Techstrong TV – February 4, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Look Woody as far as the eye can see. It's the great American firewall you're watching. Text On Gang.
Hi everyone. Happy Tuesday. It's Alan Shimel here for the Techstrong Gang.
You know, we're running, we're running lean, mean, and lean here on this Tuesday. I've just got two other gang members with me today. So we've got a bunch of people flying and trains, planes and automobiles, but couldn't think of two better people to do this with.
Let me first go to our steady Eddie in Hudson, Ohio. He is the founder and, uh, president, or CEO whatever. He's the man who breeds life into tech field day every day, and he is also a great gang member.
Stephen Foskett. Steven, welcome to the show. How are you?
I'm pretty good. Um, I prefer galactic dictator. Uh, that would be a good title for me.
We already have one of those, I thought. Okay. Or, Or maybe Alan Shimel understudy after last Week's good activity.
Yeah, that's right. You know, I saw there was a little insert into the, uh, program for the gang, right? Tonight playing the role of Shiel is FoST.
Um, funny stuff. Stephen, welcome and thanks for being here. Um, joining.
Steven and I live in our Boca Raton headquarters. She's our sustainability Echo Insights, and she has a report coming out soon, but we'll talk more about that in the days and weeks ahead, our own. Bonnie Schneider.
Hi, Bonnie. How are you? I'm doing well, Alan.
Thanks for having me. And I'm looking forward to talking about that. We, We call that a tease.
Yes, Those are good tease. Okay. Uh, so guys, let's just jump right into things here.
You know, I led off with this great American firewall. It's funny, uh, you know, a little bit of competition and all of a sudden everybody's putting up, not everybody, but a lot of folks even in Silicon Valley, where we, I would think we would know better are, are calling for the government to help them. And, you know, those are the nine most popular words, right?
I'm from the government. I'm here to help for government help in keeping out, uh, AI products, AI technologies that's not here in the us. And, you know, we want to keep out content.
We want to keep out students, we wanna keep out, we wanna keep out a lot of people, a lot of ideas, a lot of technology keep out. Seems to be the key phrase here, Steven. I don't know.
Just these things never run well, but what do you think? Yeah, I think they, they don't end well. Um, you know, walls have a tendency of trapping you in just as effectively or maybe more effectively than they do to trap people out.
Uh, it's sort of a truism that, uh, you know, you're more likely to be stymied by your own lock than somebody else be stymied by it. But the interesting thing with regard specifically to AI is that the more that they've tried to track, track down on China's access to American technology around ai, the more that the, uh, Chinese researchers have figured out ways of getting around it, whether that's making the most of the H 800 and then the H 20, or whether it's figuring out, uh, optimizations for training. And, uh, you know, I would say that the Biden administration's policies on toward China are the direct cause of deep seek mania that we lived through last week.
And frankly, if there's more great, uh, controls, uh, placed on access to technology, it's likely that, uh, it will divide the industry even further. And we'll see China have even more, um, homegrown, uh, development technical developments. Now, it is important to point out that their technical development is not entirely homegrown, as we've learned since the announcement of deep seek it leveraged.
Uh, it could not exist, not leverage. It literally could not have been done without literally all of the previous work of developing AI models and without literally using the AI models that had been exported. So maybe if those had been controlled, they couldn't have done it, but I'm not really sure how well those controls might work.
And frankly, uh, not to sound too much like a libertarian here, but maybe if we allowed more people more access to stuff and had a a, a more free market, it would prevent, uh, strange market distortions like we're seeing. Yeah, I think that's true as well. I think also there can be more of a balance between, uh, protecting intellectual property and also, you know, maybe not the extreme, like Steven was saying, that with a wall there comes consequences.
But, um, having a, a little more guidance when it comes to intellectual property theft, which tends to lead to this on a larger scale, uh, particularly from China, I think that's an important thing to note. Yep. You know, Steven, a smart man I know once told me, when you build a wall like that, it tends, tends to keep you in and not stuff out.
And I think that's what we are guilty of here. Um, look, we, we've discussed this in past gangs. The irony of, of, of OpenAI claiming deep seek used their, you know, scraped their information without permission from a company that scraped the internet and their entire being was used without permission is, is pretty ironic.
But at the end of the day, I, I'm not necessarily a libertarian either, but, but Stephen, I, I have to agree with you. I think this is a case where if you put it out there and we're all better off, we're all better off as humans as a result of it. Now that being said, there's gotta be rules.
There's gotta be rules you play by in terms of theft of IP and respecting ip. And, and certainly the Chinese over the years have been guilty of, of stealing IP and using it, whether it's espionage or, you know, state sponsored espionage or commercial espionage or just pure theft. Mm-hmm.
Um, and you need to put safeguards in place there. You need to deal with that. I don't, you know, I'm not saying go put tariffs on them for it, but, um, but you need to, people need to respect the, the, the, the rules of the game and then let the winners come where they may be.
Um, but I just think it is such a bad idea, such a bad idea to be thinking about building a, an American firewall where we're gonna try to keep others out, keep our technology to ourselves. It, it, you know, it, it just doesn't end well. I'm sorry.
Yeah. And I think it's contradicts the open source transparency. It's almost like you wanna have it both ways.
It, It contradicts, you know, whether you agree with the libertarian philosophy or not, there is something to be said about the power of a free market to, to foster innovation. And, and you know, what you got here was a great example of, and, and I wrote this in an article two weeks already. Now go, you know, necessity's the mother of invention.
If you don't give people access to this, they'll figure out how to, you know, I'm reminded of Star Wars when Obiwan tells doth he could strike him down, but he'll be stronger than he ever was. And, and that's what you get here. Let, let's not be Darth Vader.
Yeah. We don't wanna be Darth Vader. And, and, you know, so, so earlier I was channeling the, the libertarian mindset.
I don't wanna sound too protectionist, but I I can actually see a case to be made though that there should be controls on applications and access to, uh, certain applications. I mean, you know, the flip side of a free market is that the government's role should be in interest in maintaining, uh, freedom and fairness in those markets. And so, for example, anti-dumping laws make a lot of sense.
Like we shouldn't allow, uh, a, you know, AI model from some country to be introduced, um, with, uh, massive government subsidies or something so that it undercuts competition and cuts off competition. We also shouldn't allow free access. And, and, and, you know, no one, uh, not the Chinese, but not the Americans either should be breaking copyright controls and ignoring robots text and slurping up, uh, literally, uh, libraries full of copyrighted works in order to build their models.
Nobody should be allowed to do that, because that breaks the free market too. I think that that's one of those things where people forget that, you know, with, with freedom comes responsibility. I'm not Spider-Man's uncle, but, uh, you know, something like that.
You know, if, if we're gonna have a free market, we also need to have very strong control, uh, and, and responsibility, uh, to make sure that we're actually, uh, playing fairly. A free market requires fairness. And so in my mind, the government ultimately should be interested in promoting fairness and democracy and freedom along with promoting capitalism.
And that's an issue with the new administration. They seem to be very interested in capitalism, but not very interested in promoting, uh, fairness in the market. Agreed.
Agreed. Well, you know, and unfortunately, uh, you mentioned the, the Biden administration, Steven was, I think, very guilty of, of squeezing it so hard that they let the sand run through their fingers. I, that might be child's play compared to what we see over the next four years in this.
Um, and I, you know, I, I fear we are going to just be putting up walls. I mean, this, this is an administration who ran on walls, They love walls, walls, tariffs, and are just financial walls. Yeah.
So, we'll, we'll hope for the best. Mm-hmm. I guess, and prepare for the worst as well.
Because the other thing is you put up a wall and you, you know, because you wanna keep out, let's say in this case, China, well, what about some of our so-called allies or the, they were our allies. I don't know how much longer they'll be our allies, but, um, you know, we need that global collaboration. We, you can't exist in isolation like this.
This is a lesson of history that, you know, and you don't learn the lessons of history you do to repeat them. So anyway, we're gonna take a break. You know, I'm the Pink Floyd song, you know, about the Walls, um, was a great album.
Did I ever say I saw them in Nassau Coliseum? S oh, Nassau cos I guess it was maybe 1980, maybe. Something like that.
Or the wall tour. Yeah. It's teared down the wall.
Anyway. All right. You're watching Textron Gang.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching it leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Well, here's our surprise for the day. The DOJ is actually suing to block a merger, uh, $14 billion, uh, HPE takeover of Juniper Networks, which I thought was long done, but evidently not.
Steven, this doesn't, this doesn't sound like, was this a leftover from the last administration? What, what do you think? Yeah, it definitely is a leftover from the last administration.
Um, we actually covered this on the gestalt it rundown, uh, just before, uh, the handover of power when it was originally announced. And, um, I suggested at that time that maybe this might change, uh, under the new administration or maybe not since. Uh, I was also wondering if maybe they might keep Lena Khan.
They didn't spoiler alert. Um, but they did, they do seem to have, uh, some of the same antipathy toward Silicon Valley companies and, and so on. So what my suggestion at that point was, you know, it's not a sure thing that the DOJ would drop this case, and sure enough, they haven't.
They've proceeded with it. Now, I don't want to say that it's, I don't want definitely going to proceed now. They have proceeded with it.
Uh, but I, I wonder too, this could be something of a leftover or some momentum in the court system or, or some, uh, remaining Biden administration, DOJ folks who are continuing on with their goals and their mission and their project in hopes that it won't be shut down by the new administration. Um, but regardless of the politics of the thing, I think that it's also important to consider the implications here. Um, we were, you essentially, we have a few remaining enterprise it, uh, juggernauts, you know, we've got Dell and HPE who are extremely strong and, you know, kind of a full platform, uh, partners for the enterprise along with Lenovo, uh, as a key, uh, full platform partner as well.
And then we've got a lot of these, uh, monoliths that are extremely strong in their area. So you look at companies like Juniper or, uh, NetApp and Pure Storage and vast data in the, in the storage space. Um, but in the networking space, you know, Juniper really does stand alone as a interesting and very successful, uh, competitor.
I guess you could put Arista in that market as well in that. But Juniper, I think has, has been able to really find incredible success in, uh, a couple of verticals. Basically, internet routing is switching, and now thanks to the Mist acquisition, uh, enterprise wifi, to the extent that HPE, which, uh, owns the Aruba wifi assets and has been very successful with that, has been gunning for Juniper and Mist with their Beat Mist campaign for a while.
Now, Cisco, uh, remains by far the leader in some of these markets, but Juniper is a very, very strong competitor. And HPE in many cases is the third player in those markets. Um, and so having HPE acquire Juniper really is sort of a consolidation of, uh, you know, kind of the number two, number three in many markets into a very, very strong number two in those markets and would according to the DOJ stifle competition.
So, you know, if we look at the, the acquisition from that perspective, I can absolutely see why the DOJ might be interested, but frankly, I can't understand why the Trump administration would be interested, because these are very, um, kind of below the radar companies. Even HPEI, I can't imagine, has much of a seat at the table in this new administration. So let me, let me expand on that and excuse me for being snarly cynical, someone didn't, that's What do we expect, Right?
Someone didn't pay their million dollars for the inauguration ball fee. Mm-hmm. And if someone does come over there to kiss a ring, this deal will be allowed to go through.
That's my 2 cents. But to your point, Steven, you're right. The network, and I think this, this deal is not just IT enterprise IT infrastructure per se, you know, meaning servers and, and some of the things that Dell, HP and Lenovo do, but this is very specific to networking and wireless networking and, and the market isn't what it was, right?
You still have Cisco, who's the 800 pound gorilla, but when we talk about networking, especially high speed networking and stuff, you know, where there's a big money, big dollar boxes. Steven, you left our Broadcom. Well, that's true.
And, and because I was really focusing on the wireless sort of traditional enterprise market right now in the cloud market, Broadcom is the massive gorilla because they are basically the, the OEM to the stars for all of that market. Um, they, they do a tremendous, tremendous amount of business there. And of course, they also are the developers.
They're sort of the quote intel inside for most of the rest of the market as well. Uh, yeah, absolutely. Broadcom is a company that, uh, ought to be as below the radar as they possibly could to keep, uh, any DOJ interest.
Well, Especially not being US based, right? But, yeah. Well, I think Broadcom is technically a US based company, aren't they?
I'll, I'll look it up, but I, but you're right. I mean, Antonio Neri definitely should get on a plane to Mar-a-Lago and, uh, and bring a suitcase full of money. And I bet that this, uh, particular one will go away.
They always Say to bring a suitcase full of only to Florida. Remember, you are to Florida brings in case someone. But, But yeah.
So when you look and, and the other thing is, you know, I, I grew up, if you will, in the internet age, from a career point of view, right? Most of my career, well, a good chunk of my career has been spent in the, with the internet and Juniper. Yeah.
Juniper represented the fresh, bright, you know, next, uh, next gen networking, if you will, right? I look security, they bought the net screen firewalls and that that was the hottest stuff out there. They were the first ones that really hit Cisco Square in the nose with high speed routing and, and that kind of thing.
And They've been very successful with that. Yes, they have. And they always were.
But over the last five to seven years, you know, they, they fell on some harder times. I I, they didn't though they were big in, in being the internet network of a gear of choice. They didn't catch the cloud wave quick enough.
And, and Broadcom did eat their lunch there. Um, you know, Cisco is Cisco HP Pro Curve, and then they bought, as you said, Aruba and, and all of that. They, they, they've kept their niche, though.
You know, it's funny, I was just talking to Fernando Montenegro, the new, uh, Futurum analyst for security who used to work at Pro Curve back in the early two thousands. And we were talking about what an opportunity squandered there. They could have been a strong number two to Cisco, right?
And who knows what Juniper or Broadcom would've done had there been a, a more powerful or more well, you know, strategized, uh, pro curve. But, um, well, it's interesting. Go ahead.
Yeah, I mean, HP and HPE, uh, have a long history of attempting to become, uh, a competitor for Cisco. I mean, I worked for Threecom many years ago. Sure.
They bought them too. And, And so certainly there have been many, many attempts by hp Yeah. To, uh, to be active in that market.
And this, this latest one, uh, you know, Juniper would give them, uh, really a solid foundation. Um, that being said, yeah, I, I, I don't want to predict whether the, it really would like an HP plus Juniper really would, uh, end up becoming a, a, you know, a a, a strong kind of two horse race instead of, uh, a one horse race and a bunch of, uh, competitors. Um, and then on the Broadcom side, by the way, I can confirm Broadcom is a hundred percent an American company and always has been.
So, um, they just, their CEO lives in Singapore. Well, he is from Malaysia, but he, I think he lives here, doesn't he? Um, well, that's another topic anyway, but, uh, but Htan, uh, you know, I mean, he, he's, uh, incredibly, incredibly sharp guy.
And, um, I think he's been sharp enough to, uh, yeah, stay below the, below the radar. 'cause I think, I think if he, even if you ask tech people, I mean, here we are on the Textron Gang, and we have some con confusion about Broadcom and so on. They're the number, probably the number one company in, in tech in terms of, uh, importance of their products.
And, um, and like you said, I mean, especially when you look at their, you know, the, the depth and breadth of their networking capabilities and talent and products, they're everywhere. And yet, you know, many in tech, I think would kind of overlook and forget to even mention them. And I do wanna make sure that we point out Arista is another incredibly strong, uh, powerhouse in networking at, they're in wifi, they're in security, they're in, you know, enterprise and, and campus switching.
I mean, they're, they're all over the place. You know, we're seeing a game of musical chairs. That's kinda what I was alluding to at the beginning here.
I think Juniper felt that they needed a chair now, and HPE provided that chair. So it's in Juniper's interest to make this acquisition go forward. I think when Juniper sits down with HPE, which I do think they will, I think it's gonna go through, I'm, I'm not super worried that this thing won't happen.
I think when that happens, um, we're gonna see attention turning toward Arista and Pure Storage and NetApp and some of these other competitors and figure out, okay, where's your chair? And that could be an interesting 2025. Absolutely.
Steven, we'll end this segment with this. I agree with you. I think ultimately this deal gets done.
DOJ job set, whether it's someone goes to Florida with whatever, or, or something else, this deal gets done and We'll update it on, On the gang. We'll keep you posted. Yeah.
Lemme lemme Tell you, Trump Presidential Library is gonna be the Taj Mahal. 'cause remember, they're not all this money. You say what you want.
All this money is not going to Trump. It's going to Trump's presidential library. Oh.
And, uh, yeah, exactly. You know, and that is words, the day they put him in the ground, his children will be fighting over every cent of it, and none of it'll go there. It's gonna be like succession.
Exactly. That's exactly what this could be. Anyway, let's take, Steven, you're making me, we, we need a balance.
We're gonna take a break here on Text Organic. We'll be back with a, a special report from Bonnie on Sustainable technology for the DOD. I'm Bonnie Schneider, sustainability contributor to the Techstrong Group.
I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong Research.
One, welcome back to the Techron Gang. Earlier we were talking about a, a lawsuit, whether it's going to be, whether it was left over from the last administration. What's gonna happen with this administration?
Well, our next story is also sort of related to the changes in the administration. I'll tell you why. Because late last year, the Department of Defense began testing sustainable materials in weapon cleaning, um, in efficiency in buildings.
And that policy was successful. So now they're looking to expand it across military operations. Now, that was the end of last year before the new administration, but we'll see.
It could be something that's carried over. So I wanted to take a closer look at the technology behind sustainability in the military. Hi everyone, I'm Bonnie Schneider with your Ecotech Analyst Insights.
What does soybean oil, LED lights and a bio-based weapon cleaner have in common? They're part of a new US Department of Defense program to test and deploy sustainable technology. How is this implemented?
Well, one example is found with a weapon cleaner made from agricultural materials instead of petroleum. When tested by Marine Corp shooting teams, the cleaner reportedly cut maintenance time in half from 60 minutes to 30 minutes per weapon and reduced carbon buildup by 30%. Based on these results, the military issued its first sustainable materials requirement for tactical equipment.
All weapon cleaners must contain a minimum of 30% bio-based content. Other eco-friendly measures include smart controls for lighting and heating for military buildings to reduce power use. The Department of Defense is expanding the sustainability program across major commands, focusing on technologies that meet performance requirements and supply chain metrics.
You know, a lot of these things just seem like common sense of being more energy efficient in buildings, for example. That's something people are doing across the board, but the, the biodegradable weapon cleaners, um, maybe there'll be some objection to that. But overall, from, from what I've seen, the, the members of the DOD that, that are involved in this project, were very pleased with the outcomes.
And the people that were using the weapons also were pleased with the results they were getting. Steven, thoughts? Well, let's, let's get a little bit of context in here as I love to do.
So, first off, the bio preferred program was from the, actually the Department of Agriculture, and came out of the 2002 Farm Bill, 2002, not 22. Uh, and so the idea that the federal government would be investing in bio-based products is not new and is actually pretty entrenched. Unfortunately, from what I've seen, a lot of that has been somewhat controversial in whether or not those bio-based products are actually all that good for the environment.
I mean, if you think about the controversy over bio, uh, diesel and, um, ethanol based fuels for vehicles and so on, in, in many cases, those things may not be as good for the environment as, as we would hope. Now, having this extend to the DOD and, uh, to certain programs like, you know, weapons cleaners. Sure.
Uh, if the product is good, and it sounds like this product, uh, as Bonnie pointed out in the story, is a pretty good product. I can't imagine that people wouldn't want to use it. In fact, uh, I did a little research on this thing, and it looks like, uh, uh, home gun enthusiasts, yes, we have those in America, uh, for our international listeners.
Uh, they like this product too. So in that case, I imagine that this would probably take off if the thing works and is affordable and, uh, you know, is, is a good product. Um, same with, you know, smart lighting.
Uh, you know, smart lighting is not in, in itself a controversial topic, especially when, as you look at the statistics here, it says that, uh, 10% of the electricity used on military bases is for exterior lighting. Uh, yeah. How about some smart lighting?
That seems like a good idea, but at the same time, I'm just a little nervous that somebody in this current new administration is gonna get wind of something, something bio, something, something. Yeah. Or climate Climate.
Mm-hmm. And that they're gonna squash this thing down right quick. I mean, Trump has already talked about how much he hates LED light bulbs and low flow showers and electric cars.
So, No, it, it's true. It's true. This is gonna be one to watch, I think, um, going forward.
Let, let's not kid ourselves, they're gonna say, this is some walk b******t and try to get rid of it. Right? And that's unfortunately the current state of affairs in this country.
Um, they've already, they, they will purge it from the website as they're purging all of the research and stuff being done. I was Shocked to find that. It's still on the website, by the way.
I looked it Up and I was like, oh my gosh, gov, this is gonna go out in an anti woke kind of thing, and Somebody's gonna hear about it on this show. You're right. And they're gonna call Pete hea.
You know, this is, look, elections have consequences. Well, you know what, at least in, in the, in the shorter term, um, as Steven's pointing out, there's awareness about it. Um, if home enthusiasts are finding it effective, it will gain, gain awareness and maybe gain some traction.
Um, there were some, I would say, controversial aspects of it, because we're talking about smart lighting and some of the testing is done with night vision. And I think that that's gonna be hard to measure, especially in the case of, you know, a serious emergency, um, where I could see, you know, both sides coming out, you know, with, with viewpoints on it. But as of now, in early 2025, this program still, in fact, Look, when the official policy of the government is, is that climate change isn't real when you're not allowed to mention any of these types of, of clean energy and drill.
Baby drill is the motto. You're kidding yourself. Okay, let's end on a positive note.
Okay. How about a positive note? I'll give you a positive note.
As I've said about solar panels, the same is true about LED lighting. The same is true about some bio-based materials. The same is true about batteries and electric cars.
It, when the horse is outta the barn, when, um, when wind power is a, uh, effective and, uh, money generating industry across the world, you're not gonna be able to squash that just because you don't like some aspect of that. If, if, if the product works, it's gonna get used because that's how things go Across the world. That's great fear within the confines of our walled environment, who knows?
But I hope so, Steven, um, I think that's gonna wrap up our tech strong gang for this beautiful Tuesday. We'll be back tomorrow Wednesday with more fresh, good stuff to talk about. Lot going on in tech.
Yeah. Uh, we're coming into conference season as well, so we'll, we'll get some updates there. But until then, Steven, thanks.
Well, Steven, when's the next tech field day? Well, we are looking at, um, we're gonna be at Cisco live in Amsterdam, and we are also, uh, getting ready for Cloud Field Day, and both of those are happening here in February. com for more information on those.
Great, Fantastic. All until tomorrow, then. This is Alan Shimel for Textron Gang.
On behalf of Steven and Bonnie, thanks for joining us. As usual, we've got a full Textron TV lineup following this, so do stay tuned for that. But until then, we're out.
This is Textron tv. Hey, everyone. We're back here on Techron tv.
You know, I'm excited to have this next gentleman on. He is the founder and chief Innovation Officer at a, a company called Axio that you may not know about, but you're going to, if you listen in here. Let me introduce you to Baam Aldi.
Uh, BAAM. Welcome to Text Drunk tv. How are you?
I'm doing well. A thank you for having me on today. I appreciate it.
It's a pleasure, man. So, BAAM, as I said, we're going to get into ax, we'll introduce it to the audience and they'll find out all about it. But I wanted to spend a minute or two talking about you.
Right? Uh, what did you do before you founded Ax Yard, before you Chief Innovation Officer here? Give us a sense of your journey.
Yeah, so, uh, always my journey's always been within security. You know, it's, it's what I enjoyed. It's where I like, started in the, kind of, in the biometric field, uh, with biometric authentication.
Uh, and then really had an, an amazing opportunity to work on a couple of the biggest and most complex programs global, uh, which is the, uh, department of Defense Common Access card, uh, the US government, uh, PIV card, right under the, uh, under HSPD 12 directive from the, from the president at the time. Uh, and really those, uh, were a big turning point in my career and learning what proper global real security truly meant. I remember those days, you know, back back, one of the companies I co-founders was called, still Secure.
We did a lot of business with, uh, DOD Tech, Def, the agencies and so forth. I, and we, we did what they had a nac, if you remember back mm-hmm. In those days, network access control.
Mm-hmm. You get a call one day that, uh, if we could detect if the USB ports on laptops have been disabled, you know, using n tests, we could detect that pretty easily, but why would you want to disable all your USB ports? Don't worry about that.
We just wanna make sure they're disabled. And, uh, of course, later we found out, out, you know mm-hmm. Chinese had, of course put USB, uh, you know, uh, plugs in the parking lot and people were just plugging them in.
Mm-hmm. But it was around that time that the cards came out, right. That you couldn't log in to just any, any, you know, DOD laptop without your, your identity card.
And it, it was a huge deal. It was a huge deal. That's a huge deal, right?
It kinda was game changing in some ways. Um, so you, you were doing that, and I guess that kind of introduced you to the whole world of identity and access management, huh? Absolutely.
Absolutely. And, and it was, uh, it was interesting, right? Because, you know, working on, on, on global pros like that and had the opportunity to work on other global programs in Europe and in Asia, what was interesting is those were all, uh, government funded, right?
So, um, before starting axed, right? What was brewing is in, in my head, is this is amazing what, uh, what these programs do and how they secure, how they secure the nation, but how does enterprise tackle this? Really, that was the brewing question.
And why does enterprise do something like this? Right? And it came down to really two really simple cornerstones.
One, no one has the, the, the massive budget to spend. That's one. And even if you go to, you know, the Fortune 500, the global, uh, 2000, which could spend a, a significant amount of funds, they don't have the personnel, uh, to lead this, right?
From an experience perspective, uh, from a global presence, right? So it, these two challenges were the heart of why organizations can't do this at a pretty large scale. And I'm talking 20 years ago, right?
So that the, you know, going back in time now, things have evolved a lot with, uh, with a lot of the cloud computing and a lot. But 20, 25 years ago, uh, that was a big hurdle, uh, for organizations. Absolutely.
And, um, look, it is interesting that just the interview before this, I was talking to someone who did a, the part of a, a report. Only 37% of companies are using multifactor Yeah. Right?
And, and again, it comes down to two really simple thing, uh, you know, complexity and costs, right? So when I started Axio, we, we had a simple goal, or a simple vision that we wanted to achieve, which is we wanna make identity security simple, effective, and real right? Now, easier said than done.
When we, when we started this journey, and, and we looked at it and we're like, well, how are we gonna make this happen? How are we gonna take these complex global program, make them turnkey and simple for the enterprise to be able to deploy and digest? Uh, and again, I'm going back almost 15 years ago, uh, the challenge was big, uh, and we looked at how can we do that?
And we, we, we innovated in a way, um, where we are able to miniaturize these kind of similar kind of programs or similar concepts, leveraging best practice, the same security standards, uh, leverage the same security protocols, right? As, as the DOD and the federal government did. And now we have a turnkey simple platform for organizations to be able to do this on a global scale.
But back to your original question, if we look at from kind of a password perspective, uh, passwords are, are, are free, like a puppy, right? Uh, you know, you deploy passwords and, and you're like, well, it doesn't cost me anything, right? It's, it's, uh, I just tell my users to select their password and, and, and then they, then they go off on their way.
But the, the cost element to it, and then we'll get to the security and vulnerability, but just the cost element of it, you know, if you're doing it, you have to increase password complexity. You have to force your users to change the password over time. You need password reset tools, your, your overloading, your, um, uh, your help desk with, with all this password management.
And then, you know, you, you talked about the percentage that are still doing password. I'm curious, uh, from your last, uh, interview, how many are doing MFA, Right? No, they said 37% responded that they are, so 63, not so, look, I, I've been saying this for a long time, right?
I, I've been a big fan of biometrics for as long as there's been biometrics in security. I, I think passwords. And I've used the password manager forever.
I, I was hacked at Black hat in 2005. I was stupid enough. This is when iPhones automatically connected to wifi networks that had the same SSID they connected to before.
Big mistake, obviously. This is maybe iPhone three, something like that. And I got hacked, and I learned my lesson with passwords, and I've used a password manager ever since, you know, with complex passwords.
But you wanna know the truth, it's still too much of a pain in the butt for people. Mm-hmm. Mm-hmm.
The average person has 150 passwords or more, Or more, more. And you're not allowed to repeat 'em. They can't be similar.
I need a unique one, and I've gotta have a capital and a number and two special characters, but not those special characters. And I gotta change it as, you know, the, the drill besam, we need to move off of passwords. That, that's my personal thing.
We only got 15 minutes here though. I want to bring us back. Talk to me about founding a Yeah.
So as I mentioned, right, we, we, we really looked at that journey and, and, and how can we simplify the authentication journey from both perspectives? One, the organization, how can we make it, uh, how can we make security simple for 'em? Uh, and then from an end user, how do we make it effective?
And, and, and real? What does that effective and real mean? It means the user experience has to be extremely simple From everything from creating your authenticator to using your authenticator to managing the lifecycle of the authenticator.
So if we look at that journey, what Axia does it, it we can provide a, a turnkey platform that allows organizations to let users self-manage that authenticator. Well, what does that authenticator look like? Again, piggybacking off standards from, uh, from what the federal government and the DOD did back in the day based on certificate based authentication, uh, PKI, and then combining that with kind of forward, uh, looking protocols like Fido two, combining the two of 'em really gives you the best world, the best of both worlds.
And making it turnkey in a platform is, is really that criticality Axio can give you that platform. It, it's up and running in less than 45 minutes. You have a dedicated virtual private cloud that has all the necessary elements for you to have that passwordless secure, simple authentication.
So the question becomes, why did we go down this route? You know, as you mentioned, there's, there's no shortage of, uh, of passwords that the user needs to know to authenticate to all these different applications. Password manager was, was the way to go when a lot of these applications were on prem, then when a applications become more web-based, right?
That was the birth of IM identity access management, right? IEM came with a simple promise, right? Authenticate to the IEM and that it will act in a really simple way.
It will act as the SSO, uh, to all these different applications, right? One pathway to rule 'em all. Yeah, exactly.
And I'm really simplifying the, the IEM story. We can sit here and talk about I am for hours, right? Because I am also provides directory services, et cetera, et cetera.
But I just wanna, uh, for the audience, right? I just want to focus on the authentication journey. Uh, a part of I am, so I think I am really helped that story of, okay, I have all these web AppSec, right?
Uh, and I have all these online resources. Now, I, I have a way from my end user to authenticate to the IM and then the IMS acting as the SSO slash broker to all these different applications. So what do we do?
We move the risk from the application. We moved it to the IM the IM became the risk point, right? If I'm an attacker, if I'm a hacker, if I get access to the user's IEM, right?
Guess what? Now I have access to all their applications behind the scenes because I've logged on similar to a password manager. If somebody gets your main password to your password manager, now they have access to all your accounts, right?
And, and, and that, and, and that, that's why we see today with all the different IM all the, the, the hundreds of millions of dollars that are being spent or, or close to over a billion dollars is spent in IM attacks. You still see them, uh, breaches. You still hear about them, uh, and the news is flooded with this information.
Absolutely. You know, and that, look, to be fair, you're right, IAM with the birth of the cloud and prominence of the cloud, IAM became sort of the killer app of cloud security, right? Because we didn't have the remote, we didn't have the perimeter, we didn't have the molten castle kind of, you know, traditional network security stuff.
But like everything else, it, it's been around now a while, and, and we see, we see the gaps mm-hmm. In the coverage, we, we see the issues. So you guys have something new you're calling icam.
Honestly, it's not something new. It's taking a page out of the, you know, what we get back the day from the, from the DOD. What we're, what we're advocating for is, is really focusing on, on going beyond the, the traditional IM story to really start looking at, I I icam.
So what is, what is icam, what is different than icam, uh, um, the, it's identity credential access management. So why the credential? Why does the credential be, be, become a cornerstone for security within the organization?
Now, now you have, if we, if we step back a little bit on the IM journey, right? Uh, as I, I do as an, as an organization, yes, you have all these cloud applications. Everyone thought we, we'd be a hundred percent cloud by now, but that's still not the case.
There's a lot of companies out there that still have legacy applications, whether they're in the financial sector, healthcare, um, aerospace and defense, uh, oil and gas. They still have applications that are still on-prem that still need access for on-prem, and they're not web applications. They're still wi within your, uh, environment.
So you have this still this mix of authentication of some applications on-prem, some cloud. And then on top of that, what we've seen is even deploying MFA, uh, or let's call it traditional multifactor. So like, for example, you know, uh, I'm sure you've, you've used in your career kind of having the one-time password or the, the code that would, you know, on a, whether it's on a, a little token, whether it's on a mobile app, whether you get the SMS or whether you get it through your email, that has proven to unfortunately to be not secure and not because the hacker has to hack the backend, which is protected by, you know, your intrusion detection systems, your wife, your, your VPN, your proxy.
No, by simply phishing the user to provide that information. So MFA is, is losing, is, uh, is effectiveness because hackers have shifted their attack vector from attacking the AppSec directly to really focusing on attacking the user, because phishing, the user is a lot easier and a lot simpler. And with AI helping, uh, you know, with all the AI tools out there to really has made phishing is on the rise at an alarming rate.
I wanna be very clear to everyone that's listening to this. Anything's better than username and password anything, right? But if you are going to deploy something, I think it's important to look at part of your ICAM strategy is how do we move to phishing resistant authentication?
So that phishing resistant authentication is really clear. Um, we're really grateful from organizations like NIST and CISA that clearly define what is phishing resistant, what authenticator, so that there's no ambiguity. So that when you look at, uh, solutions out there and how to protect your organization from these threats, it, there's a, a clear roadmap and, and in a clear definition, uh, uh, I think is the better term of what is phish and resistant authentication.
So from an exit perspective, we really focus on bringing organi, uh, organizations, uh, bringing a simple path from security and usability. We don't believe in, in the perfect intersect between the two. On the contrary, we think both of 'em should run in parallel.
You need maximum security with maximum usability all the time, every time. And we, we use phishing resistant authenticators that are, uh, as defined and approved by CISA and de so that you can have your cake in e to two, uh, authenticate to your local AppSec, authenticate to your cloud AppSec, leverage ICAM standards, and leverage government and military grade standards with really simple way to use it and get rid of passwords completely. I love it.
I love it. Hey, you know what? We didn't tell people though.
How can they contact and, and get on board with Axia? Oh, yeah, absolutely. com, you can go to our website, uh, and there's a lot of great information there.
