Techstrong TV February 11, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hi, everyone. Welcome back here to Tech Drunk tv. I'm really happy to introduce you to my next guest.
It's his first time on. We had a great conversation off camera. I think it's gonna be a great conversation on here as well.
His name is Aaron Warner. Aaron is the CEO of a company called Pro Circular and a Aaron Welcome. Welcome, thank you To Text drunk Alan.
Excited, excited to talk to you. Lots to talk about. Yes, we do.
But you know what, before we talk about all that, I wanted to talk about you a minute. As I told you, our audience likes to know who, who's talking to them. How did they get to this chair?
Like, uh, why did Alan have him on? So, tell, tell us about Aaron. Like, Uh, like a lot of CEOs, uh, and people in the tech community, I am racked with imposter syndrome.
Uh, so, uh, all of this is, you know, a little bit uncomfortable. But I, I have enjoyed technology since being the kid that took the TV apart. Um, I, uh, I spent 22 years in biotech, uh, as a CIO and helped to build a really great company from don't cash your check on Friday to, you know, a global player.
We had facilities all over the world, um, thousands of employees, and they played a huge role in, uh, life sciences and r and d. Um, it's an interesting perspective, partially because, uh, like a lot of companies, I started pro circular out of frustration, um, of 20 15, 20 16. I could go to any of the big four and get a enterprise risk assessment, and it was like three quarters of a million dollars.
And, you know, we were doing 180 million in revenue. It's a good firm, right? But just too expensive.
And frankly, with the folks that they were sending to me at the time, I'll leave the vendor out, but my team was running circles around these guys. So, you know, 40 something just finished my MBA. I thought, you know, worst case scenario, if I really screw this up, I can go get a Joby job again.
And, uh, but I, I haven't looked back. Um, biotech was a really interesting intro to cybersecurity, but we have been neck deep in it for a decade now. Uh, at Pro Circular.
It's been quite a ride. Absolutely. You know, I, I've been in cyber myself 20, almost 25 years.
25 years now. It's 2026. Um, and I was doing, well, we didn't call it cyber, of course then, right?
We called it infoset. Information Assurance was right. Yeah.
I was doing it before 2001, even though two, Aaron, I got one question for you. When you're taking apart the TVs, was it tubes or solid state, Uh, tubes. And in fact, this is really gonna date me.
My best friend's dad was an engineer for at t or for Ma Bell. And my first, uh, foray into computing was to get these card reader machines up and running, uh, to flip the cards. I, we were so young, we pulled the vacuum tubes out and had fights with them.
Oh, God. All right. Yes, I do remember those.
So, but that was when I was in school. That was your computer class was punch cards. Sure.
And it was, yeah, a lot of, we used to throw the cards around and then try to get 'em back in that, right. Oh, uh, yeah, the box do like this and make Yeah. Make 'em, you know, holding.
So they'd fit in the, what, a paint. Anyway. Um, it's would Come a long way.
Yes, we have. And here we are where AI does that for us. But anyway, um, let's talk about pro, pro Circular.
You said you, you know, 10 years on this journey, you know, tell for, there are people out here who don't know pro circular, that's an overnight sensation to them. We, we, we take a different approach to things. I was, you know, I, I was a customer of all of these things for a long time.
So I have a long list of frustrations with cyber in general, and I just, how would, if I had to sum it up, I'd say that the biggest difference is that pro circular is about people. And everybody says that on their mast head, and it's in their core values and all of those things. Mm-hmm.
But, um, when we look at cybersecurity, we think about people, process, and tech, right? Tech is a third of the equation. And I think most people in cyber feel like it's two thirds at least.
And that many or most, or sometimes all of the problems are solvable by tools. Um, I love tools. I'm a huge practitioner of ai.
I've been doing development since forever. Um, but it's about people. At the end of the day, people make decisions, uh, about budgeting.
People make decisions about hardware or software or what your stack looks like or how you approach cybersecurity. People are the ones that click the thing that comes in that it should have protected them from in the first place, right? That's not, the user is a victim in most cases.
And I think we as an industry lose sight of that. Um, I worked in a world where my worst user, this idiot that kept clicking things had an MD PhD from Harvard and, uh, Caltech, uh, really? Yeah, a total idiot, right?
But he kept clicking things and the department would complain about him endlessly. Like, this guy, what the hell is wrong with him? Like, you mean the MD or the PhD?
Like, this is not an idiot. This is a guy that's targeted and it really is a victim of the shortcomings of my security program and the IT program. So pro circular was kind of a response to that.
Like, look, we need to take this problem seriously, but we can't just be a hammer looking for a nail. People are the ones that make decisions here. How they do things flow over into process.
And the tech is, to a certain degree, a byproduct of all of the intentions of everybody involved. So I know that everybody says this, that people are important and, and so forth, but I, as a client in cybersecurity, often felt like we were treated like bugs and, um, you know, something to be studied and measured and sort of looked down upon. We don't take that approach.
It it, it was frustrating to me as a customer. We don't do it to our clients. So if there was really one big difference, um, we have, uh, we really tried to push home.
It's the, the people connection. Um, we, we have some of the best pen testers and offensive and defensive engineers in the world, and none of that means a thing if they can't explain why. Like, why did you run this pen test?
It's great that you cracked this open. Um, what does that mean to me? Like as a bank or as an insurance firm or a house?
Oh, no, it's the risk. Yeah. What am I talking about here?
'cause it's a cyber's a great hole that you can throw money into, but what actually makes a difference, and our experience is that that's often a people related thing. So we, we focus a lot on the why not so much the how, the, how frankly. Uh, we're using AI at every turn to try and get rid of as much of that as, as we can so that humans spend their time on analysis, uh, and measurement and comparisons as opposed to data collection.
Um, you know, absolutely nothing new in in any of that. I think you can hear, you know, echoes of those sentiments elsewhere. But we've really tried to sort of focus it in a, a pro circular.
We're very good with the technical part of it, but we understand that the, the important part is that there are humans involved in this that aren't technical. So, you know, our job is to engage, help 'em understand why, help 'em to understand what are, what are we trying to accomplish here? Um, yeah, you know, a Alan, one of the first things we do in an engagement with a client, uh, is a SWOT analysis of the company.
Um, it's not meant really to be like a, yeah, it's not meant to be like a, a a, a proxy for a full enterprise assessment, but it forces the people in the room. And we try to get HR and GC and, you know, all of the sort of stakeholders from the organization, not just it, um, together we talk about what are the goals of this organization, if it's a nonprofit, like who do you serve? What good are you trying to do?
And then we weave that into the security program as opposed to just assuming that this client is the same as all other clients. And, you know, it's about the border and it's about email, and it's about all of the standard things that, that anybody can look into. We really like to understand who we work with, 'cause it enables us to, to, um, to answer the call better.
Big problem or small problem. So, Excellent. That's the long and the short of it, Alan.
I, I hope that, I hope that helps. Yeah, no, it did. Just one quick thing and we'll get it outta the way in case I forget later.
For people who want more information on Pro Circular, what's the website? com. Excellent.
Alright, Aaron, I wanted to talk to you about what we have as our topic of discussion today. You know, I think it was last week, or maybe it was the week before already, I wrote an article that, uh, cs a as as well as the NSA and FBI, as it turns out, have withdrawn from participation in the RSAC conference, biggest security conference in the world, where historically it was a great place for private industry and government and, you know, the, the, the cybersecurity industry to collaborate. And really, that's sort of the, the second shoe dropping.
The first shoe was, I don't wanna call it the gutting of csa, but let's say that they've radically changed the mission of csa. Yep. Um, you know, they did gut the budget by a lot, and that money that You're using the right words.
I I, yeah. I mean, it was when You cut 500 million, but also changed the mission million. Yeah, absolutely.
And, you know, but the mission has changed where, you know, I, I actually, I, look, I know Chris Krebs, I never met Jen Easterly, but I admired her, you know, work from afar. They, they really, I, Alan Friedman, you know, SBOs from csaw, and I knew a lot of people there, and I admired their work because of their ability to bring a public private consortium to bear on our critical infrastructure needs in this country, understanding that whatever it is, 65, 70 5% of our critical infrastructure is not actually run by the government. It's private industries, private companies that are, you know, managing this critical infrastructure.
And, you know, like Jack Nicholson in, in, uh, he walks the wall and we sleep under the, in a few good men, you can't, we sleep under, under, Can't handle the truth. You, you Can't. Exactly Right.
But we sleep under the blanket of their security that they provide. I worry at night about, right, this public private partnership is kind of, is disappearing is the mission. Who's responsible for this anymore?
You know, can we leave it just to private companies? Do we need a, some sort of community like an RSAC or someone to kind of try to bring it together? I, I don't know what the answer is.
If I did, I would say so, but Aaron, what, what are you seeing, or what do you think? We, we have very similar concerns, Alan, and, um, you know, from the top, all, all the way down. Um, normally I avoid politics like the plague, right?
That is not a as, As most of us try. Yeah. It's not often a, uh, an a helpful part of a discussion around risk and cybersecurity and so forth.
H however, in, in this case, so much of this is, and I'll be polite, we'll call it political volatility, right? Mm-hmm. So much of this upheaval and change is having a very real impact on small companies and large companies alike.
Um, one of the more telling, I think, concerns I have, and this is where we get into the political part of it, um, I'll read you something real quick. Heritage Foundation. So everybody talks about this project 2025.
Mm-hmm. Check this out. CISA is a DHS component that the left has weaponized to censor speech and affect elections at the expense of securing cyber domain and critical infrastructure.
So, Alan, you and I travel in similar circles, right? And, um, I have never heard a single member of any part of the CISA organization talk to me about censorship. Talk to me about elections.
Talk to me about anything other than trying to be that last mile for small businesses in this country when it comes to cyber protection, right? So there is this assumption for whatever reason, and I'm neither defending it, nor supporting it, but there is this assumption by a lot of people who are making decisions right now that CISA is some sort of a political organization, and that they are spreading what they believe to be disinformation. That has not been my experience at all.
And, um, as a result of that, you see all kinds of changes within that organization. Um, the fact of the matter is, you know, when cyber became started to become a word that you saw in the news, like 20 16, 20 17, the Hillary's emails, like that's where that all started, right? Um, everybody was sort of rushing to get their piece.
Everybody in federal government was rushing. So you had FBI, you had National Guard show up to the party, you had all these TLAs that have been involved, usually outward facing, you mentioned the, the NSA, um, FBI was involved, the, and CSA was sort of the trying to fit into that equation. But at the end of the day, you have the FBI, which is largely responsible for prosecutions.
Like they are cops, they catch bad guys. Mm-hmm. Proactive is not their thing, but never has been.
Right? And that, that makes perfect sense. Um, I wouldn't want the FBI going around all day looking for crimes they thought might happen, right?
Like, let's stick to investigation National Guard sounds like what it is, which is, you know, critical infrastructure protection and, but largely around government historically, uh, unless there's a huge disaster. So again, kind of disaster oriented groups, CSA was going to be, or my conception of it was that CSA was going to be that connection, uh, between where private industry protected medium sized companies and large companies, companies like Pro Circular, uh, protect banks and hospitals, and all of those folks who have enough revenue that they can afford to do something about it. The hope was that CL would be the glue that connected all of us in industry and all of us in, in federal government, and use that to protect that last mile that, um, small Walgreens or, or, uh, a corner shop that has 10 employees.
Like those are the guys that are getting killed out there. Not Dell Dell's gonna be fine, Amazon's gonna be fine, but that plumbing supply company, there're in serious trouble and they, yeah. You know, they're a threat to the rest of us as well.
So the Hope, Absolutely the hope was that CISO could be this answer. The federal government's answer to protecting private industry, and it's been completely changed, and it's left a huge vacuum. Like I don't honestly know who's supposed to fill that in.
I'm guessing it's private industry. Um, you would think I'd be excited about that, like as a business guy. But the fact is that some of these organizations, uh, uh, corner store with three or five employees can't afford what we do.
My engineers are very, very bright and not cheap. Right? Well, Not only, certainly not Aaron.
And that's always been a problem. You know, they people, a lot of organizations, you know, live below the cyber poverty line, if you will. They can't afford that.
And, um, but, but here's the thing. It also goes, you know, I was a poli sci major in undergrad, and you know, why, why do humans form governments? Because there are certain functions that a government could do, because it represents the will of the people and the critical mass of the people that no individuals or individual companies alone can do.
