Techstrong TV – January 17, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone. It's Textron Gang. If you don't like this, you could click to cancel.
Hey, everyone. Happy Friday. It's Alan Shimel for Techron Gang.
You know, I mentioned click to Cancel in the opening. We're gonna talk about click to cancel, but I kinda like the whole vibe of click to cancel. I wish we had click to cancel in more things in life, quite frankly.
Uh, it's, it's a cool concept. You could tell it's Friday, right? And it's been a hard week, but we've got click to cancel.
We've got more than that to talk about. I've got a great lineup of our gang here to talk to you about it. Let me introduce you to them starting off in Austin.
We've got our good friend Anne, a whole award. Hey, Anne, how are you? Good morning.
Great to be back, as always. Is that still those New Year's streamers I see on the fringe there? You know, I think I still needed a little sparkle in my life.
All Right, well then I, I will say Happy New Year. Happy New Year. Thank you.
It's not too late. Thanks. I have to be honest.
It'll stay up until Valentine's. Alright. It's a spring thing.
My, my friend John Nichols, Johnny Nicholson, and I, when my, my best friend growing up, once he got married and lived in his own house, he, uh, he used to keep his Christmas lights up, like it was warm already. It was March, it was April. I'd say, Johnny, when are you taking the Christmas lights down?
He'd say, that's a spring thing. And, um, and in the spring, he would take it up. Now, there are some people who say, once you make it past the spring, you better off just leaving them up.
But we, We call 'em Fiesta Lights after February. After February. They're Fiesta Lights.
Okay, we'll go with it. All right. Moving on from Ann to back, back to the throne room at the Palace in Silicon Valley.
It's our, our resident royal person, John Schwartz. Hey, John. How are you?
Um, I've just defrosted from Pittsburgh, so I'm back. And I'm back. And welcome from Silicon Valley home of a tech industrial complex, an essential cog in the oligarchy.
Beware the oligarchy. I felt it was sort of like a George Washington kind of warning to be where? Foreign entanglements.
Oh, it just goes, it just blows with the wind politically. But I will, I'll, I'll keep it at that. But, um, yeah, interesting times here.
And they'll only get more interesting and maybe frightening at the same time. John, it's Friday and I'm not taking that bait. No, don't.
Please don't. No, no. I, I'm gonna get past it.
I'm over It now. I thought I went with John Mar with George Washington, and that was nice and apolitical. Uh, let's move on from Silicon Valley.
We'll move a little west to the guitar man. Our, uh, resident futurum analyst and friend Mitch Ashley. Hey, Mitchell.
I'm glad to see you made it home. From the cold confines of Boca Raton back out to Denver. It Was just a little too cold there for me.
So I came, you know, to warm, uh, single digit degree Colorado. At least that's what we have coming here. So, um, still recovering in a good way from an amazing, uh, Greek food dinner.
We had a fantastic meal. Oh, That was the last meal. That was last, well left last night.
I, whoever was left, I brought to my house and we made dinner. I, I made dinner. That's Always fun too.
Yeah, It was good stuff. But it was good seeing you Left. 'cause of whatever it was.
Yeah, Yeah. Good. A good all hands, uh, meeting in, in Boca, speaking of traveling home from Boca, he came, he saw, he went back, Um, back, uh, you know, I, I caught that geriatric express flight and here I am back in New York.
You know what I love about the flights though? Getting on the plane, there's 25 people who need wheelchairs. Mm-hmm.
Getting off. It's like a miracle. A miracle getting off.
Two people need wheelchairs, the rest of them run. So, A, Alan, I have some, I have some good news for you though. What's that?
I was, uh, I was that Carnegie Mellon. They are developing, and actually I'm gonna add this to the story. They are developing with the airlines wheelchairs that can be taken straight onto the plane and, and part not expedite the process as part of a robotics program.
That would be, 'cause PBI, if you guys have ever flown outta PBI airport, Palm Beach, you gotta board a half an hour earlier start boarding to get all the wheelchair people in. And, and I'm not kidding. When the flight lands, it's a miracle.
No one needs a wheelchair to get off. I thought PBI stood for Please. Board Invalids.
Isn't that what It is? Yeah. No.
Well, Okay. I, I, again, don't wanna get political, but you could go see, uh, either the Trump plane or, or, or Air Force one parked out there all the time too, because God, to how many days a week the president works. It seems To me, if this conversation continues, we are gonna get canceled.
So maybe we should Jump in. People Were clicking the close by. Right.
Anyway, Mike, it's good to have you back. It was good to see you in person here in Florida. And Mike took us to some of his favorite haunts down in the area.
We had some good meals and drinking. Good, fun, good time. But we've gotta get busy.
As I mentioned when I opened the show, I love the concept of click to cancel. If only it worked. What makes me think the FTCs gonna make it work?
I don't know. But Mike, why don't you kick us off here. So we've talked about this last year, and honestly, we were all a little skeptical, but now here comes this actual order from the FTC.
And so, Ann, what's your sense? Is this actually gonna happen? Or will the new administration kind of cut their legs out from underneath them?
And this isn't gonna happen at all, but it seems to me a lot of people I talk to, you know, Alan's point, are pretty excited about this capability. I think it's an amazing thing, the concept being that if you have two, three clicks to sign up for something, it should be the equal amount or lesser to cancel. Um, I think it's a common consumer complaint.
