Techstrong TV February 16, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. Welcome to back here to Techstrong tv. You know, as I was saying before, in the Green room, before we got on here versus the Green Ball that I used behind us in the studio, Brian Dawson has been doing videos on Techstrong.
com. Yeah. And I'm happy to have him back.
He's wor a lot of hats over the year. He will tell you all about it. But let's welcome my friend Brian Dawson to Techron back to Techstrong tv.
Brian, it's good to see you. How are you man, Alan, good to see you as well. Looking good.
It's, it's been a bit, but, uh, but yeah, always in a minute good to see you. com. Been great, um, to see Techstrong grow to what it is today.
I mean, it's 12 years. 12 years ago. Yeah.
Yeah. Actually next month will be 12 years. So crazy.
Yeah. And Brian, I wanna be you when I grow up. Alan, I was Gonna say, you've done a great job.
Well, you don't wanna be me. You be, be the best Brian Dawson. You can, and that'll be enough of this world, my friend.
Okay, sir. Um, Brian, give people, you know, I, I said you've been around and, and we've know each other a long time, but give people a sense of kind of your career arc and kind of things you've done. Things You've done.
Yeah, I would love to share because I think it's, it's somewhat been atypical, but I have a lot of pride in it. Um, so, you know, I frankly, uh, started my career, uh, deciding I wanted to become a computer programmer so that I can, uh, build video games. I was able to be, uh, one of the first 100 people at Sony, uh, PlayStation or Sony Computer Entertainment of America.
And, uh, and, um, you know, that gave me, um, a great chance to learn about how you enable smart developers and smart teams to deliver technology, literally from start to finish. I had the benefit of then, um, moving forward and, uh, building out our tools and technology program for Sony Worldwide Studios, um, which led me to open source, uh, and developer tooling. And then from there, most of my career has been focused on kind of that underlying, um, substrate, um, that enables technology delivery, um, but then also with a particular focus on, on open source inner source reuse.
Um, and, you know, how do we efficiently sort of, um, capture the power of community to help us deliver software, uh, better, faster. And, uh, now we'll talk about more secure. Excellent.
Love it. So, as I think people see under your name here on the screen, you're the director of Product Management for Linux at CIQ. Tell us, well, let's start with, tell us about CIQ there, IP people out here who are not familiar with them.
And then tell us about, you know, what your role is here now, uh, with this title. Okay, great, great. And actually I'll segue from before I saw a, a fantastic fit or opportunity to come, um, join, um, CIQ 'cause CIQ, uh, is not only, uh, built on open source, and I'll tell that history in a minute.
Uh, they are focused on, on emerging and leading edge technology, starting with an HPC background and now sort of reframing and, and revolutionizing Linux. So when I had an opportunity to come here, uh, about a year ago, um, I jumped on now to tell you a bit about CIQ, really cool story. Uh, so our CEO and founder Greg Kurtzer, who I know you've had conversations with, is one of the co-founders of Cintas Lenox, uh, which were those that don't know, eventually went under Red Hat.
Um, and while he was, uh, prior to and while he was founding Lenox, uh, he was building out performant compute infrastructure, uh, for high performance computing for our national labs. You know, the systems that power, uh, our cancer research, our simulations, our our weapons armory, um, and really what a lot of people are trying to adopt with ai, um, today, um, after building that out and, um, delivering some, I think, really impactful open source technologies like, like Tainer, uh, uh, werewolf, um, uh, he founded CIQ and CIQ has a focus on delivering modern infrastructure for the gener for the generation of AI or the AI generation. And, you know, we believe that, um, both with, um, building widely adopted, um, um, um, open source platforms like Linux, as well as being able to scale high performance computing, uh, and real production environments that we're, we're in a situation where we have the skills, knowledge and experience, um, to build the modern infrastructure that people need for the next age of compute.
You know, there's another interesting story as we get, um, to Linux where I think we'll drill in. Um, you know, IBM bought Cintas. Um, Cintas was really kind of, uh, the developer's real.
It allowed you to learn, uh, enterprise Linux. It allowed you to deploy enterprise Linux in your dev and test environments without, um, high cost. Um, eventually Cintas was sort of shut down and move upstream as Linux sort of, its testing bed.
Um, so developers lost their, their, their dev stage environment, their testing, ground learning ground. I think within a week of that happening, um, Greg, uh, went to, uh, the channels and said, Hey, um, let's start a new s Immediately people responded, they named it Rocky and owed to one of his co-founders who is no longer with us. Uh, and, uh, and so that's CIQ and that brings me here with CIQ, um, today.
Um, uh, I will add as to kind of, uh, lean in. One of the thesis we have here at CIQ is that, uh, while Lennox is widely adopted, uh, general purpose Linux, um, takes significant full-time engineer hours risk and iteration to tune for the purpose workloads like security, like container hosts like ai. And, uh, we believe it's our responsibility and contribution to the industry and the Linux community to sort of build workload specific variants that close out at least 80% of that gap.
Um, so that people just have to finish off the bespoke 20%. You know, it's funny, uh, 19 98, 99, I'm helping build a company an early a SP called inter reliant. We went public in I think 2000.
Um, and, and we learned that lesson in the a SP world. Hmm, Interesting. P 25 years ago, that's the a SP World Application Service provider.
Yep. And, uh, that out of the box complex applications at best can do 80%. Right.
You, you always need to fine tune the 20%. Yeah. And it, here we are 25 years later, hasn't changed.
We're talking the same thing. Yeah, same thing. I mean, even in SaaS, right?
Salesforce, Yeah. SaaS is the same thing. Yeah.
Yeah. You think you're just gonna log in and you're good to go. Right?
What do you think all those Salesforce consultants are doing? But, you know, all, you know, all that aside, Brian Rocky Linux has made a name for itself as a secure, a hardened colonel, if you will, a hardened, uh, Linux os. Um, and in today's world, you know, where the attack surface is multiplying, you know, every day with ai and now all of that, that, that it brings, uh, what a, what a good type to have a hardening, you know, a really hardened OS here and a, and a and a, not only just the OS itself, but the, the package is the whole process around it that you can, you know, have something you trust it.
6 came out Yes. Within a couple days it found 600 vulnerabilities Opus Code for decades. Right.
Some existed for decades. Yes. If that's not enough to scare your pants off what is Right.
Right. I mean, it's enough to keep you up at night and, and just I imagine that makes a good, you know, it's a good reason to take a look at Rocky. Yeah.
Yeah. Well, and you know, to, to tell you a bit our, about our relationship to Rocky, to, to set the stage is so, um, Rocky is downstream of RL, right? It is free and open source run by the Rocky Enterprise Software Foundation.
Yes. Or, or RESF. And, um, what that does is that gives sort of enterprise Linux stability and base security that people can access for free.
Right. Replace the Cintas. Um, now what what we found is that, um, still to take that and harden it, and for many people, harden means compliant.
It means I, I configure SE Linux. I, um, I run some open scap, uh, playbooks like disa, STIG, or, uh, or NIST 800 dash 1 71 acronym soup. Right.
To kind of harden my system to be compliant and pass audits. Right. Um, so we did realize that people need help with that.
'cause that in itself Yes. Is important and takes a lot of time. Right.
But as you said, Alan, um, I think the statistic is, uh, uh, most, uh, software applications use something like 200 open source components. Um, there are roughly, uh, estimates of, uh, you know, in the area of 40 new, um, um, vulnerabilities be being discovered across the whole open source ecosystem every day. Um, and the time to remediate those takes anywhere from 47 days to a hundred plus days.
In some cases, like for some of our FRO entities, you never patch a remediate this, right? So now we enter the discussion of proactive hardening, right? We take Rocky, we give you your compliance check box, but, but your Claude Opus story is a perfect example.
There are CVEs that haven't been, that will be C vs. That haven not been identified or, or exposed yet. How do you protect yourself against those?
Right. And that is it right there, right. In a world where, you know, there's a clawed opus every day.
Right. Or someone's, and, and it's not just the good guys that are going to use it, you know, thank God it's the good guys that found these 600 vulnerabilities, but the bad guys are using it too. Yeah.
Well, and they'd be better. Yeah. 3 codex yet, but I was just reading news that OpenAI is, uh, uh, safety Commission in California, I believe it is, feels they may be in violation of AI safety laws because they're the first ones to publicly release a model that has a high level risk because it is good enough that it can be easily used by bad actors to exploit systems.
Right. So, on that note, I just saw a flash come across my screen earlier that Anthropic announced something about that anthro, that Claude can be used for heinous crimes or something to that nature, which sounds similar to what you are talking about. Yeah.
Yeah. And, um, look, they probably all can, Brian, I mean, you know, this is, but when did people ever stop for security? It's full speed ahead here and the securities we're gonna have to play catch up as we always do.
Yeah. And I think, you know, what you highlight, um, and I'm just preparing a couple of, uh, sort of things, numbers, the numbers I wanna cite. But you highlight a key thing about, um, uh, what is sweeping over technology, especially in this ai, right?
Is the technology sector in the technology space at this point is dictated by speed, who can move the fastest, right? But what we are not necessarily doing and have not figured out is, um, how can we move faster in identifying security threats, protecting ourselves against those, um, um, so we can stay ahead of the bad guys, right? So how do we balance this fact that we have this wide attack surface, the attack rate is increasing at astounding rates.
We're being told we need to ship yesterday, so we don't have the privilege to sit down and button down all of the hatches. Well, you know, what we believe, um, uh, we you need to do is you need to practice what we call proactive hard. And we no longer can, um, deploy a system and then sit and wait for alerts to bomb us and tell us that there's a potential risk.
Go out, evaluate that risk, analyze where it lives across our infrastructure, and then stop everything to go patch it, right? Um, what we need to be able to do is know that when we install this foundational piece of our infrastructure, that thing that lays beneath, beneath, um, um, our hardware, our compute, and the rest of our workloads, we need some level of assurance or protection that if somebody gets in, they're going to be stopped. And so that's what we're building with Rocky Linox, uh, from CIQ hard, this could have been a, um, uh, honestly, say Al Al and us having known us each other for a while, uh, I think this is gonna turn out to be one of my prouder moments of my career being able to be part of the team that delivered this.
You know, what, we're gonna come back to this day sometime in the future, hopefully. Yes, Brian. And you'll say, Hey, I told you I did.
I would and I did. Right? So I, I hope that happens.
You know, what, we're, we're running a little low on time, but for people who wanna get more information about CIQ maybe even information about Rocky, I realize, you know, it's different. But where, where, where can we send people to get smarter, Brian? com.
Um, and, uh, and, uh, you know, everybody go take a look at our resources and blogs in particular around some key vulnerabilities and how they're mitigated. Uh, if you're interested in rocking Linux from CIQ hardened and ensuring that you are protected against unknown vulnerabilities in zero days, um, or you just need to become compliant, um, uh, reach out, hit the contact us, uh, and, and let's have a conversation. I, I do, Alan, before I get the hook, I, I wanna call out as an example here.
There's a number of vulnerabilities. One that recently in 2025, I think it hit around, uh, April, may of last year, was publicly disclosed as something called BPF Door. And many of us in the sector probably heard about the SK Telecom brief breach.
Um, there was a vulnerability that lived in SK telecoms systems for five years, undetected, where that thing lived and stayed. Resident was in the kernel, and it was able to sort of activate when needed for BPF door, inspect that PA packet traffic, um, and take actions. Um, we did some investigations, we did some tests.
