Techstrong TV – February 25, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hi everyone. Is AI gonna make us like those fat corpus souls driving around in gravel chairs in the movie? Wally, you are watching Dex on Gang.
Hi everyone. Happy Tuesday. Welcome to Textron Gang.
It's great to have you on. Hope you've been enjoying the, uh, commentary lately. There's certainly enough to comment about in this crazy world that we live in and crazy times we're living through.
Um, we have a lot to go over today, including is AI making us that lazy and dumb. It's a terrible way to go through life. Um, let me introduce you first though, to our Audi, uh, to our gang that's gonna discuss it today, joining us.
I think she's back home in Colorado after her California Ventures. She is a FU analyst, infrastructure storage, just a lot of general all around smart. Exactly opposite of the, the AI making us stupid people.
Our friend Camberley Bates. Hey Kimberly, it's great to have you. Good to see, good to be on with Techstrong.
It's always a lot of fun. I learned something from you guys. Thank you.
Well, we always learn from you, so thank you. Speaking of smart, how's that from Hudson, Hudson, Ohio. He's the CEO of Tech Field Day.
It's my friend Stephen Foskett. Hey Steven, how are you? Uh, honestly, I thought you were talking about Mike, but, um, I might've been, but I I figured it's Tuesday.
I'll cut you a break, but Stephen popped outta there. I think he was blushing. Yeah, I think he was blushing.
Um, we'll come back to Stephen in a minute, but let's run over to Harrison, New York though and introduce our chief content officer, Mike Baard. Hey Mike. How are you?
I'm good. Uh, I'm waiting on the remake of Dumb and Dumber. I think it's gonna be called Dumb Dumber and Dumbest Thing.
Got a third, um, but certainly not Dumb. In anyone's book is our Echo Insights analyst and, and, uh, author of her new report as well as editor Bonnie Schneider. Hey Bonnie, how are you?
I'm great, Alan. Great to be here. Thanks.
Good. We're gonna talk more about your report. Yeah, we, we spoke a little bit about it, uh, last week, but we'll, we'll pick up on it today.
Um, alright. We're hoping Stephen will get back on here. But Mike, you know, I, I, I opened up with us.
I, I've had this sneaking suspicion for some time that first it was the internet and not going to the library and running, learning the Dewey Decimal system, but social media, our AI video screens and phones. Is it dumbing down the human race? And are we all destined to live in those gravel chairs like the fat people in Wally?
It all started with the calculator. Man, we all, nobody knows how to do math and it's just getting worse. Yeah.
But, but the issue is, as noted in a report put out by Carnegie Mellon University and Microsoft that we're just maybe relying too much on ai, there's a general assumption that people kind of trust whatever gets presented with them on a computer screen and that they're not gonna reason enough about what is actually being presented to them by the AI model. And once that happens, we just all kind of, sort of compound mistakes upon mistakes. And I don't know if this is something we need to just teach people.
Is this something we gotta get at, at the school level? But, um, Alan, I'll start with you. Our cognitive reasoning capabilities maybe declining even further than they are.
And I know you don't think they're pretty high to start with. No, I mean, yeah. I, I, I agree with the, kind of the findings from this report is when people start using crutches, right?
Their muscles atrophy. And, and I I think to a certain level, yes, our brain muscles have atrophied. Right?
When it, when it comes to certain things, I mean, you laughingly talking about math, but how many, how many people today actually, other than if you, you know, you work in something in ai, for instance, where you have to know, you know, some higher math skills, but even basic math skills division, right? Algebra, basic algebra and geometry. How many of us know how to do that anymore?
Or, or, you know, without a calculator, can, can we do it? Um, it's the same thing for writing, right, Mike? com or Security Boulevard.
Their writing is atrocious, atrocious. So written skills, kids don't know how to read cursive script. Um, the, the list goes on.
And I could see this happening with ai. Just tell AI what you wanted to write and it writes it for you. And I'll go one step further.
Tell AI to write the code and it writes the code for you. Is it gonna dumb down coding? You know, it's a fine mess.
We've got ourselves into here. I I don't know if this is something you learned in school. Can we teach critical thinking in school?
If so, how do we enforce the no calculators in the test rule? I don't know what the answer is. I think checking, um, that's what I was doing.
You can check, you know, if something's AI written and teach a student that, um, if you're a teacher that we can tell if it's ai, so don't, don't bother just cutting and pasting it. Um, teaching them reasoning. And then of course, before all that, teaching them how to explain an idea, which I, I think is something we all grew up with learning how to write a paragraph, you know, to support it.
But, um, kids today, that's more of a struggle 'cause they haven't had to do that. So I think that those basic skills of coming up with an idea and then finding ways to support your idea just on the basic level, um, will help. But obviously it's a long way to go.
So, lemme see. Go ahead, Kim. So I would even go beyond the kids.
That's good. I was gonna point out, This is one piece of it, and I was looking for the study on this and I can't, couldn't find it. Um, quickly this morning when we had this key topic coming over, which was one of the big, um, consulting firms, it was McKinsey, BCG one of those guys had done some analysis on this kind of work.
And they had one group that was doing marketing, a marketing plan that was using ai and another group that did not use ai. And what they found is the one that was not using AI had more creative, out of bound thinking, et cetera. And that, because, you know, to me, the reasoning behind that is because you're socializing between different thinking operations in, you know, that's why we like the concept of having a lot of different thinking and skills basis in terms of a group that works through some, some issues.
So when you think about how we have to go through and problem solve, those are the things that we're looking for potentially an AI system to be used. And, and then the other piece I'll go to that is that I was looking at, you know, as I was trying to search on this, I found a really great graphic that was done by BCG about what, what predictive AI does versus what Gen AI does. And if we think about what Gen AI is doing, it's content, it's really a lot of content.
And versus predictive AI is giving me an analysis of where something is going. And that technology of how, how we code or how we direct the computer systems to operate is very different. And then what they're also saying is, how do you join those two pieces together to create and more analysis is going?
But I absolutely agree. I mean, and I'll stop with this one is like I backpack and I cannot tell you how many times I've been in the mountain and some, I'm sorry, 20-year-old has got their GPS with them and they're expecting that to get them through the mountains. And we're going not, you know, you get lost because it, the GPS doesn't work up there.
You can have satellite, maybe that's gonna help you out, but GPS Uhuh, it's gonna go and you're screwed, you know, with that. So there we go. In theory, we should be using AI models to check the output of other AI models.
And maybe that will help us determine what's reasoning. But then I worry that the AI models will just argue with each other forever and to the point where, Well, you know, so Kimberly, I agree with you. This is not a just a kid's problem As we get older or tell us, if you don't work out right, you lose muscle mass.
If you don't use it, you lose it. It's the same thing for critical thinking skills and, and reasoning and, and stuff like this. And so, you know, young people are very resilient.
They'll figure out how to leverage this and be clever and what have you, and what they lose in, in dexterity, for lack of a better word, uh, they may make up for in, in leveraging AI in ways we haven't thought of before. But I think it's, it's the adults in the room. It's the, you know, people my age, your age, you know, 30 somethings, 40 somethings who, you know, becoming overly reliant on, on these things may in fact kinda lose that, that muscle of creativity of, of thinking out of the box, of, of doing things without it, right?
Like all of a sudden it's bad enough that most people refuse to read very much anymore, right? They just don't read. People don't read.
We see it here at Textron. They like to watch videos rather than read and they're like Bullet points And they like, yeah, they, if they do read, they want it in three or four bullet points. Uh, but when you start getting to the point where people say, well, AI can make that for me, if they don't make it for me, I don't wanna, I'm not quite sure it'll take me a very long time to make it, you know, it, we all lose, But we are also seeing long form come out.
So, whereas, I mean, one of the things that we've been seeing and why podcasts are on the swing up is because we are seeing the younger generation want the longer form. And, um, and they will hang on into that and, and listen to those longer. You know, it doesn't have to be three minutes anymore.
It can be like, this is, this is an almost an hour session, right? And we do it in 20 minute psychs, you know, cycles or 15 minute cycles. But that gives us an opportunity to go into the topic much more deeply than it does on, you know, cable news where they're only giving it two minutes if that much time.
Um, so there's an analysis, potential analysis that's going on, um, that we haven't seen before, even if it's done by video. Right? So, Steven, are you with us?
I am with you. Can you hear me? I can hear you.
So the discussion was that, um, the younger folks aren't doing enough reasoning because they're relying too much on ai. And since you're closer to this particular topic, I was just wondering, you know, do senior citizens have an advantage now? I see, I thought you were gonna call me a younger folk, and then I feel like you're calling me a senior citizen.
But, uh, you know, speaking as one of the younger folks, uh, no, you know, I was reading these articles and I placed the blame somewhat on AI itself. AI is, is the smart alec know-it-all. It has no sense of humility.
It has no sense of what it doesn't know. You know, AI confidently answers everything, and in many cases, confidently answers it wrongly, but so impressively that I feel like, you know, I don't wanna take the blame off of people entirely, but I do wanna put the blame into the way that these AI applications are made. It's no surprise that Silicon Valley made a bunch of smart Alec robots that, uh, tell you how it is without giving any opportunity to have any other thing.
But, you know, think about it. I mean, you ask chat GPT for a thing, or you're using Apple Intelligence to summarize an article or whatever. Are you really, really going to think critically about that when it comes across so confidently it doesn't say, I think these are the main points of the article, or perhaps in my opinion, this is where we should go.
It says, no, here's a summary, here's the important points, here's the bullet points. And so it's no surprise that people look at that and say, huh, okay, that must be right. Yeah, but, but Steven, you, you, you're kicking the dog, blaming the dog for being a dog.
Whether, whether AI is right or wrong, people shouldn't blindly just accept it and use it and move on. I don't care if it was right a hundred percent of the time. So, okay, AI's right all the time, let's all get into our gravel chairs and get fat.
Right? I think the answer is no. You can't just like, you don't bring calculators into the test.
Maybe there are some things that you don't use the AI for to, to exercise your brain. I think we, we need, we're humans, we're problem solvers by, by genetics. And we need to continue being problem solvers.
Now we use tools. That's what separates if so, they say that's what separates us from other animals and so forth. Though we found animals do use tools to, but we, we need to be solving problems.
That's, that's how we continue our evolution, I think To be, to be fair to the machine. To be fair to the machines though, we all have that friend who has an answer for everything and confidently tells you that this is something, and by God, this is the actual facts. And upon further review, you always discover that that friend is dead raw.
So not Always, I make a career outta this, but go ahead. So is, is AI not that new friend who's kind of sometimes right, but always has to be jet? I I Would say so.
I exactly. I'm not blaming the dog for kicking, its for getting kicked. What I'm saying is, we humans built a tool that confidently answers everything.
Is it any wonder that we're not questioning it? So it also gets back to, okay, there's another scenario here, is that open book tests, you know, they, they, they started doing open book tests. You know, when I was doing this, and you could bring your books in, if you had to go through your book to find the answer, you were gonna flunk that test.
You did not have time to go and do that. And this gets back to your argument or your friend or your whatever, giving you the statement of blah, blah, blah, blah, blah. And you not having the data to come back to it because it's not in your brain.
If you have to every time go through this to find out the answer, um, or to have a argument on any kind of, like a negotiation, I mean, if I have to go to that for negotiation, I'm doomed. If I have to go to that for a lawyer sitting in front of the, sitting in front of, you know, the, you know, questioning somebody, I'm doomed. So there's, if I have to do go to that as a doctor on everything, I'm doomed.
So there's a lot of things that we are doing that we have that is just skills and jobs that if that's what we're doing as a consultant, if I'm sitting there pulling out my phone when my client is asking me a question about something, you know, I'm doomed. No, but, so, but here's, here's, here's, you are right Kimberly, but here's the reality. There is no more consultant.
There is no more doctor. There is no more lawyer. It's the ai, you know, like right now about half of my health, uh, appointments are telehealth, right?
I, I get on Zoom with my doctor, we go over my blood work results and you know, we, we actually wind up shooting the crap about technology to try to shoot. But, um, whether that was really my doctor or some max headroom impersonation of my doctor is kind of, Imma, you know, to me, he's going through my blood result. It's going through my blood results and telling me what I should or shouldn't do based upon best practices.
Same thing when I consult a lawyer. Same thing frankly, when I consult a consultant, let's say in, in infrastructure or storage. And I think that's the scary thing, right?
Are are we gonna replace not just augment people, but replace them with, with these ais? Well, I think there's, I mean, when you look at, okay, let's take best practices for infrastructure and, you know, I just finished reading a book on cybersecurity, et cetera, and it's talking about it, you know, you have to understand that 20% of your technology within any kind of data centers changing at any point in time. So what are your best practices in addressing that?
Yes, I'm going to use tools to bring that information to me about what's changed, what's going on. But I can't just peanut butter over with an ai, it can have it bringing, you know, forward the information that I probably need and probably need to make some decisions on maybe taking some of these decisions that I don't need to have to make every day. Um, and applying that.
But hopefully what happens is, and this is what we've talked about before on here, is what we've done is we've raised the decision making to a higher level. We're having to make decisions on certain issues here and not the lower level decisions. The problem that brings is that the systems architect, the senior systems architect, can make those decisions and can use that.
But we're not bringing the junior people up because they're not getting the chance to make the mistakes, make the analysis and do the process. So that to me is the bigger threat about what AI is bringing to us as opposed to having, you know, giving us some of the information to be able to make those decisions. So how is this any better or worse than the number of queries that I've put into Google over the years?
And every time I have a cold or a symptom and it comes back and tells me I have b bubonic plate, it's like, does do that? No, no, no. It's lupus.
It's always lupus. Well, but, but, but seriously though, right? You, you talk, I have friends who are doctors and they call people like that.
You know, people who have an MD from Google. Mm-hmm. Right?
And they're, and they're the scourge of the doctor's office. 'cause everyone calls up. I think I have lupus, I think I have plague.
I think, you know, well, because WebMD said that, and I did a Google search and I probably have tumors on my brain and, you know, and they're like, calm down. You know? And that's the difference.
And, and Kimberly, I hope that that's the way it stays, right? That the doctor, the real human doctor is who we go to and we stop relying on Google Doctor. Google Doc.
Um, but it, it's hard. I, I just, I mean, I could see the, the reasoning behind this. Anyway, hey, we're over 20 minutes on this one.
We've gotta jump, we've got a lot more to talk about. You're watching Techron Gang. We'll be right back is with are our heads in the clouds of report from Tech Field Day, Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Welcome back to Textron Gang. So I, I'm Stephen Foskett and I was out at Cloud Field Day last week, and I thought I would share some of the insights that we learned, uh, on site during that event. Now, this was a special one for me because I attended Cloud Field Day as a delegate, not as the organizer, not as the founder, not as the, I I sat in the chair, I listened to the presentations.
I asked some, well, some good and some joking questions. And I, uh, started writing about some of these presentations. So it was a really interesting event.
We like to say at Tech Field Day that there's never a theme of a tech Field day intentionally, but there's always a theme just, um, after the fact. You know, because that's just sort of, it reflects the state of the industry. And this event was no different.
Almost every presentation focused on the challenges of cloud networking and security. And, um, most of the presentations also discussed the challenges of this hybrid infrastructure where you have some things running in the cloud, some things on-prem, some things running in a different cloud, and you're trying to make sense of all that. That was a really interesting observation for me because, you know, you, you see some companies here that, uh, that were presenting, for example, selector, uh, Catchpoint, Infoblox.
You know, you look at these companies and you're saying those are networking companies. What are they doing at Cloud Field day? You know, we've got Fortinet, uh, you know, haiku who have traditionally played in the, in the, uh, cyber readiness, data protection, uh, security spaces.
And, and you look at them and, and you're saying, so, so the cloud, huh? But, but it's so true. Everything they said came back to the cloud and cloud infrastructure.
And specifically in, in most cases, it came back to the challenges of dealing with this sort of proliferation of everything in the cloud. Essentially, it's become incredibly easy to spin up applications to spin up complicated web scale applications in the cloud. And now people are starting to realize, wait a second, wait a second.
We need this data protected. We need to watch for, um, bad actors who are trying to attack it. We need to figure out ways of, uh, integrating that with, uh, other aspects of it.
We need to get some control over this thing because it's just sprawling completely outta control. And there are incredible risks to that. This sounds like the kind of thing we've been talking about here on Textron Gang for a long time.
I know, Kimberly, you and I have talked about this, Mike, I know you've written about this, this whole challenge of things just getting outta hand in the cloud. I think that that resonates with y'all, right? And, and I probably, I bet to Haiku, I wasn't, I didn't listen to the session with Haiku, but Haiku two years ago launched a big initiative to, to, um, enable protection of SaaS applications.
You know, at that time we were still seeing a slow buildup of protection. com, but the rest of SaaS, those applications that you have running, and so many of the companies now, their core applications and their data is sitting in these SaaS environments. And, you know, let's say your hr, HR information is up there, or your, you, your, um, ERP system is up there and you're thinking that that company is responsible for protecting your data.
Well, Microsoft came out and said, no, we're not protecting 365. You want your data protected, you need to go do it. And so all of a sudden there's this rash of stuff that was going on with there.
And so, yes, I would understand that. It's, you know, it's that backing it up. It's about protecting it.
It's making sure that nobody can attack it. Um, so it does not, you know, and I think that had a rip had a, a ripple effect with some of the other SaaS firms to saying, no, I'm not gonna take that liability, that that's too big of a liability for me to, you know, be responsible for my company. What I'm doing is delivering an application.
I am not doing data protection on all the systems and security. I think that there were a couple, uh, there were, there were some outages about a year or so ago, a spa of them in the cloud, maybe two. And I think that made multi-cloud a more real concept in people's minds because they realized they were overly dependent upon one service and they had a single point of failure.
I feel like we've been talking about this subject for years, but I don't think many people were actually doing it until recent times. But that's just my sense of it. So I, I think they have been, I think frankly, I think for the most part, the analyst community and the press missed the boat on multi-cloud.
I think we were all very focused on hybrid cloud, private and public, but everyone thought you'd put all your eggs in one public hyperscaler, whether it's AWS or Microsoft or whoever, or Google or Oracle, whatever. But the reality is people pick the best tool for the job. And so they put this over there, this, there, that, there, and there's more.
But wait, there's more. Now we also have the edge, right? And people are putting stuff on the edge, and they're putting some stuff that's gonna run on, on the endpoint and then still runs on the data center and private cloud and VMware versus not VMware, right?
We, we truly do live in a multi-cloud, multi-home environment. You know, back in 1999, 2000, actually it was 2000. I helped write a business plan for a company called Lattice Networks, L-A-T-I-S.
And we envisioned based in Boulder Kim, and we envisioned a world where this happened. It was before contain modern containers and all of that, but we thought that applications and data would be distributed, and we, we raised some money for it, and it was a miserable failure. Um, we pivoted and that Lattice Networks became still secure.
Mitchell, Ashley and I were two of the three co-founders, and that became still secure, uh, because we were way before its time. But that's exactly the world we live in today. And a truly, truly distributed architecture.
However, when it comes to the security of SaaS data, I, I have a bone per pick, right? One of the, one of the premises, no pun intended, premises of security on the cloud is a partnership between the cloud provider and, and the user. Because I don't have access to all of that infrastructure.
I cannot protect the infrastructure. I probably can't protect anything below the OS in your average infrastructure as a service, right? I'm responsible for security above that.
Amazon AWS for one, has done a lot to give me visibility into that infrastructure security, but very little capability into that infrastructure. And it's still my, uh, responsibility, right? Because ultimately it's still my data.
And so I'm ultimately responsible. It's a terrible thing to be responsible without capability. It's like, right?
It's like taxation without representation, right? Same thing here goes for SaaS. Now you look at text, we don't really have any infrastructure.
We're basically a SaaS company. Everything we use are SaaS. I don't have a server closet.
I don't have storage on S3 or something like that, that I know of. Um, but, you know, we use a lot of sas. It's incumbent on those providers to make sure my data, right?
Because when we get third party requests, I go back to my SaaS providers, I say, are you SOC 2 compliant? Are you, gimme your proof because your proof is my proof. So, and I'll go so far as Microsoft too, right?
That data for most of us is stored in OneDrive. When OneDrive has an issue, they could say they don't, they're not responsible until their president gets his a*****e in before Congress and says, me a culpa me a culpa, right? Yeah.
But the CSPs have never been responsible for your data protection. And I think Steven has got some commentary on that, some new products that are coming out. But I mean, I've, I dealt with, 10 years ago, I dealt with the firm that had their data wiped out by the CSP and the CSP because of bad, bad practices on the data protection.
And, but if you read the fine print, they are, they are not responsible unless there is malfeasance. That's, And it's Not even fine print. I Have, that's just, yeah, it's, it's explicit.
I mean, they're available for high avail. They're responsible for availability, not even high availability. They're, you know, they, they, but, and immutability in some respects, but again, not even immutability, just sort of like, you know, yes, it's probably gonna be the right data.
They're not responsible for data protection. And that's why companies like Haiku, like you said, are impressive because they can hit that. But to Alan's point as well, I mean, you know, it really is, companies are going to be using more than one cloud.
They're gonna be using more than one environment. And that's where some of these other companies come in. So, you know, Infoblox really impressed everybody because I mean, D-D-N-S-D-H-C-P and IP address management is super boring.
It is the most boring subject in the world, but it's also the most important subject in the world when you have this proliferation of, of automatically spun up machines that are just populating the world out there. And, and Infoblox showed that they can really do a, a, a great job of that in modern cloud environments. You know, the same is true, um, with, uh, for example, Catchpoint, they came in and they were talking about basically, you know, you can't control if, um, AWS goes down or if, uh, you know, the, some infrastructure element in the internet goes down.
But it's a really good idea to monitor and manage that. Because again, you know, you can say, you can throw up your hands and say, oh, these SaaS providers should be responsible for their own stuff. They should be responsible for high availability, for data protection, but they're ultimately not.
And ultimately, if it fails, it's your problem, not their problem, because you're the one that was running your application there. And so you need to know if the infrastructure is running, you need to know if it's protected. You know, Fortinet was talking about, um, doing, uh, data protection of SaaS applications, uh, buckets and, um, AWS accounts with the wrong permissions and that sort of thing.
Again, it, it's real easy to set this stuff up wrong and end up exposing your information or having people take your stuff over. Um, you need to be able to jump in there and, and, and make sure that this stuff is configured correctly. 'cause your cloud service provider isn't just like, they're not responsible for data protection.
They're also not responsible for misconfiguration. And again, for real, uh, continuous availability and, and, and that sort of thing. They're, they're just not gonna do it.
And so you need these things, you know, you need something that's going to make sure that your network is configured properly, like Selector was talking about. You need something that is going to make sure that everything is gonna continue to run, because this is your infrastructure to Alan's point, this is your, this is my infrastructure and, and textron's and, and Futurum, we don't have a data center. We have the cloud.
And so it's, we have to, we have to apply the same concepts we would in the data center to the cloud. And I think there's two different areas that you need to be looking at. One is your infrastructure, if you're using the cloud as your infrastructure.
And the other one is if you're using a SaaS, both of those read the fine print because it will say that they're not responsible except for malfeasance. In essence, you read the fine print and then understand what you need to make sure that you projected whether or not, if you lose that data, what happens on a SaaS situation. If you lose your network, what happens?
And, um, so those are two different discussions, if you will. But related, Can I just clarify here? So are we actually saying that the phrase shared responsibility is not worth the contract it's written on?
Is that what we're basically saying? No, I don't think so. I think there is a shared responsibility, but there's a limit to how much they're sharing.
So understand what, what they are going to do. And if you want to have any more than that, then you need to have something there. I mean, understand it's, you know, trust but verify So that it's always been a shared responsibility, but the liability, the responsibility has always been on the end user.
That, and that, that's been chewing the cloud since day one. And, and really, you know, back in those days, what's the biggest inhibitor to more cloud adoption, cloud security, um, you know, that, that was the standard response we did here in the security world. Um, because the idea was I can't be responsible for what I can't control, right?
I can't do that. Now, I will tell you, you know, companies like Akamai, CloudFlare, both companies we've featured on Textron, CloudFlare, we do our last great cloud transformation with where a customer as well, um, they try to offload some of that responsibility, if you will, right? But ultimately, when the stuff hits the fan, you get left holding the back.
That, that, that is absolutely true. And it, and, and then it becomes a question of trust. Do you trust?
'cause these are your partners that SaaS providers, your partner, that cloud providers, your partner, do you trust them doing their job? And then what do you do about that? Yeah.
And there's this ugly word that I've always felt like is an ugly word called audits. And I know exactly, I cringe that. I thought they fired all those guys.
Well, you know, I, I said, I was reading this book this weekend on cybersecurity. It's called Cyber Warfare and Peace. Um, and he talked about the, when he talked about the audits, he thinking about audits is what you are gonna use to expose where you have gaps.
And that the goodness about audits is it's showing you where you may be exp if, if you're talking, as I said, infrastructure, 20% of it's changing, where are my gaps? What am I missing? So I want to have an audit basically to say, okay, here is my gap.
I need to block it. I need to take care of this. Um, so it's in a positive for the first time I'm thinking in a positive fashion about what an audit is.
I, I think that's, yeah, most people would rather 22 to the back of their head. But, uh, anyway, hey, we're over 15 minutes. We need to take a break on this, or we're going to come back and revisit part two mm-hmm.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Welcome back to the Textron gang. Well, my report I've been talking about is finally published. It was published, um, just last Wednesday, and we're getting some, uh, great feedback on it.
com. And I wanted to focus now that the report is available to everyone, the, the impact and takeaways specifically for IT practitioners since that is a, a big portion of our audience here on Techstrong tv. So here's a little short video to show you some of the findings and, and where the impacts might be felt by those practitioners.
Decisions that define executive strategies and innovations driving corporate sustainability highlights five major shifts, transforming IT infrastructure and reshaping operations. Power demands are rising. Greater computing power requires more electricity pushing companies to adopt AI driven power management, liquid cooling and greener cloud regions to improve efficiency while easing pressure on resources, optimizing energy cuts costs moving from CPUs to GPUs can significantly lower consumption with some businesses reducing usage by up to 50%, turning efficiency into a financial advantage.
Hardware is lasting longer. The standard four year replacement cycle is fading. More companies are refurbishing, repurposing and designing infrastructure for longevity with some targeting, 75% circularity by 2030, reducing e-waste.
Along the way, regulations are tightening. The eus corporate sustainability reporting directive is now in effect requiring affected companies to implement systems that track and disclose carbon emissions. IT roles are evolving.
Climate conscious technology is now a priority, yet the talent pool isn't keeping pace. Companies are working to close the gap through hiring and training initiatives. Read decisions that define executive strategies and innovations driving corporate sustainability.
com. It's been great getting feedback on this report to see what people are saying. I recently had the chance to be on the Schwab network talking about it as well.
And one of the innovations about it was talking about the AI energy use, sustainable investing. I think there's a lot of crossover into these findings, and I look forward to everyone checking out the report and, and IT practitioners that are watching us, please read it and I'd love to hear your feedback as well. Yeah, you know, it's a, it's a great report.
So what I find interesting is there are some people who hear sustainability and they, they immediately go political and, and all the stuff that's out there, but that's not what we want to talk about today. Wanted to really focus on there are truly economic reasons to do sustainability, right? Right.
To, to do these things and, um, give us, I mean, believe for instance, you had five sustainability shifts in it. S but talk about Economic behind it, the economic reasons. Um, right.
And that's one something I talked about. It started off with, well, it'd be nice if we, we were more sustainable, let's get our emissions down to net zero. And those goals remain.
Of course, we hear about that all the time from big tech. But what we're finding is that, um, vendors and, and I actually looked at the startup dates for a lot of the companies that I talked to in the report, and many of them just were created within the past three to five years. So, uh, it's really kind of exciting to see the growth in this area.
And the ones that are newer are ones that create SaaS tools for IT teams, for different types of companies. It could be any industry to track and, uh, record their carbon data emissions and how to run their IT operations more efficiently. So that's when you start getting into cost savings.
And many companies are reporting success with savings because they are running things more efficiently. They have software that can tell them when to tap into renewable energy as a resource. One of the ones I talked about for, uh, cloud regions to pick a provider.
That's where, where it's located in the case of platform SH located in Quebec, because they're relying on hydropower. So there are, there is an ROI factor that's now being able to be quantified, uh, that I really get into in the report. And I think it's important because we've talked about sustainability quite a bit on Textron gang, and it's always the same.
Well, unless it's, if it's not gonna cost more, no, but if it saves us money, okay, we're open. And I think we've crossed over to that point based on the data that we're seeing. Fair enough.
Kimberly, can I draw a line between the amount of energy being generated or consumed than the actual cost? I mean, is it that linear or, or is it more like a barometer that tells me that my costs are going up, but I can't really track it that granularly? It's definitely something that's not linear.
And I think Microsoft is finding that as well, because, um, there are Chief sustainability officer recently put out, um, a statement about it that, you know, when it comes to what the goals are, and then all of a sudden the use of AI things, things are sh things can shift. So, uh, many companies are doing offset credits for carbon to try to, to reach their goals. Um, it, it, it's a little bit of calculating how much energy is gonna be used, how much can renewable energy can we use, and then is it available?
And that's something that's, that's being decided now. And then of course, we talked also about on the show about nuclear energy as another option. Now I look at sustainability is way, way beyond the energy piece of it.
Sustainability to me is what we're putting into, um, you know, waste and how do we recycle that? Um, and recycling, you know, it's kind of like here at our lab here, we had a company come in and cart away probably close to 800 pounds of old gear, um, that they were all gonna take apart and, and recycle and recycle the metals, recycle whatever, and how it goes. So that does not go into, you know, the, the trash bin, um, company, I believe it's Marvell that the re re um, using their CXL technology and deploying it.
So CXL, which enables you to, um, pool memory. And they've designed it, and I think it's Amazon is picking it up in order to recycle their DDR, their older DDR is gonna go into this CXL technology. It's gonna go into the slower processors that they have.
But instead of jetting the ddr, you know, going directly to DDR five, you can actually have this pool. And that's good enough for certain applications. So some unique areas of different kinds of sustainability that go into definitely you, what you're talking about.
But that, that is huge thing, right? You know, Bonnie and I are down here in Florida. Florida is a notoriously plastic civilization, especially south Florida where we live.
You know, everything gets basically redone every seven years or so. They, you just tear down stuff and build new and, um, and it's so wasteful because esp especially in tech, especially just because you don't have an iPhone 16 doesn't make your iPhone 14 or 13. There are people around the world that would give their right arm mm-hmm.
For an iPhone 13. But our society, you know, I don't know if I want to do the Apple trade in, I'll just leave it here in my drawer 'cause they're only going to gimme $99 or whatever it is. And, and so we're, we're incredibly wasteful to, to that point.
And then how much of it a year or two later goes from the drawer, Kimberly, to your point, right into the garbage bin, which then winds up in some public landfill, right? Where those are good parts that should be recycled and, and they're toxic to boot to put 'em in the waste in the landfill. You know, one of the companies, um, human IT that's featured in my report is really incredible outta California.
They take all of companies unused phones or, or, uh, works laptops that they're not using and they find veterans and families in need who need them, refurbish them and at a much lower price provide them for, for schools. And, and the success has been phenomenal. And just the appreciation as you were saying, you know, those kids are thrilled to have LA any laptop.
Sure. So it's really, um, it's, it's really, I think it's one of the things that's happening in HP also is doing that with Renew Solutions. Very successful program where they military grade testing to make sure whatever they're selling reselling is, you know, functioning perfectly.
So, um, and I think that's gonna move and we're gonna see continuing because it 'cause it is profitable and it's also helping people too. Excellent. Excellent.
