Techstrong TV – January 10, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone. Happy Friday. Is it freezing where you are?
Everyone else is. You're watching Text Drunk Gang. Good morning everyone.
Happy Friday. Oh, maybe it's good afternoon where you are. I don't know, but happy Friday to you.
Anyway. Talent sh from Techstrong and you're watching Text on Gang. We've got a great show lined up for you this Friday.
We're going from mountains to the sea and to the desert, everywhere in between to bring you the greatest, the what was the old a, b, c wide world of sports, the agony of defeat and the thrill of victory. Uh, let me introduce you to our text on gang lineup for today. First of all, it's his first show for the new year as part, uh, you know, with the gang.
Unfortunately, he's had some nautical issues, but he will persevere. Uh, he's our cybersecurity expert. Great guy, Chris Blas.
Hey, Chris. Welcome. Good to see you all and nautical issues for the record.
All are always good. Yeah. Yeah.
Well, at least it's sunny. That's right. At least it's sunny today.
Yes. Could be worse. Could be worse.
But thanks from being on. I know you've been going through some, getting the stuff ready and taking time out to do this. Appreciate actually, Chris, while I got you on too.
I, I got word yesterday that your podcast is finally gonna be on tech Drunk tv. That's right. Every Wednesday now, an episode of the Inevitability Ker podcast goes live.
And, uh, the first, uh, episode with Heather McMahon, who's as fascinating as you get, is out there. So each week, you know, we pick somebody, we talk to 'em about some interesting topic, and we try to look back where we've been, how we got to where we are right now, what today looks like, and with that, see what we can say about the future. So I'm really looking forward to doing more of that.
We got some round tables coming up. It's gonna be a lot of fun. Very cool.
Glad to see it get done. All right. Moving from the seat of the mountains, well, the mountains of Westchester County.
Anyway, there more hills. Uh, our chief content officer who has a, a better internet connection today. So where he's actually gonna be able to participate.
Mike Vard. Hey, Mike. How are you crossing Fingers and toes, but yeah, here, we're here.
All right. Good to have you. Back on.
And then moving from the hills of Westchester to the valleys of Silicon, our resident royalty, John Schwartz. Hey, John. How are you?
Hi, I'm good. Hey, on a serious note though, I wanna send some positive thoughts, vibes, and condolences to our friends in Southern California who are enduring these, these horrible wildfires. I'm just, um, exchanging some texts with a cousin in Studio City who's, um, quite concerned and might be evacuating.
So I just wanted, I just wanted to mention that it's really, really horrible out here. Yeah. I, I don't know, you know, a hundred mile an hour winds is just spreading this thing around.
Like, I guess only mean, I don't, I don't mean to be a downer, but I just, it's Something No, no. You know, touching all of this is, yeah. This is climate change, another aspect of climate change and sustainability and why we should care about green initiatives and and so forth.
Absolutely. So all in there. Absolutely.
Um, yeah, our hearts and prayers, and I hate that it's such a cliche. Thoughts and prayers go out to them, but No, you know, I, I think, you know, the government's doing what they can, but this, this is unfortunately an annual thing now, uh, as a result of climate change. And, you know, we have our own issues here in South Florida as a result of climate change, as will, I guess everyone.
And we've gotta adjust to a new normal and then create some, some heartache. Anyway, thank you John, for bringing that up. And then, you know, moving from Silicon Valley to the deserts of, of Las Vegas, were a small town, a stop over for GIS on their way back from out west.
Hmm. Was made into the gambling mecca of the world. There's not even a statue.
Um, just doing a little godfather riff there. Our, our eye on the eye on the prize. Lady on the street at CES, Lisa Martin.
Hey, Lisa, how are you? Hey, Ellen. I'm great.
CES has been just outstanding. There's so much to see. I can't even comprehend it.
Absolutely. Well, we're going to hear all about it. That's actually our, our, uh, first block today.
Why don't we go right to it, Lisa, there's, there is, there's more than we could shake a stick at as they say. But give us, give us your, take some of your big stories on CES 2025. Yes.
So I had the show floor yesterday, got a lot of steps in which I knew I would, and you have to plan your CES because, and their website is great at really looking at exhibitors and understanding where there are sessions, whether are there are exhibitors getting shuttles to and from different locations. 'cause it's all over the strip. Hundreds of thousands of people here.
The excitement level, I think it's even more than last year. It's absolutely back from Covid. But some of the things that I discovered yesterday, age tech, I didn't know that was a thing.
Digital health, I saw lots on digital health. We saw technologies that are helping to really scale the, um, optometrists, um, uh, issue in terms of too many optometrists re retiring, not enough in school. We saw some crazy fitness trends there.
And, uh, just some all around very cool textile computing technologies. I wanna start with Ibob. This is a, um, a company that John and Mike turned me onto the other day.
This is what's helping scale the optometry kind of deficit, if you will, in terms of practitioners. It's like a, a kiosk, kind of like an at m machine that does eye exams with all of 20 seconds. It does also, and this is all self serve.
Think of these at malls, uh, at Costco eye exam locations, Walmart, and they are, uh, in r and d for, for testing for like glaucoma, for example, retinal scans. They can detect issues and if they do detect an issue with the health of your eye, they won't send the prescription to the provider. They will tell you to go see an eye, an eye doctor or an ophthalmologist.
But a really cool way of solving this challenge there. I even, um, put my glasses and they have a, like this little portable, uh, thing that can evaluate your current, um, prescription and understand, um, what it is and how they would modify that based on the current eye scan. So really cool optics technology there.
They weren't doing any AI washing. This isn't an AI product, but it was very cool to understand how they're solving this, um, this gap with optometry and really helping people to get prescriptions and kind of separate the eye exam or the, the need for ophthalmologists from prescriptions and making things just faster to the consumer on the age tech side. John, do you remember that company called Skip with Joy that we uncovered the a i pants a few months ago?
Remember that John? Yes. I went to their session.
They were in the age tech section that was actually sponsored by A A RP. Um, very cool technologies sponsored by Age Tech and A A RP, uh, yesterday at the show. They're doing, um, it's it's move wear and they've got this exoskeleton with this tiny motor and really efficient batteries that helps you really ascend up, say if you're hiking or going upstairs, it reduces the load on joints by 40% when you're coming down.
They're also doing work to not only make the product more efficient, more integrated into, um, fabrics like, uh, textiles from, from ARC eRx, which is their current partner, but they're doing work for Parkinson's patients. So they're gonna be doing an exoskeleton pan with the motor in the hip to allow Parkinson's patients to have more stability and mobility. So it was just a great session there.
I also found a company called Mayan, M-Y-A-N-T. This is the company that is a textile computing company. And it, it starts literally with looking at fabrics and yarn and really presenting a new way of AI optimized health options from babies to elderly people.
So they're looking at using textile wearables to help prevent sids, for example, all the way to detecting AFib. And basically what their platform does is it creates a digital replica of our bodies, which is allowing AI to continuously monitor and optimize health in real time. You could sign up your family through your app.
It was just really cool because those are things that you just don't see every day. Very cool. Very cool.
I I, Alan, I also found the BM BMW for You Did. Okay. This, uh, I did, I went specifically when I saw the BMW, I'm like, I gotta go for Alan, uh, and myself selfishly too.
So BMW and Amazon are partnering, this was in the Amazon wing. They had an X three, the current X three. Um, and it's it, and it's an Alexa powered BMW assistant.
And what's really cool about it is it uses technology. It uses AI and LLMs to allow not just the driver, but other voices, one their programmed to be able to interact with the vehicle to say, for example, uh, we did a great demo yesterday where it said where the, the, uh, the demo, uh, organizer said, find the nearest, um, gas station near me, and it found a number of gas stations near the Las Vegas strip. And he changed his mind.
So you can reason with it, change his mind and said, actually find me the nearest gas station that has the cheapest gas and a car wash. So very cool to interact with it that way. It is actually in market now.
And as the years go on, they will be offering it in more models. It's not a subscription. This is an included service from BMW, which I thought was fantastic.
I also saw probably what might be a competing product from a company called Cardone. They're based in Tel Aviv and their spatial awareness AI technology is actually taking what MW and Alexa are doing a step further where they've got a single, uh, solution that would integrate with say, a car manufacturer. So you don't even know as the car driver 'cause they're, they're a B2C company.
But what it does is it actually is able to detect all the different voices within an, within an automobile from giving it prompts to turn the car on, turn the volume up, roll the left passenger side window down, things like that. I got a great demo of it in an SUV full of people and it was able to recognize each individual voice. And they are actually partnering this year with the largest auto manufacturer in Asia.
Couldn't say who. I have a feeling I know who it is. So really cool voice recognition assistance there.
And I did find the flying cart, Alan, I'm going today to check it out for you. But it doesn't look Jetson's like, I don't think it can fold up into a briefcase That doesn't fold up to a suitcase. It's a, it's be good with that.
Yes. Hey, I, I did discover a new, um, oxymoron at CES that I think both Chris and, uh, Alan will have something to say about, they're tossing the term around boating intelligence and apparently Brunswick is showing AI and the AI will dock your boat for you. So I know you guys have both had issues with this in the past.
So, um, easy, Easy there, big fella. I, i it so many things in that, right. You know, so as, as you guys know, you know, I've been building Alexa into these boats, right?
I can control a lot of these, you know, gadgets and devices and motors and pumps and so forth, you know, just by saying the words that it's interesting how to use that and how mature it isn't. And it has not been right. But Lisa, like you're saying, you know, what we're seeing at CES right now is examples of where we're going with this.
Because if, if some hacker like me can cobble together available parts and do this much, then a generation forward, a year or two forward, a step or two forward, that combines with, because it is convenient. It's beyond the hacker phase and the consumer phase when you can literally just say, you know, I, I could, I don't wanna take up all the time 'cause we have enough, uh, topics to cover, but so much of, of the, the, the evolutions that have been coming along in the last couple decades are happening together right now. And CES and what we're seeing in the consumer side is, is such a strong indicator, I think of a lot of the opportunities, challenges, you know, where we're going in the next five, 10 years.
And it's kind of amazing. You know, the one thing that's interesting to me is, and it's, it's happening in CES and it's happening with other, other types of examples of companies they're finding, especially in healthcare. There are a lot of shortages as, as Lisa alluded to with the optometrists, hence IBO for the, for the exams.
Same thing with Dent the dental industry. So we're starting to see, uh, robots or AI systems that are either doing the work of humans or at least assisting them because of healthcare area of concerns. And it kind of brings me to this weird, I mean, almost kinda a, uh, what we see at this consumer show in a sense is, I, I want to pay homage to, to a, at the pop culture reference, if you can indulge me on this one.
So remember the movie The graduates, there's, there's a scene in a hotel where a group of young people hurdle into the hotel, and then later you see the older people leaving the hotel, like this transformational process. And a sense, CES kind of to me, gives me this long-term lens of humans going into a job and then the robots and essentially replacing them eventually, or at least assisting them. And it seems like we're in this long-term transition that Jensen Wong Wong, uh, referenced in his keynote, like the physical AI and the idea of doing work with autonomous vehicles, warehouses, uh, healthcare, et cetera.
It's like this, we're on the on-ramp to this in incredible kind of new world in several years where the workforce is gonna change significantly. John, I I, one word for you, Plastics. No plastics was there.
Oh, AI. Now, but here's Tina, Mrs. Robinson.
I, I agree though. I, I think, I think in many ways, Lisa, you said it's CES is back. Right?
It's bigger than be and better than even before Covid. I bet. But it's also, we, this is a year where we're seeing a lot of the technology that we've been talking about as tech people make its way into mainstream.
And it's, it's creating some really, uh, some really cool, cool possibilities now Cool is cool, but it's not necessarily successful unless it's must have not nice to have. Hey, hey, Lisa, did you see any of these robots that people are talking about all over the place? I haven't yet.
I think they're at the LV convention center, and that's where I'm headed today. As I, I, I've heard some great stories. I've been following some great folks on X who are looking at some of these really advanced, um, techniques and, and products.
And I wanna be able to understand that. One of the things I also found, though, from a company called Withings and Digital Health, this is a direct to consumer products. They, they have really cool, smart watches that don't look like a typical smartwatch.
They're very attractive. They've got, uh, blood pressure machines, um, other ways of, of doing like urinalysis for example. And they have a prototype of a product called Omnia, where it's a giant screen.
It reminded me of that fitness mirror that could be placed in health clouds, doctor's offices that would be able to then do a full body scan, evaluate your cardiovascular health, for example. That's kind of the closest that I got Mike, but I will be checking out some of those robots today. Right.
There's one that I'll confess that I've never owned a watch, and I know PS oh, was there getting like $175,000 robot that CNET says is almost human. That sounded kind of eerie. And also this humanoid robot companion that you can fit into a suitcase.
It's just like mind blowing type of stuff. It'll Be, I think that's at the conjunction center in one of the halls. So I'm gonna be checking that out today.
Hmm. The medical technology fascinates me the most. I mean, I've been thinking about this since I was a kid.
You get this demographic bulge, this the boomers, they get to this spot where they're all getting elderly 50 years from now. Now you know, when technology moves along, how much of that sci-fi stuff do we get? Mm-hmm.
And it's, uh, and again, Lisa mentioned a whole bunch of 'em already. It's like just, Ima, we're right at that point right now where we can still accept the idea that maybe I've got some terrible disease and I get blood work every six months and I'm gonna wait six months. But right now, in, in a couple years and five years and 10 years, that'll seem just ridiculous.
Why am I not getting measurements every single day? Why am I not, why do I not have a graph of my blood pressure 24 hours a day for the last six months? I do.
Why do I have to go and get once every three, you know, weeks? No. Build it in.
I, uh, and now you can. Yeah, I, well, you absolutely. Look, I, I, I have my aura ring and my watch and all of these things, and I do, I track my sleep.
I track my daytime activities and stress levels and all kinds, you know, You know, I think the company needs a, an Allen blood pressure metering graph that we can just keep track of Lunch. I, I have it on my, in my app, I mean, but, um, and Right. And We're calling into that now.
So, so we're getting to the point where these technologies are off the shelf. So now the next wave is build it into your hat, right? Everything you wear gives you your bio, uh, your, your health, not just special, real wearable technology that's that mm-hmm.
Tracks our health. Mm-hmm. That's actually interesting.
Ibo Yeah. Well, I, I, I bought, actually, one of the reasons they, they did the, the company, um, is because it takes so long to get an appointments, uh, eye exam, physical exam. Yes.
And I think now, I mean, you know, it's like this, the, the immediacy of your health is so important. I mean, there's a doc, the documentary that we've heard about, the tech CEO who wants to live forever. I mean, he has, he's spending $2 million a year on his health, but it's just like, there's gonna be things available to us that are going to be less expensive and more immediates and more convenience, and we'll be able to track our health almost on a daily basis.