I have 'em running on my system now. And this is a case where if, uh, five years ago, SK Telecom had installed the Lennox Kernel runtime guard that our own solar designer builds into Rocky Lenox from CIQ hardened, chances are they never would've been affected by, uh, BPF Door. And, and just to drive home the importance of that, not only was a bunch of personally identifiable information compromised, um, estimates for what that cost was for Estee Telecom are somewhere between $610 million and close to $900 million, um, just for that single breach of them.
So, So there's value here. Agreed. Agreed.
Brian, Hey, man, it's great to have you back on here. Come back and visit us again soon. Keep us posted, okay?
Okay. Thank you, Alan. It was great to see you again.
Great to see you. Brian Dawson, director of Product Management Linux at CIQ talking about you. If you're looking for real hard and systems, especially hard and Rocky Linux system, CIQ is a good place to go, check it out.
com. Brian, we'll see you soon. That's it for Techstrong tv.
We'll be back with more in a minute. Hello And welcome to the latest edition of the digital CXO Leadership Insight series. I'm your host, Mike Fazar.
Today we're with Loon Wang, who's the CEO of QDX technologies, and we're having a chat about how quantum computing will be applied to chemistry. 'cause well, it might be one of the killer apps out there for it. Hey, lo, welcome to show.
Thanks for having me, Mike. So, I think people, you know, at least they're aware of quantum computing. I don't think most people truly understand how it works, but there are a lot of use cases that have historically been intractable for conventional computing, including the infamous, uh, Schrodinger's cats and associated equations.
Correct. Um, so from your perspective though, what's exciting here? What are you looking forward to and, and what can we do today versus maybe tomorrow?
Yeah. Um, I think like it's important to understand that quantum computing basically has sort of like two ways of thinking about it. There's using these new quantum computers that are getting built to try and do computing in a, in a fundamentally new way.
And then there's like using conventional computers, classical machines that we've had for decades to try and predict quantum phenomena. And they're sort of like two sides of the same coin. Right.
I like to frame it as either you use quantum phenomena to try and do computing, or you use computing to try and predict quantum phenomena. Um, I think today we are yet to see, um, large scale applications of quantum computing, so like using these phenomena to, to do computing. But what we're increasingly seeing that we're capable of doing, um, and sort of what we're focused on as a company is how do you use conventional computers to do a lot of the things that we thought we would need quantum computers to do?
But it turns out we actually don't. And it turns out that you can make qu uh, you can make conventional computers fast enough that you can still solve many of these challenges. Hmm.
Well, how do you achieve that? Exactly, because a lot of folks have at least been convinced that we need, you know, massive data centers to run quantum computers. And, uh, we may not see the benefits of these things at the end of the decade.
And you seem to be saying we can do a lot with what we already have. Yeah, I think, um, what it requires is, going back to the drawing board a little bit, with some of the algorithms that have existed for, you know, decades. Uh, I think we're approaching the hundredth, uh, anniversary of Schrodinger publishing his equation, uh, and thinking about how to rewrite them and redesign them for modern computers.
A lot of these algorithms would've been written well before the burst of, you know, the GPU industry. And right now that's going, you know, like crazy because of ai. And there's a lot of these massively parallel accelerated pieces of hardware that you can actually take advantage of, um, and upgrade all of the old algorithms that we used to use.
Uh, and that's kind of at a very high level how one unlocks a lot of these use cases that, you know, we thought we might need quantum computers for. There's still a whole section of problems that you definitely need quantum computers for, but in chemistry at least, there's a lot of things that look, start to look like they're, they're attractable either now or in the next couple of years. A lot of those algorithms, to your point, were written, I don't know, as far back sometimes as the 1950s, um, who's gonna go in and kinda rewrite those algorithms.
Is that something that you guys are doing or is that something a community of researchers needs to do? Or how does it come about? Um, it's a mix of both.
I mean, there's lots of different people trying to do this, but it is one of the things that our company has done. Um, and so the way that we were able to get the kinds of speed up that we have been able to get was by going, you know, going back to the drawing board and rebuilding all of this technology essentially from scratch for the modern era. Are there things that you expect the chemistry sector to be able to do with conventional computers, either in the next few months or years that, you know, people would be amazed by what's, what's on your to-do list?
One of the things that, um, is particularly exciting for quantum chemistry is the ability to look at reactions. So typically, you know, if we could, we probably would simulate everything quantum mechanically. The only reason that we don't is it's like intractably hard, uh, requires a huge amount of compute power.
But as you start making your computers better, and as you start making algorithms that are far more efficient at leveraging these new computers, you do unlock a lot of these capabilities that maybe even a couple years ago, we would've thought we couldn't, couldn't achieve. So one of the ones that categorically is really interesting is like chemical reactions. So how do you model chemical reactions?
And when you're using quantum techniques to do this, typically we focused on really small systems, really simple, well simple in terms of like how long it takes and, and, um, how many atoms we're looking at. What we're starting to be able to do now is look at chemical reactions that involve entire proteins. So you're looking at like enzymes or cobell lump binders, things that, you know, involve tens of thousands of atoms, 20,000 atoms plus, uh, and you can run that whole calculation quantum mechanically.
And that's just something that, you know, wouldn't have been possible even a couple of years ago. Well, this kinda drive innovations downstream because, well, let's take for example, healthcare. There is a lot of research dependent upon what's going on in the chemistry world.
So, um, is this bigger than just the fact that I can track some interactions, uh, for chemicals? It just has implications for all kinds of things downstream. That's exactly right.
I mean, at the end of the day, drugs are just chemicals interacting with proteins in your body. And so if you can super accurately simulate the interactions between those chemicals and, and various proteins of interest, then you can massively improve the way that we drew drug, do drug discovery. Not only can you make, um, the existing types of drugs that we're trying to develop easier to develop, cheaper to develop faster to develop, you can also start thinking about building new types of drugs that traditionally have been, uh, sort of avoided because of how complex they are to make and how complex they are to get right.
But if you can model the chemistry really well, then suddenly these types of modalities become much less scary. Um, and you also pave the way for just a lot of like maybe basic infrastructure. So one of the challenges that that can occur in the space is when you design a, a interesting drug or an interesting compound that you think might be effective, there's this follow on question of how do I make this thing, what's the series of chemical reactions that I need to do to bring this design into the world physically?
Um, and that's kind of an unsolved problem in computing right now. You know, give me a compound and I'll tell you exactly what series of, uh, reactions you need to do to make it. That's, that's not something that computers can do presently, but it's absolutely something that you can do with quantum chemistry.
How do you perceive AI today? And within that context? 'cause some people sometimes talk about AI and quantum as if they're two completely different things.
But I wonder if as we go forward, are we just gonna wind up seeing these two things kind of meld together in a way that, um, gives us some greater outcome because one makes the other more accessible? I mean, that's exactly right. So, um, we're already seeing these two things come together in our company today where, uh, on one hand you can use artificial intelligence systems to make quantum chemistry more approachable to the average person, right?
Right. Now you have to be not just a computational chemist, but a very specific type of computational chemist to have a chance of correctly using quantum chemistry technology. But with the advent of LLMs, um, we're seeing it's increasingly possible to have these AI systems design their own algorithms or to be more approachable to computational chemists as opposed to specialized quantum computational chemists or even medicinal chemists instead of computational chemists.
And so the more that you can broaden access to the technology, the more that technology is gonna proliferate, and the more of those sort of problems that quantum chemistry is useful for, uh, will be, will be solved. And then secondly, um, it's becoming, you know, pretty common to use AI systems to do design in like most spaces, whether that's drug design, material sciences, et cetera. And at the end of the day, the artificial intelligence puts forward the design and it needs feedback on how good that design is.
If you don't have super high accuracy simulations, your only option is to go into the lab, make the thing, test the thing, and give that data back to the ai. And that's a really slow loop 'cause it takes weeks to, to do that. Um, and you'd like your AI ideally to iterate hundreds, if not thousands of times on its own designs.
But if you have simulations that are sufficiently accurate and sufficiently fast, then you don't need to go to the lab straight away. You can do several iterations with the ai, you know, purely on a machine before going into the lab and spot checking your work. Um, and if you want things that are sort of, if you, if you wanna be able to do that, you need simulations that are super accurate and super fast.
And at the end of the day, the, the best thing there is is quantum chemistry. Where is the funding for this coming from? Because, you know, we see massive amounts of dollars being poured into AI, and we'll see massive amounts of money lining up to be poured into quantum.
But, um, are people looking at quantum chemistry and, and, and kind of equating the two, or does it kind of fall between the two sometimes and, uh, and, and everybody else thinks somebody else is gonna do something about it? I think it integrates nicely with the two. There's a lot of complementarity between sort of the, the typical approach to quantum computing and how you accelerate quantum chemistry methods.
And there's a, a lot of overlap between how you use artificial intelligence to sufficiently advance and accelerate these quantum chemistry methods. But it is sort of like this in-between stage. And I would say it's sort of like an emerging field.
There are certainly not, you know, VCs that are specialized in quantum chemistry, whereas there are VCs that, um, you know, specialized in ai, for example. Um, but I think like the deep tech investors typically have a really broad, uh, range of capabilities, uh, and are typically able to get their heads around this kind of technology, uh, and see the value in it. What would you like to see organizations do to help us get to this goal?
Is there something that the federal government should be doing, or is there something that research labs should be doing? What's kind of missing from your perspective? I think the change in the scale at which you can use quantum chemistry has changed really rapidly over the last even two to three years.
And I think a lot of people haven't caught up with that. And when they think about using quantum chemistry, they still think in a framework of five to 10 years ago where they say, okay, well we can do quantum chemistry, but it's really restricted. We can only look at systems of, you know, that are very small of a very small timeframe.
Um, so even though we get really accurate answers, we can't look at really big systems that are, that are interesting to us. Um, and I think people just need to sort of look around and realize that that's actually not true anymore. And if you wanted to do thousands of quantum chemistry calculations on protein size systems, you know, that's something that is actually possible today cheaply and and efficiently.
Um, mm-hmm. And the kinds of research that you might do, the kinds of experiments that you might run dramatically change when you sort of reach that sort of thousand fold scale up, uh, things become sort of quantitatively different and take on a an entirely new quality. Are there things that you're hoping that maybe we will solve or issues that we've been unable to kind of wrap our heads around, whether it's, I don't know, some sort of disease that we can't really understand yet, or some interaction between, I don't know, energy and humanity and the planet, but what things do you think might get solved in the next half or decade or so?
Because we're investing in quantum chemistry, I'm really interested in two problems. Um, one that I know a lot more about and one that I know a lot less about. Um, the one that I know a lot less about is plasma facing materials.
A lot of really complex quantum chemistry calculations at a, require a very, very high level of theory in order to design the kinds of materials that you can use in modern and emerging fusion reactors. Um, and that I think would be, you know, I, I think the idea of helping advance materials in the direction of, of new types of energy is just incredibly important for humanity. Um, the other area that I'm really excited by is simulating something called the SIP family of enzymes.
So it's this sort of series of enzymes that are in your liver, and they're responsible for metabolizing 80 to 90% of all the drugs that we produce. Um, but because that metabolic process is a really complicated chemical reaction are probably one of the most complex chemical reactions that happens in your body, no one has ever simulated this thing end to end. So there's very little information on how it actually works on any given drug.
