Techstrong TV – February 26, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hi, everyone. So it seems Apple has a bad case of fomo. $500 billion worth you're watching.
Techstrong Gang. Hey everyone, it's Alan Shimel, Saint Alan Shimel. Different background.
I'm not in our studio today, unfortunately. We had some work being done here, so you're getting me in my desktop version here in my office. Uh, happy to have you with us though on this wonderful, uh, Wednesday.
We've got a great lineup for you. I mentioned Apple's, fomo. It's an expensive, one of the most expensive FOMO I've ever heard.
Uh, but we've got more than that to cover it. We've got some great people to cover it with. Let me introduce you to them real quick.
Um, first of all, it looks like he's back home high at top Silicon Valley, the one and only Jon Swartz. Hey, John, how are you? It's Good.
Good. Things are good. It was great seeing you all.
You my Mitch, Mike, Amanda last week in New York. Um, Good times. It was way too short, but yes.
Yeah, it was great seeing you. Yeah, great to see you. So, thank you.
And we, and we, you know, alluding to a editorial in-person team meeting we had in New York last week, uh, in case you were smelling anything burning, it was all those brain cells we were expanding on, on how what, what we're gonna be doing editorially for 2 20, 20 25. So, John, great to have you there. Speaking of having us there for our editorial meeting, she is our managing editors that that's the right new term, right?
Amanda? Um, Senior managing editor. Senior managing editor.
We don't have a junior managing editor. You are the only managing editor, but not all. Pete said.
Wait, we, we, we Actually do have an assistant managing editor. Oh, okay. We have an assistant managing editor.
Um, but she's back home in Texas where I hear it's in the high eighties. A little different than New York last week. Amanda Razani.
Hey, Amanda, how are you? Good. Yes.
Big temperature shift from New York back to Texas. All right, we'll stay in the warm weather for now though, and go over to our friend at sea, uh, security expert, Chris Blask. Hey Chris, how are you?
Hey, Alan. I am good for those of you following at home, this is Stock Island. We see out the window, the island next to Key West, and specifically what used to be the five Sixes Taxi company actually had a little war for their own.
So all the pink cabs for those of you who've been in Key West, that was the five Sixes Taxi Company, which I think is finally gone. Good to see you. Good To be here.
There is no Uber down in the Keys, if I remember correctly. Oh, there is Uber. Absolutely.
I use it All the time now. There is, I think last time I thought there was no Uber there. Anyway, Chris, it's great to have you on board now.
We'll go back up to our cold weather friends first. We'll go to the guitar man up in Colorado. He's back home after a quick trip to New York Pit stop in the DC area and, and home to new, uh, Colorado.
Mitchell Ashley. Hey, Mitch. How are you?
Doing well, doing well. Yeah. I made a pit stop in DC as you mentioned.
Spent some time with some BMC folks, so it was great. Uh, great to, you know, both be in New York and get a chance to be with the editorial team for a little bit, and also go and visit some companies. Excellent.
Thanks Mitch. Welcome. And then last but not least, he, he looks pink.
It must be cold up there. Um, up from Harrison, New York, the dean, Mike Vizard. It, it's quite the opposite, actually.
It's gonna be 50 degrees today. And since we live in a world where correlation is causation, you guys should stay the hell outta New York. Yeah.
As if you think 50 degrees is warm. Um, but anyway, Mike, great to have you on here. So I, I wanted to kick off today with, I, you know, I teased it in the opening.
Is this a case of Apple's fomo? Is it a case of wrapping themselves in the flag and getting in the good graces of, of the, uh, present administration? Or is it just good business?
Right? What do you think? I think this is a very extensive way to bend the knee, but, uh, John, I think you wanna like jump into this?
'cause I'm Sorry. Yeah, Sure. I'll, I'll give, I'll, I'll give, I'll give some of the details and then I'll throw in my editorialized viewpoint because I, I, I think it's a combination of, of everything Alan said in what you just said, Mike.
Basically, apple is throwing a big bone to Trump in a sense. They announced on Monday, they're investing more than $500 billion in the US over the next four years with plans to hire 20,000 people, open a new manufacturing plan in Houston, open other, or expand on other facilities in California, Michigan, Iowa, what have you, Arizona. And they've also, in a sense, made this commitment to basically, Trump kind of teased it out.
He basically dropped, he ba basically blurted out that he met with Cook very stealthily, and that cook assured him that the company Apple was gonna shift to manufacturing from Mexico to the US to avoid paying tariffs. So that's a major motivation. The other motivation is that in, in terms of China, apple also ha is, is, is a, is at risk, right?
With these, these 10% tariffs in China where most of Apple's products are made. So in a sense, THIM Cook, who I think is actually very good at playing Trump in a sense, probably, I don't, I don't believe in a mo in a second that they're gonna devote this much money. They spend $10 billion a year on capital expenses.
Now, can you imagine them doing 125 billion a year for four years? I don't think it's gonna happen, but I think what they're gonna do, they're gonna do just enough to, to get exemptions from him in terms of tariffs. They're gonna keep the White House happy.
They'll do some of the things on the list, and then they'll move on. Because once again, think about history. Back in 2018, apple made a similar pledge during the first Trump administration.
They said they were gonna create 20,000 new jobs as part of a $350 billion US investment plan. And as part of that plan, they were not targeted in terms of tariffs in China. So, in a sense, apple is playing it very smart and politically, they're also trying to stay up to date and up to, up to par with the other big tech guys who are throwing hundreds of billions of dollars into AI development.
It's, it's, it's political, but it's, it's also business wise. But I think in a sense, cook is kind of the master when it comes to playing Trump. And I think the other tech leaders would, should, could learn from him.
So, lemme ask you this though. I think, like you said, John, there, uh, the first thing I thought when I read this article was, um, they're kind of just following suit. They tend to be kind of the last, they stay back and they're the last, you know, so they're just doing, so now They, they usually draft other people and like, thinking of the car analogy, they draft other companies.
Mm-hmm. When they, when they move into a market, they wait until the market's established and they make their move. They may be late on ai.
That's debatable. But in a sense too, this is one of those things, you know, and also, is it just me or I sense a deja vu? We saw that $500 billion figure before with Stargates.
We're seeing the 20,000 new jobs figure from 2018 to now. It's just they play this narrative and this formulaic game with Trump to keep him happy and then he gets distracted and moves on to something else. Yeah.
I think it's also a difference in leadership style here. You mentioned Apple kind of follower. That's one part of it.
I think, you know, cook doesn't need to be out there with the tech bros and trying to be, you know, the Musk and the Zuck and the whoever, you know, he, he's just not into that part of it. It's all part of the, um, you know, perception is the alternate reality nowadays, instead of perception is reality. I, I agree with you.
It's a, well, what is that 500 makeup? Well, it could be, yeah. Apple Cash investment, whatever.
It could be ecosystem of Apple and all the partners and everybody that is part of, you know, investing and creating technology that ends up there to support or part of their product. So it it's, it's a game. It's a game.
And, you know, it's about creating the people that are supporting Trump's policies and, uh, getting them to be visible and vocal about it. And nobody goes back and says, let's do just sticker the tape here and see what really happened. No, that doesn't happen.
Can I just mention one really thing, thing really quickly is like a picture tells you a thousand words, right? At the inauguration. You notice we, we have this iconic photograph of Zuckerberg pka from, from Google, Bezos, Musk, all lined up together.
Guess who's behind them? To the right to the left of the camera, just out of range. So you can't pick him up.
It's Cook. He's the, the Apple's also the company along with Microsoft that wasn't too obvious when it came to doing things behind the scenes as Meadow was and as Amazon was. So in a sense, this guy is the cook in a sense is kind of this kind of cool customer politician type.
And I think he's handled it pretty well. But the, again, I'm just gonna go back to it, the $500 billion, that's just as like, I, that's, I cannot believe that's gonna happen. So let's take that number apart because you know, we used to see IBM do this crap all the time.
They'd stand up and say we're gonna spend $50 billion on something. But, you know, they added up every nickel that they spent on every other. It's like, how much do you saving us?
Right? Similar. So, I mean, $500 billion on a company that to your coin, has been spending 10 billion a year.
So that's gonna ratchet up by a factor of what that doesn't seem. Yeah. 10, 12 and a half.
Yeah. So, so if that's the case, you know, Alan, I don't know what you think, but every time I turn Around, alright, lemme tell you what I think I've been very patient. Let me just say the emperor has no clothes here.
It's no secret around the world that this buffoon can be played like a cheap suit on a, in a, in a nickel piano bar. You come up and tell 'em what you're going to do, and the more you promise and the more outlandish it is, the more he touts it. This is not a new script.
Where's where's the money from? Uh, son, from SoftBank, from the last time he was president, they never invested damn time. Where's name is Boss, right?
I'm not done yet. Where's the factory that TSMC was building the last time we were here that they never broke ground on? Has any of these MFS ever spent anywhere near the money they say they were gonna spend?
This isn't an old IBM thing. Macron did it yesterday in the White House too. This is theater at its best when you've got Charlie Chaplin playing the dictator.
And people could come in and do it and say whatever they want and he gets all happy about it. Guys, wake up, smell the coffee. First of all, what, what exact AI server is Apple making?
Are they going into the server business? Is that what I'm assume? Is that what I'm hearing?
Because I I'm not aware of any Apple servers. Mm-hmm. It's only the ones that they use for their own cloud services, theoretically.
Yeah. Yeah. They don't make servers stop.
Oh, you kidding? He But Alan Allen Cook could just make something up. He Just come up with any type jumbo.
It's not smarter than everyone else. Right. They all make s**t up because that's what we live in.
We live in a b******t world where the more you BS and the bigger the Bs and the louder you say it, and the more you say it, the more he expects people to believe it. I've had enough. It's a month in and I'm done with it.
I don't believe a damn word that comes out of these things. Just as I, I didn't say it jokingly. This is the same thing with do saving us a trillion dollars.
If, if, if 1% of that is real, the whole thing's nonsense, but it's consumed by an audience that wants nonsense us. We're not gonna, not people. We deserve what we get.
So you don't believe that. So you don't, so you don't believe that Meta's going to, uh, plans to construct the world's largest undersea cable to advance, to expand high speed internet access globally then? I'm being Facetious.
Well, no. Why would we give them our access? I'm being very facetious.
We're gonna keep all our internet access here. But Alan, you don't understand. We wanna believe, we wanna believe we want this to be true.
Because if we don't, then we're wrong. And that would be bad. We're not gonna admit we're wrong.
I'm saying we at the bigger we, not me. Yeah. No, I mean, we, we could say whatever you want, but look the facts, bear it out.
Right. Some of the nonsense too is like, how many of these jobs are actually gonna get created? Even if I built this giant factory in Houston, all that's automated.
So there's not gonna be actually a whole lot of people getting additional jobs just other than that guy maybe who's overseeing the robotic construction engine. Well, Yeah. That's, that's what can, I'll just show you the ludicrous, the, the ridiculousness of this take 20,000 jobs divided into 500 billion.
What does each job costing you? A lot? Well, yeah, that's, Each job cost something like $50 million.
Those are real expensive. F*****g, excuse my language, those are real expensive jobs. Those are real expensive jobs.
Let's, let's to pretty It Up To pretty it up. Apple said they were gonna focus on r and d, the jobs r and d, Silicon engineering. What?
Ai machine learning. Again, it's, you know, just feed the beast. Just tell the emperor what he wants to hear.
That's all. Not his ed approving. This is some, I'm not sure if it's quite Caligula or was still at Niro, but it's something in that, in that range right there.
I never thought I'd hear Caligula on this show. Wow. It's $25 million a job, by the way, Alan?
25 million. Excuse me. Okay.
Those are some pretty expensive jobs. So who, the math doesn't even work, but who cares? These people don't care.
We won. We won. You know, Irony.
They do think they really are gonna open some factories. Like are they opening a factory? Are Their AI servers Okay?
They don't have AI servers, Samantha. But, But I'm just saying, do we think they are? Like, are they gonna build a factory to start AI servers?
I'm just curious. I I think they'll build something that looks like a factory, but there won't be any workers in it because it's all gonna be run by robot. We all bought.
I Mean, look, if you're, if if Apple was serious, they would talk about building iPhones mm-hmm. In the us You know, the, the, the irony, the irony in all this is that the guy who told the truth about how ridiculous this is is Musk in his own weird way when he said that the Stargate would never bring up five, spend $500 billion, let alone raise the money. So, I mean, in a sense, he knows how, how patently ridiculous this is.
So Well, but, but, but, so there's the corruptness of the whole thing at the very top. The people like Musk and even, I don't know about Trump 'cause he, he is in a bit of his own world, but, but Musk and some of the other evil generals behind this, they know that this is all for public consumption. That this has no, no foot in reality, but it's red meat for the masses who, who consumed this crap, who are gonna say, look what he did it.
And, and no immigrants will work there either. No H one B visas on all red blooded ADEs. And it's a good thing all those people were laying off and the government will now have jobs working for Apple.
Hey, 20 million, 25 million job. I quit my government job for that job too. I'll just take the recruiting fee on that on this guys.
So I, for 1:00 AM not going to be I, that's not me. Right. My fail.
Yeah. You know, I rewind. This Is like the most, this is the most effective news Apple has announced in a long time since the products have, have been exactly knocked our socks off lately.
So, Well if they, I guess it's a great free marketing for them of products. Yep. So do you think we're gonna see, you know, Samsung show up and start talking about how they're gonna make phones in the US and Yes.
Factory next door to Apple. Mm-hmm. You know what they say?
Talk, Talking about? Yes. Mm-hmm.
Talk is cheap. And if that's all it takes that and a little flattery and they'll vote for you in the un resolution too. You're good.
I mean, this is the state of the world we live in. As, as, as Laurel would say to Hardy or Hardy would say to Laurel, it's a fine mess We've gotten ourselves into, you used to say the new normal. It is the new normal right now.
Well, On behalf of Textron and John and Amanda, I'd like to pledge right now that we're gonna write 50 billion words about this in the next five Years. Seems like we have actually No, I'm just kidding. Mm-hmm.
That's for sure words. That's about right. Transcribe this video about 20,000 times and you're close.
I'm just trying to find anything to add to this. You know, as a Siri person in the room, lemme just say it, right? You know, I said, I think you're all right.
You know, I think you're all correct. And I think, uh, Tim, uh, cook is, is in his corporate role and his responsibility to shareholder value doing, as you discuss exactly the right things, stand just outside the picture, say the right sort of mouth things, you know, and, and protect the, the corporate interest. Um, and Alan, I, you're right as well.
Like, this is again, as we discussed, this is this information warfare environment we're in. Where when you get to the point where, you know, the, the Steve Bannon goal of bearing the field in, let's say manure, um, to the point that nobody can tell one thing from the other, that's when just shouting works the best because nobody can figure out what's true. So the loudest voice wins.
And as, as you know, aside from every other role, you know, anybody in my profession has, you know, remembering that it's information security, not cybersecurity. You know, we're the folks supposed to understand how information can move around in ways that people can use that It's not working right now. We've got work to do by the answer.
Dunno. But yeah, that's, this is the world we live in, Certainly is my friends. All right.
Um, let us take a break here on Textron Gang. Let's calculate how much we could really pledge of what we're going to commit over the next four years. We'll be back.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching it, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. 4 billion on AI and data centers and all kinds of fun things. And Chris, you know, I'd love to get your opinions here because one of the things people don't really talk that much about Alibaba is they have data centers in Northern Virginia and California.
And given the current climate, how political do you think all this is gonna get? Are we gonna wind up someday serving eviction notices to Alibaba to kick 'em out of the country? Because everybody's just gonna line up on their favorite national boundaries.
And I'll add Lenovo into that mix too. So how crazy can crazy get, Oh, it can get really crazy. That's a, that's the thing about crazy, right?
The the range is always wide, and I don't know, it, it's, it has a Cold War kid, right? I, I have this funniest sort of slanted view of what's going on in the world right now, because I grew up with the idea that we have these countries, the Soviet Union and China behind their gray walls, you know, they're just, they've cut themselves off from the world where we are the free market, free speech capitalist, DD democracy side of the world. And we'll engage with everybody.
We'll, in fact, create a global supply chain and we'll teach you how to, you know, do the same things we do back at home so that you can do the same thing and make money and heck buy our product, sell us something. Heck, you know, we'll, we'll, we'll go nuts. Which is the, the whole American thing, right?
And all my life, my, I as, as I've said, you know, I belong to all three major political parties at different times. I believe that each time I, I think there's interesting points we have is a bunch of crazy yanks, but that's what it boils down to, right? Right.
Almost unique. You know, I, I think I love this country. I think it's, it, it maybe, it certainly is, you know, everything's unique, but I think we have a special role in this, and I'm a security person, I get it.
So watching Russia cut itself off from the world, you know, a, a krep, uh, uh, you know, dictatorship from this classic, uh, doke, right? You know, watching China go the opposite direction. Anybody, any American who's done business in China, you know, in the re the modern area, you walk around, it is a capitalist, boiling furnace.
People will sell you things. You can't walk fast enough not to be sold something walking down the streets. And then to see us now arguing the exact opposite of everything we've argued since Eisenhower, right?
You know, let's wall ourselves off and let's make sure that we can, I don't, I don't think that's the right direction at all. Um, but I will say that, you know, on the security, you know, having supply chain is a thing, and we really do need to, for a purely security reason, know what's in our stuff and who did it, and, and to the right level of no, all the way down. And we haven't been able to, um, we can't feel comfortable about things, not just in these massive geopolitical things, but really anything until we can figure out how to do that, and we're getting there, we will get, you know, it is achievable now this decade to implement in a individual sector, for example.
Um, really astounding visibility in the supply chain. Now, if we had that, and you could then say, now at the nation state level, geopolitically, you know, we have these concerns, where is it? Instead of just napalming, you know, entire continents with policies, you know, that might be a different world.
I don't know, John, one of the things you hear all the time is that we're losing the AI race to China. And I can't tell if that's real or if that's just some scam that the valley's running to get more funding on Wall Street and the, and the government. I think it's the fear of missing out.
You're right. It's, it's the whole FOMO factor that we mentioned at the top of the show, right? You just, you just create this.
I mean, it was like the us uh, channeling what Chris said, going back to the Cold War, the d the defense contractors would, would warn us about the, the nuclear arms race and how we, there was a missile gap. And then we would, in a sense, get more funding, more funding, more funding for defense. I think the same thing's happening in Silicon Valley where there's this fear factor.
Deep seek really hit home with it. And in fact, deep seek is coming out with its sequel to R one very soon, evidently, according to a, a Reuters report. So there's this, this, this, this calculus that the companies are making here, because they're getting so much funding for anything that's AI related, even if it's a silly idea.
And, and again, you, you prop up China as the big enemy, you know, deep seek, uh, Alibaba, whomever, or by dance. And you, you, you create this enemy, you create this fear, and it just helps you, it just is very self-rewarding. So, you're right, Mike, this is, this is where it's going.
And the, the narrative's just gonna intensify, and you're seeing it like every other day. There's like some ridiculous amount of money allegedly going to a project. Um, and it's, it, in a sense, it'd be interesting to see in hindsight, what percentage of the money's actually spent that's been promised.
You know, it probably is gonna be less than 20%. Well, you know, uh, John is, we, we, if you remember back to too big to fail, right? The institutions that are so big, we can't allow 'em to fail.
We, we have a similar kind of attitude around ai, I think at all levels in the, whether it's nation states or the latest startup is AI is, is too important to lose out. And so that's why we see such massive dollars being spent on data, ai data centers, or at least, and the big claims, the $500 billion kind of claims. Some of it is marketing position and, you know, keeping your name in the, in the conversation.
And some of it is real spend. But we're in this race to spend as much money kind of race to the bottom of how much money can we spend on ai just out of fear of losing. And at some point that will of course be so over overburdened in terms of bubbles and market sizes and ridiculousness that we'll, we'll pay the price for it.
But that, that's the era I think we're in right now, Right? It'll correct itself. It's just a question of how long this is gonna last.
I mean, it could be six months, it could be a year that there's such a volatile pace to all, everything that's going on in terms of the funding, the promises, the, the models that come out seemingly every day, that, that beat others in terms of benchmarks, which are very nebulous to be, to be charitable, Little irrational exuberance. Anyone. Um, so let me, let me give you my shimmy take on this one.
You know, I, I spoke about this, I think it was two weeks ago, and I called it, uh, AI imperialism, right? And that's what you got going on here, right? Let, make no mistake about it, Russia is probably not in this race until, until we become very, very close allies.
And Trump will probably transfer some of our best AI technology and build some factories and data centers in Moscow and, and St. Petersburg. 'cause after all, they are, are our best friends historically.
Um, but the real race here is every world power is trying to take, become a leader in ai, right? That deep seek with Sputnik. And now the us my God, they're panicking.
And we're gonna spend $500 billion on Stargate, and we're gonna do this. And Apple's spending another 500 billion, and we're putting it all here. We're gonna be the US leaders of, well, we don't wanna be leaders of the free world.
We're just gonna be the us the greatest country on earth, and it's all gonna be right here. And if you want to use it, you gotta come here. If you're over there, you can't use it.
You gotta come here. Europe says, well, we're not coming here. We're gonna make our own thing.
And we're investing a couple hundred billion dollars too, including Ukraine, right? Then you've got China, and, and China's a different cat because when Aaba says they get 52 plus billion dollars, you got the full faith and credit of the Chinese government behind them, basically, who own, I don't know, a couple trillion dollars of US bonds, right? And their game is clear.
They wanna be the preeminent power in AI because they'll be the rest of the world who is gonna want to use it? And that's really the game here. Who, who's gonna own the Spice trade?
It's the same game that's been going on in on earth for the last 500 or more years. Who's gonna own the Spice Trade? Who's going to, who's going to have the, not the monopoly, but the best of whatever the latest commodity is, right?
We're fighting for, dude, it's a rakus. He who owns price, the oil fields, it's name, the name, the, you know, most important asset. Chris, do we need, do we need the equivalent of a speech from President Eisenhower warning us about the AI industrial complex?
Uh, no. Right? You know, I, I, I, I have to, I had to put some light back in the room.
And, uh, not that, not that the, the doom prognostications or or risks aren't all over the place, you know, and, and yeah, I mean, and well, my last comment, I was thinking more general, generally, right? As you guys were saying, you know, there's, there's a lot of posturing of money I arguably throwing around and so on and so forth. And it is what it is.
You know, I'll believe it when I see it. Um, but, uh, you know, I, I think, you know, I think like a lot of waves, I'm a little crazier and stupider this time for various reasons. It's right and it's wrong.
I think that it is important. I think what we're currently calling ai, oh gosh, it's kind of what we've always thought computers are supposed to be. You know, we shouldn't have to actually know how this transistors work at the atomic level to be able to use the bloody things, you know?
So the irrational exuberance is at every level, right? So the, so our governments and our governing bodies in the state that they are responding as, as you folks are saying, kind of stupidly, you know? But, you know, and it could be the end of the world, you know, lots of things could be the end of the world.
But, uh, I don't know. I don't think the, I don't think a a nation, we, number one, we don't have an Eisenhower or anything like it. Um, and I, we don't have the same sort of reach.
There's not three channels, Right. You know, Do anything about this. You, you, you know, there, there was this in his, remember in his farewell address, Biden referred to the tech industrial complex.
I think that's what he, how he, he phrased it as kind of a warning shot as he was leaving. Since he left, things only intensified. It was almost as if he never said anything, which is probably par for the course, but, and it was, it was ignored, if anything, things accelerated and, and tech got more powerful.
So his warning shot was kind of an echo and a distant cave. Mm-hmm. I guess.
Well, you know, if you whisper for something, nobody's gonna hear it. So that's kinda, I wasn't gonna go there, but you're right. Yeah.
I mean, it's, it's a mess. As an entrepreneur. I mean, John, you're right.
You know, I mean, it's, it's funny, you know, among my left-handed friends, you know, I'm the capitalist pig corporate guy, right? Goes on pretty, I really believe in all that stuff. And, but this doesn't help.
Right? You know, concentrating all the wealth in a couple of hands and all that, that's, we did that for like, I don't know, most of human history. Um, the idea is to have consumers who can afford to buy things and start companies and do stuff.
So all this 500 billion here, 500 billion there, and tech bros who, you know, dominate the everything. This, this isn't great capitalism, aside from everything else, what it's supposed to be cut At is this move from Alibaba. It's a sad state of affairs, affairs when the Chinese not capitalist us.
Uh, but this move is clearly, they are planting flags in AI throughout the world. They wanna be the world's AI provider. And, and don't kid yourself, Tencent, Alibaba, Baidu, these companies have the, the muscle, especially if we retrench and just focus inward, that will, we could wind up not being the leader in ai.
That's true. And if you're sitting in Africa or Asia somewhere, and you're watching what the Americans are saying, who are you gonna turn to? Absolutely.
And that's, and that, that is, that's the game here. That's the game. But don't worry, we'll have Russia.
So I'm genuinely, um, curious, I just wanna hear your thoughts. Um, are there any security concerns that the rest of the world will have to have if one country comes out way on top with AI and con controls most of the ai, will there be security concerns for the rest of the world? Or that is Concern Amanda?
Security dominance in the world is obviously from weapons to economies to you name it. I mean, that's the concern. There's reasons for this big race that we're having.
Yeah. Well, it's like the, like the, the space race, right? You know, and a lot of people, you know, I live on starlink, right?
I, I had the opportunity to, uh, from long conversation with Gwen Shotwell, who runs SpaceX and Starling and all that, uh, like five years ago, and I've been using it ever since. And it is mean a lot of people saying right now, all these satellites and Kessler syndrome and messing with astronomy and so forth, the editors stand that this is, this time China is putting up massive, Europe is putting up massive communication satellites. We're in the era where there can be massive s uh, satellite communications array.
You know, there need to be more than one. And one of anything is, is dangerous and risky. Um, this, this issue, ai, big, big huge ai, right?
The sky net potential ai. Yeah. There need to be more than one, right?
It's all to all the conspiracy theorists out there, right? You know, even if you're right, there's seven other conspiracies, they're, they're arguing amongst themselves. I think mostly we can ignore things as long as there's not too much concentration in one spot.
And this is, yeah, I don't think we're at risk of that actually happening. I think we're at risk of global conflict because of perceptions is not happening. But, uh, but yeah, we can't have, there cannot be only one.
This is not Highlander. Okay. Alrighty, let's take a break Reference.
But I got, Could be only one. Sean Conner. Anyway, hey, let's take a break here on text Sean Gang.
We'll come back. We've got our third block to go over. Hopefully it's a little less contentious.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
All right, we're back with that slightly less contentious se segment that we're about to talk about, where the president took time out of his incredibly busy schedule to call out the European Union for applying taxes slash tariffs to digital services that are created outside the, of their particular country and region. Uh, that got a quick response from the EU country saying, uh, a mine drone business essentially. And we'll continue to do what we're gonna do.
But, um, this managed to get rolled up into this tariff conversation, and we talked about the impact tariffs were having on tech last week, or I don't think Alan was on that show, but, um, as you look at this, isn't there kind of strange to me at least, that everybody in the tech sector who showed up for that photo that John was talking about, last segment, has a stake in this conversation. So, is there aqui pro quo at work here? Alan, First of all, let me mention that was probably a decision he made between the eighth and ninth hole, how hard he was work.
But that, that all being said, surprisingly, this is not one where I strongly, strongly disagree. I, I, I'm against tariffs in, in, you know, as, as, as Chris said, I also grew up as a Cold War baby where the US was about free trade, and we're gonna out trade out, manufacture out, innovate, right? To maintain our leadership in the world, not, not put up walls.
Um, however, the EU clearly put up walls, right? The eu, and, and I understand why they did it. They, they, they were trying to get their mojo back, right?
And, and become a world player. And so they, they put in, they impose these digital service taxes, um, on anything not coming out of there. com days and company, I helped, uh, build inter reliant.
We, we did a deal with Sagittal in France, and we wound up putting a data center in, uh, right outta Paris. And, and we did a lot of, of, uh, European business. And, and there was clearly home cooking at play, right?
And if you were a, you know, a US company, it, it, they made it a little bit harder for you. Um, I'm not against the u I'm, I'm against the US doing tariffs, but I'm not for the EU doing tariffs either. I think we all have to play by the same rules.
And so if this is a case of, Hey, you show me yours, I'll show you mine, and let's all go back to even Steven, right? And just let the chips forward. They may, I'm all for it, but if you are going to tax us firms because you want to encourage a domestic EU domestic, um, industry of di you know, digital business, I, I don't think there's anything a matter with us reciprocating with that.
And as long as that's what it is, but that it, it sh I think we have to said, we have to remember that that doesn't mean they're not our allies or that we should go cozy up with the, the dictators in the authoritarians of the world. But I think we, we all benefit when we have an equal playing field. How that, you know, it's almost like there's three levels of this.
One is terrace, four, you're trying to incense some behavior or dis some behavior. Then there's the, uh, response to that, right? Uh, okay, if you're gonna do that, I'm gonna do that.
Then there's this third tier of I, I'll use it as a, as a, a bludgeoning tool, uh, as a political tool to get people's either to get people's attention or maybe really to, to, uh, punish people that we don't like because of some political, whether it's, you know, border crossings or drugs or whatever we wanna name it. I, I question whether at all that's really true, why Trump is doing, I think it's largely a negotiating ploy to get people's attention and to basically bully them into what he wants. So we seem to be doing a lot more of that.
And I suspect that you use response is probably more of this kind of first and middle tier, but you don't know that either. It, it's just interesting how we're suddenly thrust into this. Tariffs are only about politics, and of course they aren't.
So the thing with the tariffs though, is it seems like when we reciprocate, it's not one for one, right? We'll turn around and we will say, you know, we're gonna slap tariffs on, you know, wine because they're taxing digital services. So how do we keep this thing from escalating to the point where, you know, it just becomes this arms race of tariffs back and forth to the point where we just all destroy our respective economies.
Yeah. I've never much understood the point. Of course, I'm not in economics, uh, and I'm sure there's people who, who know better, but I've never understood the point.
'cause it just seems like one country imposes a tariff and the other country imposes it right back. So you either all have a bunch of tariffs, or you all don't have tariffs. I mean, really, it doesn't, I don't get how it works, I guess, but I, again, I'm not in economics, so, Well, I think you're spot on 'cause it doesn't work.
So that's it. Well, you know what, the idea here is fully expecting that we're gonna get into this tariff tip for tat. And the thought is, well, our market's bigger than yours, and so you wanna be here more than we wanna be there.
And, and that used to work, I think when Eisenhower spoke about the industrial military complex, complex. But you know, when you look at the combined European market, it ain't a heck of a lot smaller than the US market. When you look at, you know, from both a population and, and you know, dollars, euros, European, uh, Chinese market, not a heck of a lot smaller than ours in a much bigger population.
India rising, huge population, right? So, you know, thi this is, this is who's gonna stay in the latest, right? A little bit of a game of chicken is what you're playing.
Mm-hmm. So, So taking your thought about free markets, and let's just keep them open though. What happens though when, um, suddenly China uses its manufacturing muscle to flood the US car market and we're all driving Chinese cars?
Is that okay? Because they cost a third of us cars, or No? So here, go ahead Chris.
Go ahead. No, no, you go. So, So in, in, I think about, I'm trying to think of this in a security model, right?
You know, so you would think that security people would be happier with more security. Um, that's not true, right? You know, 'cause you can have as much security as you want.
We can lock your front door, we can lock every door in your house. We can make the keys to the locks in your doors in your house, so hard to get to that you stop using rooms, right? You know, and this tariffs, and as we all know, we're in this information space where it's hard to you, you really have to love tariffs or hate them.
You have to love firewalls or hate firewalls. You have to have no, no doors whatsoever, or all the doors need to be cemented shut. And, you know, to your, to your point, Mike, yeah, sometimes tariffs economic, you know, uh, vehicles, you know, need to be used to or levers need to be used in negotiations.
And that's how you deal with that sort of thing. You slam a tariff on it. But when you start putting, just saying, we're gonna have firewalls at every internet connection and every light bulb, and you're gonna get access by the system administrator who you can get between the hours of nine to five on Wednesdays, you don't have a network anymore or an economy.
That's true. And it's every other Wednesday and just Wednesdays. Um, but a a again, i I just, you know, if we're gonna go free, so with the Chinese cars in particular, you know, Thomas Friedman in his series of flat Earth books said, everyone wants to live like an American.
