Techstrong TV – January 15, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
You are watching Text on Gag. Hey everyone, happy Wednesday. I'm Alan Shimmel.
Welcome to Text Drug Gang. So, what the heck were we doing in that opening? Well, if you couldn't tell, he was See no evil.
I was speak no evil. And he was here. No evil.
And that pretty much sums up what we want to do here on Textron Gang. We're gonna try to keep evil out of it, though. Evil has a way of seeping into our conversation sometimes.
Um, we've got a great gang and some great stuff to talk about today. Let me introduce you first of all. Well, let's do the remote for first.
For folks first, had a little tongue twister there. First of all, joining us from somewhere at sea. He's on his boat as usual, and, uh, the Mariner, not the Submariner, but the Mariner and cybersecurity expert.
Chris Blast. Hey, Chris. Hey, Alan.
Good to see you folks. Yes, I'm anchored off a little island, uh, somewhere around Vero Beach. Very cool.
Very cool. I hope it's not too cold that you need to scarf or is that more of a, a Look, It's, I, I'm, I'm, um, coldblooded person, Don my wife Donna is on board with me. You know, we've been married for years.
For you, Chris. Yeah. So she's, she's basically in shorts and a t-shirt and I'm bundled up with mittens.
That's just the way it is. Yep. Excellent.
Well, thanks for being here. It's great to have you on joining us, I guess, home in San Angelo, Texas, where she's just come off yesterday's, uh, predict 2025 panel that she hosted live. And you could check, check that out, and you could catch it.
Well not live anymore. It can only be live once. com as well.
It's a whole bunch of other great content. It's our special content editor at large. Amanda Ra Ani.
Hey, Amanda, how are you? Great. Happy to be here as always.
Happy to have you on. Alrighty. And then I'm really happy to be joined here in our Boca Ratone Studios.
The Prodigal Sons have returned, uh, to my left. That might be your right. Our Chief Content officer visiting us from New York.
Mike Ard. Hey, Mike. Great to have you here.
The great State of Florida was kind enough to issue me a passport, so I could be here Only on, only for a short period that six o'clock You're back out. Didn't stop you at the border. Yeah, that's good.
That's good. Well, he wasn't spouting woke stuff, I guess, but, um, I, I noticed you're wearing some text stroke swag. Yeah.
Um, this came for the holidays, so I got this little Textron group vest thing here. So, you know, I, I'm still waiting on my gang colors, but I'll wear these in The meantime. Well, those are our gang colors.
Well, I'm white. Well, actually a lot of our gang members will be supporting these. I think we had them sent, but mm-hmm.
Um, anyway, thanks for being here. Mike joining us from Colorado is a little less high here. I can tell his eyes are very sharp.
Still high a little bit. He's still high. Little bit about, yeah, he future, uh, VP Analyst and now our friend Mitch Ashley Mitchell.
It's great to have you here in person, man. It's great to do it in the studio. We always have fun when we get together, so.
Absolutely. So I feel like we're men in black, at least par partially on this. We do, yeah.
We are. So of men in Black today, back in black. Um, I should mention, I actually, I did mention that Predict 2025 was yesterday.
And it was a, uh, one of the best, I think the best predict we've had. It was very good. An amazing sessions, amazing speakers.
Of course, a lot of them had to do with ai, surprise, surprise. But a lot of it had to do with the Gen AI and different aspects of ai. And we had speakers from AWS, some of the other big hyperscalers.
We had a three or four folks from Futurum. Uh, we had my friend Carolyn Wong and Jennifer Gio, and a lot of, you know, friends Mitchell from our cyber war, uh, cyber Days. Mm-hmm.
And so it was all good to have them. Uh, it was great. Including, as I mentioned, Amanda's panel with our friend Hope Lynch gang members, hope Lynch and Guy Courier.
I guess that was the Textron Gang. There you go. Panel for, uh, predict.
And, oh, one of the highlights though, for Predict every year is we announced the DevOps Dozen awards. And, uh, this was the 10th year for DevOps dozen awards. We had eight community categories and 14 tools and service categories.
And I'll tell you, it was, we had over 8,000 votes cast for the DevOps dozen awards this year. Um, judges were Hope Lynch and Mitchell and myself. And for the most part, we went along with what the audience voted for, though we did.
There were some companies shall remain nameless who tried to game the system. No, yeah. In this day and age, gaming the system.
Well, voting, yeah. Vote for all. Well, people don't vote, but these people voted over and over and over again.
Were they in Chicago? No, those are dead people who voted in Chicago. People who vote multiple times are usually right here in Florida.
Um, anyway, but we did discount those votes, so it was a fair, free and fair election. We had no riots or anything. It went well.
Um, I'm really happy to congratulate all of the DevOps dozen award winners you can get. com. com.
So congratulations to our award winners. Uh, worthy, worthy, worthy. The award winners.
Well, We're gonna jump into this in the A block cart. I thought that was the A block. Well, we normally do a little introduction there, but up to you.
Go around. Okay. Well, that was our A block.
Um, that was the DevOps dozen award guys. What do you guys think? You, you saw the winners.
You, you, Mitchell would, Amanda and Mike, you've been doing this with us for years now. Thoughts, I Felt that this was kind of the winners of the old guard, right? A lot of the vendors who won have been in the category for a long time.
So is there something indicative of that where maybe we're seeing fewer startups win? Or what's your sense of where are we in this market? I, I think it depends on the category, right?
When you look at, like, for instance, best DevOps end-to-end, uh, product. Yeah. That is, that doesn't change.
I mean, the, the nominees are always the nominees. You got GitLab in there and CloudBees and Jfr, you know, uh, end-to-end DevOps platforms, GitHub. There's just not that many harness.
So you know that that's who it is. But remember also that in those categories, look, we don't nominate the finalists. It's self nominated and open to people and then it's who votes for them.
So is there a lot of change in DevOps? But I also like to look at some of the new categories. 'cause we do add new categories every year.
So this year we had several AI categories. We had a platform engineering category, and of course, what I always call the rookie of the year, the best new DevOps tool. Mm-hmm.
So, you know, there were, if you look some, some new names and new faces and in, in there. But the fact of the matter is, in DevOps companies like Jfr and CloudBees and GitLab and Harness, there's a reason why they're leading. They're leading the space.
I think it's a sign of the maturity of the market. Yeah. It is.
A little more companies have filled out and added more to their product set of things that they're offering. Mm-hmm. Um, it's also just the maturity of DevOps.
Yeah. Um, we're gonna be coming out with a, uh, new data set for future intelligence around DevOps and, and AI and development and things like that. And, and tech strong research.
Yep. It's gonna come out, I don't know the date yet, but we're working on it as we, 56% of the people who have not 50, 60% use CREST toothpaste. Okay.
No, not, it's a different survey. Different survey. Glad to hear that.
That even our Textron research from last year, you know, showed that, uh, more people were putting themselves in kind of a, a later stage of maturity of adoption, standardizing in DevOps and even, uh, mastery level. So, you know, we've been doing this for a while, so I'm not surprised to see some of the same players continuing to do that. Sure.
As well as new players too. Absolutely. And I imagine That some companies, especially the more experienced companies who have been a part of this contest for several years, are pretty good at their marketing and, and promotion tactics as well.
Yeah. No, there is that. Look, companies that promote that they're finalists and seek votes, get votes.
People that don't, don't. Um, I, I'll tell you though, another theme that I saw this year, there, there was a category best use of AI in a DevOps product. We had a, we, we returned nomination fees.
'cause we had too many companies that were submitting. Every company is putting it AI into their, uh, product. Right?
So that, that's a new theme too that I don't think, you know, we saw last year, certainly not the year before that for sure. So I think that was big. Look, you know, it's DevOps.
And I think the DevOps doesn't reflect the DevOps market. I always like the categories involving, you know, who we recognize is kind of leading evangelist for DevOps. So, you know who came, well this year we had two different evangelist categories.
One was best community evangelists. So this is not a vendor. And we, we had two great finalists, and the winner was from the Georgia, not Atlanta, Georgia, Georgia, former Soviet Republic, Georgia DevOps community.
His name is Georgie. Uh, Kelli, I believe is his last name. And he won his best community evangelists.
He did a really nice, he does a really great job. Right? And, and more power to him.
And there was another person from India that they was in. The finalist there too was also great and worthy. And then we had the corporate evangelists, right?
And look, Derell has had a tough year, right? A lot of our friends in Dere don't have their jobs anymore. People were cutting back on Derell, going back to sales.
But there was several. And, and in that category, it was actually all new names. Hmm.
All new folks. Uh, the winner was from BMC, who, you know, you wanna talk mainframes, you want to say they're old guard, but they're out there banging the bushes and collecting votes I might add every year in and year out. So more power to them as well.
Anything else? It's just this year. No good stuff.
com. dot com. You can go there.
com with the help of our crackerjack editor edit, Amanda. So you could check in out there, or you could watch it on Predict 25. All the sessions are still up there.
And, and nominations for 2026 Open will open in August. Please don't start writing me now, but they open in August. All right, let's take a break and then we're going to come back and find out what's the hottest new podcast on the waves.
And I do mean the waves, uh, stay tuned. We're gonna tell you about it. You're watching Text on Gang Modernize your business to fuel innovation and elevate customer experiences with the builder community.
Hub AWS and its partner network provide essential tools for transforming applications and infrastructure to fully leverage the cloud. Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably. Visit the Builder community hub to learn more.
Hey everyone, we're back here. So, as I mentioned, what's the hottest new podcast? While at least on, on tv, you know, our friend Chris Blas has been building up some content and talking about and threatening us on doing a podcast for a long time.
And, uh, in between keeping his boats afloat, traveling back and forth to Canada, advising people on critical infrastructure and cybersecurity, Chris has found the time to finally launch the inevitability curve. And when I say it's the best podcast on the waves, I literally do mean the waves. He records a lot of the sessions right on his boat with guests from around the world of cyber.
And not only cyber, a bunch of stuff, but Chris, give us the scoop about the inevitability curve. So in the early 1990s, I think it was 91, 92, um, I was, uh, living in Canada again, working a little computer company. And they had an internet connection, right?
You use net connection, right? And a dial up, uh, thing. And it dawned on me that everyone on earth was gonna get on the internet.
And so a little six person company, and this is where the, where I got into security, um, uh, shortly thereafter. And, and the, the two, the two bosses, the two owners about our ages, right? You know, said, kid, you don't understand the Internet's for education and military.
It's, you know, it's never gonna be a thing. And I argued this for a couple weeks, and I finally went in, uh, to John Alsup, John, if you're out there on this whiteboard and said, let's just assume for a second that I'm right. That in some useful period of time, 10, 20, 30 years, the entire u you know, PO global population gets on the internet.
in the upper left hand, upper right hand part of his whiteboard. And the lower left has said, we're here. If I'm right, there is already a line that connects us to that future and multiple lines.
But you know, you know, the sales of whatever, right? Things will change along in a given pattern if in fact that futurist is correct. And I've found myself coming back to this over and over and over in my career and realize it really is, before all this, this is always the way I've looked at things.
It always kind of surprised me that, that we get so wrapped up in the moment. We can't say the moment is here because we have just gone through all these things. And given that we have gone through all these things to get to this spot, the only possible futures are along some range of tra trajectories that you can look at, right?
So in this series, first one was up, uh, got up last week, they come out every Wednesday, Heather McMahon, you know, amazing background. Just like so many of our peers. It was like, how did you get exactly there?
Just, just that by itself. But having gone through all the phases that she's gone in her career, we talk about marine systems and cybersecurity and, and cyber systems and automation, you know, it, it's, that gives you a lot of insight into where we're going, right? So I'm looking forward to doing more of these.
We have the, the weekly series, and we're putting together a set of round, uh, round tables. The first one, um, end of this quarter, early Q2. We'll have a couple of sponsors.
We'll sit down, we'll do the same sort of thing, you know, in a, in a larger group, uh, context, you know, with ai, where have we been? How do we get to where we are right now? What useful information about our future can we find inside that?
And I find, you know, with all, all the things I've done in my career, mostly it's this, it's talking to folks like you where we all have a pretty good understanding of what we're doing, and just ferreting out how the heck we got to this. And then looking forward a little bit and saying, all right, given that we're probably do about to do that. So, very cool.
Not planning obsessed or anything, but that's, it's a thing. Now, No one ever accused you of being obsessive, have they? I, I, God, I hope so.
As, as you look back over time, how much of the innovations that we have tracked, it wasn't really a technical issue as much as it just was a cultural issue. And it just took a while for the adoption curve to work its way through Almost all of it. Mm-hmm.
Right? And I don't want to get all Isaac Hasim off, you know, psycho history, you know, foundation series on us. You know, we are, you know, arguably, you know, freewill entities and we, you know, creatures, we, we do things because we want to, however, right?
When we're doing things, it's usually because we wanted to for a long time. And now's the time, you know, where my, you know, the network address translation, my early claim to fame. And I, I always think, you know, aside from, you know, my own back padding, I find it fascinating.
You know, the 1992, I think it was, we had started building the border wire firewall server. And I talked to some, you know, old Bart, you know, like our age. He's like, kid, you don't understand.
There's not enough IP addresses. You internet won't work. And within 15 minutes, um, with two colleagues, Andrew Flint and Amaya Lundy, we invented network address translation.
Totally unaware that there was a raging debate among the IETF about network address translation. And two other people were inventing it in parallel at the same time. You know, could that have been done earlier?
Sure. But it wasn't nat time yet. It reminds me, there was a TV series with, I think it was James Burke connections, where he walked through history and said, you know, this caused, this, led to this, that led to gunpowder.