Uh, and it's very common to see toxicity show up in the clinic when you put a compound into humans for the first time. That is a consequence of us not really understanding how the SIP enzyme was going to interact with that drug. And I think in the next year or two, we'll be able to simulate enzymes like that and completely change how med chemists think about toxicity.
So what's that one thing you kinda see us doing today that makes you shake your head a little bit going and say, you know, folks, maybe we're paying too much attention to that, not enough to this. And, you know, is there something we should be doing in at the university level now to kind of change everybody's mindsets? That's a really good question.
I think hitting the same benchmarks over and over again. So what's pretty common in this space is that you have a series of benchmarks that so sit there for many years and people develop algorithms against those benchmarks and try to retrospectively prove that their technique has some predictive power. Um, something that the AI space is doing really well right now compared to, you know, other areas, is they're constantly updating these benchmarks.
It feels like every month, every other month there's some new benchmark that people are trying to produce that better captures the idiosyncrasies of something that's super intelligent. That just doesn't happen in the chemistry space. Um, the, the rate at which we release new benchmarks to try ourselves against, uh, and the relevancy of those benchmarks to the problems that people actually care about, uh, in the world, such as drug discovery or material sciences.
There, there is correlation there, but it's not as good as you would want. And I think a lot more effort goes into trying to beat these benchmarks than goes into trying to build good benchmarks that are worth beating. Uh, and I think that's probably something we could afford to pay more attention to.
Um, at the researcher level. Folks, you heard it here. We think quantum computing is cool, but maybe quantum chemistry is even cooler still, because, well, we're talking about the building blocks of life at the end of the day.
Hey, lo, thanks for being on the show. Thanks so much, Mike. All right.
And thank you all for watching the latest episode of the digital CXO Leadership Inside series. You can find this episode and others on our website. We invite you, check all those out.
Until then, we'll see you next time. Hey everyone, it's Alan Shimel, founder, CEO here at Techron Group. Really happy to introduce this next session here for you.
In, in this, uh, session, we are gonna have a FU terms fu Fernando Montenegro, who is the analyst in the security cyberspace, speaking with Ryan Jones. Ryan is the partner, uh, partner director of product for power platform manage platform over at Microsoft. Great conversation with Ryan and Fernando.
Uh, Fernando's going to talk to Ryan as we explore how organizations can securely scale agentic apps, including power platforms, governance capabilities. This is gonna include managed environments, adaptive risk models, and lifecycle controls. Hopefully you'll get out of this video practical guidance for balancing innovation with compliance in an age of AI first development.
Let's listen in on Fernando and Ryan. Alan, thank you very much. So, and Fernando Montenegro, I am VP of security research o over at, uh, at Futurum, and I'm thrilled to be here with, uh, Ryan Jones to, to talk about the broader part, the broader topic of, uh, AI governance.
Ryan, wanna say a few words before we get started? Yeah, Thanks so much, Fernando. Uh, my name's Ryan.
I work on a number of the security governance and operational capabilities that we provide, not only to like our AI agents, but also that we provide to our low-code apps and automations that run on the, the power platform as well. Has you come across something more specific to AI risks or AI governance concerns that surface above and beyond the, the, the, the, this data sharing, the, the, the, sorry, data flow and, and, and sharing and others? You know, as we look at the maturity of agents, we see that they kind of go from being assistants that are completely directed by humans to still interactive agents where humans are dispatching tasks, but you know, the agent is completing them on behalf of the human.
And then we see kind of those fully autonomous agents. And I would say that that 10 to 20% is really more over on the end of the spectrum with those fully autonomous agents than it is with, you know, like my little assistant agent or something like that. And the types of things that we see at that end of the spectrum are things like, Hey, if I am collaborating with a set of agents, how do I understand what they are doing or what they are doing on my behalf?
The second scenario that we see is we're in the very early innings of, of ai. And so there are lots of cases where agents need help, where they sometimes get stuck. And so some of the things that we've been trying to add into our products and our offerings are things like within power apps, we have the agent feed where a human can see what all the agents are doing for them, and then within copilot studio, the request information action, which actually allows us to define an agent such that it can engage with humans as needed.
So What has been your, uh, your exposure experience? What kind of of considerations do you have in this topic of, of model drift and model security and and so on? Yeah, I think that, I mean, it's funny, we talked about how like what old, what's old is new again earlier, right?
Like Yep. We've had static tests that we perform against software for, for a long time. And what's interesting is seeing how that is evolving because models are less deterministic than, than, you know, traditional software.
We call it, you know, stochastic life, right? Um, and, and so as a part of that, you know, one of the capabilities that we've added to copilot studio is the ability to add tests and evaluations so that as our technology improves, as makers and builders go through and they modify what tools their agents can use, or what knowledge sources are used to ground those agents, those test cases, those evals can run and can return a result so that folks, as they are evolving, they know whether or not they're actually improving the quality of, of their agents. Because what we find is that the first day that an agent is shipped in an organization, this may sound negative, but that's gonna be the worst that that agent ever is.
Okay. It's only going to get better over time as folks refine the knowledge sources, as folks refine the tools as folks look at and improve the success rate across those evals over time. And so I think that those quality gates that we've had in software for a long time, we have those with AI as well.
Mm-hmm. I think also, you know, a lot of times an individual maker, they're gonna be the folks that are really interested in whether or not that agent really works well or not, while, you know, it is gonna take a bigger picture, look at things, right? They're gonna wanna understand in aggregate how are things looking, are they healthy or not?
And it could be that if they see an agent that's not performing well, but, you know, maybe just you and I use it, it probably doesn't care. But if I have an agent that 20,000 people use this month, it is gonna care. And so those same views that we provide to our makers to understand whether or not their agents are healthy, we provide those aggregated views for the admins as well.
In fact, uh, you know, had a large customer in the energy industry where someone built, um, built an agent and it was for them, and they shared it, and it kind of grew and grew and grew. Next thing they knew they had 10,000 people using it, they moved on to work on other things, right? It was able to see and observe, oh my gosh, this agent is critical to our business.
And so they took it over, they added it into their portfolio of applications that they managed. And the thing was, they saw it not as a burden, but rather as an opportunity because there's an application that's out there that delivers value to tens of thousands of people in the business every month. And their dev cost up to that point had been zero.
So it was a win-win for, for everybody. Once the technology security teams build the guardrails, right? Then it then the, the, the, the business users are free to, to go work on those use cases.
So what kind of advice, uh, do you think would, uh, would be applicable to those technology and security teams in terms of getting them ready to build or to, uh, to build those, those guardrails or, or to leverage what they have to, to implement those guardrails? I think enumerating the categories or the dimensions of risk is one of the first steps. There are huge categories of risk that these teams can eliminate through how they define policies.
And to be clear, I don't mean policies like a Word document, I mean policies that are codified in the power platform and copilot studio and these sorts of things. Sure. Organizations don't want a random person in their company to build a workflow that takes information from their core ERP system and pushes it to Twitter, right?
We have the controls that allow you to preclude that. What would you consider to be from a governance angle, uh, you mentioned, okay, let's not focus on use cases. What would be advice, uh, for, okay, let, let's move this forward, right?
Where, where typical things that you'll see people hate? Let's do this. I think the first thing that we see people do is they define like a, a zoned governance framework or a zoned governance approach, right?
They decide within their company or their organization, what does green, what does yellow, what does red look like? And then they go through and they define that using the tools that we, that we provide through the power platform and through called Pilot Studio. I think the second thing that we see folks do is that helps with kind of the supply side, right?
That sees to it that the technology is available and accessible for folks mm-hmm. Across the organization. But then there's this strong demand element.
Um, 'cause gosh, I was talking to another, uh, big company in the, the credit processing space a couple weeks ago, and they had this amazing, you know, governance framework set up, but they didn't do anything to stimulate demand, right? And so the next thing that we see is, you know, reaching out to the businesses not to harvest their use cases, but to help them implement their use cases. You know, things like hackathons, things like training, things where for the people that are interested and excited about transformation through technology, where they can roll up their sleeves and, and get into it, I mean, the number of apps and agents and automations that came out of those couple day training session and hackathons, it blows my mind ev every, every time I have the opportunity to, to participate in, in one of 'em.
Um, and it's fascinating because you see the passion of the people in the business. You see their ideas come to life. And then in many cases, that's the first step of a broader personal transformation and career journey where you have someone that's been in accounts receivable for the last two decades, and all of a sudden they realize, oh my gosh, like I can actually harness AI to completely change how this part of the business works.
And what you highlight here is super interesting because one of the things we talk about in the context of platforms is how, uh, you can have that network effect of you've already configured something in your environment for a particular use case, like I said, enterra groups for, for identity and how that can accelerate the, the, the time to value, if you will, within, uh, uh, AI development because hey, you, you, you're building on a foundation that, that you already built for your organization. So I think that's a really powerful message, right? And, and, and it, uh, it, it's something i I tie back to how do we help technology and security teams, uh, build that scaffolding so that those business users can go play with the, the, the, the on on those environments?
A thousand percent. And I think that in a lot of, you know, circumstances, it means, you know, standing on the shoulders of giants that came be ahead of us, right? Like, what, what organization today doesn't have entre deployed in one form or another for user and group management?
And so why wouldn't we use those grouping constructs as a foundational capability around which we build our security and governance frameworks, right? Like, it's already there, it already works. And I think that is one of the things that's a little bit differentiating around the, the offerings that, that we provide in the space because mm-hmm.
You know, I build an app, an agent, an automation from day zero, it's ra authenticated and authorized, right? Um, you know, another thing that we're seeing that's super common right now is as, as companies are trying to figure out how do they get these AI tools into the hands of people across the organization, and how does that center of excellence or that center of an enablement help people in the various business units upskill and, and drive transformation? One of the things that we're seeing is that our customers who already had a center of enablement or a center of excellence built out for low-code applications and automations, they're moving much, much faster when it comes to ag agentic transformation because a lot of the foundational governance concepts that you need to have in place their modality or client agnostic.
Um, and, and so that's, you know, I was talking with a financial services customer just yesterday, a big one, one of the G CFIs, and they were like, yeah, we have deployed, you know, this many thousands of agents over the course of the last, you know, month. And we would not have been able to do that if it wasn't for the fact that we already had this governance framework in place from what we've done over the course of the last five years with low-code. Well, I think that one of the areas that, uh, that we want people to be aware of, like, and we, we talk about in our research is that this evolution in models, right?
We shouldn't be, just like you said about the use cases, just like the use case conversation. You shouldn't be waiting for the use cases before you get started kind of thing. We shouldn't be waiting for a perfect model to solve, okay, once we have this model, this is how we're going to do this.
No, because these models are evolving, uh, constantly, right? And, uh, if you, if you architect your AI governance framework, right? You build in or you leverage the build in the, the monitoring capabilities to observe how a particular model is evolving, how a particular model is behaving.
So yes, it, it is a, a critical component like observing how these things are evolving. Well, and and it's interesting because I know that at times we've had discussions with some customers that are like, Hey, how do I control which version of the model is being used by this agent? And, you know, there are some places where we give customer those controls, but I will say like, I'm kind of hesitant about it because I can't tell you the last time I talked to a customer that was worried about what version of the T net framework or what version of Python I was using to deliver services to them.
And so I think it's a little bit interesting that folks are, are looking for that level of control with some of these models. And I think that if we zoom out and ask ourselves, you know, apply the good old five why's to why folks are looking for that, they wanna make sure that as new models are available, it doesn't cause functional regressions in their agents. And the thing is, like we were talking about earlier, that's quite literally why we have tests and evals, right?