They don't necessarily wanna live in America. They don't necessarily agree with everything the US is about, but one thing they all want to do is live that American lifestyle, consume, you know, live a good life. It happened to Japan, right?
And it's happened in China. When we talk about Chinese cars, for instance, flooding the US market, the thought is, it's not that they outcompete us and make a better car. The thought is, is that those cars are subsidized by the Chinese government so that they, the the costs are artificially low and not true when you take out the government subsidies, or even worse, they're made with slave LA labor from the Muslim, uh, territories in China where, you know, know, and it, and it's forced labor, right?
Part of that free market thing is, hey, if, if it's truly a free market, if it's truly a worldwide free market, all things equal and you out innovate us out, produ produce us our smarter than us, more power to you. But if you're, if you're using government subsidies free or forced slave labor, child labor, in other words, you're not playing by the same rules, then there's nothing you matter with putting up barriers to that. So if the Chinese can build a better car than we can in Ohio or Detroit or, or anywhere else in this country, more power to 'em.
I don't think that's the case with Chinese cars, though. I think they are heavily subsidized. I think the, the r and d work comes out of Chinese research labs.
I think, you know, the, the labor is, you know, you for instance, well forget cars for a second. Let's look at Foxconn and the iPhones, right? Those, they used to make it very cheap, but when they had to start kind of playing by the same rules, all of a sudden it wasn't so cheap to make 'em there no more.
So that's where I am on, on, on the free market. Some would say the, uh, r and d for those Chinese cars came from Detroit and Germany, That that's a whole, right? And that's another joke that could very well be too.
That could very well be too. And if you prove that that's the case, that's yet another reason to put up barriers. Yeah, but here's where it kind of gets very complicated in my mind because, so if you go to Africa or even South America, you start to see more and more of these Chinese cars.
So they're not just leveraging up to own their own market. They're leveraging up to own other markets around the world that we can slot tariffs on. But then that gives Those markets, we only care about our market.
Well, we have to care about Shortsighted. But, but you just put the nail on the head, Mike, is we live in a global economy, we're all interconnected, and we have gotta figure out a way to outcompete our competitors. Putting up walls and trying to just isolate ourselves in here is not the answer to our competing our competitors.
That's why it's foreign into some of those countries. So they say the US are good people, Right? All right, we're gonna, we're gonna give you a discount on AI if you buy 10 Fords, Or maybe we'll help your people feed themselves.
Oh no, we can't do that anymore. We shut that down. All right, we're gonna end it on this cheerful note.
I just had one question. What are tariffs? It's a good question.
There, there, there, there are taxes that you pay that someone cons you into thinking somebody else is paying. Yeah. Oh, there's a lot of that.
Anyway, All I'm Derek to please. Are we gonna be back? Are we gonna be back tomorrow with more, Mike?
I can't wait to see what else you come up with for us, Don. I think I tried to put all the political stuff in one episode 'cause I thought, Hey, enjoy your Wednesday. We've got a lot of great text, drunk TV following this.
Probably a little less of this politically themed charged stuff. Um, we've got some good tech, which is why you come here. Um, we'll be back tomorrow with more.
But until then, on behalf of Chris and Amanda, John Mitchell, and Mike, I'm Alan Shimel, and we're outta here. This is Textron tv. Hi everyone.
Welcome back here to Textron tv. I've got a first time guest in a new company to introduce you to here, Alan Text Drunk. Today I wanna say hi to Chris Wingfield.
Chris is senior VP for Innovations at a company called 360 Privacy. Hey Chris, welcome to Text Drunk tv. It's great to have you on here.
Yeah, thanks Alan, appreciate the time. Looking forward to our discussion. Excellent, man.
So, you know, we're gonna talk 360 privacy and what you guys do, but before we do that, I thought we'd spend a minute or two kind of talking about you, right? Perfect. SVP of Innovations.
That's not a title I hear every day. How'd you get here? What did, what did, what'd you have to know?
Who'd you have to kill? What, you know, how, how, how does that all work? Yeah, well, some of that stuff's gonna be secret out, but you know, I'll give you the gist.
Uh, So, okay, obviously My name's Chris. My background, um, before 360, I was a digital targeter for the government. Uh, so I was a member of the intelligence community.
I was embedded within Special Operations Command. And what that afforded me really was the best balance between tactical intelligence experience and strategic intelligence. Meaning I was there on the ground doing the intelligence function, but I was also helping meet, you know, strategic national level initiatives.
Um, I started on the linguistic side of the house. I studied various international languages. I then moved over to the signals intelligence side of the house, which is dig digital targeting of anything with a signal.
So thank phones, thank radios, things of that nature. Uh, I spent a lot of time around the world, uh, in that capacity. And then three years ago, uh, got out of the government space, moved back to the Northeast where I'm originally from, and I came to work at 360 Privacy.
Um, the innovation piece is interesting, right? Because I actually started as the director of Cyber Threat Intelligence. The purpose of that was, let me take all of the, the lessons I learned, the experience I had from the intelligence community.
I know how to target people. Let's target ultra high net worth individuals, executives identify points of exploitation so that 360 can provide remediation and mitigation solutions for those points. So really it's to help these executives live a little bit more of a normal life because they're not really afforded that because of their position.
Now, because of my background targeting people, I like to stay agile as this is tax surface continues to grow. So how I would target people continues to change, which means that we have to innovate through that. So having a domain driven design, it's not engineer driven, it's not product driven, it's domain driven, meaning as the domain changes, we have to change how we attack that problem set.
Man, the stories you could probably tell if you were allowed to tell 'em, huh? Yeah, absolutely. I've seen it.
A lot of the World. Where, where in the northeast are you? Uh, so greater Manhattan area.
All right, I was just there this weekend. I would've loved to grab a couple beers and, and get some, some real skinny, but next time, I'm gonna put you on my list next time. So Chris, let's, uh, let's talk 360.
Awesome. Privacy. Yeah.
So 360, uh, had an interesting start. Uh, you're gonna start seeing a common theme. Um, the CEO and founder was a former member of the special operations community.
Um, and you see that throughout the company, really, a lot of the beginning pieces of this company were special operations, community intelligence, community, uh, some corporate security individuals that were in charge of the physical security for some of the most prolific, you know, ultra high net worth people in the world that were clients of three sixty's before they came to work for 360 because they believed in what 360 was doing. They believed in the solution. But really how it started was the founder, uh, got out of the special operations community, was looking to do a physical security gig with Digital Flare, is kind of how we talk about it.
Um, but what he found within the country music theme, because the headquarters of 360 is in Nashville, um, he started to see that a lot of these physical threats were coming from a digital space. So what that turned into was, um, one of the most prolific, uh, country music stars, uh, of the last several decades. Unfortunately, you know, his bank account was taken over, his children were receiving text messages from his phone number that was spoofed.
So our CEO at the time, this was before 360, really jumped to see, hey, like, can I identify a who this person is? But the most important question was sitting down with the individual to say, how did you do this? Right?
So we found out it was a, you know, 20 something year old young female living in a trailer in the mid, in the mid east somewhere, stalking and That's right, exactly. Uh, somebody that had internet connection and she started to show him, Hey, like I was getting this through these people search sites. I was getting this through Google searches, things of that nature.
What he realized was, oh, maybe I can provide a solution to this. So he would go, he would delete this data. Two days later, the data was back.
So he realized, oh, this has to be a continuous scanning for this data. And so really that was the beginning. You know, how we became 360 privacy today and we went from the country music scene, which we still have a lot of people there, but over to, you know, ultra high net worth individuals.
Uh, you know, we have some Fortune 10 companies, uh, up to the Fortune 2000 companies, a lot of celebrities, a lot of professional athletes. And really the whole purpose of it is we look at you as this is your attack surface. So 360 is an attack surface reduction company.
So if you take you Alan, right, like through, through a Google search, maybe I can find some P-I-I-F-A. So now this is part of your attack surface and there's people search sites that have data about you. There's dark web data.
Well, the beauty of what we do is we try to look at each of those as one holistic issue. And if we can start reducing that, we make you a harder target. We make you harder to find, is what I tell clients is you're always one Google search away from someone turning a digital threat into a physical threat.
And so 360 wants to reduce that visibility so that what they see on Google is your LinkedIn, your company, the podcasts that you do, the webinars that you do, but they don't want, you don't need to see your physical address, your phone number, your relatives, and things of that nature. We live in interesting times though, right? We do.
I mean, I think everyone out here watching has probably gotten at least three letters in the mail this past year that they were the victims of a breach. Their PII was stored at Take your pick company. I mean, I know personally, you know, there's things like LifeLock and I, I used something with Experian where they're always telling me, you know, where I am on these people finder sites and trying to, and you is, it's a whack-a-mole game.
It's the people finder's a whack-a-mole man. But more ominous was, you know, I got, I remember, so I have a boat and the place I bought the boat from was a data breach. And they sent me a scary email that, I mean, they got every, they took social security numbers, addresses, everything, and they were nice enough to offer me a year of credit monitoring goes, that's the whatever.
That was really nice. Um, that was nice of them, right? And um, so I mean, for so many of us, not even, you know, VIP people we're up the creek or not the paddle.
We are all just one search away from, from Rub. Now some of us have more to lose than others, but you know, Chris, another lesson I learned in, I've been in security 25 plus years. Another lesson I learned in insecurity is unfortunately people don't get religion until, until you know something bad happens.
Right? Then all of a sudden they're big believers. They're big believers.
That's right. Um, so yeah, it's kind of chicken and eggy kind of stuff. 360 privacy.
Most of your customers come to you after they maybe have had an incident, or are they being proactive now? 'cause people are smarter. So I'd say it, it was a mix, right?
I'd say in early 20 24, 20 23, late 2022, a lot of it was probably post-incident Allen, right? Like, but I do believe now that, because you know, if somebody goes to Google right now and you search just first name, last name, city State, and then just type the words home address, you're gonna start seeing white pages and BIM verified and re and all these people search sites come up. So I believe that the situational awareness level has raised so much to where now people are more proactively reaching out about solutions, um, reputationally, right?
Like if you have people in the Fortune 10 to the Fortune 2000, all of a sudden if you're a good solution, people are gonna say, Hey, like use 360 privacy for this because it's all about a risk-based approach, right, Alan? 'cause you said, you know, everybody has something else to lose, right? A thousand dollars from an ultra high net worth executive isn't that much, but a thousand dollars from an everyday person may be a huge impact to their daily life.
And what I tell clients is, you know, just because you're not on social media, like the largest data brokers are the credit bureaus and everybody has credit scores. So we're all affected by this problem. And 360 tries to look at this as a multi-layered approach of, you know, I can't go to a credentialed data set like Axiom or LexisNexis and tell them I want you to delete my data, but I can go there and say, I want you to opt me out of the sale of that information.
Right? So what that does is hopefully what slow down that, you know, trickle downstream to these people search sites. So you want hit it from the top of the funnel.
You want to hit as many people search sites as you can, but honestly, visibility is the most important part out. Like if somebody could find you on Google or a Bing search, it doesn't matter if I removed you from 10 million websites. 'cause if you're still coming up on Google, it only takes one.
It only takes one. That's right. So the problem said is very optimal.
It's very agile. We have to continue to evolve with space to stay relevant and to keep people safe. Sure.
So Chris, one of the, in my time in security, as I said, 25 plus years, one of the big things certainly over the last 10 to 15 years has been, uh, a little bit of a change in focus. A little bit of a change in emphasis from pure prevention to response, right? So I'm not saying don't try to prevent these things, right?
You play the whack-a-mole game, you do what you can to minimize your, your attack surface, as you said, your profile online. But stuff happens. Does 360 privacy help once that stuff has happened?
How do, and if so, how? Yeah, that's, that's a great question. So, you know how, like it is a whack-a-mole game, but unfortunately some of these moles could be remediated and a lot of them can only be mitigated, right?
Because say like national public data breach in August 272 million unique Social security numbers, right? Like, can we remove that data from dark web after it? It's like absolutely not, right?
But are there actual tangible mitigation steps that we can take to better protect a principal? Right? And that's where 360 is different.
We're not so much a consumer level option. We're much more, you know, white glove concierge level option. Because after that happened, within 24 hours, we reached out to over 700 clients to say, Hey, this is what happened.
This was the data, and this is actually the tangible steps you can take. We got on calls, we shared our screen because some of our clients, they don't know what a credit freeze is, right? So let's walk you through that.
Well, I'm buying real estate right now, or, you know, I can't freeze my credit because of X, Y, or Z. No problem. Secondary option.
Let's set up a fraud alert. So then we at least start adding layers of protection. So the answer to your question now is yes, because I can never get you to a zero.
And if somebody promises that you're gonna be a zero in the digital landscape in 2025, like it's completely erroneous because it's evolving so quickly. These data brokers repopulate data every single day, right? And then the next data breach happens, all of a sudden your social security number is out there.
So it's all about remediating what we can, mitigating everything else, and just making you as hard target as possible. 'cause Alan, if you have an LLC with your home address and your name on it, 360, can't change that for you. But we know lawyers and we know how to help you and we can guide you through a process to put that into a blind trust.
You know, there's a lot of different ways that we can mitigate issues from that. It's all about, uh, cutting the connections between different data points. Because as long as we can start start making those harder targets, the lower level threat actors are not gonna be able to connect those pieces.
Absolutely, man, I, I would love to see us move, just move away from social security numbers as a personal identifier to tell you the truth. 'cause I, I do think at this point in the game, that's pretty useless with, with all of the breaches that we've had there. I don't know if you want to talk about this, Chris, but like, what is a, a white glove concierge kind of service like this cost, uh, uh, an individual or an organization?
Yeah, Yeah, that's fine. I mean, obviously depending on the size of the contract and the quantity, obviously there's gonna be discounts of volume. But typically our base package is $5,250 a year.
Uh, that's an annual subscription. Um, and a lot of that is just to say, you know, the work that goes into it because you're speaking to people that have done this, right? And like, that's why I'm very big on the domain driven approach to, you know, product and engineering because this isn't people or engineers that saw a problem, don't understand the core of the issue and just try to create automation around it.
Because to automate something, we need to understand how to make it in the first place and then replicate that through a manual to automated framework. And so you're dealing with people that have targeted before they understand how people are being targeted, and then the network space to make sure that goes there. And so really it's the daily cadence.
You look at consumer level options, they're typically going every month, every quarter. Issues with that is, you know, last month we had a data broker dump every profile 360 had ever removed from our entire database, right? For all of our clients.
We picked it up immediately and we deleted those immediately, right? Like that was our whole game plan. But if you're on a, a monthly even, you know, that may be out there for 29 days.
And that one website had all the city and states you've ever lived in all your relative names and your first, middle, last full name, right? So, and this is on a free data broker. This wasn't behind a paywall, et cetera.
So it's all about understanding the game. These data brokers, people search sites specifically, they're gonna pop up every day, arguably, right? And they may be downstream of another one, but that doesn't mean that if you removed from upstream that it removed from downstream.
There's just a lot to that concierge level. Oh, there's certainly, and, and I, and look, the fact of the matter is doing that is probably beyond the scope of what most people are comfortable being able to do, right? That's right.
And it is what it is. Chris, I don't think we mentioned the website for 360 Privacy. Yep.
io Io. Fantastic. I man.
All right. Hey Chris, thanks for coming on here and telling us about this. I, I, you know, this is a problem.
Yeah. It's, you know, my father-in-law rest his soul. He always used to say, rich report, it's nice to have money.
And, you know, if you're a high worth individual or someone with the, the means you, you become a bigger target. There's a bigger target on you back. It's the fact.
And if you, you know, you, you can engage a company like 360 privacy, but quite frankly, at five KA year or thereabouts, you know, there's a lot of people who might want to consider that going beyond, you know, the consumer level LifeLocks and, and stuff like that. Um, keep up the great work, man. We'd love to have you on.
And, you know, and hear its kinda real life stories of what's going on out there. 'cause this is a, it's, it's a crazy world we live in, man. It's just crazy.
It's, Yeah. Thanks for having me on A, I appreciate It. My pleasure.
Chris Wingfield, senior VP Innovations at 360 Privacy here on Techstrong tv. We're gonna take a break. We'll be back with more.
Hello and welcome to the latest edition of the Techstrong Do AI video series. I'm your host Mike Bezu. Today we're with Derek Hud, who is CEO for digital, do ai.
And we're gonna have a chat about, well, where does AG agentic AI fit in this whole spectrum of things that we've been playing around with. Derek, welcome to the show. Great to, uh, be here, Mike.
Thanks for having me. I think we rapidly went from, wow, we all gotta learn prompt engineering to now looking into all these so-called agents that are going to do certain things for us automatically. And when I talk to folks, everybody kind of nods their head, but then it quickly, they, I get a blank stare.
And I think the blank stare comes back to, well, I'm not sure I understand our processes well enough to insert an AI agent. So how do we kind of approach this when a lot of the things that we have been doing for so long in various processes are kind of road and we actually forgot how they work. It's a, it's a really, really good question.
And, uh, I, it, it's one of the things we think a lot about. I think those that have, um, uh, ironically automated sort of the old way, right? The hard coded automation of processes are often the ones that are most, uh, well positioned to take advantage of some of the AI capabilities.
'cause to your point, they've sort of documented these things through codification. But, um, look, we, we, we are super excited about, um, I think the productivity gains that are potential here, but I also see things at, at least at this current stage where you're gonna have a lot of humans involved, uh, in supervising, uh, some of the agentic behaviors. So, uh, while, while autonomy is obviously core to the, to the, the label of what makes, you know, regular generative AI different from let's say, agentic ai, um, I really do think, um, kind of breaking these things down to more smaller chunks where things can be handled and, and, and sort of the process is well understood and, and things can be handled in a more agentic way, we will build up from there.
But I think some of the, the, um, the hype around some of the broader scale, you know, does everything just give it a, a bit of a direction and it goes off and solves it? I think we're gonna, uh, ideally probably evolve to that versus that being the reality, uh, in the, in the foreseeable future. To your point, then, how will I orchestrate all these agents?
Many of which that a thing we're calling an agent is actually probably 20 different agents trained for different tasks. And if I want to manage something on an end-to-end basis, I have to orchestrate that. So where will that come from?
I, I think it's, it's a, it's the question and, and make it even more complicated. How do I govern it? How do I make sure that it's high quality?
How do, I mean all the things that we've thought about in what I would consider more like traditional software that is much more declarative, you now have to deal with in a much more complicated world. And I think that the key for me is, again, always taking these bigger items and breaking them down into piece parts. In the end, I look at whether it's, you know, traditional AI or, or generative AI or gen ai, all of these things are ultimately productivity tools, right?
And, and they help us ideally, uh, increase productivity, allow us to, to work on more creative work and less repetitive work. Um, I think the really interesting thinking about this wave of AI is it lowers the bar of entry even more because you don't need to know how to write code. Typically.
You can sort of just use natural language to interact at the same time to really have legs in the enterprise. It is gonna have to be explainable, it is gonna have to have high quality measures, et cetera, before I think anybody's gonna just let it go on its own. And so, really, we think about this as breaking these larger processes down into these sub subprocesses, and then identifying where AI can play a role in a safe, secure, you know, high, high quality way, um, in those lower levels.
I, I, I think about, um, uh, the evolutions of, uh, autonomous vehicles, well, albeit a bit of a different technology, uh, evolution, but like we we're gonna have fits and starts on this, right? I think it was back in 20 12, 20 13, I think we all thought we'd be not driving anymore come 2025, right? But we ran into some technology barriers, and a lot of that was around the edge cases.
A lot of that was around the fact that autonomous vehicles need to be right a hundred percent of the time, in theory, for people to, to be comfortable with them. I think you're gonna see some of the same adoption, uh, transformations as AI goes from, frankly, right now, a much better search engine. And, you know, something that helps me avoid writer's block and, and maybe helps me write code a little bit faster to like literally giving the keys, you know, keys to the, to the processes and allowing it to go end to end.
And your point, I also found myself having this conversation recently, where am I building AI agents or am I buying AI agents? And I'm probably gonna have a mix of these things, but some of these AI agents seem to be coming from Salesforce SAP Microsoft, and then in other instances, I'm gonna need to build my own AI agent that maybe knows my processes better. And how will these AI agents kind of interact, do you think?
Yeah, I, I mean, this is the thousand dollar question. I mean, ultimately, you know, we've thought about the internet as maybe one of the ultimate integration mechanisms, right? Kind of loosely coupled, uh, you know, protocols going back decades, uh, that frankly probably didn't know at the time how they were gonna be used, but it worked out pretty well.
Um, I think it gets even more challenging with, with ai, right? You have a, a, a set of discussions and concerns around data sovereignty. You got a, a, a, a set of discussions around, you know, how much is this all gonna cost?
And who am I even paying as agents are calling other agents? And so, again, it just to me is like a, a, a restatement of the fact that we're early days, we are now seeing the potential of what's possible, but how we get there is, uh, al always gonna be, I think, more incremental than, than maybe we suspect. Now, obviously, this is moving very, very quickly, but you know, the old adage, I forget, I think was a Stanford computer science professor, I highlighted that we tend to overestimate impact of technology in the near term and underestimated in the long term.
I think we're probably right in the midst of that right now. The other thing I'm also trying to sort in my head is, today we have MLOps where data science teams are using that process to kind of construct a model. And then when we build software, we have DevOps workflows.
Um, is an AI agent a type of artifact that will be built like by a DevOps team, or is it gonna be an extension of an MLOps workflow? And how do these things come together to drive something into production? It's A, it's a great question.
It's something that we're working very diligently at digital do AI as we all navigate this future. The, it's, it's really interesting when somebody asks the question, what's the, what role does AI have in, in, so the way software's developed and delivered, which is a question, you know, as the CEO of digital ai, I get a fair bit. The answer is like, multilayered right on.
On one hand, we are like everybody building out, uh, workflows in, into our existing tools, um, to, um, to, to leverage AI to make it easier to, you know, autonomously generate tests or, uh, or, uh, have intelligent pipelines that set old hard coded pipelines where the level of governance and, and risk management is ebbing and flowing based on, uh, uh, on some AI and machine learning views. Um, so there's the tooling piece. There's then the next piece that you just highlighted, which is all of our customers who have traditionally been using our tools for, for building, you know, more, more declarative AppSec, for lack of better term, right?
Like more traditional, uh, mobile AppSec and web services and whatnot, are now saying, how do we also add in AI into those, into those app experiences, right? And often, um, they are not building the AI themselves, but they are using models and using their own data and training it. And so now you've got not just model ops, but data ops and DevOps all have to converge together, right?
To successfully deliver, um, a, a product. And, and then you have a whole bunch of new, new questions around what does it mean to test such an application? What does it mean to secure such an application?
How do we get feedback when somebody calls the support desk and says, Hey, I I was using your app and x, y, Z happened. How do we replicate that in, in, in the development environment to be able to fix a potential bug or to at least, uh, determine whether a bug exists? I think we're still early days in a lot of those questions when you layer in, um, uh, this dependency on, uh, on ai, not in terms of how you use AI to build the product, but embedding AI into the solution, uh, itself.
So this is why we exist, right? Is to help our large scale enterprise customers figure that out. And we've been deferring referring to it internally as sort of, uh, X ops.
In other words, there's a whole, a whole bunch of these types of ops, whether it's traditional development or, or data or model, uh, or, you know, probably a long list of other things, um, that need, um, some of these be best practices that we've, we've leveraged for some time now in the more traditional development world. As we kind of think about how all these AI agents might play out together, I almost feel like we're working towards where we're adding AI to the DevOps and software engineering workflows, and then we're gonna use AI agents to build that out. And then we're also gonna apply that to security.
So in effect, are we not gonna wind up using AI agents to build AI agents? And they become even more kinda complicated with lots of little inter interdependencies. Yeah, it, it, it, it is, uh, uh, I mean, I think this is what a lot of folks are pontificating on.
And, and, and, um, you know, I, I'm, I always, I've learned a long time ago not to predict things that are 10 or 20 years out, right? So, uh, I'm, I'm more wrong than, uh, than right. But, but I, again, I go back to what's practical in today's world, in today's environment.
And, and I think the key for us is to really focusing, um, not just on what the technology could potentially do, but like, what is the business problem that we're solving? What is the business outcome, uh, that we're driving? And then is a, is an AI based solution, or is it more of a traditional solution, uh, that that is the right way to solve that problem?
So like, your, your scenario is potentially a very real scenario. Um, how quickly we get to that, um, and, and does that in itself create, um, a whole bunch of value? I, I think, again, I think we'll get there, um, uh, more incrementally, the, the old, uh, you know, the destination is, may, may or may not matter.
It's just the journey that's gonna get us there. And, um, I think I see people more kind of early, early stage just figuring out, like even things as simple as, for example, and, you know, I've had this conversation, if I can't measure how productive my development organization is today, how am I gonna compare that to a, an AI powered development organization, right? So some of these fundamental, uh, elements, when you think about what it takes, um, have I automated enough throughout the software development life cycle to take advantage of some of the productivity gains that we expect to see in certain areas, right?
I make, I, I write more code, but can I test it? Can I secure it? Can I get it into production?
Or am I simply creating a bottleneck elsewhere? Can I measure the, the, the before and the after? Can I, can I get a little bit more thoughtful about the way that, that we bring products to market and using some of the data that, uh, that is there to help us go faster when it's less risky and go a little slower when it's more risky?
So I think for, for all of these, I think it's gonna drive, interestingly enough, the promise of this potential future is actually driving very near term investments and very near term transformations around some of the best practices that we've been talking about for five or 10 years as a, as a, you know, a DevOps community, right? Using DevOps as a metaphor for all of this. We have this notion of observability in DevOps.
And when I look at these AI agents, something that crosses my mind a little bit is, we all talk about hallucinations, but, um, the models themselves and the AI agents drift over time. And how do we know that they're still doing what we intended them to do if we don't have some way of observing him? I, I, I, I, I totally agree with you, and I think what we'll come back to is number one, um, uh, the, the term observability in the industry has been very narrow, I would say historically.
Uh, mostly in production, mostly in sort of one area. I think you're gonna see the emergence of big O observability where we look not just in production, we look into development. And then to your point, we have to look at some of the more declarative, um, uh, uh, tools.
Things that, you know, when you click this button, we know exactly what happens and delineate that from some of the, the more, uh, generative of tools that, that, to your point, evolve over time. I, I also think this is part of the reason why, uh, again, um, how broad ag agentic gets, how big of a workload we hand over to the models and say, have at it. I think we're gonna start much smaller, because to your point, it's, it's much easier to, to identify some of that, uh, uh, some of the hallucinations, some of the drift, et cetera, in smaller work items than it is to see it in the bigger.
And, and, um, I, I actually think hallucinations are not being discussed enough. I i, if you, if you want to be frank, 'cause I think it is actually, um, probably for the, for the big model creators, it's not a convenient topic to discuss because it, uh, is a bit of a challenge. But again, go back to that autonomous vehicle example.
Um, we've, if I'm gonna hand over the keys to the way, you know, uh, support interacts with, with our, my customers, or I'm gonna hand it over to other, like, really mission critical things within my business, it's gotta be right a hundred percent of the time. And today it's not. And to your point, gen AI and the agents themselves are probabilistic, and then they take a reasonably informed guess, but we seem to be wanting to insert them into processes that are deterministic, and they're supposed to be done the same way each time a hundred percent of the time.
And no model does the same thing the same way, the same every time. We, we, we experience this ourselves, right? Just interacting.
Uh, you ask one question once and you ask it again, and you get a different answer. I, it's funny, and I forget who I should give credit to this, this is not an original thought, but somebody had, had asked a question is, is, uh, language knowledge, right? Because like in the end, what the, what the, the generative AI models that are really good at is the language piece predicting the next letter, the next word, et cetera.
Um, but, but even the computer scientists that have created these models have a hard time explaining exactly how it all, uh, how it all actually works. And so, um, does it really equate to knowledge and, and your points to the right one is you get to these more complicated scenarios, um, that is where, um, knowledge, uh, is required. And, and go all the way back to your first question.
Um, if I can't explain a process or how it's supposed to work, or I've not documented, or I've not codified it, how can we expect the, the, um, uh, the agents, uh, to follow it? So again, what, what, what I like about it, it's very, very similar. If you go back, you know, the person, the early days of personal computer, the early days of the internet, we, we both presented a much more robust, uh, much faster transformation than ended up happening.
We also had the tech optimist and the tech pessimist at the time, right? Some saying that all the jobs were gonna go away, and others saying, yeah, but don't, don't you think we'll create a whole bunch of new opportunities for new products, new jobs, new processes? Um, I tend to be in the optimist, uh, uh, camp, um, as just seeing the last few waves.
Um, but, but again, we've sort of always, I think, uh, uh, overestimated what, what's gonna happen today, tomorrow, six months from now. And, and again, probably underestimated what happens 10, 20, 30 years from now. In general.
I kind of feel like we're all a little conflicted. On the one hand, there's been a lot of talk about eliminating a lot of the regulatory oversight around AI as of late. And then at the same breath, people are saying, well, I don't know what I wanna automate using this stuff 'cause I'm afraid I don't know what's gonna be regulated tomorrow and if I'm gonna roll it back.
So are we kind of stuck in some sort of quandary? Yeah, I think a little bit, although again, I always go back to the, the history in these things and whether it's like way back to the automotive revolution to some of the other ones that had transpired, including the internet. Um, we've, we've always had sort of these fits and starts.
I think, I think a couple of things have held true. And, and, and, you know, this may be ultimately different, you won't know until sort of hindsight, but typically, uh, these technological revolutions have been really around improving productivity, right? They've ultimately about, uh, um, improving productivity and do they destroy some jobs?
Yes. But historically they've created more jobs than they've destroyed, right? Particularly in the US economy, if you look at sort of the forward-leaning kind of creative destruction economy, that that has been the, the United States, at least over the last a hundred and twenty five, a hundred and fifty years.
Um, I, so I, I ultimately think, you know, regulation, I'm not a, a government official. And, and there is this weird, there's this balance that needs to be striked around encouraging innovation and not pulling it back as well as, um, uh, making sure that their safety. I also am often reading lines, uh, or, or feedback from different companies.
And you gotta think about from each company, like what their incentive is, right? In some cases, if you've got a lead, you might have an incentive to have things regulated because it may slow down some of the startup or open source activities. So, um, I'm not an expert at all of that, but I do know that it's here to stay.
I think it's gonna fundamentally change the way that software is developed and, um, and delivered. And, and I think if we do it right, we can provide incremental, if not exponential improvements in the near term while also, you know, um, uh, kind of navigating towards what may or may not be, um, you know, agents taking over larger and larger portions of, um, of the software development lifecycle. What is that one thing you hear people talking about and maybe overly hyper focusing on?
It just makes you shake your head and go, folks, we're missing the point. Uh, that's a good question. Um, look, I think some of the things you just highlighted there, right?
I mean, I saw a demo this weekend, M two agents going back and forth and belt building an application, which was super compelling, right? It was a, a really interesting, um, uh, use case and maybe a, a glimpse of what's, what's possible in the future. But then I started to think about what would that mean to a large scale bank, right?
What would that mean to a, to a, a, a, you know, a a healthcare company? And when you start to apply the realities of, of the regulatory environment, and when you try apply the realities of, hey, if this app is wrong, once, it may have much broader implications that is wildly different than, than, Hey, I, I, you know, I I created a, uh, you know, a fake, you know, uh, app that, that is just using for demonstration purposes. So that the thing that I, I think that, that, um, I shake my head a little bit is this, this notion that it's gonna just sort of magically be able to be, um, fully accessible and impactful, um, at the agentic layer in, in the enterprise.
Again, I think we'll get there over time. And I think anytime you give a prediction without sort of an end date, like you're gonna be right. More often than not, you just don't know, uh, when it comes true.
But I think what we see is people for sure going from, you know, two years ago, maybe three years ago, like banning everything, like anything with a do AI is, is is not allowed to be accessed on your or computer to embracing it, to using it as a, certainly as a productivity tool, helping to write more codes, sort of code assist on steroids, if you will. And, um, and also as like a bit of a, a knowledge partner, right? To be able to, um, to ask a question, Hey, if I was gonna create this type of, of algorithm, what would a best practice be?
Uh, sort of the evolution of, of, um, uh, some of the, the online tools that we've all as developers been using for years, how we then get that into scale enterprise production, how it then, um, changes the way that we test and secure and other applications. I'm sure that, and we're working on stuff that, in that space, um, things like autonomous testing just point me to the app and the code base and we'll, we'll figure out, um, all of the, the test coverage that's, that's required, add in the telemetry usage data, and we can do even more, uh, interesting work. Those things are gonna happen.