Well, there's the butterfly effect that too, right? It is sort of your inevitability curve of things happen for a reason because of a lot of things that led to that enable that to happen. So I'm thinking, do we start calling Chris Dr.
Harry sell? Did, I don't know, But I, I think that if I knew where the exact points were on the curve, I'd probably be working on Wall Street making a lot more money than I am right now. 7 gigawatts.
You could go back in time and do that there, MC fly. Well, I, I think it's one of, one of the things I'm looking forward, you know, I'm enjoying actually in, in this whole conversation is defining what I mean by this, because it's not, you know, the future is not fixed. However, it's, it is, it's less about the things that will happen as, as more about the things that are not gonna happen, right?
Not now, not yet. You know, we can't make that kind of curve in that period of, of time. So its more about Bounding responsibility.
Well, this is a quantum aspect to it, right? Like, you know, the fact that, you know, it's there by, by the very fact of knowing that's gonna happen, you're changing it, right? And, and so it exists in different states and Multiverses and all of that craziness that we could get into, even though, uh, Jensen Wong says quantum computing is 10 to 15.
Yeah. And all these quantum stocks took ahead as a result. But there, but there is a, a quantum aspect to it.
Um, but let me bring us back to the real world here of relativity and all that good stuff, Chris. The inevitability curve is gonna be right here on Techstrong tv on our network, as well as on your favorite podcast, uh, platform, whether it's Apple or Spotify, or ads, any of the other places that you listen to podcasts, uh, as part of text on tv, it'll be on the YouTube, the text on tv, YouTube channel. It'll be available on all of our websites as well as LinkedIn and Facebook and Twitter, x whatever you want to call it.
If you're still on there. Um, talk about some of the guests you've got coming on here. Oh, this is, you know, you mentioned Harry Selden.
You know, I, I tend to think of Dirk Gently, you know, the Douglas Adams character. Mm-hmm. Uh, everything, the holistic de detective.
And, you know, you and I talked about that, about this, you know, over the years. It's amazing the people we know, the networks we make. And, you know, Mickey, Mickey Finn Inden, you know, Mickey is just an amazing, uh, uh, person.
You know, she's also been, uh, she'll be in the early episodes that are already recorded. Phil Engler at the Healthcare isac. Phil and I have been leading a, uh, assisted working group on ISACs as SBO M distributors.
And I'm sorry, there's so many acronyms in there that I can define them all. Hopefully, uh, people can pick up most of 'em. And discussing with him, he is working at the healthcare isac, how do we get threat intelligence out to medical device manufacturers and so on and so forth, right?
You know, so, you know, everything from the, uh, uh, talking to people, Fred Cohen, right? People who have been in the, in the industry. Fred coined the term computer virus at his PhD thesis, so he's that guy, right?
You know, these are all the people that we, that, that we've grown up with and lived in our, in our careers with. And, and young and old. I I love the fact that people are coming into the industry and, you know, it, it's, it's, it's easy to get a little pompous.
It's like, I've got 30 years, I have 25 years. It's like, look, there are people with three years and seven years of experience in security doing amazing things right now. Right?
And quite often the things that us, you know, people with too much experience are missing. You know what? It, it goes back to something you said a little earlier, earlier.
It's like, we didn't ever want to be those old farts who say, Hey kid, I don't know what you're talking about. You don't know what you're talking about. Because there's always some smart kid out there who's gonna do network address translation or whatever the next thing is, And, and they're fresh new perspective to it.
Yeah. So, right. Well, it Is.
I'll I'll throw one, right? C-I-A-C-I-H drives me mad. Confidentiality, integrity and availability are not the only three protection objectives, Killers of security.
Mm-hmm. That's an artifact of the times to our point. You know, I, I can tell you exactly how that happened.
Fred Cohen and Stephen Northcott and the, and the creation of Sands and so forth, bake that in. There are more than three possible objectives to security. So, to your point, Amanda, yeah.
Freshman wise, coming into this, and not just, not just rote. How, how often are you doing new episodes, Chris? Every week, every Wednesday, there'll be a, there'll be the interview episodes out, the round tables will be at least quarterly.
I think it's a reasonable goal to put those together and get that done. The quarterlies are sort of live audience round tables, Right? Yeah.
Get a couple, you know, those would be sponsored, you know, so we'll have some, let's Talk sponsors. What kind of sponsors you're looking for for this marketing folks out there pay attention, Right? You know, so, so this, you know, I, look, I spend a lot of marketing money, you know, again, I am vice president of strategy at SS and I, you know, do a lot of these roles.
I've been in a vendor almost my entire career. So there's thought leadership type of stuff, which has a, a less hard value. But, you know, if you're interested in, uh, um, promoting your image of, of understanding where you're going, that's, that's a good thing.
And if you're targeting, uh, these, these audiences, you know, this is, this is tech strong. We speak to a technical ar uh, audience. And, uh, uh, obviously I focus a lot on, on cybersecurity.
So cybersecurity vendors are, are interesting folks. But I've always thought it's more than that. One of the things I love about supply chain right now is though, though it's security, people talking about supply chain, it's really all about logistics and efficiency and so forth.
So, Very cool technical Vendors. And we're happy to try to make you look good if you deserve it. Excellent.
All right. The inevitability Curve comes out every Wednesday. Check it out here on TechOne tv, or as I said, wherever you listen to podcasts, it'll, you'll be able to find it.
Chris. Good luck with it. We'll, of course we'll be doing everything we can to help, but I'm sure it's gonna be a fantastic discussions there and good stuff.
Let's take a break here on TechOne Gang. We're gonna come back to our C block. I think Amanda is gonna kick that one about AI spending projections too early to say it's a failure.
Or I don't think Roseanne, that, I think it's an inevitability curve issue. Okay. That crazy pattern there.
I was nice. Mike, you should work in marketing. He's sharp.
Sharp. You're watching techron Gang. Discover Techron Group, the epicenter of tech innovation.
We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Alright, folks, we're back. And yeah, going into that whole conversation about inevitability. We all think AI is coming, but boy, there's a huge debate about the when and the where because, uh, a lot of folks from Wall Street are getting a little antsy about how come we're not seeing a huge amount of revenue flowing through these AI products just yet.
And we saw UBS now has a survey out where they asked 125 senior IT execs, and they were saying that their spending would drive to the back half of this year, maybe in into 2026. 'cause their businesses just weren't aligned around how to use AI just yet. We also have, uh, stories on text drawing, ai.
Uh, there's a FreshWorks report that says a lot of this stuff right now is just being driven from the bottom up. And part of the problem is there isn't enough leadership up top that's kind saying where we should be driving this conversation. And then NTT has the same thing going on in their survey, and I know you talked to that recently.
Um, the, everybody seems to be pointing to the same issue, which is, it's just taking longer to execute on this than people imagined. But Amanda, I know you've been covering this whole AI space, for instance, the early days. What's your take on, where are we and what's going on here?
Well, we know every company, practically every person is eyes on AI and try and integrate AI in some way. But the problem is, um, and you can see this on a lot of our articles, is, um, the value is not coming through as expected. Um, and so they're having to cut back on their spending because it's not, it's not, um, giving them what they anticipated.
So, um, while this is an issue, of course, everybody has to move forward with AI adoption. So what is necessary is good communication and, um, understanding the outcome and having a good plan of action. 2 points you're trying to solve and go forward with that first.
Um, and I think that we're seeing in, um, a few different articles and interviews, that's the way to go. Me. There's overinflated expectations on ai.
I'm shocked. Hype cycle. Shocking hype cycle.
Yeah. Gambling going, got, you know, I, I have a different, I have a different take on this. I'm surprised that's me.
It happens, it's inevitable. Um, but that, that being said here, here's my take. And I'll be honest with you, it's not my take.
I think my friend John Willis told me about it. I, there's a reason why we're seeing it from the bottom up. Because the smaller companies lower down less money at stake.
They're more nimble, they're quicker to adopt, they're quicker to experiment, they're quicker to try. When you get to the companies that USB is rep ing or you know, these large enterprises, the inertia built into driving those ships is it's the reason why the Titanic sank. Mm-hmm.
Right? They can't get out of the way of the iceberg. And so we haven't been in this AI cycle long enough for the enterprises to change the direction of their ship to overcome that inertia.
And that's why we say, oh yeah, we're gonna see it in the second half of 2025. 'cause it's gonna take at least that long for these be myths to, you know, look at their budgeting cycles. A lot of them are on, uh, fiscal, not calendar years.
It starts February one, June one, you know, and you can't do a lot of these AI projects if it hasn't really been budgeted. You only rob Peter to pay Paul so much. And so it's gonna be the second half of the year, at least, until you start seeing budgets at these large companies incorporate some of these AI uh, projects.
Them being said, though, it's, it's rocket. I mean, to that point, and, and I, this, I've lived this, right? As, as part of running IT organizations is something new comes along, you wanna start to adopt it and you're not in the cycle, especially in a very large enterprise, right?
They're, they're budgeting for 2, 3, 5 years out for projects that are multi-year projects. So what you do in the short term is you kind of Rob, Peter, Peter, PayPal, you say, where can I, let's pull back on spending here. I'll put a little bit of it on I AI when I really would like to do more, but it's gonna be maybe a year, maybe two years before I really kind of are investing the levels that I think I should be investing, especially in a big enterprise.
So in the near term, I think people are still in the experimentation phase, learning what they can do, especially with generative ai. They've got pilot projects. We're hear about a lot of projects sort of stuck in it, stuck in that pilot base, not sure how to get it into production.
Kinda getting that over the hump. We'll start to see more value. But I think the bottom up is spot on.
And, you know, John's experience there is very much true that because we don't see the larger investment by IT budgets. People buy their own co-pilot license or license to whatever tool that they like to use. But I, I don't think there's any doubt that it's a big market.
It's just not gonna happen. As fast as we'd love to get an ROI on it, If I was gonna read anything into it, I, I, I, you know, and, and don't read too much into my statements, but it, it seems like the kind of overcorrection you get when it is a real trend, right? We started the show with, with DevOps, right?
You know, 10 and more years ago. Is it really going, you know, would, would 2025 and DevOps be at the maturity level that, that all you guys were talking about at the beginning? Nobody knew.
Um, but the answer is yes. 'cause this time, that time, you know, it really was time to do the thing. And I think ai, we're at this, you know, early stage the first couple years, 1, 2, 3 years.
And like you say, Mitch, you know, people are going, I'm actually gonna start using that. Whereas in the big corporations, there's, there's healthy functions that try to damp that down. When the enthusiastic, you know, group comes up and says, we need big budget next year.
It's like, eh, the low the second year, um, maybe it goes too high. So I think we're in that overcorrect too much stage of a real trend. I don't, I don't, haven't seen any signs of this, this, uh, uh, version of what we call AI not being, frankly, as exciting as it looks.
I think that you have to keep in mind the fact that I would argue half of it spending is now driven by a line of business units somewhere, and it's not always in the IT budget. So a lot of those folks might be driving this conversation forward in a way that doesn't necessarily always include the IT folks until they get some level of scale going and then they dump it back on the CIO and say, you know, Hey, look what we did and Their funding, their funding projects based on outcome based ROI, what what they need delivered, not just, we need to invest in a technology versus B. Mm-hmm.
I, I think also, you know, one of the big things that predict yesterday was that 2025 we'll see a big move from let's say gen AI to agen ai. And I think agen ai, believe it or not, is not as radical, maybe as generative. A a generative AI had a lot of parla trick faz magical property to it, right?
Let me show you what it could do. You know, and you didn't have to be a techie to say, holy macro, that's cool as crap. AG agentic AI though is where work gets done.
And I think as in 2025, we start adopting and developing more agentic AI use cases, we're going to see more real, you know, rubber meets the road, meat and potatoes kinda work being done via ai. Yeah, I agree with that. 'cause a lot of this, you know, stuff where we were handing people like, uh, a library of prompts that they should use for different use cases, they kind of looked at that and shrugged and said, I really don't know how to operationalize that inside of my job.
But if I have an agent that I can just say, you know, go do this, that's a different experience. Well, You Know, yeah. And that was kind of my point is companies, um, need to step back.
What's a real solution? They, you know, a real problem that they need to solve, focus on one or two real problems they need to solve, get the budget for that and move forward. Yeah.
I think there's a real emphasis. I mean, my, my thing for 2025 is AI and production. You know, let's get this, let's get it in there.
And actually it's what it can do for us, right? It's time and get out. I mean, I did see an interview with Zuckerberg, mark Zuckerberg from Meta of course, who talked about in 2025, they think they're gonna replace a lot of mid-level developer engineers with, with AI stuff Benny office saying the same thing.
Is it? Yeah. So may maybe, I guess we'll have to wait and see how that comes out.
What's the prediction there? I don't think that's gonna be true, But you heard it here first. I doubt heck would predict happens.
Chaos. I doubt it. We'll see, we'll see.
Anyway, I think that's gonna wrap us for Techstrong Gang today. We are, we're busy here in Tech, strong land in Boca doing our all hands kinda meetings and planning and scheming and thinking about what's inevitable for 2025. And, uh, we'll, we'll go with that.
Chris, I've, I wanted to catch up with you too. It may wait till later this week 'cause I got these guys here. But, um, if you haven't, if you missed Predict 2025 yesterday, it's still up there.
Go register and go check out all the sessions. They're all there, including the sponsors and they have a bunch of great content on their hubs as well. So Predict 2025 churn, uh, predictions for 2025.
Oh yeah. And if you register, everybody gets the future and Prediction 2025 ebook. We'll be emailing that out.
Um, it's been a great week so far. We've got a full tech, strong TV lineup on for today as well. And, uh, we'll be back tomorrow with even more as usual from the gang.
But for now, this is Alan Shimmel on behalf of Mike, Mitch. Amanda and Chris. Thank you.