And, and that's where, by the way, if for some reason, even though I don't think I've seen it practically speaking in the last year or so, if folks did see a regression as a result of a new model, awesome. At that point, yes, you want the control to, to go back to an older version, but we're not really seeing that in practice that much. So Yeah, no, and, and it's, uh, this speaks very, the this this talk track of, of multiple tools for your SaaS apps within, within the, the, the business environments.
It's something that, uh, it's a shared pain for security teams as well, because when we speak with security executives and, and, and, and they are teams, they are swiveling between, uh, uh, multiple tools on the environment as well. As a matter of fact, we're, we're, we're, we are working now on a, on a report on security platforms precisely on, uh, on that note. And, uh, one of the areas that that, that we are tracking is, uh, uh, AI for security, right?
In the context of how do the, the, the, the, the agents that are now being deployed within Sentinel, for example, right? Uh, are, are, are helping with, okay, let's, let's, let's do exactly what you're describing from a local no-code perspective. I know it's on the power platform, but we're seeing a similar thing on the security platforms as well.
And there, and there is tremendous interest in doing that, provided that yes, we've, we've handled the, the, the governance and, and risk constraints around those. So absolutely, this is a, this is a phenomenal time. The, the, the joke I make is that, uh, like, listen, you can wake up at six o'clock in the morning, go to bed at midnight, and, and this stuff keeps coming at you with, uh, with opportunities, right?
It's, uh, it's information to collect, it's, it's, uh, information to, to, to parse and opportunities to make improvements. Perhaps you can use agents to help you with that too, as you are thinking about how you're evolving the, the, the power platform. And what have you been looking to improve in terms of security and governance capabilities on the platform?
Where do you see the platform going in terms of one of the things that, uh, and this is more of a higher end use case, but we do see requests for regulatory compliance. Like remember when the internet was new and people started creating, like those blogs that talked about like what they ate for lunch or what their dog did that afternoon because they didn't know what else to do with it. I kind of, I kind of feel like we're in the same place right now with, with ai, and so I would definitely want to preface anything I say with these are early innings, and so I kind of don't know.
Okay. Okay. At the same time as we look at, you know, the types of regulations that are coming into play with the EU AI Act, you know mm-hmm.
Some such examples that we're seeing there are like, Hey, these particular types of data need to be handled in a particular way. And one of the things that we've started doing within copilot Studio is surfacing those data labels, those information protection labels in the response so that folks don't enter, um, inadvertently start working with sensitive data in a way that they don't intend to. Um, and I foresee that in the fullness of time, this will continue to grow.
Like one of the things that, that we're seeing is we have a capability in the platform today called Advisor. Um, an advisor constantly scans over the agents and the apps and the automations to make recommendations and kind of like a reactive governance or reactive security perspective, because we believe strongly in the principle of trust but verify. And one of the things that we're starting to see with advisor, and the, the way that it can iterate through, you know, like AI generated app and agent descriptions, is we can actually start to flag when some of these apps or agents may be getting too close to that boundary of what, you know, acceptable use policy within a company looks like.
And so there's definitely something interesting going there. So one of the areas that when we speak with security practitioners comes up a lot is they are balancing two very distinct problems. On one hand, they are absolutely swamped.
The other is we need to balance two things. On one hand. We want to use as much as possible of the broader tooling we already have the security platform conversation that, that, that, that we are observing, right?
That being said, there's still, uh, in many cases, particularly the more novel use cases, there is a need to work with third parties. What's been your experience navigating this, this, uh, platform and ecosystem, um, uh, scenario in, in the conversations you've had as people have been using your platform? Yeah, I think that what we try to do is we try to start from first and foremost providing, you know, those foundational security primitives that people need to, to be able to leverage these capabilities safely.
And that, that has to be native within the platform, right? Like, if I have to go find an authentication provider or find an authorization service or figure out my auditing and, you know, uh, those sorts of scenario, like that's a non-starter, right? And so we have to provide those capabilities from the get go across power platform and copilot studio.
I think the next layer above that is, if I think about the tools that someone in the CISOs organization is using on a daily basis, I'd love to think that they come to the power platform admin center every day, but I know that's not true, right? They're spending their time in, you know, defender experiences. They're spending their time in Sentinel experiences.
And so it's critically important that all of the telemetry, all of the audit logs and these sorts of things naturally flow into those systems because we have to meet those security professionals where they are. Sure. And then I think the, the final thing that we're seeing is there are some unique and novel risks in some cases with ai, right?
When we look at things like prompt injection and, you know, kind of the emerging product categories of like XDR for ai, does Microsoft have some solutions in that space with Defender? Yes. Is it also such a quickly evolving product category that we need to plug into the broader ecosystem?
Yes. And so, you know, the same extensibility hooks that we use for integrating with Defender are actually the exact same APIs that we allow partners like zenit to connect to so that they can provide additional defense in depth when it comes to particular risks like, like prompt injection. Ryan, this was a phenomenal conversation.
Thank you so much for the time. Hey, thank you so much for your time and for all the, all the awesome discussion. And you know, my hope is that folks, as they hear what we discuss today, they, they'll feel confident, they'll feel empowered that they have the capabilities needed to manage that security governance, operational availability risk, and that they'll be able to parlay that into, you know, accelerating how AI is able to transform their business and deliver outcomes for their employees as well as their customers can't wait to see what's next.
I think that, uh, as a, as a ponder on, on what we discussed a few things. First and foremost, this notion that you have been building a platform to begin with in terms of local no-code before, and then building the AI capabilities on top of that does give people the, the, the benefit of, of building on what they've already done. It does give the benefit of tying to the rest of their, uh, of, of their ecosystem.
And it's, uh, it's as much about the, the, the culture of let's try and get started and, and work on different types of, of use cases without trying to boil the ocean. We're going to build a capability that accommodate different use cases, uh, different levels of, of governance requirements, right? And then we're going to help those teams start to work on those, on those particular scenarios.
I, I, I look forward to seeing how the platform evolves and, and, and capabilities. This area never stops. I, I, one of the taglines I use is, there is never a dull day in this industry.
And that's the case here. The world of AI is changing the way that we see work being done, but is it also going to change the way that we do security for all of that new ai? Specifically around identity podcast, AI tooling is causing identity security issues.
Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from the members of the Tech Field Day delegate community, and is often associated with one of our events. Tech Field Day is a part of the Futurum Group, and this podcast is published on our sister company site at Techstrong tv.
On this episode, which is brought to you by One Password, we're going to be discussing AI and identity security. But before we get to that, I'd like to take a moment for our guest to introduce themselves so you know who you'll be listening to, starting with Kate. Hi, my name is Kate.
I've been in cybersecurity for over 20 years. I presently am a cheer person for the CD Foundation, um, cybersecurity Special Interest Group. I'm Jack Poller.
I am principal analyst with Paradigm Technica, covering the intersection of AI identity and data security. My name is Sanjay Ramnath. I'm the Vice President of Product and Solutions Marketing here at One Password.
I've spent a little over a couple, two decades in cybersecurity, having run product teams. And prior to that, um, I cut my teeth as an, uh, engineer writing code, uh, for chip design. Um, super excited to be here.
Alright, thank you all for joining us. Let's jump into the premise for today's episode. No doubt that you have already started to experiment with ai.
Maybe you are asking some simple questions of an LLM or you've graduated to more complicated topics like building your own agent to do things for you. But no matter what you do, you should keep security at the front of your mind because as we've seen in 2026, there have been a lot of challenges when it comes to security and not just from securing things, but the way that different security paradigms integrate with each other and quite honestly, make it difficult to know what's what. In this episode of the Tech Field Day podcast, AI tooling complicates identity security.
So I wanna kind of throw this out here because one of the things that we've seen as people have started adopting AI in their daily workflows, whether it's through testing or through adopting it to do their actual job, is that they sometimes forget that a lot of their AI build outs involve the person who's doing it. If you are an individual knowledge worker with a certain security posture, that limits the blast radius in case you do something you're not supposed to. Whereas if you are a senior system administrator and you have root access over servers and the agent has your same, uh, access capabilities, it might be able to cause more problems than you might otherwise think.
Why is it so complicated for us to understand how identity security translates over to this new world of ai? Well, Tom, I'll, I'll take a stab at that. That one of the big differences up until today, up until now, everything we've done in it has been premised on a user interacting as a, essentially a client server model.
A user talks to a compute set of computers and requests some action to be done. And that's a well understood, you know, we had 60 years of understanding that, started out with passwords, got figured out, passwords weren't secure, went to something more secure like MFA, et cetera. But it's all premised on that, that one behavior.
With the introduction of ai, particularly with AI agents operating on your behalf, the line gets blurred both about who, how an activity is initiated and who is initiating that activity, and that an activity is initiated by an entity on behalf of an actual user, or maybe not on behalf of an actual user, maybe on behalf of another entity. So now we have things that are of, that are happening in the background without our explicit, uh, activity, initiating an action. And it becomes very hard to chase is the agent doing something on its own, or is it doing something on behalf of somebody else?
And that the agent sponsors multiple agents, multiple agents, and it becomes very hard to chain all that activity going forward. So that, that part of it complicates things a lot. Yeah, and just to add to that, Tom, I I, I think that the, the fundamental shift that AI and agent AI brings to identity models is that it's not just a question of securing credentials or securing access or authenticating users anymore.
It's a question of securing trust, right? Uh, the future of work is not gonna be centralized. It's not gonna be static.
Um, you don't provision a user and identity and then authorize them to perform a set of actions over the lifetime of a session or, or a workflow. And, and those privileges remain, remain static, and, uh, and they carry that with them. Uh, agents operate very differently.
They're, uh, non-deterministic. Uh, they don't authenticate the same way as humans do. Um, and all of this is happening at machine scale.
So really in this new world, the question is about how do you secure trust? How do you trust what the agents do? How do you really know what agents are even running in your environment in the first place?
How do you authorize them to do just what they're allowed to do? And then make sure you control those authorization permissions, uh, on a continuous basis so you don't over provision, over privilege, over privilege these agents. Uh, and then ultimately, how do you audit and observe the behavior?
How do you explain the behavior? How do you create the right auditable, um, uh, events and and so on? And, and this is really what causes this fundamental shift in the identity security stack or identity security models, because, um, identity is not gonna stop just at login with, with AI and with agents.
It has to be, be evaluated every time access is used, and authority has, is exercised when the credentials are used, when secrets are used, not when the sessions are created. And you have to establish distrust when this access happens. So it's a fundamental change in how we think about the identity operating model.
I, I would agree with you, Sanjay, because one of the problems that we run into is people believe that if something is authorized or should be capable of performing a task, then it will always be able to perform that task and it will never change. And there'll never be anything that could potentially change the status quo, which anyone listening to this podcast is violently checking their head right now, because we've seen that being repeated over and over again in something as simple as the NPM mod model where we have, you know, these pluggable modules and packages out there, that one of them might be purchased by a third party that has ill intentions, but because we previously authorized that NPM to run on our system, oh, well, we should just trust it from here on out. We, the in, in effect, the asset's identity has changed, even if the name is still the same.
And that's one of the things that we have to remind everyone is if the same NPM is requesting the same resources over and over again, there's a reason to trust it. But as soon as it starts requesting things that it hasn't normally requested before, that should be an identity change. And, you know, when, think about any sci-fi movie you've ever watched, it's like suddenly if you start behaving weird, something's wrong.