Alright guys, if that's it, I'd like to call a wrap on this version of the Techstrong Gang. Couple of announcements. First of all, we, we made reference of the, uh, tech Field day report that happened, I guess last week.
Uh, cloud Tech Field Day report. Of course, all of those videos are available. I believe they're on techstrong tv and they're also on the Tech Field Day YouTube channel.
So for anything that we were talking about, if it piqued your interest, go check it out. com. com.
You could download that. That's pretty cool. Um, Kimberly Infrastructure matters.
You mentioned, you know, this is something we're gonna start featuring more on Techstrong. Actually I have a, uh, this week I have my very first interview with Ryan Stroud from, uh, signal six five Lab. We're gonna be featuring the lab a lot more on Techstrong and some of the great work they're doing in the reports that are available.
You don't even have to register for them. They're free to just go download and have a look at, which is great. Yeah.
And they're doing some really cool stuff. I, I'm on their channel, their back channel and all the conversation that goes around the testing. So it's, it's pretty cool things that they're, they're learning, um, you know, through the process of what all they're doing.
And I believe there's a report coming out on Intel Granite, which will be fascinating To you. Ibm, ibm, M Granite, bm, Intel, IBM, granite, and then Intel's what other GPU it is name A, a something. Yes, we, we are gonna, there's three reports that Ryan and I are gonna hit over the next week or two.
Great. Um, so that'll be great. And in the meantime we'll just keep rocking and rolling.
Everyone, thank you for joining us today. Stay tuned for the rest of Text Drunk tv. It's probably another two, three hours at least of content today.
And of course you could also just check stuff out on Text Drunk tv, our Tech Drunk tv, YouTube channel, or any of our 8, 9, 10, 12, whatever sites that we're running here at Techstrong. Until then, though, everyone, this is Alan Shimel, we're outta here. This is Textron tv.
Hi everyone, it's Alan Shimel here for another Textron TV interview. I want to introduce you all to Chris Gibson. Chris Gibson the CEO of first, the Forum of Incident Response and Security Teams.
We'll go find out more about that in a minute. First, let's say hi and welcome Chris. Hey Chris, welcome to Techstrong tv.
Thank you. Alan's it. Great to be here.
Fantastic. So Chris, before we get into, first, let's hear more about Chris. How, how did you come to be the CEO here?
So my first job when I left my education, I went and dropped bits of explosives down holes in Saudi Arabia. I, I worked in a seismic company, really got pretty boring pretty fast. And I moved into technology.
I worked in a bank for a number of years. I moved into Citibank, I bounced around Eastern Europe, upgrading and installing banking systems. And then moved into Citi's information security proper under Steve Katz, who was the sort of the, the world's first CISO back in 19 nine.
I think. That was, um, spent a number of years there then running their incident response and their forensics gang globally supporting investigations and actually running the incident response team for a portion of that time. Uh, then I've moved into civil service in the uk, cer the government here decided to set up a national cert for the first time.
They had the pieces in place already, but there was no single entity that was a national cert. So I jumped across to them and spent three years building and running the, the UK's first formally chartered national cert, which was a joy, absolute joy. Uh, if you're gonna do incident response, do it for a country because that's when it gets really interesting.
Um, I'm sure A little bit of private sector. And then this opportunity at first came up. Now I'd already known first Citi was a member of, first we were, I was their representative to the, to the organization.
I'd been on their board, I'd been their CFO, I'd been the chair for a couple of years. And then the opportunity came up to work for them. First had moved, was moving from a volunteered led organization, purely volunteers with, with a number of contracted services, but run by volunteers to a point where they wanted to professionalize and bring someone whose job it was to do this.
So I got paid to do what I used to volunteer to do, which is just the joy. Can't think of anything better being here about six years now. And it's about building first stuff into, you know, properly global meeting, the vision and mission statements that we have.
Excellent. Excellent. You know, it's funny, I, uh, I used to, uh, have a, I co-founded a cyber firm and I remember Citi in those days.
You know, it wasn't Citi, it was Citi group. Yep. I think it might have still been, I don't know if it was Citi Banks city, but I think it was Citi Group, City Group.
Citi, No, I used to work with, um, I don't know if you ever, they had three global CIOs back then kind of thing. Right. And one of them was a fellow named Peter Fisher.
Yeah. Uh, outta New York. And I remember talking to Peter, we were trying to get our vulnerability management product tested there, you know, and this is in the days now.
Microsoft's starting to do, uh, patch Tuesdays and all that, you know, but Citi, it, it's, if you put out a patch on a Tuesday, it was 90 days or so or more Absolutely. Until they Yep. Applied it.
But interesting times, interesting times. So it sounds like first though has been around since those times though. Give us a little, Chris, give us a little first background.
So first started in 1990, after the very first worms. Um, cert CC was formed in 19 19 90, after the Morris Worm, a year or so later. There was another fairly disruptive one.
And people on the internet, you know, the internet, there's no control, no one is in charge of the internet. It's all little islands of systems that talk to each other and sort of know where to go. So nobody knew how to deal with these incidents.
There was no one place to central place to go to. So essentially an informal forum of teams grew, grew together, primarily US based and worked out, you know, if I have a problem, this is the guy I'm gonna talk to at that place, and this is the guy I'm gonna talk to. And this is his strong point, and this is my strong point.
Forced forward, move forward five years, we set up as a formal organization. So we've been a legally, you know, proper organization since 1995. We've now grown to 760 odd teams in 111 countries.
And our vision is that when there's a problem on the internet, you can go the formal route of, go to your law enforcement, go up the chain, go across to another country, come down the chain. It just takes too long. We all know that when worms hit, when viruses hit, you know, they can bring the internet down in, in seconds, minutes, hours.
There's not the time to go through that formal process. So we believe in bringing teams together, building that network of trust such that if I have a problem in Country X, I know someone in that country, I've been there, or I've met them at a conference, or I've done training with them, I can talk to them and get stuff done while we go through the formal process. We accept that's not a scalable option that works now, but we need to fix that.
So we also get involved in standards we can involved in, in building systems that talk to each other and so on. It's all about improving the art of incident response. We know we're gonna get hacked at some point.
Everybody will have a problem at some point. So let's prepare for that. Let's be ready for that and let's actually be able to deal with that fast.
That's amazed. That's great stuff. I've, I, I have to confess, I've been in security 25 years plus and probably close to 30 and I, I'm not, I was not familiar with first, so now I am.
So you at least you converted one person. That's, that's great. I think the challenge is the years we tried to defend our way out of this problem, you know, we build a better firewall, build a better system, build a better list.
Now we've got to that, you know what, we're gonna have incidents and, and central banks. Yeah. That, Well that, so I saw that starting to take place in maybe 2010 to 12.
Yes. The shift from prevention to, to response. Yes.
Right. It used to be 80, 85% prevention, 10, 15% response. I'm not saying it's 50 50 today, but it it's certainly not 85 15, which is a big, big change.
Big change. And I, I wanna jump into our topic of discussion, but before I get there, what's the website for first, Chris? It's very simple.
org. That's it. Dot org.
F-I-R-S-D. Yeah. And like a footprint at industry shows or anything like that where people can So typically, yeah, typically not.
We've always, because we believe in building this network of trust and whatever, we don't go out and do advertising. We don't go out and do marketing drives. Essentially we grow organically.
So someone meets someone from first we talk about it, they say, that sounds interesting. They come to a conference, they join. It's been very much based on that.
We grow at about 10% a year. So we grew from the original 15 to now 770 odd teams. As I say, 111 countries.
But we've never wanted to just, you know, it's not a pay to play. If you don't sign a check and join. You've gotta be, you've gotta be accepted in, you have to be sponsored in by an existing team.
But it's all about building that network of trust And the kingsmen. Just kidding. Um, but that, that, that's interesting.
You mentioned the conference though, is their first conferences. So we run An annual conference, we take it around the world. Uh, last year was in FKA Japan.
We had 997 people attending thou from 96 countries. So it's getting big. It's a full week.
This year is Copenhagen. Next year we'll be Denver, Colorado. We'll see where we go after that.
So yes, so that's the big one. But then we also do local, more regional events with local um, partners. We do training events with the ITU, we do training events to do capacity building.
We have funding from the UK government to do stuff in Africa, rural. It's, it's about building communities around the world through those training, through those events, bringing people together so they can work together, talk together, and learn to trust again, we're back to that trust. Absolutely.
Alright, Chris, if you don't mind, I want to kind of segue, turn to our topic of discussion, which today is all about securing data in 2025. Right. You know, we'd all love to live in a world where everything's a green field, it's all shiny and new, and we get the latest and greatest.
Of course, that 80 20 rule applies to that too. 80% of what we work on or more even, it's not greenfield, it's brown, muddy fields, and you've got legacies and, and obsolete stuff. And a good mixture of, you know, just a mishmash of everything securing data in 2025.
Chris, where do we go there? So I guess fundamentally the challenge is, is the first step to any of this is identifying what you've got, where it is and how much you value it. I mean, none of this is rocket science.
None of this is new you and I would've talked about this with peers for many years about that base level cyber hygiene. What have you got? What do you care about?
Why are you securing it? That's always been the challenge. When I look back at my time at Set uk, you know, we ran most of the cases, we ran, most of the incidents should just never have happened.
They were, they were bad passwords, they were bad kit, they were unpatched, they were the usual litany of stories that we've heard many, many times, which is my frustration, you know, if we could persuade people to do that really well, we would solve a lot of the problems we have. But it is, it's that not knowing what's there. So I can think of, you know, significant incidents where there was a server, it was somewhere over there, they forgot about it, it wasn't on the radar.
Someone found it and booked, and they got, and all their high tech kit that they had, you know, really well secured, was just broken by this wheat link. That's always been my prime take, just identification. I, I, I say it, you know how I always enunciate is you can't defend what you don't know you have.
Absolutely. Absolutely. Yep.
But, you know, I tell you, Chris, and I'm glad you are today because I, I had a conversation this morning with a few people about the idea of who's responsible for securing data in stats applic, right? So many of us today, and not just as individuals, these, even within organizations, you know, everything's in the cloud. We don't have data centers.
We don't have, you know, we're using all SaaS AppSec. Those SaaS AppSec store a heck of a lot of our data, a lot of it. Mm-hmm.
But when you read the fine print, they're not really responsible for that data. We're still responsible for it. Obviously, it's our data, but yet we really don't have total control.
So it's, it's like this is the old taxation without representation. I know. I, You can't say that.
Well, I, I remember going to the tower one year on a, on a, on a, a, you know, a, a terrorist trip and, and the, uh, you know, the, the, the terrorist, I think that who works at the tower, you know, they're in uniform and everything. The VP feeders. Yep.
Yep. Yeah. The V feeders.
They said, you, I had you yanks paid your taxes. You'd have a piece of this too. But, um, but anyway, you know, it, it's a funny thing.
How can we be responsible for data that we don't necessarily have full control over? And, and to me, I think this is going to be an issue. It has been an issue, but it's gonna be a bigger issue.
Couldn't agree more. It's a real challenge that we face. I believe, you know, when I look at most small, medium enterprises can't afford to have a fully functioning incident, you know, security team, let alone an incident response team.
You know, schools, small, medium enterprises, charities, nonprofits, they're lean and meaner. They don't have that time. So we would normally, I would say, move it into the cloud because then you are, you're part of a bigger thing that hopefully and normally has, you know, sophisticated people looking at it, making sure that it's all secure.
But you're right, when it all goes wrong, the blame will still come back to you, whether you like it or not. That's a challenge there, isn't it? There's that blame culture that we have that anyone who gets hacked, it's their fault, which, which is still, still ongoing and is still many cases wrong.
Um, but, but, but it's not the bad guy. You know, if someone breaks into your house and steals something, people don't tend to bring the homeowner. They blame the bad guy who turned up and did it.
But that's just the way we are today. It's the way we roll. It's not a good thing.
I, I think you're right. How do we, how do we secure that data? We need to understand what we've got.
But again, small, medium enterprise, the IT guys probably, you know, it's 50% of his job because he's doing other stuff. We roll into this. We want, you know, faster development, better applications.
We want faster to market. We want to be, you know, leading edge and all the rest of it. Every one of those things is an absolute challenge.
When you're trying to slowly make sure you understand what you've got, where it is, who owns it, what you care about, it's, it, I don't have an answer. There is no answer. I don't believe.
No. I, I, I don't have an answer either. I I also feel like, you know, the trains left the station.
We're not gonna take our stuff off of the cloud or off of SaaS. But I think that ability to have an incident response process that, or, you know, at least a plan, at least you've thought about it, you've table topped it. Maybe with the senior management, they know what they're gonna do when it goes wrong.
That's, that typically is what we see now is, you know, central banks and whatever are not saying you can't have an incident. It's how well you recover from that incident. And it's your ability to take your, you know, your public, your customers, your staff with you to make sure that you are not looking from, you know, like an idiot.
Because we've all seen incidents where they've not gone well. They've been a train wreck. Sure.
So, Chris, let me pivot a little bit to related kinda thing. I, I, I, uh, I did a, a YouTube show, LinkedIn live thing a couple weeks ago on what I call it sovereignty, right? For a long time in the cloud, we've had this concept of data sovereignty, right?
I want my data stored within, in a data center within the borders of my country, or these, what I consider friendly or secure countries, or well understood countries or what have you. And, and cloud providers have spun up all kinds of, you know, data sovereign type of clouds where, where people can do that. It seems unfortunately that we're entering into an age where this is gonna extend maybe even beyond data to it in general, right?
I only want to use it that was born and read and, and, you know, made here. 'cause I don't trust it or I just, political reasons, whatever. I don't want to use non-native meaning, you know, native to my sovereign, listen to me, this is gonna be a huge, it's just a cluster to tell you the truth, right?
How do we, how do we, how do we plan for that in terms of incident responses and everything else? It always feels as though we're going back to the days of data. If, of our own data sectors, you know, we want it closer and closer to home.
We want to understand everything that's in there. We want it to be only, you know, maybe poten, potentially, you know, our data on that bit of kit, no one else is. Yeah.
So no one else has access to those drives and so on. That feels like we're going back to the days of, you know, big data centers and IBM and, and all the other things, which, you know, maybe that's the way forward. Um, again, we're back to that identification, aren't we?
What is it? Where is it? Who's got ac, who's got access to it?
If you're on a, you know, multi hosted system with multiple people coming in and accessing bits of that data, well, if someone hacks, breaks into their systems, does that give them access to yours? So just understanding that, that's hugely complex for any organization, let alone a small, you know, back to the small medium enterprises, the charities, the nonprofits, most of the people who are, you know, generating the wealth throughout countries, they don't have those people. That's, again, it, it's a huge, huge challenge.
Again, I would say, back to the incident response, yet, if you may not understand that, but at least have a plan, have a table talk, think about who you're gonna talk to, how it's gonna work, so that you can have a response to that. You're not caught flatfooted. Yep.
I, I, I do agree. And I think, you know, it, it sounds so simple, but it's been so true for all the years I'm in insecurity stuff is gonna happen. Yep.
Right? Yep. Stuff happens.
It's having a plan for when stuff happens that separates success from failure. Right? A lot of us, for too long, you know, we used to say, if nothing happens, you did your job in security, right?
How often have you heard that, Chris? Over the years, right? When security's good, nothing happens.
But we now know you could have good security and still stuff happens, but it's how you respond. That kind of is really, at the end of the day, the, the, the line of, of whether you're successful or not. And, you know, I guess that's what first is all about at that level, right?
That is absolutely what we do. We bring people together to talk to each other, to learn from each other, to give presentations, to do training, to run exercises to help each other get better at what we do. Our mission statement talks about, you know, making the internet a safer place.
And we do that by trying, it's like we, we consider ourselves firefighters. We are there to put out the fires. We're not there to solve the problems, although clearly there's a feedback loop just in the way that firefighters do.
But we consider, we there to just keep the internet up running stable so that you and I can do all the things we want to do. We can bank, we can shop, we can talk to our friends, we can chat. We can do all those things online.
Confident that the internet is a reasonably safe place to do that. Agreed. Chris, one last question 'cause we're over time.
Um, you, you basically have to get sponsored in, but for people watching this who may want to, you know, have their organization, their team mm-hmm. Become affiliated or learn more about first, what, what's your best advice to them? The best, best, best advice Come to the conference, come to an event, see what we do, see how well, how well I think we do it.
You know, really do that. Alternatively, drop, drop a line. There's, there are contact pages on the, on the website.
You know, we will work with people. We're more than happy to have conversations and introduce them to folks. But coming to the conference, meeting people, building those relationships such that there will be teams to sponsor you, that's, that's the best way of doing it.
I love it. Chris, keep up the great work. Thanks for you coming on here, evangelizing, telling us about first Appreciate it and, and best of luck.
Okay? No, thank you very much. It's been a pleasure.
I enjoyed it greatly Love to have you back on Chris Gibson, CEO of first forum for incident response and security teams here on Tech Drunk tv. We're gonna take a break. We'll be back in a moment.
Hello and welcome to the latest edition of the Techstrong AI series. I'm your host, Mike Bazar today with Christian Lau, who is chief product Officer for Dynamo ai. And we're talking about, well, now that we've all kind of gotten our heads wrapped around ai, the hard work really begins.
We gotta deploy this and manage it and govern it and secure it. Christian, welcome to the show. Great to be here.
Thanks, Mike. What are you hearing from folks in terms of what their challenges are? I feel we went from couple of, maybe 18 months ago, a lot of irrational exuberance to a lot of experimentation.
And now I think folks are kind of trying to figure out, well, how do we, uh, deploy AI into a production system? Yeah, I think when you look back 18 months ago when this new technology was coming out, uh, there were a lot of questions about what is the, what are the risks that we even need to account for? When you have a chat bot that can basically act like a human being, you can prompt it in infinitely different ways, and it can output, you know, many different things.
It's, it's, uh, what we call like an unbounded space of a possibilities that you can prompt, you know, and so, uh, to a lot of our customers that we work with that are in more regulated sectors, like say the financial services sector or the federal or DOD sector, you have a lot of questions about how you apply existing, for example, model risk management to this new technology. And I would say over the past 18 months, you saw a lot of progress here because in order to actually deploy this into production, not only get to get the technology to work, but you also have to prove to many stakeholders across the organization that this is a technology that's gonna be secure and compliant when you actually deploy it, right? And it's gonna, uh, you know, not harm your end users or harm your company's reputation.
And so that's kind of been a, a big focus that, that we've, uh, assisted many enterprises with, is how can you generate evidence that you've properly managed the risk associated with the technology? And that's really the first step to, to unlocking the true value of all the amazing work that's being done at the Found foundation model LA layer and application layer we're seeing today. Um, that, that's kind of like, uh, what, what we're commonly seeing across our customer base.
How do I govern all that? And I'm asking the question because AI models are subject to drift. And so I may finally build one and deploy one, but it may not be acting as expected, you know, nine months after I've deployed it.
And as far as I can tell, it's not like traditional software where I just apply a patch and update it. I've gotta kind of, uh, for lack of a better phrase, rip and replace. But, um, how do I kind of wrap my head around that workflow?
That, that's totally right and kind of dive a little bit deeper into that problem. There's different aspects to this, right? So when you look at the underlying what's underneath the hood of most of these AI applications, you might find that there's a rag vector database attached to it.
Uh, you might find that the large language model might actually be swapped out at different points of time, might be updated by your foundation model provider, um, or it might be dynamically switching. And so all these things really affect the drift of these models, and there are ultimate performance, right? And so it's really important that as time goes by, you implement two sets of controls that we recommend to, to, uh, enterprises we work with.
One is doing repeated and very custom and tailored evaluations of your AI systems, of your models, uh, even behind the scenes, right? Uh, so this means that running, you wanna run a repeated test when the newest model comes out, are you gonna be able to run an evaluation, not just the general benchmarks, uh, but also benchmarks are gonna be tied to the specific use cases that you care about. Because a lot of times you'll, you'll find that the latest and greatest model that comes out may be really great at coding, but it might actually be worse at, for example, writing the types of reports that your particular use case calls for.
So you want to build these customized evaluations that kind of run in an automated way in a, in a, in a repeated way. And, and we'll give you consistent, we'll check if your, your model is giving you consistent results, right? So that's on kind of one side, these types of offline evaluations.
But the second part that you wanna implement is real time monitoring and observability, right? And this is where we really start to see now these AI systems, these, uh, you know, these models actually become products in themselves. And you want to apply, you know, as I'm, I'm I, I lead the product team at Dynamo, you wanna apply the same principles of product management, of, of gathering analytics on utilization, where things are failing, um, what type of questions users are asking and queries user are asking.
You want to collect that type of analytics and build in those customized flags. And so we have these real time detectors, for example, classifiers that we build for our customers, and that they can customize that will go and actually find, okay, was there a 80% of of your LLM outputs refusing the end user's? Uh, ultimate question, right?
And or is there a new type of question that's being asked from end users that your model wasn't prepared to answer for? And so now I need to go into my vector store and populate it with more information, or I need to figure out a better way for, for the model to retrieve that type of information if it's already in there. So it's a constant kind of monitoring of your AI system and really looking at it from a product point of view, uh, and, and getting the information you need in order to make, you know, adjustments to continue to have consistent performance.
There's an old wag that says, um, you know, it's one thing to be wrong, it's another thing to be wrong at scale. Yeah. Um, With this AI approach, we're seeing multiple LLMs and hec, there's even now small language models in the mix, and then there's all these AI agents and they're all interacting with each other alongside of humans.
So how do I keep track of whether or not something is actually performing as intended, or, um, is that just kind of, I have to wait for somebody to kind of discover it and send me a nasty note or something? Yeah, and I, I, I think, so that's, that's a fantastic question, right? Um, how do I know if the model or the AI system the product is, is performing as it's intended?
And I think the key part of that sentence is as intended, well, what does it mean to be, uh, to what, what, what are you, what's the intention behind deploying this AI system? What is the user going to extract the most value for really defining your use case? And what does success look like?
Right? And that's actually gonna be customized for each different organization, how they view success, right? How they view is this AI system being used for its intended purposes.
Um, and so like this, I think this kind of goes back to that benchmarking or evaluation type of question, is each enterprise actually has a custom kind of definition of what they view as success for their use case, right? Maybe you want to, you're in a highly regulated sector and you wanna be really careful about the types of questions that you answer. You wanna make sure you answer it in a very compliant way.
We have a, a customer, for example, that defines a very unique term in the financial services sector, a certain way that the model doesn't actually refer to it in that correct context, that's considered a hallucination, or that's considered a failure mode, right? But that's really specific to that particular customer. Or maybe you're generat generating reports and it has to follow a certain style or include certain set of references, uh, uh, et cetera, right?
That's the key thing, is to define what is your, what is success? And then build in very robust and repeatable testing for you to monitor. Is the model being able to, to, or the AI system able to meet that, that definition of success?
And a key thing here is we do see it today across, you know, solutions, uh, not a lot of capabilities that are provided to the end users, the enterprises, for them to actually define success according to the very, very specific requirements. You'll see, you know, when the, the newest, uh, foundation model comes out, people are constantly benchmarking it on coding tasks on multiple choice faster, they're giving at the lsat, et cetera. But is this actually relevant to the intended use of your particular use case, right?
Maybe it's really good at, um, ACEing the lsat, but maybe it's really poor at debugging your code, right? Uh, or, or generating your particular, you know, uh, transforming cobalt code to, to, to python code, right? Um, so, so you wanna make sure that whatever you're evaluating, you're, you're, you're explaining what is the intended behavior of the system and measuring against that.
One of the challenges that I hear about is that, well, the gen AI is probabilistic in nature, and it doesn't always do the same thing the same way every time. And a lot of the business processes that we're kind of trying to apply it to are, shall we say, deterministic, and people expect them to be done the same way every time. Um, so where do we kind of figure out it makes the most sense to apply a gen AI model to what kinds of tasks that are actually gonna, um, augment a process rather than, I don't know, break it?
Yeah. So, so there's certain parameters that you can play around with to try to get more deterministic about this. You know, there's determinism, there's also explainability.
These models may never really ever become truly explainable, uh, to the level that, that people hope they, they would be, right? Um, because if you can truly explain it, maybe you can have a more deterministic model, but let's take the determinism kind of point, um, so you can, you know, adjust the temperature to, to adjust for your particular use cases. In some cases, you're gonna want the more creative model, and those are the applications personally that I'm really, really excited about, is like, if you prompt the model multiple times, it's actually gonna give you new ideas of potential ways of reframing the problem, right?
And it's gonna be more creative and expand our creativity. I think generative AI has enormous opportunities in that space, but then generative AI also has opportunities in spaces where there's highly repeatable tasks, and you just need to get it right and have the right formula for how you do this. And that formula could be pretty dynamic, and, you know, it may be rule based, it, it may be more com complicated, but you wanna have that repeatability, uh, and, and robustness built into your system.
And so there's kind of a, a number of things that you want to do if that's the case. If, if you want to have a more deterministic and robust model, A, you can adjust the parameters of your model and make sure you have greater control over the setup of your AI system. You can't always do this with, with every model, with every AI system, but you also wanna have, again, those constant checks and controls, right?
So if some folks call this guardrails, uh, that's, that's what we refer them to, but you wanna be able to constantly monitor the AI system. And this monitoring can become really challenging as you go and scale, as you have, you know, in some many cases, we have customers with millions of queries every single day that their system's being hit with. So you need to build an automation to automatically check the behavior of the AI system and flag.
If, say, you have ingen workflow, that's kind of going outta control. Uh, the, the agents are, are kind of, you know, spiraling outta control. You want to be able to flag that type of event and have a, a human review.
But you need to do this really, really efficiently because these, these AI systems today are scaling to huge, huge, huge workloads in volumes. And so you need to have a system that's gonna automatically flag when, when things are going awry and things are not going as you expected, right? That, that non-determinism is really showing, uh, its space.
And, and you want to be able to efficiently triage that and have it reviewed by humans When, uh, you can't manage or govern that, which you cannot see. So how do I get the observability level that's required? I mean, we have observability in DevOps types of workflows, but I'm not sure we have observability around MLOps and these AI deployment models yet, or is that kind of where we're headed?
Yeah, uh, definitely I, that, that, that's where we're headed, right? And so, um, you know, it's a little easier for these homegrown solutions that are building off of, say, you know, the, the standard list of foundation models. Um, and they're kind of composing their own vector database together and, and, and building this from scratch, right?
It's a little more challenging to implement the observability. Now when you have all your different vendor applications that you're using for, let's say, like, you know, SaaS applications or your document processor, et cetera, that are now integrating AI features into those products, right? So I think your CRM think about your, your, your document processor, um, you know, even your, your, your browser, et cetera, might all have AI capabilities built into it now, right?
And that becomes much more difficult to extend observability. And, you know, we talk to CISO all day every day, and their big concern is they don't wanna look at 30 different dashboards across different applications and try to hunt out for where there's, uh, basically shadow ai, uh, being implemented across the organization and, and vendor solutions that updated with a new copilot in their last patch release, right? So what we've actually, uh, found to be really effective is actually a lot of these solutions, these vendor solutions are being operated to the browser.
Um, we personally built a browser application so that you can go and plug in, uh, your guardrails and your observability across all these different vendor solutions and then have a single pane of blast to view this. So this is something that, you know, we realized was a problem. Uh, uh, many of, uh, of the folks that we talked to, uh, were, were very worried that they were not having control over those vendor solutions that they were bringing in house, but they wanted to see all the LM inferences that were going through there.
If there was a user that was violating their, their company policies, but they were using a CRMs copilot, um, they want to have that visibility into that application as well. To your point, we've always had trouble trying to manage all the dependencies that exist within our existing software. Is that about to become exponentially more challenging in this AI era?
I think there's definitely going to be, uh, additional dependencies that, that you have to look out for, right? Um, there's a lot of creative approaches that are, um, are coming out today. Uh, so, you know, one of our, our partners that's just, uh, a notebook, OEM, uh, you know, launching, uh, different capabilities that can embed a lot of these actually out of box on your laptop device, uh, and, and have kind of actually, uh, an, an agent that goes and, and scans through, uh, the LM interactions and makes sure that, that they're being guardrail and observed, right?
Um, so there's, there's different creative ways, uh, actually leveraging AI to, to make it more scalable to do this type of work. But certainly, I, uh, you know, uh, I'd be remiss to say that, that there is a new ecosystem of, uh, kind of products and components that are coming together that enterprises need to be prepared for, uh, and, and integrate them together, right? They really, I think when the, the key things here is the more that we can get the enterprise to, uh, or, or build a product rather, or a solution for enterprises to have a single pane of glass, uh, across all the applications for managing governance, for managing observability, the better these enterprise is gonna be.
Uh, but you do see, you know, um, different kind of platforms emerge around different hyperscalers, et cetera, uh, that they're integrating a lot of these opportunities, uh, but it's hard to bridge this across cloud environments as well in a kind of multi-cloud strategy. And so you want something that, that can kind of, um, uh, uh, reach out to all these different components and, and kind of integrate them into a single place. So will we eventually wind up creating AI models and AI agents to govern AI models?
And we're gonna rely a little bit on AI to manage the ai? Is that where this might wind up? I believe there's gonna be a big component of that, right?
And especially for regulated industries, there's always going to have to be human in the loop with this, right? Um, and, and this sounds like a new idea, but actually, if you look at some of these really heavily regulated industries like financial services, they've actually to some extent been doing this for, for quite some time. You'll look at anti-money laundering, uh, su suspicious activity reports, right?
Or in the fraud space, there's a first wave of automation that comes in here that goes and tries to find the suspicious activity and then flag that suspicious activity for a human in the loop to review, right? Uh, and, and it's all about how good your automation is, how trustworthy your automation is, and you do have to continuously evaluate whatever tools are, are being used as at that, at that automation layer. Um, uh, frequently people call this, uh, space, you know, uh, LLM as a judge.
So, you know, LLM judging the outputs of another large language model, right? And, and potentially correcting those outputs or flagging or non-compliance or failure modes for hallucinations, et cetera. And that is a necessary component, I believe, for this to scale, uh, practically, right?
But you do need to build people, people shouldn't forget, I think too many companies, frankly, forget about the second component here, which is building the workflow for the human in the loop to do the forensic analysis they need on top of all that enriched metadata that the LLM judge is jar. 'cause at the end of the day, that LLM judge shouldn't be the final say. It should be really enriching the metadata and distilling down the problems for the human loop, right?
Um, and, and, um, so that, that's, that's really how, how we see this kind of rollout. And again, a lot of the folks that we work with the enterprise is they're hitting massive production scale today, uh, with hundreds of billions of tokens every year, right? So having a, a team of human reviewers go in and, and monitor these, these lms, uh, just simply is, is never going to fly.
You do need to use the power of lms, the, the scale, this kind of observability, uh, and what we call case management, but you also need to build the infrastructure to effectively manage those cases, right? And generate cases gonna be useful and relevant to, uh, the, the subject matter expert or the cybersecurity professional who will be doing the, the further investigation. So what's the one thing you see organizations doing that, you know, still makes you shake your head a little bit and go, folks, we need to be a little smarter than that.
Well, I, I think, um, most enterprises that we talk to today are, um, still very much at trying to figure out their overall governance, like how they're gonna set up, uh, uh, the, the, the governing structure for a o And this might include, um, you know, what is the role of the ciso? What is the role of, uh, model risk management? What is the role of the product owners and the business line owners, and the CIO, the generat AI platform owners, right?
We see a lot of debate across the board. Uh, you know, I wouldn't say there's a, a one size fit all solution, uh, to, to, to solving this. But we see a lot of debate across enterprises that, that we talked to about how to properly set this up, which stakeholders should be in charge of monitoring, or let's say, let's say, of, uh, of, of implementing a defining guardrail.