We're out. This is Textron tv. Hey guys, thanks for the throw.
We're here with Deepak. Tunisia is the CEO for Zillow security. And we're talking about identity and what makes securing those identities tough, because I think we're all talking about it in the era of Zero Trust, but I don't think a lot of us know exactly how to go about doing it.
Deepak welcome the show. Thanks. Thanks, uh, Mike, great to be here.
I feel like, and this just may be an opinion of one, but in some sense, I feel like we're making a strategic withdrawal, right? We couldn't secure the network perimeter anymore, and everything's coming over the top. So we need to, to find a different tier to secure.
And I think we all landed on identity, and of course we've been trying to secure identities for a while, but maybe we're getting better at it. Maybe it's even getting easier. But what's your assessment of where we are and why are we all suddenly obsessed about identity and security?
Yeah, that's a great question. Well, identity's been around for, for a long time. It's been, it's been a business enablement issue, right?
Um, managing identities and giving people access to, to the applications and data they need to do their jobs. Um, I think what's what's happened in the last 10, 15 years with the adoption of the cloud is that, um, identities become, to use a cliche, the new security perimeter, right? So it's, it's, um, I think Rob Joyce recently in the Wall Street Journal article, uh, called it the Greatest Cybersecurity Challenge.
And indeed, it is becoming the greatest cybersecurity challenge. I think identity by its right nature is built into all, all aspects of a business. It's, it's how business business runs on, on, on it and information systems.
And unless identities are managed appropriately, uh, people in the business can't do their work. Uh, so that's, that's why it's, it's becoming so critical. And of course, you know, we all have thought of the network as the foundation of enterprise security for, for a few decades now.
The idea has always been keep the bad guys out of your network. Well, there is no network anymore, right? The, the corporate network is sort of falling apart when it exists.
It's augmented with this cloud and lots of different clouds, um, that, that organizations are, are using. So, so the core, the fundamental sort of construct in security more and more is becoming identity. You know, people are coming in from work, from home, from Starbucks, from the road, they need to get their work done.
And how do you, how do you help them do that? Well, you figure out the identity of, of, of the individual, and, and, and then you give them access. You give them the right access, give them the, uh, access they need to do their jobs.
And that's, that's why identity is becoming so critical. So what makes it hard to manage that? Because know on a certain level, we've been asking, you know, who goes there since the caveman for first grunted?
So, um, how, what makes managing identity so difficult in the, in the current age of it? Yeah, right. So I think we've been trying to manage identities for a while, but it all starts with figuring out if this entity, this person is who or is what, who or she claims to be, right?
It starts with authentication. And to deal with authentication, you need a directory. So that's the, that's sort of foundational.
And then it goes from there. Well, once you can authenticate someone and you have to authorize them to, to access the right application of data, that requires giving them permissions. So now you've gotta manage those permissions.
Um, and then of course, there's, there's people who are constantly joining, moving and leaving in an organization. So you've gotta manage those identities and those permissions. And then of course, there's compliance because you have to prove to, um, to, um, to comply with all kinds of regulations.
Organizations have to ensure that they review who has access to what, and that's becomes another, another process. Um, so it, it, it's, you know, there's, um, what makes all of this difficult and challenging is that identity is, is all about processes. It's built into the fabric of an organization.
And, um, while things like we have a, as an industry, we have a pretty good handle on the fundamentals of directories and authentication. We're still grappling with the governance processes. How do you actually deal with compliance?
How do you deal with provisioning, joiners, movers, leavers? How do you deal with the, uh, the security angle, the security posture around, around identity? And while we're dealing with all of this, while we're grappling with all of these questions, um, the cloud has, has created, uh, this, this whole fabric that, that now, uh, involves not just human identities, but non-human identities.
And in fact, the non-human identities, uh, service accounts, uh, and so on, tokens, um, um, they, they outnumber human identities by a factor of a hundred to 1000 to one, um, in many organizations. So, so it's becoming a bigger and bigger problem, right? All those, if you're gonna govern just human identities, uh, and the access that human identities have, that's not enough.
Now you've got this, this problem about non-human identity governance And those non-human identities, there might be more of them than there are people because there are essentially machines and even software components. So, um, it feels like this is a, a problem of several orders of magnitude greater than people might initially realize. That is exactly right.
And that realization is, is starting to hit security teams and security leaders now, right? This is, um, you know, that cliche, I used identities, the new security perimeters been around for a number of years. The implications of that are only now starting to, to to be felt inside organizations.
Um, and, and people are starting to say, well, well, this identity business is, is critical, and in fact needs to, uh, needs much more importance in our, in our security stack. Um, and, and in fact, it is the cornerstone of security moving forward. Uh, which is not to say that you, you shouldn't, to the extent that you have a corporate network, you don't need network security or to the extent that you're using, um, large host systems, Unix, a mainframe, whatever, you don't need host security for them.
Uh, you, you still need a lot of different elements of security. But the foundation increasingly is identity. As we think all this through for a minute, um, are we too wedded to some of our legacy platforms for managing identity?
Because I can go back in time and, you know, there's various directories that are 30, 40 years old technologies at this point, or so do we need to rethink the platforms or can we extend those in a way that makes them still relevant? Yeah. And that's, that's the challenge that most organizations, particularly large organizations face.
Um, you know, the, the March of progress is, is, is so fast that it's outstripping the ability of, um, vendors to upgrade and update their old products. And, and so, and this is not new. Uh, I think we've, we've seen this in the IT industry for the last 50 years.
Um, um, the, the problems evolve and existing solutions, existing deployments inside enterprises can cope up with, uh, with the evolution of those problems. And so the challenge is how do you, how do you evolve your, your infrastructure, your identity infrastructure, uh, to deal with that? And, and most large companies are, are, are trying to figure that out.
And, and oftentimes it's not a rip and replace, it's, uh, sometimes it is. Um, but oftentimes it's a question of, um, you know, figuring out what, what part of the problem your old deployment can, can deal with effectively, and how do you start to bring in newer tools, newer solutions to, to deal with other parts of the problem. And then perhaps there's a, a whole scale replacement over 18 months or 24 months.
And we're, we're seeing that sort of thing a lot in, in the, on the identity governance side, uh, in the industry. What impact do you think AI might have on all of this? 'cause I could think about it as both a negative and a positive, but it seems like maybe this whole thing could a, become easy to manage, but then again, the bad guys will be messing with their identities, right?
That's right. That's right. So, so AI makes things worse in different ways.
Um, you know, the very nature of ai, you know, more tools, more services, more applications, all of that implies more identities, more permissions, more to manage, right? And then to your point, um, AI can be, can be used, um, against the organization by, by bad actors. But AI also makes things better.
It, it, it takes, it takes automation to the next level. Um, AI can do what humans can, um, and, and AI can help every stakeholder in an identity management process or an identity governance process. So, um, you know, we are, we, we see a lot of benefits, um, accruing from the use of ai, and we're just at the beginning of that, of that cycle.
I think, uh, there's been a lot of hoopla around generative ai and so on the last, um, the last year or two. And, and that's, that's, that's good. I think it, you know, there's copilots and so on that have come out of that, that that can help.
But I think AI is also, um, going to fundamentally create some automation that was impossible, uh, five years ago. And so, so there's, there's, there's pluses and minuses. I think overall, there's, there's a lot more, there's a lot more pluses.
I think we'll be able to take a lot of what's manual today in identity management and identity governance, and we'll be able to entrust that to, um, to ai. Um, not AI that is completely left to go off and do its own thing, but AI that collaborates with humans and, but does all the grunt work, right? And that's, that's, that's awesome.
And won't each of those AI agents that's assigned something have an identity there? What needs to be managed? Of course.
Of course. And that's what I said, that's, uh, that's the, the, one of the negatives that now there's more, more identities to be, to be managed, more entitlements to be managed. So, um, you know, um, that is certainly part of, part of the equation.
Have you given any thought to how many identities each of us has? Because I was just thinking about it before this call, and I was sorting it in my head, and it's like, so I have multiple roles and arguably multiple personalities for different jobs and functions, and each of those has an identity attached to them. So does the average individual, when you start thinking about it, have, I don't know, 10 hundreds of identities?
I I think you have to kind of separate, um, the, uh, consumer identity of a person from, from the business identity, right? So from a business standpoint, an organization really needs to be able to think about an employee or a contractor as having a single identity. 'cause that identity sort of represents the relationship that that individual has with the organization, the business relationship with the organization.
And then that identity might have 5,000 thousand different accounts in the organization, right? And so that identity, um, you know, your identity, uh, you have an identity, but then if you're using Salesforce in the organization, you have an account inside Salesforce. You could think of that as I, as an identity inside Salesforce.
But really it's an account, right? And so what, what businesses are trying to do across the board are essentially correlate all of this account information that they have about people, um, in, um, in the organization, correlate all of those accounts with a single identity, right? And that makes life much easier.
'cause now you can say, okay, what does Mike Baard really have access to across, across the enterprise? And you can say, all right, right. Mike Biard has this title, this is his relationship to the organization, and he has access to 86 applications, and out of them, 30, 30 of them are privileged access, the others are not.
And, and so on right now, that's the business identity. I think consumer identity, it's a, it's a little more complicated than that, right? Because, you know, you're dealing with lots of different kinds of businesses out there.
Consumers are doing all kinds of things in their lives. And, and every, every system that they deal with, their bank has one, has an identity, has one notion of their identity, that gym has a different notion of their identity. And even there, over time, what we might find is that, uh, certainly this is true in certain, in some European countries, that there's a, a government issued identity of some sort that, that starts to get used for consumers across the board.
But, uh, that whole area is need, still needs, uh, needs a lot of work. So what's your best advice to folks, or conversely, what are you seeing organizations that have a handle on all this doing well that others should maybe wanna copy or just be aware of? Yeah, so the thing that I think, um, first I think, um, realizing that identity is by its very nature, um, different from a lot of other elements of security.
So it's not just a security tool that someone on a security team works with, uh, by its very nature because it's built into, into all the aspects of a business. There's a lot of stakeholders in identity. Um, you know, people themselves, the employees are stakeholders.
Their supervisors are stakeholders. The application owners in the organization are stakeholders. The data owners in the organization are stakeholders.
The compliance team is their stakeholders. The auditors are stakeholders. So identity needs to be thought of in terms of these different processes that engage multiple stakeholders.
And that is fundamentally different. It's, um, you know, we talk about how identity is becoming the cornerstone of security, and yet it's not like other security tools. You have to think about how you're gonna manage a process that might have, you know, 500 or 50,000 stakeholders, right?
When there's a, to give you an example, if you think of an organization with, um, with 50,000 employees, and that organization for compliance reasons needs to do an access review every quarter. Let's say it's a public company that, uh, has to comply with sox. Now, when an access review happens across 50,000 employees, you know, let's say ballpark five employees to a supervisor, there's 10,000 supervisors who are going to be engaged in that access review, right?
Um, so, but to, to even get that access review off the ground, you need to go bring data from maybe 500 different applications in the company and you need to bring them in, pull all that data together, then reach out to the, you know, all these supervisors and get there, get them to do the access review. So it's a, it's a very process oriented view of, of things. And, and I think organizations that, that are dealing with identity, well get that they realize that, um, they need to think in terms of processes.
Uh, second, I think organizations that are doing it well realize that, um, historically identity teams have been separate from security teams, right? The, the, um, the, the security operations team, for example, doesn't understand identity in most organizations, and the identity team understands these processes and so on, but they don't understand remediation and, uh, response, immediate response to exposures, identity exposures. The organizations that are doing it well are starting to tie identity operations and identity teamwork to security operations.
'cause they realize the, the key tie in between those two, right? So that, that is really important. And then finally, I will say, uh, that the teams, that, the companies that are doing it well are giving identity.
It's due importance in their, in their stack. So they're, they, they're realizing that this is critical and we need to spend money on this. We need to, we need to take it seriously.
We need to track it carefully. We need to monitor it. Well, we need to put as much automation as we can into it.
We need to get the right tools and platforms in place, uh, to make, to make that happen. If by now you haven't figured out that identities by definition are somewhat schizophrenic, you know, it's pretty clear that that's the case. But the funny thing about it is, it seems like the best way to go about managing them all is centrally.
And to figure out some way to put your arms around them all and understand the relationships they have and the dependencies they have with each other. 'cause that is gonna be the secret to cybersecurity success going forward. Hey Deepak, thanks for being on the show.
Of course. Thanks Mike. And back to you guys in the studio.
Welcome back to Textron Unplugged. My name is Cassandra Chen, and today we have Sterling Chen, Not related. Yeah, my last name's also Chen.
So can you introduce yourself? Yeah. So, uh, my name is Sterling and I work for Postman.
Um, I'm a senior developer advocate, but in my career, I've been a developer. I've been a junior engineer all the way up to senior tech lead, moved into engineering management, and, uh, I love everything career, you know, talking about anything around our careers. So you said you have like a passion for mentorships?
I do. Mentorship to me is one of the, is something that I learned early on in my career. I had a great teacher, a great mentor of mine, uh, and if he ever sees this, his name is Andrew, uh, shout out to him.
Uh, he taught me early on that not only how, talking about how important it's to find mentorship, to find a mentor, but also to mentor others. And because of that, at every subsequent company that I've worked for, I have, I have started mentorship programs, both official and unofficial mentorship programs that, you know, bring engineers up to the ranks. There's not enough that happens.
Um, and so I can take any kind of avenue you want with it. Um, you know, I, we can talk about, you know, offic making any official things, um, what we talk about in mentorship programs. But, you know, the, for me, the only way to get into your, um, as you move into your career is to get mentored.