Um, Ax, IIAD if you were wondering how it's spelled, okay, Yes. Thank you. Thank you.
A I appreciate that. I, I take your for granted sometimes. Uh, obviously because, uh, I, I, I started Xi back in 2010, uh, and, and, and for me, it's, uh, it's, it's like another kid, obviously.
Mm-hmm. I get it. I get it.
You gotta remember though, they're cattle, not pets as someone who's founded a bunch of companies. They're cattles, not pets. com Yes, sir.
And, and people can get started right there. Yeah. com for fishing resistant, please.
When you go there, we have, uh, we focus on a couple of, uh, of products, right? One of 'em is, is really focused around phishing, uh, phishing resistant authentication. com, you can look at it under our conductor type of, uh, uh, conductor product line.
Uh, we also have identity, uh, uh, identity risk, uh, that's under our axed mesh. And Alan, that's for us for another conversation, hopefully one day. Good.
Well, anytime you want, just reach out to us. Baam, we're about outta time. Thank you for joining us today here on Tech Trunk TV and telling us a little bit about icam.
And it was a, I think it was a good, you know, we built and, and built up to it. So it was a good conversation. Best of luck with Axio.
Come back and tell us about identity mesh next time. Sounds like a good one. Absolutely.
Love to. Thank you, Alan Alrightyy. We're gonna take a break here on Text Truck tv.
We've got more coming at you today, so stay tuned. Hi everyone. I'm Alan Shimel and you're watching the Platform Engineering Show.
Let me introduce you to my co-host, where is Luca today, but Luca Gallente. Luca, how are you? I'm good.
And still in Sri Lanka? So I haven't moved Still in Sri Lanka, but a different background. Different background.
Yeah. It's a hotel room. I was hoping there was gonna be a table instead.
I'm like in, in a, like, closet holding the Computer. Okay. Who?
Hell, you know, it's that. It doesn't Well, it's re so you can't see, but, alright. Yeah, we won't make, we won't make you stand too long.
Hopefully. But where are you heading from? Shoot, we'll do a quickly, a little travel update.
A little, A little travel section. Yeah. We should have our own like, travel segment every time.
Right? And then follow Luca. No, so Maldives Maldives for the next three days, and then Japan.
So the next, next time I think we're gonna speak is gonna be from Japan. Very cool. Yeah.
You know, I would like to, I have, that's the place I haven't been to either is Japan. I was thinking about going for the CubeCon there in June. I just don't know.
I've got a lot of travel in May and June. I've got the RSA conference, and then I'm doing a trip to Italy myself, and we'll see. Anyway, let's talk platform engineering though, is what Yep.
It, it's been, you know, we are hearing more and more and more about platform engineering, but what I, what I'm encouraged about is you used to just hear platform engineering, right? It was like this monolith, if you will. It was, it like all encompassing.
But now as we're starting, it's been maturing more, it's more widely accepted in the in market and people are understanding it. We're looking at the different aspects of platform engineering. 'cause it's not a monolith like anything else, when you get up close, you find out there's different pieces of it.
Today we want to talk about MVP, not most valuable player, but, and not minimum viable product, but minimum viable platform. Luca, educate us. What do we mean by that?
Yeah. And, and I think your, your intro was, was spot on, right? Because I think, um, the minimum viable pop, the minimum viable platform framework is a great example of, I think broadly the platform engineering space really maturing, especially in the last 18 to 24 months.
Um, where, you know, we've spoken before about reference architectures and how those have been like a big game changers for the community and the space broadly in terms of really helping people visualize, okay, what does an enterprise grade internal developer platform actually looks like? And, but the issue with that was that then people were, had this kind of like target architecture that they wanted to build, and it's like, okay, let's go build it. And they wanted to build it all at once.
Um, and that's where a lot of teams got stuck. In fact, I would say the majority of platform engineer initiatives that I've seen dying, um, was mostly because of a loss of momentum, right? At the end of the day, we, as we said, right, like platform engineering is very complex org transformation that touches all these different stakeholder groups.
So you need to convince, you know, the app devs and the security teams and the architects and all these people, and you know, you go person A, B, C, D, by the time you got to person Z, person a forgot about you because it's been six months and you know, you, and that's how you lose momentum. And so the media viable platform framework was kind of developed, uh, from the community to, to help with that and to make sure that you followed this minimum viable product, you know, approach. Right?
And this is also, I think, an interesting thing that, that we discussed previously, right? This like idea of platform as a product, as one of the foundation concept, uh, foundational concepts of the, of the platform engineering space. And again, the moment you look at your platform as a product, as an internal product that you're developing, you automatically unlock all these, you know, product management best practices that we've all learned in the last couple of decades.
And one of those is MVP or mini level product, which apply to the platform is just the MV mine level platform. And the idea there is to look at this reference architectures, right? And instead of, um, trying to build everything at once, you really like focus on a subset of, of, um, of, of that reference architectures.
And the idea is to, um, really it carry quickly on it and get the, and keep getting in, you know, more and more buy-in from the stakeholders. So you don't have to focus on all the stakeholders at once. You don't have to focus on all the different sides of your infrastructure, uh, on all the different aspects of your applications.
You just, you know, strategically select, uh, different parts of that and then show value there first and then iterate from there. Excellent. Well, you know, the, the last thing here from, I remember from DevOps as well, when, when DevOps first came on, it was very rare that you'd have sort of an enterprise wide DevOps rollout.
Mm-hmm. I used to say DevOps. DevOps got done in bubbles.
And, and if you've ever seen like soap bubbles or bubbles in the bathroom when you're a kid, maybe not when you're a kid, if you like bubble baths, but you know, you get a lot of little bubbles that when those bubbles come, you know, touch on each other, they become a little bigger. And then, and then eventually you get those big bubbles, right? That you could catch.
It's the same thing when you look at how DevOps spreads in an enterprise. Generally it starts as little bubbles. There's a little project here, little project there, but it's the same thing with minimal minimum viable platform.
An important part of it is momentum, right? No one wants to go with a loser, everybody wants to be with the winner. So if you could build some small wins, you get some wins that people could point to and say, Hey, look, it works.
Hey, look, it, it helped us do that. It made that go faster. It made this more secure.
People want to do, give me some of that. I want some of that good stuff, right? More I want want that.
Yeah. Right. And or more of it.
And, and that, that's how you get buy-in across an enterprise. That's how you get those bubbles. Yeah.
Right. Creating bigger bubbles. Yeah.
And, and I think it's very important also to, you know, figure out what, you know, what is it that people want, right? Um, because like, um, again, if you're trying to make everybody happy, that's really hard, right? So you should really just focus, okay, what are the one or two stakeholder groups that are really crucial for this initial phase to prove value?
And then understand, okay, what did, what do they want? Um, because you know, if I go to developers and talk about like, oh, we're gonna cut time to market with this MVP, they don't care. Um, it's not something that they necessarily think about, right?
But, you know, executives care about that. Um, application developers might care about reducing waiting times, right? And so you just need to understand, okay, what are those two initial like wants and desires that I'm gonna target with this MVP?
Um, and then to your point, create those first bubbles, right? And then go back to them and be like, look at these bubbles. They're great, they're shiny, they, and then they're like, all right, I want more of those.
And that's when you start like adding more and more and more. Um, and that is why, I mean, so just taking a step back, right? Like the MVP framework is a framework because it has like very specific sort of, um, uh, different phases of it, right?
Particularly, it's like four phases. There's like a discovery phase. And this is why I think, um, this discovery phase is so important.
And it is exactly to do what we just said, right? To like really map out what are the desires of people, like what are the challenges that I wanna solve? And again, you know, I think like a lot of people, like a lot of platform teams get stuck in, um, you know, trying to have this like very quantitative, measurable type of things that they want to improve on.
I think especially in the MVP phase, it can really be qualitative, right? We've talked about before, you know, of like, hey, it can literally be like, Hey, you know, person X is spending, you know, 20% of their time on, you know, uh, fielding ticket ops or, you know, uh, we are approximately, it approximately takes us like, you know, a couple weeks Anyway, this like waiting time is just, is really long. It sucks, right?
And, and, and so like that can be the starting point, and then you just go back to the same stakeholder and, and look, look, now you don't have to wait weeks. You can, you know, it's in instant, or you just need to wait like a few minutes or a few hours, right? Like that's already like an insane improvement.
And then from there, you build on top of that and you professionalize it and you get, you know, more, um, you know, more secure in everything. And so this is why that first discovery phase is really, really important. Um, then the second phase is, you know, what, so it's discovery, then integration, which is really, you know, basically, you know, hooking in all the different parts, um, that of, of, of the sub part of your reference architectures that you decided to target with your, with your, um, MVP if you, you know, for people that are familiar with that.
Otherwise, we can also link it somewhere in the show notes. Um, you know, the, the reference architectures have five different planes, right? A developer control plane, which is effectively the front end of your platform and integration delivery plan, which is the backend.
Then you have a resources plane, which is, you know, all the infrastructure that your platform sits on top of. And then you have a security plan and observability plan in most mvp, successful AVPs that I've seen people mostly focused on the first three, right? You need some front end, you need some backend, and you need some resources.
You should keep all those things to a minimum. You probably don't really need, you know, security or observability in the first phase. You can obvi, you obviously need to design with that in mind, but, you know, a first MVP doesn't need to show, you know, ultra secure anything, right?
Because it's just an MVP that's working in dev, like there's no production workloads on it and so on. So, um, and so that's, that's really like the integration phase is about integrating those different pieces that you've kind of like singled out. Then you start deploying your first applications, right?
And, and, and, and you, and, and that's where you see, okay, everything is working. And then number four is the sort of like demo time, right? Um, which is also very, very important because it connects back to phase one where you first went to people and like, Hey, what do you want?
Then you need to now go back to them and it's like, Hey, you know, I actually did what you wanted, right? Uh, or close to it. And that's where the loop, you know, starts the flywheel starts going the Infinity.
Yeah. The magic happens. Yeah.
So, you know, when I hear you describe this Luca, to me, I think one of the most important things, and you know what, it's a lesson I've learned over and over and over again in 35 years of doing back work, the finding success is important. Yeah. And a lot of engineers, I guess it's the way their brain is wired.
They define success exactly the way you said, right? It has to be some metric, some KPI that I measure, right? And it's like I improved, you know, mean time to remediate by 38% or whatever, but sometimes success is, success is a feeling as much as it's a number, right?
So sometimes it's a success is just, Hey, I'm getting more done, I feel like, or my, I've got a better life balance. I've got, you know, there's a lot of ways of defining success. The important thing is that everybody agrees on what the definition of success is, right?
Right. And then when you get to, to stage four and loop back, you can say, okay, this is what we said success was gonna be. Here's, here's the reality.
Right? And do they, do they match up? Um, yeah.
And, and, and this is why I think apart from engineering is so challenging for, for that kind of profile of engineer, right? Is is because mm-hmm. Really, you know, much more of a cultural challenge than a technical challenge.
And the problem is that a lot of times it gets approached as, you know, a 98% technical challenge and maybe like 2% of culture thing like sprinkled on top. And it's really almost the other way around. Like, I've never seen platform engineer or broadly this type of org transformation, um, you know, fail because of a technical, uh, you know, choice of like this technology over desired technology.
It's always because you didn't convince the right people, you didn't get developer. It wasn't a meaning of the minds on what's success. Yeah.
And, and, and, you know, to, to define it. I think another big problem though, and I'm interested in your take on it, Luca, is the m the minimum part. Yeah.
Right? It's like a Goldilocks, sometimes it's too minimum. Sometimes it, that minimum is like a maximum, right?
I think it's important to really, it's gotta be meaningful, right? It can't be trivial, it's gotta be meaningful, but it, it's not supposed to be the whole enchilada. You, you know what I mean?
It, it's minimum. How do you, how do you, you know, balance that? Yeah.
So I think, um, you know, again, if you follow the framework, the idea is that, you know, this, the, the, the MVP needs to be representative, right? And, uh, sort of like repeatable as well, like to your point of the bubbles, right? Mm-hmm.
Um, but you know, it also doesn't have to be a bunch of different things, right? It doesn't have to work for high compliance scenarios. It doesn't have to cover any advanced architecture.
It doesn't have to any sort of like advanced resource configurations, right? And the problem to your point is that, you know, platform teams and engineers have this standard of like sliping things into it, you know, because that, because it's cool, because you never know, you know, and mm-hmm. And at the day, I think it's just like, uh, I've seen, you know, successful platform teams really going through this person almost, you know, the summer I sword fall, uh, folding thing, right?
Where it's just every time you cut it in half again, you know, and you just ask like 10 times, like, are you, you know, are we, do we really need this? You know, do we really need, you know, two different databases for this to be a representative? Do we really need, you know, um, all these different, you know, uh, different policies as code, not, you know, and every time, and it's amazing because even teams that I think like consider themselves like quite frugal in terms of like, you know, picking this like minimum set, um, um, you know, end up like cutting another 50% of fat basically, um, I, uh, by just asking it enough times.
And so I think, I think that's, that's where it's important to either have somebody external, um, as you're going through that have, you know, has experienced doing this or, um, have like a really strong product platform product manager internally that really, you know, keeps asking the same questions over and, and is not, you know, afraid of asking the same question over and over again, even if it's through like very experienced engineers. And it's like, no, but are you really sure? Right?
And then like, really pushing the, the envelope. Absolutely. Um, wanted to ask you about a, a another thing here.
When we talk about minimum, you know, MVP, what, what is the team behind it? You know, like we're, I think we're all familiar with the Amazon two pizza concept, right? If more than two pizzas, it's too big.
Um, Spotify has sort of the squad or whatever it was called, remember what, what's the right size team for a minimum viable platform engagement? Or is it just red, you know, really varies The Right, you mean team? The, the, the P team?
Yeah. Yeah. So I, you know, it definitely varies.
I think on the, depending on the scope. I think for me what's important is not necessarily the size, but that there are different roles, uh, or at least different functions clearly represented within the team, right? So as an example, right?
Um, um, and I can, I, I, we can, we can also throw up this, this, um, sort of like, um, really nice, um, bubble, actually bubble like visualization of, of platform teams and the, the different stakeholders around it. But in general, you have, um, you know, four key functions like the head of platform, the platform product manager, and then what we call, and it's funny because they're, they're really like emerging now as like very defined roles by, uh, by Garner, for example. Um, they are job ads.
They're already, um, having this title, which are infrastructure platform engineer and developer experience, or DevX platform engineer. And the point is, you don't, you don't need, you know, four different people with those four titles. A lot of times, you know, the had platform is doing the product role or the auto or vice versa.
Um, um, and you know, in some cases you just have a platform team of like two or three people. And so like, everybody's like, kind of like covering all bases. In some cases, you know, you have like, uh, apart from team, there are like a hundred people, and then it's not even that you have four different people.
You have have like four different, you know, or like, you have like many different teams and product teams, and each team has like those roles represented one way or the other. So regardless of the scale, the important thing is that there is this, um, I think, um, uh, the, you know, the dysfunctions that interface themselves with the, with the different stakeholders. So, you know, the had platform is really responsible for selling this thing internally, ultimately, right?
And so, uh, getting the executive, is he selling up, down, or both? Yeah. Uh, mostly up, I would say.
Right? And so really likes to, um, but also across to like legal and compliant, like architects to an extent. Um, and then you have, and, and I do think that the, the line between the, the, the handle platform and the platform product manager is quite blurry, right?
But then you have the platform product manager that is, I think, the most important role, right? 'cause it's really about mediating all the different, um, inbound requests slash vested interests of all these different stakeholder groups, right? So you need to, you know, balance all this stuff.
Um, and it's, it's really, I think the, the most critical one and also the, the most in demand role and the hardest to find, um, I think right now in the market. Um, and then you have this like devex and, and infrastructure platform engineer. And I think the, the, the differentiation there is really important to have, again, not necessarily as a title, but at least as an area of focus for different people, um, or even for the same person.
But it needs to be like a very conscious, like, okay, I need to cover both of these things. Why? Because I think a lot of platform teams have this tendency to over-optimize, over index on devex, because ultimately the, the end user of the platform is that application developer.
And so, okay, you know, that's the whole point of the platform. But if you don't connect the, your platform engineer initiative to the, um, you know, to the overall infrastructure and, and you don't sell it to your infrastructure and operations teams, it's, um, doomed, I think, or, um, very, very quickly, right? Um, and, and so that's where it's very important that you have yes, the devex platform engineer that maybe comes from that background to really build a tight feedback loop with developers and, you know, find the right level of obstruction, the right level of con context, the right interface to the platform for developers.
But then it's very, very important that somebody's building, um, together with the infrastructure operations team, the connection of the platform to the, the, the underlying, uh, infrastructure stack, right? Um, and, and, and also that is selling effectively the platform to them, to the INO teams as a way of effectively, hey, this is a vending machine layer, basically, right? For you to provide your infrastructure to the rest of the organization in a much more productive way where, you know, you don't have to fill ticket ops and getting annoyed and everything is like standardized and automated by design, yada, yada, right?
So you, whether you have, you know, different people, 200 people or or two, the important thing is that you're, you know, consciously thinking about those different, You have those roles. Yeah. It's important that those roles are, you know, those are kind of indispensable roles.
Let me ask you a question, Luke, and when you say, you know, dev X or working with developers, it's in today's world, it's not just the guy who's maybe coding, but is, is like, for instance, the QA person, the test person. Mm-hmm. Right?
They have a real stake in this too. 'cause they, they've gotta test all this stuff and hopefully before they deploy it, but, um, you know, but on the platform, nevertheless, so would the, would the dev person also work with like, for instance, QA or security testing or, you know, other people along that CI/CD journey, if you will, who are involved in the pipeline? Yeah.
Or in the factory, right? These are all factory, you know, you think of software as a factory. Yeah.
These are all the people working in the factory. Yeah, absolutely. And I think right now, you know, we're still in the phase where I think software, most of the times, like we spoke about in the first episode is create, is, is, is produced as this, as if you were in this like, um, you know, craftman type of, of, of, of like boutique, you know, uh, thing.
And, um, and, and so I do think as we're getting more industrialized as a, as an industry, then, um, you will, you will lose, uh, touch points. Um, or, or rather, or rather the touch points. You know, we had this like really interesting conversation with, um, with Kelsey at Platform Call 24, where he was, you know, talking about this, like, you know, sellers are a good thing, and all these people got mad.
Um, uh, but the important thing is that you have like a platform layer in between the silos that facilitates that communication whenever it's needed. But the point is, it's not needed all the time, right? Um, and so, and I think that's ultimately what then increases, to your point, the developer experience, and frankly, everyone's experience, right?
Because you don't have to, you just remove all this friction from the system, right? You can, you can like focus on what you do best, what you wanna do, like you want to code, you don't wanna necessarily, you know, spend 30% of your time configuring stuff. Um, and, and so then you can do that.
And then when you need, you know, edge educates or whatever, then you know, you have like off path options, uh, beyond whatever the, the platform normally mediates. Yep. Let me shift gears a little if we can, Luca.
Okay, so let's say we follow the four steps and everyone says, great job, Bravo. Let's, let's, now let's take it to the next level. What comes after MVP?
Um, so the way, the way we, we think about it, um, uh, whether with our products or, or in the community is, is production readiness after that, right? Because really, uh, the MVP is not meant to be production ready, ready, um, so it's really meant to like, basically get everybody, you know, uh, rallied up, you know? And it's like, yes, this is great.
We can totally see the benefit. Let's, you know, let's invest more time, let, let's invest more money. But really more than anything, let's invest more time and resources, right?
Because that's the hardest thing to get in enterprises is not necessarily the, you know, extra money. It's just like, you know, you can invest an extra like, you know, 200 k or whatever, but if you don't have the, the developers we're keying to actually keep working on this, it's not gonna go anywhere as an initiative, right? So, so that's really the main thing.
And so then the, the next phase is really, okay, how do we, and, and again, it's like a very structured kind of like production readiness, uh, checklist basically of like, okay, what are all the things that you now need to make this, uh, first minimum viable platform actually ready? And again, this is, is very important because here again, we're not talking about okay, bring your entire, you know, a software estate or cloud native setup, you know, to production redness. It's, it's again, just like one subset, usually one or two applications with a, a subset of their normal dependencies, but they're now, you know, production, production grade, right?
Um, and that's really where you start getting the traction of like, other teams looking at, ah, okay, they're, you know, that team is actually deploying all the way to production and, you know, it's taking like 30, 40% less. And then that's where you go back to your bubbles of, you know, then you grow from there. Um, and so then from there is, you know, the third phase will basically be production read, is to, you know, sort of like full, full rollout.
Cool. org, right? Free.
You can download them. org. You free to anyone there to download and, and ask questions from and stuff like that.
Speaking of people who have questions, does the community Slack? Yes. org?
I forget, is there a Discord server now too? Or is it just Slack? No, just Slack.
Slack. Just Slack, yeah. Is the way to go.
Yeah. While we're at it, we, we were talking earlier about, um, CubeCon and, and some of the other events coming up. Obviously Platform Con is next June, so we're still maybe six months, five months out of that.
But, uh, the CubeCon for people who want to be involved in the community, you have your, uh, you guys have an event going on, you want to just let people know about it. Yeah, The big party. com.
Um, you know, we, this reference architectures we launched the first time, the, the first talk about them was a platform 1 23 last year, a platform 1 24, already 20 plus percent of all the talks had this Revs architectures as a blueprint. So I'm expecting that to grow even further. org, a repository of all the talks slash articles slash you know, new com community contributions of people that wanna share their reference architectures for their platform.
And so it's starting to grow and it's becoming a really interesting library. So I recommend people checking that out as well. com.
I don't think the, um, design, I think the design is gonna be updated by the time that people listen to this, which is a new, a new branding for the, for the event, which is really cool. Um, it's something that started as a joke, uh, in, in Valencia, um, the Thing Dolphin do. Yeah.
'cause we just wanted to do like a better, a better, more fun party. Um, and it's basically grown to be this like unofficial opening party for Cube Con. We're expecting over 4,000 registrations, uh, for, for the London one.
And we've actually taken out like a proper, proper club. And I can't say who it is, but we have actually, one of our frontend engineers is a very, very, it's a, like, literally globally famous dj, um, that is a, yeah, he's a resident in one of the best Berlin clubs, um, you know, travels every week to like, you know, Mexico, India, whatever. Just plays like big shock.
Um, and he's actually gonna headline, although not with his normal, um, DJ name because he can't use that. Okay. Um, but he, he gonna, he's gonna headline the event.
Um, so, You know, we've, we've been basically saying about, Hey, this is like a techno party and then, you know, every time, because, you know, it's still like a party attached to, to like a working conference. So we always like, you know, like, did it, but not all the way, this way, you know, this time it's long. We're doing it this year, we're going All the way.
It's like a proper warehouse, proper DJs. It's gonna be fun. Very cool.
I'm cut. Yeah. Excellent.
All. Hey Luca, enjoy your last few days there in Sri Lanka. Enjoy the b Thank you Alan.
We'll catch you in Japan. Yeah. Where we'll be folding Summeri.
Exactly. Steel Allen. You'll get steel to make steel right.
com or Apple Podcast, Spotify, wherever. We hope you enjoy it. Subscribe to it.
Until next time, this is Alan Shimel and Luca Ante. We're out. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security Bloggers Network. Hi everybody, and you've joined us today on another episode of the last Great Cloud transformation.
We're happy to be, uh, be doing this series, uh, sponsored by CloudFlare, talking about really the evolution, kind of where we're going next, how the cloud is looks today, but what it's gonna look like tomorrow, what some of the drivers are behind that from the old days of hub and spoke. And just connecting places in our, through our connecting through our suppliers. Um, networks take on a lot of different characteristics today, matter of fact, what we think of as the network as quite a bit different.
So, uh, I'm Mitch Ashley and I am VP and practice lead, uh, at, uh, with one of the analyst areas at, uh, RUM Group. Also have served as CTO with the Taxon group folks that are putting this on. And I have the pleasure of being joined by a couple distinguished, uh, gentlemen here today.
First of all, uh, Dan, do you wanna introduce yourself? Both with CloudFlare, by the way? Dan, go ahead.
Sure, Sure. Thanks. Uh, Mitch, uh, Dan Caner.
I'm the field CTO for CloudFlare, um, supporting, uh, the Americans and in particular folks on public sector. Uh, prior to that I've been a CTO for six years prior to that, uh, focused on mostly around public sector offers and, uh, oms. And then, uh, prior to that I was at, uh, Cisco for 15 years, where our public supported the public sector as airfield CTO.
Great long longevity in this part of the industry, which is perfect for this conversation. Great. Let's next go to Matt.
Matt, introduce, introduce yourself. Yeah, very happy to, uh, nice to be here. Mitch, uh, Matt de Schneider.
I lead our US public sector team, uh, was brought over to CloudFlare about three years ago now to build out the public sector, go to market. Uh, my last 30 years or so in the public sector have led to this coming from service providers, then infrastructure companies over with Dan at Cisco for a long time, uh, into, into software with VMware and, uh, security with Palo Alto before joining, uh, CloudFlare, except about three years ago. So, very excited to be Excellent.
Very good. Well, when we say public sector, uh, Matt, you know, that that is a very big, you were talking about super large 'cause you're talking about everything from the Defense Department to Department of the Interior or what, pick any agency, any department. Um, maybe if you give us your thoughts initially of what some of the, the biggest challenges in modernizing it in these organizations are.
Yeah. As, as you said, public sector is, it's a microcosm of the rest of the industry. So it's everything from manufacturing for elements, you know, with, with our US department of Mint and, and where we would go on everything NSI to finance, to healthcare, to every other element that, so you, so you have, you have the, the same challenges you do in enter enterprise, but you have an increased amount of what, what we, what we unfortunately refer to as technical debt, as these programs continue to build and be ma you know, required to be maintained at a different level than a traditional enterprise mind.
So we get to the environment where government will always be in a state of modernizing. They will never be fully modernized from that footprint. So, um, whether it's, you know, the mainframes that still exist, uh, in so many parts of government today as they do in enterprise right on down to trying to increase citizen services and constituent services, um, you know, they're always gonna be chasing that goal of delivering at the same pace of, of the enterprise out there.
You know, one of the things from my experience in the public sector too, is it's not a solution from one vendor. It's a integrator or, you know, a prime on the contract. And you have a lot of companies coming together that get selected in those deals, uh, for that, which means where do you go for, for kind of support or picking up, uh, pieces of where they were left when that contract was done, what's that like to unravel and untangle that and to kind of figure out what all this is where it came from and how do we move it forward?
Give us a little bit of a thought on that. I'm, I'm interested in your ideas, Dan, you wanna go with that one? Sure.
I'll, I'll go with that one. Yeah. It is interesting.
Uh, one of the differences in, and we're talking really just the federal government right now, uh, because public sector does support, it includes state and local as well as education in most cases. Uh, but in the federal government, those very large programs and, and what differentiates the federal government agencies from commercial and, and there's com a lot of commonality like MAP brought up, uh, oftentimes. So these programs that they're building are much larger than an enterprise.
Now, obviously, gear to retail, you look at Amazon, that's a pretty large enterprise. Uh, but if you look at the, like social security, they have a program that has to support every citizen in the United States, 300 million customers. So, so, um, and it makes it, and the other issue with it is typically it's a one-off.
There's only one of them, right? So, and that's why it's complicated, and that's why they bring in these multi-vendor, uh, systems integrator. 'cause they typically are building something that wasn't built before, um, for one customer.
And so it's really hard to then repeat that and sell it somewhere else. So, uh, but interestingly, looking at that in the technical debt we've mentioned, uh, because these systems are so big and so complicated, we do find some of these applications like social Security, like the IRS that are 50 years old, still have COBOL in 'em, and we are now absolutely going through and how do we pull those back apart, and how do we modernize those? And, uh, as we, we've come to talk about micro modernization rather than the Big Bang theory of replacing it all at once, uh, because you have to do it that way.
We've realized to think, uh, one of the easiest ways to modernize is piece by piece at a time. Uh, when you try to do the Big Bang approach, uh, that's typically when you hear the core stories of the government overspending, unfortunately, and, and taking much longer than it should take. Yeah, I remember the quickest way to, uh, lose your, lose your job in telecom was to replace the billing system.
I can't imagine trying to replace a large IRS system, something like that. Um, you know, and then the commercial sector, usually it's some kind of finance, either a gain of what we're looking to, we need to do something in market, so we need to modernize this, or it's a cost reduction. Are those similar drivers in the public sector, or are there other ones that we don't see in the commercial side?
I'll, I'll jump in, Dan. I, I think those are definitely there, right? And, and you can look at budgets.
I mean, the amazing thing about working with public sector is everything is public out there. So you can look at, you know, what is spent year in and year out on maintaining these legacy systems. And you know, I I, I saw one stat that, uh, you know, I, I think it was $68 billion last year in, in the federal space towards maintaining legacy systems.
So the scale of maintaining those is massive me. Um, but the other thing that comes into play there is the fact that, you know, this revolves around the constituent, you know, the government is there to serve the constituents. So I think we have seen this change of how do we increase the delivery of services, you know, through the use of technology to the constituent at a low level we never have before.
So I think that is a shifting mindset that is driving a lot of modernization in a very good way of how do we, you know, when you log in through your state, you know, how do we make sure you have one login that gets you to your DMV, but also your applications that you need to, um, read and under your benefits that, that you're requesting, as opposed to three very different environments for that than it historically been there. You know, it, uh, at every level, you know, you were mentioning earlier about it, you know, education state and local government as well as federal one characteristic, at least on the government side, is the leadership is constantly changing, right? Or whether it's, you know, new presidential administrations is coming in with their priorities and slashes of what they change or, you know, at a, at a gov, a governor or legislature level.
So priorities change sometimes pretty quickly. We're seeing a lot of change happening with the Trump administration stepping in, um, a lot of things that were, you know, regulations now aren't, or we're not gonna follow that, we're gonna do something different. Um, it seems to me that that requires a lot of flexibility of how do you support that?
Because oftentimes it's sort of like the long chain, you know, you snap one in and it takes a while for it to make it all the way to the end. Uh, how do you help, how do you help the, the organizations you work with respond to those kinds of dangers? I'm curious.
Yeah, I'll take this one. Uh, so oftentimes those change that happens at the administration, they're not as, uh, direct or as impactful, um, as actually odd we're seeing this year, right? I think we're, uh, uh, the president came in with the plan very specifically to change a lot what was going on in the government.
So, uh, I've been in the government supporting public sector for 30 years and been through many administrative changes. This is probably the, uh, one of the, the most direct to, Hey, I want to change the government. I, and quite honestly, I think you need to go through these because the government, through bureaucracy, and I think bureaucracy isn't necessarily a bad thing in the government, right?
Uh, when things change, you don't want the machine that 300 million people are dependent on every day to change very often, frequently, but you do need to change over time. So we do a lot of the innovations that Matt talked about in, and we just, like in the commercial world, we see that happening in pockets and go forward. But every once in a while you really do need that, um, kind of the, the stoke the plane just a little to change dramatic a little more dramatically.
So I don't, this is gonna be a little different for us in the public sector than previous administrations. Um, and we'll see, I'm not sure it's a necessarily a terrible thing. Uh, how the agencies address this and, um, deal with the budget cuts and deal with the headcount changes will be interesting.
But, uh, I'm confident the, we have the ability to support it with the ecosystem that supports the government, and, uh, if there's a will, there's a way to get it to work, right? And folks that are in the commercial world have to deal with budget cuts all the time and have to deal with this all the time. So there's no reason why the government can't deal with it as well.
Yeah. And if, if I, if I can just add in and bring it, you know, more to a, to a state and a local level. 'cause that guy, I think there's some, some good lessons learned there.
Um, I, I live in the Commonwealth of Virginia, and we get a new governor every four years. Uh, you know, so you, you know, change is gonna happen every four years. A lot of government has addressed this through, you know, it strategic plans and, and publishing what their five year roadmap is.
And what, what's interesting though is, you know, as administration change and leadership changes, if you go back and look at the National Association of State CIOs, uh, NASCIO as an organization, they publish their top 10 concerns, uh, that are out there every year, every year since. And Dan, I don't remember the number if it's 15 years now that they've done it, but it, it, it goes, it goes way back. Uh, cybersecurity has been at the top every single year.
So, you know, I, I think fundamentally, as we look at things like cloud, as we look at things like AI that's coming in, which finished number two on the list this year, uh, you know, we know that cybersecurity is gonna remain up there. We know that legacy modernization has been on that list from the beginning. We know that the citizen experience, which is around, you know, data analytics and how to, to serve that constituent or that citizen, we know that AI is gonna come into play.
So I think generally government working together knows where they need to go. It's how can, how can industry partner with them, and how can we, you know, achieve those bite side chunks that have very meaningful impact for them. That is really gonna be the different from damage in these big bank projects.
I don't think there's an appetite anywhere, whether that's at, at the federal level or, you know, down to your local, you know, local government to be able to say, let's take on a project that's gonna take four more years to do it. So it, it's about that incremental change to serve the citizen. And, you know, cybersecurity is at the top, uh, of how do we continue to do this in, uh, in a manner that keeps, uh, the citizen data safe.
I, I, I imagine nobody walks in and says, we're not gonna do cybersecurity anymore. That's not important. Let's do something else.
No, that's, that's on everybody's top list in commercial and in government. Well, let's talk about the network side of this. You know, when I was doing network kind of work, it was still in the days of this point to this point, who the provider was.
And you kind of built Stitch it all together as like an erector set, right? And what Box does what in the, in the rack that does this kind of security or this kind of routing or whatever it might be. Um, and Network doesn't look anything like that today, right?
It's, it's all software driven, and you have providers like, you know, CloudFare, like Flare, like yourself, and full disclosure, tech Strong is a customer of CloudFlare. So I've worked with you and your organization a lot and enjoy that. You have a great service.
Um, talk about how that fits into the strategy that you mentioned, Matt, uh, in that priority. So you're, you're obviously advising and working with, uh, the governmental agencies at all levels on where they're going, and you know, how you obviously can help them get there and make that transition. Yeah, I, I think one of the biggest ways it fits in is we talked about, you know, where the government wants to modernize too, but we also talked about those legacy infrastructures that they're coming from, whether that's on-prem or one of the first generation, you know, cloud migrations they've had, whether it's, you know, SaaS, you know, services inside of that.