And we, we need to figure out why have you been replaced by Agent Smith or something like that? And you're talking about moving to a behavior model as a, as right at the end of the day. And that really becomes important because machines are gonna behave differently than humans, and especially when they start accessing, you know, tokens and, and you know, is it persistent?
And so it's nice to hear that you guys are looking at the behavior. Yeah, that, that's correct. I, I think, I think looking at the behavior is one way of, of, of putting it, for sure.
Um, and it, it's not, it's not just the behavior, it's all the way from, um, lemme take a step back. The, the way I would, I would characterize the, the operating model in the agentic world is, um, you know, first you need to discover, you need to understand what ex exactly is happening on your network and your environment. Um, especially at the edge of the business because, um, you know, the, the agent ticket adoption will start at the end point.
It'll start with your developers adopting, uh, co-pilots to, to write code. Um, and, um, the first step is even knowing, okay, these are the agents that are actually running in the environment. Um, and then making sure that that visibility can be translated to the right guardrails and right go knowing what credentials those agents are using, knowing what permissions being, um, provisioned with, uh, to operate and the workflows they're integrated into.
So that's the second step is how do you secure the agents once you have discovered them and give them the right guardrails and the right permissions and broker the right set of credentials, um, in a scope manner, right? So they don't, are, again, not, not going rogue, uh, and doing things they're not supposed to do, or carrying forward permissions and privileges that are not supposed to have after the task is completed. Um, and then the third step is really being able to audit and being able to track behavior and being able to observe, uh, in, on a continuous basis, knowing what the agents are doing and being able to correct the governance posture policies based on the, the visibility and that, and observability.
So it's almost like a continuum of sorts. And you're right, behavior is at the core of, um, of the continuum. So something, something you said, uh, that you and Tom said sort of lead me, uh, around the concept of trust, and you brought up trust early on, Sanjay, and I think one of the things we're sort of dancing around is this concept of we used to understand the behavior of an application.
Tom's example was NPMs, right? A module that you've installed or you've installed, just a simple application that's gonna database queries. We understand it, it's well scoped, well understood.
So when you install that application, you can go ahead and look at it and say, I understand it, I can put guardrails around it, and if it steps out these guard steps outside the guardrails, I can then say something's wrong. Right? The science fiction characters gone crazy has hasn't been replaced, but advent AI behaves differently in that it doesn't have a well understood behavior profile because it's not limited in scope or actions, and it is non-deterministic.
So it's very hard early on to be, to put those types of guardrails on. So we wanna change that concept of putting guardrails around it. And, and also, you know, you talked a little bit about understanding visibility of what, what things are happening out there.
The, the world is now moving so fast and agents spawning other agents and creating their own task profiles that we can't keep up with it. We can't have pre, pre for, for knowledge and whitelist blacklist type environments to look at what agents are doing. So I think what we're saying is instead of trying to identify the agents, try to identify the users and the agents having an identity and being another form of a user and authorizing them for specific actions with limited scope at limited points in time, which is really sort of bringing that whole concept of zero trust in to apply that everywhere, starting with identities and whether it's AI and agents or other applications, we really have to get back to this concept of we have an entity that's trying to access data and take action based on that data.
And should it be allowed to do that or not? Regardless of what type of application, it's, it's really, is it authorized at this particular moment in time to do this activity? Yeah, that, that's correct.
I, I think the one, uh, maybe nuance I would add to that is the non-determinism or the non probabilistic nature of agents is also a superpower in a way, right? Because that's what you want agents to do. You want them to be adaptable, you want them to perform tasks based on, um, environments and, and conditions that they can learn from.
Um, and from a security standpoint, um, you know, from a, at least a one password ethos is really to help our, our customers, uh, safely embrace the future. Um, without looking at this more as a, hey, it's a, it's a threat, or it's, it's not a doom and gloom scenario, I think AI can be powerful if harness properly. Um, so really the question is how do security models evolve?
Um, how does the technology stack evolve so we can adapt the models, adapt the technology, adapt the way we configure policies and roles and provision identities and track behavior and things like that to this new world where you have agents operating, um, on behalf of humans, um, at machine scale, uh, and operating in that more adaptive, um, environment. So it's really about empowering the business to harness the power in a safe and secure manner as opposed to, um, managing the fear that, hey, you have rogue agents and swarms of agents that are just gonna, you know, go wild and, and do things they're not supposed to, uh, supposed to do. I, I think it's an important distinction.
It's a nuanced distinction, but, uh, the conversation should be one of enablement rather than one of fear. And I think it's important that you bring up this whole enablement versus fear discussion, because one of the problems that tends to grow out of this particular dichotomy is what happens when users meet friction in the real world. Because time and time again, we have seen users will tend to avoid the friction instead of trying to fix the problem, saying, oh, well, the reason why my efforts to do this aren't as good as anybody else's is because, you know, there's all these extra security controls in place, or you've mandated that we're gonna use this particular AI platform instead of that one, but I really prefer the one that's installed on my laptop.
You don't typically hear, let's, let's try to resolve this security policy, so that won't be a problem. Instead, what you usually see is, oh, well, I, I just did what I wanted to do anyway, and, and I went around it. And, and we've seen that happen quite a bit recently, where people are like, oh, well, I'm just gonna download this program and it's not corporate approved, but that's okay, I'm just gonna test it out.
And then a couple of days later, what you find out is that, you know, oh, well now it's, it's going out and it's requesting information on my behalf and doing all of these things. And the people that work in the corporate risk department are like, well, we shouldn't be doing this. This wasn't on the approved list.
How can organizations work together with their users to allow them to work at the speed they want to, while also continuing to protect the things that they know really shouldn't be uploaded to the public internet or introduced into these models that could potentially cause exposure later? Yeah, the, the, the term that comes to mind, um, Tom, uh, and we, we use it a lot and it's, it's part of our DA is that security should be about making the easy thing, the secure thing, right? So if, if you make the easy way of doing things, also the secure way of doing things, then naturally you have, uh, uh, alignment across, um, the security requirements and the business requirements.
And that's, it's not easy. It's, it's, it's, uh, I recognize as a security, um, a vendor that we always run into this friction where, um, security teams wanna to buy in, in, in, in, it's the right thing to do. You have to be paranoid if you're, because there is, uh, a lot of bad stuff out there.
Um, but what that ends up translating to is, um, a set of, of, of rules and policies and a model really that starts constraining business velocity. Uh, and when security starts constraining business velocity, the business almost always wins. Um, developers need to write and ship code faster, and you need to operate the business faster, especially in this world where, um, SaaS is the norm, um, browsers at the front door of work, um, people are allowed to use their own devices, um, on, on enterprise networks.
Um, so you need speed and you need to kind of maintain that, that competitive edge. So the challenge that security practitioners have is how do we make sure that we do this, um, in a secure way? How do we empower the business to move with velocity?
How do we empower developers to move velocity? How do we empower users to, um, find and adopt the tools they need to, to operate and do their best creative, innovative work, uh, but make sure there's the right set of guardrails around it. So, um, you know, moving security closer to the business, closer to the edge where work really happens, and this is massively amplified by ai, as you can, you can imagine, um, AI is all about empowering, um, users to, uh, create this parallel workforce of sorts that, that massively accelerates their ability to do productive work.
So now really the question for security is, um, you know, how do you, uh, how do you build the right framework to empower and enable the business to move with the velocity we call this business led? It. Um, and that's gonna really come from, uh, moving the controls, um, and the, um, to the happens the old model where everything was centralized, where your identity registries were centralized, your policies were centralized, your authentication systems happened in one place, and the users are only allowed to do what the centralized system allowed them to do, uh, is gone.
That's, that's not going to survive. It's, it's already broken with SA already, and with ai, it's gonna be obliterated to the point where you have to move the identity model, the security model, to a place where, um, the, the, the users are empowered, um, to, to do their best work. And your CIO and Cs CISO is empowered to say yes rather than say no.
That's the model of the future. So you're talking about velocity and speed and everything else, um, in order to not basically be the no, right, we don't want cybersecurity to always be the no. So how are you gonna for, for ci, cd and automation pipelines, which is, you know, something that I deal with, how do you prevent AI assisted pipelines from becoming these secret brokers?
Yeah. Yeah. So, so one of the, the, um, use cases that we've been helping customers with is, uh, managing, uh, developer secrets and, um, environment files and, and, uh, artifacts of that nature, um, and enabling them to utilize those credentials and secrets, um, in a secure manner.
Um, so an example is, um, today we have developers that use our enterprise vault, uh, to store, um, SSH Keys store, API keys store secrets and tokens and environment files, uh, in a way that makes it super easy to integrate into their ci cd pipelines, into their ID environments. We've also integrated into, uh, AI development environments now, like cursor and so on. So, uh, so that's an example where, um, using our vaulting capability and then having the, the guardrails that are built around, uh, our ability to, to provision those credentials and also govern how those credentials are used in development pipelines, we're able to enable developers to continue building with velocity, continue adopting the tools they need at the endpoints to build with velocity at the same time, provision secrets and keys and tokens and environment files, uh, and also share, uh, those types of artifacts in, in a very secure manner.
Does, does it, does that answer the question, Kate? Well, I think my, my, my one question though is, um, doesn't that then, aren't we then talking about static and then doesn't static then how do you cut off the access, like, you know, the whole thing with AI and, and security for the, for agents, isn't it important to only have like a time of use moving forward? Yes, Exactly.
So that, that's really where the policy framework around all of this will evolve. And that's, that's some of the ideas we're working on right now is around how do you provide scoped access to those credentials? And the scope could have multiple dimensions.
It could be time-based, it could be role-based, it could be based on the resources they're trying to access. It could be based on the environment it's working on. Um, so it's really a multidimensional problem when it comes to scoping credentials, access, and absolutely right.
Uh, that's gonna be a critical, uh, aspect of, uh, how we provision, uh, AI agents or agent development, uh, and not just development even, you know, a agents that are operating outside of developer environments. How do you provide them the right information and the credentials they need and the secrets they need in that scope matter? And I think if, if I remember correctly, um, one password, you have a a pretty nice user interface when it comes to governance, right?
And, and will that basically translate to AI agents? I mean, is that, I'm not saying it's easy for you guys, but is that gonna be something that you look at within the interface that you can easily identify the AI agents and the whole scope of work so that things are done within a single pool glass? That's correct.
Yeah, that's, that's correct. I, I, I think, um, you know, if, if you, if you step back in time and look at one password's history, um, we built, um, tools, um, for, for users, um, and there were secure tools, but ultimately it was all about making things easy for users, uh, to secure their digital identities and their digital lives. Uh, and that, uh, that thread will, you know, carry through everything that we build as we build tools for enterprise.
As we get into agent ai, um, that's a northstar that we hold ourselves to is let's make sure that this is super easy, not just for the administrators, not just from a control and a policy standpoint, but it should be super easy for, um, ultimately for the users to embrace it. Uh, no. An example there is, um, you know, one of the, the capabilities we have in our, in our identity stack is the ability to add device context, um, as a dimension, um, uh, of trust, right?
So when, when there's an access request, making sure that we govern that request, not just based on identity, um, or the resource being requested, but also make sure the device from where the request is made is compliant. Um, and, uh, when you find non-compliance, uh, you wanna make it easy for the user to remedy that. So we provide guidance, we provide, um, you know, a quick way for the user to self-correct that and get back on track without having to file an IT ticket and without having to wait for a few days for somebody to respond to it.