Absolutely. And share it with your healthcare provider as well. Yeah.
Right? That's, that's another big thing about it. And quite frankly, look, I think the whole healthcare provider game is going to change because Yeah.
You know, like this optometrist kind of machine, well, it, it, you know, rather than fill your prescription, it's gonna send it to a, a real life human to confirm its fines. Right? It does.
Yes. That's immediate step, because quite frankly, the machine will do it better than with less mistakes than the human will at scale. Yeah.
And Faster. Yes. And faster.
So I, I think so Lisa, thanks for that. You know, now, now you're on the hook to tell us about robots next week. So You got it.
Sign me up and flying cars and flying my chief priorities for today. Cars and flying cars, Rosie. All right.
Uh, let's take a break here on Textron Gang, and we'll come back and we'll talk about, uh, someone broke into the Cheesehead store. My God. What will, what?
How low can you go? You're watching Textron Gang Modernize your business to fuel innovation and elevate customer experiences with the builder community. Hub AWS and its partner network provide essential tools for transforming applications and infrastructure to fully leverage the cloud.
Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably. Visit the builder community hub to learn more. All right, folks, we're back.
And Green Bay Packer fans have had an insult added to injury. First, they lost the last regular season game against the Bears and now have to travel to Philadelphia in the cold to go play a playoff game this week. But then they also were informed that the online store for the Packers had been hacked, and that a lot of their details may have been stolen by the cyber criminals.
That, as far as I can tell, according to reports, went in and actually compromised the code on the website. So, Chris, um, I know we've been talking about deficit ops forever in a day, but are we gonna see a lot more of these types of attacks in 2025 where, you know, it's the actual code that somebody used on a website is gonna be compromised? Is yes.
Too short an answer for our, for our purposes here today? I mean, yeah, right. And, and you know, and you know, as I'm perhaps saying too much, but we're always going through phases, right?
We're going through the phase right now where we've been able to get away with sloppy coating for, I don't know, forever. And that's been falling because the big, the biggest fire was something else. And now we're at this point and is, as you know, I'm spending most of my time looking at supply chain.
And it's, you know, it's not all just about supply chain. You know, you can make right, wrong, bad code. Um, but our lack of ability to see what we have and where it came from is untenable, right?
We have to get to the point where we have a better idea of what we're running, right? And then we just see this over and over and over again in cybersecurity. It's like, up to this point, we've been fine and everybody said we had to do the thing.
It's like, well, what we've said is, sooner or later you'll have to do the thing. Now you have to do this thing. So now, yes.
Yeah. Knowing the code you have, knowing what shape it's in, you know, this is not 1998 anymore, right. You actually have to pay attention.
So I, I got a few things. First of all, Mike, do not feel sorry for the Green Bay Packers having to go play in the cold with the Philadelphia Eagles. It's probably the Eagles who are at the disadvantage.
The Packers. The Packers are the cold weather team in the NFL, right? Um, secondly though, the fact that they altered the, you know, they actually hacked the, the, the code of the store itself, in addition to, to exposing the customer's names screams to me as some sort of, not terrorists, but, you know, look, I'm pointing the fingers.
Chicago Bears Fence. The only ones in that they didn't make the playoffs. They did get some revenge in that they won this last game.
But the other three teams are playoff bound and, and the bears, the bears stunk this year. So I, there's your motive. They had the opportunity, they were playing Green Bay this weekend, so we got motive and opportunity.
I'm looking for alibis, right? Where they have no alibi. I I, I'm gonna point the finger at the Chicago Bears here.
What you have to ask the question. There are so many other teams, and they all have online stores, and they all probably have similar issues. So why are you picking on the Packers?
So there has to be some correlation, right? That's What I'm saying. So, So, but I actually, I have a theory about this.
So the Packers are one of the more well-known, I'm not sure if they're one of the more valuable NFL teams, but they're one of the more well-known teams that sell a lot of merchandise. And that brought me back to something that the CIO of the Cowboys, the Dallas Cowboys said a few months ago during an interview, he said something that was really interesting to me. He said that the, the true value in moneymaking enterprise for the team be beside the obvious TV revenue is their merchandise sales, and that their id it departments spend as much time and money on it as anything else.
It's a treasure trove of data. And I actually think in a sense it would be a value rich target. So, in a sense, the Packers, at first I thought, why the Packers?
And then I started thinking about the guy, the Cowboys and the merchandise. And, and especially among the more well-known teams. Well, the, the Packers are the only publicly owned team you could actually buy shares in the Packers bank.
So, um, so least Lisa, is this a marketer's worst nightmare to wake up one morning? And, you know, you got the big game coming up and suddenly the website's down. And I got a feeling a lot of marketers are gonna be dealing with this in the future.
It's absolutely a challenge that marketing and security have to partner to, to really understand how to message it. One thing that kind of caught my attention, I don't, I don't know if it did any of you guys, is that this breach happened in September October through certain payment methods. So if you use like a gift card or Amazon Pay, or I think PayPal, you were fine, but they disclosed it in December, and I thought, usually we hear about breaches and the disclosure is so much farther down the road.
Um, in fact, the San Francisco 49 ERs, John, were breached in 2022. 22,000. Uh, individuals had like personal, like social security information taken.
But marketing can really help here, Mike, to your point, from a messaging perspective, to help those affected. And this is about 8,500 Packers fans understand what was shared, how they can help credit monitoring, protection services and things like that, so that this doesn't just become routine. It is a messaging and marketing, um, arena where they can really help to, uh, asage some of the concerns that are currently obviously there.
Right? Well, all I have to say is, thank God I'm a New York Giants fan. 'cause no one cares about us.
This Parents, yeah. Merchandise sales haven't been as great lately. Yeah.
Chris, Can you get a second? I'm Just gonna add, you know, because I've, I've been the vendor in these sort of situations where there's some massive security thing is my, my products, my, uh, my fault and very strong feelings about this. You own it, own it.
Large, right? You're saying, Lisa, yeah. Marketing is huge.
Absolutely. But you know, the, you know, there's, there's, if you're gonna sustain this, you're really gonna build trust. You have to actually mean it because it's easy to sound good.
But if you mean it, then I will, then it'll last. Right? I, I'm trying to figure, find, find a way to say this doesn't sound too hallmark.
You're absolutely right. This, go over the top. Don't give, you know, if you'll say, we will not only give you credit monitoring, we're gonna send you shoes, I don't know, something, you know, just, just own it all the way.
Still more value. Been furious about it, right? Yep.
It, it, whatever that costs you is nothing to compare to the reput Sitting on a world. Brett fav, uh, jerseys. Get rid of them.
Thank everyone in the Bob Jersey. Number free game Ticket, whatever, you know, make a, make a statement and mean it. Yep.
All right. Well, good luck to the cheese heads out there, and good luck to all the playoff teams this weekend. Especially my Pittsburgh Steels who are the largest underdogs in the, in the playoffs this weekend.
I think we're about nine and a half point underdogs traveling to Baltimore to play our arch rival nemesis the Ravens. Um, but maybe we got something up our sleeve. We'll find out.
I'll talk about it on Monday. Um, let's take a break here on Textron Gang, and we're gonna move away from football and Cheeseheads to ai. What else is new?
You're watching Textron Gang. Hey everyone, it's Sunny And Cher Share. Ladies and gentlemen, tech enthusiasts and future Gazers gather round the biggest, boldest, most mind blowing predictions for 2025 are coming your way at the Predict 2025 virtual event on January nights.
Oh, sunny, you're predicting something again. Last time you tried this, you said laser dip for the future. How'd that work out for you?
Hey, hey, Cher. Not every prediction's a hit, you know, but that's why we've got the real experts this time, top analysts, visionaries and tech leaders sharing what's going to rock our world in 2025. So, no sunny predictions this time, no flying toasters making a comeback.
Very funny chef. But seriously, we're talking AI breakthroughs, cybersecurity game changers, the future of DevOps, cloud Innovations, and so much more. And what about my favorite prediction?
A smart mirror that tells you how fabulous you look every morning. That's real innovation. You're already ahead of the tech share.
But if you want to hear the really big stories in tech for 2025, you've gotta tune in on January 9th. The event kicks off at 8:45 AM Eastern and runs until 2:30 PM And the best part, it's all virtual. No stuffy conference rooms, no long commutes.
Just grab your coffee, your laptop, and join us from anywhere in the world. You know what else? It's not just predictions, it's insights, strategies, and a whole lot of fun.
0, predicting your jokes before you tell them. That's a good one, Cher. But the real joke is if you're missing out on this, so don't miss predict 2025.
That's right. Mark your calendar's. January 9th, 8:45 AM Eastern.
Be there. Or you'll miss the biggest scoop on the future of tech. See you.
I predict 6 20, 25. Be there. Hey guys, we're back.
And we're gonna talk a little bit about AI and cybersecurity. So we have an article over on Security Boulevard contributed by one of the thought leaders at, at, uh, Malwarebytes. And it talks about how cyber criminals will soon be using AI to create more zero day vulnerabilities.
'cause they can scan with the code and discover something and then launch an attack almost instantaneously. And, uh, the article is posing the fact that this whole thing is gonna dramatically escalate in terms of timelines. We're also seeing, however, that the providers of security platforms like torque or adding, uh, AI agents into their platforms to automate some of the workflow and the response.
Um, Chris, what's your assessment and what's going on here? I know we've been in an arms race for cybersecurity as long as I can remember, but this seems to be escalating. Well, you know, security is always, you know, always in a conflict.
That's literally the, the definition of it. And this, I think in the security community, we need to get past the eye rolling stage into the wrench turning stage, right? You know, this hearkens on the, well, what am I gonna use to protect me from rogue ai, my own ai?
Yes. In fact, that's what you're going to do, right? You know, you need to expect the, the adversaries.
You're going to use these automated tools with these characteristics that speak to scale and speed and so forth. And if you're gonna respond by hand, you are going to lose, right? So I think this year and next year will, you know, my industry will, will embrace that more.
You know, because it, and again, it, it's the obvious sort of thing. It sounds so cliche. It's like, I'm being attacked by cheese.
What do I need? Well, you need more cheese. It's like, seriously?
It's like, yeah, yes. You know, AI is the problem. So what you need to fix, the problem is ai, you need to automate yourself.
If I'm being attacked by cheese, I need more mice, Right? Right. Or crackers.
You said, let Me, I, I was gonna go with Packer fans, but yeah, I'm with Back to the packer. Leave that Alone Packer fans. So Stop the Bear Fans.
First of all, if you don't think that the hackers are already using ai, not just to make better phishing emails, which they certainly are, but also to do more fuzzing and, and and prodding to find zero days. 'cause they don't make zero days. They find zero days by testing.
And then once they find a zero day, they write an exploit for it, right? And so if you don't think they're using AI to help find more zero days and, and write exploits for it, you're kidding yourself. Of course they are.
You know, and this is, this is the double-edged sword of technology when it comes to cybersecurity. Every time we find something that can help us, you know, the, the adversaries are not dummies. They're smart.
You know, they're not dumb like that. And, and they, they use it too. And, and this has been one of my big fears, frankly, with ai, is that boy in the wrong hands, these guys can do some serious damage.
And, and Kristen's, right? We need, we're gonna need to deploy AI bigger, better, faster than the bad guys to stay. Just to stay even, not even to stay one step ahead.
There's a why don't, Sorry about that. It is doing the same work, right? You know, as a, as an attacker.
And again, you know, security is, is always yin and yang. There's defense and offense. You know, we, by any definition, literally any definition of we are sometimes the attackers, you know, I wanna be able to attack, you know, people that are pausing a threat to me or whatnot.
And, and you know, this, this is, you know, we wanna do the same thing, you know, as an attacker. I have way too many options. I wanna use automation, AI in this case LLM call.
What you want to narrow down those options to the number of things that I can really focus on as a defender, I want the same thing. So in the same way that these tools do in, in fact present a lot of risks, they present exactly the same set of opportunities. So it really depends on how you choose to use them.
So Alan, do you think we're prepared to spend the amount of money required to make this defense? Or is this gonna be a year where we stand on our hands a little bit and wait to see how hard we're gonna get whacked around before we respond? Chris, how long are you in security?
30 something years. I'm coming up on 30 myself. In all of those years, have you ever heard a security person say, oh no, we have too much money, we're fine.
No, no, of course we don't have enough money or resources. You know, if you ask the security people will there, I think a better question is, will there be substantial resources thrown at this and spent on using AI to hone our security postures and processes and so forth? You bet.
Here's what I'm interested in. I probably won't get a better feel for this till the RSA conference later this year. Um, we're gonna see innovation around AI and security.
Are we gonna see a new crop of security startups that are bringing this innovation? 'cause that's usually where innovation lives in security, right? It's not, You know, there there was some, there was something, sorry to, to, there was, there was a company, there's a company called Code Intelligence in Germany that on Thursday introduced, uh, an AI agent that autonomously finds bugs and vulnerabilities and unknown code.
Yeah. I mean, so we're gonna start seeing more of these types of companies, Perhaps. There's no doubt we're gonna see it.
My question is where coming from, I mean, it's right, because generally speaking, the security companies that you know and love aren't where that innovation takes place, right? You're not gonna see Cisco, Palo Alto, McAfee, uh, you know, the, the big security guy Sentinel one necessarily innovate. They usually buy innovation.
So I'm, I'm interested to see next crop of code intelligence type of companies who are native AI natives who, you know, are, are utilizing this technology to, to improve us. And, and then by the next RSA after that, they'll all be worn up by those big guys. 'cause that's how, that's how security works.
Um, but you know, it, it, we, for the last couple years, Chris, you've probably heard this too, at RSA and Black hat, you know, the, the kind of mantra's been, well, where's the innovation? Where's something, where, where's the next big thing here? And I, I hope this year we actually see that what is, you know, where, where the innovation is.
I'm all for, I'm all for these tools that help you find these vulnerabilities. But I ask the question, who's gonna fix 'em again? Ai, well, if you Your own down, you, you, you know, we have people fixing things that don't need be fixed now, but you don't really know which they are, right?
So I think that's, I think we get a, a lot more efficiency in the existing resources being applied to things that have otherwise been overlooked. Um, and to your question, Alan, I I am, I'm advising a, an AI startup right now called Radian. You know, looking at ai, AI for compliance, AI compliance, which I think is an interesting spot.
So yeah, I think those, I think we'll see across the startups. Yeah, that'll be great. We, because we could use it in all honesty, right?
We could use some new Yeah. Well, it depends who you talk to, I guess, right? Um, I, I remember when, you know, we had seven or 800 venture backed cybersecurity companies, and, and my friends would say, oh, we only need 300 at most.