But again, I keep thinking more and more that, um, the large scale changes end up happening more, uh, evolutionarily than revolutionary. And when we zoom out 10, 15 years from now, we'll say, boy, that was a big revolution. But when you're in the, in, in it every day, it feels like these incremental improvements.
There you go folks. I think we've seen this movie before, and one way I kind of described it as, uh, technology innovation is here. It's just being applied unevenly and AI is no exception.
Derek, thanks for being on the show. Awesome, thanks Mike. And thank you all for watching the latest episode of the Text Drawing AI video series.
You can find this episode and others on our website. We'd like you to check them all out. Until then, we'll see you next time.
Hi, I am Nick, patience, vice president and AI practice Lead at rum, and these are some of my predictions for ai. In 2025, agen AI will take center stage. This is the evolution of the, the generative AI revolution that started in late 2022, and now we're getting to the stage where AI enabled agents are gonna be able to take decisions, they're gonna be able to interact with other agents, they're gonna be able to interact with other kinds of software applications and interact with humans.
And this is the, the, the, the evolution of this. So we actually get to the stage where AI can execute business processes, and that opens up all sorts of new opportunities. This year we're gonna see, uh, a successful IPO of one of the AI focused companies.
The IPO market has been, um, fairly fallow in the last, um, few years. There's been a lot of venture capital invested, obviously, and that also needs to go somewhere. And we we're expecting the IPO market to open up a little bit in 2025.
We're also expecting one of the smaller large language model companies to get acquired. OpenAI has obviously stormed ahead here and, and is the dominant player. Um, but there's quite a few others that are fairly small in comparison to OpenAI, but might make attractive acquisition targets probably for application software vendors, but maybe also for infrastructure, uh, vendors as well.
Agents and reasoning models, these reasoning models where they kind of act sort of like a human with chain of thought reasoning and show they're working and show how they're actually coming to a decision. We think both those kind of trends, A, they're related, and B, they're gonna drive an increase in need for inference infrastructure. So you have more power at the inference stage because of this, this chain of thought, uh, process going on.
This is not as just a simple putting in a a simple question into a an LLM and text and getting the answer back or, or anything like that. This is gonna require more investment, we think. So those are some of my predictions for 2025.
Thanks for taking the time to listen, and if you wanna know more about these predictions and all of our predictions, you can check out the future and research ebook, which is available now. Hi, I am Olivier Blanchard. I am the research director and practice lead for AI devices, automotive and AI device semiconductors at the FU and research group.
And so what we're thinking here in, in our holistic practice, looking at all of our dif different technology categories is that AI devices is actually taking off this year. Uh, and it's, it's probably going to be one of the bigger trends in, uh, in the overall tech sector. Up until now, we've had AI living in the cloud, in, in terms of training inferencing services.
Most of it has been handled in the cloud through data centers and cloud services. But what we're doing this year, or what we're seeing this year rather, is a, a migration, not away from the cloud, but into devices towards the edge. So essentially it's an expansion of, uh, of the AI ecosystem from the cloud outward to the edge to devices, and these devices are IPCs.
That's obviously one of the big, uh, developments for this year. I'll come back to it in a second. Another one is, uh, AI enabled mogul devices, which actually isn't new, but we're going to start seeing a lot more on device agent AI entering the market this year.
And also all of the other devices that are sort of peripherals to, uh, PCs and mobile. So that's the wearables like your watches and xr. So smart glasses, it's also drones.
It's also smart cameras, smart smart speakers, all of the, the, the little ecosystem of, of intelligent devices that you can interface with, either by voice or, or other types of, uh, uh, of interfaces. And we're also seeing an expansion of that into the automotive space where cars aren't just about self-driving and a DAS, they're also about agentic experiences inside the vehicle for the drivers and passengers. So all of these things together are essentially driven by advancements in two areas.
One is, uh, semiconductors. So the small semiconductors, the semiconductors that go into your devices, your PCs, your mobile phones, your watches, your smart glasses, your speakers, your, all of your wearables and in the vehicles are getting much better. Uh, a lot of them are equipped with something called an NPU, which is a neural processing engine or unit that allows AI workloads to happen on device.
And increasingly what we're seeing is not just inference, which is sort of the AI interacting with you on devices, it's also the training itself. And, and we're, we're now able with IPC's mobile devices and, and, and vehicles to train AI directly on the device without necessarily needing a, um, a cloud connection or connection to the cloud or, or to a data center. So that's, that's a huge thing because it allows training of AI to be remain local, to be secure, and to be a little bit more immediate.
And that's also with the inferencing, which is kind of the interactions that we have with ai. AI models are becoming a lot more efficient to trade. And so what used to have to be trained in the cloud a year ago that required, you know, 70, a hundred billion parameters can now is, is much smaller now and can run directly on devices or can be trained directly on a device.
So we're gonna see an expansion of training AI models from the cloud into smaller solutions like small servers, more local, and also some of that training being, uh, being moved to AI devices. All of that and more, uh, can be found in our ebook about our predictions for 2025. Uh, we're talking about not just AI devices, but a lot of other technology categories as well that all play into this big AI revolution that we have.
Also, I recommend that you follow us on the socials. So we're on LinkedIn, obviously, uh, we're on X anywhere. You can find us, uh, anywhere you can find me where I talk about AI devices, and also follow us on our websites where you'll find a lot of other resources.
com. Thanks a lot, happy reading, and I hope to see you at. Hello, I'm Fernando Montenegro, and I recently joined Futuro Research as vice president and practice lead for cybersecurity research.
You may have seen the video from my colleague Krista case, so this is a bit of a compliment to that. I also encourage you to check out our ebook. We want to highlight several crucial areas for the security landscape in 2025.
First up is the discussion around security platforms. We emphasize that a very nuanced discussion to be had about what is actually a platform and how do you consume one. We typically think of a conversation as a dichotomy between platform versus best of breed, but we think that have actually evolved into a much more complex decision matrix besides choosing on functionality, pricing, et cetera.
We argue that there are now at least three dimensions that people should consider. First one is, do we buy it as a platform or as a point product? Do you consume it and, uh, as a product and then you have to integrate it yourself?
Or is it integrated into a platform? Which one evolves quickly? Which one, how gives you more, uh, faster time to value?
The second conversation is, are you buying something that is best of breed versus quote unquote good enough? Of course, we all want best of breed, but that comes at a cost. So how can organizations choose with where they want to pay for a premium versus where good enough is?
Well, good enough. Lastly, you have the, the, the topic of how do you consume it, how you do, how do you deliver it? Is it something that you are choosing to buy from a vendor directly, or if it's something that you are working with a service provider or a channel partner on, each of these dimensions has pearls and cons, and you have to evaluate based on specific organ organizational requirements.
We argue that a cybersecurity becomes much more strategic. These types of decisions become much more tied to an economic angle to them, and we have to frankly just navigate what the economic trade-offs are between these choices. Another key area for us for 2025 is the evolution in the convergence of application security with cloud security.
Now, cloud security best practice in general is encouraging us to use more automation and infrastructure as code as principles, and that by itself fits really well with how application security already works. Also, the developers that are typically outputting, uh, front end code H-T-M-L-C-F-F, JavaScript or backend code go Python know what have you, they are also very comfortable creating Kubernetes configurations in YA l or helm charts or cloud formation templates with cloud formation or Terraform, et cetera. So it's not that big of a jump to include those configurations into the software supply, uh, pipeline.
This alignment is really interesting because it creates this proximity between consuming application security and cloud security functionality. That being said, this convergence is also interesting because we have to rethink how teams are structured, how responsibilities flow from one to another. So that's another area that we're looking at.
Third area I want to highlight is this evolution of third party risk management. We think that modern third party risk management is much more about addressing both the business level risks as well as the technical risks across your value chain. So this includes evaluating, for example, security libraries or cloud posture or SaaS components that you're using, as well as vendor reliability, financial viability, et cetera.
The challenge of here is how do you as an organization maintain this complex, uh, information set on first party, second party, third party, fourth party relationships. So it's really interesting. One more point I want to mention before you wrap up, and that is that there are quite a few security areas that actually are very good at spanning multiple domains, if you will.
We all talk about AI security, for example, as one of these, but that said, we think there are other areas. Ransomware response and, and uh, and protection, for example, is one of those. It's not just an endpoint security issue, just like it's not a only a data security issue, it actually flows into a bigger conversation around risk management and cyber resiliency.
Also, secure access service edge implementations, SAE, right? They themselves are interesting because they stand from network security to cloud security, data security and so on. All of these are really interesting areas that require us to look at them with different perspectives and, uh, from different lenses.
As we look into these in 2025, we here at, uh, at Tuum are paying very close attention to the needs of all the stakeholders in this, in this areas. As I get to wrap up, I want to thank you very much for your attention, and I want to encourage you to do three things. First of all, if you can please review Krista Case's video for some other cyber predictions, please review our ebook for a complete set of predictions from cybersecurity and other areas.
And also I want you to stay connected with for term research. com. I often like to say, I mean, there is never ADU day in the fiber security industry, so thank you very much for your time and I wish you all a great day.
Hi, my name is Richard Gordon. I'm vice president and practice lead for Semiconductors here at Future Own Group. Today I'd like to talk a little bit about what's going on in the semiconductor industry, and we'll maybe have two or three predictions as well.
So first of all, let's start with the state of the industry right now at the end of 2024, and as we enter 2025 last year, the industry grew at around about 20%, and that growth was driven by a boom in data center semiconductors, particularly AI chips, and, uh, also from a boom in, in memory from the likes of Samsung, esky, Hynek, and Micron. The industry growth rate's gonna slow down a little bit and we'll probably see growth of around 10% this year. Overall, that's gonna be driven, um, I think by a pause in investment in the data center space, and also a recovery in the rest of the market as supplied and demand comes more into balance.
So the industry going from strong growth last year to slightly more moderate growth in 2025. As we head towards 2030, I think we'll see another upcycle in the industry pushing the market towards a trillion dollars or so in the early 2030 timeframe. Second prediction I wanna talk a little bit about is to do with the technology roadmap.
Over the, the past few decades in the industry, technology has been driven by Moore's law. Investment in semiconductor scaling is what drove chip performance and cost reduction. However, it's increasingly challenging for companies to invest in keeping to the Moores law curve.
Really only the leading foundries and leading memory players can afford to do that these days. So we're gonna see increasing investment in advanced packaging to drive the technology roadmap. In fact, one of the equipment manufacturers reckons that by 2030, around a quarter of foundry revenue will come from triplet space.
Benefit of triplets is that semiconductor devices can be partitioned up into functional blocks and then recombined and advanced packaging so that there's different types of semiconductors with different properties available in a single package. The last thing I wanna talk a little bit about is geopolitics. Of course, the industry has, is very much a globalized industry and has a globalized supply chain, but increasingly we're seeing semiconductors seen as a driver of economic growth and also very important from a national security perspective.
So what we're going to see going forward is more Onshoring of semiconductor design and manufacturing. We're gonna see increased technology transfer restrictions around the world, and also increased tariffs and trade as well. Uh, uh, that will not apply just semiconductors, of course it'll apply to to business more generally, but it will affect, affect the semi space.
So that's a little bit of a a look into what's going on in the industry right now. If you wanna find out more, you can download, uh, our ebook, um, where we have some more detail on these predictions. That's RUM 2025 key Issues and predictions.
Hello, my name is Chris Blask, and once again, I am your host for another episode of the Inevitability Curve. In each episode, we take a particular topic and look back with an interesting guest on where we've been in this topic, where we are today, and where we're going in the future. Perhaps our guest today is Stuart Phillips, and Stuart and I have worked together for many years in cybersecurity.
Hey, Stuart, how are you doing? I'm doing great, Chris. Great to see you.
Good to see you too. So it's looking very Pacific northwest, uh, behind you. Thank You.
Thank you. I live in, uh, lake Stevens, which is a little north of Seattle, and today we're having a great fall day. It's raining and cloudy, you know?
Yeah. As one does. So you and I may have worked together in cybersecurity for many years, right?
And since, uh, 1998, you know, when I joined Cisco and in all of those contexts, and for both of us before that, you know, there was contact with military organizations and helping them with security and helping private sector organization with security and, you know, the, this issue of conflict of human conflict and how the lessons of, of all of human conflict applied today. You know, whether today is your late nineties or the 2020s is a constant, constant topic, right? And you're, you know, quite a military history buff and history buff in, in general, kind as I am.
So let's talk back there a little bit, right? So in recent, more recent history, without going back to Assyria this time, um, a hundred years ago, 80 years ago in World War ii, uh, most folks, certainly everybody in the cybersecurity world knows about Bletchley Park, right? And the information warfare that both the hacking of, um, of, of access codes.
So they read the messages, right? And the manipulate manipulation of physical artifacts and people and things to give, uh, a wrong impression, right? Exceeding the wrong information.
Where would you like to start in the past in mapping into where we are today with, with information warfare and conflicts in general? Well, I mean, you bring up a really good point about, uh, you know, the enigma efforts and all the things, and a lot of it, you know, where there was a combination of human error and technology, right? And so what happens is you have German operators who are sending every message with the same couple words.
And, um, the, I will not repeat on this, you know, call, call. And the also the fact that they were able to create the bomb, the ability to create a, you know, very early computer that was able to decode it by trying thousands or hundreds of thousands of combinations, even though they did have a really good guess. But the advantage of the human error was that they were able had a place to start.
And it interesting because even today you have a combination of human error, which is people clicking on email links, people accepting in invitations for people who are not the person they think they are. And then you also have technology where now you have like the deep fake technology where someone can sound like your boss or someone can sound, you know, present themselves very realistically, uh, or what we're seeing at Reversing Labs where people are creating an individual malware package just for a single target, you know? So instead of 10, 20, 30 years ago, they would create malware and then email it to everybody in the world.
Now they're actually using AI to create a single crafted malware package just for Chris Blask. You know, and so you may be the only person to see it. And a lot of tools are the traditional tools that were like, have you seen this before?
Is this in your antivirus type? Things like that. Those tools don't really work anymore.
And so we're seeing a lot of, you know, changes in how these, you know, types of attacks. But the other thing that's been really interesting to me lately, of course, has been the conflict in the Middle East and also the, uh, Ukraine where we're looking at, you know, how drones and thermal sites and people riding an e-bike in the woods and coming up on a tank and being able to take it out with a handheld missile. And, you know, the tank costs several million dollars, and that whole setup for that person costs $2,000.
And so you see a huge distinction between these types of traditional military, you know, belief that, you know, having tanks, having big planes, having big missiles and all this kind of stuff makes you invincible. And somebody coming along with a, you know, $600 commercial drone and dropping a hand grenade on, on, you know, into the cockpit of your $35 million airplane is devastating. And, but, but again, how much of that is, is some of that sounds similar to me, you know, the, the, uh, world War ii, the tanks and the, uh, forgetting the German word for the little, uh, The pounds are false.
Yeah. Mine are false. Yeah.
Right. You know, so, and knowing where those are at the, at the right time, you know, having the intelligence and information right, to get your, you know, asymetrical advantage out of, out of is itself not a new thing. No, not at all.
I mean, all of these types of technologies, these advantages, we've seen them, you know, move forward. And that the challenge now is that how do you as a, uh, defender prepare for these things when quite literally the technology's changing quickly. You're seeing a lot of things happening that are unprecedented.
I mean, you in, uh, you know, Yemen a place that you're familiar with. You have the hoodie shooting ballistic missiles. Um, you know, again, when I, you know, during the Cold War ballistic, only three or four countries had ballistic missiles, right?
And, you know, and when India got ballistic missiles, it was a really big deal. Now, apparently anybody with a tractor trailer can have a, you know, ballistic missile. So, you know, it's not as, it's not a, uh, you know, and again, it's, it's this idea that you could shoot missiles at another country and there's really, you know, war doesn't break out like you think it's going to, You know?
Well, and, and following that pass, right? And getting more into the cyber side of it, you know, this, we recorded a text Wrong gang episode this morning and got on the topics of, of mainframes, right? And for most of us in the IT world today, you know, we're, you know, DevOps and DevSecOps, I mean, these are words, words and terms and phrases that we understand, and we think mainframe is like, hang on a second.
But as, as we're talking about there, uh, there's, there's a lot to be learned from that. You know, mainframes were the mainframe platform, the mainframe environment, um, was a very solid and stable and secure thing. And today, mainframes, you and I worked at Unisys where mainframes continue to operate, you know, the entire global financial backbone.
Yeah. And they do that because they're doing things that in the, the broader IT world. Now, we kind of think we're impossible, but that's the way they were built all along.
Yeah. And, and again, there's this idea, you know, uh, the centralized system with terminals that really don't have any type of capability on their own. And you see that now though, with virtual systems.
You see that with like, um, you know, systems that boot up, you know, you have a laptop, but there really isn't anything there. You boot up an image that comes from somewhere else, the image runs on your PC while you're doing your work, and then when you shut it off, it's gone. Someone breaks into your house and steals your laptop.
They don't have any of your secrets. So, I mean, that that mainframe centralized terminals is dumb model is, is very heavily replicated today in a lot of this, you know, systems that do these distributed, uh, you know, deployments and, you know, having everything in the cloud, which again, is just a computer in another state, um, is not, to me it's really no different than a mainframe, right? I mean, way we, we dealt with mainframes, you know?
Uh, I think that the main difference now is that your ability to spin up these things is, is quite easy right? Before to get a mainframe, you know, I would go, when I worked at network systems, we sold front end controllers and all that stuff, you know, back in the mid early eighties, uh, if you wanted to have your own mainframe, that was great, but it was gonna be a five-year effort and you needed a specialized building. Now you just need to go on, uh, you know, Microsoft Azure and you have a credit card.
Um, you're good to go. You know, you can have a complete operating data center within a few minutes. Well, yeah.
Which plays right down my, you know, my favorite eight, you know, inevitability curve sort of thread. You know, the same thing as you said about ballistic missiles. If you have a technology at some point, and it's very exclusive for whatever reasons, if it, it can be made less exclusive, you know, then eventually it will.
Right? So you can think forward into that world and say, okay, by then we need to do what? And, and again, just in our, our, uh, you know, relatively short working, uh, careers, we've seen a lot of this, well, you can't ever do that 'cause therefore you couldn't do X, Y, Z we're doing already, but we did it anyways.
Right? We find ourselves looping back to the those same, uh, uh, primaries, right? Right.
That, you know, we need to be able to do these things. And Well, I, I think it comes back to the exactly, it's the same idea, right? That nothing, there's nothing new under the sun.
You know, it's, I think that's in the Bible in the back somewhere, you know? Yeah. Yeah.
Anyway, um, but no, that's the idea that there is not, you know, these types of attacks are coming out. I mean, the, the type of email fraud attacks are just very simple. Re you know, you know, people were doing that in the 1920s, right?
With, they were just doing it with e uh, with letters. They were doing it with, you know, then they were doing it with telegrams, and now they do it with email. It's really not any different.
The main difference is now you can, instead of sending 10 e uh, 10 letters a day, you can send a million emails, and then you could have each one of them individually crafted by AI to target the person that you're going after. You know? And again, uh, human error is still the, the bane of, of cybersecurity, right.
You know, the people that will click on things, uh, because they're afraid of getting in trouble. And again, that's company culture, right? I mean, you know, I get a, uh, at Reversing Labs, we have this, uh, we have all Slack, right?
We use Slack for everything. And we have a Slack channel called Mario Needs Help, and Mario's our big boss, and he's, you know, great guy. And he, he, he, you know, a lot of people know him and talk to him.
He's very, uh, he's very present, right? He's one of those guy, uh, CEOs who's always, you know, you're always talking to him in meetings and he is always asking really relevant questions. Um, but Mario needs help.
You know, anybody who starts at Reversing Labs within a day or two will get a text message saying, Hey, this is Mario. I need you to go down and buy $1,500 worth of Apple gift cards for this customer. We don't know who's doing it.
We don't care that much. 'cause it never worked. And the amount of effort to put into it to try and find out who it is, it's not like we're gonna be able, you know, like always say like, you can't really call the police in, you know, these countries and say, Hey, we'd like to bribe you to go arrest somebody.
You know, that kind of thing. So, you know, these people operate in corrupt countries and they have all this thing, and, but it's just a, it's just a thing. And then we, the way we dealt with it is very straightforward.
We made, you know, made it really visible within the company. So it's part of our new hire training. It's very clean, but again, it's also incredibly helpful that everybody knows what Mario sounds like.
Everybody's talked, you know, a lot of people, almost everybody in the company has talked directly with Mario, so they, they kind of know what to do and what they don't. You know? Um, I've worked at companies where I didn't really actually know who the CEO was and the idea that somehow they were wanting me to, you know, do something.
And we see that where people are just afraid of getting in trouble, you know? And they're more afraid of like, you know, somebody being mad at them for not paying a bill or versus paying a fraudulent, uh, invoice. You know?
And then that plays to me. Yeah. So we're talking about the present right now.
So that plays to some of my favorite buttons. Right. You know, and what you described to me sounds like a nice practical human, you know, human trust-based solution, right.
You know? Mm-hmm. You hire decent people, you expose 'em to the information, the people in this case, you know, they need to be able to, to respond to, and you put the technology underneath that to support that, but you're not basing it on, like you say, you have the fear of being fired for not doing something.
Right. So company culture, you know, so the Department of Energy and the, the, um, cyber informed engineering initiative, you know, has a term that I just absolutely love, which is radical transparency. Mm-hmm.
Which lines up exactly what, you know, I've been focusing on the last five years or so, the supply chain stuff, right? And you and I have talked this to death, and we're both working in companies that do that stuff these days. And it's just an exercise of the same things we've talked about in 1998.
Like, how do you get trust with a market if in that case you're a big faceless company called Cisco, um, by personally doing it and doing things and demonstrating the trust and being visible about it and being transparent. And, uh, and it's not a trick, right? And in the current conflict environment, right.
You know, so everything from misinformation, disinformation campaigns, organized by nation states to influence demographics, and to your point, you know, now support of I AI to like sound just like Iran. Um, you know, what do you do? Right?
And I personally, I think the, the answer is the same as in cybersecurity and supply chain and open source, you know, be absolutely transparent, right? But to the people you should be transparent to in the ways you should be transparent to them. Um, yeah.
Yeah. I absolutely agree. And I think that there's a lot of, um, a lot of, a lot of it has to be able to, you know, organizations really need to be able to, uh, quickly respond to changes.
And, um, you know, you and I still deal with companies that say, I have a five year, uh, planning cycle, you know, where, you know, we're not gonna be able to do anything for a couple years. Um, I know like, you know, a lot of the traditional industries have, you know, planning cycles where they, you know, it's like, yeah, I know this thing where drones fly over the, uh, you know, the electrical plant. That's really, really bad.
But we really don't have, you know, we can't really address that for like two or three years. 'cause we don't have, you know, now that we don't have the money, we just don't, you know, our methodology, you know, our planning cycle, our, you know, the, uh, security council only meets once a year, you know, that kind of thing. So there's a lot of, a lot of challenges within how companies respond and how are they able to, uh, react to these new types of attacks.
But again, we're seeing, you know, even in the last year or two with AI and how it's not, you know, it's AI is not smarter or better than us. It's just able to do the same thing a million times over. So if I, if I'm able to grab a list of email addresses, I'm then able to have a chat GTP program that's able to look everybody up on LinkedIn, figure out, you know, what, what, you know, what kind of, what messages might be appealing to them, and then be able to send those emails.
And I could do that in a day, you know, I can get that done, you know, I could be, I could be processing millions of them. And then again, you know, one of the, uh, you know, you look at traditional, like, you know, 1950s with a Russian spies, they would send a, a Russian who was, had been born in America, but grown up in Russia, so he had an American passport, and there were very few of those people. And then they would come to the United States, and they would be Russian spies, and then they would do spy stuff, and they eventually would get caught, and then they would be traded for, you know, our U2 pilots and things like that.
And now I don't really need to do that, right? I can, uh, I can bribe or I can pay for influencers in a certain country, right? I can literally go online and find influencers who will spout whatever messaging I wanna, you know, give.
They, they are local, right? They speak the local language. They, I don't have to worry about translation.
I don't have to worry about, I don't have to send my agents to that country and worried they'll be arrested at the airport because it's, you know, a triple cross type situation, right? I mean, I can, you know, countries now like Russia, they can just sit back, pay American influencers to spout their lies, and they don't have any risk, right? What's they're, they're not sending anybody here.
If those influencers get found out, they, you know, may get arrested, they may get charged with tax fraud or some other types of crimes, but there's no risk to the Russians. There's no, you know, the Chinese, you know, the North Koreans, the people that are doing these types of ESP espionage programs, the traditional risk where, you know, this was gonna cost millions. It was gonna take, you know, all these things.
Russia really did have a village that was an American town, and they sent their agents there, and their agents had to speak English only, and they had to drive American cars, and they had to know what an air conditioner is and, and, you know, and all these types of things, because that was the only way to get them assimilated into these countries. And it costs millions and millions of dollars and took years and years. And, you know, you'd have an agent that you've invested years and years and years of training in, and then he arrives at the airport and gets picked up, uh, because of a problem with his passport.
And next thing you know, the whole thing's a failure. Hmm. So I think, you know, the, the, the way that espionage is being done now, the way the fraud is being committed, there's very, very, there's significantly less risks to the people who are doing it than the way there was in the nineties.
Right? And the a, you know, when we we're not, we were dealing with criminal gangs, there was a point where in Russia, you could call the Russian police and they would arrest people. Um, that time is gone, right?
And then, you know, traditionally you had criminal gangs that were only interested in money and criminal gang, you know, and intelligence agents and government people, uh, you know, you and I used to do this. We used to laugh at the Chinese spies because they would work like nine to five, right? They would start working, they'd be in Beijing, they would start working at nine o'clock locally, and they would quit around five o'clock and they would take lunch.
And so when we would look at the activities, we'd actually know, well, okay, based on where these people, you know, the time that they take lunch, this is where we think they're based. Now this is all done by, you know, AI tools. It doesn't really matter, you know, when it's done, or it's just being outsourced, you know?
And so they're, you're going on, you know, these, uh, you know, dark web, uh, mailing, you know, lists and, you know, and, uh, chat boards and things like that. And just hiring people and you don't really care where they are. And so a lot of this is, you know, uh, uh, the, the challenge, and again, this is just the disappointing part, is things are getting worse, right?
I mean, the, you know, the, the risk of being attacked is a hundred percent, and the ability for people to attack you has Dr. Dropped dramatically, right? So instead of us needing an army, and, you know, it's $20 million to buy a tank and seven months to train somebody how to drive the tank, you can buy an e, you know, e-bike off of TMO for 400 bucks and, uh, you know, a little j and old Javelin missile, which, you know, has a half hour training video that you watch on YouTube, and, um, you know, you're good to go.
So, I mean, it's a, a dramatic ri you know, dramatic difference in, you know, these types of attacks. Well, and before we get into, you know, uh, uh, even the near term future, much, much less longer, slaughter bots, you know, you remember that, uh, yeah. Seven minute video put together by some concerned scientists.
Oh, was that been five years ago or so now? Something like That. Yeah.
Yeah. And, uh, the, the premise, anybody who hasn't Googled have already, you know, is that terrorists start using drones. Mm-hmm.
And, uh, and, and social media identification information so forth to individually target, you know, uh, um, uh, victims, you know, politically or, you know, you're posting on Instagram a certain way and a drone with an explosive is coming after you. And what you're describing is, is perhaps we're getting closer to, or maybe in that phase already, right? Yeah.
I think it's interesting. You know, you think about, um, like in Afghanistan, our opponents there, um, used handheld radios, you know, commercial, you know, available ham radios or, you know, the type of things you can buy, uh, for $50. And they use those because they did not have location-based services, right?
If you, you know, we have some incredible, uh, electronic warfare devices, the, uh, airplanes that, you know, fly around recording everybody's phone conversation, tracking everybody's phone, doing all that kind of stuff. That gives us an incredible view of the battlefield if somebody's using a phone. And so, you know, they shifted over to handheld radios.
Uh, same thing with pagers, right? Um, uh, you know, I, uh, took a police sciences course recently, and they were talking about if you catch somebody who has a flip phone, they are a hundred percent a bad guy. Right?
Now that's a generalization, unfortunately, just turns out to be true. You know, unless it's somebody's great grandmother, you know, people who carry flip phones have, don't not have location based services on them, and they're doing it so that it can't be tracked. So, again, you look at it for two types of behaviors, right?
One is, are you doing this, uh, for these reasons or are you actually a criminal? It's interesting to me though, that because most criminals are just stupid and do stupid things, and that's why they're criminals and they get caught. Yes.
Most of the people I know, thank God, right? Most of the people who have carried flip phone, I mean, you go to the Black hat or you go to RSA or some of these other shows, you'll see guys with flip phones because they're just convinced that the government is tracking them and they're really worried about it. And it's a really big deal to them.
And you can't really, it's not a topic you wanna bring up with them, right? You know, I, I never mention it because they'll just go onto this long rant about how the government is listening to everybody, and it's like, well, they are, but they're not interested in you. You know?
Um, they're interested. Are you not that important? Yeah.
Sorry. I mean, you know, um, you know, unless you're selling drugs or being a terrorist, they're not as interested in you as you might think. Well, you had mentioned, you know, pagers 'cause we had to go there in the, in the current tense.
'cause we're, you know, this summer, right? You know, just recently, you know, we all know every there in the world, you know, the supply chain attack against pagers and then Maie talkies, you know, in the Middle East, you know, presumably, you know, uh, affected by Israel, which makes perfect sense. And it's, and you know, I mean, you know, this digital bill of materials thing, you know, that you and I have been talking about since 2019, right?
You know, this is exactly the kind of use case I like running through. And, you know, five years ago it was a bit, you know, you had to scratch your heads. You had to go to Scottish, you know, the National Manufacturing Institute of Scotland to find folks who can really speak to the idea that I may need to know what software was running on the machine tool that made an individual part, like say a battery, you know, that's physically inside some device.
I need to know that right now. Right? Um, this is a demonstration that those, it's not just about software security because I would, you know, you talk about you're sending something into space, I may want to know who made the plastic case at a level of no.
That I would can use to put things in space. And we have to build those systems. And it's interesting because, uh, you know, we always talk about the insider threat, right?
You know, if you are a criminal, right? And you are, your intention from the beginning was to commit criminal acts, you are the hardest person to deal with it within the organization, right? You know, if you are an active criminal, sending you to the class where you learn about what emails to click on isn't really gonna help the situation, right?
Um, and so, you know, you see this idea that, you know, I can trust but verify, right? How do I know if someone has done this? I mean, uh, reversing Labs, we have comprehensive supply chain, uh, security tools that will actually deconstruct a file.
And the main reason being is I can't necessarily trust you if I, I, I'm, and I'm, I I love you like a brother, you know that, right? But if it's my job, I can't say, Hey, Chris, we're buying this phone from you. 999% of the time, that's fine, right?
The challenge is, what if you don't send me the right software, or you're a criminal and you intentionally send me the wrong software without the malware on it, and when I get the phones, they all have the malware on it, so I can't trust you. I love you, but I can't trust you. And so I have to, um, I do have to check it myself.
I do have to deconstruct the software as it is not as I want it to be. Or, you know, Hey, send me your, your files and the link to, you know, your Python repository, right? That is, that doesn't really help.
I need to see the actual software. So being able to take the software, deconstruct it with like our short tools and things like that, that allows you to have a hundred percent confidence in this. And I think the thing that I don't understand, and again, I I will, I will just say this, and again, there's many, many things that you, and I know that there are a lot of lies told by everybody in this industry, right?
You know, vendors lie, customers lie, governments don't necessarily represent what happened for various reasons. And so, you know, we hear the story of these pagers were made in Hungary. They, or, you know, they were made somebody set up a company 15, you know, all that stuff.
And, and, and, and as you know, sometimes we're in the deal, right? And we go and watch tv and you go, that's not what happened, man. Um, I was there, I was in Korea on that day when that attack happened.
And that's not what happened. And it doesn't matter because that's the story, right? That's the story they're gonna go with.
So you have to deal with that. But I find it really hard that nobody, you know, if you received a couple thousand pagers, no one took one apart and looked at it. I mean, is, is, and, and, and again, if that's true, that's in incredible level of incompetence.
You know? And you know, the idea that I, you know, hiding a piece of plastic explosive and some ball bearings and on inside a pager, I had a, I carried a pager for a long time, right? I was a field engineer and, you know, get pager pay, which I really miss, by the way.
