Techstrong TV February 21, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Trouble with Tribbles. I mean, tariffs.
You're watching Textron Gang. Hey everyone. Happy Friday.
Thank God it's Friday. It's Alan Shimmel here for Textron Gang, and thanks for joining us. We've got a lot to go over today.
We've got trouble with triples and tariffs. We've got soft last soft software supply chain issues, and serendipity is a strategy, or as some might say, throw it on the wall. Um, a lot to go over.
Let me introduce you to our gang members for today, though. First of all, joining us out west. She's still pretty in pink, not red for Valentine's Day, but think today it's our own marketing guru, radio host, everything.
Little bit of everything. Lisa Martin. Hey, Lisa, how are you?
Hey, Alan. Great to see you. Excited to break into AI powered serendipity in C Block today.
I'm excited for it as well. Any, I always like serendipity where he reminds me of the, the ice cream shop in New York. Aw.
Yeah. We used to have one down here, Boca at the Boca Resort, but they closed it and been missing it since. But I'll be in New York soon.
Maybe I'll stop. It's gonna be a little cold for ice cream. But anyway, welcome Lisa.
It's great to have you here joining us. Our man, he's not lost at sea, but he's out at sea. Resident security expert defender of the Maple Leaf, our own Chris Blas.
Hey Chris, how are you? Loving life. Hankered off.
Marjo key. M-A-R-J-O-E. You can Google maps that to see where we are today.
And, uh, glad to be here. Looking forward to the conversations. Is Marjo key, uh, settled?
Are there people living on there or is that just No, It's, yeah, it's an island. It's a hundred, a hundred yards sort of north or south 50 yard east or west, you know, north of, uh, uh, the sugar loaf keys. Yep.
So the Snipe keys kind of cut the lower keys in a half. Yeah. And the east side is the quiet side.
So we navigated over here last night after visiting friends and family in Key West and spend the last week with Donna on board and enjoy the manatees and inheritance. Absolutely. You're still south of Marathon?
Yeah. Yeah. Lower, lower keys.
So the, the top of the floor reefs is about 300 square miles of shadow water here that these boats were designed to build for. So, excellent. This is their home stomping ground, Enjoying the weather's.
Been well, it's been a little windy up this way, but the weather's been nice otherwise, besides the wind. So, enjoying my friend moving from the Florida Keys, which is it about, well, zero sea level. He's on sea level.
Up to the Rocky Mountain Highs. It's the guitar man, Mitch Ashley. Hey, Mitchell, how are you?
Hey, good to be here. Best Friday ever. No manatees around here, but, you know, Hey, we got the Rockies and, you know, got other stuff.
No manatees, huh? No manatees this week. All right.
If you ever see a manatee out there, you let us know though, right? Boy. Uh, yeah, we've definitely lost the coastline in sea of Florida.
Yeah, it'll be, it'll be quite a, a thing. Alright, moving from Colorado to Harrison, New York. It's cold.
It's cold, and, and we're stocking up on wine beer from Europe because, well, it's gonna get more expensive. Well, isn't that a great segue? He's our chief content author of Mike Ard.
Mike, you know, I, i I, I said something about Tribbles, but I meant tariffs. Mm-hmm. We've got troubles with tariffs perhaps here.
I think, uh, grant, you kick it off. This Has been foreshadowed for some time now, but we've seen Acer raise prices 10% because of tariffs. I'm sure others are gonna follow suit.
And we're taking a look at a little bit at how all this stuff is gonna impact technology. The big tech companies, all the way down to the people who make laptops. Seems like everything's gonna get a little more expensive.
And it's not clear to me that it's for a good reason. But Alan, what should we expect? I think we should get, expect a kick in the rational exuberance where it hurts, right?
Irrational exuberance. It's what made this country great. And then every time someone pulls the plug in, and this could be the plug coming out here.
I mean, look, I, I call this issue tech sovereignty, spoke about it yesterday on my shimmy, says LinkedIn live segment, and you'll be up on YouTube. We, the consumer, meaning all of us as consumers, are the ones who are gonna get hurt here, right? Because not only does our technology wind up costing us more money, and, and let's face it for some of us, we'll say, we'll bite the bullet and pay more money.
'cause I need it for some of us, it'll just move that technology a stone too far right? To, to, to do. But we shouldn't think for a second that it doesn't have a reciprocal thing where our technology, our goods become too expensive for people in those markets.
And some of those markets are pretty damn big, right? And so this has a, a rebound domino effect around the globe that we wind up. Just that we, like, we have data sovereignty where we're going to keep our data just on our board in our borders.
We're just going to keep our technology within our borders, and we'll all wind up driving those little bad cars that they had in the Soviet Union right before it collapsed. Because we get, don't have access to other vehicles, right? Because the other flip side of this is, it stifles innovation, right?
If I'm, if I'm in essence selling in a walled garden, a protected market where I don't have to worry about external competition, where's my, where is my, and I can't sell to external markets 'cause I've been shut out. Where's, where's my motive for innovation? Where is, you know, where's the market at work here?
So this is gonna put a hurt. I, I don't realize, I, I think America is rah rah, rah, but this, this cuts both ways. And it's gonna put a hurt on these larger American technology companies who need the world market to make the money.
They do. We can't make enough money just selling to an US market. Hmm.
Lisa, there's a cascading effect here, and I wonder if marketers are talking about it yet, because, um, if I can't hire, or if I can't keep enough people employed, then I start to lay folks off and then it has a cascading effect through all kinds of vertical industries. And suddenly the people in who might be working for, I don't know, Dell or hp, pick whoever can't afford to buy that car, buy and then et cetera, et cetera. So quite literally, are we, you know, in Alan's point about to shoot our toes off, It's a really precarious situation that we are in.
Uh, over the last couple of weeks we've seen China reacting. Mike, you mentioned a is already saying, we're gonna have to raise our prices by 10%. I think it's a challenge for, it's gonna be a challenge for every organization to understand how this is actually going to unfold, how it's going to impact the end user, the consumer of whatever product.
It's, whether it's, um, an ace or laptop or something more from Apple or a product you're buying on Amazon or eBay. And I think that from an employment perspective, uh, organizations are gonna have to be really mindful about how they're hiring, who's on their teams, what talent they need to have to be able to combat the price increases that they're no doubt gonna have to invoke in order to survive and make the money that used to making, I don't know, I don't know, Chris, you know, is this buy American? How far are we gonna go?
Do I have to wait for a laptop that's gonna be made in, I don't know. I'll pick Ohio or wherever it might randomly be. That might be, what, three years from now?
If I'm lucky. If you're lucky. I was gonna say 2035.
No, even, I can't find anything good to say about this. So look, you know, the, you know, this is a freedoms issue, right? You know, free market capitalism, freedom of speech, democracy, all these things, open source, you know, free internet, you know, these are very American topics, not uniquely American, but very, this is one of our founding principles.
And we've watched, and you know, maybe all of us here have had some hand in, you know, selling products to countries like China, you know, who want to have the great firewall. They want to have the closed this. And we've watched Russia go through this in the last, you know, five years trying to have the, you know, the, uh, every man's, every nation's an island, you know, uh, approach to things.
And in my opinion, we rightly look at that and say, oh, can go ahead. You will reduce your competitiveness. Go geopolitical globally, economically, and, you know, we will stay open and engaged.
But terrorists are a thing, you know, sometimes you need to do things free, free of speech, you know, doesn't mean you can yell, fire in a theater, you know, to have, uh, free markets and, and proper, you know, uh, cap capitalism. You need, uh, some rules. And if you look at, I correct my focus on supply chain.
I've looked at the presidential executive orders across the Obama, uh, Trump, Biden and Trump, uh, and this current administration on supply chain. And I, you know, interestingly kind of line up, there are some reasons to do things. You know, the two political sides can throw this back and forth.
You did it too. You did it too. But what we're doing right now, blanket, tariffs, you know, this is the great firewall thing.
Again, we're gonna make a wall around America, and that's going to work better than it doesn't work in China, or it doesn't work in Russia. No, you know, this is not, this is not a useful approach, and we're just doing a big transfer from the consumer into the government. Every tariff is a tax on every product that goes from the private sector to the public sector, which again, you know, is not particularly an American approach.
We like to have money in private hands so that people can innovate as opposed to shoveling it into a federal coffer. Hmm. Alan, how silly when this skit, because I remember being down in Florida, and you go to the mall and people would be coming up from South America, various countries, and they would buy a suitcase and then load up crap and it, and make like they owned it the whole time.
And so, you know, are we gonna see Americans doing that overseas? Yeah. I mean that, that, but most of the goods they were buying were not made here.
They just bought 'em. Here they go. Came from China for the most part.
Or Thailand, or Vietnam or wherever else in the world, right? Because, you know, it goes back to Tom Friedman's flat Earth capital goes to the, it's like liquid. It goes to the lowest, you know, to the most efficient place usually.
And now you're kind of messing with the natural laws of physics there, if you will. But how bad can it get? Let me give you the worst case scenario, actually, let me, in a best case scenario, other countries retaliate and they put up their own walls.
And we all live in this walled walled garden where we all keep our own, we all consume all everything we make. And that's a best case scenario. If you believe, you know, the rose colored glasses in from the, if you believe the people with rose colored glasses, the world will come begging at their knees to please give them access to the US market.
They can't exist without it. I don't think that's what's gonna happen. So at best, we have this world garden where Europe is its own market.
China's its own market. The US is its own market, et cetera. But it gets worse.
It could get worse. Canada, Mexico, go make deals with China. China go make deals with Europe, as a matter of fact, Europe, China, Canada, Mexico, the rest of the industrialized world as we know.
It says, you know what? We don't need America between the six seven of these markets with three times the size. Let America keep America.
We're gonna do our own ai, we're gonna do, we, we proved we can do it cheaper and better. We're gonna do our own space systems. We're gonna grow our own food.
We're gonna do our own tech. Thank you very much. Google, apple, and Microsoft.
Nice knowing you. And this is, you know, the, I grew up in the seventies, you know, and, and watching this play out through the eighties, you know, the free market, remember the, the when the GOP when I was a Republican, right? You know, is, you know, the argument was you shouldn't be able to, you shouldn't limit the US federal government should limit an American citizens rights and ability to do commerce internationally.
You know, again, certain tariffs, rules, you know, we're not talking about, well, You weren't allowed to bribe people, which you can now. No. Right?
Yeah. And just Want to throw that in. And we won, right?
The Cold War, you know, we, we got China and Russia basically to a accept capitalism. I mean, you know, that whole argument that we were making back then that that has driven positive change in the world. And now we're arguing the opposite.
You know, smaller is better. Lock the doors, put up the walls. Historically, as you look across nations states, that's a very normal thing to do.
You know, the modern era and the benefits we have are predicated basically on not doing that. So now we're adding to the, adding to the, the, the drag on the system, which will slow down economic growth and everything that goes along with it. Yes.
Well, one of the things that this does is it forces everyone to start looking at their supply chain and what alternatives do we have. And where it hurts is where you don't have alternatives, whether it's shipped from Taiwan or, or China, um, or, you know, goods from Canada for building homes and, you know, things like that. So it, it's, it, it's something that I, I saw this interview and I actually had someone who said, no, tariffs aren't attack, aren't attacks on us.
There are attacks on the person who makes the goods. And the interview was also with a second party who was a importer of goods. And he explained, he said, no, I've been doing this for 30 years.
It sits on the dock until I pay the tariff in order for the good or good to enter their country. And, you know, I don't, I don't eat that. That goes into my pricing to my customers.
So I think America's gonna learn pretty quick what tariffs are really about, where, who really pays those, uh, those amounts and, you know, what's politics and what's reality of it. So I I I also think that a lot of this is bluster, you know, to try to, you know, pick it out the big hammer and wield it, swing it around. As soon as you hear people complaining about it on the news, being interviewed by the local TV station, it's not gonna be pretty, Look what we've done for the price of eggs.
Look at those eggs. That's, that's probably A lot as in it. Yeah.
Let me, let me wrap up a little bit on this. You know, I lost my thought there for a second, Mitch, with the eggs thing. But what, what we have, or what we're going to have is, you know what, cancel my thing.
I forgot what I wanted to say, right? We gonna talk about Triples. Wait, wait, wait.
Let me, let me jump in there and then you can kick it All. You go, Mike. All right, So let's take this to its MP logical conclusion.
Would we see Alan, US companies deciding to move their headquarters outside of the US because it just made more economic sense for them to pay taxes somewhere else? Well, if, and, and if the markets are there, look, it, laws of physics don't change. I, you know, that's a science fact.
Everyone's entitled to their own opinion, but facts are facts, right? It's another hard lesson I think we have to learn. Facts are facts.
Opinions are like butt holes. Everyone has one. So if it makes economic sense to move your headquarters outta the US 'cause you have economic advantages and selling to a bigger market, making more money, it's gonna happen.
That's, that's the way of, that's the way markets work. You, you know, it, it, it is what it is with that. And I, you know, who can blame them?
Quite frankly, who can blame them? You gotta go where, where your business is. I just wouldn't recommend calling someone else's opinion a butt hole.
But that's a different topic. Well, sometimes I do. But, but here, here's the good news.
Here's the good news. If all of these countries stop taking guns that we manufacture here, think of all of the guns that'll be available here. That's the good news.
Or the guns that might never get made. It's another Thought. Oh no, we won't stop making guns.
We're America. America. We make guns in America.
America. So, I mean, it, it's gonna be an interest as it plays out. It will be interesting.
Certainly nothing else will take a break here on tech strung gang. Let's come back and talk about software supply chains. There's, it feel like we shoveling sand against the tide.
We'll go to our boat person right after this Discover Textron group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back. And if you hadn't noticed, there was a report about the Lazarus group, which is associated with North Korea as attacking various software repositories that are out there.
And I feel like we've talked about this issue before, but I cannot help but wonder if these hubs are essentially defenseless because, well, maybe all the warnings and concern about DevSecOps just gets lost in the noise. Or Chris, is there something else at work here where we can't seem to get our act together around the notion that these things are a part of the attack surface? Well, We're getting our head around it, right?
You know, and the, you know, the, I I was just thinking I should know this. I don't know if we share the backgrounders for these segments with, uh, the viewers, but if we don't, we should, right? Because there's a article, uh, uh, on the background on this one about, you know, are we defenseless in supply chain?
And, and the short answer is for most organizations, kind of, yes, that's where we are. And we always have been, always have been. This has been a known issue for a long, long time.
This is about off, uh, inventory. It's no, you know, do you know who you are, what you have, what is doing, and what's going on around you? It's one way.
Look at situational awareness on that. Do you know, you know what? You have no, right?
Just inventory of the hardware in organizations has been, has evolved. Well, we have asset inventory stuff and so forth. Inventory of the actual software, what's in the software.
That's where we're right now. That's, this is, you know, when we talk supply chain now we're talking about people putting code inside the code that you actually bought and that people who bought it from didn't know that it was there because they're including open source libraries or whatnot. And there's been no way logistically and economically to do better than that until about now.
So the, you know, and then that background article, you know, as we're talking about in the green room, I think defenseless is the long word, is more defensible. You know, is this reasonably something that you as a small organization can defend yourself against now? No.
Um, however, you know, there are major vendors. There are thanks and other organizations have been working on this for years. It is can be done quite well.
And I think in, in the, in the right sectors with the, that have the resources and have the motivation and so forth. I think in the next, you know, in this decade, you know, in the next several years, we will see some systems that are remarkably defensible and defended from these sort of attacks. Uh, but we're just not there yet.
Not, not, not for everyone. Well, right now we talk about the software supply chain security, and a lot of that is talking about what are the software that goes into our software creation process, whether it's open source or NPM packet managers and, you know, PII for, for Python. You know, it, it's, I think it's almost one step beyond that, though.
We're at a point where we need to think about this as software supply chain integrity. Just like we do software, supply chain integrity for products, right? It isn't just the Tylenol that someone broke into and put in some, you know, foreign substance that we don't want in our, in our bottle of Tylenol capsules.
It's the ingredients that go into making, you know, the product. And in this case, we're talking about software. And so what are, what is the integrity of all of the ingredients of software that's, whether it's libraries or, or repositories or our own, as well as the manufacturing process, our own tool chains.
So we, I think we have to kind of trace it back one more step and learn the lesson that we did in the physical supply chain about, it's the integrity and the, uh, providence of where things came from, uh, in really knowing what's going into our software. And ultimately, that's where it's headed. That's what you have to do to really secure the whole supply chain.
In my cynical moments, Alan, I will look at this and I will say, wow, we've been talking about this for a while. And then I, I wonder if the cyber criminals and the folks over in North Korea like read these discussions, watched these videos, and said, what an awesome idea. And now we're gonna see more of it because they figured out that they can do it.
So how much of this is kind like, you know, we kind of led them to the right idea. No, well, look, the bad guys never miss an opportunity to take advantage of a, of a weakness, right? They're constantly, they're not, they're, they're not me too guys.
They're not followers. They're always probing and figuring out. But this is an obvious, this particular thing we're talking about here is sort of an obvious whole weakness that's been exploited number of times.
Here's, here's the real facts, and I think most of our audience probably knows this. 'cause we deal with a lot of developers and a lot of cybersecurity people. But for those who don't, let me, let me explain it to you.
80% or so of the components that go into any app that you're using today are probably open source or preexisting components that get stitched together Frankenstein style into an application. These open source or pre-ex prefabbed components aren't just existing out on the edge wherever the edge in the cloud is. They live in something we call repos repositories.
And there are some very, very big repos. Uh, the, the, uh, nexus repo artifactory, GitHub itself is a huge repo, right? There's probably less than a dozen reposts that probably account for 90 plus percent of all the software components that go into every application that we use today.
That concentration represents an opportunity for supply chain security because there's an obvious choke point. That choke point exists when you download that component from a repo, it's gotta be downloaded. I've never understood why we haven't put the onus on these repo managers to check the integrity of the software that's being downloaded from the repo.
If we could do that, we'd go a long way to improving our software supply chain security. Now, I recently had a conversation with a security vendor who actually manages one of those large repos Mitchell notes, who it is, I don't know if they've announced this product yet, but they're doing just that. They're gonna put, you wanna call it a firewall, Chris, you like firewalls, you wanna call it a firewall at the repo that says, Hey, before you download it, I'm gonna make sure this is the right file.
It's the latest. It doesn't have a known vulnerability. The check sum is correct, whatever.
Right? But we're not gonna let you download an insecure component. Now, the real win will be if someone says, I can make one firewall that works across all of the repos, not any one repo.
'cause as I said, there's probably less than a dozen that you want to hit. But if we could do that, and I don't know for the life of me why we haven't done it yet, right? But if I, if I was gonna go start a company, I'd go do that right now.
Go build a repo firewall that works across the 10, 12 biggest repos, and I'm gonna filter out any bad stuff and watch what it does for our software supply chains. Chris, I saw you had your hand up. Go ahead.
Yeah, you know, I've always loved supply chain, uh, because it just begs all the questions, right? You know, firewalls are great, right? I started my career in firewalls, and it's a very simple thing.
On the edge of your thing, you should probably do a stop, you know, supply chain, you know, threat intelligence, you know, spreads that we've done it in the last 20, 25 years. You know, how do I actually get outside my walls? You know, again, to our, our first segment topics like that, and we're pretty good at that.
But with supply chain, there is no single point, right? And a number of us have been working on this for a long time. I think I, I think I have a, a vision.
I, I think a view on architecture that I think works has been tested enough, but it's, you have to include yes, repos. And I've been working with, you know, various repos and so forth over the last couple years. They've been going down this road, they're getting better.
They have a role to play. But when you look at the entire supply chain, you take, you know, a a high demand sector and put all the pieces together from the isec that's already sharing information and the vendors and the integrators, you have a lot of choices. You know, the simple, the sort of firewall answer is, I am going to take all of my supply chain information and get in, in advance and have it in one spot.
And that makes you think through the fact that this is not how anything works. You know, it's a dynamic. What we really need to do is represent our entire supply chains.
And this to, to my earlier point in critical enough industries that can be done today, and I think will be done in the very, very near future in real time ways. So that every regulation, every contract, every agreement, every really, every, the, the characteristics that define my relationship with my supply chain partners and their supply chain partners is not just something I can call legal and pull up in two weeks, but is actually acting. So when I want, for example, an SBO from a third tier provider who had, and everyone has agreed in advance, and I will get that within 12 milliseconds.
I'll have it in 12 milliseconds, and I will have the right, and then What are you gonna do? But then what are you gonna do? Yeah, we could do a whole, we could do a whole half hour on that one, but, right, because that's what, again, supply chain forces you to go through all the steps.
And they're not infinite. And in our entire industry, for my, you know, decades of doing this, we're addressing the firewall. We're coming up with one thing at a time.
That's a good idea. It needs to be done. But putting it all systemically together, doing the dirt, gently, holistic detective agency, inevitably curve sort of thing takes a long time.
But we're getting there. And, and supply chain is one of the things that forces us to work through each of those steps where we find we have, I think we have workable answers at each of those steps. We don't have the workable system that ties it all together.
You know, I, as much as I'm all about software, supply chain security and, and think that that's critical for us to do, seems to me that though, that that's a step along the way to zero trust software. Let's learn the lesson from security, right? We can firewall things off, we can protect things.
Um, but until you're in a world where I don't trust any software that's part of that I'm building software from, and that's, that's the attitude you have to have of, you know, just because it came from Google doesn't mean that I trust it or just 'cause it came from this repo. And I know the repo said that they are gonna secure. It doesn't mean that I believe that it's, it's secure.
It's sort of the old trust but verify. Maybe it's don't trust and also verify. That's the whole zero zero trust model.
And I think that's ultimately where we have to go to, to be able to, to secure This. So my, my problem is though, and this is, this is the problem in security. If security is too much of a pain in the ass, no one wants to do it.
And is what you just described too much of a pain, PIA, 'cause if it is, it's not going to get done. And maybe that repo firewall resides not at the repo, but at the gateway to my supply chain. But somewhere you need, look, I'm, I'm a child of network security, that's where I, I got introduced into security.
It's all I know, Right? But, but that's my point, Alan, is, is just knowing that you go through certain certifications or you fill out my questionnaire that says that you follow good security practices still doesn't mean something can't happen. Something Can get into No, I want that.
I wanna scam that. So you have to, the zero trust, I gotta be able to defend, defend against wherever it comes from. Well, I gotta be able to test whatever I'm taking down.
I gotta be satisfied that it's Legit. I'm act, I think I'm actually making the point you're making, okay. Which is zero Trust.
Once again, Mitchell, you and I are in violent agreement. Thank you. Absolutely.
Hey, hey, Lisa. You know, as you listen to this conversation and you got all these guys talking about security, I'm just reminded of that phrase that says, you know, every company's a software company and I have a really warm, fuzzy feeling right about now. Yeah.
Yeah. I see two parallel paths here on the marketing side and the learning side. On the marketing side, any company that's a software company needs to be able to explain because trust is currency with its customers, how they're sourcing software, that it is secure, that they can guarantee that.
And then on the learning side is this for developers and organizations to be continually educated about all the things that are popping in, whether it's from a Lazarus group in North Korea or other bad actors because the cyber attack landscape is spreading. So amorphously, I really see two parallel paths on the, on the educate, well continual education side that the marketing side as well. Because consumers need to understand that what they're downloading, the apps they're interacting with, for example, even if they don't understand the technology, that the data secure it's, and, and is kept there.
And that's something I think is a huge challenge for any organization these days. Seems to me software should come with a warning label. Oh, it does.
Yeah. That's the yes form. You can't tear it off.
It's a federal offense, Just explicit lyrics. That's all. Yep.
Well, you the sort of, there's sort of three phases, right? You know, you know, in each of these things, as we're all saying, we've all been aware of this, we issue forever, right? You can mandate something when it's impossible and nobody will do it because it's impossible.
You can mandate something when it's possible and enforce, you know, or, you know, whether internally Manding firewall in 1990 cost a hundred, uh, million dollars a year, right? And there were 10 or a hundred of them in the world, mostly internally. Many organizations, you know, said, this is worth it.
This expense is worth it for us. Um, but at a certain point, by 2000, if you don't get a firewall, you're going outta business because you're losing money. And I think this, as I said, I think right now, if you are mandated internally or externally to really secure your supply chain, and you really should, you can do it.
It's expensive. It's a, it's a cost. But I think we'll move fairly rapidly as these things go into the point where if you don't do it, your, your costs are higher.
'cause a lot of benefits other than, other than security, logistics and management, knowing where your stuff is and spending less time and money running your world is when security really gets adopted. But it's not a burden. I think we'll wait and see on this.
All right, let's take a break here on this one. We're gonna come back and we're gonna talk about serendipity is a strategy. I know Lisa's been waiting the whole show for this.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
All right, we're back. And we're talking about serendipity, which in my mind at least is a happy accident that I discovered something and it was all not pre-programmed, but here we are in the age of AI and some of those social media folks talking about using AI to well, program serendipity. Lisa, walk us through how this works, because in my mind, these are conflicting thoughts.
That's a great point. It, it's a bit conflicting in terms of the use of the word serendipity and what it means in real life. But you picture this, you're scrolling through Netflix or Spotify or any sort of streaming service.
You're not sure what you're in the mood for, and suddenly a movie pops up or a song or a playlist, and you just think that's weird. But yes, that's what I want right now. That's what's known as AI powered serendipity, where it's using multimodal machine learning and taking all these explicit and implicit signals.
You are giving the service to surprise and to let you in, hopefully a non-creepy way. So what it's doing is it's looking at different data types, textual data. What are you searching for, um, in your search queries, for example, uh, visual data.
Are you pausing? If you're watching Netflix, for example, are you pausing or hovering over certain thumbnails? Maybe you're a big fan of, of beach scenes in movies, and you pause on lots of beach scenes.
So it's starting to get those implicit signals to be able to tailor the experience for you. And then it's behavioral data combined with the visual, visual and the textual to understand what you're clicking on, what you're scrolling on, that sort of thing to give you the idea is this really hyper-personalized experience that's gonna deliver something that surprises and delights you. But what we have to be concerned about is ai, algorithmic bias.
Algorithms used to be deterministic. If you like, a, then you'll probably like B And now we have all these other signals coming in, taking note about what we're doing, how we're interacting with an app, for example, to serve up content it thinks we might like. But we have to be concerned, any company that's using this, and companies already are, I think have to be really, really explicit with their users, because trust is currency as we talk about all the time.
And if you're, if my data about what I'm hovering over is gonna be used to help me, I want to know that as a consumer at any sort of product. So data privacy, I think needs to become much more transparent for any organization that's gonna be using AI to surprise and delight customers in this serendipitous way. How far will this go?
Because, um, it's not just me. I mean, I'm friends with Mitch there, and if the machine knows that, you know, he likes Batman, suddenly I'm gonna get all this weird Batman s**t from him because we're friends and, and all these groups that we're in kind of send a signal, right? Yes, They do.
Those are more signals that are coming in that the devices, the software is interpreting. We talked about this the other day with Alexa and all the things that it's doing and sharing from a data perspective, like people in your household, people, you, your friends with email addresses. So the, the concern there is how do you stop this spread?
How is it contained in a way that is applicable to this end user only so that they get an experience that is delightful rather than creepy? Um, I don't know whether those li I think those lines are blurred right now. I think we're gonna see more of that, because I don't think, I mean, right now, you, you look up something on your laptop for a product, and then it appears all over your social feeds that you're scrolling on your phone through, um, are, are our friends and associates and people that we have text threads going to get similar information.
I think it's highly possible, and it's probably already happening. Well, first of all, Mike, you should be watching more Batman, but that's, that's for another conversation. Um, your life would be much, much enriched.
But anyway, um, yeah. So we're talking about, just if you wanna combine the two topics, serendipitous is sort of happy accident is, you know, my unsophisticated definition of it. Um, and, and that's what machine learning is doing, is in essence it's taking and doing rich analysis around, uh, user's behavior.
And it's doing that, of course, on large amounts of users. So what it's doing more than just correlating this video is tagged as a cartoon character, comic book character, and, and it's Batman. And so is this over here?
So let's suddenly start showing you Batman clothing or something, or, you know, trinkets. Um, it, it's really looking at the behavior of the user. And so that can take into a lot of factors.
It can take in time of day, it can take in more recent patterns, can take it, take into account historical patterns. Um, it can also take into account other people who have similar patterns that you do that you may not share exactly the same thing with. And learning from your reactions to what I think might be a serendipitous behavior.
So popping up that Batman reference might be, yeah, that's very cool, or no, that sounds like Mitch and I don't like his stuff anyway. Um, but you know, it's part of it, it's, there's a, uh, sort of a fine line between personalization and creepy, right? At one point, is it okay who, you know, who's watching right now?
How did you know that too? That was really great. I really appreciate that.
That was super valuable. I'm glad it happened. So Chris does this, Chris, does this not feel like a recipe for the perfect online scam and a little social engineering, and I take all these signals and I kind of send you something that's like so spot on you, you just can't help yourself?
Well, on that thread, I mean, this is going on right now and has been for a while from the Cambridge Analytica, you know, dust up to, uh, to today. The issues are the same, right? The same tools we need for marketing demographics, right?
You know, as a vendor, you know, I don't wanna spend extra money on advertising and marketing and outreach because my, my competitors don't, you know, and I do the all go business, right? And has been true since the dawn of time. You know, you know that on a stormy day 50,000 years ago, that everybody gathers by this rock, and you have all this raw fish you would like to, you know, trade for things.
So you, every Friday you're there. You, we know these demographics, you know, the, the, the, the, as you say, downside of this, this is, we are and have been open, and not just open, but actively exploited by malicious actors. You know, we using nation state resources down to the individual level.
You know, this is another path down, you know, part down this path. You know, the risk for exploitation, further exploitation, the, the sort of nightmare scenarios are unacceptably high. You know, again, my, my hope for this one is that as this, you know, I, I think we're already, we're already there, right?
At peak, creepy, uh, the creepiness factor will be enough to drive the necessary and entirely possible adaptations from a security and privacy perspective. So that begin by reducing the creepiness factor, reduce the actual risk of malicious exploitation. I think some of it's in the delivery too, Chris.
'cause if you can imagine, if it's something you trust, like let's say you do have a bot that personalizes things for you and says, Hey Chris, I found this really interesting reference. I think you might like it. You are like, okay, okay, I know who that is.
I know that even though it's a bot gave it to me versus suddenly this popping up in my feed. And like, how the hell did it know that, you know, a lot of it is, is the delivery or the source of what you, would you view the source of how that got to you? Yeah.
Well, You only, you think about it as, you know, AI's gonna give us assistance, right? Everybody gets an assistant, they get a staff, which is wonderful. But look how this plays out in a really effective organization, a good, uh, corporation.
You got the CEO for example, sitting there and all these people around him helping that person make decisions. Then the negative version, you have some royal court where the monarch at the center can't actually see the real world anymore 'cause they're surrounded by sy defense and corruption. Well, This sounds Familiar and right.
So yeah, this can go either way. It does go either way, right? It can either be very helpful or it can be its own disease.
Lisa, lemme wait. Lisa, Chris used the phrase, I just wanna check in with you on this, Pete. Creepy in there.
We're at that point right now, I mean, I just heard a bunch of marketers say challenge accepted. Oh my dear, oh dear. Oh my beer.
Exactly. The line, I think between hyper-personalized, delightful experiences and creepy is so thin. It's, it's blurry.
But I think it's, I think it's a dotted line right now. 'cause we're seeing companies already do this. We're seeing organizations in media, entertainment, social media, for example, hospitality already using multimodal machine learning in this way to be able to deliver these delightful experiences.
But any marketer would need to be aware of how are we doing this? What are the outcomes that we're delivering? And can we explain the, how we're doing this to our users to maintain their trust, to show them it's not creepy.
There's no algorithmic bias happening here. That's a huge job for any organization. Marketing can take the charge there because that line is so dotted and maybe very sparsely dotted at this point between relevant, contextual and creepy.