Um, no one else is gonna mentor you. No one's, no one's gonna come to you as a junior engineer and say, Hey, can I mentor you? That doesn't happen.
So you have to take, take your career by the horns and say, I'm gonna go find someone to men. I'm gonna go find someone to mentor me. What is like a mentorship actually?
Like what do you learn? And It's kind of everything. So the way I, the way I like to structure my mentorships is I have a hard, fast role that they're not someone on my team.
Now that sounds a little counterproductive, but if I'm mentoring someone, I don't want them on my team. And that is for a couple reasons. One, I'm assuming that I'm already mentoring people on my team, or I'm already getting, or if I'm a junior, I'm already getting mentored by the rest of my team, right?
I've got senior engineers who are gonna be looking at my code, they're gonna be working with me from on a day-to-day basis. And so they're already gonna know a lot about, a lot about, you know, how I code, why I code or, or, or so on and so forth. So that's my first hard fast rule.
My second rule is that it is an open book. It is completely driven by the mentee. Um, so for me, if I'm being mentored, I'm gonna be asking questions.
I'm a safe place for mentees to come and ask any questions no matter what. And I think that's why I also have that hard, fast rule that it's not on the same team. Because sometimes as a junior engineer, you're a little, you feel a little awkward.
You're like, that may be a stupid question. Or maybe something that you've, you know, a senior engineer on your team has asked, or you've asked the senior engineer multiple times, and you feel kind of, you feel embarrassed to ask that question again. Um, at a, for me, as a mentor, having like, I, I can sit down and say, look, you can ask me any question you want.
You can ask me what the, the quote unquote dumb questions, and know that I'm not going to judge you in any way, shape, or form. I'm here to teach you. I'm here to, uh, I'm here to like, help you get better to that next level.
Um, and so the second, the, the, the second aspect of that is that there's always goals in mind. There's always an outcome goal. What are you trying to get better at?
Are you a frontend engineer? Then? My hope is, as a frontend engineer, I'm gonna be teaching you.
If I'm mentoring you, for instance, I'm gonna be teaching you all the ins and outs of building react components, JavaScript type script, CSS, why you use one thing or another. Why, what's the difference between a four loop and a and a while loop? You know, when to use them, when to, you know, when to use if, you know, uh, switch, switch case statements.
So I see that as a teaching moment. Um, and I take that very seriously. So that was the third, the third part of it.
Uh, the second one or the fourth, I'm switching up my numbers here. I think I'm at, I'm at four now. Um, I would talk about is having a regular meeting every week or every other week, and having it for at least half an hour, 45 minutes.
Um, it gives you enough time to come in, ask questions, um, but then it also is not enough, not long enough that you're, you know, I'm breaking into like, momentum somewhere else. So oftentimes it's afternoons because most of your meetings are in the mornings. Um, so that's, yeah.
Kinda the structure. Do you learn from being a mentor yourself? Oh, 100%.
It's why. So the, the next avenue, I, I would, we were gonna go, and I love that you asked me. That is the moment I find someone to mentor my, so my initial mentor, Andrew, within two months, and I was a junior engineer at the time, so I had no idea what the heck I was doing.
He came in and said, okay, Sterling, I've mentored you for two months now. You need to go and find a mentee. I asked him like, what the heck are you talking about?
I am in no way positioned to mentor someone else. And he said, no, every time you teach somebody, every time you teach someone a new skill, you yourself are solidifying it and learning it yourself. So, how we did it in, in my mentor pro, or, or how we mentored in that case is Andrew would teach me, and that I would teach the pre the people I was mentoring.
And so he would talk about regex. He'd go, okay, we're gonna, this week we're gonna focus on regex. If there was, if I had other questions, he would obviously, um, you know, you, I could ask them at that point, but sometimes he had come up with say, Hey, we're gonna focus on RegX, or we're gonna focus on a skill that you haven't yet mastered.
And then the, the goal at that point was, after he taught me about RegX, my job was not to go teach my mentees about RegX. And he goes, that, that act of teaching, it solidifies the skills and the knowledge in your head, because now I have to be ready to answer those questions that I was just doing a week ago, asking those same questions to him. So absolutely, mentoring is a learning experience for both.
And like, where can you find a mentorship or be a mentee? So if, if you're at one of my companies that I've worked for, I built, uh, and integrated like full on mentorship programs within the companies. If not, I would go and actually seek out mentorship.
Uh, I would find someone that you respect. So if you're at a company and you're on a, you're on a dev team, I would immediately go find someone within the company that you, that you respect, and just ask them straight up, will you, Ben, will you mentor me? I'm looking for a mentor to someone, someone to teach me, you know, JavaScript, someone to get me to that next level.
Um, if you're brand new in the career and have, don't, and, and you're looking for jobs, the next best place is to start going to meetups, dev meetups, anywhere you go, there's always gonna be teachers and students. There, there are gonna be people who are in their careers, who are trying to pay it forward and, and give, you know, give back to the community. And there's gonna be people who are there trying to learn from the community.
So that's another great resource to, uh, find mentorship. 10 Developers of all skill levels benefit from this 100% every skill level. If you're a senior engineer, you should be finding a mentor who's someone who's a staff architect, however, you know, whatever the next level is at your company.
Um, or you could be doing, like having, being mentored by an engineering manager if you think you want to go into management. It. So every le every step of your career.
Right now, I'm in, I'm a senior developer advocate, and I have an active mentor, someone who's not at my company, someone that I've worked with in the past. And I said, and, and I respected that. I've seen what they've done.
I said, I'm still asking. I still have questions. I'm still learning.
Will you teach me? Um, and so I'm always on that, on that note, I'm also always actively looking for people to mentor, because I think it's, it's just such a skill that, and so beneficial to everybody. I think that's really good that like, we're still learning Always.
I mean, my parents were teachers. Um, so I grew up in an educator's home, and life is, my dad always told me, life is the life is your classroom, or the world is your classroom life is your teacher. And so I take that into everything.
Always be learning. There's always something, someone, it doesn't matter who you are, even if I'm a junior, if, if I'm a senior engineer, or when I was a senior engineer, for instance, I learned from my junior engineers on a regular basis. They had life experiences that I didn't have.
And so they would approach problems in novel ways that I didn't, I didn't look at. Um, so it, it, like I said, you're, I'm always learning. There's always, there's always something to learn from somebody else.
So you kind of combined your technology passions and like teaching. Yes, absolutely. Have you always been passionate about technology?
Yes. Um, I, I wish I was a little bit more passionate earlier on, uh, in my career. So my career path is a little different.
Coming into tech, I spent, uh, 15 years in construction, in transportation logistics. So I was not doing tech. Um, when I was a kid, my, I was always been big into video games.
I'd take my computer apart, I would try to do soldering, I would do all these things. Um, my dad had tried to get me into doing a CS degree when I was in college, and I said, no, I wish I had. Um, but, uh, a few years back, I decided to go into, go back to school and become a software engineer.
And at that point, I started to really, so I was able to combine my love of teaching into a passion of, into the passion that they now have, or a continued growth of passion into technology. What do you do today as a job? I'm a senior developer advocate, which means I get to, I get to come to conferences, talk.
Uh, I, in this case, I get to speak at conferences, talk about my experiences, share at a, on a larger scale, uh, mentor from the podium. So it's still related to mentoring. Yes, I still, I take every one, every time I, every time I speak, um, whether it's on stage at a conference or whether it's at within a demo at at work, um, or whatever, I try to instill some type of mentorship in there.
Sometimes it, I, I just, I'm always a teacher. I'm always gonna be a teacher. Uh, so it kind of, it kind of fits in.
Um, will you write your demos for work? Like is there some form of mentorship in that? Yeah, so when I'm demoing, I also look at it.
I was, I worked on a product, uh, on a product team that built an ai, uh, assistant that said a postman. And at that point, I was also having to teach mentor sales, the customer service department, like the customer success teams. Uh, the rest of the field team, uh, talked to Derel at the time, I was, I was demoing these new products to the rest of the organization, and I had to be ready to answer all of their questions.
So that was a really perfect, like, so even those demos are a perfect opportunity to mentor and talk to others. I think that's interesting how mentorships really ex extend everywhere. Yeah, I find it, I find mentorship, again, key to my success, key to anyone is who's coming into this industry key to anyone who's, I mean, doesn't even have to be in tech.
Find someone who's better at you in some way and ask to have them mentor you. That's how you'll learn. There are, you know, in my, in my, the way I look at it, there's no stupid questions.
That's a very teacher mentor type of thing to say, but I don't find that there are any stupid questions out there. You just have to find someone who's willing to answer those questions for you. That's really inspirational.
Thank you. So thank you today, Sterling, It was a pleasure. Thanks for having me.
This is Textron tv. Hello, and welcome to another episode of The Inevitability Curve. As always, I am your host, Chris Blak.
I'll have an interesting guest with me today, as hopefully we always do. And we'll pick a topic and look back where we've been, how did we get to where we are right now? What does now even look like?
You know, what is today? What's the space that we're currently existing in? And with that, perhaps, what are the range of possibilities going forward?
And joining me today is a very good friend and sort of constant working partner these days. Phil Engler. Phil, how are you?
I'm doing well, Chris, and thanks for having me on your episode. Couldn't be happier. So for everybody else's background, so you can see in the, uh, Phil's title, Phil is the, uh, VP of Medical Device Security, I believe, right title with the Healthcare isec.
There's Healthcare Information Sharing and Analysis Center. And this is a, a group of organizations that, uh, centered around the, the need to have a US public, public-private, uh, facility to share threat intelligence, vulnerability information around the, I think currently, I believe 16 critical sectors as we define them here in the us. So the healthcare ISAC is, has been around, oh, probably 30 years since now almost, well, since 2010, right?
We were formed in 2010. The Health ISAC is a member driven organization, you know, that specifically fosters the sharing of InfoSec information across the entire healthcare sector, whether it's medical device manufacturers, large pharma, healthcare providers, academic medical centers, health information exchanges, uh, and the like. So, um, if you have a role in patient care, you know, either as a precursor as in medical device manufacturers or in direct patient care, or even managing, you know, the transactions that, that support patient care through insurance, uh, and health information exchanges and, and elements like that, they're eligible for membership.
Uh, we are about 900 organizations globally, uh, representing almost 12,000, um, individuals, uh, in those 900 organizations. So we like to say you, we've got 12,000 analysts working for you. Good explanation.
And lemme little bit of background. So permanently, so there was the industrial control system isac, which is currently you, uh, dormant, you know, uh, uh, or defunct or whatnot. But I led that with a gentleman by the name of Sean McGirk who created the ICS cert and the end kicked, you know, some of the functions inside the Oath, federal government, and left, you know, to, to work with the private sector on that sort of information sharing.
And it's been a very interesting path. The isac, we'll get into this in the, in the discussion, but the ISACs were basically kicked off in the late nineties. You by a, you know, US federal government recognition and working in the private sector to get, to get this going, um, these days, normally in these, in these, this series, I don't talk about my other day jobs, but I am vice president of strategy for side beats.
That is a software bill of materials and SCOM management, uh, vendor company. Um, so, and that's gonna be part of our topic here. So just for transparency, everybody knows what my interests are, and SBE and Healthcare, healthcare ISAC have been partnering, you know, to help get supply chain information flowing through this ISAC infrastructure.
And which is more of the, the topic I think for today. You and I have been working for the last, uh, well over the last couple years, but know this, this calendar year has been interesting working with the Department of Homeland Security Cybersecurity and the infrastructure security agency, where we call it, we, we, uh, pronounce cisa. Um, we've been running a, a set of tiger teams set of working groups where we work with our peers in the industry and, and then the US public sector to try to solve certain, certain issues.
And in that path, over the last couple years, there's been, uh, a couple interesting documents. The information sharing side of this, you know, with my ISAC background, I come into SBOs and supply chains of the same sort of thing, same sort of concerns, same sort of mechanisms, um, and thinking we can leverage those and, and the artifacts we had to work with now mentioned two specific documents that people can look up if you like. gov/sbo, om SBOM, and there is a, uh, SBO m sharing, um, lifecycle report that defines discovery, access and transport, which turns out to be important in the process of sharing, uh, the sensitive supply chain information.
There's a SBO m sharing roles and considerations document that a, a working group, uh, that I was, uh, in last year produced that looks at, you know, the author of an SBO m the consumer of an sbo. And more to our point here, uh, the distributor, the people in the middle, you know, how do I facilitate access to this information for a perfect example as an isac, you know, for my stakeholders and constituents. And we cycled through putting a process together this summer, and now we're cycling through other information sharing centers to see if we can help them move forward, which plays exactly to everything we're talking about today.
So, that's a very long intro to say that we're, we're gonna be talking about information sharing and threat intelligence sharing, and how we've gotten to where we are today, you know, what today looks like and what we can perhaps expect. Sure, sure. Yeah.
And just, you know, to provide a little bit of, uh, historical context, right? Especially around healthcare. Um, in December of 2022, the omnibus bill got passed.
It included, uh, a large portion of the patch Act, which gave the FDA statutory authority for, uh, cybersecurity of medical devices. So this was a huge change. Prior to that, the FDA only had statutory authority only safety over safety.
And since, you know, we know that there's an intersection of safety and security, right? But it's a Venn diagram, and sometimes the van is a little gray as to exactly how those impacts are, because they're not always direct. Uh, and with cybersecurity, it's, and particularly in medical devices, it's not always obvious, right?
So in that it precluded or included the, the, the need for medical device manufacturers to provide to regulatory agent the FDA, the regulatory agency in a submission that an SOMB provided. So the sub-asset of a medical device be identified and declared, and also the threats to the device itself, as well as the risk assessments of the components chose, chosen to provide the clinical functionality needs to be addressed and mitigated to a controlled state, right? Um, so there's uncontrolled and controlled state, meaning that it can be managed through either patches, compensating controls, uh, other elements in place, um, and it does not propose a safety risk to patients or patient populations or staff.