Should it be legal? Should it be cyber? Should it be compliance?
Should it be the product owners? Should it be a mix of all those, right? And what we find is that those organizations that kind of speed ahead without figuring out this governance structure, ultimately run into bottlenecks down the road, right?
They ultimately will have a showstopper where they're like, we don't know. It's not a, uh, that this problem can't be technically solved. Let's say there's, um, certain level.
Uh, but let's say that, you know, uh, certain, uh, uh, stakeholders within an organization are not comfortable with productionizing a use case yet until there's more controls. Well, who, who's responsible for building those controls? Is it the product owner or is the, the CISO who's supposed to be recommending those controls?
The more that organizations can understand how to set up their governing structure and which stakeholders are responsible for these roles, and, and build really a robust process for productionizing these solutions, the better these enterprises are gonna be down the line. I think there's just a ton of work, not only on that, the technical side, but, but just on the organizational side, uh, that, that, uh, enterprises are still working through Folks, you here, human in the loop. It's not just some sort of buzzword that we use to pacify people.
It's actually the difference between success and failure. Hey, Christian, thanks for being on the show. Thanks so much.
Great to be here. And thank you all for watching the latest episode of techstrong ai. When you can find this in other episodes on our website, we invite you to check them all out.
Until then, we'll see you next time. Hey, everyone, I'm Alan Shimel of Text Drug tv, and welcome to another episode of the Last Great Cloud Transformation. You know, uh, we've been doing this show for months now, and we hope you've caught some of the previous episodes, but if you're not clear on what it is we do here, you know, we we're seeing, we call it the last great cloud transformation, but what we're really referring to is that this next wave of cloud migration, if we could call it that, is a little different than what we've seen before for the last almost 20 years, 18 years, something like that.
For many people, cloud migration meant moving from a private data center, whether it was a private cloud or, or just a, you know, posted in a private data center up to one of the public clouds, the hyperscale, cloud hyperscale, you know, provider clouds. And, and a lot of times it was just a shift in lift from, from private to public. Other times there was some transformation, maybe moving to a cloud native microservice architecture or something like that.
Um, but what we've seen over the last three years, five years, may, let's say, since covid types, right, is a migration not only from the private data center to the hyperscaler public cloud, but from there to the edge, from the edge to the endpoint, in some cases from the public hyperscaler cloud, back to the private data data center, or private cloud running things like Kubernetes on bare metal and, and so forth, right? And so, really, our cloud infrastructure is everywhere. And so in many ways, this latest wave is the last great cloud transformation.
Our partner for this show is our friend, our friends at CloudFlare Cloud, CloudFlare, which look, I think 22% or something like that of the internet travels over its network, right? CloudFlare has come up with a solution, a, a aid in this last great cloud transformation, and they call it the connectivity cloud, because what they have found is, look, when you have a little bit of something everywhere, right? You get some assets in the public cloud, I'm in the private cloud, some on the edge, some exist on endpoints.
Everywhere you need something that connects all of them. And, and in connecting all of them, you're dealing with several key issues, latency, security, huge, right? And some sort of intelligence, I'm not going to use the AI word per se, but some sort of intelligence that knows where to go when and what to put, what where, right?
Does this is, is the edge the, the right place for this? Is the core the right place for it? Is the private this, should this be on a, an endpoint?
So that's what we're talking about when we talk about the last great cloud transformation. I hope that makes sense to you. Let me, um, introduce you to our panel today as we're gonna discuss just a, a small slice of this.
We're gonna focus in on securing the API economy within the context of this last great cloud transformation. Joining me today, first of all, from CloudFlare. I went through all that time.
I hope I get his name right. Cy Saikrishna Chavali. Am I close?
Very close. I'm s Krishna Chaley. Thank you Alan for the introduction.
Uh, product marketing at CloudFlare, been in the security space for a decade now. I actually, uh, started off in application security and now back to the API and application economy. So excited to talk to all of you.
Absolutely. And Cy Christner, it's great to have you on here. Joining Cy Krishna and myself, though is my co-host of the last great cloud transformation.
Uh, him and I co-host a whole bunch of things and we like to do things together for a long time now, he is a, uh, futur VP for DevOps analyst, Mitch Ashley. Hey, Mitchell. How are you man?
Good to be there. And I'm glad I'm buttoned down in my cold little bunker here in Colorado. I'm getting some snow this week in cold weather, so you all might see a little bit later on East Coast, so hang in there.
Absolutely. Alright, let's, um, let's turn to the issue at hand, gentlemen, right. Securing the API economy, before we talk about securing the API economy, I think that we probably need to define what we mean by the API economy, Right?
Yep. And you know, it's a term that's, I've seen the term used probably for 10 years already, right? Eight years.
And, and really what it is, is so much turns so much of our economy, so much of our e-commerce, so much of our online digital presence turns on API to API communication, right? In fact, uh, I'm actually doing an interview with Grant, is it Baz? Bazookas Berser, yeah.
From CloudFlare, uh, on this, and I've done in the past with him on this, a majority of all the traffic on the internet today is actually API to API traffic. It's a majority of all the traffic on the internet. So when we talk about the API economy, we're talking about a majority of every bit that gets pushed over the internet.
So, I mean, that's, that's the scale of this thing, but peeling that off, what do we, you know, what is this API to API traffic? So, Krishna Mitchell, do you want to expand on that? Sure, sure.
So actually, I, I wanna do a quick overview of, uh, APIs itself, because I think the API economy is a, um, maturation of how we have been using APIs. Uh, and one of the things that APIs compared to web AppSec or mobile AppSec, you're touching them every day. You're using them as a consumer, even as a, a business user, et cetera.
But APIs, you don't think about that happen behind the scenes, and they're meant to be behind the scenes. The, the value of APIs is that they can enable one system to talk to another system, exchange data, and do that in an automated fashion. And so all the automation that we talk about in the world out there is happening via APIs that are between applications, whether they are APIs in the, you know, software defined JSON format, or whether they're in older school formats, or whether they're specific to an industry.
It actually, when you think about APIs, they've always existed inside of applications not to the, to the public world, um, when there were service buses. But since then, and especially when we think about the first big push with mobile phones and mobile AppSec, especially the, when Steve Jobs talked about the App store, um, and then Google, Android store, et cetera, the Play Store, what it meant was all of those AppSec were being run behind the scenes via APIs. So mo the mobile economy provided a huge boost to APIs.
Second, we saw that, um, the social and e-commerce space became a huge area whereby when you're just a very active uploading fo photos from your phone to the cloud, um, to back it up or put it on Instagram, et cetera, was all via APIs. And so that provided another second boost, uh, with the consumers coming in to play. And then what we are seeing in today's world, you know, uh, organizations trying to reimagine how their applications are built, uh, as you talked about Alan, with the re-architecting of applications, that was that microservices element behind the scenes to make sure they break down their applications, to talk to each other and talk each service talking to each other using APIs.
And the, the fourth one that we are living in today, that everybody is familiar with, generative ai, I know you didn't want to use that word, but I brought it in. Um, It is being run while a lot of us are using it via web AppSec, behind the scenes. It is all being run via APIs.
And that is how this API economy is continuing to explode, um, whereby organizations are now making money just like open ais and the other AI models, um, making money based on how much their API is being used and being integrated into other systems. So when you talk about the API economy, it has many tentacles, and it is continuing to grow, uh, in importance. You know, like Krishna, uh, excellent, uh, description, I think of how the match oration of AI have taken place.
So I'll just, I'll just add to what you said and, uh, kind of build from it. One is, as APIs have gone from sort of the exception to being the rule, the exception was those are the few things we exposed to other applications outside the organization, outside the firewall. Um, maybe you mentioned message bus, but boy, I had a, I had a flashback there for a moment, going back to so architectures and things.
Um, but, um, but it's evolved even even beyond that to the point where we now think of, uh, AI IS products. Many services on the net only are offered via API, that that's how you use it. You consume it, you might stick a front end to it, a web interface or a mobile phone, but, uh, the service may be only API.
So you think about that as your storefront for your service is other pieces of code talking to your services through APIs. Another, another aspect that's changed, which is kinda how it's manifest, which you talk about in that, that fourth wave is, is what's called API first, where essentially applications are built around the fact that everything is an API, and it will all talk to each, each component, whether it's the user interface or some backend service, front end microservice, whatever it is, everything will talk via APIs. And what's interesting about that from a networking perspective is, you know, sometimes software and software architecture is a bit of a head scratcher for a network security person, or maybe even a network person that's really a network inside the application that's talking to itself over T-C-P-I-P, whatever we're using, whatever GraphQL or restful interfaces, fancy words for different kinds of APIs.
Um, so it's, it's, we've really gone from it being the exception to being how everything works. And that's the, that's why you see all this traffic, whether it's over the internet and the cloud providers or inside your own networks. That's why it's all happening over APIs.
Agreed. I'm sorry, um, Mitch, because when we talk about that last great, uh, cloud transformation, it's again, back to the fact that the, at the app layer, you're exposing all of these APIs, but coordinating them, mm-hmm. Retaining them, making sure the performance is optimal, is all part of the cloud transformation that is so critical, even before you get security and obviously security is a critical portion.
Good point. Very good point. Yeah.
I want to turn to security and specifically around securing all this, but before we do, you know, so Krishna, you opened up the, the, the, the Pandora's box with the AI stuff we warned yet, right? It's gonna happen at some point in every cover. Yeah, yeah.
So look, this, this, this is a whole different ballgame, quite frankly right now, especially with the onset of, of agentic ai, right? Who do you think these, all of these AI agents are gonna be talking to people? No, they're gonna talk to APIs.
So if we think that a majority of the internet traffic now is API to API, how much of it is gonna be a agentic AI to API? Some may say that really what is, you know, a good chunk of the very essence of what an AI agent is, is some sort of AI bridge, API bridge, right? It, it it's an API that lets you plug into everything or that plugs into other things.
So I think, you know, we're just at the beginning of the API economy and, and how much of it, or how much of the total digital world is gonna be riding on that, right? But let's, as I said, let's turn to security. Well, before you do, just wanna mention this.
Go ahead. This is so pervasive that my granddaughter told me she wants to dress up as an API for her Halloween costume this year. That's how pervasive this is.
Really? I'm kidding. Of course.
Oh, okay. You she's wired. Dude, I'm just security, not just security though.
So look, if something's this important, you know, it's the law of why we can't have nice things, it becomes a target. There's a bull bullseye on its back, so to speak, right? Of, of how can that be disruptive?
How can you know, how can it be disrupted? Excuse me. How can people exploit it, hack it, make something out of it?
And therein lies the problem. Therein lies the issue, right? How do we, how do we secure this gigantic monster of API to API or API to agent communication?
So, Christian, I know CloudFlare, I mean, you guys have put a lot of resources into this very issue. Let, let's talk about some of the things, you know, some of the ways and things that you guys have come up with. Yeah.
So we've done a bit of research into what are we seeing in terms of threats. So, we'll, we break this down into what are the threats we are seeing live, and then what are the problems around API security to do API security well in an organization. Um, so in terms of threats, let's just kind of break it down.
The, the actually most common threat that you see on, in, uh, kind of real time traffic is business logic or DD distributed Nile of service attacks that are just hitting their APIs to try and either exhaust resources or to try and get into a service and then figure out what is a, what is behind that service at the end of the day, you know, an API is mostly a communication mechanism, and therefore they're trying to figure out what is that API talking to in the backend. Um, and that's something that we are seeing a lot of constant traffic, uh, around that. Beyond that, when we think about actual data breaches, what's unfortunately very clear is that we hadn't fully thought through what needs to be behind a authentication mechanism.
And then, you know, we're still, we're still trying to figure out what is the authorization mechanisms and methods that we go through. But even authentication, putting basic authentication is not something that was, uh, has been very common, and therefore we have seen a lot of public major data, uh, breaches that have an API that's just openly accessible. So that's the second part.
Now on that, when you're talking about leakage, you're essentially leaking data. And the most important, uh, types of data that what we are seeing is attackers using that to do reconnaissance, to then use that in other attacks that are a bit more targeted in nature, um, because they found all these public APIs just spewing a lot and lot of data, um, that can be used in other places. So it may not be necessarily sensitive on its own, but it's a piece in the larger, uh, targeted attacks that we are seeing.
And then lastly, what we also see is just like with, uh, applications, APIs at the end of the day are also code. And so they can be vulnerabilities in that zero day attacks that we zero day exploits that we are seeing, just like with applications that can happen with APIs as well. Just because an API does not have a front end does not mean that it will not have the, the code level vulnerabilities, um, given they may be written similar languages to, um, the, the, uh, web application, uh, code that is, or the, uh, the, um, code behind the web applications, uh, that we all use.
And so being able to protect against that helps you protect against, as we think about, as Mitch has talked about the economy and Alan talking about how the economy will continue to grow, so will fraud, and we're gonna see fraudsters trying to go after the APIs to get access to money, to get access to, um, credentials, et cetera. And so that's the next area that we're, we're really seeing growth in, unfortunately. Yeah.
Mitch, thoughts? You know, I was just thinking about, um, not to bring AI back into the conversation, there's a lot of discussion about how did deep seek train its models, and it's done through something called reinforcement learning. And of course, um, the other aspect of it was as trained on OpenAI's models or other people's models kind of ing models, control models, that that's a great example of where automation comes in, where something you couldn't do on a large scale through any other way other than through automated API calls, uh, into applications or models or whatever it might be.
So it's, it'd probably be shocking to, to just the average user or maybe us that has a little more technical background of how much of what's happening inside an app or looks like it's inside an app, is actually taring through API calls, and how our AppSec wouldn't function at all without it. I mean, some of 'em wouldn't even start up, right. Couldn't present a user interface to you.
So I'm, I'm curious, uh, aside, Krishna, as, as you think about from a cloud perspective, when so much of the traffic is APIs rather than, you know, HTB calls over web browsers and, and email types of things, protocols, you know, the old, the old internet protocols, right? That, that built the internet. Uh, how, how does that make you think about the cloud differently?
Especially because customers like myself, we are a customer of CloudFlare, by the way, um, wanna put parts of our AppSec in the cloud, not only at at the Edge, but also in multiple places across your cloud instead of us trying to figure out how to deploy it to some point past the cloud? Yeah, I think this gets to some of the, uh, big problems with trying to secure your APIs. So there is two parts to this broadly.
One is, at the end of the day, APIs are written as code, just like web applications are. And there is a portion of it, which is the typical vulnerabilities that, um, the laws for open web application security, uh, project has, uh, kind of outlined as the top 10, uh, kind of risks are very similar between web applications and, um, APIs. So being able to protect against those so that they don't even reach your API servers, um, wherever they may be, is going to be super critical.
The second is making sure that when you are, when you are looking at, uh, APIs unique part about APIs is they should have some sort of authentication and authorization on them, and exceptions should be those that are unauthenticated, that should be the exception. Whereas with the web applications, a vast majority of the traffic maybe are not authenticated because they're just looking at, um, and reading data. But with, with, um, with APIs, that should be an exception.
And so being able to put that in place and then be able to enforce it function that developers don't have to come up with it, come up with the authentication mechanism every single time they're creating a new API, which, which is just so very common in organization, which, which just as an aside, that forces developers to become security experts. And while we want developers to know something about security, security expertise is not gonna be the first thing on their plate. Um, and therefore being able to standardize that and push that to, to the edge is gonna be so very critical.
Um, on, on the authentication side, and the last part is, as a security team, you're constantly thinking about governance. What is happening in, in my estate of APIs, applications, other assets that might be there, what are, how are they being configured? Because once you have, you know, coded an application or an API and then you have, um, put it into a release cycle and it's out there, there're gonna be multiple ways that it's being deployed, run, configured for different, uh, use cases.
And so all of those can have misconfigurations. And we see that all the time today. In fact, one of the things that we see is the, uh, problem of APIs leaking sensitive data because once they, when they were first, um, released, they were very pristine, well done over time.
You keep adding a bit of fun functionality and over time that leads to things where just for that one use case, you will, you are, uh, uh, you know, able to kind of expose a bit of data, but now in another context, it is leaking sensitive data. So, um, that is something that you need to be able to constantly be able to monitor and where appropriate without having to burden the development teams be able to put in place, uh, protections in real time at the edge so that, again, there's much less burden on developers and those that malicious traffic is not reaching your, um, your, your, um, a i servers themselves. And the way that connectivity cloud really helps in this context is to make sure that all of those protections, you don't have to put them in place at each of your data centers on each of your APIs separately.
You can push, you know, rules into a, uh, common engine and then make sure that they're propagated at all locations that you are, that you are serving, uh, from which you're serving your applications on, in what we call an edge or a connectivity cloud edge. Excellent. Excellent.
You know, Mitch, I, I was listening to what you said and then what, say Krishna came with, I, I think one of the things I said earlier really is, I mean, it complicates thing, but it's so true of what, what, what applications look like today, right? Our applications are dispersed, they're microservice based applications, and you know, when people think of APIs, they may think of, I'm a user of an application and I, and that's the A PII interface with that internal to external or external to internal, if you will. But in the microservice cloud native kind of world that we live in now, right?
Something like 70% of Greenfield applications are built in a cloud native, uh, architecture, much more than that. External to internal. API is the internal to internal API, it's one container talking to another container.
It's one function of an application going out to a SaaS based API coming back in, talking to another piece of the internal, right? Internally an API to API thing. As you know, our applications are sort of little Frankenstein's, if you will, right?
We're all stitched, they're all stitched together. And what's, and what is the thread? What is those stitches?
It's, it's APIs. And so I, I'm going to guess that there's probably four x five x internal API calls for every internal or external API call. And they have their own security requirements.
And that's, those security requirements have to be orchestrated, governed. What have you managed, you know, whether it's at that COBE level, the orchestrator level, or the mesh level, right. Of how these things are, are talking to each other.
But that's a, you know, and, and they're all, you know, let me add one more little complicator in there. They're all over the place. They're in the edge.
They're in the core, they're in the data center, they're on the endpoint. Mm-hmm. It's enough to make you go crazy, right?
Because that, now that's a job. Right? If you could secure all that, that's a job.
I don't know if it's a good analogy, but it, it's kinda like an air traffic control system of multiple wind. Yeah. Really, it's right.
Whether, whether you're international travel, continental, you know, local, et cetera. It's 3D 360 degrees, right? Right.
You mentioned cobe, Kubernetes, you know, and then the cluster has an API gateway and it does security for APIs. What can talk to what within that and other, other Kubernetes clusters. And of course things go outside of that.
And then service providers have API gateways and firewalls and things that control, uh, both security and authentication, uh, as well as traffic of those APIs. So it, it is, it's, it's kind of a cellular system almost, if you want to think of it that way, of multiple layers of, uh, how APIs work. And, and the good thing is the APIs give you a lot of autonomy in code and in design.
'cause I can create a, a microservice that just specialize in pulling data from Salesforce because I need these customer records for my application to process an order or to go get, uh, background information from, you know, say a science database that's got, uh, medical information in what I'm gonna include in some deliverable to a end user, some product I'm producing, but that can be specialized. So it lets us build autonomous pieces of code, not, maybe it's a tic AI agents at some point, not too far down the road that can go do, do its thing and not worry about the rest of the world of all the software and the APIs happening. It also lets developers go, eh, nail.
Okay, I, I know, I know where those API calls happen, or I know how to trace it down using observability tools and things like that around tracing. Um, but it, it, it's a different world. It's a very different world than the days of I will talk over a solo bus, um, or a monolith application.
Um, but it's like everything, it's just a different mindset. Has advantages, brings with it other challenges and, but the advantages outweigh the negatives. And I think, Mitch, you, you mentioned, um, something around, uh, agenda AI agents, but that touches back to Alan's point, which is, you know, Alan, you were talking about there'll be one, um, a one API call between the, or many fewer API calls between external and internal boundaries.
Uh, and then there'll be a lot on the internal side. Totally agree on the internal side, but the unique part now is there is an even more blurring with gentech AI agents of what is internal and external when you are calling AI models to do things as a step in your application. And so you are, uh, a service may actually be calling, not the application, the application that everybody's touching, but a service that is trying to do some data analysis, trying to pull the latest information so that it can be passed to a user may actually just call on its own an AI model of, of some sort that has to do some data analysis and then be brought back to the application.
And now what is happening is when in the old world you had an understanding of, okay, here are things that are exposed to the internet, everything that the developers are doing behind the scenes, I, I don't really have to really care about that. Now you need to be thinking about all of those services as well, because those could be exposed. And when you are talking to another, um, AI models that are open source, you know, by third party commercial one, or whether it is sitting in some other location that you, you own, you are building your own, um, it just makes the, that world of API traffic even more complicated.
And one of the things that we are finding is, um, in the past, even just pre pre covid, think the pre covid days when APIs were still, uh, quite common, um, not as common as today. One of the thing, one of the things that customers struggled with was identifying what are all the APIs that my organizations have exposed? Because the security team is not everywhere.
And talking to every development team, now this problem has multiplied. Now it is not just what are the APIs, but developers, what are the AI models you're using? 'cause almost always those are being discussed or, or that's being communicated with through APIs.
And we need to think about what is the data not just coming out of the API, but what is the data I'm putting into the, uh, into the API that is going into an AI model, whether it could be PO for poisoning purposes or leaking your organization's sensitive information. So I think those two things, especially with the world of agent AI, have become a lot more critical, uh, for organizations to deal with. That is the cutting edge of what we think of API security today.
You know, there's another dimension to this too, and that is, um, what, what goes hand in hand with API first software architecture is also stateless, which means, you know, we used to make calls, meaning I open a connection to this, whatever it is, on the other side, I do things across, you know, whatever that connection, the socket or whatever it was back then. Um, and then close the connection. It's kind of the difference between TP and UDP, right?
You know, am I doing that connection or open I close, or am I just sending it and it will happen? That's a lot of how software in order to scale and, and have that independence of microservices or whatever that function is that is providing or requesting the service, that's a lot of what scales this up. So that also increases not only the security, but also the manageability of those applications, because I can't take, like, freeze point time of the state of the machine and I can go see where everything is at.
No. You know, that that same process that requested that might have been updated two minutes ago, or might have scaled from one to 53 instances of that microservice across the network that's distributed. So that's why we're able to get such high performance out of systems because we can distribute 'em through that stateless architecture as well as APIs and networks.
I, I think that, I just wanna mention one thing on that, on the stateless point, because it's so very critical in, and it, it applies to cybersecurity in the sense that the CIA triad one part, one leg of that stool is availability and the importance of a stateless architecture, um, that can be ideally based, uh, edge, uh, you know, post out to the edge. Um, especially some things that are, can be provided by a connectivity cloud enable cold starts to be diminished because you be waiting, when you're thinking about being very dynamic providing data, and this is of data we're talking about, especially with AI models and AI agents, that difference between a bit of latency is very significant to the user, uh, at the end of the day. And so, minimizing cold starts, that is something that, you know, only in a, a provider and a that has been thinking about stateless architecture at the edge can, can really provide.
Um, and that's something that we have definitely been, uh, seeing with a lot of customers, um, that they need, that those cold starts to be reduced so that whenever they call a function and it is un up, the instances un up, they're ready to take, uh, workloads. You had to mention cold starts. It was 11 degrees when I woke up here this morning.
So thanks for that reminder there. So, Christian. Alright.
All right guys, we're about outta time. So Krishna, for people wanting to get more information about connectivity Cloud, securing their APIs and so forth on CloudFlare, where, where's the best place for them to go? com has very in-depth technical analysis on the latest cybersecurity threats and API performance and security conversations.
Thank you. Sorry, Krishna, thank you for coming on here today. What a great conversation, Ben Mitchell.
Good work. I, I enjoyed, I learned a little too, which is always a good thing. It's gonna wrap up though, this episode of the last Great Cloud transformation.
Stay tuned. I think our next one might be a live round table again. So if you watching this, you enjoyed it, you want to be involved in the next one, it's live.
You could come in and chat your questions and comments and we will incorporate those into the show. But until then, on behalf of CloudFlare Text Strong Mitch Ashley, Cy Krishna, help me, Val, Val Shival. I always think give it a little French there at the end, Val and myself, I hope you've enjoyed this episode.
Take care. We're out. This is Textron tv.
Hello and welcome everyone. This is Infrastructure Matters, episodes 72. Uh, and I'm joined by my partners in crime, um, at FU with, um, uh, Keith Townsend and, uh, Camberley Bates.
Um, and, uh, it's, uh, been, uh, it, it kind of an offbeat week for, for news. Um, and so let's, let's dive right into it. Uh, uh, who wants to kick off with, uh, Lenovo earnings?
Sure, I will. I just went through their earnings, came through yesterday. Um, they're doing well.
They're, um, both the PC business and the, um, like the ISG, which is the server storage business, et cetera, has done well. Um, they, um, I'll focus on the ISG overall. They're up 20% in the revenue, so they're hitting all their numbers and expecting things to continue to go very well, which I think is positive for everybody.
The ISG business is the stuff, is the area that has the server and the storage. Um, they highlighted the growth with the CSP and the SMB market. Um, they're up year to year, 60% in their group, which is significant.
It seems to be most of that is coming through their OEM business where they're customizing the server business for the, uh, CSPs. Um, they didn't go much into the details about how that is going. They have a new, um, SVP or EVP running that division.
Um, Ashley and I am not gonna try his name because it's like, it's like this long Ashley g he comes from, I should know how to pronounce it by now, but he comes from a long time ago he was with, um, Dell, and then most recently he was with IWDC, Western Digital, um, on their HT D side, and he joined them this last fall. So I think that they're kind of being quiet about what you know is going exactly is going on, and that's, and this server business, et cetera, other than it is growing, it is break even though. So they need to get to a profitable business.
Um, and so the strategy is being developed, but they're gonna continue to hammer into the profitability of develop the profitability on the OEM business. So all good, all good. Um, news for our industry, um, continuing to grow and, um, and healthy.
So that's, that's what I was looking for, is how, how healthy is this business? Yeah, I know. It's, it, um, it's interesting to see.
So, um, on my end, I saw how, uh, I, I saw, uh, Nvidia and ARC Institute re-released a new AI model called EVO two. Um, and it's a biology model. So this is, we're we're seeing a lot more, uh, uh, you know, directed a AI models, uh, focused on areas like STEM and like, uh, AI models, really good at certain things like coding, uh, which was kind of unexpected.
3 trillion DNA base pairs. And this allows you to ask almost any question that you could possibly imagine, uh, having to do with genetics or biology. But what's interesting is that it can generate genomes.
So it's not just, you can, you know, ask it about, you know, uh, you know, how does this, uh, organism work or how does that organism work? But it, it can technically, uh, create the entire sequence for new organisms or, or, or, you know, new, uh, you know, uh, how to repair a certain cell or, uh, fix a certain disease. I mean, it's incredibly powerful.
So it's got a lot of attention because it's the largest biology model yet created, uh, by alar, by a large margin. Uh, it's, you know, it's effectively the, uh, the chat GPT of biology. And this is, um, highlighting something we saw with alpha fold.
Alpha fold is Google's model for coming up with new molecules, specifically new drug molecules. And that model is generated more, um, novel treatments and novel drugs than we can currently test. Uh, it, it, uh, has a, I believe it has 60% accuracy rate and, and creating a, a new molecule that will address a specific situation.
Uh, and the, uh, this is what you're highlighting, something that I, I think a lot of us didn't expect with ai, which is, uh, these models are creating, um, uh, they're actually, uh, evolved in new knowledge discovery, scientific discovery. They're creating new things, uh, discovering, um, new substances and new treatments, um, faster than we can actually process them by, you know, by, uh, you know, a hundred x. Uh, so, uh, EVO two got a lot of attention in the science industry that is, is taken, uh, very seriously by people in biology and genomics.
Uh, and it should be a, should be a breakthrough, but this is something we're, we're gonna see more and more is, um, the companies that have access and control of these models with the ones that'll be creating the innovations. And now our biggest challenge is how do we organize to, to take advantage of all of the scientific discoveries that will come out of these models, uh, a pretty exciting time. So this is a model that is not only a human biology, but it's all organism.
Yes. It's been every that everybody, it's like type GBT was fed every, every scrap of a text and every book, and every magazine, every scientific re uh, page, uh, research paper, and every webpage ever created, this has been fed every genome that is known. So it, yeah, it's gonna be interesting to see how this helps downstream with drug formulation.
And more importantly, you end it to this Diane, like, how do we catch up to the technology from a, uh, from a, uh, regulation perspective? How do we test this stuff in the real world? You know, there's the theoretical and AI and these formulations, and then downstream, how do we literally make sure that, uh, these things do what they say and, and can get back that closed loop feedback to make the models even better?
That also gets into interesting, how do you do clinical trials then? Does clinical clinical trials end up changing? Is there areas that we can take this and do the predictive modeling about what that looks like and what the side effects are?
I mean, I think about the commercials that I have. You know, you, you've got the commercial about what it's gonna do for you, and then the other half of the commercial is what it's gonna do to you. And, uh, so that, that makes it a very interesting, um, Yeah, well, we're not structured for it.
We're, we're, you know, we're, we're structured for an environment where we occasionally discover a novel new substance, and we, we wanna, you know, test it. Uh, and now we're gonna be overwhelmed by these types of things. We need to find a new way to curate and manage, uh, these types of, you know, I mean, it's an amazing, the, the potential is incredible.
I mean, it's gonna revolutionize human health and all sorts of other things, uh, but we don't know how to manage it, uh, and, and really take advantage of it. Uh, and what was interesting is, is that, you know, they came out with announced three new important drugs that were, uh, developed with including a cure for, for a new type of leukemia that was created by the model itself. So this isn't theoretical, it's actually happening.
And so it's, I mean, it's great. It's wonderful to watch. We just dunno how to manage technology that is so powerful.
Like, And that gets into that discussion. You know, we had at one time is talking about prompts, you know, learning how to do prompts, which is kind of, kind of sounds weird, but it's off often, you know, what is, you know, the questions that we ask or sometimes it's the question we forget to ask that are really super important to exploring ideas in areas. And that goes back to some, you know, really deep critical thinking, um, on our part as well.
Um, Yeah, and this goes back to, uh, you know, relating this back to the enterprise and enterprise it, one of the conversations I've been having with practitioners, I'm looking forward to a podcast interview I'm doing with Brian Lau of AWS next week, is how do you adopt things like AI application development? Like if you've ever done AI code or coding with AI looks very different than human code. So how do you adopt the governance around using AI code and how does that affect the downstream, yes, you're coding faster, but what you're, the output doesn't look anything like the, the original output of code and dealing with it and code management.
And it also impacts the human side of the equation of how do you get people to get consistent input. You know, that prompting that you're talking about Kimberly mm-hmm. How do we get that consistent input because the LLMs are not consistent in themselves and we get a deterministic output.
So, you know, there's a lot to learn from this breakthrough on how do we use some of the same discipline to apply this to enterprise it. Yeah, Absolutely. Yeah, exactly.
And so, uh, getting back to more traditional it, um, uh, HPE had some server news, uh, recently. Who wants to, who wants to tackle that one? Yeah, so if you follow server generation nomenclature, HPE is now in their 12th generation of their ProLiant server platform.
We were stuck on Gen 10 for quite some time. The TikTok was Gen 10, gen 10 plus Gen Lab and Gen 12. And what those previous models had in common was the reliance on Intel.
So this is kind of a proxy for where the industry is going. We're looking, we're wa we're still waiting on the sixth generation of Intel Zion and the server manufacturers, since the previous generation of servers are no longer waiting on Intel, this has all been driven by Nvidia, the ability to liquid. Cool.