So here, I, I have a bright line for creepy, right? It's one thing to use machine learning and AI to say I'm in the Batman Club. So I probably like Iron Man too, though.
That's a DC to Marvel thing. Maybe not, but you know, it. So it's one thing to, to gather my, what groups I belong to on LinkedIn, Facebook, what have you, who people I follow on Twitter or whatever.
It's another thing. And, and then present products or things to me based upon that. I, I, I get that, that's part of the thing.
And I don't think that crosses necessarily. The creepy, creepy is when I'm talking to my child or my wife about something and I get a popup for that thing. And this is like the Lisa, if you remember, I think it was last week or the week before a case was started in California against Amazon, that they were listening in.
Listening in is creepy message to marketers. Don't be listening in. If I'm giving you permission to track where I go online, what groups I interact with, what banners I click on, I get what I deserve.
And, and you know what, sometimes I do get some very serendipitous kind of things that I didn't think of. I especially like it when they recommend movies or TV shows that I've never heard of that I wind up loving, right? I've caught a lot of those lately, but I don't like when they're listening in.
That, that to me is, that's peak creepiness. Creepiness, really. I completely agree with you.
So that needs to be a key message. We're not that we're not listening unless you're opting in specifically You wanna do that, God bless you. But you know, to me that that crosses the creepy line where I'm not gonna buy stuff from you or, or, you know, contribute to your creepiness.
Well, and, and this is where I spend my supply chain thoughts. 'cause yeah, again, as a vendor, if I was that vulnerable to that sort of, you know, creepiness, you know, crashing my market, it's possible that I would might go to this extent of saying, we will give you, you know, a trustworthy to a given, you know, high level of trust, little archive of everything we ever touch, touch, record everything right there, all the time in your hands, not in ours. That sort of thing.
'cause in, in, again, supply chain context, we have to have those things have to, in the near term future in certain areas to run anything as a, as a product vendor, serving consumers, you can put that sort of thing together. You just, you know, go over the fence. Not only are we not listening, we will be really absolutely clear with you.
Everything we touch everywhere we put it, why not? What do you have to lose? Maybe That's where we headed it.
Well, well, well, Jeepers creepers. I got all this email from Batman that I gotta go answer, so I gotta go. Okay.
Boy, wonder I'm Iron Man. Hey, we got it. We gotta go though 'cause we're outta time here on Text Drunk Gang, have a great weekend, everyone.
Um, stay tuned. Monday we'll be back with even more Great Text Drunk Gang and Text Drunk TV material. It's been, it's been a crazy week.
Here's so much going on. I'm telling you. This show is therapy.
Mitch, Lisa, Chris, Mike, thanks for joining us on The Gang. Thank you for joining us on The Gang. Stay tuned.
For the rest of Text Drunk TV is Alan Shimmel. We're out. Hello and welcome to the latest edition of the Techstrong AI video series.
I'm your host, Mike Biard. Today we're talking with JB Baker, who's vice president of Product for Scale Flu. And we're having a chat about, well, AI and energy and the environment and how might all this stuff actually come together.
JB welcome to the show. Thank you and great to be here. A lot of interesting promises have been made of late, including a Project Stargate, but every time I turn around lately somebody is pledging billions of dollars to go build data centers for these AI initiatives.
And I cannot help but wonder, um, are those things realistic? 'cause last time I checked, it wasn't so much that we didn't have enough or say power. We just don't have the ability to distribute it where it needs to go.
And so can we actually build these things? Can JB what's your thought on where are we on this adventure? Yeah, that's, uh, as I've been looking at this part over the last couple of years, um, yeah, uh, getting the power to the data centers is, is a tremendous challenge.
Um, and, you know, we see, uh, I've seen plenty of information about, uh, data center build out plans being delayed because they're still fighting through the regulatory issues to get local power plants put on, brought online or, you know, more power brought to the grid. So that is, uh, that's definitely something that has to be done hand in hand as we are, uh, as an industry planning out these, uh, these massive build outs for data centers to, to support the, the demand for AI and other compute functions. And how much do environmental concerns play in this conversation?
'cause every time we kick up a new data center, we've kicking off some carbon, but to what degree are the data centers contributing to global climate change? And how might that be more complicated than it already is? Yeah, I mean, data centers are depending, I see different stats, uh, but you know, they somewhere from, from high single to low double digit percentage of total worldwide power consumption.
So they're a, you know, a massive contributor to the potential for, for carbon, uh, you know, emissions. Uh, I know that companies like, you know, some of the major hyperscalers like Microsoft and Amazon and, uh, meta and Google, that they have renewable energy initiatives to try to make their data centers net zero or, or or negative in terms of total carbon. Um, so those initiatives are there.
Uh, I, well, it, it's kinda governments are are playing in that as well. You know, the EU seems to be a little more aggressive on pushing for, for those, uh, carbon neutral and, and carbon improvement, uh, capabilities and then other GOs that we seem to go seem to push for it and then back off and push forward and back off. So time will tell on that.
It's hard to say where we're gonna be in by the end of the decade, but, um, there's a lot going on here and not to mention the least of which is we are gonna see new classes of processors, right? Not everything needs to be a GPU to run these models. So will we get more efficient in terms of the infrastructure that we're deploying as we go along?
And will that make a difference? Yeah, that's a, that's a great direction. I mean, efficiency is crucial to, uh, to meeting the demand that we have, that this massively growing demand for the compute and the data generation, data storage, data movements.
So, uh, yes, absolutely generation over generation, the individual components are becoming more efficient in terms of how much work they can do per wa you know, it it at scale flex, we've, we're focused in the storage and memory domain. So like within our components, every generation is, is being able to provide twice the amount of performance, twice the, the throughput of data transfer, uh, per watt of energy consumed. And if you listen to the NVIDIA keynotes, um, I don't remember his exact, uh, jenssen's exact percentage or, or number of, of improvement there in terms of, uh, flops per watt.
But every generation of Nvidia, GPU is massively more power efficient, though they're also massively more power debts, right? You're, each processor is consuming a lot more power, but they're able to do, say multiple times the amount of work per p per watt. Uh, and you're, you're definitely right there on, it's not just gonna be, uh, the general purpose GPUs, right?
That's, um, the, the Blackwell and, and that class of product. Uh, 'cause just as if you, if you look back several years, we, there was, uh, a migration or a fragmentation of the, the general purpose processing capabilities. You know, you had the X 86 processor as kind of the standard in the industry, right?
But then graphics processors came online to handle specific tasks in a much more efficient manner. The same thing is starting to happen already, even in the the GPU segment, even for ai, where you're gonna have, rather than just general purpose GPUs, you will have, uh, LLM specific GPUs. You will have inference specific GPUs and other types of tasks.
You're gonna have processors that are optimized for that, for those tasks. Uh, a couple of examples already. You see meta investing in their own, uh, internally developed processors that are focused on what they care about most.
The LLMs, uh, GR as well, uh, offering GPUs that are more focused. And their claim is that they're able to handle the LLM like a chat GPT, um, request much more rapidly than, and much more efficiently than general purpose GPUs. So you'll see that fragmentation to enhance the efficiency of the processors.
And then other components in the, in the industry are gonna have to step up as well. I mentioned the storage components becoming more efficient. Um, there are innovations in the memory domain to allow for more capacity and more bandwidth of memory attached to each processor, um, or each core within those processors to ensure that those processors are fed with the data that they need to be productive with all of the energy that they're consuming On the software side of this equation.
Not everyone in these AI models is the same, and some of them are gonna be smaller than others, and others are gonna probably be even larger than the ones we have today. So, yeah. Um, can we, how does that spectrum kind of play out in your mind when we see more smaller ones in the future?
Or, you know, people are talking about, uh, make an AI smarter, which might in involve some really huge language models. So where, where are we? Yeah, I, I think you're gonna s you're gonna see both ends of the spectrum, right?
You, you will see that the massive LLMs will continue to, to grow larger. Uh, there's plenty of, of graphs out there of, of the doubling of inputs or the, the exponential increase in the amount of data that gets put into training that next model to make it more generally intelligent and more generally applicable. Uh, but at the same time, you, you're gonna see things where, hey, I don't need to have, uh, my model be able to answer every question and act like every different type of profession.
Maybe I need my model to act as a, a patent lawyer. Uh, and so that dramatically constrains the, uh, the scope of the inputs that you need to put in there to get to that same level of accuracy or, or value out of a model. So yes, I, I believe you will see more and more of these, uh, very focused models that, uh, that people will be able to, to train on much smaller data sets, and then those will be more efficient in their searches and their res their responses as well.
Do you think all this AI concerns about energy is also gonna wind up becoming a political issue? Because as the data center folks increase demand for electricity might exacerbate a limited supply and the price of electricity goes up and suddenly, you know, all the local neighbors are up in arms. Yeah, I'm, I'm gonna, I'll try to shy away from anything, any true political statements, but, uh, the absolutely, it is a challenge and, and the, the knot in my backyard or, or nimby, uh, perspective will come into play.
Uh, I mentioned earlier you're already gonna, you see that already, particularly I saw a lot of information about in the Northern Virginia arena where there's sort of a data center alley and they're struggling to, to provide enough power there. So, um, in order to awash that concerns about data center power consumption, pre putting pressure on the grid, and raising overall power rates for you and I as consumers in our households, uh, there is definitely gonna have to be a, uh, a hand in hand plan of, Hey, as I, as I pro project putting out this, uh, this data center, I'm gonna bring online additional power. Uh, you know, you see like the, the three mile island thing be where three mile islands will be brought back up to provide the, the data, the power to, uh, supply.
I think it was Microsoft's data centers that they're building in that region. Um, and then even in the Stargate, uh, the proposed data center that Ian, Texas, that's gonna be, um, what was it, 360 megawatts, that they are co-planning power, uh, generation facilities to, to provide that power. Uh, 'cause otherwise that's 90,000 homes worth of electricity that you're, you need to supply.
And I don't think there's that excess in the grid as it stands. We also see people talking about various forms of green slash clean energy. And some people wanna build, uh, many nuclear reactors that are essentially dedicated for data centers.
I'm not quite clear how those things work or how feasible that is, but how much can these alternative energy sources make a difference? Uh, it can make a huge difference. And, you know, there's not one magic pill or one panacea for solving this energy.
Uh, de demand. It has to come from multiple sources. Um, you know, I, I have, I have seen many initiatives from like, like the hyperscalers in the US where they're, you know, they're combining geothermal with, um, with solar, with localized, uh, fossil fuel based, um, energy, consum, energy, uh, creation.
And as you mentioned, the those small nuclear reactors that are gonna be more sized specifically to provide the, uh, the electricity for those power for those data centers. That's another aspect of the solving the, the, the total, um, supply. And even the going, going back many years, the location choice for where you put the data centers, um, you know, they've, they've chosen colder environments in many cases so that they could leverage just the, the natural environment, uh, to help them with the cooling.
So absolutely, it's gonna require many different types of power generation, uh, to, to help minimize the, the carbon footprint that gets put in place. But what impact will all this have on the cost of ai? If the price of energy is significant, and I have all this infrastructure that's out there, is AI gonna get any cheaper?
Or is it maybe actually gonna get more expensive? That is a, uh, you know, a lottery question, I guess. But, um, you know, in terms of the, the cost of performing an AI task, I, I can't, I can't wager in any direction other than that will decrease, right?
The, the cost of, of performing a, a chat GPT task or, uh, doing, uh, uh, as Jensen referred to it as the, the virtual factories of modeling, you know, how should we set up our warehouse or, or, or testing these models? Tho that's gonna come down, absolutely. But that does not say that the investment levels in the amount of dollars that are poured into generating AI capability would decrease.
I, I still see that as that's, that's on the rise. Because as we, as we decrease the cost of, of performing an individual task, you know, just following economic, you know, supply and demand, we will find demand in ways to, to consume that. And we'll find more and more complex tasks to put out there to, to utilize still those large clusters of GPUs.
So what's your best advice to folks as you kind of look at all this stuff and they all sit there and kind of try to figure out their own plans, but, um, should I just like pick a handful of projects to focus on for the short term and, or am I, is it just gonna be, you know, pedals in the metal and here we go? I think, you know, that's gonna vary quite a bit by, by industry and job function. But, uh, but absolutely, you have to be finding ways and looking for ways in which you can leverage AI to improve your organizational efficiency.
Um, you know, it, those who don't will fall behind, will, will be falling behind. Um, you know, and even as we look at, uh, you know, from my perspective as a hardware component and, and software, uh, developer company, we have to start leveraging AI in the, uh, the development of our next generation components. Um, and leveraging AI to help us accelerate the, the generation of code and generation and testing of the code.
Um, that's an area that I, I personally, I believe that there's a, there's gonna be a, a tremendous value there in terms of being able to test, um, and find the bugs and find the root causes for child problems in, in hardware, uh, and chips as well as in software. Um, 'cause having been in this industry for 20 something, uh, years, then, you know, I just re I think back to all of the problems that, that we had as, uh, not just scale flux, but at Intel and LSI and other companies of finding a bug in the hardware and fixing it. You know, what is that root cause for that?
Something that appears so, so, so infrequently, it, it's hard to recreate the conditions. And AI with these virtual factories has the potential of being, making it where you can recreate those, uh, those conditions much more rapidly. Hey folks, the genie's out of the bottle.
I'm definitely not going back in. But as is always the case, you gotta be really precise about what you're wishing for or may not turn out exactly how you imagined. Jv thanks for being on the show.
Great, Thanks. Appreciate the time. All right.
Thank you all for watching the latest episode of the Techstrong AI video series. You can find this episode and others on our website. We invite you to check them all out.
Until then, we'll see you next day. Hello, and welcome to the digital CXO podcast. I'm Amanda Ani, and with me today I have Doug Steven, he is the president of CGS Immersive.
How are you doing today? I'm Doing really well. How you doing, Amanda?
It's, uh, thanks for having me on. Yes. Happy to have you on the show.
I'm doing well. So tell me a little bit about CGS. What, what services do your, does your company provide?
Uh, so CGS has, has been around since actually 1984, privately held, located in, uh, in New York City. Got 8,000 people across, uh, all the continents, with the exception of Antarctica. Primarily involved in, in developing, uh, enterprise learning, as well as, uh, A BPO support.
And we've got, uh, an application for the fashion industry. But my, my specialty is on enterprise learning and creating tools that will, uh, make an impact on our clients. Presently working with about 89 of the fortune of 500 companies.
So, uh, it's great, this tribal knowledge that we actually learned from them. So a lot of great stuff. We're working with great companies and, and, and we learn a lot from them, and we package together to, to make solutions that's, uh, for the betterment of all of them.
Wonderful. So today's topic is new innovative technology and how it's helping with learning and skill building. So can you share a little bit about some of the tech you're working on and some of the technology that's making an impact in learning?
Sure. So, um, you know, we're, we've, we have the pleasure of being involved in technology, but also our pedigree is learning. And in a lot of cases, we've seen a lot of technologies come outta there, um, that, uh, are great for technology, but not for really retention.
So we, we've been historically been involved in, you know, process and technical type of training, and we've always wanted to dip our toes into, uh, role-based, uh, soft skills, human skills training, is what they now call it. Uh, but we, we always thought that, um, we don't know if, if we could do as well as we should, as we did in our other different, uh, areas that our expertise four and a half years ago, we became part of the OpenAI Foundation. Uh, that was a hallelujah moment for us because then we saw the advantage of, uh, you know, combining ai, uh, into learning to make a significant dis difference.
So we created a product called Cicero. And, and what's advantageous about this, it was born on ai. Uh, it was literally grab, built from the ground up on ai, and it's number one goal is to create a role playing in businesses as well as coaching.
We're pretty excited about it. That's awesome. So, um, can you share a few use cases where, where it's, uh, making an impact?
Yeah. So just to back up a little bit, one of the things that we found, uh, we pulled our, our customers is that 86% of the people thought role playing was very, very critical, um, in, you know, in really enhancing the skills of people. Um, but when we ask 'em if they really like to do it, it dropped to 38%.
'cause they, it won't be embarrassed in front of their peers, right? So then we said, um, you know, role playing as itself is, is very expensive. Uh, especially you have to get a peer, you have to take them off their job, they have to take time out to work with it.
And, and really only from the director level up would be able to have that experience. And we said, let's look at the democratization of skills acquisition. And what I mean by that is, can we bring great training down to frontline users and make it affordable and make it so that it's attainable and accessible?
So what we did is we, we created Cicero and it's really, it's, it's really claim to fame is a person can practice safely, don't have to be embarrassed. Um, they're not gonna be judged wrongly because the person on the other end had a bad day. If the computer has a bad day, it goes down.
So it's, it's one of those days. And second of all, can we empower the people in the companies to create these, um, role playing scenarios without relying on technology companies to do it? So there were the big three, and could we do that in multiple languages?
So we created it, and one of the things we, we said is, let's be broad based, meaning let's empower our customers to create snares. They think best. And I, I can tell you, uh, we're dealing with one of the largest, uh, medical device companies in the world, and they're presently using it.
And it dropped, um, it, it increased the success of their salesman in the surgical sales because they were able to practice when they're dealing with the COOs and the surgeons at these hospitals, they can practice against those type of personas and be very successful. So, just little things. We're working with a blood collection company where they, you know, have to have difficult conversations with donors.
You know, some of them, you know, can't give blood or you have to tell 'em they can't give blood for six to eight weeks and they're volunteering or taught, you gotta be, you know, these are ways that become difficult conversations. Uh, to be able to practice that safely and to be able to judge on the fly is something that we thought was very, very important, and that's why we created it. Awesome.
So we talk about how AI can be used, uh, for learning. Um, and I think about, there's a lot of different ways, but I think about most recently, I had a conversation with a friend and they said that someone came to a job interview and they just absolutely blew it. So I think that this could al also be used for helping train people for interviews.
It's funny you mentioned that. So we, we have a component called, uh, called Cicero interview. And then what's interesting is, um, a couple things happen.
The job description is posted. People, um, submit the resumes against the job posting, and the companies that are praising it have these scales of what they think are best. So now the tide is turned where the avatar is now asking you questions, and it's gauging against, it's looking at your resume.
It's where saying, if you have six years, you can calculate the number of years, it can ask you all those questions. And it can become really important when it's, say, technical architects, where now it can ingest all, say the coding of PHP and ask them technical questions and see how well they do on that. So it, you know, and people can practice this without being embarrassed.
That, that to me is really, you know, holy cow. You know, one of the things we were talking about, uh, there's a lot of people that you meet that you don't wanna meet in roleplaying, but you will meet them. And you just can't go to your peer and say, you find not all people in your organization are bad people.
They're great people. So it's hard to get someone that's really tough this way. You change the persona to as aggressive f you want using the five different personality forms.
Um, and now you're into a real difficult conversation. And if you can overcome that, then you know, you have a really great chance to be successful when you face the people. Now, it's not the be all for all of it.
Like we, we still look, we look at this as complimentary to, to a lot of the different tools, like the little nuances that you get when you're seeing a human to human interaction. But this really is fantastic, uh, for getting people prepared, at least to the last level. Absolutely.
I always say communication is key. And if you're able to develop your communication skills to handle any personality type and know how to have a good conversation with them, you will get far anywhere. I feel like, You know, it's, it's funny you say that because, uh, uh, there's been, there's been such a push on, on, you know, technical skills and then when the pandemic happened and people were, were doing Zoom and back and forth, and, and that whole interpersonal skills and communication, I think took a blip.
And, uh, it's, it's hard, uh, for people. A lot of people say, I just wanna do it on, on the web and don't wanna face 'em. This is a good prep for it.
And, and that's where we see that, um, these technologies can be used for the betterment. And it's, it's really just to go as to an aside on that, you know, a lot of people are nervous about losing their jobs. And we're looking at, in our industry, it's the instructional designers and we're saying, but now an instructional designer can spend time on what they think is the best scenario to create versus the creating a bunch of tools or a bunch of different pages.
Now they can think of, you know, pedagogically what's best for my company, versus, oh, I gotta get storyline and put this thing together. They can spend quality time on what's right for the situation. Absolutely.
So kind of, um, bespoke for each company exactly what they need. That I, I'll have to remember that. Yes.
Yeah, it is. 'cause that's what we said is like, everyone says, well, you know, are you gonna go into the farm industry, the customer service? And I said, obviously, but we don't know that business as well as the business themselves.
Why can't we just empower them? And if, if they know how to write in Word, they can write their scenario and let, and what we do is AI takes a look at all the documents they have in their secure folder, and if they give PDF, it can be videos and, uh, you know, the ID writes a paragraph or two what they want, then let AI create the scenario for you, and you edit it. So within 15 minutes, uh, people can start testing it.
That's fantastic. Well, you know, technology is advancing quite rapidly. Where do you see the future of this technology, say a year from now?
Holy, I mean, before we had runways of one in three years. It's, it's weekly. Um, it's, the change is frightening.
And I think, um, you know, you're, you're going to see in a lot of cases the, the combination of, of not just ai, but now the combination of, of ar where you'll be able to, you know, drop your digital twin assistant into your own office and do that type of practice. We're seeing some of our great partners, what they're doing is they're actually connecting, uh, Cicero to Salesforce to get all the data on a particular, say, physician. So now not only are they not practicing against physician, they're practicing against Dr.
Smith. Now you then have a hologram of Dr. Smith, you have his voice.
Now all of a sudden, this is as real as you're gonna get and it's gonna come. It's a, we're doing it now. Um, but it's exciting.
But it's, it's, it's a little scary sometimes when you see just how quick change is coming. It's, and I'm an technologist. I mean, I, I see it, I say it's, uh, it's an interesting time that we're in.
Yes, it definitely is. Well, if there was one key takeaway you could leave our audience with, what would that be? The most important thing is embrace it.
There's always going to be, there's always trepidation of, of change. But those early adopters who take it, embrace it and look at it, will become the leaders of tomorrow. Period.
Yes, indeed. Well, thank you so much for coming on our show and sharing your insights with us. Thank you, Amanda.
I appreciate the time you gave me. All right. And thank you to our audience.
Stay tuned. There's more. Hey, everybody, this is Mitch Ashley, welcome to DevOps Dialogue.
This is the podcast, the interview where we talk to the most interesting people about topics that are really top of mind. So we're, I'm very pleased to have, uh, Medi Dowdy, who is co-founder and CEO of Catchpoint joining us. Good to be talking with you again.
Thank you, Mitch. Thank you. Happy New Year.
Good to see you as well. And thank you for having me. Absolutely.
Happy, happy 2025. Good to see you, me, Medi and team. Were at the tech field, Dale events.
I think you're gonna be at some more if you're having tuned into that. Be sure and do that. Some great content there.
So it was interesting this morning I was having this conversation about, we're a wash with data, but we're not a wash with information. We have a lot. And that's probably true.
I'm guessing from a, from application performance monitoring standpoint. I, I know there's a lot of lights, but who knows what that all means, right? When something's blinking or that's not blinking, which give us, give us, first of all, tell us about you and, and, uh, Catchpoint, and then we'll dive into how do we deal with this and a little more, uh, holistically.
So Mitch, thank you again. So my name is Mary, a co-founder, CEO of Catchpoint. Been, uh, launched Catchpoint in 2008.
So we've been at this in by 16 years, almost, uh, worked at DoubleClick and Google where I was in charge of actually monitoring. So I was on the buying, building, deploying, and using the tools to, to keep, uh, uh, the ad technology system that, uh, DoubleClick was known for alive and performing super well. And, uh, I love monitoring, uh, whether we call it observability monitoring, et cetera.
The reason why I love it is because when we do a good job, um, you deliver better services, you deliver, you have better outcomes, and then the monitoring becomes an enabler for running a better business. And that's what I saw firsthand. Uh, and I was very proud of being part of that, of creating what often is called a culture of performance, which is like, Hey, how can we be the best at doing what we do with the most reliable, the most available, the most fa the fastest, et cetera.
And so, and uh, throughout that journey, of course, we learned a lot of stuff. Uh, which is one of the, for example, you, you mentioned it is too much data, right? The data overload, uh, because as humans, uh, we go through some kind of outage and we regret that we didn't have the right data.
And so the immediate, uh, knee jerk reaction is like, okay, we're going to log everything now, right? And we're going to log, but nobody for, nobody thinks about how much going to cost. So then there is usually A-A-C-F-O coming down on, on you and saying, okay, you just spent like x number of millions of dollars on storage just for the monitoring system.
But the other thing is like, it's, it's, nobody knows how to interpret the data. The correlation, the causations, the connecting the dots becomes even more, uh, difficult to make, right? So the more data you have, the more cardinality you have, the more like, I don't know, what am I looking forward?
And, uh, and so I was just on the phone with the customer earlier and literally the, they were talking about how, you know, we went from looking for a needle in a haystack to looking for a needle in haystacks. Mm-hmm. And, uh, and so more data, more silos, more people, et cetera, can, can lead to prop.
Now the bad thing is like, it takes longer to that detect a problem, identify a problem, and resolve it. So I think, uh, I think we're in too, for some recalibration of that. What I talk to customers is they're trying to figure out a solution to end that either through, uh, you know, of course, uh, wouldn't be 2025 without throwing ai, but those are the kind of tools and capabilities that are hopefully going to allow us to go through a lot of data faster, and then maybe helping us connect the dots better.
I remember a day when we used to say, the best way to provide the highest qualities don't change anything. Well, that's not, that's not even possible. It's all changing.
It's like, you know, it's no longer a solid, it's a fluid, it's under constant change, different, And even if you don't want to change Mitch mm-hmm. The internet is changing. Your, your third party providers are changing.
Amazon is AWS is making a change, GCP is making a change. Your SaaS applications all. Exactly.
And so how do you get ahead of that? How do you, how do you keep up with the constant changes? And oh, by the way, you can't go to the principal's office.
I say, well, it's outside of my control. I'm not responsible for availability, performance, or reliability. You're still in the hooks, right?
I can't point the finger and have that me make any difference. Well, so where does a PM kind of end it's usefulness, it's useful life, and then how do you fill in that gap? I mean, I remember a PM was, oh, good, I can have some w servers out on the internet, load my webpage and measure them how fast it loads it, right?
We're in a much different world now, but yes, I mean, a PM that even means a lot more than that. Well, I, first, I, I think, uh, uh, what I usually tell folks I talk to, especially on the customer side, is, you know, terms, terminology sometimes can be limiting in the way we look at things, right? Mm-hmm.
So if you think of your house as your application, you have valuable stuff inside. You need to secure it. You need to make sure that you have your humidity monitors inside the house, et cetera.
But then you also need an alarm system. You need to, you, you need to make sure that, uh, can, can, hopefully nobody can get it. Um, so, so thinking about that from, from that perspective allows you to say, okay, what pool do I need to get the job done?
And the job is very simple. You need to be up, you need to be fast, you need to be, you need to be, uh, available to all your customers, right? So if you have users that are worldwide, you need to make sure that whatever tool you have or whatever perspective you have, is a, is represents what the end user, where your end users are.
Uh, and so, so I think it's first like walking backward. What are we trying to accomplish? What are the metrics we want to do?
Maybe say we need to improve avail availability, then what are the tools I need to do to, to do that? Uh, but a PM is still the best. Uh, and tools like Dynatrace and, and, and, and New Relic, et cetera, do a fantastic job at, at making you understand what's going on in your house, right?
Being able to understand when a, when a, somebody does a search, what database it's called, how long it took to query the, try to map the dependencies, et cetera. But the challenge becomes for some companies that, that rely on many, many other third party services who's keeping an eye on the internet stack, right? That the same way you have an application stack, uh, what happens to CloudFlare?
What happens if CloudFlare is having a problem? What happens if Akamai is having an issue? What happens if the network in India is congested?
Again, being able to understand all of that. So it's not, I, I think it's understanding what each tool does, right? Uh, I don't use my toothbrush to comb my hair, obviously.
Maybe I think it will work for me, but, uh, bad example, maybe. But you know what I, right. So it's like you need, you use the right tool for the right job.
Interesting. Yeah. It, it's a, it is a great point, and like your analogy, it's sort of like driving down the interstate.
I know my inside of my car is all looking good, but the road conditions can change drastically weather, correct? Yeah. So any things outside of your control really, essentially correct, is what a lot of that is.
Well, so talk about Catchpoint and some of the lessons you learned, you know, at, uh, at DoubleClick and at, uh, at Google that informed you of, okay, here's the next approach we have to take to answer the rest of the equation of what's going on in this picture. Right? So, very fortunate enough to have been part of, of the beginning of the internet kind of-ish, right?
From the commercial standpoint in 97. And, uh, and so, and then Google, of course, had a super, uh, focus on the end user, right? So if you think of Google, you think of that, that search page that needed to load in, in Subec subsequent.
And, uh, and I think that set the stage for the, the whole concept of like, everything needs to be available. And Yahoo too. I mean, Yahoo spent a lot of time inventing a lot of the tools and the concepts that, uh, exist today.
So the end user is where it matters the most. It doesn't matter. And this is what happened to me at DoubleClick one day.
Uh, I walked into our knock, our network operation center, and I, I saw my team chilling and, uh, you know, as if nothing was happening, uh, and double click was broken. We were not serving ads, which are live a livelihood, but all the systems were green. Like literally all of our internal monitoring was showing, okay, uh, no network issues, no database issues.
The servers were fine, 15,000 servers were, were up and running fine, et cetera, but we were not delivering ads. And, and so that's where the monitoring is, like, what are you monitoring? Are you monitoring for an outcome or you're monitoring for CPU and memory kind of stuff.
Mm-hmm. And so that was my big aha moment when it came to, you need to monitor what matters from where it matters, right? Uh, uh, it's, it's, it's so critical and it does what, this is the philosophy that still drive us today.
So, um, and that was one of the biggest lesson is again, monitor the end user and monitor where the end user is. And then also, if you're an e-commerce, then can I buy something and add it to my cart and check out, right? If I am a sneaker company, can I, if, if, if every time I go and pick size 10 you have an error, then something, you should do something about it, you should first know about it and then fix it.
So I think it driving the outcomes monitoring, should you be here to help businesses run better, right? So align the monitoring strategies to the business outcomes. That's, I think, one of the biggest things I've learned.
And, uh, and when I see customers, some of the customers and partners that we do that for, it brings a lot of joy to, to me just like to see that, that causation between better monitoring, better observability to direct impact to, to, to business outcomes. It, it reminds me of the metrics we always create for our technical organizations, as, you know, meantime between failure or whatever it might be, or know these kinda responsive things. That's, they're all important.
Yeah. That doesn't mean the customer had a great experience though. Correct?
Because failure, we live in a world, failure's gonna happen. It isn't avoid failure at all costs. That's impossible.
It, it just, so much is out of our control, right? Talk, talk about, so how do you, how do you do this from the end user's viewpoint? So you really are measuring as much as possible, or you really assessing, I should say, the experience that you're delivering.
So with the concept of, we, we want to monitor from, from as many places as possible to simulate where the end users are. So that was one of the design philosophies of Catchpoint. So we do what is in the industry called synthetic margin, which is a robotic process of monitoring.
Um, it's like digital mystery shoppers, you know, mystery shoppers have existed for a hundred years, uh, where the digital version of it. So we have them, uh, located in the right cities, the right ISPs, the right carriers, the right telecom carriers, et cetera. And those things, uh, those machines, they do very simple tasks.
They basically simulate what an end user does, uh, and they do it across all the different stacks of the internet. So your DNS your network, your application, your APIs, your third party services, et cetera. And our job is to really, from there, help customers triangulate the problem.
So if you show up at your doctor, God forbid, tomorrow you're going to show up with a symptom, my head hurts. Great. A good doctor is going to go through, okay, based on what I see, let me see if it's this, that, or whatnot.
So monitoring and the data that we provide that needs to help the customer go through that triangulation as fast as possible so we can reduce the meantime to repair. And so what's also very important in our business is the data quality. So we focus on the data quality, the signal, what we call the, the signal to noise ratio is very, very important because you don't want false positive, right?
I mean, no hospital can deal with like people ev showing up at the hospital every time they cough, right? That you have to have fever, this, that whatnot. So, so it's very important for us to deliver the right qual, the right metrics and the right quality to be able to drive better triangulation.