These guys are gonna go outta business. Then I heard the same thing at about 2,500 venture backed cyber security companies. Then I think the last count I saw there was about 7,500 either public or venture backed cyber security companies.
So it seems like you could have enough. So we'll see, call, Call me dubious. But I think a lot of those patches created by the AI systems are gonna break a lot of things.
And it's gonna be interesting times. It won't be dog. Well, if you digital twinning, you could actually maybe make sure you don't have another crowd string kind of thing, right?
I, I think is a good technology for, for testing patches. Mm-hmm. Um, yeah, I Know, I, I say I think, you know, this year, we'll, we'll see some people, to your point, Mike, you know, getting this, you know, notably wrong and the only advice having don't be them every Year, right?
Yeah. So it want nothing new there, but, you know, slowly but surely, it's, it's the cybersecurity chacha. You take two steps forward, one step back, but over the course of time, like evolution, you know, it, it moves along ever so slowly, but moves forward.
Those of you who are about to patch, we salute you. Okay. Alright Guy, I, if we don't have anything else, we'll, we'll, we'll call it a wrap on this edition of the gang.
Lisa, thanks for the report, Vegas, enjoy your next day there, Chris. Thank you. My pleasure.
Ah, it's our pleasure, Chris. Good luck with the boat, man. I hope, I hope you headed down this way soon.
And it warms up and it warms up a little by then. Mike John, as always, thank you for joining us. Thank you all for joining us.
As usual, we have a full day of Techstrong TV immediately following today's gang, so stay tuned on that. Um, we'll be back next week with our full lineup once again, but have a great weekend everyone, and, uh, we'll speak to you soon. This is Alan Hummel, we're out.
This is Textron tv. Hey everyone, welcome back here to Textron tv. I got a first time guest here for you.
His name is, uh, Nicolo or Nick Loo. I hope, I hope we got that right. Nick is the VP of research for ML at Relational ai.
And we're gonna talk a little bit about, of course, ai. 'cause we don't spend enough time talking about AI as it is. M**k, welcome to Techstrong tv.
It's a pleasure to have you on here, my friend. How are you? I'm fine.
Thank you all for customer me today, and happy new Year. Happy New Year to you. Um, Nick, before we jump into things like graph Rag and and relational ai, let's hear a little bit about Nicholas's story.
Um, if you wouldn't mind share with our audience, kind of, you know, I said you're the VP of research ml, but tell us your kind of path to here. Yeah, so I came to the US uh, uh, probably 20 years ago, more than 20 years ago. I did my PhD at Georgia Tech.
And when I was, uh, graduating back in 2009, uh, that term, big data and machine machine learning was becoming very hot. That was exactly what I did in my PhD. So, um, I started working as a machine learning software engineer, started a small company and I worked with a bigger startup called Logic Log those days.
Um, and we did, uh, very scalable library in CPL plus plus about a machine learning. We were calling that, or statistical learning those days, which we did apply a lot to, uh, retail, you know, building demand forecasting systems. Uh, and then I moved on to security where we applied graph techniques, uh, very successfully on, uh, botnet detection.
We have a trilogy of papers, kind of like, uh, part of the rigs, uh, where we, um, we kind of, so how you can use machine learning. We discovered some boats that they were, uh, unknown before. Uh, really cool stuff.
Um, and then, uh, um, my startup got acquired by, uh, logic Lock, and then Logic got acquired by Infor. And then after that acquisition, we started the company with, uh, uh, a relational ai. So it's been a journey of about 15, 16 years now with, uh, the people from, uh, uh, what was then called Lolo in our relational ai.
Of course, many have joined, um, working on something, uh, that, uh, started as machine learning. And, uh, now we know it as, uh, uh, ai. Um, also wanted to highlight that during my journey, I spent a lot of time, uh, publishing at conferences, but also organizing.
I started a company, uh, conference called ML Conf, which was kind of a big hit for, uh, uh, industry. And, uh, I just came back from Europe, which is the, uh, biggest, uh, conference of ai. This is everything you hear about AI in all the cheering awards and Nobel Awards.
They all came from that community, which I had. Uh, really, I had the pleasure to, to be part, you know, I wasn't the smartest there. There are other people smarter than me.
You Never wanna be the smartest this's a lesson I learned in business. Never be the smartest person there. 'cause you'll never learn anything that way.
Right. Always better to surround yourself with smarter people, and that's how you learn. But, uh, interesting.
Excellent. What was the name of that community, by the way again? It's called, uh, it's called New.
It's started, it's about 35 years old. They started as nips, but then they remained into Europes. It's Neuro Information Processing Systems.
It's a conference that, uh, competes with Taylor Swift because they sell out competes Swift is gonna sell out first, you know, when they announce the conference, it was good. They can sell out in minutes. So Burning Man, really, Taylor Swift and Europes sell out very quickly.
I hope that tickets don't cost as much as the Taylor Swift tickets, but where, where was the, the most recent conference? Where was it held? It was in Vancouver.
It was in Vancouver. Ah, That's beautiful there. Good.
So you heard it here first. Thanks for that tip Nip. I, Nick, I'm gonna keep my eyes open on that one.
Um, so you, you know, tied into your journey, of course, was this journey that led to relational ai, but for people out here now, okay, they, they heard what you said, but maybe they're still not sure exactly what it is relational AI does and yes. Problems it solves. What, how, what would you tell 'em?
Uh, you know, it's kind of interesting. We, we started with a temporary name as relational ai. We spent, you know, we're doing AI in the relational world, but then we liked it, people understood it, and we kept it.
So just very quickly, um, I like, uh, uh, there, there's several definitions of what we're doing. I think that the thing that people would understand the most is the digital twin. First of all, we are, uh, a native app on, uh, on Snowflake, which means that if you have your data on Snowflake, you just turn on, you know, you just go to the marketplace, find relational ai, we're highlighted, and you turn that app on and you can immediately start using the app.
It's, it's a very quick and efficient way. Uh, sometimes we call ourselves the knowledge graph co-processor of a snowflake as just to explain to people just, you know, so if you don't know what a knowledge graph is, if you don't know, um, you know, even what AI is, um, I wanna say, like, I give you a simple example. I think it's better to understand, for people to understand, you know, if I was asking any, any of our friends here today to look at their, uh, enterprise database and explain their business, it will be extremely hard the way that you store the data in a, in a, in your enterprise database.
It serves multiple purposes. But one of the purposes that it doesn't serve is, you know, having an overview, an explanation of your business. You know, it doesn't have concepts, it doesn't have, you know, it doesn't show.
People are understand diagrams. They understand concepts. You know, if I have a supply, if I'm a supply chain, a CPG company, like Broker Gamble, somewhere like that, I have, you know, vendors, I have factories, I have, uh, transportation, uh, I have warehouses.
And people try, you know, they, they like drawing arrows and explaining their business as, as a big graph. This is what you can do if you have relational ai. And the nice thing is you tie that on your enterprise database.
So you don't, you don't move to a different system. You go to your database and you create this nice, let's call it relational modeling. People call it knowledge graphs.
There's different names for that where you describe your business. Now, once you have it like that, you can do magic because that diagram and that kind of type of modeling can help you run optimization problems like, you know, optimize your supply chain. 'cause you just set it constraints that this can only go here, it cannot go there, and I can only see 20 packages from here to there in a week.
All the, all this expression of constraints. You can do that naturally in our system. And then if you want to do ai, you wanna start asking questions and have, you know, a language model generating your business analytics and all that stuff.
We do know these days that the best way to do that is by having an knowledge graph. So all the effort you do to model your business as a knowledge graph, then, you know, automatically translates to an, uh, uh, uh, a planner. It can translate to a language model that takes that and generates ways for you and a lot of other stuff.
You can, you can, because we're gonna talk about that later. You can build agents, you can, you can do a lot of interesting things. So, uh, you know, if I had to summarize, you know, native on Snowflake, you don't have to move your data.
You don't have to worry about security parameters. Easy way to model your business, build a digital twin, and then build intelligence applications with the modeling you've got. But I think that's the most important aspect.
Absolutely. Look, you know, we, we covered graph, graph databases, knowledge graphs and stuff, a, a fair amount here on Textron through, whether it's on the videos or in articles or, or what have you. Another thing we've been covering, because it's become a very hot term, is the term rag, right?
And now, you know, part of, uh, relational AI is, is combining graph rack. Graph rack and how that helps address AI limitations. Make us smarter a little.
Nick, I I said before, right? I don't like to be the smartest person. You're smarter than me on this.
Go ahead. Talk to me. What do we mean by graph rack?
Yeah, so, uh, you know, let's start with the problem. I mean, the, the, the beauty about Gen AI was that we can, people want to ask questions and get answers, okay? And the question could be as simple as what's the capital of grace?
Or, uh, prove, how do I prove the firm theory one is like mm-hmm. Uh, one, uh, one word. The other is 200 pages of, of complicated math.
Okay? So this is the problem. We're talking, I want, I have a question and I need an answer.
Okay? So, uh, the, when you have a single point question, which is, you know, when was Apple founded? Who was Alexander the Great Sister?
Something like that. It's, it, it boils down to a retrieval. And we don't, this is called rug retrieval or, uh, augmented generation, which means that you take your documents, you assume that your knowledge is in documents.
That's the other thing. Like where's my knowledge? Is my knowledge in documents?
Or is it in a database? Is it on images? Where is it?
Okay? When your knowledge is not in the database, you use something called you know, rug, which means that I take my documents, I use a term called vectorization, which means that I collapse them to a vector, you know, a set of numbers. And, uh, and then I retrieve the most relevant stuff.
I put them on a language model and it gives me an answer. It's plenty of articles. It's extremely simple.
You can code it in three lines. You know, it's, it's very easy. Even if you're not technical, you can do that.
Okay? Now, there are some other questions that I call them multipoint. Okay?
So, which is, has Bill Gates ever worked at the same company with Steve Jobs? You know, uh, it could also be, let me give you a more complicated one. So I want to invest in the stock market.
Give me a stock that if I invest, it's gonna help Rwanda. Okay? How do I answer that?
Now, what happens is that in, in the typical drug, the first one that I described before, it's more like you, you treat your information, your documents as, as a pile of, you know, you stuck them, you know, it's a pile of books. Like you, you, you set them, but you, you don't exploit any relations between them. Okay?
And I wanna take people back, uh, the, the older, uh, uh, people from our audience back in the nineties where the web came out and you wanted to do a search and you were using Alta Vista, okay? And, uh, people might not remember how difficult it was. 'cause Alta Vista and all these searcher sensors, they were just doing a keyword search.
They were trying to find webpage that they match the, they weren't, you know, they weren't very successful until Google came. And what Google did said, well, you know what? The web is not just documents, web pages.
It is also, you know, they have links. They're linked together, okay? The hyperlinks.
And they took advantage of that. And voila, here we have Google, okay, so, and no one knows Al Vista no more. No figure.
I loved Avita, but that's another story. Go ahead. Yeah.
Anyway, they were pioneers for their time because there were of course, other problems except for just the, uh, the two Bobby. Sure. Now, so now Ra what it does, it says, well, you got all this documents, but before you ask a question, can I try and create links between them?
Okay. So you use the language model. Basically, I won't describe the process, it's an it alternative process to describe links between documents that they didn't exist before.
So if you find Bill Gates in this document and you find him in another document, you know that these two documents are connected. And if there's another document that talks about, you know, uh, just to give you an answer, bill Gates has still jobs never worked at the same company, but there's other case, uh, where can happen, you know, so you start extracting edits and relations and, and basically you build something which is, it's not exactly knowledge graph because it's not perfect. So let's call it the graph of knowledge.
It's a graph where different pieces of knowledge are. So what happens is that when you are asking the question, you know, you are able to retrieve pieces that they can be in completely different documents. And let me give you the, let me answer the example of, uh, uh, of, uh, stock market in Rwanda.
Okay? So if you take documents out of the web, you will find that, uh, an NASDAQ stock is Microsoft. Okay?
Now we know that, uh, uh, uh, bill Gates sits on the board, okay? And we know that, uh, bill Gates also has the Bill Gates Foundation and the Bill Gates Foundation invest in malaria. And malaria is the prominent disease in, in Rwanda, okay, rda.
So if, if, if you, if you wanted to, to solve that, to ask that answer, you would have to navigate over a graph and give that, okay? So basically, if the query has the term Nasdaq and Rwanda, and we know that there is a path that connects them, okay? So now we can navigate that graph and answer that question.
But of course, there's another case, which is what if my documents and my information is not into documents, but I have a relational database, you know, your typical enterprise database, that basically what graph, I guess it boils down, it boils down to, uh, you know, taking a natural language question and translating it to a formal query language, whether this is SQL or this is zq, well, or this is the language that we use or sparkle and it answers the question. So that's another way of, of, you know, of thinking about graph. Uh, so I hope I didn't confuse the audience, so No, no, I, you know what, that was illuminating.
Amazing. Thank you, Nick. You know what I'm sitting here thinking, I don't think we told people the website.
Is it relational ai? Relational ai, relational Ai, Tom? Uh, I think AI both work.
I think both work. com, um, uh, yes, using the relation ai, yes, but you can, as I said, you can always find us through Snowflake as well. Absolutely.
So, you know, we, we did, it's time of year. You're doing your year in review, your year, looking forward, you know, this type of thing. And certainly 2024, like 2023 for that matter, a uh, generative AI was, was all the rage, right?
That was the big story. A lot of people say the big story this coming year though, will be a agentic ai, right? Because now we're moving in agentic AI and then also physical AI robots and, and all of these things.
Um, how early are we, right? How I've been an entrepreneur many, many years. There's, I always wasn't always on media, I, it startups.
And the lesson I learned is if you just have a nice to have product. You're not gonna be successful. You gotta have a must have, must have products make money.
Is Graph Rag must have at this point, or will it be must have in the near future? I think it's becoming, I think it's maturing. Uh, it has matured enough.
We, we do have some, uh, uh, indications in the market that, uh, uh, people want it more and more. Um, but I wanna tie that to, to what you call the, about Advent ai. Okay.
If that's, that's fine. 'cause they, they're actually Yeah, no connected. They're actually connected.
So as I said, I came back from URIs, and 90% of the conference was EnTec ai. Even, uh, one of the key players from Open AI who got the Test of Time award, this is an award that you get, he got for a paper he published 10 years ago. And it turns out, it turned out to be very influential, which is what OpenAI is doing.
Iki, uh, he talked about that the future, like the oh one model is, you know, the is is a way of doing genetic ai. And, and many, many other people talked about that. Uh, I'm actually preparing a, a, a, a review of the conference where I'm gonna, um, talk more about that.
Um, so let's, can, can we define what an agent is? Okay. Uh, if I, if I may, go ahead.