Right? And, and things like a common defense, why we have a, you know, department of defense, regardless of what you wanna call it these days, why we have a Department of Defense, why do we have, you know, basic government functions, is because the government, these are the functions that you need something bigger than the individual to do band, you know, banding together the social contract. If you want to get back to Locke and Rousseau and, and all of these things, it's a social contract.
Yeah. The Wolf Man versus the civilized man, if you remember from school. But, and then if you, you know, and it, and in today's world, part of that common defense is a defense of our critical infrastructure from cyber attack.
And that, so to me, that clearly now, make no mistake, it, the irony should not be lost that the Project 25 and Heritage people are calling out CSA for, for election fraud, when it was, you know, a form Chris Krebs and CSA was fired for saying there was no fraud in the election. Yeah. Probably because there was no fraud in the election.
Yeah. For right. For spreading di well, more than probably that's pretty clear, you know, spreading disinformation.
Well, Jen Easterly would put in something its sister to say, Hey, we're gonna look for DI disinformation because that's a threat to critical infrastructure. And who's dealing this information? Well, you know, we, we, besides the Russian and Chinese and Iranians and North Koreans and all these other bots and their allies.
So the irony should not be lost. That what they're blaming sisa for was exactly the thing sis was defending as part of it. Right.
It, it's, it's, this is truth speak from 1984 or something. You, you hit a really important point, and I'm so gonna dodge all of those stuff. No, no, you should.
That's why I could say it here and you can't. Um, I'll, So let, I'll Put, let me, let me fast forward. We're gonna fast forward forward.
Aaron, you said it an in one, your company, any company, bigger company, smaller companies, we can't do this without a partner mm-hmm. In Washington without a partner at, at the state levels, perhaps. Will we see the states, I mean, that's a logical solution perhaps, is individual states help form that private public partnership, at least at the state level or at the local municipalities.
What can we, what can we expect? How do we facilitate it? I, I think that's a start.
I think you hit on a really important topic right after we started the cisa. If nothing else plays a role in connecting some of those various federal organizations and private industry and private practitioners of cybersecurity, um, the, uh, the FBI has a huge role to play in that. I'll give you a really quick firsthand.
Um, when we get called out on a, on an incident today, the fifth, 5th of February, 2026, when a client calls us and says, Hey, I have a really bad day. Um, I would like you to come to Atlanta right now. When we do that, one of the first things that we look for are not just the threat actor that has been visible, but the variety of threat actors that can also be in an environment, right?
You've got access brokers who sell keys. I've gotta login and password to kind of anyone. So when we get on the steam, yes, we may have a ransomware guy, but we got two or three other people in there.
Um, there, there may be PHI theft, there may be credit card theft. All of those things are patterns that we need to recognize really quickly. So when one of our folks gets on the ground, the way it used to work is that we would get in touch with the bureau, say, hi, this is Aaron.
I'm on site at this location. I have this threat actor. Here's what we think they're doing.
Here's what the behavior looks like. Now what do I need to worry about? People within the FBI are organized in what are called AORs and the specific, specific AR that specializes in that bad guy can tell us all sorts of things that are very helpful to the client.
This guy normally ex filtrates data watch for that. It's not just ransomware or this threat actor really likes credit cards. They don't care about your HR data, so don't worry about that.
Those kinds of things, real time inform the approach that we have to incident response when it's difficult to get a call returned from the FBI because those guys have been re-tasked to 50 different things. Um, we have to go online and work with our colleagues in private industry, rely on our, our intelligence feed, but it cuts some really valuable real-time information out. The person who pays the bill for that is the client, not us, not the FBI, but the person who, their company isn't processing orders or anything like that, right?
That they're shut down. That's the net effect of, of all of this. So, CSA at a, at a minimum, at we benefit as a community so much from sharing what we see and what we learn.
Um, the bad guys have to be right once, we've gotta be right all day long. So co coordination and communication is, is part of how we do that. So I would love to see things like pulling out of RSA, uh, the, the board that Krebs, uh, built with, with CISA was a great way to get industry and federal to share information to one another.
I don't know why you would take that apart and it has a very real, like today effect on on. Yeah, Unfortunately, I, I just pray that we don't all pay a huge price before this gets rectified. Anyway, Aaron, we're about outta time, man.
What a great conversation. Appreciate You. I really appreciate it.
Uh, thank you, Alan. Yeah, very cool. Come back, keep us posted.
Good luck with Pro Circular. com. You can see the spelling in the bottom third with Aaron's name.
Aaron, I don't know if you'll be at RSA this year, but we'll be there live at Broadcast Alley all week. Maybe stop by and say hello. I will, I will.
I'll see you there, Alan. Thanks. All righty.
Aaron Warner, CEO Pro Circular here on Tech Drug tv. We'll be back with more in a second. ai Leadership Insights series.
I'm your host, Mike Va. Today we're with Jeremiah Stone as the CTO for SnapLogic, and we're having a little chat about AI and legacy systems and how we kind of stitch all this stuff together. Jeremiah, welcome to the show.
Thanks for having me on, Mike. Uh, it's a really fascinating topic, and we're working with many companies right now that are really grappling with, you know, this fundamental question of how do they introduce AI into their existing landscapes and accelerate their businesses and do so in a sort of cost, you know, responsible way, uh, and get the speed they want without having to throw everything away they've been working on for a long time. So it's a really interesting topic.
Well, that is the nut of the thing, right? So if I look back at everybody's environments, we have applications in some cases that have been running for decades. We're not gonna throw those away overnight, and that's where all the data is.
And sometimes that data's on premise and sometimes it may be in the cloud. And then we have all these great new AI tools and models, and most of that stuff probably is running in the cloud. And we're trying to mash all this together.
So, um, how do I think about this? Or is there maybe a set of best practices that you've seen people adopt to help navigate this stuff? Well, I think we are starting to, uh, see repeatable patterns emerge, and that's, that's, you know, often what we look for in these times of rapid technological progress, where we definitely have a high intuition and then start to see proof points of, of technology starting to, um, really have an impact.
And then look for patterns to be able to put that to work that doesn't take, you know, another decade to, to get to work. And I think one of the really interesting, um, things that I'm starting to see, you know, relative to, to the companies we're working with is a reevaluation and a different approach to thinking about technology strategy with existing landscapes and trying to isolate the systems that have enormous amounts of value that can loop forward. And I, and then systems that need to be refactored need to be replaced.
And the term that, um, we're using quite often these days, and I think it really, really kind of came out of financial services, is starting to distinguish between legacy systems that are gonna need to be put on a timeline for retirement, refactoring renewal, and heritage systems that need to have a, an architectural approach that preserves potentially decades of, you know, continuous investment, business logic, you know, deep organizational, um, information that, that, you know, is going to carry domain expertise and a high degree of value, but do not need to be refactored and thrown away and, and starting to take a more nuanced approach to understanding the existing landscape. And then an architecture that allows us to deliver rapid, uh, value and new capabilities, you know, for, for the business without getting, you know, caught up in business value neutral, you know, sort of shiny object activities, hacker news architecture, I think somebody's called that, uh, you know, that that, uh, you know, is just the implementation of something because it's contemporary, but not necessarily because it's required. Is this, when you peel it all back, you know, just a huge exercise in business process re-engineering that, you know, we've been trying to get at for decades now, but in the age AI maybe easier to accomplish, but we're now doing it at a level of scale and sometimes in production environments, we're just moving ahead and seeing what happens.
Well, you know, actually it feels like, like deja vu for me. I I came into the industry in the late nineties, early two thousands when we were having a very large scale move to, um, you know, local gooey interfaces, three, two architectures moving away from mainframes and saw the rise of, um, a completely different penetration into the workforce with, you know, these systems. And were able to take, you know, basically knowledge work really rose at that period of time.
And you were able to, you know, give people personal, you know, computers, but a techno technology on the desktop and expand what used to be, you know, just sort of a terminal operation. Now, you, you are giving technology to every employee, and I think we're in another one of these sort of expansions of high value, high interaction, um, technology being provided in different ways now via conversational interfaces primarily, but also this idea of digital labor where we have this entirely new domain of work that can be automated and it can be automated because predominantly language models are able to handle unstructured, semi-structured data in addition to what we do well already, which is highly structured data. And so, you know, I think that that is, is, is what is a redefinition of how do we get to those same outcomes?
How do we support new improvements to business processes, taking out cycle time, taking out costs, delivering more value, but apply these technologies in a way that allows to support that. So yeah, I think that I keep thinking back to, you know, business process for engineering, business process automation, that we were traditionally looking only at transactional workflows where we could use a, you know, interface that was delivered to the employee to be able to go through checking a purchase order, onboarding an employee, you know, doing other elements of the business. But now we're doing that in a different way to the end user, but also we're able to automate things that we couldn't automate previously without.
And we tried with expert systems, but that proved to be far too heavy a lift, uh, to be able to do. And now we can do with these new systems. Now the element of how quickly we can do it and how heavily is happening at scale, I do think that there is a, um, difference between what is being rushed out into production very, very quickly is every, you know, what some people refer to as everyday ai, the ability to include these, these tools in productivity tools in your document editing system, in your email, in your spreadsheets, et cetera, versus a core business process that is not, you know, direct knowledge work, but it's actually something that would've only been in a transactional system, seeing a ton of the everyday AI incorporating these systems.
You know, all of us, you know, over Christmas, everybody's got, you know, I don't know, you know, uh, you know, Claude, um, you know, running now on their desktops, doing knowledge work, that sort of thing. Um, I've got a couple of windows open on my desktop, uh, for, for stuff that I need to do. Um, but what I'm really starting to see with businesses is now, okay, how do we take these things and now go after those core workflows, maybe create new products, different user experience, different customer experiences, but that has been happening more slowly than the introduction to individual employees.
And now we're starting to see these larger, more scalable architectures, predominantly, I think two things. One is orchestrating across transactional systems using agents, um, as, as did the labor, seeing a lot of that in financial services with processes like loan underwriting, um, other traditionally heavy document based personnel based processes, um, but then also better ad hoc analysis systems where we're using often a, a conversational interface like a Slack or teams or, or even a, you know, self-developed ui. But for doing things that would've typically been a dashboard, now we're able to use MCP across existing, um, systems to be able to answer a business leader's question or a customer support person's question, et cetera, to be able to increase, you know, customer support readiness and customer intimacy, people would say by decreasing, again, cycle times to useful information to take action more effectively.
To your point, I think this is maybe occurring in phases. Um, we are seeing employees being more productive because they're using AI tools, but they're also having to spend some additional time maybe cleaning up after those AI tools, what some people occasionally refer to as AI work slot. But you know, on the whole, they're better off.
But when I look at the workflows that you're describing with AI agents, I think part of the challenge is, is that a lot of the workflows are, shall we say, deterministic, and they're supposed to be done the same way 100% of the time. And we have a lot of AI tools that are probabilistic being added to the mix. And well, many of them don't do the same thing the same way twice ever.
Um, and I think people are struggling with how to kind of meld those two or figure out, you know, exactly where do I kinda overlay a probabilistic tool to a deterministic process, and well, how deterministic can I make that ai? But yeah, I think it's a very important distinction, and actually I'm not seeing a lot of value and yield going back at well understood deterministic processes and introducing AI into them other than cross deterministic process orchestration. Uh, what I am seeing a ton of is existing human processes, which were probabilistic already now getting the value of, um, decreased cycle time better, basically raising the level of an individual employee.
I'll tell you, for example, in our business, um, one of the things that we really prize is great relationships with our, our customers, because we're operating at the infrastructure layer, and it's just high, high, high contextual complexity. In principle middleware is not that complicated. You're connecting sy, you know, a system to system application, or you're taking data from applications and putting them in in databases.
The technology in the middle isn't complicated. What's incredibly complicated is the context around it. Every customer has different systems, they have different workflows, they have different data extensions they've made, um, et cetera.
So for our staff, maintaining a level of deep individual customer understanding and getting that understanding before you have a conversation with the customer is pretty onerous. It means going back and reading all the information about the customer, reading all the customer records, um, those sorts of things. And when, when we have turnover or a customer has turnover, you have to reestablish those relationships and reestablish an understanding of the customer.