So those, so that element was a game changer here. And so when that happened, the Health ISAC saw an opportunity as a trusted, uh, source and a trusted venue of security information exchange to extend that to the SBOs and other security artifacts. So what we set up was with, uh, the cooperation of, of CY Beats, um, we identified a tool that would allow manufacturers to, uh, produce, assemble, and prepare for distribution, uh, SBOs, and then make those available to healthcare providers.
And not just member healthcare providers, but any healthcare provider because, you know, um, not every member, um, or not every healthcare entity is a member of Health isac, but we didn't want to preclude the opportunity to distribute, you know, critical, um, information to those entities. So we're sharing from member healthcare organizations to healthcare delivery organizations, and, you know, the policies that led to that, you know, like, to start with that, because I think it's a, a linear sort of thing, right? You know, I, from, it's now, you know, some are smacking around 30 years, you know, that I've been asked by journalists, you know, you know, what about this and that, you know, quite often it's what about this, you know, latest US federal government move or legislation or statement or whatever it is.
And I found over the years that I can honestly answer is kind of following the evolutionary path that I would've reasonably expected, right? You know, stucks net, you know, when the, when the, uh, uh, first operational technology cyber attack, you know, against in, you know, critical infrastructure happened in this case, you know, a nuclear enrichment facility in the tans around 2010, you know, the activity probably started around 2006. And, uh, I was, uh, a French pressed journalist, uh, contacted me and tried really hard to gimme, say, you know, you're living in a glass house throwing stones.
And my answer is like, anybody that didn't think that right about now in the nation state level, you know, that's the sort of thing you should worry about, or, you know, pro or con, you know, defend against you or use as a, as a tool of statecraft is missing the point, right? And this, what you just said about policy and supply chain, I think is a good, another good example. You know, it's easy for us to say that should have been in place in 1979.
It's like, no, I mean, there's no way to explain to the stakeholders, the legislators that you know, their voters why we need to spend any time and, you know, and what the answer is. Um, but now we have to, you know, we we're getting to the point where we can't keep, for example, the healthcare infrastructure working without that sort of timely, transparent, you know, trusted, um, uh, uh, pathways. So, so let me back to the policy parts, right?
So there's the, there's, correct me this, when I always get this wrong. There was a presidential directive in 1996 or 1998 that started of the isac, uh, I think 96 96, but don't quote on that. And that said, and to, to the point that I'm trying to get to here, the interesting thing to me in that of everything else was that it, what it said, there shall be an singular information sharing analysis center, and there immediately you as, as we discussed, turned out there's a bunch of different sectors, and having multiple ISACs focusing on different things turned to be better.
And in fact, the National Infrastructure Protection Plan, you know, the whole structure that the US federal government uses to deal with all of this was built around that experience by that taking a step moving forward. So there should be one and learning immediately, oh, okay, there should be bunches. And we're still on that path today, leading to exactly what you just said, that in this environment, you know, federal agencies like the FDA can take logical steps that make sense, you know, and, and, you know, require those or provide the opportunities for organizations like ISAC to say, you're right, we can do that and lines up with our goals and motivations.
It's kind of optimistic. We actually got it that, right? It is os optimistic, you know, and, and, um, there's the healthcare Sector Coordinating Council, which really is a public-private government, uh, uh, collaboration to, to look at things more at a, at a high level policy level, if you will.
Um, and one of their, uh, mantras, you know, is to beat one of us, you must beat all of us. So we know that together we are stronger. If, if a bad actor is attacking, you know, one member of our, of our organization, and that information is shared, those IOCs are shared out right to other members, then they can ingest those into their detect and response capabilities in their own environments, right?
And be much better prepared to thwart or respond and minimize the damages. So, you know, the concept of, you know, each of us watching out for each other and helping each other and, um, sharing the information, you know, willingly, we share it, uh, in, in the sticks and taxi protocol, right? There is a bit of safe harbor protection that information shared in the ISACs is, you know, um, can't be used against the agencies, right?
That, that share that information. And that's a very important point because it's one of the reasons that we thought, you know, now let's share these SBOs and other security artifacts between the manufacturers and the healthcare providers that operate them. And having, you know, that, that we can share this, we share it under with an understanding, you know, that it's not public information that is controlled information, you know, that it's to be used, you know, in its attendant purpose and not, uh, put out in the public space, you know, but really to, with the goal of increasing the resilience of, in the entire healthcare sector, and it's those sorts of practical applications of policies, right?
You know, we in here in the states need to understand, you know, the impact. All these structures we put together, you know, through all our conversations, literally just a bunch of working groups, the sector coordinating councils, as you say, these are people, you know, representing public sector in the A sector, representing the private sector, sitting down repeatedly and having conversations and structuring and figuring out the process. You know, this has a huge impact on the world.
You know, my involvement, you know, in per sector has been more in the electric sector than healthcare over the decades. And I've watched the creation of the NERC sip the acronyms on North American Electric re reliability council, critical infrastructure protection, uh, um, regulations, you know, thou shalt, you know, if you're a regulated US utility, and then do these 13 things, and I've watched those evolved, and I've used that with, you know, some of our friends who help create that to help other nation states put together similar structures. You know, they may have four sectors instead of 16 or do things one way or the other, but we keep creating repeatable structures where trusted information can be shared, which in our professional lives is a, is a empirical thing.
And in, you know, as we all understand in the public sphere right now, there's a lot of angst about, right. You know, how do we, how can we really know what's real? Well, examples, isec, all these different interests, public sector and private sector and non-profit and for-profit and consumers and distributors can all get down and literally trust each other enough to handle sensitive information and reliable ways that addresses everybody's concerns.
Wow. Yeah. It's, it's, that's an important point, right?
It's, it's the ability to share information and not only security information. You know, when you know new technologies come out, you know, we are talking about, you know, like chat GTP or, or AI or, or, or elements like that. What are the policies?
What are the constraints? What are the risks of using, you know, chat TPP, you know, and other, uh, artificial intelligence engines in the healthcare environment, you know, knowing that they have great promise to build inefficiencies and, and provide benefits of patient care, but they're not without risks, you know, knowing that AI is, you know, designed to provide an answer, though, not necessarily the correct answer or even the truth, right? So that's a risk in that technology.
Um, caregivers may not understand that non-technical people, you know, that are more focused on biology and chemistry and not on electron flow and ones and zeros may not quite understand the nuances of that. So bringing the entire organizations together, right, having these discussions, sharing this information, you know, helping people get, you know, to where they need to be faster, you know, by doing it collectively. And, and working cooperatively is a powerful way, you know, that we enrich the, uh, member organizations, you know, we have 24, I think currently different working groups, you know, one of them is the medical Device Security council, where we're the only group in the world that brings manufacturers and healthcare providers to the table to talk about how do we secure the medical device, you know, environment from concepts from the r and d through delivery, you know, uh, configuration integration, you know, maintenance and monitoring, you know, and, and remediation and response while it's in, you know, the healthcare environment.
How do we take maybe 1200 different models makes and models of equipment and stick them into a single organization's network, you know, that have endpoints counted in the tens, if not hundreds of thousands, you know, and then manage the interoperability so that we're, we're trusting the information and utilizing the information to improve patient outcomes. You know, and I say that, and I, and it's, you know, I go back to accountable care, which incentivized healthcare to generate the data to show that the outcomes they're delivering today are better than the outcomes they were delivering yesterday. And that kind of pushed the whole interoperability.
We were taking devices that were basically pneumatic or mechanical devices and putting electronic sensors in them, and then creating this, these data sets, which we could then analyze, you know, what was happening on the device, what were the treatments, what were the utilizations, what kind of protocols did we use for scanning, you know, and taking images, creating diagnostic imaging, and then turning that into, and looking at studying that, using scientific analysis to determine, you know, can we impact patient care in a positive way? It's a wonderful opportunity. It's why I've been in this business for 35 plus years, you know, because it's amazing every single day, you know?
But as we've, as we've put this information in and created these large data sets, at the same time, we painted a target on our back. And because healthcare is a very emotional business, you know, we don't care. It's my son, my daughter, my mother, I don't care what it costs.
We'll figure that out later. That's, you know, sometimes risk management gets thrown out the window when you are thrown into or drawn into the healthcare sector. And so finding that balance between the promise, you know, of improved care and reducing managing the risks, and the, you know, if, if, uh, if we were to go back to the IT folks that we're often seen as barriers to innovation because of the cybersecurity risks, you know, um, and that friction, uh, we are now beginning to deal with as an industry, we've learned how to have these strong conversations.
We've brought cybersecurity to the board, and they understand the risks that are there. Healthcare still pays enormously change. Health paid a $20 million ra uh, ransom, you know, within a few weeks of being, of, of being ransom, which is unbelievable.
If we go back to 2019, I believe it was when Presbyterian, um, hell or, um, yeah, pres, not Presbyterian, but the, uh, large healthcare system in LA that got hit in urban, you know, they paid, I think, $17,000 in, in ransom. You know, so, so the opportunity for criminals to, to make money in healthcare is very real. It's very rapid.
Um, and so we continue to be a, a target, uh, for that. They say that healthcare is much weaker than, you know, much less protected than other industries. I think a couple of things might contribute to this perception, and I'm not sure that I've seen empirical data that it actually is, but because of the breadth and depth of technology that we have, the breadth of relationships that we have with all these different organizations, you know, just create more opportunities for bad actors to find weaknesses within any system, uh, there and exploit those.
So it's important for us to, you know, think about these, um, these systems, uh, in a holistic fashion, but because of the depth and breadth of technologies, the span of relationships that we develop to de to deliver healthcare, you know, from the acute care centers, you know, to, you know, the laboratories that do special clinical diagnostics to the imaging centers, to the surgical centers that all operate out, that right down to primary care providers, that, that are the first point of entry, you know, to, you know, the therapy centers that you see afterwards, you know, that, that help you go, so help you, uh, finish your treatment regimen, right? All of these connections create, you know, a, a increase, I guess, our threat surface, right? And we need to think about that.
Sharing security information is one way to help organizations really, you know, drive focus on what's real, what's, um, what needs to be, what are the, what creates the largest risk for those organizations, and help them, you know, to deliver the, the protections that are necessary to, to reduce those risks. And this, you know, we're, we're at that point in the conversation to look at the future. And I think this is a, a, a perfect crux, right?
Because in the early nineties when I was getting involved with security and then critical infrastructure, you know, I, I found, I really liked working in, you know, what we call operational technology, OT now, right? And you start looking at the sectors and, you know, I've worked with nuclear power, security and everything else. How, how extreme do you want to get, right?
And things are what they are. And if you wanna deal, you know, start in the early nineties dealing with nuclear plant cybersecurity, you're first gonna deal with how are we doing it now, right? And it turns out there's a lot of good lessons in that, right?
But healthcare, I, I can, like, as you're talking, I'm trying to remind me of a conversation. I can almost remember exactly what it was, but it was 1992 for sure the first time. I'm like, yeah, but your healthcare, which means that the critical infrastructure, you're literally plugging into human beings, not just a generator or a power turbine or a, you know, a a maritime, uh, system.
And you use terms like teaching hospitals. So you have a university and the infrastructure mixed all together so that the, you know, universities are, are classic hives of hackers, right? You know, just a very curious bunch young folks.
So we take the most critical thing from a human perspective and mix it with the most hard, you know, and then the networks are mixed up and everything's connected and all along, you know, this is among honestly, my earliest inevitability curve thoughts. It's like, well, someday we address all that. Someday we can do not only the things you just said, but take that to 11, right?
That that device in, you know, connected to inside that patient is in real time acting on and trusting information that it's getting not just from a second party, but a 15th party through 17 different connections. And it still works. And we can do that because we will find ways to build the trust, you know, and we'll take as long as it takes, a lot of it will be humans, right?
Be building trust with actual organizations and comparing that to how we're doing things already. And based on that, taking a step forward. So what do you think this tells us about the, the, the future?
You know, what do you think the next ticket timeframe you want 10, 20, 30, 300 years? Where are we going? So the, you know, the technology will only continue to advance, right?
Um, every seven years, I forget the principle, right? That says at it doubles every seven years, right? Like, so many things, um, we know the promise of improved care.
You know, the, the capability to utilize, you know, adaptive learning, machine learning, AI to help evaluate information passed along, um, uh, and shape care delivery is going to be real. And that means more data, right? And so that means more devices that can be, you know, connected to a network, right?
Um, with the patch Act and the other requirements in there that new technology be delivered, you know, be developed in a safe, you know, um, or a secure development framework, that there is a mechanism in place to monitor the health of the components after a device is put into the market, and to develop patches and, uh, updates to keep those devices cyber secure. You know, the FDA has said, you know, um, and, and I don't think this is their quote, but, but engineering is about making sure that certain things happen, and cybersecurity is about making sure certain things don't, right? And so that's an important concept, right?
The ability to build in detection, the ability to have a device that fails safely, you know, so that it doesn't, if it is compromised, right? That it doesn't lose the data that it has, that it doesn't, that it can't do something it's not supposed to do. You know, and you made a very important point, right?
That, you know, iot is iot, the difference between i, OT and traditional computing is that it does interact with the environment that it can either sense the environment or act upon it, right? And whether that's creating energy from, from nuclear fusion, you know, uh, controlling, you know, uh, floodplains through dams, whether that's distributing power, distributing people through the airline industry, distributing produce or, or products through transportation, you know, or delivering healthcare, right? In healthcare, the environment is very often the patient themselves, right?