Um, and they're actually rolling it out or enforcing it as early as May of this year. So I do think that they're serious about it. Um, I think that the key aspects that I, I think are particularly helpful is the ease of cancellation, the transparency of what you're signing up for.
Um, definitely like in in places like the App store, you can subscribe to things and not even know it. Um, and it, it's something that's really meant to protect consumers and help them understand how to get out of things that they can get into so easily. Um, I think the consent requirements are also really important.
But the thing that, uh, I read this week that I hadn't heard about before was the prohibition of dark patterns. So that means deceptive, manipulative, user interface designs, things that make consumers go into unwanted subscriptions. I would say this is probably gonna get heavily litigated because a lot of companies are gonna lose this.
Um, I can remember two instances where this took hours of my time, one of which was, uh, XM radio. I basically had to threaten legal years ago to get them to finally cancel our subscription. And then Adobe, I fought with Adobe, uh, my subscription there for over a year.
I had to actually involve my credit card company because they, they just kept charging me. And so the idea is that this will also save consumers time because a lot of time gets wasted in trying to understand how to get out of these things that you can get into so easily. So it's a, a very logical and helpful, uh, mandate.
And I hope that it, it, I hope they're successful with this. And then we can move on to resort fees because I didn't know about you. Yeah.
But they're working on that too. And, and that particularly grinds my gears because you can book a hotel for less than $200 and then you spend another 50 on a, on a hidden fee. So I applaud them for doing this.
I hope it actually works. So I, I have a rule at, at the very least, if I could sign up for something online, I should be able to cancel something online Companies that say, oh no, if you wanna cancel, you gotta call this 800 number, press 1, 3 5, and then seven. And then wait in the queue and listen to their stupid music for a half hour.
And then they're gonna try to, in the case of like a Sirius F uh, uh, the satellite radio, oh, well, we'll, we'll give you, you know, a terrific deal. It's only 9 95. No, if I want, I'm canceling.
Well, how about if I give it to you for 7 95, what would you do if I gave it to you for a dollar? No, just get away from me. I'm canceling.
Adobe does that too. I, I, um, I do think it's, it's part of the deceptive practice. I think it, yes.
I think it's gonna, another, another, oh, sorry, go ahead. I think it's gonna be good for them in this sense, right? I think a lot of people got wise to this over the years and don't buy things.
'cause they know that they're gonna get beat up on subscriptions. And longer term, maybe more people will actually subscribe to something. 'cause they won't feel like they're gonna get ripped Up.
I'm not that optimistic. I think this goes away in the new administration. I think it's gonna be heavily litigated.
How are you gonna sell all of those Trump gold coins and flags? Oh, geez. I, I'll say I, I hope that it, I think one of the other things it was meant to combat was signing up for something online and then requiring an in person.
So like my gym for example, that I haven't been doing it in a year. They require me to go in person Yes. To cancel.
And it's like, Well, that's, that's interesting. If I was showing up there, then this wouldn't be a problem. There are health clubs that you demand that demand that, um, members cancel by certified mail or in person.
And then I don't even want to go into cable subscriptions, you know, in the time you, you spend on the phone. I mean, this reminded me of a controversy that a OL went through years ago. Decades ago they were in hot water because it was so simple to sign up for it then yet utterly impossible to unsubscribe because you couldn't find numbers, contact information.
This is something that is just an, just analogous for the, the tech industry. And I think they're gonna be a little bit, uh, put off by this and probably fighting and, and whispering to certain officials that they, we need to dissuade and get away from this. But, um, You know, there's one, one area where we already have this, um, apple, if you subscribe to a service using hide my email, uh, it goes into your subscriptions.
Like other things you buy through the app store. Yeah. And you can go into your app store subscriptions there, any of those, you can, can right from there.
I found that very useful too, Mitch. Oh, I love that. I love that.
Me too. And I used, it's it over and over. I hope it's less clumsy than the rollout of GDPR.
Yeah. No, it, it, if you go in, like if you're on Mac and you go with your, to your, you know, apple account and it has your subscriptions there, and you could turn 'em off as you go. Exactly.
You know, Michael, Mike, to your point about how consumers get wise to this, now I would do a, a a a variation on this when I was looking at, like, I was a DirecTV customer years ago, and they were, they would give you these great come ons and then six months later your price would double. And what I quickly found out, if I would just get on the phone and say I want to cancel, they would put me to the savor department basically. And they'd say, oh, wait, before you cancel, let us do this for you.
I'd say, I, you know, they'd say, why are you cancel? I said, 'cause you're too expensive. And they would roll out every offer they had mm-hmm.
Until I accepted something. And so I really wasn't looking to cancel. I was just looking to save money.
Yes. That's, my wife does it exactly the same. She does that a annually.
Yeah. She'll threaten to cancel, then she gets a sweetened deal that that's part of, And you know, that, that's another part of the consumer experience. It's kinda like going to the Shook Right.
And, and bargaining with, with the, with the, uh, people. But if you look at the Legislation, it actually, or legislation F FTCs rules, it has a lot of what we're talking about. It has to be the same medium.
You don't have to talk to a person. Yep. Mm-hmm.
Um, to do that. Um, and you should be able to do it on should, should take the same effort to, as it does to sign up as it does to cancel. So, agreed.
If this, if this flows through, I think it's a great thing for the consumer. Certainly good for us. Agreed.