Cool. These systems, gen 12 is much more focused on liquid cooling versus Gen 11. Uh, the support to cool these GPU resources and getting ahead of not just competitors, but Intel itself.
So is this a MD as well A MD as well? They're no longer, the TikTok X 86 is no longer driving the product schedules of the server, uh, of the two major server manufacturers, Dell and Intel. I mean, I'm sorry, I'll in tell the difference here.
So we used to think it's like we 10, 11, you know, 9, 10, 11. It was just the next generation of the Intel chips and then you some sort of design that's around there. So what's so different about when we go from 11 to 12, are we going to, is It 12?
Yeah. So it's all about the things we care about around GPUs, right? Power efficiency, how much, uh, CPI mean, how much power are the CPU components, the non GPU components using so that we can get the energy efficiency?
HPE is touting up to 41% better, uh, energy performance per watt. So when you're talking about, you know, the stinginess of a enterprise data center, uh, rack at around 15 kilowatts per rack, and these systems themselves can push up to 10 kilowatts that it matters. So then usually when we, we'd go in, I mean, my past life many, many years ago when I was working, you know, IBM or whatever, you know, your, your pitch as a salesperson was going in and saying you could get, you know, 30% more for the same amount of money, or 30% whatever, 30% more power for the same amount of money.
What is the pitch for the Gen 12? So it's going to be, I would imagine we we're going to, uh, go down to a special tech Field day event in a few weeks to get a deep dive on it. But I would imagine the story is about the things that enterprise data center managers care about, which is, how am I going to power and how am I going to cool these systems?
The I'm not retrofit fitted for liquid cooling. How do I get liquid cooling into these systems so that I can manage my heat, uh, uh, the, the heat that's coming out of these systems? I imagine that that's going to be much of the sales pitch of you.
You can't do ai, at least not big AI with previous generation systems, at least not as efficiently, as efficiently as these Gen 12 next generation systems. Well, I will be looking forward to that Tech field day. Yeah.
Well, I've been working with Proli since, uh, man, since the nineties. Is that, is that how long they've been out? Well, ironically, I have a friend that's doing a, a network assessment for a company for a piping company, not too far from you, Kimberly.
And he called me this week and said, Keith, you'll never believe this. I just saw a compact ProLiant server in production. And this is the irony, running Windows 95.
So that, that was hilarious. I'm like, this, this can't be true. You have to, you have to send me a picture, otherwise it never happened.
Yeah. The number of workloads still running on, um, windows 95 and xp, I just fell under 10%. But it's still, so we're surprisingly high.
It takes a, the, the, um, something has to break for it to, to move a workload off of a, an existing environment, right? So it's interesting. Uh, so Cisco had some earnings, um, and, uh, uh, can someone, uh, someone take us away on that one?
Yeah, so the interesting thing, revenue up to $14 billion, that's a 9% increase. And you think about a business the size of Cisco, this is unusual. So, di diving into the numbers, surprise, surprise driven by ai, Cisco is seeing, uh, orders, uh, for, uh, webscale systems or web scalers go from 350 million to 700 million.
That's a proxy for ai. They're, they're seeing more demand for ai. One of those companies you wouldn't expect to benefit as much from ai.
Cisco has lagged in their server design and refresh for their UCS platform. But I talked to a Cisco, uh, engineer, uh, uh, this is a few months ago, and he was telling me that they're able to justify an entire network refresh by the savings and efficiency for GPU to GPU communication, uh, alone. So Cisco is absolutely benefiting from the carry-on impact from AI and AI training.
Well, and they just re released a, uh, new, a major new product called AI Defense, uh, which is designed specifically to say, how do you do systematically, uh, you know, defend against, um, all the challenges of ai, um, that, that you might have, uh, across your entire environment. Uh, and so, um, it's, you know, and yet to be seen how much lift they'll get from it. But they're doing major product releases around AI that I think a lot of people were not necessarily expecting.
So, um, data management, uh, was another topic. Uh, we had, uh, um, unified our platform data systems. Kimberly, you wanna take?
Yeah, I started thinking about this yesterday with the vast announcement this week. Vast Data announced that they added blocks block protocol to their platform. And Vast has, you know, been highly focused on the AI or, um, data analysis kind of market that you're going after, which has traditionally been file and, and somewhat in the same area of object.
There's also been this noise about platform data systems, meaning you should have this, you should, your strategy should be for a platform, for one platform for all. Um, and I think many years ago we'd get briefings from vendors, you know, that come in and what we would call the God box, God box, I have to do it in here, that that gave you file block and object. And we'd kind of go, thank you very much, but I'm gonna set up, you know, this system for transaction processing.
I'm gonna set up this system to manage, you know, shared file systems. I'm gonna, you know, and you had it, your selection of what you did with your data management system was based upon the application and, and not necessarily an operational efficiency, which is what a unified platform more or less gives you is because you've got some common, common kind of technology you don't move the data around. So in reflecting of that, there's this been quite a bit of data that's coming out of our C-I-O-C-E-O discussion and around ai.
Is that one of the biggest problems that they have? And we've talked to the at infinitum, which is data management aspo, that is the data is the data problem is preventing them to get to ai, Correct? Yes.
Platform block file an object on the same platform is not going to fix the other problem. It's a different problem. Data management has to do with relating either understanding what is in that bit or, or whatever.
What is the, What you have and where is It, right? I mean, that's, that's the right that, and that's an amazingly hard problem in it even today. Yeah.
So, you know, once we think about the context of this problem, right? The Elon Musk was quoted as saying that we've run outta data to train ai. Well, you've run outta data that's on the internet, just looked up some rough numbers.
And then these are the numbers that I've seen consistently. About 60% of the world's data is stored in a public cloud, 40%. And the private data center, what that tells us is that systems like Vast, whether you're talking about, and this is their story, right, Kimberly, that they vast doesn't care if your data's in the public cloud, doesn't care if it's in private data center.
They want it behind a vast system. They want to be the front end to you accessing that data. And you need to be able to access that data in various ways, block storage and file.
But I think when we talked about this a little bit before the show, the problem isn't necessarily access to the data. Uh, the problem is the organization of the data, and I don't know if putting the data on a single system solves that problem of organizing your data to use with cloud as we're advising in customers how to adopt ai. It's all about organizing the data versus, you know, making sure you access it in the same way.
Yeah. And that's knowing what's in the data's having a risk profile for your data. It's knowing what data that you need to mask in order to move it into the information into your, your data lake or how, however, that one storage place that you wanna be able to access it to pull it through.
So I, there's pieces of it, some things that it does solve having in a platform, but there's many, many things it does not solve. And there's this discipline of what we used to call the master data management people, you know, that needs to be Well, and they're still around and they haven't gone anywhere. In fact, you can say their pay grades gone up a little bit, uh, with ai.
But, um, you know, unifying block file and object is, uh, evidently useful, uh, because it takes, you know, arguably it takes three silos and combines them. And the problem is, is cloud and SaaS sprawl, uh, uh, you know, is, is the biggest enemy of anything. Like, um, you know, you've got all your, your data used to, all your data used to be in the data center and the ci I used to know where all other data is, every scrap of it.
And now it's in data centers all over the world, um, uh, through all of these SaaS applications and cloud platforms. Um, you know, how, how does FAST is either of you have a sense of how VAST is, is gonna help address those sorts of things. 'cause without that, you, you still don't really solve the problem.
Well, We're mentioning vast Europe, it's only because they announced that, you know, we have many others that are kind of marching in the same direction. And I guess what I wanna do, you know, as an analyst in this environment, talk about what does Unified give you, you know, what does mixing these things together, here's where the benefits are, but it's not, it's not the be all and end all that the CEO is looking for in terms of solving the data management problem. It's just a piece of it.
And it potentially, and I think solves it. And I think, and there's other methods through any of this too. And I think one of the bookends of the announcement from Vast, and I, we will, we're picking on Vast as they made the announcement, but one of the, uh, bookends is that, is their, uh, broker, their event bro broker service.
So, Diane, coming back to your question of how does this help the event broker is one of those things, you know, that hints to what enterprise data architects and art architects can do. If you adopt this idea that you want to receive an event, there's some type of message bus of when data's accessed, when data's written, when, uh, a a a type of data is accessed, then there's an event created. And that if that, if you are able to have a consistent architecture or data architecture or event architecture is when data is accessed in SaaS, when it's accessed in the cloud, when it's accessed on block or in object, that you get some type of event notification, then that helps with the problem, doesn't solve the problem, but at least it gives your architecture to help mitigate some of the challenges associated with, uh, knowing where your data is at, how it's accessed, and how it's used In, in terms of, um, you know, we talked about, we already mentioned ai.
Uh, it seems like we, it's obligatory for every episode of the show so far. Uh, the last, uh, um, you know, so far this year, um, it's interesting, uh, we're starting to get data from 2024. So I, I, you know, I, I do a lot of database analysis as I, the numbers often tell the story about what's really happening on the ground in technology.
And it, um, and a new study came out, um, uh, uh, from a, um, you know, from from leading an analyst firm, uh, reporting at 47% of CIOs say that they're, they're reporting positive ROI on their generative AI efforts, uh, which is, um, a, you know, a good number because, uh, a a lot of the initial technology pilots and prototypes don't actually work out that well, especially with, with, with high difficulty or high complexity technologies. So 47% of CIOs reporting, uh, um, positive ROI is a good thing. Um, and that's gonna pretty much ensure that we're going to see sustained investment on the IT side, uh, for gen AI in the industry for the rest of the year.
So that's, uh, that's great news. 5% on average, uh, this year. Um, that's all gonna be eaten up by, uh, AI and inflation.
That's basically where we are. So in fact, it's not, that's not even a cover AI and inflation. And so most, in real terms, most IT departments are gonna see a net cut in their, uh, IT budgets because of that, which Is, which is why we're already seeing in terms of, in my conversations, we're already seeing, you know, the issue about how do I get more efficient on what I'm doing?
How do I con either consolidate, look at operational efficiencies, streamline whatever I'm doing, um, we're, you'll see, I think we'll see more investment into AI being used for coding, which takes out staffing. Yes. Right, exactly right.
You'll see, right, you'll see more investment in what operational efficiencies can I gain from doing some different types of technology. So I think we're going back to that, to, you know, good strong total cost of ownership analysis as we get into purchases that are happening because we have, because they're gonna continue to cycle in terms of upgrade their systems. They, they need to, they can't just continue to pour the money onto the AI side and ignore the, the core infrastructure areas.
Yeah. And this is why, again, bringing the whole conversation back together, this is why understanding from adjacent industries, genomics, manufacturing, how these industries are using deterministic outcomes to drive their AI initiatives. It has led in this actually pre AI for a long time with the, the Security Operations Center and finding false positives and filtering out those false positives to get to a outcome in which we're using less human capital to, uh, disposition those, those false positives and find true security events.
AI has improved that now that we've, you know, kind of taken these LLMs and moved that human assisted, uh, filtering down to the input level and come out with more deterministic outcomes, we're using less humans to detect and respond to security events. I see, ironically, a doubling down on, as you two seem to as well, a doubling down on AI and automation to help alleviate many of these budget concerns. It's also telling, you know, how, uh, the reaction to the Broadcom VMware price, uh, effective price increase.
The, the cost may, you know, the skew may not have gone up, but customer, customers are spending more on basically undifferentiating, Just more. I mean, it's a price skyrocket. I mean, that's, that's, yeah, it's, it's quite A bit more if you, if you're not, so, you know, again, if, if you're all in, in, in VMware, you're going to learn how to use the entire portfolio to reduce your cost.
How does this private AI solution help you reduce costs, adopt ai, uh, in a more cost efficient manner, get more benefit of your VMware investment, or do what companies like, uh, like Geico are doing and moving away from VMware into open source? Yeah, I did a, I did a, a, a case, a study of that on, on the CIO post report. Uh, Geico's make up majors move away.
Uh, you know, so, uh, I'm very impressive to watch. But this brings up the whole AI ops discussion, which is, uh, in increasingly, um, it is gonna be operated, uh, uh, you know, first tier operations will be done by AI and not by humans. Uh, is the unblinking gaze of the robots can yeah.
Can manage things 24 7. And it's only when things, you know, exceptions happen that you need to bring humans in. So that does seem to be, you know, a, a major focus in terms of reducing, you know, fixed costs and reducing overhead for it.
Uh, and so I'll, we're, we're almost at time, so I'll, I'll do, uh, I wanna do my last, uh, piece of news before we wrap the show. Um, the, uh, avalanche protocol, which is a, um, it's a blockchain I kind of use as a PostIt trial for enterprise, um, uh, digital ledgers, uh, enter Enterprise Web3, which is not a topic that I find is particularly popular in IT and CIOs, but it's, it's important because things are actually happening as an example. And the, again, one of the reasons I talk about Avalanche is, um, the California Department of Motor Vehicles, um, last year moved all 42 million vehicle titles into Avalanche last year.
Uh, that's, that's a big deal. We're we're actually seeing people moving, um, important records, uh, into a blockchain based technology. Um, and the, the advantage being that, that data can't be tampered with.
'cause you can't modify data in a blockchain. You can only add data to it. So records are, are, are considered safe and, um, uh, and, and will last a long time.
Um, uh, since the, the data is replicated across, you know, thousands of different nodes, you can't lose the information. There's, there's no, you know, single point of failure. And the whole point is that there's massive multiple redundancy.
Uh, so Avalanche has got, uh, uh, about 9 million, uh, addresses, uh, half a billion tokens in a market cap of about $10 billion. Uh, and they just announced the holiday protocol, which is, uh, uh, the whole Web3, um, subcultures really, you know, likes, uh, uh, pop culture references. So this is a, you know, ready player one reference to the, to the creator of, of the metaverse in that, in that, in that story.
But the holiday protocol is the first, the, the very first agentic AI announcements, uh, in the blockchain space. Uh, if you want agents to work with anything in, in the blockchain world, you have to create a smart contract normally. Uh, and that's, even though that's relatively easy to do, that's still a higher burden than most people want, want to take on it.
You want agents to be able to work with something that they've, you know, essentially never seen before. You don't wanna write code for every, every type of, uh, transaction or every, every type of thing you wanna do in a, in a given blockchain. So the holiday protocol, uh, allows you to use agentic AI to manipulate or interact with the avalanche blockchain.
And I think it'll be the, the beginning of a lot of announcements like that, I think, see most, most blockchains doing that so that you can use agent agents without writing, um, smart contract code every time. Uh, and again, this is still early days, but the way that the blockchains are not designed, I mean, they're, they're, the, the total market cap of all blockchain technology is around around 3 trillion, making it about the ninth largest economy in the world. Uh, and, uh, I've, I've talked to retirement, um, uh, uh, retirement network CIOs, uh, from like, uh, federal and state retirement programs program.
They're not tracking this stuff at all other than they know it's coming. They're like, we don't care about this. We don't even like it, but we know that it's coming.
And so we're having to watch it. So it's worth it. It's then it's gonna be ultimately a, a big part of some new record keeping infrastructure.
We just dunno how big yet. So it's not that. So Diane's gonna make you listen to it, even though you don't wanna hear it.
Guys, on infrastructure matters, we're gonna bring it up. Dang it. And that brings us to the end of another great infrastructure matters.
Um, and, uh, we hope, uh, you got, uh, but useful knowledge out of this, uh, and, uh, I think all three of you will, uh, all three of us will, will see you next week. Hi everyone. Uh, my name is Alejandro Mercado, very honored to be here.
Um, I'm going to talk about, um, this kind of new trendings now. It's about predictions 2025. So let's get started.
So my talk is about the, an experiment that I am making is, is a little bit about make our life easy. I, I mean, in terms of, we, we need to handle a lot of things, lot of activities, lot of consideration when dealing with, in technology and specifically with software development. So it's come to my mind to, to what if I can handle my, in this case, my cluster, because my Kubernetes clusters, because, well, you know, I am the Babs engineer, so, so I think this can be a good idea to, to be more productive and, and yeah, to get my job done.
So this is an introduction. We using voice comments and virtual assistants like Alexa, I mean, can be any other assistant, but I have an Alexa to efficiently manage and deploy a Kubernetes cluster. So, a little bit about me.
I'm Alex, Alejandro Mercado, uh, rise and Board in Mexico City. Uh, I spend most of my time doing the Bobs and, you know, cow engineer, automation related activities, observability, um, just currently living in Mexico City, uh, where I also co-organized the KCD. This is a little bit of topic, but, uh, call for proposal you want.
Please apply. Please, please do it. Um, and well, there's are a couple of links about my, my blog where I, I write a lot of, in, of course, in Spanish and in English about technical stuff.
Um, the presentation, if, if you want to download. So I, I'm not pretty sure about to talk about predictions because you know how I don't have a crystal ball to, to predict anything. Uh, uh, I, I better will say to prospective of technology, because I mean, 20, 25 is already here.
So this is for sure that this is going to happen because we are, we have, there is a, uh, a lot of strains of activity related to that. Several topics. This is just a couple of them.
I mean, it's not an extensive list, and as I said, it is more like a prospective, i, I will better say prospective than prediction. So definitely artificial intelligence and machine learning is here. Maybe you get involved in, in this several tools.
There is a lot of folks, uh, a huge explosion of these tools to democrat the, the use of these two technologies. So I mean, it, it is going to impact any, any activity in our lives. So if you're a developer, you are a tester, you are a writer, even a musician, or I dunno, all the, all the areas in, in, in our life, it's going to be impacted by artificial intelligence.
So being from the technical side as a engineer, well, this is where my, my talk is, is going to want to cover one of these aspects. So, quantum compute, quantum computing, uh, networks like 5G and beyond Blockchain, blockchain, we have been hearing about blockchain lot of years. So we are going to see more, more cryptos, more technologies.
So be aware of that because, uh, for sure there is going to be a lot of jobs, a lot of opportunities around this. Security. Security has been always a thing, a consideration and important aspect in everything of our developments.
Uh, so more people focusing in the security side is going to be required, um, built a reality of mental reality. We are, uh, well, not, not just starting talking about sustainable technology. We have been talking about these, um, for several years ago, but it's, it's gaining popularity and importance because, you know, all the situations as we are facing as, um, I mean, in the whole world, it's very important to talk about this, this kind of topic.
So for sure, we are going to hear more about sustainable technologies and of course, uh, remote work and keep working on col collaboration tools. You know, from, from this COVID-19 situation, we have been dealing with that a, a as many others, I can imagine the work, if not remotely, but for sure, we, we are going to see another ways to interact, to communicate, to be more productive. Um, the last topic of this short list, this is my, my humble opinion, of course, uh, human computer interaction has been with us like many, many years ago.
But we are going to keep seeing, uh, innovations in human computer interactions, spray computer interfaces, and advances for recognition that this is the topic of my, of this brief talk. So we will create more intuitive and seamless ways for humans to interact with technology. So like, to handle more of my activities on the techie side.
So I would like to emphasize that we're going to see more of this boys assisted technologies, especially in, in other sector. I mean, I, I, I did at experiment because I am lazy. I just want to have just, if I am on my, in my bedroom, just to, to talk to Alexa and say, Hey, how is my, my cluster?
Or, or do I have any problem on production or development or any other environment? But, uh, when I think about other sectors of people, I mean elderly or I, I don't know, uh, talking a little bit about accessibility, we can see that this kind of technologies is going to help a lot. Uh, why or how?
Because, well, because these technologies offer significant benefits in term of health monitoring and wellness support for elderly. This is by instance, is just a couple of examples. Um, uh, if you take a look of this slide, um, voice and apple technologies will assist senior sentences and professionals, um, and to adopt an environmentally sustainable solutions.
And there is a, a lot of, lot of examples that we are still developing, and we are, uh, evolving this, this, these examples. But I mean, I just want to, if you wanna take away from this talk, we are going to see more of this, uh, not just experiments. I, uh, I, I will better say projects around technologies like voice assistant technologies that is going to help in so many different ways that it's, that I, I mean, this is just one example.
So as a DevOps engineer dealing with software in the software development lifecycle as a business daily, it's, I, I see that, well, when I started to think about this project, I see that, well, I was not the first person in, in this world to, to think about it. So, uh, not for surprise or I see that there was a lot of, or we, we have a lot of different project related to that. I mean, it's like, once you get the something to help you with the underlying infrastructure, you can handle and manage, instead of using a, a keyboard, you can use your voice.
So we, I, I, I, I find, or you can find a lot of examples about this similar, uh, concept. So just do a quick research on internet, and you are going to find a lot of, uh, similar ideas. So I, I just, uh, I am proposing one that this is just as I said, because makes my life easier, uh, just to have this introduction to two boys activated Kubernetes management.
So why, because, well, of course, uh, is, is scalable, is adoptable. You take a look at this slide. Mm.
And I, I, I would let to say that this is not just for a Kubernetes cluster. I mean, mean, this is pretty specific for my related activities, but it can be any kind of technology. I mean that any kind of application that it's running on the cloud, you can handle, you can manage it.
So, uh, take this, uh, introductory talk, like a, like a 360 degrees view of what can we do, what is going on or, or what we're going to see in the next couple of years. So by leveraging the power of voice comments, organization can streamline their Kubernetes management workflows, improve AccessAbility and enhance overall efficiency of the DevOps processes. But I mean, I, I repeat it can be testing process processes, dev processes, uh, development, software development process.
Uh, so, uh, I, I focus my, my experiment and the Kubernetes side, because some people say that Kubernetes is, is, is hard. It's tough to, to main, you know, to think the beast. Um, uh, and yeah, I, I can I agree about that, but well, you think, uh, I, I think that it can be, we can have better tools to, to manage this complexity.
So we have been dealing with that a lot of times since you can see this, this slide. So when we started dealing with Kubernetes, uh, it implies a lot of components, a lot of situations, con connectivity, communication, networking, et cetera, et cetera, et cetera. So, so it's a long history around Kubernetes, and there is like an explosion of tools.
If, if you take a look at the C-N-F-C-N-F-C landscape, you are going to see a huge amount of technologies around Kubernetes for different purposes to service mesh, to package managers, to, to deal in a different ways with the control plane data planes. Um, I, uh, uh, I don't know. I mean, there is a lot of tools for monitor and observability networking, uh, and the idea behind is to, to make things easier.
But it's ironic because it's more complex. So I think that we are just reaching the top. We, we, we are dealing with that, but I mean, this is just to have, uh, a voice assistant.
It is just to, to have a, a different and simple way to, to handle, to manage things. So, um, talking about not predictions, if not prospective, we are going to see a lot of, um, this kind of new ways to interact. We're not so new, but we are going to interact more and more with this kind of new technologies.
Um, we're going to see more, if you take a look at the final milestones of this slide, we're going to, to see more web assembly for sure, uh, internal development platforms. Um, there, there, there was a, a boom of this, uh, internet development platform like backstage. So you can expect to have more and more activity related to that.
Um, this is a not some well-known term that is, is bring your own cloud for sure. I'm pretty sure that this year we are going to see more about this concept. I mean, for a lot of people it's going to be new, but, you know, it's not like a big bang.
This concept had been on the, on the way, uh, that there's a lot of history behind this concept is bring your own cloud if you want to take a look after this talk. So, um, why Kubernetes and where Boha system, I mean, this just an experiment, but as companies scale, there are Kubernetes sage, the challenges around clusters management, security, and optimization become increasingly complex recurring data tools and experts when you have a, a couple of hundreds of microservices. So things are getting to start more complex to deal with.
So you'll require, you are going to require dedicated tools and of course, expertise. Expertise. So, uh, the integration of voice controller technology with Kubernetes management has the potential to revolution at the DevOps workflow.
So, and I'm talking about the, as I said, the whole DevOps workflow being a very important aspect, our next cluster. But I mean, you can do, uh, you can think about any other aspect of the DevOps workflow that we can handle, manage, uh, or manage with, with these technologies. So this experiment was, um, uh, about enabling hands-free control and real time updates.
So this converse convergence and enhanced efficiency, productivity and agility in software development and deployment process. So the, the idea is was to just to talk with my Alexa, just to get the system status held to create a, a cluster to delete bots, to delete the whole cluster. And I mean, this is something that I can do, of course, with, with the user interface or even with the, with a comment.
Uh, but I mean, I, I, if I driving or, or doing something else, I dunno, washing the dishes, uh, at the kitchen, maybe I, I, I, I want to know if something is going wrong with my, my cluster. So, so I just can get alarm, uh, in, in my Alexa. Um, well, yeah, if some felt, if I, if a critical error arise because some reason, maybe I just want to know about it.
I mean, I don't want Alexa to, to keep, uh, I, I don't want to keep getting messages from Alexa every, every minute or two minutes. No, but thinking about critical or fat errors, I mean, I, I just want to know about it, so I I can, yeah, I mean, if, if I'm not in front of the computer, I can have even notifications on my, on my, on my, on my cell phone or, or me Alexa device. So, so the, the, this project can, can you go further to get more details on the pops?
On the lots on, yeah. Uh, it's, oh, uh, a work in progress, but that's, uh, the, the idea just to observe my, my, my whole Kubernetes infra. So, and, and, well, I, I, I think that Alexa, it's just one of the, the options that you have on the market, but I mean, it's the same for other assistants.
Uh, just because I have one Alexa, it is what I have, uh, it's handy to me to, to make this experiment, uh, in my house. But I mean, uh, it's not just Alexa. It can be any other, uh, voice assistant.
I just want to clarify that. Um, and there is a lot of benefits, uh, having in this kind of new approaches to handle and manage infra, uh, I mean, is in, uh, early stage, but definitely where I want to see more of these kind of projects, uh, to increase, reduce errors, to be aware of what is going on in my infra, I think is, it's like, um, uh, I important point. Yeah.
So accessibility, you have some, I know elderly people or with some visual problems, maybe this is going to be a, a, a great help, uh, streamline workflows, contextual awareness. So I can ask my, my Alexa, uh, like this experiment proposed, Hey, Alexa, tell me the, the, the health about my microservice or, or which microservice, uh, uh, has the, the lower latency just to say something so I can have an idea, of course, is it's not about to solve the problem, just interact. It, it, it, it is, we are not in that part yet.
But, uh, to be a, uh, aware of what is going on, just to, once you are in front of your computer, you, you can have like a, a solid clue or way to go. So, uh, this is like real go use cases. So infrastructure automation, IT operations has free control in manufacturing, emergency response coordination, leading to remote site administration, that this is something that is, we're not too, too far from that.
So the experiment, so a couple of years ago I started to think about it because I, I use my voice assistant a lot, you know, to, to several things. Uh, so, so my idea was to, in, in, in a conversation that I had with other colleagues, uh, we have this idea of what if we can handle it when I, I am driving or commuting to work, or when we have friends, I, I mean, doing something else. So it, it'll be at the beginning with basic stuff, and you could do more advanced activities, uh, with more experience.
But because, I mean, it's not that easy know, just to set up or to create accordance, clusters implies a lot of considerations. So it's not that easy just to say, Hey, Alexa, create my cluster. That, that, I, I started to think about that.
So through this journey, I realized that it was not that easy and there is a lot of consideration. So, well, uh, this is, uh, mm, very brief diagram of the architecture of my system is, is you are going to see just a lot of lambdas and, and as you can see, it is running on AWS just because, I mean, it's, it's not tied to, to AWS you can use Azure or cloud or any other cloud provider. I mean, but, um, the idea is, is the same.
We have a lot of functions that call, you know, this interface between the LAN Alexa skill and the, and the functions. So once we, we accomplish the first thing, I mean, to create something, you can create anything on the, on the cloud. I mean, it, it, it is like the same concept.
So, so I started to, to create A-A-B-P-C as subnet, and of course, the, the, the Elastic Bernet cluster, uh, the, the E-K-S-E-K-S, so a, a lot of per permission policies, et cetera, et cetera. So, so, but the, the idea behind is, is it's like the can be extrapolated to do a lot of things. I mean, to manage the whole, anything that you can do in, in AWS you, you can do it with this idea.
So the idea is to end this call of having a voice interface to handle everything that you want. So the idea is that the functions are so dynamic. I mean, my, my voice interaction is, is so dynamic that I can do anything.
But I mean, to achieve that is, is going to take a lot of time because there is a lot of services, a lot of considerations, a lot of configurations, a lot of dependencies. So in this journey, I realized that, but I, I just wanted to, to focus on a Kubernetes cluster because you asked me about to do something else. Well, of course, it, it can be achievable, but it's going to take a while until the, the, the voice interface is enough smart to handle all the requirements, but we are not in that point yet.
I mean, maybe, maybe in a couple of years, uh, this is the, the, the experiment. Um, I, I can do a, a, a real demo, but, uh, it's going to take a lot of fun, you know, to create a, a Kubernetes cluster can take like 15 or 20 minutes, so it's going to take a long, too long to, to have the, the cluster running. So it, this is just like a couple of images, uh, about the, the test, the test that I did to deploy the Kubernetes cluster.
So I have this voice comment to open, um, my, my Alexa skills name is Kubernetes Manager. So, so I can deploy a cluster, I can delete a cluster, I can monitor the cluster it, and in, in the, in the arena of monitoring and observability is where I see more opportunities because, you know, to, to create a cluster takes a lot of considerations. But I mean, it's not that easy.
And you have to be pretty sure you have lot of, lot of Jamal files with, with manifests to be pretty sure that e everything is going to, to be up running. So I started to think that, well, maybe it not a pretty good idea just to create the, the, the cluster with a voice comment. But I think that for monitoring and observe and have like a real time, a status check, uh, to see if there is any cluster health issues, I mean, it, it's going to be pretty handy.
So in, I, I, I don't want to talk a lot about the technical aspect, uh, because there is a record that I want to show in the next slide, but, well, it's about the interaction model. So that's the way that the Alexa skill, uh, works. You have to define the, the, the intent.
So this, this is like more in the more technical side. So if you are curious about it, you can take, um, uh, a look of that in, in this repo. But, uh, the, all the magic, all the heavy stuff is done through Terraform.
I mean, we can use another technology for infra code, but, well, I, I have experience with Terraform, so, so that's the way that I, I, I deal with the, the whole heavy lifting. So the Alexa skill is, is calling, uh, some land and the land are calling the, the, the, the Terraform stuff. So yeah, this way I can achieve, I, I, and I can say anything that you can achieve with this kind of tools like Terraform, pluming, uh, A-W-S-C-D-K, I mean, you can do everything.
I mean, in the cloud, any resource, any object, any configuration that it's possible. It's just like adding to the interface. So, oh, well, this is, um, just, uh, you have never heard about infra code.
It's like, uh, this way to handle infra this new way, not, not that new, but, uh, it's the process of managing and provision and computer data centers through machine readable definition files. It's all about definition files. So there are, as I said, there are a lot of options in the market, open source and legacy.
So, uh, again, it's not tied to Terraform. Well, my idea is not to tie to any, any, any particular technology. Uh, Terraform is agnostic to the cloud, so it can be this easily.
Uh, we can do an easy immigration to other clouds like Google, Azure, Alibaba, anything that you have in mind, we, we can just adjust this, this, this project. So, well, that's my idea to, to get or to reach a point in the near future to have this voice interface to handle any kind of, of technology, not just the Kubernetes cluster. But I think that this is possible achievable, and it's going to be, uh, pretty handy.
And we are going to be more productive in, in, in terms of our, I mean, talking about my, my side engineer side. Uh, I would like to have an interface like that, definitely. So thank you very much.
Uh, I'm going to be around here. If you have any question, comment, please be, be my guest. Um, please reach me or contact company, uh, my LinkedIn profile, the information is right on this at the bottom of this slide.
So, yeah, thank you very much. It's been a pleasure. And have a nice and happy 2025.