We've developed a system we called Sonar, uh, which, uh, leads across 1520 different, um, you know, areas of data and then creates automated, um, updates to a customer service representative or to myself as a sponsor of a customer on a monthly, weekly, or even an event driven basis. It just increases the ambient knowledge of what's happening in the business. That was already a non-deterministic Q and centric process.
We were already trying to do it, we've been working forever. There's a core value of the company, but now we've been able to add, add ai and basically take the toil of going and reading Salesforce, reading Zendesk, reading our other information, and having that abstractly summarized and provided up to us, as has been completely transformative in terms of taking these lossy, um, processes out of, you know, individual burden of, of work and then putting it into an automate system. That wasn't a transactional process, it wasn't something that was well handled in aggregate across the different systems, but now we're able to get, get value there.
On the other hand, have we ally changed the way we onboard a new vendor? Not yet. But even within that transactional process, there are things like credit checks, you know, risk, risk, uh, scoring or, you know, other types of things that typically would've involved a person in our finance department to look at these things.
We can now, you know, establish, um, you know, individual workflows that, again, this is a probabilistic judgment on whether the vendor, um, meets these particular criteria that a human would've had to do. We can now automate those and have evaluations within those individual workflows that give us a level of confidence that, that we're performing well. Do I think you're gonna do your gross to net or your general ledger operations or your payroll using arrange model?
No, and I just don't think there's a lot of value there. What's challenging the industry, however, is that for the last 30 years, we've been stuck in these common business processes that became best practice in the last BPR wave. And it's almost like we as professionals have to go back and reread the books from the late nineties and early two thousands when we created these processes and apply that same mindset to an entirely new domain of opportunity.
Um, I also think that a lot of business leaders thought that if they invested in ai, that they were gonna see some massive ROI, and there'd be some competitive advantage, but as we get into it, I can't help but start to look around a little bit and figure out that, well, a lot of this stuff is just the new table stakes, right? Everybody's trying to automate the same processes. And so I have to distinguish between an AI investment that I'm gonna make just to stay competitive, and the one that I might think is actually gonna, you know, gimme some sort of sustainable advantage.
But I'm not sure everybody has a firm handle on what those are. I think you're right. I, I, I think the table stakes are the efficiency outcomes.
So where we can gain more efficiency in processes, where we can run leaner, where we can, um, essentially instead of looking for a labor cost arbitrage, I think that was table stakes previously. Are you offshoring, are you nearshoring for certain non-core portions of the business? I heard somebody refer to it as digital shoring.
I, I don't know if that works, but, you know, automating, using, um, you know, essentially a language model in a loop, an agent to, to be able to do these things, I think that's table stakes. I think that is where, um, it, it's just expected in business to be competitive. What I think we really haven't seen a lot of great examples of are new types of services, new types of things that actually increase the top line, um, that, that improve the business through new products, new services, different ways of, of, you know, growing the business or creating new value.
And I think that's still an area where, you know, we're, we're working harder. I do think that there are examples of that underway, and there are, you know, folks working on this. But, you know, think back to, you know, how I would guess, you know, predictive analytics really had massive changes.
And you think about, I dunno if regionally when, when Uber was just a good idea, it was, could we locate the car, the black car originally before there were ever, you know, individuals involved? Could you predict where the ride demand would be, create an entirely new industry and new new way of doing things? I think that that moment is still to come, you know, for language model based systems where we see things and the where it's really happening right now is in the software development space.
I think that's the first really interesting product market fit, where you have fundamentally different ways of doing things where you look at spectrum driven development tools like AWS hero or, or other, um, things that come out, you know, what, what cloud code is doing right now. We're definitely seeing, you know, an emergence there, but you know, more broadly in the economy, I think it's still early days. Mm-hmm.
Um, so as we kinda noodle this all for a minute, um, do you think we will start to see the flattening of organizations because as workflows change and maybe my sales and marketing motion is tighter, and maybe my salespeople are creating their own collateral instead of waiting for the marketing department, but, you know, that's just one example, but, um, today the way organizations are structured is around, you know, some time honored things, right? There's sales, marketing, manufacturing, whatever. Um, will we flatten that in the age of ai, Social norms changing is, is hard, right?
Those, those things are pretty durable. Um, I I do think that we're continuing on an arc that we've been on for quite some time, which is more empowerment of the individual. And, and I do think that, you know, certainly these tools put more capabilities in the talented, motivated, creative individual to not have dependencies on the product marketing team to be able to help build, build a collateral deck or something like that.
On the other hand, um, it is, you mentioned AI slop earlier, it very much is, um, an age where, you know, the more seasoned higher expertise individuals are getting a lot more out of these tools than individuals that don't have the domain expertise or, or capability to, to utilize them. So, you know, I I think in some ways I, I've one wondering if very talented individuals, the great deal of expertise that may have, you know, been put in managerial positions, that there would be almost a return to individual contribution. And yes, flattening in that sense that will have more player coach type, um, organizations where because you've managed to take a lot of the, um, administrative overhead in some cases out, you're able to then take these, you know, more seasoned individuals and put them into the, the frontline.
You know, go back to my, my project sonar example here, here at SnapLogic. I definitely think our customer, um, success leaders are more client facing now because they're doing less, um, administrative stuff in the backend. Um, does, does that ultimately lead to, you know, less hierarchy and, you know, leaner, tighter organizations?
I think it certainly could, and I think that's what we've seen traditionally is you gain more and more productivity, you have less and less need for, um, just large employee populations, and that requires less hierarchy and less, um, administrative control. On the other hand, um, I don't think there's ever been a greater need for good leadership and, and leadership and, and guidance when you have, um, such a fast dynamic market. You know, the, the burden and pressure on consistent direction, clarity of goals and, and execution is, is I think more profoundly felt than ever.
I I think that's what we see continuously is now we're having to improve our processes around corrective action plans, around, you know, program management, those sorts of things. Because following through and ensuring that the outcome is achieved, um, these tools don't fix that, you know, element of, of the process. And that's to a large extent, the responsibility of management of leadership is to ensure longer arc, um, delivery and, and outcomes.
Mm-hmm. So what is that one thing you see people doing these days that just makes you shake your head a little bit and go, folks, I think we need to be a little bit smarter than that. Well, Um, it's, it's hard to pick.
Uh, I think there's, there's a lot of that going on. I, I do think that the, um, widespread, oh, next year knowledge work will be obsolete, will have, you know, a large, um, technical unemployment. Um, I, I shake my head at that.
I'm just, I'm just not seeing it. Um, in, in fact, what I'm seeing is almost a, you know, jevons paradox that the more productive these tools get, the more demand there will be for people to actually, you know, develop these systems. And I think that, um, what people are not doing is really seeking to invest in upskilling and, you know, deeper education for, for how to use these tools and doing better workforce planning and management.
So I think, and now is the time to be really recruiting and hiring new grads. And I think that there's been a lot of stories where, um, you know, companies are deferring bringing new graduates in into the workforce. Um, and I think that's gonna hurt, um, companies because as we see this explosion of creativity, development and growth, um, that you're going to want to continue to build out the ability for people to, to develop and, and deliver these systems.
And so even though we have individual productivity increasing, we also have this huge expansion of the domain of things we can now go after and, and improve with these technologies. And I think the thing that shakes my head is the, um, I guess the, the pause, um, on investing in talent and, and coaching and growing, um, the, the, you know, early and mid-career, um, individuals. And I think that's more important than ever, um, given these tools.
All right folks, you heard it here. Hey, maybe this one play after all is to invest in the people first and the AI will fall. Jeremiah, thanks for being on the show.
Thank you very much, Mike. It been a fun conversation. All right.
And thank you all for watching the latest episode of the Text drawing AI Leadership Insight series. You can find this in others on our website. We invite you to check all those out.
Until then, we'll see you next Amazon AI investments again versus stops AI leaks states are not okay with ai. Zscaler dances with Square X Google API ai Oh my oh, YAWS gets hacked in an eight minutes. And we're gonna take a look closer, look at some of the EU AI moves in this week's episode of the Tech Field Day rundown.
Hello everyone. Welcome to the Tech Field Day rundown. It is February the 11th and I am already tired of saying ai, but I wanted to let you all know that it is national Make a Friend day, but I don't need to do that because you're all my friends, because you all show up every Wednesday to listen to the rundown that I record with my other good friend, Mr.
Alistair Cook. Al, it's good to see you again. It is a to be here on such a beautiful morning.
Yeah, we'll go with that. It's funny because for some people it's a cold, miserable morning that they need a latte, uh, for others that it is so hot outside that we wouldn't even think about drinking coffee. But the good news is, is that all of the stories that we have are both hot and cool for whatever you might need.
And we're gonna start off by talking about everybody's favorite subject, hyperscalers and billions of dollars that they're using to build out for generative ai. Boy, this seems like the never ending story that will probably eventually end with a small popping noise. For now, though we chose the AWS news that we've linked in the show notes article to represent all of those billions of dollars that still seem to be committed to building a home for some future AI application.
We think, we hope, are we getting jaded with these announcements, as you could tell by my read-in from the story? Or are these still vital investments in the future of AWS's clients' businesses? Time will tell.
We don't run. We really don't at this stage. It is an investment in the future that many of us are very skeptical about.
As you can tell, Tom is one of the most skeptical about this, and we've heard these stories so much. It really is getting kind of dull to hear of another $200 billion being spent as part of maybe 500 billion. That's half a trillion dollars of spend amongst the three big cloud vendors that just in 2026.
So we've seen announcements that are about three years worth of commitment to building things. We've seen announcements that are about huge amounts of power being contracted. Uh, this continues to be a big bet that AI is gonna be transformative and specifically generative AI using the tool sets that we currently have is gonna be transformative for how people operate their businesses over the next few years.
And yeah, it does seem like maybe things are getting overhyped that maybe we're getting to the point where we covered last week that there've been a little bit of pushback on Oracle. They're having trouble borrowing some of these hundreds of billions of dollars that they need for their build out. So maybe there is some challenges going on here.
What we have seen is, um, some actual returns, some actual value being delivered by these AI applications. And so quietly what's going on is businesses are actually using AI to generate value quite a lot of the time. It's not generative ai quite a lot of the time it's old fashioned machine learning or what we refer to as predictive ai, but there are absolutely some use cases where generative AI is providing some real value.
Uh, we've seen some of that being covered very quietly. It doesn't get nearly as much noise when you actually become profitable or more profitable in your business compared to these hundreds of billions of dollars. So I think, uh, I hope I will have the courage to take a break from bringing any of these massive purchase stories until somebody is spending over a trillion dollars on ai.
Um, and I know Tom will keep me honest on that one, but in the meantime, I hope to bring you some more stories of businesses that are getting value out of these, these large spans, because in the end, nobody's getting value from it. It's gonna be quite a loud popping sound when, uh, the patience runs out. Versa has added some new capabilities to its universal SASS e platform to be, to detect and protect sensitive data being shared with AI dos.
The update improves text analysis and adds OCR to inspect text. That's actually in images like inside some of those terrible PDF documents that adjust scanned images. And it uses ai, the tool uses AI to reduce alert noise and improve threat detection.
This features help organizations secure their data and manage new AI related risks without adding separate security tools. I think as we start to see AI in the core of both protection and operation, that's a good thing for us, Tom, I think it is. And the reason why it's so valuable is because you know those policies that you have in place that say, don't upload company documents to a public AI repository like Claude or, or chat GPD or anything like that.
Yeah. Do you think those are being followed? Because I have proof that even the head of CSA didn't even follow those and uploaded sensitive government information to a public AI repository.
So how are you gonna prevent that from happening? 'cause shadow AI is how we got into this mess in the first place when people started playing around with it. Well, that is a combination of two things I've already talked in the past about companies that are detecting tokenization and invalidating those tokens, but that's very invasive.
If you already have a perimeter security set up like you would if you were using some kind of an SD-WAN appliance, you can do this because part of the SD-WAN and SS ESSE platform, SS e in this particular case is the ability to do security scanning at the edge. And if you think, oh, well, being able to detect data being uploaded is, is that new? No, we used to call that data loss prevention or DLP, and in the old days it was looking for very specific things.
It was looking for social security numbers that were being sent in emails. I was looking for credit card numbers that were being sent in the clear text of an email or in an attachment. Again, these are very important things and we definitely wanna stop them, but the game has been upped.
com or anywhere that's running some kind of a system that I may not want my data being uploaded to, you're probably thinking to yourself, well, that's probably a good idea, but I would never use one of those things. So is the person running Windows 11? Because you're probably uploading data to Microsoft's copilot and and you don't even realize it.