I think those gaming Companies are gonna be in a lot of trouble though, because I can't tell you the number of times that I, over the years that I had to go look at one of my kids' accounts and say, so there subscriptions are doing subscriptions to this thing. How does that work exactly? Right.
Well, but, but you know what, again, apple and Google, when you download an app or a game like that, it'll tell you in app subscriptions. Mm-hmm. So, you know, at least it's giving you a heads up.
I don't know how many people read what The charges are Before which the average 13-year-old dutifully ignores Well, but not on purpose. They are year dad's problem. You saying I'm 13?
Is that what you're saying? You know what, They're, they're wise to it. They just don't care.
But it's not like they don't know. I've had instances where I've deleted an app and it still charges me, which baffles me as well. Deleting does not mean canceling.
No, it doesn't not. And maybe that'll change. Look, there's two sides to all of these things, right?
I, I, uh, you know, I Mean, there's a certain amount, there's a certain amount of pleasure in canceling something, right? There's a Certain Absolutely. It is.
It releases some end things. It's like cleansing. Yeah.
Mm-hmm. Uhhuh. It's like, but somebody like, who wants to get rid of, get rid of their meta or Facebook account.
I mean, that's really hard to do, to scrub it completely. But I mean, psychologically it does feel good. Why I always wonder, too, is that the FT C with the new FTC chair coming in, does this, is this all moot?
That's What I'm saying. We're wasting time talking about it. They're not gonna do it.
But to your point, with meta and, and our friend, uh, over ZY whatever the heck they call that one now, um, what I find interesting is a lot of my friends who have abandoned those platforms have not canceled per se, especially if it's free accounts that don't cost 'em anything. 'cause they wanna preserve their name. So that Exactly I do that.
Or comes in and tries to impersonate them with their need. And I I and that Is happening. That is, that is actually happening.
I I, I ran across a friend of mine, she has, I don't think she knows this, but she has two other profiles associated with their name, with different birth dates. Yeah. So, I Mean, that is some So is that called, is, is that called quiet canceling?
How does that work? I guess you would call I, I call it a bit. I like that quiet canceling.
Make sure you credit Mike Ard for that. Well, sure. I I'll put it in Urban Dictionary.
Yeah, that's a good one. Quiet canceling. Anyway, let's take a break here on Textron Gang.
We're gonna come back and talk about one of our favorite topics, AI with AI in healthcare. You're watching Textron Gang Modernize your business to fuel innovation and elevate customer experiences with the builder community. Hub AWS and its partner network provide essential tools for transforming applications and infrastructure to fully leverage the cloud.
Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably. Visit the builder community hub to learn more. Folks, we're back.
And we're talking about AI and healthcare specifically. Some stuff that NVIDIA's doing to help drive research and development in this area. And I gotta tell you, this story's a little raw for me because, um, close friend of ours in my family passed away yesterday, and it was a long battle with cancer.
And part of the issue was it took them too long to discover the root cause of that. It was even there and it became a bigger issue than maybe should have, who knows? But John, you're looking into this story and you wrote a couple other things in this area, and I've also talked to AstraZeneca about what they're doing.
There's a lot of good work being done here. Yes, there is. I mean, Nvidia did, made an announcement Monday.
It was a pretty ambitious announcement. They had a, they had a briefing, uh, with, uh, Kimberly Powell, who's the vice president of healthcare there. And they mentioned a, a number of partnerships.
Uh, one was with IV, which I cannot pronounce, to accelerate drug and medical device developments, um, through, uh, I think it's the AI foundry service and agen ai. At Nvidia Arc Institute, they're going to accelerate computational biomedical research via AI models, Illumina, uh, geo genomic genomics insights with, um, also Mayo Clinic. They're gonna speed up AI driven digital pathology through computing platforms such as that are powered by Blackwell.
And in a sense, they're, they're doing a, a lot of things that I think are, are incredibly important. And they have high ambitions. They're talking about basically using agentic AI and physical AI to revolutionize healthcare, increase access and drive discovery.
Um, it's, this is all part of this larger, uh, edict within the company to diversify beyond data centers and position itself as a, uh, leader in, in multiple industries, particularly healthcare. And here's one reason why. Here's 10, 10, 10 trillion reasons why that's the size of the global healthcare and life sciences industry.
So they see this as a huge opportunity, but I also see it as an incredible, great opportunity for us, um, an aging nation where we all have our issues. As Mike mentioned. Um, I'm sorry for your loss, Mike.
And I'm, and I'm kind of going through the same thing with my parents. Uh, this is, there, there is a push, not just among Nvidia, but other companies to go into, um, embracing or medical professionals embracing AI to, um, expedite everything. There are shortages of medical personnel and there are antiquated facilities.
So, um, I look at this as a positive. I also look at it as a huge opportunity for Nvidia. But first and foremost, I, I think it's something that we, we all have got to do a much better job with.
And that's just healthcare in general. What, what also would be good to see John is, uh, AI tackling the insurance and coverage. Yes.
That is a big In the insurance Paper's. Not an obstacle to getting healthcare. That's also, if we could, if you could streamline that by 15%, it'd be massive.
Just think about how much that would improve delivering care to customers. You ain't kidding. You're not kidding.
I'll tell you, I'll tell you what I'm a little concerned about is that I look up and down the landscape and there's a shortage of GPUs. There's a shortage of data centers and a shortage of energy. So AI is a limited resource.
Are we really applying it to things that matter? Or are we just using it to write better emails? And, you know, it's Kinda like, you know what you gotta, where Is there more unstructured data than healthcare?