So that's one thing we do. The other one is we married, we enrich the data with other things. So for example, synthetic and run.
So real user monitoring, um, fantastic, uh, uh, vast way of, of answering the question. So what, right? So the robots say there is a problem in Saudi Arabia, Ram should be able to say, oh, yes, holy cow, it is a big problem.
And oh, by the way, we dropped by 30% of the traffic. Uh, so again, it's like, how do you put all these things together, uh, in one dashboard, et cetera, to answer the question, what's broken where? And whose fault is it?
Right? Is it us? Is it the internet?
Is it, is it a particular third party? And all of that needs to happen super, super fast. You know, we do this SRE survey, we've been doing it for seven years now.
Uh, and I'm very proud of the work that team does. And this year, something that, uh, was very interesting that came up and his performance is the new doubt. Uh, so we went from like availability, and I've seen, we've seen that with some other customers where, you know, the, on the maturity side, they cared mostly about, am I up?
Are we up? Is the stuff up and running to now performance, meaning that after three seconds, even though the site or the application is up, it's actually down because the person, the customer is not willing to tolerate that. So the, the level of, of how much you're willing to tolerate slowness is going to be an indicator of, of availability.
Um, so again, how can we do all of this stuff as quickly as possible to customers can get to fix things as fast as possible themselves? Well, if we can wrap with the AI question. Yes.
On all of our minds, everybody's talking about agent ai. It seems like we're not very far away from synthetic users that are AI agents. And you know, a world of of, you know, I'm, I'm actually out there doing multiple things 'cause I've got agents Correct.
Or my business does. Is there anything that customers or organizations can do to kind of prepare for that unknown of what that future may look like? I imagine, I would imagine the more you understand an instrument and understand the experience that you're delivering today, as you add a new factor into it now, now you could assess how to manage it better or understand it better, versus, I don't know what I'm doing now that just makes it worse, Right?
So I, I think it's an excellent question. So, uh, let's, let's answer it two ways. So the first one is, what are we doing to prepare for a world where now there's going to be a combination of humans using the internet and then synthetic agents, right?
Uh, that are going to be also doing stuff like, uh, there, I was reading an article where Microsoft is, is allow you to create a robot to literally answer emails on Outlook without, without you doing anything. So, so I think that doesn't change the way we look at things, which is like availability, reachability performance, reliability are, are, are pillars that exist in an AI or non-AI world, right? I would say, I would even argue that in an, in an AI world, the tolerance for speed, reliability, et cetera, are going to go down and people, we, we need better, we need faster, et cetera.
So I think, I think that is a fundamental thing. Uh, the other part of your question, the way I look at it is when I talk to our customers and the SREs, the DevOps, et cetera, um, we're all trying to do our job better, faster, and be more productive and more efficient. Ultimately, that's what the, the promise and the revolution of AI is.
And so what we are seeing, uh, is we're seeing customers that have, uh, a more methodical approach to ai. It's like, okay, pick three problems that we want to solve, rather than like peanut butter kind of thing. Like, let's put AI everywhere.
So it's like, okay, what are the areas where we're having a hard time finding talent, we don't have enough manpower, uh, and let that drive, uh, uh, for example, either automation or whatnot. Uh, but on the monitoring side, et cetera, there is definitely some incredible efforts that are being led to connect the dots faster, better, right? Being able to pull all the data and solutions.
Like we're seeing a lot of that in Databricks where customers are pushing all kind of data into Databricks and then being able to connect the various dots at, at scale over there. And people are seeing some really good benefits so far is Databricks, snowflake, et cetera. I think that's one area where we're going to see a lot of stuff.
Now, the benefit of that, which is we're going to have less issues where people missed an alert, because I see that a lot with our customers. Oh, we, we got too many alerts, or somebody took a large break and we missed something, that stuff is going to go away, or it's going to supplement or, or, or augment, however you want to look at it. But I think that's one of the benefit.
I think that AI is going to drive better availability and reliability to, to, to a lot of companies. Uh, Well, very exciting. It's interesting time.
You live in interesting times up. This is one of the correct, funny funnest times in my career. Funnest is a word.
Yeah. Maybe, uh, tell folks where they can find out more about Catchpoint and learn more about what you all do and get engaged with you. Sure.
com. Obviously we're on LinkedIn, Twitter X, sorry. Uh, our blog is fantastic.
Highly encourage you to, to search that, uh, and, uh, read some of the content we produce, whether it's the SRE study that, again, 70 in a row, uh, uh, super impressive and or the reliability and resiliency report we publish. org. I'm sure some of your listeners, uh, know about WPT.
Uh, and, uh, so that's another free tool that, uh, that we have for the community to test your performance. So again, slow is the new down. So start testing There.
You good? There you go. You heard it from the expert.
Well, thank you Medi, it's great to chat with you again. Thank, thank you. And we appreciate everybody tuning in to this episode of DevOps Dialogue.
And look for me on another future room event or a Textron tv. He's around. We like having him on.
Thank You so much. Take care. Happy to you, everyone again.
Hi. So my name is Ape Shaw. I'm the senior partner solution architect at AWS, and today I'm going to use, uh, what is quite hot in the industry, which is how we can leverage the gen AI for the next generation automation and efficiency.
Um, and the answer to this problem is Amazon Queue developer, um, which is, uh, Amazon's product, uh, which helps, uh, the developers, uh, to, uh, do a lot of things. So, which we will go through in the details. So what is the agenda for today?
So we are going to start talking about why generative ai, uh, what is the need for the customers, uh, give you the overview of the service, what is the key features about the service, uh, some of our customers who have used this services, and how you can get started, uh, with the features of Amazon Queue developers so that this becomes part of your everyday work. So, um, we did a lot of analysis about this before launching this service, and what we found was that, um, a median developer spends only an R writing the code that is developing new features and, uh, getting something, uh, straight to the business, what they're looking for, rest of the seven Rs. He is either debugging the application, he is writing the comments onto the code, he is doing the unit testing or operation support and so on, which constitute a lot of time.
Yeah. So if you take five hours in a week, that is significantly low, um, uh, effort, which has been put into to develop the new features and new business requirement. So this is something which is quite important to understand because that's something which is what we are trying to improve upon.
So what is the key needs for innovating faster? We want to build faster, we want to increase the velocity so that in a sprint we can release more things to our customers rather than spending the time on the undifferentiated works, which is required as part of developing the software. Yeah.
Let the machine do the work, what is not fundamentally, uh, which, which can be automated. Whereas what requires a new features, which is where we want new developers efforts to be put onto. Yep.
Uh, a lot of, uh, time goes into the operations. So there is an efficient way to manage and optimize the AWS cloud environment. Uh, and we will go through into that as well.
Uh, there's a lot of transformation things. So basically, uh, you have a Java application, which is running on Java seven, Java eight, Java nine. You need to upgrade those to Java 10 11 17, um, uh, and so on.
Because there is a new fixes, there is a new security vulnerabilities. Your security team is behind you lot of this times, which builds up into the developer's backlog and enhance into the product backlog because the product need to be kept up to date. Yeah.
As well as you want to do migration from t net framework to t net core. Yeah. Uh, which is where you can run the Windows software onto the Linux platform so that you can get the business benefits, uh, get the license freedom, and you can do the ization and all the benefits which comes with it.
And last but not least, but with the ai, everything is data. Yeah. So the more precise your data is, the more better you build your analytic solutions, the better the AI and ML solutions will be.
So how we can leverage Amazon queue developer to be faster in terms of developing our AI and ML solutions when we have the data with us. So if we go into that, then, uh, what, as we discussed that Amazon Queue developer helps with the quality, uh, it helps with the efficiency, it helps with the speed and how it does it, we will go through that into the detail. It has.
It is built upon the generative AI and has, hence it helps down to reduce the cost, basically. Uh, because if the efficiency high, if you're delivering more features as to what the business needs, then obviously the cost will be less. So there is a tremendous amount of, uh, uh, what we say the enthusiasm about saying, Hey, you know, uh, we should be using the generative ai, which will transform and which will power our business.
Um, but lot of companies have, one of the thing is that, hey, but what happens about the, um, uh, my particular, uh, security framework will, my code will be used to train, uh, the, uh, uh, Amazon queue developers LLM models. The answer to that one is no. And the reason for that to make it upfront was that we make sure that we don't use the customer's data to train those LLM models.
Those LLM models are already being trained, and they, we are using your data just to generate the core and provide to you basically. So that is nothing that this trains our LLM models. So that's something which I wanted to put first thing into the rest.
So there is a new experience altogether. So you are, whether you are in the ID where you are, uh, trying to, um, um, do the coding, whether you are doing the mass transformation. So like I was saying that you might have a lot of applications which you want to transform, move from T net framework to net, uh, core.
You want to boost the productivity, you want to have the content creation, which you want to do. You want to see the insights, and you want to have the creativity. All those things can be powered with the generative ai.
So what is the fundamental, um, uh, thing which we are talking about? So, uh, a customer comes to us and say, Hey, you know, we have a lot of systems. We have thousands of applications, which has been running on true, and there's a lot of core which has been written on true.
But then every time we try to build something, it takes a similar amount of effort because we can learn from the systems what we have built, and we cannot quickly convert them into the next level of features. What we want to develop onto, so this is where Amazon queue is differentiator. Uh, we learn from the knowledge of your company, your code, your systems, um, and we, it's not used to train the LLM models, as I said before.
And if, when you ask the question saying, Hey, you know, I want to develop the new feature, it based upon your company's core and systems, it develops the new functions, which is required into your, uh, preferred id, which we have been integrating with. It's available wherever you work. So it's either you are in the id, whether you are into the AWS consoles, whether you are in a particular service, wherever you want, uh, the service to be available.
It's available with you in order to do the development and enhancement. Um, there are superior generative AI performance on tasks. So we have specifically integrated with lots and lots of knowledge base, which we have got at AWS so that this performs better.
And it gives you the exact content, what you're looking for, the integration. So for example, if you want to integrate with the S3, what is the SCDK and SDKs, which we have available as part of the AWS, which you can integrate with. Uh, so what does the stack looks like?
So at the bottom of the stack, as you can see, there is an infrastructure. Uh, those infrastructure is our core. Uh, if you say EC2 instances, uh, which has been used, which are specifically used to train the model, those are the foundation models on which training and influence happens.
On top of that, we have got the bad drug, uh, which helps with the, uh, guardrails and all the customization capabilities, what is required to power your business, uh, and, uh, uh, the LLM models, uh, so that you can access whatever LLM models, which you want to integrate with and so on. And then on top of that, we have used, uh, certain applications, which can be used around, so you might have heard about Amazon Queue business. Uh, we will get into the retail as to what is the use of that Amazon Queue developer, which we are talking about right now, um, which helps the developers to carry out their development, operational security task into the code.
We do have Amazon queue in QuickSight, so user can type in the queries into the natural language, and then Amazon queue in Connect as well. So if the customer is calling, uh, into your data set, into, into the call centers and want to, uh, and the customer care person wants to know the specific information, then Amazon Queue can help with that knowledge base as well, with respect to quite optimizing and telling the consistent message back to your customers. So it's, Amazon Queue is powered by the ai, um, as we were talking about.
So there are two kind of Amazon queue developers, Amazon Queue developer, and Amazon Queue business. So Amazon Queue business is for every employee, uh, who are using the things like Teams or Slack or, uh, uh, you are, you might have a knowledge base, which is your SharePoint. Uh, you might have a lot of Outlook application, Microsoft, uh, which can be integrated, so that, which can be used by the business, uh, team to derive the better, uh, uh, optimized information to put that into the task.
And then the other side, we have the Amazon Q developer, which is for the developers and data scientists and IT professionals basically. So that is something which we are going to talk in detail today, not Amazon Q business. So, uh, queue Developer, as it says that it helps the developers and IT professionals build the software faster.
We want more accurate coding recommendation. Um, agents can autonomously help you implement feature If you want to say, Hey, you know, this code is very complex and someone has returned it, can you please add the code to, uh, the comments to the code? Uh, it'll add you the Java comments or net comments or JavaScript comments is what you want.
And if you, if you can, it can also say saying, Hey, you know, the code is very complex, uh, which you have written. So you can re, you can ask it to refactor the code, uh, as well as it performs the software upgrade as we were talking about. Um, and also Amazon Queue, as you can, um, understand it, that every other knowledge which we have acquired over the years has been fit into the Amazon queue.
So anything which you require the information about the Amazon AWS, you have that information available. And obviously, um, security is Job Zero at Amazon, so we never start with anything which is not built with security and privacy. Um, and that's, that's most of our customers ask as well.
So, uh, wherever you are working. So it's available in Amazon queue. So nowadays when you log in onto the console, you'll be able to see the Amazon queue, um, which is on the right side of your, uh, uh, of your screen.
Uh, if you click on that and if you ask any questions, that's something which has been powered by the Amazon queue, and it can answer any questions, what you want to know, say how much you have spent, and saying, what is the issue with my service? And so on. You can get the information.
You can also use it into the ID integrated development environment, so like Visual Studio or Jet Brains, if you're using one two, you can integrate that and start using straight Amazon Queue developers. Um, AWS documentation it has been trained onto. So anything which you require with respect to the AWS, it provides the information about that as well.
Uh, same as I was talking about, you can integrate with Slack and Teams as well, and it's available on the mobile application as well. One recent thing, uh, which we have partnered with is our partner GitLab. So GitLab now has got the GitLab duo, which has been powered with the chain ai.
Um, and it's using the Amazon Q developer at the back of it. So, which is something fundamentally allows you, if you're using GitLab quite heavily, you all the source code are into the GitLab. Uh, you can leverage Amazon queue straight away by using the GitLab over there.
And Amazon Queue developer is been recognized, um, as the leader. So in the AI code assistant, so we are in the leaders' quadrant of the 2024. So as you can see that, um, uh, it's, it's has got, uh, all the capabilities, what is required, uh, to match up those things.
So, uh, as I was talking about, build faster, operate at scale, transform the workloads and leverage data and ai, this is what it makes the things, deliver new features to the company and make the innovation faster for the developers rather than the mundane task which they need to go through. So we'll dive into the deeper, so, uh, build faster. How does the build faster happens?
So where are the developers spending the time? So they want to explore, uh, saying, Hey, you know, I want to build a website and in order to build a website, what are the things I will need to do? Uh, I want to create the software.
How do I create the software I want to test and secure review and deploy? And then the last but not least, maintain, transform and modernize. So this is usually the time where the developers are spending it, and we'll go through, into the details by going through how in every part of the SPLC, this tool is helping you out.
Um, so let's see a demo. So as you can see, this is your id. Um, you have connected with the A WSQ developers, and you start asking the question in the consulting, Hey, you know, I want to develop a web app.
How should I do it? And it gives you the answer. Um, so that's the first exploration part of which services I should use onto the AWS in order to develop the application.
It can help you with the service selection, when should you use what service? And so on. So that's basically the exploration part before any development activities happens.
Then it comes down to the creating, generating the code. So as you can see, uh, you can just write the comment and say, Hey, I want to write a function to square a number. You connect to the Amazon queue developers in the browser.
This is the visual Studio. Um, and once it's been connected, you can do all your merging. Um, the, the release of the software writing, the unit case test cases, um, writing the, uh, functions.
As you can see that the function is getting returned, you just write the comment and you just accept those code. So the core, the developers can accept the code, or if there are sometimes multiple options available, it shows to the developer which part of the function you want to use it as well. Um, and it's, it's significantly, um, uh, what we say the, the faster way of developing the software.
Even if you want to edit it, you can edit it. Um, once the base code has been available to your business specific domains, which, which LMS might not have been trained with. So once it has been trained, um, there are, there are quite a lot of, as I was saying, the, our customers asking, saying, Hey, you know, but, uh, it's great if I want to write something completely from scratch, but my organization has got a lot of, um, source core already available.
And most of the time it's the integration of, uh, one application to another application and how to do that integration and so on, which is taking the time. So what the answer to that is that you have the private repository, uh, on which the private repository you want Amazon queue developers to uh, integrate with. And using the Amazon queue developers, it can recommend you when you ask in the natural language saying, Hey, you know, can you please, uh, give me the list of, um, uh, unassigned food deliveries, uh, which which is around the driver's current location so that we can take the better, um, uh, we can develop this feature quickly and deliver it.
Now this is something which is, you already know the driver's current location that is already the code, which has been written down. And you want to write a new feature, which is to say unassigned for deliveries, uh, around that. So it leverages it, understand your code, it find it out as to how to retrieve the driver's current location and based on the driver's current location, then it tries to retrieve the list of the unsign full so it understand your code.
It makes, it makes, it's not a code recommendation, which comes down, it comes down to the customized code recommendation, which is what is required by your organization. Um, there are advanced features, which is available as well. So, uh, q can write, uh, um, uh, q can write, and it can provide you the features with respect to how you can document, uh, the code.
So as you can see over here, uh, there is a document you want to create a read me file, uh, read me file for the whole project as to how to use it. And in no time it'll scan through the source code, it'll create the knowledge graph, it summarize the source file, and it'll generate the documentation. Um, uh, previously this used to take, if you, if you are, I remember in the projects where I was doing the development, and if the read me file was not there, and if the developer has left, someone will come back and say, Hey, you know, I, in order to create this, uh, read me file, which you're asking, which is required for every application, it'll take me X amount of days or sometimes week, uh, in order to generate this is just now available at click of what is needed.
Yeah. And it is formatted, it is ready for checked in, um, and it is ready for review and then merge and release to the production as well. So this is all part of the integration, what you can see too, testing.
So from in the past, unit test was one of the thing which we were putting into the estimation. And then we say, Hey, you know, I've written the code, which is working, but you know, we cannot still release because there are no unit test cases, or there are no, um, uh, the, uh, the proper testing which has been carried out onto this code. So now we can also support writing up the unit testing.
So the agent supports that saying, Hey, you want to write the test? So here is your clause and you want to write the testing of this methods. Then we can support that as well.
And it can create the test, uh, the unit test cases for every function, which you have been using it. So as you can see onto my screen, which has been showing around saying, Hey, you have four functions, and we have generated all the test cases. Developers accepted it and say, Hey, come on to build and execute now.
So it is building and it is, uh, uh, it can deploy. As you can see, it's a MA one clean verify, which is happening around it's building and executing into the browsers. And then from there, it can take around in order to your ci cd pipeline to deploy to the, uh, uh, into whatever environments that you want to deploy onto security.
So one of the major thing which was coming around is, Hey, great, we develop new feature, we, uh, fix the test issues, but now we want to make sure that, uh, security wise, it is, um, uh, it is quite secure. So the great feature about this is it does the real time check. It provides you any vulnerabilities and not only provide it with the vulnerabilities, it provides you how to fix it as well.
So, for example, if you're using the libraries, which are quite legacy libraries, then it can help you to upgrade those libraries and it can fix those libraries, uh, in no time as well. And it categorizes, as you can see on the left side of the screen, that it categorizes critical, high, medium, low, or if it's just for information as well. So you have all the information which is required in order to make the features, uh, the development quicker.
Um, the last but not least is review and deploy. So we all know that once it's been, uh, once the feature has been developed by the developer, we want someone to be reviewing that code. And once it's been reviewed, then the, as part of the merge and released, then the review happens.
Now, this part, um, I have seen in the company, there was a lot of debate and discussion saying, Hey, though, this variable name is right and this variable name is not right, and there was a lot of friction between the developers, this developer doesn't like me, and all those things believe that to the system Now. So the system will say, Hey, you know, that based upon, um, the review which I've carried out, first of all, it's consistent review and based upon the review, which I've carried out, uh, I think these are the issues which needs to be fixed upon. Um, so that's something which gets reduced down in minutes to hours basically, rather than in dates.
Uh, and it's a consistency of which with which the code is getting reviewed. So the great questions which customers always ask us is saying, so what is the metrics, uh, which I should measure? Uh, because, uh, previously we, we used to a developer used to take, say, 10 days to develop a feature.
Uh, is it going to be all of a sudden it's a one day? Uh, there is a bit of a learning curve as to how to, how to prompt, uh, the Amazon queue developer. So over the period of time, you will have the metrics, uh, which will show you that, uh, how significantly the impact which has made, uh, by using Amazon Queue developer.
So we recommend this four metrics. One is the report time saving across a range of tasks, what the developers was doing before, uh, suggestion acceptance rate. So basically the what is your acceptance rate, which looks like, so Amazon two developer in your ID has recommended the code, and is it the code is ready and it has increased your velocity, uh, of the code changes in deployment.
So you measure those aspects as well. And what is the context switching with the ability to query code base and hundred knowledge into id? So basically the things which you are having the legacy core, and we don't have the any documentation around that.
Those things gets resolved in no time. So, um, what we have been told by our customers is that this enhances, it accelerates 80% of the development task. Uh, there are 60% of the code acceptance rate.
Yeah. Uh, and when we say 60% rest, 40% is, hey, you know, but I have a very specific business requirement, which I need to do, which I need to code. Um, so what we are saying is, but most, and most developers are saying, Hey, you know, 60% of the core as it is, is coming, which is a great, um, uh, and that's something which has been coming out from, uh, one of our customers, which we were going through as well at the end.
Um, so it's a real, it's a real numbers from a customer, and the developers are quite happy because they are now developing new features. Um, a 40% productivity increase, which has happened around the, the task which they were not liking, like writing unit or doing the, uh, comments, uh, documentation that gets resolved automatically and security fixes and upgrade, uh, all those aspects so they can focus on developing the new features, which was where the developers trends were and what business was looking for. A, as I was saying earlier, that GitLab deal, this has been integrated with Amazon queue, so it has got quite advanced, uh, capabilities, which is in the Dev X Ops workflows, uh, which the developers use every day.
So have a look into it. Uh, if you're using GitLab, that's something which is a, a great, great, great, uh, thing, which has been, uh, we have been doing behind the scene, working with the GitLab. Uh, and it'll help you to innovate, um, and deliver quicker, uh, at every step of your journey.
Um, so friction through the SDLC and those aspects, which was there, it has been making now seamless. Uh, it's an AI powered experience, um, as we were talking about. So it's available in preview very soon to be ga, uh, but feel free to start using it around on those aspects.
Aspects. We did the build, um, and then we were doing the operations, and then every time the operation there was an issue. Uh, it was again, going to the developers.
So, uh, I don't know if you have seen recently, but that is, um, in the CloudWatch. We have got AI ops now, uh, AI for ops, which helps you to tell saying, Hey, you know, um, you have obs, you, you have observed an error into the logs, and based on that error on the logs, you can just create, um, uh, the ai, uh, uh, enterprise issues, and then you can track through your Jira and so on, which is all to the integration, and then it'll do its magic and find it out. What could be the reason this issue has happened?
What was the change which has gone in? Uh, is that the change which is stopping your system to perform well? Or what, what is the kind of, uh, things which has been, which needs to be corrected?
Um, so it's a great thing, uh, which we have been working on. Again, it's been powered by Amazon queue. So, um, and it's built upon the best practices and our support, uh, uh, mechanisms, which has been there.
Um, man is and optimiz. So customer were asking, saying, Hey, great. Um, lot of time around billing.
How can I do the usage trends and intuitive visualizations? All these are now supported with the, um, AWS using the qs, and as I was saying, diagnose and troubleshoot error as well. So you can go to the CloudWatch, use the IW AI ops, and using the AI ops, you can see that, hey, uh, what could be the diag diagnose and what is the troubleshooting error, which has been there and remediate quickly, uh, uh, those aspects.
So what, what are the kind, so the thing was it, the tools are available, but then other aspect is asking the tool what your problem is. So here are some of the queries which you can use. So you can ask saying, Hey, Lambda, hey Amazon queue, what is wrong with my Lambda function?
Um, and it'll try to go through every aspect of the Lambda function logs and so on, and it can figure it out as to what does it looks like, uh, customer asking, saying, Hey, you know, I at the click of my button in the non-techy language, uh, my program has been asking me saying, what is the forecasted cost for the rest of the year? Uh, we don't need to go through the number fudging and all those things. We can just derive those aspects, which has been available on to the billing console, and we can provide that the cost of the breakdown.
Uh, how much am I spending on the data transfer? Uh, show me alarms for my S3 buckets. Uh, how can I leverage agents?
How can I leverage my a PA gateway, which has been seeing errors to resolve those issues in no time? So all of those things can be helping with Amazon queue to operate the things as well. The most important aspect that, uh, we have recently announced at the reinvent, uh, which was around the transformation of the workload.
Um, and fundamentally when we talk about the transform, it's a slow modernization. There is a complex legacy systems, which requires a lot of, uh, uh, workforce in order to carry out any transformation. There's a limited scalability options, which has been available, and hence it takes quite a lot of months and months in order to do any transformation.
So we have specifically created some solutions which has been tailored for, uh, specific problems. Um, and as you can see, that we have done now, uh, if you want to move from Java version, legacy version 7, 8, 9 to Java 17, you can start leveraging the Amazon Queue developer. If you have been using dotnet framework and you want to move to dotnet core, you can do that so that your application has been portable from the legacy version of the net into the conet core, and hence, you can run it onto the Linux as well, giving you the business benefit back, uh, in terms of, uh, running the net applications onto the Linux, uh, platform as well, saving you the license cost of the windows, and also taking the benefit of ization and scaling and all those aspects, which comes around mainframe, which was the biggest, biggest, uh, challenge you can.
Now, I'm not saying all the problems of the mainframe is going to be solved, um, but what we have started getting was that from point where the biggest question was saying, Hey, I don't know what has been running on my mainframe. We can easily now generate the documentation from the mainframe applications, what has been running onto those mainframes, which then helps us to create the business, um, uh, move forward onto the latest technologies. Uh, as you can see, last year, Broadcom came out and say, Hey, you know, VMware licenses are going to be changed.
Uh, and there was a lot of things which was changing around the VMware. Uh, one of the pathway was migrating those VMware VMs onto the EC2. So using the Amazon Q developers transformation capabilities, we are supporting now to migrate those workloads in no time from the on-premise VMware or VMC onto the, uh, EC2 instances.
So that's something which is a great, great significant benefit, uh, for the transformation which our customers are facing. It can be into the id, it can be into the, um, uh, web browser. What we are saying is that the customer is saying that we are Forex times faster.
We are saving 40%, uh, savings when we are doing this kind of a transformation, which is a significant number. If you look around from months and months, which we were talking about. It has reduced down, got everything, uh, been recommended to the customers.
Customer can select saying, Hey, yes, this is moving great. I want to trans, I want to migrate thousand applications. And this thousand applications, um, uh, needs to be, uh, done.
Previously, uh, it used to take months. Now, in the recent, um, uh, migration of the thousand Java applications where we needed to move from, uh, Java eight nine to Java 17, we were able to do it in two days on average, 10 minutes basically. So the developer can put it and then they can start developing the new feature.
Once all the development, the migration has happened, it comes back and shows to the developer saying, Hey, you know, your application has been updated. Do you want to adapt all the changes? You say Yes, and it'll take over from there and then progress the next steps of the function to integrate and deploy and deliver as well.
Um, it saves us 4,500 years of development work and 260 million. So this is based upon the real, real work which has been done at Amazon. It's a significant numbers, uh, if you look around, uh, the last leverage data in ai.
So data is the core of everything, what we have been doing now. So you can start writing in your natural language, the pipelines, you can build it onto the SQL queries, uh, actionable insights. So basically, if you go to the QuickSight and you say, Hey, what is my, uh, projection for this month, which is looking like, based upon this particular product which we have been using on two, you write in the natural language and it'll create you the, uh, output what you're looking for.
You can analyze that data and integrate that data into the, uh, features, what you want to have it, uh, as a business. And you can train to do the business, uh, ML model as well to train the ML models. Uh, Amazon sales maker has been widely used to develop your own models.
Uh, you can do the development into the Visual Studio code or any id, which you prefer done to, and it's, it has got a step by step guidance, uh, in the no-code truthing. And hence, you can leverage the data and AI together, uh, with, with zero expertise, um, and full blown product to be available for, uh, building up any product based, uh, product database product. So, um, as I was saying, couple of business, uh, uh, recommendation or customers who have used it, uh, national Australia Bank, they're one of the largest financial institution in Australia, and they have been using it.
And what they are saying is that 50% of the code suggestions what has been made by AM Amazon Q developers, our developers are just accepting it. And, uh, this has significantly enhanced our productivity, delivering better service to our customers. Similarly, um, NOVA Comp, we are into the IT services, uh, as I was saying that, uh, you can do the transformation.
So there was Java eight to Java 17 transformation and 10,000 lines of code. Um, we have 60% decrease in average in our tech depth. So it does all the thing for you.
Uh, eight synchronically, take your code, go to put it into the three, uh, do the transformation of the project from Java to Java 17, along with the testing and so on. One, it is, once it is a compilable state, it tells you saying, Hey, you know, you want to see the code changes, which has gone through, and it shows you how significantly improvement in terms of the developer's experience, uh, and acceptance for that. Similarly, Toyota has been using it as well, and as I was talking about, they had the Copa, uh, mainframe, and it's been used for the persona driven insights in order to develop the lot of documentation so that they can take the documentation and start doing the better things, uh, with respect to those capabilities.
Volkswagen as well, um, as I was talking about the GitLab, uh, they are using GitLab and they're using the AI capability with Amazon Q Developer, which has been integrated, and again, a great feedback, uh, which has been given by the Amazon feedback. Similarly, Mercedes, they have been using it, uh, DevSecOps, uh, for the purpose of DevSecOps and devs have been something which is significantly, uh, their developers are loving it. Uh, and common task has been left to the Amazon queue developer.
So, uh, what you can do, so, uh, there are two versions of Amazon Queue Developer, which is available. Um, uh, one is you can use the free trial, um, uh, and that is something which you can just register at the Amazon and just like how you were using the free car of the AWS, you can start using this, uh, uh, as an AWS builder. Uh, yeah, another option is the Amazon Pro.
So Amazon Pro is where we don't learn anything from your data. This model has been tuned, fine tuned, uh, and they will put the recommendations and so on. So, uh, the pro subscription is something which you require in order to be using the Amazon Queue developer, which is what our most enterprise customers have been using it, and plan your POC next time you're doing the upgrade.
Don't just do the upgrade next time you're doing the security fixes. Don't do any security fixes without using the Amazon Queue developer. This will significantly improve, and you can showcase to your, um, uh, leadership that how this amazing Amazon True Developer is helping in order to make the things faster and better.
Uh, and we are happy to support that in case anything is needed from the AWS. With that, thanks a lot today. Uh, absolutely pleasure to talk with.
Um, feel free to put any questions into the chat, and I will address it. Thank you. Thanks a lot.
Hi, everybody. Welcome. We're glad you've joined us today for another episode of the latest greatest cloud transformation late great cloud transformation.
We're talking about really sort of the next generation of how we think about the cloud and the things that we're doing with it. We're talking about security today, about safeguarding innovation and, uh, strengthening that security. Well, we jumping into app, app security and a lot of things here.
But, uh, before we get too far down the road, thank you for joining us for this video series. Uh, the, the last Great cloud transformation is sponsored by CloudFlare. We're glad to have them, uh, on board with, with us working on this, uh, helping input with some topics and things like that, and obviously participating on, on our, uh, live editions, which we do on a monthly basis, as well as these recorded episodes.
So, thank you for being here with us. My name is Mitch Ashley, I'm VP and practice lead with futurum Group, analyst firm, uh, heading up the analyst area for DevOps, DevSecOps, application development, AppSec, et cetera. So kind of right in, in vain with this, uh, my co-host Alan Shimel is, uh, unintendedly, uh, de detained or whatever the word is the phrase is.
And, uh, so I'll be, I'm, I'm hosting both parts of the chair today. Uh, you know, it's a little bit of a coup, but he'll be back next time. We'll see him on our next episode, I'm sure.
So let's get to our conversation, to our topic. Um, let's first start by doing some introductions. I know Chris has been with us on a few episodes here on some different topics.