And that's part of the problem is that a lot of times these agents are sending data where we may not expect them to be sent. And we saw that from things like, uh, Claude bought malt bought open claw, whatever we're calling it this week, uh, where it would actually go out and proactively try to find things that it could be used to do. Uh, there was actually a, uh, great, uh, video that I saw where it was talking about how MT bought, uh, would go out and it would actually try to, you know, say, Hey, I wanna create an API integration with this, um, uh, insulin pump company to measure your, your system so that I can, uh, send you a text alert whenever your blood sugar gets too low.
Well, if the system did that all on its own, that means that there had to be communications and calls and things like that. What if it accidentally sent all your patient information into the cloud or pulled it down and uploaded it someplace you didn't want it to go? Yeah, that's not a HIPAA violation 'cause you're not a provider, but you may not want your medical information being uploaded in places that you don't want it to be.
And so by creating these perimeter systems to prevent that data from being uploaded both with your consent or without it, that helps organizations kind of overcome this, this desire to just feed everything to a, an AI system and, and code security breaches because that's of what you're doing. Um, I, I, I honestly believe that more people should be taking a very close look at what data is actually being uploaded to these places and probably scream and horror when they realize they really don't want people to find that out. So props to my friends over at Versa for taking a close look at this.
Uh, I know Kelly Haja has been a presenter at Tech Field Day many times and he has a very, uh, unique grasp on the SD-WAN and SS E community. And I'm sure that this is something that a lot of companies have been asking for, and I'm glad that they're delivering it. We're gonna take a trip over to New York State because they are the latest state to consider forcing a pause on building all of these new data centers.
I don't know if you've heard this or not, but there is a massive build out of said data centers. And the reason for it is, do I even need to say it? AI that's putting pressure on a range of essential resources.
Several states are considering restricting planning permission to prevent increases in power prices, in water demands, and conservation of the land from other productive uses. Many of the loudest voices are concerned about the environmental impact of these new data centers. Now, al the question that I have is, are we gonna see data centers being built elsewhere?
I know we've seen some people that have considered building them under the ocean and Lord knows that every super villain is obsessed with rail, building them in space, You know, we know that building them in space is just plain stupid, but building under the sea seemed to work, but nobody's carrying on. So yeah, we're, we're still gonna see these things on land. Uh, this pushback in, in New York is just the latest of a series.
There's been a wider, other states have been doing this at state level, including Virginia, Georgia, Maryland, and Oklahoma. Uh, and then we've also seen this in local communities as well. There been previous stories that, that I've read of, uh, this being in, in state, uh, hand or in county hands rather than in state hands.
Um, but the whole point here is that local communities don't really like the idea that there are gonna be massive data centers soaking up or, um, a lot of the resources that they would otherwise rely on. Uh, and power and cooling are a couple of the really big ones that, uh, there's some concerns that there aren't enough environmentally sound power sources for these massive build outs. So yeah, there's, there's some real concerns, uh, and a variety of communities, uh, spread across the entire country about these data centers being built out.
The impact of these data centers on local communities, local resources, and the wider environment. The story's gonna continue. I think we'll, we'll see more of these stories of people basically saying, not in my backyard, but maybe this is more than just straight up than theism.
Maybe this is a, uh, stand against what we possibly think might be a bit of a bubble going on with these builds and that nobody really wants a half built and then abandoned data center, uh, right next to their town center. So yeah, there, this is definitely a speed bump for a lot of the companies that are wanting to build out these data centers and they wanna build them close to where large populations are. And of course, that's where resources tend to be scarce.
It's a real chicken and egg kind of challenge for them. Just gonna increase the cost of your AI if you end up getting value for that ai. Zscaler has acquired the browser security for firm square X to extend zero trust protections directly into standard web browsers.
The deal integrate square x browser based threat detection into Zscaler zero trust exchange, helping protect users from phishing, malicious extensions and, uh, data leakage from AI tools, AI's everywhere. Uh, again, all of this without requiring enterprise managed browsers and secure Legacy VPNs to tunnel everything through the slow core of your network. Did I say that?
Slow the core of your network's not slow. Is it Tom? Well, you'd hope it wouldn't be, but that's not where you wanna be scanning for this stuff anyway.
'cause you want those packets to fly across there as fast as possible. And I have been talking to Vivek and the people over at Square X for quite a while. In fact, you probably saw them present last year at Security Field Day.
And the biggest question that always gets raised is, why do you want to create a secure browser? As you're watching this from Safari or Chrome or Firefox, you're probably watching it on a web kit or a chromium browser because that's literally the only two browsers that are left. Um, they're, they're all using the same rendering engines.
All of the applications that we use are browser based using Slack. Guess what? Kids?
That's Electrum, that's a browser based app. It's just the browser is locked down and it's on your system and it doesn't look like a browser. So why wouldn't you wanna protect that?
It goes back to the story we talked about with the, the SASS e gateway. If you know all of your traffic's going through one place, why don't you just scan at that location? And I, I love the fact that Square X is like, we're not gonna use those stupid VPNs, by the way, if anybody needs to know, like tunnels are the duct tape of the internet because you can't make something work, force it through a tunnel and then you can do things to it.
And they don't want to do that. Instead what they do is they have an agent that lives inside of a browser and it enforces security protocols. And when you think about a corporate laptop, that is absolutely perfect because I'm not gonna let you download other stuff, right?
If you're supposed to be using Edge, you're gonna use Edge. If you're supposed to be using Chrome, you're gonna use Chrome. And I think most people are using Chrome.
I don't think anybody's using Edge. But what it allows this now to do is to integrate with the rest of the Zscaler platform, right? Because that's ZScaler's thing.
They are the SSE King, all of these security services. So it's loaded into your browser with ZScaler's plugins. And now you can do content filtering.
You can do redirection, you can do, uh, posture assessment. You can do all of that stuff. This was a really good exit from the team over at Square X.
Um, you know how it is, like you, you create a product and you think to yourself, man, I would love to see this being used in a platform. And that's exactly what Zscaler said. If this is the next frontier, everybody uses a browser now, whether they realize it or not.
And this is a great way to provide security for that without having to install tons and tons of plugins and agents. You just use what Square X has already developed and delivered, and that allows you to provide a secure workspace for everybody. So I'm, again, big, big, uh, shout out to the team over at Square X and I'm excited to see where this goes with, uh, Zscaler and Zscaler.
We'd love to see you at Security Fuel Day. So gimme a call. We're gonna be talking about our friends over at Google because they have released a new developer knowledge, API, which allows coding assistance to directly access the latest Google documentation.
What you may not have to Google for it, the new API provides programmatic access to Google documentation rather than relying on the version that was available when the model was originally trained. Does this mean that we're going to see more APIs to provide assistance to assistance doing things so that they have the most current documentation? Yes.
Yes it does. Uh, and it's awesome. What I, this is the, the right application of the MCP standard.
The standard for allowing one AI tool to gather data out of some other tool, whether it's another AI or in this case, this is it of documentation. Uh, this is absolutely awesome. Uh, as background, you probably aware that large language models take a lot of compute power and a lot of time to build, and they only know about what was in their training data at the time that they were built.
So if I'm using a large language model that was built six months ago, that's great for working with enterprise software where there probably hasn't been a new version in the last six months. So it knows maybe my, my old version of maybe on-premises, uh, installed word. But cloud services are constantly updating.
That's why software companies love delivering things as a software as a service because they can always have the latest, most secure, most UpToDate version running. And that means that there's a newer version than when your large language model was trained. So your coding assistant is not aware of the changes.
Uh, this ability to link your coding assistant to Google's canonical source of truth of what the current state of all of their services and the way you interact with them, this is awesome. And we'll see more of this. We'll see the same kind of capabilities turning up for anywhere that we need to have our code integrate with something that updates reasonably frequently.
Uh, myself, I do a bit of embedded development, so working with microcontrollers and having access to the, the latest information about both the libraries that work with my microcontrollers, but also having my AI coding assistant able to directly access the documentation for the specific micro controller I'm using now, that will be really beneficial to me. It's, uh, one of the reasons I'm looking at using some sort of, uh, AI coding assistant maybe for some of my embedded projects. But it doesn't just have to be documentation.
It can also be around the capabilities of every other microservice within your organization. You could have the segregation where, uh, the, the tool that is being used to develop one microservice doesn't read the source code of all of the other microservices. It just has access to an interface to the documentation of their interfaces.
Um, if you're building, building microservices to talk to another, each microservice should treat the other one like a black box. It shouldn't know what's going on inside it. It should only know what the API is to access.
So again, this kind of programmatic access for your AI assistant to know the interfaces, the capabilities that it should interact with is something we'll see more and more of. And it will significantly help to make these AI coding assistance better. Uh, whether they're good now or great.
Now, uh, we've had some interesting reports. We've had some great reports about improvements in, uh, AI coding assistance over the last two years since we've been looking at this kind of space. So they're there, they're creating code and hopefully tools like these, uh, MCP servers to provide access to up-to-date information are gonna improve the quality of that code over time.
Security researchers at SIG report that attackers are used AI tools to breach a company's ai, uh, AWS environment and gain admin can access in under 10 minutes by exploiting exposed credentials and automating reconnaissance and privilege escalation with a large language model. The attackers rapidly move through the cloud identities and access sensitive services. The incident highlights how AI is accelerating cloud attacks and raising the stakes for credential management and runtime security.
AI is making it much easier to attack you when you're bad at it. Hopefully you aren't exposing credentials to, oh yeah, Hopefully I'm not. Um, and hopefully no one else is either.
Here's the problem, and this is actually, I recorded this in this week's episode of, uh, security Boulevard. If you're not subscribed to, uh, please go do so. Security boulevard com.
Just look for the podcast. Um, if there's one thing that a, that humans are really, really bad at, uh, okay, there's a lot of things that humans are really, really bad at. Um, but one of the things that they think they're actually really good at is math.
Um, it turns out, no, no, you are not. Isaac Newton was good at math 'cause he invented math. Uh, some of it, uh, you average user are really, really crappy at math.
And I'll tell you why. Um, you know how, uh, we've always been telling you guys for years and years and years that you need to make your passwords longer and you need to add things like uppercase and lowercase letters. If you actually go out and look right now, if your password is, uh, six characters long and consists of only numbers, it can be instantly cracked as in a single GPU.
If you can find one or rent one from the cloud, uh, we'll instantly crack your password. And, and realistically speaking, just adding lowercase and upcase letters would, would link to that to about a month for a single GPU to crack it probably thinking, okay, cool, I've got a month. No, you don't.
You know why? Because I can rent 50 GPUs do the math. I can crack it in less than a day now because I can parallelize that workload.
Now, what if I could rent more than 50? What if I could rent a hundred? What if I could rent a thousand?
You're probably thinking to yourself, well, man, renting a thousand GPUs is super expensive, isn't it? Uh huh. You know, who has a lot of money hacking groups and nation state backed actors and people who really, really, really want to get in?
Now, imagine this, some company rents a crapload of GPUs from Microsoft and uses it to hack Amazon, or rents a whole bunch of GPUs from Google, the tus in Google's case, and uses them to hack Microsoft Azure. Why would they ever want to do that? Well, one thing, you're distributing the workload and all you're doing is you're, you're running a security scan, right?
You're, you're checking the hash value of this password. But realistically, what you're doing is you're parallelizing the workload. Um, if you're my age and AL'S age, you might remember a little project called Seti at home, or maybe even folding at home.
Remember when we were leveraging every screensaver on the planet to try to find proteins and alien life? Um, that's, that's what we're doing here, except we're doing this at a massive scale and we're making it very, very easy to do. And that's the problem.
Again, humans are bad at math. They do not understand that when you double the amount of computing power that's being dedicated to a resource, it's trivially easy to compromise something. 10 minutes.
Folks, if anything, if there is even the smallest, uh, like hole in the armor, it's going to find it and it's going to exploit it instantly. You know how we, if you've ever seen like any kind of discussion of things like Von Neumann machines or you know, the, the, the Nanobot Gray Plague kind of thing, you know that once it hits critical mass, it's the next iteration that causes disaster. So it goes from like a half life to a full life instantly.
And that's our problem. If it took 20 minutes for this to happen before it now takes 10, which means the next time it will probably only take five because these things get better. They learn, they, they, they grow.