Where is there more opportunity for automation Than healthcare? Where is there more money And also potential to save actual human lives? Yeah.
But I don't believe the hype about data space and energy and data centers, that that's just, what do they call it? Grist for the mill or whatever. Greasing the skids.
Yeah. Something though, something with the mill John would know. He has a way with it.
It's grist for the, it's grist for the mill. You are, It's grist for the mill. That's right.
Okay. Well we had mills and we were milling stuff. We put grist in there.
Right. Anyway, but I, I'll be back to you on that subject next week with some real data. Oh, absolutely.
You know what? Show me, show me one AI implementation. That's not happening because we don't have enough data center space, or we don't have enough energy.
They want more and we'll overbuild it. I remember when they used to, if only we had more fiber for the internet. We can't, if only we had more fiber level three and Interlochen, when I used to live there with Mitchell, they had, they were sitting on enough dark fiber for 30 years that they're just starting to use it now.
But that's all you heard is only we had more fiber for the Internet. We'll, we'll get back to that. That, Yeah.
Nonsense. If there's one thing we've never, we've never underbuilt and that's data centers. I mean, think about Going back.
IBM is still selling data centers from the Cold War. If Anything, we'll over rotate on data centers. I think, We'll, we'll wind up with too much.
But here's my issue. 'cause I'm a meat and potatoes kind of guy here. Right.
And I think we're biting at the edges of what AI can really do in healthcare. It's not about reducing errors in clinical paperwork. That's a great, I'm not saying it's not a good thing, it's a good thing.
But let's talk about where the real shortage is. Qualified doctors, qualified professionals. Right.
When AI hits that head on, then we're gonna be somewhere. Right? It's, it's getting more beds in hospitals and emergency rooms and urgent care.
It's getting more people able to be treated. That's the, that's the thing here. And Mike, I'm I'm sorry for your loss as well.
I think unfortunately all of us have suffered in our family from a result of people. It just took too long to get care. It took too long to get the right care.
Oh, looks like you might have a malignancy. Well, let's schedule an MRI, when can I get that MR MRI done? Uh, about two weeks from tomorrow.
Then it's gonna take a week to get the results. And then I'm gonna have to show it to the doctor. And then he's gonna refer you to the oncologist.
And then the oncologist. He's a good oncologist. One of the best.
Can't get in to see him for three months. By the time you do, you're dead. That's the issue.
And that's what AI has to tackle. You know, Mike, you has To tackle that too. Alan, I, I wrote about this actually comment on a post that, uh, Keith Townsend put up with future is that, you know, all the focus on general productivity copilot for your pc, et cetera, those are all interesting.
But that's not the real value of ai. Improving individual productivity is a very hard thing to measure. How, how much time do you really truly save writing emails?
What really matters is, is re is, uh, improving process, eliminating processes. That's the way that you want to get more efficient, not have to do something. That's another way.
And I think that's the big question about AI, is what's the ROI people are asking you, we had that conversation the other day about are we backing off on AI investment? 'cause there's not a ROI for it. Well, you know, if you're just doing it as, as another Slack or another team or another kind of productivity tool, that's hard to justify.
But if you're streamlining processes, if you're making an, maybe even redesigning 'em because you have ai, just to pick one thing more or less, finding the shortage of talent that you can't have security people. Let's find more security people Right. As well as doctors.
So I, I think there's a continuum of value, but it's not just general productivity. Yes, it'll help us, but that's not where the real money is. I think that I agree with everything you're saying, and I think it's not just getting people from being in the hospital, it's getting them from staying too long in the hospital.
Because the longer you stay, the sicker you get is the theory I've had for many years. Uh, one of the early applications I saw of AI in healthcare that I still continue to watch and think is one of the best use cases is the Duke sepsis watch. Sepsis is one of the most common causes of death in hospitals.
And this, this pilot study showed that they were able to detect early signs of sepsis before humans could. And that to me is exactly what this technology can and should be doing that will save human lives. Guaranteed.
Everything else is window dressing. You know, chat bots for getting appointments or triaging symptoms like that to me is not the killer app here. To me, the killer app is literally saving someone Staff infection From a major infection that would kill them.
You're reminding me of, my Father Used to always tell me, don't go near the hospital. That's where the germs Are. Well, So my grandmother used to say, and she was a wise woman, she used to say, the, the doors to the hospital on the way in are very wise, and they get very narrow on the way out.
And, and I think that's still true. But no, I I, I, I foresee a day where AI is, I'll give you friends, my wife, I go, I walked the dog this morning. I go upstairs, Barney's getting dressed to go to the gym and she says, my cholesterol, I got my blood work results.
You know, because you get that before you go to the doctor. Right. My cholesterol's back up.
I said, when are you going to the doctor? Oh, not till I think two or three weeks. I said, well, if I were you, I'd start taking the, I take citrus bergam or, or bergamot, whatever you call it.
It's really good. I'm not a doctor. I'm not telling anyone to take it, but it reduces your cholesterol.
I said, start taking my citrus bergamot. She said, well, I'm not sure. Maybe I should wait for the doctor.
I said, Bonnie, if you start taking this now, by the time you go to the doctor, your cholesterol's, it's not sky high anyway. But we need, I mean, it would be so much better. So much of what we waste people's like doctor's times with is something like that when they should be looking at, so triage is important, right?