The reality is government, just like industry has struggled with, you know, retaining top talent, recruiting talent, you know, a retired workforce. So the challenge of how do I support all of those environments is ever at the forefront of mind, uh, uh, of government leadership. So the, the use of network needs to be thought of, not in terms of how do I get a user to one specific application, which was a lot of the legacy, you know, mindsets of how we did it.
Do I need to get this user to this in terms of how do I, a how am I able to get all users to all the environments they might need to go to knowing that that's a changing environment of where that user might be, whether that is a constituent coming in, whether that's a contractor working with government coming in, whether it's a return to work that, that we're seeing take place. And those applications don't all live behind, you know, the, the moat and castle of the Legacy network anymore. So if I'm getting a user to an application that's outside of my world, how do I make sure I have the right controls?
And do I wanna have to think of security independently from network, or should I be thinking of one, you know, common layer of connectivity across the board? So how do I connect all users to all applications in the right way, you know, when they should add access to it. And more and more often that involves using the internet as that core foundation of connectivity.
And that, that's where obviously CloudFlare fits in quite nicely as we're talking to customers about that. Dan, I imagine you've got something to say about this. Yeah, and I, I, I help build a lot of those networks back in the day.
Um, I can imagine. So, uh, yeah, but like Matt was saying, you know, we're not saying it's your fault though, Dan, just to Not judging, no judging, We're experience, because I realize we have to replace those systems with the newer systems, new models. So when we, when we built those networks, like Matt was saying, 80% of your traffic flow stayed within your environment, whether that your environment was a campus or, you know, your environment was a land and your campus and 20% went outside.
Um, it's reversed that now, right? The way we write, build applications through microservices architectures, it, it, it's, none of that is built into your, in your environments necessarily. A lot of our customers in public sector don't have data centers anymore, right?
There's, you know, if you look at where Harlo sector has helped lead, they were very quick to push for cloud, um, and, and very quick to look at how this new environment was gonna impact cybersecurity. So terms such as Zero Trust actually came from the public sector, uh, because the landscape has now much larger than it's ever been before, because the way we build net applications, the fact that we have a workforce that's distributed and, and it's just gonna keep growing, right? You, you'll have less and less resources in your physical environment, uh, and you'll share resources outside your physical environment.
So you have to be prepared for that from a cybersecurity perspective. Um, but that's, like you said, that's why cloud player is here. We understand that the, the internet is not just a nice to have, it is a critical infrastructure for most every company and many public service customers now because of that new environment that which we live in.
So, um, how do you then secure that properly? How do you control that threat landscape and shrink it through zero trust technologies and capabilities, and how do you prevent the, uh, the nefarious actors that are out there from coming into your environment, right? So, um, we talk a lot about that with our customers, and we show them how we can do that, uh, from a, a different approach than what the way we did it 10 years ago, quite honestly.
And, and it's probably a whole nother podcast just on, uh, you know, certifications in the public sector that would, would be good to put anyone to sleep, but, you know, how do you do it with compliance? How do you, how do you make sure you maintain, you know, you know, all the regulations that's put in front of, uh, you know, our customers to, to, to, to achieve across the board as well? So, and that, that's one of those other great challenges out there that government's faced with, with, I think the way I positioned it with people are we, the public sector has the same issues and concerns as the public, as the private sector.
They just have a different security equation, right? We all have the security equation. If you work with a bank, they can, uh, give loans and they give loans based on a risk management risk assessment.
Um, and they have an equation that they can take so much risk on for so much investment. Uh, if you put point that back into a public sector, they don't have the same risk equation. Um, and it's because they have constituents that they worry about and they, they, they have a zero, um, uh, risk in, in some areas because it's Department of Defense, you know, you just don't have risk you're gonna take on there.
Um, and, and, and that's, that's really the biggest difference. And compliance is a big part of making sure that that risk equation is addressed. Um, and, and there's a lot of outta that.
I mean, we can thank the Department of Defense on the internet because they built it because they needed to have redundancy and communications for Department of Defense Back to the Darnet days. Right. Thank you very much.
Um, no, it's interesting. It seems like one of the things, and I'm not trying to just, you know, be a fan boy for CloudFlare, but you know, one of the things you try to do is save money through consolidation, right? Bringing things together and take out the redundancy and redundant systems, and certainly networks.
'cause they might all get built at different times for different projects. Uh, not always share that, but it seems like as more things have moved to the cloud, um, both as the hyperscalers and also yourselves, that's one of the ways you can start to move some more security into the cloud, even even parts of the AppSec into the cloud. And now you're not stuck in a, you know, like what used to be in a standalone data center that was built for that project in that era.
Yeah, absolutely. And, and I think one of the, one of the key factors to that me is making sure that, that, we'll call it that legacy application has the same level of confidence around the controls when you move it to, when you move it to that new environment, right? What one of the challenges for government is they've had such purpose-built infrastructures and security around an application based upon where I lived, as opposed to based upon how it needs to live in the future.
So we built stacks on protecting an application that lived in a data center in a very certain way, or protecting an application in a SaaS environment in a very particular way. And I, I think that's one of the powers that, that has to come to play for government to fully modernize, is I need a consistent level of security across the board. So once I get that common visibility, that common control and understanding of who's accessing it, how it needs to be accessed, and how that needs to fit into my risk scenario, then I can, I can maintain that across the different environments.
So if I can bring something to every one of my environments with consistency, then I can decouple where that application actually lives in a much more rapid environment. So that legacy application, once I have confidence that I'd have the same control and protection in the cloud, I can move it to the cloud with much more ease. And, and that's been one of the really powerful conversations we've been able to have with customers is one, understanding the risk to that application, which in all, not all risk is equal.
I think that's another thing that governments had to take on is, is recognizing that there's levels of risk inside of their environment. Uh, and that how do I, how do I control that risk to in and mitigate any risk based upon, uh, where it lives? That that is one of the advantages that, that I've seen from working with, you know, a cloud provider like yourselves, is that you can do things in the cloud, like, uh, just simple examples, bot management, web application, firewall, uh, API security, things you can manage in the cloud, but also tailor to different environments, different locations, different, uh, policies, regulations, whatever it might be.
But you're still working on a consistent platform for the most part. So it makes it much easier to manage and the visibility of it. I'm curious about, you know, a big topic today is resilience.
And so my working definition, you know, like any term we have in our industry, there's a thousand definitions. Whatever's purpose it serves to help me is usually the definition that we use, right? Um, I kind of think of resilience as the ability to, you know, withstand or, or kind of tolerate the unexpected.
You know, we all are doing things to increase uptime, but it's those things that we can't totally plan for. And, you know, a meteor hitting the earth is probably one we're not all gonna survive, but there's a lot of other ones we might be a little bit more resilient towards. How is the public sector thinking about resilience when it comes to networking?
Well, been thinking about resilience for a long time, right? A as i I said earlier, that's, that's why we have the internet, right? Because of the Department of Defense looking at resilience.
Uh, but it, it's trickled down. I think cyber resilience is the buzzword this year, um, in, in every CISO is thinking, what is their role in that? In, in, to your point, whether it was cyber threats or, or physical threats that are happening, they're happening more and more frequently.
How do you get prepared when the, the, the tsunami or the fires hit, or, you know, hurricane knocks out a city block or two city blocks that happen, have a big part of your data centers there. So, um, our, our customers are always thinking of, uh, resilience clearly. Um, and we're a big part of that.
Obviously, the, the nice thing as you go to the cloud, uh, you have inherently built in re redundancies. We built in tools, so to help that redundancy come to light and be active immediately, uh, so that the citizens never even know a, a, a location went down or there was an outage in this, uh, due to this storm or a cyber attack. Um, and that, that's the beauty of one, this, this next generation, um, architecture, I'd say shouldn't say next generation.
It is the generation we are in right now, right? This cloud generation architecture that was built for applications that are out there in the cloud so that they can withstand a lot of that by default. Um, but we, so we built that into, as part of what cloud play does for our customers and what we really focus on and, and which is our customers, like about us, it's multicloud, right?
Because what we're not seeing is not, no one's gonna jump everything into Microsoft or into AWS or into CloudFlare. Everybody has this multi-cloud environment. So it's really important for us to give you that cyber resiliency in a multi-cloud environment.
Um, you know, being that overlay that can do it, whether you're doing it with the CDN technologies or DNS technologies to let you get that resiliency built in at the layer seven, uh, not just the layer one, two, and three level. Uh, we have to have both, quite honestly. Uh, but we can do it so that you can have your infrastructure or your applications in multiple clouds, and we will help you give you that resiliency across those clouds to include your product.
So it, it, it's what all of our customers want. And, uh, I think we're hitting a home run on that, that part of the world. Yeah, and, and I think back, you know what, we'll, we'll do the US old guys kind of reminiscing of you.
We used to build up our coop sites or our failover sites and talk about what was the downgraded experience in resilience? Like what had to live there. I I haven't had a conversation like that in years anymore.
Um, the power of cloud technologies, you know, whether it's CloudFlare working with a quote unquote competitor or one of our complimentary offerings, you can often layer those in, in an environment where your level of resiliency is, is much greater, and it, it's no longer seen by the end user who needs to get to that certs. And that's so powerful to be able to say, wow, I can think about this massive legacy, legacy infrastructure that I'd have to build twice, you know, five, 10 years ago. And now I can have two cloud providers sit there and have redundancy in my DNS environment or of my connectivity to my infrastructure or across the multiple clouds that completely has changed the game.
And we have to break away from that mindset of, you know, oh, this is a separate infrastructure, it's something else. And really just go, how does this service live beyond a failure at one place or another? Hopefully no one has that, but, but we know we have to prepare for it in today's world.
And I think our customers have the, uh, unique, um, vision that they have to take not only resiliency in the backend systems, but the front end systems, right? So because our customers are the folks that go into those disaster areas, right? So how do you create a, when there is no last mile, how do you create the last mile with wireless technologies, et cetera?
And then we can ride right along with that. So, and we talk about the criticality of, of service. Mitch, if, if you tell us, you know, a student or a teacher these days that, that inter, you know, internet's less critical for them, that they'll tell you how long they are, right?
You, you talk, talk to your kids about what happens at school when internet goes off these days. So, uh, it's a very different world, you know, than, uh, you know, open the textbook and turn to page, you know, 32, uh, in today's world of the internet is foundational in every element, whether we're talking education right on through to, uh, the critical services of defense and healthcare and beyond. So you're saying the internet is somewhere in the lower stack of the Maslow's hierarchy of needs, you know, up there with food and safety and Things like that by, uh, teenagers and ear, early 20 year olds, um, might put it above food.
I'll, I'll say yeah, Barely, right? Yeah. I don't know your house when TikTok, uh, was shut down for that.
Oh, You would think the tragedy was happening. You know, and, and it's funny you you mentioned that too, uh, Dan, 'cause I was thinking about y you're in a world thinking about physical, you know, kind of of events. You're in a world where you now don't have to operate and be resilient when something happens, or hurricane or tornado or something.
You have to respond. You, you also have to be able to execute. And that's where other parts of, you know, EMA and other organizations come into play.
They have to go in the field and rebuild and get a capability back up. So you have to live on both ends of it. You can't say, well, we're waiting for our providers to get back going again.
No, you are, you are the frontline, uh, in all situations. Yeah, it makes it a challenge, but it's also fun, right? It's, uh, you, you, you see the, that's the public sector has some very unique use cases that no one else gets to, to play around with.
So that's one of the reasons why it stuck around for so long public sector, because we do really interesting, fun things out there. So. Well, let's do this.
We're we're just about out of time and we could, I could spend another four hours talking to you guys. Um, what, what are, what is kind of top of mind for the next, let's say, this year, maybe going into next year? What are some, some of the top conversations, the topics of those conversations that you're working on with people?
Matt, you kind of alluded to some of 'em around cyber and API security. Yeah. Any other thoughts on that?
I, I mean, if, if we wanna a whole podcast without talking about ai, I think, uh, we'd be remiss. I mean, that, that, that's clearly top of mind, um, by the way, It takes so long to not make Exactly. So, um, you know, we think about it in a few ways.
Um, and it's interesting. It's not just the model that's gonna serve the, the services out to the student or the constituent or the citizen. It's what should government be using AI for?
How do we, as government, takes on more ai? How do we protect those AI models? Um, how do we make sure that our employees and our contractors are going out and using the right AI tools and, you know, not uploading, you know, the wrong data to the wrong, you know, user setup there.
And then ultimately, where is that AI gonna be delivered from? And, and, you know, we, we talked a little bit about, uh, you know, some of the data sovereignty and regulations and stuff, but where is that gonna be delivered from? How's that gonna be delivered on government services?
That, that's very top of mind across the board for whether we're talking educational research, educational sharing, government services, and, and even national defense, uh, of how do we take on all of those elements in government? You might not want, uh, government employees saying up for their deep seek service, not yet anyway. What's, find out what's going on.
I'm not your perspective, Dan. I, yeah, I, I think every customer I talk with wants to talk about ai. How do I get prepared for it?
How do I secure my environment? Look before it's here, how do I make sure I'm doing the right thing? Interestingly enough, the government's been doing AI for a long time.
I like call it legacy ai, right? Um, and, and machine learning has been in place for many, many, uh, in use cases in the government. When we did the assessment, there were like 1700 use cases of which probably, you know, three fourths of those were in machine learning.
Now, generative AI is doing, and they are definitely taking that on. Uh, but it is, how do we get prepared for it? What do we need to do?
Uh, they don't want to be behind that curve, right? And the government has very quickly realized the dependency of data, um, with ai. And so, and the government has a data problem.
They've got way too much data, right? And a lot of that data has never been labeled or, uh, and so you got all this data. So they, we spent a lot of time with, you know, customers talking about where do we start?
Well, we start with looking at your data. Um, understand the AI technology going and get familiar with how they act and build guardrails around those. And, uh, but really you gotta focus on your data management, uh, strategy first.
Um, and that's pretty daunting, especially in the federal government because they've been collecting data on many things for a long time. Um, but it, it, it, it trickles all the way down to universities and, and, uh, state and local as well. So that's what we talk about.
We talk about ai, how they can use AI in various use cases. And very quickly, we've got to, let's talk about data management and let's talk about protecting your assets that you have, um, while building out these new AI models. Well, we do have, we do have a parting gift for everybody that waits till the end of the episode to bring up ai.
So you guys, let's get one. We'll send that to you in the mail, right? Gentlemen, it's been a real pleasure, uh, both Matt and Kent.
Uh, fantastic talking with you about it. You know, it, having done worked with the government a little bit myself, both in education, but also in in work. You, you get to see how much research is actually funded by the government, which is why there's so much adoption of AI and other technologies, security technologies, a lot of things that, you know, not everybody in private sector realizes that's there.
So we appreciate the hard work that's also done, but also funded by the government. Well, thank you both for, uh, joining us here on the last great cloud, cloud transformation, uh, program, video series and episode, talking about the public sector. Wish you both, uh, all the success as you work with the new administration now, and the next one after that, whenever that happens, as well as whatever level that is.
So, uh, keep us safe and secure, and thanks for helping deliver those services that we get from our government. So, thanks again. Thanks everybody for tuning in.
We look forward to seeing you next time. This is Textron tv. Hey guys, thanks for Thero.
We're here with Lan, Yeshua, and Avi Hi Cohen, who are both the CEO and the CTO for terrific and security, adding the security to the back end of that to make sure. Um, and they're just recently raised $29 million in funding. They address this nagging problem we've always had around browser security.
So we're gonna jump into this in a second. Gentlemen, welcome to show. Thank you.
Bye. Nice to be here. Thank you.
All right, let's start with Alan. What exactly is the problem we're trying to solve? 'cause I think I've been hearing about we're gonna solve this browser security problem now for more years than I care to count, and it never seems to quite get solved.
Some people say, you know, well, I've got this perfect browser over here, but nobody uses that browser. And other people say, well, we're gonna secure the browser that everybody uses, but eh, it doesn't seem to never actually quite work out. So walk me through how we're solving this problem.
So, uh, uh, that's correct. I mean, the browser gradually became in recent year, the most dominant application in, in Copo is, uh, and it was mostly secure from the outside, either from the operating system or from the cloud. And, um, uh, the recent, uh, uh, emergence of this new, new category of enterprise browser security is actually coming to secure the browser from, uh, from inside, uh, because the existing solution don't have the necessary visibility and, uh, control, uh, inside the browser.
And, um, the new approach is actually, uh, uh, providing this, this, uh, visibility and control, therefore taking it at completely different level. Of course, important thing is that while you are doing it, you don't impact performance. Uh, any performance impact on the browser level will be intolerable.
One is ready to wait even the millisecond until the website is uploaded. Avi, hi. Um, how did you get inside the browser?
Because I think, you know, what Alan just said makes perfect sense, but how do you get in there and actually do the thing he just described? Yeah, so as Dylan said, the browser is highly complex, especially today, web applications are coming extremely complex. Looking at it at the network level, for instance, no longer works.
So, um, we bring the capabilities, ZI side, the visibility and controls into the browser, um, either through deployment, like an extension, which is local to the browser, no, uh, network inspection or SL scripting, not none of that, uh, legacy, uh, tech. And if it's for instance, uh, BYLD or other unmanaged devices, uh, we bring the browser itself. So we always add the browser, uh, local to the user, uh, without the, uh, necessary like other legacy solutions that may require either an OS agent or, uh, uh, some form of a proxy, which as I said, uh, no longer works.
But I wanted just to add, uh, uh, uh, regarding your question, how do we get this visibility and control in the browser? I can elaborate about it more, but the uniqueness of our solution is actually that we are intimately involved with the JavaScript engine, which is the kind of the canal of, of the browser. And, uh, having full execution context, how I can elaborate a lot.
This is the uniqueness of our solution. Raffic is a deep tech, uh, company. We have about five patents and additional 15 in, in filing.
So we developed our own solution for JavaScript engine, and therefore, by the way, it's extended beyond browser also to any JavaScript and ever application, like all the model application teams, slack, et cetera. Which, which is making it very important because when you look today on the desktop, the modern desktop of, of your worker, either employee or contractor, it is actually composed of multiple browser and multiple, uh, modern applications. I behi, is that a standalone browser that you created, or did you get inside, say Google Chrome or any of the commercial browsers, or where, when do I have to exactly deploy it?
So since we have a, a native, uh, JavaScript agent that is capable of executing in every JavaScript enabled application like browsers, but not limited to browsers, um, we have the ability to also, uh, provide the commercial consumer based browsers, uh, while we actually, uh, infuse our tech into it. Also, we do have a commune based, uh, browser that, again, it's plain old commune, but we, uh, the addition of our unique agent, uh, fused into it. So we, we have, we, we actually enjoy in pretty much, uh, both worlds.
So we can provide a lightweight solution like an extension, a, a, a hybrid one, like a commercial browsers fused with our tech or a full-blown COR based, uh, enterprise browser Lan. So if I upgrade my browser, do I have to upgrade your engine? Or how does that work?
Or how do you keep that in a way that, um, makes it all feel seamless? You don't have to upgrade and, and to add to whatever has said, we, with us, you don't need to change the browser. You keep your native browser, your, your mainstream browser.
We bring that security to the browser. The browser is updated automatically by the vendors, and you don't need to update our solution. Aha.
If you want to update here, uh, to, Yeah, I, I will just add that in order to add more context. And when we look at the problem, we need to look at it in two, uh, different use cases. There is the managed, and there is the unmanaged managed, meaning corporate devices, managed devices.
Uh, so you do want to protect the device, the endpoint. In order to do so, you need to protect all browsers, right? On the unmanaged devices, it's a different story.
There is, uh, uh, the device may be compromised, uh, um, and you just want to isolate the user interaction with the enterprise, uh, data in a way that is secure, even if the device is compromised. Um, so our tech plays in both, uh, uh, walls, allowing us to actually, uh, provide the feature parity in the same level of, uh, capabilities, uh, in both ways, including security, which are highly important to the, uh, managed devices. And, uh, using our unique tech and exploit prevention, we can actually, um, uh, prevent, uh, browser exploitation even from zero days and end days.
So you don't necessarily need to update your browser, or it's not signature based. It's based on a, um, tech called MTD moving target defense, meaning using randomization just like a SLR, uh, uh, without any detection. So just by randomizing and making the environment non-deterministic, we're actually able to prevent exploitation, meaning that even if your browser is outdated, which is pretty much a common practice among, uh, enterprises, they, they need to test new releases before they update, uh, their employees.
So, um, we provide, uh, uh, prevention capabilities, uh, uh, a strong and robust protection for that gap, no matter wide, it is, uh, for the enterprise until, uh, the enterprise decides to update the, the browsers, uh, but it's not signature based. So there is no, uh, need for constant updates from our side, uh, for that specific engine. So, Alan, what's next from here?
What's the plan? I mean, you know, $29 million is still a big number, and I'm sure everybody, you know, applauded and maybe everybody got a couple of beers, but where are we going from here? Uh, more than a couple of beers, actually.
So, uh, uh, you are right. I mean, I mean, the main effort, I mean, we have a material product, uh, now, uh, with, uh, about 70 customers already, large enterprises, there is a demand in the market. The main, uh, um, uh, most of the proceeds will go first and foremost to, to increase, uh, and build our sales organization, sales and market organization in North America.
We do have a sales team here that worked nice in 24, otherwise we wouldn't have, uh, this, uh, uh, uh, round, obviously. Uh, so sales and marketing team in the us, uh, we already more than tripled the, the team in the last, uh, 45 days, but also to continue and support the r and d of the product. As I indicated before, the, the, the main fault of raffic is the technology depth, and we have a very aggressive innovation roadmap for, for the product specifically.
Now we are, we are, uh, releasing, uh, a new version that will, uh, obviously leverage on ai, uh, all the capabilities of AI on, on three aspects, and, and provide also enablement for, for organization as the browser is becoming, uh, actually also a gateway for ai, uh, users. So, so, so it's r and d enhancement and the go-to market. These are the two main things.
Avi, why didn't somebody else think about this approach before? What was kind of the aha moment for you? So I think, um, enterprises look at the browser as a part of, mainly a feature of, uh, SASE, right?
Uh, SW supposed to take, uh, uh, uh, hand handle all traffic, including web-based browsers. So browsers until just a few years ago was not that widespread. And some applications, at least not the majority of ones, was native applications.
Now, the browser, the trend is always web-based. So many native applications become web-based, the application themself, um, become more and more complex. So looking at it, as I said, at the network level, is no longer enough, no context.
Um, traditional file uploads or downloads are no longer the same. Um, so you need to be at the access point, at the access tool, the, the browser, um, in order to be in the browser. Now you have two approaches, either to be the browser or in some form, some, uh, uh, uh, agent on top of it.
Now, extensions were not, uh, uh, uh, something abnormal, right? They're quite common. It's not something new.
Uh, our approach is unique because the extension is just the delivery vector for us. It's injecting our agent. Um, and extensions are by itself highly limited in terms of APIs.
They don't have always level visibility. That's why no one, uh, push forward on extension only solutions. We have a unique tech that allows us to leverage the extension framework, although, uh, we are pretty much, uh, resilience against changes and stuff like that because our, uh, capabilities are not at the extension.
Um, and since it's quite, uh, uh, unique and, uh, a generic approach, we can use the same agent in different, uh, methods and delivery mechanism. Extension is one of those, but it can happen in different ways. But in order to gain context and in order to handle the more complex web applications that other legacy solutions can't, you need to be at the browser in some way or form.
Uh, and we have that capability, including os level visibility. So we can provide feature parity and across, uh, different deployment methods. Ellan, last word on this, but the bad guys, you know, they, they're at work on all this stuff.
I mean, are they squarely focused on the browser? Is this their point of entry or how big a a a whole is this particular part of our extended attack service? Obviously, what we see is, uh, uh, in enterprises that we made, we see a great demand.
And usually, you know, the driver of the demand is breaches. The breaches are, are the best friends of, of, uh, security vendors. And the breaches are, uh, on the rise in spite of the, uh, significant amount, uh, that that enterprise are investing.
And, and some of them have something between 50 to even 100 vendors, the type of security vendors providing to them the, the solution. So obviously, we don't have a big problem sitting with enterprises and, uh, uh, exploring with them, um, gaps in browsers. So the statistic is talking for itself.
Uh, uh, uh, 76% of ransomware is actually happening because of, uh, web browsing and, and the, uh, the semi tool regarding, uh, exploit about 40% of zero days are in browsers. So the browser is a very sophisticated piece of call. You can't have such a sophisticated code, and you want it, it's a wonderful piece of code.
See, it's driving the productivity of all of us in the world, but there is no way to do it without bugs, and there is no way. And bugs means vulnerabilities. And vulnerabilities are the first step for, for, for, for breaches and for for attacks.
This fact of the sophistication of the browser, uh, and the facts that the vendors are investing so much and so many line, uh, code lines are written every day, plus the fact that here is an application that the only one that is used by employees, both at work, but also to render external code from, for untrusted side. And let's assume that almost any site should be untrusted, even the most trusted one that are used by, by, by, uh, better by bad actors. So this combination of sophisticated of the code plus sophistication of the code, plus the fact that it's rendering external goal is creating, uh, uh, this fantastic opportunity for adversaries.
But I want to say just one thing. The fact that today, all of us, most of us are spending most of the time in the browser, is at the same times creating, uh, uh, an amazing opportunity for adversaries, but it's also an opportunity to consolidate the security requirement into the browser. And this is the big sh uh, uh, shift and earthquake in the industry because suddenly the things that you could have done only by very sophisticated, uh, SSIS solution, with all these moving parts in the cloud and pops and reverse boxes, all of this, you don't need it.
If 99 or sometimes 100% of your traffic is web-based, why should you do all of your analysis in, in the, in the cloud where things are, uh, uh, encrypted today, sometimes end to head, you have self pinning and all of this where actually you can bring the security to the, let's call it to the, uh, uh, crime scene. This is the crime scene. And, and this is, I think what is creating a shift, and this is the rhythm that you see that, uh, uh, um, technology leaders, both SS e company and EDR are looking, uh, uh, quite closely, uh, are watching quite closely on this category and saying, okay, we need visibility in controlling the browser, either if I'm a DR or SE and if I have the gaps.
So I need to get this visibility. And this is what is creating the momentum in the market. It's disrupting quite big categories.
All right? You heard in here, ultimately it is all about, well, the crime scene. And if the crime is occurring on the web browser, well then that's where we need to fight the crime.
Gentlemen, thanks for being on the show. Thank you. Thank you so much, Mike.
Bye-bye. And, and back to you guys in the state. Hey guys, thanks for the throw.
We're here with Michael Thompson, who is currently president and COO of Unisys and will soon be the CEO starting in April. And we're gonna have a little chat about, well, what technologies are really the most disruptive for enterprises specifically in 2025. Michael, welcome to the show.
Thank you, Mike, for, uh, having me. Really a pleasure to speak with you today and look forward to the conversation. I think we've got some great topics to, to run through.
Alright, well, we always seem to be caught up in one technology hype cycle versus another, and AI appears to be no different, but I feel like people are, or organizations are having a little trouble trying to figure out how to operationalize this latest wave of gen ai. And I wonder if we have not found ourselves stuck in some permanent experimentation loop. I mean, what do you think is gonna happen in 2025?
Yeah, look, that, that's the billion dollar question as, as they say, right? Um, I, I think your, your pulse on that is spot on. Uh, I think there is still, uh, a very heavy discovery stage, especially when you talk about gen ai, right?
But, um, in, in, in my opinion, and I think the way we treat it, there are, there are several elements of AI that are not hype, that are real, and we've been working with for a decade, and they continue to expand and and extend. And so when I think about it, or we think about it from a strategic perspective, and I think it's indicative of the market as well, there, there's kind of two vectors, right? The first is the AI that you're using embedded in your organization, and then for us as an IT solution slash services company, that extends to how we deliver to clients and the, the things that we're able to do for clients.
And it also is embedded in the back office functions, marketing, finance, advertising, et cetera. I think that piece of the utilization of ai, whether it is the, uh, enhancement of AI operations and delivery of provisioning a cloud environment, uh, and, and, and kind of automating that component, whether you're focused on the data abstraction layer and how you actually can, uh, align these, these, uh, variable data points to get a better outcome, a better experience, predictive analytics, all of those types of things, that's pretty well defined known. And there's some really interesting and and utilization cases for gen AI in that I, I think about thought leadership, uh, and, and managing, um, frontline tickets and service and all of that.
So that, that's pretty well defined. And, and on its way, the, the thing that you mentioned that I think is really real and, and the billions of dollars that are being spent in this space is about how you commercialize ai. How do you make it revenue oriented?
How do you bring new products to a client that is definitely still in this kind of search and destroy mission, right? That everyone's looking for the ROI on the next big thing. There are clearly some things out there where, uh, they're already known and are moving forward.
I would say financial services and, and healthcare are probably the two industries that are on the forefront of how to use that technology to actually bring, uh, I'll say new and innovative products to the market. And I think the rest of the market is really in the other prong, which is around how you do what you do better and how you engage with the technology to be i'll, I'll say another tool in the toolkit, uh, to really either lower the cost of delivery, hire the, or, or raise the, the element of, um, utilization and or experience to, to the end user. I think those are the, the two ways we look at that.
But at you, you're spot on with this hype cycle in the sense of it's the issue du jour, but, but I think it's starting to come down to it's the next issue de jour, and how are we using that and how will it ultimately, you know, reflect itself in, in the market prospectively, To your point, I feel like last year was the year of fomo, right? We had the fear of missing out. And when I look at it this year, though, oddly enough, I think things are starting to split into two categories.
One is kind of like, one are the new AI table stakes, right? I gotta have this capability 'cause everybody's gonna have this capability. And then how do I actually start identifying things that will provide, say, unique differentiated value for my company?
That's a competitive advantage. So how do you have that conversation? Yeah, again, like spot on, um, uh, question wise that everyone's wrestling with.
Uh, I love the FOMO analogy, and, and it's true, right? There was a little bit of this there. Everyone's applying ai and if you don't, you're left behind, right?
And so you're, you're running forward with it even though you don't know where you're going, but you have to do something right to stay competitive. I, I think it actually ties into the second part of what you've described, and I think it ties into our lead in here on the technology in general, the application of it in how you deliver, whether you're, how you deliver your own framework, your platform or the differentiation of your platform to your clients is where it's actually being applied. So if I go back to my first, um, you know, commentary on that first vector on utilization of it, you know, if you think about the primary use cases that came out of the shoot, um, one would be co-development from a software perspective.
One would be, you know, how you're using it in advertising and marketing to create content. One would be how you're managing your service desk in a, in, in an omnichannel way that includes the ability for digital agents to, uh, you know, support that those are elements that are real and differentiating in how you bring your solutions to market. No question.
But now we're starting to get into, and, and this will continue by the way, I, I believe it will continue. The first stage is how do you adopt the technology? Where do you adopt the technology?
The second stage is really how it becomes part of your workforce, if you will, right? So just another element of your workforce, whether that's the toolkit or actually as a digital agent and those types of things. The third is how it ultimately interacts with the unit, right?
Instead of you prompting it to do something, how can it interpret what you want or need and ultimately deliver a better outcome without being asked and removing that kind of prompt engineering component of it. We're not at that stage with this, but we are in our lives and typically how we operate with technology in our lives, we want in our work. So, you know, simple analogy.
You go into your kitchen and you say, Alexa, make me coffee, or turn on the coffee and it works, right? If you think about a smart, um, conference room and all the data telemetry to understand the physical environment, the tools that you use and the user sentiment, in a perfect world, I'm booking a meeting and it knows it to me, it knows the type of projector I want, it knows the room temperature. I'd like an added nose where I want the shades.
I go in, it's tested all the equipment, the zoom call is up and operational. That is a great user experience, and I didn't have to ask it to do that from a prompting perspective because it knows who I am from a persona, persona point of view. And it, and it's delivering that to of quality.
And the preventative measure there is, let's say it does, its pre-check and the projector's not working well, it ships me to a new room and does that same setup and I don't even know what happened and I just go to my new room, right? So that to me is the experience you want in a business environment without having to pay, you know, additional, right? You, you still are managing your budget, but using technology to provide that level of client experience by using the data telemetry of all the different components that we just mentioned is how it comes to life, right?
And, and I think that's where that's really going. I think at the risk anyway of being overly simplistic, when I talk to some folks, they're trying to figure out where to insert these AI models and LLMs because they're probabilistic and a lot of the business processes are deterministic. They're generally need to be done the same way every time.
And the last thing an LLM does is the same thing every time the same way. So, so how do we figure out where these things actually fit in a workflow That that's, that's a, again, a, a a great dynamic that we're actually all encountering right now, right? And we, when I think about, and I'll just, I'll, I'll point it to Unisys just for a second here, and then we could take it to the industry view, but so having a definitive AI practice that can help companies do exactly what you've described, right?
And an LLM if you think about data in general, and you think about where data resides, the, the current statistics will tell you 70% of data still resides on prem. So do you take the data to the AI or the AI to the data? Well, it's pretty costly to take the data to the ai and, you know, and, and you've seen this, um, dialogue, especially recently with deep seek and you know, the, the elements of what's going on there from an AI perspective, that's that the heart of that is the question you asked.
It's a data construct issue, and it's very similar to what we used to think about as master data management. And, and when you think about an LLM and the creation of an LLM, that's really about master data management, the dynamic nature of what those data sources are, how you secure those data sources, how you power the ability to do that compute, and then you really think about, well, if you see how, how it's happened in the past and how it may evolve in the future, those LLMs become, you know, s SLMs or small language models and they get pushed to the edge and you do GPU compute at the edge at the server, or you do it at the device level with a small language model that's fit for purpose to be more deterministic as, as you've described, right? As opposed to, so it, so the art is really about establishing the data model, making sure it's dynamic, how it connects to the certain processes that you're really trying to own in on automation, and then cultivating that data model to a small language model via, you know, dynamic tokens where you can interact very specifically and get, you know, great speed, no latency.
The answer you want predictive in a smaller subset that can help you be deterministic, right? I, I, I think that's what everyone's trying to coalesce around. And, and if I just tie it into deep seek, which is, you know, obviously the, the, the new thing that came out in the last couple, you know, week or so in regards to what, what China's doing on their AI modeling, essentially, it's that, right?