And these people who are programming them are probably getting better at prompting them on what to look for, right? Look for sensitive secrets that are being held in the wrong spot. Analyze GitHub repos, pull all the information, information out that you can.
That means you've just gotta get better at defending all of your stuff. And yeah, I, I know I hate to say it, but you're gonna have to involve some AI tools to fight fire with fire. Because if the AI tools can catch the easy stuff before you let it get out, then that means that the people who are trying to get into your system are gonna have a harder time if only because they don't get to have the easy wins.
So we're gonna have to do a lot better about this. And that includes the providers. So Amazon specifically all my, all my buddies that still work at Amazon, remember how I've been telling you for years that you needed to make S3 buckets private by default?
And you know how you finally did that? And I'm taking full credit for that, by the way, like that, that's all on me. I, I, you should put that my name on there.
You need to start doing these things. You need to have automated checks that run against systems before they're put live and make sure that nobody has any of these easy to do things. And luckily in these cases, because researchers publish all their information, guess what you have, you have a roadmap to figure out what they got into and how they got into it.
And you can tell your customers, don't save your password. There. People are gonna find it.
It's the only way we're gonna get through this. And, and, and I hope that we don't end up with a great plague of bond Neumann machines because that's gonna be terrible. You know, it's not terrible, though, a closer look, because we had something we wanted to look, take a look at.
And I thought it was kind of interesting because it kind of speaks to the market right now. Uh, we're not gonna do this in the US though. We're gonna go somewhere that actually has regulations, you know, the eu because they are taking action against our friends over at Meta Over concerns that they are restricting competition by blocking third party AI assistance in WhatsApp.
The European Commission says that Meta's recent policy changes may potentially violate EU antitrust rules, and they're considering interim measures to restore access for rival AI developers while their investigation continues. Now, look, people in the us I know you don't know anything about this, but there is a program called WhatsApp that pretty much everybody not in the US uses to communicate with each other, and it's owned by Meta. And one of the things that Meta wants to do is put AI in everything, because they can use that as a way to justify all this massive spend that they're doing.
Uh, but one of the problems is that if meta only wants to put their AI models in WhatsApp and other companies are like, but we wanna do that too. And if meta restricts that, uh, something, something monopoly, something something antitrust, um, you know, again, a foreign concept to most people who live in the us but I wanna get the perspective of someone who doesn't live in the us. Al do you think that the EU is onto something here by saying, no, if you wanna put AI in these tools, you have to let everybody put AI in these tools?
Well, I think the, the key thing that's gone on here is that there has been a change in META'S rules. So, uh, last October 15th of October, meta announced an update to their business solution terms. So not just the the general meta, but meta business solutions terms.
And it effectively means that the only AI assistant available in, uh, WhatsApp is META'S meta ai. And that's as of the 15th of January. So this, this has been in play for a couple of weeks now, uh, looking at the eu, the European Commission, uh, site, their objection is that, yeah, this, this is a change to what you allowed to block competitors.
It's not that there've never been competitors providing AI assistance in, in WhatsApp, WhatsApp, you are now actively blocking those competitors. Well, that's very clearly an anti-competitive move, and I think it would be a very different status if there had never been any way to have a different AI assistant inside WhatsApp. Uh, and yes, for those of you who live in the US or live entirely in an Apple, uh, kind of space where you can use iMessage to message people over the internet, uh, WhatsApp, WhatsApp is that equivalent for people who don't use exclusively iPhones who are using, in particular, I use WhatsApp a lot when I was traveling to the US with my, uh, to the US and to Europe with my Android device, uh, because it was the easiest way to message anybody I knew without having to work out which country I was actually making the call from.
I just needed connection. Uh, WhatsApp absolutely is incredibly useful. Uh, and I'm kind of relieved that it's owned by Meta rather than some shady organization from some, some shady other company, uh, country.
However, this kind of behavior, yeah, it sits along with what we'd expect from Meta. Uh, they want us and everybody to be using their ai, they want all of our information to be feeding their AI as well. Because remember, if you're not being, if you're not paying to use the AI while you're paying with your data rather than your wallet, um, Tom, have you used, uh, WhatsApp as you've traveled around the world?
I know internally within the Tech Field Day team, we extensively use iMessage. So the utility for WhatsApp is a little lower, but I'm interested to see if you've used it a bit. I have used it, um, on and off.
Uh, my, my preference is not to use it. I prefer to use Signal for most everything because again, it's not owned by a s****y wannabe billionaire who created a website to rate how hot college students were that he then turned into a global ad empire that is creating filter bubbles that might be ruining society. But who am I to judge about that?
Uh, I, I agree with you. Here's the problem In a nutshell. You can create a platform that people want to use.
We've seen that happen so many times over the years. SAP, Salesforce, um, iMessage, zoom, you name it. What you can't do is change the rules to lock everybody out because suddenly you wanna harvest all of the data that's being sent in that platform for your own needs.
Now, they had a little bit of a problem at the beginning because the biggest selling point for things, not WhatsApp, namely iMessage and Signal, was that little thing called end-to-end encryption. You know, we've had this debate many, many times, end-to-end encryption means that the provider in the middle cannot see any of your messaging information. It means that they can't do things like analyzing it for, um, you know, add functionality or, you know, that kind of stuff.
Yeah, I like that idea. I don't like the idea of forcing me to use your AI model when I want to ask a question, because when I ask that AI model that question, that means that you get to collect the data on the exchange between those two things. Yeah.
You know, like the rest of the people that Mike, mark Zuckerberg is idolizing with the Sam Altman's of the world that, that are doing that. Oh, hey, by the way, did you see that chat GT has now sending, uh, has ads for the free tier? Yeah.
I wonder where those ads are gonna come from. They're probably gonna come from the things that you asked check GPT about. And that's the value is you remember in the old days with Facebook, the, the breakthrough in advertising was I'll just serve you ads based on things you hit the like button on, right?
Because I can request a whole bunch of information there, but even that's not enough now because people use likes like currency, like this post and I, and you'll get a free this or that you, they're driving using it to drive engagement. So people might actually like that thing. They may just be using it as a, a way to gain free things or follow a post or something like that.
But if I'm specifically asking a platform for a thing that is kind of a a, a direct intention, right? Like we've all seen it. If we start Google searching for cars of a specific kind, suddenly all of our ads turn into those cars.
But if I were to log into a, an AI platform and ask it, you know, which is better, this four cylinder engine or the six cylinder engine, then the system knows, oh, he's probably shopping for a car. Which cars have those engines? I'm gonna serve him ads from those locations.
Again, this is how they're gonna pay for it. The trick is, is that if you wanna not fall on the wrong side of regulation, you have to allow me to use whatever I want. And nobody is immune from this.
Apple's had this problem for a while. We've had chat GPT integration for an entire version of iOS. We're reportedly gonna get integrations with Google Gemini very soon.
But you cannot lock people out exclusively because that's what everybody wants to do. The, the problem with all of this, if I could stand even higher on my soapbox for just a minute, is not that these tech billionaire bros want to make AI invade our lives. It's that they want their AI to invade our lives exclusively.
Elon wants you to use xai and Grok Zuck wants you to use whatever meta is using Llama or some something. Altman really wants you to use OpenAI for everything because that is the value that is their competitive advantage that they have the data that nobody else does and they can't get it out anywhere. But if it's very easy for me to go up to the radio button and say, I wanna switch from using chat GPT to Gemini, then they're locked out and they're trying to make their platform sticky.
And uh, I hate to say it, 'cause again, this is a little bit of the political step on the soapbox. It appears that the people in the places where these things are being built don't seem to care. And so we once again rely on the EU who actually seem to give a damn about regulations and fairness to say, Nope, that's not gonna fly.
And they're gonna institute these things. And by the way, way the reason why the EU doing it, why, why it feels like it means more is because they don't just find you a few million dollars as a way to say, look, we are gonna slap you on the wrists. They're finding them a percentage of their annual revenue, they really make it hurt, which means people really don't wanna do that.
And one of the things that we're starting to find out is it turns out that EU regulations actually have a lot to do with making things better. If you don't believe me, think about GDPR and look at CCPA, which was instituted in California, which is very much closely related to GDPR. Our lives are probably better because of that.
And yeah, I know clicking on the allow all cookies pop up every time you go to a website feels kind of stupid. But would you rather be clicking on it and not and knowing that there are cookies or would you rather be blissfully ignorant of what's going on? Gimme blissful ignorance, man.
Just protect me without me either having to think about it. And that's one of the things that, uh, the EU does seem to, to like to do is to provide common sense protection for everybody as a sort of fundamental right. I like it.
Something else I really like is tech Field day events. And I'll be back in the US for Cloud Field Day 25 on the 11th and 12th of March. I have a great time there.
The delegate panel and the, uh, sponsor panels are both building out beautifully and stay in touch with us. Uh, keep an eye out on the Tech Field Day website as we update who all is gonna be joining us there. Uh, of course then Tom gets to travel.
Although you're not traveling to California in March, are you? Well, no, I am, I'm going to San Francisco because that's where RSAC is. I I love Moscone and Union Square and apparently in the news as of late the Tenderloin, um, it's, it's okay.
Uh, but we're gonna be there for RSAC, the RSAC conference. It's not RSA conference anymore. Uh, but we have great presentations coming up from Beam Object First Commvault and probably more we're gonna be listing those people on the website as soon as we confirm their participation.
And we're also gonna be listing our delegates, our friends like Sky Fugate and Shala Denise. They're gonna be there and we love to hear what they have to say about the state of security. And I'll probably be hanging out talking to some people.
I might crash one of Alan Shiels parties. You never know, just look for me randomly invading a podcast somewhere. Uh, the important thing is, is that I'm going to enjoy the fine March San Francisco weather if there is such a thing.
And then I'm gonna take a couple of weeks off for break and then I'm gonna come back and once again to Silicon Valley because we're gonna be talking about networking Field Day. This is gonna be big three days, April 8th, ninth, and 10th. We have some great conversations that are going gonna be going on.
com. Just click on the link for Networking Field Day. And by the way, that's Networking Field Day 40 XL Baby.
We hit it. We, we are gonna have to start using Roman numerals. It's gonna be wonderful.
And then we're gonna have to start doing it in Hex because you know, we need to preserve, preserve as much space as we can. What you also need to preserve is time on your calendar every Wednesday because that was when you get to watch the Tech Field Day rundown. We're gonna publish those episodes on YouTube.
We're gonna put them up in your favorite podcast application of choice. And we're also gonna put the show notes up so you can check out the stories that we link to and read those. The rundown is also streamed on Techstrong tv if that is your preferred place to watch it.
And don't forget that Al and I also spend a lot of time on other Techstrong and Futurum group properties like the Security Boulevard podcast or the Tech Field Day podcast. We're gonna be back next Wednesday to talk about all the IT news of the week that was, and we get to show off our Valentine's Day presence, uh, if they're cool until then for myself, Tom Hollingsworth and Alistair Cook, and as well as all of the people who bring you the TechDay rundown. Thanks for tuning in, we sincerely appreciate it.
And we'll be back next week. Phil Menez here, go to Market Execution lead at Vast Data and today we're gonna spend a little bit of time talking about some of the things we're doing beyond storage. Um, so again, VAST really launched our product to the world here in 2019.
We were founded in 2016 on the basis of this new shared everything architecture that really breaks the scale and efficiency challenges that customers are facing as they bring legacy challenges or architectures into ai. First thing that we did was build a storage product. Then we added a database product that rides right on top of that architecture.
Now I have the capability to have structured data next to unstructured data. Think about the world of having vector database local to where the actual source data is. And beyond that, we've now started to bring more compute in to figure out how customers can execute um, models and build agents.
And we're gonna talk about some of these things today in only a little bit of time. So one of the things that we have seen, common theme that's coming up and I mentioned shared, nothing shows up everywhere, not just storage, but eventing infrastructure. Eventing is becoming really critical to inference infrastructure.
And that is really in two ways. One, it's like events are happening. That's how my AI knows things are changing.
So someone's purchasing something, a stock price is changing. Uh, an iot uh, event has tripped, right? Something's broken.
But what we're also seeing is all these players that are actually deploying inferences scale are using eventing for feedback on how the user experience is, right? How long did it take to give me that answer? Uh, if I gave the customer, do you like this answer or that answer?
What data that is? So all the data around the user experience, how these models are working is being sent home being a venting infrastructure, right? And because of venting infrastructure is based on shared nothing.