Triage is prioritizing where we put our time and who gets a bed and, and stuff like that. And that, that, that could be really helped with AI really helped. And that will save lives if my doctor's concentrating on the guy who might be having, we have another friend, Mike and I, he's in the hospital right now with the myocardial infarction.
I don't know if you saw this morning. He said it was close. He wouldn't be alive except his wife made him go to the doctor for chest pains.
Um, we, you know, those are the people you gotta prioritize. Not necessarily, you know, and there may be, I'm not, I'm not a doctor, but I do believe that AI's gonna have a profound impact on improving mm-hmm. The healthcare system up and down.
And I hope it's an equalizer because I have to be honest, as a woman, I'm less likely statistically to be listened to and diagnosed properly than a man. And that's not just because women don't get listened to or pain is ignored. It's because statistically more money goes to men's health issues.
I I, I'm, I agree with you in studies. It's a terrible thing by far. And, and that's women.
Let's not, let's not go to economically, but Could, but could AI equalize that? Because AI doesn't care if I'm a man or a woman. Absolutely.
And they don't care if you're black or white or Hispanic or Asian. Right. Exactly.
Which goes double if you Minority. That's a whole other, that's a whole nother boogeyman. Boogeyman.
But anyway, don't get me started. It's Friday. We're taking a break here on Textron Gang.
Let's come back and talk about something not controversial like the FBI deleting files. You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back in.
Yes, it is maybe controversial. We'll see how this conversation works out. But the FBI has been deleting some files that contain some malware that were allegedly distributed by some folks associated possibly with China.
You know how all these legal terms are, but, um, I think this is one of the first times, or maybe they've been doing it, but, uh, a I'd love to get your thoughts here. FBI is actually reaching into people's systems to delete files. And, um, it seems like, uh, you know, you should get some permission maybe, I don't know.
But, uh, what's your take on this and are there legal implications here? Yeah, I can sum up my take on this. In one line, the road to perdition is lined with the best of intentions, and I get what they're looking to do.
And, and it's a, it's a noble right? The, the, the end, the goal is, is a noble goal. Like let's get rid of malware.
The means leaves a lot to be desired. Right? And, and so the road to hell is lined with the best of of intentions.
Do I trust the FBI to come onto my machine and delete files? That's how I trust I I trust them over the Chinese government. Yeah.
Well the Chinese government puts files on and then take, you know, well, exactly. But, you know, but that's, but that's a different thing. The Chinese government are cl clearly doing that.
Not with the best of intentions. Well, maybe it's their intentions. The FBI is doing it here to do the right thing.
But the, you know, this is akin to should the FBI have the ability to crack your iPhone encryption. Well, or they have, have they already been doing this, Alan? Yes.
Here's, you know, what's, here's what's fascinating to me about this, is it's not the FBI deleting the files. They actually hacked into the servers that delivered the plug X code, um, that's been out this, uh, forget it with the panda group, whatever it is that funded this. So they hacked into the servers and put in their own code that, uh, will go out and, and deliver an instruction that was already there that deletes all the files that were part of this plug x, uh, Trojan and any files it created.
So you're using the, the hackers, the bad guys own mechanisms to do this. It isn't the FBI logging into your system, they actually hacked the hackers. Um, I'm not sure if that's a bad thing.
I don't know. That sounded like two wrongs making a right, but I don't know. Well, but you end up in the right place.
Right. But did they do this without notice? Did they do this undercover of darkness?
Oh, Did they not, wasn't the servers in the us I don't know where the servers are. I have to look at the article and see what, what it says. You know, I'm, I'm reminded of the case a few years ago during covid, I forgot why.
I think, I don't know if it was a Chinese in Eastern European group hacked some healthcare folks. I think it was Atlanta, Baltimore, one of the towns. And they were paid in Bitcoin.
And miraculously about a week later, the, the, the bitcoin, the, the, the, the malware group got all mad and put out sort of, you know, stuff online. How dare that their Bitcoin was stolen. You know, their Bitcoin disappeared.
And that's when I first realized, you know what the NSA can make Bitcoin disappear. Um, and what, you know, that something we've gotta, that's a reality. And I, you know, so again, road to to tradition, right?
The, the, the, the, the, the intent and the cause is, right. And Mitchell, in this particular case, yeah, they did the right thing. It sounds like the problem is the, the, the potential for malfeasance here is, is bad.
Did they go get some sort of court order for this? Like, what, what was, what was the, from nine 11 Bush, the Patriot Act, they set up the court. We, we, law enforcement would have to go get permission before they did something similar to this.
So this is even more entwined, Alan, because the servers, I just was doing a little search, the servers were actually taken over by the French government servers are located in Tokyo. And so the FBI worked with the, the French, uh, law enforcement agencies to put this, turn this coat on and have it delivered. So it's not just us doing this.
If we actually have a multi government plot here to, uh, delete files, A assuming that the servers are under Japanese sovereignty, did they say Okay. I mean, that's kind of the, I don't know. That's a good question.
Yeah. Dynamics. Did this thing get really compelling?
You'll, I don't think the Japanese are gonna come forward and say that. No. I mean, what servers were taking over, think about it.
Are the Japanese gonna say, yeah, we gave permission to this French and American to come in here and hack in the servers under our jurisdiction. So none of yours just letting you know the French and Americans, if we would decide, we're gonna let 'em come into your servers too, here in Japan. Japan is never gonna say that.