Um, you know, I could, I knew which pager was mine by how much it weighed, you know? And, uh, I think that, you know, um, I think it's, it's really hard to understand that what happened there with the idea that somehow these were bought, acquired, distributed in high, in, in, in active use, and at no point over this period of time did one break, and therefore somebody had to take it apart and look at it, or the battery died and somebody took it apart and went, wait a minute. Why is there a little bit of plastic in here with some ball bearings?
Well, they just don't understand that. And that's, and that's and interesting because, but again, having gone through all of these types of things, um, you know, we know that there, the story about what really happened and what didn't happen, it usually comes down to either laziness of corruption. Yeah.
I, I, I love that you mention, you know, criminals are stupid, you know? 'cause I, I can't tell you how often I use that because you have to understand, you know, that the, the, you know, evil mastermind from Hollywood, you know, who's got the big brain bigger than everybody else, and, and has for some reason invented teleportation, decided not to just get rich on that, doesn't exist. Right.
You know, usually people making bad choices are making bad choices 'cause they're not thinking about everything properly. Right? And we can call that stupid if we want, because it works, right?
Well, A again, you have, um, you have your, your two basic types of criminals, right? You have your typical career criminal who's very much used to going to jail, and you have your, uh, you know, I have, I have friends that are like parole officers and things like that. They, they say there's two types of criminals, right?
The one that was never expecting to get caught and is scared to death of going to jail again. You know, the person has a, like a DUI or criminal DUI, or you know, did a little bit of time and now he's just absolutely terrified and shows up early to their parole meeting, you know, and all that kind of stuff. And you have your career gang member who's been and outta jail since he was 11, and is just ast comfortable in jail as they are at home, and doesn't really, you know, would prefer not to be in jail.
But the idea that, you know, they're somehow not gonna be a gang member. It's just crazy. They, they're, they're gang members, their whole identity, you know?
So we, yeah. So with all this, anyways, let's, let's look out in the future, right? You know, so I, you know, I have a ongoing poit.
I keep saying that I can't see a medium term to distant future where some of these problems still exist and not because, you know, morally or ethically, you know, we all love puppies or whatnot because you just can't keep the lights running. You know, we need these systems to, you know, work at a high fidelity to the point that, you know, mainframes, you know, have been working for the last 50 years. Mm-hmm.
Um, but, you know, a much more complicated, much more distributed environment it requires and calls for the kinds of structures that, again, I, you know, I think folks like you and I have a good idea, right or wrong, exactly what they are. But, you know, once they're done we'll, we'll be able to look at it and say, aha, that's how that works. Right?
Right. Makes all this stuff a lot harder everywhere from the nation state level. And just to, to see that.
So David Bryn, right? The science fiction off, uh, author was at RSA in San Francisco this, uh, this year. And in the text wrong booth to hang out with him for a bit.
And in one of his favorite books of mine, uh, killing People, one of the basic premises is that crime and, and particularly, you know, complicated, you know, uh, a conspiracy is really, really, really, really hard to the point that it almost doesn't happen anymore. And I, I think that is the direction we're going, how long it takes to get there is a big question. Yeah.
I, I, I, you know, again, I think that the challenge is going to be how quickly can these, uh, organizations adjust to these types of things? We're, we're starting to see people now we're, you know, we're dealing with customers who are saying, uh, before I would only check one or two software packages that came into the company. Now I wanna check everyone.
And, you know, and again, if you and I were, I mean, honestly, you and I have been around doing this so long. I remember you and I going to like a, uh, can't remember what bank it was, but the guy was like, why would we need a firewall? We're never gonna connect to the internet.
People like going to the bank who let, like, the guy, I remember that guy was like, who let you in here? Like, you know, why, why are we having this meeting? We're never gonna, you know, internet banking, are you crazy?
You know, banks are judged by how many branches they have. You know, that's the most important thing. Uh, you know, even, uh, even when ATMs and things were coming along, it still was, uh, the idea that somehow there was a, uh, you know, it was not gonna be something that people really wanted.
Right? Why would you wanna take money out after the banks closed? That's crazy.
You should have planned ahead. Well, And, and, and to our topic, well, here, you know, and, and I think I have these conversations all the time, basically, you know, anonymize, but, you know, generalize it. But it's something executive saying, you know, what, you, what do you mean?
You know, my employees can't make most, most of the decisions about, you know, their, their work responsibilities by what they generally pick up on the internet. Right. You know, because that's, you know, to your point about, uh, your, your boss, your CEO and so forth, and that, you know, that process you have with employees, it's generally works, right?
Yeah. It's not very scientific works. I mean, it generally works until it doesn't anymore.
Yeah. And I think, I think you have to, you know, the, you and I were down in, uh, in Columbia Meine, right? Uh, before the pandemic and so forth.
Don't talk about That. No, just kidding. Keep going.
You Know, as I was, I, I said the public information was public, public Information. Uh, yeah. Only Ever shared on this channel.
Why didn't we go by canoe? That's what I don't understand. Right.
I should have taken Mark Twain is another topic. Exactly. But, you know, in that time, working with those folks and that, uh, national infrastructure and so forth, and looking out at work periods of time, you know, that 25 year plan, right?
You know, we're right at about seven years in right now, and the seven and 15 years were the sort of break points where we said, you know, by this point, you seriously need to be thinking about, right. These issues. And one is, you know, how do you really know when you're turning the power off and on, you know?
Right. It's, it's gotta be, there's gotta be systems of automation and transparency that don't exist yet, but will exist by then. Right.
And they, and they do. Right? And you look out, you know, that next, you know how much 18 years on that, on that roadmap, right?
And I think that we and the peoples, you know, involved in that and similar efforts are, are right. You know, to your point, in 15 more years and 18 more years, we're gonna be living in a slightly different world, right? Where we will have, have had to adopt certain parts of that transparency and clarity, right?
Just so we can live in, in conflict environments, Right? And I think it, it comes back to experience, right? I mean, I, like many, many people in the cybersecurity world thought that, um, Russia was going to be able to attack Ukraine and launch a massive cyber Pearl Harbor and wipe out everything and turn all the power off and turn off all communications, and it would just be completely dark and their phones wouldn't work, and everything else like that.
And it turned out none of that happened. And that the turned out the Ukrainians, because they had been actually experiencing this for years, were very good about defending themselves, right? And I know a lot of people have been to Ukraine.
I know, uh, some of our mutual friends have worked there and tell stories and stuff, but they have, uh, you know, Ukraine was able to turn around their situation. And when these Russian attacks happen and they happen every day, thousands of times a day, they were able to dramatically defend themselves quite well because they had experience, right? And that's the thing, that's the difference between a lot of these organizations.
I think that they should be looking to guidance from people that are having these types of, uh, you know, incidents happening and using them to predict what's going to happen in the future, rather than what they did 10 years ago or what they did 20 years ago when they worked at the NSA, right? I mean, that's, you know, and that you look at, you know, when we look at cybersecurity, some of the best cybersecurity setups are by people who run commercial Minecraft servers, right? Because you have your own private Minecraft server.
You sell that to, to people who are really into Minecraft, who wanna have their own, you know, landscape or world or whatever you call it. And if people in the industry will try and knock yours down, uh, so when we look at people who are very good at defending their infrastructure, you know, you wanna look at somebody who's getting attacked every day and doing wallet defending themselves, right? If you look at the situation in the Middle East where you have hundreds of missiles being fired and hundreds of missiles being shot down, that's incredible, right?
That was, that is just science fiction, right? The idea that somebody could launch a hundred, you know, I mean, all those, you know, diagrams, you know, the, the, the Iranians have so many missiles and you know, this is what you need to worry about. And then they fire most of them and it costs them billions of dollars to do that.
And very few actually get through. And, you know, and again, it's a terrible thing. It's a tragedy.
It's absolutely the worst thing in the world. But if you were looking to defend yourself, you would look at something like that and say, okay, how did they do that? Right?
And the same thing you wanna look at, you know, so you look at people who have high level of competence, competence, and at the same time have a high level of ex, you know, direct experience in doing these types of things. So when you're reaching out to, uh, security organizations or looking into with different groups and things like that, you just want to be talking with somebody who's actually done it, right? Who's actually run a, you know, a system and been under high attack and successfully defended themselves.
And now those people are rare and they're hard to acquire, but you should listen to them. You don't, they don't necessarily have to work for you, but you can go, you can, you know, listen to them. You can listen to people like yourself who have had this experience and have gone through, but you just have to open up and say, you know, what are we trying to do?
We're trying to defend our organization. We can't trust anybody. We need tools that can, uh, do this.
And we need policies and procedures to effectively use those tools. 'cause even with the best tools, if you don't have the skills to use them or the ability to use them, uh, that's where you get into the frustration. And everybody I know who's left cybersecurity, and I'm sure it's the same with you as well, has left because of their frustration with their organization, right?
Hey, I, we had a meeting about this six months ago and I told you this was gonna happen, and you know, you told me to shut up and go back to work, or, you know, we needed to work on our, you know, Are we done with the budget? Yeah. We had to, you know, we can't, you know, we can't, uh, we can't go back to our bosses and say we were wrong.
We, you know, we can't change, ask for a change in the budget 'cause it'll make it look like we don't know what we're doing. And the reality is, you should be almost fluid. Like wake up today and say, what are we gonna do?
And, and you know, the difference, again, used to have criminal gangs who were trying to steal money, and that was really straightforward. And then you have government organizations now before you had to steal money and print fake credit cards and hire people locally to go and, you know, cash out crew and go into the local mall and buy TVs and jewelry and things like that. And then, you know, it would only work for like 20, 20 hours maybe.
And after that, the credit cards were no good. And you have to start over. And now you have crim, uh, you know, bitcoin and cryptocurrency.
Now that's very fluid and you know, harder to track and very, you know, easy to do. And then you have a rise of like, you know, North Korea where they're actively stealing money, right? The biggest cr you know, heists, the crimes, the bank robberies, if you wanna say in history, are done by employees of the, you know, north Korean government, you know, who probably wear a uniform to work, but at the same time they're stealing millions of dollars because they're using it to fund their own country.
Right? How long ago they were, that is science fiction, right? That, you know, 20, 30 years ago that was, I mean, you know, you read Norra Menser, right?
The idea of winter moot, and you had the idea of an AI that escaped and went and lived in Antarctica. And that was, you know, and was, you know, hiding from people. That was incredible.
That's as real today as anything you want, you can spin up your own organization on, you know, hide it, have, you know, put it, have it running on servers in another country, never have any physical access to them. And the only time you get caught is when, you know, you get tricked into, Hey Chris, you've won a free trip to Crete. You know, you wanna come, you wanna come to Cyprus?
We have a conference I do to come to, and when you land there, there's two FBI agents waiting for you. Right. You know, it's, that's the, you know, the, the only way that you get caught now is by being tricked, you know?
And, you know, but, and the cost of doing that, I, you could do that for $10,000, right? And, uh, you know, there are countries in the world that don't have jet fighters, but have cyber warfare groups that are very effective. Yeah.
And then when you have a merging of that with corrupt government officials who are using this for disinformation, uh, you know, you know, things that have happened in some countries, um, it becomes even worse, right? You have, you know, it becomes a, uh, uh, a situation where we see that in, uh, where, you know, we have, uh, news people, you know, journalists who get arrested by the government for telling the truth. And so now you see, you know, news organizations actually having virtual, uh, journalists, right?
You know, it's an AI representation of a journalist reading a news story because all of their, you know, otherwise the government guys are gonna come over and arrest you in the middle of the night at your house and no one's gonna see you again. That again, it's science fiction, but now it's just as real as can be. And the resources for that are not, I don't need a a hundred million dollar, you know, plant and, you know, several top scientists, PhD, AI guys, uh, I can go on app Sumo and, you know, buy something for 90 bucks and it'll do what I wanna do.
You know? So it's just, you know, again, it's just a different world. It is.
And we're living in it and we're moving into, uh, yet another one. And I wish we had more time, we could do this stuff, uh, in tell the cows literally come home. So I thank you for your time today.
Thanks for decades of being a good person, good friend, and, uh, everything you've done to help make the world a slightly better place. Well, thank you. And again, thank you for being able to give me a platform to rant for a little bit.
But, uh, and then being these types of ideas, but I think the main thing again, is that while things are bad, you know, you and I go to these security conferences and it always, it was always doom and gloom, right? End of the world. This is all terrible.
And I'm like, no, no, the lights are on, right? The right internet is working. Um, you know, there's, you know, if, if things are so terrible, then why, why is everything just, you know, as good as it is, right?
Global hunger is moving down, It's global poverty has been halved in our lifetime, right? You're talking about a billion people moved out of poverty. Uh, that's incredible.
And again, it's done because of technology and because of people that really wanna make a difference, but also because of, you know, free markets and capitalism, being able to say, you know, if we raise these people up, then maybe they'll buy, you know, cars. So, you know, let's do, let's do that. Okay.
So again, it's this idea that, you know, things are not that bad. I mean, just you, you do have to be more flexible and, and be a little more fluid and, and things like that. But that's just 'cause of the way things are, you know, the technology is evolving, but the defenses are evolving just as quickly.
And again, you're, it's your ability to be able to use them. So get some good people around you and get some, you know, get some good on training and get some transparency. Get a few, couple good tools, learn how to use them and take advantage of them.
And you know, everything will be reasonably good. I agree. Well, thank you again.
Thank you out in the world for spending some time with us. No problem. Look forward to seeing you again on another episode.
Absolutely. You have a great day. You too.
Bye folks all. Hey everyone, thanks so much for joining me today. My name's Jonathan Singer, I'm from Checkmarks.
And today I'm gonna talk a little bit about putting the SEC into DevSecOps today. There are three things that I want to convince you. The first is that high performing code that is not secure, it's not high performing.
So insecure code, it's actually a, a culture problem. The second thing, security tools are or must be developer tools. And the third thing is that DevSecOps is a culture problem.
Before it's a technology problem, I'm also going to give you five requirements to build your organization's DevSecOps maturity. Those are one, education, two automation, three speed, four shared measurements, and five integrations. Let's begin.
I wanna start by asking us where are we today on our DevSecOps journey? We ran a survey of over 200 chief information security officers and only one in five that we surveyed have actually begun integration and automation. And that's a lot of the main work of DevSecOps.
Alright, so, you know, we look up at these survey numbers and it looks like we're not really doing DevSecOps yet as an industry. So the question is why is that? Well, look at the way the answers here are formatted.
You know, I work for an AppSec vendor and do any of the answers here mention a tool? No, they don't because buying a tool is easy. Well easy, I'll put that in quotes because you have to go through procurement and, and all that.
Um, but honestly, you wanna buy something. Send me a message on LinkedIn, I'll introduce you to my sales rep. You can go buy something, but getting you to buy something is hard work for my company.
But it's not the hard work that you need to do if you wanna do DevSecOps, hard work for you is in building a DevSecOps culture. So let's talk about DevSecOps at the highest level. What is it exactly?
What it's not is not just DevOps with security. 'cause a lot of you are probably already trying. What DevSecOps is, is the continued merging of organizational cultures that began with DevOps, right?
So if you go back to 2009, that's when DevOps really kind of started to hit the ground running. And from there it's been a series of cultural challenges. And now remember the, the name of this talk square peg in a round hole.
Why did I name it that? Well, where did DevOps people come from? They come from the land of move fast and break things, right?
They they, they build applications, they try things, they get them to work, they're about getting product out value out quickly. Cool. They spend all their day as developers hopefully in their IDE coding as quickly as possible, trying to be really thoughtful about what they're building.
Where do security people come from? Well, they come from the land of never, ever, ever let anything break will be in trouble, right? So it's, it's just a very different mentality.
Um, DevOps or sorry, security people live all day getting alerts flashing at them. You know, we've got a WAF problem here, we've got a problem with this tool. They get alerts all day and their job is to keep the organization safe and not let things break.
So if you wanna talk about DevSecOps, it's about taking the needs and outcomes of security, which are risk management and mitigation of threats and integrating them into the processes and culture of DevOps. And this is possible, the point is for DevOps DevSecOps to become the same thing differently, I would argue that they are. Alright, so cool.
How do we get there? I wanna talk next about DevSecOps maturity. So what you see here is a graph that I definitely didn't free draw with my track ad and then have the design team put some lipstick on.
Um, alright, that's exactly what I did. But what it represents is actually how organizations at a very high level end up on the road to DevSecOps, if you want a super formal maturity model with like a lot of really detailed steps, Gartner's got you covered for that. They got a great report, but this is a really easy place to start your thinking.
So let's look at the three different levels, the bottom level security focused. This is where the application security team gets a tool, scans for some vulnerabilities and hucks them over the wall to developers saying, here you go, it's your problem. Now.
Um, so that's not entirely fair to security people, but I'm gonna be even more unfair here for a second. This right here, that's shift left. We've shifted the problem left, we're scanning earlier and here are some vulnerabilities.
We need to fix them all right? And it's a really important first step and it's important that your AppSec team takes it, but you really need to then take the next step. And that's developer experience.
Here's where it starts to get in. Interesting for the people who are probably watching this presentation, right? This is where we start thinking about how you as developers work, right?
And that's integrations. That's can you sit in your IDE and get your results there? Can you get remediation guidance there?
Can you get everything you need there? How do we make it easier for developers to stay in their workflow, right? So once the AppSec team starts thinking about that, providing you with tools that integrate, you're getting on the road towards DevSecOps, but you haven't necessarily had all the important conversations.
This last part of, uh, of maturity where we get to actually DevSecOps equaling DevOps, right? That's where we really start to work together, right? We figured it out, we've got some tools, we've made sure that they're connected.
But here's what we realize that that's not entirely enough. And and you've probably been doing some of this work along the way, so I'm not gonna say that it just appears here, but this is where security and development teams and platform engineers, they all sit down and they set joint policies and they enable developers to be more secure wherever they are in the software development life cycle, right? This is where you get automations going, this is where you really, really start working together smoothly and it just becomes a part of your cycle.
And if you wanna see what it actually looks like in person, this is actually what it can look like. So this is a customer of ours, uh, fortune 100 utility provider, pretty big company, no joke. And you'll note if you go all the way to far left of this graph, they had a tool, they bought that tool, it was in fact our tool for a year and a half.
And uh, they were gonna get rid of us because as you can see, they're not really using it. Why weren't they using it? Security is flowing things down.
Developers aren't fixing the vulnerabilities. Vulnerabilities we send them, right? So you've got developers saying things are slow and security is saying you're not doing the work, right?
They shifted, left, didn't really work, okay? So then we started to talk to them about the process, about how do you fit AppSec into the development process. How do you give developers a good experience?
Oh, and then you start to see it start to perve up. Then you start to form some joint policies and you realize, hey, we've got these joint workflows and we're really starting to get some work done. We're really making our applications more secure.
And so here's where you say that you know a tool, it's a tool, but security is the process. And that's why, because it's process oriented in the end, security can find a successful home in DevOps. But what it means is that next we need to talk about DevOps and DevSecOps in the lens of human culture, right?
Enablement, measurement, speed, automation, integration. How do we make these things work together? So we need for the DevOps crowd to get to DevSecOps, we need platform engineers, architects, developers, we all need them to see security tools as developer tools and secure code as performance code.
So I told you that I was gonna talk about integrations well or sorry about um, about DevSecOps requirements. And I've put together, I thought like kind of long and hard about this and I put together a few and I lined them up with calls from the DevOps handbook, right? Almost as great accurate culture automation, lean measurement sharing.
I'm sure that you've read the book. Um, I've come up with my own list of, um, requirements that nest within columns. I'm not gonna do it in that order, but I think that these are gonna help you get you on your way.
So we've got integrations, we've got shared measurements, we've got useful security education, we've got matching security velocity to developer velocity and we've got automations. So let's talk about requirements. If you remember back to our maturity model, the first step away from throwing vulnerabilities over the wall is thinking about the developer experience.
So the first requirement for DevSecOps is to keep developers in their flow state. That means tools need to be delivered directly to the ID to keep things moving. So if you're a platform architect, architect and you're picking a tool, you know, you likely have, you know, multiple, possibly thousands of pipelines.
But what does that mean in terms of support? How many different tools does whatever you're gonna buy integrate with? How many languages it does it support, right?
These are all tool questions and that's because it, these integrations actually become culture themself. The culture part is where its security thinking about how developers work and how they operate. And that's how you take that first step up in maturity.
If security isn't thinking about how developers work, you're not even on the road, right? And all this is important because the goal on the end again, is for developers to see security as a tool at their disposal in developing high performing code and not a rate block. The second requirement is what I call shared metrics.
What are shared metrics? 'cause if you've got metrics, presumably you're sharing them with someone. But simply put, these are metrics that everyone on the DevOps side and the security side can relate to.
And it's actually not what this graph shows. In fact, um, sorry about this graph. If you're colorblind, I'm super sorry about this graph 'cause there's no way you can read it.
All I can say is even if you can still see colors, you probably can't read it, but I'm gonna talk about it for a second. 'cause what it shows is all the way on one side what developers care about in jail is their responsibility. And on the other side what security believes is their responsibility.
And you can kind of see where they sort of meet in the middle. Um, but the point is this illustrates how security and development at DevOps, they're thinking about vastly different things, right? So security teams and development teams, we know already that they think in very different metrics and they feel responsible for very different metrics and they contribute to tracking different metrics.
But if you wanna do DevSecOps, you need everyone thinking about the same things to to a point, right? So sure security can go, they can look at total number of all our abilities, they can look at how many of each severity they have, uh, that's been remedied and that's really good for them for their own reasons. Um, it's really helpful for security to show that they're doing things but it doesn't drive forward DevSecOps.
So the question becomes what are good metrics? So good metrics from a DevSecOps perspective are those that show you how quickly your integrated team is delivering value for the organization. Metrics that help you direct your efforts, identify problems in your pipeline so that you can work more efficiently.
And that isn't to say that these other metrics don't have a place. You know that the DevOps metrics, if you're a developer or platform engineer or an architect, you know that those are useful and you know why they're useful. Um, and these, these numbers on the left, the AppSec metrics, those are fantastic for application security teams to say, Hey, we're doing work.
Justify it up the chain, justify the purchase of tools, justify headcount, which they need to do a lot of, right? Because a lot of people see security is just a cost center. So they need those justifications.
But what you need to get to together is you need to get over to the right where you're watching these DevSecOps metrics that are gonna keep your machine running, right? And the most important of those is mean time to remediate. So that is how quickly are security and developers working together to get vulnerabilities fixed, right?
Need time to detect how quickly are we detecting metrics? How quickly are we getting them through the pipeline issue volume? How many security vulnerabilities are there?
And that's becomes really interesting if you can break it up by application and team, what are your top vulnerable applications? Where do you need to really like spend your limited security resources? Do you have a security champion program?
Do you have security consulting teams internally? Where do they need to spend their effort? Security coverage?
How deep are we actually scanning applications? How does that factor into the risk? Are we looking at internal applications that are behind internal firewalls, not as risky.
Maybe we give them quicker scans versus the stuff that's really important that goes out there in front of customers, collects PII that needs the really deep scanning. These are all things that need to be figured out and need to be measured to show that your DevSecOps effort is really working together as a machine. Third thing I wanna talk about is security education.
So performance is really firmly ingrained in development culture. You can see it along the timeline here. The problem is security is so, you know, 20 years ago performance wasn't really either, but now it's, so if we're looking at this timeline, we're saying, okay, you know, the building blocks for DevOps happened in the early two thousands, 2009.
We've got that great presentation. Things start to take off. You know, it's now, it's been 15 years since 2009 and still in some places DevOps efforts are just getting off the ground, right?
So DevSecOps, we know we've been talking about it for a few years. It's got probably another time 10 years before we're really getting it down. Well, but we know we need to get it down faster than that.
We know that, uh, you know, there are a lot of threats out there and they're all targeting, uh, these new applications that people are building. So, you know, how do we get, what do we follow on the road of tho those next 10 years and get to the place we need to be at? And education is a big part of that.
So if you look at the stat at the bottom, only 50% of de bars state that they have access to security training. That's because we know that universities don't teach secure coding. We know bootcamps don't really train devs and secure coding.
And we know that it's also a big complaint of security teams. Uh, the developers don't know secure coding. But we also know that's not really developer's fault, right?
Developers learn through especially about security through experience. So like, hey, that guy over there, he had a problem with a big cross-site scripting vulnerability and he had to fix that. He's the guy who can tell you all about, or, oh, that lady over there, um, she was working on the lock four J stuff, so she really knows her stuff, right?
It's, it's not their fault. And knowledge becomes tribal here and there. But what do we do about that?
And what we need to do is give developers options, right? And we've got three different types of options. We've got training, we've got just in time and we've got inline education, right?
So what do these look like? Formal training? It's you get access to a security coding course, uh, or a secure coding course and you put your developers through it takes a lot of time.
Um, and maybe, maybe they have time to work on it during the week. You know, I know that, uh, developers focus a lot on learning. And maybe you have like a Tech Thursdays or Coffee Mondays or you know, some sort of learning program and, but this is just a part of it, right?
So who has time to really sit and do formal training all the time? Not everyone, but it needs to be an option. The next is just in time training.
So this is help when they need it. So do, when you get a vulnerability sent to you through a tool, is there a mediation guidance attached to it? Can we save developers the effort of spending an hour or two hours going to Google, doing as much research, figuring out what is this vulnerability?
How does it manifest? How do I fix it? Am I doing this properly?
Right? What can we give them right there in that moment to help them learn? And then going even faster than that, there's inline training.
So that's, you know, do you have some sort of a probably gen AI tool that's gonna give you feedback as you're coding, right? And some of those are available in various states. So these are the three sorts of things that, um, you know, platform engineering teams need to be thinking about when they're enabling their developers, right?
This is the thing that development teams need to look at. Hey, we need education. We know we need to get better at security.
How do we do it? Here's three different types that are available. Next, I want to talk about getting security up to the speed of DevOps.
And usually I'll ask people in the room, Hey, how often do you release? And I presented this library recently, and the general answer I get is, you know, two weeks or three weeks. And how often you release drives the rhythm for everything else you do.
And for DevSecOps, that means it needs to include security. So the question becomes, how does security fit into that release schedule? And we started the conversation earlier with metrics.
Alright, so now what does security need to do? If you were to speak to a vendor like my company, these are some of the answers you'd get. And these are really good questions to ask in comparing tools during a purchase cycle.
They're good for internal requirements building, can this tool do these things for me? And you should ask these questions. You know, these are all methods of reducing developer toil.
Very important, right? Because in the end, you don't wanna buy a junkie tool. But do these questions get you to DevSecOps?
No. 'cause again, DevSecOps, it's people, processes, and then tools. So when you think about speed, you need to think about it from a DevOps perspective, right?
What's the business goal? What's gonna drive value? And the business goal of DevSecOps is to quickly deliver secure features and applications.
And I want you to take a second and think about how important this is, right? 77, and this is all some survey data that we've put out there, but 77% of CISO say that at least 50% of their organization's revenue runs on application for the responsibility for protecting. 91% of organizations have deployed no vulnerable code into production to meet deadlines.
And 92% of organizations have had at least one breach as a result of a vulnerable application they deployed, right? So revenue's coming in through your AppSec, everyone's deploying known vulnerable code, and everyone is getting breached. So the question becomes, if you grind through your DevOps processes, you release an app quickly and it gets breached, maybe your company gets fined, there's brand reputation damage, and you need to maybe take an app offline for a big emergency patch session.
So the question is, did DevOps work and was it actually fast, or was it just fast in the moment? And I think we know the answer to that, right? Remember, the original Agile manifesto was about responding to business needs.
And did the business need that breach? No, it needed a secure application. So then what really is speed?
It's how quickly you as a team solve problems. It's about meeting time to re remediation. It's about training developers to understand risk and about training security teams to understand how they contribute to developer velocity, right?
It's training and it's culture. It's about redefining high performing code as secure code where the biggest risks have already been mitigated. And if your organization doesn't believe this, it's never gonna do DevSecOps.
Everyone needs to be on board with everyone else's needs. And that of the business as a whole. I'm gonna talk about automation last because you just can't do it very well without everything else coming together from a culture perspective, right?
But everyone's got their own role to play. Everyone's got their own little bits and pieces, and we know that automation is absolutely what you need to get to, right? If you wanna reduce friction with security teams, everyone has to be going in the same direction.
And again, this is the coming together of very different cultures we've been talking about this entire time. But in the end, they're both primarily interested in what's best for the business. So the point to get to automation is to get them both thinking about what's best for the business in the same way.
So let's talk about nation, but first, some survey data. We asked our group of CISO where they were putting their security controls, and you can see some red flags here, right? Training, not a lot going on there.
Uh, go live also pretty low. So we know we as an industry need to do a better job of folding that into AppSec, but there is this reasonable bulge in the middle of our data that's around code, build, test, and deploy. It's a good place to start with automation.
And the question is what's possible? And if we line up potential automations with the SDLC like I've done here, we get lots of options. And I'll leave you all afterwards to take a look at this slide.
I'm sure the slide will be distributed. Um, I'm gonna pick a few, uh, I'm gonna pick one from each section here just to talk about examples. Um, so the first in in training is security tickets, right?
Um, that security tickets being auto-populated with remediation guidance. This is something I talked about earlier when I was talking about education, right? And that is, it's a basic automation.
Your tools can do it. Basically, everyone out on the market has some form of remediation GUI guidance. We think ours is the best, but you know, that's my job to say that.
Um, but just getting developers right away in a ticket in their IDE, here's your vulnerability and here's how to fix it, that's a great help. That's an automation right there. Next, uh, in design phase, secure by default pipeline templates.
And honestly, this is just like standardizing your build, right? So if you do the security work back, then you get to reduce developer toil on security fixes later. If everything you're working for has been hardened to begin with, if I go to this third section, I wanna talk about fast lanes for a second.
They're super aspirational. And they happen when security teams and DevOps teams are really, really tightly aligned. It's about trust in one another and in your tools.
So this is essentially, um, an automatic approval to deploy to production from a security scan, right? So essentially what you've got is you've got different dev teams and they're working on different applications. And when you get to a certain level of, Hey, I, we've built out this code, we've got no high or no critical vulnerabilities, rather than saying, this has to go through all of your security processes, boom.
You can, you just get the okay to deploy, right? So if you're looking at, if you know it, it's essentially about removing humans from the loop as much as possible, right? You've looked at your results, you're feeling confident by not take an auto approval, right?
If you get this, the scan, again, no highs, handful of new mediums, just deploy it automatically get there, and you can set different levels of fast lanes as you go. Um, and it takes really strong governance and cooperation efforts between security and development teams. But the more that you're able to set these up, the more that you're able to, uh, allow developers to kind of get things out into production as quickly as possible and have the security team feel confident about what's been going on.
The question is next, alright? We've talked about what can be automated, what can't, or remediation. You're not gonna let an outside vendor change your code.
You're not gonna let it, you know, AI automatically remediate your stuff. Yet there are limits to automation. So if there are limits, especially around remediation, what can we do to make remediation as fast as possible for developers?
All right? It looks a lot like what we've been talking about just in time training, trusted scanning, gen ai, remediation guidance, right? Production and security, uh, champions and mentors, right?
All these sorts of cultural things and these tool things, they all come together and it's about getting developers the most information, um, that they can get. And that last thing on there, I, I know I mentioned it only briefly, security champions, that's like its own talk it entirely. Um, but if you do automation and training correctly, you can actually free up developer resources for this sort of team, right?
So imagine having the floating team of developers and security people who keep an eye on the metrics, they know, Hey, this team over here is having trouble, their applications are the most risky, consistently, what's going on? Send in that team to do training, to do mentorship, right? Help them, uh, for extra remediation, you know, and make loads of coding.
Really get them in there and help. And I highly recommend you look into security champion programs. There's a lot of other information out there, but I think it's an important part of the culture.
I wanna end with a slide that I usually put at the beginning, and that's because you all know everyone who's watching this, you know, you're all part of this, this evolution of application development. Everything about your job is changing year after year. And I would say that you have an opportunity right now to think more about security, to work with AppSec teams, to build DevSecOps pipelines.
Because as you look at this, if your business doesn't already demand it, with everything that's happening in your applications, your business is gonna demand it pretty soon. So what I urge you to do is take some of today's keys concepts back to your organization. Think about how you would do your job differently if everyone believed that high performing code was secure code.