So that's people, and again, there's that emotional aspect that, that, that doesn't exist in some other, uh, industries. So we have a couple of things, right? Um, you know, we need to be, get better about sharing information, right?
We have to think that, that, uh, you know, stop thinking that if I, if I give somebody my sbo, you know, the hackers will get it, and then they'll know what's in my device, and they'll be able to, you know, tell or find exploits in that, right? So there's two things that have to happen. One, we have to build devices that have fewer vulnerabilities, right?
Meaning that we make better selection of components that we, that we select components that have a longer life, support life in them as we're building and, and delivering these products into market, that we understand where the risks lie, and we're honest with ourselves, we're honest with our customers about where those risks are, you know, so that we can under, you know, evaluate those risks, determine whether we're okay with them, right? We're, we are all, we do risk assessment every day. Uh, we cross the street, it's a risk assessment.
I turn left, you know, can I cross? Yes, I'm good to go. No cards coming, coming.
I'm not. That's a risk assessment. Doctors do risk assessments every day, right?
They, a patient comes in, they present with symptoms, uh, uh, a physician, you know, will consider what are the treatments that are available? And what they want to do is, is select the one that provides the best outcome. Not necessarily to make you wholly health, but give you the best outcome with the least downside, right?
That's risk management. That's what we do in healthcare. And so it requires information to do that.
So sharing, you know, SBOs freely amongst, you know, the, the makers of the devices and the users of the devices only allows the users to a understand, you know, what is the density of certain components in my environment? Where are they, how do they interact with what's critical in order for me to provide healthcare? Not all vulnerabilities, you know, are the same, have the same risk, have that they may not really impact the functionality of a device device, even if they were exploited.
Uh, and, you know, there are devices that don't have, uh, an equal weight in producing the healthcare outcome. You know, you can replace, you know, a, a bear hugger with blankets that come out of a warming cabinet if you want to control a patient's temperature. So there's, there's methods that we can use to, to get around things that may not be cyber connected, uh, to that.
And so it's important for organizations to understand, a, what their critical devices are for delivering the mission, right? And then what are the risks within those critical components of mission delivery? And then having plans to respond and recover from those gracefully so that they can get back to the business of mission delivery.
You know, should there be an interruption? And it doesn't matter whether that interruption is cyber related, a bad actor or physical, you know, as in a component failure. You know, we still have to think, if this goes down, what does it do to my ability to do my job?
And how am I gonna get around it until I can get back to doing it correctly? Very well said. And I would love to keep saying things with you all day long, and I wish we had, uh, more time for this, but for the, the exigencies of, uh, content creation, we should probably, uh, find an end to this now.
So, just wanna thank you for all your time, you know, for your time today, you helping people understand these things and, you know, have some clarity and some hope for the future. And, and all the work, you know, you and I have done together, I think makes the world a better place. It's, well, I appreciate our, uh, collaboration, Chris.
It's been enlightening for me. Um, I'm a clinical engineer. I fixed medical devices.
Cyber is my second skill. It's my second language, if you will. And so leaning into experts like yourself has been super beneficial.
So appreciate that. Thank you. And thank all of you out in the world, you know, for spending your time with us today.
Remember to be kind to yourselves, be nice to people around you, and look forward to seeing you again in the continually wonderful future. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com, home of security bloggers network.
Good morning, everyone. We are back in 2025, and we are at episode number 66 for infrastructure matters. I'm here with my buds, Keith Townsend and Dan Hinchcliffe.
Welcome to the, the New Year. Um, and usually this week is kind of quiet, but it seems like, uh, some people decided to throw some things up in the wall and, you know, and, and, um, and not to mention, you know, in a call out to our friends in California that are dealing with what they're dealing with, um, which is, uh, very, very tragic. Um, but we're gonna kind of pivot over here to the technology side of the house and give you guys a break from watching out what's going on with the fires, et cetera.
So with that, um, anybody get some skiing in or any fun stuff over the holidays? Just family. Just family.
Yeah, I didn't get any skiing. I did bring in the new year and camping. We went, uh, we, we, we amped a, a little bit.
So, uh, that's not a bad way to bring in New Year Back in t in Tennessee, Back in t, good old horn wall, Tennessee. Well, I can't say I gotta work on my accent. I can't, I can't say I amped.
I did the, uh, back did camp and, uh, tent camp and et cetera, and biked, and hiked in a death valley. If you haven't been there, a fabulous place to go, especially at Christmas time when it's weather is good. Very, very good.
Good. So we are going to, we are gonna go into, um, this week big show in Vegas, um, right off the New Year is CES Consumer Electronics Show. Um, and usually this is not part of the data center infrastructure kind of guys, but nowadays it is, um, because so much of what we deliver as services, et cetera, is through these kind of devices, et cetera.
So it's now kind of all blending in. And, and J's got a whole lot to talk about, especially with what, how Nvidia stole the show there again. That's right.
Well, and, and while none of us were there, we all, uh, we, we did have, uh, folks who were there, including our CEO, Daniel Newman, um, who met, who met, I believe, with Jensen. Uh, it was, um, amazing show. Uh, he had, uh, a whole rat announce announcements.
Some of 'em were consumer, uh, and not really related to this show, uh, but unusually for CES, uh, there were some absolutely, you know, very, very much enterprise relevant announcements. Uh, the first significant one was Project Digits. It's a personal AI supercomputer, uh, that has a thousand times the power of a regular laptop.
Uh, and it's powered by the new Grace Hopper chip. Um, and it's gonna be, you're gonna see it in data centers. There was already people stacking 'em up, um, uh, as high as they could go high, they could get 'em before they, you know, started to melt.
Uh, the, just the, the compute density of this thing, and it's not really rack mountable, uh, but it, it's the fastest way to get a big model running anywhere you want it, anywhere you wanna put it. Uh, almost the biggest model you can think of. It'll run.
And it's about the size of a, of, uh, of the new, um, uh, apple, uh, Mac Mini. So it's very small, intense compute density. Um, you'll see it, um, really helping development shops, uh, and people actually operationally run some ai.
Uh, it's, it's, uh, and the price point, it's $3,000, so it's for a thousand times more power than you can on a regular, uh, laptop. So that was pretty cool. But that was not, uh, super enterprisey, although you will see it absolutely, uh, in data centers and in, um, businesses around the world, in my opinion.
Uh, but, uh, Jensen came out with a full size wafer, uh, showing that the GB 200, um, the data center super Tripp, that has 72 Blackwell GPUs on it really exists. It's in production. They, uh, he, he was walking around on stage with this single wafer that have 72 interconnected Blackwell, GPUs, uh, that will form a basis of their, of their massive compute.
If you want to go all Nvidia and get the, the biggest configuration that they have, you get stacks of this, the, the, this giant wafer with 72 Blackwell. So I see wafer that's like this big, or whatever it is, and you're say there's 72. That's big.
It's like, it's like three feet across the biggest wafer I've ever seen. Uh, and on it is the, is is 72 connected blackwells. They, they were actually, they were made that way on the wafer, on the wafer con interconnect.
So they're gonna put this in one computer then? Yeah, like a mainframe. Yeah, The main AI mainframe, I think IBM m ai mainframe, yeah.
IBM has something to say about, uh, AI mainframes. So, you know, to help give some perspective here, the digits is a, is one, uh, Blackwell chip, basically. Uh, and that one Blackwell chip has, uh, a, uh, p floop of compute capability up to FP four with the FP four standard.
That enables you, so what kind of real work that means that it can comfortably handle a 200, build a 200 million parameter model, a intel CPU type deal, uh, goes up to about, uh, I'm sorry, 200 billion parameter model A, Intel CPU will handle about a 75 billion parameter model. So you, this GP 272 times that raw compute performance. So the networking, the memory, everything that needs to be done to kind of, to to scale that out on a waiver.
There's some pretty good Computer science. So way back when, if we're gonna go talk about the mainframe again, of course I will. Um, some analysts made this huge prediction of how many mainframes would be sold.
I think it was something less than 20, maybe it's 15 or something. Who the heck is gonna buy this? But, and I'm not, I'm not gonna say they're only gonna sell 15 of them, but, so this is, this will be used for the, the languages, the largest language.
Yeah. This is, this is all still just training. So there's a question, we'll, we'll get to our predictions over the next few weeks, but I, I do have a prediction around kind of where AI is going in the enterprise.
Enterprise teams are not going to do massive training. They'll do retraining. This is for the hyperscalers, the Facebook, the matters of the world, the, uh, all these companies, uh, uh, grok.
Uh, so Z And Microsoft has already, uh, announced they have Blackwell in the data center. And you can, you can get special instances. You can, you can specially select that.
And this chip is intended for those massive installations. Microsoft just this week announced at $80 billion in CapEx. They're gonna invest this year in 2025 in their data centers.
And of course, a lot of that spend will be exactly on this particular chip. So it does bring up questions around that we've talked about over the past 2024 around heating cooling, so power cooling, and how do you keep these things cool. That that is going to be one of the biggest problems.
And of course, how are you going to power them? We, we don't have enough power now. It's going to take, you know, four to five years of bring on new nuclear reactors.
Uh, companies are buying, like Microsoft are buying coal reactors and putting their data centers next to these coal reactors and taking up all the power from those reactors. It, it's, it's fascinating arms race around ai. Wow.
But I mean, just as kind of like, even, I, I, I'll need to go online and take a look at it stuff because I missed it kind of this week. And like, I wanna see this chip, or you can't even call it chip. Can you really call that thing a chip if it's like, It's so three feet wide chip wafer.
It's a wafer. It's a big, huge mess of wafer. Wow.
Okay. Yes. What else Can, oh, and finally they announced n we announced, uh, uh, cosmos.
It's their new AI friendly world model. Um, what, what, uh, a lot of these large language models, they don't really have a good model of the world. Um, they can make a lot of inferences that, that are trained up on a lot of incidental information about how the world works.
But there's, um, uh, consequently a real need for world models. And it's supposed to be the most enterprise ready, capable way. So you can build true AI powered digital twins that understand all the physics and all the geometries and everything all about the world.
Uh, they had, they had some pretty cool demonstrations of, uh, of AI wandering around inside Cosmos, um, interacting with that world as if they were in the real world. It was pretty cool. I, I don't see that with Elastic.
We'll see that in a lot of simulation, r and d manufacturing, healthcare, things like that. When we get to those world models, I'm assuming that we're gonna need these, uh, wafers. Yes.
Yeah. All they consume massive amounts of power. Well, yes.
Yeah. It, it, it, it's a leading credence that maybe we are in a simulation 'cause we're building equipment that can run simulations. So it is hilarious.
This is, this is amazing time to be in technology. It really is. It's amazing.
Well, on the flip side of all this technology that we're building, and the, the things that NVIDIA's doing, there are some new, and we are, you're calling them AI export rules that are potentially coming out or seeing pretty strong coming out from the Biden administration, um, even before we pass over the baton to the Nixon administration. So, um, Dionne, you wanna kind of walk through what's going on, and I understand that there is a massive amount of conversation on this because it's giving some huge angst to companies. It, it really is.
So the Biden administration has proposed something called the export control framework for artificial intelligence diffusion. And the intent is, is ostensibly a good one, which is to prevent very powerful AI to getting into the hands of our enemies and being used against us. Um, and the, um, uh, however, uh, companies like Oracle, um, uh, have come out very publicly, uh, against it, uh, saying, uh, I quote, uh, it is one of the most destructive, uh, rules to ever hit US technology industry.
And, uh, they warned a few weeks ago, uh, but now it looks like it, it is gone through the interim final rule stage. Um, it is not public. I can cannot get access to this because of how, how it's supposed to be enforced is highly secret.
Um, and so it's one to watch, uh, the, the, um, the Semiconductor Industry Association ha had didn't come out swinging so hard as Oracle, but is very much against it. Uh, and the prediction is that it would reduce, uh, GPU sales in the United States about the 80%. Um, and you know, I think some of that is debatable.
Uh, the, the thing is we, it's just because we, it's hard to tell, it's hard to understand what is in, in it and how it works. It's hard to judge it, but it's, it's basically what the government did with cryptography way back in the days so that our enemies couldn't, you know, keep their secrets from us. Um, uh, and, and this is, this is something similar.
It is like we just keeping very powerful AI out of the hands of our animation. So, um, it's unclear if what will happen if, uh, you know, if it will make it to, to actual official enforcement, uh, before the new administration comes in, who very, very well, you know, uh, you know, get rid of it after that. But anyway, it was the very much, the topic of, uh, discussion this week in semiconductor and in AI circles, uh, is it's kind of, you know, it's on the fast track and came out of nowhere.
I mean, no one's really, we haven't been tracking this and this is kind of what we do. Um, so it's very interesting to see what will happen. It's, it's something that, that certainly our infrastructure friends in the industry will have to watch very closely and try to influence to make sure it, it does not, cause it does not, does not overreach in it.
Is this specifically on GPUs or is it on the large language models, or is it, what, what does it cover? The um, so it, it's targeted high risk uses and it restricts users of, uh, very high volume users of GPUs. And, um, so we're, I'm still going through everything that it, it's, it's trying to, it is trying to cons control the quantities of GPUs that are, that come outta the United States.
Um, and it's, it's, it's a little bit less on the models because they're really trying to, it's control the ability to even run the models. Yeah. So this has, uh, been highly debated for quite some time, right?
There's g there's already GPU controls on the, on how, who, who we can export GPUs out of. And China came out with, uh, I forget the name of the model, but that hit the news, uh, last week, what was, uh, a model that works four times faster than I think it was llama or the model that it, that mimics. So the, I think the cat is already out of the bag with, with some of this.