I mean, 'cause they took over the servers to, to basically cur, curtail and block the botnet that was happening. That Plug X was distributing. So there were good reasons why they took it over right now.
Okay. What about this scenario? I mean, if it's not them, who should it be?
Or wait, No, no. I'm not saying if it's, I I I'm just saying there needs to be an oversight. There needs to be much is in the Patriot Act they set up, I forgot the name of the court that was set up for Patriot Act Court, The Pfizer court When, uh, yes.
I think that was it. You need to set something like that up to prevent abuse. 'cause this is, this, this activity is prone to abuse depending who you believe.
Right? I, I mean, I think that that's true of any situation where you're dealing with centralized networks and, you know, we've seen Facebook employees getting caught stalking people through the platforms that they mm-hmm. Are supposed to be protecting.
This is, this is true of, of anybody that has too much power. I totally agree with you. And I think we have five watchdogs here.
If anyone's Watching, maybe we should be the court, not a kangaroo court. I Mean, I'm just saying. Yeah, no, I, I hear you.
But that's what you need. You know, you don't want whistleblowers per se. I'd rather have a court that they go to beforehand and get permission for this kind of thing.
I, I think what they did, they very well have been extremely reasonable and good. And I applaud it More real time research. They got, they went to court to nine different courts in the US starting in August of last year to get explicit permission to delete.
So They did have permission. Yes. Yes.
Alright, so then good for them. I applaud them. Good work story's over.
There you go. Congratulations to the FBI and our good friends in the French government, it was probably Interpol or someone. Right?
I think, I think more transparency is still required here to kind of say, okay, what exactly did the court approve and when and why, and Well, you can make a freedom of information act on that. Yeah, I'll get that. Well, hopefully with ai I might get that in a week, but right now I'll get it in nine months if I'm lucky.
Good Reason. Here's an AI tool. I would use something to expedite the request of documents.
Mm-hmm. Hmm. So how long though will it be before you think and, and I'm not throwing red meat out there at Allen just for grins, but, um, you know, so I take over your server, I insert malware and suddenly I'm deleting all the files blowing to the political opposition because, you know, I've met, oh, I'm sorry.
They were all, Are you saying that doesn't happen already? I don't know. Maybe, Well, Mike, now taking another example, who's being naive now?
Mike, maybe they Should delete TikTok for us if they, once they ban it, maybe, you know, what about that scenario, right? Mm-hmm. That's a real scenario.
That's A, that's a really good point. Yes. Only if Elon doesn't get his hands on it.
If he can't have it, no one can. Yeah. It's one of the reasons, by the way, the head of the don't, By the way, there's a, there's a headline out that, that the head of TikTok will be, has been invited to the inauguration just sitting near the swearing in.
Um, Well, he paid a million dollars to the inauguration committee too. Why? Show it me?
Yeah. Yeah. Beware Foreign entanglements.
George Washington, what was it? 1796, Mike. So what they gonna do, just flip a coin and give it to one of the cronies for, is that how that's gonna work?
Isn't that how Putin does it? I it's oligarch. You parcel it out.
Uh, that's how land barons, that's how Barons work. Sorry, sorry to sorry, to set this on a Background saying, oh boy, we go Friday. I Know, I knew to, I, I, I figured we'd get into TikTok given that there's, you know, we're talking Chinese government, and this is obviously very fresh on our minds.
I think Elon running it is NA non solution. Um, i, I just can't see that happening. I think more real we'll see an extension.
Oh yeah, that's going awesome. You know, it all could be, it all could be moot too. I mean, if there's also a trumpet issue, an executive order and just say nevermind.
So anyway, I think that that's likely to happen because there's too, there's too much money at stake That one. So would you, Would you sign up for an FBI service that would essentially do cyber hygiene on your system to delete all these files that, you know, essentially it's a national security issue. So maybe we should all just kind of, you know, subscribe to some service, hopefully one that we can turn off with a Single point.
What, what could go wrong with That? Well, that would make them a commercial interest. I don't know that that would ever happen, but Yeah, it's patriot.
It would be, It would be free. It's part of your tax dollars. It's national security.
Look, if you had, if, if you don't have anything to hide, what difference does it make? Mm-hmm. That was always The thing.
Well, yes, but I'm Never gonna buy, I'm kidding. I'm being No, I'm never gonna buy a car that has the ability to be shut off externally. I have a very, how Do you know That these newer cars have kill switches?
And they do. Yeah. And I will never buy a car that has that.
I'm never gonna be in my, So are you gonna stop walking and biking? What are you gonna do? I'm gonna keep fixing up My old, my old Mercedes.
You Can presume they'll take over your electric bike too. So. Right.
But, but the point is that I have no intent of ever, You know, I, I'm remind Just our principle don't like that capability. Mitchell and I are, it's still secure around 2006, seven, something like that. Six or five.
We get a, we we're doing NAC for the DOD, we get a call from SecDef office if we can write a NAC test, net network access control test to make sure that the USB port on laptops are, are, um, disabled. Disabled, yeah. Yeah.
It's pretty easy enough for us to do what, you know, why you wanna do that, nevermind why you wanna do it. We just wanna know if we can, and if they're not disabled, do not let the machine on the network. Relatively simple thing.
Mitchell has the engineering team do that. We edit to the next release for DOD and it goes in right away. We find out about a year later, not through freedom of information acts that, you know, some foreign entity, probably the Chinese government just went into the Pentagon parking lot and threw USB sun drives into you.