If everyone believed AppSec tools were developer tools that must be part of their workflow. And if DevSecOps was a culture problem that your organization needed to solve, because it does. So, thank you all so much for your time today.
I appreciate it very much and have a great rest of your day. Hi everyone. So it seems Apple has a bad case of fomo, $500 billion worth you're watching, Techron Gang.
Hey everyone, it's Alan Shimel. Say, Alan Shimel. Different background.
I'm not in our studio today, unfortunately, we had some work being done here, so you're getting me in my desktop version here in my office. Uh, happy to have you with us though on this wonderful, uh, Wednesday. We've got a great lineup for you.
I mentioned Apple's, fomo, it's an expensive, one of the most expensive FOMO I've ever heard. Uh, but we've got more than that to cover it. We've got some great people to cover it with.
Let me introduce you to them real quick. Um, first of all, it looks like he's back home high at top Silicon Valley one and only Jon Swartz. Hey, John, how are you?
It's good. Good. Things are good.
It was great seeing you all. You mi Mitch, Mike Amanda, last week in New York. Um, good times.
It was way too short, but yes. Yeah, it was great seeing you. Yeah, great to see you.
So thank you. And we, and we, you know, alluding to a editorial in person team meeting we had in New York last week, uh, in case you were smelling anything burning, it was all those brain cells we were expanding on, on how what, what we're gonna be doing editorially for 2 20, 20 25. So John, great to have you there.
Speaking of having us there for our editorial meeting, she is our managing editor. Is that, that's the right new term, right? Amanda?
Um, senior Managing editor. Senior managing editor. We don't have a junior managing editor.
You are the only managing editor, but that all be said Wait, wait, wait, wait. We actually do have an assistant managing editor. Oh, okay.
We have an assistant managing editor, um, but she's back home in Texas where I hear it's in the high eighties. A little different than New York last week. Amanda Razani.
Hey Amanda, how are you? Good. Yes.
Big temperature shift from New York back to Texas. All right, we'll stay in the warm weather for now though, and go over to our friend at sea, uh, security expert, Chris Blask. Hey Chris, how are you?
Hey, Alan, I am good for those of you following at home, this is Stock Island. We see out the window, the island next to Key West. And specifically what used to be the five Sixes taxi company actually had a little war for their own.
So all the pink cabs for those of you who've been in Key West, that was the five Sixes Tag Z Company, which I think is finally gone. Very good to see you. Good to be Here.
There is no Uber down in the Keys, if I remember correctly. Oh, there is Uber. Absolutely.
I use it all the Time now. There is who I think last time I thought there was no Uber there. Anyway, Chris, it's great to have you on board now.
We'll go back up to our cold weather friends first. We'll go to the guitar man up in Colorado. He's back home after a quick trip to New York pit stop in the DC area and, and home to new, uh, Colorado.
Mitchell Ashley. Hey, Mitch. How are you?
Doing well, doing well. Yeah. I made a pit stop in DC as you mentioned, spent some time with some BMC folks, so it was great.
Uh, great to, you know, both be in New York and get a chance to be with the editorial team for a little bit, and also go and visit some companies. Excellent. Thanks Mitch.
Welcome. And then last but not least, he, he looks pink. It must be cold up there.
Um, up from Harrison, New York, the dean, Mike Vizard. It, it's quite the opposite, actually. It's gonna be 50 degrees today.
And since we live in a world where correlation is causation, you guys should stay the hell outta New York. Yeah. As if you think 50 degrees is warm.
Um, but anyway, Mike, great to have you on here. So I, I wanted to kick off today with, I, you know, I teased it in the opening. Is this a case of Apple's fomo?
Is it a case of wrapping themselves in the flag and getting in the good graces of, of the, uh, present administration? Or is it just good business, right? What do you think?
I think this is a very extensive way to bend the knee, but, uh, John, I think you wanna like jump into this? 'cause I'm sorry. Yeah, Sure.
I'll, I'll give, I'll, I'll give, I'll give some of the details and then I'll throw in my editorialized viewpoint because I, I, I think it's a combination of, of everything Alan said and what you just said, Mike. Basically, apple is throwing a big bone to Trump in a sense. They announced on Monday, they're investing more than $500 billion in the US over the next four years with plans to hire 20,000 people, open a new manufacturing plan in Houston, open other, or expand on other facilities in California, Michigan, Iowa, what have you, Arizona.
And they've also, in a sense, made this commitment to basically, Trump kind of teased it out. He basically dropped, he ba basically blurted out that he met with Cook very stealthily, and that cook assured him that the company Apple was gonna shift to manufacturing from Mexico to the US to avoid paying tariffs. So that's a major motivation.
The other motivation is that in, in terms of China, apple also ha is, is, is, is at risk, right? With these, these 10% tariffs in China where most of Apple's products are made. So in a sense, thi Cook, who I think is actually very good at playing Trump in a sense, probably, I don't, I don't believe in a mo in a second that they're gonna devote this much money.
They spend $10 billion a year on capital expenses. Now, can you imagine them doing 125 billion a year for four years? I don't think it's gonna happen, but I think what they're gonna do, they're gonna do just enough to, to get exemptions from him in terms of tariffs.
They're gonna keep the White House happy. They'll do some of the things on the list, and then they'll move on. Because once again, think about history.
Back in 2018, apple made a similar pledge during the first Trump administration. They said they were gonna create 20,000 new jobs as part of a $350 billion US investment plan. And as part of that plan, they were not targeted in terms of tariffs in China.
So, in a sense, apple is playing it very smart politically. They're also trying to stay up to date and up to, up to par with the other big tech guys who are throwing hundreds of billions of dollars into AI development. It's, it's, it's political, but it's, it's also business wise.
But I think in a sense, cook is kind of the master when it comes to playing Trump. And I think the other tech leaders would, should, could learn from him. So lemme ask, I think, like you said, John, there, uh, the first thing I thought when I read this article was, um, they're kind of just following suit.
They tend to be kind of the last, they stay back. Yep. And they're the last, you know, so they're just doing, so now They, they usually draft other people and like, thinking of the car analogy, they draft other companies.
Mm-hmm. When they, when they move into a market, they wait until the market's established, then they make their move. They may be late on ai.
That's debatable. But in a sense too, this is one of those things, you know, and also, is it just me or I sense a deja vu? We saw that $500 billion figure before with Stargates.
We're seeing the 20,000 new jobs figure from 2018 to now. It's just they play this narrative and this formulaic game with Trump to keep him happy and then he gets distracted and moves on to something else. Yeah.
I think it's also difference in leadership style here. You mentioned Apple kind of follower, that's one part of it. I think, you know, cook doesn't need to be out there with the tech bros and trying to be, you know, the Musk and the Zuck and the whoever, you know, he, he's just not into that part of it.
It's all part of the, um, you know, perception is the alternate reality nowadays, instead of perception is reality. I I, I agree with you. It's a, well, what is that 500 makeup?
Well, it could be, yeah. Apple Cash investment, whatever. It could be ecosystem of Apple and all the partners and everybody that is part of, you know, investing and creating technology that ends up there to support or part of their product.
So it it's, it's a game. It's a game. And, you know, it's about creating the people that are supporting Trump's policies and, uh, getting them to be visible and vocal about it.
And nobody goes back and says, let's do just sticker the tape here and see what really happened. No, that doesn't happen. Can I just mention one really thing, thing really quickly is like a picture tells you a thousand words, right?
At the inauguration. You notice we, we have this iconic photograph of Zuckerberg pka from, from Google, Bezos, Musk, all lined up together. Guess who's behind them?
To the right to the left of the camera, just out of range. So you can't pick him up. It's Cook.
He's the, the Apple's also the company along with Microsoft that wasn't too obvious when it came to doing things behind the scenes as Meadow was and as Amazon was. So in a sense, this guy is the cook in a sense is kind of this kind of cool customer politician type. And I think he's handled it pretty well.
But the, again, I'm just gonna go back to it, the $500 billion that's just is like, I, that's, I cannot believe that's gonna happen. So let's take that number apart because you know, we used to see IBM do this crap all the time. They'd stand up and say we're gonna spend $50 billion on something.
But, you know, they added up every nickel that they spent on every other thing. It's like, how much do you're saving us? Right?
Similar. So I mean, $500 billion on a company that to your coin, has been spending 10 billion a year. So that's gonna ratchet up by a factor of what that doesn't seem.
12 and a half. Yeah. So, so if that's the case, you know, Alan, I don't know what you think, but every time I turn around, alright, Lemme tell you what I think I've been very patient.
Let me just say the emperor has no clothes here. It's no secret around the world that this buffoon can be played like a cheap suit on a, in a, in a nickel piano bar. You come up and tell him what you're going to do, and the more you promise and the more outlandish it is, the more he touts it.
This is not a new script. Where's, where's the money from? Uh, sun from SoftBank from the last time he was president, they never invested.
Damn. Done. Where's the new boss name Is Old Boss, right?
Not done yet. I'm not done yet. Where's the factory that TSMC was building the last time we were here that they never broke ground on?
Has any of these MFS ever spent anywhere near the money they say they were gonna spend? This isn't an old IBM thing. Macro did it yesterday in the White House too.
This is theater at its best when you've got Charlie Chaplin playing the dictator and people can come in and do it and say whatever they want and he gets all happy about it. Guys, wake up, smell the coffee. First of all, what, what exact AI server is Apple making?
Are they going into the server business? Is that what I'm assume? Is that what I'm hearing?
Because I I'm not aware of any Apple servers. Mm-hmm. It's only the ones that they use for their own cloud services, theoretically.
Yeah. Yeah. They don't make servers stop.
Oh, you're kidding. He But Alan, Alan a a a cook could just make something up. He Used it come up any type of lumbo, jumbo, it's not book.
It's smarter than everyone else. Right. They all make s**t up because that's what we live in.
We live in a b******t world where the more you bs in, the bigger the Bs and the louder you say it and the more you say it, the more he expects people to believe it. I've had enough. It's a month in and I'm done with it.
I don't believe a damn word that comes out of these things. Just as I, I didn't say it jokingly. This is the same thing with Doug saving us a trillion dollars.
If, if, if 1% of that is real, the whole thing's nonsense, but it's consumed by an audience that wants nonsense us. We're not, we're not people. We deserve what we get.
So you don't believe that. So you don't, so you don't believe that Meta's going to, uh, plans to construct the world's largest undersea cable to advance, to expand high speed internet access globally then? I'm being Facetious.
Well, well, why would we give them, I'm being very facetious access. We're gonna keep all our internet access here. But Alan, you don't understand.
We wanna believe, we wanna believe we want this to be true. Because if we don't, then we're wrong. And that would be bad.
We're not gonna admit we're wrong. I'm saying we at the bigger we not me. No.
I mean, we, we could say whatever you want, but look the facts, bear it out. Right. Some of the nonsense too is like, how many of these jobs are actually gonna get created?
Even if I built this giant factory in Houston, all that's automated. So there's not gonna be actually a whole lot of people getting additional jobs just other than that guy maybe who's overseeing the robotic construction engine. Well, Yeah, that, that's definitely, can I just show you the ludicrous, the, the ridiculousness of this take 20,000 jobs divided into 500 billion.
What does each job cost to you? A lot? Well, yeah, that's, Each job costs something like $50 million.
Those are real expensive. F*****g, excuse my language, those are real expensive jobs. Those are real expensive jobs.
Let's let to Pretty it up to pretty it up. Apple said they were gonna focus on r and d, the jobs r and d, Silicon engineering. What?
Ai machine learning. Again, it's, you know, just feed the bees. Just tell the emperor what he wants to hear.
That's all. He's not his head approving What this, this is. So I'm not sure if it's quite Caligula or was still at Niro, but it's something in that, in that range right there.
I never thought I'd hear Caligula on the show. Wow. It's $25 million a job, by the way, Alan?
25 million. Excuse me. Okay.
Yeah. Those are some pretty expensive jobs. So who, the math doesn't even work, but who cares?
These people don't care. We won. We won.
You know. But do you think they really are gonna open some factories? Like are they opening a factory?
They build their AI servers. Okay. They don't have AI servers, Amanda, but, But I'm just saying, do we think they're like, are they gonna build a factory to start AI servers?
I'm just curious. I I think They'll build something that looks like a factory, but there won't be any workers in it because it's all gonna be run by Robot. The all automated, I mean, look, if you're, if if Apple was serious, they would talk about building iPhones mm-hmm.
In the us You know, the, the, the iron, the irony in all this is that the guy who told the truth about how ridiculous this is is Musk in his own weird way when he said that the Stargate would never bring up five, spend $500 billion, let alone raise the money. So, I mean, in a sense he knows how, how patently ridiculous this is. So Well, but, but, but, so there's the corruptness of the whole thing at the very top.
The people like Musk and even, I don't know about Trump 'cause he, he is in a bit of his own world, but, but Musk and some of the other evil generals behind this, they know that this is all for public consumption. That this has no, no foot in reality, but it's red meat for the masses who, who consume this crap, who are gonna say, look what he did it. And, and no immigrants will work there either.
No. H one B visas want all red blooded ADEs. And it's a Good thing all those people were laying off and the government will now have jobs working for Apple.
Hey, 20 million million, yes. 25 million job. I quit my government job for that job too.
I'll just take the recruiting fee on that, on this. So I for 1:00 AM not gonna be, I, that's not me, right. My film.
Yeah. You know, rewind, this Is like, like the most, this is the most effective news Apple has announced in a long time since the products have, have been exactly. Knocked our socks off lately.
So, Well if they start, I guess it's A great Free marketing for them products. Yeah. So do you think we're gonna see, you know, Samsung show up and start talking about how they're gonna make phones in the US and Everybody Factory next door to Apple.
Mm-hmm. You know what they Say talk, talking about? Yes.
Mm-hmm. Talking is cheap. And if that's all it takes that and a little flattery and they'll vote for you in the un resolution too.
You're good. I mean, this is the state of the world we live in. As, as, as Laurel would say to Hardy or Hardy would say to Laurel, it's a fine mess we've gotten ourselves into.
So you used to say the new normal. It is the new normal right now. Well, On behalf of Textron and John and Amanda, I'd like to pledge right now that we're gonna write 50 billion words about this in the next five Years.
Seems like we have actually No, I'm just kidding. Mm-hmm. That's for sure.
It's about right. Transcribe this video about 20,000 times and you're close. I'm just trying to find anything to add to this.
You know, as a Siri person in the room, lemme just say it, right? You know, I said, I think you're all right. You know, I think you're all correct.
And I think, uh, Tim, uh, cook is, is in his corporate role and his responsibility to shareholder value doing, as you discuss exactly the right things, stand just outside the picture, say the right sort of mouth things, you know, and, and protect the, the corporate interest. Um, and Alan, Kevin, you're right as well. Like, this is again, as we discussed, this is this information warfare environment we're in.
Where when you get to the point where, you know, the, the Steve Bannon goal of bearing the field in, let's say manure, um, to the point that nobody can tell one thing from the other, that's when just shouting works the best because nobody can figure out what's true. So the loudest voice wins. And as, as you know, aside from every other role, you know, anybody in my profession has, you know, remembering that it's information security, not cybersecurity.
You know, we're the folks supposed to understand how information can move around in ways that people can use that It's not working right now. We've got work to do by the answer. Dunno.
But yeah, that's, this is the world we live in, Certainly is my friends. All right. Um, let us take a break here on Textron Gang.
Let's calculate how much we could really pledge of what we're gonna commit over the next four years. We'll be back. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching it, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
4 billion on AI and data centers and all kinds of fun things. And Chris, you know, I'd love to get your opinions here because one of the things people don't really talk that much about Alibaba is they have data centers in Northern Virginia, California, and given the current climate, how political do you think all this is gonna get? Are we gonna wind up someday serving eviction notices to Alibaba to kick 'em out of the country?
Because everybody's just gonna line up on their favorite national boundaries. And I'll add Lenovo into that mix too. So how crazy can crazy get, Oh, it can get really crazy.
That's a, that's the thing about crazy, right? The the range is always wide, and I don't know, it, it's so has a Cold War kid, right? I, I have this funniest sort of slanted view of what's going on in the world right now because I grew up with the idea that we have these countries, the Soviet Union and China behind their great walls.
You know, they're just, they've cut themselves off from the world where we are the free market, free speech capitalist, de de democracy side of the world. And we'll engage with everybody. We'll, in fact, create a global supply chain and we'll teach you how to, you know, do the same things we do back at home so that you can do the same thing and make money and heck buy our product, sell us something.
Heck, you know, we'll, we'll, we'll go nuts. Which is the, the whole American thing, right? And all my life, my, I've as, as I've said, you know, I belong to all three major political parties at different times.
I believe that each time I, I think there's interesting points we have is a bunch of crazy yanks, but that's what it boils down to, right? Right. Almost unique.
You know, I, I think I love this country. I think it's, it, it maybe, it certainly is, you know, everything's unique, but I think we have a special role in this, and I'm a security person, I get it. So watching Russia cut itself off from the world, you know, a, a creto, uh, uh, you know, dictatorship from classic, uh, doky, right?
You know, watching China go the opposite direction. Anybody, any American who's done business in China, you know, in the re in the modern area, you walk around, it is a capitalist, boiling furnace. People will sell you things.
You can't walk fast enough not to be sold something walking down the streets. And then to see us now arguing the exact opposite of everything we've argued since Eisenhower. Right?
You know, let's wall ourselves off and let's make sure that we can, I don't, I don't think that's the right direction at all. Um, but I will say that, you know, on a security, you know, having a supply chain is a thing, and we really do need to, for a purely security reason, know what's in our stuff and who did it, and, and to the right level know all the way down. And we haven't been able to, um, we can feel comfortable about things, not just in these massive geopolitical things, but really any things, until we can figure out how to do that, and we're getting there, we will get, you know, it is achievable now this decade to implement any individual sector, for example, um, really astounding visibility in supply chain.
Now, if we had that, and you could then say, now at the nation state level, geopolitically, you know, we have these concerns, where is it? Instead of just napalming, you know, entire continents with policies, you know, that might be a different world. I Don't know, John, one of the things you hear all the time is that we're losing the AI race to China.
And I can't tell if that's real or if that's just some scam that the valley's running to get more funding on Wall Street and the, and the government. I think it's the peer missing out. You're right.
It's, it's the whole FOMO factor that we mentioned at the top of the show, right? You just, you just create this enemy. It was like the us uh, channeling what Chris said, going back to the Cold War, the d the defense contractors would, would warn us about the, the nuclear arms race and how we, there was a missile gap.
And then we would, in a sense, get more funding, more funding, more funding for defense. I think the same thing's happening in Silicon Valley where there's this fear factor. Deeps seq really hit home with it.
And in fact, deeps Seq is coming out with its sequel to R one very soon, evidently, according to a, a Reuters report. So there's this, this, this, this calculus that the companies are making here, because they're getting so much funding for anything that's AI related, even if it's a silly idea. And, and again, you, you prop up China as the big enemy, you know, deep seek, uh, Alibaba, whomever, or by dance.
And you, you, you create this enemy, you create this fear, and it just helps you, it just is very self rewarding. So, you're right, Mike, this is, this is where it's going. And the, the narrative's just gonna intensify, and you're seeing it like every other day.
There's like some ridiculous amount of money allegedly going to a project. Um, and it's, it in a sense, it'd be interesting to see in hindsight, what percentage of the money's actually spent that's been promised. You know, it probably is gonna be less than 20%.
Well, you know, uh, John is, we, we, if you remember back to too big to fail, right? The institutions that are so big, we can allow fail. We, we have a similar kind of attitude around ai, I think at all levels in the, whether it's nation states or the latest startup is AI is, is too important to lose out.
And so that's why we see such massive dollars being spent on data, ai, debt centers, or at least, and the big claims, the $500 billion kind of claim. Some of it is marketing position and, you know, keeping your name in the, in the conversation. And some of it is real spend.
But we're in this race to spend as much money kind of race to the bottom of how much money can we spend out AI just outta fear of losing at some point that will course be so over overburdened in terms of bubbles and market sizes and ridiculousness that we'll, we'll pay the price for it. But that, that's the era I think we're in right now, Right? It'll correct itself.
It's just a question of how long this is gonna last. I mean, it could be six months, it could be a year that there's such a volatile pace to all, everything that's going on in terms of the funding, the promises, the, the models that come out seemingly every day that, that beat others in terms of benchmarks, which are very nebulous to be, to be charitable, Little irrational exuberance. Anyone.
Um, so let me, let me give you my shimmy take on this one. You know, I, I spoke about this, I think it was two weeks ago, and I called it, uh, AI imperialism, right? And that's what you got going on here, right?
Let, make no mistake about it, Russia is probably not in this race until, until we become very, very close allies. And Trump will probably transfer some of our best AI technology and build some factories and data centers in Moscow and, and St. Petersburg.
'cause after all, they are, we are our best friends historically. Um, but the real race here is every world power is trying to take, become a leader in ai, right? That deep seek was Sputnik.
And now the us my God, they're panicking. And we're gonna spend $500 billion on Stargate, and we're gonna do this. And Apple's spending another 500 billion and we're putting it all here.
We're gonna be the US leaders of, well, we don't wanna be leaders of the free world. We're just gonna be the us the greatest country on earth, and it's all gonna be right here. And if you want to use it, you gotta come here.
If you're over there, you can't use it. You gotta come here. Europe says, well, we're not coming here.
We're gonna make our own thing. And we're investing a couple hundred billion dollars too, including Ukraine, right? Then you've got China, and, and China's a different cat because when Aaba says they fit 52 plus billion dollars, you got the full faith and credit of the Chinese government behind them, basically, who own, I don't know, a couple trillion dollars of US bonds, right?
And their game is clear. They wanna be the preeminent power in ai because there'll be the rest of the world who is gonna want to use it? And that's really the game here.
Who, who's gonna own the spice trade? It's the same game that's been going on in on earth for the last 500 or more years. Who's gonna own the Spice trade?
Who's going to, who's gonna have the, not the monopoly, but the best of whatever the latest commodity is, right? We're fighting for Dune. It's ar rakus.
He who owns spice, the oil fields, it's name, the, you name, the, you know, most important asset. Chris, do we need, do we need the equivalent of a speech from President Eisenhower warning us about the AI industrial complex? Uh, no.
Right? You know, I, I, I, I have to, I have to put some light back in the room. And, uh, not that, not that the, the doom prognostications or or risks aren't all over the place, you know, and, and yeah, I mean, and, but my last comment, I was thinking more generally, generally, right?
As you guys were saying, you know, there's, there's a lot of posturing, money I arguably throwing around and so on and so forth. It is what it is. You know, I'll believe it when I see it.
Um, but, uh, you know, I, I think it, you know, I think like a lot of waves, I'm a little crazier and stupid this time for various reasons. It's right and it's wrong. I think that it is important.
I think what we're currently calling ai, oh gosh, is kind of what we've always thought computers are supposed to be. You know, we shouldn't have to actually know how this transistors work at the atomic level to be able to use the bloody things, you know? So the irrational exuberance is at every level, right?
So the, so our governments and our governing bodies in the state that they are responding as, as you folks are saying, kind of stupidly, you know? But, you know, and it could be the end of the world, you know, lots of things could be the end of the world. But, uh, I don't know.
I don't think the, I don't think a a nation, we, number one, you don't have an Eisenhower or anything like it. Um, and I, we don't have the same in our reach. There's not three channels, Right?
You know, you know, Do anything about this. You, you, you know, there, there was this in his, remember in his farewell address, Biden referred to the tech industrial complex. I think that's what he, how he, he phrased it as kind of a warning shot as he was leaving.
Since he left, things only intensified. It was almost as if he never said anything, which is probably par for the course, but, and it was, it was ignored, if anything, things accelerated and, and tech got more powerful. So his warning shot was kind of an echo and a distant cave.
Mm-hmm. I guess. Well, you know, if you whisper something, nobody's gonna hear it.
So that's kind. I wasn't gonna go there, but you're right. Yeah.
I mean, it's, it's mess as an entrepreneur. I mean, John, you're right. You know, I mean, it's, it's funny, you know, among my left-hand friends, you know, I'm the capitalist pig corporate guy, right?
Those entrepreneur, I really believe in all that stuff. And, but this doesn't help. Right?
You know, concentrating all the wealth in a couple of hands and all that, that's, we did that for like, I don't know, most of human history. Um, the idea is to have consumers who can afford to buy things and start companies and do stuff. So all this 500 billion here, 500 billion there, and tech bros who, you know, dominate the everything.
This isn't great capitalism, aside from everything else is good at what it's supposed to be at Ali Baba is this move from Ali Ba it's a sad state of affairs. Affairs when the Chinese not capitalist us. Uh, but this move is clearly, they are planting flags in AI throughout the world.
They wanna be the world's AI provider. And, and don't get yourself, Tencent, Alibaba, Baidu. These companies have the, the muscle, especially if we retrench and just focus inward, that will, we could wind up not being the leader in ai.
That's true. And if you're sitting in Africa or Asia somewhere, and you're watching what the Americans are saying, who are you gonna turn to? Absolutely.
And that's, and that, that is, that's the game here. That's the game. But don't worry, we'll have Russia.
So I'm genuinely, um, curious, I just wanna hear your thoughts. Um, are there any security concerns that the rest of the world will have to have? If one country comes out way on top with AI and can controls most of the ai, will there be security concerns for the rest of the world?
That's a concern, Amanda. Security and dominance in the world is obviously from weapons to economies to you name it. I mean, that's the concern.
There's reasons for this big race that we're having. Yeah. Well, it's like the, like the, the space race, right?
You know, and a lot of people, you know, I live on Starling, right? I, I had the opportunity to, uh, long conversation with Gwen Shotwell, who runs SpaceX and Starling and all that, uh, like five years ago, and I've been using it ever since. And it is mean a lot of people sitting, right?
All these satellites and Kessler syndrome and messing with the stormy and so forth. You have to understand that this is, this time China is putting up massive, Europe is putting up massive communication satellites. We're in the era where there can be massive s uh, satellite communications array.
You know, there need to be more than one. And one of anything is, is dangerous and risky. Um, this, this issue, ai, big, big huge ai, right?
The sky net potential ai. Yeah. There need to be more than one, right?
It's all to all the conspiracy theorists out there, right? You know, even if you're right, there's seven other conspiracies, they're, they're arguing amongst themselves. I think mostly we can ignore things as long as there's not too much concentration in one spot.
And this is, yeah, I don't think we're a risk of that actually happening. I think we're a risk of global conflict because of perceptions is not happening. But, uh, but yeah, we can't have, there cannot be only one.
This is not Highlander. Okay, alrightyy, let's take a break Reference, but I got It could be only one Sean Carner. Anyway, hey, let's take a break here on Textron Gang.
We'll come back. We've got our third block to go over. Hopefully it's a little less contentious.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
All right, we're back with that slightly less contentious se segment that we're about to talk about, where the president took time out of his incredibly busy schedule to call out the European Union for applying taxes slash tariffs to digital services that are created outside the, of their particular country and region. Um, that got a quick response from the EU country saying, uh, mind your own business essentially, and we'll continue to do what we're gonna do. But, um, this managed to get rolled up into this tariff conversation, and we talked about the impact tariffs were having on tech last week, or I don't think Alan was on that show, but, um, as you look at this, isn't there kind of strange to me at least, that everybody in the tech sector who showed up for that photo that John was talking about, last segment, has a, a stake in this conversation.
So is there a quick pro quo at work here? Alan, First of all, let me mention that was probably a decision he made between the eighth and ninth hole, okay? How hard he was working.
But that, that all being said, surprisingly, this is not one where I strongly, strongly disagree. I, I I'm against tariffs in, in, you know, as, as, as Chris said, I also grew up as a Cold War baby where the US was about free trade, and we're gonna out trade out, manufacture out, innovate, right? To maintain our leadership in the world, not, not put up walls.
Um, however, the EU clearly put up walls, right? The eu, and, and I understand why they did it. They, they, they were trying to get their mojo back, right?
And, and become a world player. And so they, they put in, they imposed these digital service taxes, um, on anything not coming out of there. com days and company, I helped, uh, build inter reliant.
We, we did a deal with Sagittal in France, and we wound up putting a data center in, uh, right outta Paris. And, and we did a lot of, of, uh, European business. And, and there was clearly home cooking at play, right?
And if you were a, you know, a US company, it, it, they made it a little bit harder for you. Um, I'm not against the u I'm, I'm against the US doing tariffs, but I'm not for the EU doing tariffs either. I think we all have to play by the same rules.
And so if this is a case of, Hey, you show me yours, I'll show you mine, and let's all go back to even Steven, right? And just let the chips forward. They may, I'm all for it, but if you are gonna tax us firms because you want to encourage a domestic EU domestic, um, industry of di you know, digital business, I, I don't think there's anything a matter with us reciprocating with that.
And as long as that's what it is, but that it, it sh I I think we have to said, we have to remember that that doesn't mean they're not our allies or that we should go cozy up with the, the dictators in the authoritarians of the world. But I think we, we all benefit when we have an equal playing field. You know, it's almost like there's three levels of this.
One is terrorists, four, you're trying to incense some behavior or dis in some behavior. Then there's the, uh, response to that, right? Uh, okay, if you're gonna do that, I'm gonna do that.
Then there's this third tier of I, I'll use it as a, as a, a bludgeoning tool, uh, as a political tool to get people's either to get people's attention or maybe really to, to, uh, punish people that we don't like because of some political, whether it's, you know, border crossings or drugs or whatever we wanna name it. I, I question whether at all that's really true, why Trump is doing, I think it's largely a negotiating ploy to get people's attention and to basically bully them into what he wants. So we seem to be doing a lot more of that.
And I suspect that eus response is probably more of this kind of first and middle tier, but you don't know that either. It, it just interesting how we're suddenly thrust into this. Tariffs are only about politics and of course the arts.
So the thing with the tariffs though, is it seems like when we reciprocate, it's not one for one, right? We'll turn around and we will say, you know, we're gonna slap tariffs on, you know, wine because they're taxing digital services. So how do we keep this thing from escalating to the point where, you know, it just becomes this arms race of tariffs back and forth till the point where we just all destroy our respective economies.
Yeah. I've never much understood the point. Of course, I'm not in economics, uh, and I'm sure there's people who, who know better, but I've never understood the point.
'cause it just seems like one country imposes a tariff and the other country imposes it right back. So you either all have a bunch of tariffs or you all don't have tariffs. I mean, really, it doesn't, I don't get how it works, I guess, but I, again, I'm not in economics, so, Well, I think you're spot on 'cause it doesn't work.
So that's it. Well, you know what, the idea here is fully expecting that we're gonna get into this tariff tip for tat and the thought is, well, our market's bigger than yours, and so you wanna be here more than we want to be there. And, and that used to work, I think when Eisenhower spoke about the industrial military complex, complex.
But you know, when you look at the combined European market, it ain't a heck of a lot smaller than the US market. When you look at, you know, from both a population and, and you know, dollars, euros, European, uh, Chinese market, not a heck of a lot smaller than ours in a much bigger population. India rising, huge population, right?
So, you know, thi this is, this is who's gonna stay in the latest, right? A little bit of a game of chicken is what you're playing. Mm-hmm.
So, So taking your thought about free markets, and let's just keep them open though. What happens though when, um, suddenly China uses its manufacturing mus to flood the US car market and we're all driving Chinese cars? Is that okay?
Because they cost a third of us cars, or No? So here, go ahead Chris. Go ahead.
No, no, you go. So, So in, in, I think about, I'm trying to think of this in a security model, right? You know, as you would think that security people would be happier with more security, um, that's not true, right?
You know, 'cause you can have as much security as you want. We can lock your front door, we can lock every door in your house. We can make the keys to the locks in your doors in your house, so hard to get to that you stop using rooms, right?
You know, and this tariffs, and as we all know, we're in this information space where it's hard to you, you really have to love tariffs or hate them. You have to love firewalls or hate firewalls. You have to have no, no doors whatsoever, or all the doors need to be cemented shut.
And, you know, to your, to your point, Mike, yeah, sometimes tariffs economic, you know, uh, vehicles, you know, need to be used to or levers, need to be used in negotiations. And that's how you deal with that sort of thing. You slam a tariff on it.
But when you start putting, just saying, we're gonna have firewalls at every internet connection and every light bulb, and you're gonna get access by the system administrator who you can get between the hours of nine to five on Wednesdays, you don't have a network anymore or an economy. That's true, but it's every other Wednesday, not just Wednesdays. Um, but a a again, i I just, you know, if we're gonna go free, so with the Chinese cars in particular, you know, Thomas Friedman in his series of flat Earth books said, everyone wants to live like an American.