So the best way to understand that is if we follow the, the very famous paradigm from Daniel Kaman, the, uh, the Noble, uh, Laureate, uh, uh, in economics who Coursely passed away, uh, this year, we, we do have a blog post, uh, explaining, uh, his theory in through the, the lenses of, uh, uh, advent AI on our website. Um, so we have the system one, there's a system two thinking, you know, uh, if, if, if you know, a rabbit crosses the road as you, you are, uh, driving, you know, you immediately hit the brakes. You don't think about it, oh, there's a rabbit.
Uh, I might get, I might kill it. You know, it's something that happens instantly. And then when I ask you to prove the, uh, Ethereum a pgo Ethereum, or solve a task, you know, assemble a, a, a furniture, this is the system too.
Like, you have to understand where I'm gonna, like, you start planning, you start trial. You, you know, trying something, failing, trying again, like it's a search process until you get there. Okay?
This is the Slow, there's a famous book called by Daniel Kahneman, thinking Fast and Slow. Now, in, in practice in Ingen ai, the language models, in the beginning, they were trained to answer a question immediately. You ask something, it starts generating, and you expect this to be correct, or you expect to be as the, as, uh, as complete as possible.
So that's kind of like the system one thinking immediately. I give you a que, I ask you a question, five plus five, you say 10, you don't analyze it, you know how to do it now. And as they kept, you know, increasing the size and the chaining data, um, it was becoming better and better, but then it saturated.
And then they realized that, well, what if I ask the language model several times and it gives me an answer, then I correct it. And I say, well, uh, I think you made a mistake there. Try again and try again.
And this is kind of like the people, you might, people might heard of that as chain of thoughts, which basically is, I'm trying to solve something, but in iterations and I'm searching different directions. So the language model using itself as a tool is, in my opinion, the definition of an agent. You know, uh, and it starts searching that when it plays tests, uh, you know, uh, it's smart enough to think of some moves, but it tries, you know, several thousands of different moves.
Uh, and it might even play a small game between itself for some time until it gives you an answer. Now, the importance of that AAD is, is huge. I'm, I'm gonna give you a reference from a, a talk.
Um, when a researcher was trying to solve the poker game, he saw his journey. He says, I kept training with more and more data, and I was getting to know my, um, better results. But I realized that if I was giving to my model 20 seconds to think the results were going through the roof.
And he says, by using 20 seconds to think, and to do this advent thinking, you are scaling a hundred thousand x compared to training my model with, you know, giving it more and more games, uh, past games to get trained. So we realized that by giving more time for the model to search, we can actually, uh, solve much harder problems. Absolutely.
And I, I, you know, so I use open ai, uh, GPTI, and I've been using the 1 0 1 model, uh, and you, and you're right, I see it's telling you what it's doing as a thing. It's a, you, you actually do see that. And I see a big difference.
Someone told me, oh three is coming out now. Um, I'm not, I haven't seen it yet, but, we'll, we'll see. Anyway, Nick, we're way over time.
But I'd lo I find this fascinating and I could sit and listen all day. We're gonna invite you back for more. You know, you're going to be, have to become one of our go-to smart people here around ai.
And, uh, I want to thank you. I want to wish you tremendous success with relational ai, ai, it sounds like a fantastic concept and graph rags. And as this becomes bigger and bigger, thanks for joining us today.
I appreciate it. Thanks for everything. Thanks for, We'll see you soon.
Nicholas Sili Siglo, VP of research ML at Relational AI here on Text Drug tv. We're gonna take a break. We'll be back in just a minute.
Hey, everyone, it's Alan Shimel from Techstrong, and welcome to our latest video series, the Last Great Cloud Transformation. You know, I was here in 2005 and six when cloud first kind of burst on the scene, and we talked about moving payloads, workloads, applications from data centers up to the cloud, or running clouds in data centers. And over the course of that 20 or so years, now, almost 20 years, we've seen various migrations, transformations involving adopting cloud.
But we're at a, a juncture in time right now where macro factors have come in that are really pushing, pulling and changing what we can do and what business demands like never before. We, we, we've built this huge capacity at the core, if you will, of cloud. But we also have the edge.
We have endpoints, we have people doing anything from anywhere. What's holding us back from going even faster further than we've ever gone before. Basically, it's network and security, right?
And our friends at CloudFlare call this the connectivity cloud, right? Joining in that core Edge Central with a strong network and, and security, connecting it all to do things better, faster than we ever did before with the advent of ai, gen, ai, and some of the other technologies available to us today. This is now possible where it wasn't possible before.
And that's why we say this is the last great cloud transformation that happened right here. We're gonna talk about it. We've got a great panel for today.
Let me introduce you to them and our, and our guest for today. First of all, is John in Gates? Did I get that right?
John In Gates? Close enough in Gates? Yep.
Yes, sir. Okay. John, introduce yourself to the audience.
Yeah, so I'm John. Uh, I am field CTO at CloudFlare. I've been here for about three years, and my background has been in cloud computing and infrastructure and data centers for many years.
I was, I got to know CloudFlare back in the early days when they were working with us at Rackspace. I was CTO over at Rackspace. And, um, just saw the power of the CloudFlare platform firsthand for a lot of our customers.
It was sort of like this magic capability that when you put it in front of their sites, it, like you were saying, it made things more reliable, more protected. And, um, you know, many, many years later, I come back around after the pandemic and I see what cloudflare's up to, and I just really get excited about it. And so I joined the company, like I said, about three years ago.
And in my role as a field CTO, I spent a lot of time doing events and conferences and customer engagements, and even panels like this. So I'm pleased to be here. I'm, I'm happy to be a part of this, uh, conversation.
And I hope we have a great series with you on, on, uh, on, on this topic at hand. Well, if we have you on a lot, it will be, it's funny, my background's in the hosting business too, right? com days.
Uh, we were first a, a host and then became an a SP and mm-hmm. Uh, application service provider. This was before there was a cloud, of course, right?
Of course. It was whole, it was a whole different game with Enron, conductivity, ob beer. Someday we could talk about it.
But John, thanks for joining us. Also joining us is my partner and the compadre. He's worked with me.
We've worked together for about 25 years now, actually. Uh, he's our CTO here at Techstrong, as well as CTA at RUM Research, uh, chief Technology Advisor there, my friend Mitchell Ashley. Hey, Mitchell, welcome.
Always love this topic. I'm so excited. Cloud transformation, and, and I'm convinced I'm not gonna have to pull any fiber or ethernet cable.
This will be the best transformation ever. Yay. Yeah.
We, we just had this conversation the other day about Interlochen, right? And all the dark fiber that level three, and back to your Rackspace, Rackspace days, John, right? Remember, there was a time where, where are we gonna do it?
All this data center capacity. Well, guess what? We don't have a lot of data center excess capacity these days.
You know, it seems that, uh, people are looking to move to the edge. And, and that's the kind of the kinds of stuff we're gonna be talking about, you know, for 20 years, 20 2005, about cloud first burst on the scene. And, and we've gone through, as I said, in the opening, several transformation errors of what it means to move to the cloud.
You know, first it was, let's face it, first it was lift and shift, right? You, it was our friend Rich Mobile would call it cloud washing. We would take what we had in the data center at a rack search, so throw it up into a private cloud public.
It was just really AWS is the public cloud deck. And voila, you're a, you're a cloud, right? You're in the cloud.
Tell grandma how pictures are in the cloud. I guess that was a cloud transformation, right? Um, but early, early on, we recognized that networking and security, you, you couldn't cloud wash those that easily.
It just didn't translate. It didn't. That's right.
That's right. Like a, it was a dud. And, and so we've had to sometimes do unnatural acts even right?
To, to kind of fit five pounds or 10 pounds into a five pound bag, and, and, you know, different form factors and different ways of thinking it. Um, but nevertheless, right? Time marches aren't right.
Progress weights for nomad. And, and we've seen people being very innovative in, in their transformation. But like every technology evolution revolution, there comes a point where you of diminishing returns.
We've gotta try something. We've reached, you know, what we can do here in a reasonable way without really doing unnatural acts. I feel like we've come to that border again, we've come to that church, that boundary, if you will, that boundary layer where, look, the rules have changed.
The game is changing, and we need, we need new rules, new games, right? We, we need to think about it differently. John Cloudflare's a leader out here, right?
It used to be you just were a CDN, but you've gone way there. CloudFlare is way, way beyond just CDN today, right? That's true.
What do you, what do you think? What do you think? Well, I had a lot of thoughts as you were talking there.
I couldn't, I'm Sorry, but, uh, no, I, I, I couldn't help. But, uh, think back to the word cloud. And you know, you said pre-cloud, you know, you were an a SP, you were building applications that were delivered over the internet.
It wasn't called the cloud then. It wasn't even called cloud when I was working hard at Rackspace, building websites and, you know, building up scale or company companies that, uh, that needed that sort of level of infrastructure. But the term cloud, if we trace it all the way back, it really goes back to how we used to represent networks on a, on a whiteboard.
You know, we used to draw a picture of a cloud, and that was kind of the internet. And the internet was represented that way because it was this sort of great unknown, right? We didn't know how it worked and how packets went from point A to point B.
We just knew we connected into one side, and the destination was the other side, right? And in the, in the middle, we had this nebulous thing. And so that's where that term cloud came from, right?
And so, as we think about cloud computing, we moved applications. They kind of went first, right? So that was your, uh, earliest days of the a SP business.
Um, then Amazon had that great idea of, of, uh, building out infrastructure services. So compute cloud, storage, cloud, maybe database, cloud, all these other capabilities. Then the, the software as a service vendors came into the picture and started using those tools to build out their own software and deliver it as a cloud service.
But if you go back to that original, uh, problem, the network, right? The network was never made cloudy, right? It was never cloudified.
I don't know what the right term is, but it was never taken to the cloud in the same way that some of those other services were. And that's for a variety of reasons. I mean, we can talk through that if you want to, but it's just, that's really where we are headed as a company at CloudFlare, is bringing the network and the security, because the security was also a disjointed element of this.
I mean, there have been attempts to bring, uh, cloud type, um, uh, architecture to the network, but sometimes they were missing pieces like security. And so when we bring all of that together, and we add in services that developers might use, we bring, you know, sort of, um, serverless compute or edge compute plus AI at the edge, those kinds of things start to transform into something completely different than what we have ever seen before, uh, when we, when we think about networks. And so that's really, I think, what, uh, I, uh, I guess the foundational thought behind a connectivity cloud is solving for all of those kinds of challenges.
Now, John, as I think about you just listening to both of you and Alan, you know, back in the day building networks, I thought about building networks, right? Instead of building clouds, it was all about, good analogy might be an erector set. Here's the pieces.
You know, can I be A to B and B2C and C to C, you know, where's it all going? And I don't have a great path to get here. So let me fill that in with another provider.
Let me put in my network here. Let me figure out what security boxes I need to install. What, then what do I do about my providers that I'm connecting to?
It was a, a real construction project, as I kind of think about it. And today, what, what you're describing is, it's not just where you need to connect to and who you need to connect to. You're, that's kind of assumed, right?
You're building a cloud, but it's also capabilities in the cloud, right? Whether it's application protection or APIs or it's bot protection that you're preventing. Maybe you're, you're looking at how do we, uh, block ourselves from the owas top 10 there?
There's all these different elements. And, and now even developers, they're programming to the cloud, right? It's not this network thing sitting in the background that just connects us all together, Right?
And, and look, we need really the idea of, of not just connecting point A and point B, like I said before. I mean, we need any, to any connectivity. We need to connect users and applications and devices, and I, uh, AI services, which usually are delivered via APIs.
We need all of that to be connected and secured and made private and made reliable and made programmable. Because we can't wait anymore for somebody to go rack and stack a piece of hardware in a data center like we used to do. We, that's just, you know, far, uh, too slow, right?
For, for the modern era, we need that flexibility to be able to program that just like we would other cloud services. And because of the fact that everything is going to expect an API, we're gonna need to have the responsiveness of an API and be able to bring things up and down, uh, you know, at, at a, at a moment's notice. And then again, the security, we can't leave that behind because security threats are everywhere.
They're constant. They're an ever present risk to anything that we want to do on, on top of the internet or on even on private networks. And so we need to be able to get some threat intel, some network intelligence.
So we need to make sure that that's, um, integrated and unified and tightly, uh, connected with all the other capabilities. You know, what I find fascinating though, guys, for all of the success we've had in previous cloud migrations, cloud trans transforming cloud transformations, there's always this sort of, there's always this sort of thing of, well, you know what, a majority of workload's still not on the cloud. We still have a ton of private data centers.
It's not secure enough. The network's not fast enough. We, we we're moving everything there.
I need stuff to work on my phone. I need stuff to work at the edge. I need, I need, I need, I need is what it comes down to, right?
People always give them an edge, take a foot. They always want more. And it, and so there's this feeling of, to realize the full potential of the cloud, we need something else.
We need something more. We need this next great. Or maybe it's the last great transformation.
And, and we're also, you know, you can't mention any of this without talking about AI today as well, right? AI is a game changing. Do we need LLMs on the edge?
Do we need AI on our end devices? And does that have to talk to the AI back at the core? And that's gonna take a network and security, right?
It, you can't make wine before it's time, but now is the time to do this. Great last great transformation. That kind of a grand unification, if you will, bringing them all together.
CloudFlare is calling this the connectivity cloud. We've heard this term not knocked around. Mm-hmm.
The connectivity cloud, this last great cloud transformation. John, I know you can talk about what it is, but Mitchell, I'm interested first from you, what you think about it. And then let's let John tell us what the real thought on it is.
Yeah. We'll get, we'll get it from the real authority. Yeah.
You know, you know, it, it's interesting. It seems like living in a network or world environment up to this point, it's always been about kind of building the highway where traffic needs to go, how it needs to get there, how fast it needs to get there, the latency speeds, layering, layering on security on top of that. And we're in an era now where the business doesn't really care about that.
Matter of fact, they don't want to hear from us about, oh, we can't go there 'cause we, we have to order equipment, and that's gotta show up on site. We have to have somebody to go there and put that together for us, or we need to work with this provider. All of those kind of things seems the last, last great transformation is about anything, anywhere.
And it is a network of networks and a software environment that we're delivering this all across. And it's powered by software, it's fueled by software, meaning those are the capabilities that we can access through APIs or through services that come through a cloud flare, or the connectivity that's going between Cloud flare, my other providers that are part of this complex, uh, array of networks. Because you know what?
We just acquired a new company and now I've got a different topology than I had five minutes ago. I can't take six months to fold that in. I've gotta operate it tomorrow, and I have to respond quickly to what's going on in the business.
So for me, and I'll let you John, kind of describe more the meat of it, but the environment of what we need has changed drastically. And the expectations of us to deliver that have changed drastically as well. Yeah, for sure.
