflows, but you cannot automate vulnerability management because it's deterministic.
Every CV is different, every vulnerability is different, and environment is different. So how can you automate? You can't.
This is why we're failing. And I ask him, it's like, if I can take this problem and automatically reduce 90% of that backlog automatically without any human touch, just eliminate it and leave you with that 10 or maybe 5% to actually handle. It's like, that sounds good.
That sounds great. That's great prioritization. And then I, then they told me, what about remediation?
I was like, okay. So once we have that 10 or 5%, I know, and we practice that, then we identify it, take that five to 10% and simulate remediation and give you that one, two, or three steps that you need in order to reduce Back to the buck. Exactly.
That's exactly what we're saying in our website. Mm-hmm. And they say like, that's amazing.
If I have something like that, I will, I will buy it. We, uh, close a seed round in a month really quickly. We just took the money, great investors, and we built ZE security, which is the current company we're at today.
Very excited about it. So that's basically the story of, Of you and Zes ze security. Yeah.
And Uwe. So let me give you a little background. I, I've been inside, but we didn't call it cyber, we called it security.
I've been in security 30 years. Information security. InfoSec.
InfoSec. Yep. Exactly.
And, um, I actually, I've co-founded a couple companies, one of which was called Still Secure back in 2001. And we in 2003 came out with a vulnerability management product. And back then it was very different.
Back then you had to convince people to do a scan once a year. Mm-hmm. It was like pulling teeth.
But when you, but it was job security for the security guy. 'cause you would do the scan, you'd deliver like a telephone book of vulnerabilities. Let's say I give it to 'em for Christmas or New Year's, you know, you're from New York.
It was like painting the Veno Bridge. Amazing. You know how they paint Theno Bridge?
Amazing. They start on one end, it takes 'em a whole year To finish, To finish. And then when they're done, you know what they do, they go back and start again on the other, The best job security ever.
That was vulnerability management. It was almost by design that you didn't get to zero vulnerabilities. So then people got smarter.
They said, look, we don't need to get to zero vulnerabilities. We should only worry about the vulnerabilities that are exploitable, reachable real. You know, I had, I had a friend, I don't know if you ever heard of this guy, giddy Cohen, Skybox Security.
Yeah, of course. Giddy just started a new company. I know too.
Um, you know, and that was one of when I first saw his attack maps is what he called them, right? Mm-hmm. That was a revelation.
I was like, wow, this is great. Now I only have to worry about 20%, 25%, Which is a couple of millions. It's Still a couple of still job security.
Yeah. But unfortunately, it's been almost by design that we never get to zero vulnerabilities. And as a matter of fact, even you mentioned, we were talking off camera about Black hat.
I was a black hat in August. I was talking to a friend of mine, uh, two friends who actually just, uh, just starting a new company. They just raised money now.
And, um, their, their thing is, look, forget all these vulnerabilities. There's only a handful that are real mm-hmm. That are responsible for incidents.
And just focus in on those. That's good. If I knew exactly which ones to focus in on, you know, that's like the old's an old joke.
A plumber comes and says, the lady says, I don't have heat. A plumber says, let me look. He takes out his pipe and he, he bangs the, he takes out his wrench and he bangs the pipe with the wrench and the heat starts working.
And the lady says, oh my God, what do I owe you? He says, $250. She says, $250.
All you did was bang your wrench on the pipe. He said, oh no, that was free. Knowing where to bang my wrench on the pipe is $250.
I love that. I I'm going to use that. Tell You Got it.
Is yours. Wow. But that's the thing about vulnerabilities, right?
If you know which of the ones that are exploitable are dangerous, you can mitigate. But to get to zero, I'm not gonna ask you to give away secrets here, but what is the secret to getting to zero vulnerabilities? So What we, and I don't know if we want to get to zero.
Okay. I don't think we need to get to zero. Yeah.
But we definitely need, like, why do the world need is important since you start talking about scanning. Today's scanning is mandatory. Yes.
You have requirements, right? You have continuous regulators. You have auditors.
More than that, if you want to provide services as a SaaS company to customers, you need to have an SLA. Yep. And what happened in 2025?
These regulators, uh, requirements are stop asking you for visibility. Because visibility, everyone knows everyone have that list of vulnerabilities, right? Mm-hmm.
Everyone can scan. Everyone's scanning today, even SMBs. Yeah.
They're required to. Yeah. But now the regulators starting to ask, because again, I will, I will give some more information because I think it's important.