Like they dropped, a bag dropped, and the hyper intelligent people over there picked them up off the floor and said, oh, great. A USB driver, I could use one of these and plugged it into their laptops. Hence the Chinese stealth fighter program was born.
Um, so, you know, this is real deal stuff happens. And certainly when you're in the government or affiliated with the, because you know, only 20% of the people in the Pentagon work for the Pentagon. The rest of them work for the, you know, beltway bandits.
Um, but when you are doing work, you, you do give up your right for them to come onto your machine. And I, I don't, so that I don't have a problem with, I, I do have a problem if I'm not, if it's not government affiliated my work or my laptop or my device or what have you. Um, we served with like the, remember Mitch, there was a time at RSA all the rage was the bifurcated phone systems where really you couldn't, you couldn't pass through that.
It was like a blood brain barrier, A blood brain or brain blood, whatever barrier. Um, versus having two separate phones. I, I don't, you know, I could see us heading that way.
That that's the way of it. Um, I, I do think the gover our governments have a right to make sure that critical infrastructure, national secrets stuff that, you know, we need, if they deem it necessary is, is, uh, protected. It's the same thing during nine 11 or right after nine 11, remember, they wanted to hack in all the phones and, and computers to see if there were plans for more attacks.
And there was this whole debate raging that gave rise to the Patriot Act and the fe of court. Right. Given, Given the level of trust, you know, if you ask the question, do you trust your government, at least to US citizens, I think the overwhelming answer would be no.
Given the climate we're in. So them doing something like this would, I think would meet a, a lot of opposition. Sure.
What's interesting is the reason for the no. Yes, exactly. Depending if you're blue red here or there.
Right. The, the no has a very different thing right there. The Blue and who's in office and you know, red who's in office, and you know.
Exactly. Exactly. But that's, I think that's the world we live in.
But who knows, in this case, let me just wrap the bow here. In this case, it does appear as if the French government and the US FBI went to appropriate courts, worked with the Japanese government and did the right thing here from a, you know, following the good Doobie rules. And, and so kudos to them for that.
And thank you for doing this, And don't pick up any USB drives in the parking Lot. No. That, and that's the moral of that story.
And Tony's airport wifi chargers that are public, Arguably do it faster next time then, because it takes too damn long to get it through the court system and prove Well, but, so, okay. So maybe we need a FEA court kind of set up where that can be expediated. Mm-hmm.
Well make use AI to make it faster. Right. And I, and I would say, you know, we should set up a red and a blue service.
You can sign up to, depending on your personal, A forum shopping for that. That'll work. Yeah.
Excellent. Excellent. I think you know what, it's time to start the weekend.
Oh, boy. So we can write that, uh, spy novel we're all talking about. Yeah.
This has been, this has been a great Friday edition of Textron Gang. We hope you've enjoyed it. We had a good time.
Um, we've got a full on Textron TV day for you after this. Check it all out. We'll be back Monday with lots of, lots of good fun here on Textron Gang.
But we hope you have a great weekend. Stay away from that Chinese malware. And until next time, this is Alan Shimel for Textron Gang.
We're out. Hello and welcome to the digital CXO podcast. I'm Amanda Ani.
I'm excited to be here today with the Work Leap, co-founder and chief Innovation Officer. Gr, how are you doing today? Hmm, I'm doing good.
Uh, thanks for having me. Can you share a little bit about Work Leap? What does your company provide?
Yeah, that's for sure. So, uh, work Leap, uh, we are a, um, SaaS company. So basically we do software to help, uh, organization to, uh, build a better employee experience and to make work simpler.
So, uh, or software or services, uh, goes all around the employee experience. So from the first day someone is hired, we help them become productive from day one. And then we do, uh, everything around engagement and recognition.
So we, um, analyzing, um, employee engagement, making sure that people recognize themselves, performance management as well. So making sure that, uh, everyone stays, uh, on top of their game, uh, uh, all along the journey with the company. And, uh, we have various, uh, and we have the learning, uh, aspect too.
So helping every people to keep, uh, developing themselves during their, uh, lifecycle with the business. So it's, uh, it's large. We have a lot of different product and in place, but, uh, this is something that, um, we see as mostly small and medium mid market type of businesses are looking for.
And to be a good, let's say, uh, number, we, we could, we have to call ourself the number one, add, add-on on top of your, let's say, basic HR system. So payroll benefits and stuff. So we are the, uh, the all-in-one for everything else to create a good employee experience.
Great. Thanks for sharing. Well, that means you're the person to talk to about our topic today, which is vanishing workplace data.
And, uh, HR is losing a lot of data about its employees and you feel that, uh, this is a problem. 'cause there's a lot of great information there that could help companies. So can you share a little bit about that and what you're seeing?
Yeah, for sure. So, um, it's fun because, uh, most of the time I've meet, uh, I meet with HR people. So, uh, the, um, uh, people that, uh, that, that is strictly focused on people.
And now, uh, I know, and the part is more on around IT professional. I have a dual background, so I am an it, well, well, an engineer, uh, uh, from, uh, from my training. And I've worked a lot, a lot in, in, in that field.
But then from, for the last 10 year, I've been building stuff for HR people. So I have a, a specific view, specific view on the topic. So the way I'm seeing it is that, uh, since hybrid work or remote work for some organization started a couple of years back, so, um, or digital footprint just grow, grew a year over year.