And you know, you, you guys have been talking about this and, and we, we've been talking about it as well as the last great cloud transformation. I'll say that again just because I twisted my words last great cloud transformation, and I use that term or that phrase the other day. And somebody asked me, why do you call it that?
And I said to them, well, it's not last in the sense of least important, like the last, but not least, you know, that sort of last, it was just in order of what has been transformed, it seems to have been put off to the end, right? And in some ways it should have been brought to the beginning. If you're going to move things out of your data center into somebody else's data center, you said the word highway, you better have a good highway to get to that destination.
You better have something that connects you. But we didn't build that first. We built that later, right?
And we've had to do sort of magic tricks to, to continue to make it work with VPNs and tunnels and cross connects inside of colos and all kinds of, you know, um, unnatural acts to get, to get to the point where we can actually get to those applications reliably. And as we saw during the pandemic, a lot of companies fell on their face when they put everybody in a work from home or a, a work from remote kind of environment because they didn't have that connectivity in place. They were still routing traffic through those racks and stacks of equipment.
And that just didn't make sense. So now I think people have woken up to the fact that there is so much going on. There's a need to start to think about the infrastructure that connects and protects and, and makes everything work together well.
And I think that's why we're finally seeing some movement. Also, the technology has evolved, frankly. You know, there were, there were things that were holding us back, um, just even, uh, enterprise, you know, enterprises themselves and the politics and the people inside of those organizations.
Sometimes they wanted to hold onto the gear, right? There are people that loved the whole, um, idea of logging into a network switch and configuring it and being the smartest person in the room when it came to doing that. And even that is starting to fall away.
Those people recognize even the, the most, uh, ardent of the, uh, the, the server huggers or the network device huggers or whatever you call them, have figured out that they, they need to elevate their game. They need to start to program these devices to be more agile. They need to take advantage of, of sort of the, the same concepts of DevOps and do sort of net DevOps, if you will.
Uh, and, and DevOps. Yep. So basically taking that approach and, um, and, and you know, that it's not new, but there are still companies that are stuck in, in what I'd say are the dark ages, right?
And so, uh, we're, we're recognizing that there's a better way and, uh, and companies are embracing that today. And it's for a variety of reasons. You know, sometimes it's to enable new applications like we're talking about with AI and, and, uh, new services like that.
Sometimes it's for compliance reasons. They need to, uh, be in a lot of different countries. And every one of those countries has a different patchwork of regulation and compliance.
And the way you encrypt data, where you encrypt data, how you, uh, you know, move your security keys around. All that stuff's very complicated, right? And, and the, uh, the, the, the, you know, I mentioned the VPN, the VPN really laid bare the, the problems of, you know, having one or two or three different places where you're onboarding users into your, into your cloud, uh, network.
It just doesn't work at the, at the way that world is, is moving around. I've, you know, been traveling, uh, I see people working from home and, and different places all around the country. You have to have infrastructure that supports that end of it, as well as the, uh, sort of what lives in the data center and, and, and the cloud side of things as well.
You know, once we moved to the, to the cloud like that, the whole idea of making your network relying on like VPNs. So think about this. I work from anywhere, I do everything from anywhere, anything, anywhere.
But in order to do anything, I'm going to VPN back into my homeland, which then goes back out to the cloud, and then I take information down from that cloud back to my homeland, then back out over the VPN to where, anywhere where I am. Well, that's not anything from anywhere. That's just waste, right?
A lot of, lot of round trips on the, on the network, right? Lot Of latency. A lot of latency.
Yep. And, and so just look, anyone who's still doing that at this day in age, I, I, I feel sorry if I pity, but I pity the fool to quote Mr. T.
But anyway, um, but it goes back to something I said earlier though too, is that you can't make wine before it's time. We couldn't have this level of secure cloud networking, cloud ops, dev cloud ops, or DevNet ops, or whatever you want to call it. It's people processing technology.
A the technology wasn't in place. People were still hugging their being the idea of being in their own data center or in their own closet down the hall too much, right? Excuse me.
And we didn't have the processes to, to, to think of it even now, right? We, we talk about having stuff on the edge, like, so I, I just got my head around that, you know, maybe that big honking AWS or whoever data center has some good security and there's an awful lot of connectivity into it, but now you want me to move my data to the edge, right? And, and what's the connectivity there?
What's the network like there? How secure is that? Again, that's why we need this connectivity cloud idea.
Mm-hmm. Right? That, that handles this connectivity in a secure, fast modern man, or running T three lines isn't, that's not cool no more, right?
There was a time, John, I'm sure when you were Rackspace, I remember T three lines 45 megabits a second. 5, no, If T 30 was 45, 5 45, right? You know, and Mike, God, who's gonna need that much bandwidth?
Well, that don't cut it, right? You not in today's world. And it, and it wasn't secure then.
So as we dive into this subject over the next weeks and months, I wanna talk really what is involved in securing, you know, what does security in the connectivity cloud era mean? Yeah. What is connectivity in a connectivity cloud error, right?
That's important to us. Yeah. Well, let's talk about connectivity first, and then we'll talk about the security later.
Um, the connectivity, you know, with cloud, um, it's been the internet the whole time, right? The internet has been the predominant way that most users access their cloud applications when they're roaming, right? It maybe if they're in the office, they're not using the internet, but when they're anywhere else, by definition, if you're in a coffee shop or you're at home or somewhere else, you're using the internet.
So the internet is the foundational underpinning of all this. Um, the problem though is that the internet was never designed for all of this. It's never been a enterprise network.
It's never had, um, you know, sort of SLAs around performance or latency. Your upstream ISP makes decisions that are in their best interest, not your best interest. Uh, you know, you have a patchwork of different ISPs with all kinds of different technologies.
It's kind of lucky, this whole thing, you know, it's amazing. This whole thing works, right? The internet is just this amazing thing that, uh, has evolved in, in so many amazing ways over the years to work like it does, but yet it was never designed for what we're using it for.
It never had security. If you look back at the earliest RFCs of the internet, there was no real, uh, plan for security. It was kinda like, yeah, it's, you know, put it on the wire and, and let it go and, and, uh, hope for the best.
So we had to over time, layer in encryption and, and sort of more reliability into the, into the mix to make these things, um, you know, sort of ready for the applications that we were throwing at them. And I think we're continuing to evolve what that, what that means. I mean, today people jump on a Zoom call like we're on, and they expect perfection or they want perfection.
Um, they, they oftentimes don't get it because of the unpredictability of what's in between them and the other end of that, uh, connection. So that's what we aim to fix in terms of connectivity is put, um, you know, sort of edge locations. We have like 330 different cities where we have edge computing infrastructure.
CloudFlare runs that. It's not in somebody else's cloud. It is our cloud, and it exists all over the world.
And every one of those locations is an on-ramp to the CloudFlare network. And in between those edge locations is a fiber backbone that we've built, um, over time. Some of it's, um, interconnects between, uh, you know, telcos and CloudFlare via peering arrangements, but other pieces of it, the really core important pieces are, are fiber that, that CloudFlare has, uh, built out over time with, uh, with the help of other, you know, the providers that fiber providers, all fiber providers.
So we, uh, take that network and then improve the performance for our customers and for the data flowing across, we can be more, um, you know, active in terms of directing how traffic flows, and we can make decisions that ISPs don't either know to know to make or, or can't make. And then the next question is, once you have that, um, connectivity sort of improved using Cloudflare's Edge as, and, and, and the, uh, the technology we use in between, then it's about security, right? And so we want to make sure that we're encrypting that traffic as soon as we possibly can near the edge, or we're, uh, applying a security policy near the end user so that they're not having to traverse the entire internet only to get to some data center where the firewalls or the zero trust platform exists, and then the security gets applied.
We do that right out at the edge at all of our Edge locations. And so we wanna be able to connect users and devices and applications and anything that, anything anywhere, right? And, and those, uh, are, are increasingly, um, you know, just an array of things that, that are unpredictable because it's evolving constantly.
You know, John, I think that that whole idea of redefining what connecting or connectivity is, I, I would submit to you that connectivity is the killer app. I mean, we used to talk about the killer app is the thing that's gonna really demonstrate what this, what this new technology can do. And, and connectivity, it's about connecting everything, right?
Whether it's your IO OT device at home, it's your commercial IOT device. It's a, we're opening a new store, we want to do a, um, you know, a a a quick popup business here, and I've got 5G, but I need to get that where I'm, where my business and my customers are. Um, it, it's connecting anything, whether it's an application through APIs, it's a new functional capability.
It's a partner I need to connect. It's, um, an app that I'm building or maybe, uh, through a relationship now that I can combine what we offer and another organization can offer. Like you're talking about with the, with the provider network that you connect with it, it is that connectivity.
And then how do you lower the barrier to entry to be able to do that? Because if it's hard, it's gonna take a long time. I, even if it's, if it's complex, it's gonna take a long time.
If you can simplify it, which is all, a lot of it is our great protocols that, you know, bounded and built a lot of the network Ts, BIP, et cetera. Um, but it seems to me that's what we really, when you say anything to anything anywhere, it's that connectivity killer app, right? Yeah.
You just mentioned something that's one of the, the most, um, common, uh, you know, I guess one of the most common problems we're trying to solve for customers is, is how do we bring up, um, new branch offices or how do we make, uh, new locations around the world productive more quickly? And, you know, if, if you can imagine a network that's no longer tied to a collection of physical boxes that need to be shipped out to a remote site, like there's no more, you know, uh, the, the Hub and spoke, Right? Right.
There's no, that was, Yeah. It'll be a Cisco 2300 showing up at your side Yeah. Winning, whatever that, right?
I mean, the, the last job I had just prior to, to CloudFlare was building out these giant SD WAN networks for the large enterprises. And there we were having the SD WAN boxes shipped to our headquarters to configure them only to turn around and ship them back out via FedEx to the remote site so that they could plug it in. And, you know, I know that's not how that was supposed to, to evolve, but that's what was happening for a lot of big companies.
Um, they couldn't, they couldn't do it any other way. And that doesn't make sense in the world where you're trying to be more dynamic and, and, uh, you know, respond to the demand that's happening all around you and, uh, be more nimble and agile and, and take advantage of all the, the modern technology. Um, and, you know, the other problem we solve is the VPN, right?
The, the modernizing, the VPN via zero trust and SS e and using those edge compute sites as on-ramps into that SS e network that is a, a very different security architecture than what's, you know, come before. And that is so much more efficient, so much more powerful, uh, and more dynamic, um, than, than, you know, sort of the alternatives. It's just hard to resist it once you sort of understand what it can mean.
And, and for a small company, it absolutely makes sense because you would never go and buy all that equipment and build out a data center. Um, you'd, you'd use the cloud, right? And that is where most companies that are, you know, getting started would, would start.
But now big companies are recognizing that it just doesn't make sense to try to manage sort of building out your own connectivity cloud. 'cause that's what people were doing. They were piecing together their own small version of CloudFlare by having two or three or four VPN sites around the world where they were building out their own zero trust network by partnering with one of the other zero trust vendors and hoping that their cloud locations made sense for, for the business.
And, you know, trying to stitch those two different vendors together and have the logs coming outta different ones, that was a connectivity cloud, but it was a homegrown one. It was one that, that people were sort of building up themselves. What we're trying to present is a unified vision for what this can mean at global scale, what it can mean when it works well together, when it comes out of the box with functionality that is already proven.
I mean, we use it ourselves, we use it. This was, this was born out of the need for CloudFlare to protect its own employees from the threats that we face every day, which are massive in scale and very sophisticated. And so, you know, it's, it, it came from there, but it is now operating out in, in the, in the, uh, in some of the largest enterprises.
Some of the largest, um, you know, companies out there in the world are using this technology and it works. And, and there's nothing more to say, but once you sort of get a taste of this, it, it's just irresistible because nobody wants to go back to that old world of buying and racking and building Lego bricks to get your network up and running. It just, it doesn't work for the modern era.
No, but you know what? You mentioned something, and I want to end on that. In order to do this and to do it well, you need a certain scale that very few organizations can bring to, to the problem, right?
Sean, I don't know if you know off the top of your head, but I remember at one time something like 21 or 26% of all the internet traffic traveled over CloudFlare. Roughly 20% of websites are behind CloudFlare. And we protect, we protect those websites from the, the, the attacks.
Yeah. Right? So you can't, you could try building your own connectivity cloud and God bless you for doing so, but if you don't have that kind of scale, this, this is, you know, this is something that just almost by very nature requires that scale.
You want to get good security, you wanna have good connectivity, you want to continue to build and protect and deploy. You need that kind of scale. Guys, I think we've gotten this off to a terrific start.
We're gonna dive deep on all of these little nooks and crannies we've hit on here, but we can, we can't do it all in one show. John, thank you so much for coming on here and, and kicking this off with us. You've got an open invitation anytime you wanna come back on, you know, we'd love to have you here.
Uh, well, thanks for having me. You come down here to Boker and do it in person with us too. Mitchell, as always, it's great to have you on, most of all for you folks watching this out there.
Thank you so much for sitting in on the inaugural, uh, premier edition of our next greatest series, the Last Great Cloud Transformation, and, um, stay tuned 'cause there's a lot more coming. Many thanks to CloudFlare for sponsoring and co-producing with us. This thanks to Jody Ashley, you producing, uh, doing the behind the scenes production work that makes this possible.
Until next time, this is Alan Shiel. We're out. This is Textron tv.
Hey guys, thanks for the throw. We're here with Matthew Gold, who has a lot of experience working on cybersecurity issues in England, and particularly the National Health Service. And if you've been following things lately, well, the National Health Service in England is under a steady stream of cyber attacks.
And we're gonna get into what can we learn from this and maybe what should we be doing elsewhere in healthcare organizations? 'cause there's probably more of this to come. Matthew, welcome to the show.
Thank you very much for having me, Mike. Alright, for those that don't know you and are not familiar with what's going on, kinda lay the land here for us, but, um, we've seen this wave of attacks and I think it's becoming a pattern. Yeah.
Um, so look, I, um, for, for several years I was the chief executive of what's called NHSX, which was the, the body in the NHS tasked with digital transformation. But I also, um, carried or owned the, the cyber risk for the National Health Service. So, um, I spent a lot of my time and, uh, my sleepless nights thinking about, um, how, uh, the, the levels of vulnerability, uh, to cyber attack and what we could be doing about them, and particularly how we could ensure that, um, cybersecurity wasn't a, uh, a vector to undermine public confidence in the, the sort of information sharing that we need to happen.
Uh, if we are going to deliver maximally efficient, effective public services, It seems like we have a little control over the attackers, so they're gonna just do what they're gonna do. So what should organizations like the NH Ls be doing to kind of make their environments more resilient to these attacks so that we don't lose that confidence? So look, I think you're right.