They're, they're, they're taking this large language model and they're building these, um, you know, partitions if you will, to, you know, minimize the throughput that's needed, and then they need less compute power to get to the same result. And it's no different than those same premises that we've used in, uh, ma master data management and data oceans and data lakes, and, you know, just environments that are smaller, more fit for purpose quicker and at the edge, right? And, and I think we're at the very early stages of how we do that.
And, and, and the cautious thing here is obviously prevention of hallucinations, using it in a matter that's practical, using it from a point of view that's, you know, not, not causing the company harm, making sure that data is secured and that you really have rights to all of the component pieces in there. So it, it's still a security issue. You've got a lot of issues around data Coventry and where people are that are accessing that data.
So there's all these different levers, and it's not just the data, but it needs to start with the data, if that makes sense. You mentioned a agentic AI earlier, and I've been scratching my head about this. So I'm gonna have all these AI agents running around, they're gonna be optimized for performing a specific task, but those tasks are part of a larger workflow.
So how do I orchestrate all that into some sort of end-to-end cohesive process? Yeah. That again, like, that's a, you know, obviously, Mike, you're plugged into all of this, right?
Because you really are hitting the heart of the challenges that all of our clients are facing, and we as IT solutions providers are facing. And when I mentioned earlier about having, uh, AI be a member of the workforce, that's exactly what I meant by that, right? It's very few processes where AI is going to do the process end to end.
You, you know, there, there's this fear that you, you know, at at, at a manual level, AI is gonna take over all the manual jobs. I don't think that's true at all. I think it's how we develop our manual workforce to work alongside of an AI component.
You know, what you've described is your typical RPA or you know, component where you punch out of a process, you do something in an automated way, you come back into the process workflow and you pick up with that process. And so it, it's no different than any, it goes back to TQM, right? You define your process flow, you find the nodes that are either repetitive in nature or pieces that you can save certain elements of time because you're doing the same things.
You punch out and do that and you come back into the process and then you finish that process cycle. I, I, I think part of the, the fear of adoption in some cases here is there's this big, this big ticket price, right? For putting AI in.
And so everyone's chasing the big ticket, ROI on it. And I think if we take a viewpoint that a whole host of small innovations in a process at the end of its lifecycle begets a ROI output, and we, and we think about it chunking up that way, it's actually a more practical way to adopt the technology. And as the technology evolves and our processes evolve, we'll change our processes.
But to do all of that in one fail swoop to say, I need to replace this entire process with this AI to make the ROII, I don't think you can make a case for that. And the other thing that I was wondering about is, have we thought through the security implications of these AI agents? 'cause I got a feeling that there's a bunch of cyber criminals out there looking their chops going, Hey, you built a what that I can hack into and make, do almost anything.
It, it again, it like that is, that is the quandary, right? We, you hear a lot about ethical ai and that's about how people are using it. But what you don't hear about is the unethical hacking exposure to that, right?
So that is the biggest issue with these data models. And, and you know, the, the, if, if you think about hacking component into your LLM and what it can do to all of the outputs, right? Uh, it it's incredibly, um, uh, painful and, and, and something that we really need to think about, uh, in, in a holistic way.
And it's not going to get less. It's gonna get more, I mean, we, we talked about a little about the utilization and the familiarity with the technology. Let me just give you a brief example then see how these si if you don't protect it, what the output could be.
So let, let's say we have facial recognition at a bank, and when I walk in the door, it knows who I am. So before I even walk up to the teller, they know who I am, what accounts I'm there. And, and it's an automatic experience of, you know, good morning Mr.
Thompson, what would you like to do? And, you know, I don't have my card. I'm not like they, they know who I am and they know everything or elements about me.
Now, now think about if you were able to get access illegally to that same data and modify the recognition so your face became my face when I walked in. And there's no other form of verification. If you don't think that's a playground for nation state actors to spend billions of dollars to get into that on any scale.
Uh, your kidding yourself, there are very sophisticated. They're spending as much to use this technology in a nefarious way than we're spending to use it in an ethical way. And so, so I see that as being more and more problematic.
And I also see it, if and when it happens, it is more detrimental to the company because the, the proliferation of what they have access to in an LLM or in the environments that you and I have been talking about is exponential to just taking data, which is kind of the viewpoint today. So there's one other topic that people are talking about, and it's this whole quantum computing thing. And I cannot figure out if the hype around that is just a case of AI envy, or are there actual use cases for this stuff?
And when might that manifest itself? Well, it's not AI envy. Uh, I look, I, I look at, I look at Quantum, uh, as a Y 2K event where we don't know when the actual trigger date's going to be.
I, I think it is, it is known and understood that at some point, uh, in the near future, and the near could be over the course of the next five years, Liz, if we just bound that, that quantum computers will be able to break the current encryption we have. And the second that that happens, and, and that's why I say it's a Y 2K event, if you're not prepared for that transaction, you're done. Everything we talked about from a security perspective is, is on the table.
It has two elements to it that I think are pretty interesting. There's a software element to that, and there's a hardware element to that. And, you know, so, so part of it is building the, uh, quantum defense mechanism in the proprietary software that many companies have, and that keeps the bad actors out from using the hardware to break that encryption.
The other piece of that is the infrastructure, you know, the VPNs of the world and the encryption embedded in that. And, and you really need to look at your entire estate and pinpoint the areas where encryption is critical. And it's critical to everyone when you talk about, you know, your, your access directory or, or you know, anything like that.
Uh, and the, and the gateway to get to that. So you've gotta pinpoint all of those areas and determine the fixes that have to happen now to prevent that level of forced entry. And you've gotta do that same thing on the software side.
It's coming. The same billions that are being spent in a nefarious way are being spent on that. And there's this whole concept of, you know, steal now decrypt later.
Right? Uh, when you, when you think about that, that's also real. So, but, so you have to have a protection against that standing where your vulnerabilities are and, and having a, um, a plan to how you get to, uh, prevention and, and you, and you, and you damn well better have that before 2029 or 2028 in some people's cases, um, because once it happens, it's too late and it's too long a lead time to actually fix it.
There you go. As they say, Q day is coming, Hey, the Chinese have a proverb. That's something that says along the lines of, may you live in interesting times.
Well, we're here And we'll be here for quite a while, I'm sure. Go. Hey, Mike, thanks for being on the show.
Thank you for having me. Pleasure talking to you. And, uh, love to catch up as as frequent as we can.
All right, back to you guys in the studio. This is Textron tv. Hello, my name is Chris Blask.
I'm going to be your host yet again for an Inevitability Curve episode where we take some current topic and look over it, uh, look at it over periods of time, spans of time, could be very long periods of time. The conversation will determine. So today we're gonna be joined by Deb Radcliffe that I've known for quite some time.
Hey, Deb, how are you? Good. How are you, Chris?
I'm loving life. There's hurricanes and all sorts of things, but, uh, there's always a vo on battle fleet coming to destroy the earth, you know, so why not? Did Your planes get through the hurricane?
Okay. I haven't checked my Facebook yet. I lost starlink connection last night.
Um, I'm ex, there was obviously some damage, you know, it may just be, uh, the power system on one boat, Sam Clemens, you know, got wet, so the AC power is down, but, uh, I'm sure they're fine. I'm gonna have a friend fly over, uh, with a drone on Saturday when the winds come down and we'll assess things and go from there. So these are the solar powered boats I've been sailing up and down the Florida coast as Deon to Yeah, and you're, and they're remote to you right now, so you have to do remote management of them.
Yeah, that's right. I'm a thousand miles away in Ontario, Canada, you know, so I'm logging through my AppSec and devices to control cameras and water cannon to keep some of the, uh, the bird population down and do other thing. But now I can't do any of that.
But it's All, if you aren't Facebook friends with Chris, you miss all this stuff. He has videos of the water cannon going after the birds and stuff. It's fun.
Well, I say in Instagram is more public. I think, you know, it's, it is funny how we use social media these days, right? Which is, you know, getting us to our topic, right?
The, the, you know, my expectations of Main on Facebook is effectively may as well just, you know, post it, you know, on, on, on Twitter, you know, I may as well be just, just be public, however, right? There is the friends posting the, and then there's room return public on and saying, Nope, really, I am saying this. And, you know, so be it, God, right?
So we've developed these sort of levels, right? Yeah. But before, so before I get into all that, right, as, as we're talking about in the Green Room, you and I met somewhere back in the nineties, you know, I think when you first started doing this stuff and I was doing firewall stuff, and the path you have taken is, is investigative journalism, cyber crime, all, you know, fiction narrative, you know, talking about how we, how we put all this stuff together from a perspective that is now fairly common, but has developed entirely under your, your purview.
So it's been a hell of a hat. Yep. How's that been?
Well, in 1995 when I was working on a book about Kevin Mitnick, my eyes got opened, and then in 96 I started telling magazines like, bite that they needed information to get out to their readers because this was gonna be a juicy, scary situation, and that their readers weren't ready for it. That the corporate America wasn't ready for it, that government wasn't ready for it. And neither were the poor consumers that we were leading to the web, like sheep to the slaughter at the time, and then blaming them for getting hacked.
And so it's always been my mission to sort of blend all three of those constituents together as I do my reporting. Uh, you and I were talking before we went live about how I felt back then, I was the only one shouting in the wilderness that this was coming and this was here, and we needed to deal with it with legislation, with better security controls. I remember when Cisco adopted its first firewall, I think it was through acquisition, was it Accent Technologies?
Or who did they acquire when they came up with the Cisco Picks Firewall way back then? That was a kinda the interesting backstory behind that. That was Network Translation Incorporated, you know, was, you know, to this day great friend Richard Clark.
Um, and oh, I'm, I'm gonna go into hell for this. I've forgotten, uh, his name, but, you know, there's a, a guy that was at the same time that I was out there in the world, you know, thinking about firewall things. And, and this is really leads me to down this whole inevitability curve thing, right?
10 yeah. Eight thing. Um, I had this idea for, uh, a firewall and we, my boss and our little company had said, okay, let's do this in 19 92, 91, 9 2, and we're go running along and somebody said, Hey, there's no not enough, uh, IP addresses on the internet.
And I lost my mind a little bit because he was right. I'd never really thought about it. And I ran to my boss's office, said, oh, no, no, maybe this whole thing is a bad idea.
And he didn't blink an eye. And he says, John Alsup, he said, I found that anytime there's enough of a need, you know, a technical solution is is just found. And within 15 minutes, uh, Andrew Flint and El El Maya UND and I at a whiteboard came up with network address translation.
And the point of the story here is this, John Mays, so did John Mays and Richard Clark, 'cause he was consulting and setting people up with internet addresses, uh, internet connections. And every time he did it, their IP address, we get a mess. And he thought, you know, this is a thing.
So he came up with the same table mechanism that we came up with and add the same time another group who wrote the actual RFC, uh, Tony something or whatnot, did the same thing. So it was just time. Right?
Wow. Fun to be there. I forgot, I forgot how hands on you were back then.
It's a, it is been a strange world. But NTI was the picks firewall, actually, I had, that Was it. Okay.
Had cheese dogs at an internet world conference back when it was like 80 people or whatever. Uh, he not quite that small with John. And, uh, he had the, had the picks the private internet, uh, exchange.
And I had the border wear firewall, if that was a firewall. He wasn't. So, uh, after that he was right.
And then we competed in the, in the market for a while, and I ended up at Cisco running his old, old, uh, uh, firewall. But that was the time to paved the world with firewalls, right? We went from, you know, it was, uh, it was supposed to be end of life to end of 98.
John Chambers and the executive staff had actually issued the end of life. Uh, and, uh, uh, myself and Adam Wal and a, a bunch of folks kept alive through the winter of 98, 99. And, and the rest was, uh, that path.
But, okay, so what I got confused with was Accent Technologies was one of the first intrusion detection companies, and I'm not sure if they're the one that got acquired by Cisco or Wheel Group, got acquired from Austin Tech Wheel Group. Wheel Group, okay. And when I interviewed the wheel group, they didn't even have a quote unquote product.
And they were telling me about a virtual first ever. What they suspected was a mob hit on a, a patient in a hospital and they were, the nurse was about to go to court because they were gonna blame her, but somehow they found through their intrusion detection, someone had gone and changed a record in the computer right before the nurse administered the medicine that killed the patient. I was never able to go public with that, because that was all told to me off the record.
And sometimes I don't know how much to believe, but it was one of the founders of the wheel group. I remember having, I think we were in Texas having a meal together, and he was telling me the story and I was just going, God, why can't I report on this? You know?
And so that was way back before anybody had a name for intrusion detection, except for maybe Becky Base over at the NSA, Right, Becky? Yeah. Yeah, yeah.
Uh, you know, and then, and then, you know, I can tell I have to really try to control the squirrel instinct, you know, in this conversation. 'cause we can take this everywhere, right? And this Exactly.
So that, that story right there, you know, that's literally the murder mystery sort of thing you associate with crime and novels and the kind of things, you know, you're, you're, you're doing now. And it, there's always that boundary between, you know, let's say for a second, say investigative journalism, um, and, and narrative fiction, right? Yes.
And line between the two, right? Yep. Yep.
And that one would've made a great like Hollywood movie, even back then. The, uh, narrative fiction. You know, Richard Clark has taken the same path that I've taken.
He published his first fiction book long before I did. And, uh, it was more of a sort of a single case, you know, legal case. And, and, uh, I remember getting on his case 'cause he sort of skipped over the romance scenes and I said, you, you're pretty shy about that.
And he says, I don't care. I'm gonna write it the way I'm gonna write it. But I really liked his book, his first book, and I haven't read his other books yet.
But that wasn't something I was ready to do yet. That was years before I put my series out. But the culmination of all of our experiences, right, Chris, and as a journalist, my people have always been the hackers.
They law enforcement and federal agencies came later when they finally caught up. But in the beginning it was just the hackers. And some of them acted tougher than they were.
Some of them were a little scary, but most of them were very helpful. They helped me get on the internet for the first time ever. Um, I had to pay long distance for a point of presence way back then.
I don't know if you remember those days, dial up modems and then after that, you know, they were the ones who were sounding the alarms. Going to, my first devcon was extremely eyeopening. Um, and just moving forward, so the hackers are the good guys in my cyber thriller series.
'cause they're the ones that who, who wanna fight this corporation that's taking over the world through human chip implants. And they're the ones who end up helping the NSA avert a cyber war. And people say, does this stuff really happen?
Yes, it really happens. NSA brings in hackers all the time. You know, they need 'em for certain things.
They bring 'em in. Some of them end up hiring in with the NSA, you know, so it's, it's all of it was based on technical fact, historical fact possibilities that could be done with today's tech. And I wrote that because I wanted people to understand what people like Chris Blask and others do in the hands-on environments that they're in trying to stave off is tidal wave of cyber threats.
Well, and you, as, as I think about this conversation we're having, this is, uh, I think probably, maybe, maybe my favorite episode to date on this topic because, you know, you and I shared this, this experience, right? And I, I, you know, now, now we're both here, right? And back in, in your first days, you know, you, you as well, we're all sort of young folks.
You, I speak for myself, I'm like, I don't know like how I got here, But I was in my thirties. I'm not gonna say how old I am now, but you can extrapolate, right? And, and, uh, and you know, I, I remember being so, you know, sort of well suggesting things getting slapped down for 'em that today, you know, you know, as, as you say, you know, the, the, the, our peers and our folks, you know, Fred Cohen, um, who coined the term computer virus in his PhD thesis right?
In the late eighties. And you mentioned Kevin Mitnick, right? You know, uh, these are the names.
Back in the earliest days before I got into cybersecurity, these the names you'd hurt, you'd see the, the, the thing on national news about this thing. You know, that was when, you know Fred and Kevin were both, you know, you know, the folks everybody was talking about. And then there was the I Love You Virus, one of my favorites or reference.
That's The one I remember. I'm like, why is Bernstein Young sending me a note that says, I love you? Right.
Well, you know, and I immediately realized there was something wrong, but it was the first virus I ever received, but, well, it's, Yeah. And I actually, it Was weird. I think it was the I love You virus, but I maybe saying this from wrong there.
There's, there was one reaction, real virus, but this one was the, uh, it was an email that said, Hey, tell all your friends, there's this virus. Oh, oh, I love you virus, and if you'd open the, uh, email, it'll delete your hard drive. Right?
And then all the, what the internet was, was all text back in those days that used net news groups email and so forth. And that just got enough. People just said, oh, I better do the right thing and post this to all my newsgroups.
And then everybody else replied to say, stop posting this to all the newsgroups. And it literally took down the internet, you know, all over the world. It did.
And I had like a dozen emails that morning and every single subject line in capital letters, I love you. And I was like, gosh, this is just weird. So it was my first like, time I'd ever been emailed a virus before, you know?
And of course I didn't click anything or do anything as like you said, everything was really rudimentary back then. But, but, But, but, but the, the point of this, you know, particularly this, this conversation is there was no virus. The whole joke, you know, is there was no virus, the virus was the email, right?
Oh, okay. It was getting people sending emails back and forth, right? And then, and for those, you know, folks who weren't there, so it was More of a do a BDOs type thing or a spam, right?
And this, and I'm sitting there and in Mississauga, the Ontario, Canada, you know, this little internet company before we came up with a firewall idea and, you know, trying not to work, of course, and waste my time on Usenet like, uh, like the kids do these days. And the, and I just couldn't help chiming in and saying, 'cause everybody was saying, you know, stop sharing this email. It's not a real virus.
It's a hoax. It's a hoax. It's not a real virus, it's a hoax.
It's not a virus. And I just couldn't help myself. And I had to say, actually, I think it is a virus.
It's like a Wetware virus, which started this whole other argument thread that went back and forth and consumed more of the remaining last bit of bandwidth on earth. But it, but it was, uh, you know, and everybody, you know, shouted me down. Right.
You know, my my point though is I was just this young guy, and I don't know what I'm talking about, and I felt pretty sure about it, but all the authoritative figure in, you know, academia and so forth, jumping all over me and I now, you know, I do a podcast with Fred, you know, we've had a radio show together. We, you know, the last 10 15 Fred Cohen. Fred Cohen.
Yeah, we do. We're yeah. Talking all the time.
We're recording episode, another episode of that podcast tomorrow. And I guess, so I've got to, to, to, you know, live and have my career long enough to go and ask the guy that coined the term, right? Was that a virus or was I wrong or was that a mimetic virus?
Somebody wrote code And what did they say, Fred? Absolutely. It's a virus.
Yeah, we long, that's what I thought. Okay. Yes.
And it's, and it's, and it's proven to both our topic here and to kinda the world that, you know, we're talked, you know, we've talking about the, the past, you know, how we got to this point, right? And now we're at this point where things like that, this concept of a virus, everybody knows what a virus is today. It's not 1991 anymore.
But we're approaching, I think, a common understanding of what misinformation, mental viruses people are trying to write. Oh, yeah. It goes into your head and makes you do things like forward this email to your friends, just like in 1991 or whenever that was, right?
Yeah. Except, yeah, except 5, 7, 10 years ago. Most, you know, your, your friends and family don't really understand that idea.
But I think just like computer viruses, the misinformation, disinformation, information, integrity, you know, we wanna give it a positive, uh, uh, term is something we've all got in our heads now. Right. So where do you think we've gotten to with all that, you know, several decades of you and I and various other folks trying to get information and security into the popular culture, Into the minds of the common man?
Yeah. So I think that there's a lot more awareness. Um, she right, the non geek, right?
Yes, that's Right. But the normal people, but Right. Um, there's a lot more awareness.
Uh, so my Breaking Backbones hacker trilogy book has been at many, um, book reading groups. And one of the biggest ones, I was at a regional session with a bunch of retired ladies. And when I stood in front of them, they asked me to read a section from the book.
And then we did question and answers. They were very sophisticated in the questions they were asking about, I got this on my mobile device, this is what I did to get back at them. And I'm like, well, that's really smart.
I'm actually going to use that trick that you just taught me. 79-year-old lady, you know. So it was very nice to see the level of awareness has extremely improved since way back then.
I remember, uh, about 10 years into my career when everybody started getting mobile phones, the, I was at a bank, at my bank and there was this young girl pregnant with her young boyfriend, and they were e you could tell they had emancipated, they were on their own. They weren't 18 yet. And the girl comes in with her phone at this was heartbreaking.
She said, she started saying, and she was in line. She didn't wanna wait in line 'cause she was in trouble. And she said, I just gave this man money because they said I needed to, blah, blah, blah.
And she's waving her phone and she goes, now they want more money and I don't have any more money. What do I do? And the whole line, and all the tellers got silent.
And I was in the front of the line and I turned and I said, honey, you've been hosed. Like you're in trouble. You've got your money stolen.
And she goes, what? And she starts crying. I said, please step in front of me.
Go up and talk to a manager right now and see what they can do to help you. And that was my eye-opening moment about handheld devices and how we had the first level of us got educated. 'cause I came from a general assignment newspaper background.
That's why I am for every man out there on in the cyberspace. I didn't come from a geek background. So I remember thinking, okay, so wave one was email and computers, and then laptops, wave two was handheld devices.
She had never had a computer, she had never had a laptop. But now she had this smartphone in her hand and she was getting scammed off the phone. So fast forward 15, 20 years later, however long it's been since cell phones got into the hands of everybody.
And I think that the level of sophistication is gone. You know, we understand that bad things come in text. We understand that, uh, you know, people are trying to scam us on social media.
What we're not understanding is we still believe what we read on social media like nudes. And that's the misinformation part that's happening. Now.
That's the part that's really scary. I, as a journalist, you as a, a journalist and an analyst and a thought leader, I have to sort through stuff that I see. And if it's that hard for me, and we've got deep fakes and everything else coming down the road, we've got elections, we've got misinformation, social media is now the big bugaboo in terms of misinformation.
And how do we set filters? How do we create it, ease an easier environment for these people to either sort through or should we just unplug? Because did you read these Neil Stevenson's book 70 EEPs?
Oh yeah. Okay. Do you remember how the Space colony basically killed themselves off because of misinformation on social media?
I Love, uh, Stevenson. And my, my first bit of journalism was a article in the, uh, in Index news in the 12th grade, uh, uh, high school news newspaper where I did a review of T HX 1138. And my summary there was, this has nothing to do with futurism.
This is commentary on current social issues. And I love Stevenson, but you know, who does the same sort of thing, right? So I'm, I'm hoping, and that's my whole, so whole point of this whole inevitability curve thing.
And it is, is that 5,000 years from now, we'll probably have figured this out, even if the moon Calls 5,000, we need to figure it out. That, but 87 inside joke for the Neil Stevenson fans. But, But this is, yeah, I think that's, I think this speaks a lot to where we are right now.
Right. And, and again, your background is, is a fascinating one on top of it because you've both done this, you know, transition across the, what we now call content creation. We used to call writing.
Uh oh Yeah. There's so much content out there now. But, uh, you know, but, but in cybersecurity and privacy and cyber crime and all these other related topics, right?
And mm-hmm. And I, I find in the information integrity space, you know, I, I think that really is the issue. You know, we ca we see dis information campaigns and influence campaigns of, you know, malicious actors and so forth.
But it's really not all of those negative things. It's, it's, it's about information integrity, right? We've got, you and I both know that the actual ability of the, you know, public-private, commercial, technical community to deliver the integrity you think you're actually getting from information.
Uh, we're not there yet. It never was. So We, I mean, my really LinkedIn Want to change things by, you know, issuing a certain amount of b******t that's actually possible for now, but it's not likely to be possible forever.
And in part because of what, you know, we're just talking about that. I think everybody, all of my friends, I had a shout out to a life, another lifelong friend, bud Houston, best guy on earth. I've known his son Tre since he was born.
He is, you know, now a, a military, uh, retired mil military veteran. Great guy. Great, great.
I wanna say great kid because I'm 60 years old, but whatever. Right? And he's, you know, he was exactly the kind of guy, you know, he very patriotic, you know, very energetic.
He is always has been believe it was this tall, holy cow. But, uh, you know, and, and so he is absolutely not an idiot, right? But, you know, he is, thank God, you know, in some of the same social media that I am, instead of retreating and saying this, I've had the opportunity to counter a little bit and say, all right, you know, what you're seeing, I don't think is what you think it is, and connect him with other friends.
Why John Baumgartner, you know, John and, uh, uh, who Oh yeah, He's been posting about he and his damage in Nashville, Right? And he's, the, this is, you know, for anybody who doesn't know John Baumgartner, you should, 'cause he's a, a, uh, a retired military combat veteran, you know, wonderful guy, peer, you know, peer end pillar and icon of the information security community as reputable source. I mean, seriously, if you get, you want any more better than Joan, you're not getting, it lives in Nashville.
His tree was hit by an 80 foot oak tree. He is been organizing his community and he understands emergency response, right? So, Yep.
And he's been sharing those, his capabilities with his community, Right? And his experience with the rest of us. You know, and to, to our point of our, our, our thread here, I think that sort of thing works, right?
I think we need better technical things and maybe some regulations, God help us, or, you know, laws or whatnot on how information is is handled. But I think most of it is a, a public understanding. You know, we need to evolve past this.
Maybe a generational kind of thing. I think Trey's generation is in a better position than ours, perhaps, right? To really understand.
I challenge that assumption a little bit, Chris, because we are sharing understanding. We fact check, we put stuff out there and people still wanna believe what they want to believe. Well, I, I, I, my caveat, you know, to what I just said, it was today, right?
I think in 10 and 20 and 30, 40 years, you know, well, that this generation now is, you know, living through it from, you know, my kids' age, you know, the 20 something to 30 something, right? You know, um, Much more exposure than we had when we were kids. We had no exposure to any of this.
You know, my kids grew up with one computer in the living room, and now they all have their phones and everything. Parents have to deal with that. So everybody's getting exposed and from a very young age now, and what does that mean?
Sometimes I think we are part of a large video game that we put ourselves in that's very realistic. And when we die, we go back to whatever it was we came from. And then we have a virtual world within the virtual world happening now.
And it, you start looking at this, like, when you're looking at a hundred different mirrors, and you see all the images of the images of the images, and that's what it's feeling like to me right now. You know, It, it, and it really does, right? It's really common.
You know it, and it's easy to feel that way. And you can see us expressing it through popular culture, mor, you know, um, Mor not Morty, Rick and Morty, right. You know, and that the, the multiple, there's so many different parallel universes.
Doesn't matter what anybody does in any one of them, or simulation. I like that one. Right.
You know, we're living inside of simulation, inside of simulation, inside of simulation. And, uh, and I think, you know, so, and looking, you know, just try to, you know, get this at, at the end of this looking forward, right? So I think we posit this.
I do think, you know, the generations coming up, the millennials and so on and, uh, around them, um, will over time, I think they were kind of the answer to, you know, this information integrity thing, in part because as we just say, I think So too. They were literally, you know, you and I have had to learn this. You know, we came from a world where, seriously, the amount of information, when you say three channels of television, you don't understand.
Right? I remember those days. Right.
And that's, you know, you know, the antennas and tinfoil and, but we really do have a, you know, a a cohort of folks who are coming along who are quite bright or quite educated, quite connected, you know, maybe as a, as a gestalt group, a little confused today, but give them 10 years, another 10 years and another 10 years, and tell me we haven't worked our way through this. I agree. I, I might be working on a book about seasoned expert advice from our top security pros, the icons in the industry.
It's may or may not happen, but if I do, I think that what we need to do is we need a two-way dialogue from the old folks down and from the young folks up, because I know young folks are much more open with their use of technology than I am. I am, I'm shy. I'm not shy, but I'm careful what I adopt, what I don't do, TikTok, I don't, you know, I use Instagram, but not TikTok.
And I, there are places I stay away from because I know that they're not controlled by the US or, you know, other reasons. And the rest of the kids, the younger people just don't care or where their platforms are gonna be their platforms, or gonna be their platforms. And so I look at that as they are going to be teaching us eventually because they've got the background and the savvy that maybe some of us don't have.
You know, I heck with three kids in my, in their twenties. They're spanning that decade. I am biased, you know, that's my, uh, that's my bias statement.
I, I, I just agree. And it was just not to say I know what it is exactly what that future is gonna look like, right. But I, I see, you know, that's certainly the ability, you know, we are gonna have the ability to have a good future, you know, 10 years and 20 years and 30 years and 40 years and 50 years from now.
Best, you know, more would Be, I won't be here then. And, but yeah, I Fact on, I won't either, right? I know young folks who will and, and, and heck with some medicine, you know, I'll always try to look at that one.
It's like, look, I'm not planning on Ben, you know, being the one, the first one to benefit from, or sending, you know, technol, uh, technology or medicine, whatnot. But I won't be surprised at any point in my life, you know, it seems more and more clear that someone my age is gonna live to be really old. This, if you're lucky enough to live to 120, anyways, you're 60 now, we're talking 60 years from now.
You might be, you know, a good candidate for some of the, you know, genetic where God knows what, uh, medical changes happen in the next 60 years. So that, you know, none of us need to count on this to, to my point here. But, you know, we're in that realm, right?
So my kids, you know, the generation after them, generation after them, you know, there are people walking around right now that I have an interest in seeing the future for and thinking about this, right? And on this true that every time I've seen angst and, you know, uh, uh, all, all my life, right? Where they're gonna run out of food, we're gonna nuke ourselves to death, yada, yada, yada.
Uh, haven't so far. It's amazing. We haven't yet, right?
It's amazing. We haven't yet. No, I, I frankly don't think we're going to.
Right. You know, I don't think Kim Jong is gonna launch a thing because he likes his caviar and schnapps, and he is spoiled little brat. But, uh, and you, that's spoil A big Brat.
Yes. But, uh, Well, so, but yeah, back to the future, like where we're going in the future, I see some of that where the younger people are gonna come up the ranks and come up with new solutions and new ways of utilizing technology and then screening my whole career, I feel like I've been a, can I use a bad word here? Oh, Absolutely.
It's brought me on, on the internet. My Whole career has been to be a s**t screen. And there is a lot of information coming at security leaders that needs to be filtered before it gets to them.
Uh, because every vendor in the book thinks that they have the silver bullet. And my whole job has been to be say, yeah, no. So you fix this little problem over here, but there is these 10,000 problems over here that you're missing.
And so no way are you gonna be the silver bullet. It's also asking the hard questions. Were you at the Cisco event when, I don't know, 20 years ago, I raised my hand and I said, excuse me, Mr.
Cisco people, it seems to me like we should change internet protocol. We should change ip, or we should get rid of it all together. I got laughed out of the room, and now we have IPV six, but even that isn't good enough.
We're still on technology that was created in the eighties, and it's open and says, hello, here I am. I'm sending out my beacon. Hello.
I'm here. Come hack me. You know?
And that's the way I've always seen ip. And so the whole thing about Cisco laughing me out in the room, and then 20 years later we've got IPV six. It just, those are the hard questions.
No one really stops to ask. No one really stops to, maybe we do need to tear it out and start over or start over and then tear it out with some, you know, once we have something better, you know? But those are the big questions who I think we need to be looking at in the future.
I, I think, uh, you know, this, this, this is, this conversation has led to an interesting point, right? Because I think that, you know, if I was be really honest about the, the short term future, the next 20, you know, 20, 30 years on these topics, um, it could go either way. You know, it's, it's tending to look pretty ugly.
You're right. There's so many legacy issues that it will take a lot of redoing. Um, but in that same, uh, era, you know, this whole cohort of, you know, what, you and I can call kids these days, you know, we're gonna get to our age, and they'll come up with all sorts of amazing things.
So I think we'll get out of that midterm, you know, that, uh, that, uh, that we can see really, you know, see close enough from here to, to, you know, do things about it. Um, I hope that smart people don't get egos though, like Elon Musk has. And I think that we need smart people helping, but not trying to become gods.
And I find in, in technical, technical industry, there's so much ego. And as a female in the industry who has to interview a lot of men, I'm very good at petting their little egos to get the information I need. But, you know, come on, this is a huge problem, and we're all a team and we should all be working together.
And there should be no gods of tech out there, and there should be no billion bazillionaires in tech out there. And I hope that the younger generation is able to collaborate and, you know, not push up these icons like Elon and let them be the deciding factor of everything, you know? Well, I, I think if I look in inside my, my home, my kids, I think, uh, I think we're in good shape.
So we'll have to, we'll have to see. Well, Deb, unfortunately, we have tabs, the allocated time bucket again, and, And we just barely scratched the surface, Right? That's kind of the whole, the whole point.
You know, and I, I'll, you know, I'll the last thought on my own on this, and you can have yours, but, uh, I think that's the most fascinating thing about the near and far future. We're all, you know, obsessed with AI right now. And ai yeah, AI is doing a lot of things, but the thing we're really good about is doing a few right.
You know, you know, we all know the yes, the, the old truism about, you know, items actually seeing a very small part of what I think I'm seeing my eyes aren't really biologically capable of grabbing, you know, uh, the definition of a camera. I'll always be the case, right? We had to, we have 35 minutes, you know, we we're not, you know, made outta silicon.
And that's where we find our arc. Correct. Well, I just wanna plug my book, the Cyber thriller series, the Breaking Backbones Hacker Trilogy.
Just look it up on Amazon or anywhere you buy books and give me good reviews, please. I need to play the algorithm game, speaking of social media and algorithms and everything else. So it's a constant hustle, uh, to get people to buy these books, but they buy them and they love them.
And so I've got all five star reviews, and some people who read them are technical, some are not. Uh, some think they're too technical. Some think they need to be more technical.
It was the balance I was trying to get all along throughout all three books. So hopefully you'll enjoy the story. 'cause it does start with a drone more and a kamikaze drone in book one, and takes off from there.
And when you read 'em, you'll know that I actually wrote them for Netflix. And I do have a producer. Uh, we haven't been able to get it off the ground yet, but we're still working on that.
Well, I, I thoroughly endorse all those and, and, and give the book on Amazon, Kindle, those nor normal places, or, and I will have a link As well everywhere. And we will put a link. Let's definitely put a link in the abstract.
Got it. I'll send that to you. Awesome.
Alright. Thank you. Thanks everybody.
Thanks Chris. Wonderful to see you from Hawaii, right? I usually ask that From Maui.
Yes, from Maui. God bless the Internets. All right.
See you folks. Look Woody, as far as the eye can see, it's the great American firewall you are watching Text on Gang. Hi everyone.