You've been on other webinars with me and TA talking a lot about application security and, and, uh, cloud Chris Blas, introduce yourself. Oh, I've been Forest Company my way through the security industry for 30 something years. Uh, I inflicted an early firewall in the markets, something called Border Ware, uh, in the early nineties, and ran Cisco's firewall business, the turn of the century.
I've been following this inevitability curve, uh, my new series on here on Textron, um, from one spot to another, from firewalls into, uh, sim and network management. From that, you know, the obvious next step is threat intelligence. So I, uh, chaired an IAC for a while, and, uh, supply chain has been my focus the last five or six years, you know, so, you know, software, bill of materials, hardware, bill of materials.
How do we connect all these things, which, and, and currently, so currently I'm, I, my main role is I'm vice president of strategy for sbe, which is involved in the SBO space. And I've been, uh, co-chairing several, uh, cisa uh, working groups on SBO sharing. So we're currently have a group looking at ISACs, um, as s OM distributors.
How does that no, to the middle start taking this information and, and propagating it Software bill materials. Absolutely. Great.
Thank you Chris. Um, Katherine, Katherine, welcome. Glad to have you on, I think the first time we've had you on the show.
Katherine Newcomb with CloudFlare, please introduce yourself. Yeah, great to be here. I'm excited to talk about application security.
Um, my name's Katherine Newcomb. I live in Denver right now. Um, I've been in cybersecurity for about five years at this point.
Um, and I started in the network firewall space, um, and encryption. And now I'm a product marketing manager for Cloud Flare, um, for their application security business, uh, where I focus on their web application firewall product, um, our software supply chain product, as well as our encryption and certificate lifecycle management products. Very nice.
And, and I do like to say full disclosure, Textron is a customer of cloud flares. We do use their services and enjoyed very much so thank you Katherine, and team for that. Uh, last but not least, another newcomer to our show, Kurt Handel, who's with, uh, Teradata.
Tell us about yourself, Kurt. Yep. So I've been working in security probably eight or nine years at this point, uh, but in the software industry for close to 15 years now, anywhere from development, uh, into business analysis, product management, even, uh, doing a little bit of red teaming myself, but, uh, I am currently the chief security architect at Teradata.
And so I've been focused on architecture mostly for the past six, seven, possibly eight years, and really kind of a generalist. So AppSec is where I spend the least amount of my time, but we focus on the architecture, the requirements, threat modeling, um, especially compliance. We do a lot of the, the major compliance frameworks at Teradata.
So we've been pushing that recently. Um, and I'm based in the Pacific Northwest, up in the Seattle area, and happy to be here. Very nice.
All the weather and fires and it's cold and I'm just glad we all made it. Maybe it's 'cause we didn't have to travel anywhere, so, so I hang tight. I'm glad we're all here.
And you know, our, our thoughts go our, our hearts go out to the folks dealing with the fires and, and, uh, some weather down south and southeast, et cetera. So, um, let, let's kind of jump in this way. Um, it, it's a big topic when we talk about sort of the kind of current state of the cloud and where it's moving to.
Um, but I don't think it's too much news to everyone that application and app APIs, API first kind of design into applications, you know, it isn't just things that sit at the edge anymore. We think about also the security of the apps and the kind of, uh, software we're creating, the innovation that we're making, um, as maybe as part of the cloud. 'cause sometimes application lives within it, you know, like a, like a provider like CloudFlare or certainly at the edge or at the core as well.
Maybe Catherine, if you wanna start us out with, how do you, you're, you're, you're managing, doing product management in this space. How do you look at this, uh, sort of this problem or this space and define it? Um, so looking at application security, um, when we're talking about this at cloud, we're mostly talking about web application and API security.
So if you're an OSI person, layer seven model, um, and you know, when people are accessing these external facing web applications, they're doing it from a ton of different devices and in a ton of different ways. So they're accessing from things like mobile, uh, desktop, laptop, and they're accessing these apps that could be hosted anywhere. So on-prem, in public clouds, private clouds, hybrids.
Um, so as we're securing, we need to think about how can we secure, um, all of these users and the end servers as they're sort of accessing these web apps, right? So how do we make sure that, um, mobile traffic is protected, user data is protected, um, and sensitive data is not, you know, leaving an app. And then how do we make sure that a web app server itself is protected?
Um, so at a very high level, that's about what I think, that's what I think about when it comes to application security. Um, some new things we're thinking about in this space. Um, I talked about software supply chain.
This is increasingly becoming, um, an area of interest as people create more complex apps with more third parties in them. Of course, API first development has also meant we've had to adjust our thinking a little bit around application security as well. Kurt, how about you as a, as an architect, security architect, you may, maybe you don't get into the innards of applications per se, application security, but traffic over there.
Obviously our networks are heavily API driven. Um, you know, when you think about the security architecture, where does this fit into your purview? I think it, it fits in really everywhere, right?
So we're, we're building these huge applications, sometimes small applications. I mean, we do all sorts of scale at Teradata, and in my previous roles, I've, I've worked with pretty simple apps all the way to super complex microservices architectures. And so, like Catherine could said, you have the mobile aspect, you have the server, either there's application code literally everywhere, including on the person's device.
And so how do you secure it as best you can, um, within reason, right? Because if it's too secure, it doesn't work. If it's not secure enough, well, you end up in the Wall Street Journal and you're in trouble.
Um, so we, from an architecture standpoint, we really try to focus on all different aspects of it, where the biggest threats lie, um, and then implement controls and use technologies to, to simplify the implementation and streamline it without making it overly complex. And so it's, it's just becoming more difficult given that, um, the, this kind of classic perimeter is gone. Right?
I'm sure you can relate to that, Chris. Oh, yeah. Well, it was easy back in the day, right?
You know, you had to get on the internet and you needed a firewall. Get a firewall, right? And I'm thinking as Kurt and Catherine, you're co remind me of these transitions we go through.
Like there was the mainframes before our time, but you know, I, I'm old enough to have seen the end of that where all of your capabilities are just to keep one computer running and run terminals and printers and things off that. And then we get into, you know, sort of where I came in, where we're starting to build networks, fractally more complicated, just, you know, how do we do that with, when all of our resources were just keeping one computer running, we figured it out, you know, now we're here, we're talking about web APIs, Catherine, you know, the data going in and out and with being stored 30 years ago, you couldn't have that conversation. Now we're saying, alright, what do we do in this case?
And it's very complicated. And I think in, and Catherine you mentioned the supply chain. This is, I think we're filling in the dots.
Security has been, is not, is not new, right? People have been saying, you should know your inventory for a long, long time, and we've gotten away with not knowing it. Now we're starting to fill it in, need to actually know where the software is, where the data is, and we're working through that.
So it's exciting times, but it's not different in type than other transitional periods. Certainly is an evolution, right? Of what we've gone through.
And to think about, you know, from the baston host days earlier on pre firewall, um, Well, firewalls used to be a million dollars a year. I think when I got involved, you know, at least as I tell the story, there were a hundred in the world and they typically were seven computers and a team of people. And my argument at the time was my mom needs one.
Yeah. You know, and so we're at this stage where what used to take so much time in here in the API, uh, world, it has to take less time a lot. It, it, so let me, let me throw out this hypothesis here.
I think it may be pretty obvious, but maybe it isn't, is I think we live in a world, you know, now we we're thinking about things as zero trust, right? Of, of you, you know, anything is susceptible, being compromised and could compromise other things. How do you pro protect all parts of the network applications, the infrastructure?
But we're also living in a world where if so much is determined by what our applications do, not just connecting users to apps, but applications really utilizing the network, being part of the network. It's a dynamic world, right? It, it isn't a good set of firewall rules and an application firewall, and we're all good, kind of set that up.
And it isn't the old days of, if I've got a pizza box in, in my rack for every function that I need, and they're all doing their thing, I'm good. Right? We need it.
It's a much more dynamic environment. So I'm not saying we're reconfiguring our security all the time, but a security has to adapt to, you know, what's happening in the application. Because we may distribute it to a different part of the edge tomorrow with Kubernetes, or we may, you know, uh, acquire business and suddenly a network has looked much different than it did, you know, three weeks ago.
I'm, I'm curious, Kurt, as a practitioner, you know, how do you think about that of, you know, you mentioned microservices and all the things that are being created, you know, in the groups that you're working with. Um, we, we hate for security to be sort of the last thing to be thought of, but you wanna be in the conversation so you can prepare as well as react when you need to react. I think what you just said is, is really important, but you wanna be in the conversation.
You don't wanna be doing this retroactively. And so when you're, when you try to tackle security retroactively, it is infinitely harder to accomplish than if you do it from the beginning. So I have, I do it both ways.
I have teams that we work with proactively where they bring us in at the very start and we're building the design with them shoulder to shoulder, drawing the picture in doing security by design or by default as we like to say now. Or we have legacy applications, which you're doing retroactively and they're quite a bit higher in terms of risk because they've been neglected for so long. Or you find out about something after the fact and it's like, well, how did this get out there?
Well, there's shadow IP in a lot of the world. And so it's, it's hard to, to really kind of put a, a recipe together that successfully achieves it. And then with the, the rapid pace of technology today and how the cloud has just kind of blown this wide open where people can deploy new applications in a hundred different ways faster than ever.
How do you keep up? So you have to implement tooling within reason without doing, without having too much sprawl. You have to have the right personnel partnering with these teams, uh, to ensure that you have coverage and that you, you're really architecting things from the start.
Um, and not just kind of using bandaids in bubblegum per se, to, to secure your environment later on. Catherine, appreciate your thoughts on this because, you know, I remember the days of networks for speeds and feeds and points of presence and connecting A to B and kinda looked like this nice diagram that you stitched together and that was a network and you secured it, now it's overlay on top of overlay and it's changing and, you know, it's, it's multiple pieces that, uh, much more complex to, to secure. How do you, how do you have this conversation with people?
Yeah, definitely. So as you were sort of talking about this, you know, obviously there's a need for responsiveness and customizability and security, but I actually also wanna make the argument for unified policy management in application security. This is something that I've seen actually, for example, um, we have some customers who have protected their SaaS apps, like what is traditionally more of a network firewall or zero trust type use case with the same policy they're using for their web applications.
And by doing this, they're able to do things like make sure that zero day exploits aren't able to exploit their SaaS apps, you know, as well as their, um, web apps. And we see a lot of value out of these unified policy managements. I was talking earlier about, you know, how we have all these apps hosted in different places.
We see a lot of customers, for example, we'll host, um, you know, an app across multiple clouds for like a resiliency use case. If they're worried about outages, you'll, you'll certainly see that, um, for example. But then how do you have to, you know, actually secure an app that's stored in multiple places?
Do you write different policies for, for wherever those are stored? Um, do you write different policies for APIs versus, you know, traditional apps? Um, so we see a lot of benefit out of like a unified policy for all of those disparate sort of endpoints and all of those disparate, um, locations that they're stored.
Uh, for CloudFlare in particular, how this sort of works out is our WAF is like the backbone, the architectural backbone of the rest of our application, um, security portfolio. And this works out really well because you can do things like have a WAF and an API like positive security model protecting your APIs. Um, so you could do things like detect zero days and volumetric attacks, which are, you know, APIs can also be susceptible to as well as, you know, do the things like Ebola and, and all those API specific attacks all within sort of one, um, control plane, which we find a lot of people get a lot of value out of because of this really, really disparate environment.
Okay. Chris, I saw a lot of hand waving head nodding, your bud jumped outta your chair on this one. And so I kind of have a feeling you might resonate with this.
No, um, I, I gotta throw out there, I was gonna, uh, before Catherine got into the, the policy thing, I swear it's been a lot time, but yeah, the concept of an SBO m the software bill of material for the current release version of Adobe Acrobat as opposed to an SBO m for as we're look talking about here, some ephemeral web app that one time for five seconds exists in the cloud. You know, think about that. How do we, how do we deal with that?
And I, and, but I think policy is, is the answer all hacking? All hacking is policy hacking. I will figure out how you do things and I will figure out where the gaps are and I'll engineer that gap.
And we live in a world right now where we generally have no idea what policy applies to any of us anywhere, with few exceptions. And in this topic, and because I'm used to the supply chain topic, imagine I needed to get the, the SBO M or custody information about a piece of software on his phone right now. I could get it in between five days and six months today I need to get it in a half a second.
That means I need to read the policies between me, the person who bought the phone and the first time the company I bought it from, and like their relationship, their contracts, their policies, you know, upstream all the way. And we have to get that done in the next decade. So without unified and, and, and adaptable, you know, transparent policy frameworks, none of this technology is gonna make a difference.
So I think we, we will do that. And there's interesting things going on down that path. It's kinda interesting in a way, just connecting dots between what you said, Catherine and you were talking about Chris, there's your own unified policy management, right, of what you're doing.
So you know, you're, you, what you're applying where and how you're applying it, and then that's how that interconnects or interrelates with the people you connect with, work with, use their service product, whatever that is too. And I, and I appreciate what you said Chris, about, think about just serverless technology like a lamb to kinda service, right? You know, it's there now, it's gone tomorrow may not be the same thing.
It was a second ago when it, when it ran. Um, so it in some ways, Catherine, it's all sort of a dynamic unified policy management, right? It can't be a static thing.
Am I, am I on base here? Yes, of course. You know, you do have to be responsive to the environment, um, you know, threat landscape.
Um, this is one, one area where I strongly advocate for actually ML driven, um, detections and policy. Uh, this is a thing where, for example, if you have a really large data set, uh, you can train your ML models. Um, how we do this at CloudFlare, just 'cause I think it's a little easier if I give an example and it's, uh, we will score each request on a scale of like one to 99.
And if something is less than 30, that means like it is very likely to be an attack. And because we have, um, hundreds of terabytes of requests, or sorry, hundreds of millions of requests every single day, um, we have so much data we could train this on and say a little blog in Malaysia gets attacked by a new attack we've never seen before. Suddenly because that tiny blog in Malaysia got attacked that gets feed and fed into our ML model, we don't have to rely on a security engineer to like go and find and analyze that attack and turn it into a regular expression like firewall rule.
Um, the ML will basically just say, okay, like since it matches something like this, um, we will just automatically block it. And this is why I'd say ml um, sort of combined with that traditional, um, you know, security analyst looks at the traffic and writes a rule that matches it and then blocks traffic. Um, you gotta combine I think these types of approaches.
So ML is a really, really great application, um, when it comes to being responsive to the threat landscape. And we have some data around this as well. Um, we recently, not that recently, like half a year ago released our annual application security trends report.
Um, and we found out that, uh, for example, like zero day vulnerabilities, um, we probably wouldn't have been able to find this out with just security engineers analyzing it. But with our ml, we were able to detect, um, and exploit 22 minutes after the, uh, proof of concept was posted online. Um, really, really great applications there.
A lot of interesting stuff going on for sure. Well, that doesn't make the case for dynamic security. What does, right.
Um, I, I'm curious, Kurt, how do you, is, is someone, you know, applying these things, applying security? Are you, are you looking at things like ml, are you doing it via yourself? It's something you look for in the vendors, the partners that you work with.
How do you leveraging either that or the kind of technologies to help shorten that cycle between when things change and how you can account for it and secure it? Right. Uh, I think the ML piece of it is, is hugely important because I mean, humans, we're slow.
The, the technologies we use, the computers and I, each servers process all of this far faster than the human brain and I ever could. And so we need to augment ourselves with this technology. So anytime we're evaluating new solutions and bringing them in, like I'm currently in the process of implementing a big one right now that focuses on platformization and ai, ml, it's all part of it because it humans with eyes on glass, like it's great to have those guys in the sock, but they'll get overwhelmed very easily with the speed at which things happen today.
And so we need to leverage technology and machine learning enables us to do this faster than ever, and it's only getting better, right? And so augment the human with that technology and you can very quickly pare down all of that information to what matters most and focus on real attacks like Katherine was just talking about. I wonder, you know, there's so much activity around ai, of course, a lot of it because of gen generative ai, um, Chris, do, do security engineers have to become machine learning experts to be able to do this stuff?
What does it take to really leverage it? No, but knowing, knowing something isn't gonna, um, uh, causing any problems. But, uh, I, I just couldn't agree more with, with both, uh, with Kurt and Catherine.
'cause you know, and, and you're point, point Kurt, it's all about time, time to transparency. How, how long, and again, I've seen this over and over in my career where we get to these points where what we're mostly doing is sharing the war stories. You know, I have no idea it was 72 hours, none of us slept.
There was caffeine. And, and my my question always is, okay, if there was twice as much, what would you do? Because obviously that we're at the limit, we can't possibly work any harder to stay awake any longer.
And, and this, yeah, ai, ml, Oracles, whatever we call it, this, uh, my, a big has been a big part of my, uh, my focus on supply chain before it would, you know, AI became, you know, uh, a general, um, uh, generative, what the hell do we call it? I'm sorry, I forgot. Yeah.
Generative Ai. Yep. Generative ai.
Yes. Uh, too many terms to throw around. Yeah, because again, we need to, you know, just for supply chain things, I need to read the contracts.
I mean, I can literally call someone up, you know, it's not a security engineer, but it's some administrative person of the company and I had to get them on the phone and get them to pull A-A-P-D-F and read the contract and find out if the clause allows me to get the information I need. That's not worth a human's time. I mean, that's the kind of stuff that computers can do really well, and they're just beginning, but that's obviously the direction we're going.
And if you can't see your policy environment five years from now, by various definitions, your competitors will be so much faster than you are. That don't matter anymore. Cur I'm, I'm curious, without giving us too many specifics about Teradata, I'm not asking you for that, but what's your sense of, what are the, what are the new priorities that are on your yeah, on your horizon or things you're dealing with now and that you've kind of added in the last year or so?
What's changed about how you're thinking about security and that you've gotta address now? I think there's, there's always classic problems that we, we have to deal with and tackle. Like, we can't forget things like identity and network security and the rest of it.
But the, the prevalence in the emergence of generative AI and putting AI and machine learning in everyone's hands has meant that security teams have to be hyper aware more so than ever because these new technologies, people are latching onto them without considering the risks. They're like, that's awesome. I can speed up everything I'm doing.
And suddenly you see a new story about, well, what was it like Samsung engineers leak their code through regenerative AI solution or whatever. So you're, you can quickly lose intellectual property or put it at risk. And so we have to think about securing our environment for those solutions, or putting the guidance out for people to use AI and machine learning.
Um, and I mean, getting visibility of all of this, and another big one that's been getting pretty popular and we're seeing a lot from different vendors and acquisitions and whatever, is data security, posture management. Where is my data? Where is it moving?
How secure is it? Because at the end of the day, that's what the attackers want. They don't wanna sit in your network and use your resources to, to launch attacks as much as they used to.
They wanna grab your data, steal it, monetize it. So need, we're, we're focusing on data security big time in, in the more recent years, especially, um, forward looking because we have more data than ever. Interesting.
Catherine, from your perspective, you know, communicating with so many companies, what are some of the changing priorities from your, from your viewpoint? Yeah, I mean certainly the gen ai, um, piece is something we're seeing a lot. Um, everybody wants to put in an an LLM on their web application.
Um, and of course that means that you have to think of that as like a data security concern as well. Um, because you wanna make sure your LLM is not gonna like accidentally leak somebody else's social security number because that's certainly happened before. Um, and so at, at CloudFlare we're thinking about this of like, basically how could you basically just put a WAF in front of an LLM, um, from that perspective, how could you prevent it from exposing sensitive data to the end user?
Um, but then, you know, you gotta think about these more complex issues as well. Like how do you prevent somebody from poisoning the model? How do you prevent, um, you know, some of these other, like how do you prevent it from hallucinating?
Uh, these are all, you know, sort of adjacent to security concerns. But, um, but nonetheless, we see some security teams focusing on this, um, increasingly. Um, additionally we also think about, you know, the, the LLM sort of security use case is a little bit of a just, um, increased API security use case since a lot of times, um, people are not building these LLMs themself and hosting them themselves.
They're often, you know, bringing in LLMs from third parties, which, uh, necessitates, um, APIs, right, for integration. So how can you make sure that these APIs are staying secure and not leaking them back to the host and whatnot. Um, so that's definitely something we're seeing as well.
Um, I would say additionally, one thing I've been hearing a lot lately is, uh, software supply chain security. Um, I think Kurt mentioned the beginning, um, sort of securing code that lives on the client device as well. Um, this is something that we've been hearing a lot about, especially as it comes with the PCI four, um, compliance, which is gonna be mandated at the end of March, um, in a couple months.
Um, PCI four has a new compliance requirement around client side security and securing, um, the client side, like software supply chain. Um, so this is something we've been getting a lot of questions and inquiries lately. Um, you know, how much are organizations responsible for, um, the code that loads on their end users' devices, uh, when they visit their websites?
Um, this is something we are seeing a lot of people trying to actually actively get control over, um, and make sure that they're not, you know, serving, uh, code to the client devices that could do things like download a crypto mining software onto their phone, which, um, believe it or not, we have seen somebody's trying to make, you know, personal laptops part of a crypto mining network, which is pretty crazy. But, um, so yeah, I would say the client side component is, is something I've been hearing a lot lately as well. I, I just have to say, I, I love living in a world where we can use the term, uh, you know, hallucinating artificial intelligence in a conversation like this.
Seriously, just, we, we understand about that. It's not a sci-fi movie. It's real.
Oh, It's, it's real. Yeah. Hey, so I've, I've kind of a left field question for you, Chris.
So if this, if I throw you too far off the track, I'm guessing you're thinking about this though, is, is there an SBO in our future for LLMs and s SLMs and all of these things? 'cause in a way, this is a whole nother part of the software supply chain, right? We're handing off to something that's doing inferencing, either on a chip on our handset or in the cloud, all of the above.
How does that fit into, do we need to be thinking or at least wondering how we're gonna solve this problem And not only not left field, and that's, that's right in the middle of the, the, the track. So in short, yes. You know, there's ano there's another system working group.
Um, Dmitri Rayman, uh, my colleague CTO at at SBE is, uh, a co-chairing now on, on AI bomb, right? An AI bomb has been talked about for a long time. So what does that even mean?
You know, so AI is code. So there's this, you know, same sort of standard SBOs stuff about that, but there's also the training data and the models are produced, right? And this sort of goes back to my last comment about ephemeral, ephemeral SBOs.
You know, we start with the idea that IMA software provider and every 16 years I release new code and I carve a new sbo, you know, on purist graphite. Um, but we live in a world where code gets compiled and used all over the place. You know, how do we even look forward and say that I can commit to a policy that says I will, if asked, provide the contents of this code without, um, actually going out and printing or saving or producing quadrillions of SBOs forever, you know, in, in exabytes storage.
Uh, so this AI is, you know, what we're currently calling AI is just another forcing function of the level of complexity we're at. So we need to be able to provide the answers to live up to the policies that we've agreed to, um, which is, you know, you know, in the s om case we're talking about a software inventory that I will be able to tell you what code that was running or you know, what data set was used, and we have to get there. And, and, and it's, it is reasonable progress down that path.
It's a, it's a complicated one that is very similar patterns to how we'll do other things, uh, similar complexity. Um, Kurt is, is that on your radar yet at all, kind of thinking about security of, from a supply chain for LLMs and AI and ML algorithms and all that kind of stuff? No, I mean, it's, it's certainly jumped up on the radar, especially since the whole SolarWinds thing happened.
Um, as Chris was talking, it got the wheels turning in mind of, well, if we're gonna be kind of, we're moving towards leveraging ai, AI in the sense and dynamically generating SBOs and things, is this another attack vector we potentially have to watch out for? Is how do you weaponize that and, and protect against it? Because I mean, as we see attackers evolve their tactics and techniques faster than ever, they're coming up with new creative ways that defeat the traditional approach in microseconds.
And so how, how do you stay ahead of that curve now? And so I obviously, I don't have the answer right now, but it's, it's really interesting as Chris talked to start thinking about this, this new sort of problem that we're facing. And again, it all falls back to the rapid evolution of technology.
Yeah. Speaking of that evolution, uh, just in the last week or so, uh, Satya Nadal, the head of the Microsoft was talking about the death of SaaS, meaning that's kinda the clickbait one-liner. The, what I think he was really talking about is evolving nature of software architecture that I would describe it as Today's microservices or backend code are tomorrow's AI agents, right?
We'll see more and more parts of apps built through, you know, with or through or maybe completely with AI agents. And it reminds me of going into the, uh, cloud native era of, oh, how do we secure microservices now that we're gonna do that kind of thing? That's kind of the, that's the next edge that we're, we have to work on and think about how, uh, there are different things we have to do for securing AI agents.
How are they orchestrated? Is it Kubernetes or it, some other thing that's managing all those things. And, uh, given that we're putting AI agent building capabilities in everybody's hands, in many cases, it, uh, could make for interesting.
I use that in a nice way, uh, interesting environment to try to secure and manage. So in some ways, the future is bright, but it may be, uh, pretty intense at the same time, same time. Well, and I think kind of building on that too is the, the technology behind ai, it's backed by machine learning.
Like you're, you're making technology autonomous, right? So it's not as predictable anymore. So how do you secure what, when you don't exactly know what turn it's gonna take next, Non-deterministic, right.
Well, I, I gotta add a note, a note of hope though, because it's easy, you know, to your point, uh, Kurt, the short answer is yes, because there's a new attack vector. Oh, yeah. Um, but you know, throughout my career I've been arguing this one, it's like, we'll probably keep the lights on.
It's like, no, no, if we don't do this and that, then you, we will, you know, the, we're on this, we're doing this call right now. We've managed to figure out everything else up to this point. And not only that, but I think that we, we've been mowing the lawn.
I think, you know, what we need to do, generally speaking in cybersecurity has been known maybe forever, certainly 50 years, but we haven't gone around to doing the vast majority of it yet. 'cause we haven't had to. But as we do, and I, I will take a risk and, and put a lot of my, my faith in policy, you know, in, in real policy transparency, you know, in, again, in this decade it gets harder to be an adversary because, you know, these are the happy World War II fans out there, you know, or no fans, you know, but the, the Ubo wars, right?
There was the happy days when you could just have a u-boat and sink shipping all day long. You know, that's kind of, most of the world, most of the, the history of the internet to date. It's not necessarily gonna stay that way, that long forever, where there's always a new attack service and there's always a, a, a new way when the last one is, is blocked.
I think we will, we'll keep it running. We will all be fine. And I think over, you know, at least over a period of decades, being an attacker will become much, much more difficult.
I mean, I might argue it already is becoming more difficult. It 'cause the, while, while the, the technologies we use as practitioners are getting more advanced, that helps make it more difficult for the adversaries of the world. But that's not to say that they can't employ similar technologies, right?
So now we're kind of, we're creating that chicken and egg problem all over again and playing the game of cat and mouth. It's kind of the next arms race, if you will, as technology evolves, everybody has access to it. Well, let's do this.
I appreciate all the conversation and we brought up a number of topics Um, just as a kind of concluding thought, uh, we, we've been talking about what are the things we need to be thinking about. Maybe they're newer, maybe they're on the horizon, maybe already working on this today. Um, if you had to say, there's one thing you'd really want to emphasize this, if you were, you know, somebody who's listening to this and maybe making a few notes, the thing that sort of stands out to you as something really important to be thinking about in the next, let's say, six to 12 months, if not today.
Um, Kurt, do you want to give us your thoughts and then Kathleen, if you would, and Chris, you can wrap it up for us. Sorry, did I say Kathleen? I mean Catherine.
Excuse me. Kathleen. I work with a Kathleen.
Sorry. I've been doing that. All good.
Okay. Yeah, I, go ahead, Kern. I mean, it's, we wanna avoid that situation where everything is a priority, so nothing's a priority.
Right. I think we, throughout this conversation, we've highlighted the importance of esmo, is we've highlighted the importance of application security and how it's, it's becoming more important than ever because our application code is, is literally going everywhere. And that's, that's kind of the gateway for a lot of the attacks we're seeing in the world today.
And so I think the, the emphasis is on application security, but it's also to say, let's not forget the rest of it. Because all of the, the other parts of cybersecurity are hugely important, and we still need that visibility. We still need the coverage, and we need to be thinking about ease of use as well, and avoiding the sprawl.
So I know these aren't necessarily specific cybersecurity things, but they, they help you simplify your approach and, and focus on what matters. And that depends, that, that changes everywhere you go. Every enterprise or company has different priorities.
And so I think focusing on those things help enable us to, to focus on what matters for where we're at currently. Good. Catherine?
Yeah, so I mean, like Kurt said, you know, we wanna make sure that we're not making everything equal priority. So I think when it comes to application security, which is of course, my area, what I would say is most important in this space is visibility. Um, the attack surface is getting more complex, applications are getting more complex.
Um, you know, where they're hosted is getting more complex. So how do we actually have visibility into our entire, entire application attack service? How do we have visibility into the APIs developers are creating so we can actually secure them?
How do we have visibility into the software they're adding, um, to these apps? Uh, that I would say is probably the most important thing for application security and also one of the most challenging things. Excellent.
Chris, You know, Kurt and Catherine both on exactly where I'm going, so I'll just build on that. You know, do do things that save you time to transparency. You know, if you, you know, don't panic, nothing's on fire.
And, and when things are on fire, panic less, right? Just take your time and, uh, getting visibility, you know? Yeah.
Look at how long it takes you to figure out. And anytime you find a, a, a way, you know, in this, in this topic we're talking about here, to spend less time to figure things out, you have all that time back to do things. And it's easy to just, you know, particularly in transitional periods, to just do more and more and more of what you've been doing, you know?
But, uh, understanding the environment you're in so you can apply your resources appropriately is, is everything. And there are lots of ways to do that these days. You know, there's, there's a lot of rush, panic, and there are a lot of, and you know, I will say it, AI and things like that out there who will actually make your life easier, give you some of your time back.
Mm-hmm. And to feel better knowing what's going on, make, make, and make better plans, a better strategy, Uh, to that point. Exactly.
Chris, and, and Catherine mentioned it around, uh, ml, you, some of the things that I'm really excited about AI is actually just the understandability of what's happening. You know, Kurt mentioned about as things ramped up or, or you did, uh, uh, in, in the, if the tax doubled, right, how would we handle that if we're already maxed out? So some of it is just handling the volume of things that are happening.
But I think one of the things that I think is most exciting about generative AI is it's also so complex. No one person can understand the full system, right? Or maybe even understand truly what's going on in a case of an attack or where you have vulnerabilities.
And generative AI is starting to make some inroads and help us understand systems and, and giving us some insights to some of the complexity. We may not be able to fully get into our head all at once. So, for example, I've been doing some work around how do you modernize mainframe applications?
Well, nobody was around that built those things. Well, maybe people that built the network aren't even around, right? So help us understand what really is happening with all this data that we've collected.
And the natural language interface through that is, is a great aid. And I think it's just a real practical thing that we can start to begin to use today. So, don't think of AI as just as the next, you know, it's gonna replace all of our software, and it's all gonna be different.
And what do we do? There's things today that is already helping us with. So, you know, there's some real things too, not just what's on the horizon.
Well, thanks to all of you. It's been great, Catherine. Uh, we appreciate your perspective, and Kurt, you're bringing, um, your experience and perspective.
And of course, Chris, always good to be chatting with you and your connections into the security world. And some of the folks are working, collaborating together, which by the way, is another superpower we have in security. And that's the fact that we work together and collaborate on, on these things.
We're not going at it alone. So thank everybody for their good work that we're doing to help advance. We hope this has been a helpful conversation for you in thinking about the, the last great cloud transformation, what we're doing differently and thinking about, uh, as we move forward.
So as we've got our heads down, getting stuff done, getting our priorities done, getting our plans in place, and executing for 2025, but also kind of thinking a little bit about what's next and what we might be considering and learning from others that are working in our space. So thanks to all of you. Thanks everybody for joining us today.
And thank you to the Cloud four team for, uh, for sponsoring, um, our show today. And we look forward to joining us either on another recording or Sure. And check the calendar for one of our live events where folks can ask questions and engage with us in a similar kind of conversation.
We have many of those coming up. We'll talk to you again soon. Take care, everybody.