The first thing is these attacks are not going to go away. They're clearly a fact of life, and any large organization, particularly, uh, organizations with a a, a pretty serious attack surface can expect to be, um, constantly bombarded and attacked. Uh, and so the question is not how do you make yourself hermetically secure, but what can you do to mitigate any damage to make sure that your crown jewels are properly protected and that the, the confidence that you need in your users and customers to, to underpin the system is preserved despite the, the, the wider security environment.
And I think it comes down to several things. I mean, first of all, and this is just the sort of inescapable fact of life for everyone online, is there are certain key basic things that everyone should be doing in terms of good cyber hygiene, in terms of best practice, in terms of making sure, for example, that, um, you are controlling your accesses, making sure that the, the really basic elements are in place that you don't have an open door for attackers. And in the UK there's a program called Cyber Essentials, uh, which is a government backed program, uh, supported by the National Cybersecurity Center.
Um, that is really, uh, an accreditation that you are doing those basic things, right? I think secondly, you need, uh, to create cultures of secure practice where people understand why it's important they don't, for example, click on the link that looks a bit weird, um, and potentially open up a, um, a hazard for the wider organization by doing so. But then there's a third element, which I think is really important in healthcare, which is to be really careful with people's personal health data.
Because if you are a patient of the NHS, if you're a patient of any hospital, you are really sensitive to the idea that people who aren't authorized or people with malign intent might have access to your health data, like financial data, it's something people are really, uh, have a really low threshold of tolerance for, um, misuse or, um, it, it, it going astray. So I think particularly when you get to, um, looking at sharing health data, health health data across different health entities between, um, health and other sectors, you need to have in place really strong, um, technologies, structures, uh, systems and culture to make sure that when you do that data sharing, it's done, it can be done in a way that gives confidence to the people whose data it is. Did we kind of fall into a trap where somehow or other organizations seem to think that the data they collect is theirs, when in actuality they're kind of stewards for data that actually belongs to somebody else?
And we have to have a different mindset when we think about it in those terms because suddenly it's a trust and it's a responsibility versus something that I'm just trying to protect. And we're the only ones that are affected if something goes wrong. Yeah.
So, um, I mean, well, interestingly, the UK still follows the basic, uh, GDPR EU model, which doesn't have a concept of data ownership. It has a concept of data controllership, uh, which is in the UK health system, uh, primarily the, the general practice doctors, the the family doctors in primary care. Um, but despite that, the reality is that people feel they own their own health data, they feel strong sense of, um, uh, rightful authority over it, and will react very badly if they feel that their data is being in any way treated with carelessness or, um, proper security.
And one of the things we find over and over in the UK is well-intentioned schemes to share data are, um, crash on the rocks of concern by people about their, their own privacy. So if we, we are, I'm really clear they've done the jobs, I've done that. If we want to deliver effective health services, effective public services, you need to be able to share data safely and appropriately.
We need to be able to share it between primary care and secondary care. You need to be able to share it between, um, health and social care, for example. Um, but you can't do that if you don't do it in a way which keeps public trust with you.
So I think it starts, we started with cyber security, but actually it comes down to how do we do data sharing that will allow us to offer really good, effective, efficient services in a way that keeps public trust. This is, this is existential as far as I can see for delivering effective health services. Is the conversation among cyber security teams starting to change where you hear a lot more about the phrase, you know, cyber resiliency, um, what does that exactly mean though?
I mean, am I trying to just limit The, The scope of an attack? Or am I trying to prevent an attack? Well, I think resilience comes down to, to some degree, to all of that.
But I think it starts from the basis that you can't, uh, deliver efficient, in this case, efficient health services without being, while being a sort of hermetically sealed fortress for data, which means in turn that there will always be an element of, um, risk of attack. And therefore it's not just about sealing yourself off from the world. It's about ensuring that were the worst to happen as far as possible.
The things that most needed to be protected have maximum levels of protection and the things that are, um, most need to be able, the services that most can need to be able to continue to be offered, for example, um, emergency care can still function. Um, so cyber resilience is an incredibly important concept in healthcare. Um, and really, I mean, that's why, I mean, some of my continuing involvement in this space is looking at technology which can allow data sharing or, um, the use of data, particularly across different institutions with the level of confidence that's needed.
So I'm working with a, a, a US startup called, uh, duality Technologies who developed, I, I mean really strong trustworthy techniques including, um, uh, homomorphic encryption to allow, um, data to be interrogated safely, but in a federated way. And that's the sort of technology I think that can give confidence to be able to share data that keeps the public with you. We, of course, are all tracking the rise of ai.
What impact do you think this is gonna have? Because it seems like we're in some sort of arms race here. The good guys are clearly gonna use ai, but so are the bad guys and is that gonna change the nature of the threats that we face?
Uh, uh, we are always in an arms race. I mean, I think cybersecurity has been an arms race from the start. Um, and I think AI turbocharges that, I don't know, I suspect it will create both opportunities for attack and opportunities for defense in ways we haven't even thought about yet.
It will speed everything up. Um, it will, um, certainly I think for those, for the unprepared will present, um, uh, a serious new angle or depth of threat. But, um, it fundamentally doesn't change what's needed, which is good cyber practice, effective defense, but also the ability to share data across institutions with real confidence based on the technology that underpins it.
Do you think we need some sort of, particularly in the healthcare space, maybe something that feels like a, a Manhattan project for improving cybersecurity? Because it is, touches everybody. It is such a broad thing and that the data that is in those systems is probably more valuable than even what's in my banking system.
So, you know, what do we collectively all need to do together that's gonna be different? So it's a really good question, and I think like financial data, health data is incredibly important to the people whose data it is. Unlike the financial sector, which is invested huge amounts into cybersecurity, the health sector is always cash strapped.
And, um, I would say certainly in the UK hasn't had the level of investment that the financial sector has had. So, um, and then on top of that, and I don't know if it's the same in the US but certainly in the uk you have real issues around a multiplicity of legacy systems, data sharing across numerous systems, both within and between institutions, all of which makes the problem much more complex. So what can we do differently?
I mean, firstly, there is an irreducible amount of investment that's required to do this properly. Um, secondly, um, I've always been, um, a fan of the approach where the good guys work together to share what they know and create a, as far as possible, a sort of common approach to, uh, to the threat. And it's one of the reasons why, um, we set up the National Cybersecurity Center in the uk was to allow a sort of safe pooling of what people know, um, but together with, with, with governments and the agencies.
And then the third thing is, and it does come back to data sharing, it's finding ways and technologies to allow data to be shared between healthcare institutions with confidence. Because until you can do that, you are never going to be able to deliver the services that are needed. In the absence of all that though, what's your best advice to the average cybersecurity IT team working in the healthcare sector?
It's really good. It's a really good question. I mean, I think number one, um, they need to be friends with their board and boards need to be on top of the cyber risk.
Um, if a board isn't asking questions, interrogating cyber resilience and key indicators around cybersecurity, they're not doing their job. I think number two, and it's the same theme of senior leadership, is making sure that they translate the threat from the technical to language that their chief executives and C-Suite leadership understand. Because I think one of the continuing issues around cybersecurity has been, it's seen as an issue for the IT guys in the basement when it has to be an issue for leadership.
I think the third thing is just grind through the basics. Make sure that the checklist of things that are needed in the UK cyber essential scheme is constantly met and remet. And that's a never ending task.
Uh, it sounds straight forward, it's not, it's not glamorous, it's not sexy, but it'll, it, it is the foundation of cyber defense. And then finally, um, and this is where I think it starts to be a bit more interesting, is look at what technology can allow you to deliver the services that are needed. Um, how can you share data with the confidence that needed that's needed based on technological solutions that to prove be secure?
All right, folks, you heard it here. I think we all know the bad guys are not going away anytime soon. The only question is, is how are we gonna respond to it?
Hey, Matthew, thanks for being on the show. It's been a real pleasure talking to you. Thanks, Mike.
All right, and back to you guys in the studio. Discover Techron group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients, let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Welcome back to Textron Unplugged. My name is Cassandra Chin, and today we're here with Grace Francisco.
Hello. Can you introduce yourself? Sure.
I'm Grace Francisco. I'm originally from San Francisco. I did work for a company called Cisco for a little while as well.
Um, I am now working as an advisor to a number of different startups. Uh, I have my own advisor from called MTY, and I am also, uh, spending time thinking about my own startup, but mostly working on, uh, helping to coach and mentor other startups. Right now I I've had a long career in tech.
Um, so I've worked at companies like Microsoft, Atlassian, MongoDB, Cisco Roblox. Um, so I've had a, a very long 20 plus year career mostly working with developers. I did start my career off as a software developer myself though.
Um, and you know, I started my career not knowing what I wanted to do. I went to school, I knew I was good at math, and I thought originally, well, I'll go be an accountant. And I found out what accountants actually did.
I decided that was a really, really bad idea. Um, but because I had to work my way through college, um, I had the sort of lucky accident working for a software startup that was in San Francisco, and that's where I got to observe other software developers. And that's when I had that aha moment of I wanna be a software developer.
So that's where I started my career originally, but I've now had a long career as a leader. It was called developer relations, or developer ecosystems and leading teams to help drive adoption of developer tools or platforms. You said you've worked for a lot of companies before.
Is that all as a software developer or No. Most, most of the companies I've worked with in the last 12 plus years have been companies where I led initiatives to drive adoption. So I was a, uh, developer what's called a developer relations leader and executive and running developer programs to drive adoption and education of technologies and tools.
Can you tell me more about what you mean, like adoption of education, adoption of tools is really getting developers excited and interested about whatever platform or tool that you're representing at that time? So, you know, at MongoDB it was their, their data platform. At Atlassian, it was Jaron Confluence platform.
At Roblox, it was the gaming platform that developers would build on. So depending on the context, and so understanding the different types of developers and their needs is really important key to understanding how to get them excited and engaged and how to educate them properly. Like how did you go from being a software developer to like, uh, guiding other developers?
That was accidental. And I, part of it was that I had spent a bunch of my software development curve working long hours coding. Um, I, one of the startups that I worked at, I was starting my day at 6:00 AM and ending at 11 o'clock at night.
Many days, not every day, but a lot of days I was doing very long days so much that I was having three, um, triple shot espressos a day. And then that made me very jittery, so much so that if I went around the corner, somebody was coming around that corner at the same time, I would be on the ceiling because I was just so, um, jittery from all the caffeine in that timeframe. I observed other people in the company who were technical but weren't coding.
They weren't at the office all the time. They were going out and about and meeting customers, going to conferences and doing demos, demonstrations of the product. And I thought, well, I could do that.
And they got to go travel the world and go meet customers and not just stay at their terminal coding away. And that's where I started develop an interest in exploring other avenues of leveraging my technical skills. Um, and so that's, that, that was the sort of path that I took.
It's first started in what's called technical marketing and helping the marketing team and another startup to craft their content and their samples and demos to be used as part of their marketing campaigns. And then shortly thereafter, I ended up becoming a sales engineer for a little bit and understanding how to help the sales, uh, team demonstrate with the technical tools that we were representing. So I was the technical arm of a sales pitch and I was able to translate that really easily when I went to Microsoft as a a developer evangelist.
There weren't that many developer evangelists back then back in the early two thousands. And so I got to learn the craft of evangelism at one of the places where developer advocacy or evangelism was born out of. Uh, so that's where I started my career in developer relations and ecosystems.
It's interesting how like your coding skills can translate to that many diverse, diverse jobs. Absolutely. If you don't talk about that at school, I even today, not, not much.
I mean, they teach you the academic portions of coding and algorithms, um, and then they're teaching like really deep, uh, technical topics, but they don't really help you carve that path to the different kinds of roles you can have. There's always this, essentially you're gonna go and just be an engineer, but you can go be a sales engineer, you can go be a technical marketing person, you could be a technical writer. There are lots and lots of other opportunities now where if you don't necessarily wanna be coding all the time, you could be doing some coding and teaching.
You could be doing some coding and demoing. You could be doing some coding. And just as so many, so much variety that we don't talk about in school.
I'm currently a computer science student and I think we're still missing that. Yeah, yeah. That, that, that hopefully will change.
Especially we've got generative AI now, um, generative AI to some degree. I know there's a lot, a little bit of mass panic. And, and I actually had someone recently ask me for their, for their, uh, college bound kid, should he still be studying computer science?
Are there gonna be programmers in the future? And I said, absolutely. They're not going away just because it's generative ai.
That's like saying the, like a decade, more than a decade ago, there was this NA panic in the IT sector where the cloud came about and they thought, oh my God, my job is going away 'cause everything's going in cloud. Well, that wasn't true either. Their, their work was transformed and some of the things they just shifted a bit.
But they were, they're still there, they're still an IT organization. Their responsibilities may have changed a little bit and they had to probably develop other skill sets, but they're still an IT department. And so it's similarly, uh, while during AI is helping, uh, to actually accelerate this, this notion of citizen developer, uh, where anyone can actually build things without being a, a heavy coder that just offloads sort of the mundane things that developers don't wanna do anyway, so they can do the creative, innovative pieces of programming.
Yeah, that definitely makes sense. Yeah, I think a lot of programming once, you know, the basics is all the creative part. Yeah, yeah, exactly.
So, you know, I would say don't be afraid of going into that track just because some people are in this panic that, you know, we're, they're not gonna need programmers. We're always gonna need developers who are thinking creatively and thinking about, you know, how to innovate and not just doing the mundane tasks that maybe some developers are doing today and might get replaced by generative ai. But that only means that that frees you up to do much more creative, more challenging projects that will really help build your, so it's not like, it's not like their jobs are truly going away.
We still need the manpower and man power. Yeah, yeah. Um, aside from just technology, what do you enjoy doing in your spare time?
Um, in my spare time, I'm often in the kitchen. And in the kitchen I am often doing sort of experimental cooking. Uh, sometimes when I don't have time, I'll just walk into my kitchen and I'll take whatever is there to build a quick meal without using a recipe.
So it's like my sort of cooking challenge of the day. And I'll just piece things together and think about like what flavors will go together and how to like, assemble, you know, the meat portion with the vegetables and the, the carbs that are gonna be on the plate. Um, and I find that fun.
I usually will do that while I've got jazz in the background playing. Like, what's a fun hobby to do? So, yeah, I mean I, I find it's, um, a nice way at the end of the day to sort of transition from my work mode.
'cause I work at home, so transition from work mode to like my, my home mode and spending time with my family. Um, and it gives me that sort of showtime that if I were going to an office, it would've been my drive home. I don't have a drive home.
So my transition time is being in the kitchen, creating something new, and listening to my jazz music before I spend time with my family dinner. I also enjoy cooking, but usually I try to follow a recipe, but I might end up not following it along the way. Yeah.