Uh, they just fix the problem and they move on. So those are the kind of of things that we would wanna carry on, um, through the agent AI workflows, through developer workflows, is to make it super easy, not just to identify where the security gaps exist, but also make sure that we provide enough information and context to the users themselves so they can, they can remediate and, and, and correct, at the same time, providing the administrators with the visibility they need to apply those guardrails and, and tune, tune the policy. So that balancing act is gonna be really important.
So Sanjay, one of, one of the things that you brought up a little bit earlier in the conversation was the, the world of centralized identity store is basically over. And it's funny because, you know, 2, 3, 4 years ago when I was talking about this, we would always talk about how we had many silos of identity, and that that's, that was a challenge, and the centralized tools were the solution to that challenge, right? Bring everything under one roof and then you can control it better.
And I think what you're saying, which I agree with, is that the modern way of working, particularly with AI and agent AI, is you and with developers, what Kate's talking about with the CSCD stack and needing to have access to so many different things simultaneously, programmatic access is you need to be able to have and work with silos of identity. And so you need to enable that type of framework instead of saying it doesn't work, bring everything under a central roof when you have, um, you know, anywhere from 40 times to a thousand times more non-human identities as human identities. And we probably get even more than that now.
It becomes untenable to try to have a central repository of all those identities as well as the associated secrets and API secrets and stuff like that. It's just not manageable in that fashion. So I think I'm very enamored with the one password approach was just saying, how do we enable silos of identity and how do we control access while still having silos of identity and enable that to become an enabler of the business rather than a blocker of the business?
Yeah, absolutely. I, I, I think there is, there is a place, um, for, uh, for the centralized control plane, if you, if you will, right? Uh, there are things that, that make sense to, to centralize.
For example, I think, uh, visibility is something that, that belongs in, in that centralized control plane. Um, auditability is something that belongs in that centralized control plane. But then when you think about, um, authorization and authentication and enforcement of policies and governance, those are some of the aspects that need to start moving outta that kind of centralized, siloed approach and start moving closer and closer to where the work actually happens, where the access requests are actually made.
So you can do this on a more continuous basis, as opposed to having a static set of policies that are enforced statically, uh, in a centralized manner, because that just breaks the entire model. Uh, you cannot do that in this, in this new world where you have, um, the actual actions are moving away from, from the center of the business and moving closer and closer to the users and the endpoints. And, and that's where work actually happens.
And then, don't we actually go back to the original, you know, these behavior indicators. I mean, isn't there definitely a difference between behavior, um, from a machine and how you can see it and how it can act and as opposed to a human? Yeah, no, absolutely.
And, and that's one of the, um, uh, things that I, I believe one password is in a, in a really good position to, um, uh, to act on because, um, we have, um, uh, a tremendous scale and presence on endpoints today. We started our journey as, uh, credentials vault as a, as a password manager. Uh, and that by definition is, uh, securing credentials for users or users securing their own credentials at the endpoint.
Um, and now if you translate that to what you just said, Kate, which is behavior, um, one of the important aspects of, of discovering and understanding behavior is knowing what's happening at the end point. You need signals. You need to know what your users are doing, what they're accessing, what credentials are being used, how they're being used, where they're being used, what they're being used for.
Um, and being able to get those signals, uh, is a very important part of, of, uh, building that kinda identity security continuum we talked about as we push it more and more to the edge of the business. Um, so spot on, right? Um, being able to get those different signals, identity, application usage and credential and device signals even, and then using those signals to build the identity model and applying that to the security model is gonna be really important going forward.
And I think we're, we're pretty well positioned to do that. And, and I, I totally agree with that. Um, and I think you guys are, and don't you then start to look at, um, time-based versus intent based?
Like, doesn't that come as a part of your conversation? Yes, yes. It'll, I mean, I think that's, uh, you know, going back to the, the question that you asked earlier about scoping and, and just in time provisioning, I think those are all components that, uh, we're gonna have to like, start looking at, um, as we build, build this model and build this framework.
Um, and it starts with getting signals. It starts with the presence at the endpoint. And then once we have that, and, and I believe we're kind of already there, um, we can build a, a, a number of different dimensions of scope and dimensions of, of control, if you will, around those signals.
And those could be intent based, this could be time-based, that could be environment based, it could be based on identity, it could be based on the resource that's being accessed. All those to factor in, you're absolutely right, intent and time would be important components of that. So as you can tell, the new world of AI tools have shifted the way that we think about doing work, but it shouldn't just do that.
It should shift the way that we think about security and the way that we look at our new digital coworkers and how they are going to be performing their roles. Because one of the things we don't want to do is let the business leave security behind in order to be more enabled, because that's how we end up having more issues to solve than we initially started with. And we need to have a good understanding of how all of those pieces come together so we can create the right policy, the right procedures, and the right protections in order to keep everyone safe and secure and doing things that they need to be doing.
This episode is brought to you by one password, and I know that one password has been working very hard on solving a lot of these challenges. Sanjay, if people wanna learn more about some of the solutions that you've come up with, where can they go to see that? com.
There is a wealth of information on our website. Um, if you're a developer, we also have a dedicated section on our website. It's developers, uh, uh, there's a bunch of tools for developers.
You can, um, uh, download the tools. You can, I can, I can try the, the vaulting capabilities. There's guides on integrating our tools within developer pipelines and so on.
So those are the two resources I would, I would start with. We've also published, um, some, some interesting thought provoking blog articles, uh, around AI and Agent AI problem. Uh, those would be good, uh, good readings as well.
So, um, so yeah, that's where I would, I would start. Alright, well thank you very much to everyone for listening to this episode of the Tech Field Day podcast. If you enjoyed this discussion, please do us a favor, subscribe on YouTube or in your favorite podcast application of choice.
So you don't miss this episode or any of our other ones. We'd also love it if you'd leave us a rating, a review, and possibly a comment on what you thought about this episode, because those all help our show grow. This podcast is brought to you by Tech Field Day, the home of IT experts from across the enterprise, which is a part of the Futureum Group.
com/podcast or check us out on Text Strong tv. Thank you very much for listening and we'll hope to see you next week. Hey everyone, welcome to our next session here at Predict 2026, what a day this has been.
We have, you know, we started things off with Daniel Newman this morning, giving us his kind of overview. And we have really, I think this might be the first time actually, we have seen a, toward the force of the Futurum analyst crew coming in here and each one of them giving us their view of what 2026 has in store in their particular areas of expertise. But as we got later in the day, I wanted to take a more strategic view of things.
And so who better than the Futurum chief strategy officer? Tiffany Bova. Tiffany, welcome and thanks for coming here to predict 2026.
Oh, Alan, you know, I'm glad that you have been so thrilled with my team. You know, I, I, they're just the best and I, and I'm thrilled to be here. Yeah.
You know, as I was saying, I really am. We, we have really, this has been a tour of force, right? We have looked at from marketplaces to end users and, and the computers they're using to security and software ai, of course.
'cause everything's ai. I mean, it's been, it's been a great day of learning of, of predictions, of, of analysis. And I, I think, I hope our audience has enjoyed it.
I'll also remind our audience, we do have a FUTUREUM booth set up within the virtual event experience where you could go download some of the latest research video, other videos and, and work product from the FU team. Um, a lot of great stuff there. So go check that out.
But not right now. Tiffany, I, I introduced you as the Chief Strategy Officer, but you also manage the FU of research team. I do.
I'm chief strategy and research, both of 'em. So, uh, you know, it's, it's a great position to be in. 'cause I get to have conversations with Daniel Newman, obviously that spoke this morning, our CEO on kind of where we trying to take the business, but then more importantly on the research side, you know, how do we wanna be not only a research organization, but one that is really disrupting the status quo and, and trying to bring deli differentiated value to the market in new ways.
And that's been a lot of fun. Absolutely. It is.
And I, you know, I, I get to interact from my seat here at Techstrong on it. And, and it is from where I sit, you know, I, I was a Chief strategy officer in 2005 at one of the companies I founded, still Secure. A lot of people don't understand everything that goes into that role, right?
You wear a lot of hats, you, you're already wearing two big hats, but as a CSO, you're wearing a lot of hats. Part of that though is, is being almost like an insect with your antennae up, right? Taking in external stimuli, if you will, translating that a strategy for the corporation.
Now, 2025 had to be a year of overload in turn of, in terms of stimulus coming in. I can't even imagine. Explain to our audience a little bit about what 2025 was like for you.
Just, I mean, the bombardment of all of this ai, of all of the advancements of all of the hype and, and not just hype, but changes, disruptions. How, how does this transl or how do you translate this into strategy? Well, first and foremost, I joined at the end of sort of 2023.
So I had a full 2024 here. Um, and my goal ultimately was how do I protect this amazing influence brand that Daniel had built over the years of this? You know, it has tech strong, it has visible impact, it has Signal six five, it has six five media, it has future research, uh, visible impact.
I mean, it, it had a lot of brands with a lot of different value propositions. And how did we pull that together in a way that clients understood the lifecycle of how we can really support them and their business all the way from labs, you know, testing all the way to launching a product, to helping them tell the story and nar, you know, give them the narratives and, and also help influence externally in the marketplace. That's a very unique position to be in.
You know, some analyst firms are very strong on insight and analysis. You have some that are very strong on media. You have some that are strong on labs and testing.
You have some that are, that, uh, firms that are strong on marketing and sales enablement. But it's, I'd be hard pressed to find anybody else that has the depth and breadth that we have across all of those categories. But it can be confusing.
You know, sometimes you do a lot of things, what do you do? Uh, and so that's really where we had to organize ourselves in, in a way that told a story to the market that people would go, I understand, I understand the value of each of these parts and components. And the sum of all of them is really the power of the Futurum group.
It is this multiplier of being able to help clients understand what the market is looking for, what their clients are looking for, what their competitors are doing, how we can help amplify their story. And really, ultimately, at the end of the day, our goal is to help our clients grow. I mean, at the end of the day, it's about helping our clients grow along the way.
If they grow, we grow. And so mm-hmm. It is the nature of the beast of, you know, giving advice that no one listens to or writing content that no one reads.
Um, there's no value there. But if we really start to embed ourselves in that process for them during their strategic cycle, then, then we have really accomplished what we set out to accomplish. Absolutely.
Tiffany, both you and I have been in the tech space probably longer than we want to admit. Um, have you ever seen a year like this? Have you, have we ever sat at a, a moment in time as we look ahead now into 2026 that, I mean, the, the, there's so much promise, it, there's so much to be excited about, but then you have to be tempered about it too, right?
And that's part of that chief strategy officer role, right? To, to kind of separate the hype from the reality, the what's doable versus I can't just be, you know, chasing our tails here from your seat. How do you, how do you distinguish, how do you say, Hey, this is, this is real, this is maybe not so real right now.
Yeah, so I, I've been in tech now 30 years, so it, it has been a minute. Mm-hmm. But this is my third where I feel like every conversation is about this.
So I remember a time, and which I'm sure you will as well, where every conversation was about Y 2K, like every conversation was about Y 2K. Yes. That was, that was sort of my indoctrination into a big technological shift in conversation.
I was very early in my career, I was very early. And so, um, you know, I was selling technology at that time, so it was a boom for us, right? Because Y 2K was with, with, with fear and with a challenge is a lot of opportunity to sell a lot of stuff.