Hi everyone. Is AI gonna make us like those fat corpus souls driving around in gravel chairs in the movie? Wally, you're watching Dextron Gang.
Hi everyone. Happy Tuesday. Welcome to Textron Gang.
It's great to have you on. Hope you've been enjoying the, uh, commentary lately. There's certainly enough to comment about in this crazy world that we live in, in crazy times, we're living through.
Um, we have a lot to go over today, including is AI making us that lazy and dumb. It's a terrible way to go through life. Um, let me introduce you first though, to our Audi, uh, to our gang that's gonna discuss it today, joining us.
I think she's back home in Colorado after her California Ventures. She is a future analyst, infrastructure storage, just a lot of general, all around smart. Exactly opposite of the, the AI making this stupid people, our friend Camberley Bates.
Hey, Kimberly, it's great to have you. Good to see, good to be on with Techstrong. It's always a lot of fun.
I learned something from you Guys. Thank you. Well, we always learn from you, so thank you.
Speaking of smart, how's that from Hudson, Hudson, Ohio. He's the CEO of Tech Field Day. It's my friend Stephen Foskett.
Hey, Steven, how are you? Uh, Honestly, I thought you were talking About Mike, but, Um, I might have been, but I, I figured it's Tuesday. I'll cut you a break, but Steven popped out of there.
I think he was blushing. Yeah, I think he was blushing. Um, we'll come back to Steven in a minute, but let's run over to Harrison, New York though, and introduce our chief content officer, Mike Baard.
Hey, Mike. How are you? I'm good.
Uh, I'm waiting on the remake of Dumb and Dumber. I think it's gonna go dumb dumber and dumbest. I got a third, um, but certainly not dumb.
In anyone's book is our Echo Insights analyst and, and, uh, author of her new report, as well as editor Bonnie Schneider. Hey, Bonnie, how are you? I'm great, Alan.
Great to be here. Thanks. Good.
We're gonna talk more about your report. Yeah, we, we spoke a little bit about it, uh, last week, but we'll, we'll pick up on it today. Um, alright.
We're hoping Steven will get back on here. But Mike, you know, I, I, I opened up with us. I, I've had this sneaking suspicion for some time that first it was the internet and not going to the library and running, learning the Dewey Decimal system, but social media, our AI video screens and phones.
Is it dumbing down the human race? And are we all destined to live in those gravel chairs, like the fat people in Wally? It all started with the calculator.
Man, we all, nobody knows how to do math, and it's just getting worse. Yeah. But, but the issue is, as noted in a report put out by Carnegie Mellon University and Microsoft that we're just maybe relying too much on ai, there's a general assumption that people kind of trust whatever gets presented with them on a computer screen, and that they're not gonna reason enough about what is actually being presented to them by the AI model.
And once that happens, we just all kind of, sort of compound mistakes upon mistakes. And I don't know if this is something we need to just teach people, is this something we gotta get at, at the school level? But, um, Alan, I'll start with you.
Our cognitive reasoning capabilities may be declining even further than they are. And I know you don't think they're pretty high to start with. No, I mean, yeah, I, I, I agree with the, kind of the findings from this report is when people start using crutches, right?
Their muscles atrophy. And, and I, I think to a certain level, yes, our brain muscles are atrophied, right? When it, when it comes to certain things, I mean, laughingly talking about math, but how many, how many people today actually, other than if you, you know, you work in something in ai, for instance, where you have to know, you know, some higher math skills, but even basic math skills division, right?
Algebra, basic algebra and geometry. How many of us know how to do that anymore? Or, or, you know, without a calculator, can, can we do it?
Um, it's the same thing for writing, right, Mike? com or Security Boulevard. The writing is atrocious, atrocious.
So written skills, kids don't know how to recursive script. Um, it, the, the list goes on. And I could see this happening with ai.
Just tell AI what you want it to write, and it writes it for you. And I'll go one step further. Tell AI to write the code and it writes the code for you.
Is it gonna dumb down coding? You know, it's a fine mess. We've got ourselves into here.
I I don't know if this is something you learn in school, or can we teach critical thinking in school? If so, how do we enforce the no calculators in the test rule? I don't know what the answer is.
I think checking, um, that's what I was doing. You can check, you know, if something's AI written and teach a student that, um, if you're a teacher that we can tell if it's ai, so don't, don't bother just cutting and pasting it. Um, teaching them reasoning.
And then of course, before all that, teaching them how to explain an idea, which I, I think is something we all grew up with learning how to write a paragraph, you know, to support it. But, um, kids today, that's more of a struggle 'cause they haven't had to do that. So I think that those basic skills of coming up with an idea and then finding ways to support your idea just on the basic level, um, will help.
But obviously it's a long way to go. So, lemme see. Go ahead, Kim.
So I would even go beyond the kids. That's what I was gonna point out. This Is one piece of it, and I was looking for the study on this and I can't, couldn't find it.
Um, quickly this morning when we had this key topic coming over, which was one of the big, um, consulting firms, it was McKinsey, BCG one of those guys had done some analysis on this kind of work. And they had one group that was doing marketing, a marketing plan that was using ai and another group that did not use ai. And what they found is the one that was not using AI had more creative, out of bound thinking, et cetera.
And that, because, you know, to me, the reasoning behind that is because you're socializing between different thinking operations in, you know, that's why we like the concept of having a lot of different thinking and skills basis in terms of a group that works through some issues. So when you think about how we have to go through and problem solve, those are the things that we're looking for potentially an AI system to be used. And, and then the other piece I'll go to that is that I was looking at, you know, as I was trying to search on this, I found a really great graphic that was done by BCG about what, what predictive AI does versus what Gen AI does.
And if we think about what Gen AI is doing, it's content, it's really a lot of content. And versus predictive AI is giving me an analysis of where something is going. And that technology of how, how we code or how we direct the computer systems to operate is very different.
And then what they're also saying is, how do you join those two pieces together to creative and more analysis is going? But I absolutely agree. I mean, and I'll stop with this one is like, I backpack, and I cannot tell you how many times I've been in the mountain, and some, I'm sorry, 20-year-old has got their GPS with them, and they're expecting that to get them through the mountains.
And we're going not, you know, you get lost because it, the GPS doesn't work up there. You can have satellite, maybe that's gonna help you out, but GPS Uhuh, it's gonna go and you're screwed, you know, with that. So there we go.
In theory, we should be using AI models to check the output of other AI models. And maybe that will help us determine what's reasoning. But then I worry that the AI models will just argue with each other forever and to the point where, Well, you know, so Kimberly, I agree with you.
This is not a just a kid's problem As we get older or tell us, if you don't work out right, you lose muscle mass. If you don't use it, you lose it. It's the same thing for critical thinking skills and, and reasoning and, and stuff like this.
And so, you know, young people are very resilient. They'll figure out how to leverage this and be clever and what have you, and what they lose in, in dexterity, for lack of a better word, uh, they may make up for in, in leveraging AI in ways we haven't thought of before. But I think it's, it's the adults in the room.
It's the, you know, people my age, your age, you know, 30 somethings, 40 somethings who, you know, becoming overly reliant on, on these things may in fact kinda lose that, that muscle of creativity, of, of thinking out of the box, of, of doing things without it, right? Like all of a sudden it's better enough that most people refuse to read very much anymore, right? They just don't read.
People don't read. We see it here at Textron. They like to watch videos rather than read, and They're like bullet points And they like, yeah.
And they, if they do read, they want it in three or four bullet points. Uh, but when you start getting to the point where people say, well, AI can make that for me, if they don't make it for me, I don't wanna, I'm not quite sure it'll take me a very long time to make it, you know, it, we all lose, But we are also seeing long form come out. So, whereas, I mean, one of the things that we've been seeing and why podcasts are on the swing up is because we are seeing the younger generation want the longer form.
And, um, and they will hang on into that and, and listen to those longer. You know, it doesn't have to be three minutes anymore. It can be like, this is, this is an almost an hour session, right?
And we do it in 20 minute psychs, you know, cycles or 15 minute cycles. But that gives us an opportunity to go into the topic much more deeply than it does on, you know, cable news where they're only giving it two minutes if that much time. Um, so there's an analysis, potential analysis that's going on, um, that we haven't seen before, even if it's done by video, Right?
So, Steven, are you with us? I am with you. Can you hear me?
I can hear you. So the discussion was that, um, the younger folks aren't doing enough reasoning because they're relying too much on ai. And since you're closer to this particular topic, I was just wondering, you know, do senior citizens have an advantage now?
I See, I thought you were gonna call me a younger folk, and then I feel like you're calling me a senior citizen. But, uh, you know, speaking as one of the younger folks, uh, no, you know, I was reading these articles and I place the blame somewhat on AI itself. AI is, is the smart alec know-it-all.
It has no sense of humility. It has no sense of what it doesn't know. You know, AI confidently answers everything, and in many cases, confidently answers it wrongly, but so impressively that I feel like, you know, I don't wanna take the blame off of people entirely, but I do wanna put the blame into the way that these AI applications are made.
It's no surprise that Silicon Valley made a bunch of smart Alec robots that, uh, tell you how it is without giving any opportunity to have any other thing. But, you know, think about it. I mean, you ask chat GPT for a thing, or you're using Apple Intelligence to summarize an article or whatever.
Are you really, really going to think critically about that when it comes across so confidently it doesn't say, I think these are the main points of the article, or perhaps in my opinion, this is where we should go. It says, no, here's a summary, here's the important points, here's the bullet points. And so it's no surprise that people look at that and say, huh, okay, that must be right.
Yeah, but, but Steven, you, you, you're kicking the dog, blaming the dog for being a dog. Whether, whether AI is right or wrong, people shouldn't blindly just accept it and use it and move on. I don't care if it was right a hundred percent of the time.
So, okay, AI's right all the time, let's all get into our gravel chairs and get fat, right? I think the answer is no. You can't just like, you don't bring calculators into the test.
Maybe there are some things that you don't use the AI for to, to exercise your brain. I think we need, we need, we're humans, we're problem solvers by, by genetics. And we need to continue being problem solvers.
Now we use tools. That's what separates if so, they say that's what separates us from other animals and so forth. Though we found animals do use tools too, but we, we need to be solving problems.
That's, that's how we continue our evolution, I think To, to be fair to the machine, to be fair to the machines though, we all have that friend who has an answer for everything and confidently tells you that this is something, and boy, God, this is the actual facts. And upon further review, you always discover that that friend is dead raw. So not Always, I make a career outta this, but go ahead.
So is, is AI not that new friend who's kind of sometimes right, but always has to be ju I would say so. I, exactly. I'm not blaming the dog for kicking, its for getting kicked.
What I'm saying is, we humans built a tool that confidently answers everything. Is it any wonder that we're not questioning it? So it also gets back to, okay, there's another scenario here, is that open book tests, you know, you, they, they, they started doing open book tests, you know, when I was doing this, and you could bring your books in, if you had to go through your book to find the answer, you are gonna flunk that test.
You did not have time to go and do that. And this gets back to your argument, or your friend or your whatever, giving you the statement of blah, blah, blah, blah, blah. And you not having the data to come back to it because it's not in your brain.
If you have to every time go through this to find out the answer, um, or to have a argument on any kind of, like a negotiation, I mean, if I have to go to that for negotiation, I'm doomed. If I have to go to that for a lawyer sitting in front of the, sitting in front of, you know, the, you know, questioning somebody, I'm doomed. So there's, if I have to do go to that as a doctor on everything, I'm doomed.
So there's a lot of things that we are doing that we have that is just skills and jobs that if that's what we're doing as a consultant, if I'm sitting there pulling out my phone when my client is asking me a question about something, you know, I'm doomed. No, but, so, but here's, here's, here's, you are right Kimberly, but here's the reality. There is no more consultant.
There is no more doctor. There is no more lawyer. It's the ai, you know, like right now about half of my health, uh, appointments are telehealth, right?
I, I get on Zoom with my doctor, we go over my blood work results and you know, we, we actually wind up shooting the crap about technology to try you. But, um, whether that was really my doctor or some max headroom impersonation of my doctor is kind of, Imma, you know, to me, he's going through my blood result. It's going through my blood results and telling me what I should or shouldn't do based upon best practices.
Same thing when I consult a lawyer. Same thing, frankly, when I consult a consultant, let's say in, in infrastructure or storage. And I think that's the scary thing, right?
Are are we gonna replace not just augment people, but replace them with, with these ais? Well, I think there's, I mean, when you look at, okay, let's take best practices for infrastructure and, you know, I just finished reading a book on cybersecurity, et cetera, and it's talking about it, you know, you have to understand that 20% of your technology within any kind of data center is changing at any point in time. So what are your best practices in addressing that?
Yes, I'm going to use tools to bring that information to me about what's changed, what's going on. But I can't just peanut butter over with an ai, it can have it bringing, you know, forward the information that I probably need and probably need to make some decisions on maybe taking some of these decisions that I don't need to have to make every day. Um, and applying that.
But hopefully what happens is, and this is what we've talked about before on here, is what we've done is we've raised the decision making to a higher level. We're having to make decisions on certain issues here and not the lower level decisions. The problem that brings is that the systems architect, the senior systems architect, can make those decisions and can use that.
But we're not bringing the junior people up because they're not getting the chance to make the mistakes, make the analysis and do the process. So that, to me is the bigger threat about what AI is bringing to us as opposed to having, you know, giving us some of the information to be able To make those decisions. So how is this any better or worse than the number of queries that I've put into Google over the years?
And every time I have a cold or a symptom and it comes back and tells me I have b bubonic plate, It's like, It does do that. No, no, no. It's lupus.
It's always lupus. Well, but, but, but seriously though, right? You, you talked, I have friends who are doctors and they call people like that, you know, people who have an MD from Google.
Mm-hmm. Right? And they're, and they're the scourge of the doctor's office.
'cause everyone calls up. I think I have lupus, I think I have plague. I think, you know, well, because WebMD said that, and I did a Google search and I probably have tumors on my brain and, you know, and they're like, calm down.
You know? And that's the difference. And, and Kimberly, I hope that that's the way it stays, right?
That the doctor, the real human doctor is who we go to and we stop relying on Google Doctor. Google Doc. Um, but it, it, it's hard.
I, I just, I mean, I could see the, the reasoning behind this. Anyway, hey, we're over 20 minutes on this one. We've gotta jump, we've got a lot more to talk about.
You're watching Techron Gang. We'll be right back is with are our heads in the clouds of report from Tech Field Day, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Welcome back to Textron Gang.
So I, I'm Stephen Foskett and I was out at Cloud Field Day last week, and I thought I would share some of the insights that we learned, uh, on site during that event. Now, this was a special one for me because I attended Cloud Field Day as a delegate, not as the organizer, not as the founder, not as I, I sat in the chair, I listened to the presentations. I asked some, well, some good and some joking questions, and I, uh, started writing about some of these presentations.
So it was a really interesting event. We like to say at Tech Field Day that there's never a theme of a tech Field day intentionally, but there's always a theme just, um, after the fact. You know, because that's just sort of, it reflects the state of the industry.
And this event was no different. Almost every presentation focused on the challenges of cloud networking and security. And, um, most of the presentations also discussed the challenges of this hybrid infrastructure where you have some things running in the cloud, some things on-prem, some things running in a different cloud, and you're trying to make sense of all that.
That was a really interesting observation for me because, you know, you see some companies here that, uh, that we're presenting, for example, selector, uh, Catchpoint, Infoblox. You know, you look at these companies and you're saying those are networking companies. What are they doing at Cloud Field day?
You know, we've got Fortinet, uh, you know, haiku who have traditionally played in the, in the, uh, cyber readiness, data protection, uh, security spaces. And, and you look at them and, and you're saying, so, so the cloud, huh? But, but it's so true.
Everything they said came back to the cloud and cloud infrastructure. And specifically in, in most cases, it came back to the challenges of dealing with this sort of proliferation of everything in the cloud. Essentially, it's become incredibly easy to spin up applications to spin up complicated web scale applications in the cloud.
And now people are starting to realize, wait a second, wait a second. We need this data protected. We need to watch for, um, bad actors who are trying to attack it.
We need to figure out ways of, uh, integrating that with, uh, other aspects of it. We need to get some control over this thing because it's just sprawling completely outta control. And there are incredible risks to that.
This sounds like the kind of thing we've been talking about here on Textron Gang for a long time. I know, Kimberly, you and I have talked about this, Mike, I know you've written about this, this whole challenge of things just getting outta hand in the cloud. I think that that resonates with y'all, right?
And, and I probably, I bet to Haiku, I wasn't, I didn't listen to the session with Haiku, but Haiku two years ago launched a big initiative to, to, um, enable protection of SaaS applications. You know, at that time we were still seeing a slow buildup of protection. com, but the rest of SaaS, those applications that you have running, and so many of the companies now, their core applications and their data is sitting in these SaaS environments.
And, you know, let's say your hr, HR information is up there, or your, you, your, um, ERP system is up there and you're thinking that that company is responsible for protecting your data. Well, Microsoft came out and said, no, we're not protecting 365. You want your data protected, you need to go do it.
And so all of a sudden there's this rash of stuff that was going on with there. And so, yes, I would understand that. It's, you know, it's about backing it up.
It's about protecting it, it's making sure that nobody can attack it. Um, so it does not, you know, and I think that had a rip had a, a ripple effect with some of the other SaaS firms to saying, no, I'm not gonna take that liability, that that's too big of a liability for me to, you know, be responsible for my company. What I'm doing is delivering an application.
I am not doing data protection on all the systems and security. I think that there were a couple of, there were, there were some outages about a year or so ago, a spade in them in the cloud, maybe two. And I think that made multi-cloud, uh, more real concepts in people's minds.
They realized they were overly dependent upon one service and they had a single point of failure. I feel like we've been talking about this subject for years, but I don't think many people were actually doing it until recent times. But that's just my sense of it.
So I, I think they have been, I think frankly, I think for the most part, the analyst community and the press missed the boat on multi-cloud. I think we were all very focused on hybrid cloud, private and public, but everyone thought you'd put all your eggs in one public hyperscaler, whether it's AWS or Microsoft or whoever, or Google or Oracle, whatever. But the reality is people pick the best tool for the job.
And so they put this over there, this, there, that, there, and there's more. But wait, there's more. Now we also have the edge, right?
And people are putting stuff on the edge, and they're putting some stuff that's gonna run on, on the endpoint and then still runs on the data center and private cloud and VMware versus not VMware, right? We, we truly do live in a multi-cloud, multi-home environment. You know, back in 1999, 2000, actually it was 2000.
I helped write a business plan for a company called Lattice Networks, L-A-T-I-S. And we envisioned based in Boulder Kim, and we envisioned a world where this happened. It was before contain modern containers and all of that, but we thought that applications and data would be distributed, and we, we raised some money for it, and it was a miserable failure of we pivoted and that Lattice Networks became still secure.
Mitchell, Ashley and I were two of the three co-founders, and that became still secure, uh, because we were way before its time. But that's exactly the world we live in today in a truly, truly distributed architecture. However, when it comes to the security of SaaS data, I, I have a bone per pick, right?
One of the, one of the premises, no pun intended, premises of security on the cloud is a partnership between the cloud provider and, and the user. Because I don't have access to all of that infrastructure. I cannot protect the infrastructure.
I probably can't protect anything below the OS in your average infrastructure is a service, right? I'm responsible for security above that. Amazon, AWS for one, has done a lot to give me visibility into that infrastructure security, but very little capability into that infrastructure.
And it's still my, uh, responsibility, right? Because ultimately it's still my data. And so I'm ultimately responsible.
It's a terrible thing to be responsible without capability. It's like rep, it's like taxation without representation, right? Same thing here goes for SaaS.
Now you look at Tech Truck, we don't really have any infrastructure. We're basically a SaaS company. Everything we use are SaaS.
I don't have a server closet. I don't have storage on S3 or something like that, that I know of. Um, but, you know, we use a lot of SaaS.
It's incumbent on those providers to make sure my data, right? Because when we get third party requests, I go back to my SaaS providers, I say, are you SOC 2 compliant? Are you, gimme your proof because your proof is my proof.
So, and I'll go so far as Microsoft too, right? That data for most of us is stored in OneDrive. When OneDrive has an issue, they could say they don't, they're not responsible until their president gets his a*****e in before Congress and says, me a culpa me a culpa, right?
Yeah. But the CSPs have never been responsible for your data protection. And I think Steven has got some commentary on that, some new products that are coming out.
But I mean, I've, I dealt with, 10 years ago, I dealt with the firm that had their data wiped out by the CSP and the CSP because of bad, bad practices on the data protection. And, but if you read the fine print, they are, they are not responsible unless there is malfeasance that's only, And it's Not even fine print. I Mean, have, that's just, yeah, it's, it's explicit.
I mean, they're available for high avail. They're responsible for availability, not even high availability. They're, you know, they, they, but, and immutability in some respects, but again, not even immutability, just sort of like, you know, yes, it's probably gonna be the right data.
They're not responsible for data protection. That's why companies like Haiku, like you said, are impressive because they can hit that. But to Alan's point as well, I mean, you know, it really is, companies are going to be using more than one cloud.
They're gonna be using more than one environment. And that's where some of these other companies come in. So, you know, Infoblox really impressed everybody because I mean, D-D-N-S-D-H-C-P and IP address management is super boring.
It is the most boring subject in the world, but it's also the most important subject in the world when you have this proliferation of, of automatically spun up machines that are just populating the world out there. And, and Infoblox showed that they can really do a, a, a great job of that in modern cloud environments. You know, the same is true, um, with, uh, for example, Catchpoint, they came in and they were talking about basically, you know, you can't control if, um, AWS goes down or if, uh, you know, uh, the, some infrastructure element in the internet goes down.
But it's a really good idea to monitor and manage that. Because again, you know, you can say, you can throw up your hands and say, oh, these SaaS providers should be responsible for their own stuff. They should be responsible for availability for data protection, but they're ultimately not.
And ultimately, if it fails, it's your problem, not their problem, because you're the one that was running your application there. And so you need to know if the infrastructure is running, you need to know if it's protected. You know, Fortinet was talking about, um, doing, uh, data protection of SaaS applications, uh, buckets and, um, AWS accounts with the wrong permissions and that sort of thing.
Again, it, it's real easy to set this stuff up wrong and end up exposing your information or having people take your stuff over. Um, you need to be able to jump in there and, and, and make sure that this stuff is configured correctly. 'cause your cloud service provider isn't just like, they're not responsible for data protection.
They're also not responsible for misconfiguration. And again, for real, uh, continuous availability and, and, and that sort of thing. They're, they're just not gonna do it.
And so you need these things, you know, you need something that's going to make sure that your network is configured properly, like Selector was talking about. You need something that is going to make sure that everything is gonna continue to run, because this is your infrastructure to Alan's point, this is your, this is my infrastructure and, and textron's and, and Futurum, we don't have a data center. We have the cloud.
And so it's, we have to, we have to apply the same concepts we would in the data center to the cloud. And I think there's two different areas that you need to be looking at. One is your infrastructure, if you're using the cloud as your infrastructure.
And the other one is if you're using a SaaS, both of those read the fine print because it will say that they're not responsible except for malfeasance. In essence, you read the fine print and then understand what you need to make sure that you protected whether or not, if you lose that data, what happens on a SaaS situation? If you lose your network, what happens?
And, um, so those are two different discussions, if you will. But related, Can I just clarify here? So are we actually saying that the phrase shared responsibility is not worth the contract it's written on?
Is that what we're basically saying? No, I don't think so. I think there is a shared responsibility, but there's a limit to how much they're sharing.
So understand what, what they are going to do. And if you want to have any more than that, then you need to have something there. I mean, understand it's, you know, trust but verify So that it's always been a shared responsibility, but the liability, the responsibility has always been on the end user.
That, and that, that it's been true in the cloud since day one. And, and really, you know, back in those days, what's the biggest inhibitor to more cloud adoption, cloud security, um, you know, that, that was the standard response we did here in the security world. Um, because the idea was I can't be responsible for what I can't control, right?
I can't do that. Now, I will tell you, you know, companies like Akamai, CloudFlare, both companies we've featured on Textron, CloudFlare, we do our last great cloud transformation with, we're a customer as well. Um, they try to offload some of that responsibility, if you will, right?
But ultimately, when the stuff hits the fan, you get left holding the back. That, that, that is absolutely true. And it, and, and then it becomes a question of trust.
Do you trust? 'cause these are your partners that SaaS provider's, your partner, that cloud provider's, your partner, do you trust them doing their job? And then what do you do about that?
Yeah. And there's this ugly word that I've always felt like is an ugly word called audits. And I know exactly, I cringe that.
I Thought they fired all those guys. Well, you know, I said, I was reading this book this weekend on cybersecurity. It's called Cyber Warfare and Peace.
Um, and he talked about, when he talked about the audits, he thinking about audits is what you are gonna use to expose where you have gaps. And that the goodness about audits is it's showing you where you may be. If, if you're talking, as I said, infrastructure, 20% of it's changing, where are my gaps?
What am I missing? So I want to have an audit basically to say, okay, here is my gap. I need to block it.
I need to take care of this. Um, so it's in a positive for the first time I'm thinking in a positive fashion about what an audit. I, I think that's, yeah, most people would rather 22 to the back of their head.
But, uh, anyway. Hey, we're over 15 minutes. We need to take a break on this one.
We're going to come back and revisit part two mm-hmm. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Welcome back to the Textron gang. Well, my report I've been talking about is finally published.
It was published, um, just last Wednesday, and we're getting some, uh, great feedback on it. com. And I wanted to focus now that the report is available to everyone, the the impact and takeaways specifically for IT practitioners since that is a, a big portion of our audience here on Techstrong tv.
So here's a little short video to show you some of the findings and, and where the impacts might be felt by those practitioners. Decisions that define executive strategies and innovations driving corporate sustainability highlights five major shifts, transforming IT infrastructure and reshaping operations. Power demands are rising.
Greater computing power requires more electricity pushing companies to adopt AI driven power management, liquid cooling and greener cloud regions to improve efficiency while easing pressure on resources, optimizing energy cuts costs moving from CPUs to GPUs can significantly lower consumption with some businesses reducing usage by up to 50%, turning efficiency into a financial advantage. Hardware is lasting longer. The standard four year replacement cycle is fading.
More companies are refurbishing, repurposing and designing infrastructure for longevity with some targeting, 75% circularity by 2030, reducing e-waste. Along the way, regulations are tightening. The eus corporate sustainability reporting directive is now in effect requiring affected companies to implement systems that track and disclose carbon emissions.
IT roles are evolving. Climate conscious technology is now a priority, yet the talent pool isn't keeping pace. Companies are working to close the gap through hiring and training initiatives.
Read decisions that define executive strategies and innovations driving corporate sustainability. com. It's been great getting feedback on this report to see what people are saying.
I recently had the chance to be on the Schwab network talking about it as well. And one of the innovations about it was talking about the AI energy use, sustainable investing. I think there's a lot of crossover into these findings, and I look forward to everyone checking out the report and, and IT practitioners that are watching us, please read it and I'd love to hear your feedback as well.
Yeah. You know, it's a, it's a great report. So what I find interesting is there are some people who hear sustainability and they, they immediately go political and, and all the stuff that's out there, but that's not what we want to talk about today.
I wanted to really focus on there are truly economic reasons to do sustainability, right? Right. To, to do these things and, um, give us, I mean, believe for instance, you had five sustainability shifts in IT odds, but talk about that Economic plea.
Yeah. It's really the economic reasons. Um, right.
And that's one something I talked about. It started off with, well, it'd be nice if we, we were more sustainable, let's get our emissions down to net zero. And those goals remain.
Of course, we hear about that all the time from big tech. But what we're finding is that, um, vendors and, and I actually looked at the startup dates for a lot of the companies that I talked to in the report, and many of them just were created within the past three to five years. So, uh, it's really kind of exciting to see the growth in this area.
And the ones that are newer are ones that create SaaS tools for IT teams, for different types of companies. It could be any industry to track and, uh, record their carbon data emissions and how to run their IT operations more efficiently. So that's when you start getting into cost savings.
And many companies are reporting success with savings because they are running things more efficiently. They have software that can tell them when to tap into renewable energy as a resource. One of the ones I talked about for, uh, cloud regions to pick a provider.
That's where the, where it's located in the case of platform SH located in Quebec because they're relying on hydropower. So there are, there is an ROI factor that's now being able to be quantified, uh, that I really get into in the report. And I think it's important because we've talked about sustainability quite a bit on Textron gang, and it's always the same.
Well, unless it's, if it's not kind cost more, no, but if it saves us money, okay, we're open. And I think we've crossed over to that point based on the data that we're seeing. Fair enough.
Kimberly, can I draw a line between the amount of energy being generated or consumed than the actual cost? I mean, is it that linear or, or is it more like a barometer that tells me that my costs are going up, but I can't really track it that granularly? It's definitely something that's not linear.
And I think Microsoft is finding that as well, because, um, their chief sustainability officer recently put out, um, a statement about it that, you know, when it comes to what the goals are and then all of a sudden the use of AI things, things are sh things can shift. So, uh, many companies are doing offset credits for carbon to try to, to reach their goals. Um, it, it's a little bit of calculating how much energy is gonna be used, how much can renewable energy can we use, and then is it available?
And that's something that's, that's being decided now. And then of course, we talked also about on the show about nuclear energy as another option. Now I look at sustainability as way, way beyond the energy piece of it.
Sustainability to me is what we're putting into, um, you know, waste and how do we recycle that? Um, and recycling, you know, it's kind of like here at our lab here, we had a company come in and cart away probably close to 800 pounds of old gear, um, that they were all gonna take a part and, and recycle and recycle the metals, recycle whatever, and how it goes. So that does not go into, you know, the, the trash bin, um, company, I believe it's Mar Valve that the re re um, using their CXL technology and deploying it.
So CXL, which enables you to, um, pool memory. And they've designed it, and I think it's Amazon is picking it up in order to recycle their DDR, their older DDR is gonna go into this CXL technology. It's gonna go into the slower processors that they have.
But instead of jetting the DDR r you know, going directly to DDR five, you can actually have this pool. And that's good enough for certain applications. So some unique areas of different kinds of sustainability that go into definitely, you know, what you're talking about.
But that, that is huge thing, right? You know, Bonnie and I are down here in Florida. Florida is a notoriously plastic civilization, especially South Florida where we live.
You know, everything gets basically redone every seven years or so. They, you just tear down stuff and build new and, um, and it's so wasteful because especially in, in tech, especially just because you don't have an iPhone 16 doesn't make your iPhone 14 or 13. There are people around the world that would give their right arm mm-hmm.
For an iPhone 13. But our society, you know, I don't know if I want to do the Apple trade in, I'll just leave it here in my drawer 'cause they're only going to gimme $99 or whatever it is. And, and so we're, we're incredibly wasteful to, to that point.
And then how much of it a year or two later goes from the drawer, Kimberly, to your point, right into the garbage bin, which then winds up in some public landfill, right? Where those are good parts that should be recycled and, and they're toxic to boot to put 'em in the waste in the landfill. Yeah.
One of the companies, um, human IT that's featured in my report is really incredible outta California. They take all of companies, uh, unused phones or, or, uh, works laptops that they're not using, and they find veterans and families in need who need them, refurbish them and at a much lower price provide them for, for schools. And, and the success has been phenomenal.
And just the appreciation as you were saying, you know, those kids are thrilled to have LA any laptop. So Sure. It's really, um, it's, it's really, I think it's one of the things that's happening in HP also is doing that with Renew Solutions, very successful program where they military grade testing to make sure whatever they're selling reselling is, you know, functioning perfectly.