We see these scaling challenges, right? I'm a legacy storage guy. I had to learn about eventing infrastructure at vast.
It is very complicated, right? When I scale eventing infrastructure, again, I'm breaking up my data across different nodes. Every node's a broker.
That node owns a partition, which is like a piece of what we're capturing and eventing and partitions, uh, brokers own partitions. Um, there's ordering of a venting infrastructure is only maintained within a partition, right? So I can guarantee data in a partition came in order.
This one came first. That one came second. I can't guarantee which one came first in a separate partition.
So it's really complicated to build this out. My main example for that is you need something called a zookeeper to keep all this stuff working, right? Because this stuff is like wild animals, very difficult to scale.
And ultimately what you generally see is customers having to break up their eventing infrastructure into smaller clusters, right? We see a lot of right amplification here. We use something called replication to keep that data.
What if a server fails, right? Comes in. I've gotta write that to generally two different other servers exploding capacity, um, you know, really killing utilization.
And then the other problem here is that the analytics on eventing infrastructure super weak. It's really hard to query this stuff because it's not in like a table form. It's basically like a long run on sentence where every event is a new word.
So I have to, if I'm doing analytics, I've gotta go out to all the different nodes and really like replay the events that happen looking for the data I'm looking for. So customers don't really do analytics on this. And that means depending on how quickly that data moves from my eventing infrastructure into a data lake, I might have a 15 minute gap or hours long gap between, I have real insights into what's happening in real time as we're moving to more real time ai, I wanna be able to act on things that are happening now.
Someone's stealing something, something's on fire, whatever it is, I wanna be able to act on it now. So the shared nothing architecture not only solves the scaling challenges of storage, also solves the scaling challenges of eventing infrastructure. Because I now have this parallel architecture.
I have the compute layer, right? Everything that lands in the system is acid, right? So we will tell you what order everything came in across partitions.
We don't have to worry about any of that. We have NVME parallel access to every single device in the system. That means I don't have to worry about any of that ownership ordering.
What we actually do is take data that's events and every topic that's like what we're talking about in terms of eventing infrastructure. A topic's usually broken up into partitions. And every topic is a table in the vast database living on that day's architecture.
And every new event is a row. And uh, something I learned about databases, row based databases are really good for capturing data. Column based databases are really good for analyzing data.
So what we actually do is capture the data coming into the system in storage class memory in row format, and migrate it down to column format into the QLC. So that means that I have really fast capture on storage, class memory and really strong analytics on the QLC. So now this is really important as I want to be able to have agents interacting with data that's still on my eventing infrastructure so I can make decisions on what's happening in real time.
But we're also seeing customers love this for more traditional data analytics workloads that have eventing infrastructure. I can't get any insights from it. I've gotta move that to a data lake.
Move that to a data warehouse. Yep. The challenge with, you know, events and brokerage and things of this, it, it's quite high throughput activities and you're building a a row relational database out of it and then moving it to a column and database.
Um, did you have the compute structure to be able to support this at, I don't know, million transactions a second? I mean what would that look like from a cluster perspective? Absolutely.
So fun lead in, uh, we've tested this per server. Not only is it simpler, more scalable, we are dramatically faster, right? 5 million transactions per server.
You know, one of the first ever customers that I knew that was looking at vast, they needed 11 servers in their eventing infrastructure, three on ours, right? So it's faster, it's easier to scale and it's dramatically simpler, right? So when I look at trying to consolidate this and give my agents a view into what's happening in my real time environment, this is a game changer for our customers.
The whole white paper on the details of the performance. Yeah, love that T in question. Okay, so couple things that we're gonna hit on.
Shared nothing, it's everywhere. It's causing problems everywhere. We're also seeing huge problems with shared nothing in the vector database world because it's the same thing.
Another distributed architecture vector databases, right? Some of the things that are challenging with vector databases, I wanna scale beyond a server. Same thing like we're doing with data reduction.
I've gotta create shards right now every one of my servers only has a piece of that vector index, right? These are very memory bound. Generally speaking, when you're building vector databases, you're trying to get all the activity in the database to happen in memory.
So I either need to scale more servers, right? Which adds more complexity or beef up the server's memory footprint. We've seen customers with like 10 terabytes of memory in a server trying to squeeze as much as many vectors as they can into one server.
And then another real problem here is that inserts and updates very, very slow, right? The data structures that make it easy to search vectors make it really difficult to add new ones. 'cause I've gotta like understand how do you relate to what's already in the system?
I wanna make sure that you actually do some clustering. So data that looks the same, you're trying to keep it close together so I don't have to go really far apart to find things that are close together. So that's some big scale challenges.
We see more of the scale challenges as customers do more data or get into more rich types of media. I wanna do AI and inference on video instead of documents, right? So we do see customers and are like our vector databases are working fine.
But something that we've realized, if all you're doing is like PDF search, you're not gonna create that many vectors. So here's a a a real example. Customer 600 million documents, 600 terabytes of storage.
It's like 4 billion vectors, right? It's not that meaningful. If I looked at, you know, a blue chip enterprise with a hundred petabytes of data, I wanna vectorize the whole thing.
43 trillion vectors, right? That's a lot of different vector databases that I'm gonna have to sard up and move around and my data's very fragmented. I have to build a lot of intelligence on top of that to make sure that my AI can get to the right index that's gonna have the data that I'm looking for.
So we now have a vector database built on the day's architecture that solves a bunch of these scaling problems. So one, we're able to get to trillions of vectors, right? So I can store a ton of data and consolidate without worrying about sharding and breaking up my databases.
One giant vector database, we did a really cool smart cities project. That customer had 52 different shards of their vector database one on vast, right? They really couldn't get it to work.
Um, vector search scalability. Again, a lot of times these struggle with search at scale. As I add more, I'm constantly trying to move data around, keeping things that I expect people will ask about right next to each other.
That becomes harder and harder and harder as the system scales insert scalability. The fact that we can do real time performance at scale into that storage class memory means that we can do rapid inserts. Generally speaking, that's one of the biggest areas where we see vector databases tip over.
I want an agent to watch a video feed and while that video feeds coming in, I need to be embedding it and chunking it up and storing new vectors. That in-memory model does not work for that. It just tips over.
Pretty much everyone gets to video, everything falls over PDF's, fine video bad on legacy vector databases. And another problem is around security. And this is something really cool, like why are we not just all these different products?
It's one product because we can actually take the same permission structure and apply it from the document image video that you've given us to the vector that's created based on that video, right? So it's really easy to say like, I can access a document and Scott can't, right? That's kind Enterprises have figured that out.
But what they didn't figure out was how do I make it so my large language model won't answer a question about that document for me if I don't have access to it? That's hard. The first time we saw happen when enterprises started dropping everything into large language models, everyone started asking questions about stuff they weren't supposed to know.
Mm right? Like how much does my CEO make? Where does he live?
It's like, alright man, here we gotta shut that down. So how do we put that in place and make sure if the permission of a data piece of data changes at the permission of the vector changes? And we can do that with Vast because I apply a common data set of permissions across tables, objects, files, right?
And I know we're really running on time. Something that we can also do. We haven't talked about our data engine that I can also create data-driven workflows on Vest.
So as a video comes in, I recognize it's a video. I launched the embedding process for a video and I store those vectors back into the vast database. So I know I'm at time.
Um, there's other things I wanted to cover but we won't hit on. But we do have our first user conference coming up at the end of next month, February 24th in Salt Lake City. We're gonna have a bunch of announcements, a bunch of great customers there.
Um, so if you wanna learn more, it's definitely a great place to tune in on what's happening with Vast and what's going forward. Thank you again, Scott and the team and all the delegates for having us today. Oh, good morning everybody.
Uh, my name's Scott Shaley. I'm a Director of Leadership Narrative and Evangelist for Soy. And just in case you're wondering why I have such a long title, I decided to get paid by the letters in my title.
So it helps with the, with the whole process of up upping my annual income. And alongside me today is Phil, um, Menes. I said that right?
Right. Menes Menes, thank you. Go to Market Execution lead at Vast Data.
So we're gonna split this up a little bit for you guys today. He's gonna step off for a bit. We're gonna give you the, uh, look and feel of the world from a storage provider, IE hardware.
And then we're gonna bring Phil up and give you a great rundown of how software and hardware work well together in the ecosystem. So awesome. Looking Forward to talking to you guys soon.
Alrighty. So we wanted to talk to you today a little bit. It's the beginning of the year.
There's lots of fun things going on in 2026. We're gonna talk about the market some drives 'cause you know, that's what I make the cooling effect of what's going on in the world. And also, uh, a little bit about a lab that we might have, uh, spun up at solid IME as well.
But before we get into it, I wanted to kind of give an analogy and kind of wake up the room. You know, it's eight o'clock on a Friday, day three, we gotta have some fun. So feeding the data requirements, how can we talk about storage in a fun different and sugar filled way because I have a sugar problem.
So we have this really cool feature known as the glazed donut. You look at it, it has some very interesting things about it, but there's always this problem with the hole and the hole. And the look of this to me says hard drive and it spins and it has a certain feature and there's a, there's a gap.
You have to cross with some data processing and things like that. And if you put everything in the same shape and of a glazed donut, it's always gonna take like a glazed donut. So SSDs have spent decades following the hard drive mantra, but we've decided to have some fun now in the ecosystem.
And now we've brought in the maple bar, kind of looks like the form factor of certain drives that now exist in the marketplace. E one SE three, things like that. We broke the mold of going round.
We've gone off and done our own thing with storage and we make some amazing dough at soy. Soy is a great data houser because you can store all kinds of data in the nice little intricacies of the dough inside. And we put a nice little glaze on top 'cause we wanna make sure that you have some flavor as well.
A little bit of performance kick here, a little bit of capacity kick there. But we also know that at the end of the day, you gotta have a little bit more once in a while. And I'm not gonna break it open 'cause it's gonna spill jelly everywhere.
But there's this thing called a jelly donut. And so if I build a really amazing storage drive and you guys have lots of fun putting your data in there, what are you gonna do with your data? 'cause I'm not the guy that's gonna sit here and figure out how to manipulate, play and manage your data, but I'm gonna hold it.
I'm gonna store it, I'm gonna keep it safe. So that's why we've brought our partner, Phil, from Vast Data along because they're kind of like the jelly in the jelly filled donut. We make the right amount of room, we make the right cavity in the space of the data at how it's managed, stored can be transferred in and out.
And they fill it up very nicely with their software solutions and take advantage of some of the features that when we partner together, make the products even more effective and useful. So that's my, uh, morning wake up for the how to bring sugar because I love sugar into a presentation at eight o'clock on a Friday morning. So when you think about data and you think about next time you pick up a donut, there's so many different varieties of donut, but you know, the right one is always the solid item one.
How about that? So I also wanna ask the room 'cause you guys get to speak up. So there's this whole thing about storage for ai.
We've got a lot going on, we're gonna dig into a whole bunch of it today. But before we kick it off, I'm just curious, anybody awake enough to kind of throw out their thoughts about what's going on with the bubble that we're in today and where we see that bubble going? Does anybody willing to throw out a, a thought on what they think of this?
Is it a flash in the pan? Are we three years, five years? Does this last forever?
Just open it up for a quick thought. We Need do is take the jelly donut and do this to it. I was told not to throw things, But you can smash them.
You can smash them. No, that's true. But then I would make a mess and I'd have to get involved with chain the cleanup bill.
That's your answer. That's the answer. It's going to be a mess.
I I like that. Yes, it's going to be a mess. So we don't disagree.
There's definitely been a lot of challenges and a lot of it has to do with supply and demand and how they cycle. I've been doing this for way too long. It was fun when I hit 20 years.
I'm like, I'm a 20 year veteran in the industry. I hit 30 this year, starting to feel a little old. Um, so I've been doing this for 30 years and my first cycle was the year I started in 1996.
'cause I joined a, a semiconductor company and everybody was raving about the bonus checks and the up cycle and everything like that. And I started when it hit. And so I saw the big checks, but I never saw the big check.
All my coworkers started selling cars and all that kinda stuff because of that first cycle all the way back in 96. And we've ebbed and flowed through these cycles and I've got a couple of examples of the big cycles that have hit the market. So when we transition from the 2D architectures to 3D architectures, there was a huge hit.