Hey, everyone. Trouble with Tribbles, I mean, tariffs. You're watching Textron Gang.
Hey everyone. Happy Friday. Thank God it's Friday.
It's Alan Shimmel here for Textron Gang, and thanks for joining us. We've got a lot to go over today. We've got trouble with triples and tariffs.
We've got software, software, supply chain issues, and serendipity as a strategy, or as some might say, throw it on the wall. Um, a lot to go over. Let me introduce you to our gang members for today, though.
First of all, joining us out west. She's still pretty in pink, not red for Valentine's Day, but pink today, it's our own marketing guru, radio host, everything. Little bit of everything.
Lisa Martin. Hey Lisa, how are you? Hi, Alan.
Great to see you. Excited to break into AI powered serendipity in C Block today. I'm excited for it as well.
Anyth, I always like serendipity. It reminds me of the, the ice cream shop in New York. Aw, yeah.
We used to have one down here in Boca at the Boca Resort, but they closed it and been missing it since. But I'll be in New York soon, maybe I'll stop. It's gonna be a little cold for ice cream.
But anyway, welcome Lisa. It's great to have you here joining us. Our man, he's not lost at sea, but he's out at sea.
Resident security expert defender of the Maple Leaf, our own Chris Blas. Hey Chris, how are you? Loving life.
Hankered off Marjo key. M-A-R-J-O-E. You can Google maps that to see where we are today.
And, uh, glad to be here. Looking forward to the conversations. Is Marjo key, uh, settled?
Are there people living on there or is that just No, it's, yeah, it's an island. It's a hundred, a hundred yards sort of north or south, 50 yard, east to west, you know, north of, uh, uh, the Sugarloaf Keys. Yep.
So the Snipe keys kind of cut the lower keys in a half. Yeah. And the east side is the quiet side.
So we navigated over here last night at their visiting friends and family in he west, and spend the last week with Donna on board and enjoy the manatees and herons. Absolutely. You're still south of marathon?
Yeah. Yeah. Lower, lower keys.
So the, the top of the floor reefs is about three or the square miles of shallow water here. These boats were designed to build for. So excellent.
This is their home stomping round, Enjoying the weather's. Been well, it's been a little windy up this way, but the weather's been nice otherwise, besides the wind. So enjoy my friend moving from the Florida Keys, which is it about, well, zero sea level, he's on sea level.
Up to the Rocky Mountain Highs. It's the guitar man, Mitch Ashley. Hey, Mitchell, how are you?
Hey, good to be here. Best Friday ever. No manatees around here, but you know, hey, we got the Rockies and, you know, got other stuff.
No manatees, huh? No manatees this week. Alright.
If you ever see a manatee out there, you let us know though, right? Boy. Uh, yeah, we've definitely lost the coastline in sea of Florida.
Yeah, it'll be, it'll be quite a, a thing. Alright, moving from Colorado to Harrison, New York. It's cold.
It's cold, and, and we're stocking up on wine beer from Europe because, well, it's gonna get more expensive. Well, isn't that a great segue? He's our chief content author of Mike Ard.
Mike, you know, I, i I, I said something about Tribbles, but I meant tariffs. Mm-hmm. We've got troubles with tariffs perhaps here.
I think, uh, grant, you kick it off. This Has been foreshadowed for some time now, but we've seen Acer raise prices 10% because of tariffs. I'm sure others are gonna follow suit.
And we're taking a look at a little bit at how all this stuff is gonna impact technology. The big tech companies, all the way down to the people who make laptops. Seems like everything's gonna get a little more expensive.
And it's not clear to me that it's for a good reason. But Alan, what should we expect? I think we should expect a kick in the rational exuberance where it hurts, right?
Irrational exuberance. It's what made this country great. And then every time someone pulls the plug in, and this could be the plug coming out here.
I mean, look, I, I call this issue tech sovereignty, spoke about it yesterday on my shimmy, says LinkedIn live segment, and you'll be up on YouTube. We, the consumer, meaning all of us as consumers, are the ones who are gonna get hurt here, right? Because not only does our technology wind up costing us more money, and, and let's face it for some of us, we'll say, we'll bite the bullet and pay more money.
'cause I need it for some of us, it'll just move that technology a stone too far right? To, to, to do. But we shouldn't think for a second that it doesn't have a reciprocal thing where our technology, our goods become too expensive for people in those markets.
And some of those markets are pretty damn big, right? And so this has a, a rebound domino effect around the globe that we wind up. Just that we, like, we have data sovereignty where we're going to keep our data just on our boor in our borders.
We're just going to keep our technology within our borders, and we'll all wind up driving those little bad cars that they had in the Soviet Union right before it collapsed. Because we get, don't have access to other vehicles, right? Because the other flip side of this is, it stifles innovation, right?
If I'm, if I'm in essence selling in a walled garden or protected market, right? I don't have to worry about external competition. Where's my, where is my, and I can't sell to external markets 'cause I've been shut out.
Where's, where's my motive for innovation? Where is, you know, where's the market at work here? So this is gonna put a hurt.
I, I don't realize, I, I think America is rah rah, rah, but this, this cuts both ways. And it's gonna put a hurt on these larger American technology companies who need the world market to make the money. They do.
We can't make enough money just selling to a US market. Hmm. Lisa, there's a cascading effect here.
And I wonder if marketers are talking about it yet, because, um, if I can't hire, or if I can't keep enough people employed, then I start to lay folks off and then it has a cascading effect through all kinds of vertical industries. And suddenly the people in who might be working for, I don't know, Dell or hp, pick whoever can't afford to buy that car, and then et cetera, et cetera. So quite literally are we, you know, in Alan's point about to shoot our toes off, It's a really precarious situation that we are in.
Uh, over the last couple of weeks we've seen China reacting. Mike, you mentioned Ace is already saying, we're gonna have to raise our prices by 10%. I think it's a challenge for, it's gonna be a challenge for every organization to understand how this is actually going to unfold, how it's going to impact the end user, the consumer of whatever product.
It's, whether it's, um, an acce or laptop or something more from Apple or a product you're buying on Amazon or eBay. And I think that from an employment perspective, uh, organizations are gonna have to be really mindful about how they're hiring, who's on their teams, what talent they need to have to be able to combat the price increases that they're no doubt gonna have to invoke in order to survive and make the money that they are used to making. I don't know, I don't know, Chris, you know, is this by American?
How far are we gonna go? Do I have to wait for a laptop that's gonna be made? And I don't know, I'll pick Ohio or wherever it might randomly be.
That might be, what, three years from now? If I'm lucky. If you're lucky.
I was gonna say 2035. No, even, I can't find anything good to say about this. So look, you know, the, you know, this is a freedoms issue, right?
You know, freedom market, capitalism, freedom of speech, democracy, all these things, open source, you know, free internet is a very American topic, not uniquely American, but very, this is one of our founding principles. And we've watched, and you know, maybe all of us here have had some hand in, you know, selling products to countries like China, you know, who want to have the great firewall that want to have the close this. And we've watched Russia go through this in the last, you know, five years trying to have the, you know, the, uh, every man's, every nation's an island, you know, uh, approach to things.
And in my opinion, we rightly look at that and say, fine, go ahead. You will reduce your competitiveness geopolitical globally, economically. And, you know, we will stay open and engaged.
But terrorists are a thing, you know, sometimes you need to do things free, free of speech, you know, doesn't mean you can yell, fire in a theater, you know, to have, uh, free markets and, and proper, you know, uh, cap capitalism. You need, uh, some rules. And if you look at, know, I correct my focus on supply chain.
I've looked at the presidential executive orders across the Obama, uh, Trump, Biden and Trump, uh, and this current administration on supply chain. And I, you know, interestingly, kind of wind up, there are some reasons to do things, you know, the two political sides can throw this back and forth. You did it too.
You did it too. But what we're doing right now, blanket, tariffs, you know, this is the great firewall thing. Again, we're gonna make a wall around America, and that's going to work better than it doesn't work in China, or it doesn't work in Russia.
No, you know, this is not, this is not a useful approach. And we're doing a big transfer from the consumer into the government. Every tariff is a tax on every product that goes from the private sector to the public sector, which again, you know, is not particularly an American approach.
We like to have money in private hands so that people can innovate as opposed to shoveling it into a federal coffer. Hmm. Alan, how silly when this get, because I remember being down in Florida and you go to the mall and people would be coming up from South America, various countries, and they would buy a suitcase and then load up crap in it and make like they owned it the whole time.
And so, you know, are we gonna see Americans doing that overseas? Yeah. I mean that, that, but most of the goods they were buying were not made here.
They just bought 'em here. They called, came from China for the most part. Or Thailand, or Vietnam or wherever else in the world, right?
Because, you know, it goes back to Tom Friedman's flat Earth Capital goes to the, it's like liquid. It goes to the lowest, you know, to the most efficient place usually. And now you're kind of messing with the natural laws of physics there, if you will.
But how bad can it get? Let me give you the worst case scenario, actually, let me, in a best case scenario, other countries retaliate and they put up their own walls. And we all live in this walled walled garden where we all keep our own, we all consume all everything we make.
And that's a best case scenario. If you believe, you know, the rose colored glasses and from the, if you believe the people with rose colored glasses, the world will come begging at their knees to please give them access to the US market. They can't exist without it.
I don't think that's what's gonna happen. So at best, we have this world garden where Europe is its own market. China's its own market.
The US is its own market, et cetera. But it gets worse. It could get worse.
Canada, Mexico, go make deals with China. China go make deals with Europe, as a matter of fact, Europe, China, Canada, Mexico, the rest of the industrialized world as we know. It says, you know what?
We don't need America between the six seven of these markets. We're three times the size. Let America keep America.
We're gonna do our own ai, we're gonna do, we, we proved we can do it cheaper and better. We're gonna do our own space systems. We're gonna grow our own food.
We're gonna do our own tech. Thank you very much. Google, apple, and Microsoft.
Nice knowing you. And this is, you know, the, I grew up in the seventies, you know, and, and watching this play out through the eighties, you know, the free market. Remember the, the when the GOP when I was a Republican, right?
You know, was, you know, the argument was you shouldn't be able to, you shouldn't limit the US federal government should limit an American citizens' rights and ability to do commerce internationally. You know, again, certain tariffs, rules, you know, we're not talking about, well, You weren't allowed to bribe people, which you can now. Well quite, yeah.
And just want To throw that in. And we won, right? The Cold War, you know, we, we got China and Russia basically to a accept capitalism.
I mean, you know, that whole argument that we were making back then that that has driven positive change in the world. And now we're arguing the opposite. You know, smaller is better.
Lock the doors, put up the walls. Historically, as you look across nations states, that's a very normal thing to do. You know, the modern era and the benefits we have are predicated basically on not doing that.
So now we're adding to the, adding to the, the, the drag on the system, which will slow down economic growth and everything that goes along with it. Yes. Well, one of the things that this does is it forces everyone to start looking at their supply chain and what alternatives do we have.
And where it hurts is where you don't have alternatives, whether it's shipped from Taiwan or, or China, um, or, you know, goods from Canada for building homes and, you know, things like that. So it, it's, it, it's something that I, I saw this interview and I actually had someone who said, no, tariffs aren't attack, aren't attacks on us. There are attacks on the person who makes the goods.
And the interview was also with a second party who was a importer of goods. And he explained, he said, no, I've been doing this for 30 years. It sits on the dock until I pay the tariff in order for the good or good to enter their country.
And, you know, I don't, I don't eat that. That goes into my pricing to my customers. So I think America's gonna learn pretty quick what tariffs are really about, where, who really pays those, uh, those amounts and, you know, what's politics and what's reality of it.
So I I I also think that a lot of this is bluster, you know, to try to, you know, pick it out the big hammer and wield it, swing it around. As soon as you hear people complaining about it on the news, being interviewed by the local TV station, it's not gonna be pretty. Look what we've done for the price of eggs.
Look those eggs, that's, that's probably a lot As it, yeah. Let me, let me wrap up a little bit on this. You know, I lost my thought there for a second, Mitch.
What the eggs thing, but what, what we have, or what we're going to have is, you know what? Cancel my thing. I forgot what I wanted to say.
We Gonna talk about triples. Lemme Wait, wait. Let me, let me jump in there and then you can kick It all.
You go, Mike. All right, So let's take this to its MP logical conclusion. Would we see Alan, US companies deciding to move their headquarters outside of the US because it just made more economic sense for them to pay taxes somewhere else?
Well, if, and, and if the markets are there, look, it, laws of physics don't change. I, you know, that's a science fact. Everyone's entitled to their own opinion, but facts are facts, right?
It's another hard lesson. I think we have to learn facts or facts. Opinions are like buttholes.
Everyone has one. So if it makes economic sense to move your headquarters outta the us 'cause you have economic advantages in selling to a bigger market, making more money, it's gonna happen. That's, that's the way of, that's the way markets work.
You, you know, it, it, it is what it is with that. And I, you know, who can blame them? Quite frankly, who can blame them?
You gotta go where, where your business is. I just wouldn't recommend calling someone else's opinion butt hole. But that's a different topic.
Well, sometimes I do. But, but here, here's the good news. Here's the good news.
If all of these countries stop taking guns that we manufacture here, think of all of the guns that'll be available here. That's the good news. Or the guns that might never get made.
That's another thought. Oh no, we won't start making guns. We're America.
America. We make guns in America. America.
So, I mean, it, it's gonna be an interest as it plays out. It will be interesting, certainly nothing else. We'll take a break here on Techron Gang.
Let's come back and talk about software supply chains. Does it feel like we shoveling sand against the tide? We'll go to our boat person right after this Discover Techron group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back. And if you hadn't noticed, there was a report about the Lazarus group, which is associated with North Korea, is attacking various software repositories that are out there. And I feel like we've talked about this issue before, but I cannot help but wonder if these hubs are essentially the defenseless because, well, maybe all the warnings and concern about DevSecOps, it just gets lost in the noise.
Or Chris, is there something else at work here where we can't seem to get our act together around the notion then these things are a part of the attack surface. Well, we're getting our head around it, right? You know, and the, you know, the, I I was just thinking I should know this.
I don't know if we share the backgrounders for these segments with, uh, the viewers, but if we don't, we should, right? Because there's article, uh, uh, on the background on this one about, you know, are we defenseless in supply chain? And, and the short answer is for most organizations, kind of, yes, that's where we are.
And we always have been, always have been. This has been a known issue for a long, long time. This is about off, uh, inventory.
It's no, you know, do you know who you are, what you have, what is doing, and what's going on around you? It's one way to look at situational awareness on that. Do you know, you know what?
You have no, right? Just inventory of the hardware in organizations has been, has evolved. Well, we have asset inventory stuff and so forth.
Inventory of the actual software, what's in the software. That's where we're right now. That's this issue.
You know, when we talk supply chain, now we're talking about people putting code inside the code that you actually bought and the people you bought it from didn't know that it was there because they're including open source libraries and whatnot. And there's been no way, logistically, economically to do better than that until about now. So the, you know, and then that background article, you know, as we're talking about in the green room, I think defenseless is the long word, is more defensible.
You know, is this reasonably something that you as a small organization can defend yourself against now? No. Um, however, you know, there are major vendors or banks and other organizations have been working on this for years.
It is can be done quite well. And I think in, in the, in the right sectors with the, that have the resources and have the motivation and so forth. I think in the next, you know, in this decade, you know, in the next several years, we will see some systems that are remarkably defensible and defended from these sort of attacks.
Uh, but we're just not there yet. Not, not, not for everyone. Well, right now we talk about the software supply chain security, and a lot of that is talking about what are the software that goes into our software creation process, whether it's open source or NPM packet managers and, you know, PII for, for Python.
You know, it, it's, I think it's almost one step beyond that, though. We're at a point where we need to think about this as software supply chain integrity. Just like we do software, supply chain integrity for products, right?
It isn't just the Tylenol that someone broke into and put in some, you know, foreign substance that we don't want in our, in our bottle of Tylenol capsules. It's the ingredients that go into making, you know, the product. And in this case, we're talking about software.
And so what are, what is the integrity of all of the ingredients of software that's, whether it's libraries or, or repositories or our own, as well as the manufacturing process, our own tool chains. So we, I think we have to kind of trace it back one more step and learn the lesson that we did in the physical supply chain about it's the integrity and the, uh, provenance of where things came from, uh, in really knowing What's going into our software. And ultimately, that's where it's headed.
That's what you have to do to really secure the whole supply chain. In my cynical moments, Alan, I will look at this and I will say, wow, we've been talking about this for a while. And then I, I wonder if the cyber criminals and the folks over in North Korea like read these discussions, watched these videos and said, what an awesome idea.
And now we're gonna see more of it because they figured out that they can do it. So how much of this is kinda like, you know, we kind of led them to the right idea. No, well, look, the bad guys never miss an opportunity to take advantage of a, of a weakness, right?
They're constantly, they're not, they're, they're not me too guys. They're not followers. They're always probing and figuring out.
But this is an obvious, this particular thing we're talking about here is sort of an obvious whole weakness that's been exploited number of times. Here's, here's the real facts, and I think most of our audience probably knows this. 'cause we deal with a lot of developers and a lot of cybersecurity people.
But for those who don't, let me, let me explain it to you. 80% or so of the components that go into any app that you're using today are probably open source or preexisting components that get stitched together Frankenstein style into an application. These open source or pre-ex prefab components aren't just existing out on the edge wherever the edge in the cloud is.
They live in something we call repos repositories. And there are some very, very big repos. Uh, the, the, uh, nexus repo artifactory, GitHub itself is a huge repo, right?
There's probably less than a dozen reposts that probably account for 90 plus percent of all the software components that go into every application that we use today. That concentration represents an opportunity for supply chain security because there's an obvious choke point. That choke point exists when you download that component from a repo, it's gotta be downloaded.
I've never understood why we haven't put the onus on these repo managers to check the integrity of the software that's being downloaded from the repo. If we could do that, we'd go a long way to improving our software supply chain security. Now, I recently had a conversation with a security vendor who actually manages one of those large repos Mitchell notes, who it is, I don't know if they've announced this product yet, but they're doing just that.
They're gonna put, you wanna call it a firewall, Chris, you like firewalls, you wanna call it a firewall at the repo that says, Hey, before you download it, I'm gonna make sure this is the right file. It's the latest. It doesn't have a known vulnerability.
The check sum is correct, whatever. Right? But we're not gonna let you download an in secure component.
Now, the real win will be if someone says, I can make one firewall that works across all of the repos, not just any one repo. 'cause as I said, there's probably less than a dozen that you want to hit. But if we could do that, and I don't know for the life of me why we haven't done it yet, right?
But if I, if I was gonna go start a company, I'd go do that right now. Go build a repo firewall that works across the 10, 12 biggest repos, and I'm gonna filter out any bad stuff and watch what it does for our software supply chains. Chris, I saw you had your hand up.
Go ahead. Yeah, you know, I've always loved supply chain, uh, because it just begs all the questions, right? You know, firewalls are great, right?
I started my career in firewalls, and it's a very simple thing. On the edge of your thing, you should probably do a stuff, you know, supply chain, you know, threat intelligence, you know, spreads that we've done in the last 20, 25 years. You know, how do I actually get outside my walls?
You know, again, to our, our first segment topics like that, and we're pretty good at that. But with supply chain, there is no single point, right? And a number of us have been working on this for a long time.
I think I, I think I have a, a vision. I, I think a view on architecture that I think works has been tested enough, but it's, you have to include yes, repos. And I've been working with, you know, various repos and so forth over the last couple years.
They've been going down this road, they're getting better. They have a role to play. But when you look at the entire supply chain, you take, you know, a a high demand sector and all the pieces together from the ISAC that's already sharing information and the vendors and the integrators, you have a lot of choices.
You know, the simple, the sort of firewall answer is, I am going to take all of my supply chain information and get in, in advance and have it in one spot. And that makes you think through the, the fact that this is not how anything works. You know, it's a dynamic.
What we really need to do is represent our entire supply chains. And this to, to my earlier point in critical enough industries that can be done today, and I think will be done in the very, very near future in real time ways. So that every regulation, every contract, every agreement, every really, every, the, the characteristics that define my relationship with my supply chain partners and their supply chain partners is not just something I can call legal and pull up in two weeks, but is actually acting.
So when I want, for example, an SBO from a third tier provider who had, and everyone has agreed in advance that I will get that within 12 milliseconds. I'll have it in 12 milliseconds, and I will have the right, And then what are you gonna do? But then what are you gonna do?
You, we could do a whole, we could do a whole half hour on that one, but, right, because that's what, again, supply chain forces you to go through all the steps. And they're not infinite. And in our entire industry, for my, you know, decades of doing this, we're addressing the firewall.
We're coming up with one thing at a time. It's a good idea. It needs to be done.
But putting it all systemically together, doing the dirt, gently, holistic detective agency inevitability curve sort of thing takes a long time. But we're getting there. And, and supply chain is one of the things that forces us to work through each of those steps where we find we have, I think we have workable answers at each of those steps.
We don't have the workable system that ties it all together. You know, I, as much as I'm all about s software, supply chain security and, and think that that's critical for us to do, seems to me that though, that that's a step along the way to zero trust software. Let's learn the lesson from security, right?
We can firewall things off, we can protect things. Um, but until you're in a world where I don't trust any software that's part of that I'm building software from, and that's, that's the attitude you have to have of, you know, just because it came from Google doesn't mean that I trusted or just 'cause it came from this repo. And I know the repo said that they are gonna secure.
It doesn't mean that I believe that it's, it's secure. It's sort of the old trust but verify. Maybe it's don't trust and also verify.
That's the whole zero zero trust model. And I think that's ultimately where we have to go to, to be able to, to secure this. So my, my problem is though, and this is, this is the problem in security.
If security is too much of a pain in the ass, no one wants to do it. And is what you just described too much of a pain, PIA, 'cause if it is, it's not going to get done. And maybe that repo firewall resides not at the repo, but at the gateway to my supply chain.
But somewhere you need, look, I'm, I'm a child of network security, that's where I, I got introduced into security. It's all I know. But, but that's my point, Alan, is, is just knowing that you go through certain certifications or you fill out my questionnaire that says that you follow good security practices still doesn't mean something can't happen.
Something can get No, I want that. I wanna scam that. So you have the zero trusses.
I gotta be able to defend, defend against, wherever it comes from. Well, I've gotta be able to test whatever I'm taking down. I gotta be satisfied that it's legit.
I'm act, I think I'm actually making the point you're making, okay. Which is at zero Trust. Once again, Mitchell, you and I are in violent agreement.
Thank You. Absolutely. Hey, hey, Lisa, you know, as you to this conversation and you got all these guys talking about security, I'm just reminded of that phrase that says, you know, every company's a software company and I have a really warm, fuzzy feeling Right about now.
Yeah. Yeah. I see two parallel paths here on the marketing side and the learning side.
On the marketing side, any company that's a software company needs to be able to explain because trust is currency with its customers, how they're sourcing software, that it is secure, that they can guarantee that. And then on the learning side is this for developers and organizations to be continually educated about all the things that are popping in, whether it's from a Lazarus group in North Korea or other bad actors because the cyber attack landscape is spreading. So amorphously, I really see two parallel paths on the, on the educa well, continual education side, but the marketing side as well, because consumers need to understand that what they're downloading, the apps they're interacting with, for example, even if they don't understand the technology, that the data secure, its, and, and it's kept there.
And that's something I think is a huge challenge for any organization these days. Seems to me software should come with a warning label. Oh, it does.
Yeah. That's the s form. You can't tear it off.
It's a federal offense, just explicit lyrics, that's all. Yep. Yeah, there's sort of, there's sort of three phases, right?
You know, you know, in each of these things, as we're all saying, we've all been aware of this, we issue forever, right? You can mandate something when it's impossible and nobody will do it because it's impossible. You can mandate something when it's possible and force, you know, or you know, whether, whether internally a man firewall in 1990 costs a hundred, uh, million dollars a year, right?
There were 10 or a hundred of them in the world, mostly internally. Many organizations, you know, said, this is worth it. This expense is worth it for us.
Um, but at a certain point, by 2000, if you don't get a firewall, you're going outta business because you're losing money. And I think this, as I said, I think right now, if you are mandated internally or externally to really secure your supply chain, and you really should, you can do it. It's expensive.
It's a, it's a cost. But I think we'll move fairly rapidly as these things go into the point where if you don't do it, your, your costs are higher. 'cause a lot of benefits other than, other than security logistics and management, knowing where your stuff is and spending less time and money running your world is when security really gets adopted.
But it's not a burden. I think we'll wait and see on this. All right, let's take a break here on this one.
We're gonna come back and we're gonna talk about serendipity is a strategy. I know Lisa's been waiting the whole show for this. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. All right, we're back.
And we're talking about serendipity, which in my mind at least is a happy accident that I discovered something and it was all not pre-programmed, but here we are in each AI and some of those social media folks talking about using AI to well, program serendipity. Lisa, walk us through how this works, because in my mind, these are conflicting thoughts. That's a great point.
It, it's a bit conflicting in terms of the use of the word serendipity and what it means in real life. But picture this, you're scrolling through Netflix or Spotify or any sort of streaming service. You're not sure what you're in the mood for, and suddenly a movie pops up or a song or a playlist, and you just think that's weird.
But yes, that's what I want right now. That's what's known as AI powered serendipity, where it's using multimodal machine learning and taking all these explicit and implicit signals. You are giving the service to surprise and delight you in hopefully a non-creepy way.
So what it's doing is it's looking at different data types, textual data. What are you searching for, um, in your search queries, for example, uh, visual data. Are you pausing?
If you're watching Netflix, for example, are you pausing or hovering over certain thumbnails? Maybe you're a big fan of, of beach scenes in movies, and you pause on lots of beach scenes. So it's starting to get those implicit signals to be able to tailor the experience for you.
And then it's behavioral data combined with the visual and the textual to understand what you're clicking on, what you're scrolling on, that sort of thing to give you the idea is this really hyper-personalized experience that's gonna deliver something that surprises and delights you. But what we have to be concerned about is ai, algorithmic bias. Algorithms used to be deterministic.
If you like a, then you'll probably like B And now we have all these other signals coming in, taking note about what we're doing, how we're interacting with an app, for example, to serve up content it thinks we might like. But we have to be concerned, any company that's using this, and companies already are, I think have to be really, really explicit with their users, because trust is currency as we talk about all the time. And if you're, if my data about what I'm hovering over is gonna be used to help me, I want to know that as a consumer at any sort of product.
So data privacy, I think needs to be become much more transparent for any organization that's gonna be using AI to surprise and delight customers in this serendipitous way. How far will this go? Because, um, it's not just me.
I mean, I'm friends with Mitch there, and if the machine knows that, you know, he likes Batman, suddenly I'm gonna get all this weird Batman s**t from him because we're friends. And you how all these groups that we're in kind of send a signal, right? Yes, They do.
Those are more signals that are coming in that the devices, the software is interpreting. We talked about this the other day with Alexa and all the things that it's doing and sharing from a data perspective, like people in your household, people, you, you're friends with email addresses. So the, the concern there is how do you stop this spread?
How is it contained in a way that is applicable to this end user only so that they get an experience that is delightful rather than creepy? Um, I don't know whether those lines, I think those lines are blurred right now. I think we're gonna see more of that, because I don't think, I mean, right now you, you look up something on your laptop for a product and then it appears all over your social feeds that you're scrolling on your phone through, um, our, our, our friends and associates and people that we have text reads going to get similar information.
I think it's highly possible and it's probably already happening. Well, first of all, Mike, you should be watching more Batman, but that's, that's for another conversation. Um, your life would be much, much enriched.
But anyway, um, so we're talking about, just if you wanna combine the two topics, serendipitous is sort of happy accident is, you know, my unsophisticated definition of it. Um, and, and that's what machine learning is doing, is in essence it's taking and doing rich analysis around, uh, users' behavior. And it's doing that, of course, on large amounts of users.
So what it's doing more than just correlating this video is tagged as a cartoon character, comic book character, and, and it's Batman. And so is this over here? So let's suddenly start showing you Batman clothing or something, or, you know, trinkets.
Um, it, it's really looking at the behavior of the user. And so that can take into a lot of factors. It can take in time of day, it can take in more recent patterns, can take it, take into account historical patterns.
Um, it can also take into account other people who have similar patterns that you do that you may not share exactly the same thing with. And learning from your reactions to what I think might be a serendipitous behavior. So popping up that Batman reference might be, yeah, that's very cool, or no, that sounds like Mitch and I don't like his stuff anyway.
Um, but you know, it's part of it, it's, there's a, uh, sort of a fine line between personalization and creepy, right? At one point, is it okay who, you know, who's watching right now? How did you know that too?
That was really great. I really appreciate that. That was super valuable.
I'm glad it happened. So Chris does this, Chris, does this not feel like a recipe for the perfect online scam and a little social engineering and I take all these signals and I kind of send you something that's like so spot on you, you just can't help yourself? Well, on that thread, I mean, this is going on right now and has been for a while from the Cambridge Analytica, you know, desktop to, uh, to today the issues are the same, right?
The same tools we need for marketing demographics, right? You know, as a vendor, you know, I don't wanna spend extra money on advertising and marketing and outreach because my, my competitors don't. You know, and I do then talk about a business, right?
And it has been true since the dawn of time. You know, you know that on a stormy day 50,000 years ago, that everybody gathers by this rock and you have all this raw fish you would like to, you know, trade for things. So you, every Friday or there, you, we know these demographics, you know, the, the, the, the, as you said, downside of this, this is, we are and have been open and not just open, but actively exploited by malicious actors.
You know, we using nation state resources down to the individual level. You know, this is another path down, you know, part down this path. You know, the risk for exploitation, further exploitation, the, the sort of nightmare scenarios are unacceptably high.
You know, again, my, my hope for this one is that as this, you know, I, I think we're already, we're already there, right? At peak, creepy, uh, the creepiness factor will be enough to drive the necessary and entirely possible adaptations from a security and privacy perspective so that we can, by reducing the creepiness factor, reduce the actual risk of malicious exploitation. I think some of it's in the delivery too, Chris.
'cause if you can imagine if it's something you trust, like let's say you do have a bot that personalizes things for you and says, Hey Chris, I found this really interesting reference. I think you might like it. You are like, okay, okay, I know who that is.
I know that even though it's a bot gave it to me versus suddenly this popping up in my feed. And like, how the hell did it know that, you know, a lot of it is the delivery or the source of what you, would you view the source of how that got to you? Yeah.
Well, You, you think about it as, you know, AI's gonna give us assistance, right? Everybody gets an assistant, they get a staff, which is wonderful. But look how this plays out in a really effective organization, a good, uh, corporation.
You got the CEO for example, sitting there and all these people around him helping that person make decisions. Then the negative version, you have some royal court where the monarch at the center can't actually see the real world anymore 'cause they're surrounded by syco offense and corruption. Well, this Sounds familiar and right.
So yeah, this can go either way. It does go either way, right? It can either be very helpful or it could be its own disease.
Lisa, lemme wait. Lisa, Chris used to phrase, I just wanna check in with you on this peak. Creepy in there.
We're at that point right now, I mean, I just heard a bunch of marketers say challenge accepted. Oh my dear, oh dear. Oh My beer.
Exactly. The line I think between hyper-personalized, delightful experiences and creepy is so thin. It's, it's blurry, but I think it's, I think it's a dotted line right now.
'cause we're seeing companies already do this. We're seeing organizations in media, entertainment, social media, for example, hospitality or using multimodal machine learning in this way to be able to deliver these delightful experiences. But any marketer would need to be aware of how are we doing this?
What are the outcomes that we're delivering? And can we explain the, how we're doing this to our users to maintain their trust, to show them it's not creepy. There's no algorithmic bias happening here.
That's a huge job for any organization. Marketing can take the charge there because that line is so dotted and maybe very sparsely dotted at this point between relevant, contextual and creepy. So here, I, I have a bright line for creepy, right?
It's one thing to use machine learning and AI to say I'm in the Batman Club, so I probably like Iron Man too, though. That's a DC to Marvel thing. Maybe not, but you know, it.