So, um, and I think that's gonna move and we're gonna see continuing because it 'cause it is profitable and it's also helping people too. Excellent. Excellent.
All right guys, if that's it, I'd like to call a wrap on this version of the Techron Gang. Couple of announcements. First of all, we, we made reference of the, uh, tech field day report that happened, I guess last week.
Uh, cloud Tech Field Day report. Of course, all of those videos are available. I believe they're on techron tv and they're also on the Tech Field Day YouTube channel.
So for anything that we were talking about, if it piqued your interest, go check it out. com. com.
You could download that. That's pretty cool. Um, Kimberly Infrastructure matters.
You mentioned, you know, this is something we're gonna start featuring more on Techstrong. Actually I have a, uh, this week I have my very first interview with Ryan Stroud from, uh, signal six five Lab. We're gonna be featuring the lab a lot more on Techstrong and some of the great work they're doing in the reports that are available.
You don't even have to register for them. They're free to just go download and have a look at, which is great. Yeah.
And they're doing some really cool stuff. Like I'm on their channel, their back channel, and all the conversation that goes around the testing. So it's, it's pretty cool things that they're, they're learning, um, you know, through the process of what all they're doing.
And I believe there's a report coming out on Intel Granite, which will be fascinating To you. Ibm, bm, Granite, I bm, Intel, IBM, granite, and then Intel's what other GPU it is name A, a something. Yes, we, we are gonna, there's three reports that Ryan and I are gonna hit over the next week or two.
Great. Um, so that'll be great. And in the meantime, we'll just keep rocking and rolling.
Everyone, thank you for joining us today. Stay tuned for the rest of Text Drunk tv. It's probably another two, three hours at least of content today.
And of course, you could also just check stuff out on Text Drunk tv, our Text Drunk tv, YouTube channel, or any of our 8, 9, 10, 12, whatever sites that we're running here at Text Drunk. Until then, though, everyone, this is Alan Shimel, we're outta here. This is Textron tv.
Hey, every, This is Textron tv. Hi everyone, it's Alan Shimel here for another TechOne TV interview. I wanna introduce you all to Chris Gibson.
Chris Gibson the CEO of first, the Forum of Incident Response and Security Teams. We'll go find out more about that in a minute. First, let's say hi and welcome Chris.
Hey Chris, welcome to Techstrong tv. Thank you. Alan's it.
Great to be here. Fantastic. So, Chris, before we get into, first, let's hear more about Chris.
How, how did you come to be the CEO here? So my first job when I left my education, I went and dropped bits of explosives down holes in Saudi Arabia. I, I worked in a seismic company, really, that got pretty boring pretty fast.
And I moved into technology. I worked in a bank for a number of years. I moved into Citibank, I bounced around Eastern Europe, upgrading and installing banking systems, and then moved into cities, information security proper under Steve Katz, who was the sort of the world's first CISO back in 99.
I think that was, um, spent a number of years there then running their incident response and their forensics gang globally supporting investigations and actually running the incident response team for a portion of that time. Uh, then I moved into civil service in the UK cert. The government here decided to set up a national cert for the first time.
They had the pieces in place already, but there was no single entity that was a national cert. So I jumped across to them and spent three years building and running the, the UK's first formally chartered national cert, which was a joy, absolute joy. Uh, if you're gonna do incident response, do it for a country because that's when it gets really interesting.
Oh, I'm sure. And then A little bit of private sector. And then this opportunity at first came up.
Now I'd already known first Citi was a member of, first we were, I was their representative to the, to the organization. I'd been on their board, I'd been their CFO, I'd been the chair for a couple of years. And then the opportunity came up to work for them.
First had moved, was moving from a volunteer led organization, purely volunteers with, with a number of contracted services, but run by volunteers to a point where they wanted to professionalize and bring someone whose job it was to do this. So I got paid to do what I used to volunteer to do, which is just the joy. Can't think of anything better.
Been here about six years now, and it's about building first stuff into, you know, properly global meeting, the vision and mission statements that we have. Excellent. Excellent.
You know, it's funny, I, uh, I used to, uh, have a, I co-founded a cyber firm and I remember Citi in those days. You know, it wasn't Citi, it was Citigroup. Yep.
I think it might have still been, I don't know if it was Citibank city Banks. I think it was Citigroup, Citi Group. Citi, Yeah.
No, I used to work with, um, I don't know if you ever, they had three global CIOs back then kind of thing. Right. And one of them was a fellow named Peter Fisher.
Yeah. Uh, outta New York. And I remember talking to Peter, we were trying to get our vulnerability management product tested there, you know, and this is in the days now, Microsoft's starting to do, uh, patch Tuesdays and all that.
And you know, but Citi, it, it's, if you put out a patch on a Tuesday, it was 90 days or so or more Absolutely. Until they Yep. Applied it.
But interesting times, interesting times. So it sounds like first those been around since those times, though. Give us a little, Chris, give us a little first background.
So, First started in 1990, after the very first worms. Um, cert CC was formed in 19 19 90, after the Maurice Worm. A year or so later, there was another fairly destructive worm and people on the internet, you know, the internet, there's no control.
No one is in charge of the internet. It's all little islands of systems that talk to each other and sort of know where to go. So nobody knew how to deal with these incidents.
There was no one place to central place to go to. So essentially an informal forum of teams grew, grew together, primarily US based, and worked out, you know, if I have a problem, this is the guy I'm gonna talk to at that place, and this is the guy I'm gonna talk to. And this is his strong point, and this is my strong point.
Forced forward, move forward five years, we set up as a formal organization. So we've been a legally, you know, proper organization since 1995. We've now grown to 760 odd teams in 111 countries.
And our vision is that when there's a problem on the internet, you can go the formal route of, go to your law enforcement, go up the chain, go across to another country, come down the chain. It just takes too long. We all know that when worms hit, when viruses hit, you know, they can bring the internet down in, in seconds, minutes, hours.
There's not the time to go through that formal process. So we believe in bringing teams together, building that network of trust, such that if I have a problem in Country X, I know someone in that country, I've been there, or I've met them at a conference, or I've done training with them, I can talk to them and get stuff done while we go through the formal process, we accept that's not a scalable option that works now, but we need to fix that. So we also get involved in standards, we get involved in, in building systems that talk to each other and so on.
It's all about improving the art of incident response. We know we're gonna get hacked at some point. Everybody will have a problem at some point.
So let's prepare for that. Let's be ready for that, and let's actually be able to deal with that fast. That's amazing.
That's great stuff. I've, I, I have to confess, I've been in security 25 years plus and probably close to 30. And I, I'm not FI was not familiar with first, so now I am.
So you at least you converted one person. That's, that's great. I think the challenge is the years we tried to defend our way out of this problem, you know, we build a better firewall, build a better system, build a better list.
Now we've got to that, you know what, we're gonna have incidents and, and central banks. No. That, that, so I saw that starting to take place in maybe 2010 to 12.
Yes. The shift from prevention to, to response. Yes.
Right. It used to be 80, 85% prevention, 10, 15% response. I'm not saying it's 50 50 today, but it it's certainly not 85 15, which is a big, big change.
Big change. And I, I wanna jump into our topic of discussion, but before I get there, what, what's the website for first, Chris? It's Very simple.
org. That's it. Dot org.
F-I-R-S-D. Yeah. And like a footprint at industry shows or anything like that where people can Change?
So typically, yeah, typically not. We've always, because we believe in building this network of trust and whatever, we don't go out and do advertising. We don't go out and do marketing drives.
Essentially, we grow organically. So someone meets someone from first we talk about it, they say, that sounds interesting. They come to a conference, they join.
It's been very much based on that. We grow about 10% a year. So we grew from the original 15 to now of 770 odd teams, as I say, 111 countries.
But we've never wanted to just, you know, it's not a pay to play. If you don't sign a check and join, you've gotta be, you've gotta be accepted in. You have to be sponsored in by an existing team.
It's all about building that tr network of trust. And The king's been, uh, just kidding. Um, but that, that, that's interesting.
You mentioned the conference, though. It is their first conferences. So we run An annual conference.
We take it around the world. Uh, last year was in FKA Japan. We had 997 people attending thou from 96 countries.
So it's getting big. It's a full week. This year is Copenhagen.
Next year will be Denver, Colorado. We'll see where we go after that. So yes, so that's the big one.
But then we also do local, more regional events with local, um, partners. We do training events with the ITU. We do training events to do capacity building.
We have funding from the UK government to do stuff in Africa. We're all, it's, it's about building communities around the world through those training, through those events, bringing people together so they can work together, talk together, and learn to trust again, we're back to that trust. Absolutely.
Alright, Chris, if you don't mind, I want to kind of segue, turn to our topic of discussion, which today is all about securing data in 2025. Right. You know, we'd all love to live in a world where everything's a green field, it's all shiny and new, and we get the latest and greatest.
Of course, that 80 20 rule applies to that too. 80% of what we work on, or more even, it's not greenfield, it's brown, muddy fields, and you've got legacies and, and obsolete stuff, and a good mixture of, you know, just a mishmash of everything securing data in 2025. Chris, where do we go there?
So I guess fundamentally the challenge is, is the first step to any of this is identifying what you've got, where it is, and how much you value it. I mean, none of this is rocket science. None of this is new.
You and I would've talked about this with peers for many years about that base level cyber hygiene. What have you got? What do you care about?
Wow. You securing it. That's always been the challenge.
When I look back at my time at certain uk, you know, we ran, most of the cases, we ran, most of the incidents should just never have happened. They were, they were bad passwords. They were bad kit, they were unpatched, they were the usual litany of stories that we've heard many, many times, which is my frustration, you know, if we could persuade people to do that really well, we would solve a lot of the problems we have.
But it is, it's that not knowing what's there. So I can think of, you know, significant incidents where there was a server, it was somewhere over there, they forgot about it, it wasn't on the radar. Someone found it and booked and they got, and all their high tech kit that they had, you know, really well secured, was just broken by this weak link.
That's always been my prime take, just identification. I, I, I say it, you know how I always enunciate is you can't defend what you don't know you have. Absolutely.
Absolutely. Yep. But, you know, I tell you, Chris, and I'm glad you you're odd today because I, I had a conversation this morning with a few people about the idea of who's responsible for securing data in SaaS applications, right?
So many of us today, and not just as individuals, these, even within organizations, you know, everything's in the cloud. We don't have data centers. We don't have, you know, we're using all SaaS AppSec.
Those SaaS AppSec store a heck of a lot of our data, a lot of it. Mm-hmm. But when you read the fine print, they're not really responsible for that data.
We're still responsible for it. Obviously, it's our data, but yet we really don't have total control. So it's a, it's like this is the old taxation without representation.
I know You can't say that. Well, I, I remember going to the tower one year on a, on a, on a, a, you know, a terrorist trip and, and the, uh, you know, the, the, the ISTs, I think that who works at the tower, you know, they're in the uniform and everything. Yep, yep.
Yeah. The V feeders, they said, yeah, I had you yanks paid your taxes, you'd have a piece of this too. But, um, but anyway, you know, it, it's a funny thing.
How can we be responsible for data that we don't necessarily have full control over? And, and to me, I think this is going to be an issue. It has been an issue, but it's gonna be a bigger issue.
Couldn't agree more. It's a real challenge that we face. I believe, you know, when I look at most small, medium enterprises can't afford to have a fully functioning incident, you know, security team, let alone an incident response team.
You know, schools, small, medium enterprises, charities, nonprofits, they're lean and meaner. They don't have that time. So we would normally, I would say, move it into the cloud because then you are, you're part of a bigger thing that hopefully and normally has, you know, sophisticated people looking at it, making sure that it's all secure.
But you're right, when it all goes wrong, the blame will still come back to you, whether you like it or not. That's a challenge there, isn't it? There's that blame culture that we have that anyone who gets hacked, it's their fault, which, which is still, still ongoing and is still many cases wrong.
Um, but, but, but it's not the bad guy. You know, if someone breaks into your house and steals something, people don't tend to bring the homeowner. They blame the bad guy who turned up and did it.
But that's just the way we are today. It's the way we roll. It's not a good thing.
I, I think you're right. How do we, how do we secure that data? We need to understand what we've got.
But again, small, medium enterprise, the IT guys probably, you know, it's 50% of his job because he's doing other stuff. We roll into this, we want, you know, faster development, better applications. We want faster to market.
We want to be, you know, leading edge and all the rest of it. Every one of those things is an absolute challenge when you're trying to slowly make sure you understand what you've got, where it is, who owns it, what you care about, it's, it, I don't have an answer. There is no answer.
I don't believe. No. I, I, I don't have an answer either.
I I also feel like, you know, the trains left the station. We're not gonna take our stuff off of the cloud or off of SaaS. But I think that ability to have an incident response process that, or, you know, at least a plan, at least you've thought about it, you've table topped it.
Maybe with the senior management, they know what they're gonna do when it goes wrong. That's, that typically is what we see now is, you know, central banks and whatever are not saying you can't have an incident. It's how well you recover from that incident.
And it's your ability to take your, you know, your public, your customers, your staff with you to make sure that you are not looking, you know, like an idiot. Because we've all seen incidents where they've not gone well. They've been a train wreck.
Sure. So, Chris, let me pivot a little bit to related kinda thing. I, I, I, uh, I did a, a YouTube, short LinkedIn live thing a couple weeks ago on what I call it sovereignty, right?
For a long time in the cloud, we've had this concept of data sovereignty, right? I want my data stored within, in a data center within the borders of my country, or these, what I consider friendly or secure countries, or well understood countries or what have you. And, and cloud providers have spun up all kinds of, you know, data sovereign type of clouds where, where people can do that.
It seems unfortunately that we're entering into an age where this is gonna extend maybe even beyond data to it in general, right? I only want to use it that was born and read and, and, you know, made here. 'cause I don't trust it or I just, political reasons, whatever.
I don't want to use non native meaning, you know, native to my sovereign, to me, this is gonna be a huge, it's just a cluster to tell you the truth, right? How do we, how do we, how do we plan for that in terms of incident responses and everything else? It always feels as though we're going back to the days of data.
If, of our own data sectors, you know, we want it closer and closer to home. We want to understand everything that's in there. We want it to be only, you know, maybe poten, potentially, you know, our data on that bit of kit, no one else is.
Yeah. So no one has access to those drives and so on. That feels like we're going back to the days of, you know, big data centers and IBM and, and all the other things, which, you know, maybe that's the way forward.
Um, again, we're back to that identification, aren't we? What is it? Where is it?
Who's got ac, who's got access to it? If you're on a, you know, multi hosted system with multiple people coming in and accessing bits of that data, well, if someone hacks, breaks into their systems, does that give them access to yours? So just understanding that, that's hugely complex for any organization, let alone a small, you know, back to the small medium enterprises, the charities, the nonprofits, most of the people who are, you know, generating the wealth for our countries, they don't have those people.
That's again, it, it's a huge, huge challenge. Again, I would say back to the incident response. Yeah.
If you may not understand that, but at least have a plan, have a table talk, think about who you're gonna talk to, how it's gonna work, so that you can have a response to that. You're not caught flatfooted. Yep.
I, I, I do agree. And I think, you know, it, it sounds so simple, but it's been so true for all the years I'm in security stuff is gonna happen. Yep.
Right? Yep. Stuff happens.
It's having a plan for when stuff happens that separates success from failure. Right? A lot of a for too long.
You know, we used to say, if nothing happens, you did your job in security, right? How often have you heard that, Chris? Over the years, right?
When security's good, nothing happens. But we now know you could have good security and still stuff happens, but it's how you respond. That kind of is really, at the end of the day, the, the, the line of, of whether you're successful or not.
And, you know, I guess that's what first is all about at that level, right? That is absolutely what we do. We bring people together to talk to each other, to learn from each other, to give presentations, to do training, to run exercises to help each other get better at what we do.
Our mission statement talks about, you know, making the internet a safer place. And we do that by try. It's like we, we consider ourselves firefighters.
We're there to put out the fires. We're not there to solve the problems, although clearly there's a feedback loop just in the way that firefighters do. But we consider, we there to just keep the internet up running stable so that you and I can do all the things we want to do.
We can bank, we can shop, we can talk to our friends, we can chat. We can do all those things online. Confident that the internet is a reasonably safe place to do that.
Agreed. Chris, one last question 'cause we're over time. Um, you, you basically have to get sponsored in, but for people watching this who may want to, you know, have their organization, their team mm-hmm.
Become affiliated or learn more about first what, what's your best advice to them? Best, best, best advice. Come to the conference, come to an event, see what we do, see how well, how well I think we do it.
You know, really do that. Alternatively, drop, drop a line. There's, there are contact pages on the, on the website.
You know, we will work with people with more than happy to have conversations and introduce them to folks. But coming to the conference, meeting people, building those relationships such that there will be teams to sponsor you, that's, that's the best way of doing it. I love it.
Chris, keep up the great work. Thanks for you coming on here, evangelizing, telling us about first appreciate it and, and best of luck. Okay.
No, thank you very much. It's been a pleasure. I enjoyed it greatly Love to have you back on Chris Gibson, CEO of first forum for incident response and security teams here on Tech Drunk tv.
We're gonna take a break. We'll be back in a moment. Hello and welcome to the latest edition of the Textron AI series.
I'm your host, Mike Baard today with Christian Lau, who is chief product Officer for Dynamo ai. And we're talking about, well, now that we've all kind of gotten our heads wrapped around ai, the hard work really begins. We gotta gotta deploy this and manage it and govern it and secure it.
Christian, welcome to the show. Great to be here. Thanks, Mike.
What are you hearing from folks in terms of what their challenges are? I feel we went from couple of, maybe 18 months ago, a lot of irrational exuberance to a lot of experimentation. And now I think folks are kind of trying to figure out, well, how do we, uh, deploy AI into a production system?
Yeah, I think when you look back 18 months ago when this new technology was coming out, uh, there were a lot of questions about what is the, what are the risks that we even need to account for? When you have a chat bot that can basically act like a human being, you can prompt it in infinitely different ways, and it can output, you know, many different things. It's, it's, uh, what we call like an unbounded space of a possibility is that you can prompt, you know, and so, uh, to a lot of our customers that we work with that are in more regulated sectors, like say the financial services sector or the federal or DOD sector, you have a lot of questions about how you apply existing, for example, model risk management to this new technology.
And I would say over the past 18 months, you saw a lot of progress here because in order to actually deploy this into production, not only you to get the technology to work, but you also have to prove to many stakeholders across the organization that this is a technology that's gonna be secure and compliant when you actually deploy it, right? And it's gonna, uh, you know, not harm your end users or harm your company's reputation. And so that's kind of been a, a big focus that, that we've, uh, assisted many enterprises with, is how can you generate evidence that you've properly managed the risk associated with the technology?
And that's really the first step to, to unlocking the true value of all the amazing work that's being done at the found foundation model LA layer and application layer we're seeing today. Um, that, that's kind of like a, what, what we're commonly seeing across our customer base. How do I govern all that?
And I'm asking the question because AI models are subject to drift. And so I may finally build one and deploy one, but it may not be acting as expected, you know, nine months after I've deployed it. And as far as I can tell, it is not like traditional software where I just apply a patch and update it.
I've gotta kinda, uh, for lack of a better phrase, rip and replace. But, um, how do I kind of wrap my head around that workflow? That, that's totally right and kind of dive a little bit deeper into that problem.
There's different aspects to this, right? So when you look at the underlying what's underneath the hood of most of these AI applications, you might find that there's a rag vector database attached to it. Uh, you might find that the large language model might actually be swapped out at different points of time, might be updated by your foundation model provider, um, or it might be dynamically switching.
And so all these things really affect the drift of these models and their, uh, ultimate performance, right? And so it's really important that as time goes by, you implement two sets of controls that we recommend to, to, uh, enterprises we work with. One is doing repeated and very custom and tailored evaluations of your AI systems, of your models, uh, even behind the scenes, right?
Uh, so this means that running, you want to run a repeated test when the newest model comes out, are you gonna be able to run an evaluation, not just the general benchmarks, uh, but also benchmarks are gonna be tied to the specific use cases that you care about. Because a lot of times you'll, you'll find that the latest and greatest model that comes out maybe really great at coding, but it might actually be worse at, for example, writing the types of reports that your particular use case calls for. So you want to build these customized evaluations that kind of run in an automated way in a, in a and a repeated way.
And, and we will give you consistent, we'll check if your, your model is giving you consistent results, right? So that's a kind of one side, these types of offline evaluations. But the second part that you wanna implement is real time monitoring and observability, right?
And this is where we really start to see now these AI systems, these, uh, you know, these models actually become products in themselves. And you want to apply, you know, as I'm, I'm I, I lead the product team at Dynamo, you wanna apply those same principles of product management, of, of gathering analytics on utilization, where things are failing, um, what type of questions users are asking and queries user are asking. You want to collect that type of analytics and build in those customized flags.
And so we have these real time detectors, for example, classifiers that we build for our customers, and that they can customize that will go and actually find, okay, was there a 80% of of your LLM outputs refusing the end user's, uh, UL ultimate question, right? And or is there a new type of question that's being asked from end users that your model wasn't prepared to answer for? And so now I need to go into my vector store and populate it with more information, or I need to figure out a better way for, for the model to retrieve that type of information if it's already in there.
So it's a constant kind of monitoring of your AI system and really looking at it from a product point of view, uh, and, and getting the information you need in order to make, you know, adjustments to continue to have consistent performance. There's an old wag that says, um, you know, it's one thing to be wrong, it's another thing to be wrong at scale. Yeah.
Um, With this AI approach, we're seeing multiple LLMs and hec, there's even now small language models in the mix, and then there's all these AI agents and they're all interacting with each other alongside of humans. So how do I keep track of whether or not something is actually performing as intended, or, um, is that just kind of, I have to wait for somebody to kind of discover it and send me a nasty note or something? Yeah, And I, I think, so that's, that's a fantastic question, right?
Um, how do I know if the model or the AI system the product is, is performing as it's intended? And I think the key part of that sentence is as intended, but what does it mean to be, uh, to what, what, what do you, what's the intention behind deploying this AI system? What is the user going to extract the most value for really defining your use case and what does success look like, right?
And that's actually gonna be customized for each different organization, how they view success, right? How they view is this AI system being used for its intended purposes. Um, and so like, I think this kind of goes back to that benchmarking or evaluation type of question, is each enterprise actually has a custom kind of definition of what they view as success for their use case, right?
Maybe you want to, you're in a highly regulated sector and you wanna be really careful about the types of questions that you answer. You wanna make sure you answer it in a very compliant way. We have a, a customer, for example, that defines a very unique term in the financial services sector, a certain way that the model doesn't actually refer to it in that correct context, that's considered a hallucination, or that's considered a failure mode, right?
But that's really specific to that particular customer. Or maybe you're generat generating reports and it has to follow a certain style or include certain set of references, uh, uh, et cetera, right? That's the key thing, is to define what is your, what is success?
And then build in very robust and repeatable testing for you to monitor. Is the model being able to, to, or the AI system able to meet that, that definition of success? And a key thing here is we do see it today across, you know, solutions, uh, not a lot of capabilities that are provided to the end users, the enterprises, for them to actually define success according to the very, very specific requirements.
You'll see, you know, when the, the newest, uh, foundation model comes out, people are constantly benchmarking it on coding tasks on multiple choice faster, they're giving at the lsat, et cetera. But is this actually relevant to the intended use of your particular use case, right? Maybe it's really good at, um, ACE in the lsat, but maybe it's really poor at debugging your code, right?
Uh, or, or generating your particular, you know, uh, transforming cobalt code to, to, to python code, right? Um, so, so you wanna make sure that whatever you're evaluating, you're, you're, you're explaining what is the intended behavior of the system and measuring against that. One of the challenges that I hear about is that, well, the gen AI is probabilistic in nature, and it doesn't always do the same thing the same way every time.
And a lot of the business processes that we're kind of trying to apply it to, or shall we say, deterministic, and people expect them to be done the same way every time. Um, so where do we kind of figure out it makes the most sense to apply a gen AI model to what kinds of tasks that are actually gonna, um, augment a process rather than, I don't know, break it? Yeah.
So, so there are certain parameters that you can play around with to try to get more deterministic about this. You know, there's determinism, there's also explainability. These models, models may never really ever become truly explainable, uh, to the level that, that people hope they, they would be, right?
Uh, because if you can truly explain it, maybe you can have a more deterministic model, but let's take the determinism kind of point, um, you, so you can, you know, adjust the temperature to, to adjust for your particular use cases. In some cases, they're gonna want the more creative model, and those are the applications personally that I'm really, really excited about, is like, if you prompt the model multiple times, it's actually gonna give you new ideas of potential ways of reframing the problem, right? And it's gonna be more creative and expand our creativity.
I think generative AI has enormous opportunities in that space, but then generative AI also has opportunities in spaces where there's highly repeatable tasks, and you just need to get it right and have the right formula for how you do this. And that formula could be pretty dynamic and, you know, maybe rule space, it, it may be more com complicated, but you wanna have that repeatability, um, and, and robustness built into your system. And so there's kind of a, a number of things that you want to do if that's the case.
If, if you want to have a more deterministic and robust model, A, you can adjust the parameters of your model and make sure you have greater control over the setup of your AI system. You can't always do this with, with every model or with every AI system, but you also want to have, again, those constant checks and controls, right? So if some folks call this guardrails, uh, that's, that's what we refer them to, but you wanna be able to constantly monitor the AI system.
And this monitoring can become really challenging as you go to scale, as you have, you know, in some many cases we have customers with millions of queries every single day that their system is being hit with. So you need to build an automation to automatically check the behavior of the, a AI system and flag. If, say, you have agen workflow, that's kind of going outta control.
Uh, the, the agents are, are kind of, you know, spiraling outta control. You want to be able to flag that type of bent and have a, a human review. But you need to do this really, really efficiently because these, these AI systems today are scaling to huge, huge, huge workloads and volumes.
And so you need to have a system that's gonna automatically flag when, when things are going awry and things are not going as you expected, right? That, that non-determinism is really showing, uh, its space. And, and you want to be able to efficiently triage that and have it reviewed by humans When I, you can't manage or govern that, which you cannot see.
So how do I get the observability level that's required? I mean, we have observability in DevOps types of workflows, but I'm not sure we have observability around MLOps and these AI deployment models yet, or is that kind of where we're headed? Yeah, uh, definitely I, that, that, that's where we're headed, right?
And so, um, you know, it's a little easier for these homegrown solutions that are building off of, say, you know, the, the standard list of foundation models. Um, and they're kind of composing their own vector database together and, and, and building this from scratch, right? It's a little more challenging to implement the observability.
Now when you have all your different vendor applications that you're using for, let's say, like, you know, SaaS applications or your document processor, et cetera, that are now integrating AI features into those products, right? So I think your CRM think about your, your, your document processor, um, you know, even your, your, your browser, et cetera, might all have AI capabilities built into it now, right? And that becomes much more difficult to extend observability.
And, you know, we talk to CISO all day every day, and their big concern is they don't wanna look at 30 different dashboards across different applications and try to hunt out for where there's, uh, basically shadow ai, uh, being implemented across the organization and, and vendor solutions that updated with a new co-pilot in their last patch release, right? So what we've actually found to be really effective is actually a lot of these solutions, these vendor solutions are being operate to the browser. Um, we personally built a browser application so that you can go and plug in, uh, your guardrails and your observability across all these different vendor solutions and then have a single pane of blast to view this.
So this is something that, you know, we realized was a problem. Uh, uh, many of, uh, of the folks that we talked to, uh, were, were very worried that they were not having control over those vendor solutions that they were bringing in house, but they wanted to see all the LM inferences that were going through there. If there was a user that was violating their, their company policies, but they were using a CRMs copilot, um, they want to have that visibility into that application as well.
To your point, we've always had trouble trying to manage all the dependencies that exist within our existing software. Is that about to become exponentially more challenging in this AI era? I think there's definitely going to be, uh, additional dependencies that, that you have to look out for, right?
Um, there's a lot of creative approaches that are, um, are coming out today. Uh, so, you know, one of our, our partners that's just, uh, a notebook, OEM, uh, you know, launching, uh, different capabilities that can embed a lot of these actually out of box on your laptop device, uh, and, and have kind of, uh, actually, uh, an, an agent that goes and, and scans through, uh, the LM interactions and make sure that, that they're being guardrail and observed, right? Um, so there's, there's different creative ways, uh, actually leveraging AI to, to make it more scalable to do this type of work.
But certainly, I, uh, you know, uh, I'd be remiss to say that, that there is a new ecosystem of, uh, kind of products and components that are coming together that enterprises need to be prepared for, uh, and, and integrate them together, right? They really, I think one of the, the key things here is the more that we can get the enterprise to, uh, or, or build a product rather, or a solution for enterprises to have a single pane of glass, uh, across all the applications for managing governance, for managing observability, the better these enterprise is gonna be. Uh, but you do see, you know, um, different kind of platforms emerge around different hyperscalers, et cetera, uh, that they're integrating a lot of these opportunities, uh, but it's hard to bridge this across cloud environments as well in a kind of multi-cloud strategy.
And so you want something that, that can kind of, um, uh, uh, reach out to all these different components and, and kind of integrate them into a single place. So will we eventually wind up creating AI models and AI agents to govern AI models? And we're gonna rely a little bit on AI to manage the ai?
Is that where this might wind up? I believe there's gonna be a big component of that, right? And especially for regulated industries, there's always going to have to be human in the loop with this, right?
Um, and, and this sounds like a new idea, but actually, if you look at some of these really heavily regulated industries like financial services, they've actually to some extent been doing this for, for quite some time. You'll look at anti-money laundering, uh, su suspicious activity reports, right? Or in the fraud space, there's a first wave of automation that comes in here that goes and tries to find the suspicious activity and then flag that suspicious activity for a human in the loop to review, right?
Uh, and, and it's all about how good your automation is, how trustworthy your automation is, and you do have to continuously evaluate whatever tools are, are being used as at that, at that automation layer. Um, uh, frequently people call this, uh, space, you know, uh, LLM as a judge. So, you know, LLM judging the outputs of another large language model, right?
And, and potentially correcting those outputs or flagging or non-compliance or failure modes for hallucinations, et cetera. And that is a necessary component, I believe, for this to scale, uh, practically, right? But you do need to build people, people shouldn't forget, I think too many companies, frankly, forget about the second component here, which is building the workflow for the human in the loop to do the forensic analysis they need on top of all that enriched n and metadata that the LLM judge is generating.
'cause at the end of the day, that LLM judge shouldn't be the final say. It should be really enriching the metadata and distilling down the problems for the human loop, right? Um, and, and, um, so that, that's, that's really how, how we see this kind of rollout.
And again, a lot of the folks that we work with, the enterprises, they're hitting massive production scale today, uh, with hundreds of billions of tokens every year, right? So having a, a team of human reviewers go in and, and monitor these, these ls, uh, just simply is, is never going to fly. You do need to use the power of alums, the, to scale this kind of observability, uh, and what we call case management, but you also need to build the infrastructure to effectively manage those cases, right?
And generate cases and be useful and relevant to, uh, the, the subject matter expert or the cybersecurity professional who will be doing the, the further investigation. So what's the one thing you see organizations doing that, you know, still makes you shake your head a little bit and go, folks, we need to be a little smarter than that. Well, I, I think, um, most enterprises that we talk to today are, um, still very much at trying to figure out their overall governance, like how they're gonna set up, uh, uh, the, the, the governing structure for a o And this might include, um, you know, what is the role of the ciso?