'cause when you change a wafer from one technology to another technology, there's gonna be a gap. It doesn't matter if you've got more fabs, more wafers, whatever to bring one online. You have a glu in the old one.
But then the new one comes online at such a higher density that boom, we hit this massive oversupply. So 2D went, 3D we had an oversupply problem. So that was induced by the vendors.
So there's a, there's a storyline here. The pandemic came around, this is jumped, you know, a few decades later. And we started having the hoarding happen and I threw up here my favorite little object that's been hoarded by all the folks during the pandemic.
And we remember those days, right? They did the same thing with semiconductor products. People were like, oh my word, the world's shutting down.
We've gotta have everything on the shelf to spare because there's no way we're gonna be able to replace products. Over time people were locking their engineers in data centers. I had a friend of mine who literally was on a one month cycle.
He got one month, he got to stay in the data center, sleep on a cot in a, in a storage room. And then he got a month off and he went back in and he was getting paid hazard pay for the month. He was in the, in the building, but he could not interact with anybody.
And so we, the, the industry hoarded our products. And so we sold everything in 20 20, 20 21. And then it stopped.
Everybody kind of said, whoa, hold back. And then we hit the next big down cycle. And it was a big down cycle because the world shut down.
Innovation had stopped. Everybody was just keeping the lights on. So the, the wells dried out for the innovation on the r and d side to put up new fabs, new this, new that.
And now we come into the current cycle and all of a sudden we've got this situation where we've got a, a good amount of supply. We've got a great situation in the market for the opportunity for amazing upside, but nobody was investing at the back half of the pandemic. 'cause we didn't have the money to do it.
Nobody did. And so we get things like the CHIPS Act, which help a bunch of companies do things and we get a bunch of stuff happening and all of a sudden the AI bubble hits and we're like, oh my gosh, memory, memory, memory, memory, memory. Well, soy doesn't make memory, but we use memory in our drives and we have a parent company that makes memory.
And it turns out that the memory fab and the nan fab are not interchangeable anymore. That stopped around the 3D era where you had to have dedicated man lines and dedicated memory lines. All the investment in the last 18 months to two years.
Memory fab, memory fab, memory fab. Because the storage was just still not really being the, the, the bell of the ball, if you will. But now we're starting to see, especially with what's happened and we'll get into a, a little bit of the demonstration of that with the recent uptick of need of storage.
So we've hit the memory wall, we've got memory, they're building more memory and the memory will come online in the next 18 months. But we still have a problem on the storage side. So we have capacity that's coming online.
People have made announcements, we've talked about what we're gonna do to increase supply and how we're gonna manage all that. But you throw in the AI bubble, the lack of investment and the Moore's loss slowdown of the two, the two on two. And you have this amazing situation we're now riding, which is this, uh, little bit of lack of supply for the amount of demand we have.
And the demand is driven by the industry. Think of all the iot devices. Everybody's watch, everybody's everything.
The autonomous car takeover, the humanoid robots. It's not just the simple fact that we don't have enough wafers to make stuff. It's the fact that people are consuming it in so many different ways.
Even more so now than we did 20, 30 years ago. So the age of AI is definitely gonna keep us moving. You know, you've heard a lot of people talk about being sold out for 26 and going into 27.
Our friends in the spinning world just yesterday on the earnings announcement said they've got LTAs through 27 for their spinning products. So we're gonna see this for a little while longer, but we're excited about it because it gives us an opportunity at soy to do things that are on the forefront of innovation instead of just making the next great drive. How do we make what we've got, what you can get access to work better, faster, stronger.
And that's where partnerships like, uh, with Vast come into play that you'll hear about as we get through this presentation. So it's an opportunity for us to actually engage more and do more with our customers than we've already been doing. 'cause one of the big things is, um, there's a lot of recent headlines that come from a whole bunch of different places.
Tech Crunch, Bloomberg, Fords, Benzinga, that are all talking about what needs to happen for the AI data center. And we managed to throw up a headline from our site about all the work that we've already done to address some of these problems today and that we can move forward into the next world. So talking about, you know, went from back end to center stage from a data center perspective.
So we've talked about economics, we've got a great bunch of stories on, uh, TCO including a great one with our partner, vast achieving, uh, the scale. We're very close to several of the Neo Cloud players in the marketplace. Core weaves and others that have been very good about being partners with us in this industry.
Drive as we move things forward. And then, you know, the market that never existed, we'll get a little bit more into that, but Jensen at CES made this comment that storage is now important and I think everybody at solid on kind of took a, you know, fall off the chair moment and said, yay, somebody finally talks about storage. So, but the idea is we've been thinking about this from day one.
We've always been that. We've talked about it. We were here at field day two, AI infrastructure field day two talking about the AI cycle, how we impact it, how we work with it.
It's not about building a ECI Gen six drive that operates at seven gigabytes per second and 200 million iops. It's about how do you use that product in a system and make it most effective for the customer. And that's what we spend most of our time.
It's all that I'm doing is focusing on this concept of how to drive customer success with the portfolio of products that they need, not necessarily the big shiny object in the room. So this is the one product pitch slide I have for you in the entire presentation. And you can see we've basically got two categories of products for, uh, people to consume from a, uh, performance perspective and a capacity perspective performance.
Our flagship product here is the PS 10 10. I've highlighted it because we're gonna talk about it a little bit more in the deck with some of the stuff we're doing around our cooling infrastructure. And of course the, uh, P 53 36 is our bell of the ball.
It's the 1 22 drive. If you were lucky enough to join us last year at, uh, the, the second field day, you all received your own personal version of a 1 22. Unfortunately it was Legos, but you did receive one.
Um, but some of the metrics around that. So high capacity is a thing that a lot of people were like, we're never gonna see it, we're never gonna be able to ship it because it's, you know, it's just too big, it's just too expensive. But at the same point in time, you can see the metrics here, four and five exabytes of a high capacity derive in 2025 were sold by soy.
30, 61, 22, 1 in two exabytes of anything over 30 terabytes were shipped by soy in the market. And we had 100% of the 1 22 market in 25. So a lot of people talk about delivering a product and a lot of people talk about, look at my, my pretty little object and some announcements were made last August FMS, but we're out the door shipping it, delivering this product.
And you'll hear how it's being consumed by my co-presenter filth a little bit later on. So we don't just build a product, build a product, we build a product that customers want to consume. Because if you look at the market and the mix, PCIE Gen 3, 4, 5, and we've got these pretty graphs in our marketing decks that we can send out if you guys are interested, that show the transitions of who's consuming what form factor or what generation of PCAE, what capacity, we track it all and we make sure that we're always in the sweet spot.
Our products and our solutions are always gonna be where people can get them, use them and deploy them effectively. And at some point the TCO asked to work out to the cost structure. So when we were here last time, I talked to you guys a little bit about liquid cooling and I brought a cool little um, uh, display.
That display is currently running around at many different places and actually getting in the process of being deployed. But we thought about this and we said, you know what, cooling has three aspects. First of all, we got the fans, everybody knows the fans, we hear some fans in the room from the projector, things like that.
Everything was cooled by a fan and that dictated very much like the round, uh, circle of storage, a specific form factor and deployment model for customer server solutions. So the only way to get around that is to either slow them down by adding bigger fatter fins on our drives and making airflow adjustments and all these conversations about linear feet per minute or LFM, not the nice LLMs in L and ai. But then we get this AI bubble and we get these massive GPUs consuming hundreds of watts of power and we'll talk about that as well.
And they started putting ch cold plates on them. But it's interesting, if you look at a server configuration, the one product in most servers today that is considered the must still be 100% human serviceable. It's the storage product.
Because the history of certain types of round media had lots of problems. They were, they're great products, don't get me wrong. I love our friends in industry, but they just have mechanical issues.
And when we switched over to the solid state drive market, we put 'em in the same boxes. 'cause it had to fit in the same slot that made it serviceable. But if I look, if I show you failure rates for these drives, the, the solid state drive, there's so much less.
But yet people still don't trust them the same way they do the GPU in the back that's mounted to the board with a cold plate. And if it decides to fail, you replace the server. My little drive out front still has to come in and out because you might just wanna replace it.
And so how do you do that? You put a liquid coal plate on the drive and we showed that off to you guys, uh, last time. And I have a slide of it as well.
But then we gotta go one step further. Okay. If we're gonna talk about cooling, there's this really cool thing called a dunk tank.
And when I first started selling enterprise drives into the immersion market, it was 2008 and we had to pull the drive apart conformally code it, sell it as NCNR and pray and hope it never failed. Because once you conformally code it, there's no rework, no nothing. We can't do that and make it a mass scale at the way an AI data center is going.
So we have to find other ways around it. So what does solid m do? We tell our quality guys, go figure out how to make a dunk tank work.
You know, for, for, for example, so we showed off the liquid cold plate architecture last time. This is the cool little sliding uh, instrument where we take our E one s and we slide it in against a cold plate. We actually had to take that cold plate design that we showed off last year to snea because we're an active and leader in snea standard body around form factors.
Because when you put up drive against a cold plate, and if you look at my nice broken pinky fingers, they don't touch. And if they don't touch, you don't get cooling. Mm-hmm.
So we actually took the specifications, we designed around that E one s drive to snea to redefine the form factor requirements for a cold plate for the entire industry. We gave that information away so that we can enable this market moving forward. It's not just about us, it's about making sure the customers get what they want and they're not always gonna buy us, they're gonna buy someone else.
We want them to have a working solution at all times. And so we, we, we stiffened the flatness, we made the, the tolerances different and we made sure that you had to put the sticker on the appropriate side. 'cause if you've looked at drives from all the vendors, we tend to put stickers on whatever side we want.
And of course a sticker is a dielectric so you lose your cooling and effects and things like that. We had to champ for the corner of a drive. We have these nice square blocks 'cause it just works.
And when you come from a mechanical pressing perspective, a square corner is actually easier than a round corner. But when you're sliding hard metal on soft metal, you really don't wanna scrape it. And it has to be insertion friendly.
So we actually cut the corner off the drive, things like that. Those are the kinds of work that went into just doing a liquid cold plate solution. So now we take a look at full immersion.
We're sitting and we're dunking the server in a tank. We have two versions of that that exist today. Single phase and two phase.
I've grayed out two phase 'cause we're kind of not playing in that space right now. It's a little bit more of a, an interesting ecological and environmental beast. And not as much work is done in that space today.
'cause it's a constrained, confined and somewhat caustic environment depending on how you look at it. So we're focused on single phase, which is an open air tank, and we worked with partners like Hypertech around the server design, how to help them make sure the server solution in our drives work well together. And we work with a company Doug, who does portable edge friendly data centers.
It's literally a container that you can take out and drop anywhere and plug it in, fire it up, and you've got a portable data center and an immersion tank. And they've been doing that for quite some time. But it's fun to talk about it.
But you guys like data, technical presentations are always a good thing. And so we wanted to give you a little bit of detail on this. So we were at Super Compute in, uh, November last year, and we had Hypertech as a server vendor, Valvoline as a fluid vendor, and Midas as a tank vendor in our booth together showing a combined architected solution for our customers.
So we are one little cog in that wheel and we're not the biggest cog in that wheel, but we bring these people together intentionally to show the innovation and capabilities of these technologies. And Scott? Scott, Yes.
Ray There. Sorry. I heard, I heard the voice of God.
I'm trying to understand where NAND requires that much cooling. It's not like it was a big thermal, you know, heat sink in the, in the past. I mean, is it because of the capacity?
Is it because of the, uh, density, maybe the speeds of your logic or, or, or what's going on? So interesting question. It, they do get, they have gotten warmer over the years.
PCI, gen four, gen five, just nature and thermals. Just like with going from hopper to grace to Vera. Yeah.
It gets hotter and hotter and hotter. We're not the hottest thing in there, but in order to cool us, you still have to cool us in the right environment. And if everything else in the box has a fan or has a liquid and I have to have a fan, you've put something together.
If you look at the CS presentation from Jensen, the 2 million parts down to, you know, 15 parts, yeah, they got there because we worked with them to define the liquid cold plate for the storage. So we're not, it's not necessarily about how, how much heat we generate or how cool you have to keep us, But you're in a SEC system that has to, requires we Enable the rest of the ecosystem to move forward with net innovation. So the, the Vera Rubbin compartmentalized liquid cooled system exists because we worked with them to define how the cold plate can work with the storage device.