So it's one thing to, to gather my, what groups I belong to on LinkedIn, Facebook, what have you, who people I follow on Twitter or whatever. It's another thing. And, and then present products or things to me based upon that.
I, I, I get that, that's part of the thing. And I don't think that crosses necessarily. The creepy, creepy is when I'm talking to my child or my wife about something and I get a popup for that thing.
And this is like the Lisa, if you remember, I think it was last week or the week before a case was started in California against Amazon that they were listening in. The listening in is creepy message to marketers. Don't be listening in.
If I'm giving you permission to track where I go online, what groups I interact with, what banners I click on, I get what I deserve. And, and you know what, sometimes I do get some very serendipitous kind of things that I didn't think of. I especially like it when they recommend movies or TV shows that I've never heard of that I wind up loving, right?
I've caught a lot of those lately, but I don't like when they're listening in that, that to me is, that's peak creepiness. Creepiness. Absolutely.
I completely agree with you. So that needs to be a key message. We're not let that, we're not listening unless you're opting in specifically You wanna do that, God bless you.
But you know, to me that that crosses the creepy line where I'm not gonna buy stuff from you or, or, you know, contribute to your creepiness. Well, and, and this is where I set my supply chain thoughts. 'cause yeah, again, as a vendor, if I was that vulnerable to that sort of, you know, creepiness, uh, crashing my market, it's possible.
And I would might go to this extent of saying, we will give you, you know, a trustworthy to a given, you know, high level of trust, little archive of everything we ever touch, touch, record everything right there, all the time in your hands, not in ours. That sort of thing. Because in, again, in supply chain context, we have to have those things have to, in the near term future in certain areas to run anything as a, as a product vendor, serving consumers, you can put that sort of thing together.
You just, you know, go over the fence. Not only are we not listening, we will be really absolutely clear with you. Everything we touch everywhere we put it, why not?
What do you have to lose? Maybe that's where we're headed. Well, Well, well, jeepers creepers.
I got all this email from Batman that I gotta go answer, so I gotta go. Okay. Boy, wonder I'm Iron Man.
Hey, we got it. We gotta go though 'cause we're outta time here on Text Drunk Gang, have a great weekend, everyone. Um, stay tuned.
Monday, we will be back with even more great Textron Gang and text Drunk TV material. It's been, it's been a crazy week. Here's so much going on.
I'm telling you the show is Therapy. Mitch, Lisa, Chris, Mike, thanks for joining us on The Gang. Thank you for joining us on The Gang.
Stay tuned for the rest of text on tv. This is Alan Shimel, we're out. Hello and welcome to the latest edition of the Techstrong AI video series.
I'm your host, Mike Bazar. Today we're talking with JB Baker, who's vice president of Product for Scale Flu. And we're having a chat about well, AI and energy and the environment and how might all this stuff actually come together.
JB welcome to the show. Thank you and great To be here. A lot of interesting promises have been made of late, including a Project Stargate, but every time I turn around lately somebody is pledging billions of dollars to go build data centers for these AI initiatives.
And I cannot help but wonder, um, are those things realistic? 'cause last time I checked, it wasn't so much that we didn't have enough or say power. We just don't have the ability to distribute it where it needs to go.
And so can we actually build these things? JB what's your thought on where are we on this adventure? Yeah, that's, uh, as I've been looking at this part over the last couple of years, um, yeah, uh, getting the power to the data centers is, is a tremendous challenge.
Um, and, you know, we see, uh, I've seen plenty of information about, uh, data center build out plans being delayed because they're still fighting through the regulatory issues to get local power plants put on, brought online or, you know, more power brought to the grid. So that is, uh, that's definitely something that has to be done hand in hand as we are, uh, as an industry planning out these, uh, these massive build outs for data centers to, to support the, the demand for AI and other compute functions. And how much do environmental concerns play in this conversation?
'cause every time we kick up a new data center, we kicking off some carbon, but to what degree, are the data centers contributing to global climate change? And how might that be more complicated than it already is? Yeah, I mean, data centers are depending, I see different stats, uh, but you know, they somewhere from, from high single to low double digit percentage of total worldwide power consumption.
So they're a, you know, a massive contributor to the potential for, for carbon, uh, you know, emissions. Uh, I know that companies like, you know, some of the major hyperscalers like Microsoft and Amazon and, uh, meta and Google, that they have renewable energy initiatives to try to make their data centers net zero or, or, or negative in terms of total carbon. Um, so those initiatives are there.
Uh, I, well, it, it's kinda governments are, are playing in that as well. You know, the EU seems to be a little more aggressive on pushing for, for those, uh, carbon neutral and, and carbon improvement, uh, capabilities, and then other geos that we seem to go seem to push for it and then back off and push for it and back off. So time will tell on that.
It's hard to say where we're gonna be and by the end of the decade, but, um, there's a lot going on here and not to mention the least of which is we are gonna see new classes of processors, right? Not everything needs to be a GPU to run these models. So will we get more efficient in terms of the infrastructure that we're deploying as we go along?
And will that make a difference? Yeah, that's a, that's a great direction. I mean, efficiency is crucial to, uh, to meeting the demand that we have, that this massively growing demand for the compute and the data generation, data storage, data movements.
So, uh, yes, absolutely generation over generation, the individual components are becoming more efficient in terms of how much work they can do per wat. You know, it, it at scale. Fluex, we've we're focused in the storage and memory domain.
So like within our components, every generation is, is being able to provide twice the amount of performance, twice the, the throughput of data transfer, uh, per wat of energy consumed. And if you listen to the NVIDIA keynotes, um, I don't remember his exact jenssen's exact percentage or, or number of, of improvement there in terms of, uh, flops per watt. But every generation of Nvidia, GPU is massively more power efficient, though they're also massively more power debts, right?
You're, each processor is consuming a lot more power, but they're able to do, say, multiple times the amount of work per power per watt. Uh, and you're, you're definitely right there on, it's not just gonna be, uh, the general purpose GPUs, right? That's, um, the, the black walls and, and that class of product.
Uh, 'cause just as if you, if you look back several years, we, there was, uh, a migration or a fragmentation of the, the general purpose processing capabilities. You know, you had the X 86 processor as kind of the standard in the industry, right? But then graphics processors came online to handle specific tasks in a much more efficient manner.
The same thing is starting to happen already, even in the the GPU segment, even for ai, where you're gonna have, rather than just general purpose GPUs, you will have, uh, LLM specific GPUs. You will have inference specific GPUs and other types of tasks. You're gonna have processors that are optimized for that, for those tasks.
Uh, a couple of examples already. You see meta investing in their own, uh, internally developed processors that are focused on what they care about most. The LLMs, uh, GR as well, uh, offering GPUs that are more focused.
And their claim is that they're able to handle the LLM like a chat GPT, um, request much more rapidly than, and much more efficiently than general purpose GPUs. So you'll see that fragmentation to enhance the efficiency of the processors. And then other components in the, in the industry are gonna have to step up as well.
I mentioned the storage components becoming more efficient. Um, there are innovations in the memory domain to allow for more capacity and more bandwidth of memory attached to each processor, um, or each core within those processors to ensure that those processors are fed with the data that they need to be productive with all of the energy that they're consuming On the software side of this equation. Not every one in these AI models is the same, and some of them are gonna be smaller than others, and others are gonna probably be even larger than the ones we have today.
So, yeah. Um, can we, how does that spectrum kind of play out in your mind? Will we see more smaller ones in the future?
Or, you know, people are talking about, uh, making AI smarter, which might in involve some really huge language models. So where, where are we? Yeah, I, I think you're gonna s you're gonna see both ends of the spectrum, right?
You, you will see that the massive LLMs will continue to, to grow larger. Uh, there's plenty of, of graphs out there of, of the doubling of inputs or the, the exponential increase in the amount of data that gets put into training that next model to make it more generally intelligent and more generally applicable. Uh, but at the same time, you, you're gonna see things where, hey, I don't need to have, uh, my model be able to answer every question and act like every different type of profession.
Maybe I need my model to act as a, a patent lawyer. Uh, and so that dramatically constrains the, uh, the scope of the inputs that you need to put in there to get to that same level of accuracy or, or value out of the model. So, yes, I, I believe you will see more and more of these, uh, very focused models that, uh, that people will be able to, to train on much smaller data sets, and then those will be more efficient in their searches and their res their responses as well.
Do you think all this AI concerns about energy is also gonna wind up becoming a political issue? Because as the data center folks increase demand for electricity might exacerbate a limited supply and the price of electricity goes up and suddenly, you know, all the local neighbors are up in arms. Yeah, I'm, I'm gonna, I'll try to shy away from anything, any true political statements, but of the Absolutely.
It is a challenge and, and the, the knot in my backyard or, or nimby, uh, perspective will come into play. Uh, I mentioned earlier, you're already gonna, you see that already, particularly, I saw a lot of information about in, uh, Northern Virginia arena where there's sort of a data center alley and they're struggling to, to provide enough power there. So, um, in order to awash the can about data center power consumption, pre putting pressure on the grid, and raising overall power rates for you and I as consumers in our households, uh, there is definitely gonna have to be a, uh, a hand in hand plan of, Hey, as I, as I pro project putting out this, uh, this data center, I'm gonna bring online additional power.
Uh, you know, you see like the, the three mile island thing being where three mile islands will be brought back up to provide the, the data, the power to, uh, supply. I think it was Microsoft's data centers that they're building in that region. Um, and then even in the Stargate, uh, the proposed data center that Ian, Texas, that's gonna be, um, what was it, 360 megawatts, that they are co-planning power, uh, generation facilities to, to provide that power.
Uh, 'cause otherwise that's 90,000 homes worth of electricity that you're, you need to supply. And I don't think there's that excess in the grid as it stands. We also see people talking about various forms of green slash clean energy, and some people wanna build, uh, many nuclear reactors that are essentially dedicated for data centers.
I'm not quite clear how those things work or how feasible that is, but how much can these alternative energy sources make a difference? Uh, it can make a huge difference. And, you know, there's not one magic pill or one panacea for solving this energy, uh, de demand.
It has to come from multiple sources. Um, you know, I, I have, I have seen many initiatives from like, like the hyperscalers in the US where they're, you know, they're combining geothermal with, um, with solar, with localized, uh, fossil fuel based, um, energy, consum, energy, uh, creation. And as you mentioned, the those small nuclear reactors that are gonna be more sized specifically to provide the, uh, the electricity for those power for those data centers.
That's another aspect of the solving the, the, the total, um, supply. And even the going, going back many years, the location choice for where you put the data centers, um, you know, they've, they've chosen colder environments in many cases so that they could leverage just the, the natural environment, uh, to help them with the cooling. So absolutely, it's gonna require many different types of power generation, uh, to, to help minimize the, the carbon footprint that gets put in place.
So what impact will all this have on the cost of ai? If the price of energy is significant, and I have all this infrastructure that's out there, is AI gonna get any cheaper? Or is it maybe actually gonna get more expensive?
That is a, uh, you know, a lottery question, I guess. But, um, you know, in terms of the, the cost of performing an AI task, I, I can't, I can't wager in any direction other than that will decrease, right? The, the cost of, of performing a, a chat GPT task or, uh, doing, uh, uh, as Jensen referred to it as the, the virtual factories of modeling, you know, how should we set up our warehouse or, or, or testing these models, though, that's gonna come down, absolutely.
But that does not say that the investment levels in the amount of dollars that are poured into generating AI capability would decrease. I, I still see that as that's, that's on the rise. Because as we, as we decrease the cost of, of performing an individual task, you know, just following e economic, you know, supply and demand, we will find demand in ways to, to consume that.
And we'll find more and more complex tasks to put out there to, to utilize still those large clusters of GPUs. So what's your best advice to folks as you kinda look at all this stuff and they all sit there and kind of try to figure out their own plans, but, um, should I just like pick a handful of projects to focus on for the short term and, or am I, is it just gonna be, you know, pedals in the metal and here we go? I think, you know, that's gonna vary quite a bit by, by industry and job function, but, uh, but absolutely, you have to be finding ways and looking for ways in which you can leverage AI to improve your organizational efficiency.
Um, you know, it, those who don't will fall behind, will, will be falling behind. Um, you know, and even as we look at, uh, you know, from my perspective as a hardware component and, and software, uh, developer company, we have to start leveraging AI in the, uh, the development of our next generation components. Um, and leveraging AI to help us accelerate the, the generation of code and generation and testing of the code.
Um, that's an area that I, I personally, I believe that there's a, there's gonna be a, a tremendous value there in terms of being able to test, um, and find the bugs and find the root causes for child problems in, in hardware, uh, and chips as well as in software. Um, 'cause having been in this industry for 20 something, uh, years, then, you know, I just re I think back to all of the problems that, that we had as, uh, not just scale flux, but at Intel and LSI and other companies of finding a bug in the hardware and fixing it. You know, what is that root cause for that?
Something that appears so, so, so infrequently, it, it's hard to recreate the conditions. And AI with these virtual factories has the potential of being, making it where you can recreate those, uh, those conditions much more rapidly. I think folks, the genie's out of the bottle and definitely not going back in, but as is always the case, you gotta be really precise about what you're wishing for or may not turn out exactly how you imagined.
Jv thanks for being on the show. Great, thanks. Appreciate the time.
All right. ai video series. You can find this episode and others on our website.
We invite you to check them all out. Until then, we'll see you next day. Hello, and welcome to the digital CXO podcast.
I'm Amanda Ani, and with me today I have Doug Steven, he is the president of CGS Immersive. How are you doing today? I'm doing really well.
How you doing, Amanda? It's, uh, thanks for having me on. Yes.
Happy to have you on the show. I'm doing well. So tell me a little bit about CGS.
What, what services do your, does your company provide? Uh, so CGS has, has been around since actually 1984, privately held, located in, uh, in New York City. Got 8,000 people across, uh, all the continents, with the exception of Antarctica.
Primarily involved in, in developing, uh, enterprise learning, as well as, uh, uh, BPO support. And we've got, uh, an application for the fashion industry. But my, my specialty is on enterprise learning and creating tools that will, uh, make an impact on our clients.
Presently working with about 89 of the fortune of 500 companies. So, uh, it's great, this tribal knowledge that we actually learned from them. So a lot of great stuff.
We're working with great companies and, and, and we learn a lot from them, and we package together to, to make solutions that's, uh, for the betterment of all of them. Wonderful. So today's topic is new innovative technology and how it's helping with learning and skill building.
So can you share a little bit about some of the tech you're working on and some of the technology that's making an impact in learning? Sure. So, um, you know, we're, we, we have the pleasure of being involved in technology, but also our pedigree is learning.
And in a lot of cases, we've seen a lot of technologies come outta there, um, that, uh, are great for technology, but not for really retention. So we, we've been historically been involved in, you know, process and technical type of training, and we've always wanted to dip our toes into, uh, role-based, uh, soft skills, human skills training, is what they now call it. Uh, but we, we always thought that, um, we don't know if, if we could do as well as we should, as we did in our other different, uh, areas that are expertise.
Four and a half years ago, we became part of the OpenAI Foundation. Uh, that was a hallelujah moment for us because then we saw the advantage of, uh, you know, combining ai, uh, into learning to make a significant dis difference. So we created a product called Cicero.
And, and what's advantageous about this, it was born on ai. Uh, it was literally grab, built from the ground up on ai, and its number one goal is to create, uh, role playing in businesses as well as coaching. We're pretty excited about it.
That's awesome. So, um, can you share a few use cases where, where it's, uh, making an impact? Yeah.
So just to back up a little bit, one of the things that we found, uh, when we poll our, our customers is that 86% of the people fought role playing was very, very critical, um, in, you know, in really enhancing the skills of people. Um, but when we ask 'em if they really like to do it, it dropped to 38%. 'cause they, it won't be embarrassed in front of their peers, right?
So then we said, um, you know, role playing as itself is, is very expensive. Uh, especially you have to get a peer, you have to take them off the job, they have to take time out to work with it. And, and really only from the director level up would be able to have that experience.
And we said, let's look at the democratization of skills acquisition. And what I mean by that is, can we bring great training down to frontline users and make it affordable and make it so that it's attainable and accessible? So what we did is we, we created Cicero and it's really, it's, it's really claim to fame is a person can practice safely, don't have to be embarrassed, um, they're not gonna be judged wrongly because the person on the other end had a bad day.
If the computer has a bad day, it goes down. So it's, it's one of those days. And second of all, can we empower the people in the companies to create these, um, role playing scenarios without relying on technology companies to do it?
So there were the big three, and could we do that in multiple languages? So we created it, and one of the things we, we said is, let's be broad based, meaning let's empower our customers to create snares. They think best.
And I, I can tell you, uh, we're dealing with one of the largest, uh, medical device companies in the world, and they're presently using it. And it dropped, um, it, it increased the success of their salesman in the surgical sales because they were able to practice when they're dealing with the COOs and the surgeons at these hospitals, they can practice against those type of personas and be very successful. So, just little things.
We're working with a blood collection company where they, you know, have to have difficult conversations with donors. You know, some of them, you know, can't give blood or you have to tell 'em they can't get blood for six to eight weeks and they're volunteering or taught, you gotta be, you know, these are ways that become difficult conversations. Uh, to be able to practice that safely and to be able to judge on the fly is something that we thought was very, very important, and that's why we created it.
Awesome. So we talk about how AI can be used, uh, for learning. Uh, and I think about, there's a lot of different ways, but I think about most recently, I had a conversation with a friend and they said that someone came to a job interview and they just absolutely blew it.
So I think that this could al also be used for helping train people for interviews. It's funny you mention that. So we, we have a component called, uh, called Cicero interview.
And then what's interesting is, um, a couple things happen. The job description is posted. People, um, submit the resumes against the job posting, and the companies that are praising it have these scales of what they think are best.
So now the tide is turned where the avatar is now asking you questions, and it's gauging against, it's looking at your resume. It's where's saying, if you have six years, you can calculate the number of years. It can ask you all those questions.
And it can become really important when it's, say, technical architects, where now it can ingest all, say the coding of PHP and ask them technical questions and see how well they do on that. So it, you know, and people can practice this without being embarrassed. That, that to me is really, you know, holy cow.
You know, one of the things we're talking about, uh, there's a lot of people that you meet that you don't wanna meet in role playing, but you will meet them. And you just can't go to your peer and say, you find not all people in your organization are bad people. They're great people.
So it's hard to get someone who's really tough this way. You change the persona to as aggressive f you want using the five different personality forms. Um, and now you're into a real difficult conversation.
And if you can overcome that, then you know, you have a really great chance to be successful when you face the people. Now, it's not the be all for all of it. Like we, we still look, we look at this as complimentary to, to a lot of the different tools, like the little nuances that you get when you're seeing a human to human interaction.
But this really is fantastic, uh, for getting people prepared, at least to the last level. Absolutely. I always say communication is key, and if you're able to develop your communication skills to handle any personality type and know how to have a good conversation with them, you will get far anywhere.
I feel like, You know, it's, it's funny you say that because, uh, uh, there's been, there's been such a push on, on, you know, technical skills and then when the pandemic happened and people were, were doing Zoom and back and forth, and, and that whole interpersonal skills and communication, I think took a blip. And, uh, it's, it's hard, uh, for people. A lot of people say, I just wanna do it on, on the web and don't want to face 'em.
This is a good prep for it. And, and that's what we see that, um, these technologies can be used for the betterment. And it's, it's really just to go as to an aside on that, you know, a lot of people are nervous about losing their jobs.
And we're looking at, in our industry, it's the instructional designers and we're saying, but now an instructional designer can spend time on what they think is the best scenario to create versus the creating a bunch of tools or a bunch of different pages. Now they can think of, you know, pedagogically what's best for my company, versus, oh, I gotta get storyline to put this thing together. They can spend quality time on what's right for the situation.
Absolutely. So kind of, um, bespoke for each company exactly what they need. That I, I'll have to remember that.
Yes. Well, yeah, it is. 'cause that's what we said is like, everyone says, well, you know, are you gonna go into the farm industry, the customer service?
And I said, obviously, but we don't know that business as well as the business themselves. Why can't we just empower them? And if, if they know how to write in Word, they can write the scenario and let, and what we do is AI takes a look at all the documents they have in their secure folder, and if they give PDF, it can be videos and, uh, you know, the ID writes a paragraph or two what they want, then let AI create the scenario for you, and you edit it.
So within 15 minutes, uh, people can start testing it. That's fantastic. Well, you know, technology is advancing quite rapidly.
Where do you see the future of this technology, say a year from now? Holy, I mean, before we had runways of one in three years. It's, it's weekly.
Um, it's, the change is frightening. And I think, um, you know, you're, you're gonna see in a lot of cases the, the combination of, of not just ai, but now the combination of, of ar where you'll be able to, you know, drop your digital twin assistant into your own office and do that type of practice. We're seeing some of our great partners, what they're doing is they're actually connecting, uh, Cicero to Salesforce to get all the data on a particular, say, physician.
So now not only are they not practicing against physician, they're practicing against Dr. Smith. Now you then have a hologram of Dr.
Smith. You, you have his voice. Now all of a sudden this is as real as you're gonna get and it's gonna come.
It's a, we're doing it now. Um, but it's, it's exciting. But it's, it's, it's a little scary sometimes.
And you see just how quick change is coming. And I'm an technologist. It's, I mean, I, I see it, I say it's a, it's an interesting time that we're in.
Yes, it definitely is. Well, if there was one key takeaway you could leave our audience with, what would that be? The most important thing is embrace it.
There's always going to be, there's always trepidation of, of change. But those early adopters who take it, embrace it and look at it, will become the leaders of tomorrow. Period.
Yes, indeed. Well, thank you so much for coming on our show and sharing your insights with us. Thank you, Amanda.
I appreciate the time you gave me. All right. And thank you to our audience.
Stay tuned. There's more. Hey, everybody, this is Mitch Ashley, welcome to DevOps Dialogue.
This is the podcast, the interview where we talk to the most interesting people about topics that are really top of mind. So we're, I'm very pleased to have, uh, Medi Dowdy, who is co-founder and CEO of Catchpoint joining us. Good to be talking with you again.
Thank you, Mitch. Thank you. Happy New Year.
Good to see you as well. And thank you for having me. Absolutely.
Happy, happy 2025. Good to see you. Me, me and team.
We're at the tech field, Dale events. I think you're gonna be at some more. We're having tuned into that.
Be sure and do that. Some great content there. So it was interesting this morning I was having this conversation about, we're a wash with data, but we're not a wash with information.
We have a lot. And that's probably true, I'm guessing from a, from application performance monitoring standpoint. I know there's a lot of lights, but who knows what that all means, right?
When something's blinking or that's not blinking, which give us, give us, first of all, tell us about you and, and, uh, Catchpoint, and then we'll dive into how do we deal with this and a little more, uh, holistically. So Mitch, thank you again. So my name is Mary, a co-founder, CEO of Catchpoint.
Been, uh, launched Catchpoint in 2008. So we've been at this by 16 years, almost, uh, worked at DoubleClick and Google where I was in charge of actually monitoring. So I was on the buying, building, deploying, and using the tools to, to keep, uh, uh, the ad technology system that, uh, DoubleClick was known for alive and performing super well.
And, uh, I love monitoring, uh, whether we call it observability monitoring, et cetera. The reason why I love it is because when we do a good job, um, you deliver better services, you deliver, you have better outcomes, and then the monitoring becomes an enabler for running a better business. And that's what I saw firsthand.
Uh, and I was very proud of being part of that, of creating what often is called the culture of performance, which is like, Hey, how can we be the best at doing what we do with the most reliable, the most available, the most fa the fastest, et cetera. And so, and, uh, throughout the journey, of course, we learned a lot of stuff. Uh, which is one of the, for example, you, you mentioned it is too much data, right?
The data overload, uh, because as humans, uh, we go through some kind of outage and we regret that we didn't have the right data. And so the immediate, uh, knee jerk reaction is like, okay, we're going to log everything now, right? And we're going to log, but nobody for, nobody thinks about how much going to cost.
Mm-hmm. So then there is usually A-A-C-F-O coming down on, on you and saying, okay, you just spent like x number of millions of dollars on storage just for the marching system. But the other thing is like, it's, it's, nobody knows how to interpret the data.
The correlation, the causations, the connecting the dots becomes even more, uh, difficult to make, right? So the more data you have, the more cardinality you have, the more like, I don't know, what am I looking forward? And, uh, and so I was just on the phone with the customer earlier and literally the, they were talking about how, you know, we went from looking for a needle in a haystack to looking for a needle in haystacks.
Mm-hmm. And, uh, and so more data, more silos, more people, et cetera, can, can lead to prop. Now the bad thing is like, it takes longer to detect a problem, identify a problem, and resolve it.
So I think, uh, I think we're too, for some recalibration of that, what I talk to customers is they're trying to figure out a solution to end that either through, uh, you know, of course, uh, wouldn't be 2025 without throwing ai, but those are the kind of tools and capabilities that are hopefully going to allow us to go through a lot of data faster, and then maybe helping us connect the dots better. I remember a day when we used to say, the best way to provide the highest qualities don't change anything. Well, that's not, that's not even possible.
It's all changing. It's like, you know, it's no longer a solid, it's a fluid, it's under constant change, different File. And even if you don't want to change Mitch mm-hmm.
The internet is changing. Your, your third party providers are changing. Amazon is AWS is making a change, GCP is making a chance.
Your SaaS applications, All of it. Exactly. And so how do you get ahead of that?
How do you, how do you keep up with the constant changes? And oh, by the way, you can't go to the principal's office. I say, well, it's outside of my control.
I'm not responsible for availability, performance, or reliability. Mm-hmm. You're still in the hooks, right?
I can't point the finger and have that me make any difference. Well, so where does a PM kind of end it's usefulness, it's useful life, and then how do you fill in that gap? I mean, I remember a PM was, oh, good, I can have some w servers out on the internet, load my webpage and measure them how fast it loads it.
Right? We're in a much different world now. Yes.
I mean, AP m even means a lot more than that. Well, I, first, I, I think, uh, uh, what I usually tell folks I talk to, especially on the customer side, is, you know, terms, terminology sometimes can be limiting in the way we look at things, right? Mm-hmm.
So if you think of your house as your application, you have the valuable stuff inside, you need to secure it. You need to make sure that you have your humidity monitors inside the house, et cetera. But then you also need an alarm system.
You need to, you, you need to make sure that, uh, can, can, hopefully nobody can get it. Um, so, so thinking about that from, from that perspective allows you to say, okay, what pool do I need to get the job done? And the job is very simple.
You need to be up, you need to be fast, you need to be, you need to be, uh, available to all your customers, right? So if you have users that are worldwide, you need to make sure that whatever tool you have or whatever perspective you have, is a, is represents what the end user, where your end users are. Uh, and so, so I think it's first like walking backward.
What are we trying to accomplish? What are the metrics we want to do? Maybe say we need to improve avail availability, then what are the tools I need to do to, to do that?
Uh, but a PM is still the best. Uh, and tools like Dynatrace and, and, and, and New Relic, et cetera, do a fantastic job at, at making you understand what's going on in your house, right? Being able to understand when a, when a, somebody does a search, what database it's called, how long it took to query the, try to map the dependencies, et cetera.
But the challenge becomes for some companies that, that rely on many, many other third party services who's keeping an eye on the internet stack, right? The, the same way you have an application stack. Uh, what happens to CloudFlare?
What happens if CloudFlare is having a problem? What happens if Akamai is having an issue? What happens if the network in India is congested?
Again, being able to understand all of that. So it's not, I, I think it's understanding what each tool does, right? Uh, I don't use my toothbrush to comb my hair, obviously.
Maybe I think it'll work for me, but, uh, bad example, maybe, but you know what I means, right? So it's like you need use the right tool for the right job. Interesting.
Yeah. It, it's a, it is a great point, and I like your analogy. It's sort of like driving down the interstate.
I know my inside of my car is all looking good, but the road conditions can change drastically, whether, correct. Yeah. So any, there's things outside of your control really, essentially is what a lot of that is.
Well, so talk about Catchpoint and some of the lessons you learned, you know, at, uh, at double click and at, uh, at Google that informed you of, okay, here's the next approach we have to take to answer the rest of the equation of what's going on in this picture. Right? So, very fortunate enough to have been part of, of the beginning of the internet kind, ofish, right?
From the commercial standpoint in 97. And, uh, and so, and then Google, of course, had a super, uh, focus on the end user, right? So if you think of Google, you think of that, that search page that needed to load in, in Subic subsequent.
And, uh, and I think that set the stage for the, the whole concept of like, everything needs to be available. And Yahoo too. I mean, Yahoo spent a lot of time inventing a lot of the tools and the concepts that, uh, exist today.
So the end user is where it matters the most. It doesn't matter. And this is what happened to me at double Click one day.
Uh, I walked into our knock, our network operation center, and I, I saw my team chilling and, uh, you know, as if nothing was happening, uh, and double click was broken. We were not serving ads, which a live a livelihood, but all the systems were green. Like literally all of our internal monitoring was showing, okay, uh, no network issues, no database issues.
The servers were fine, 15,000 servers were, were up and running fine, et cetera, but we were not delivering ads. And, and so that's where the monitoring is, like, what are you monitoring? Are you monitoring for an outcome?
Or are you monitoring for CPU and memory kind of stuff. Mm-hmm. And so that was my big aha moment when it came to, you need to monitor what matters from where it matters, right?
Uh, uh, it's, it's, it's so critical and it does what, this is the philosophy that still drive us today. So, um, and that was one of the biggest lesson is again, monitor the end user and monitor where the end user is. And then also, if you're an e-commerce, then can I buy something and add it to my cart and check out, right?
If I am a sneaker company, can I, if, if, if every time I go and pick size 10 you have an error, then something, you should do something about it, you should first know about it and then fix it. So I think it driving the outcomes monitoring, should you be here to help businesses run better, right? So align the monitoring strategies to the business outcomes.
That's, I think, one of the biggest things I've learned. And, uh, and when I see customers, some of the customers and partners that we do that for, it brings a lot of joy to, to me just like to see that, that causation between better monitoring, better observability to direct impact to, to, to business outcomes. It, it reminds me of the metrics we always create for our technical organizations, as, you know, meantime between failure or whatever it might be, or know these kind of responsive things.
That's what they're all important. Yeah. That doesn't mean the customer had a great experience though.
Correct? Because failure, we live in a world, failure is gonna happen. It isn't avoid failure at all costs.
That's impossible. It, it just, so much is out of our control, right? Talk, talk about, so how do you, how do you do this from the end user's viewpoint?
So you really are measuring as much as possible, or you really assessing, I should say, the experience that you're delivering. So with the concept of we, we want to monitor from, from as many places as possible to simulate where the end users are. So that was one of the design philosophies of Catchpoint.
So we do what is in the industry called synthetic margin, which is a robotic process of monitoring. Um, it's like digital mystery shoppers, you know, mystery shoppers have existed for a hundred years, uh, where the digital version of it. So we have them, uh, located in the right cities, the right ISPs, the right carriers, the right telecom carriers, et cetera.
And those things, uh, those machines, they do very simple tasks. They basically simulate what an end user does, uh, and they do it across all the different stacks of the internet. So your DNS your network, your application, your APIs, your third party services, et cetera.
And our job is to really, from there, help customers triangulate the problem. So if you show up at your doctor, God forbid, tomorrow you're going to show up with a symptom, my head hurts. Great.
A good doctor is going to go through, okay, based on what I see, let me see if it's this, that, or whatnot. So monitoring and the data that we provide that needs to help the customer go through that triangulation as fast as possible so we can reduce the meantime to repair. And so what's also very important in our business is the data quality.
So we focus on the data quality, the signal, what we call this, the signal to noise ratio is very, very important because you don't want false positive, right? I mean, no hospital can deal with like people ev showing up at the hospital every time they cough, right? That you have to have fever, this, that whatnot.
So, so it's very important for us to deliver the right qual, the right metrics and the right quality to be able to drive better triangulation. So that's one thing we do. The other one is we married, we enrich the data with other things.