They don't necessarily wanna live in America. They don't necessarily agree with everything the US is about, but one thing they all want to do is live that American lifestyle, consume, you know, live a good life. It happened to Japan, right?
And it's happened to China. When we talk about Chinese cars, for instance, flooding the US market, the thought is, it's not that they outcompete us and make a better car. The thought is, is that those cars are subsidized by the Chinese government so that they, the, the costs are artificially low and not true when you take out the government subsidies, or even worse, they're made with slave labor from the Muslim, uh, territories in China where, you know, and it, and it's forced labor, right?
Part of that free market thing is, hey, if, if it's truly a free market, if it's truly a worldwide free market, all things equal, and you out innovate us out. Produ produce us are smarter than us, more power to you. But if you're, if you're using government subsidies free or forced slave labor, child labor, in other words, you're not playing by the same rules, then there's nothing a matter with putting up barriers to that.
So if the Chinese can build a better car than we can in Ohio or Detroit or, or anywhere else in this country, more power to 'em. I don't think that's the case with Chinese cars. I think they are heavily subsidized.
I think the, the r and d work comes out of Chinese research labs. I think, you know, the, the labor is, you know, you, for instance, we'll forget cars for a second. Let's look at Foxconn and the iPhones, right?
Those, they used to make it very cheap, but when they had to start kind of playing by the same rules, all of a sudden it wasn't so cheap to make 'em there no more. So that's where I am on, on, on the free market. Some would say the, uh, r and d for those Chinese cars came from Detroit and Germany.
That that's a whole, right. And that's another term that could very well be too. That could very well be too.
And if you prove that that's the case, that's yet another reason to put up barriers. Yeah, but here's where it kinda gets very complicated in my mind, because, so if you go to Africa or even South America, you start to see more and more of these Chinese cars. So they're not just leveraging up to own their own market.
They're leveraging up to own other markets around the world. They, we can slot tariffs on, but then that gives the, About those markets. We only care about our market.
Well, we have to care about, That's shortsighted. But, but you just put the nail on the head, Mike, is we live in a global economy. We're all interconnected, and we have gotta figure out a way to outcompete our competitors.
Putting up walls and trying to just isolate ourselves in here is not the answer to outcompeting our competitors. That's why it's foreign into some of those countries. So they say the US are good people, People, right.
All right, we're gonna, we're gonna give you a discount on AI if you buy 10 Fords, Or maybe we'll help your people feed themselves. Oh no, we can't do that anymore. We shut that down.
All right. We're gonna end it on this cheerful note. I just had one question.
What are tariffs? Yeah, that's a good question. There, there, there, there are taxes that you pay that someone cons you into thinking somebody else is paying.
Yeah. Oh, there's a lot of that. Anyway, Hey.
All right. I'm please, are we gonna be back? Are we gonna be back tomorrow with more, Mike?
I can't wait to see what else you come up with for us. Go, come. I think I tried to put all The political stuff in one episode.
'cause I thought, Hey, enjoy your Wednesday. We've got a lot of great text on TV following this. Probably a little less of this politically themed charged stuff.
Um, we've got some good tech, which is why you come here. Um, we'll be back tomorrow with more. But until then, on behalf of Chris and Amanda, John Mitchell, and Mike, I'm Alan Shimel, and we're outta here.
This is Textron tv. Hi everyone. Welcome back here to Text Drug tv.
I've got a first time guest at a new company to introduce you to here on Text Drug. Today, I wanna say hi to Chris Wingfield. Chris is senior VP for Innovations at a company called 360 Privacy.
Hey, Chris, welcome to Text Drug tv. It's great to have you on here. Yeah, thanks Alan.
Appreciate the time. Looking forward to our discussion. Excellent, man.
So, you know, we're gonna talk 360 privacy and what you guys do, but before we do that, I thought we'd spend a minute or two kind of talking about you. Right? Perfect.
SVP of Innovations. That's not a title I hear every day. How'd you get here?
What did, what did, what'd you have to know? Who'd you have to kill? What, you know, how, how, how does that all work?
Yeah. Well, some of that stuff's gonna be secret out, but you know, I'll give you the gist. Uh, so, Okay, obviously My name's Chris.
My background, um, before 360, I was a digital targeter for the government. Uh, so I was a member of the intelligence community. I was embedded within Special Operations Command.
And what that afforded me really was the best balance between tactical intelligence experience and strategic intelligence. Meaning I was there on the ground doing the intelligence function, but I was also helping meet, you know, strategic national level initiatives. Um, I started on the linguistic side of the house.
I studied various international languages. I then moved over to the signals intelligence side of the house, which is dig digital targeting of anything with a signal. So thank phones, thank radios, things of that nature.
Uh, I spent a lot of time around the world, uh, in that capacity. And then three years ago, uh, got out of the government space, moved back to the Northeast where I'm originally from, and I came to work at 360 Privacy. Um, the innovation piece is interesting, right?
Because I actually started as the director of Cyber Threat Intelligence. The purpose of that was, let me take all of the, the lessons I learned, the experience I had from the intelligence community. I know how to target people.
Let's target ultra high net worth individuals, executives identify points of exploitation so that 360 can provide remediation and mitigation solutions for those points. So really it's to help these executives live a little bit more of a normal life because they're not really afforded that because of their position. Now, because of my background targeting people, I like to stay agile as this is tax surface continues to grow.
So how I would target people continues to change, which means that we have to innovate through that. So having a domain driven design, it's not engineer driven, it's not product driven, it's domain driven. Meaning, as the domain changes, we have to change how we attack that problem set.
Man, the stories you could probably tell if you were allowed to tell 'em, huh? Yeah, absolutely. You know, a lot of the world Where, where in the northeast are you?
Uh, so greater Manhattan area. All right, I was just there this weekend. I would've loved to grab a couple beers and, and get some, some real skinny, but next time, I'm gonna put you on my list next time.
So Chris, let's, let's talk 360. Awesome. Privacy.
Yeah. So 360, uh, had an interesting start. Uh, you're gonna start seeing a common theme.
Um, the CEO and founder was a former member of the special operations community. Um, and you see that throughout the company, really, a lot of the beginning pieces of this company were special operations, community intelligence, community, uh, some corporate security individuals that were in charge of the physical security for some of the most prolific, you know, ultra high net worth people in the world that were clients of three sixty's before they came to work for 360, because they believed in what 360 was doing. They believed in the solution.
But really how it started was the founder, uh, got out of the special operations community, was looking to do a physical security gig with Digital Flare, is kind of how we talk about it. Um, but what he found within the country music theme, because the headquarters of 360 is in Nashville, um, he started to see that a lot of these physical threats were coming from a digital space. So what that turned into was, um, one of the most prolific, uh, country music stars, uh, of the last several decades of, unfortunately, you know, his bank account was taken over.
His children were receiving text messages from his phone number that was spoofed. So our CEO at the time, this was before 360, really jumped to see, hey, like, can I identify a who this person is? But the most important question was sitting down with the individual to say, how did you do this?
Right? So we found out it was a, you know, 20 something year old young female living in a trailer in the mid, in the mid east somewhere, stalky. And that's right, exactly.
Uh, somebody that had internet connection. And she started to show him, Hey, like I was getting this through these people search sites. I was getting this through Google searches, things of that nature.
When he realized was, oh, maybe I can provide a solution to this. So he would go, he would delete this data. Two days later, the data was back.
So he realized, oh, this has to be a continuous scanning for this data. And so really that was the beginning. You know, how we became 360 privacy today and we went from the country music scene, which we still have a lot of people there, but over to, you know, ultra high net worth individuals.
Uh, you know, we have some Fortune 10 companies, uh, up to the Fortune 2000 companies, a lot of celebrities, a lot of professional athletes. And really the whole purpose of it is we look at you as this is your attack service. So 360 is an attack surface reduction company.
So if you take you Alan, right, like through, through a Google search, maybe I can find some PII of Alan. So now this is part of your attack surface, and there's people search sites that have data about you. There's dark web data.
Well, the beauty of what we do is we try to look at each of those as one holistic issue. And if we can start reducing that, we make you a harder target. We make you harder to find, is what I tell clients is you're always one Google search away from someone turning a digital threat into a physical threat.
And so 360 wants to reduce that visibility so that what they see on Google is your LinkedIn, your company, the podcasts that you do, the webinars that you do, but they don't want, you don't need to see your physical address, your phone number, your relatives, and things of that nature. Nature. We live in interesting times though, right?
We do. I mean, I think everyone out here watching has probably gotten at least three letters in the mail this past year that they were the victims of a breach. Their PII was stored at Take Your Pick company.
I mean, I know personally, you know, there's things like LifeLock and I, I used something with Experian where they're always telling me, you know, where I am on these people finder sites and trying to, and it is, it's a whack-a-mole game. The people finders a whack-a-mole man. But more ominous was, you know, I got, I remember, so I have a boat and the place I bought the boat from was a data breach.
And they sent me a scary email that, I mean, they got ev they took social security numbers, addresses, everything, and they were nice enough to offer me a year of credit monitoring of whatever. That was really nice. That was nice of them, right?
And um, so I mean, for so many of us, not even, you know, VIP people we're up the creek or not the Paddle. We are all just one search away from, from Rube. Now some of us have more to lose than others.
But you know, Chris, another lesson I learned in, I've been in security 25 plus years. Another lesson I learned in security is unfortunately people don't get religion until, until you know something bad happens. Right?
Then all of a sudden they're big believers. That's right. They've big believers.
That's right. Um, so, you know, it's kind of chicken and eggy kind of stuff. 360 privacy.
Do most of your customers come to you after they maybe have had an incident? Or are they being proactive now? 'cause people are smarter.
So I'd say it, it was a mix, right? I'd say in early 20 24, 20 23, late 2022, a lot of it was probably post incident Alan, right? Like, but I do believe now that, because you know, if somebody goes to Google right now and you search just first name, last name, city State, and then just type the words home address, you're gonna start seeing white pages and BIM verified and re and all these people search sites come up.
So I believe that the situational awareness level has raised so much to where now people are more proactively reaching out about solutions, um, reputationally, right? Like if you have people in the Fortune 10 to the Fortune 2000, all of a sudden, if you're a good solution, people are gonna say, Hey, like, use 360 privacy for this because it's all about a risk-based approach, right, Alan? 'cause you said, you know, everybody has something else to lose, right?
A thousand dollars from an ultra high net worth executive isn't that much, but a thousand dollars from an everyday person may be a huge impact to their daily life. And what I tell clients is, you know, just because you're not on social media, like the largest data brokers or the credit bureaus, and everybody has credit scores, so we're all affected by this problem. And 360 tries to look at this as a multi-layered approach of, you know, I can't go to a credential data set like Axiom or LexisNexis and tell them I want you to delete my data, but I can go there and say, I want you to opt me out of the sale of that information.
Right? So what that does is hopefully we'll slow down that, you know, trickle downstream to these people search sites. So you want to hit it from the top of the funnel.
You want to hit as many people search sites as you can. But honestly, visibility is the most important part. Allen.
Like if somebody could find you on Google or a Bing search, it doesn't matter if I removed you from 10 million websites, is if you're still coming up on Google, it only takes one. It only takes one. That's right.
So the problem said is very optimal, is very agile. We have to continue to evolve with space to stay relevant and to keep people safe. Sure.
So Chris, one of the, you know, in my time in security, as I said, 25 plus years, one of the big things certainly over the last 10 to 15 years has been, uh, a little bit of a change in focus. A little bit of a change in emphasis from pure prevention to response, right? So I'm not saying don't try to prevent these things, right?
You play the whack-a-mole game, you do what you can to minimize your, your attack surfaces. You said your profile online, but stuff happens. Does 360 privacy help once that stuff has happened?
How did, and if so, how? Yeah, that's, that's a great question. So, you know, I like it is a whack-a-mole game, but unfortunately some of these moles could be remediated and a lot of them can only be mitigated, right?
Because say like national public data breach in August 272 million unique Social security numbers, right? Like, can we remove that data from dark web after it? It's like absolutely not, right?
But are there actual tangible mitigation steps that we can take to better protect a principle, right? And that's where 360 is different. We're not so much a consumer level option.
We're much more, you know, white glove concierge level option. Because after that happened, within 24 hours, we reached out to over 700 clients to say, Hey, this is what happened. This was the data, and this is actually the tangible steps you can take.
We got on calls, we shared our screen because some of our clients, they don't know what a credit freeze is, right? So let's walk you through that. Well, I'm buying real estate right now, or, you know, I can't freeze my credit because of X, Y, or Z.
No problem. Secondary option. Let's set up a fraud alert.
So then we at least start adding layers of protection. So the answer to your question now is yes, because I can never get you to a zero. And if somebody promises that you're gonna be a zero in the digital landscape in 2025, like it's completely erroneous because it's evolving so quickly.
These data brokers repopulate data every single day, right? And then the next data breach happens, all of a sudden your social security number is out there. So it's all about remediating what we can, mitigating everything else, and just making you as hard a target as possible.
'cause Alan, if you have an LLC with your home address and your name on it, 360, can't change that for you. But we know lawyers and we know how to help you and we can guide you through a process to put that into a blind trust. You know, there's a lot of different ways that we can mitigate issues from that.
It's all about, uh, cutting the connections between different data points. Because as long as we can start start making those harder targets, the lower level threat actors are not gonna be able to connect those pieces. Absolutely, man, I, I would love to see us move, just move away from social security numbers as a personal identifier to tell you the truth.
'cause I, I do think at this point in the game, that's pretty useless with, with all of the breaches that we've had there. I don't know if you want to talk about this, Chris, but like, what is a, a white glove concierge kind of service, like this cost, uh, uh, an individual or an organization? Yeah, Yeah, that's fine.
I mean, obviously depending on the size of the contract and the quantity, obviously there's gonna be discounts of volume. But typically our base package is $5,250 a year. Uh, that's an annual subscription.
Um, and a lot of that is just to say, you know, the work that goes into it because you're speaking to people that have done this, right? And like, that's why I'm very big on the domain driven approach to, you know, product and engineering, because this isn't people or engineers that saw a problem, don't understand the core of the issue and just try to create automation around it. Because to automate something, we need to understand how to make it in the first place and then replicate that through a manual to automated framework.
And so you're dealing with people that have targeted before they understand how people are being targeted, and then the network space to make sure that goes there. And so really it's the daily cadence. You look at consumer level options, they're typically going every month, every quarter.
Issues with that is, you know, last month we had a data broker dump every profile 360 had ever removed from our entire database, right? For all of our clients. We picked it up immediately and we deleted those immediately, right?
Like that was our whole game plan. But if you're on a, a monthly even, you know, that may be out there for 29 days. And that one website had all the city and states you've ever lived in all your relative names and your first, middle, last full name, right?
So, and this is on a free data broker. This wasn't behind a paywall, et cetera. So it's all about understanding the game.
These data brokers, people, search sites specifically, they're gonna pop up every day, arguably, right? And they may be downstream of another one, but that doesn't mean that if you removed from upstream that it removed from downstream. There's just a lot to that concierge level.
Oh, there's certainly, and, and I, and look, the fact of the matter is doing that is probably beyond the scope of what most people are comfortable being able to do, right? That's right. And it is what it is.
Chris, I don't think we mentioned the website for 360 Privacy. Yep. io Io.
Fantastic IO man. All right. Hey Chris, thanks for coming on here and telling us about this.
I, I, you know, this is a problem. Yeah. It's, you know, my father-in-law rest his soul.
He always used to say, rich report, it's nice to have money. And, you know, if you're a high worth individual or someone with the, the means you, you become a bigger target. There's a bigger target on your back is the fact.
And if you, you know, you, you can engage a company like 360 privacy, but quite frankly, at five KA year or thereabouts, you know, there's a lot of people who might want to consider that going beyond, you know, the consumer level LifeLocks and, and stuff like that. Um, keep up the great work, man. We'd love to have you on and, you know, and hear its kinda real life stories of what's going on out there.
'cause this is a, it's, it's a crazy world we live in, man. Just crazy. It is.
Yeah. Thanks for having me on, Alan, I appreciate it. My pleasure.
Chris Wingfield, senior VP Innovations at 360 Privacy here, ONT Techstrong tv. We're gonna take a break. We'll be back with more.
Hello and welcome to the latest edition of the Techstrong AI video series. I'm your host, Mike Bezu. Today we're with Derek Holt, who is CEO for Digital Do ai.
And we're gonna have a chat about, well, where does AG agentic AI fit in this whole spectrum of things that we've been playing around with. Derek, welcome to the show. Great to, uh, be here, Mike.
Thanks for having me. I think we rapidly went from, wow, we all gotta learn prompt engineering to now looking at all these so-called agents that are going to do certain things for us automatically. And when I talk to folks, everybody kind of nods their head, but then it quickly, they, I get a blank stare.
And I think the blank stare comes back to, well, I'm not sure I understand our processes well enough to insert an AI agent. So how do we kind of approach this when a lot of the things that we have been doing for so long in various processes are kind of road and we actually forgot how they work. It's a, it's a really, really good question.
And, uh, I, it, it's one of the things we think a lot about. I think those that have, um, uh, ironically automated sort of the old way, right? The hardcoded automation of processes are often the ones that are most, uh, well positioned to take advantage of some of the AI capabilities.
'cause to your point, they've sort of documented these things through codification. But, um, look, we, we, we are super excited about, um, I think the productivity gains that are potential here, but I also see things at, at least at this current stage where you're gonna have a lot of humans involved, uh, in supervising, uh, some of the agentic behaviors. So, uh, while, while autonomy is obviously core to the, to the, the label of what makes, you know, regular generative AI different from let's say agentic ai, um, I really do think, um, kind of breaking these things down to more smaller chunks where things can be handled and, and, and sort of the process is well understood and, and things can be handled in a more agentic way, will build up from there.
But I think some of the, the, um, the hype around some of the broader scale, you know, does everything just give it a, a bit of a direction and it goes off and solves it? I think we're gonna, uh, uh, ideally probably evolve to that versus that being the reality, uh, in the, in the foreseeable future. To your point, then, how will I orchestrate all these agents?
Many of which that a thing we're calling an agent is actually probably 20 different agents trained for different tasks. And if I want to manage something on an end-to-end basis, I have to orchestrate that. So where will that come from?
I, I think it's, it's a, it's the question and, and make it even more complicated. How do I govern it? How do I make sure that it's high quality?
How do, I mean all the things that we've thought about in what I would consider more like traditional software that is much more declarative, you now have to deal with in a much more complicated world. And I think that the key for me is, is again, always taking these bigger items and breaking them down into piece parts. In the end, I look at whether it's, you know, traditional AI or, or generative ai or generative ai, all of these things are ultimately productivity tools, right?
And, and they help us ideally, uh, increase productivity, allow us to, to work on more creative work and less repetitive work. Um, I think the really interesting thing about this wave of AI is it lowers the bar of entry even more because you don't need to know how to write code. Typically.
You can sort of just use natural language to interact at the same time to really have legs in the enterprise. It is gonna have to be explainable, it is gonna have to have high quality measures, et cetera, before I think anybody's gonna just let it go on its own. And so, really, we think about this as breaking these larger processes down into these sub subprocesses, and then identifying where AI can play a role in a safe, secure, you know, high, high quality way, um, in those lower levels.
I, I, I think about, um, uh, the evolutions of, uh, autonomous vehicles, well, albeit a bit of a different technology, uh, evolution, but like we we're gonna have fits and starts on this, right? I think it was back in 20 12, 20 13, I think we all thought we'd be not driving anymore come 2025, right? But we ran into some technology barriers, and a lot of that was around the edge cases.
A lot of that was around the fact that autonomous vehicles need to be right a hundred percent of the time, in theory, for people to, to be comfortable with them. I think you're gonna see some of the same adoption, uh, transformations as AI goes from, frankly, right now, a much better search engine. And, you know, something that helps me avoid writer's block and, and maybe helps me write code a little bit faster to like literally giving the keys, you know, keys to the, to the processes and allowing it to go end to end.
To your point, I also found myself having this conversation recently, where am I building AI agents or am I buying AI agents? And I'm probably gonna have a mix of these things, but some of these AI agents seem to be coming from Salesforce SAP Microsoft, and then in other instances, I'm gonna need to build my own AI agent that maybe knows my processes better. And how will these AI agents kind of interact, do you think?
Yeah, I, I mean, this is the thousand dollar question. I mean, ultimately, you know, we've thought about the internet as maybe one of the ultimate integration mechanisms, right? Kind of loosely coupled, uh, you know, protocols going back decades, uh, that frankly probably didn't know at the time how they were gonna be used, but it worked out pretty well.
Um, I think it gets even more challenging with, with ai, right? You have a, a, a set of discussions and concerns around data sovereignty. You got a a, a set of discussions around, you know, how much is this all gonna cost and who am I even paying as agents are calling other agents?
And so, again, it just to me is like a, a, a restatement of the fact that we're early days, we are now seeing the potential of what's possible, but how we get there is, uh, always gonna be, I think, more incremental than, than maybe we suspect. Now, obviously this is moving very, very quickly, but you know, the old adage, I forget it was a Stanford computer science professor, I highlighted that we tend to overestimate impact of technology in the near term and underestimate it in the long term. I think we're probably right in the midst of that right now.
The other thing I'm also trying to sort in my head is, today we have MLOps where data science teams are using that process to kind of construct a model, and then when we build software, we have DevOps workflows. Um, is an AI agent a type of artifact that will be built like by a DevOps team, or is it gonna be an extension of an MLOps workflow? And how do these things come together to drive something into production?
It's a, it's a great question. ai as we all navigate this future. The, it's, it's really interesting when somebody asked the question, what's the, what role does AI have in, in, so the way software is developed and delivered, which is a question, you know, as the CEO of digital ai, I get a fair bit.
The answer is like multi-layered, right on. On one hand, we are like everybody building out, uh, workflows in, into our existing tools, um, to, um, to, to leverage AI to make it easier to, you know, autonomously generate tests or, uh, or, uh, have intelligent pipelines. That set of old hardcoded pipelines where the level of governance and, and risk management is ebbing and flowing based on, uh, uh, on some AI and machine learning views.
Um, so there's the tooling piece. There's then the next piece that you just highlighted, which is all of our customers who have traditionally been using our tools for, for building, you know, more, more declarative AppSec, for lack of better term, right? Like more traditional, uh, mobile AppSec and web services and whatnot, are now saying, how do we also add in AI into those, into those app experiences, right?
And often, um, they are not building the AI themselves, but they are using models and using their own data and training it. And so now you've got not just model ops, but data ops and DevOps all have to converge together, right? To successfully deliver, um, a, a product.
And, and then you have a whole bunch of new, new questions around what does it mean to test such an application? What does it mean to secure such an application? How do we get feedback when somebody calls the support desk and says, Hey, I I was using your app and x, y, Z happened.
How do we replicate that in, in, in the development environment to be able to fix a potential bug or to at least, uh, determine whether a bug exists? I think we're still early days in a lot of those questions when you layer in, um, uh, this dependency on, uh, on ai, not in terms of how you use AI to build the product, but embedding AI into the solution, uh, itself. So this is why we exist, right?
Is to help our large scale enterprise customers figure that out. And we've been deferring referring to it internally as sort of, uh, X ops. In other words, there's a whole bunch of these types of ops, whether it's traditional development or, or data or model, uh, or, you know, probably a long list of other things, um, that need, um, some of these be best practices that we've, we've leveraged for some time now in the more traditional development world.
As we kind of think about how all these AI agents might play out together, I almost feel like we're working towards where we're adding AI to the DevOps and software engineering workflows, and then we're gonna use AI agents to build that out. And then we're also gonna apply that to security. So in effect, are we not gonna wind up using AI agents to build AI agents?
And they become even more kinda complicated with lots of little inter interdependencies. Yeah, it, it, it, it is, uh, uh, I mean, I think this is what a lot of folks are pontificating on. And, and, and, um, you know, I, I'm, I always, I've learned a long time ago not to predict things that are 10 or 20 years out, right?
So, uh, I'm, I'm more wrong than, uh, than right. But, but I, again, I go back to what's practical in today's world, in today's environment. And, and I think the key for us is to really focusing, um, not just on what the technology could potentially do, but like, what is the business problem that we're solving?
What is the business outcome, uh, that we're driving? And then is a, is an AI based solution, or is it more of a traditional solution, uh, that that is the right way to solve that problem? So like your, your scenario is potentially a very real scenario.
Um, how quickly we get to that, um, and, and does that in itself create, um, a whole bunch of value? I, I think, again, I think we'll get there, um, uh, more incrementally, the, the old, uh, you know, the destination is, may, may or may not matter. It's just the journey that's gonna get us there.
And, um, I think I see people more kind of early, early stages just figuring out, like even things as simple as, for example, and you, and I've had this conversation, if I can't measure how productive my development organization is today, how am I gonna compare that to a, an AI powered development organization, right? So some of these fundamental, uh, elements, when you think about what it takes, um, have I automated enough throughout this software development lifecycle to take advantage of some of the productivity gains that we expect to see in certain areas, right? I make, I, I write more code, but can I test it?
Can I secure it? Can I get it into production? Or am I simply creating a bottleneck elsewhere?
Can I measure the, the, the before and the after? Can I, can I get a little bit more thoughtful about the way that, that we bring products to market and using some of the data that, uh, that is there to help us go faster when it's less risky and go a little slower when it's more risky? So I think for, for all of these, I think it's gonna drive, interestingly enough, the promise of this potential future is actually driving very near term investments and very near term transformations around some of the best practices that we've been talking about for five or 10 years as a, as a, you know, a DevOps community, right?
Using DevOps as a metaphor for all of this. We have this notion of observability in DevOps. And when I look at these AI agents, something that crosses my mind a little bit is, we all talk about hallucinations, but, um, the models themselves and the AI agents drift over time, and how do we know that they're still doing what we intended them to do if we don't have some way of observing them?
I, I, I, I totally agree with you, and I think what we'll come back to is number one, um, uh, the, the term observability in the industry has been very narrow, I would say historically. Uh, mostly in production, mostly in sort of one area. I think you're gonna see the emerges of big O observability where we look not just in production, we look into development.
And then to your point, we have to look at some of the more declarative, um, uh, uh, tools. Things that, you know, when you click this button, we know exactly what happens and delineate that from some of the, the more, uh, generative of tools that, that, to your point, evolve over time. I, I also think this is part of the reason why, uh, again, um, how broad ag agentic gets, how big of a workload we hand over to the models and say, have at it.
I think we're gonna start much smaller because to your point, it's, it's much easier to, to identify some of that, uh, the, some of the hallucinations, some of the drift, et cetera, in smaller work items than it is to see it in the bigger. And, and, um, I, I actually think hallucinations are not being discussed enough. I i, if you, if you want me to be frank, 'cause I think it is actually, um, probably for the, for the big model creators, it's not a convenient topic to discuss because it, uh, uh, is a bit of a challenge.
But again, go back to that autonomous vehicle example. Um, we've, if I'm gonna hand over the keys to the way, you know, uh, support interacts with, with our, my customers, or I'm gonna hand it over to other, like, really mission critical things within my business, it's gotta be right a hundred percent of the time. And today it's not.
And to your point, gen AI and the agents themselves are probabilistic, and then they take a reasonably informed guess, but we seem to be wanting to insert them into processes that are deterministic, and they're supposed to be done the same way each time a hundred percent of the time. And no model does the same thing, the same way, the same every time. We, we, we experience this ourselves, right?
Just interacting, uh, ask one question once, and you ask it again and you get a different answer. I, it's funny, and I forget who I should give credit to this, this is not an original thought, but somebody had, had asked a question is, is uh, language knowledge, right? Because like in the end, what the, what the, the generative AI models that are really good at is the language piece predicting the next letter, the next word, et cetera.
Um, but, but even the computer scientists that have created these models have a hard time explaining exactly how it all, uh, how it all actually works. And so, um, does it really equate to knowledge and, and your points to the right one is you get to these more complicated scenarios, um, that is where knowledge is required. And, and go all the way back to your first question.
Um, if I can't explain a process or how it's supposed to work, or I've not documented or I've not codified it, how can we expect the, the, um, the agents to follow it? So again, what I like about it, it's very, very similar. If you go back, you know, the per the early days of personal computer, the early days of the internet, we, we both presented a much more robust, uh, much faster transformation than ended up happening.
We also had the tech optimist and the tech pessimist at the time, right? Some saying that all the jobs were gonna go away and others saying, yeah, but don't, don't you think we'll create a whole bunch of new opportunities for new products, new jobs, new processes? Um, I tend to be in the optimist, uh, uh, camp, um, as just seeing the last few waves.
Um, but, but again, we've sort of always, I think, uh, uh, overestimated what, what's gonna happen today, tomorrow, six months from now. And, and again, probably underestimated what happens 10, 20, 30 years from now. In general.
I kind of feel like we're all a little conflicted. On the one hand, there's been a lot of talk about eliminating a lot of the regulatory oversight around AI as of late, and then at the same breath people are saying, well, I don't know what I wanna automate using this stuff 'cause I'm afraid I don't know what's gonna be regulated tomorrow and if I'm gonna roll it back. So are we kind of stuck in some sort of quandary?
Yeah, I think a little bit, although again, I always go back to the, the history on these things and whether it's like way back to the automotive revolution to some of the other ones that had transpired, including the internet. Um, we've, we've always had sort of these fits and starts. I think, I think a couple of things have held true.
And, and, and you know, this may be ultimately different, you won't know until sort of hindsight, but typically, uh, these technological revolutions have been really around improving productivity, right? They've ultimately about, uh, um, improving productivity and do they destroy some jobs? Yes.
But historically they've created more jobs than they've destroyed, right? Particularly in the US economy, if you look at sort of the forward-leaning kind of creative destruction economy, that that has been the, the United States, at least over the last a hundred and twenty five, a hundred and fifty years. Um, I, so I, I ultimately think, you know, regulation, I'm not a, a government official.
And, and there is this weird, there's this balance that needs to be striked around encouraging innovation and not pulling it back as well as, um, uh, making sure that their safety. I also am often reading lines, uh, or, or feedback from different companies. And you gotta think about from each company, like what their incentive is, right?
In some cases, if you've got a lead, you might have an incentive to have things regulated because it may slow down some of the startup or open source activities. So, um, I'm not an expert at all of that, but I do know that it's here to stay. I think it's gonna fundamentally change the way that software is developed and, um, and delivered.
And, and I think if we do it right, we can provide incremental, if not exponential improvements in the near term while also, you know, um, uh, kind of navigating towards what may or may not be, um, you know, agents taking over larger and larger portions of, um, of the software development lifecycle. What is that one thing you hear people talking about and maybe overly hyper-focusing on that just makes you shake your head and go, folks, we're missing the point. Uh, that's a good question.
Um, look, I think some of the things you just highlighted there, right? I mean, I saw a demo this weekend of two agents going back and forth and building an application, which was super compelling, right? It was a, a really interesting, um, uh, use case and maybe a, a glimpse of what's, what's possible in the future.
But then I started to think about what would that mean to a large scale bank, right? What would that mean to, uh, to a, a a, you know, a a healthcare company? And when you start to apply the realities of, of the regulatory environment, and when you try apply the realities of, hey, if this app is wrong, once, it may have much broader implications that is wildly different than, than, Hey, I, I, you know, I I created a, a, you know, a fake, you know, uh, app that, that is just using for demonstration purposes.
So the, the thing that I, I think that, that, um, I shake my head a little bit is this, this notion that it's gonna just sort of magically be able to be, um, fully accessible and impactful, um, at the agentic layer in, in, in the enterprise. I, again, I think we'll get there over time, and I think anytime you give a prediction without sort of an end date, like you're gonna be right. More often than not, you just don't know, uh, when it comes true.
ai is, is, is not allowed to be access on your more computer to embracing it, to using it as a, certainly as a productivity tool, helping to write more code, sort of code assist on steroids, if you will. And, um, and also as like a bit of a, a knowledge partner, right? To be able to, um, to ask a question, Hey, if I was gonna create this type of, of algorithm, what would a best practice be?
Uh, sort of the evolution of, of, um, uh, some of the, the online tools that we've all as developers been using for years, how we then get that into scale enterprise production, how it then, um, changes the way that we test and secure and other applications. I'm sure that, and we're working on stuff that, in that space, um, things like autonomous testing just point me to the app and the code base and we'll, we'll figure out, um, all of the, the test coverage that's, that's required, add in the telemetry usage data, and we can do even more, uh, interesting work. Those things are gonna happen.