What is the role of, uh, model risk management? What is the role of the product owners and the business line owners, and the CIO, the generated AI platform owners, right? We see a lot of debate across the board at, you know, I, I wouldn't say there's a, a one size fit all solution, uh, to, to, to solving this, but we see a lot of debate across enterprises that, that we talked to about how to properly set this up, which stakeholders should be in charge of monitoring, or let's say, let's say, of, uh, of, of implementing and defining guardrail.
Should it be legal? Should it be cyber? Should it be compliance?
Should it be the product owners? Should it be a mix of all those, right? And what we find is that those organizations that kinda speed ahead without figuring out this governance structure, ultimately run into bottlenecks down the road, right?
They ultimately will have a showstopper where they're like, we don't know. It's not a, that this problem can't be technically solved. Let's say there's, um, certain level, uh, let's say that, you know, uh, certain, uh, uh, stakeholders within an organization are not comfortable with productionizing a use case yet until there's more controls.
Well, who, who's responsible for building those controls? Is it the product owner or is the, the CISO who's supposed to be recommending those controls? The more that organizations can understand how to set up their governing structure and which stakeholders are responsible for these roles, and, and build really a robust process for productionizing these solutions, the better these enterprises are gonna be down the line.
I think there's just a ton of work, not only on that, the technical side, but, but just on the organizational side, uh, that, that, uh, enterprises are still working through Folks, you're hearing it here, human in the loop. It's not just some sort of buzzword that we use to pacify people. It's actually the difference between success and failure.
Hey, Christian, thanks for being on the show. Thanks so much. Great to be here.
ai. When you can find this in other episodes on our website, we invite you to check them all out. Until then, we'll see you next time.
Hey, everyone, I'm Alan Shimel of Text Drug tv, and welcome to another episode of the Last Great Cloud Transformation. You know, uh, we've been doing this show for months now, and we hope you've caught some of the previous episodes, but if you're not clear on what it is we do here, you know, we're, we're seeing, we call it the last great cloud transformation, but what we're really referring to is that this next wave of cloud migration, if we could call it that, is a little different than what we've seen before for the last almost 20 years, 18 years, something like that. For many people, cloud migration meant moving from a private data center, whether it was a private cloud or, or just a, you know, posted in a private data center up to one of the public clouds, the hyperscale, cloud hyperscale, you know, provider clouds.
And, and a lot of times it was just a shift in lift from, from private to public. Other times there was some transformation, maybe moving to a cloud native microservice architecture or something like that. Um, but what we've seen over the last three years, five years, may, let's say, since covid times, right, is a migration not only from the private data center to the hyperscaler public cloud, but from there to the edge, from the edge to the endpoint, in some cases from the public hyperscaler cloud, back to the private data data center, or private cloud running things like Kubernetes on bare metal and so forth, right?
And so, really, our cloud infrastructure is everywhere. And so in many ways, this latest wave is the last great cloud transformation. Our partner for this show is our friend, our forensic CloudFlare Cloud CloudFlare, which look, I think 22% or something like that of the internet travels over its network, right?
CloudFlare has come up with a solution, a, a aid in this last great cloud transformation, and they call it the connectivity cloud, because what they have found is, look, when you have a little bit of something everywhere, right? You get some assets in the public cloud, some in the private cloud, some on the edge, some exist on endpoints, everywhere, you need something that connects all of them. And, and in connecting all of them, you're dealing with several key issues, latency, security, huge, right?
And some sort of intelligence, I'm not going to use the AI word per se, but some sort of intelligence that knows where to go when and what to put, what where, right? Does this is, is the edge the, the right place for this? Is the core the right place for it?
Is the private this, should this be on a, an endpoint? So that's what we're talking about when we talk about the last great cloud transformation. I hope that makes sense to you.
Let me, um, introduce you to our panel today is we're gonna discuss just a, a small slice of this. We're gonna focus in on securing the API economy within the context of this last great cloud transformation. Joining me today, first of all, from CloudFlare.
I went through all that time. I hope I get his name right. S Saikrishna Chavali.
Am I close? Very close. I'm s Krishna Chaley.
Thank you, Alan for the introduction. Uh, product marketing at CloudFlare, been in the security space for a decade now. I actually, uh, started off in application security and now back to the API and application economy.
So excited to talk to all of you. Absolutely. It's like, Kris, it's great to have you on here.
Joining Cy Krishna and myself, though is my co-host of the last great cloud transformation. Uh, him and I co-host a whole bunch of things, and we like to do things together for a long time now, he's a, uh, FU VP for DevOps analyst, Mitch Ashley. Hey, Mitchell.
How are you, man? Good to be there. And I'm glad I'm buttoned down in my cold little bunker here in Colorado.
I'm getting some snow this week in cold weather, so you all might see a little bit Oh, goodness. Later on the East Coast, so hang in there. Absolutely.
All right, let's, um, let's turn to the issue at hand, gentlemen, right? Securing the API economy, before we talk about securing the API economy, I think that we probably need to define what we mean by the API economy, right? Yep.
And you know, it's a term that's, I've, I've seen the term used probably for 10 years already, right? Eight years. And, and really what it is, is so much turns so much of our economy, so much of our e-commerce, so much of our online digital presence turns on API to API communication, right?
In fact, uh, I'm actually doing an interview with Grant, is it Baz? Bazookas Berser, yeah. From CloudFlare, uh, on this, and I've done in the past with him on this, a majority of all the traffic on the internet today is actually API to API traffic.
It's a majority of all the traffic on the internet. So when we talk about the API economy, we're talking about a majority of every bit that gets pushed over the internet. So, I mean, that's, that's the scale of this thing, but peeling that off, what do we, you know, what is this API to API traffic?
So, Krishna Mitchell, do you want to expand on that? Sure, sure. So actually, I, I wanna do a quick overview of, uh, APIs itself, because I think the API economy is a, um, maturation of how we have been using APIs.
Uh, and one of the things that APIs compared to web AppSec or mobile AppSec, you're touching them every day. You're using them as a consumer, even as a, a business user, et cetera. But APIs you don't think about.
They happen behind the scenes, and they're meant to be behind the scenes. The, the value of APIs is that they can enable one system to talk to another system, exchange data, and do that in an automated fashion. And so all the automation that we talk about in the world out there is happening via APIs that are between applications, whether they are APIs in the, you know, software defined JSON format, or whether they're in older school formats, or whether they're specific to an industry.
It actually, when you think about APIs, they've always existed inside of applications not to the, to the public world, um, when there were service buses. But since then, and especially when we think about the first big push with mobile phones and mobile AppSec, especially the, when Steve Jobs talked about the app store, um, and then Google, Android store, et cetera, the Play Store, what it meant was all of those AppSec were being run behind the scenes via APIs. So the mobile economy provided a huge boost to APIs.
Second, we saw that, um, the social and e-commerce space became a huge area whereby when you're just a very active uploading fo photos from your phone to the cloud, um, to back it up or put it on Instagram, et cetera, was all via APIs. And so that provided another second boost, uh, with the consumers coming in to play. And then what we are seeing in today's world, you know, uh, organizations trying to reimagine how their applications are built, uh, as you talked about Alan, with the re-architecting of applications, that was that microservices element behind the scenes to make sure they break down their applications, to talk to each other and talk each service talking to each other using APIs.
And the, the fourth one that we are living in today, that everybody is familiar with, generative ai, I know you didn't want to use that word, but I brought it in. Um, it is being run while a lot of us are using it via web AppSec, behind the scenes. It is all being run via APIs.
And that is how this API economy is continuing to explode, um, whereby organizations are now making money just like open ais and the other AI models, um, making money based on how much their API is being used and being integrated into other systems. So when you talk about the API economy, it has many tentacles and it is continuing to grow, uh, in the importance, You know, side Krishna, uh, excellent, uh, description, I think of how the matcher education of AI have taken place. So I'll just, I'll just add to what you said and, uh, kind of build from it.
One is, as APIs have gone from sort of the exception to being the rule, the exception was those are the few things we exposed to other applications outside the organization, outside the firewall. Um, maybe you mentioned message bus, but boy, I had a, I had a flashback there for a moment, going back to so architectures and things. Um, but, um, but it's evolved even even beyond that to the point where we now think of, uh, AI a IS products.
Many services on the net only are offered via API, that that's how you use it. You consume it, you might stick a front end to it, a web interface or a mobile phone, but, uh, the service may be only APIs. So you think about that is your storefront for your service is other pieces of code talking to your services through APIs.
Another, another aspect that's changed, which is kinda how it's manifest, which you talk about in that, that fourth wave is, is what's called API first, where essentially applications are built around the fact that everything is an API, and it will all talk to each, each component where it's the user interface or some backend service, front end microservice, whatever it is, everything will talk via APIs. And what's interesting about that from a networking perspective is, you know, sometimes software and software architecture is a bit of a head scratcher for a network security person or maybe even a network person. It's really a network inside the application that's talking to itself over T-C-B-I-P, whatever we're using, whatever GraphQL or restful interfaces, fancy words for different kinds of APIs.
Um, so it's, it's, we've really gone from it being the exception to being how everything works. And that's the, that's why you see all this traffic, whether it's over the internet and the cloud providers or inside your own networks. That's why it's all happening over APIs.
Agreed. Um, Mitch, it is, when we talk about that last great, uh, cloud transformation, it's again, back to the fact that the app at the app layer, you're exposing all of these APIs, but coordinating them, mm-hmm. Maintaining them, making sure the performance is optimal, is all part of the cloud transformation that is so critical, even before you get security.
And obviously security is a critical portion. Good point. Very good point.
Yeah. I want to turn to security and, and specifically around securing all this, but before we do, you know, so Krishna, you opened up the, the, the, the Pandora's box with the AI stuff we warned yet, right? It would, it's gonna happen at some point in every cover.
Yeah, yeah. So look, this, this, this is a whole different ball game, quite frankly right now, especially with the onset of, of agentic ai, right? Who do you think these, all of these AI agents are gonna be talking to people?
No, they're gonna talk to APIs. So if we think that a majority of the internet traffic now is API to API, how much of it is gonna be agentic AI to API? Some may say that really what is, you know, a good chunk of the very essence of what an AI agent is, is some sort of AI bridge, API bridge, right?
It, it it's an API that lets you plug into everything or that plugs into other things. So I think, you know, we're just at the beginning of the API economy and, and how much of it, or how much of the total digital world is gonna be riding on that, right? But let's, as I said, let's turn to security.
Well, some do just wanna mention this. Go ahead. This is so pervasive that my granddaughter told me she wants to dress up as an API for her Halloween costume this year.
That's how pervasive this is. Really? I'm kidding.
Of course. Oh, okay. I was gonna say you she's wired in.
I'm just security, not just security though. So look, if something's this important, you know, it's the law of why we can't have nice things, it becomes a target. There's a bull bullseye on its back, so to speak, right?
Of, of how can that be disruptive? How can you know, how can it be disrupted? Excuse me.
How can people exploit it, hack it, make something out of it? And therein lies the problem. Therein lies the issue, right?
How do we, how do we secure this gigantic monster of API to API or API to agent communication? So, Christian, I know CloudFlare, I mean, you guys have put a lot of resources into this very issue. Let, let's talk about some of the things, you know, some of the ways and things that you guys have come up with.
Yeah. So we've done a bit of research into what are we seeing in terms of threats. So we'll, we break this down into what are the threats we are seeing live, and then what are the problems around API security to do API security well in an organization.
Um, so in terms of threats, let's just kind of break it down. The, the actually most common threat that you see on, in, uh, kinda realtime traffic is business logic or deep de di distributed nile of service attacks that are just hitting their APIs to try and either exhaust resources or to try and get into a service and then figure out what is a, what is behind that service at the end of the day, you know, an API is mostly a communication mechanism, and therefore they're trying to figure out what is that API talking to in the backend. Um, and that's something that we are seeing a lot of constant traffic, uh, around that.
Beyond that, when we think about actual data breaches, what's unfortunately very clear is that we hadn't fully thought through what needs to be behind a authentication mechanism. And then, you know, we're still, we're still trying to figure out what is the authorization mechanisms and methods that we go through. But even authentication, putting basic authentication is not something that was, uh, has been very common.
And therefore we have seen a lot of public major data, uh, breaches that have an API that's just openly accessible. So that's the second part. Now on that, when you're talking about leakage, you're essentially leaking data.
And the most important, uh, types of data that what we are seeing is attackers using that to do reconnaissance, to then use that in other attacks that are a bit more targeted in nature, um, because they found all these public APIs just spewing a lot and lot of data, um, that can be used in other places. So it may not be necessarily sensitive on its own, but it's a piece in the larger, uh, targeted attacks that we are seeing. And then lastly, what we also see is just like with, uh, applications, APIs at the end of the day are also code.
And so there can be vulnerabilities in that zero day attacks that we zero day exploits that we are seeing, just like with applications that can happen with APIs as well. Just because an API does not have a front end does not mean that it will not have the, the code level vulnerabilities, um, given they may be written in similar languages to, um, the, the, uh, web application, uh, code that is, or the, uh, the, um, code behind the web applications, uh, that we all use. And so being able to protect against that helps you protect against, as we think about, as Meisha talked about the economy and Alan talking about how the economy will continue to grow, so well fraud, and we're gonna see fraudsters trying to go after the APIs to get access to money, to get access to, um, credentials, et cetera.
And so that's the next area that we're, we're really seeing growth in, unfortunately. Yeah. Mitch, Thoughts?
You know, I was just thinking about, um, not to bring AI back into the conversation, there's a lot of discussion about how did TSE train its models, and it's done through something called reinforcement learning and of course, um, the other aspect of it was as trained on OpenAI's models or other people's models kind of ing models models. That, that's a great example of where automation comes in, where something you couldn't do on a large scale through any other way other than through automated API calls, uh, into applications or models or whatever it might be. So it's, it probably be shocking to, to just the average user or maybe us that has a little more technical background of how much of what's happening inside an app or looks like it's inside an app, is actually taring through API calls.
And how our AppSec wouldn't function at all without it. I mean, some of 'em wouldn't even start up. Right.
Couldn't present a user interface to you. So I'm, I'm curious, uh, aside, Christian, as, as you think about from a cloud perspective, when so much of the traffic is APIs rather than, you know, HTB calls over web browsers and, and email types of things, protocols, you know, the old, the old internet protocols, right? That, that built the internet.
Uh, how, how does that make you think about the cloud differently? Especially because customers like myself, we are a customer of CloudFlare, by the way. Um, wanna put parts of our AppSec in the cloud, not only at at the Edge, but also in multiple places across your cloud instead of us trying to figure out how to deploy it to some point past the cloud.
Yeah, I think this gets to some of the, uh, big problems with trying to secure your APIs. So there is two parts to this broadly. One is, at the end of the day, APIs are written as code, just like web applications are.
And there is a portion of it, which is the typical vulnerabilities that, um, the laws or open web application security, uh, project has, uh, kind of outlined as the top 10, uh, kind of risks are very similar between web applications and, um, APIs. So being able to protect against those so that they don't even reach your API servers, um, wherever they may be, is going to be super critical. The second is making sure that when you are, when you are looking at, uh, APIs, the unique part about APIs is they should have some sort of augmentation and authorization on them.
And exceptions should be those that are unauthenticated, that should be the exception. Whereas with the web applications, a vast majority of the traffic maybe are not authenticated because they're just looking at, um, and reading data. But with, with, um, with APIs, that should be an exception.
And so being able to put that in place and then being able to enforce it function that developers don't have to come up with it, come up with a application mechanism every single time they're creating a new API, which, which is just so very common in organizations, which, which just as an aside, that forces developers to become security experts. And while we want developers to know something about security, security expertise is not gonna be the first thing on that plate. Um, and therefore being able to standardize that and push that to, to the edge is gonna be so very critical.
Um, on, on the authentication side, and the last part is, as a security team, you're constantly thinking about governance. What is happening in, in my estate of APIs, applications, other assets that might be there? What are, how are they being configured?
Because once you have, you know, coded an application or an API and then you have, um, put it into a release cycle and it's out there, there're gonna be multiple ways that it's being deployed, run, configured for different, uh, use cases. And so all of those can have misconfigurations. And we see that all the time today.
In fact, one of the things that we see is the, uh, problem of APIs leaking sensitive data because once they, when they were first, um, released, they were very pristine, well done over time. You keep adding a bit of fun functionality. And over time that leads to things where just for that one use case, you will, you are, uh, uh, you know, able to kind of expose a bit of data.
But now in another context, it is leaking sensitive data. So, um, that is something that you need to be able to constantly be able to monitor and where appropriate without having to burden the development teams be able to put in place, uh, protections in real time at the edge so that, again, there's much less burden on developers and those that malicious traffic is not reaching your, um, your, your, um, API servers themselves. And the way that connectivity cloud really helps in this context is to make sure that all of those protections, you don't have to put them in place at each of your data centers on each of your APIs separately.
You can push, you know, rules into a, uh, common engine and then make sure that they're propagated at all locations that you are, that you are serving, uh, from which you're serving your applications on, in what we call an edge or a connectivity cloud edge. Excellent. Excellent.
You know, Mitch, I, I was listening to what you said and then what, say Krishna came with, I, I think one of the things I said earlier really is, I mean, it complicates thing, but it's so true of what, what, what applications look like today, right? Our applications are dispersed, they're microservice based applications. And, you know, when people think of APIs, they may think of, I'm a user of an application, and I, and that's the A PII interface with that internal to external or external to internal, if you will.
But in the microservice cloud native kind of world that we live in now, right? Something like 70% of greenfield applications are built in a cloud native, uh, architecture, much more than that. External to internal.
API is the internal to internal API, it's one container talking to another container. It's one function of an application going out to a SaaS based API coming back in, talking to another piece of the internal, right? Internally and API to API think as you know, our applications are sort of little Frankenstein's, if you will, right?
We're all stitched, they're all stitched together. And what's, and what is the thread? What is those stitches?
It's, it's APIs. And so I, I'm going to guess that there's probably four x five x internal API calls for every internal or external API call, and they have their own security requirements. And that's, those security requirements have to be orchestrated, governed.
What have you managed, you know, whether it's at that COBE level, the orchestrator level, or the mesh level, right? Of how these things are, are talking to each other. But that's a, you know, and, and they're all over, you know, let me add one more little complicator in there.
They're all over the place. They're in the edge, they're in the core, they're in the data center, they're on the endpoint. Mm-hmm.
It's enough to make you go crazy, right? Because that, now that's a job, right? If you could secure all that, that's a job.
I don't know if it's a good analogy, but it, it's kinda like an air traffic control system of multiple wind. Yeah. Really, it's whether you're international travel, continental, you know, local, et cetera.
It's 3D 360 degrees, right? You mentioned Kube, Kubernetes, you know, and then the cluster has an API gateway, and that does security for APIs. What can talk to what within that and other, other Kubernetes clusters.
And of course things go outside of that. And then service providers have API gateways and firewalls and things that control, uh, both security and authentication, uh, as well as traffic of those APIs. So it, it is, it's, it's kind of a cellular system almost, if you want to think of it that way, of multiple layers of, uh, how APIs work.
And, and the good thing is the APIs give you a lot of autonomy in code and in design. 'cause I can create a, a microservice that just specialize in pulling data from Salesforce because I need these customer records for my application to process an order or to go get, uh, background information from, you know, say a science database that's got, uh, medical information in what I'm gonna occlude in some deliverable to a end user, some product I'm producing, but that can be specialized. So it lets us build autonomous pieces of code, not, maybe it's a tic AI agents at some point not too far down the road that can go do, do its thing and not worry about the rest of the world of all the software and the APIs happening.
It also lets developers go nail, okay, I, I know, I know where those API calls happen, or I know how to trace it down using observability tools and things like that around tracing. Um, but it, it, it's a different world. It's a very different world than the days of I will talk over a solo bus, um, or a model if application.
Um, but it's like everything, it's just a different mindset, has advantages, brings with it other challenges and, but the advantages outweigh the negatives. And I think, Mitch, you mentioned, um, something around, uh, agenda AI agents, but that touches back to Alan's point, which is, you know, Alan, you were talking about, there'll be one, um, a one API call between the, or many fewer API calls between external and internal boundaries. Um, and there'll be a lot on the internal side.
Totally agree on the internal side, but the unique part now is there is an even more blurring with agent AI agents of what is internal and external when you are calling AI models to do things as a step in your application. And so you are, uh, a service may actually be calling, not the application, the application that everybody's touching, but a service that is trying to do some data analysis, trying to pull the latest information so that it can be passed to a user may actually just call on its own an AI model of, of some sort that has to do some data analysis and then be brought back to the application. And now what is happening is when in the old world you had an understanding of, okay, here are things that are exposed to the internet, everything that the developers are doing behind the scenes, I, I don't really have to really care about that.
Now you need to be thinking about all of those services as well, because those could be exposed. And when you are talking to another, um, AI models that are open source, uh, you know, by third party commercial one, or whether it is sitting in some other location that you, you own, you are building your own, um, it just makes the, that world of API traffic even more complicated. And one of the things that we are finding is, um, in the past, even just pre pre covid, think the pre covid days when APIs were still, uh, quite common, um, not as common as today.
One of the thing, one of the things that customers struggled with was identifying what are all the APIs that my organizations have exposed? Because the security team is not everywhere. And talking to every development team, now this problem has multiplied.
Now it is not just what are the APIs, but developers, what are the AI models you're u using? 'cause almost always those are being discussed or, or that's being communicated with through APIs. And we need to think about what is the data not just coming out of the API, but what is the data I'm putting into the, uh, into the API that is going into an AI model, whether it could be PO for poisoning purposes or leaking your organization's sensitive information.
So I think those two things, especially with the world of AI, have become a lot more critical, uh, for organizations to deal with. That is the cutting edge of what we think of API security today. You know, there's another dimension to this too, and that is, um, what, what goes hand in hand with API first software architecture is also stateless, which means, you know, we used to make calls, meaning I open a connection to this, whatever it is, on the other side, I do things across, you know, whatever that connection to socket or whatever it was back then.
Um, and then close the connection. It's kind of the difference between TP and UDP, right? You know, am I doing that connection and open or close or am I just sending it and it will happen?
That's a lot of how software in order to scale and, and have that independence of microservices or whatever that function is that is providing or requesting the service, that's a lot of what scales this up. So that also increases not only the security, but also the manageability of those applications, because I can't take, like, freeze a point in time of the state of the machine and I can go see where everything is at. No.
You know, that that same process that requested that might've been updated two minutes ago, or might've scaled from one to 53 instances of that microservice across the network that's distributed. So that's why we're able to get such high performance out of systems because we can distribute 'em through that stateless architecture as well as APIs and networks. I, I think that, I just wanna mention one thing on that, on the stateless point, because it's so very critical in, and it, it applies to cybersecurity in the sense that the CIA triad one part, one leg of that stool is availability and the importance of a stateless architecture, um, that can be ideally based, uh, edge, uh, you know, pushed out to the edge.
Um, especially some things that are, can be provided by a connectivity cloud enable cold starts to be diminished because you can't be waiting when you're thinking about being very dynamic providing data. And this is the amount of data we're talking about, especially with AI models and AI agents, that difference between a bit of latency is very significant to the user, uh, at the end of the day. And so minimizing cold starts, and that is something that, you know, only in a provider and a that has been thinking about stateless architecture at the edge can, can really provide.
Um, and that's something that we have definitely been, uh, seeing with a lot of customers, um, that they need, that those call starts to be reduced so that whenever they call a function and it is spun up, the instances spun up, they're ready to take, uh, workloads. You had to mention cold starts. It was 11 degrees when I woke up here this morning.
So thanks for that reminder there. Like, Christian. Alright guys, we're about outta time.
Like Krishna, for people wanna get more information about connectivity Cloud, securing their APIs and so forth on CloudFlare, where, where's the best place for them to go? com has very in-depth technical analysis on the latest cybersecurity threats and API performance and security conversations. Thank you.
Thanks, Krishna. Thank you for coming on here today. What a great conversation, man.
Mitchell. Good work. I, I enjoyed, I learned a little too, which is always a good thing.
It's gonna wrap up though, this episode of the last great Cloud transformation. Stay tuned. I think our next one might be a live round table again.
So if you watching this, you enjoyed it, you want to be involved in the next one, it's live. You could come in and chat your questions and comments and we will incorporate those into the show. But until then, on behalf of CloudFlare text Strong Mitchell, Ashley s Krishna, help me shival Val Val, I always think give it a little French there at the end, Val and myself, I hope you've enjoyed this episode.
Take care. We're out. This is Textron tv.
Hello and welcome everyone. This is Infrastructure Matters, episode 72. Uh, and I'm joined by my partners in crime, um, rum with, um, uh, Keith Townsend and, uh, Camberley Bates.
Um, and, uh, it's, uh, been, uh, it, it kind of an offbeat week for, for news. Um, and so let's, let's dive right into it. Uh, who wants to kick off with, uh, Lenovo earnings?
Sure, I will. I just went through their earnings, came through yesterday. Um, they're doing well.
They're, um, both the PC business and the, um, like the ISG, which is the server storage business, et cetera, has done well. Um, they, um, I'll focus on the ISG overall. They're up 20% of the revenue, so they're hitting all their numbers and expecting things to continue to go very well, which I think is positive for everybody.
The ISG business is the stuff, is the area that has the server and the storage. Um, they highlighted the growth with the CSP and the SMB market. Um, they're up year to year, 60% in their group, which is significant.
It seems to be most of that is coming through their OEM business where they're customizing the server business for the, uh, CSPs. Um, they didn't go much into the details about how that is going. They have a new, um, SVP or EVP running that division.
Um, Ashley and I am not gonna try his name because it's like, it's like this long, Ashley Gee, he comes from, I should know how to pronounce it by now, but he comes from a long time ago he was with, um, Dell, and then most recently he was with, uh, WDC Western Digital, um, on their HDD side, and he joined them this last fall. So I think that they're kind of being quiet about what you know is going exactly is going on, and that's, and this server business, et cetera, other than it is growing, it is break even though. So they need to get to a profitable business.
Um, and so the strategy is being developed, but they're gonna continue to hammer into the profitability of develop the profitability on the OEM business. So all good, all good. Um, news for our industry, um, continuing to grow and, um, and healthy.
So that's, that's what I was looking for, is how, how healthy is this business? Yeah, no, it's, it, um, it's interesting to see. So, um, on my end, I saw how, uh, I, I saw, uh, Nvidia and ARC Institute re-released a new AI model called EVO two.
Um, and it's a biology model, so this is where we're seeing a lot more, uh, uh, you know, directed a AI models, uh, focused on areas like STEM and like AI models, really good at certain things like coding, uh, which was kind of unexpected. 3 trillion DNA base pairs. And this allows you to ask almost any question that you could possibly imagine, uh, having to do with genetics or biology.
But what's interesting is that it can generate genomes. So it's not just, you can, you know, ask it about, you know, uh, you know, how does this, uh, organism work or does that organism work? But it, it can technically, uh, create the entire sequence for new organisms or, or, or, you know, new, uh, you know, uh, how to repair a certain cell or, uh, fix a certain disease.
I mean, it's incredibly powerful. So it's got a lot of attention because it's the largest biology model yet created, uh, by alar, by a large margin. Uh, it's, you know, it's effectively the, uh, the chat GPT of biology.
And this is, um, highlighted something we saw with alpha fold. Alpha fold is Google's model for coming up with new molecules, specific in new drug molecules. And that model is generated more, um, novel treatments and novel drugs than we can currently test.
Uh, it, it, uh, has a, I believe it, a 60% accuracy rate in, in creating a, a new molecule that will address a specific situation. Uh, and the, uh, this is what, you know, highlighting something that I, I think a lot of us didn't expect with ai, which is, uh, these models are creating, um, uh, they're actually, uh, evolved in new knowledge discovery, scientific discovery. They're creating new things, uh, discovering, um, new substances and new treatments, um, faster than we can actually process them by, you know, by, uh, you know, a hundred x.
Uh, so, uh, EVO two got a lot of attention in the science industry that it, it's taken, uh, very seriously by people in biology and genomics. Uh, and it should be a, should be a breakthrough, but this is something we're, we're gonna see more and more is, um, the companies that have access and control of these models were the ones that will be creating the innovations. And now our biggest challenge is how do we organize to, to take advantage of all of the scientific discoveries that will come out of these models, uh, pretty exciting time.
So this is a model that is not only a human biology, but it's all organism. Yes. It's been every, as, every that everybody, it's like type GBT who's fed every, every scrap of a text and every book and every magazine, every scientific page, uh, research paper, and every webpage ever created, this has been fed every genome that is known.
So, Yeah, it's gonna be interesting to see how this helps downstream with drug formulation. And more importantly, you get it to this Diane, like, how do we catch up to the technology from a, uh, from a, uh, regulation perspective? How do we test this stuff in the real world?
You know, there's the theoretical in AI and these formulations, and then downstream, how do we literally make sure that, uh, these things do what they say and, and can get back that closed loop feedback to make the models even better? That also gets into interesting, how do you do clinical trials then? Does clinical clinical trials end up changing?
Is there areas that we can take this and do the predictive modeling about what that looks like and what the side effects are? I mean, I think about the commercials that I have. You know, you, you've got the commercial about what it's gonna do for you, and then the other half of the commercial is what it's gonna do to you.
And, uh, so that, that makes it a very interesting, um, Yeah, well, we're not structured for it. We're we, you know, we're, we're structured for an environment where we occasionally discover a novel new substance, and we, we wanna, you know, test it. Uh, and now we're gonna be overwhelmed by these types of things.
We need to find a new way to curate and manage, uh, these types of, you know, I mean, it's an amazing, the, the potential is incredible. I mean, it's gonna revolutionize human health and all sorts of other things, uh, but we don't know how to manage it, uh, and, and really take advantage of it. Uh, and what was interesting is, is that, you know, they came out with announced three new important drugs that were, uh, developed with including a cure for, for a new type of leukemia that was created by the model itself.
So this isn't theoretical, it's actually happening. And so it's, I mean, it's great. It's w wonderful to watch.
We just dunno how to manage technology that is so powerful like that. And that gets into that discussion. You know, we had at one time is talking about prompts, you know, learning how to do prompts, which is kind of, kind of sounds weird, but it's off often, you know, what is, you know, the questions that we ask or sometimes it's the question we forget to ask that are really super important to exploring ideas in areas.
And that goes back to some, you know, really deep critical thinking, um, on our part as well. Um, Yeah, and this goes back to, uh, you know, relating this back to the enterprise and enterprise it, one of the conversations I've been having with practitioners, I'm looking forward to a podcast interview I'm doing with Brian Lau of AWS next week, is how do you adopt things like AI application development? Like if you've ever done AI code or coding with AI looks very different than human code.
So how do you adopt the governance around using AI code and how does that affect the downstream, yes, you're coding faster, but what you're, the output doesn't look anything like the, the original output of code and dealing with it and code management. And it also impacts the human side of the equation of how do you get people to get consistent input. You know, that prompting that you're talking about Kimberly mm-hmm.
How do we get that consistent input because the LLMs are not consistent in themselves and we get a deterministic output. So, you know, there's a lot to learn from this breakthrough on how do we use some of the same discipline to apply this to enterprise it. Yeah, Absolutely.
Yeah, exactly. And so, uh, getting back to more traditional it, um, uh, HPE had some server news, uh, recently. Who wants to, who wants to tackle that one?
Yeah, so if you follow server generation nomenclature, HPE is now in their 12th generation of their ProLiant server platform. We were stuck on Gen 10 for quite some time. The TikTok was Gen 10, gen 10 plus Gen Lab and Gen 12.
And what those previous models had in common was the reliance on Intel. So this is kind of a proxy for where the industry is going. We're looking, we're wa we're still waiting on the sixth generation of Intel Zion and the server manufacturers, since the previous generation of servers are no longer waiting on Intel, this has all been driven by Nvidia, the ability to liquid.