Happy Tuesday. It's Alan Shimel here for the Techstrong Gang. You know, we're running, we're running lean, mean, and lean here on this Tuesday.
I've just got two other gang members with me today. So we've got a bunch of people flying and trains, planes and automobiles, but couldn't think of two better people to do this with. Let me first go to our steady Eddie in Hudson, Ohio.
He is the founder and, uh, president, or CEO, whatever. He's the man who breeds life into tech field day every day. And he is also a great gang member.
Stephen Foskett. Steven, welcome to the show. How are you?
I'm pretty good. Um, I prefer galactic dictator. Uh, that would be a good title for, For me.
We already have one of those, I thought. Okay. Or, or maybe Alan Shimel understudy after last Week's activity.
Yeah, that's, say, you know, I saw there was a little insert into the, uh, program for the gang, right? Tonight playing the role of Alan Shimel is Foskett. Um, funny stuff.
Stephen, welcome and thanks for being here. Um, joining. Steven and I live in our Boca Raton headquarters.
She's our sustainability Echo Insights, and she has a report coming out soon, but we'll tell more about that in the days and weeks ahead, our own. Bonnie Schneider. Hi, Bonnie.
How are you? I'm doing well, Alan. Thanks for having me.
And I'm looking forward to talking about that. We, We call that a tease. Yes, those Are good tease.
Okay. Um, so guys, let's just jump right into things here. You know, I led off with this great American firewall.
It, it's funny, uh, you know, a little bit of competition, and all of a sudden everybody's putting up, not everybody, but a lot of folks even in Silicon Valley, where we, I would think we would know better, are, are calling for the government to help them. And, you know, those are the nine most popular words, right? I'm from the government.
I'm here to help for government help in keeping out, uh, AI products, AI technologies that's not here in the us. And, you know, we want to keep out content, we want to keep out students, we wanna keep out, we wanna keep out a lot of people, a lot of ideas, a lot of technology. Tee out seems to be the key phrase here, Steven.
I don't know. Just these things never end well, but what do you think? Yeah, I think they, they don't end well.
Um, you know, walls have a tendency of trapping you in just as effectively or maybe more effectively than they do to trap people out. Uh, it's sort of a truism that, uh, you know, you're more likely to be stymied by your own lock than somebody else be stymied by it. But the interesting thing with regard specifically to AI is that the more that they've tried to track crack down on China's access to American technology around ai, the more that the, uh, Chinese researchers have figured out ways of getting around it, whether that's making the most of the H 800 and then the H 20, or whether it's figuring out, uh, optimizations for training.
And, uh, you know, I I would say that the Biden administration's policies on toward China are the direct cause of deep seek mania that we lived through last week. And frankly, if there's more great, uh, controls, uh, placed on access to technology, it's likely that, uh, it will divide the industry even further. And we'll see China have even more, um, homegrown, uh, development technical developments.
Now, it is important to point out that their technical development is not entirely homegrown, as we've learned since the announcement of deep seek, it leveraged. Uh, it could not exist, not leverage it, it literally could not have been done without literally all of the previous work of developing AI models and without literally using the AI models that had been exported. So maybe if those had been controlled, they couldn't have done it.
But I, I'm not really sure how well those controls might work. And frankly, uh, not to sound too much like a libertarian here, but maybe if we allowed more people more access to stuff and had a a, a more free market, it would prevent, uh, strange market distortions like we're seeing. Yeah, I think that's true as well.
I think also there can be more of a balance between, uh, protecting intellectual property and also, you know, maybe not the extreme, like Steven was saying, that with a wall there comes consequences. But, um, having a, a little more guidance when it comes to intellectual property theft, which tends to lead to this on a larger scale, uh, particularly from China, I think that's an important thing to note. Yep.
You know, Steven, a smart man I know once told me, when you build a wall like that, it tends, tends to keep you in and not stuff out. And I think that's what we are guilty of here. Um, look, I, we, we've discussed this in past gangs, the irony of, of, of OpenAI claiming deep seek used their, you know, scraped their information without permission from a company that scraped the internet and their entire being was used without permission is pretty ironic.
But at the end of the day, I, I'm not necessarily a libertarian either, but, but Steven, I, I have to agree with you. I think this is a case where if you put it out there and we're all better off, we're all better off as humans as a result of it. Now, that being said, there's gotta be rules.
There's gotta be rules you play by in terms of theft of IP and respecting ip. And, and certainly the Chinese over the years have been guilty of, of stealing IP and using it, whether it's espionage or, you know, state sponsored espionage or commercial espionage or just pure theft. Um, and you need to put safeguards in place that you need to deal with that.
I don't, you know, I'm not saying go put tariffs on them for it, but, um, but you need to, people need to respect the, the, the, the rules of the game and then let the winners come where they may be. Um, but I just think it is such a bad idea, such a bad idea to be thinking about building a, an American firewall where we're going to try to keep others out, keep our technology to ourselves. It, it, you know, it, it just doesn't end well.
I'm sorry. Yeah. And I think it's contradicts the open source transparency.
It, it's almost like you wanna have it both ways. It, it contradicts, you know, whether you agree with the libertarian philosophy or not, there is something to be said about the power of a free market to, to foster innovation. And, and you know, what you got here was a great example of, and, and I wrote this in an article two weeks already.
Now go, you know, necessity's the mother of invention. If you don't give people access to this, they'll figure out how to, you know, I'm reminded of Star Wars when Obiwan tells doth he could strike him down, but he'll be stronger than he ever was. And, and that's what you get here.
Let, let's not be doth Vader. Yeah. We don't wanna be Darth Vader.
And, and, you know, so, so earlier I, I was channeling the, the libertarian mindset. I don't wanna sound too protectionist, but I I can actually see a case to be made though that there should be controls on applications and access to, uh, certain applications. I mean, you know, the flip side of a free market is that the government's role should be in interest in maintaining, uh, freedom and fairness in those markets.
And so, for example, anti-dumping laws make a lot of sense. Like we shouldn't allow, uh, a, you know, AI model from some country to be introduced, um, with, uh, massive government subsidies or something so that it undercuts competition and cuts off competition. We also shouldn't allow free access.
And, and, and, you know, no one, uh, not the Chinese, but not the Americans either should be breaking copyright controls and ignoring robots text and slurping up, uh, literally, uh, libraries full of copyrighted works in order to build their models. Nobody should be allowed to do that, because that breaks the free market too. I think that that's one of those things where people forget that, you know, with, with freedom comes responsibility.
I'm not Spider-Man's uncle, but, uh, you know, something like that. You know, if, if we're gonna have a free market, we also need to have very strong control, uh, and, and responsibility, uh, to make sure that we're actually, uh, playing fairly. A free market requires fairness.
And so in my mind, the government ultimately should be interested in promoting fairness and democracy and freedom along with promoting capitalism. And that's an issue with the new administration. They seem to be very interested in capitalism, but not very interested in promoting, uh, fairness in the market.
Agreed, agreed, agreed. Well, you know, and unfortunately, uh, you mentioned the, the Biden administration, Stephen was, I think, very guilty of, of squeezing it so hard that they let the sand run through their fingers. That might be child's play compared to what we see over the next four years in this.
Um, and I, you know, I, I fear we are going to just be putting up walls. I mean, this, this is an administration who ran on walls, They love walls, golden walls, tariffs, and are just financial walls. Yeah.
So, we'll, we'll hope for the best. Mm-hmm. I guess, and prepare for the worst as well.
Because the other thing is you put up a wall and you, you know, because you want to keep out, let's say in this case, China, well, what about some of our so-called allies, or they, they were our allies. I don't know how much longer they'll be our allies, but, uh, you know, we need that global collaboration. We, you can't exist in isolation, like, right, this, this is a lesson of history that, you know, and you don't learn the lessons of history you do to repeat them.
So anyway, we're gonna take a break. You know, I'm Pink Floyd song, you know, VE the Walls, um, was a great album. Did I ever say I saw them in Nassau Coliseum?
S oh, NAAU co. I guess it was maybe 1980, maybe. Something like that.
The Wall tour. Yeah. It's Tear down the wall.
Anyway. All right. You're watching Textron Gang.
Discover Techron Group, the epicenter of Tech Innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Well, here's our surprise for the day, the DOJ is actually suing to block a merger, uh, $14 billion, uh, HPE takeover of Juniper Networks, which I thought was long done, but evidently not. Steven, this doesn't, this doesn't sound like, was this a leftover from the last administration?
What, what do you think? Yeah, it definitely is a leftover from the last administration. Um, we actually covered this on the gestalt it rundown, uh, just before, uh, the handover of power when it was originally announced.
And, um, I suggested at that time that maybe this might change, uh, under the new administration or maybe not since. Uh, I was also wondering if maybe they might keep Leanna Khan. They didn't spoiler alert.
Um, but they did, they do seem to have, uh, some of the same antipathy toward Silicon Valley companies and, and so on. So what my suggestion at that point was, you know, it's not a sure thing that the DOJ would drop this case, and sure enough, they haven't. They've proceeded with it.
Now, I don't want to say that it's, I don't want definitely going to proceed now. They have proceeded with it. Uh, but I, I wonder too, this could be something of a leftover or some momentum in the court system or, or some, uh, remaining Biden administration, DOJ folks who are continuing on with their goals and their mission and their project in hopes that it won't be shut down by the new administration.
Um, but regardless of the politics of the thing, I think that it's also important to consider the implications here. Um, we were, you know, essentially we have a few remaining enterprise it, uh, juggernauts, you know, we've got Dell and HPE who are extremely strong and, you know, kind of a full platform, uh, partners for the enterprise along with Lenovo, uh, as a key, uh, full platform partner as well. And then we've got a lot of these, uh, monoliths that are extremely strong in their area.
So you look at companies like Juniper or, uh, NetApp and Pure Storage and vast data in the, in the storage space. Um, but in the networking space, you know, Juniper really does stand alone as a interesting and very successful, uh, competitor. I guess you could put Arista in that market as well, and that, but Juniper, I think, has, has been able to really find incredible success in, uh, a couple of verticals, basically internet routing and switching.
And now thanks to the missed acquisition, uh, enterprise wifi, to the extent that HPE, which, uh, owns the Aruba wifi assets and has been very successful with that, has been gunning for Juniper and Mist with their Beat Mist campaign for a while. Now, Cisco, uh, remains by far the leader in some of these markets, but Juniper is a very, very strong competitor. And HPE in many cases is the third player in those markets.
Um, and so having HPE acquire Juniper really is sort of a consolidation of, uh, you know, kind of the number two, number three in many markets into a very, very strong number two in those markets and would according to the DOJ stifle competition. So, you know, if we look at the, the acquisition from that perspective, I can absolutely see why the DOJ might be interested, but frankly, I can't understand why the Trump administration would be interested, because these are very, um, kind of below the radar companies. Even HPEI, I can't imagine, has much of a seat at the table in this new administration.
So let me, let me expand on that and excuse me for being snarkly cynical someone. That's what we Expect, right? Someone didn't pay their million dollars for the inauguration ball fee.
Mm. And if someone does come over there to kiss a ring, this deal will be allowed to go through. That's my 2 cents.
But to your point, Steven, you're right. The network, and I think this, this deal is not just IT enterprise IT infrastructure per se, you know, meaning servers and, and some of the things that Dell, HP and Lenovo do, but this is very specific to networking and wireless networking and, and the market isn't what it was, right? You still have Cisco, who's the 800 pound gorilla, but when we talk about networking, especially high speed networking and stuff, you know, where there's a big money, big dollar boxes.
Steven, you left out Broadcom. Well, that's true. And, and because I was really focusing on the wireless, sort of the traditional enterprise market right now in the cloud market, Broadcom is the massive gorilla because they are basically the, the OEM to the stars for all of that market.
Um, they, they do a tremendous, tremendous amount of business there. And of course, they also are the developers. They're sort of the quote intel inside for most of the rest of the market as well.
Uh, yeah, absolutely. Broadcom as a company that, uh, ought to be as below the radar as they possibly could to keep, uh, any DOJ interest near well, Especially not being US based, right? Yeah.
Well, I think Broadcom is technically a US based company, aren't they? I'll, I'll look it up, but I, but you're right. I mean, Antonio Neri definitely should get on a plane to Mar-a-Lago and, uh, and bring a suitcase full of money.
And I bet that this, uh, particular one will go away. They Always say to bring a suitcase full of money to Florida, remember you are to Florida, bring a suitcase of money. But, But yeah.
So when you look, and, and the other thing is, you know, I, I grew up, if you will, in the internet age, from a career point of view, right? Most of my career, well, a good chunk of my career has been spent in the, with the internet and Juniper. Yeah.
Juniper represented the fresh, bright, you know, next, that next gen networking, if you will, right? I look security, they bought the net screen firewalls, and that that was the hottest stuff out there. They were the first ones that really hit Cisco Square in the nose with high speed routing and, and that kind of thing.
And They've been very successful with that. Yes, They have. And they always were.
But over the last five to seven years, you know, they, they fell on some harder times. I I, they didn't though they were big in, in being the internet network of a gear of choice. They didn't catch the cloud wave quick enough.
And, and Broadcom did eat their lunch there. Um, you know, Cisco is Cisco HP Pro Curve, and then they bought, as you said, Aruba and, and all of that. They, they, they've kept their niche, though.
You know, it's funny, I was just talking to Fernando Montenegro, the new, uh, FU analysts for security who used to work at Pro back in the early two thousands, and we were talking about what an opportunity squandered there. They could have been a strong number two to Cisco, right? And who knows what Juniper or Broadcom would've done had there been a, a more powerful, a more, well, you know, strategized, uh, pro curve.
But, um, well, it's interesting. Go ahead. Yeah, I mean, HP and HPE, uh, have a long history of attempting to become, uh, a competitor for Cisco.
I mean, I worked for Threecom many years ago. Sure. They bought Them too.
And so certainly there have been many, many attempts by hp Yeah. To, uh, to be active in that market. And this, this latest one, uh, you know, Juniper would give them, uh, really a solid foundation.
Um, that being said, yeah, I, I, I don't, I wanna predict whether the, it really would like an HP plus Juniper really would, uh, end up becoming a, a, you know, a a, a strong kind of two horse race instead of, uh, a one horse race and a bunch of, uh, competitors. Um, and then on the Broadcom side, by the way, I can confirm Broadcom is a hundred percent American company and always has been. So, um, just their CEO lives in Singapore.
Well, he is from Malaysia, but he, I think he lives here, doesn't he? Um, well, that's another topic anyway, but, uh, but Htan, uh, you know, I mean, he, he's a incredibly, incredibly sharp guy. And, um, I think he's been sharp enough to, uh, yet stay below the, below the radar.
'cause I think, I think if you, even if you ask tech people, I mean, here we are on the Textron Gang, and we have some con confusion about Broadcom and so on. They're the number, probably the number one company in, in tech in terms of, uh, importance of their products. And, um, and like you said, I mean, especially when you look at their, you know, the, the, the depth and breadth of their networking capabilities and talent and products, they're everywhere.
And yet, you know, many in tech, I think would kind of overlook and forget to even mention them. And I do wanna make sure that we point out Arista is another incredibly strong, uh, powerhouse in networking. They're in wifi, they're in security, they're in, you know, enterprise and, and campus switching.
I mean, they're, they're all over the place. You know, we're seeing a game of musical chairs. That's kinda what I was alluding to at the beginning here.
I think Juniper felt that they needed a chair now, and HPE provided that chair. So it's in Juniper's interest to make this acquisition go forward. I think when Juniper sits down with HPE, which I do think they will, I think it's gonna go through, I'm, I'm not super worried that this thing won't happen.
I think when that happens, um, we're gonna see attention turning toward Arista and Pure Storage and NetApp and some of these other competitors and figure out, okay, where's your chair? And that could be an interesting 2025. Absolutely.
Steven, we'll end this segment with this. I agree with you. I think ultimately this deal gets done.
DOJ drop set, whether it's someone goes to Florida with whatever, or, or something else, this deal gets done, we'll Update it on, on the gang. We'll Keep you posted. Lemme Tell you, Trump Presidential Library is gonna be the Taj Mahal.
'cause remember, they're not all this money. You say what you want. All this money is not going to Trump.
It's going to Trump's presidential library. Oh, and yeah, exactly. You know, and that my words, words, the day they put him in the ground, his children will be fighting over every cent of it, and none of it'll go there.
It's Gonna be like succession. Exactly. That's exactly what this could be.
Anyway, let's take, Steven, you're making me, we, we need a balance. Oh, we're gonna take a break here on Text Organic. We'll be back with a, a special report from Bonnie on Sustainable technology for the DOD.
I'm Bonnie Schneider, sustainability contributor to the Techstrong Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry.
Position your company as a leader in the industry and differentiate from your competitors with the sustainability Pulse meter offered exclusively from Techstrong Research. Welcome back to the Techstrong Gang. Earlier we were talking about a, a lawsuit, whether it's going to be, whether it was leftover from the last administration, what's gonna happen with this administration?
While our next story is also sort of related to the changes in the administration. And I'll tell you why. Because late last year, the Department of Defense began testing sustainable materials in weapon cleaning, um, in efficiency in buildings.
And that policy was successful. So now they're looking to expand it across military operations. Now, that was the end of last year before this new administration, but we'll see.
It could be something that's carried over. So I wanted to take a closer look at the technology behind sustainability in the military. Hi everyone, I'm Bonnie Schneider with your Ego Tech Analyst insights.
What does soybean oil, LED lights and a bio-based weapon cleaner have in common? They're part of a new US Department of Defense program to test and deploy sustainable technology. How is this implemented?
Well, one example is found with a weapon cleaner made from agricultural materials instead of petroleum. When tested by Marine Corp shooting teams, the cleaner reportedly cut maintenance time in half from 60 minutes to 30 minutes per weapon and reduced carbon buildup by 30%. Based on these results, the military issued its first sustainable materials requirement for tactical equipment.
All weapon cleaners must contain a minimum of 30% bio-based content. Other eco-friendly measures include smart controls for lighting and heating for military buildings to reduce power use. The Department of Defense is expanding the sustainability program across major commands, focusing on technologies that meet performance requirements and supply chain metrics.
You know, a lot of these things just seem like common sense, uh, being more energy efficient in buildings, for example, that's something people are doing across the board, but the, the biodegradable weapon cleaners, um, maybe there'll be some objection to that. But overall, from, from what I've seen, the, the members of the DOD that, that are involved in this project, were very pleased with the outcomes. And as the people that were using the weapons also were pleased with the results they were getting.
Steven thoughts? Well, let's, let's get a little bit of context in here as I love to do. So, first off, the bio preferred program was from the, actually the Department of Agriculture and came out of the 2002 Farm Bill, 2002, not 22.
Uh, and so the idea that the federal government would be investing in bio-based products is not new and is actually pretty entrenched. Unfortunately, from what I've seen, a lot of that has been somewhat controversial in whether or not those bio-based products are actually all that good for the environment. I mean, if you think about the controversy over bio, uh, diesel and, um, ethanol based fuels for vehicles and so on, in, in many cases, those things may not be as good for the environment as, as we would hope.
Now, having this extend to the DOD and, uh, to certain programs like, you know, weapons cleaners. Sure. Uh, if the product is good, and it sounds like this product, uh, as Bonnie pointed out in the story, is a pretty good product.
I can't imagine that people wouldn't want to use it. In fact, uh, I did a little research on this thing, and it looks like, uh, uh, home gun enthusiasts, yes, we have those in America, uh, for our international listeners. Um, they like this product too.
So in that case, I imagine that this would probably take off if the thing works and is affordable and, uh, you know, is, is a good product. Um, same with, you know, smart lighting. Uh, you know, smart lighting is not in, in itself a controversial topic, especially when, as you look at the statistics here, it says that, uh, 10% of the electricity used on military bases is for exterior lighting.
Uh, yeah. How about some smart lighting? That seems like a good idea, but at the same time, I'm just a little nervous that somebody in this current new administration is gonna get wind of something, something bio, something, something.
Yeah. Climate Climate. Mm-hmm.
And that they're gonna squash this thing down right quick. I mean, Trump has already talked about how much he hates LED light bulbs and low flow showers and electric cars. So Good luck.
No, it's true. It's true. This is gonna be one to watch, I think, um, going forward.
Let, let's not kid ourselves, they're gonna say, this is some b******t and try to get rid of it, right? That, and that's unfortunately the current state of affairs in this country. Um, they've already, they, they will purge it from the website as they're purging all of the research and stuff being done.
I was, I was Shocked to find that it's still on the website, by the way. I looked it up and I was like, oh my gosh, gov this is, this is gonna go out in an anti woke kind of thing, and Somebody's gonna hear about it on this show. You right?
And they're gonna call Pete hea. You know, this is, look, elections have consequences. Well, you know what, at least in, in the, in the shorter term, um, as Steven's pointing out, there's awareness about it.
Um, if home enthusiasts are finding it effective, it will gain, gain awareness and maybe gain some traction. Um, there were some, I would say controversial aspects of it, because we're talking about smart lighting and some of the testing is done with night vision. And I think that that's gonna be hard to measure, especially in the case of, you know, a serious emergency, um, where I could see, you know, both sides coming out, you know, with, with viewpoints on it.
But as of now, in early 2025, this program still, in fact, Look, when the official policy of the government is, is that climate change isn't real when you're not allowed to mention any of these types of, of clean energy and drill. Baby drill is the motto. You're kidding yourself.
Okay, let's end on the positive note. Okay. How about a positive note?
I'll give you a positive note. As I've said about solar panels, the same is true about LED lighting. The same is true about some bio-based materials.
The same is true about batteries and electric cars. It, when the horse is out of the barn, when, um, when wind power is a, uh, effective and, uh, money generating industry across the world, you're not gonna be able to squash that just because you don't like some aspect of that. If, if, if the product works, it's gonna get used because that's how things go Across the world.
That's great here within the confines of our walled environment. Who knows? But I hope so, Steven, uh, I think that's gonna wrap up our tech strong gang for this beautiful Tuesday.
We'll be back tomorrow Wednesday with more fresh, good stuff to talk about. Lot going on in tech. Yeah.
Uh, we're coming into conference season as well, so we'll, we'll get some updates there. But until then, Steven, thanks. Well, Steven, when's the next tech field day?
Well, we are looking at, um, we're gonna be at Cisco live in Amsterdam, and we are also, uh, getting ready for Cloud Field Day, and both of those are happening here in February. com for more information on those. Great.
Fantastic. All right, until tomorrow, then. This is Alan Shimel for Textron Gang.
On behalf of Steven Ani, thanks for joining us. As usual, we've got a full Techron TV lineup following this, so do stay tuned for that. But until then, we're out.
This is Textron tv. Hey, everyone, we're back here on Techron tv. You know, I'm excited to have this next gentleman on.
He is the founder and chief innovation officer at a, a company called Axio that you may not know about, but you're going to, if you listen in here. Let me introduce you to Baam El Kdi, uh, BAAM. Welcome to Text Drunk tv.
How are you? I'm doing well, Alan. Thank you for having me on today.
I appreciate it. Ah, it's a pleasure, man. So, BAAM, as I said, we're going to get into Axion.
We'll introduce it to the audience and they'll find out all about it. But I wanted to spend a minute or two talking about you. Right?
Uh, what did you do before you founded ard, before you Chief Innovation Officer here? Give us a sense of your journey. Yeah, so, uh, always my journey has always been within security.
You know, it's, it's what I enjoyed. It's what I like, started in the, kind of in the biometric field, uh, with biometric authentication. Uh, and then really had an, an amazing opportunity to work on a couple of the biggest, the most complex programs global, uh, which is the, uh, department of Defense common Access card, uh, the US government, uh, PIV card, right under the, uh, under HSPD 12 directive from the, from the president at the time.
Uh, and really those, uh, were a, a big turning point in my career and learning what proper global real security truly meant. I remember those days, you know, back back, one of the companies I co-founders was called, still Secure. We did a lot of business with, uh, DOD, tech d, the agencies and so forth.
I, and we, we did what they had a knack, if you remember back in those days, network access control. You get a call one day that, uh, if we could detect if the USB ports on laptops have been disabled, yeah. Using that test, we could detect that pretty easily.
But why would you want to disable all your USB ports? Don't worry about that. We just wanna make sure they're disabled.
And, uh, of course, later we found out, you know, mm-hmm. Chinese had of course put USB, uh, you know, uh, plug in the parking lot and people were just plugging them in. But it was around that time that the cards came out, right?
That you couldn't log in to just any, any, you know, DOD laptop without your, your identity card. And it, it was a huge deal. It was a huge deal.
That's a huge deal, right? It kinda was game changing in some ways. Um, so you, you doing that, and I guess that kind of introduced you to the whole world of identity and access management, huh?
Absolutely. Absolutely. And it was, uh, it was interesting, right?
Because, you know, working on, on, on global pros like that and had the opportunity to work on other global programs in Europe and in Asia, what was interesting is those were all, uh, government funded, right? So, um, before starting axed, right? What was brewing is in, in my head, is this is amazing what, uh, what these programs do and how they secure, how they secure the nation, but how does enterprise tackle this?
Really, that was the brewing question. And why does enterprise do something like this? Right?
And it came down to really two really simple cornerstones. One, no one has the, the, the massive budget to spend. That's one.
And even if you go to, you know, the Fortune 500, the global, uh, 2000, which could spend a, a significant amount of funds, they don't have the personnel, uh, to lead this, right? From an experienced perspective, uh, from a global presence, right? So it, these two challenges were the heart of why organizations can't do this at a pretty large scale.
And I'm talking 20 years ago, right? So that the, the, you know, going back in time now, things have evolved a lot with, uh, with a lot of the cloud computing and a lot. But 20, 25 years ago, uh, that was a, a big hurdle, uh, for organizations.
Absolutely. And, um, look, it was interesting, they just, the interview before this, I was talking to someone who did a they part of a, a report. Only 37% of companies are using multifactor Yeah.
Right? And again, it comes down to two really simple thing, uh, you know, complexity and costs, right? So when I started Axio, we, we had a simple goal, or a simple vision that we wanted to achieve, which is we wanna make identity security simple, effective, and real right Now, easier said than done.
When we, when we started this journey and, and we looked at it and we're like, well, how are we gonna make this happen? How are we gonna take these complex global program, make them turnkey and simple for the enterprise to be able to deploy and digest? Uh, and again, I'm going back almost 15 years ago, uh, the challenge was big, uh, and we looked at how can we do that?
And we, we, we innovated in a way, um, where we are able to miniaturize these kind of similar kind of programs or similar concepts, leveraging best practice, the same security standards, uh, leverage the same security protocols, right? As, uh, as the DOD and the federal government did. And now we have a turnkey simple platform for organizations to be able to do this on a global scale.
But back to your original question, if we look at from kind of a password perspective, uh, passwords are, are, are free, like a puppy, right? Uh, you know, you deploy passwords and, and you're like, well, it doesn't cost me anything, right? It's, it's, uh, I just tell my users to select their password and, and, and then they, then they go off on their way.
But the, the cost element to it, and then we'll get to the security and vulnerability, but just the cost element of it, you know, if you're doing it, you have to increase password complexity. You have to force your users to change the password over time. You need password reset tools.
You're, you're overloading your, um, uh, your help desk with, with all this password management. And then, you know, you, you talked about the percentage that are still doing password. I'm curious, uh, from your last, uh, interview, how many are doing MFA, Right?
No, they said 37% responded that they are, so 63, not so, look, I, I've been saying this for a long time, right? I, I've been a big fan of biometrics for as long as there's been biometrics in security. I, I think passwords.
And I've used the password manager forever. I, I was hacked at Black Hat in 2005. I was stupid enough.
This is when iPhones automatically connected to wifi networks that had the same SSID they connected to before. Big mistake, obviously this is maybe iPhone three, something like that. And I got hacked and I learned my lesson with passwords, and I've used the password manager ever since, you know, with complex passwords.
But you wanna know the truth, it's still too much of a pain in the butt for people. Mm-hmm. Mm-hmm.
The average person has 150 passwords or more Or more. More. And you're not allowed to repeat 'em.
They can't be similar. I need a unique one and I've gotta have a capital and a number and two special characters, but not those special characters. And I gotta change it as, you know, the the drill Besam, we need to move off of passwords.
That, that's my personal thing. We only got 15 minutes here though. I want to bring us back.
Talk to me about founding ard. Yeah, so as I mentioned, right, we, we, we really looked at that journey and, and, and how can we simplify the authentication journey from both perspectives. One, the organization, how can we make it, uh, how can we make security simple for them?
Uh, and then from an end user, how do we make it effective? And, and, and real? What does that effective a real mean?
It means the user experience has to be extremely simple From everything from creating your authenticator to using your authenticator to managing the lifecycle of the authenticator. So if we look at that journey, what Axia does it, it we can provide a, a turnkey platform that allows organizations to let users self-manage that authenticator. W well, what does that authenticator look like?
Again, piggybacking off standards from, uh, from what the federal government and the DOD did back in the day based on certificate based authentication, uh, PKI, and then combining that with kind of forward, uh, looking protocols like Fido two, combining the two of them really gives you the best world, the best of both worlds. And making it turnkey in a platform is, is really that criticality Axio can give you that platform. It, it's up and running in less than 45 minutes.
You have a dedicated virtual private cloud that has all the necessary elements for you to have that passwordless secure, simple authentication. So the question becomes, why did we go down this route? You know, as you mentioned, there's, there's no shortage of, uh, of passwords that the user needs to know to authenticate to all these different applications.
Password manager was, was the way to go when a lot of these applications were OnPrem then when a applications become more web-based, right? That was the birth of IEM, identity access management, right? IEM came with a simple promise, right?
Authenticate to the IEM and that it will act in a really simple way. It will act as the SSO, uh, to all these different applications, right? One pathway to rule 'em all.
Yeah, exactly. And I'm really simplifying the, the I am story. We can sit here and talk about I am for hours, right?
Because I am also provides directory services, et cetera, et cetera. But I just wanna, uh, for the audience, right? I just want to focus on the authentication journey.
Uh, a part of I am, so I think I am really helped that story of, okay, I have all these web AppSec, right? Uh, and I have all these online resources. Now I, I have a way from my end user to authenticate to the IM and then the IMS acting as the SSO slash broker to all these different applications.
So what do we do? We move the risk from the application. We moved it to the IEM.
The IEM became the risk point, right? If I'm an attacker, if I'm a hacker, if I get access to the user's IEM, right? Guess what?
Now I have access to all their applications behind the scenes because I've logged on similar to a password manager. If somebody gets your main password to your password manager, now they have access to all your accounts, right? Uh, and, and that, and, and, and that, that's why we see today with all the different IM all the, the, the hundreds of millions of dollars that are being spent or, or close to over a billion dollars is spent in I am attacks.
You still see them, uh, breaches. You still hear about them, uh, and the news is flooded with this information. Absolutely.
You know, and that, look, to be fair, you're right, IAM with the birth of the cloud and prominence of the cloud, IAM became sort of the killer app of cloud security, right? Because we didn't have the remote, we didn't have the perimeter, we didn't have the molten castle kind of, you know, traditional network security stuff. But like everything else, it, it's been around now a while.
And, and we see, we see the gaps in the coverage. We, we see the issues. So you guys have something new you're calling ica.
Honestly, it's not something new. It's taking a page out of the, you know, what we did back in the day from the, from the DOD. What we're, what we're advocating for is, is really focusing on, on going beyond the, the traditional IM story to really start looking at, I I icam.
So what is, what is icam? What is different than icam, uh, um, the, it's identity credential access management. So why the credential?
Why does the credential be, be, become a cornerstone for security within the organization? Now, now you have, if we, if we step back a little bit on the IEM journey, right? As I, I do as an, as an organization, yes, you have all these cloud applications.
Everyone thought we, we'd be a hundred percent cloud by now, but that's still not the case. There's a lot of companies out there that still have legacy applications, whether they're in the financial sector, healthcare, um, aerospace and defense, uh, oil and gas. They still have applications that are still on-prem that still need access for on-prem, and they're not web applications.
They're still wi within your, uh, environment. So you have this still this mix of authentication of some applications on-prem, some cloud. And then on top of that, what we've seen is even deploying MFA, uh, or let's call it traditional multifactor.
So like, for example, you know, uh, I'm sure you've, you've used in your career kind of having the one-time password or the, the code that would, you know, on whether it's on a, a little token, whether it's on a mobile app, whether you get the SMS or whether you get it through your email, that has proven to unfortunately to be not secure and not because the hacker has to hack the backend, which is protected by, you know, your intrusion detection systems, your wife, your, your VPN, your proxy. No, by simply phishing the user to provide that information. So MFA is, is losing, is, uh, is effectiveness because hackers have shifted their attack vector from attacking the AppSec directly to really focusing on attacking the user, because phishing, the user is a lot easier and a lot simpler.
And with AI helping, uh, you know, with all the AI tools out there to really has made phishing is on the rise at an alarming rate. I wanna be very clear to everyone that's listening to this. Anything's better than username and password anything, right?
But if you are going to deploy something, I think it's important to look at part of your ICAM strategy is how do we move to phishing, resisting authentication? So that phishing resistant authentication is really clear. Um, we're really grateful from organizations like NIST and CSA that clearly define what is phishing resistant, what authenticator, so that there's no ambiguity.
So that when you look at, uh, solutions out there and how to protect your organization from these threats, it, there's a clear roadmap and, and in a clear definition, uh, I think is the better term of what is phish and resistant authentication. So from an exit perspective, we really focus on bringing organ organiz, uh, organizations, uh, bringing a simple path from security and usability. We don't believe in, in the perfect intersect between the two.
On the contrary, we think both of 'em should run in parallel. You need maximum security with maximum usability all the time, every time. And we, we use phish and resistant authenticators that are, uh, as defined and approved by cisa and Desk so that you can have your k and e to two, uh, authenticate to your local AppSec, authenticate to your cloud AppSec, leverage ICAM standards, and leverage government and military grade standards with a really simple way to use it and get rid of passwords completely.
I love it. I love it. Hey, you know what?
We didn't tell people though. How can they contact and, and get on board with Axia? Oh, yeah, absolutely.
com, you can go to our website, uh, and there's a lot of great information there. Um, A-X-I-A-D if you were wondering how it's spelled. Okay.