So for example, synthetic and run. So real user monitoring, um, fantastic, uh, uh, fast way of, of answering the question. So what, right?
So the robots say there is a problem in Saudi Arabia, Ram should be able to say, oh, yes, holy cow, it is a big problem. And oh, by the way, we dropped by 30% of the traffic. Uh, so again, it's like, how do you put all these things together, uh, in one dashboard, et cetera, to answer the question, what's broken where?
And whose fault is it? Right? Is it us?
Is it the internet? Is it, is it a particular third party? And all of that needs to happen super, super fast.
You know, we do this SRE survey, we've been doing it for seven years now. Uh, and I'm very proud of the work that team does. And this year, something that, uh, was very interesting that came up and is performance is the new doubt.
Uh, so we went from like availability, and I've seen, we've seen that with some other customers where, you know, the, on the maturity side, they cared mostly about, am I up? Are we up? Is the stuff up and running to now performance, meaning that after three seconds, even though the site or the application is up, it's actually down because the person, the customer is not willing to tolerate that.
So the, the level of, of how much you're willing to tolerate slowness is going to be an indicator of a, of availability. Uh, so again, how can we do all of this stuff as quickly as possible so customers can get to fix things as fast as possible themselves? Well, if we can wrap with the AI question.
Yes. On all of our minds, everybody's talking about ag agentic ai. It seems like we're not very far away from synthetic users that are AI agents and you know, a world of of, you know, I'm, I'm actually out there doing multiple things 'cause I've got agents correct.
Where my business does. Is there anything that customers or organizations can do to kind of prepare for that unknown of what that future may look like? I imagine, I would imagine the more you understand an instrument and understand the experience that you're delivering today, as you add a new factor into it now, now you could assess how to manage it better or understand it better, versus, I don't know what I'm doing now.
That just makes it worse, Right? So I, I think it's an excellent question. So, uh, let's, let's answer it two ways.
So the first one is, what are we doing to prepare for a world where now there's going to be a combination of humans using the internet and then synthetic agents, right? Um, uh, that are going to be also doing stuff like, uh, there, I was reading an article where Microsoft is, is allow you to create a robot to literally answer emails on Outlook without, without you doing anything. So, so I think that doesn't change the way we look at things, which is like availability, reachability performance, reliability are, are, are pillars that exist in an AI or non-AI world, right?
I would say, I would even argue that in an, in an AI world, the tolerance for speed, reliability, et cetera are going to go down and people, we, we need better, we need faster, et cetera. So I think, I think that is a, the other part of your question, the way I look at it is when I talk to our customers and the SREs, the DevOps, et cetera, um, we're all trying to do our job better, faster, and be more productive and more efficient. Ultimately, that's what the, the promise and the revolution of ai.
And so what we are seeing, uh, is we're seeing customers that have, uh, a more methodical approach to ai. It's like, okay, pick three problems that we want to solve, rather than like peanut butter kind of thing. Like, let's put the AI everywhere.
So it's like, okay, what are the areas where we're having a hard time finding talent, we don't have enough manpower, uh, and let that drive, uh, uh, for example, either automation or whatnot. Uh, but on the monitoring side, et cetera, there is definitely some incredible efforts that are being led to connect the dots faster, better, right? Being able to pull all the data and solutions.
Like we're seeing a lot of that in Databricks where customers are pushing all kind of data into Databricks and then being able to connect the various dots at, at scale over there. And people are seeing some really good benefits so far, Databricks, snowflake, et cetera. I think that's one area where we're going to see a lot of stuff.
Now, the benefit of that, which is we're going to have less issues where people missed an alert, because I see that a lot with our customers. Oh, we got too many alerts, or somebody took a large break and we missed something. That stuff is going to go away, or it's going to supplement or, or, or augment, however you want to look at it.
But I think that's one of the benefit, I think that AI is going to drive better availability and reliability to, to, to a lot of companies. Uh, Well, very exciting. It's interesting time and you live in interesting times up.
This is one of the correct, funny funnest times in my career. Funnest is a word. Yeah.
Maybe, uh, tell folks where they can find out more about Catchpoint and learn more about what you all do and get engaged with you. Sure. com.
Obviously we're on LinkedIn, Twitter X, sorry. Uh, our blog is fantastic. Highly encourage you to, to search that, uh, and, uh, read some of the content we produce, whether it's the SRE study that, again, 70 in a row, uh, super impressive and or the reliability and resiliency report we publish.
org. I'm sure some of your listeners, uh, know about WPT. Uh, and uh, so that's another free tool that, uh, that we have for the community to test your performance.
So again, slows the new down. So start testing. Very good.
There you go. You heard it from the expert. Well, thank you, Medi, it's great to chat with you again.
Thank you. And we appreciate everybody tuning in to this episode of DevOps Dialogue. And look for me on another FU room event or a Textron tv, he's around.
We like having him on. Thank you so much. Take care.
How can you, everyone again? Hi. So my name is API Shaw.
I'm the senior partner solution architect at AWS. And today I'm going to use, uh, what is quite hot in the industry, which is how we can leverage the gen AI for the next generation automation and efficiency. Um, and the answer to this problem is Amazon Queue developer, um, which is, uh, Amazon's product, uh, which helps, uh, the developers, uh, to, uh, do a lot of things.
So, which we will go through in the details. So what is the agenda for today? So we are going to start talking about why generative ai, uh, what is the need for the customers, uh, give you the overview of the service, what is the key features about the service, uh, some of our customers who have used these services, and how you can get started, uh, with the features of Amazon Queue developers so that this becomes part of your everyday work.
So, um, we did a lot of analysis about this before launching this service, and what we found was that, um, a median developer spends only an R writing the code that is developing new features and, uh, getting something, uh, straight to the business, what they're looking for, rest of the seven Rs. He is either debugging the application, he is writing the comments onto the code, he is doing the unit testing or operation support and so on, which constitute a lot of time. Yeah.
So if you take five hours in a week, that is significantly low, um, uh, effort, which has been put into to develop the new features and new business requirement. So this is something which is quite important to understand because that's something which is what we are trying to improve upon. So what is the key needs for innovating faster?
We want to build faster, we want to increase the velocity so that in a sprint we can release more things to our customers rather than spending the time on the undifferentiated works, which is required as part of developing the software. Yeah. Let the machine do the work, what is not fundamentally, uh, which, which can be automated.
Whereas what requires a new features, which is where we want new, uh, developers efforts to be put onto. Yep. Uh, a lot of, uh, time goes into the operations.
So there is an efficient way to manage and optimize the AWS cloud environment. Um, and we will go through into that as well. Uh, there's a lot of transformation things.
So basically, uh, you have a Java application, which is running on Java seven, Java eight, Java nine. You need to upgrade those to Java 10 11 17, um, uh, and so on. Because there is a new fixes, there is a new security vulnerabilities.
Your security team is behind you a lot of this times, which builds up into the developer's backlog and enhance into the product backlog because the product needs to be kept up to date. Yeah. As well as you want to do migration from dotnet framework to dotnet core.
Yeah. Uh, which is where you can run the Windows software onto the Linux platform so that you can get the business benefits, uh, get the license freedom, and you can do the ization and all the benefits which comes with it. And last but not least, but with the ai, everything is data.
Yeah. So the more precise your data is, the more better you build your analytic solutions, the better the AI and ML solutions will be. So how we can leverage Amazon queue developer to be faster in terms of developing our AI and ML solutions when we have the data with us.
So if we go into that, then, uh, what, as we discussed that Amazon Queue developer helps with the quality, uh, it helps with the efficiency, it helps with the speed and how it does it, we will go through that into the detail. It has, it is built upon the generative AI and helps, hence it helps down to reduce the cost, basically. Uh, because if the efficiency highs, if you're delivering more features as to what the business needs, then obviously the cost will be less.
So there is a tremendous amount of, uh, uh, what we say the enthusiasm about saying, Hey, you know, uh, we should be using the generative ai which will transform and which will power our business. Um, but lot of companies have, one of the thing is that, hey, but what happens about the, um, uh, my particular, uh, security framework will, my code will be used to train, uh, the, uh, uh, Amazon queue developers LLM models. The answer to that one is no.
And the reason for that to make it upfront was that we make sure that we don't use the customer's data to train those LLM models. Those LLM models are already being trained, and they, we are using your data just to generate the core and provided to you basically. So that is nothing that this trains our LLM models.
So that's something which I wanted to put first thing into the rest. So there is a new experience altogether. So you are, whether you are in the ID where you are, uh, trying to, um, um, do the coding, whether you are doing the mass transformation.
So like I was saying that you might have a lot of applications which you want to transform, move from net framework to net to code. You want to boost the productivity, you want to have the content creation, which you want to do. You want to see the insights, and you want to have the creativity.
All those things can be powered with the generative ai. So what is the fundamental, um, uh, thing which we are talking about? So, uh, a customer comes to us and say, Hey, you know, we have a lot of systems.
We have thousands of applications, which has been running on true, and there's a lot of core which has been written on true. But then every time we try to build something, it takes a similar amount of effort because we cannot learn from the systems what we have built, and we cannot quickly convert them into the next level of features. What we want to develop onto, so this is where Amazon Q is differentiator.
Uh, we learn from the knowledge of your company, your code, your systems, um, and we, it's not used to train the LLM models, as I said before. And if, when you ask the question saying, Hey, you know, I want to develop the new feature, it based upon your company's core and systems, it develops the new functions, which is required into your, uh, preferred id, which we have been integrating with. It's available wherever you work.
So it's either you are in the id, whether you are into the AWS consoles, whether you are in a particular service, wherever you want, uh, the service to be available. It's available with you in order to do the development and enhancement. Um, there are superior generative AI performance on tasks.
So we have specifically integrated with lots and lots of knowledge base, which we have got at AWS so that this performs better. And it gives you the exact content, what you're looking for, the integration. So for example, if you want to integrate with the s3, what is the s, CDK and SDKs, which we have available as part of the AWS, which you can integrate with.
Uh, so what does the stack looks like? So at the bottom of the stack, as you can see, there is an infrastructure. Uh, those infrastructure is our core.
Uh, if you say EC2 instances, uh, which has been used, which are specifically used to train the model, those are the foundation models on which training and influence happens. On top of that, we have got the bad drug, uh, which helps with the, uh, guardrails and all the customization capabilities, what is required to power your business, uh, and, uh, uh, the LLM models, uh, so that you can access whatever LLM models, which you want to integrate with and so on. And then on top of that, we have used, uh, certain applications, which can be used around, so you might have heard about Amazon Queue business.
Uh, we will get into the retail as to what is the use of that Amazon Queue developer, which we are talking about right now, um, which helps the developers to carry out their development, operational security task into the code. We do have Amazon queue in QuickSight, so user can type in the queries into the nature language, and then Amazon queue in Connect as well. So if the customer is calling, uh, into your data set, into, into the call centers and want to, uh, and the customer care person wants to know the specific information, then Amazon Queue can help with that knowledge base as well, with respect to quite optimizing and telling the consistent message back to your customers.
So it's, Amazon Queue is powered by the ai, um, as we were talking about. So there are two kind of Amazon queue developers, Amazon Queue developer, and Amazon Queue business. So Amazon Queue business is for every employee, uh, who are using the things like Teams or Slack or, uh, uh, you are, you might have a knowledge base, which is your SharePoint.
Uh, you might have a lot of Outlook application, Microsoft, uh, which can be integrated, so that, which can be used by the business, uh, team to derive the better, um, uh, optimized information to put that into the task. And on the other side, we have the Amazon Queue developer, which is for the developers and data scientists and IT professionals basically. So that is something which we are going to talk in detail today, not Thomas, Amazon Q business.
So a Q developer, as it says that it helps the developers and IT professionals build the software faster. We want more accurate coding recommendation. Um, agents can autonomously help you implement feature if you want to say, Hey, you know, this code is very complex and someone has written it, can you please add the code, uh, the comments to the code?
Uh, it'll add you the Java comments or t net comments or JavaScript comments as what you want. And if you, if you can, it can also say it saying, Hey, you know, the code is very complex, uh, which you have written. So you can re, you can ask it to refactor the code, uh, as well as it performs the software upgrade as we were talking about.
Um, and also Amazon Queue, as you can, uh, understand it, that every other knowledge which we have acquired over the years has been fit into the Amazon queue. So anything which you require the information about the Amazon AWS, you have that information available. And obviously, um, security is Job Zero at Amazon, so we never start with anything which is not built with security and privacy.
Um, and that's, that's most of our customers ask as well. So, uh, wherever you are working. So it's available in Amazon queue.
So nowadays when you log in onto the console, you'll be able to see the Amazon queue, um, which is on the right side of your, uh, uh, of your screen. Uh, if you click on that and if you ask any questions, that's something which has been powered by the Amazon queue, and it can answer any questions, what you want to know, say how much you have spent, and saying, what is the issue with my service? And so on.
You can get the information. You can also use it into the ID integrated development environment, so like Visual Studio or JetBrains. If you're using on two, you can integrate that and start using straight cameras on Q developers.
Um, AWS documentation it has been trained onto. So anything which you require with respect to the AWS, it provides the information about that as well. Uh, same as I was talking about, you can integrate with Slack and Teams as well, and it's available on the mobile application as well.
One recent thing, uh, which we have partnered with is our partner GitLab. So, GitLab now has got the GitLab duo, which has been powered with the chain ai. Um, and it's using the Amazon Q developer at the back of it.
So, which is something fundamentally allows you, if you're using GitLab quite heavily, your all these source codes are into the GitLab. Uh, you can leverage the Amazon queue straight away by using the GitLab over there. And Amazon Queue developer is been recognized, um, as the leader.
So in the AI code assistant, so we are in the leader's quadrant of the 2024. So as you can see that, um, uh, it's, it has got, uh, all the capabilities, what is required, uh, to match up those things. So, um, as I was talking about, build faster, operate at scale, transform the workloads and leverage data and ai, this is what it makes the things, deliver new features to the company and make the innovation faster for the developers rather than the mundane task which they need to go through.
So we'll dive into the deeper. So, uh, build faster. How does the build faster happens?
So where are the developers spending the time? So they want to explore, uh, saying, Hey, you know, I want to build a website, and in order to build a website, what are the things I will need to do? Uh, I want to create the software.
How do I create the software I want to test and secure review and deploy? And then the last but not least, maintain, transform and modernize. So this is usually the time where the developers are spending it, and we'll go through, into the details by going through how in every part of the SPLC, this tool is helping you.
Um, so let's see a demo. So as you can see, this is your id. Um, you have connected with the A WSQ developers, and you start asking the question in the consulting, Hey, you know, I want to develop a web app.
How should I do it? And it gives you the answer. Um, so that's the first exploration part of which services I should use onto the AWS in order to develop the application.
It can help you with the service selection, when should you use what service? And so on. So that's basically the exploration part before any development activities happens.
Then it comes down to the creating, generating the code. So as you can see, uh, you can just write the comment and say, Hey, I want to write a function to square a number. You connect to the Amazon queue developers in the browser.
This is the visual studio. Um, and once it's been connected, you can do all your merging. Um, the, the release of the software writing, the unique case test cases, um, writing the, uh, functions.
As you can see that the function is getting returned, you just write the comment and you just accept those code. So the co the developers can accept the core, or if there are sometimes multiple options available, it shows to the developer which part of the function you want to use it as well. Um, and it's, it's significantly, um, uh, what we say the, the faster way of developing the software.
Even if you want to edit it, you can edit it. Um, once the base code has been available to your business specific domains, which, which LMS might not have been trained with. So once it has been trained, um, there are, there are quite a lot of, as I was saying, the, our customers asking, saying, Hey, you know, but, uh, it's great if I want to write something completely from scratch, but my organization has got a lot of, um, source score already available.
And most of the time it's the integration of, uh, one application to another application and how to do that integration and so on, which is taking the time. So what the answer to that is that you have the private repository, uh, on which the private repository you want Amazon queue developers to, uh, integrate with. And using the Amazon queue developers, it can recommend you when you ask in the natural language saying, Hey, you know, can you please, uh, give me the list of, uh, uh, unassigned food deliveries, uh, which which is around the driver's current location so that we can take the better, um, uh, we can develop this feature quickly and deliver it.
Now, this is something which is, you already know the driver's current location that is already the code, which has been returned down. And you want to write a new feature, which is to say unassigned food deliveries, uh, around that. So it leverages it, understand your code, it find it out as to how to retrieve the driver's current location, and based on the driver's current location that it tries to retrieve the list of the unassigned for ies.
So it understand your code, it makes, it makes, it's not a genre code recommendation, which comes down. It comes down to the customized code recommendation, which is what is required by your organization. Um, there are advanced features, which is available as well.
So, uh, q can write, uh, um, uh, q can write, and it can provide you the features with respect to how you can document, uh, the code. So as you can see over here, uh, there is a document you want to create a read me file, uh, read me file for the whole project as to how to use it. And in no time, it'll scan through the source code, it'll create the knowledge graph, it summarize the source file, and it'll generate the documentation.
Um, previously this used to take, if you, if you are, I remember in the projects where I was doing the development, and if the read me file was not there, and if the developer has left, someone will come back and say, Hey, you know, I, in order to create this, uh, read me file, which you're asking, which is required for every application, it'll take me x amount of days or sometimes weeks, uh, in order to generate this is just now available at click of what is needed. Yeah. And it is formatted, it is ready for checked in, um, and it is ready for review and then merge and release to the production as well.
So this is all part of the integration. What you can see, testing. So from in the past unit test was one of the thing which we were putting into the estimation.
And then we say, Hey, you know, I have written the code, which is working, but you know, we cannot still release because there are no unit test cases, or there are no, um, um, uh, the, uh, the proper testing which has been carried out onto this code. So now we can also support writing up the unit testing. So the agent supports that saying, Hey, you want to write the test?
So here is your clause and you want to write the testing of this methods, then we can support that as well. And it can create the test, uh, the unit test cases for every function, which you have been using it. So as you can see onto my screen, which has been showing around saying, Hey, you have four functions, and we have generated all the test cases.
Developers accepted it and say, Hey, come on to build and execute now. So it is building, and it is, uh, uh, it can deploy. As you can see, it's a MA one clean verify, which is happening around it's building and executing into the browsers.
And then from there, it can take around in order to your ci cd pipeline to deploy to the, uh, uh, into whatever environments that you wanna deploy onto security. So one of the major thing which was coming around is, hey, great, we develop new feature, we, uh, fix the test issues, but now we want to make sure that, uh, security wise, it is, uh, uh, it is quite secure. So it's, the great feature about this is it does the realtime check, it provides you any vulnerabilities, and not only provide it with the vulnerabilities, it provides you how to fix it as well.
So, for example, if you're using the libraries, which are quite legacy libraries, then it can help you to upgrade those libraries and it can fix those libraries, uh, in no time as well. And it categorizes, as you can see on the left side of the screen, that it categorizes critical, high, medium, low, or if it's just for information as well. So you have all the information which is required in order to make the features, uh, the development quicker.
Um, the last but not least is review and deploy. So we all know that once it's been, uh, once the feature has been developed by the developer, we want someone to be reviewing that code. And once it's been reviewed, then the, as part of the merge and released, then the review happens.
Now, this part, um, I have seen in the company, there was a lot of debate and discussion saying, Hey, though, this variable name is right and this variable name is not right, and there was a lot of friction between the developers, this developer doesn't like me, and all those things believe that to the system now. So the system will say, Hey, you know, that based upon, um, the review which I've carried out, first of all, it's consistent review and based upon the review, which I've carried out, uh, I think these are the issues which needs to be fixed upon. Um, so that's something which gets reduced down in minutes to hours basically, rather than in dates.
Uh, and it's a consistency of which with which the code is getting reviewed. So the great questions which customers always ask us is saying, so what is the metrics, uh, which I should measure? Uh, because, uh, previously we, we used to a developer used to take, say, 10 days to develop a feature.
Uh, is it going to be all of a sudden it's a one day? Uh, there is a bit of a learning curve as to how to, how to prompt, uh, the Amazon queue developer. So over the period of time, you will have the metrics, uh, which will show you that, uh, how significantly the impact which has made, uh, by using Amazon Q Developer.
So we recommend these four metrics. One is the report time saving across a range of tasks, what the developers was doing before, uh, suggestion acceptance rate. So basically the what is your acceptance rate, which looks like, so Amazon two developer in your ID has recommended the code, and is it the code is ready and it has increased your, uh, velocity, uh, of the code changes in deployment.
So you measure those aspects as well. And what is the context switching with the ability to query code base and hundred knowledge in the id? So basically the things which you are having the legacy core, and we don't have the any documentation around that.
Those things gets resolved in no time. So, um, what we have been told by our customers is that this enhances is accelerates 80% of the development task. Uh, there are 60% of the core acceptance rate.
Yeah. Uh, and when we say 60% rest, 40% is, hey, you know, but I have a very specific business requirement, which I need to do, which I need to code. Um, so what we are saying is, but most, and most developers are saying, Hey, you know, 60% of the core as it is, is coming, which is a great, um, uh, and that's something which has been coming out from, uh, one of our customers, which we were going through as well at the end.
Um, so it's a real, it's a real numbers from a customer, and the developers are quite happy because they are now developing new features. Um, a 40% productivity increase, which has happened around the, the task which they were not liking, like writing unit testing or, uh, doing the, uh, comments, uh, documentation that gets resolved automatically and security fixes and upgrade, uh, all those aspects so they can focus on developing the new features, which was where the developers trends were and what business was looking for. A, as I was saying earlier, that GitLab deal, this has been integrated with Amazon queue, so it has got quite advanced, uh, capabilities, which is in the DevX ops workflows, uh, which the developers use every day.
So have a look into it. Uh, if you're using GitLab, that's something which is a, a great, great, great, uh, thing, which has been, uh, we have been doing behind the scene, working with the GitLab. Uh, and it'll help you to innovate, um, and deliver quicker, uh, at every step of your journey.
Um, so friction through the s dlcss and those aspects, which was there, it has been making now seamless. Uh, it's an AI powered experience, um, as we were talking about. So it's available in preview very soon to be ga.
Um, but feel free to start using it around on those aspects. We did the build, um, and then we were doing the operations, and then every time the operation there was an issue. Uh, it was again, going to the developers.
So, uh, I don't know if you have seen recently, but that is, um, in the CloudWatch. We have got AI ops now, uh, AI for ops, which helps you to tell saying, Hey, you know, um, you have obs you, you have observed an error into the logs, and based on that error on the logs, you can just create, um, uh, the ai, uh, uh, enterprise issues, and then you can track through your Jira and so on, which is all inbuilt to the integration, and then it'll do its magic and find it out. What could be the reason this issue has happened?
What was the change which has gone in? Uh, is that the change which is stopping your system to perform well? Or what, what is the kind of, uh, things which has been, which needs to be corrected?
Um, so it's a great thing, uh, which we have been working on. Again, it's been powered by Amazon queue, so, um, and it's built upon the best practices and our support, uh, uh, mechanisms, which has been there, um, manage and optimize. So customer were asking, saying, Hey, great.
Um, lot of time around billing. How can I do the usage trends and intuitive visualizations? All these are now supported with the, um, AWS using the Q course, and as I was saying, diagnose and troubleshoot error as well.
So you can go to the cloud CloudWatch, use the IW AI ops, and using the AI ops, you can see that, hey, uh, what could be the diag diagnose and what is the troubleshooting error, which has been there and remediate quickly, uh, uh, those aspects. So what, what are the kind, so the thing was it, the tools are available, but then other aspect is asking the tool what your problem is. So here are some of the queries which you can use.
So you can ask saying, Hey, Lambda, hey Amazon queue, what is wrong with my Lambda function? Um, and it'll try to go through every aspect of the Lambda function logs and so on, and it can figure it out as to what does it looks like, uh, customer asking, saying, Hey, you know, at the click of my button, in the non-techie language, uh, my program has been asking me saying, what is the forecasted cost for the rest of the year? Uh, we don't need to go through the number fudging and all those things.
We can just derive those aspects, which has been available onto the billing console, and we can provide that the cost of the breakdown. Uh, how much am I spending on the data transfer? Uh, show me alarms for my S3 buckets.
Uh, how can I leverage agents? How can I leverage my a PA gateway, which has been seeing errors to resolve those issues in no time? So all of those things can be helping with the Amazon queue to operate the things as well.
The most important aspect that, uh, we have recently announced at the reinvent, uh, which was around the transformation of the workload. Um, and fundamentally when we talk about the transform, it's a slow modernization. There is a complex legacy systems, which requires a lot of, uh, uh, workforce in order to carry out any transformation.
There's a limited scalability options, which has been available, and hence, it takes quite a lot of months and months in order to do any transformation. So we have specifically created some solutions which has been tailored for, uh, specific problems. Um, and as you can see, that we have done now, uh, if you want to move from Java version, legacy version 7, 8, 9 to Java 17, you can start leveraging the Amazon Queue developer.
If you have been using dotnet framework and you want to move to dotnet core, you can do that so that your application has been portable from the legacy version of the net into the conet core, and hence, you can run it onto the Linux as well, giving you the business benefit back, uh, in terms of, uh, running the dotnet applications onto the Linux, uh, platform as well, saving you the license cost of the windows, and also taking the benefit of ization and scaling and all those aspects, which comes around mainframe, which was the biggest, biggest, uh, challenge you can. Now, I'm not saying all the problems of the mainframe is going to be sold, um, but what we have started getting was that from point where the biggest question was saying, Hey, I don't know what has been running on my mainframe. We can easily now generate the documentation from the mainframe applications, what has been running onto those mainframes, which then helps us to create the business, um, uh, move forward onto the HS technologies.
Uh, as you can see, last year, Broadcom came out and say, Hey, you know, VMware licenses are going to be changed. Uh, and there was a lot of things which was changing around the VMware. Uh, one of the pathway was migrating those VMware VMs onto the EC2.
So using the Amazon queue developers transformation capabilities, we are supporting now to migrate those workloads in no time from the on-premise VMware or VMC onto the, uh, EC2 instances. So that's something which is a great, great significant benefit, uh, for the transformation which our customers are facing. It can be into the id, it can be into the, um, uh, web browser.
What we are saying is that the customer is saying that we are four x times faster. We are saving 40%, uh, savings when we are doing this kind of a transformation, which is a significant number. If you look around from months and months, which we were talking about.
It has reduced down, got everything, uh, been recommended to the customers. Customer can select saying, Hey, yes, this is looking great. I want want to trans, I want to migrate thousand applications.
And this thousand applications, um, uh, needs to be, uh, done. Previously, uh, it used to take months. Now, in the recent, um, uh, migration of the thousand Java applications where we needed to move from, uh, Java eight nine to Java 17, we were able to do it in two days on average, 10 minutes basically.
So the developer can put it and then they can start developing the new feature. Once all the development, the migration has happened, it comes back and shows to the developer saying, Hey, you know, your application has been upgraded. Do you want to adapt all the changes?
You say yes, and it'll take over from there and then progress the next steps of the function to integrate and deploy and deliver as well. Um, it saves us 4,500 years of development work and 260 million. So this is based upon the real, real work which has been done at Amazon.
It's a significant numbers, uh, if you look around, uh, the last leverage data in ai. So data is the core of everything, what we have been doing now. So you can start writing in your natural language, the pipelines, you can build it onto the SQL queries, uh, actionable insights.
So basically, if you go to the QuickSight and you say, Hey, what is my, uh, projection for this month, which is looking like, based upon this particular product, which we have been using on two, you write in the natural language and it'll create you the, uh, output what you're looking for. You can analyze that data and integrate that data into the, uh, features, what you want to have it, uh, as a business. And you can train to do the business, uh, ML model as well to train the ML models.
Uh, Amazon sales maker has been widely used to develop your own models. Uh, you can do the development into the Visual Studio Code or any ID, which you prefer drawn to, and it's, it has got the step by step-by-step guidance, uh, in the no-code truthing. And hence, you can leverage the data and AI together, uh, with, with zero expertise, uh, and full blown product to be available for, uh, building up any product based, uh, product database product.
So, um, as I was saying, couple of business, uh, uh, recommendation or customers who have used it, uh, national Australia Bank, they're one of the largest financial institution in Australia, and they have been using it. And what they are saying is that 50% of the code suggestions what has been made by Amazon Queue developers, our developers are just accepting it. And, uh, this has significantly enhanced our productivity, delivering better service to our customers.
Uh, similarly, um, NOVA Comp, we are into the IT services, uh, as I was saying that, uh, you can do the transformation. So there was Java eight to Java 17 transformation and 10,000 lines of code. Um, we have 60% decrease in average in our tech depth.
So it does all the thing for you. Uh, eight synchronically, take your code, go to put it into the three, uh, do the transformation of the project from Java to Java 17, along with the testing and so on. One, it is, once it is a compilable state, it tells you saying, Hey, you know, you want to see the code changes, which has gone through, and it shows you significantly improvement in terms of the developer's experience, uh, and acceptance of that.
Similarly, Toyota has been using it as well, and as I was talking about, they had the Copa, uh, mainframe, and it's been used for the persona driven insights, it order to develop the lot of documentation so that they can take the documentation and start doing the better things, uh, with respect to those capabilities. Volkswagen as well, um, as I was talking about the GitLab, uh, they are using GitLab and they're using the AI capability with Amazon Q Developer, which has been integrated, and again, a great feedback, uh, which has been given by the Amazon feedback. Similarly, masteries, they have been using it, uh, DevSecOps, uh, for the purpose of DevSecOps, and that's have been something which is significantly, uh, their developers are loving it.
Uh, and common task has been left to the Amazon queue developer. So, uh, what you can do, so, uh, there are two versions of Amazon Queue Developer, which is available. Um, uh, one is you can use the free trial, uh, uh, uh, and that is something which you can just register at the Amazon and just like how you were using the free car of DAWS, you can start using this, uh, uh, as an AWS builder.
Uh, the another option is the Amazon Pro. So Amazon Pro is where we don't learn anything from your data. This model has been tuned, fine tuned, uh, and they will put the recommendations and so on.
So, uh, the pro subscription is something which you require in order to be using the Amazon Queue developer, which is what our most enterprise customers have been using it, and plan your POC next time you're doing the upgrade. Don't just do the upgrade next time you're doing the security fixes. Don't do any security fixes without using the Amazon Queue developer.
This still significantly improve, and you can showcase to your, um, uh, leadership that how this amazing Amazon True developer is helping in order to make the things faster and better. Uh, and we are happy to support that in case anything is needed from the AWS. With that, thanks a lot today.
Uh, absolutely pleasure to talk with. Um, feel free to put any questions into the chat, and I will address it. Thank you.
Thanks a lot. Hi, everybody. Welcome.
We're glad you've joined us today for another episode of the latest greatest cloud transformation late great cloud transformation. We're talking about really sort of the next generation of how we think about the cloud and the things that we're doing with it. We're talking about security today, about safeguarding innovation and, uh, strengthening that security.
We be jumping into app, app security and lot, a lot of things here. But, uh, before we get too far down the road, thank you for joining us for this video series. Uh, the, the last Great cloud transformation is sponsored by CloudFlare.
We're glad to have them, uh, on board with, with us working on this, uh, helping input with some topics and things like that, and obviously participating on, on our, uh, live editions, which we do on a monthly basis, as well as these recorded episodes. So thank you for being here with us. My name is Mitch Ashley, I'm VP and practice lead with futurum Group, analyst firm, uh, heading up the analyst area for DevOps, DevSecOps, application development, AppSec, et cetera.
So kind of right in, in vain with this, uh, my co-host Alan Shiel is, uh, unattainable, uh, the detained or whatever the word is, the phrase is. And, uh, so I'll be, I'm, I'm hosting both parts of the chair today. Uh, you know, it's a little bit of a coup, but he'll be back next time.
We'll see him on our next episode, I'm sure. So let's get to our conversation, to our topic. Um, let's first start by doing some introductions.