Cool. Cool. These systems, gen 12 is much more focused on liquid cooling versus Gen 11.
Uh, the support to cool these GPU resources and getting ahead of not just competitors, but Intel itself. So is this a MD as well A MD as well? They're no longer, the TikTok X 86 is no longer driving the product schedules of the server, uh, of the two major server manufacturers, Dell and Intel.
I mean, I'm sorry. I would tell the difference here. So we used to think it's like we 10, 11, you know, 9, 10, 11.
It was just the next generation of the Intel chips and then, you know, some sort of design that's around there. So what's so different about when we go from 11 to 12, are we going to, is it 12? Yeah.
So it's all about the things we care about around GPUs, right? Power efficiency, how much, uh, CPI mean, how much power are the CPU components, the non GPU components using so that we can get the energy efficiency? HPE is touting up to 41% better, uh, energy performance per watt.
So when you're talking about, you know, the stinginess of a enterprise data center, uh, rack at around 15 kilowatts per rack, and these systems themselves can push up to 10 kilowatts that it matters. So then usually when we, we'd go in, I mean, my past life many, many years ago when I was working, you know, IBM or whatever, you know, your, your pitch as a salesperson was going in and saying you could get, you know, 30% more for the same amount of money, or 30% whatever, 30% more power for the same amount of money. What is the pitch for the Gen 12?
So it's going to be, I would imagine we we're going to, uh, go down to a special tech Field day event in a few weeks to get a deep dive on it. But I would imagine the story is about the things that enterprise data center managers care about, which is, how am I going to power and how am I going to cool these systems? The I'm not retrofit fitted for liquid cooling.
How do I get liquid cooling into these systems so that I can manage my heat, uh, uh, the, the heat that's coming out of these systems? I imagine that that's going to be much of the sales pitch of you. You can't do ai, at least not big AI with previous generation systems, at least not as efficiently, as efficiently as these Gen 12 next generation systems.
Well, I will be looking forward to that Tech field day. Yeah. Well, I've been working with Proli since, uh, man, since the nineties.
Is that, is that how long they've been out? Well, ironically, I have a friend that's doing a, a network assessment for a company for a piping con company, not too far from you, Kimberly. And he called me this week and said, Keith, you'll never believe this.
I just saw a compact ProLiant server in production, and this is the irony, running Windows 95. So that, that was hilarious. I'm like, thi this can't be true.
You have to, you have to send me a picture, otherwise it never happened. Yeah. The, the number of workloads still running on, um, windows 95 and XP just fell under 10%, but it's still, so we're surprisingly high.
It takes a, the, the, um, something has to break for it to, to move a workload off of a, an existing environment, right? So it's interesting. Uh, so Cisco had some earnings, um, and, uh, uh, can someone, uh, someone take us away on that one?
Yeah, so the interesting thing, revenue up to $14 billion, that's a 9% increase. And you think about a business the size of Cisco, this is unusual. So, di diving into the numbers, surprise, surprise driven by ai, Cisco is seeing, uh, orders, uh, for, uh, web scale systems or web scalers go from 350 million to 700 million.
That's a proxy for ai. They're, they're seeing more demand for ai. One of those companies you wouldn't expect to benefit as much from ai.
Cisco has lagged in their server design and refresh for their UCS platform. But I talked to a Cisco, uh, engineer, uh, a few months ago, and he was telling me that they're able to justify an entire network refresh by the savings and efficiency for GPU to GPU communication, uh, alone. So Cisco is absolutely benefiting from the carry on impact from AI and AI training.
Well, and they just re-released a, uh, new, a major new product called AI Defense, uh, which is designed specifically to say, how do you do systematically, uh, you know, defend against, um, all the challenges of ai, um, that, that you might have, uh, across your entire environment. Uh, and so, um, it's, you know, yet to be seen how much lift they'll get from it, that they're doing major product releases around AI that I think a lot of people were not necessarily expecting. So, um, data management, uh, was another topic.
Uh, we had, uh, um, unified our platform data systems can't believe all one thing. Yeah, I started thinking about this yesterday with the vast announcement this week. Vast Data announced that they added blocks block protocol to their platform.
And Vast has, you know, been highly focused on the AI or, um, data analysis kind of market that you're going after, which has traditionally been file and, and somewhat in the same area of object. There's also been this noise about platform data systems, meaning you should have this, you should, your strategy should be for a platform, for one platform for all. Um, and I think many years ago we'd get briefings from vendors, you know, they come in and what we would call the God box, God box, I have to do it in here, that, that gave you file block and object.
And we'd kind of go, thank you very much, but I'm gonna set up, you know, this system for transaction processing. I'm gonna set up this system to manage, you know, shared file systems. I'm gonna share, you know, and you had it, your selection of what you did with your data management system was based upon the application and, and not necessarily an operational efficiency, which is what a unified platform more or less gives you is because you've got some common, common kind of technology you don't move the data around.
So in reflecting of that, there's this been quite a bit of data that's coming out of our C-I-O-C-E-O discussion and around ai. Is that one of the biggest problems that they have? And we've talked to the a infinitum, which is data management as oppo.
Uh, that is the data is the data problem is preventing them to get to ai, Correct? Yes. Platform block file and object on the same platform is not going to fix the other problem.
It, it's a different problem. Data management has to do with relating either understanding what is in that bit or, or whatever. What is in That, what you have and where is it, right?
I mean, that's, that's the right that, and that's an amazingly hard problem in it even today. Yeah. So, you know, once we think about the context of this problem, right?
The Elon Musk was quoted as saying that we've run out data to train ai. Well, you've run outta data that's on the internet, just looked up some rough numbers. And then these are the numbers that I've seen consistently.
About 60% of the world's data is stored in a public cloud, 40%. And the private data center, what that tells us is that systems like Vast, whether you're talking about, and this is their story, right, Kimberly, that they vast doesn't care if your data's in the public cloud, doesn't care if it's in private data center. They want it behind a vast system.
They want to be the front end to you accessing that data. And you need to be able to access that data in various ways, block storage and file. But I think when we talked about this a little bit before the show, the problem isn't necessarily access to the data.
Uh, the problem is the organization of the data, and I don't know if putting the data on a single system solves that problem of organizing your data to use with cloud, is we're advising in customers on how to adopt ai. It's all about organizing the data versus, you know, making sure you access it in the same way. Yeah.
And that's knowing what's in the data. It's having a risk profile for your data. It's knowing what data that you need to mask in order to move it into the information into your, your data lake or how, however, that one storage place that you wanna be able to access it to pull it through.
So I, there's pieces of it, some things that it does solve having it a platform, but there's many, many things it does not solve. And there's this discipline of what we used to call the master data management people, you know, that needs to be Well, and they're still around and they haven't gone anywhere. In fact, you can say their pay grades gone up a little bit, uh, with ai.
But, um, you know, unifying block file and object is, uh, evidently useful, uh, because it takes, you know, arguably it takes three silos and combines them. And the problem is, is cloud and SaaS sprawl, uh, uh, you know, is, is the biggest enemy of anything. Like, um, you know, you've got all your, your data used to all you data used to be in the data center and the CIA used to know where all other data is, every scrap of it.
And now it's in data centers all over the world, um, uh, through all of these SaaS applications and cloud platforms. Um, you know, how, how does fast, uh, is either of you have a sense of how VAST is, is gonna help address those sorts of things. 'cause without that, you, you don't, don't really solve the problem.
So well Mentioning was only because they announced that, you know, we had many others that are kind of marching in the same direction. And I guess what I wanna do, you know, as an analyst in this environment, talk about what does Unified give you, you know, what is mixing these things together? Here's where the benefits are, but it's not, it's not the be all and end all that the CEO is looking for in terms of solving the data management problem is just a piece of it.
And it potentially, and I think solves it. And I think, and there's other methods through this too, And I think one of the bookends of the announcement from Vast, and then we will, we're picking on Vast as they made the announcement, but one of the, uh, bookends is that, is their, uh, broker, their event bro broker service. So Diane, coming back to your question of how does this help the event broker is one of those things, you know, that hints to what enterprise data architects and art architects can do.
If you adopt this idea that you want to receive an event, there's some type of message bust of when data's accessed, when data's written, when, uh, a a a type of data is accessed, then there's an event created. And that if that, if you are able to have a consistent architecture or data architecture or event AR architecture is when data is accessed in SaaS, when it's accessed in the cloud, when it's accessed on block or in object, that you get some type of event notification, then that helps with the problem, doesn't solve the problem, but at least it gives your architecture to help mitigate some of the challenges associated with, uh, knowing where your data is at, how it's access, and how it's used In terms of, um, you know, we talked about, we already mentioned ai. Uh, it seems like we, it is obligatory for every episode of the show so far.
Uh, the last, uh, um, you know, so far this year, um, it's interesting, uh, we're starting to get data from 2024. So I, I, you know, I, I do a lot of database analysis as I, the numbers often tell the story about what's really happening on the ground in technology. And it, um, and a new study came out, um, uh, uh, from a, um, you know, from, from a leading an analyst firm, uh, reporting that 47% of CIOs say that they're, they're reporting positive ROI on their generative AI efforts, uh, which is, um, a, you know, a good number because, uh, a a lot of the initial technology pilots and prototypes don't actually work out that well, especially with, with, with high difficulty or high complexity technologies.
So 47% of CIOs reporting, uh, um, positive ROI is a good thing. Um, and that's gonna pretty much ensure that we're going to see sustained investment on the IT side, uh, for gen AI in the industry for the rest of the year. So that's, uh, that's great news.
5% on average, uh, this year. Um, that's all gonna be eaten up by, uh, AI and inflation. That's basically where we are.
So in fact, it's not, that's not even a cover AI and inflation. And so most, in real terms, most IT departments are gonna see a net cut in their, uh, IT budgets because of that, which is, Which is why we're already seeing, in terms of my conversations, we're already seeing, you know, the issue about how do I get more efficient on what I'm doing? How do I either consolidate, look at operational efficiencies, streamline whatever I'm doing, um, where you'll see, I think we'll see more investment into AI being used for coding, which takes out staffing.
Yes. Right. Exactly right.
You'll see, right, you'll see more investment in what operational efficiencies can I gain from doing some different types of technology. So I think we're going back to that, to, you know, good strong total cost of ownership, a analysis as we get into purchases that are happening because we have, because they're gonna continue to cycle in terms of upgrade their systems. They, they need to, they can't just continue to pour the money onto the AI side and ignore the, the core infrastructure areas.
Yeah. And this is why, again, bringing the whole conversation back together, this is why understanding from adjacent industries, genomics, manufacturing, how these industries are using deterministic outcomes to drive their AI initiatives. It has led in this actually pre AI for a long time with the, the Security Operations Center and finding false positives and filtering out those false positives to get to the outcome in which we're using less human capital to, uh, disposition those, those false positives and find true security events.
AI has improved that now that we've, you know, kind of taken these LLMs and moved that human assisted, uh, filtering down to the input level and come out with more deterministic outcomes, we're using less humans to detect and respond to security events. I see, ironically, a doubling down on, as you two seem to as well, doubling down on AI and automation to help alleviate many of these budget concerns. It's also telling, you know, how, uh, the reaction to the Broadcom VMware price, uh, effective price increase.
The, the cost may, you know, the skew may not have gone up, but customer, customers are spending more on basically undifferentiating. Well, I just more, I mean, it's a price skyrocket. I mean, that's, that's, yeah, it's quite A bit more if you, if you're not, so, you know, again, if, if you're all in in VMware, you're going to learn how to use the entire portfolio to reduce your cost.
How does this private AI solution help you reduce costs, adopt ai, uh, in a more cost efficient manner, get more benefit of your VMware investment, or do what companies like, uh, like Geico are doing and moving away from VMware into open source? Yeah, I did a, I did a, a, a case, uh, study of that on, on the CIO post report. Uh, Geico's make amnesia, move away, you know, so, uh, and very impressive to watch.
But this brings up the whole AIOps discussion, which is, uh, in increasingly, um, it is gonna be operated. Uh, uh, you know, first tier operations will be done by ai, not by humans, uh, is the unblinking gaze of the robots can, can manage things 24 7. It's only when things, you know, exceptions happen that you need to bring humans in.
So that does seem to be, you know, a, a major focus in terms of reducing, you know, fixed costs and reducing overhead for it. Uh, and so I'll, we're, we're almost at time, so I'll, I'll do, uh, I wanna do my last, uh, piece of news before we wrap the show. Um, the, uh, avalanche protocol, which is a, um, it's a blockchain I kind of use as a Post-IT child for enterprise, um, uh, digital ledgers, uh, enter enterprise Web3, which is not a topic that I find this particularly popular in IT and CIOs, but it's, it's important because things are actually happening as an example.
And the, again, one of the reasons I talk about avalanche avalanches, um, the California Department of Motor Vehicles, um, last year moved all 42 million vehicle titles into Avalanche last year. Uh, that's, that's a big deal. We're we're actually seeing people moving, um, important records, uh, into, uh, blockchain based technology.
Um, and the, the advantage being that, that data can't be tampered with. 'cause you can't modify data in a blockchain. You can only add data to it.
So records are, are, are considered safe and, um, uh, and, and will last a long time. Um, uh, since the, the data is replicated across, you know, thousands of different nodes, you can't lose the information. There's, there's no, you know, single point of failure.
And the whole point is that there's massive multiple redundancy. Uh, so Avalanche has got, uh, uh, about 9 million, uh, addresses, uh, half a billion tokens in a market cap of about $10 billion. Uh, and they just announced the holiday protocol, which is, uh, uh, the whole Web3, um, subcultures really likes, uh, uh, pop culture references.
So this is a, you know, ready player one reference to the, to the creator of, of the metaverse in that, in that, in that story. But the holiday protocol is the first, the, the very first agentic AI announcement, uh, in the blockchain space. Uh, if you want agents to work with anything in the blockchain world, you have to create a smart contract normally.
Uh, and that's, even though that's relatively easy to do, that's still a higher burden than most people want, want to take on, feel it. You want agents to be able to work with something that they've, you know, essentially never seen before. You don't wanna write code for every, every type of, uh, transaction or every, every type of thing you wanna do in a, in a given blockchain.
So the holiday protocol, uh, allows you to use agentic AI to manipulate or interact with the avalanche blockchain. And I think it'll be the, the beginning of a lot of announcements like that, I think, see most, most blockchains doing that so that you can use agent agents without writing, um, smart contract code every time. Uh, and again, this is still early days, but the way that the blockchains are not designed, I mean, they're, they're, the, the total market cap of all blockchain technology is around around 3 trillion, making it about the ninth largest economy in the world.
Uh, and, uh, I've, I've talked to your retirement, um, uh, uh, re retirement network CIOs, uh, from like, uh, federal and state retirement programs. They're not tracking this stuff at all other than they know it's coming. They're like, we don't care about this.
We don't even like it, but we know that it's coming. And so we're having to watch it. So it's worth it.
It's then it's gonna be ultimately, uh, a big part of some new record keeping infrastructure. We just dunno how big yet. So it's not, so Diane's gonna make you listen to it, even though you don't wanna hear it, guys on infrastructure matters.
We're gonna bring it up. Exactly. Dang it.
And that brings us to the end of another great infrastructure matters. Um, and, uh, we hope, uh, you, you got, uh, much useful knowledge out of this. Uh, and, uh, I think all three of you will, uh, all three of us will, will see you next week.
Hi everyone. Uh, my name is Alejandro Mercado, very honored to be here. Um, I'm going to talk about, um, this kind of new trendings now It's about predictions 2025.
So let's get started. So my talk is about the, an experiment that I am making is, is a little bit about make our life easy. I, I mean in terms of, we, we need to handle a lot of things, lot of activities, lot of consideration when dealing with, uh, in technology, um, and specifically with software development.
So it's come to my mind to, to what if I can handle my, in this case, my cluster, because my Kubernetes clusters, because, well, you know, I am the BS engineer, so, so I think this can be a good idea to, to be more productive and, and yeah, to get my job done. So this is an introduction. We using voice comments and virtual assistants like Alexa, I mean, can be any other assistant, but I have an Alexa to efficiently manage and deploy a Kubernetes cluster.
So a little bit about me. I'm Alex, Alejandro Mercado, uh, rise and board in Mexico City. Uh, I spend most of my time doing the box and, you know, cow engineer, automation related activities, observability.
Um, Jeff currently living in Mexico City, uh, where I also co-organized the KCD. This is a little bit of topic, but, uh, call for proposal you want, please apply, Liz, please do it. Um, um, well, there's are a couple of links about my, my blog where I, I write a lot of, in, of course, in Spanish and in English about technical stuff.
Um, the presentation, if, if you want to donor, so I, I'm not pretty sure about to talk about predictions because you know how I don't have a crystal ball to, to predict anything. Uh, uh, I, I better will say to prospective of technology, because I mean, 20, 25 is already here. So this is for sure that this is going to happen because we are, we have, there is a, a, a lot of strains of activity related to that.
Several topics. This is just a couple of them. I mean, it's not an extensive list, and as I said, it is more like a prospective, i, I will better say prospective than prediction.
So definitely artificial intelligence and machine learning is here. Maybe you get involved in, in these several tools. There is a lot of folks, uh, a huge explosion of these tools to Democrats.
The, the use of these two technologies. So I mean, it, it is going to impact any, any activity in our life. So if you're a developer, you're a tester, you are a writer, even a musician, or, I dunno, all the, all the areas in, in, in our life is going to be impacted by artificial intelligence.
So being from the technical side as a engineer, well, this is where my, my talk is, is going to want to cover one of these aspects. So, quantum compute, quantum computing, uh, networks like 5G and beyond blockchain, blockchain, we have been hearing about blockchain lot of years. So we are going to see more, more cryptos, more technologies.
So be aware of that because, uh, for sure there is going to be a lot of jobs, a lot of opportunities around this. Security. Security has been always a thing, a consideration and important aspect in everything of our developments.
Uh, so more people focusing in the security side is going to be required. Um, virtual reality of mental reality. We are, uh, well, not, not just starting talking about sustainable technology.
We have been talking about these, um, foreseeable years ago, but it's, it's gaining popularity and importance because, you know, all the situations as we are facing as, um, I mean, in the whole world, it's very important to talk about this, this kind of topic. So for sure, we are going to hear more about sustainable technologies and of course, uh, remote work and keep working on col collaboration tools. You know, from, from this covid COVID-19 situation, we have been dealing with that a a as many others, I can imagine the work, if not remotely, but for sure, we, we are going to see another ways to interact, to communicate, to be more productive.
Um, the last topic of this short list, this is my, my humble opinion, of course, uh, human computer interaction has been with us like many, many years ago. But we are going to keep seeing, uh, innovations in human computer interactions as brain computer interfaces and advances for recognition that this is the topic of my, of this brief talk. So we will create more intuitive and ling seamless ways for humans to interact with technology.
So like to handle more of my activities on the techie side. So I would like to emphasize that we're going to see more of this voice assisted technologies, especially in, in other sector. I mean, I, I, I did that experiment because I am lazy.
I just want to have just, if I am on my, in my bedroom, just to, to talk to Alexa and say, Hey, how is my, my cluster? Or, or do I have any problem on production or development or any other environment? But, uh, when I think about other sectors of people, I mean elderly or I, I don't know, uh, talking a little bit about accessibility, we can see that this kind of technologies is going to help a lot.
Uh, why or how? Because, well, because this technologies offer significant benefits in term of health monitoring and wellness support for elderly. This is by instance, just a couple of examples.
Uh, uh, if you take a look of this slide, um, voice novel technologies will assist senior sentences and professionals, um, and to adopt an environmentally sustainable solutions. Um, there is a, a lot of, lot of examples that we are still developing and we are, uh, evolving this, this, this examples. But I mean, I just want to, if you want a take away from this talk, we are going to see more of this, uh, not just experiments, uh, uh, I, I will better say projects around technologies like voice assistant technologies that is going to help in so many different ways that it's, that I, I mean, this is just one example.
So as a DevOps engineer dealing with software in the software development lifecycle as a business daily, it's, I, I see that, well, when I started to think about this project, I see that, well, I was not the first person in, in this world to, to think about it. So, uh, not for surprise or I see that there was a lot of, or we, we have a lot of different project related to that. I mean, it's like, once you get the something to help you with the underlying infrastructure, you can handle and manage, instead of using a keyboard, you can use your voice.
So we, I, I, I find, or you can find a lot of examples about this similar, uh, concept. So just do a quick research on internet, and you are going to find a lot of, uh, similar ideas. So I, I just, uh, I am proposing one that this is just as I said, because makes my life easier, uh, just to have this introduction to, to voice activated Kubernetes management.
So why, because, well, of course, uh, is, is scalable, is adoptable. You take a look at this slide. Um, and I, I, I would like to say that this is not just for AC acronym, it's cluster.
I mean, this is pretty specific for my related activities, but it can be any kind of technology. I mean that any kind of application that it's running on the cloud, you can handle, you can manage it. So, uh, take this, uh, introductory talk like, uh, like a 360 degrees view of what can we do, what is going on or, or what we're going to see in the next couple of years.
So by leveraging the power of voice commons organization can streamline their Kubernetes management workflows, improve AccessAbility and enhance a overall efficiency of the DevOps processes. But I mean, uh, I repeat it can be testing process processes, DevOp processes, uh, uh, development, support development process. Uh, so, uh, I, I focus my, my experiment and the Kubernetes side, because some people say that Kubernetes is, is, is hard.
It's tough to, to main, you know, to think the beast. Um, uh, and yeah, I, I can I agree about that, but well, you think, I, I, I think that it can be, we can have better tools to, to manage this complexity. So we have been dealing with that a lot of times.
And since you can see this, this slide, so when we started dealing with Kubernetes, uh, it implies a lot of components, a lot of situations, con connectivity, communication, networking, et cetera, et cetera, et cetera. So, so it's a long history around Kubernetes and there is like an explosion of tools. If, if you take a look at the C-N-F-C-N-F-C landscape, you are going to see a huge amount of technologies around Kubernetes for different proposals to service manage, to package managers, to, to deal in, uh, different ways with the control plane data, planes.
Um, I, I, uh, I don't know. I mean, there is a lot of tools for monitor and observability networking, uh, and the idea behind is to, to make things easier. But it's ironic because it's more complex.
So I think that we are just reaching the top, we, we are dealing with that, but I mean, this is just to have, uh, a voice assistant. It is just to, to have a, a different and simple way to, to handle, to manage things. So talking about not prediction, if not prospective, we are going to see a lot of, um, this kind of new ways to interact.
We're not so new, but we are going to interact more and more with this kind of new technologies. Um, we're going to see more, if you take a look at the final milestones of this slide, we're going to to see more web assembly for sure. Uh, internal development platforms.
Um, there, there, there was, um, a boom of this, uh, internal development platform like backstage. So you can expect to have more and more activity related to that. Um, this is a not some well known term that is, is bring your own cloud for sure.
I'm pretty sure that this year we are going to see more about this concept. I mean, for a lot of people it's going to be new, but you know, it's not like a big bang. This concept had been on the, on the way, uh, that there's a lot of history behind this is concept is bring your own cloud if you want to take a look after this talk.
So, um, why Kubernetes and where the Boha system, I mean this just an experiment, but as companies scale, there are Kubernetes usage. The challenges around clusters management, security and optimization become increasingly complex recurring tools and experts when you have a, a couple of hundreds of microservices. So things are getting to start more complex to deal with.
So you, you'll require, you are going to require dedicated tools and of course expertise. So, uh, the integration of voice controller technology with Kubernetes management has the potential to revolution at the DevOps workflow. So, and I'm talking about the, as I said, the whole DevOps workflow being a very important aspect according next cluster.
But I mean, you can do, uh, or you can think about any other aspect of the DevOps workflow that we can handle, manage, uh, or manage with, with these technologies. So this experiment was, um, uh, about enabling hands free control and real time updates. So this converse convergence and enhanced efficiency, productivity and agility in software development and deployment process.
So the, the idea is was to just to talk with my Alexa, just to get the system status held to create a, a cluster to delete bots, to delete the whole cluster. And I mean, this is something that I can do of course with, with a user interface or even with the, with a comment. But I mean, it, I I, if I driving or, or doing something else, I dunno washing the dishes, uh, at the kitchen.
Maybe I, I, I want to know if something is going wrong with my, my cluster. So, so I just can get an alarm, uh, in, in my Alexa. Um, well, yeah, if some fail, if I, if, uh, critical error arise because some reason, maybe I just want to know about it.
I mean, I don't want Alexa to, to keep, uh, I don't want to keep getting messages from Alexa every, every minute or two minutes. No, but thinking about critical or fat errors, I mean, I, I just want to know about it so I I can, yeah, I mean, if, if I'm not in front of the computer, I can have even notifications on my, on my, on my, on my cell phone or, or me Alexa device. So, so the, the, this project can, can you go further to get more details on the pops?
On the lots on, yeah. Uh, it's, oh, uh, a work in progress, but that's, uh, the, the idea just to observe my, my, my whole Kubernetes infra. So, um, and well, I, I think that Alexa is just one of the, the options that you have on the market, but I mean, it's the same for other assistants.
Uh, just because I have one Alexa, it is what I have, uh, it's handy to me to, to make this experiment, uh, uh, in my house. But I mean, uh, it's not just Alexa. It can be any other, uh, voice assistant.
I just want to clarify that. Um, and there is a lot of benefits, uh, having in this kind of new approaches to handle and manage infra, uh, I mean, it is in the early stage, but definitely where I want to see more of these kind of projects, uh, to increase ent, reduce errors, to be aware of what is going on in my infra, I think it is, it's like, um, uh, important point. Yeah, so accessibility, you have some, I know elderly people or with some visual problems, maybe this is going to be a, a, a great help, uh, streamline workflows, contextual awareness.
So I can ask my, my Alexa, uh, like this experiment propose, Hey, Alexa, tell me the, the, the help about my microservice or, or which microservice, uh, uh, has the, the lower latency just to say something so I can have an idea. Of course, it's, it's not about to solve the problem, just interacting. It, it, it, it is, we are not in that part yet.
But, uh, to be, uh, aware of what is going on, just to, once you are in front of your computer, you, you can have like a, a solid clue or way to go. So, uh, this is like real go use cases. So infrastructure automation, IT operations has free control in manufacturing, emergency response coordination, leading to remote site administration, that this is something that is, we are not too, too far from that.
So the experiment, so a couple of years ago I started to think about it because I, I use my voice assistant a lot, you know, to, to several things. Uh, so, so my idea was to, in, in, in a conversation that I had with other colleagues, uh, we have this idea of what if we can handle it when I, I am driving, commuting to work, or when we have friends, I, I mean, doing something else. So it, it'll be at the beginning with basic stuff, and you could do more advanced activities, uh, with more experience.
But because, I mean, it's not that easy, not just to set up or to create accord. Clusters implies a lot of considerations. So it's not that easy just to say, Hey, Alexa, create my cluster.
That, that I, I started to think about that. So through this journey, I realized that it was not that easy and there is a lot of consideration. So, well, uh, this is, uh, very brief if diagram of the architecture of my system is, is you are going to see just a lot of lambdas, and, and as you can see it is running on AWS just because, I mean, it's, it's not tied to, to AWS you can use Azure or, or cloud or any other cloud provider.
I mean, but, um, uh, the idea is, is the same. We have a lot of functions that call, you know, this interface between the LAN Alexa skill and the, and the functions. So once we, we accomplish the first thing, I mean, to create something, you can create anything on the, on the cloud.
I mean, it, it, it is like the same concept. So, so I started to, to create A-A-B-P-C as subnet, and of course the, the, the, the elastic Bernet cluster, uh, the, the E-K-S-E-K-S, so a, a lot of per permissions policies, et cetera, et cetera. So, so, but the, the idea behind is, is is like the can be extrapolated to do a lot of things.
I mean, to manage the whole, anything that you can do in in AWS you, you can do it with this idea. So the idea is to end this call of having a voice interface to handle everything that you want. So the idea that the functions are so dynamic, I mean, my, my voice interaction is, is so dynamic that I can do anything, but I mean, to achieve that is it's going to take a lot of time because there is a lot of services, a lot of considerations, a lot of configurations, a lot of dependencies.
So in this journey, I realized that, but I, I just wanted to, to focus on a Kubernetes cluster because did you ask me about to do something else? Well, of course, it, it can be achievable, but it's going to take a while until the, the, the voice interface is enough smart to handle all the requirements, but we are not in that pond yet. I mean, maybe, maybe in a couple of years, uh, this is the, the, the experiment.
Um, I, I can do a, a, a real demo, but, uh, it's going to take a lot of fun, you know, to create a, a Kubernetes cluster can take like 15 or 20 minutes, so it's going to take a long, too long to, to have the, the cluster running. So it, this is just like a couple of images, uh, about the, the test, the test that I did to deploy the Kubernetes cluster. So I have this voice comment to open, um, my, my, my Alexa skills name is Kubernetes manager.
So, so I can deploy a cluster, I can delete a cluster, I can monitor the cluster it, and in, in the, in the arena of monitoring and observability is where I see more opportunities because, you know, to, to create a cluster takes a lot of considerations, but I mean, it's not that easy, and you have to be pretty sure you have lot of, lot of Jamal files with, with manifests to be pretty sure that e everything is going to, to be up running. So I started to think that, well, maybe it is not a pretty good idea just to create the, the, the cluster with a voice comment. But I think that for monitoring and observe and have like a real time status check, uh, to see if there is any cluster health issues, I mean, it, it's going to be pretty handy.
So in, I, I, I don't want to talk a lot about the technical aspect, uh, because there is a record that I want to show in the next slide, but well, it's about the interaction model. So that's the way that the Alexa skill, uh, works. You have to define the, the, the intent.
So thi this is like more in the more technical side. So if you are curious about it, you can take, um, a look of that in, in this repo. But, uh, the, all the magic, all the heavy stuff is done through Terraform.
I mean, we can use another technology for infra code, but, well, I, I have experience with Terraform, so, so that's the way that I, I, I deal with the, the whole heavy lifting. So the Alexa skill is, is calling, uh, some land and the land are calling the, the, the, the Terraform stuff. So yeah, this way I can achieve, I, and, and I can say anything that you can achieve with this kind of tools like Terraform, pluming, uh, A-W-S-C-D-K, I mean, you can do everything.
I mean in the cloud, any resource, any object, any configuration that it's possible, it's just like adding to the interface. So, oh, well, this is, uh, just, uh, you have never heard about infra code is like, uh, this way to handle infra this new way, not, not that new, but, uh, it's the process of managing and provision and computer data centers through machine readable definition files. It's all about definition files.
So there are, as I said, there are a lot of options in the market, open source and legacy. So, uh, again, it's not tied to Terraform. Well, my idea is not to tie to any, any, any particular technology.
Uh, Terraform is agnostic to the cloud, so it can be this easily, uh, we can do an easy immigration to other clouds like Google, Azure, Alibaba, anything that you have in mind, we, we can just adjust this, this, this project. So, well, that's my idea to, to get or to reach a point in the near future to have this voice interface to handle any kind of, of technology, not just the Kubernetes cluster. But I think that this is possible achievable, and it's going to be, uh, pretty handy.
And we are going to be more productive in, in, in terms of our, I mean, talking about my, my side, the engineer SE side. Uh, I, I would like to have an interface like that, definitely. So thank you very much.
Uh, uh, I'm going to be around here. If you have any question, comment, please be, be my guest. Um, please reach me or contact me, uh, my LinkedIn profile, the information is right on this at the bottom of this slide.
So, yeah, thank you very much. It's been a pleasure and have fun, nice and happy 2025.