Um, A lot of fun. Yep. So, well, there was a mix of both and, and you know, it, and ultimately, um, uh, I would say during that Y 2K time, um, I, I sold one of the very first deployments of electronic medical records, um, to Loma Linda University.
And so I remember that conversation of like digitizing, you know, medical records. They all looked at us like, what are you talking about? Right?
But we had been focused on the legal market, and we knew it was fairly similar, massive amounts of documentation needs to be secure. How do we scan it all? Then how do we search it all?
Then how do we categorize it all? And this is very, very long before all the stuff we have now. Um, you know, we were just kind of right out of DOS based systems.
Like, you know, it was, it was a long time ago, but the first one for me was Y 2K. The second one, the second sort of wave I was on was the internet, right? This thing called the Worldwide Web.
Um, and I ran sales, marketing and customer service for the US' largest web hosting company back in 2000 to 2004. And I remember sitting in front of clients and saying, you know, you, you're not gonna go, don't go have lunch with your server. Like, put it on, you know, our equipment.
And that was kind of infrastructure as a server, uh, infrastructure as a service, which it is now. Back then it was an a SP provider, right? An application service provider.
I had no idea what company was this? It was Interland. So we were about four times the size of Rackspace at the time.
We almost bought Rackspace, actually. Um, and we, I was interline Well, close, close. We were, we were in as SB too.
We were doing Lotus Plea. I'll talk to you offline about it. Yeah.
But, but yes, I remember those days. Well, Crazy, crazy. And no cloud.
No, no. And I was the beta client for Constant Contact, and I was the beta client, um, for Eloqua. Um, we were pushing the envelope on e-commerce, and we were selling domain names.
com, and now it's kind of gone on mm-hmm. To become other things. Um, but, you know, during that time, it, it was, uh, we had built a $115 million a RR business, um, you know, in a very quick amount of time.
And we were doing private label hosting for Verizon. And I mean, it was just, it was a wild time. And, and mm-hmm.
And I would say that was sort of the second period where I was like, wow, okay, Y 2K. Wow. I thought that was crazy.
This worldwide web stuff is nuts. You know, getting executives at, at traditional technology companies to really think differently about how they sell and deploy technology. And Salesforce at the time was like a year old.
Like it was 98, 99. So we were really talking early, as you know, SaaS, we're talking very early in, in infrastructure as a service. Um, those terms weren't, um, available.
Not everyone had, you know, high bandwidth in their homes. Not every we were carrying blackberries, you know, it was very different. Now, here we are on the third one for me, right?
Which is ai, where every conversation is ai. But this has, um, a very different feel. I feel like this is like, angry Birds meets AI because the adoption of Angry Birds in a consumer product, right?
Was faster than telephone and electricity and automobiles and all the things during the Industrial Revolution, right? And, but the consumer embraced it first. Well, you could argue GPT did the same thing, right?
That everyone started playing with GPT chat, GPT in, in a way, in their personal consumer lives. And then businesses are like, hold on, how do I take advantage of this in the B2B world, right? And similar with applications, um, where many, you know, millennials were using, um, technology very different than Gen X's.
Um, we were digital immigrants, not digital natives. And so you now have digital natives with, with chat GPT, where they're just like, look, I can do things so quickly in my personal life. I can plan travel and I can get answers to questions.
What does that mean to businesses? And so now I see this huge transition of, um, remember when the web came out and people are like, look, you have to put your information out on the web, like a, like a digital brochure. Sure.
So if someone's looking for your business, they can find you, right? A digital Yellow Pages, some of you don't even know what that is, but a digital Yellow Pages. Yeah.
What you mean, and, and, and that's what you need. Well, now, AI is the same way that customers, you know, I used to work for another firm many years ago in the analyst world. And, and, and back when I was there, um, we were the ones that first started saying like, the buyer journey was collapsing because people were going to the web to do their, um, their research before they ever reached out to sales.
And so you could argue 65 or 70% of research was happening before they ever reached out to sales. Well, now it's happening with AI and GPT where customers are going out there and going, what are the top best three security products for a mid-size bank? You know, or mm-hmm.
And then it gives you an answer. Yeah. And then it goes, well, okay, how would I compare against what's the cost model?
Like, give me ROI analysis, like, let me hear what clients are saying or customers are saying, or what about this and this? And they're asking all these questions, getting all these details. 0.
0 at this point. And you could argue industrial. Are we at the fourth industrial revolution?
5? 0 now? I, i, i, I don't know, you know, but, but I would say that, that that is really a change for providers.
Um, and we leaned into that here at Futurum by launching something called Futurum Signal to, to capitalize on the fact that now clients are looking for new ways to assess and understand different technologies in a more expediated way using ai. Absolutely. Daniel and I spoke a little bit about Signal this morning, and I think to your point, Tiffany, not only has sort of that buying process drastically changed 'cause they're self-educating, whether it's a consumer as a consumer of an, as an individual or a, a corporate consumer, they're, they're much, they're much more informed by the time they reach you.
But also that has crunched the, the buying cycle from a time where a, a product like ci, they can't afford to read what, what the analysts thought six months ago, nine months ago or less year. Stuff's happening too quickly, right? We we're living, we're living in, we were talking about going live on video.
You and I, before we started this session. We're living in a live world where people need up to the up to the moment kind of information. So telling me in 2026, where 2025 information you had is nice, but it's not what I'm looking for.
Yeah. And I think it, it move, it moves to, uh, you know, you almost could say, look, it used to be a reactive model. I'm a client, I'm looking for, I'm a pers prospective buyer of technology, and I'm looking for a solution.
I'm gonna call three people. I'm gonna leave them a message, and then they'll call me back. Right?
Very reactive. And then maybe it became a little more proactive where salespeople would like, you know, in an unsolicited manner, write cold call businesses and say, I think we can really help you with what you're trying to accomplish. They read an article in a newspaper or a magazine, they find the company, they look 'em up, they buy a list, they do something, and they outbound call, right?
So that was being more proactive. And then we moved technically to being more predictive. Okay, companies who look like this and buy this are more likely to then buy that, or this is gonna be the pace in their adoption cycle, or, you know, they're gonna grow at this rate because we've seen a hundred companies of similar size or ilk do something very similar.
So we can see through that analysis that we think they're more likely to want this or want that. And so that was technology really starting to help be more predictive. Now we're in this, uh, AI world where the system is able to do everything I just described very, very quickly, but I'm always, always a fan of human in the loop at the, either at the end or the beginning, right?
In the context prompting and what the AI is actually doing for you and the rules associated with that, and then a human at the loop at the end. So I've talked to a lot of companies now that are saying, look, we're actually hiring in the sales organization at our big technology firm like a sales AI expert, that all they're doing is working those models and those systems and those prompts. Um, and really making sure that when they're reaching out in this selling motion that they're doing so in a way that isn't AI slop, right?
It's just bad data or it's too much, it's spam, right? It's too much communication, or it's not even relevant. And so while you may go, look, we went from touching a hundred customers to touching a thousand, let, let's give a small golf clap to, but those other 900 are really bad and they've done worse for your brand than if you had just stuck with the hundred.
So, you know, I'm a fan of technology, but I'm a fan of human and tech, not human alone, not tech alone. I mean, I think there are things tech can do alone, and I think there are things humans can do alone, obviously, but in the mean, the, the, the ma the maximum performance enhancement happens when those two things work in harmony. And then the one plus one is absolutely not even three.
The one plus one is like 10 or 10 x what it used to be. Uh, and I think that while promising and exciting, and everyone talks about the promise of that, very few have been able to capitalize on that yet. Yeah.
And, and I think, you know, when we look back at 2025, I think that right there is might be the, the, the big, the big answer, right? Very few have been able to capitalize on it yet, but I guess that begs the question, is 2026 the year that more capitalize on it, or are we talking further out 27, 28 beyond that? Yeah.
I wonder if we're about to go down the trough of disillusionment, right? Because AI's been on a massive hype, right? I mean, it's been rocketing up And you could live up to it.
Yeah. And, and not only that, it's, it's, it's, look, you know, companies used to do transformation efforts, technically based transformation efforts, let's say two to three a year. Like Lisa said, we're gonna modernize our ERP, we're gonna update our CRM, we're going to, you know, change our security protocols.
We're gonna, you know, go to, uh, all web-based tools and not, you know, ship a, you know, a hundred CDs, uh, or whatever it might be. Um, and, and those two to three transformations a year for an organization has now become like 10 or 12. And so the problem with that volume of transformation is people, humans cannot absorb all that transformation.
So as a CTO or CIO, if you're listening to this, you know, or a CEO and you're listening to this and you're like, we're gonna do these 10 things this year in 2026, I want you to always remember on the other side of all that change are humans. And not all humans will get every change motion. Like your finance and billing team might get a change that doesn't touch anybody else, or your sales team might get a change that doesn't touch anybody else.
Um, but if you're going to change tools that the company is using, you know, across the board and you're doing six to eight big transformation changes or digitization over 2026, you will burn your people out. And what will happen is they just won't adopt it. So you've spent all this money on this technology, you've rolled it out, you've told your board, you've told your team, like the promise of the ROI of this, of how much better it's gonna make your life.
And then it's like, wah, wah, nothing happened. Or it, it missed the expectations. Was it a technology miss or was it a people miss?
And executives usually point to people saying, ah, they're not adopting it, or they're not doing what we want. And no one's actually saying, well, why not? Were they not trained?
Is this the fifth thing we've changed in the last 90 days? A human can change behavior in 66 days on average. So if you change 10 things in a year, times 66 days, it's 660 days worth.
It's too many days. 2360 days Right now, you might double up and go, well, we're changing three things at a time. Well, so I'm gonna change my diet, start working out and, you know, move to a new city.
Sounds Like my New Year's resolutions right's. It's, You're not gonna, it'll work. Do it work, it don't work.
Yep. Right? So I just, I always want, you know, while the shiny things are exciting, while all of it is, is, um, really important and can have impact the smaller your organization is, the harder it is to absorb that much change simultaneously.
The larger your organization is. It's easier to absorb that much change, but it's harder to get consistency because of the volume and the number of people now in my prior life to future of my work, eight years at Salesforce, which, you know, everybody knows who they are, knows our CEO. Um, and he could change, uh, something on the dime because the operating philosophy and, and culture of the organization was such that when he made a change in a 30 day period, the, you know, 60,000 employees would absolutely turn left or turn right because of the operating model.
But not everybody is like that. Most people, it takes, we're on a three year transformation path. We're on a two year transformation path.
We've just launched a new strategy. We've told the board it's gonna be three years, right? Any of those things, um, you know, my boss, right?
My, our CEO, uh, there is no strategy transformation that has a three in front of it or a two in front of it and or a one in front of it, right? Right. It's in a quarter or two.
Um, and so moving that fast requires the right organizational structure and infrastructure to handle that kind of demand. So people are saying, she's right. How do I get that?
And so how do you instill that sort of organizational structure to, to, to, to play it the speed of business today? 'cause that's really what we're talking about, right? Yeah.
It, it all, the Achilles heel for all of this is process. Processes are the achilles heel of any organization. If there's too many manual touches, you can't scale.
If the processes are broken, you can't scale. Um, I'll get really basic here for a second. If you're, if your technology solutions don't talk to each other, you can't maximize AI because the data isn't consistent and the data's not valid.