It's a complex question because there's this, um, there's this debate on what controls Congress and the government wants to pass. 'cause I think, uh, there's probably pretty good, if I was to guess, looking at the news around, you know, TikTok, there's probably pretty good bipartisan support for something like this. Uh, the, the government and tech and tech leaders are, are, seem, seem to be at odds at what's best for technology versus what's best for us, uh, national interest, security interest.
Well, and, and what identifies 20, what are called artificial intelligence authorized countries. Uh, and they're the ones that can run, get hardware that can run frontier models. They're the ones that will be able to develop ai.
'cause the concern is even if we keep our models away from them, uh, the, the bad actors, they can still build their own. But what if we take that power away too? And so the, there's only 20 countries that are on that authorized list, and everyone else has very sharply reduced access to any powerful GPUs using this export rule.
And this is coming out of the Department of Commerce? Correct. Because they're the import export folks that are, and um, those, those organizations, It's a very complicated, um, there's a lot of agencies involved in it.
It obviously would've to be commerce, but, uh, well, there's also the Department of Homeland Security, which is sponsor of IT and things like that. So this will probably, yeah, This is the street. This is stopping To watch even from change from administration to administration.
The, uh, the folks in congress are, are not, uh, the friends of technologists right now. Right? Well, it depends.
Fast developing story, Fast developing story and, and what everyone should be watching the tech business. So coming off of the, the current administration area, which I'm gonna try to try, try to stay away from that and everything that's going on. We did have, uh, in my world the data infrastructure world.
There's this company and a lot of people don't know who they are, but DDN data direct, um, networks folks, they've been privately held. They, um, by Alex and Paul, um, very, very, uh, Alex is a very flamboyant Frenchman, I believe he's French. Uh, and, um, they, they've been very darling's in the HPC market.
They have traditionally only focused on HPC market or the r and d market. And with AI coming on board, they have just taken off like crazy. And, and I know from talking to some folks, all they've been doing is pouring money into just ship boxes, which means that's all the inventory and everything else that you're moving.
So they've just taken a $300 million investment from Blackstone, which is a private equity. They're actually publicly traded company if you wanna go look at them. Um, but that brings their valuation to 5 billion, which I think is kind of, seems like that would be a little low, um, when you think about comparison to some of the other guys that have gone up.
But, um, we'll see. I mean, I'm sure what's happening here is that the, the co-owners are, are holding, um, their ownership, um, and their, the power of the company because it's just been these two guys that have owned it and it's extremely profitable, et cetera. So it's very exciting to see another, yet again, another hardware vendor and software vendor that has taken on, um, some big dollars into this market.
So it's not just about software anymore. It's definitely the, Oh, hardware is back big time. And of course, but that's a, that's a capital intensive game.
Um, and you need to be very well funded for the long term to even play these days. Yeah. And they've been, um, very, very close with Nvidia all along because this has been their mark.
I mean, this is all they've done. Yes. They bought a company called Ry, uh, means five, six years ago, um, that had was, and they were, looked like they were starting to try to expand into some traditional data center space, but with AI taking off, there's really no need for them to do that, uh, in terms of their valuation or who the company is.
They just exploded on that side. So it's been very, very cool and a big congratulations to these guys out there. So, Yes.
Yeah, and that kind of goes along with, and I guess the other thing we were gonna do, um, we were going to take this, this session and really kind of go through our predictions for 2025, but with all the things that were going on, we said we didn't have time. So what we're gonna do is split it over the next few weeks for each of us to take a section and talk about it. Um, so I had mine ready to go, which is of course the, you know, my first two issues.
They're, and they're, they're more granular in terms of predictions because there's, you know, yes, the market's gonna grow. Yes, data's gonna grow. Yes, all these things are gonna happen, but it's kind of like, what are the specific things that we're gonna start to see that probably weren't part of on our venue in the past?
And when I sat down and looked at that, I said, one of the biggest things I think is gonna happen is the rise of scale out file and their understanding what we need, the need for parallel file systems and requirements for ai. And to this time, it's always been a secondary market. It's been a market for r and d, it's been a market for the lang, you know, the, the big labs, et cetera.
That's who was, because these were so difficult, parallel file systems are not the easiest things to manage to, um, you had, you know, the ones that I'm thinking about would be, Lester would be GPFS or IBM scale would be BGFS. You know, some of the guys are out there and, you know, it's just not something that somebody wants to go play on. But as we're seeing each and every one of the, the vendors are bringing out something to say parallel scale out, and not just scale out, but parallel file systems.
Dell is working on something, you're, you're hearing vast kind of move in some of those areas. So they have those relationships, some of them have those relationships with tho those systems already. But we're also seeing like hammer spaces being put on top of some of these file systems and in order to bring a parallel like activity that's out there.
And basically what that means is that the enterprise that's never paid attention to this guy, unless you are a big, big r and d facility, is all of a sudden saying, I can't get my very high speed file system such as power scale from Dale or NetApp to perform at the level I've got to make it perform at for ai. Mm-hmm. What else is on here?
Those file systems, you're not designed for that. I mean, yeah, we're, we're dealing in, in, in entirely new levels. Petabytes of trading data and things like that.
It's crazy. So this next year, I think that conversation is gonna rise up. I think the enterprise is gonna start saying, okay, so what is this?
Tell me more about it. What is the difference between A and B? Why can't I do this with this?
Um, so that to me is the big rise of that. The second piece of that is the understanding and the tuning in of where objects and file belong in that data pipeline for the ai, um, initiative where that's going. So we've got the data lake that needs to exist.
How is that going to exist in the data center? What's that gonna look like? How am I gonna afford that?
Because we're hearing from the enterprise folks that the, there's a huge sticker shock in terms of what this is gonna look like potentially. So we've gotta look at different ways for storing that, because if this, uh, this side is too expensive, I can't justify the ROI here, but can I not justify the ROI here? So somewhere along the line, there is invention and opportunity in here to understand what's gonna have to happen from these big object file data lakes.
Well, I, I think there's a whole ROI problem in general. I'm looking at, you know, all the, uh, the, the venture capital firms are putting the graphs together of the expenditure on AI and the expected profits over the next 10 years, and they don't add up, um, mm-hmm. And you, and you have to do it, but, uh, you have to invest in ai or you're just, you're outta the game all altogether.
But, uh, even any billion dollars Microsoft is spending on infrastructure, uh, which is gonna involve all those things you're talking about, you know, massive file systems of even greater amounts of trading data and all of these things. Um, where's the, the end game? Are we gonna see exponential growth in, in, in profits taken from all these investments?
We don't see that. I, I'm not sure it's, it's seems like the industry's not heading in a sustainable direction. So it's interesting.
Yeah, I think in my experience with file systems in the enterprise, it is very, very, very difficult to get enterprises to change file systems when you're talking about where they're stored, uh, changing user habits. Uh, and in this case, we're probably talking about data scientists. We're probably talking about researchers, uh, in the enterprise.
And it's, uh, and people who are looking to get the data into AI systems, the challenges that these, these, the data, you know, exist on Fowlers and NAS systems and it's distributed, it's in the public cloud and trying to get a, uh, without interrupting users', workflows, getting this data into distributed, uh, into some type of parallel file system that that's usable and that can use rag, et cetera, et cetera. I think that will be the challenge of 2025, the need for performance, we'll obviously see, but, uh, uh, smart folks coming up with solutions that make this as, as seamless as a transition as possible, as, as the challenge. And, and then throw in two, two of the technologies that are part of this, part of this entire AI capability.
One is streaming data. If I'm gonna do real time AI with streaming data, et cetera, all of a sudden it brings more complexity to what we're doing to the pipeline. And, you know, we hear, you know, the different folks about how do I adopt a streaming data that's coming in for those decisions?
And the second piece of it, which is already part of the environment, is a vector databases. And as I take, you know, as the vector databases get indexed, they grow, they grow significantly. And so how do I deal with that?
So there's probably invention to be had in, in those areas from an eng from an engineering standpoint. Um, as we move forward, this, these next, next few years in addressing, as you were saying, um, the, the ROI, et cetera, um, the last two that I had on my list is that from the enterprise standpoint, we're gonna see continuing decrease of any stop, uh, uh, hard drives there and moving to QLC that's been driving revenue for these guys, um, and is going to continue to drive revenue, um, for the, the major vendors, um, as they roll out. So we'll see less and less of those blended boxes that are in there as they come of age.
And that will fuel the, the revenue in those spaces. And, and the fourth, fourth area that I'll bring up is the area of data protection and, uh, cybersecurity that does not leave. Um, Diana, as you well pointed out in your CIU insights, it is still number one on the list.
And, um, we will still continue to look at what do we need to change for data protection in order to improve the recoverability and the speed of recoverability. So there's two pieces there. It's not just making sure that we're safe, but now what they're looking at is, how fast can I restore, um, and when I get hit, um, and then the other piece of that is how do I protect not only the secondary data, but the primary data that's been going on.
So we'll see the increase of technology, and that will become a competitive advantage for those vendors that have built into their primary storage, those capabilities to protect those devices. Yeah. And that the, in combining kind of two ideas that you are looking forward to, how do you do this with ai, you know, with AI and streaming data, and now when ai, when this secondary data now becomes production data, and, uh, the need to protect that from ransomware, from cyber threats in real time and be able to recover in real, real time, I think we're gonna see, again, your, your premise that, you know, we're gonna see the reduction of hard drives.
We're gonna need much better io so much better in denser io. So 27 terabytes, I, if I'd ever say this, a 27 terabyte hard drive just is not enough. Uh, it, it is not enough, and it's too slow compared to the a hundred and, uh, the 122 terabytes we're seeing out of the major vendors.
There's talk of being, uh, uh, SSDs, I'm sorry, and, uh, going to 256, uh, terabytes of SSDs this year, and the need to just have faster and bigger io it's, uh, it's a, it's an amazing set of challenges going into the new year. GPUs are so they can, they can take so much data is how do you get the networks and the hard drives to deliver information and the astic process that, that's the, that's the, the core problem right there is you basically have to match the, the data throughput of the GPUs across the entire data center. And that's, that's amazing.
And they're gonna try and do it, you know? Yeah. And we're so, you know, obviously we're gonna see opportunities for folks like Cisco, the tech field day folks will be at Cisco Live eu.
And, uh, uh, I think that's next month of when we're recording this, and obviously HPE with this acquisition of Juniper and the ability to have these tightly integrated stacks. Uh, Dell has its network stack and this ability to build these Nvidia blessed stacks, which Nvidia has competitive networking. So just as you start to tear this a apart, apart, and we start talking about vendors, vendor relationships, the ecosystem, it makes for a really interesting year of, you know, how do we get these engineered systems that we want from our favorite vendors that are blessed by the people who are controlling ai, which is basically Nvidia, And then the us our, our US manufacturer.
All all of our US customers should consider themselves blessed because they won't fall underneath these export control issues. So if we're gonna tie all of this pieces together, they'll have the freedom to acquire whatever they want to acquire, um, right. And, and be able to build on those systems.
So, wow. Well, that brings us almost to the end of the hour. Any other final comments coming out of any kind of cool stuff you guys got, and we'll wrap up here.
No, I just wanna give a head tip to our fans at kaza. They got, uh, they've been horr fighting. Luke and Matt, uh, have been ha hard plugging, working with our folks in the Signal 65 lab, doing some really interesting ai.
The, they received the $11 million in funding from some Seattle based venture capitalists. This will enable them to continue what the venture capitalist is calling the docker of ai. So, uh, stay tuned from some, uh, some insights from our signal, 65 labs from some of the work we've u uh, used, uh, KAA to help us produce some really interesting research.
So, are they, did you say they're located in my backyard? They're located in your backyard? Uh, I think, uh, Luke's home overlooks the sisters.
So the, the, the, he is a, i I, I, I saw it as he was a rehab, then he worked for a different, uh, data based, uh, data enterprise data company. So, yeah. Okay.
Well, I'll have to look him up then. Very cool. All right, guys, thank you very much for tuning in.
Don't, don't forget to, like, share all those good things that we ask you to do, um, as we continue to bring you infrastructure matters and probably the most interesting podcast that you will listen to all week long. All right, have a great week. Hi everyone.
Welcome to this talk. Today, I bring some ideas on how you can shift left the operation mindset and why Debs must, and how they can this from scratch. Because from my experience, years and years working with different companies, I have seen that developers, they are too much focused on the business side, and they sometimes they forget that it's important also the operations side to maintain this in production, to maintain this for customer.
So I, I can explain some of the problem from the scratch for you. And then, uh, we gonna, uh, learn from my, my failures and my success, right? Some ideas I have to share on how to shift that ops mindset.
So who am I? I am Eros Brazilian, but uh, base in Chile now, uh, working at Citi. But, uh, across my career, I have been a DevOps human and a software engineer.
Uh, a month ago, I just joined the ambassador program of DevOps Institute. Uh, so I, I am so happy to be here speaking as an ambassador. Uh, but also I participate in some communities like the DevOps days in Santiago, the Chile where I'm based at now, uh, to bring this amazing event here.
And also some other communities, open source communities like open source, Santiago platform engineering, and, uh, CNCF there, you're gonna find me, right? Uh, here is my picture at the last Cuon in South Lake City was an amazing event. Uh, you can also find me in my bank.
So let's start, let's start, um, understanding or generating a shared understanding of observability. Probably you'll see a lot of this in the other, in the other talks today, but, uh, I want to use my own words right from scratch. So to understand all the concepts, right?
And have this prevent communication between us, right? So let's start from the SDLC issue, right? And in a simple value stream mapping of, of our development lifecycle, we're gonna have customer needs that will turn through this flow to be a product, a product that will be supplying those needs of the customer right to, to challenge the marketplace.