But again, I keep thinking more and more that, um, the large scale changes end up happening more, uh, evolutionarily than revolutionary. And when we zoom out 10, 15 years from now, we'll say, boy, that was a big revolution. But when you're in the, in, in it every day, it feels like these incremental improvement.
There you go folks. I think we've seen this movie before, and one way I kind of described it as, uh, technology innovation is here. It's just being applied unevenly and AI is no exception.
Derek, thanks for being on the show. Awesome, Thanks Mike. And thank you all for watching the latest episode of the Text Drawing AI video series.
You can find this episode and others on our website. We'd invite you to check them all out. Until then, we'll see you next time.
Hi, I am Nick, patience, vice president and AI practice Lead at rum, and these are some of my predictions for ai. In 2025, agen AI will take center stage. This is the evolution of the, the generative AI revolution that started in late 2022, and now we're getting to the stage where AI enabled agents are gonna be able to take decisions, they're gonna be able to interact with other agents, they're gonna be able to interact with other kinds of software applications and interact with humans.
And this is the, the, the, the evolution of this where we actually get to the stage where AI can execute business processes, and that opens up all sorts of new opportunities. This year we're gonna see, uh, a successful IPO of one of the AI focused companies. The IPO market has been, um, fairly fallow in the last, um, few years.
There's been a lot of venture capital invested, obviously, and that also need, needs to go somewhere. And we we're expecting the IPO market to open up a little bit in 2025. We're also expecting one of the smaller large language model companies to get acquired.
Open. AI has obviously stormed ahead here and, and is the dominant player. Um, but there's quite a few others that are fairly small in comparison to OpenAI, but might make attractive acquisition targets probably for application software vendors, but maybe also for infrastructure, uh, vendors as well.
Agents and reasoning models, these reasoning models where they kind of act sorta like a human with chain of thought reasoning and show they're working and show how they're actually coming to a decision. We think both those kind of trends, A, they're related, and B, they're gonna drive an increase in need for inference infrastructure, so you have more power at the inference stage because of this, this chain of thought, uh, process going on. This is not as just a simple putting in a a simple question into a an LLM in text and getting the answer back or, or anything like that.
This is gonna require more investment, we think. So those are some of my predictions for 2025. Thanks for taking the time to listen, and if you wanna know more about these predictions and all of our predictions, you can check out the FUTURUM research ebook, which is available now.
Hi, I'm Olivier Blanchard. I am the research director and practice lead for AI devices automotive and AI device semiconductors at the Futurum Research Group. And so what we're thinking here in, in our holistic practice, looking at all of our dif different technology categories is that AI devices is actually taking off this year.
Uh, and it's, it's probably going to be one of the bigger trends in, uh, in the overall tech sector. Up until now, we've had AI living in the cloud, in, in terms of training inferencing services. Most of it has been handled in the cloud through data centers and cloud services.
But what we're doing this year, or what we're seeing this year rather, is a, a migration not away from the cloud, but into devices towards the edge. So essentially it's an expansion of, uh, of the AI ecosystem from the cloud outward to the edge to devices, and these devices are IPCs. That's obviously one of the big, uh, developments for this year.
I'll come back to it in a second. Another one is, uh, AI enabled mogul devices, which actually is new, but we're going to start seeing a lot more on device ag agentic AI entering the market this year, and also all of the other devices that are sort of peripherals to, uh, PCs and mobile. So that's the wearables like your watches and xr.
So smart glasses, it's also drones, it's also smart cameras, smart speakers, all of the, the, the little ecosystem of, of intelligent devices that you can interface with, either by voice or, or other types of, uh, of interfaces. And we're also seeing an expansion of that into the automotive space where cars aren't just about self-driving and a DAS, they're also about agentic experiences inside the vehicle for the drivers and passengers. So all of these things together are essentially driven by advancements in two areas.
One is, uh, semiconductors. So the small semiconductors, the semiconductors that go into your devices, your PCs, your mobile phones, your watches, your smart glasses, your speakers, your, all of your wearables. And the vehicles are getting much better.
Uh, a lot of them are equipped with, uh, something called an NPU, which is a neural processing engine or unit that allows AI workloads to happen on device. And increasingly what we're seeing is not just inference, which is sort of the AI interacting with you on devices, it's also the training itself. And, and we're, we're now able with IPC's mobile devices and, and, and vehicles to train AI directly on the device without necessarily needing a, um, a cloud connection or connection to the cloud or, or to a data center.
So that's, that's a huge thing because it allows training of AI to be remain local, to be secure and to be a little bit more immediate. And that's also with the inferencing, which is kind of the interactions that we have with ai. AI models are becoming a lot more efficient to trade.
And so what used to have to be trained in the cloud a year ago that required, you know, 70, a hundred billion parameters can now is, is much smaller now and can run directly on devices or can be trained directly on a device. So we're gonna see an expansion of training AI models from the cloud into smaller solutions like small servers, more local, and also some of that training being, uh, being moved to AI devices. All of that and more, uh, can be found in our ebook about our predictions for 2025.
Uh, we're talking about not just AI devices, but a lot of other technology categories as well that all play into this big AI revolution that we have. Also, I recommend that you follow us on the socials, so we're on LinkedIn, obviously, uh, we're on X anywhere. You can find us, uh, anywhere you can find me where I talk about AI devices, and also follow us on our websites where you'll find a lot of other resources.
com. Thanks a lot, happy reading, and I hope to see you at. Hello, I'm Fernando Montenegro, and I recently joined futu Research as vice president and practice lead for cybersecurity research.
You may have seen the video from my colleague Krista case, so this is a bit of a compliment to that. I also encourage you to check out our ebook. We want to highlight several crucial areas for the security landscape in 2025.
First up is the discussion around security platforms. We emphasize that there's a very nuanced discussion to be had about what is actually a platform and how do you consume one. We typically think of a conversation as a dichotomy between platform versus best of breed, but we think that have actually evolved into a much more complex decision matrix besides choosing on functionality, pricing, et cetera.
We argue that there are now at least three dimensions that people should consider. First one is, do we buy it as a platform or as a point product? Do you consume it and, uh, as a product and then you have to integrate it yourself?
Or is it integrated into a platform? Which one evolves quickly? Which one, how gives you more, uh, faster time to value?
The second conversation is, are you buying something that is best of breed versus quote unquote good enough? Of course, we all want best of breed, but that comes at a cost. So how can organizations choose with where they want to pay for a premium versus where good enough is?
Well, good enough. Lastly, you have the, the, the topic of how do you consume it, how you do, how do you deliver it? Is it something that you are choosing to buy from a vendor directly or is it something that you are working with a service provider or a channel partner on?
Each of these dimensions have pros and cons, and you have to evaluate based on specific organ organizational requirements. We argue that a fiber security becomes much more strategic. These types of decisions become much more tied to an economic angle to them, and we have to frankly just navigate what the economic trade-offs are between these choices.
Another key area for us for 2025 is the evolution in the convergence of application security with cloud security. Now, cloud security best practice in general is encouraging us to use more automation and infrastructure as code, as principles, and that by itself fits really well with how application security already works. Also, the developers that are typically outputting, uh, front end code H-T-M-L-C-F-F, JavaScript or backend code go by know what have you, they are also very comfortable creating Kubernetes configurations in yml or helm charts or cloud formation templates with cloud formation or Terraform, et cetera.
So it's not that big of a jump to include those configurations into the software supply, uh, pipeline. This alignment is really interesting because it creates this proximity between consuming application security and cloud security functionality. That being said, this convergence is also interesting because we have to rethink how teams are structured, how responsibilities flow from one to another.
So that's another area that we're looking at. Third area I want to highlight is this evolution of third party risk management. We think that modern third party risk management is much more about addressing both the business level risks as well as the technical risks across your value chain.
So this includes evaluating, for example, security libraries or cloud posture or SaaS components that you're using, as well as vendor reliability, financial liability, et cetera. The challenge of here is how do you as an organization maintain this complex, uh, information set on first party, second party, third party, fourth party relationships. So it's really interesting.
One more point I want to, uh, mention before you wrap up, and that is that there are quite a few security areas that actually are very good at spanning multiple domains, if you will. We all talk about AI security, for example, as one of these, but that said, we think there are other areas. Ransomware response and, and uh, and protection, for example, is one of those.
It's not just an endpoint security issue, just like it's not a only a data security issue, it actually flows into a bigger conversation around risk management and cyber resiliency. Also, secure access service, edge implementations, SAE, right? They themselves are interesting because they span from network security to cloud security, data security and so on.
All of these are really interesting areas that require us to look at them with different perspectives and, uh, from different lenses. As we look into these in 2025, we here at, uh, at Tuum are paying very close attention to the needs of all the stakeholders in this, in this area. As I get to wrap up, I want to thank you very much for your attention, and I want to encourage you to do three things.
First of all, if you can please review Krista Casey's video for some other cyber predictions, please review our ebook for a complete set of predictions from cybersecurity and other areas. com. I often like to say, I mean, there is never a dull day in the cybersecurity industry.
So thank you very much for your time, and I wish you all a great day. Hi, my name is Richard Gordon. I'm vice president and practice lead for Semiconductors here at Future Own Group.
Today I'd like to talk a little bit about what's going on in the semiconductor industry, and we'll maybe have two or three predictions as well. So, first of all, let's start with the state of the industry right now at the end of 2024, and as we enter 2025, last year, the industry grew at around about 20%, and that growth was driven by a boom in data center semiconductors, particularly AI chips. And, uh, also from a boom in, in memory from the likes of Samsung, esky, Hynek, and Micron.
The industry growth rate's gonna slow down a little bit, and we'll probably see growth of around 10% this year. Overall, that's gonna be driven, um, I think by a pause in investment in the data center space and also a, a a, a recovery in the rest of the market has supplied and demand comes more into balance. So the industry going from strong growth last year to slightly more moderate growth in 2025.
As we head towards 2030, I think we'll see another upcycle in the industry pushing the market towards a trillion dollars or so in the early 2030 timeframe. Second prediction I wanna talk a little bit about is to do with the technology roadmap. Over the, the past few decades in the industry, technology has been driven by Moore's law.
Investment in semiconductor scaling is what drove chip performance and cost reduction. However, it's increasingly challenging for companies to invest and keeping to the Moore's law curve. Really only the leading foundries and leading memory players can afford to do that these days.
So we're gonna see increasing investment in advanced packaging to drive the technology roadmap. In fact, one of the equipment manufacturers reckons that by 2030, around a quarter of foundry revenue will come from triplet space. Benefit of triplets is that semiconductor devices can be partitioned up into functional blocks and then recombined and advanced packaging so that there's different types of semiconductors with different properties available in a single package.
The last thing I wanna talk a little bit about is geopolitics. Of course, the industry has, is very much a globalized industry and has a globalized supply chain, but increasingly we're seeing semiconductors seen as a driver of economic growth and also very important from a national security perspective. So what we're going to see going forward is more onshoring of semiconductor design and manufacturing.
We're gonna see increased technology transfer restrictions around the world, and also increased tariffs and trade as well. Uh, uh, that won't apply just the semiconductors, of course, it will apply to, to business more generally, but it will affect, affect the semi space. So that's a little bit of a, a look into what's going on in the industry right now.
If you wanna find out more, you can download, uh, our ebook, um, where we have some more detail on these predictions. That's Futurum 2025 key Issues and predictions. Hello, my name is Chris Blask, and once again, I am your host for another episode of the Inevitability Curve.
In each episode, we take a particular topic and look back with an interesting guest on where we've been in this topic, where we are today, and where we're going in the future. Perhaps our guest today is Stuart Phillips, and Stuart and I have worked together for many years in cybersecurity. Hey, Stuart, how are you doing?
I'm doing great, Chris. Great to see you. Good to see you too.
So it's looking very Pacific northwest, uh, behind you. Thank you. I live in, uh, lake Stevens, which is a little north of Seattle, and today we're having a great fall day.
It's raining and cloudy, you know? Yeah. As one does.
So you and I may have worked together in cybersecurity for many years, right. And since, uh, 1998, you know, when I joined Cisco. And in all of those contacts, and for both of us before that, you know, there's contact with military organizations and helping them with security and helping private sector organization with security.
And, you know, the, this issue of conflict of human conflict and how the lessons of, of all of human conflict apply today. You know, whether today is the late nineties or the 2020s is a constant, constant topic. Right.
And you're, you know, quite a military history buff. History b in general kind as I am is, so let's talk back there a little bit. Right?
So in recent, more recent history, without going back to Assyria this time, um, a hundred years ago, 80 years ago in World War ii, uh, most folks, certainly everybody in the cybersecurity world knows about Bletchley Park, right? And the information warfare that both the hacking of, um, of, of access codes. So they read the messages, right?
And the manipulate manipulation of physical artifacts and people and things to give, uh, a wrong impression, right? Exceeding the wrong information. Where would you like to start in the past in mapping into where we are today with, with information warfare and conflicts in general?
Well, I mean, you bring up a really good point about, uh, you know, the enigma efforts and all the things, and a lot of it, you know, where there was a combination of human error and technology, right? And so what happens is you have German operators who are sending every message with the same couple words. And, um, the, I will not repeat on this, you know, call, call.
And the also the fact that they were able to create the bomb, the ability to create a, you know, very early computer that was able to decode it by trying thousands or hundreds of thousands of combinations, even though they did have a really good guess. But the advantage of the human error was that they were, had a place to start. And it interesting because even today you have a combination of human error, which is people clicking on email links, people accepting in invitations for people who are not the person they think they are.
And then you also have technology where now you have like the deep fake technology where someone can sound like your boss or someone can sound, you know, present themselves very realistically. Uh, or what we're seeing at Reversing Labs where people are creating an individual malware package just for a single target, you know? So instead of 10, 20, 30 years ago, they would create malware and then email it to everybody in the world.
Now they're actually using AI to create a single crafted malware package just for Chris Blask. You know? And so you may be the only person to see it.
And a lot of tools are the traditional tools that were like, have you seen this before? Is this in your antivirus type? Things like that.
Those tools don't really work anymore. And so we're seeing a lot of, you know, changes in how these, you know, types of attacks. But the other thing that's been really interesting to me lately, of course, has been the conflict in the Middle East and also the, uh, Ukraine where we're looking at, you know, how drones and thermal sites and people riding an e-bike in the woods and coming up on a tank and being able to take it out with a handheld missile, and the, you know, the tank costs several million dollars, and that whole setup for that person costs $2,000.
And so you see a huge distinction between these types of traditional military, you know, belief that, you know, having tanks, having big planes, having big missiles and all this kind of stuff makes you invincible. And somebody coming along with a, you know, $600 commercial drone and dropping a hand grenade on, on, you know, into the cockpit of your $35 million airplane is devastating. And, but, but again, how much of that is, is some of that sounds similar to me, you know, the, the, uh, world War ii, the tanks and the, uh, forgetting the German word for the little, Uh, the s are false.
Yeah. Mines are false. Yeah.
Right. Yeah. You know, so, and knowing where those are at the, at the right time, you know, having the intelligence and information right, to get your, you know, as metrical advantage out out of I is itself not a new thing.
No, not at all. I mean, all of these types of technologies, these advantages, we've seen them, you know, move forward. And that the challenge now is that how do you as a, uh, defender prepare for these things when quite literally the technology's changing quickly.
You're seeing a lot of things happening that are unprecedented. I mean, you in, uh, you know, Yemen a place that you're familiar with. You have the hoodie shooting ballistic missiles.
Um, you know, again, when I, you know, during the Cold War ballistic, only three or four countries had ballistic missiles. Right? And, you know, and when India got ballistic missiles, it was a really big deal.
Big. Now apparently anybody with a tractor trailer can have a, you know, ballistic missile. So, you know, it's not as, it's not a, uh, you know, and again, it's, it's this idea that you could shoot missiles at another country, and there's really, you know, war doesn't break out like you think is going to, you know, well, and, And following that past thread and getting more into the cyber side of it, you know, so we recorded a Textron gang episode this morning and got on the topics of, of mainframes, right?
And for most of us in the IT world today, you know, we're, you know, DevOps and DevSecOps, I mean, these are words, words and terms and phrases that we understand, and we think mainframe is like, hang on a second. But as, as we're talking about there, uh, there's, there's a lot to be learned from that. Sure.
You know, mainframes were the mainframe platform, the mainframe environment, um, was a very solid and stable and secure thing. And today, mainframes, you and I worked at Unisys where mainframes continue to operate, you know, the entire global financial backbone. Yeah.
And they do that because they're doing things that in the, the broader IT world. Now, we kind of think are impossible, but that's the way they were built all along. Yeah.
And, and again, there's this idea, you know, uh, the centralized system with terminals that really don't have any type of capability on their own. And you see that now though, with virtual systems. You see that with like, um, you know, systems that boot up, you know, you have a laptop, but there really isn't anything there.
You boot up an image that comes from somewhere else, the image runs on your PC while you're doing your work, and then when you shut it off, it's gone. Someone breaks into your house and steals your laptop. They don't have any of your secrets.
So, I mean, that, that mainframe centralized terminals as dumb model is, is very heavily replicated today in a lot of this, you know, systems that do these distributed, uh, you know, deployments. And, you know, having everything in the cloud, which again, is just a computer in another state, um, is not, to me, it's really no different than a mainframe, right? I mean, the way we, we dealt with mainframes, you know, uh, I think that the main difference now is that your ability to spin up these things is, is quite easy.
Right? Before to get a mainframe, you know, I would go, when I worked at network systems, we sold front end controllers and all that stuff, you know, back in the mid early eighties, uh, if you wanted to have your own mainframe, that was great, but it was gonna be a five year effort and you needed a specialized building. Now you just need to go on, um, you know, Microsoft Azure and you have a credit card.
Um, you're good to go. You know, you can have a complete operating data center within a few minutes. Well, yeah.
Which plays right down my, you know, my favorite, you know, inevitability curve sort of thread. You know, the same thing as you said about ballistic missiles. If you have a technology at some point, and it's very exclusive for whatever reasons, if it, it can be made less exclusive, you know, then eventually it will.
Right? So you can think forward into that world and say, okay, by then we need to do what. And, and again, just in our, our, uh, you know, relatively short working, uh, careers, we've seen a lot of this.
While you can't ever do that, 'cause therefore you couldn't do X, Y, Z we're doing already, but we did it anyways. Right? And we find ourselves looping back to the those same, uh, uh, primaries, right?
Right. That, you know, we need to be able to do these things. And Well, I think, I think it comes back to the exactly, it's the same idea, right?
That nothing, there's nothing new under the sun. You know, it's, I think that's in the Bible in the back somewhere, you know? Yeah.
Yeah. Anyway, um, but no, that's the idea that there is not, you know, these types of attacks are coming out. I mean, the, the type of email fraud attacks are just very simple.
Re you know, you know, people were doing that in the 1920s, right? What they were just doing it with e uh, with letters. They were doing it with, you know, then they were doing it with telegrams, and now they do it with email.
It's really not any different. The main difference is now you can, instead of sending 10 e uh, 10 letters a day, you can send a million emails, and then you could have each one of them individually crafted by AI to target the person that you're going after. You know?
And again, uh, human error is still the, the bane of, of cybersecurity. Right. You know, the people that will click on things, uh, because they're afraid of getting in trouble.
And again, that's company culture, right? I mean, you know, I get, uh, uh, at Reversing Labs, we have this, uh, we have all Slack, right? We use Slack for everything.
And we have a Slack channel called Mario Needs Help, and Mario's our big boss, and he's, you know, great guy. And he, he, he, you know, a lot of people know him and talk to him. He is very, uh, he's very present, right?
He's one of those guy, uh, CEOs. He's always, you know, you're always talking to him in meetings. He is always asking really relevant questions.
Um, but Mario needs help. You know, anybody who starts at Reversing Labs within a day or two will get a text message saying, Hey, this is Mario. I need you to go down and buy $1,500 worth of Apple gift cards for this customer.
We don't know who's doing it. We don't care that much. 'cause it never worked.
And the amount of effort to put into it to try and find out who it is. So it's not like we're gonna be able, you know, like I always say, like, you can't really call the police in, you know, these countries and say, Hey, we'd like to bribe you to go arrest somebody. You know, that kind of thing.
So, you know, these people operate in corrupt countries and they have all this thing, and, but it's just a, it's just a thing. And then we, the way we dealt with it is very straightforward. We made, you know, made it really visible within the company.
So it's part of our new hire training. It's very clean. But again, it's also incredibly helpful that everybody knows what Mario sounds like.
Everybody's talked, you know, a lot of people, almost everybody in the company has talked directly with Mario, so they, they kind of know what to do and what they don't. You know? Um, I've worked at companies where I didn't really actually know who the CEO was and the idea that somehow they were wanting me to, you know, do something.
And we see that where people are just afraid of getting in trouble, you know? And they're more afraid of like, you know, somebody being mad at them for not paying a bill or versus paying a fraudulent, uh, invoice. You know?
And then that plays to me. Yeah. So we're talking about the present right now.
So that plays to some of my favorite buttons. Right. You know, and what you've described to me sounds like a nice practical human, you know, human trust based solution, right.
You know? Mm-hmm. You hire decent people, you expose 'em to the information, the people in this case, you know, that they need to be able to, to respond to.
And you put the technology underneath that to support that. But you're not basing it on, like you say, you know, the fear of being fired for not doing something. So company culture, you know?
So the Department of Energy and the, the, um, cyber informed engineering initiative, you know, has a term that I just absolutely love, which is radical transparency. Mm-hmm. Which lines up exactly what, you know, I've been focusing on the last five years or so, the supply chain stuff.
Right? And you and I have talked this to death, and we're both working in companies do that stuff these days. And it's just an exercise of the same things we talked about in 1998.
Like, how do you get trust with a market if in that case you're a big faceless company called Cisco, um, by personally doing it and doing things and demonstrating the trust and being visible about it and being transparent. And, uh, and it's not a trick, right? And in the current conflict environment, right.
You know, so everything from misinformation, disinformation campaigns, organized by nation states to influence demographics, and to your point, we now, now support of I AI to like, sound just like Iran. Um, you know, what do you do? Right?
And I personally, I think the, the answer is the same as in cybersecurity and supply chain and open source, you know, be absolutely transparent, right? But to the people you should be transparent to in the ways you should be transparent to them. Um, Yeah, I absolutely agree.
And I think that there's a lot of, um, a lot of, a lot of it has to be able to, you know, organizations really need to be able to, uh, quickly respond to changes. And, um, you know, you and I still deal with companies that say, I have a five year, uh, planning cycle, you know, where, you know, we're not gonna be able to do anything for a couple years. Um, I know like, you know, a lot of the traditional industries have, you know, planning cycles where they, you know, it's like, yeah, I know this thing where drones fly over the, uh, you know, the electrical plant.
That's really, really bad. But we really don't have, you know, we can't really address that for like two or three years. 'cause we don't have, you know, now that we don't have the money, we just don't, you know, our methodology, you know, our planning cycle, our, you know, the, uh, security council only meets once a year, you know, that kind of thing.
So there's a lot of, a lot of challenges within how companies respond and how are they able to, uh, react to these new types of attacks. But again, we seeing, you know, even in the last year or two with AI and how it's not, you know, it's AI is not smarter or better than us. It's just able to do the same thing a million times over.
So if I, if I'm able to grab a list of email addresses, I'm then able to have a chat GTP program that's able to look everybody up on LinkedIn, figure out, you know, what, what, you know, what kind of, what messages might be appealing to them, and then be able to send those emails. And I could do that in a day. You know, I can get that done, you know, I could be, I could be processing millions of them.
And then again, you know, one of the, uh, you know, you look at traditional, like, you know, I 1950s with the Russian spies, they would send a, a Russian who was, had been born in America, but grown up in Russia, so he had an American passport, and there were very few of those people. And then they would come to the United States, and they would be Russian spies, and then they would do s spies stuff, and they eventually would get caught, and then they would be traded for, you know, our YouTube pilots and things like that. And now I don't really need to do that, right?
I can, uh, I can bribe, or I can pay for influencers in a certain country, right? I can literally go online and find influencers who will spout whatever messaging I wanna, you know, give. They, they are local, right?
They speak the local language. They, I don't have to worry about translation. I don't have to worry about, I don't have to send my agents to that country and worry they'll be arrested at the airport because it's, you know, a triple cross type situation, right?
I mean, I can, you know, countries now, like Russia, they can just sit back, pay American influencers to spout their lies, and they don't have any risk, right? What's they're, they're not sending anybody here. If those influencers get found out, they, you know, may get arrested, they may get charged with tax fraud or some other types of crimes, but there's no risk to the Russians.
There's no, you know, the Chinese, or, you know, the North Koreans, the people that are doing these types of espionage programs, the traditional risk where, you know, this was gonna cost millions. It was gonna take, you know, all these things. Russia really did have a village that was an American town, and they sent their agents there, and their agents had to speak English only, and they had to drive American cars, and they had to know what an air conditioner is and, and, you know, and all these types of things, because that was the only way to get them assimilated into these countries.
And it costs millions and millions of dollars and took years and years. And, you know, you'd have an agent that you've invested years and years and years of training in, and then he arrives at the airport and gets picked up, uh, because of a problem with his passport. And next thing you know, the whole thing's a failure.
Mm-hmm. So I think, you know, the, the, the way that espionage is being done now, the way the fraud is being committed, there's very, very, there's significantly less risk to the people who are doing it than the way it was in the nineties, right? In the a, you know, when we we're not, we were dealing with criminal gangs.
There was a point where in Russia, you could call the Russian police and they would arrest people. Um, that time is gone, right? And then, you know, traditionally you had criminal gangs that were only interested in money and criminal gang, you know, and intelligence agents and government people, uh, you know, you and I used to do this.
We used to laugh at the Chinese spies because they would work like nine to five, right? They would start work in, they'd be in Beijing, they would start working at nine o'clock locally, and they would quit around five o'clock and they would take lunch. And so when we would look at the activities, we'd actually know, well, okay, based on where these people, you know, the time that they take lunch, this is where we think they're based.
Now this is all done by, you know, AI tools. It doesn't really matter, you know, when it's done, or it's just being outsourced, you know? And so they're, you're going on, you know, these, uh, you know, dark web, uh, mailing, you know, lists and, you know, and, uh, chat boards and things like that.
And just hiring people and you don't really care where they are. And so a lot of this is, you know, uh, uh, the, uh, the challenge, and again, this is just the disappointing part, is things are getting worse, right? I mean, the, you know, the, the risk of being attacked is a hundred percent, and the ability for people to attack you has dropped dramatically, right?
So instead of us needing an army and, you know, $20 million to buy a tank and seven months to train somebody how to drive the tank, you can buy an e, you know, e-bike off of TMO for 400 bucks and, uh, you know, a little and old javelin missile, which, you know, has a half hour training video that you watch on YouTube, and, um, you know, you're good to go. So, I mean, it's a dramatic wr, you know, dramatic difference in, you know, these types of attacks. Well, and before we get into, you know, uh, even the near term future, much, much less longer, slaughter bots, you know, you remember that, uh, yeah.
Seven minute video put together by some concerned scientists. Oh, was that been five years ago or so now? Something like That.
Yeah. Yeah. And, uh, the, the premise, everybody who hasn't Googled it already, you know, is that terrorists start using drones.
Mm-hmm. And, uh, and, and social media identification information so forth to individually target, you know, uh, um, uh, victims, you know, politically or, you know, you're posting on Instagram a certain way and a drone with an explosive is coming after you. And what you're describing is, is perhaps we're getting closer to, or maybe in that phase already, right?
Yeah. I think it's interesting. You know, you think about, um, like in Afghanistan, our opponents there, um, used handheld radios, you know, commercial, you know, available ham radios or, you know, the type of things you can buy, uh, for $50.
And they used those because they did not have location based services, right? If you, you know, we have some in incredible, uh, electronic warfare devices, the, uh, airplanes that, you know, fly around recording everybody's phone conversation, tracking everybody's phone, doing all that kind of stuff. That gives us an incredible view of the battlefield if somebody's using a phone.
And so, you know, they shifted over to handheld radios. Uh, same thing with pagers, right? Um, I, you know, I, uh, took a police sciences course recently, and they were talking about if you catch somebody who has a flip phone, they are a hundred percent a bad guy right?
Now that's a generalization, unfortunately, just turns out to be true. You know, unless it's somebody's great grandmother, you know, people who carry flip phones have, don't not have location based services on them, and they're doing it so that it can't be tracked. So, again, you look at it for two types of behaviors, right?
One is, are you doing this, uh, for these reasons or are you actually a criminal? It's interesting to me though, that because most criminals are just stupid and do stupid things, and that's why they're criminals and they get caught. Yes.
Most of the people I know, thank God, right? Most of the people who have carried flip phone, I mean, you go to the black hat or you go to RSA or some of these other shows, you'll see guys with flip phones because they're just convinced that the government is tracking them and they're really worried about it. And it's a really big deal to, you can't really, it's not a topic you wanna bring up with them, right?
You know, I, I never mention it because they'll just go onto this long rant about how the government is listening to everybody. And it's like, well, they are, but they're not interested in you. You know?
Um, they're interested. Are You not that important? Yeah.
Sorry. I mean, you know, um, you know, unless you're selling drugs or being a terrorist, they're not as interested in you as you might think. Well, you had mentioned, you know, patriot 'cause we had to go there in the, in the current tens.
'cause we're, you know, this summer, right? You know, just recently, you know, we all know every there in the world, you know, the supply chain attack against pagers and then walkie talkies, you know, in the Middle East, you know, presumably, you know, uh, affected by Israel, which makes perfect sense. And it's, and you know, I mean, you know, this digital bill of materials thing, you know, that you and I have been talking about since 2019, right?
You know, this is exactly the kind of use case I like running through. And, you know, five years ago it was a bit, you know, you had to scratch your heads. You had to go to Scottish, you know, the National Manufacturing Institute of Scotland to find folks who can really speak to the idea that I may need to know what software was running on the machine tool that made an individual part, like say a battery, you know, this physically inside some device.
I need to know that right now. Right? Um, this is a demonstration that, that those, it's not just about software security because I would, you know, you talk about it, you're sending something into space.
I may want to know who made the plastic case at a level of no. That I would can use to put things in space. And we have to build those systems.
It is interesting because, uh, you know, we always talk about the insider threat, right? You know, if you are a criminal, right? And you are, your intention from the beginning was to commit criminal acts, you are the hardest person to deal with it when the organization, right.
You know, if you, you're an active criminal, sending you to the class where you learn about what emails to click on isn't really gonna help the situation, right? Um, and so, you know, you see this idea that, you know, I can trust but verify, right? How do I know if someone has done this?
I mean, reversing labs, we have comprehensive supply chain, uh, security tools that will actually deconstruct a file. And the main reason being is I can't necessarily trust you if I, I, I'm, and I'm, I I love you like a brother, you know that, right? But if it's my job, I can't say, Hey, Chris, we're buying this phone from you.
999% of the time, that's fine, right? The challenge is, what if you don't send me the right software, or you're a criminal and you intentionally send me the wrong software without the malware on it. And when I get the phones, they all have the malware on it, so I can't trust you.
I love you, but I can't trust you. And so I have to, um, I do have to check it myself. I do have to deconstruct the software as it is not as I want it to be.
Or, you know, Hey, send me your, your files and the link to, you know, your Python repository, right? That is, that doesn't really help. I need to see the actual software.
So being able to take the software, deconstruct it with like our short tools and things like that, that allows you to have a hundred percent confidence in this. And I think the thing that I don't understand, and again, I I will, I will just say this, and again, there's many, many things that you, and I know that there are a lot of lies told by everybody in this industry, right? You know, vendors lie, customers lie, governments don't necessarily represent what happened for various reasons.
And so, you know, we hear the story of these pagers were made in Hungary. They, or, you know, they were made somebody set up a company 15, you know, all that stuff. And, and, and, and as you know, sometimes we're in the deal, right?
And we go and watch tv and you go, that's not what happened, man. Um, I was there, I was in Korea on that day when that attack happened. And that's not what happened.
And it doesn't matter because that's the story, right? That's the story they're gonna go with. So you have to deal with that.
But I find it really hard that nobody, you know, if you received a couple thousand pagers, no one took one apart and looked at it. I mean, is, and, and, and again, if that's true, that's in incredible level of incompetence. You know?
And you know, the idea that I, you know, hiding a piece of plastic explosive and some ball bearings and on inside a pager, I had a, I carried a pager for a long time, right? I was a field engineer and, you know, get pager pay, which I really miss, by the way. Um, you know, I could, I knew which pager was mined by how much it weighed, you know?