Over 60% of incidents today, and this is vouch number, are related directly to vulnerabilities that were known to the organization. Absolutely. I think it's higher than 60.
I think it's closer to 80. Um, I'm just basing on ENT report and Verizon report. Yep.
The time to exploit this vulnerability were reduced in the past three years in 90%. Now it's less than a day. Last year in 2024 was less than three days.
Before that it was five. So we got to less Than a day. Remember it was 30, 45 days.
Exactly. It keeps going down. So regulators, cyber insurance, your customers want, if you have something critical, they want you to commit to an SLA and God forbid something happened.
You miss your SLA, your regulators will come up to you, especially if you highly regulated environment. Yep. Most of our customers are biotech, financial services, health, and even SaaS company that provides services to this healthcare.
And today, look, it's, it's about who your third parties are. Yeah. Right?
It's not who you are. It's who they are. So, you know, and further down the List, and they want to get these deals.
It's like, yeah, I cannot get these deals because I cannot commit. Or they're committing. But now they need to deliver a seven days or six days critical vulnerability in production remediation.
Absolutely. It's the whole SOC two and all of these other Yeah. Audit.
And what we actually realize is there is a need like not in zero vulnerability. There is a need in remediation. Yeah.
And how we do what we do is basically, you cannot automate, but you can AI it. So we using different type of LLA models, we acting as an army of security engineers that going one by one of these vulnerabilities. And it doesn't matter if they have high score or low score.
It doesn't matter if they're being exploited in the wild or not exploited in the wild. They're in your environment. Yeah.
And what I need to tell you, if in your environment this vulnerability is actually risky or not, and you'll be surprised how the more, the most advanced scanners, these tools that you paying million dollars to, they're giving you this list of vulnerabilities with attack path with mm-hmm. What will happen if, but they're not correlating that with your environment. No.
So you have an open SSH vulnerabilities, right. That open SSH vulnerability have requirements for exploitation. You need to run the service with specific permission.
That asset that is vulnerable need to live in specific environment, environment terms. Without them, this vulnerability can never be exploited. And to understand that you need to send someone to do this test.
Yeah. That's exactly what our gent KI, uh, uh, capabilities are. Wait, I needed to say it.
You you said it. We but you made a long time till you mentioned it. Look.
Exactly. We're here at AWS reinvent. I don't hear them talking about cloud.
I hear them talking about AgTech ai. So talk to me about how your agent is working to do this. Uh, we actually announce, uh, we're going to have an announcement, uh, early next year, but in a reinvent, we doing a private preview of a new capability that was very, very interesting to all of our AWS enterprise customers.
AWS investing a lot in security. Yes, they are. And we call it native security controls.
So they're allowing today DevOps and, and platform teams and engineering teams that build a cloud to build a cloud in a secure by default way. And they have a lot of native capabilities around resources. You can build policies around services.
You can have security policies without paying money, just using the native capabilities of the cloud. If you will look in this native security capabilities and you will correlate that information. The hard work that your cloud architect actually infuse into your cloud correlate that with your vulnerability backlog that you need to solve.
You will realize very fast that many of these native security controls basically reducing 50 to 60 to sometimes 70% of your attack surface. But because you're not marrying these two together, you, you dunno, that means that you can focus on vulnerabilities that were already diffused and solved by and mitigated by this amazing AWS cloud native controls that you have. So one of the capabilities of our agenda AI is to look and understand your policies around services, resources, encryptions, VPCs, microsegmentation in your cloud, and understand if this remote code execution vulnerability can actually exist.
Even if you take into consideration these policies, most of them are not exploitable. Right. That's the idea.
I love it. It's great. You already, you, you don't have a problem.
You already solved the problem. Right. And you don't know that you solved it.
You know, some, some part of me sits here and says, did it take AI agents agentic AI to reach this level? Like, it's always bothered me to tell you the truth, why we didn't do better with this problem. Right.
I I was working on it 2003 22 years ago. It's a technology limitation. It's not a need limitation.
We always have that need. I think we've always had the need. I I always thought we didn't have the will.
Right. People, people talk a good game, but their hands don't reach their pockets when it comes time to, to really prioritize. But this makes it easier more, it's, I don't wanna say automated, but it, it's just, it's easier to, to do this.
You can win. I love it. Yeah.
I, I agree. We, we are giving a lot of, I I I'm really proud of it, but we are giving more life years to our security engineering. Yeah.