And, uh, some companies will try to win through this process, growing this from understanding the, the need ideating that something, developing some software, some solution with technology to later verify and promote this production. If we go a bit deeper of the over this, this pro, and we check of the, the outputs of this software development lifecycle, we're gonna see that from the need. We can have an idea, and that idea will be developed by some, someone inside the company, someone inside the team having a white box where we'll be able to see everything inside, right?
Because we have the code in the development phase. But later, when we move that idea that is being transformed to code to technology, we cannot see that this white box will turn into black box where we will not be able anymore to see what is inside, right? We'll need to get back to the code to see what is inside.
But, uh, definitely during the runtime will be hard to see what is happening inside. And this thing, black box from the development phase will go through prep production, later production to turn into a product and provide some service, some feature to our end customers that can be, uh, internal external customer, right? But the, at the end, this black box will be worked by different teams, right?
So, uh, it's not just a matter of the development in that traditional we have in the development phase that we'll be able to know what is happening inside. Because also they are writing the code. So it's easy for them to know if the software is falling is crashing, if something is not working as expected, because they have the directly the code, it's the source code.
And also they can back directly from the code, from the EDE. I can connect my software running and go through each of the lines of code to understand what is happening there. But, uh, again, to the, from a traditional organization, we are gonna see all these different roles, different teams working across the value stream to finally release this product as a black box.
So the approach where they wanna probably have some tool gates to ensure that this black box they are receiving is, uh, secure is safe, uh, is reliable, right? So there is a lot of things, right? And also these barriers between the teams that traditionally have well known from the DevOps movement as wall of confusion, generating even more disruption across the flow.
So going and deeper on this concept that is DevOps, that probably you are, you will be saying, okay, with DevOps, I can solve all these problems, right? But, uh, the depth of humans, usually they are too focused on breaking down these barriers, the walls of fusion between teams to make them communicate right, to speed up the flow from left to right, or even moving these tool gates and make NG four more to the left to make this, uh, fast and better feedback available in the areas stages. But, uh, the problem I have seen even as a DevOps human working as a DevOps engineering side economy or a DevOps deal, is that sometimes we focus too much on implement automation and implement a lean to remove the waste of the flow and make it fast from left to right using a lot of metrics.
So there is a set of metrics called Dora DevOp assessment and re research and assessment at this. Why use it that focus a lot on the, on the reliability of the, the software that is going through the software development lifecycle and also the productivity. But sometimes we are missing some aspects that is coming from the non-functional requirements, non-functional requirements that will help to, uh, even remove more of the waste of the flow generating a better solution at the end for our end customers.
So I, I broke one of the practices I have used in the past. com, that is called it non-functional requirements map. Uh, usually I use this practice to help teams inside organizations to identify that there is a lot of concepts and also aspects of the software that sometimes we are not seeking incur in the early phases, right?
When we are ideating something to supply a need, where we are, when we are developing something from a idea like observability, if we turn back to the example I mentioned it before of the software development next cycle, on the outputs of each of the spaces, we are gonna have our black box, right? Our black box that should be running introduction. But what happens if this black box start to fade, right?
They start to, uh, not work as properly as expected, right? Uh, and, but, and we have the development team, or even in the organizations that already change their ways of working and the infrastructure, uh, where the, the, the developers, they are more involved in the operations side. We still have all the business working and, and running, right?
We need to keep the operation up as the time we are developing new features to keep competitive in the marketplace. So not always the operators of the software, this, the engineers that are looking to software will be able to understand what is happening here in this black box, because it's not easy to communicate with the software that was developed by someone else, right? Uh, I was developer in the past, so I know this is a pain, right?
Usually we have logs, we have metrics, a lot of monitoring tools, but, uh, if we don't take care of, of how this black box is communicating to the engineers, that was not part, were not part of the development pro process. The the black box will be a challenge, right? And it, it's the norm.
It, even when we, we said, okay, we are 13 years ago of DevOps movement, or even observability is not something new, but we still have a lot of developers with this technical debt, right? Teams developing, just focusing on the business. And when we have the black box failing in production, it's hard to know what is happening there, right?
It's just like a baby. And, uh, if you, when you are parents or if you, you're part of only, you know that the babies, they, they don't, don't, they cannot speak, right? And explain what they are feeling, uh, with the specific language we have, right?
So sometimes as parents, maybe we will think, uh, uh, where is the handbook? Where is the manual, the guide they can use to understand what is happening there? It's something similar, right?
It is not the same definitively, but, uh, when we have this black box in production, we need to have a way to understand what is happening. Uh, right? Or even in the early stages, right?
Something you're gonna talk later, uh, it's super critical to keep this amazing idea that was supplied by the new product, developed it super fast up and running in production, because you can have, uh, the most valuable product. But if that product is not, uh, available or reliable in production, your customers will move to another company for sure. So the observability comes with all these different aspects that should be ticking in cans, even in early stages when we are ideating some solution.
Because ideating is not just a matter of selecting the features that will be used by our customers, but also the architecture, the different standards I should be using to code is part of the ideation and also the development base. So there, I should be looking to how my application is lagging, it's generating proper information to my operators. I would be able to notify what is happening with my black box after it packaging everything and deploy in production.
Same thing with metrics, RAC and, uh, why not other thing, right? I need to have my other visible. And there are, uh, based it on the behavior of my application, my software, but I know, I know there is a word of difference between what is knowing and what is actually needed to do, right?
There is a chance from the, the needs and the product it, and even have the product up and running all time reliable in production with all the SLAs that's lower. So we can set the define agree, right? So it's important to understand that gap and work with that.
It's part of the DevOps mindset. I try to promote every time I sharing some idea or some learning, the continuous improvement, the continuous learning, the continuous, um, challenging of the flow, right? So show me how ship left, right?
Because we already, so that, uh, there is a, an important aspect of the software development lifecycle, which is how I can talk with my black box in production, my software, which is already packaged, and, uh, probably I will not be able to publish, uh, the pack each of the nines of code when it's feeding the product. And obviously I will not be there and it's failing properly. So, uh, I need to be able to have the, the standards defined there and the part of the area stages, right?
Because I don't want to fall in production, right? I want to be their reliable and stable. So Cayo, what do you, what do you learn from your failures?
What do you learn from your, your successes? So the first thing is contracts. This is something, um, it's not something proper only of the DevOps ward.
It's also something that is connected with a lot of other movements and aspects of the software, developmental lifecycle, it and in general, which is, uh, how we are defining our conditions to work together, right? And, uh, using agile, uh, and one of the frameworks of agile, which is, uh, scram, we're gonna see the definition of done there, right? So it is one of the conference.
So if I can align with my developers or my stream, align a team, if we have, you know, team topologies in place and we have teams focused on the value stream, we, and they have the mindset of, uh, if I code it, I build it, I ran it, then I can bring the idea of this non-functional requirement, which is observability to the contract, which is the definition of that. And I can include some aspects of observability there. Like, uh, standards of logging.
Ensure that my developers, they are logging properly based it on the standards. They find that by, you know, an architect inside the organization, right? Same thing, using the right agents or the right technologies, right?
To, uh, integrate with the monitoring tools and ensure that my software, the, the, the, that code that will turn in my black box will be able to express what is happening inside if it fails or even before it fails. So we are gonna have the definition of done there, right? And if we are implementing fast iterations, we'll be able to even improve the observability in early stages right before to go to UAT before to go even to, uh, uh, to, um, pull request from my feature branch to master, right?
Because I gonna have all these tool gates that usually I, I learn from the failures in operate in, in production, why we are operating, uh, learn from them from the beginning, right? The other thing is complement, uh, this, um, practice of, uh, ensuring that my software is speaking the same language and being able to express what is happening inside with the child's engineering, right? There are a lot of technologies in the marketplace, or even in open source communities we can use to challenge our software in a production like invite.
Uh, and using this practice of, uh, injecting error there, I will be able to understand if my, my logs, my metrics are really showing the right information I'm expecting from them using the small cycles of P-D-P-D-C-A, uh, which channels engineering, s engineering, I will be able to, uh, learn from my observability aspect of my software and ensure that in production at least I will be prepared for the scenario. I define that during the, my challenge engineering practices later. We have a platform engineering.
It's another huge movement, which is, uh, there, right? We have a lot of, uh, material in the market, uh, talking about platform engineering, the state of DevOps 2023, where was based on, on, on platform engineering. We already have, uh, a lot of communities.
I'm part of platform engineering, do com, dot org, uh, community and, and invite everybody to be there as well. Uh, so platform engineering is helping a lot organizations to reduce the cognitive load on developers understanding that developers, they, they have an experience part as well. Or even, uh, if we go outside of this concept, concept of software development, life cycle, the platform engineering needs any aspect of the organization, of the business, right?
But turning back to, to software development life cycle, using platform engineering, I will be able to reduce the complexity of my developers to introduce observability aspects in the, in the beginning of the development phase, right? How with the reusable components, tools, platform, services and knowledge base available for them to help them to adopt these technologies principles or even standards like, uh, using open source technologies that we have in, in the marketplace to supply this, uh, these needs like open telemetry that, uh, have a huge, uh, support for different languages to improve the visibility of the software inside this black box, right? Uh, removing the cognitive load of developers to write the right logins, right?
Uh, that, um, sometimes will make the code a bit more difficult to maintain, right? So using technologies like this, it's the, the developers or the different teams across the software development life cycle will be able to make the, the baby more understandable, right? And, uh, using technologies like, uh, Kraken to do chow engineering, uh, they will be able even to challenge what they are doing with technology like open telemetry and the platform engineering will be providing the platform teams.
They can provide these tools in a on demand solution, a doc solution for the, the, the internal teams reducing the, the, the, again, the, the cognitive load to start adapting this or even reducing the, the gap between know that I, I should be doing this and actually doing this, right? I had the experience in the past working with development teams or string alignment teams, actually, that they didn't talk before, that observability was a non-functional requirement. Important thing to, to include there.
And, uh, actually sometimes they didn't know how to start doing anything with observability, which tools, which technology they can use. So with platform teams, we can provide the stable, uh, compliance solution inside the organization with well-documented and boilerplate solutions. I mean, uh, templates they can restart from, uh, with the right, also the right configurations to integrate with other platforms inside the organization to make a visible information like AANA Pro Ana unlock, GKI, jigger Ali, right?
To make everything more visible, more understandable in production. And finally, some other things I want to share today is, uh, something outside of the, the use of technologies, right? And, and practices, which is the communication inside organization, right?
Uh, sometimes it's different things. They are working for the value stream, but they didn't know where one start and where other start. And also they are totally disconnected.
Some of the open leadership, uh, transformation I have been doing when I was part of Red Hat was communicating these different things and generating shared goals. And shared goals can be related also with observability, ensuring that the, uh, the software we are generating together is really understandable in production, is prepared to generate, to provide the right service. And observability is critical for that, right?
I want to know that my software is properly logging the information. So I am, if it, it did it, if it crash, right? I will be able to know what is happening there.
It's the connection to the database. It's a third party. A PII had just one issue today with the some one team.
They were asking me how I can increase the timeout of my Kubernetes deployment. So I asked him, why do you want to configure the timeout directly in your Kubernetes resources? If, uh, probably is your software, which is taking too long, or it's, uh, integration that is taking too long, did you look to the logs?
Do you look to the tracing? Do you, are, are you implementing tracing features to know what is happening inside or the, the, through the, the, the cycle of the process that from a client reaching your API and receiving a response, that that is crucial. So if we have shared goals across the organization, across the team, uh, everybody connected to the end and the outcome, which is have proper products supplying the needs of our customers, and, uh, have everything there reliable and stable.
Observability, observability would turn something important as well. And, uh, part of this will be outcomes, metrics, right? OKRs, TBIs, uh, a lot of all, I I will say most of companies better, uh, are trying to use metrics.
Metrics. It's super important because we cannot know where we are. We'll not be able to really improve if we don't know where we are, right?
So using metrics, I'm gonna be able to see I'm here, right? And Dora is one of the metrics I mentioned before, right? It's why use it and help us a lot to understand what is happening in production, because the four of them are based on what is happening there, right?
Uh, how much time I take to move something done to production, how much, uh, I'm deploying production, how much take to restore something production and, uh, how much phase my deployment? So, uh, the, the specific metric, meantime to restore is, uh, from my, my experience is, uh, use it sometimes wrong to, uh, help teams or enforce teams to take care of observability. And, uh, I want to stop here because sometimes, uh, metrics, they are important.
Again, we cannot stop the use of metrics because if not, we'll not be able to really know where we are, right? And if we're improving or not. But metrics must be part of how we are progressing, where we are today, where we should be tomorrow, right?
Not part of our targets, right? I have seen a lot of teams pay because they set targets of, as, as an example, meantime to restore because the observability was not good in the beginning. So they define it that meantime to restore must reduce 50%, right?
Uh, setting the specific numbers right was not this abstract outcome that I just said, which is not bad, but the, they just enforced from top down changes in observability, enforcing tools, enforcing practices to the teams that have been working a lot of time as they want, right? Uh, and uh, at the end of the year, they failed. They have a lot of teams running, sorry, uh, running in s because they didn't know how to pick something they must show in one week day, right?
So improvement actions should be the target, right? How are you logging? How are you implementing the standards of logging?
Which kind of technologies, uh, you are implementing as part of the design or as part of the development process to all to ensure that the observability is good enough to reduce the meantime, to restore the time I need to solve something in production that is messing my service, right? So this is more or less what I have prepared, right? So I gonna thank you for joining this conversation, this talk with me.
Uh, if you have any questions, you can join me in the chat, use the code cure to, to, so to see me there, to talk with me, uh, maybe share with me your experience, maybe you have something related with, uh, what I expose today and keep joining the skill, the skill update is on this event. Thank you very much.