Yes. Thank you. Thank you, Alan.
I appreciate that. I, I take you for granted sometimes. Uh, obviously because, uh, I, I, I started Xi back in 2010, uh, and, and, and for me, it's, uh, it, it's, it's like another kid, obviously.
Mm-hmm. I get it. I get it.
You gotta remember though, they're cattle, not pets as someone who's founded a bunch of companies. They're cattle's, not pets. com Yes, sir.
And, and people can get started right there. Yeah. com for phishing resistant, please.
When you go there, we have, uh, we focus on a couple of, uh, of products, right? One of 'em is, is really focused around phishing, uh, phishing resistant authentication. com, you can look at it under our conductor type of, uh, conductor product line.
Uh, we also have identity, uh, uh, identity risk, uh, that's under our axid mesh. And Alan, that's for us for another conversation, hopefully one day. Well, anytime you want, just reach out to us.
Baam, we're about outta time. Thank you for joining us today here on Tech Trunk TV and telling us a little bit about icam. And it was a, I think it was a good, you know, we built and, and built up to it.
So it was a good conversation. Best of luck with Ax iad. Come back and tell us about identity mesh next time.
Sounds like a good one. Absolutely. Love to.
Thank you, Alan. All righty. We're gonna take a break here on Text Drug tv.
We've got more coming at you today, so stay tuned. Hi, everyone. I'm Alan Shimel and you're watching the Platform Engineering Show.
Let me introduce you to my cohost. Where is Luca today? But Luca, GTE Luca, how are you?
I'm good. And still in Sri Lanka. So I a Move still in Sri Lanka, but a different background.
Different background. Yeah. It's a hotel room.
I was hoping there was gonna be a table instead. I'm like in, in a, like, closet holding the computer. Okay.
You know, it's that. It doesn't, well, it's blurred, so you can't see. But alright.
We won't make, we won't make you stand too long, hopefully. But where are you heading from? We'll do a quickly, a little travel update.
A little Travel. Yeah. We should have our own like, travel segment every time.
Right. And then Follow lookup. No, Maldives.
Maldives for the next three days. And then Japan. So the next, next line I think we're gonna speak is gonna be from Japan.
Very cool. Yeah. I would like to, I have, that's the place I haven't been to either, is Japan.
I was thinking about going for the Cube con there in June. I just don't know. I've got a lot of travel in May and June.
I've got the RSA conference, and then I'm doing a trip to Italy myself, and we'll see. Anyway, let's talk platform engineering though. Um, is what Yep.
It, it's been, you know, I, we are hearing more and more and more about platform engineering, but what I, what I'm encouraged about is you used to just hear platform engineering, right? It was like this monolith, if you will. It was, it, like all encompassing.
But now as we're starting, it's been maturing more, it's more widely accepted in the in market and people are understanding it. We're looking at the different aspects of platform engineering. 'cause it's not a monolith like anything else, when you get up close, you find out there's different pieces of it.
Today we want to talk about MVP, not most valuable player, but, and not minimum viable product, but minimum viable platform. Luca, educate us. What do we mean by that?
Yeah. And, and I think your, your intro was, was spot on, right? Because I think, um, the minimum viable pop, the minimum viable platform framework is a great example of, I think broadly the platform engineering space really maturing, especially in the last 18 to 24 months.
Um, where, you know, we've spoken before about reference architectures and how those have been like a big game changer for the community and the space broadly in terms of really helping people visualize, okay, what does an enterprise grade internal developer platform actually looks like? And, but the issue with that was that then people were, had this kind of like, target architecture that they wanted to build, and it's like, okay, let's go build it. And they wanted to build it all at once.
Um, and that's where a lot of teams got stuck. In fact, I would say the majority of platform engineer initiatives that I've seen dying, um, was mostly because of a loss of momentum, right? At the end of the day, as we said, right?
Like platform engineering is very complex org transformation that touches all these different stakeholder groups. So you need to convince, you know, the app devs and the security teams and the architects and all these people, and you know, you go person A, B, C, D, by the time you got to person Z, person A forgot about you because it's been six months and you know, you, and that's how you lose momentum. And so the medium available platform framework was kind of developed, uh, from the community to, to help with that and to make sure that you followed this minimum viable product, you know, approach, right?
And this is also, I think, an interesting thing that, that we discussed previously, right? This like idea of platform as a product, as one of the foundation concept, uh, financial concepts of the, of the platform engineering space. And again, the moment you look at your platform as a product, as an internal product that you're developing, you automatically unlock all these, you know, product management best practices that we've all learned in the last couple of decades.
And one of those is MVP or mini level product, which applied to the platform. It's just the MV mini level platform. And the idea there is to look at this reference architectures, right?
And instead of, um, trying to build everything at once, you really like, focus on a subset of, of, um, of, of that reference architectures. And the idea is to, um, really iter quickly on it and get the, and keep getting in, you know, more and more buy-in from the stakeholders. So you don't have to focus on all the stakeholders at once.
You don't have to focus on all the different sides of your infrastructure, uh, all on all the different aspects of your applications. You just, you know, strategically select, uh, different parts of that and then show value there first, and then I from there. Excellent.
Well, you know, the, the last thing here from, I remember from DevOps as well, when, when DevOps first came on, it was very rare that you'd have sort of an enterprise wide DevOps rollout. I used to say DevOps, DevOps got done in bubbles. And, and if you've ever seen like soap bubbles or bubbles in the bath when you're a kid, maybe not when you're a kid, if you like bubble baths, but you know, you get a lot of little bubbles.
And when those bubbles come, you know, touch on each other, they become a little bigger. And then, and then eventually you get those big bubbles, right? That you could catch.
It's the same thing when you look at how DevOps spreads in an enterprise. Generally it starts as little bubbles, right? There's a little project here, a little project there, but it's the same thing with minimal, minimal viable platform.
And important part of it is momentum, right? No one wants to go with a loser, everybody wants to be with the winner. So if you could build some small wins, you get some wins that people could point to and say, Hey, look, it works.
Hey, look, it, it helped us do that. It made that go faster. It made this more secure.
People want to do, give me some of that. I want some of that good stuff, right? I want more.
I want that more. Yeah. Right?
And or more of it. And, and that, that's how you get buy-in across an enterprise. That's how you get those bubbles.
Yeah. Right? Creating bigger bubbles.
Yeah. And, and I think it's very important also to, you know, figure out what, you know, what is it that people want, right? Um, because like, um, again, if you're trying to make everybody happy, that's really hard, right?
So you should really just focus, okay, what are the one or two stakeholder groups that are really crucial for this initial phase to prove value? And then understand, okay, what did, what do they want? Um, because you know, if I go to developers and talk about like, oh, we're gonna cut time to market with this MVP, they don't care.
Um, it's not something that they necessarily think about, right? But, you know, executives care about that. Um, application developers might care about reducing waiting times, right?
And so you just need to understand, okay, what are those two initial like, wants and desires that I'm gonna target with this MVP? Um, and then to your point, create those first bubbles, right? And then go back to them and be like, look at these bubbles.
They're great. They're shiny, right? And then they're like, all right, I want more of those.
And that's when you start like adding more and more and more. Um, and that is why, I mean, so just taking a step back, right? Like the MVP framework is a framework because it has like very specific sort of, um, uh, different phases of it, right?
Particularly, there's like four phases. There's like a discovery phase. And this is why I think, um, this discovery phase is so important.
And it is exactly to do what we just said, right? To like really map out what are the desires of people, like what are the challenges that I wanna solve? And again, you know, I think like a lot of people, like a lot of platform teams get stuck in, um, you know, trying to have this like very quantitative, measurable type of things that they want to improve on.
I think especially in the MVP phase, it can really be qualitative, right? We've talked about before, you know, of like, hey, it can literally be like, Hey, you know, person X is spending, you know, 20% of their time on, you know, uh, fielding ticket ops or, you know, uh, we are approximately, it approximately takes us like, you know, a couple weeks anyway, this like, waiting time is just, is really long. It sucks, right?
And, and, and so like that can be the starting point. And then you just go back to the same stakeholder and, and look, look, now you don't have to wait weeks. You can, you know, it's in instant, or you just need to wait like a few minutes or a few hours, right?
Like that's already like insane improvement. And then from there, you build on top of that and you professionalize it and you get, you know, more, um, you know, more secure in everything. And so this is why that first discovery phase is really, really important.
Um, then the second phase is, you know, what, so it's discovery then integration, which is really, you know, basically, you know, hooking in all the different parts, um, that of, of, of the subpart of your reference architectures that you decided to target with your, with your, um, MVP if you, you know, for people that are familiar with that. Otherwise, we can also link it somewhere in the show notes. Um, you know, the, the Revs architectures have five different planes, right?
A developer control plane, which is effectively the front end of your platform, an integration delivery plane, which is the backend. Then you have a resources plane, which is, you know, all the infrastructure that your platform sits on top of. And then you have a security plane and observability plan in most mvp, successful MVPs that I've seen, people mostly focus on the first three, right?
You need some front end, you need some backend, and you need some resources. You should keep all those things to a minimum. You probably don't really need, you know, security or observability in the first phase.
You can obv you obviously need to design with that in mind, but, you know, a first MVP doesn't need to show, you know, ultra secure anything, right? Because it's just an MVP, it's working in dev, like there's no production workloads on it and so on. So, um, and so that's, that's really like the integration phase is about integrating those different pieces that you kind of like singled out.
Then you start deploying your first applications, right? And, and, and, and you, and, and that's where you see, okay, everything is working. And then number four is the sort of like demo time, right?
Um, which is also very, very important because it connects back to phase one where you first went to people and like, Hey, what do you want? Then you need to now go back to them and it's like, Hey, you know, I actually did what you wanted, right? Uh, or close to it.
And that's where the loop, you know, starts, the flywheel starts going the utility. Yeah. The magic happens.
Yeah. So, you know, when I hear you describe this Luca, to me, I think one of the most important things, and you know what, it's a lesson I've learned over and over and over again. In 35 years of doing tech work, the finding success is important.
Yeah. And a lot of engineers, I guess it's the way their brain is wired. They define success exactly the way you said, right?
It has to be some metric, some KPI that I measure, right? And it's like, I improved, you know, mean time to remediate by 38% or whatever, but sometimes success is, success is a feeling as much as it's a number, right? Sometimes it's a success is just, Hey, I'm getting more done, I feel like, or my, I've got a better life balance.
I've got, you know, there's a lot of ways of defining success. The important thing is that everybody agrees on what the definition of success is, right? Right.
And then when you get to, to stage four and loop back, you can say, okay, this is what we said success was gonna be. Here's, here's the reality, right? And do they, do they match up?
Um, yeah. And, and, and this is why I think apart from engineering is so challenging for, for that kind of profile of engineer, right? Is is because mm-hmm.
Really, you know, much more of a cultural challenge and the technical challenge. And the problem is that a lot of times it gets approached as, you know, a 98% technical challenge and maybe like 2% of culture thing like spring cold on top. And it's really almost the other way around.
Like, I've never seen platform engineer or broadly this type of org transformation, um, you know, fail because of a technical, uh, you know, choice of like this technology over desired technology. It's always because you didn't convince the right people, you didn't get developer. It wasn't a meaning of the minds on what's success.
Yeah. And, and, and, you know, to, to define it. I think another big problem though, and I'm interested in your take on it, Luca, is the m the minimum part.
Yeah. Right? It's like a Goldilocks, sometimes it's too minimum, sometimes it, that minimum is like a maximum, right?
I think it's important to really, it's gotta be meaningful, right? It can't be trivial, it's gotta be meaningful, but it, it's not supposed to be the whole enchilada. You, you know what I mean?
It, it's minimum. I see. How do you, how do you, you know, balance that?
Yeah, so I think, um, you know, again, if you follow the framework, the idea is that, you know, this, the, the, the MVP needs to be representative, right? And, uh, sort of like repeatable as well, like to your point of the bubbles, right? Mm-hmm.
Um, but you know, it also doesn't have to be a bunch of different things, right? It doesn't have to work for high compliance scenarios. It doesn't have to cover any advanced architecture.
It doesn't have to do any sort of like advanced resource configurations, right? And the problem to your point is that, you know, platform teams and engineers have this tendency of like, slip things into it, you know, because that, because it's cool, because you never know, you know, and mm-hmm. At end of the day, I think it's just like, uh, I've seen, you know, successful platform teams really going through this person almost, you know, the summer I sword fall, uh, folding thing, right?
Where it's just every time you cut it off again, you know, and you just ask like 10 times, like, are you, you know, are we, do we really need this? You know, do we really need, you know, two different databases for this to be a representative? Do we really need, you know, um, all these different, you know, uh, different policies as code, not, you know, and every time, and it's amazing because even teams that I think like consider themselves like quite frugal in terms of like, you know, picking this like minimum set, um, um, you know, end up like cutting another 50% of fat basically, um, I I, by just asking it enough times.
And so I think, I think that's, that's where it's important to either have somebody external, um, as you're going through that have, you know, has experience doing this or, um, have like a really strong product platform product manager internally that really, you know, keeps asking the same questions over and, and is not, you know, afraid of asking the same question over and over again. Even if it's through like very experiencing engineers. And it's like, no, but are you really sure?
Right? And then, like, really pushing the, the envelope internally. Absolutely.
Um, wanted to ask you about a, a another thing here. When we talk about minimum, you know, MVP, what, what is the team behind it? You know, like we're, I think we're all familiar with the Amazon two pizza concept, right?
If more than two pizzas, it's too big. Um, Spotify has sort of the squad or whatever it was called, remember what, what's the right size team for a minimum viable platform engagement? Or is it just ran, you know, really varies The Right, you mean team?
The, the, the team? Yeah. Yeah.
So I, you know, it definitely varies. I think on the, depending on the scope. I think for me what's important is not necessarily the size, but that there are different roles, uh, or at least different functions clearly represented within the team, right?
So as an example, right? Um, um, and I can, I, I, we can, we can also throw up this, this, um, sort of like, um, really nice, um, bubble, actually bubble like visualization of, of platform teams and the, the different stakeholders around it. But in general, you have, um, you know, four key functions like the head of platform, the platform product manager, and then what we call, and it's funny because they're, they're really like emerging now as like very defined roles by, uh, by Gartner, for example.
Um, they are job ads already, um, having this title, which are infrastructure platform engineer and developer experience, or DevX platform engineer. And the point is, you don't, you don't need, you know, four different people with those four titles. A lot of times, you know, the had platform is doing the product role or the auto or vice versa.
Um, um, and you know, in some cases you just have a platform team of like two or three people. And so like, everybody's like, kind of like covering all bases in some cases, you know, you have like, uh, platform team, there are like a hundred people, and then it's not even that you have four different people. You have like four different, you know, or like, you have like many different teams and product teams, and each team is like those roles represented one way or the other.
So regardless of the scale, the important thing is that there is this, um, I think, um, uh, you know, the dysfunctions that interface themselves with the, with the different stakeholders. So, you know, the had platform is really responsible for selling this thing internally, ultimately, right? And so, uh, getting the executives or keep selling up, down, or both, yeah, mostly app, I would say, right?
Mm-hmm. Um, so really like to positives to, um, but also across to like legal and compliant, like architects to an extent. Um, and then you have, and, and I do think that the, the line between the, the, the handle platform and the platform product manager is quite blurry, right?
But then you have the platform product manager that is, I think, the most important role, right? 'cause it's really about mediating all the different, um, inbound requests slash vested interests of all these different stakeholder groups, right? So you need to, you know, balance all this stuff.
Um, and it's, it's really, I think the, the most critical one and also the, the most in demand role and the hardest to find, um, I think right now in the market. Um, and then you have this like devex and, and infrastructure platform engineer. And I think the, the, the differentiation there is really important to have, again, not necessarily as a title, but at least as an area of focus for different people, um, or even for the same person.
But it needs to be like a very conscious, like, okay, I need to cover both of these things. Why? Because I think a lot of platform teams have this tendency to over optimize, over index on devex, because ultimately the, the end user of the platform is that application developer.
And so, okay, you know, that's the whole point of the platform. But if you don't connect the, your platform eng energy initiative to the, um, you know, to the overall infrastructure and, and you don't sell it to your infrastructure and operations teams, it's, um, doomed, I think, or, um, very, very quickly, right? Um, and, and so that's where it's very important that you have yes, the DevX platform engineer that maybe comes from that background to really build a tight feedback loop with developers and, you know, know, find the right level of obstruction, the right level of con context, the right interface to the platform for developers.
But then it's very, very important that somebody's building, um, together with the infrastructure and operations team, the connection of the platform to the, the, the underlying, uh, infrastructure stack, right? Um, and, and, and also that is selling effectively the platform to them, to the INO teams as a way of effectively, hey, this is a vending machine layer, basically, right? For you to provide your infrastructure to the rest of the organization in a much more productive way where, you know, you don't have to fill ticket ops and getting annoyed and everything is like standardized and automated by design, yada, yada, right?
So you, whether you have, you know, different people, 200 people or or two, the important thing is that you're, you know, consciously thinking about those different, You have those roles. Yeah. It's important that those roles, you know, those are kind of indispensable roles.
Let me ask you a question, Luke, and when you say, you know, dev X or in working with developers, it, it's in today's world, it's not just the guy who's maybe coding, but is, is like for instance, the QA person, the test person. Mm-hmm. Right?
They have a real stake in this too. 'cause they, they've gotta test all this stuff and hopefully before they deploy it, but, um, you know, but on the platform, nevertheless, so would the, would the dev person also work with like, for instance, QA or security testing or, you know, other people along that CI/CD journey, if you will, who are involved in the pipeline? Yeah.
Or in the factory, right? These are all factor, you know, if you think of they're fact software as a factory. Yeah.
These are all the people working in the factory. Yeah, absolutely. And I think right now, you know, we're still in the phase where I think software, most of the times, like we spoke about in the first episode is create, is, is, is produced as this, as if you were in this like, um, you know, craftman type of, of, of, of like boutique, you know, uh, thing.
And, um, and, and so I do think as we're getting more industrialized as a, as an industry, then, um, you will, you will lose, uh, touch points. Um, or, or rather, or rather the touch points. You know, we had this like really interesting conversation with, um, with Kelsey at Platform Call 24, where he was, you know, talking about this, like, you know, silos are a good thing, and all these people got mad.
Um, uh, but the important thing is that you have like a platform layer in between the silos that facilitates that communication whenever it's needed. But the point is, it's not needed all the time, right? Um, and so, and I think that's ultimately what then increases, to your point, the developer experience, and frankly, everyone's experience, right?
Because you don't have to, you just remove all this friction from the system, right? You can, you can like focus on what you do best, what you wanna do, like you want to code, you don't wanna necessarily, you know, spend 30% of your time configuring stuff. Um, and, and so then you can do that.
And then when you need, you know, educate or whatever, then you know, you have like off path options, uh, beyond whatever the, the platform normally mediates. Yep. Let me shift gears a little if we can, Luca.
Okay, so let's say we follow the four steps and everyone says, great job, Bravo. Let's, let's, now let's take it to the next level. What comes after MVP?
Um, so the way, the way we, we think about it, um, uh, whether with our products or, or in the community is, is production readiness after that, right? Because really, uh, the MVP is not meant to be production ready, ready, um, so it's really meant to like, basically get everybody, you know, uh, rallied up, you know? And it's like, yes, this is great.
We can totally see the benefit. Let's, you know, let's invest more time, let, let's invest more money. But really more than anything, let's invest more time and resources, right?
Because that's the hardest thing to get in enterprises. It is not necessarily the, you know, extra money. It's just like, you know, you can invest an extra like, you know, 200 k or whatever, but if you don't have the, the developers we're keying to actually keep working on this, it's not gonna go anywhere as an initiative, right?
So, so that's really the main thing. And so then the, the next phase is really, okay, how do we, and, and again, it's like a very structured kind of like production readiness, uh, checklist basically of like, okay, what are all the things that you now need to make this, uh, first minimum viable platform actually ready? And again, this is, is very important because here again, we're not talking about okay, bring your entire, you know, uh, software estate or cloud native setup, you know, to production redness.
It's, it's again, just like one subset, usually one or two applications with a, a subset of their normal dependencies, but they're now, you know, production, production grade, right? Um, and that's really where you start getting the traction of like, other teams looking at, ah, okay, they're, you know, that team is actually deploying all the way to production and, you know, it's taking like 30, 40% less. And then that's where you go back to your bubbles of, you know, then you grow from there.
Um, and so then from there is, you know, the third phase will basically be production readiness to, you know, sort of like full, full rollout. Cool. We only got a few minutes left, but I, I want to kinda wrap a bow around this.
org, right? You could download them. org.
You free to anyone there to download and, and ask questions from and stuff like that. Speaking of people who have questions, does the community Slack? Yes.
org? I forget, is there a Discord server now too? Or is it just Slack?
No, slack. Slack. Just Slack.
Yeah. Yeah. Is the way to go.
Yeah. While we're at it, we, we were talking earlier about, um, CubeCon and, and some of the other events coming up. Obviously Platform Con is next June, so we're still maybe six months, five months out of that.
But, uh, for CubeCon, for people who want to be involved in the community, you have your, uh, you guys have an event going on, you want to just let people know about it. Yeah. com.
Um, you know, we, these reference architectures we launched the first time, the, the first talk about them was a platform Con 23 last year, platform 1 24. Already 20 plus percent of all the talks had this reference architectures as a blueprint. So I'm expecting that to grow even further.
And actually we now started building on platform engineer do org, a repository of all the talks slash articles slash you know, new com community contributions of people that wanna share their reference architectures for their platform. And so it's starting to grow and it's becoming a really interesting library. So I recommend people checking that out as well.
com. I don't think the, um, design, I think the design is gonna be updated by the time the people listen to this, which is a new, a new branding for the, for the event, which is really cool. Um, it's something that started as a joke, uh, in, in Valencia, um, Be things off and do, Yeah.
'cause we just wanted to do like a better, a better, more fun party. Um, and it's basically grown to be this like unofficial opening party for Q Con. We're expecting over 4,000 registrations, uh, for, for the London one.
And we've actually taken out like a proper, proper club. And I can't say who it is, but we have actually, one of our frontend engineers is a very, very, it's a like, literally globally famous dj, um, that is a, yeah, he's a resident in one of the best Berlin clubs, um, you know, travels every week to like, you know, Mexico, India, whatever. Just plays like big shock.
Um, and he's actually gonna headline, although not with his normal, um, DJ name because he can't use that. Okay. Um, But he's gonna, he's gonna headline the event.
Um, so, You know, we've, we've been basically saying about, Hey, this is like a techno party and then, you know, every time, because you know, it's still like a party attached to, to like a working conference. So we always like, you know, like did it, but not all the way, this way, you know, this time it's Long. We're doing it this year, we're Going all the way.
It's like a proper warehouse. Proper DJs is gonna be fun. Very Cool.
I'll give, yeah. Excellent. All.
Hey Luca, enjoy your last few days there in Sri Lanka. Enjoy the, thank you Alan. We'll catch you in Japan.
Yeah. Where we'll be folding Summeri. Exactly.
Steel. Exactly. You'll catch, take steel to make steel, right.
Alright, Luca Gallente, uh, platform engineering do org. com or Apple Podcast, Spotify, wherever. We hope you enjoy it, subscribe to it.
Until next time, this is Alan Shimel and Luca Galante. We're out. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security Bloggers Network. Hi everybody.
And you've joined us today on another episode of the last Great Cloud transformation. We're happy to be, uh, be doing this series, uh, sponsored by CloudFlare, talking about really the evolution, kind of where we're going next, how the cloud is looks today, but what's gonna look like tomorrow, what's some of the drivers are behind that from the old days of hub and spoke and just connecting places in our, through our connecting through our suppliers. Um, networks take on a lot of different characteristics today, matter of fact, what we think of as the network as quite a bit different.
So, and I'm Mitch Ashley and I am VP and practice lead, uh, at, uh, with one of the analyst areas at, uh, FU Group. Also have served as CTO with the Taxon group folks that are putting this on. And I have the pleasure of being joined by a couple distinguished, uh, gentlemen here today.
First of all, uh, Dan, do you wanna introduce yourself? Both with CloudFlare, by the way? Dan, go ahead.
Sure, Sure. Thanks. Uh, Mitch, uh, Dan Kent here.
I'm the field CTO for CloudFlare, um, supporting, uh, the Americas and in particular folks on public sector. Uh, prior to that I've been a CTO for six years prior to that, uh, focused on mostly around public sector offers and, uh, os And then, uh, prior to that I was at, uh, Cisco for 15 years before I public supported the public sector as airfield CTO. Great long longevity in this part of the industry, which is perfect for this conversation.
Great. Let's next go to Matt. Matt and you introduce yourself.
Yeah, very happy to, uh, nice to be here. Mitch, uh, Matt de Schneider. I lead our US public sector team, uh, was brought over to Effler about three years ago now to build out the public sector, go to market.
Uh, my last 30 years or so in the public sector have led to this coming from service providers and infrastructure companies over with Dan at Cisco for a long time, uh, into, into software with VMware and, uh, security with Palo Alto before joining, uh, CloudFlare, except about three years ago. So very excited to be here. Excellent.
Very good. Well, when we say public sector, uh, Matt, you know, that that is a very big, you were talking about super large 'cause you're talking about everything from the Defense Department to Department of the Interior or what I pick any agency, any department. Um, maybe if you give us your thoughts initially of what some of the, the biggest challenges in modernizing it in these organizations are.
Yeah. As, as you said, public sector is, it's a microcosm of the rest of the industry. So it's everything from manufacturing for elements, you know, with, with our US department of Mint and, and where we would go on everything on side to finance, to healthcare, to every other element in that.
So you, so you have, you have the, the same challenges you do in enter enterprise, but you have an increased amount of what, what we, we have for refer to as technical debt as these programs continue to build and be ma you know, required to be maintained at a different level than a traditional enterprise mine. So we get to the environment where government will always be in a state of modernizing. They will never be fully modernized from that footprint.
So, um, whether it's, you know, the mainframes that still exist, uh, in so many parts of government today as they do in enterprise right on down to trying to increase citizen services and constituent services, um, you know, they're always gonna be chasing that goal of delivering at the same pace of, of the enterprise out there. You know, one of the things from my experience in the public sector too is it's not a solution from one vendor, it's a integrator or, you know, a prime on the contract. And you have a lot of companies coming together that get selected in those deals.
Uh, for that, which means where do you go for, for kind of support or picking up, uh, pieces of where they were left when that contract was done, what's that like to unravel and untangle that and kind of figure out what all this is where it came from and how do we move it forward? Give us a little bit of a thought on that. I'm, I'm interested in your ideas, Dan, you wanna go with that one?
Sure. I'll, I'll go with that one. Yeah.
It is interesting. One of the differences and, and we're talking really just the federal government right now, uh, because public sector does support, includes state and local as well as education in most cases. Uh, but in the federal government, those very large programs and, and what differentiates the federal government agencies from commercial and, and there's com a lot of commonality like MAP brought up, uh, oftentimes.
So these programs that they're building are much larger than an enterprise. Now, obviously here to retail, you could at Amazon, that's a pretty large enterprise. Uh, but if you look at the, like social security, they have a program that has to support every citizen in the United States, 300 million customers.
So, um, and it makes it, and the other issue with it is typically it's a one-off. There's only one of 'em, right? So, and that's why it's complicated and that's why they bring in these multi-vendor, uh, systems integrator.
'cause they're typically are building something that wasn't built before, um, for one customer. And so it's really hard to then repeat that and sell it somewhere else. So, uh, but interestingly, looking at that in the technical debt we've mentioned, uh, because these systems are so big and so complicated, we do find some of these applications like social Security, like the IRS that are 50 years old, still have COBOL in them, and we are now absolutely going through and how do we pull those back apart, and how do we modernize those?
And, uh, as we've come to talk about micro modernization rather than the Big Bang theory of replacing it all at once, uh, because you have to do it that way. We've realize to think, uh, one of the easiest ways to modernize is piece by piece at a time. Uh, when you try to do the Big Bang approach, uh, that's typically when you hear the core stories of the government overspending, unfortunately, and, and taking much longer than it should take.
Yeah, I remember the quickest way to, uh, lose your, lose your job in telecom was to replace the billing system. I can't imagine trying to replace a large IRS system, something like that. Um, you know, and in the commercial sector, usually it's some kind of finance, either a gain of what we're looking to, we need to do something in market, so we need to modernize this, or it's a cost reduction.
Are those similar drivers in the public sector or are there other ones that we don't see in the commercial side? I'll, I'll jump in, Dan. I, I think those are definitely there, right?
And, and you can look at budgets. I mean, the amazing thing about working with public sector is everything is public out there. So you can look at, you know, what is spent year in and year out on maintaining these legacy systems.
And you know, I I, I saw one stat that, uh, you know, I, I think it was $68 billion last year in the federal space towards maintaining legacy systems. So the scale of maintaining those is massive niche. Um, but the other thing that comes into play there is the fact that, you know, this revolves around the constituent, you know, the government is there to serve the constituents.
So I think we have seen this change of how do we increase the delivery of services, you know, through the use of technology to the constituent at a LE level we never have before. So I think that is a shifting mindset that is driving a lot of modernization in a very good way of how do we, you know, when you log in through your state, you know, how do we make sure you have one login that gets you to your DMV, but also your applications that you need to, um, read and under your benefits that, that you're requesting, as opposed to three very different environments for that that had historically been there. You know, it, uh, at every level, you know, you were mentioning earlier about it, you know, education state and local government as well as federal one characteristic, at least on the government side, is the leadership is constantly changing, right?
Or whether it's, you know, new presidential administrations is coming in with their priorities and slashes of what they change or, you know, at a, at a gov a governor or legislature level. So priorities change sometimes pretty quickly. We're seeing a lot of change happening with the Trump administration stepping in, um, a lot of things that we're, you know, regulations now aren't, or we're not gonna follow that, we're gonna do something different.
Um, it seems to me that that requires a lot of flexibility of how do you support that? Because oftentimes it's sort of like the long chain, you know, you snap one in and it takes a while for it to make it all the way to the end. Uh, how do you help, how do you help the, the organizations you work with respond to those kinds of dangers?
I'm curious. Yeah, I'll take this one. Uh, so oftentimes those change that happens at the administration, they're not as, uh, direct or as impactful, um, as actually on we're seeing this year, right?
I think we're, uh, uh, the president came in with a plan very specifically to change a lot what was going on in the government. So, uh, I've been in the government supporting public sector for 30 years and been through many administrative changes. This is probably the, uh, one of the, the most direct to, Hey, I want to change the government.
And quite honestly, I think you need to go through these because the government, through bureaucracy, and I think bureaucracy isn't necessarily a bad thing in the government, right? Uh, when things change, you don't want the machine that 300 million people are dependent on every day to change very often and frequently, but you do need to change over time. So we do a lot of the innovations that Matt talked about, and, and we just, like in the commercial world, we see that happening in pockets and go forward, but every once in a while you really, you need that, um, kind of the, the stoke, the flame, just a little to change dramatic a little more dramatically.
So I don't, this is gonna be a little different for us in the public sector than previous administrations. Um, and we'll see, I'm not sure it's a necessarily a terrible thing. Uh, how the agencies address this and, um, deal with the budget cuts and deal with the headcount changes will be interesting.
But, uh, I'm confident the, we have the ability to support it with the ecosystem that supports the government, and, uh, if there's a will, there's a way to get it to work, right? And folks that are in a commercial world have to deal with budget cuts all the time and have to deal with this all the time. So there's no reason why the government can't deal with it as well.
Yeah. And if, if I, if I can just add in and bring it, you know, more to a, to a state and a local level. 'cause that guy, I think there's some, some good lessons learned there.
Um, I, I live in the Commonwealth in Virginia, and we get a new governor every four years. Uh, you know, so you, you know, change is gonna happen every four years. A lot of government has addressed this through, you know, it strategic plans and, and publishing what their five year roadmap is.
And what's, what's interesting though is, you know, as administration change and leadership changes, if you go back and look at the National Association of State CIO and nassio as an organization, they publish their top 10 concerns, uh, that are out there every year, every year since. And Dan, I don't remember the number, if it's 15 years now that they've done it, but it, it goes, it goes way back. Uh, cybersecurity has been at the top every single year.
So, you know, I, I think fundamentally as we look at things like cloud, as we look at things like AI that's coming in, which finished number two on the list this year, uh, you know, we know that cybersecurity is gonna remain up there. We know that legacy modernization has been on that list from the beginning. We know that the citizen experience, which is around, you know, data analytics and how to, to serve that constituent or that citizen, we know that AI is gonna come into play.
So I think generally government working together knows where they need to go. It's how can, how can industry partner with them and how can we, you know, achieve those bite side chunks that have very meaningful impact for them. That is really gonna be the different from Dan.
I mentioned these Big Bang projects. I don't think there's an appetite anywhere, whether that's at, at the federal level or, you know, down to your local, you know, local government to be able to say, let's take on a project that's gonna take four more years to do it. So it, it's about that incremental change to serve the citizen.
And, you know, cybersecurity is at the top of, of how do we continue to do this in a, in a manner that keeps, uh, the citizen data safe? I, I, I imagine nobody walks in and says, we're not gonna do cybersecurity anymore. That's not important.
Let's do something else. No, that's, that's on everybody's top list in commercial and in government. Well, let's talk about the network side of this.
You know, when I was doing network kind of work, it was still in the days of this point to this point who the provider was. And you kind of built stitch it all together as like an erector set, right? And what Box does what in the, in the rack that does this kind of security or this kind of routing or whatever it might be.
Um, and network doesn't look anything like that today, right? It's, it's all software driven, and you have providers like, you know, CloudFare, like Flare, like yourself, and full disclosure, Techron is a customer of CloudFlare. So I've worked with you and your organization a lot and enjoy that.
You have great service. Um, talk about how that fits into the strategy that you mentioned Matt, uh, in that priority. So you're, you're obviously advising and working with, uh, the governmental agencies at all levels on where they're going and you know, how you obviously can help them get there and make that transition.