Every time we talk to a team and the team sounds tired and unmotivated mm-hmm. This is the team we want to work with, the teams that have this backlog of vulnerabilities that every day of their life is chasing down this vulnerability. Look, this is a whole big problem.
You, you've been in security long enough, you know this. Right? The, the depression of, because for those of us who've been in security a long time, we have a lot of people in security who are, they suffer from depression.
They, it, the, the, the issue is, it's like what does winning look like in security? That question is, I didn't get breached today. Mm-hmm.
Right. Did I not get breached? 'cause I was the zebra in the herd and the lion ain't someone else today.
Or because I did a good job, or I convinced my CISO and the board had to manage risk what, you know, what's acceptable risk or not. And, and so anything that I think Im improves that is, is an amazing thing. I was gonna ask you what Zest security's doing here at AWS, but you already answered that Ben, so that's fantastic.
Um, what has been, so there are security people here, but there's everyone here, there's ccio CSOs, there's that. Do people understand, like the security people obviously do, but does the CIO do the cloud engineers understand what a, a load this is off of their chest, right off of their shoulders? Mm-hmm.
I don't think they care. No. I think at the end of the day it's part Of the problem too.
I like, it's not part of the problem as much as, you know, we, me managing over 100 people, I knew everyone personally and I cared. Right. When you walk in a large enterprise, you like many times you can't do that.
You don't know what the security team in the trenches actually going through. Even not the ciso not talking about the CEO and the CO what I, what I actually, um, what what what I like to surface is if your security team, if your vulnerability management team that in charge of prioritizing vulnerabilities and fight the vulnerabilities are drowning, which they are, it's going to bubble up into management problem. Yeah.
It's going to bubble up in audits. It's going to bubble up the way you look in front of your customers that asking you about what do you do about this? What do you do about that?
It's going to bubble up when you have a red team or penetration test. It's going to look bad when you have a customer that's saying like, Hey, I asked you about this couple of days ago, what's going on? And we're getting these emails, right?
So the management team needs to look good and needs to act good and it start from the vulnerability. Start from the team. So what I'm, I'm basically telling this COO and CIO is like today you have a backlog of do you have vulnerabilities?
It's like, yes. Do you want to eliminate a and at least 90% of this vulnerabilities without spending money and asking favors from the CTO and engineering team without asking and pushing tickets into teams that need to build your business? It's like, yes, of course.
It's like I can guarantee you that with agent AI infuse into your exposure management program, your C program, you don't need to hire 200 security engineer. You can walk with your existing team, maybe add some more people if you want to, but you can win. If you infuse AI into that operation, you can open less ticket.
But each and every ticket you give to your engineering team, that ticket was 20 or 30% of your risk reduction. And that's what they like, they, they think numbers. Right.
But at the end of the day, I'm helping the vulnerability management team. Yeah. And if they do a better job, the COO, the CFO even will be happier.
They don't understand that. But it's okay. That's my job to make sure that both sides agree to embrace our technology.
This will get, like these guys will get their executive report and the vulnerability management will get an amazing, amazing tool that will make them survive the holidays. We need to survive the holidays. Right.
Well Always. But then there's always another holiday. You, Ben, we're running low on time.
I want to just make sure we hit a couple of things for people out there who, like what they're hearing, what's the website to go to here? io. io.
Very Z vst Zs T zes, like Lemon ze. Yeah. io.
And we're very transparent about what we do and about our technology and we have our customers use cases there. Everything you need to know. It's in the website if you want to see it live.
If you don't believe what you're reading, which is okay, we have a dedicated security team that can show you a 30 demo, 30 minutes demo and actually to see it by yourself. And we also have a, um, a free, we just announced a few months ago, a free remediation assessment really, which is not a risk assessment. We're not showing you your problems.
Right. Uh, we are basically showing you, uh, the probability of your remediation operation. How can you remediate more with less?
And it, it takes I think seven days of the platform to run, analyze, and get you everything you need without having any sales calls during that time. So Absolutely. Yeah.
io. Yeah. Hey, I think you're onto something, man.
Good for you. Thank you so much. I really enjoyed the conversation.
I enjoyed having you on here. io. Go check it out.
Look, this is, this is, uh, this is kind of a holy grail a little bit if you've been in vulnerability management and security like I have. So go check it out for yourselves. I'd love to hear what you say about it.
Enjoy the rest of reinvent. I will. Thank you.
All right. We're live. We'll be back with more.
Stay tuned.