Well, in the beginning when I left home, I didn't know how to cook anything. I mean, I was living on Top Ramen for all, which is very, very bad fear, heart health, by the way. Um, so I eventually learned how to cook some really simple meals.
Um, mostly I was forced to when I had a family, but when you're single and just you, it's kind of hard to want to cook for just yourself. Uh, but I'm, I'm glad I was able to figure out how to make certain recipes and, and even sort of backwards engineer certain, um, dishes that my mother would make or that I would have at a restaurant. So it became like sort of fun challenges for me.
Sort of like, you know, backwards engineer, uh, certain recipes. Yeah, I think that's a lot of fun. And like, going back to technology, like how do you feel as a woman in this career?
Well, it is challenging. I am not gonna, you know, fluff that in any way because it, it has been challenging, but I would not deter any woman from going down this route simply because it's probably one of the most empowering careers that you can have. Technology really is such an enabler in many ways.
For me, when I was coding, it gave me so much, uh, happiness to be able to build something and run it and see it running that I was always really, really happy about. Um, it, it's just that sort creator process of building gives you a sense of empowerment. I think that that's really great.
I think the one thing that I would say to other women who are potentially pursuing this career is to not be afraid. And it can be daunting to walk into a group where you're the only woman on the team, but to, you know, really go in with, with some sense of confidence that you're just as good as anybody else on that team. And in your early part of your career, everyone early in their career is learning still.
And even as you're much more mature and seasoned, nobody knows everything. And so being willing and vulnerable to asking the questions is important to accelerating your learning. The biggest mistake that I made when I was just starting out was to feel like I had to know everything.
So I had to like, learn it on my own. And while I was smart and I learned a lot on my own, I would've learned so much faster if I was willing to be vulnerable and ask the questions. And yes, there are gonna be some jerks on the team that may treat you like you asked a dumb question.
But the reality is, I met so many nice, sincerely helpful engineers that would've also politely answered and helped coach me on whatever the solution was. And, and that's, that's a true issue in any kind of work environment where you're gonna have some jerks, you are gonna have some nice people. Um, but the, the benefit of asking that question is that ability to really accelerate your learning cycle and just continually moving forward and knowing that no one knows everything.
And so, you know, thinking about it through that lens is important because it's not like, especially when you're coming out of college, that anyone is ex, no one should be expecting you to know everything. You're in a learning process. And that is the expectation.
And so people who have been there for a while should have truly an obligation to help coach and mentor. I think I can relate to that. 'cause it feels like we go to college to learn and we, we come out of it.
We have a big degree, so maybe we think we should be experts. No, but actually in the job, we're still learning all the time. Yeah.
I mean, the hands-on experience though is so different from the academic experience. You learn so much in a real world environment, just getting really hands-on, being in the pain points of the development lifecycle and just really understanding what that day-to-day truly is in the real world. It's so different than what you learn in, in an academic environment.
And so it's really applying some of that academic learning into a real world context and then realizing, okay, it's not as black and white as what you learned in school can definitely see the difference there. Yeah. Yeah.
I think we've had a really good talk today, so thank you, grace. Oh, well if, my honor a pleasure to be here. Thank you.
Nice, nice to be here. Hi, um, welcome everyone. We are so glad that you're joined today.
Uh, so we have, uh, the theme of the day's observability, and we have 10 interesting sessions by industry experts lined up. And then we are very thrilled to kick off this series of sessions, uh, on a very critical topic, very crucial topic, which is observability again. So with the first session, what we're trying to do is, um, we are gonna briefly describe what observability is and how, uh, how important it is in the current software industry and, um, um, why it's very crucial to, to stay ahead of failures and keep the systems running smoothly.
So that's what you're trying to cover in this first session. The title of the topic is Signals That Safe Using Metrics to Predict and Prevent Outreach. Um, little bit, a bit about us.
And, um, so, so there is, let me introduce ourself first. I'm Vinod, um, and I'm joined by my colleague and a good friend Santos. So we both are cloud and DevOps engineers.
And, uh, we have a passion for platform engineering. And, uh, we're apart from the technical bits, we are very passionate about, you know, we are very active in the community, uh, in an, in the open, open, SOS and, uh, cloud native space. And, uh, OSH is a season speaker in, um, and yes, shared as insights in multiple international conferences.
And we have been organizing events, advocating, uh, the cloud native best practices and also innovation. So that's bit about us. Um, so I, I'll I'll start off with the same, um, which, which goes like this, so you can't improve what you can't measure.
So this specific saying lies in perfectly with the topic today, which is observability. So we need to measure key metrics like, uh, traces, uh, metrics, uh, traces and logs to gain the visibility that are needed to detect and prevent issues. Uh, so, so that it helps us to understand, um, the problems that might occur.
And you can even prevent issues even before it occurs. So this, this saying goes, uh, very apt with the topic today. Okay.
So straight to the point. What is observability? So we had this traditional monitoring, um, which has served the purpose for so long.
When we had this, um, um, monolithic systems, traditional monitoring was sufficient. So to understand what if, if a fault occurred or if a problem occurred to understand what is a problem, and to diagnose the issue, the traditional monitoring was good. So in monolithic system, what has happened is, like you have the entire applications run in one system, and then all your logs metrics are all at a centralized place.
So to diagnose and to, uh, find out the problem, it was easy. But in the, in the current times, we have more distributed and, um, uh, decentralized and distributed and microservices and serverless, uh, kind of systems, um, more in use. So the traditional monitoring doesn't serve that purpose are currently, so you will have to have an upgrade to the traditional monitoring.
So that is observability. So if I have to give a definition for an observability, it is, it is like an upgrade to the monitoring and, and it understanding the internal state of the system based on the outputs of the system. So you'll have metrics, logs, and uh, traces.
And based on that, you need to understand what's happening in the system. So when you have multiple microservices, they're all interconnected in a complicated way. And, and to understand how the entire system works, you need to have the entire context.
You, you, you can't. So this individual microservice, again, will create its own metrics and others metrics and, um, its own logs and its own traces. So to have a holistic view of the system, you need the entire thing.
So that's observability, uh, for you. So it provides, so again, going back to traditional monitoring, it was wherein you will define some, uh, predefined thresholds like CPU, uh, or memory thresholds. And once it crosses that limit, you will be alerted and you will either do some manual activity or you do some automation.
So that's how traditional amounting used to work. But in the current days, um, observability, um, in a microservices space and distributed kind of, uh, setup, you need something more proactive. Um, and, um, so you need to understand the unknown issues.
You can't always go with a predefined threshold or you need more kind of proactive setup to cover all the bases. So that's observability. And, um, if I go to the next, and, and I think it sort of covered how does it matter?
So, um, if you look at it, um, firstly the increased complexity of the software system. So now we use, uh, microservices, containers, serverless architectures, and, uh, without the complete visibility in the context, it'll be very harder to identify and fix problems. And like in the monolithic, uh, architecture.
And also these systems are very dynamic in nature. So, um, it, it gets autoscale based on the demand and, um, um, it, it moves the workloads between systems all based on the demand and the requirements. So to manage this sort of dynamic environment, you can't have a static monitoring, which is not sufficient.
So that's why observability, uh, is very crucial. And, um, if you look at the other, uh, big reason why it matters more, it's like, it, it of course prevents the downtime. So, um, we know what outages or downtime means, so it, it is lost revenue.
It is, uh, lost trust for, for an application or, or an enterprise. So observability helps you identify the issue proactively and prevent failures. So it, it identifies even, uh, even when in a, a problem request.
So you'll, you'll be ready. So, um, you can typically identify the problem. So, uh, if you look at it, it improves the reliability, right?
So, um, it, it helps in reducing the MTTD, which is mean time to detect. So the pro, the time it takes to detect a problem, or the time it takes to resolve the problem, uh, an outage or an issue has drastically brought down when observed was introduced. So that's why it is, um, it is very crucial in the current times.
So that's about the criticality of the, um, the observ, if you have sort of figured what is observability and why is it crucial. So now onto the, um, uh, the key pillars of observability. So we have, uh, three key pillars in observability, which is metrics, logs, and traces.
And, uh, if I have to briefly tell you what each does, so metrics is like, uh, the numerical data points that represents the state of the system. So for instance, if I give you an analogy, if you're driving a car, you're seeing the speedometer, and that's a metric, right? So the speed at which you're going, so that's a metric, a specific, it's a data point at a specific time.
So similarly in an, in a software system, you'll have metrics like, uh, CPU usage, uh, memory usage, or, um, so similar to that, Eric, it's all, it's, it's a, that's a metric. And then when you come to logs, logs are more like, um, it's, it's, it's a detailed timestamped record of events. So, um, it's like your system events in the system, or if there are any error message in the system that gets locked.
So that's the log, right? So if I, again, give an analogy, uh, think of like a, um, log book for a driver. So if he keeps a log book, and he records when the trip started and when the passenger started with the timestamp, and it's like a log, right?
So you're recording all the information with the detailed timestamp and information. So similarly in it, the software system, you'll have logs that's collected. And then the last one is traces, which is like, um, the com it, it is recording the complete journey of a request as it travels through various components.
We have explained, we have, we sort of, uh, um, pointed that in the recent, in the current systems, we will have microservices and, um, they're interconnected. And a user request might go through different microservices, and it might involve, uh, calls from one microservice to another. There'll be API calls, stuff like that.
So you, you need to have the entire trace. So how, how the entire system, entire request app gone through. And, uh, how does the, uh, the request app, uh, gone from one to another?
So, because this is very crucial in the modern distributed systems, because only if you know, um, uh, how the entire, uh, request have processed through different systems, you'll understand how, how it, uh, worked or where it failed. So there could be a problem where wherein, one, the request has failed and one specific microservice, and if, if we have not proper trace, it'll be very difficult to understand where it failed. So metrics, logs, and traces very important.
That's three key pillars of observability. And if I go to the next slide, um, this is the, um, this is from Google's, um, reference. So Google in their site, reliability engineering, um, says these are the golden signals for observability.
They listed four golden, um, um, signals, as they call. These are telemetry signals, uh, for any user base systems, see any user, uh, um, oh, like, uh, any systems that use being accessed by users like a public open user systems. So they are latency traffic errors, and saturation latency is like the delaying system.
So imagine if you're accessing a website and, um, um, the web webpage is taking time to load. So you need to understand what's the latency. So if you track the latency, you'll understand, uh, where it is being, um, slowed down, and what is the latency time, um, where is the delay query?
And the second one is traffic. That's the number of transaction process per second, which means the amount of load or what is the demand for the system, how loaded the system is. So these also need to be tracked to understand how the system is performing.
And the third one is errors, which is like, um, self-explanatory. So you need to track the number of errors that's being logged against the system. So the percentage of failed request or percentage of operations, for instance, if you see a 4 0 4 RL when you're an accessing website, so that needs to be logged down.
So you, you need to understand what are the different kind of errors that being logged when a user is accessing the application. And the last one is saturation, which means, um, how much capacity is being used So you have a fixed set of resource, and how much of that is being used. Um, so resource when you say like CPUs or memory or, or, or whatever resources that is set up for the application.
So you need to consider what's at what percentage is being used currently. So then you can decide if you have to, um, um, upscale it to meet the demands or if you need to, um, uh, if, if it's sufficient or so that sort of regular analysis. Very important to understand.
So these are the four four, uh, golden signals framework that is suggested by Google now that we saw what is observability and what are all the, uh, you know, key golden signals? And we also looked at the three pillars of observability. Let's take a deep dive into understand like what are the tools that is needed to effectively, you know, monitor a cloud native application.
So before, you know, even actually looking the tools required to monitor a cloud native application, let's take a deep dive into understand why we really need a cloud native observability stack and how it makes difference monitoring a traditional application when it comes to monitoring our observability, and, uh, how it is different for a cloud-based application. So monitoring application in on-prem data center is different from monitoring cloud-based application because it's quite complex to use the same traditional tools. And, uh, tools for monitoring have undergone significant, you know, item shift over past few years.
And the need of observability arises due to unique challenges of distributed architecture. So like vendor specific tools often, you know, struggle to pace up with this rapid speed. And that is one of the, you know, key reasons why, you know, industry or companies are choosing open source tools, uh, when compared to vendor solutions, not just that, that are, you know, pretty much more advantages when it comes to open source.
Uh, one of the major key advantages, cost effectiveness. So it's highly cost effective and it helps you to solve the vendor lock-in situation so you're not, you know, locked into any kind of a vendor. Uh, unlike you're using appropriate tool, uh, uh, think about a scenario where, you know, uh, you're using the tool within your organization for around five to 10 years.
And, uh, you wanted to, you know, transition to a different tool tool, and the whole application would've been, you know, instrumented using the APAs of a vendor tool, or you might be using a vendor specific agent, uh, which will be, you know, pulling up all your, uh, metrics or, which will be exporting all your metrics to the, uh, backend. And it, it, it involves so much amount of, you know, changes in your application and the whole migration to a different monitoring tool. It's a painful job.
So vendor lock situation is one of the key advantage which the open source tools solve. And that is, uh, that is something that we really need to think about it, uh, whenever we are, you know, trying to get into a tech stack and, uh, faster innovation. It's quite, you know, faster to innovate things.
When you have things open source, uh, you, you can easily pitch in, understand what is the code and how it is, you know, being implemented across different companies as it is open source and transparent, and it is customizable. So since it is open source, there are a lot of things like, uh, you know, you'll have multiple, uh, blogs or you'll have multiple success stories and case studies, uh, or, you know, white papers, uh, that has been submitted across, uh, for a particular open source tool, which gives you a lot of confidence in order to adopt the tool and also in order to, you know, understand how the functionality of the, you know, particular tool is, you know, working within the system. And last, but not the least, it is community driven.
When I say community driven, uh, there is against, you know, quite amount of challenges where if you, you know, select a project which is not graduated, uh, when I say, which is not graduated, um, CNCF, uh, uh, is one of the, you know, majorly used open source, uh, foundation. Uh, there are a couple of other, uh, you know, open source foundation, but, uh, most of the cloud native and, uh, you know, predominant tools like Kubernetes, Prometheus, all this come under CNCO Foundation. So they have a couple of, uh, you know, stages when they onboard a project.
So they start with a stage called Sandbox, uh, which is the initial stage where, uh, you know, a project is given an opportunity to, uh, you know, prove themself, try new things, address the solution, uh, for a given problem slowly, uh, once, you know, they make a, uh, you know, remarkable, uh, you know, achievement there in the sandbox layer. It's then the, uh, CNCF community, uh, try to promote that particular project from sandbox to, uh, incubation. And from incubation, it moves towards the, uh, graduation.
The name itself says graduation is the, uh, highest point for any project within CNCF. And Kubernetes is one of the, uh, key project which most of the organizations are using, which is a graduated pro, you know, project. And, uh, eagar is another, uh, you know, tool that we are going to discuss about with, again, a graduated project.