Yeah, I, I think one of the biggest ways it fits in is we talked about, you know, where the government wants to modernize to, but we also talked about those legacy infrastructures that they're coming from, whether that's on-prem or one of the first generation, you know, cloud migrations they've had, whether it's, you know, SaaS, you know, services inside of that. The reality is government, just like industry has struggled with, you know, retaining top talent, recruiting talent, you know, a retire workforce, so the challenge of how do I support all of those environments is ever at the forefront of mine, uh, uh, of government leadership. So the, the use of network needs to be thought of, not in terms of how do I get a user to one specific application, which was a lot of the legacy, you know, mindsets of how we get it.
Do I need to get this user to this in terms of how do I a how am I able to get all users to all the environments they might need to go to knowing that that's a changing environment of where that user might be. Whether that is a constituent coming in, whether that's a contractor working with government coming in, whether it's a return to work that, that we're seeing take place. And those applications don't all live behind, you know, the, the moat castle of the Legacy network anymore.
So if I'm getting a user to an application that's outside of my world, how do I make sure I have the right controls? And do I wanna have to think of security independently from network, or should I be thinking of one, you know, common layer of connectivity across the board? So how do I connect all users to all applications in the right way, you know, when they should add access to it.
And more and more often that involves using the internet, is that core foundation of connectivity. And that that's where obviously CloudFlare fits in quite nicely as we're talking to customers about that. Dan, I imagine you've got something to say about this.
Yeah, And I, I, I helped build a lot of those networks back in the day. Um, so, uh, yeah, but like Matt was saying, you know, we're not saying it's your fault though, Dan, just Not judging, no judging. We're my friends here because I realized we have to replace those systems with the newer systems, new models.
So when we, when we built those networks, like Matt was saying, 80% of your traffic flow stayed within your environment, whether that your environment was a campus or, you know, your environment was a land and your campus and 20% went outside. Um, it's reversed that now, right? The way we write, build applications through microservices architectures, it, it, it's, none of that is built in your, in your environments necessarily.
A lot of our customers in public sector don't have data centers anymore, right? There's gonna, you know, if you look at where Harlo sector has helped lead, they were very quick to push for cloud. Um, and, and very quick to look at how this new environment was gonna impact cybersecurity.
So terms such as Zero trust actually came from the public sector, uh, because the landscape has now much larger than it's ever been before because of the way we build net applications, the fact that we have a workforce that's distributed and, and it's just gonna keep growing, right? You, you'll have less and less resources in your physical environment, uh, and you'll share resources outside your physical environment. So you have to be prepared for that from a cyber security perspective.
Um, but that's, like you said, that's why cloud player is here. We understand that the, the internet is not just a nice to have, it is a critical infrastructure for most every company and many public service customers now because of that new environment that which we live in. So, um, how do you then secure that properly?
How do you control that threat landscape and shrink it through zero trust technologies and capabilities, and how do you prevent the, uh, the nefarious actors that are out there from coming into your environment? Right? So, um, we talk a lot about that with our customers, and we show them how we can do that, uh, from a, a different approach than what the way we did it 10 years ago, quite honestly.
And, and it's probably a whole nother podcast just on, uh, you know, certifications in the public sector that would, would be good to put anyone to sleep, but, you know, how do you do it with compliance? How do, how do you make sure you maintain, you know, you know, all the regulation that's put in front of, uh, you know, our customers to, to, to, to achieve across the border as well? So, and that, that's one of those other great challenges out there that governments faced with, with, I think the way I positioned it with people are we, the public sector has the same issues and concerns as the public, as the private sector.
They just have a different security equation, right? We all have this security equation. If you work with a bank, they can, uh, give loans ba and they give loans based on a risk management risk assessment.
Um, and they have an equation that they can take so much risk on for so much investment. Uh, if you put point that back into a public sector, they don't have the same risk equation. Um, and it's because they have constituents that they worry about and they, they, they have a zero, um, uh, risk in, in some areas because it's Department of Defense, you know, you just don't have risk you're gonna take on there.
Um, and, and, and that's, that's really the biggest difference. And compliance is a big part of making sure that that risk equation is addressed. Um, and, and there's a lot of outta that.
I mean, we can thank the Department of Defense on the internet because they built it because they needed to have redundancy and communications for Department of Defense Back to the Darpanet days. Right. Thank you very much.
Um, yeah, no, it's interesting. It seems like one of the things, and I'm not trying to just, you know, be a fanboy for CloudFlare, but you know, one of the things you try to do is save money through consolidation, right? Bringing things together and take out the redundancy and redundant systems, and certainly networks.
'cause they might all get built at different times for different projects. Uh, not always share that, but it seems like as more things have moved to the cloud, um, both as the hyperscalers and also yourselves, that's one of the ways you can start to move some more security into the cloud paving even parts of the AppSec into the cloud. And now you're not stuck in a, you know, like what used to be in a standalone data center that was built for that project in that era.
Yeah, absolutely. And, and I think one of the, one of the key factors to that, Mitch, is making sure that, that we'll call it that legacy application has the same level of confidence around the controls when you move it to, when you move it to that new environment, right? One, one of the challenges for government is they've had such purpose-built infrastructures and security around an application based upon where I lived, as opposed to, based upon how it needs to live in the future.
So we built stacks on protecting an application that lived in a data center in a very certain way, or protecting an application in a SaaS environment in a very particular way. And I, I think that's one of the powers that, that has to come to play for government to fully modernize, is I need a consistent level of security across the board. So once I get that common visibility, that common control and understanding of who's accessing it, how it needs to be accessed, and how that needs to fit into my risk scenario, then I can, I can maintain that across the different environments.
So if I can bring something to every one of my environments with consistency, then I can decouple where that application actually lives in a much more rapid environment. So that legacy application, once I have confidence that I'd have the same control and protection in the cloud, I can move it to the cloud with much more ease. And, and that's been one of the really powerful conversations we've been able to have with customers is one, understanding the risk to that application, which in all, not all risk is equal.
I think that's another thing that governments had to take on is, is recognizing that there's levels of risk inside of their environment. Uh, and that how do I, how do I control that risk in and mitigate any risk based upon, uh, where it lives? That that is one of the advantages that, that I've seen from working with, you know, a cloud provider like yourselves, is that you can do things in the cloud, like, uh, just simple examples, bot management, web application, firewall, uh, API security, things you can manage in the cloud, but also tailor to different environments, different locations, different, uh, policies, regulations, whatever it might be.
But you're still working on a consistent platform for the most part. So it makes it much easier to manage and the visibility of it. I'm curious about, you know, a big topic today is resilience and my working definition, you know, like any term we have in our industry, there's a thousand definitions.
Whatever purpose it serves to help me is usually the definition that we use, right? Um, I kind of think of resilience as the ability to, you know, withstand or, or kind of tolerate the unexpected. You know, we all are doing things to increase uptime, but it's those things that we can't totally plan for.
And, you know, a meteor hitting the earth is probably one we're not all gonna survive, but there's a lot of other ones we might be a little bit more resilient towards. How is the public sector thinking about resilience when it comes to networking? Well, they've been thinking about resilience for a long time, right?
That, as I I said earlier, that's, that's why we had the internet, right? Because of the Department of Defense looking at resilience. Uh, but it, it's trickled down.
I think cyber resilience is the buzzword this year, um, in, and every CISO is thinking what is their role in that? In, and to your point, whether it was cyber threats or, or physical threats that are happening, they're happening more and more frequently. How do you get prepared when the, the, the tsunami or the fires hit, or, you know, hurricane knocks out a city block or two city blocks, you ha have a big part of your data centers there.
So, um, our, our customers are always thinking of, uh, resilience clearly. Um, and we're a big part of that. Obviously.
The, the nice thing is you go to the cloud, uh, you have inherently built in re redundancies. We built in tools. So to help that redundancy come to light and be active immediately, uh, so that the citizens never even know a, a, a location went down or there was an outage in this, uh, due to this storm or cyber attack.
Um, and that, that's the beauty of one, this, this next generation, uh, architecture, I'd say, I shouldn't say next generation. It is the generation we are in right now, right? The, this cloud generation architecture that was built for applications that are out there in the cloud so that they can withstand a lot of that by default.
Um, but we, so we built that into, as part of what cloud play address for our customers and what we really focus on it and which is our customers, like about us, it's multi-cloud, right? Because what we're not seeing is not no one's gonna jump everything into Microsoft or into AWS or into cloud cloud. Everybody has this multi-cloud environment.
So it's really important for us to give you that cyber resiliency in a multi-cloud environment. Um, you know, being that overlay that can do it, whether you're doing it with the CDN technologies or DNS technologies to let you get that resiliency built in at the layer seven, uh, not just the layer one, two, and three level. Uh, we have to have both, quite honestly.
Uh, but we can do it so that you can have your infrastructure or your applications in multiple clouds, and we will help you give you that resiliency across those clouds to include your product cloud. So it, it, it's what all of our customers want. And, uh, I think we're hitting a home run on that, that spiral of the world.
Yeah. And, and I think back, you know, we'll, we'll, we'll do the US old guys kind of reminiscing of, you know, we used to build up our coop sites or our failover sites and talk about what was the downgraded experience in resilience? Like what had to live there.
I I haven't had a conversation like that in years anymore. Um, the power of cloud technologies, you know, whether it's CloudFlare working with a quote unquote competitor or one of our complimentary offerings, you can often layer those in, in an environment where your level of resiliency is, is much greater, and it, it's no longer seen by the end user who needs to get to that search. And that's so powerful to be able to say, wow, I can think about this massive leg legacy infrastructure that I'd have to build twice, you know, five, 10 years ago.
And now I can have two cloud providers sit there and have redundancy in my DNS environment or of my connectivity to my infrastructure, or across the multiple clouds that completely has changed the game. And we have to break away from that mindset of, you know, oh, this is a separate infrastructure, it's something else. And really just go, how does this service live beyond a failure at one police or another?
Hopefully no one has that, but, but we know we have to prepare for it in today's world. And I think our customers have the, uh, unique, um, vision that they have to take not only resiliency in the backend systems, but the front end systems, right? So because our customers are the folks that go into those disaster areas, right?
So how do you create a, when there is no last mile, how do you create the last mile with wireless technologies, et cetera? And then we can ride right along with that. So, and we talk about the criticality of, of service.
Mitch, if, if you tell us, uh, you know, a student or a teacher these days that, that inter, you know, internet's less critical for them, that they'll tell you how long they are, right? You, you talk, talk to your kids about what happens at school when internet goes off these days. So, um, it's a very different world, you know, than, uh, you know, open the textbook and turn to page, you know, 32, uh, in today's world of the internet is foundational in every element, whether we're talking education right on through to, uh, the critical services of defense and healthcare and beyond.
So you're saying the internet is somewhere in the lower stack of the Maslow's hierarchy of needs, you know, up there with food and safety and Things like that. I, uh, teenagers and ear early 20 year olds, um, might put it above food. I'll, I'll say yeah, barely, Right?
Yeah. I don't know your house when TikTok, uh, was shut down for that, that Instance, oh, you would think a tragedy was happening. You know, and, and it's funny you you mentioned that too, uh, Dan, 'cause I was thinking about you're in a world thinking about physical, you know, kinds of events.
You're in a world where you now don't have to operate and be resilient when something happens, hurricane or tornado or something. You have to respond. You, you also have to be able to execute.
And that's where other parts of, you know, EMA and other organizations come into play. They have to go in the field and rebuild and get a capability back up. So you have to live on both ends of it.
You can't say, well, we're waiting for our providers to get back going again. No, you are, you are the frontline, uh, in all situations. Yeah, it makes a, a challenge, but it's also fun, right?
It's, uh, you, you, you see the, that's, the public sector has some very unique use cases that no one else gets to, to play around with. So that's one of the reasons why it stuck around for so long in public sector, because we do really interesting, fun things out there. So.
Well, let's do this. We're we're just about outta time, and we can, I could spend another four hours talking to you guys. Um, what, what are, what is kind of top of mind for the next, let's say, this year, maybe going into next year?
What are some, some of the top conversations, the topics of those conversations that you're working on with people? Matt, you kind of alluded to some of 'em around cyber and API security. Yeah.
Any other thoughts on that? I, I mean, if, if we wanna a whole podcast without talking about ai, I think, uh, we'd be remiss. I mean, that, that, that's clearly top of mind.
Um, by the way, It takes so long to not make that EE Exactly. So, um, you know, we think about it in a few ways. Um, and it's interesting.
It's not just the model that's gonna serve the, the services out to the student or the constituent or the citizen. It's what should government be using AI for? How do we, as government, takes on more ai?
How do we protect those AI models? Um, how do we make sure that our employees and our contractors are going out and using the right AI tools and, you know, not uploading, you know, the wrong data to the wrong, you know, user setup there. And then ultimately, where is that AI gonna be delivered from?
And, and, you know, we, we talked a little bit about, uh, you, some of the data sovereignty and regulations and stuff, but where is that gonna be delivered from? How's that gonna be delivered on government services? That, that's very top of mind across the board for whether we're talking educational research, educational sharing, government services, and, and even national defense, uh, of how do we take on all of those elements in government?
You might not want, uh, government employees saying up for their deep seek service, not yet anyway, was find out what's going on about your perspective, Dan. I, yeah, I think every customer I talk with wants to talk about ai. How do I get prepared for it?
How do I secure my environment before it's here? How do I make sure I'm doing the right thing? Interestingly enough, the government's been doing AI for a long time.
I like call it legacy ai, right? Um, and, and machine learning has been in place for many, many, uh, in use cases in the government. When we did the assessment, there were like 1700 use cases, of which probably, you know, three fourths of those were in machine learning.
Now, generative AI is new, and, and they are definitely taking that on. Um, but it is, how do we get prepared for it? What do we need to do?
Uh, they don't want to be behind that curve, right? And the government has very quickly realized the dependency of data, um, with ai. And so, and the government has a data problem.
They got way too much data, right? And a lot of that data has never been labeled or, uh, and so you got all this data. So they, we spent a lot of time with, you know, customers talking about where do we start?
Well, we start with looking at your data, um, understand the AI technology to go on and get familiar with how they act and build guardrails around those. And, uh, but really you gotta focus on your data management, uh, strategy first. Um, and that's pretty daunting, especially in the federal government because they've been collecting data on many things for a long time.
Um, but it, it, it, it trickles all the way down to universities and, and, uh, state and local as well. So that's what we talk about. We talk about ai, how they can use AI in various use cases.
And very quickly we get to, let's talk about data management and let's talk about protecting your assets that you have, um, while building out these new AI models. Well, we do have, we do have a parting gift for everybody that waits till the end of the episode to bring up ai. So you guys, let's get one.
We'll send that to you in the mail, right? Gentlemen, it's been a real pleasure, uh, both, uh, Matt and Kent, uh, fantastic talking with you about it. You know, it, having done worked with the government a little bit myself, both in education, but also in in work.
You, you get to see how much research is actually funded by the government, which is why there's so much adoption of AI and other technologies, security technologies, a lot of things that, you know, not everybody in private sector realizes that's there. So we appreciate the hard work that's also done, but also funded by the government. Well, thank you both for, uh, joining us here on the last great CL cloud transformation, uh, program, video series and episode, talking about the public sector.
Wish you both, uh, all the success as you work with the new administration now, and the next one after that, whenever that happens, as well as whatever level that is. So, uh, keep us safe and secure, and thanks for helping deliver those services that we get from our government. So, thanks again.
Thanks everybody for tuning in. We look forward to seeing you next time. This Is Textron tv.
Hey guys, thanks for the, we're here with Lan, Yeshua and Hai Cohen, who are both the CEO and the CTO for terrific and security, adding the security to the back end of that to make sure. Um, and they're just recently raised $29 million in funding. They were address this nagging problem we've always had around browser security.
So we're gonna jump into this in a second. Gentlemen, welcome to the show. Thank you.
Bye. Nice to be here. Thank you.
All right, let's start with Alan. What exactly is the problem we're trying to solve? 'cause I think I've been hearing about we're gonna solve this browser security problem now for more years than I care to count, and it never seems to quite get solved.
Some people say, you know, well, I've got this perfect browser over here, but nobody uses that browser. And other people say, well, we're gonna secure the browser that everybody uses, but eh, it doesn't seem to never actually quite work out. So walk me through how we're solving this problem.
So, uh, uh, that's correct. I mean, the browser gradually became, in recent year, the most dominant application in, in coppers. And it was mostly secure from the outside, either from the operating system or from the cloud.
And, um, uh, the recent, uh, uh, emergence of this new, new category of enterprise browser security is actually coming to secure the browser from, uh, from inside, uh, because the existing solution don't have the necessary visibility and, uh, control, uh, inside the browser. And, um, the new approach is actually, uh, uh, providing this, this, uh, visibility and control, therefore taking it at completely different level. Of course, important thing is that while you are doing it, you don't impact performance.
Uh, any performance impact on the browser level will be intolerable. No one is ready to wait even a millisecond until the website is uploaded. Um, how did you get inside the browser?
Because I think, you know, what Alan just said makes perfect sense, but how do you get in there and actually do the thing he just described? Yeah, so as Elian said, the browser is highly complex, especially today, web applications are coming extremely complex. Looking at it at the network level, for instance, no longer works.
So, um, we bring the capabilities, Zi said, the visibility and controls into the browser, um, either through deployment, like an extension, which is local to the browser, no, uh, network inspection or SSL script, not none of that, uh, legacy, uh, tech. And if it's for instance, uh, BYLD or other unmanaged devices, uh, we bring the browser itself. So we always add the browser, uh, local to the user, uh, without the, uh, necessary like other legacy solutions that may require either an OS agent or, uh, uh, some form of a proxy, which as I said, uh, no longer works.
But I wanted just to add, uh, uh, uh, regarding your question, how do we get this visibility and control in the browser? I can elaborate about it more, but the uniqueness of our solution is actually that we are intimately involved with the JavaScript engine, which is the kind of the cannel of, of the browser, and, uh, having full execution context, how I can elaborate a lot. This is the uniqueness of our solution.
Rafik is a deep tech, uh, company. We have about five patents and additional 15 in filing. So we developed our own solution for JavaScript engine, and therefore, by the way, it's extended beyond browser also to any JavaScript and ever application, like all the model application teams, slack, et cetera.
Which, which is making it very important because when you look today on the desktop, the modern desktop of of, of your, uh, welcome either employee or contractor, it is actually composed of multiple browser and multiple, uh, modern applications. Abhai, is that a standalone browser that you created, or did you get inside, say, Google Chrome or any of the commercial browsers, or where, when do I have to exactly deploy? So since we have a, a native, uh, JavaScript agent that is capable of executing in every JavaScript enabled application like browsers, but not limited to browsers, um, we have the ability to also, uh, provide the commercial consumer based browsers, uh, while we actually, uh, infuse our tech into it.
Also, we do have a commune based, uh, browser that, again, it's plain old commune, but we, uh, the addition of our unique agent, uh, fused into it. So we, we have, we, we actually enjoy in pretty much, uh, both worlds. So we can provide a lightweight solution like an extension, uh, a, a hybrid one, like, uh, commercial browsers fused with our tech, or a full blown commune based, uh, enterprise browser, Alan.
So if I upgrade my browser, do I have to upgrade your engine? Or how does that work? Or how do you keep that in a way that, um, makes it all feel seamless?
You don't have to upgrade and, and to add to whatever you high said, we, with us, you don't need to change the browser. You keep your native browser, your, your mainstream browser. We bring the security to the browser.
The browser is updated automatically by the vendors, and you don't need to update our solution. Iha, if you want to update your, uh, to, to, Yeah, I, I will just add that in order to add more context. And when we look at the problem, we need to look at it in two, uh, different use cases.
There is the managed, and there is the unmanaged managed, meaning corporate devices, managed devices. Uh, so you do want to protect the device, the endpoint. In order to do so, you need to protect all browsers, right?
On the unmanaged device, it's a different story. There is, uh, uh, the device may be compromised, uh, um, and you just want to isolate the user interaction with the enterprise, uh, data in a way that is secure, even if the device is compromised. Um, so our tech plays in both, uh, uh, walls, allowing us to actually, um, provide the feature parity in the same level of, uh, capabilities, uh, in both ways, including security, which are highly important to the, uh, managed devices.
And, uh, using our unique tech and exploit prevention, we can actually, um, uh, prevent, uh, browser exploitation even from zero days and end days. So you don't necessarily need to update your browser, or it's not signature based, it's based on, uh, um, tech called MTD moving target defense, meaning using randomization just like a SLR, uh, uh, without any detection. So just by randomizing and making the environment non-deterministic, we're actually able to prevent exploitation, meaning that even if your browser is outdated, which is pretty much a common practice among, uh, enterprises, they, they need to test the new releases before they update, uh, their employees.
So, um, we provide, uh, uh, prevention capabilities, uh, uh, a strong and robust protection for that gap, no matter wide, it is, uh, for the enterprise until, uh, the enterprise decides to update, uh, the browsers. Uh, but it's not signature based. So there is no, uh, need for constant updates from our side, uh, for that specific engine.
So Lan, what's next from here? What's the plan? I mean, you know, $29 million is still a big number, and I'm sure everybody, you know, applauded and maybe everybody got a couple of beers, but where are we going from here?
More than a couple of beers, actually. So, uh, you are right. I mean, I mean, the main effort, I mean, we have a material product, uh, now, uh, with, uh, about 70 customers already, large enterprises, there is a demand in the market.
The main, uh, um, uh, most of the proceeds will go first and foremost to, to increase, uh, and build our sales organization, sales and marketing organization in North America. We do have a sales team here that we nice in 24, otherwise we wouldn't have, uh, this, uh, uh, uh, ground, obviously. Uh, so sales and marketing team in the us, uh, we already more than tripled the, the team in the last, uh, 45 days, but also to continue and support the r and d of the product.
As I indicated before, the, the, the main fault of raffic is the technology depth, and we have a very aggressive innovation roadmap for, for the product specifically. Now we are, we are, uh, releasing, uh, a new version that we, uh, obviously leverage on ai, uh, all the capabilities of AI on, on three aspects, and, and provide also enablement for, for organization as the browser is becoming, uh, actually also a gateway for ai, uh, users. So, so, so it's r and d enhancement and the go-to market.
These are the two main things, HAI, why didn't somebody else think about this approach before? What was kind of the aha moment for you? So I think, um, enterprises look at the browser as a part of, mainly a feature of, uh, ssi, right?
Uh, SW supposed to take, uh, uh, uh, and handle all traffic, including web-based browsers. So browsers until just a few years ago was not that widespread. And some applications, at least not the majority of ones, was, uh, native applications.
Now, the browser, the trend is always web-based. So many native applications become web-based, the application themself, um, become more and more complex. So looking at it, as I said, at the network level, is no longer enough, no context.
Um, traditional file uploads or downloads are no longer the same. Um, so you need to be at the access point, at the access tool, the, the browser, um, in order to be in the browser. Now you have two approaches, either to be the browser or in some form, some, uh, uh, uh, agent on top of it.
Now, extensions will not, uh, uh, uh, something abnormal, right? They're quite common. It's not something new.
Uh, our approach is unique because the extension is just the delivery vector for us. It's injecting our agent. Um, and extensions are by itself highly limited in terms of APIs.
They don't have always level visibility. That's why no one, uh, pushed forward on extension only solutions. We have a unique tech that allows us to leverage the extension framework, although, uh, we are pretty much, uh, resilience against changes and stuff like that because our, uh, capabilities are not at the extension.
Um, and since it's quite, uh, uh, unique and, uh, a generic approach, we can use the same agent in different, uh, methods and delivery mechanism. Extension is one of those, but it can happen in different ways. But in order to gain context and in order to handle the more complex web applications that other legacy solutions can't, you need to be at the browser in some way or form.
Uh, and we have that capability, including always level visibility. So we can provide feature parity and across, uh, different deployment methods. Ellan, last word on this, but the bad guys, you know, they, they're at work on all this stuff.
I mean, are they squarely focused on the browser? Is this their point of entry or how big a, a, a hole is This particular part of our extended attack service, Obviously what we see is, uh, uh, in enterprises that we made, we see a great demand. And usually, you know, the driver of the demand is breaches.
The breaches are, are the best friends of, of, uh, security vendors. And the breaches are, uh, on the rise in spite of the, uh, significant amount, uh, that, that the enterprise are investing. And, and some of them have something between 50 to even 100 vendors, the type of security vendors providing to them their, their solution.
So obviously we don't have a big problem sitting with enterprises and, uh, uh, exploring with them, um, gaps in browsers. So the statistic is talking for itself. Uh, uh, uh, 76% of ransomware is actually happening because of, uh, web browsing and, and the, uh, the semi tool regarding, uh, exploit about 40% of zero days are in browsers.
So the browser is a very sophisticated piece of code. You can't have such a sophisticated code, and you want it, it's a wonderful piece of code. See, it's driving the productivity of all of us in the world, but there is no way to do it without bugs, and there is no way.
And bugs means vulnerabilities. And vulnerabilities are the first step for, for, for, for breaches and for for attacks. This fact of the sophistication of the browser, uh, and the facts that the vendors are investing so much and so many line, uh, code lines are written every day, plus the fact that here is an application that the only one that is used by employees, both at work, but also to render external code from, for untrusted site.
And let's assume that almost any site should be untrusted, even the most trusted one that are used by, by, by, uh, bed, by bad actors. So this combination of sophisticated of the code plus sophistication of the code, plus the fact that it's rendering external code is creating, uh, uh, this fantastic opportunity for adversaries. But I want to say just one thing.
The fact that today, all of us, most of us are spending most of the time in the browser, is at the same times creating a, uh, an amazing opportunity for adversaries, but it's also an opportunity to consolidate the security requirement into the browser. And this is the big sh uh, uh, shift and earthquake in the industry because suddenly the things that you could have done only by very sophisticated, uh, sais solution with all these moving parts in the cloud and pops and reverse boxes, all of this, you don't need it. If 99 or sometimes 100% of your traffic is web-based, why should you do all of your analysis in, in the, in the cloud where things are, uh, uh, encrypted today, sometimes end to head, you have self pinning and all of this where actually you can bring the security to the, let's call it to the, uh, uh, crime scene.
This is the crime scene. And, and this is, I think what is creating a shift. And this is the reason that you see that, uh, um, um, technology leaders, both SS e company and EDR are looking, uh, uh, quite closely, uh, watching quite closely on this category and saying, okay, we need visibility in controlling the browser, either if IADR or SASS E and if I have the gaps.
So I need to get this visibility. And this is what is creating the momentum in the market. It's disrupting quite big categories.
All right? You heard in here, ultimately it is all about, well, the crime scene. And if the crime is occurring on the web browser, well then that's where we need to fight the crime.
Gentlemen, thanks for being on the show. Thank You so much, Mike. Bye-bye.
And, and back to you guys in. Hey guys, thanks for the throw. We're here with Michael Thompson, who is currently president and COO of Unisys and will soon be the CEO starting in April.
And we're gonna have a little chat about, well, what technologies are really the most disruptive for enterprises specifically in 2025. Michael, welcome to the show. Thank you, Mike, for, uh, having me.
Really a pleasure to speak with you today and look forward to the conversation. I think we've got some great topics to, to run through. Alright, well, we always seem to be caught up in one technology hype cycle versus another, and AI appears to be no different, but I feel like people are, or organizations are having a little trouble trying to figure out how to operationalize this latest wave of gen ai.
And I wonder if we have not found ourselves stuck in some permanent experimentation loop. I mean, what do you think is gonna happen in 2025? Yeah, LA that, that's the billion dollar question as, as they say, right?
Um, I, I think your, your pulse on that is spot on. Uh, I think there is still, uh, a very heavy discovery stage, especially when you talk about gen ai, right? But, um, in, in, in my opinion, and I think the way we treat it, there are, there are several elements of AI that are not hype, that are real, and we've been working with for a decade, and they continue to expand and and extend.
And so when I think about it, or we think about it from a strategic perspective, and I think it's indicative of the market as well, there, there's kind of two vectors, right? The first is the AI that you're using embedded in your organization, and then for us as an IT solution slash services company, that extends to how we deliver to clients and the, the things that we're able to do for clients. And it also is embedded in the back office functions, marketing, finance, advertising, et cetera.
I think that piece of the utilization of ai, whether it is the, uh, enhancement of AI operations and delivery of provisioning a cloud environment, uh, and, and, and kind of automating that component, whether you're focused on the data abstraction layer and how you actually can, uh, align these, these, uh, variable data points to get a better outcome, a better experience, predictive analytics, all of those types of things, that's pretty well defined known. And there's some really interesting and and utilization cases for gen AI in that I think about thought leadership, uh, and, and managing, um, frontline tickets and service and all of that. So that, that's pretty well defined.
And, and on its way, the, the thing that you mentioned that I think is really real and, and the billions of dollars that are being spent in this space is about how you commercialize ai. How do you make it revenue oriented? How do you bring new products to a client that is definitely still in this kind of search and destroy mission, right?
That everyone's looking for the ROI on the next big thing. There are clearly some things out there where, uh, they're already known and they're moving forward. I would say financial services and, and healthcare are probably the two industries that are on the forefront of how to use that technology to actually bring, uh, I'll say new and innovative products to the market.
And I think the rest of the market is really in the other prong, which is around how you do what you do better and how you engage with the technology to be i'll, I'll say another tool in the toolkit, uh, to really either lower the cost of delivery higher the, or, or raise the, the element of, um, utilization and or experience to, to the end user. I think those are the, the two ways we look at that. But at you, you're spot on with this hype cycle in the sense of it's the issue du jour, but, but I think it's starting to come down to it's the next issue du jour, and how are we using that and how will it ultimately, you know, reflect itself in, in the market perspectively, To your point, I feel like last year was the year of fomo, right?
We had the fear of missing out. And when I look at it this year, though, oddly enough, I think things are starting to split into two categories. One is kind of like, what are the new AI table stakes, right?
I gotta have this capability 'cause everybody's gonna have this capability. And then how do I actually start identifying things that will provide, say, unique differentiated value for my company? That's a competitive advantage.
So how do you have that conversation? Yeah, again, like spot on, um, uh, question wise that everyone's wrestling with. Uh, I love the FOMO analogy, and, and it's true, right?
There was a little bit of this, Hey, everyone's applying ai and if you don't, you're left behind, right? And so you're, you're running forward with it even though you don't know where you're going, but you have to do something right to stay competitive. I, I think it actually ties into the second part of what you've described, and I think it ties into our lead in here on the technology in general, the application of it in how you deliver, whether you're, how you deliver your own framework, your platform or the differentiation of your platform to your clients is where it's actually being applied.
So if I go back to my first, um, you know, commentary on that first vector on utilization of it, you know, if you think about the primary use cases that came out of the ch um, one would be co-development from a software perspective. One would be, you know, how you're using it in advertising and marketing to create content. One would be how you're managing your service desk in a, in a, in an omnichannel way that includes the ability for digital agents to, uh, you know, support that those are elements that are real and differentiating in how you bring your solutions to market.
No question. But now we're starting to get into, and, and this will continue, uh, by the way, I, I believe it will continue. The first stage is how do you adopt the technology?
Where do you adopt the technology? The second stage is really how it becomes part of your workforce, if you will, right? So just another element of your workforce, whether that's the toolkit or actually as a digital agent and those types of things.
The third is how it ultimately interacts with the unit, right? Instead of you prompting it to do something, how can it interpret what you want or need and ultimately deliver a better outcome without being asked and removing that kind of prompt engineering component of it. We're not at that stage with this, but we are in our lives and typically how we operate with technology in our lives, we want in our work.
So, you know, simple analogy. You go into your kitchen and you say, Alexa, make me coffee, or turn on the coffee and it works, right? If you think about a smart, um, conference room and all the data telemetry to understand the physical environment, the tools that you use and the user sentiment, in a perfect world, I'm booking a meeting and it knows it to me, it knows the type of projector I want, it knows the room temperature.
I'd like an added nose where I want the shades. I go in, it's tested all the equipment, the zoom call is up and operational. That is a great user experience, and I didn't have to ask it to do that from a prompting perspective because it knows who I am from a persona, persona point of view.
And it, and it's delivering that type of quality. And the preventative measure there is, let's say it does, its pre-check and the projector's not working well, it ships me to a new room and does that same setup and I don't even know what happened and I just go to my new room, right? So that to me is the experience you want in a business environment without having to pay, you know, additional, right?
You, you still are managing your budget, but using technology to provide that level of client experience by using the data telemetry of all the different components that we just mentioned is how it comes to life, right? And, and I think that's where that's really going. I think at the risk anyway of being overly simplistic, when I talk to some folks, they're trying to figure out where to insert these AI models and LLMs because they're probabilistic and a lot of the business processes are deterministic.
They generally need to be done the same way every time. And the last thing an LLM does is the same thing every time the same way. So, so how do we figure out where these things actually fit in a workflow That that's, that's a, again, a, a a great dynamic that we're actually all encountering right now, right?
And we, when I think about, and I'll just, I'll, I'll point it to Unisys just for a second here, and then we could take it to the industry view, but so having a definitive AI practice that can help companies do exactly what you've described, right? And, and an LLM, uh, if you think about data in general, and you think about where data resides, the, the current statistics will tell you 70% of data still resides on-prem. So do you take the data to the AI or the AI to the data?
Well, it's pretty costly to take the data to the AI and you know, and, and, and you've seen this, um, dialogue, especially recently with deep seek and you know, the, the elements of what's going on there from an AI perspective, that's that the heart of that is the question you asked. It's a data construct issue, and it's very similar to what we used to think about as master data management. And, and when you think about an LLM and the creation of an LLM, that's really about master data management, the dynamic nature of what those data sources are, how you secure those data sources, how you power the ability to do that compute, and then you really think about, well, if you see how, how it's happened in the past and how it may evolve in the future, those LLMs become, you know, s SLMs are small language models and they get pushed to the edge and you do GPU compute at the edge at the server, or you do it at the device level with a small language model that's fit for purpose to be more deterministic as, as you've described, right?
As opposed to, so it, so the art is really about establishing the data model, making sure it's dynamic, how it connects to the certain processes that you're really trying to own in on automation, and then cultivating that data model to small language model via, you know, dynamic tokens where you can interact very specifically and get, you know, great speed, no latency. The answer you want predictive in a smaller subset that can help you be deterministic, right? I, I, I think that's what everyone's trying to coalesce around.