I know Chris has been with us on a few episodes here on some different topics. He'd been on other webinars with me and TA talking a lot about application security and, and, uh, cloud Chris Blas, introduce yourself. Oh, I've been Forest Company my way through the security industry for 30 something years.
Uh, I inflicted an early firewall in the markets, something called Border Ware, uh, in the early nineties, and ran Cisco's firewall business, the turn of the century. I've been following this inevitability curve, uh, my new series on here on Textron, um, from one spot to another, from firewalls into, uh, sim and network management. From that, you know, the obvious next step is threat intelligence.
So I, I chaired an IAC for a while, and, uh, supply chain has been my focus the last five or six years, you know, so, you know, software, bill of materials, hardware, bill of materials. How do we connect all these things, which, and, and currently, so currently I'm, my main role is I'm vice president of strategy for sbe, which is involved in the SBO M space. And I've been, uh, co-chairing several, uh, cisa uh, working groups on SBO m sharing.
So we're currently have a group looking at ISACs, um, as SBO M distributors. How does that node in the middle start taking this information and, and propagating it As bonds software, bill of materials? Absolutely.
Great. Thank you Chris. Um, Katherine, Katherine, welcome.
Glad to have you on, I think first time we've had you on the show. Katherine Newcombe with CloudFlare, please introduce yourself. Yeah, great to be here.
I'm excited to talk about application security. Um, my name's Katherine Newcomb. I live in Denver right now.
Um, I've been in cybersecurity for about five years at this point. Um, and I started in the network firewall space, um, and encryption. And now I'm a product marketing manager for CloudFlare, um, for their application security business, uh, where I focus on their web application firewall product, um, our software supply chain product, as well as our encryption and certificate lifecycle management products.
Very nice. And, and I do like to say full disclosure, Textron is a customer of cloud flares. We do use their services.
Enjoyed very much. So thank you Catherine, and team for that. Uh, last but not least, another newcomer to our show, Kurt Handel, who's with, uh, Teradata.
Tell us about yourself, Kurt. So I've been working in security probably eight or nine years at this point, uh, but in the software industry for close to 15 years now, anywhere from development, uh, into business analysis, product management, even, uh, doing a little bit of red teaming myself, but, uh, I am currently the chief security architect at Teradata. And so I've been focused on architecture mostly for the past six, seven, possibly eight years, and really kind of a generalist.
So AppSec is where I spend the least amount of my time, but we focus on the architecture, the requirements, threat modeling, um, especially compliance. We do a lot of the, the major compliance frameworks at Teradata. So we've been pushing that recently.
Um, and I'm based in the Pacific Northwest, up in the Seattle area, and happy to be here. Very nice. Well, all the weather and fires and it's cold and I'm just glad we all made it.
Maybe it's 'cause we didn't have to travel anywhere, so, so I hang tight. I'm glad we're all here. And you know, our, our thoughts go our, our hearts go out to the folks dealing with the fires and, and, uh, some weather down south and southeast, et cetera.
So, um, let, let's kind of jump in this way. Um, it, it's a big topic when we talk about sort of the kind of current state of the cloud and where it's moving to. Um, but I don't think it's too much news to everyone that application and app APIs, API first kind of design into applications, you know, it isn't just things that sit at the edge anymore.
We think about also the security of the apps and the kind of, uh, software we're creating, the innovation that we're making, um, as maybe as part of the cloud. 'cause sometimes application lives within it, you know, like a, like a provider like CloudFlare or certainly at the edge or at the core as well. Maybe Catherine, if you wanna start us out with, how do you, you're, you're, you're managing, doing product management in this space.
How do you look at this, uh, sort of this problem or this space and define it? Um, so looking at application security, um, when we're talking about this at cloud, we're mostly talking about web application and API security. So if you're an OSI person, layer seven model, um, and you know, when people are accessing these external facing web applications, they're doing it from a ton of different devices and in a ton of different ways.
So they're accessing from things like mobile, uh, desktop, laptop, and they're accessing these apps that could be hosted anywhere. So on-prem, in public clouds, private clouds, hybrids. Um, so as we're securing, we need to think about how can we secure, um, all of these users and the end servers as they're sort of accessing these web apps, right?
So how do we make sure that, um, mobile traffic is protected, user data is protected, um, and sensitive data is not, you know, leaving an app. And then how do we make sure that a web app server itself is protected? Um, so at a very high level, that's about what I think, that's what I think about when it comes to application security.
Um, some new things we're thinking about in this space. Um, I talked about software supply chain. This is increasingly becoming, um, an area of interest as people create more complex apps with more third parties in them.
Of course, API first development has also meant we've had to adjust our thinking a little bit around application security as well. Kurt, how about you as a, as an architect, security architect, you may, maybe you don't get into the ins of applications and per se application security, but traffic over there. Obviously our networks are heavily API driven.
Um, you know, when you think about the security architecture, where does this fit into your purview? I think it, it fits in really everywhere, right? So we're, we're building these huge applications, sometimes small applications.
We, we do all sorts of scale at Teradata. And in my previous roles, I've, I've worked with pretty simple apps all the way to super complex microservices architectures. And so, like Catherine kind of said, you have the mobile aspect, you have the server, there's application code literally everywhere, including on the person's device.
And so how do you secure it as best you can, um, within reason, right? Because if it's too secure, it doesn't work. If it's not secure enough, well, you end up in the Wall Street Journal and you're in trouble.
Um, so we, from an architecture standpoint, we really try to focus on all different aspects of it, where the biggest threats lie, um, and then implement controls and use technologies to, to simplify the implementation and streamline it without making it overly complex. And so it's, it's just becoming more difficult given that, um, the, the kind of classic perimeter is gone, right? I'm sure you can relate to that, Chris.
Oh, yeah. Well, it was easy back in the day, right now, you had to get on the internet and you needed a firewall. Get a firewall, right?
And I'm thinking as Kurt and Catherine, you, your commitments remind me of these transitions we go through. Like there was mainframes before our time, but you know, I, I'm old enough to have seen the end of that where all of your capabilities are just to keep one computer running and run terminals and printers and things like that. And then we get into you, or where I came in, where we're starting to build networks, fractally more complicated.
Just, you know, how do we do that with, when all of our resources, were just keeping one computer running, we figured it out, you know, now we're here, we're talking about web APIs, Catherine, you, you know, the data going in and out and what's being stored. 30 years ago you couldn't have that conversation. Now we're saying, alright, what do we do in this case?
And it's very complicated. And I think in, and Catherine you mentioned the supply chain. This is, I think we're filling in the dots.
Security has been, is not, is not new, right? People have been saying, you should know your inventory for a long, long time, and we've gotten away with not knowing it. Now we're starting to fill it in, need to actually know where the software is, where the data is, and we're working through that.
So it's exciting times, but it's not different in type than other transitional periods. Certainly is an evolution, right? Of what we've gone through.
And to think about, you know, from the BA and host days, early, early on, pretty firewall. Um, Well, firewalls used to be a million dollars a year. I think when I got involved, you know, at least as I tell the story, there were a hundred in the world and typically were seven computers and a team of people.
And my argument at the time was my mom needs one. Yeah. You know, and so we're at this stage where what used to take so much time in here in the API, uh, world has to take less time a lot.
It, it, so let me, let me throw out this hypothesis. I think it may be pretty obvious, but maybe it isn't, is I think we live in a world, you know, now we we're thinking about things as zero trust, right? Of, of you, you know, anything is susceptible, being compromised and could compromise other things.
How do you pro protect all parts of the network applications, the infrastructure? But we're also living a world where if so much is determined by what our applications do, not just connecting users to apps, but applications really utilizing the network, being part of the network. It's a dynamic world, right?
It, it isn't a good set of firewall rules and an application firewall, and we're all good, kind of set that up. And it isn't the old days of I've got a pizza box in, in my rack for every function that I need, and they're all doing their thing. I'm good, right?
We need it. It's a much more dynamic environment. So I'm not saying we're reconfiguring our security all the time, but a security has to adapt to, you know, what's happening in the application.
Because we may distribute it to a different part of the edge tomorrow with Kubernetes, or we may, you know, uh, acquire business and suddenly our network has looked much different than it did, you know, three weeks ago. I'm, I'm curious, Kurt, as a practitioner, you know, how do you think about that of, you know, you mentioned microservices and all the things that are being created, you know, in the groups that you're working with. Um, we, we hate for security to be sort of the last thing to be thought of, but you wanna be in the conversation so you can prepare as well as react when you need to react.
Well, I think what you just said is, is really important that you wanna be in the conversation. You don't wanna be doing this retroactively. And so when you're, when you try to tackle security retroactively, it is infinitely harder to accomplish than if you do it from the beginning.
So I have, I do it both ways. I have teams that we work with proactively where they bring us in at the very start and we're building the design with them shoulder to shoulder, drawing the picture in doing security by design or by default as we like to say now. Or we have legacy applications, which you're doing retroactively and they're quite a bit higher in terms of risk because they've been neglected for so long.
Or you find out about something after the fact and it's like, well, how did this get out there? Well, there's shadow IP in a lot of the world. And so it's, it's hard to, to really kind of put a, a recipe together that successfully achieves it.
And then with the, the rapid pace of technology today and how the cloud has just kind of blown this wide open, or people can deploy new applications in a hundred different ways faster than ever. How do you keep up? So you have to implement tooling within reason without doing, without having too much sprawl.
You have to have the right personnel partnering with these teams, uh, to ensure that you have coverage and that you, you're really architecting things from the start. Um, and not just kind of using bandaids and bubblegum per se, to, to secure your environment later on. Catherine, appreciate your thoughts on this because, you know, I remember the days of networks for speeds and feeds and points of presence and connecting A to B and kinda looked like this nice diagram that you stitched together and that was a network and you secured it, now it's overlay on top of overlay and it's changing and mm-hmm.
You know, it's, it's multiple pieces that, uh, much more complex to, to secure. How do you, how do you have this conversation with people? Yeah, definitely.
So as you were sort of talking about this, you know, obviously there's a need for responsiveness and customizability and security, but I actually also wanna make the argument for unified policy management in application security. This is something that I've seen actually, for example, um, we have some customers who have protected their SaaS apps, like what is traditionally more of a network firewall or zero trust type use case with the same policy they're using for their web applications. And by doing this, they're able to do things like make sure that zero day exploits aren't able to exploit their SaaS apps, you know, as well as their, um, web apps.
And we see a lot of value out of these unified policy managements. I was talking earlier about, you know, know how we have all these apps hosted in different places. We see a lot of customers, for example, will host, um, you know, an app across multiple clouds for like a resiliency use case.
If they're worried about outages, you'll, you'll certainly see that, um, for example. But then how do you have to, you know, actually secure an app that's stored in multiple places? Do you write different policies for, for wherever those are stored?
Um, do you write different policies for APIs versus, you know, traditional apps? Um, so we see a lot of benefit out of like a unified policy for all of those disparate sort of endpoints and all of those disparate, um, locations that they're stored. Uh, for CloudFlare in particular, how this sort of works out is our WAF is like the backbone, the architectural backbone of the rest of our application, um, security portfolio.
And this works out really well because you can do things like have a WAF and an API like positive security model protecting your APIs. Um, so you could do things like detect zero days and volumetric attacks, which are, you know, APIs can also be susceptible to as well as, you know, do the things like Ebola and, and all those API specific attacks all within sort of one, um, control plane, which we find a lot of people get a lot of value out of because of this really, really disparate environment. Okay.
Chris, I saw a lot of hand waving head nodding, bud jumped outta your chair on this one. And so I kind of have a feeling you might resonate with this. No, um, I, I gotta throw out there, I was gonna, uh, before Catherine got into the, the policy thing that's swear I, I spent a lot time, but yeah, the concept of an SBO m the software bill of material for the current release version of Adobe Acrobat as opposed to an SOM four as we're look talking about here, some ephemeral web app that one time for five seconds exists in the cloud.
You know, think about that. How do we, how do we deal with that? And I, and, but I think policy is, is the answer all hacking?
All hacking is policy hacking. I will figure out how you do things and I will figure out where the gaps are and I'll engineer that gap. And we live in a world right now where we generally have no idea what policy applies to any of us anywhere, with few exceptions.
And in this topic, and because I'm used to the supply chain topic, imagine I needed to get the, the SBO M or custody information about a piece of software on his phone right now. I could get it in between five days and six months. Today I need to get it in of half a second.
That means I need to read the policies between me, the person who bought the phone and the first time the company I bought it from, and like their relationship, their contracts, their policies, you know, upstream all the way. And we have to get that done in the next decade. So, so without unified and, and, and adaptable, you know, transparent policy frameworks, none of this technology is gonna make a difference.
So I think we, we will do that. And there's interesting things going on down that path. It's kinda interesting in a way, just connecting dots between what you said, Catherine and you were talking about Chris, there's your own unified policy management, right, of what you're doing.
So you know, you're, you, what you're applying where and how you're applying it, and then that's how that interconnects or interrelates with the people you connect with, work with, use their service product, whatever that is too. And I, and I appreciate what you said Chris, about, think about just serverless technology, like a lambda kind of service, right? That, you know, it's there now, it's gone tomorrow may not be the same thing.
It was a second ago when it, when it ran. Um, so it in some ways, Catherine, it's sort of a dynamic unified policy management, right? It can't be a static thing.
Am I, am I on base here? Yes, of course. You know, you do have to be responsive to the environment, um, you know, threat landscape.
Um, this is one, one area where I strongly advocate for actually ML driven, um, detections and policy. Uh, this is a thing where, for example, if you have a really large data set, uh, you can train your ML models. Um, how we do this at CloudFlare, just 'cause I think it's a little easier if I give an example and it's, uh, we will score each request on a scale of like one to 99.
And if something is less than 30, that means like it is very likely to be an attack. And because we have, um, hundreds of terabytes of requests, or sorry, hundreds of millions of requests every single day, um, we have so much data we could train this on and say a little blog in Malaysia gets attacked by a new attack we've never seen before. Suddenly because that tiny blog in Malaysia got attacked that gets feed and fed into our ML model, we don't have to rely on a security engineer to like go and find and analyze that attack and turn it into a regular expression like firewall rule.
Um, the ML will basically just say, okay, like since it matches something like this, um, we will just automatically block it. And this is why I'd say ml um, sort of combined with that traditional, um, you know, security analyst looks at the traffic and writes a rule that matches it and then blocks traffic. Um, you gotta combine I think these types of approaches.
So ML is a really, really great application, um, when it comes to being responsive to the threat landscape. And we have some data around this as well. Um, we recently, not that recently, like half a year ago released our annual application security trends report.
Um, and we found out that, uh, for example, like zero day vulnerabilities, um, we probably wouldn't have been able to find this out with just security engineers analyzing it. But with our ml, we were able to detect, um, and exploit 22 minutes after the, uh, proof of concept was posted online. So, um, really, really great applications there.
A lot of interesting stuff going on for sure. Well, that doesn't make the case for dynamic security. What does, right.
Um, I, I'm curious, Kurt, how do you, is, is someone, you know, applying these things, applying security? Are you, are you looking at things like ml, are you doing it via yourself? It's something you look for in the vendors, the partners that you work with.
How do you leveraging either that or other kind of technologies to help shorten that cycle between when things change and how you can account for it and secure it? Right. Uh, I think the ML piece of it is, is hugely important because humans, we're slow.
The, the technologies we use, the computers and each servers process all of this far faster than the human brain and I ever could. And so we need to augment ourselves with this technology. So anytime we're evaluating new solutions and bringing them in, like I'm currently in the process of implementing a big one right now that focuses on platformization and ai, ml, it's all part of it because in humans with eyes on glass, like it's great to have those guys in the sock, but they'll get overwhelmed very easily with the speed at which things happen today.
And so we need to leverage technology and machine learning enables us to do this faster than ever, and it's only getting better, right? And so augment the human with that technology and you can very quickly pare down all of that information to what matters most and focus on real attacks like Katherine was just talking about. I wonder, you know, there's so much activity around ai, of course, a lot of it because of gen generative ai, um, Chris, do, do security engineers have to become machine learning experts to be able to do this stuff?
What does it take to really leverage it? No, but knowing, knowing something isn't gonna, um, uh, cause you any problems. But, uh, I, I just can agree more with, with both, uh, with Kurt and Catherine.
'cause you know, and, and you're point Kurt, it's all about time, time to transparency. How, how long, and again, I've seen this over and over in my career where we get to these points where what we're mostly doing is sharing the war stories. You know, I have no idea it was 72 hours, none of us slept.
There was caffeine. And, and my my question always is, okay, if there was twice as much, what would you do? Because obviously that we're at the limit, we can't possibly work any harder to stay awake any longer.
And, and this, yeah, ai, ml, Oracles, whatever we call it, this, uh, my, a big has been a big part of my, uh, my focus on supply chain before it would, you know, AI became, you know, uh, a general, um, uh, generative, what the hell do we call it? I'm sorry, I forgot. Yeah.
Ative ai. Yep. Generative ai.
Yes. Uh, too many terms to throw around. Yeah, because again, we need to, you know, just for supply chain things, I need to read the contracts.
I mean, I can literally call someone up, you know, it's not a security engineer, but it's some administrator person at the company and I had to get them on the phone and get them to pull A-A-P-D-F and read the contract and find out if the clause allows me to get the information I need. That's not worth a human's time. I mean, that's the kind of stuff that computers can do really well and there just beginning, but that's obviously the direction we're going.
And if you can't see your policy environment five years from now, by various definitions, your competitors will be so much faster than you are that it won't matter anymore. Kurt, I'm, I'm curious, without giving us too many specifics about Teradata not asking you for that, but what's your sense of, what are the, what are the new priorities that are on your yeah, on your horizon or things you're dealing with now that you've kind of added in the last year or so? What's changed about how you're thinking about security and that you've gotta address now?
I think there's, there's always classic problems that we, we have to deal with and tackle. Like, we can't forget things like identity and network security and the rest of it. But the, the prevalence in the emergence of generative AI and putting AI and machine learning in everyone's hands has meant that security teams have to be hyper aware more so than ever because these new technologies, people are latching onto them without considering the risks.
They're like, that's awesome. I can speed up everything I'm doing. And suddenly you see a new story about, well, what was it like Samsung engineers leak their code through regenerative AI solution or whatever.
So you're, you can quickly lose intellectual property or put it at risk. And so we have to think about securing our environment for those solutions, or putting the guidance out for people to use AI and machine learning. Um, and I mean, getting visibility of all of this, and another big one that's been getting pretty popular and we're seeing a lot from different vendors and acquisitions and whatever, is data security, posture management.
Where is my data? Where is it moving? How secure is it?
Because at the end of the day, that's what the attackers want. They don't wanna sit in your network and use your resources to, to launch attacks as much as they used to. They wanna grab your data, steal it, monetize it.
So need, we're, we're focusing on data security big time in, in the more recent years, especially, um, forward looking because we have more data than ever. Interesting. Catherine, from your perspective, you know, communicating with so many companies, what are some of the changing priorities from your, from your viewpoint?
Yeah, I mean certainly the gen ai, um, piece is something we're seeing a lot. Um, everybody wants to put an an LLM on their web application. Um, and of course that means that you have to think of that as like a data security concern as well.
Um, because you wanna make sure your LLM is not gonna like accidentally leak somebody else's social security number because that's certainly happened before. Um, and so at, at CloudFlare we're thinking about this of like, basically how could you basically just put a WAF in front of an LLM, um, from that perspective, how could you prevent it from exposing sensitive data to the end user? Um, but then, you know, you gotta think about these more complex issues as well.
Like how do you prevent somebody from poisoning the model? How do you prevent, um, you know, some of these other, like how do you prevent it from hallucinating? Uh, these are all, you know, sort of adjacent to security concerns, but, um, but nonetheless, we see some security teams focusing on this, um, increasingly.
Um, additionally we also think about, you know, the, the LLM sort of security use case as a little bit of a just, um, increased API security use case since a lot of times, um, people are not building these LLMs themself and hosting them themselves. They're often, you know, bringing in LLMs from third parties, which, uh, necessitates, um, APIs, right, for integration. So how can you make sure that these APIs are staying secure and not leaking them back to the host and whatnot.
Um, so that's definitely something we're seeing as well. Um, I would say additionally, one thing I've been hearing a lot lately is, uh, software supply chain security. Um, I think Kurt mentioned the beginning, um, sort of securing code that lives on the client device as well.
Um, this is something that we've been hearing a lot about, especially as it comes with the PCI four, um, compliance, which is gonna be mandated at the end of March, um, in a couple months. Um, PCI four has a new compliance requirement around client side security and securing, um, the client side, like software supply chain. Um, so this is something we've been getting a lot of questions and inquiries lately.
Um, you know, how much are organizations responsible for, um, the code that loads on their end users' devices, uh, when they visit their websites? Um, this is something we're seeing a lot of people trying to actually actively get control over, um, and make sure that they're not, you know, serving, uh, code to the client devices that could do things like download a crypto mining software onto their phone, which, um, believe it or not, we have seen somebody's trying to make, you know, personal laptops part of a crypto mining network, which is pretty crazy. But, um, so yeah, I would say the client side component is, is something I've been hearing a lot lately as well.
I, I just have to say, I, I, I love living in a world where we can use the term, uh, you know, hallucinating artificial intelligence in a conversation like this. Seriously, just, we, we understand about that. It's not a sci-fi movie.
It's real. Oh, it's, it's real. Yeah.
Hey, so I've, I've kind of a left field question for you, Chris. So if this, if I throw you too far off the track, I'm guessing you're thinking about this though, is, is there an SBO m in our future for LLMs and s SLMs and all of these things? Because in a way, this is a whole nother part of the software supply chain, right?
We're handing off to something that's doing inferencing, either on a chip on our handset or in the cloud, all of the above. How does that fit into, do we need to be thinking or at least wondering how we're gonna solve this problem? And not only not left field.
And that's, that's right in the middle of the, the, the track. So in short, yes. You know, there's ano, there's a, another sister working group, uh, Dimitri Rayman, uh, my colleague CTO at, at cy Beats is, uh, a co-chairing now on, on AI bomb, right?
An AI bomb has been talked about for a long time. So what does that even mean? You know, so AI is code.
So there's this, you know, same sort of standard SBO stuff about that, but there's also the training data and the models that produced. Right. And this sort of goes back to my last comment about ephemeral, ephemeral SBOs.
You know, we start with the idea that I am a software provider and every 16 years I release new code and I carve a new sbo, you know, on purist graphite. Um, but we live in a world where code gets compiled and used all over the place. You know, how do we even look forward and say that I can commit to a policy that says I will, if asked, provide the contents of this code without, um, actually going out and printing or saving or producing quadrillions of SBOs forever, you know, in, in exabytes storage.
Uh, so this AI is, you know, what we're currently calling AI is just another forcing function of the level of complexity we're at. So we need to be able to provide the answers to live up to the policies that we've agreed to, um, which is, you know, you know, in the SOM case we're talking about a software inventory that I will be able to tell you what code that was running or you know, what data set was used. And we have to get there.
And, and, and it's, it is reasonable progress down that path. It's a, it's a complicated one that is very similar patterns to how we'll do other things, uh, similar complexity. Complexity.
Um, Kurt, is, is that on your radar yet at all, kind of thinking about security of, from a supply chain for LLMs and AI and ML algorithms and all that kind of stuff? No, I mean, it's, it's certainly jumped up on the radar, especially since the whole SolarWinds thing happened. Um, as Chris was talking, it got the wheels turning in my mind of, well, if we're gonna be kinda, we're moving towards leveraging ai, AI in the sense and dynamically generating SBOs and things, is this another attack vector we potentially have to watch out for?
Is how do you weaponize that and, and protect against it? Because I mean, as we see attackers evolve their tactics and techniques faster than ever, they're coming up with new creative ways that defeat the traditional approach in microseconds. And so how, how do you stay ahead of that curve now?
And so I obviously, I don't have the answer right now, but it's, it's really interesting as Chris talked to start thinking about this, this new sort of problem that we're facing. And again, it all falls back to the rapid evolution of technology. Yeah.
Speaking of that evolution, uh, just in the last week or so, uh, Satya Nadal, head of, uh, Microsoft was talking about the death of SaaS, meaning that's kinda the clickbait one liner that what I think he was really talking about is e evolving nature of software architecture that I would describe it as today's microservices or backend code or tomorrow's AI agents, right? We'll see more and more parts of apps built through, you know, with or through or maybe completely with AI agents. And it reminds me of going into the, uh, cloud native era of, oh, how do we secure microservices now that we're gonna do that kind of thing?
That's kind of the, that's the next edge that we're, we have to work on and think about how, uh, there are different things we have to do for securing AI agents. How are they orchestrated? Is it Kubernetes or it, some other thing that's managing all those things.
And, uh, given that we're putting AI agent building capabilities in everybody's hands, in many cases, it, uh, could make for interesting. I use that in a nice way, uh, interesting environment to try to secure and manage. So in some ways, the future is bright, but it may be, uh, pretty intense at the same time, same time.
Well, and I think kind of building on that too is the, the technology behind ai, it's backed by machine learning. Like you're, you're making technology autonomous, right? So it's not as predictable anymore.
So how do you secure what, when you don't exactly know what turn it's gonna take next, Non deterministic. Right. Well, I, I gotta add a note, a note of hope though, because it's easy, you know, to your point, uh, Kurt, the short answer is yes, because there's a new attack vector.
Oh, yeah. Um, but, you know, throughout my career I've been arguing this one, it's like, we'll probably keep the lights on. It's like, no, no, if we don't do this and that, then, you know, we will, you know, we're on this, we're doing this call right now.
We've managed to figure out everything else up to this point. And not only that, but I think that where we've been mowing the lawn, and I think, you know, what we need to do, generally speaking in cybersecurity has been known maybe forever, certainly 50 years, but we haven't gone around to doing the vast majority of it yet. 'cause we haven't had to.
But as we do, and I, I will take a risk and, and put a lot of my, my faith in policy, you know, in, in real policy transparency, you know, in, again, in this decade, it gets harder to be an adversary because, you know, these are the happy World War II fans out there, you know, or no fans, you know, but the, the ubo wars, right? There was the happy days when you could just have a U-boat and sink shipping all day long. You know, that's kind of most of the world, most of the, the history of the united to date.
It's not necessarily gonna this day that way, that long forever where there's always a new attack service, and there's always a, a, a new way when the last one is, is locked. I think we will, we'll keep it running. We will all be fine.
And I think over, you know, at least over a period of decades, being an attacker will become much, much more difficult. I mean, I might argue it already is becoming more difficult. It 'cause the, while, while the, the technologies we use as practitioners are getting more advanced, that helps make it more difficult for the adversaries of the world.
That's not to say that they can't employ similar technologies. Right? So now we're kind of, we're creating that chicken and egg problem all over again and playing the game of cat and mouth.
It's kind of the next arms race, if you will, as technology evolves, everybody has access to it. Well, let's do this. I appreciate all the conversation and we brought up a number of topics, um, just as a kind of concluding thought.
Uh, we, we've been talking about what are the things we need to be thinking about? Maybe they're new, maybe they're on the horizon, maybe already working on this today. Um, if you had to say, there's one thing you'd really want to emphasize this, if you were Yeah.
Somebody who's listening to this and maybe making a few notes. The thing that sort of stands out to you as something really important to be thinking about in the next, let's say six to 12 months, if not today. Um, Kurt, do you want to give us your thoughts and then Kathleen, if you would, and Chris, you can wrap it up for us.
Sorry, did I say Kathleen? I mean Catherine, excuse me. Kathleen.
I work with a Kathleen. Sorry if I've been doing that. It's all good.
Okay. Yeah, I, go ahead, Kern. I mean, it's, we wanna avoid that situation where everything is a priority, so nothing's a priority, right?
I think we, throughout this conversation, we've highlighted the importance of, we've highlighted the importance of application security and how it's, it's becoming more important than ever because our application code is, is literally going everywhere. And that's, that's kind of the gateway for a lot of the attacks we're seeing in the world today. And so I think the, the emphasis is on application security, but it's also to say, let's not forget the rest of it, because all of the, the other parts of cybersecurity are hugely important.
And we still need that visibility. We still need the coverage, and we need to be thinking about ease of use as well, and avoiding the sprawl. So I know these aren't necessarily specific cybersecurity things, but they, they help you simplify your approach and, and focus on what matters.
And that depends, that, that changes everywhere you go. Every enterprise or company has different priorities. And so I think focusing on those things help enable us to, to focus on what matters for where we're at currently.
Good. Catherine? Yeah, so I mean, like Kurt said, you know, we wanna make sure that we're not making everything equal priority.
So I think when it comes to application security, which is of course, my area, what I would say is most important in this space is visibility. Um, the attack surface is getting more complex, applications are getting more complex. Um, you know, where they're hosted is getting more complex.
So how do we actually have visibility into our entire, entire application attack service? How do we have visibility into the APIs developers are creating so we can actually secure them? How do we have visibility into the software they're adding, um, to these apps?
Uh, that I would say is probably the most important thing for application security and also one of the most challenging things. Excellent. Chris, You know, Kurt and Catherine both want exactly where I'm going, so I'll just build on that.
You know, do do things that save you time to transparency. You know, if you, you know, don't panic, nothing's on fire. And, and when things are on fire, panic less, right?
Just take your time and, uh, getting visibility, you know? Yeah. Look at how long it takes you to figure out.
And anytime you find a, a, a way, you know, in this, in this topic we're talking about here, to spend less time to figure things out, you have all that time back to do things. And it's easy to just, you know, particularly in transitional periods, to just do more and more and more of what you've been doing, you know? But, uh, understanding the environment you're in so you can apply your resources appropriately is, is everything.
And there are lots of ways to do that these days. You know, there, there's a lot of Russian panic and there are a lot of, and you know, I will say it, AI and things like that out there who will actually make your life easier, give you some of your time back. Mm-hmm.
And point, feel better knowing what's going on, make, make, and make better plans, a better strategy, Uh, to that point. Exactly. Chris, and, and Catherine mentioned it around, uh, ml, you, some of the things that I'm really excited about AI is actually just the understandability of what's happening.
You know, Kurt mentioned about as things ramped up or, or you did, uh, uh, in, in the, if the tax doubled, right, how would we handle that if we're already maxed out? So some of it is just handling the volume of things that are happening. But I think one of the things that I think is most exciting about generative AI is it's also so complex.
No one person can understand the full system, right? Or maybe even understand truly what's going on in a case of an attack or where you have vulnerabilities. And generative AI is starting to make some inroads and helping us understand systems and, and giving us some insights to some of the complexity.
We may not be able to fully get into our head all at once. So for example, I've been doing some work around how do you modernize mainframe applications? Well, nobody was around that built those things.
Well, maybe it's people that built the network aren't even around, right? So help us understand what really is happening with all this data that we've collected. And the natural language interface through that is, is a great aid, and I think it's just a real practical thing that we can start to begin to use today.
So don't think of AI as just as the next, you know, it's gonna replace all of our software and it's all gonna be different. And what do we do? There's things today that is already helping us with.
So, you know, there's some real things too, not just what's on the horizon. Well, thanks to all of you. It's been great, Catherine.
Uh, we appreciate your perspective and Kurt, your bringing, um, your experience and perspective. And of course, Chris, always good to be chatting with you and your connections into the security world. And some of the folks are working, collaborating together, which by the way, is another superpower we have in security.
And that's the fact that we work together and collaborate on, on these things. We're not going at it alone. So thank everybody for their good work that we're doing to help advance.
We hope this has been a helpful conversation for you in thinking about the, the last great cloud transformation, what we're doing differently and thinking about, uh, as we move forward. So as we've got our heads down, getting stuff done, getting our priorities done, getting our plans in place and executing for 2025, but also kind of thinking a little bit about what's next and what we might be considering and learning from others that are working in our space. So thanks to all of you.
Thanks everybody for joining us today. And thank you to the Cloud four team for, uh, for sponsoring, um, our show today. And we look forward to joining us either on another recording or Sure.
And check the calendar for one of our live events where folks can ask questions and engage with us in a similar kind of conversation. We have many of those coming up. We'll talk to you again soon.
Take care everybody.