So it, it's necessary for a company, uh, to, you know, understand these stages because, uh, you have to pick the tools based on the adoption rate and, uh, based on how much community support you are getting in terms of that particular project. So that's, that's where I was trying to emphasize more about community driven. So when I say community driven, keep all these points in your mind whenever you are trying to build your, uh, you know, tool stack for your cloud native observability.
So let's discuss some of the widely adopted, you know, open source projects around this absorbability area. So starting with flu D, flu D is, it's kind of, you know, uh, helps you to integrate or unify all of your logging into one place. It helps you to collect and process all your logs, and it, it basically, it helps you to forward your logs in one place, followed by Agar.
Uh, agar is predominantly, you know, famous across the distributed, uh, tracing. When I say distributed tracing, uh, the, the system is so, you know, uh, what, what I would say the system is so much complex nowadays. Uh, unlike a monolithic, it's a distributed architecture where you have, you know, a 50 or sometimes like more than 50 microservices talking to each other.
And it makes, you know, highly challenging for an SRE or for a production support engineer, uh, to debug a particular issue, uh, without any end-to-end tracing. And that's the main area where distributed tracing is solving and is trying to help you to visualize your end-to-end observability using, uh, concepts like tracing. When I, when I say tracing, it involves, uh, multiple other concepts like how to export the trace, what is span, uh, you know, all those things that we discussed about latency.
All those things can be graphically visualized with distributed tracing. So Ger serves this purpose, and if you're looking to build a, you know, robust distributed tracing system, uh, ger is one of the, uh, solution that I would suggest followed by Prometheus. Prometheus is a, you know, go-to monitoring toolkit if you are trying to do a metric based monitoring.
Uh, we, we just saw that, uh, how important is metric and using metric, there are a lot of things that you can be, you know, doing, like, you can be creating a dashboard, or you can be creating a chart. You can create a alert based off the metric. Similarly, if you, if you keep on, you know, uh, expanding your, uh, functionalities around this metric, then, uh, Prometheus is one of the, uh, key tool if you are looking for metric based monitoring.
Last but not least is the open telemetry. I would say Open Telemetry is one of the widely adopted, uh, project, uh, like other open source tools that I mentioned. But this is more of a framework that helps you to standardize your, uh, applications instrumentation.
When I say instrumentation, uh, I think most of the, most of the companies get into vendor lock by using agents. So this is the area where Open Telemetry is trying to solve. So it, it tries to eliminate that agent.
And instead of you using agents, you'll be using open tele telemetry APIs and SDKs, and using, which you'll be exporting the telemetry, uh, to the, uh, backend. When I say exporting telemetry to the backend, it might be all those, you know, things that we saw, like it can be metrics logs, or it can be traces, but how we are exporting, we are not using any vendor specific tools here or agents. We are using a standard which is open to everyone, and that's make, you know, life simple when you migrate your tools to a different tool, uh, in future here.
So, moving on to next slide. Let's look at some of the case studies. Uh, when I say case studies, uh, we only look at some of good companies, uh, you know, where they are having a huge number of, uh, you know, applications or their ecosystem is quite big when compared to, you know, uh, basically a fan companies.
So we are going to look at, um, some of the case studies, how, you know, they're trying to proactively, uh, look the outages and it comes to metrics starting with eBay. Uh, so transitioning to metrics first, culture with open source tools like Prometheus and Grafana, it helped them to, you know, release 30 percentage of MTTR within 12 months of time. And Google being one of the pioneer of, uh, SRE principles.
So SRA practices at Google led to increase automation, reducing manual toy, and allowing engineers to focus more on impactful and interesting problems, rather than getting, you know, looped into repeating or, you know, mundane works. This, this is one of the, you know, uh, good, uh, you know, area that we can focus on, like SRE is a big, big word. So when I say SRE, a lot of things within SRE, like S-L-O-S-L-I-S-L-A error budget, these are the key areas where that you need to focus on if you are looking at customer satisfaction, because, uh, SLA is a very key metric that you need to, you know, look at, and you need to make sure as a company we are not breaching SLA and, uh, a proper alerting mechanism set will help you to, you know, achieve that kind of, uh, a good customer's, um, you know, uh, feedback or customer, uh, experience.
And, uh, Netflix. Netflix is using, uh, uh, engineering combined with the observability to monitor their globally distributed architecture. So this helped them to isolate their failures during the outages.
So this is like from a high level, uh, but there are definitely, uh, a lot of other case studies and, uh, like all the companies are trying to achieve that, you know, uh, that is the end goal. They want a proper customer, uh, feedback or customer experience. And, um, I, you know, having, reading this kind of case studies will give you some kind of idea to implement these kind of, uh, things within your organization.
Let's look at some of the facts and stats. So starting with efficiency gains teams with high observability maturity results, insurance, 50% faster than those without it. This is some, you know, uh, this is from Dynatrace, and this is something that we'll have to look at as well.
And cloud a adoption impact, 90% of the organizations using multi-cloud setups, seat observability as a critical to managing complexity. This is from CNCF and coming to reliability studies sh shows that outages cost enterprises around $9,000 per minute. Observability releases, developers, time spent, diagnosing production issues by up to 40%.
And this is from Google. Yeah, let's look at the recent trends in observability. So coming to the open source dominance, as I clearly mentioned about, uh, the different open source tools, which, you know, we discussed about like Prometheus and Ager.
Uh, we also looked at, uh, couple of other things, open telemetry as well. So if you, if you see the GitHub project and if you see the number of, you know, people commenting or number of people talking about it raising issues, you'll understand the dominance that it has taken across other projects and other tools. So that is one of the key thing.
And, uh, the study shows that Open Telemetry adoption has been increased over 80% in 2024 and coming with a per observability, uh, as all of you know, everyone is moving towards, or everyone is trying to include a and ML along with their existing tech stack. And this is also true in terms of observability. So one of the examples, a and models is now helping to detect anomal list in real time to prevent incidents before they, you know, kind of escalate and also predictive insights, enabling better capacity planning.
So this is one of the, uh, you know, area that, uh, you know, people are trying to go deeper and understand how AI and ML can go hand in hand with the observability tool stack. Let's look some of the forecast, uh, when I say forecast the future of observability. So the growth projection says that as per Gartner observability tooling market is expected to grow up to $10 billion by 2027.
And, um, that's huge. And, uh, coming to evolving role of ai, that's what we saw. Just, uh, the previous slide of like how a and ML is, you know, going hand in hand with observability.
Some of the, you know, major advantages, like you can identify issues that might otherwise go unnoticed by a software engineer or by a production engineer using AI and automations because it's quite difficult that, um, you know, you keep monitoring this. Definitely there is one of the other thing that is that's going to be missed. So using ai, definitely it's that you are going to be training the, uh, you know, model on your data sets or on the, I know, public data sets.
You want to make sure that the model is able to perform the task, uh, and trying to help you, you know, efficiently manage your system. It's not like you're going to give the control to AI completely. It's like you're taking the advantage of AI along with the, uh, you know, stack that you have built.
So that's where, you know, uh, the actual, uh, advantage is going to come in and you can prevent problems before they arise, as I said, like by integrating AI in your cloud native logging and monitoring tools and, uh, the standardization as I mentioned, uh, we will have to, you know, always look at, uh, uh, in a solution which is standard and, uh, portable. When I say portable, uh, open telemetry is one such example. So you instrument your code with Open Telemetry and you are free to be, you know, portable across any kind of, uh, monitoring, uh, tech stack.
So Open Telemetry is becoming the universal standard for telemetry data collection. Yeah. Uh, this is our LinkedIn handles, uh, both we know and myself.
So feel free to, you know, connect with us. We happy to, you know, have a chat, uh, or if you wanted to understand more about observability or if you wanted to, you know, share something that you found it useful and we are happy to, you know, learn as well. So feel free to connect with us.
And, uh, that's it for today. Um, we are going end this session. Thanks a lot for everyone for joining this wonderful session, and it's a pleasure to, you know, be here and, you know, helping you guys to understand more about absorbability and, you know, monitoring.
Thank you. Hi everyone. Good.
I'm going to talk about enabling observability to achieve faster resolution times and minimize customer impact. Uh, in today's dynamic digital landscape, uh, customer experience hinges on the reliability and performance of systems and applications. Uh, a single failure or delay can result in dissatisfied customers, reputational damage and financial loss to counter, uh, act these risks.
Enabling observability has emerged as a strategic priority for organizations aiming to ensure rapid solution times and a seamless service delivery. Um, if you are, uh, a first time listener, uh, or first time hearing about the topic observability, I would like to give you a background. What does observability mean and, and how it really help your organization?
So the observability refers to the ability to measure the internal state of a system based on the data it generates, such as logs, metrics, and traces. It transcends the traditional monitoring by providing deeper insights into the why behind issues. Rather than merely identifying what went wrong, observability empowers teams to detect anomalies early, understand the system behavior in real time, and diagnose, uh, and diagnose the root cause of issues with precision and proactively prevent future incidents.
And to talk in detail, uh, some of the key components of observability, um, are logs, metrics, traces, and synthetic, uh, monitoring. Let me take you, uh, on some of the details, uh, how you should be able to implementing observability tools and practices, as I mentioned about some of the key components such as logs, metrics, traces, and synthetic monitoring. Um, so logs provides some of the detailed even level data that helps teams understand specific occurrences within a system.
They are essential for diagnosing intricate issues and conducting foreign sake analysis. Um, in other, uh, words, metrics, quantify the performance and health of a system over time. Key indicators like CP usage, memory consumption, response time, and throughput help identify trends and deviations and tracers.
In the other hand, follow the flow of request through distributed systems, offering visibility into performance, bottlenecks and dependencies across your services or any of your monolithic applications. Synthetic monitoring, uh, which is, uh, a simulated user interactions with the system help identify the potential problems before customers experience them. I'm gonna, uh, take you through a journey of how implementing these observability tools and practices can enhance your organization's, uh, stability across your systems.
So the first one, um, I would like to talk about is the centralized data collection. Uh, like when you integrate all your telemetry data, uh, such as logs, metrics, and, and traces into a unified platform, uh, tools such as Splunk, observability, cloud, Grafana, or Datadog can streamline this process. And the other approach that you can take is automating your anomaly detection, using some of the artificial intelligence and machine language based solutions to identify patterns and detect anomalies automatically.
This reduces manual effort and accelerate problem identification. And the third one is correlating across data types. For example, by correlating your logs, metrics and traces, teams can gain a holistic view of the system, enabling them to pinpoint root causes faster.
Establishing a real-time dashboards, you can create intuitive dashboards or some of the dashboards that you can build using all of your data to monitor key performance indicators in real time. This ensures teams are alerted instantly when thresholds are breached. And lastly, the in, when you integrate it with some of the incident management tools, when you connect observability platforms with incident management tools like PagerDuty or jira, this facilitates seamless ticketing prioritization and resolution workflows in terms of implementation plan.
Um, if you are, uh, in a journey of, um, integrating observability into your ecosystem, um, if you can start with the four phases approach that could really help you to, um, have a seamless and a smooth transition of enabling observability into your organizations. The first one is you need to assess the current state, um, because when you begin with a comprehensive assessment of your organization needs, uh, it'll really help you to understand what is the current state in your critical, uh, path towards how you want to support your monitoring and troubleshooting. And the next one is adopting the right tools.
Um, so implementing tools, uh, such as Splunk, Grafana, um, new Relic, uh, this will allow your team to evaluate, uh, some effectiveness and also gather feedback and make necessary adjustments before a full scale rollout. This will really help identify potential challenges early. Um, and the third one is integrating across system.
Imagine, uh, think about you have a large ecosystem, uh, with your infrastructure, um, being your frontend backend, um, in terms of your user perspective. So when you think about your ecosystem, uh, you need to make sure you have a comprehensive training sessions, all relevant teams to ensure they're well equipped to utilize the new tools, um, efficiently. So this, uh, focus will be on maximizing adoption and operational.
And the last one is fostering a culture of observability when new rollouts, observability in each and every piece of your infrastructure. Um, so you need to make sure you have a robust feedback for continuous monitoring, improving your observability tools and analyzing your performance metrics, which will help you to adapt and optimize the tools, um, based on user experiences and evolving. And I would like to, um, talk about some of the benefits of observability in resolution and in resolution times.
Uh, the first one is the proactive problem detection. Um, so observability really helps identify potential issues before they escalate, reducing your mean time detection from hours to minutes. Um, to give you an example, think about in a real digital world, um, you want to give a better experience to your customers, um, I'll walk you through some of the examples that I've gone through in my similar experience.
Let's say your customers, um, you have a web application and you have your customers who are heavily using your website, and they are backend, uh, services. It could be your, um, microservices, it could be your AWS cloud servers or any of their cloud offering service. Imagine if, if something goes wrong, something is not, um, working as it expected, um, it is really challenging for you to know what exactly the problem is.
Your customer might be experiencing a different, uh, issue, and your application might be, um, having a different issue. The way observability really helps you in terms of proactive monitoring is when you correlate all of your, um, front end with the backend with your application. The, the way you can do it is by enabling the synthetic monitoring, uh, along with your application monitoring, such as a PM and rum correlation, which will really help you to nail down, uh, some of the unknowns.
Uh, uh, that would really help you to, uh, bring down your, um, meantime to detection. So if your user is going through an, an, an issue, so the observability will really help you to pin down the specific trace id, uh, from the, uh, rum, like the realtime user monitoring, which is apparently also synthetics monitoring, which will really help you to nail down the specifics of the specific application, um, which will really help you to navigate and find which application is causing that problem instead of you, uh, figuring out, um, and which will really cause problems and, uh, impacting your customers. Uh, as I said, the faster root cause analysis is something a centralized and a correlated view of telemetry data eliminates like guesswork, uh, significantly lowering mean time, uh, resolution, uh, to minutes from hours to minutes.
And the other part is reduced downtime. So the observability really helps you to quickly detect and resolution, ensure minimal impact on customer facing services, uh, maintaining a high level of satisfaction and trust and, and the improved collaboration. Uh, in terms of, um, observability, fosters cross team collaboration by providing a single source of truth like your developers, your operations teams and DevOps engineers can all work together, um, more effectively, um, because of this collaboration across the teams using observability in each and every space.
And lastly, the customer-centric resilience. So by ensuring system reliability, businesses can consistently meet, uh, customer expectations of fostering loyalty and competitive advantage. Um, and I just wanna conclude, um, saying, you know, enabling observability is not just a technical initiative, it's a business enabler.
Uh, by investing in observability tools and practices, organizations can achieve faster resolution times, minimize service disruptions, and protect their reputation. In a world where customer expectations are higher than ever, observability is, uh, a cornerstone of operational excellence. Thank you.