And, and if I just tie it into deep seek, which is, you know, obviously the, the, the new thing that came out in the last couple, you know, week or so in regards to what, what China is doing on their AI modeling, essentially, it's that, right? They're, they're, they're taking this large language model and they're building these, um, you know, partitions if you will, to, you know, minimize the throughput that's needed, and then they need less compute power to get to the same result. And it's no different than those same premises that we've used in, uh, ma master data management and data oceans and data lakes and, you know, just environments that are smaller, more fit for purpose quicker and at the edge, right?
And, and I think we're at the very early stages of how we do that. And, and, and the cautious thing here is obviously prevention of hallucinations, using it in a matter that's practical, using it from a point of view that's, you know, not, not causing the company harm, making sure that data is secured and that you really have rights to all of the component pieces in there. So it, it's still as security issue.
You've got a lot of issues around data sovereignty and where people are that are accessing that data. So there's all these different levers, and it's not just the data, but it needs to start with the data, if that makes sense. You mentioned agent AI earlier, and I've been scratching my head about this.
So I'm gonna have all these AI agents running around, they're gonna be optimized for performing a specific task, but those tasks are part of a larger workflow. So how do I orchestrate all that into some sort of end-to-end cohesive process? Yeah, that again, like that's a, you know, obviously Mike, you're plugged into all of this, right?
'cause you really are hitting the heart of the challenges that all of our clients are facing and we as IT solutions providers are facing. And when I mentioned earlier about having, uh, AI be a member of the workforce, that's exactly what I meant by that, right? It's very few processes where AI is going to do the process end to end.
You, you know, there, there's this fear that, you know, at at, at a manual level, AI is gonna take over all the manual jobs. I don't think that's true at all. I think it's how we develop our manual workforce to work alongside of an AI component.
You know, what you've described is your typical RPA or you know, component where you punch out of a process, you do something in an automated way, you come back into the process workflow and you pick up with that process. And so it's no different than any, it goes back to TQM, right? You define your process flow, you find the nodes that are either repetitive in nature or pieces that you can save certain elements of time because you're doing the same things.
You punch out and do that and you come back into the process and then you finish that process cycle. I, I, I think part of the, the fear of adoption in some cases here is there's this big, this big ticket price, right? For putting AI in.
And so everyone's chasing the big ticket, ROI on it. And I think if we take a viewpoint that a whole host of small innovations in a process at the end of its lifecycle begets a ROI output, and we, and we think about it chunking up that way, it's actually a more practical way to adopt the technology. And as the technology evolves and our processes evolve, we'll change our processes.
But to do all of that in one fail swoop to say, I need to replace this entire process with this AI to make the ROII, I don't think you can make a case for that. And the other thing that I was wondering about is have we thought through the security implications of these AI agents? 'cause I got a feeling that there's a bunch of cyber criminals out there looking their chops going, Hey, you built a what that I can hack into and make to almost anything.
It, it again like that is, that is the quandary, right? We, you hear a lot about ethical ai and that's about how people are using it. But what you don't hear about is the unethical hacking exposure to that, right?
So that is the biggest issue with these data models. And, and you know, the, if, if you think about hacking component into your LLM and what it can do to all of the outputs, right? Uh, it it's incredibly, um, painful and, and, and something that we really need to think about, uh, in, in a holistic way.
And it's not going to get less. It's gonna get more, I mean, we, we talked about a little about the utilization and the familiarity with the technology. Let me just give you a brief example then see how these si if you don't protect it, what the output could be.
So let, let's say we have facial recognition at a bank, and when I walk in the door, it knows who I am. So before I even walk up to the teller, they know who I am, what accounts I'm there. And, and it's an automatic experience of, you know, good morning Mr.
Thompson, what would you like to do? And you know, I don't have my card. I'm not like they, they know who I am and they know everything or elements about me.
Now, now think about if you were able to get access illegally to that same data and modify the recognition so your face became my face when I walked in. And there's no other form of verification. If you don't think that's a playground for nation state actors to spend billions of dollars to get into that on any scale, uh, you're kidding yourself.
They're very sophisticated. They're spending as much to use this technology in a nefarious way than we're spending to use it in an ethical way. And so, so I see that as being more and more problematic.
And I also see it, if and when it happens, it is more detrimental to the company because the, the proliferation of what they have access to in an LLM or in the environments that you and I have been talking about is exponential to just taking data, which is kind of the viewpoint to that. So there's one other topic that people are talking about, and it's this whole quantum computing thing, and I cannot figure out if the hype around that is just a case of AI envy or are there actual use cases for this stuff, and when might that manifest itself? Well, it's not AI envy, uh, look, I, I look at, I look at Quantum, uh, as a Y 2K event where we don't know when the actual trigger date's going to be.
I, I think it is, it is known and understood that at some point, uh, in the near future, and the near could be over the course of the next five years, Liz, if we just bound that, that quantum computers will be able to break the current encryption we have. And the second that that happens, and, and that's why I say it's a Y 2K event, if you're not prepared for that transaction, you're done. Everything we talked about from a security perspective is, is on the table.
It has two elements to it that I think are pretty interesting. There's a software element to that and there's a hardware element to that. And you know, so, so part of it is building the, uh, quantum defense mechanism in the proprietary software that many companies have, and that keeps the bad actors out from using the hardware to break that encryption.
The other piece of that is the infrastructure, you know, the VPNs of the world and the encryption embedded in that. And, and you really need to look at your entire estate and pinpoint the areas where encryption is critical. And it's critical to everyone when you talk about, you know, your, your access directory or you know, anything like that.
Uh, and the, and the gateway to get to that. So you've gotta pinpoint all of those areas and determine the fixes that have to happen now to prevent that level of forced entry. And you've gotta do that same thing on the software side.
It's common. The same billions that are being spent in a nefarious way are being spent on that. And there's this whole concept of, you know, steal now decrypt later.
Right? Uh, when you, when you think about that, that's also real. So, but, so you have to have a protection against that standing where your vulnerabilities are and, and having a, um, a plan to how you get to, uh, prevention and, and you, and you and you damn well better have that before 2029 or 2028 in some people's cases.
Um, because once it happens, it's too late and it's too long a lead time to actually fix it. There you go. As they say, Q day is coming, Hey, the Chinese have a proverb.
That's something that says along the lines of, may you live in. Interesting times. Well, we're here And we'll be here for quite a while, I'm sure.
Go. Hey Mike, thanks for being on the show. Thank you for having me.
Pleasure talking to you. And, uh, love to catch up as, as frequent as we can. All right, back to you guys in the studio.
This is Textron tv. Hello, my name is Chris Blask. I'm going to be your host yet again for an Inevitability Curve episode where we take some current topic and look over it, uh, look at it over periods of time, spans of time, could be very long periods of time.
The conversation will determine. So today we're gonna be joined by Deb Radcliffe that I've known for quite some time. Hey, Deb, how are you?
Good. How are you, Chris? I'm loving life.
There's hurricanes and all sorts of things, but, uh, there's always a vo on battle fleet coming to destroy the earth, you know, so why not? Did Your planes get through the hurricane? Okay.
I haven't checked my Facebook yet. I lost Starling connection last night. Um, I'm ex, there was obviously some damage, you know, it may just be, uh, the power system on one boat, Sam Clemons, you know, got wet.
So the AC power is down, but, uh, I'm sure they're fine. I'm gonna have a friend fly over, uh, with a drone on Saturday when the winds come down and we'll assess things and go from there. So these are the solar powered boats I've been sailing up and down the Florida coast is Deon to me, right?
Yeah. And you're, and they're remote to you right now, so you have to do remote management of them. Yeah, that's right.
I'm a thousand miles away in Ontario, Canada, you know, so I'm logging in through my AppSec, absent devices to control cameras and water cannon to keep some of the, uh, the bird population down and do other things. But now I can't do any of that. But it's all, if you aren't Facebook friends with Chris, you miss all this stuff.
He has videos of the water cannon going after the birds and stuff. It's fun. Well, I'd say Instagram is more public.
I think, you know, it's, it is funny how we use social media these days, right? Which is, you know, getting us to our topic, right? The, the, you know, my expectations or main thing on Facebook is effectively may as well just, you know, post it, you know, on, on, on Twitter, you know, I may as well be just, just be public.
However, right? There is the friends posting then, and then there's room We turn public on and saying, no, really I am saying this, and, you know, so be it, God, right? So we've developed these sort of levels, right?
Yeah. But Before, so before I get into all that, right, as, as we're talking about in the Green Room, you and I met somewhere back in the nineties, you know, I think when you first started doing this stuff and I was doing firewall stuff, and the path you have taken is, is investigative journalism, cyber crime, all, you know, fiction narrative. You know, talking about how we, how we put all this stuff together from a perspective that is now fairly common, but has developed entirely under your, your purview.
So it's been a hell of a hat. Yep. How's that been?
Well, in 1995 when I was working on a book about Kevin Mitnick, my eyes got opened, and then in 96 I started telling magazines like, bite that they needed information to get out to their readers because this was gonna be a juicy, scary situation, and that their readers weren't ready for it. That the corporate America wasn't ready for it, that government wasn't ready for it, and neither were the poor consumers that we were leading to the web, like sheep to the slaughter at the time, and then blaming them for getting hacked. And so it's always been my mission to sort of blend all three of those constituents together as I do my reporting.
Uh, you and I were talking before we went live about how I felt back then, I was the only one shouting in the wilderness that this was coming and this was here, and we needed to deal with it with legislation, with better security controls. I remember when Cisco adopted its first firewall, I think it was through acquisition, was it Accent Technologies? Or who did they acquire when they came up with the Cisco Picks Firewall?
But way back then, That was a kinda the interesting backstory behind that. That was Network Translation Incorporated, you know, was it, you know, to this day, great friend Richard Clark. Um, and oh, I'm, I'm gonna go into hell for this.
I've forgotten, uh, his name, but, you know, there's a, a guy that was at the same time that I was out there in the world, you know, thinking about firewall things. And, and this is, you really leads me to down this whole inevitability Kurt thing, right? Because the network address translation, you know, those whole 1 92, 1 8 thing?
Oh, yeah. Um, I had this idea for, uh, a firewall and we, my boss and our little company had said, okay, let's do this in 19 92, 91, 9 2, and we're go running along and somebody said, Hey, there's no not enough, uh, IP addresses on the internet. And I had lost my mind a little bit because he was right.
I'd never really thought about it. And I ran to my boss's office, said, oh no, maybe this whole thing is a bad idea. And he didn't blink an eye.
And he says, John Sup. He said, I found that anytime there's enough of a need, you know, a technical solution is, is just found. And within 15 minutes, uh, Andrew Flint and El El Maya Al Gundi and I at a whiteboard came up with network address translation.
And the point, point of the story here is that John Mayes, so did John Mays and Richard Clark, 'cause he was consulting and setting people up with internet addresses, uh, internet connections. And every time he did it, their IP address would get a mess. And he thought, you know, this is a thing.
So he came up with the same table mechanism that we came up with. And at the same time, another group who wrote the actual RFC, uh, Tony something or, or whatnot, did the same thing. So it was just time.
Right. Wow. Fun to be there.
I forgot, I forgot how hands on you were back then. It's a, it is been a strange world. But NTI was the picks firewall, actually, I had that Was it?
Okay. At Cheese Dogs at an internet world conference back when it was like 80 people or whatever. Uh, not quite that small with John.
And, uh, he had the, he had the pics, the private internet, uh, exchange. And I had the Border wear firewall. If I was a firewall, he wasn't.
So, uh, after that he was right. And then we competed in the, in the market for a while, and I ended up at Cisco running his old, old, uh, uh, firewall. But that was the time to pave the world with firewalls, right?
It went from, you know, it was, uh, it was supposed to be end of life to the end of 98. John Chambers and the executive staff had actually issued the end of life. Uh, and, uh, uh, myself and Adam Wal and a bunch of folks kept alive through the winter of 98, 99.
And, and the rest was, uh, that path. But, okay, so what I got confused with was Accent Technologies was one of the first intrusion detection companies, and I'm not sure if they're the one that got acquired by Cisco. Cisco, it was Wheel Group got acquired from Austin, Texas Wheel Group.
Wheel Group. Okay. And when I interviewed the Wheel group, they didn't even have a quote unquote product.
And they were telling me about a virtual first ever. What they suspected was a mob hit on a, a patient in a hospital, and they were, the nurse was about to go to court because they were gonna blame her, but somehow they found through their intrusion detection, someone had gone and changed a record in the computer right before the nurse administered the medicine that killed the patient. I was never able to go public with that because I was all told to me off the record, and sometimes I don't know how much to believe, but it was one of the founders of the wheel group.
I remember having, I think we were in Texas having a meal together, and he was telling me this story and I was just going, God, why can't I report on this? You know? And so that was way back before anybody had a name for intrusion detection, except for maybe Becky Base over at the NSA, Right, Becky?
Yeah. Yeah, Yeah. Uh, you know, and the, and the, you know, I can tell I'm gonna have to really try to control the squirrel instinct of, you know, hitting this conversation.
'cause we can take this everywhere, right. And this Exactly. So that, that story right there, you know, that's literally the murder mystery sort of thing you associate with crime and novels and the kind of things, you know, you're, you're, you're doing now.
And it, there's always that boundary between, you know, let's say for a second, investigative journalism, um, and, and narrative fiction, right? Yes. And line between the two, right?
Yep. Yep. And that one would've made a great like Hollywood movie, even back then.
The, uh, narrative fiction. You know, Richard Clark has taken the same path that I've taken. He published his first fiction book long before I did.
And, uh, it was more of a sort of a single case, you know, legal case. And, and, uh, I remember getting on his case 'cause he sort of skipped over the romance scenes. And I said, you, you're pretty shy about that.
And he says, I don't care. I'm gonna write it the way I'm gonna write it. But I really liked his book, his first book, and I haven't read his other books yet.
But that wasn't something I was ready to do yet. That was years before I put my series out. But the culmination of all of our experiences, right, Chris, and as a journalist, my people have always been the hackers.
They, law enforcement and federal agencies came later when they finally caught up. But in the beginning it was just the hackers. And some of them acted tougher than they were.
Some of them were a little scary, but most of them were very helpful. They helped me get on the internet for the first time ever. Um, I had to pay long distance for a point presence way back then.
I don't know if you remember those days, dial up modems and then after that, you know, they were the ones who were sounding the alarms. Going to my first devcon was extremely eye-opening. Um, and just moving forward.
So the hackers are the good guys in my c cyber thriller series. 'cause they're the ones that who, who wanna fight this corporation that's taking over the world through human chip implants. And they're the ones who end up helping the NSA avert a cyber war.
And people say, does this stuff really happen? Yes, it really happens. NSA brings in hackers all the time.
You know, they need 'em for certain things. They bring 'em in. Some of them end up hiring in with the NSA, you know, so it's, it's, all of it was based on technical fact, historical fact possibilities that could be done with today's tech.
And I wrote that because I wanted people to understand what people like Chris Blask and others do in the hands-on environments that they're in trying to stave off this tidal wave of cyber threats. Well, and yeah, as, as I think about this conversation we're having, this is, uh, I think probably maybe my favorite episode to date on this topic because, you know, you and I shared this, this experience, right? And I, I, you know, now, now we're both here, right?
And back in, in your first days, you know, you as well, we're all sort of young folks. I speak for myself. I'm like, I don't know, like how I got here.
I was in my thirties. I'm not gonna say how old I am now, but you can extrapolate, right? And, and the, and you know, I, I remember being so, you know, sort of well suggesting things getting slapped down for him that today, you know, you know, as, as you say, you know, the, the, our peers and our folks, you know, Fred Cohen, um, who coined the term computer virus in his PhD thesis right?
In the late eighties. And you mentioned Kevin Mitnick, right? You know, uh, these are the names.
Back in the earliest days before I got into cybersecurity, these the names you'd heard, you'd see the, the thing on national news about this thing. You know, that was when, you know Fred and Kevin were both, you know, you know, the folks everybody was talking about. And then there was the I Love You Virus, one of my favorites or reference.
That's the one I remember. I'm like, why is Bernstein Young sending me a note that says, I love you? Right.
Well, you know, and I immediately realized there was something wrong, but it was the first virus I ever received. Well, but Yeah. And I, I actually, it was Weird, or I think it was the I love You virus, but maybe saying this from wrong because there's, there's, there was one reaction, real virus, but this one was the, uh, it was an email that said, Hey, tell all your friends, there's this virus Oh, called I love You virus, and if you open the, uh, email, it'll delete your hard drive.
Right? And then all the, what the internet was, was all text back in those days. They used net news groups, email and so forth.
And that just got enough. People just said, oh, I better do the right thing and post this to all my news groups. And then everybody else replied to say, stop posting this to all the news groups.
And it literally took down the internet, you know, all over the world. It Did. And I had like a dozen emails that morning and every single subject line in capital letters, I love you.
And I was like, gosh, this is just weird. So it was my first like, time I'd ever been emailed a virus before, you know? And of course I didn't click anything or do anything as like you said, everything was really rudimentary back then.
But, But, but, but, but the, the point of this, you particularly this in this you conversation is there was no virus. The whole joke, you know, is there was no virus. The virus was the email.
Right. Okay. Oh, okay.
It was getting people sending emails back and forth. Right. And then, and for those, you know, folks who weren't there, so it was More of a do a de BDOs type thing.
Yes. Or a spam. Right.
And this, and I'm sitting there and in Mississauga, the Ontario, Canada, you know, this little internet company before we came up with the firewall idea, and, you know, trying not to work of course. And waste my time on use net like, uh, like the kids do these days. And the, and I just couldn't help chime me in and saying, 'cause everybody was saying, you know, stop sharing this email.
It's not a real virus. It's a hoax. It's a hoax.
It's not a real virus, it's a hoax. It's not a virus. And I just couldn't help myself.
And I had to say, actually, I think it is a virus. It's like a Wetware virus, which started this whole other argument thread that went back and forth and consumed more of the remaining last bit of bandwidth on earth. But it, but it was, uh, you know, and everybody, you know, shouted me down.
Right. You know, my my point though is I was just this young guy, and I don't know what I'm talking about, and I felt pretty sure about it, but all the authoritative fingers in academia and so forth, jumping all over me. And I now ha you know, I do a podcast with Fred.
You know, we've had a radio show together. We, you know, the last 10 15 Fred Cohen. Fred Cohen.
Yeah, we do. We're yeah. Talking all the time recording episode, another episode of that podcast tomorrow.
And I guess, so I've got to, to, to, you know, live and have my career long enough to go and ask the guy that coined the term, right. Was that a virus? Was I wrong or was that a mimetic virus?
Somebody wrote code And what did they say? Fred's absolutely, it's a virus. Yeah, we long, that's what I thought.
Okay. Yes. And it's, and it's, it's proven to, to both our topic here and to kinda the world that, you know, we're talked, you know, we've been talking about the, the past, you know, how we got to this point, right?
And now we're at this point where things like that, this concept of a virus, everybody knows what a virus is today. It's not 1991 anymore. But we're approaching, I think, a common understanding of what misinformation, mental viruses people are trying to write.
Oh, yeah. It goes into your head and makes you do things like forward this email to your friends, just like in 1991 or whenever that was, right? Yeah.
Except, yeah, except 5, 7, 10 years ago. Most, you know, your, your friends and family don't really understand that idea. But I think just like computer viruses, the misinformation, disinformation, information, integrity, you know, we wanna give it a positive, uh, uh, term is something we've all gotten in our heads now.
Right. So where do you think we've gotten to with all that, you know, several decades of you and I and various other folks trying to get information and security into the popular culture, Into the minds of the common man? Yeah.
So I think that there's a lot more awareness. Um, she write the non geek, right? Yes, That's right.
But the normal people, But Right. Um, there's a lot more awareness. Uh, so my Breaking Backbones hacker Trilogy book has been at many, um, book reading groups.
And one of the biggest ones, I was at a regional session with a bunch of retired ladies. And when I stood in front of them, they asked me to read a section from the book. And then we did question and answers.
They were very sophisticated in the questions they were asking about, I got this on my mobile device, this is what I did to get back at them. And I'm like, well, that's really smart. I'm actually going to use that trick that you just taught me.
79-year-old lady, you know. So it was very nice to see the level of awareness has extremely improved since way back then. I remember, uh, about 10 years into my career, when everybody started getting mobile phones, the, I was at a bank, at my bank, and there was this young girl pregnant with her young boyfriend, and they were e you could tell they had emancipated, they were on their own.
They weren't 18 yet. And the girl comes in with her phone at this was heartbreaking. She said, she started saying, and she was in line, she didn't wanna wait in line 'cause she was in trouble.
And she said, I just gave this man money because they said I needed to, blah, blah, blah. And she's waving her phone and she goes, now they want more money and I don't have any more money. What do I do?
And the whole line, and all the tellers got silent. And I was in the front of the line and I turned and I said, honey, you've been hosed. Like, you're in trouble.
You got your money stolen. And she goes, what? And she starts crying.
And I said, please step in front of me. Go up and talk to a manager right now and see what they can do to help you. And that was my eye-opening moment about handheld devices and how we had the first level of us got educated.
'cause I came from a general assignment newspaper background. That's why I am for every man out there on in the cyberspace, I didn't come from a geek background. So I remember thinking, okay, so wave one was email and computers, and then laptops, wave two was handheld devices.
She had never had a computer, she had never had a laptop. But now she had this smartphone in her hand and she was getting scammed off the phone. So, fast forward 15, 20 years later, however long it's been since cell phones got into the hands of everybody.
And I think that the level of sophistication is gone. You know, we understand that bad things come in text. We understand that, uh, you know, people are trying to scam us on social media.
What we're not understanding is we still believe what we read on social media like nudes. And that's the misinformation part that's happening. Now, that's the part that's really scary.
I, as a journalist, you as a, a journalist and an analyst and a thought leader, I have to sort through stuff that I see. And if it's that hard for me, and we've got deep fakes and everything else coming down the road, we've got elections, we've got misinformation, social media is now the big bugaboo in terms of misinformation. And how do we set filters?
How do we create an ease, an easier environment for these people to either sort through or should we just unplug? Because did you read these Neil Stevenson's book 70 EEPs? Oh yeah.
Okay. Do you remember how the Space colony basically killed themselves off because of misinformation on social media? I Love, uh, Stevenson and you, my, my first bit of journalism was a article in the, uh, in Index news in the 12th grade, uh, uh, high school news newspaper where I did a review of T HX 1138.
And my summary there was, this has nothing to do with futurism. This is commentary on current social issues. And I love Stevenson, but you know, it does the same sort of thing, right?
So I'm, I'm hoping that's my whole, so whole point of this whole inevitability curve thing. And it, I is that 5,000 years from now, we'll probably have figured this out, even if the moon calls Apart 5,000, we need to figure it out 87, right? For inside joke for the Neil Stevenson fans.
But, but this is, yeah, I think that's, I think this speaks a lot to where we are right now. Right. And, and again, your background is, is a fascinating one on top of it because you've both done this, you know, transition across the, what we now call content creation.
We used to call writing. Uh oh Yeah. There's so much content out there now.
But, uh, you know, but, but in cybersecurity and privacy and cyber crime and all these other related topics, right? Mm-hmm. And I, I find in the information integrity space, you know, I, I think that really is the issue.
You know, we, we see dis information campaigns and influence campaigns of, you know, malicious actors and so forth. But it's really not all of those negative things. It's, it's, it's about information integrity, right?
We've got, you and I both know that the actual ability of the, you know, public, private, commercial, technical community to deliver the integrity you think you're actually getting from information. Uh, we're not there yet. You see how it never was.
So now, I mean, my free LinkedIn Want to change things by, you know, issuing a certain amount of b******t that's actually possible for now, but it's not likely to be possible forever. And in part because of what, you know, we're just talking about that. I think everybody, all of my friends, I had shout out to a life, another lifelong friend, bud Houston, best guy on earth.
I've known his son Trey since he was born. He is, you know, now a, a military retired mil military veteran and great guy. Great, great.
I wanna say great kid because I'm 60 years old, but whatever. Right? And he's, you know, he was exactly the kind of guy, you know, he is very patriotic, you know, very energetic.
He always has been. Believe it. He was this tall, holy cow.
But, uh, you know, and, and so he is absolutely not an idiot, right? But, you know, he is, thank God, you know, in some of the same social media that I am, instead of retreating and saying this, I've had the opportunity to counter a little bit and say, all right, you know, what you're seeing, I don't think is what you think it's, and connect him with other friends. Why John Baumgartner, you know, John and, uh, uh, who Oh yeah, he's Been posting about he and his damage in Asheville, Right?
And he's the, this is, you know, for anybody who doesn't know John Baumgartner, you should, 'cause he's a, a, uh, uh, retired military combat veteran, you know, wonderful guy, peer, you know, peer end pillar and icon of the information security community as reputable source. I mean, seriously, if you get, you want any more better than Joan, you're not kidding. It lives in Nashville.
His tree was hit by an 80 foot oak tree. He is been organizing his community and he understands emergency response, right? So, yep.
And he's been sharing those, his capabilities with his community, right? And his experience with the rest of us. You know, and to, to our point of our, our, our thread here, I think that sort of thing works, right?
I think we need better technical things and maybe some regulations, God help us, or, you know, laws or whatnot on how information is is handled. But I think most of it is, uh, a public understanding. You know, we need to evolve past this.
Maybe a generational kind of thing. I think Trey's generation is in a better position than ours, perhaps, right? To really understand.
I challenge that assumption a little bit, Chris, because we are sharing understanding. We fact check, we put stuff out there and people still wanna believe what they want to believe. Well, I, I, I, my caveat, you know, to what I just said, it was today, right?
I think in 10, 20 and 30, 40 years, you know, well, that this generation now is, you know, living through it from, you know, my kids' age. You know, the 20 something is 30 something, right? You know, um, Much more exposure than we had when we were kids.
We had no exposure to any of this. You know, my kids grew up with one computer in the living room, and now they all have their phones and everything. Parents have to deal with that.
So everybody's getting exposed and from a very young age now, and what does that mean? Sometimes I think we are part of a large video game that we put ourselves in that's very realistic. And when we die, we go back to whatever it was we came from.
And then we have a virtual world within the virtual world happening now. And it, you start looking at this like when you're looking at a hundred different mirrors and you see all the images of the images of the images, and that's what it's feeling like to me right now. You know, It, it, it, and it really does, right?
It's really common. You know it, and it's easy to feel that way, and you can see it expressing it through popular culture more, you know, um, mor not Morty, Rick and Morty, right. You know, and that the multiple, there's so many different parallel universes.
Doesn't matter what anybody does in any one of them, or simulation. I like that one. Right.
You know, we're living inside of simulation, inside of simulation, inside of simulation. And, uh, and I think, you know, so, and looking, you know, just try to, you know, get this at, at the end of this and looking forward, right? I think we posit this.
I do think, you know, the generations coming out, the millennials and so on and, uh, around them, um, will over time, I think they were kind of the answer to, you know, this information integrity thing in part because that's what you were saying. I think so too. They were literally, you know, you and I have had to learn this, you know, we came from a world where seriously, the amount of information, when you say three channels of television, you don't understand.
Right? I remember those days. Right.
And that's, you know, you know, the antennas and tinfoil and, but we really do have a, you know, a a cohort of folks who are coming along, who are quite bright, are quite educated, quite connected, you know, maybe as a, as a gestalt group, a little confused today, but give them 10 years, another 10 years and another 10 years, and tell me we haven't worked our way through this. I agree. I, I might be working on a book about seasoned expert advice from our top security pros, the icons in the industry.
It's may or may not happen, but if I do, I think that what we need to do is we need a two-way dialogue from the old folks down and from the young folks up, because I know young folks are much more open with their use of technology than I am. I am, I'm shy. I'm not shy, but I'm careful what I adopt, what I don't do, TikTok, I don't, you know, I use Instagram, but not TikTok.
And I, there are places I stay away from because I know that there not controlled by the US or, you know, other reasons. And the rest of the kids, the younger people just don't care where their platforms are gonna be. Their platforms are gonna be their platforms.
And so I look at that as they are going to be teaching us eventually because they've got the background and the savvy that maybe some of us don't have. Yeah. I think with three kids in my, in their twenties, they're span that decade.
I am biased. You know, that's my, uh, that's my bias statement. I, I, I just agree.
And I, it was just not to say I know what it is exactly what that future is gonna look like. Right. But I, I see, you know, that's certainly the ability, you know, we are gonna have the ability to have a good future, you know, 10 years and 20 years and 30 years and 40 years and 50 years from now mess, you know, more.
I won't be here then. And, but yeah, I, I won't either. Right?
I know young folks who will and, and, and heck with some medicine, you know, as I always try to look at that one, it's like, look, I'm not planning on benef, you know, being the one, the first one to benefit from, or sending, you know, techno, uh, technology or medicine, whatnot. But I won't be surprised if at any point in my life, you know, it seems more and more clear that someone my age is gonna live to be really old. Right?
There's, if you're lucky enough to live to 120, anyways, you're 60 now, we're talking 60 years from now. You might be, you know, a good candidate for some of the, you know, genetic or God knows what, uh, medical changes happen in the next 60 years. So that, you know, none of us need to count on this to be my point here.
But, you know, we're in that realm, right? So my kids, you know, the generation after them, generation after them, you know, there are people walking around right now that I have an interest in seeing the future for and thinking about this, right? And on this true that every time I've seen angst and, you know, uh, uh, all, all my life, right?
We we're gonna run out of food, we're gonna nuke ourselves to death, yada, yada, yada. Uh, haven't so far. It's amazing.
We haven't yet, right? It's amazing. We haven't yet.
No, I, I frankly don't think we're going to. Right. You know, I don't think Kim Jgi is gonna launch a thing because he likes his caviar and schnapps, and he is spoiled little brat.
But, uh, and you go spoiled A big brat. Yes. But, uh, Well, so, but yeah, back to the future, like where we're going in the future, I see some of that where the younger people are gonna come up the ranks and come up with new solutions and new ways of utilizing technology and then screening my whole career, I feel like I've been a, can I use a bad word here?
Oh, Absolutely. It's brought on me on, on the internet. My whole career has been to be a s**t screen.
And there is a lot of information coming at security leaders that needs to be filtered before it gets to them. Uh, because every vendor in the book thinks that they have the silver bullet. And my whole job has been to be say, yeah, no.
So you fix this little problem over here, but there is these 10,000 problems over here that you're missing. And so no way are you gonna be the silver bullet. It's also asking the hard questions.
Were you at the Cisco event when, I don't know, 20 years ago, I raised my hand and I said, excuse me, Mr. Cisco people, it seems to me like we should change internet protocol. We should change ip, or we should get rid of it all together.
I got laughed out of the room, and now we have IPV six, but even that isn't good enough. We're still on technology that was created in the eighties, and it's open and says, hello, here I am. I'm sending out my beacon.
Hello. I'm here. Come hack me.
You know? And that's the way I've always seen ip. And so the whole thing about Cisco laughing me outta the room, and then 20 years later we've got IP V six, it just, those are the hard questions.
No one really stops to ask. No one really stops to, maybe we do need to tear it out and start over or start over and then tear it out with some, you know, once we have something better, you know? But those are the big questions who I think we need to be looking at in the future.
Right. I think, uh, you know, this, this, this is, this conversation has led to an interesting point, right? Because I think that you, if I can be really honest about the, the short term future, the next 20, you know, 20, 30 years on these topics, um, it could go either way.
You know, it's, it's tending to look pretty ugly. You're right. There's so many legacy issues that it will take a lot of redoing.
Um, but in that same, uh, era, you know, this whole cohort of, you know, what, you and I can call kids these days, you know, we're gonna get to our age and they'll come up with all sorts of amazing things. So I think we'll get out of that midterm, you know, that, uh, that, uh, that we can see really, you know, see close enough from here to, to, you know, do things about it. Um, I Hope the smart people don't get egos though, like Elon Musk has.
And I think that we need smart people helping, but not trying to become gods. And I find in, in technical technical industry, there's so much ego. And as a female in the industry who has to interview a lot of men, I'm very good petting their little egos to get the information I need.
But, you know, come on, this is a huge problem and we're all a team and we should all be working together. And there should be no gods of tech out there, and there should be no billion b zillionaires in tech out there. And I hope that the younger generation is able to collaborate and, you know, not push up these icons like Elon and let them be the deciding factor of everything, you know?
Well, I, I think if I look in inside my, my home, my kids, I think, uh, I think we're in good shape. So we'll have to, we'll have to see, well, Deb, unfortunately, we have tabs, the allocated time bucket again, and, And we just barely scratched the surface, Right? That's kind of the whole, the whole point, you know, and I, I'll, you know, I'll the last thought on my own on this, and you can have yours, but, uh, I think that's the most fascinating thing about the near and far future.
We're all, you obsessed with AI right now, and Ai AI is doing a lot of things, but the thing we're really good about is doing a few Right. You know, you know, we all know the Yes, the, the old truism about, you know, i's actually seeing a very small part of what I think I'm seeing eyes aren't really biologically capable of grabbing, you know, uh, the definition of a camera. I think it'll always be the case, right?
We had to, we have 35 minutes, you know, we we're not, you know, made outta silicon, you know, and that's where we find our art. Correct. Well, I just wanna plug my book, the Cyber thriller series, the Breaking Backbones Hacker Trilogy.
Just look it up on Amazon or anywhere you buy books and give me good reviews, please. I need to play the algorithm games, speaking of social media and algorithms and everything else. So it's a constant hustle, uh, to get people to buy these books, but they buy them and they love them.
And so I've got all five star reviews and some people who read them are technical, some are not. Uh, some think they're too technical, some think they need to be more technical. It was the balance I was trying to get all along throughout all three books.
So hopefully you'll enjoy the story. 'cause it does start with a drone more and a kamikaze drone in book one and takes off from there. And when you read 'em, you'll know that I actually wrote them for Netflix.
And I do have a producer. Uh, we haven't been able to get it off the ground yet, but we're still working on that. Well, yeah, I, I thoroughly endorse all those and, and, and give the book on Amazon, Kindle, those nor normal places or, and I will have a link As well everywhere.
And we will put a link. Let's definitely put a link in the abstract. Got it.
I'll send that to you. Awesome. Alright.
Thank You. Thanks, everybody else. Thanks Chris.
Wonderful to see you from Hawaii. Right? I usually ask that From Maui.
Yes, from Maui. God bless the Internets. All right.
See you folks.