And so when we talk to people that want to do immersion, you talk about supercomputing like Cray and other companies like that, that have been immersing things for decades, that's the next logical step. So it isn't about just the thermal of our drive, but how our drive impacts the ability to deploy the system, if that makes sense. And so to do this, as I mentioned, you used to have to conformally coat these things and all that kind of stuff and it creates a whole new product category, cost category.
People want off the shelf products going into an immersion tank. And so I had the luxury of going up to Montreal and that's, that's, I'm, I'm the hand can, that's why it's not a pretty hand. Um, dragging my drive out of a live server in an immersion tank, pulling it up, putting it back in.
I would show a video, but videos don't tend to work great. So you get a screen cap. Um, but there's interesting challenges again for our product in this solution, like used to be front accessible.
Well now it has to be top accessible, right? They still have to architect an immersion server where I can reach in and do that without causing problems to the rest of the system. Now it's interesting, Valvoline, Castrol, all these companies that do the, the fluids, it's classified as a food grade lubricant so that they can ship it from around the world and it comes in these massive tanks that are being shipped back and forth.
And now the problem when you go to display one of these at a trade show isn't about physical footprint. It's can this floor support the weight mm-hmm. Of the solution.
Mm-hmm. Because these things are now laying down and think of a giant bathtub full of electronics. So it's, you know, thousands, tens of thousands of pounds being put on floors.
So now going to deploy immersion, it's even more entertaining, things like that. But what we found out in doing this research is we started playing with a bunch of these different fluids. There's a whole bunch of different types I'm not gonna get into today.
If you wanna learn a little bit more about that, go to OCP Global 20 fives. Uh, a history file in our hardware engineer does an actual deep dive where my little graph comes from. But one of the benefits that we found for soy was that when you have an A fan, you have certain amount of nuance how the LFM works.
When you have a cold plate, you've got, is the water temperature always the same in a tank? You have the most succinct, sustained temperature of any environment. And what is a semiconductor like consistent temperature?
The hardest problem with doing things like endurance and reliability on a, on a semiconductor is going really warm and going really cold and keeping the data accurate. The flatness of an immersion tank is amazing from a temperature and The throttle limit is when you would start throttling the performance of the drive because of the thermal. Yeah, because it's getting too hot.
We, if we program too hot on a four bit per cell product, you go cold for whatever reason, like you decide to turn it off for a while, it's a little harder to read type of thing. So we throttle it intentionally to make sure that we don't overstress the semiconductor. But in the fluid you can see doesn't really matter.
It's always very subtle, very comfortable at those temperatures. So Are those drives then targeted for storage solutions or, or also for servers? Because I mean, CPUs will have liquid cooling GPUs.
Yeah. You know, memory. So does everybody do their own little thing then Everybody has to play well in the ecosystem.
Right? And so for us, what the big focus was is validating our products are are warrantable and usable in these environments for long term people have been putting them in tanks without quote permission forever. Right?
But now we're saying it's time to be part of the party and make sure we understand what's going on. So the, the middle picture of the drive, the reason it's showing it open is one of the biggest challenges with these food grade lubricants is the Tim acts like a sponge and or it can start to melt away. Now you've still got the fluid running through the drive 'cause it flies in its ways in the nooks and crannies, but it has a potential to create too much, uh, liquid connection to a single part because the sponge just sits there and is constantly pressing one temperature dot on a mini transistor inside the drive that can literally cause the drive to fail.
So we've done this research to make sure what's going on and our partners at Hypertech actually take an off the shelf air cold ready GPU, tear it apart and remove the Tim and put it back together to put it in their servers for these tanks. Because the, Tim is one of the biggest problems in these drives. So when I, I was there in Montreal, I said, how do you guys test these products without going into this giant suber or dug or whatever tank and validate whether the products work or not?
And he said, he walked me over to the corner, he is like, can't take a picture because there's too much other stuff going on there, but it's an industrialized deep fryer from like a, a food truck. Mm-hmm. And I'm like, we used to joke about can I get my tater tots in the tank?
But they really do use a industrial sized 'cause it's the only thing you can put a smaller component in and keep it at the right temperatures. Right. They're not frying it, but they use the fryer to get the temperature, have the basket and all that kind stuff.
I thought it was absolutely hilarious. So the number one problem that we actually have with our drive in an immersion tank system is the sticker, the food grade lubricant eats the sticker glue and the label falls off. It doesn't cause any problems in the server just is now unidentifiable.
So we actually, the the current solution is to put a layer of, uh, nail polish lacquer over the stickers for all the components, not just ours. Any label on any drive falls off in these fluids. So they literally to get that drive to stay intact for the label, for the pretty, uh, you know, Photoshop, we put nail polish on it.
Scott, in play real Quick. You mentioned, I think you said Tim. Tim, what was That Tim?
Uh, the, the blue goo on the drive is thermal interface material. Tim, sorry, I used an acronym without defining it. I'm not really, don't tend to forget that.
Thank you very much. So that's an example of how we're working that. And so what we have to do is now we have to validate our drive in all these different fluids.
So we have to get our own version of an industrial fryer, if you will, put our products in it, test it, make sure they work. And there's, as you would with any kind of fan system, there's multiple vendors that we're playing with. So we're doing a lot of work right now to validate, uh, the immersion cooling architectures for our products At This point.
Are you doing any of the kind of new stuff like Microsoft is doing where they're actually sending the fluid to, uh, to with a, they have cold plates and they send the fluid to directly to the component that's overheating when it needs it. Have you seen that? Um, not specifically if it's cold plate involved, it's gonna be, it's gonna be a different type of fluid.
It can just be a glycol or even water. The, these are different types of things. These are oil based derivative, which Yeah, I think they're doing it without water.
That's the whole initiative we're doing. So no, I thought you knew about it. You have to tell me.
But that, Not that specific version of it. No. Okay.
But yeah, the, the whole process here is also to avoid the, the water loss, right? Because we've talked about one of the things that we're actually working on in our efficiency stories that you'll be seeing coming out from solid over the, over the rest of the year and we'll introduce a little bit at our next field day event that we're coming to is the idea of A WWE. So we have a PUE, which is power utilization effectiveness.
Now there's a water utilization effectiveness and we actually help customers understand, we've gone to the point where some of our TCO models take into the amount of carbon footprint com, uh, impact of the concrete used for the footings underneath the data center that our drivers are going into to help customers understand how to use these products. So we're, we're definitely very much thinking outside the box on help on how we help customers solve, uh, their net problems with these products. Now Scott, you mentioned something about changing the interface.
So it's top versus uh, side. I mean I don't see that in the drive here. Well, Uh, so if the server's inserted in a rack right?
You call it a front loaded drive, right? But if the server's vertical, it's now a top loaded drive. Well it's the same.
It's semantic. I gotcha. It was part of a fun conversation.
There's a video I can send you that lead to of that that's, but we were discussing is it really front loaded now because it's coming out of the top, but no, it, it is effectively the same architecture for our cage. Right? But even in a liquid cold environment, the cage is 100% sealed around the drives and it kind of has its own little baby ecosystem.
But we, we have to work with them to build the slots for the drives to allow the fluid around it. So we go from making sure air can flow, getting it as tight as we can with liquid coplay and then we open it back up again. Mm-hmm And then making it stay effective for the different uses of the drives.
So as you can see E one s and this thing, we've done the U twos as well. Um, but it's all about helping our customers figure out how to play well with these products and these ecosystems. So customer innovation, there's this wonderful thing called AI and the AI factory and we started talking to a whole bunch of our customers and we were like, so I can give you a drive.
Where are you gonna put it? Whatcha gonna do with it? We want help you.
And they're like, well we like the help you part, we're not sure where to put it 'cause we don't actually have one either because nobody can get 'em 'cause they're all getting deployed by a neo cloud here, this, that or the other thing. Mm-hmm. So soy built the soy AI central lab.
We actually went out, acquired a whole bunch of architectures, footprints, partner platforms and we've built an independent lab that can allow customers to remote in and test our architecture because lack of infrastructure, we fix that problem. High cost of a lab, we're taking on that burden limited real world storage data generated on these tools in our environment. It's remote to you, it's secure.
We've got all those data sovereignty problems solved and then we can help you work on how to optimize it If you want us to play nice with you, if you just wanna play with it, let us know how you wanna work together. And so the first version of the lab, um, looks something like this. So we've got E three two petabytes in granite rapid servers.
We've got four J BFS full of 122 terabyte drives. And we've got another petabyte in storage servers the whole north, south, east, west. This is built, this shows all the hoppers and the B two hundreds, H two hundreds that we have.
We've got Grace, uh, Blackwells coming in and we are, we will be getting the Vera Rubbin platforms as well to put into this lab. So it's an ever evolving ecosystem and that's why it says quote exciting new infrastructure updates. So this lab has the ability to create whatever architecture you want.
You wanna play with performance drives in a storage server. I've got 'em in my E three S platform. You wanna play with my 1 22 drives and you want two petabytes of storage to play with but you don't wanna buy it and I really don't wanna ship it to you for free.
Guess what? I can let you remote into it here in the AL lab. So we've actually got a wait list right now of partners that want to come in and do work in this lab on these infrastructures.
And we found out that some of our partners have even wanted to deliver their hardware solution that taps into this to go in the labs so that we can actually do it real time in our lab that way as well. We've, we've changed the game on the concept of sampling a customer. 'cause sending drives out to everybody is always a lot of fun.
People like to see the real product and sometimes do those direct compares. But a one-to-one never really helps sell the value of a solid day drive. It never has.
Maybe in a laptop environment sure, send them OneDrive, but in a server environment you need to send a rack of data to make it work. And this is a way that we solve that problem is give you direct access remote in, load your tools up, we'll help you design, develop around it. We actually partnered with a Neo Cloud Phar GPU and run pod to help us run it.
So it's not just us, we're not doing it in a vacuum. We're playing with the proper players in the ecosystem to drive this lab environment. Just because you have so many customers who are generating 120 terabytes of data every day.
It Will, they're generating lots and lots of data and I don't wanna ship drives that I can sell for no good reason either. If you'll, 'cause again, you can't sample one or two and make it work for an AI software solution involvement. It seems to me that you could actually generate some data to fill this up by just having Q chat JPTs talk to each other.
Uh, we've we've played around with that actually. Yes. Uh, our, our good friend, uh, John Michael Hands has done a lot of work with his lab environment and playing with different ways to utilize it and we're using a lot of some of those resources actually when they're not active with customers.
We're using them internally due to exactly what you're talking about, optimizing even internal soy systems using stuff from our own AI lab. So drinking our own Kool-Aid. Um, so when we were here, uh, last time we introduced our friends from Metro AI and we talked about a little demo that we put up about how to do rag offload and that's the 65% lower um, DRAM with no performance loss that we talked about.
And that white paper is out on our website. We can get you the link for that if you're interested. Phase two of that was introduced at Super Compute and will be published very shortly.
But with the whole KV cash environment, we started looking at it again before the CES announcement. We were already like, ha, cash is something we gotta play with. We gotta understand it how it works.
It's been slightly redefined and we'll get into that in this next little section. But we already have been able with this AI lab working with Metro in this environment showcase that we can get 27 times faster time to first token because we're using offloaded KV cash to our SSDs to help solve the problem. So we basically have pre-pro what was announced by what's coming soon in the Vera Rubbin platform using the existing architectures.
So that time to first token, those really big karabots that you have, we've already been able to validate because of the access of this lab to the data sets, to the infrastructure and to those architectures, You seem to be getting to be getting more and more involved in the system functionality rather than just plain storage. We are, we are a, we're storage for AI and to be able to be storage for ai, we have to know how people use it. That's been one of the biggest gaps in a lot of the storage interactions.
And one reason we bring a software partner to an event like this is it is about making sure you know how your product's being used. I can throw a FIO test at something, I can throw a customer test at something that's not real world data. Yeah.
And if anything it helps improve my next generation product. 'cause I can tweak my designs, I can tweak how I do the over provisioning, how many flash channels I have, how I utilize the DRAM in the drive because I know how the customers are actually using the product. KB cache is a lot different than having tweaking, you know, over provisioning and numbered channels and things of that nature.
Yeah, it's a scale thing. Right? Exactly.
So that's, that's what we focus on. We, most of our current customer base is scale customer, whether it's hyperscale, neo cloud partners, all that kind of stuff. It's about how we can scale our product most effectively.
So.