AI is all about data. If you don't have good data and data in one place and data, it can, it can trust and it can rely on, it's gonna give you bad data in bad insights out. So, um, if your technology doesn't talk to each other, uh, you know, that's a, that's another, that's another area for improvement.
But I would say processes would be the first place I'd start. Now, it's not sexy, you know, it, it isn't like someone grows up and says, if you remember that commercial where like, when I grow up, I wanna be a middle manager. Um, it's like mm-hmm.
When, when I grow up, I wanna be responsible for, for process and change management. But it is the most critical because if you can't fix a process and change your process quickly, everyone is operating in this bimodal way, right? Um, we're operating the old way while simultaneously being forced to work the new way.
And, and it's very difficult to do both. So, um, I'll give you one little stat. So switching tabs.
So I always ask this question, if you're watching this right now, I want you to look up at the tabs, uh, of all the tabs you have open on your desktop. And I doubt you have one tab open. I, I doubt it's okay.
And some people will have like a hundred tabs open over the course of a day. 02 millisecond. It's like an instant.
Your eyes will see the change, but your brain doesn't catch up over the course of a year. Just context switching between tabs. So between your sales tool and your marketing tool and your service tool, or your Slack and your Zoom and your teams and your whatever it is, like, right?
Switching between all those is five weeks of switching time. Wow. Five weeks.
Five weeks. You waste on just going tab to tab to tab. So when someone says, we Need it almost 10% of the year, You need to, you need to increase productivity of your team.
I'm always like, okay, I'm just gonna start at the lowest hanging fruit. How many systems do they need to log into? How many, you know, where's the data sitting?
And if I can cut that down to 50%, I can give back two and a half weeks of time. And if I did that three or four or four times, so I, I mean, I'm getting really tactical here, like obviously I'm not talking at 40,000 feet, but you asked how sometimes it's really the basics and people get caught up in the big aircraft carrier of change that has to happen. And it's overwhelming.
It's intimidating versus thinking about the small little changes you can make every day over the course of 2026. And by the time you get on the backside of this year, the company will look markedly different than it does today. And I think that's where technology has an opportunity to accelerate that.
But you can't do it if you're not paying attention to the foundation of the business. Tiffany, I want to bring up an example where the rubber meets the road here. All Right.
You call it the fip. I, I always ref I'm slow. I say futurum intelligence platform.
That's what it's called. That's what it's called. Yep.
A great example of everything you just spoke about in many ways, right? We we're gathering meaningful data. Mm-hmm.
We're putting it all, we're use, you're utilizing, you know, technology that, and AI and everything else. com and you know, take a, take a peek at it. But Tiffany, how does, how does that, right, that's where strategy meets reality, right?
Into a real product. How does that enable Futura To Well, I'll just, yeah, I'll go ahead. Just, I'll just, yeah, but I'll just use the example I was just talking about.
Look, No, what made me think of it. Yeah. The promise of the future of intelligence platform, I'm just gonna talk internally here for a second, right?
Is it allows me to have, um, a agentic analysts working alongside my human analysts. So if I have a practice leader in, you know, enterprise software as an example, I want him to have five principal analysts in parentheses, AI agents working for him, Coworkers. Mm-hmm.
Working for him. So he's directing the prompts and writing the prompts and all of that. And the power of me saying, do I need five more humans or can I have one human and five agents?
And then, you know, we start to test and learn and it's looking for signals and it's writing content. Obviously human is in the loop, human is in the loop doing all of this. And then I go, now I need to add another human, but I've got all this capability through the agents.
Now, in theory, on a piece of paper, in a PowerPoint slide, everyone's like, yes. Like, how do we get 10 principal analysts, you know, AI agents, how do we create, you know, will our org charts of the future actually have agents on the org chart? And you're hiring and firing agents.
This agent no longer is necessary. We get rid of this agent, we need another agent that does these things. Or this agent is getting smarter and smarter, and now it's becoming more and more, um, capable.
Do we track that performance improvement? And that agent starts to take on more and more responsibility? Like, I know that might sound crazy, but possible right?
Now, while it sounds good on a slide, do humans just go, I'm in. No. Well, wait a minute.
That's the problem. Wait a minute. My name's on this research.
I wanna make sure it meets my standards. It's my brand, it's my reputation. And all, all warranted comments, they are absolutely, um, warranted comments.
So it's a, this is a behavior change. This is a, I'm not saying tomorrow you're gonna have five agents working for you and they'll be cranking out a hundred research pieces and it's gonna be perfect. And the world as butterflies and, and unicorns and rainbows, we know that that's not true.
So I, I have to crawl, but I need everyone to crawl with me. And it's been interesting, right? People will crawl at different speeds and be interested in doing things.
How do they take their own way of working and apply it to how we're trying to do things now? It's not easy. It is, it is definitely a lot of people management and process management and behavior change on the other side of this.
When do I think we're gonna get there? I hope we get there soon, right? And, and I'd say Daniel would hope we get there sooner than I hope.
Um, but I, but ultimately I underestimated, um, what I needed to do on the people side versus how heavy the and hard the lift was gonna be on the technology side, right? Because we have a killer team on the tech side, and it's my responsibility to get the people aligned to what our technology can do. Um, and, and even in the last 60 or 90 days, and really since Signal launched, we've come miles from where we, you know, if we're, if we're on a football field, right?
We were on the other end zone and we're going to the end zone, right? We were like probably on the 15 yard line and Signal got us to about midfield, um, where everyone now is understands and starting to adopt and is using it in new and unique ways. So now how do I capture that and repeat it across the team?
And with every day we're just making plays and getting a little yardage, and yep, we get sacked, we move back a little bit and we go forward. And for those of you outta the us, you know, think, uh, think your football, um, same thing, right? You don't always pass forward.
Sometimes you gotta pass backwards. And so, you know, ultimately at the end of the day, um, it's been, um, it's inspiring and exciting, uh, to get back into the analyst world, um, in an environment like this where it isn't just the same old thing. Uh, and I think we've got the right team to do it.
Absolutely. Tiffany, we've got five minutes left. Alrightyy For our folks out there.
Look, as I said, they can go sign into future and see what we've built and, and see for themselves. But not everyone out there is gonna have the capability of building their own platform, of their own kind of base. But we're coming to a point where you don't have to just rely on the large frontier LLM model.
Yep. Everyone should have the ability to, you know, they say 95% of the data on the Internet's behind the firewall and hasn't been incorporated into the models anyway. Everyone hopefully should get the opportunity or the ability to, to, to use their own data to make their AI ventures smarter, better, faster, more effective, more ROI.
What's your advice to these companies? How do they, how do they harness this power that at Futur we, we've been able to harness it. How, how do other folks get to harness?
It's short of, you know, they could sign up for subscription, um, but, and, and we do sell them, but beyond that, what else would you advise them? Well, The first thing I'd say is I would get an understanding of what people are doing now in your own organization. What tools they're using and how they're using them.
First stop is to make sure that you've got strong governance around what your companies are doing today. You definitely do not want your employees uploading proprietary information or NDA information or company specific information up to the public chat, GPT or Perplexity or Gemini or something else, right? So at a minimum, you need to understand what's happening in your own organization today and make a decision on what is your strategy around using AI in what roles, you know, do you, maybe you never want legal and finance using it, but customer service should be using it all day.
Okay, then come up with rules for that or sales or something like that. So I'd understand what you're currently doing and using. It's kind of like shadow it back in the day when, you know, we were selling things and we would avoid selling to a CIO and we'd go sell to a business unit leader.
We could sell faster than trying to go to the CIO and it was called Shadow it. Um, it's almost like shadow AI where everyone's using their own preferred tool and they could be uploading things because there's no governance, there's no rules, there's no checks. And so that is really dangerous.
Um, especially if you're in a highly regulated industry. It is, yeah. Even more of a no-no.
Right. So I'd say start there secondarily, then come up with what is, what is gonna be your preferred LLM and your preferred model, and then who gets to use it and how they get to use it. And then, you know, you work with your IT team, your CIO on where is your data?
Do you want to, you know, use that data as part of your own? I mean, you can create your own San I have my own Tiffany Bova, uh, ai, um, and it's only my content. So it's my books and my podcasts and my keynotes and everything I've ever written, everything I've ever done.
And so I can ask it, you know, like, write me something, 50 words about this topic. It's gonna write it in my voice, it's gonna use my examples, it's gonna use my things, but it's only me. Now if I wanna do it and I want it to go to the web and look for other things, then I do it a different way.
'cause I never sort of commingle the two because I wanna keep that proprietary to me. Um, you know, and it's like anthropic ingested my books, and so I'm part of the lawsuit. Like, you don't just get to ingest my stuff, right?
Right. And so you, you don't want, you don't want that to happen either. So I would say really understanding the governance and rules around what tools you're using, how you're using them, how and where your data is showing up, um, is, is absolutely priority number one, because it's already happening.
And if you don't know what's happening, that's even worse. And, and I'd be surprised if many people weren't sort of aware that it was happening and trying to get their arms around it. I think that they may be like, how do we put the cat back in the bag?
Right? Um, because it's out and running around, everything goes in the bag. Um, yeah.
And so, um, I don't envy anybody who's in that situation, but I think at the end of the day, uh, you know, or even hire out, uh, you know, outside help to help you get your arms around this, but it's gonna be one of those things, um, that if you don't get your, your arms around it and you don't get a handle on it, uh, it becomes very dangerous. Especially as if your information on your company is, you know, proprietary and you don't want it out there on the web. Is this a 2026 thing, Tiffany?
Can we do this in this year coming up? Absolutely. Um, you know, I absolutely, I, you know, I, I definitely see it.
What's interesting is very small businesses are able to do it because they can move faster and they don't have as much stuff they have to fix. And, you know, they can be very quick on governance, you know, uh, Futurum is a great example of that. Um, when you're up at the upper end of the enterprise, they can put a lot of money and energy and resources to it.
It's kind of in that middle set where the, you know, a a, a good midsize business, call it, you know, a hundred million to a billion, you know, you've got a lot of employees, you've got a lot of processes, you've got a lot of shadow it, you've got a lot of things happening. Like that's an investment you're gonna have to make. And if you're not public and you're private, you can do that kind of investment without the eyes of the street on you.
Um, it's different if you're public, but if you're private, uh, I definitely think so because I see it happening all the time. Uh, you know, I hear people saying they're getting much smarter on selling and marketing and customer service and using ai, you know, making decisions at the executive level. They have a, yeah, they have AI board members, they have AI on their org charts.
Like while it sounds, you know, very out there, I I do hear it. It, it is on the edge. It is not the norm.
It is on the edge. Um, but it is, it is happening. I, I do believe 2026 will continue to gain momentum and we'll start to see more, um, use cases and we'll see, uh, real true ROI on it.
Um, forget the big hyperscalers and the neo, uh, clouds. Like forget that sort of 7 trillion that's moving around those guys, but just for businesses in that mid-market space, uh, I I, I think that, that that's, this year's gonna be the year we start to see, see them really make inroads. If I had to boil down your 2026 outlook, you're extremely bullish on ai.
I'm bull, I'm Bullish, but Keep humans in the loop. I I am bullish on both of those things. Yes, Absolutely.
Tiffany Bova, chief Strategy Officer here on Predict 2026. Hey, we've still got more, including the DevOps does an award winner. So stay tuned, go check out the FU booth and our virtual event here, and you can download more of Tiffany's writings and, and the whole team's writings and videos.
There you're watching Predict 2026.