And, uh, I think that, you know, um, I think it's, it's really hard to understand that what happened there with the idea that somehow these were bought, acquired, distributed in high, in, in, in active use, and at no point over this period of time did one break, and therefore somebody had to take it apart and look at it, or the battery died and somebody took it apart and went, wait a minute. Why is there a little bit of plastic in here with some ball bearings? They just don't understand that.
And that's, and that's and interesting because, but again, having gone through all of these types of things, um, you know, we know that there, the story about what really happened and what didn't happen, it usually comes down to either laziness of corruption, right? Yeah. I I, I, I love that you mention, you know, criminals are stupid, you know?
'cause I, I can't tell you how often I use that because you have to understand, you know, that the, the, you know, evil mastermind from Hollywood, you know, who's got the big brain big and everybody else, and, and it was for some reason invented teleportation, decided not to just get rich on that doesn't exist. Right. You know, usually people making bad choices are making bad choices 'cause they're not thinking about everything properly.
Right? And we can call that stupid if we want, because it works, right? Well, Again, you have, um, you have your two basic types of criminals, right?
You have your typical career criminal who's very much used to going to jail, and you have your, uh, you know, I have, I have friends that are like parole officers and things like that. They, they say there's two types of criminals, right? The one that was never expecting to get caught and is scared to death of going to jail again.
You know, the person has a, like a DUI or criminal DUI or you know, did a little bit of time and now he's just absolutely terrified and shows up early to their parole meeting, you know, and all that kind of stuff. And you have your career gang member who's been and outta jail since he was 11, and is just isn't comfortable in jail as they are at home, and doesn't really, you know, for, would prefer not to be in jail. But the idea that, you know, they're somehow not gonna be a gang member is just crazy.
They, they're, they're gang members, their whole identity, You know? So we, yeah. So with all this, anyways, let's, let's look out in the future, right?
You know, so I, you know, I have a ongoing positive. I keep saying that I can't see a medium term to distant future where some of these problems still exist and not because, you know, morally or ethically, you know, we all love puppies or whatnot because you just can't keep the lights running. You know, we need these systems to, you know, work at a high fidelity to the point that, you know, mainframes, you know, have been working for the last 50 years.
Mm-hmm. Um, but, you know, a much more complicated, much more distributed environment it requires and calls for the kinds of structures that, again, I, you know, I think folks like you and I have a good idea, right or wrong, exactly what they are. But, you know, once they're done we'll, we'll be able to look at it and say, aha, that's how that works.
Right? Right. Makes all this stuff a lot harder everywhere from the nation state level.
And just to, to see that. So David Bryn, right? The science fiction au, uh, author was at RSA in San Francisco this, uh, this year.
And in the text Wrong booth To Hang out with him for a bit. And in one of his favorite books of mine, uh, killing People, one of the basic premises is that crime and, and particularly, you know, complicated, you know, uh, a conspiracy is really, really, really, really hard to the point that it almost doesn't happen anymore. And I, I think that is the direction we're going, how long it takes to get there is a big question.
Yeah. I, I, I, you know, again, I think that the challenge is going to be how quickly can these, uh, organizations adjust to these types of things? We're, we're starting to see people, now we're, we're dealing with customers who are saying, uh, before I would only check one or two software packages that came into the company.
Now I wanna check everyone. And, you know, and again, if you and I were, I mean, honestly, you and I have been around doing this so long. I remember you and I going to like a, uh, I can't remember what bank it was, but the guy was like, why would we need a firewall?
We're never gonna connect to the internet. People like going to the bank who let, like, the guy, I remember that guy was like, who let you in here? Like, you know, why, why are we having this meeting?
We're never gonna, you know, internet banking, are you crazy? You know, banks are judged by how many branches they have. You know, that's the most important thing.
Uh, you know, even, uh, even when ATMs and things were coming along, it still was, uh, the idea that somehow there was a, uh, you know, it was not gonna be something that people really wanted. Right? Why would you wanna take money out after the banks closed?
That's crazy. You should have planned that. Well, And it, and to our topic, well, here, you know, I think I have these conversations all the time, basically, you know, anonymizes, but, you know, generalize it.
But it's something executive saying, you know, what, you, what do you mean? You know, my employees can't make most, most of the decisions about, you know, their, their work responsibilities by what they generally pick up on the internet. Right.
You know, because that's, you know, to your point about, uh, um, your, your boss, your CEO and so forth, and that, you know, that process you have with employees, it's generally works, right? Yeah. It's not very scientific.
It works. It generally works in until it doesn't anymore. Yeah.
And I think, I think you have to, you know, the, you and I were down in, uh, in Columbia Meine, right? Uh, before the pandemic and so forth. Don't talk About that.
No, just kidding. Keep going. You know, as I was, I, I said the public information was public, public Information.
Uh, yeah. Only Ever shared on this channel. Why didn't we go by canoe?
That's what I don't understand. Right? I should have taken Mark Twain.
It's another topic. But, you know, in that time, working with those folks that, uh, national infrastructure and so forth, and looking out over periods of time, you know, that 25 year plan, right? You know, we're right at about seven years in right now, that's seven and 15 years where those sort of break points where we said, you know, by this point, you seriously need to be thinking about, right.
These issues. And one is, you know, how do you really know when you're turning the power off and on, you know? Right.
It's, it's gotta be, there's gotta be systems of automation, transparency that don't exist yet, but will exist by then. Right? And they, and they do.
Right? And you look out, you know, that next, you know how much 18 years on that, on that roadmap, right? And I think that we and the people, you know, involved in that and similar efforts are, are right.
You know, to your point, in 15 more years and 18 more years, we're gonna be living in a slightly different world, right? Where we will have, have had to adopt certain parts of that transparency and clarity, right? Just so we can live in, in conflict environments, Right?
And I think it just comes back to experience, right? I mean, I, like many, many people in the cybersecurity world thought that, um, Russia was going to be able to attack Ukraine and launch a massive cyber Pearl Harbor and wipe out everything and turn all the power off and turn off all communications, and it would just be completely dark and their phones wouldn't work and everything else like that. And it turned out none of that happened.
And that the turned out the Ukrainians, because they had been actually experiencing this for years, were very good about defending themselves, right? And I know a lot of people have been to Ukraine. I know, uh, some of our mutual friends have worked there and tell stories and stuff, but they have, uh, you know, Ukraine was able to turn around their situation.
And when these Russian attacks happen and they happen every day, thousands of times a day, they were able to dramatically defend themselves quite well because they had experience, right? And that's the thing, that's the difference between a lot of these organizations. I think that they should be looking to guidance from people that are having these types of, uh, you know, incidents happening and using them to predict what's going to happen in the future, rather than what they did 10 years ago or what they did 20 years ago when they worked at the NSA, right?
I mean, that's, you know, and that you look at, you know, when we look at cybersecurity, some of the best cybersecurity setups are by people who run commercial Minecraft servers, right? Because you have your own private Minecraft server. You sell that to, to people who are really into Minecraft who want to have their own, you know, landscape or world or whatever you call it.
And if people in the industry will try and knock yours down, uh, so when we look at people who are very good at defending their infrastructure, you know, you wanna look at somebody who's getting attacked every day and doing wallet defending themselves, right? If you look at the situation in the Middle East where you have hundreds of missiles being fired and hundreds of missiles being shot down, that's incredible, right? That was, that is just science fiction, right?
The idea that somebody could launch a hundred, you know, I mean, all those, you know, diagrams, you know, the, the, the Iranians have so many missiles and you know, this is what you need to worry about. And then they fire most of them and it costs them billions of dollars to do that. And very few actually get through.
And, you know, and again, it's a terrible thing. It's a tragedy. It's absolutely the worst thing in the world.
But if you were looking to defend yourself, you would look at something like that and say, okay, how did they do that? Right? And the same thing you wanna look at, you know, so you look at people who have high level of competence, competence, and at the same time have a high level of ex, you know, direct experience in doing these types of things.
So when you're reaching out to, uh, security organizations are looking into with different groups and things like that, you just want to be talking with somebody who's actually done it, right? Who's actually run a, you know, a system and been under high attack and successfully defended themselves. And now those people are rare and they're hard to acquire, but you should listen to them.
You don't, they don't necessarily have to work for you, but you can go, you can, you know, listen to them. You can listen to people like yourself who have had this experience and have gone through, but you just have to open up and say, you know, what are we trying to do? We're trying to defend our organization.
We can't trust anybody. We need tools that can, uh, do this. And we need policies and procedures to effectively use those tools.
'cause even with the best tools, if you don't have the skills to use them or the ability to use them, uh, that's where you get into the frustration. And everybody I know who's left cybersecurity, and I'm sure it's the same with you as well, has left because of their frustration with their organization, right? Hey, I, we had a meeting about this six months ago and I told you this was gonna happen, and you know, you told me to shut up and go back to work, or, you know, we needed to work on our, you know, are we done with the budget?
Yeah. We had to, you know, we can't, you know, we can't, uh, we can't go back to our bosses and say we were wrong. We, you know, we can't change, ask for a change in the budget 'cause it'll make it look like we don't know what we're doing.
And the reality is, you should be almost fluid. Like wake up today and say, what are we gonna do? And, and you know, the difference, again, used to have criminal gangs who were trying to steal money, and that was really straightforward.
And then you have government organizations now before you had to steal money and print fake credit cards and hire people locally to go and, you know, cash out crew and go into the local mall and buy TVs and jewelry and things like that. And then, you know, it would only work for like 20, 20 hours maybe. And after that, the credit cards were no good.
And you have to start over. And now you have cri, uh, you know, Bitcoin and cryptocurrency. Now that's very fluid and you know, harder to track and very, you know, easy to do.
And then you have a rise of like, you know, North Korea where they're actively stealing money, right? The biggest cr you know, heist crimes, the bank robberies that if you wanna say in history are done by employees of the, you know, north Korean government, you know, who probably wear a uniform to work, but at the same time they're stealing millions of dollars because they're using it to fund their own country, right? And how long ago there were, that is science fiction, right?
That, you know, 20, 30 years ago that was, I mean, you know, you read Nor Manser, right? The idea of winter moot, and you had the idea of an AI that escaped and went and lived in Antarctica, and that was, you know, and was, you know, hiding from people. That was incredible.
That's as real today as anything you want. You can spin up your own organization, uh, uh, you know, hide it, have, you know, put it, have it running on servers in another country, never have any physical access to them. And the only time you get caught is when, you know, you get tricked into, Hey Chris, you've won a free trip to Crete.
You know, you wanna come, you wanna come to Cyprus? We have a conference we love you to come to, and when you land there, there's two FBI agents waiting for you. Right.
You know, it's, that's the, you know, the, the only way that you get caught now is by being tricked, you know? And, you know, but, and the cost of doing that, I, you could do that for $10,000, right? And, uh, you know, there are countries in the world that don't have jet fighters, but have cyber warfare groups that are very effective.
Yeah. And then when you have a merging of that with corrupt government officials who are using this for disinformation, uh, you know, you know, things that have happened in some countries, um, it becomes even worse, right? You have, you know, it becomes a, uh, uh, a situation where we see that in, uh, where, you know, we have, uh, news people, you know, journalists who get arrested by the government for telling the truth.
And so now you see, you know, news organizations actually having virtual, uh, journalists, right? You know, it's an AI representation of a journalist reading a news story story because all of their, you know, otherwise the government guys are gonna come over and arrest you in the middle of the night at your house and no one's gonna see you again. That, again, is space fiction, but now it's just as real as can be.
And the resources for that are not, I don't need a a hundred million dollar, you know, plant and, you know, several top scientists, PhD, AI guys, uh, I can go on app Sumo and, you know, buy something for 90 bucks and it'll do what I wanna do. You know? So it's just, you know, again, it's just a different world.
It is. And we're living in it and we're moving into, uh, yet another one. And I wish we had more time, we could do this stuff, uh, until the cows literally come home.
So let, we thank you for your time today. Thanks for decades of being a good person, good friend, and, uh, everything you've done to help make the world a slightly better place. Well, thank you.
And again, thank you for being able to give me a platform to rant for a little bit. But, uh, and then being these types of ideas, but I think the main thing again, is that while things are bad, you know, you and I go to these security conferences and it always, it was always doom and gloom, right? End of the world.
This is all terrible. And I'm like, no, no, the lights are on, right? The right, the internet is working.
Um, you know, there's, you know, if, if things are so terrible, then why, why is everything just, you know, as good as it is, right? Global hunger is moving down, It's global poverty has been halved in our lifetime, right? You're talking about a billion people moved out of poverty.
Uh, that's incredible. And again, it's done because of technology and because of people that really wanna make a difference, but also because of, you know, free markets and capitalism, being able to say, you know, if we raise these people up, then maybe they'll buy, you know, cars. So, you know, let's do, let's do that.
So again, it's this idea that, you know, things are not that bad. I mean, just you, you do have to be more flexible and, and be a little more fluid and, and things like that. But that's just 'cause of the way things are, you know, the technology is evolving, but the defenses are evolving just as quickly.
And again, you're, it's your ability to be able to use them. So get some good people around you and get some, you know, get some good on training and get some transparency. Get a few, couple good tools, learn how to use them and take advantage of them.
And, you know, everything will be reasonably good. I agree. Well, thank you again, thank you out in the world for spending some time with us today.
Look forward to seeing you again on another episode. Absolutely. You have a great day.
You Too. Bye folks. Bye.
Hey everyone, thanks so much for joining me today. My name's Jonathan Singer, I'm from Check marks. And today I'm gonna talk a little bit about putting the SEC into DevSecOps today.
There are three things that I want to convince you. The first is that high performing code that is not secure, it's not high performing. So in secure code, it's actually a, a culture problem.
The second thing, security tools are or must be developer tools. And the third thing is that DevSecOps is a culture problem. Before it's a technology problem, I'm also going to give you five requirements to build your organization's DevSecOps maturity.
Those are one, education, two automation, three speed, four shared measurements, and five integrations. Let's begin. I wanna start by asking us where are we today on our DevSecOps journey?
We ran a survey of over 200 chief information security officers and only one in five that we surveyed have actually begun integration and automation. And that's a lot of the main work of DevSecOps. Alright, so, you know, we look up at these survey numbers and it looks like we're not really doing DevSecOps yet as an industry.
So the question is why is that? Well, look at the way the answers here are formatted. You know, I work for an AppSec vendor and do any of the answers here mention a tool?
No, they don't because buying a tool is easy. Well easy, I'll put that in quotes because you have to go through procurement and, and all that. Um, but honestly, you wanna buy something.
Send me a message on LinkedIn, I'll introduce you to my sales rep. You can go buy something, but getting you to buy something is hard work for my company. But it's not the hard work that you need to do.
If you wanna do DevSecOps, the hard work for you is in building a DevSecOps culture. So let's talk about DevSecOps at the highest level. What is it exactly?
What it's not is not just DevOps with security. 'cause a lot of you are probably already trying. What DevSecOps is, is the continued merging of organizational cultures that began with DevOps, right?
So if you go back to 2009, that's when DevOps really kind of started to hit the ground running. And from there it's been a series of cultural challenges. And now remember the, the name of this talk square peg in a round hole.
Why did I name it that? Well, where did DevOps people come from? They come from the land of move fast and break things, right?
They they, they build applications, they try things, they get them to work, they're about getting product out value out quickly. Cool. They spend all their day as developers, hopefully in their IDE coding as quickly as possible, trying to be really thoughtful about what they're building.
Where do security people come from? They come from the land of never, ever, ever let anything break. We'll be in trouble, right?
So it's, it's just a very different mentality. Um, DevOps, or sorry, security people live all day getting alerts flashing at them. You know, we've got a WAF problem here, we've got a problem at this tool.
They get alerts all day and their job is to keep the organization safe and not let things break. So if you wanna talk about DevSecOps, it's about taking the needs and outcomes of security, which are risk management and mitigation of threats and integrating them into the processes and culture of DevOps. And this is possible, the point is for DevOps DevSecOps to become the same thing differently, I would argue that they are.
Alright, so cool. How do we get there? I wanna talk next about DevSecOps maturity.
So what you see here is a graph that I definitely didn't free draw with my track pad and then have the design team put some lipstick on. Um, alright, that's exactly what I did. But what it represents is actually how organizations at a very high level end up on the road to DevSecOps, if you want a super formal maturity model with like a lot of really detailed steps, Gartner's got you covered for that.
They got a great report, but this is a really easy place to start your thinking. So let's look at the three different levels, the bottom level security focused. This is where the application security team gets a tool, scans for some vulnerabilities and hucks them over the wall to developers saying, here you go, zero problem now.
Um, so that's not entirely fair to security people, but I'm gonna be even more unfair here for a second. This right here that's shift left. We've shifted the problem left, we're scanning earlier and here are some vulnerabilities.
We need to fix them, right? And it's a really important first step and it's important that your AppSec team takes it, but you really need to then take the next step. And that's developer experience.
Here's where it starts to get in. Interesting for the people who are probably watching this presentation, right? This is where we start thinking about how you as developers work, right?
And that's integrations. That's can you sit in your IDE and get your results there? Can you get remediation guidance there?
Can you get everything you need there? How do we make it easier for developers to stay in their workflow, right? So once the AppSec team starts thinking about that, providing you with tools that integrate, you're getting on the road towards DevSecOps, but you haven't necessarily had all the important conversations.
This last part of, uh, of maturity where we get to actually DevSecOps equaling DevOps, right? That's where we really start to work together, right? We figured it out.
We've got some tools, we've made sure that they're connected. But here's what we realized, that that's not entirely enough. And, and you've probably been doing some of this work along the way, so I'm not gonna say that it just appears here, but this is where security and development teams and platform engineers, they all sit down and they set joint policies and they enable developers to be more secure wherever they are in the software development life cycle, right?
This is where you get automations going. This is where you really, really start working together smoothly and it just becomes a part of your cycle. And if you wanna see what it actually looks like in person, this is actually what it can look like.
So this is a customer of ours, uh, fortune 100, utility provider, pretty big company, no joke. And you'll note if you go all the way to far left of this graph, they had a tool, they bought that tool. It was in fact our tool for a year and a half.
And, uh, they were gonna get rid of us because as you can see, they're not really using it. Why weren't they using it? Security is slowing things down.
Developers aren't fixing the vulnerability vulnerabilities we send them, right? So you've got developers saying things are slow and security is saying you're not doing the work, right? They shifted, left, didn't really work.
Okay? So then we started to talk to them about the process, about how do you fit AppSec into the development process. Why do you give developers a good experience?
Oh, and then you start to see it start to curve up. Then you start to form some joint policies and you realize, hey, we've got these joint workflows and we're really starting to get some work done. We're really making our applications more secure.
And so here's where you say that, you know, a tool, it's a tool, but securities the process. Process. And that's why, because it's process oriented in the end, security can find a successful home in DevOps.
But what it means is that next we need to talk about DevOps and DevSecOps in the lens of human culture, right? Enablement, measurement, speed, automation, integration. How do we make these things work together?
So we need for the DevOps crowd to get to DevSecOps. We need platform engineers, architects, developers. We all need them to see security tools as developer tools and secure code as performance code.
So I told you that I was gonna talk about integrations well, or sorry, about um, about DevSecOps requirements. And I've put together, I thought like kind of long and hard about this and I put together a few and I lined them up with calls from the DevOps handbook, right? Almost as great accurate culture automation, lean measurement sharing.
I'm sure that you've read the book. Um, I've come up with my own list of, um, requirements that nest within columns. I'm not gonna do it in that order, but I think that these are gonna help you get you on your way.
So we've got integrations, we've got shared measurements, we've got useful security education, we've got matching security velocity to developer velocity and we've got automations. So let's talk about requirements. If you remember back to our maturity model, the first step away from throwing vulnerabilities over the wall is thinking about the developer experience.
So the first requirement for DevSecOps is to keep developers in their flow state. That means tools need to be delivered directly to the ID to keep things moving. So if you're a platform or tech architect and you're picking a tool, you know, you likely have, you know, multiple, possibly thousands of pipelines.
But what does that mean in terms of support? How many different tools? Does whatever you're gonna buy integrate with many languages?
Does it support, right? These are all tool questions. And that's because it, these integrations actually become culture themself.
The culture part is where it's security thinking about how developers work and how they operate. And that's how you take that first step up in maturity. If security isn't thinking about how developers work, you're not even on the road, right?
And all this is important because the goal in the end again, is for developers to see security as a tool at their disposal in developing high performing code and not a, the second requirement is what I call shared metrics. What are shared metrics? 'cause if you've got metrics, presumably you're sharing them with someone.
But simply put, these are metrics that everyone on the DevOps side and the security side can relate to. And it's actually not what this graph shows. In fact, um, sorry about this graph.
If you're colorblind, I'm super sorry about this graph 'cause there's no way you can read it. All I can say is even if you can still see colors, you probably can't read it, but I'm gonna talk about it for a second. 'cause what it shows is all the way on one side what developers care about in jail is their responsibility.
And on the other side what security believes is their responsibility. And you can kind of see where they sort of meet in the middle. Um, but the point is this illustrates how security and development DevOps, they're thinking about vastly different things, right?
So security teams and development teams, we know already that they think in very different metrics and they feel responsible for very different metrics and they contribute to tracking different metrics. But if you wanna do DevSecOps, you need everyone thinking about the same things to to a point, right? So sure security can go, they can look at total number of all our abilities.
They can look at how many of each severity they have, uh, that's been remediated and that's really good for them for their own reasons. Um, it's really helpful for security to show that they're doing things but it doesn't drive forward DevSecOps. So the question becomes what are good metrics?
So good metrics from a DevSecOps perspective are those that show you how quickly your integrated team is delivering value for the organization. Metrics that help you direct your efforts, identify problems in your pipeline so that you can work more efficiently. And that isn't to say that these other metrics don't have a place.
You know that the DevOps metrics, if you're a developer or a platform engineer or an architect, you know that those are useful and you know why they're useful. Um, and these, these numbers on the left, the AppSec metrics, those are fantastic for application security teams to say, Hey, we're doing work. Justify it up the chain, justify the purchase of tools, justify headcount, which they need to do a lot of, right?
'cause a lot of people see security as just a cost center. So they need those justifications. But what you need to get to together is you need to get over to the right where you're watching these DevSecOps metrics that are gonna keep your machine running, right?
And the most important of those is mean time to remediate. So that is how quickly are security and developers working together to get vulnerabilities fixed, right? Mean time to detect How quickly are we detecting metrics?
How quickly are we getting them through the pipeline issue volume? How many security vulnerabilities are there? And that's becomes really interesting if you can break it up by application and team, what are your top vulnerable applications?
Where do you need to really like spend your limited security resources? Do you have a security champion program? Do you have security consulting teams internally?
Where do they need to spend their effort? Security coverage? How deep are we actually scanning applications?
How does that factor into the risk? Are we looking at internal applications that are behind internal firewalls, not as risky. Maybe we give them quicker scans versus the stuff that's really important that goes out there in front of customers, collects PII that needs the really deep scanning.
These are all things that need to be figured out and need to be measured to show that your DevSecOps effort is really working together as a machine. Third thing I wanna talk about is security education. So performance is really firmly ingrained in development culture.
You can see it along the timeline here. The problem is security is so, you know, 20 years ago performance wasn't really either, but now it's, so if we're looking at this timeline, we're saying, okay, you know, the building blocks for DevOps happened in the early two thousands, 2009. We've got that great presentation.
Things start to take off. You know, it's now, it's been 15 years since 2009 and still in some places DevOps efforts are just getting off the ground, right? So DevSecOps, we know we've been talking about it for a few years.
It's got probably another time 10 years before we're really getting it down. Well, but we know we need to get it down faster than that. We know that, uh, you know, there are a lot of threats out there and they're all targeting, uh, these new applications that people are building.
So, you know, how do we get, we follow on the road of tho those next 10 years and get to the place we need to be at? And education is a big part of that. So if you look at the stat at the bottom, only 50% of Delphis state that they have access to security training.
That's because we know that universities don't teach secure coding. We know bootcamps don't really train depths in secure coding. And we know that it's also a big complaint of security teams.
Uh, the developers don't know secure coding, but we also know that's not really developer's fault, right? Developers learn through especially about security through experience. So like, hey, that guy over there, he had a problem with a big cross site scripting vulnerability and he had to fix that.
He's the guy who can tell you all about it. Or, oh, that lady over there, um, she was working on the lock four J stuff, so she really knows her stuff, right? It's, it's not their fault and knowledge becomes tribal here and there, but what do we do about that?
And what we need to do is give developers options, right? And we've got three different types of options. We've got training, we've got just in time and we've got inline education, right?
So what do these look like? Formal training? It's, you get access to a security coding course, uh, or a secure coding course and you put your developers through it takes a lot of time.
Um, and maybe, maybe they have time to work on it during the week. You know, I know that, uh, developers focus a lot on learning and maybe you have like a Tech Thursdays or Coffee Mondays or you know, some sort of learning program and, but this is just a part of it, right? So who has time to really sit and do formal training all the time?
Not everyone, but it needs to be an option. The next is just in time training. So this is help when they need it.
So do, when you get a vulnerability sent to you through a tool, is there a mediation guidance attached to it? Can we save developers the effort of spending an hour or two hours going to Google, doing as much research, figuring out what is this vulnerability? How does it manifest?
How do I fix it? Am I doing this properly? Right?
What can we give them right there in that moment to help them learn? And then going even faster than that, there's inline training. So that's, you know, do you have some sort of a probably gen AI tool that's gonna give you feedback as your coding, right?
And some of those are available in various states. So these are the three sorts of things that, um, you know, platform engineering teams need to be thinking about when they're enabling their developers, right? This is the thing that development teams need to look at.
Hey, we need education. We know we need to get better at security. How do we do it?
Here's three different types that are available. Next I want to talk about getting security up to the speed of DevOps. And usually I'll ask people in the room, Hey, how often do you release?
And I presented this live recently and the general answer I get is, you know, two weeks or three weeks and how often you release drives the rhythm for everything else you do. And for DevSecOps, that means it needs to include security. So the question becomes how does security fit into that release schedule?
And we started the conversation earlier with metrics. Alright, so now what does security need to do? If you were to speak to a vendor like my company, these are some of the answers you'd get.
And these are really good questions to ask in comparing tools during a purchase cycle. They're good for internal requirements building, can this tool do these things for me? And you should ask these questions.
You know, these are all methods of reducing developer toil. Very important, right? Because in the end, you don't wanna buy a junkie tool.
But do these questions get you to DevSecOps? No. 'cause again, DevSecOps, it's people, processes, and then tools.
So when you think about speed, you need to think about it from a DevOps perspective, right? What's the business goal? What's gonna drive value?
And the business goal of DevSecOps is to quickly deliver secure features and applications. I I want you to take a second and think about how important this is, right? 77, and this is all some survey data that we've put out there, but 77% of CISO say that at least 50% of their organization's revenue runs on application for the responsibility for protecting.
91% of organizations have deployed known vulnerable code into production to meet deadlines. And 92% of organizations have had at least one breach as a result of a vulnerable application they deployed, right? So revenue's coming in through your AppSec, everyone's deploying known vulnerable code and everyone is getting breached.
So the question becomes, if you grind through your DevOps processes, you release an app quickly and it gets breached, maybe your company gets fined, there's brand reputation damage and you need to maybe take an app offline for a big emergency patch session. So the question is, did DevOps work and was it actually fast or was it just fast in the moment? And I think we know the answer to that, right?
Remember the original agile manifesto was about responding to business needs, and did the business need that breach? No, it needed a secure application. So then what really is speed?
It's how quickly you as a team solve problems. It's about meeting time to re remediation. It's about training developers to understand risk and about training security teams to understand how they contribute to develop our velocity, right?
It's training and its culture. It's about redefining high performing code as secure code where the biggest risks have already been mitigated. And if your organization doesn't believe this, it's never gonna do DevSecOps.
Everyone needs to be on board with everyone else's needs and that of the business as a whole. I'm gonna talk about automation last because you just can't do it very well without everything else coming together from a culture perspective, right? But everyone's got their own role to play.
Everyone's got their own little bits and pieces and we know that automation is absolutely what you need to get to, right? If you wanna reduce friction with security teams, everyone has to be going in the same direction. And again, this is the coming together of very different cultures we've been talking about this entire time.
But in the end, they're both primarily interested in what's best for the business. So the point to get to automation is to get them both thinking about what's best for the business in the same way. So let's talk about nation, but first some survey data.
We asked our group of CISO where they were putting their security controls and you can see some red flags here, right? Raining, not a lot going on there. Uh, go live also pretty low.
So we know we as an industry need to do a better job of folding that into AppSec, but there is this reasonable bulge in the middle of our data that's around code, build, test, and deploy. It's a good place to start with automation. And the question is what's possible?
And if we line up potential automations with the SDLC like I've done here, we get lots of options. And I'll leave you all afterwards to take a look at this slide. I'm sure the slides will be distributed.
Um, I'm gonna pick a few, uh, I'm gonna pick one from each section here just to talk about examples. Um, so the first in in training is security tickets, right? Um, that's security tickets being auto-populated with remediation guidance.
This is something I talked about earlier when I was talking about education, right? And that is, it's a basic automation. Your tools can do it.
Basically everyone out on the market has some form of remediation, guidance, guidance. We think ours is the best, but you know, it's my job to say that. Um, but just getting developers right away in a ticket in their IDE, here's your vulnerability and here's how to fix it, that's a great help.
That's an automation right there. Next, uh, in design phase, secure by default pipeline templates. And honestly, this is just like standardizing your build, right?
So if you do the security work back, then you get to reduce developer toil on security fixes later. If everything you're working for has been hardened to begin with, if I go to this third section, I wanna talk about fast lanes for a second, they're super aspirational and they happen when security teams and DevOps teams are really, really tightly aligned. It's about trust in one another and in your tools.
So this is essentially, um, an automatic approval to deploy to production from a security scan, right? So essentially what you've got is you've got different dev teams and that work a different applications. And when you get to a certain level of, Hey, I, we built out this code, we've got no high or no critical vulnerabilities, rather than saying this has to go through all of your security processes, you can, you just get the okay to deploy, right?
So if you're looking at, if you know it, it's essentially about removing humans from the loop as much as possible, right? You've looked at your results, you're feeling confident, why not take an auto approval, right? If you get the the scan, again, no highs, handful of new mediums, just deploy it automatically get there, and you can set different levels of fast lanes as you go.
Um, and it takes really strong governance and cooperation efforts between security and development teams. But the more that you're able to set these up, the more that you're able to, uh, allow developers to kind of get things out into production as quickly as possible and have the security team feel confident about what's been going on. The question is next, alright, we've talked about what can be automated, what can't remediation.
You're not gonna let an outside vendor change your code. You're not gonna let a, you know, AI automatically remediate your stuff. Yet there are limits to automation.
So if there are limits, especially around remediation, what can we do to make remediation as fast as possible for developers? All right? It looks a lot like what we've been talking about just in time training, trusted scanning, gen ai, remediation guidance, noise production and security, uh, champions and mentors, right?
All these sorts of cultural things and these tool things, they all come together and it's about getting developers the most information, um, that they can get. And that last thing on there, I, I know I mentioned it only briefly, security champions, that's like its own talk entirely. Um, but if you do automation and training correctly, you can actually free up developer resources for this sort of team, right?
So imagine having the floating team of developers and security people who keep an eye on the metrics, they know, hey, this team over here is having trouble, their applications are the most risky, consistently what's going on? Send in that team to do training, to do mentorship, right? Help them, uh, for extra remediation, you know, and big loads of coding.
Really get them in there and help. And I highly recommend you look into security champion programs. There's a lot of other information out there, but I think it's an important part of the culture.
I wanna end with a slide that I usually put at the beginning, and that's because you all know everyone who's watching this, you know, you're all a part of this, this evolution of application development. Everything about your job is changing year after year. And I would say that you have an opportunity right now to think more about security, to work with AppSec teams, to build DevSecOps pipelines.
Because as you look at this, if your business doesn't already demand it, with everything that's happening in your applications, your business is gonna demand it pretty soon. So what I urge you to do is take some of today's keys concepts back to your organization. Think about how you would do your job differently if everyone believed that high performing code was secure code.
If everyone believed AppSec tools were developer tools that must be part of their workflow. And if DevSecOps was a culture problem that your organization needed to solve, because it does. So thank you all so much for your time today.
I appreciate it very much and have a great rest of your day.