So just, uh, as a, a key stat, let's say. So we see that, uh, around 300 million terabytes of data is created every day, uh, in, um, in organization. So that's a lot of, um, of data.
Uh, this thing or this context makes it really harder to manage your people to get a better sense of how they, they are doing online. They are not always at the office. You don't have all of these small, small, uh, habits or small, uh, things that people does as a manager in, in presents with your team, let's say, and things like that.
So the, the, the job of knowing your people, uh, managing your people, uh, managing performance of your people became really harder with all of these data. So second revolution is obviously ai. I won't be the first talking about that in, uh, this year in, in the, in the, in the upcoming episode.
But AI is a good way to analyze a lot of data and get a sense out of it. So what we do, or what we are, uh, working on is how can we, um, analyze all of these, the digital footprint of every worker. Obviously we specialize with knowledge worker, so people working on the computer that don't, don't necessarily, it's not necessarily true for every type of worker, but let's say for knowledge worker, me, you, the audience right now.
So people that is interested in that, like, how can we look at all of these, uh, documents, this data and get a sense of what's going on in the business. So from, uh, the employee from the first day someone came in to the last day, let's say, what happened, um, and, uh, and and so forth. So the goal there is to connect to all your, um, your, um, your internal system.
And then with ai, we analyze everything. We get some insights around people, like employees, their experience, how they collaborate with each other and everything. And then, uh, get some insights and take action on that.
So for company leaders who want to implement AI to get these better data insights, what is step one? Yeah, that's a, that's a great question and this is something that I've been working a lot, uh, internally as well at work. So, uh, I think that the, the good first step to really, um, leverage ai, uh, to, to get some insights for your, your teams is really, so I, I will just explain what I'm currently doing, and I think it will help people to understand.
So basically the goal is to have like a clean, clean sources of data. And we know it's not that easy for, uh, every business. So worke is a 18 year business.
Uh, we grew, let's say we had, we had two acquisition in the past two years. Every time you, you change a business, you have new people, new systems coming in and things like that. So just a basic example.
So we have let, let's say five CRMs inside the business as of today. So if you have five CRMs, the data is a little bit scattered in every system, and it's really hard to, to to, to get a good sense of what's going on. And then, uh, ultimately the goal would be to automate stuff based on the, these data.
So, uh, the first step that, uh, that I'm, uh, that I always suggest is to clean up your mess or clean up your, uh, your data, data, uh, system or data architecture. So consolidating your internal system, uh, making sure, uh, put, put some processes in place to make sure that the data is, uh, actually good because it's not, because you only have one system that that data is good. So making sure that you, you put some processes in place to, uh, to help having like a good quality of data.
Uh, so setting up your business to have a good data quality and then, uh, implementing solution, uh, like work leap on top of that would be way better. Obviously there is also some product that can help you, uh, do that, but, uh, this is de least step one would be to, yeah, clean up your mess. But I, I see it in, uh, with a smile in the sense that it'll always, it will never be perfect, but at least having, uh, a clear guidelines on how you want to have your data set up.
And then you, it would be way more easier to, to set up some tech on top of that. Okay. And so then once they've started this process and they're in and they're in that, um, integration phase, what are some things you've seen companies struggle with during that implementation phase face?
Yeah, I think, uh, like, like we just talked, uh, I think the data quality is definitely the, uh, ultimate things. We've been talking about it like for 10 years, 20 years, you probably had some podcasts on that subject, uh, a couple years back and things like that. But I think it's, uh, and this type of project is always hard to, to, to get funded in the sense that, okay, I have a big, uh, a million dollar project to clean up, like data and all of the system, things like that.
So it's, it's really hard to, to get, uh, something. But I think the, the yield, what we need to remember is before that, it was mostly for a analyzing data. So having some good report or, uh, operational report around like the data that you have.
But now with ai, you'll actually be able to automate and take real decision and apply those decisions live. So let's say, let's say it's a million dollar investment, so you'll be able to, uh, automate stuff that will probably save you a million dollar in the future. And we see, we see this, uh, this trend, uh, coming in and a lot of specific, uh, vertical, let's say customer success is a good example of that.
Uh, we see a support center, um, starting to, um, to, to analyze, let's say a support the tickets and everything and be able to, uh, answer the customer automatically having a better response. And so it's faster. So it's good for the customer, it's good for your business because you, you don't have, you don't need to do all that repetitive, uh, work.
And I, I think it's also good for the customer in the sense that they, they have, uh, a, uh, faster response. And when you escalate the thing, so basically for people that is working behind the these AI thing, they can actually take the time to look at the solution and find like, okay, what's, what's going on there? So that's one vertical, uh, on the, on our side work mostly with the employees, but, uh, this is a good parallel to do and this is the type of thing that, uh, I think we'll see in various, um, type of worker and departments in the upcoming years.
Mm-hmm. So for the future, AI is advancing rapidly. What do you see for HR and the workplace that you envision AI being used for employee, uh, data retention or anything?
Yep. Uh, so I think I will, I will start with the most obvious thing and one of my favorite topic as well. So performance reviews, performance management.
This is, uh, in my opinion, it's one example, but this is, I think the, the one that will speak to everyone here. So doing performance reviews, performance management, it's not that fun and it's pretty hard. Uh, couple of things around that subject.
So, uh, when I say that it's, it's hard, it's like, okay, you need to take, you need to gather some information about, normally, uh, companies do the 360 feedback. So basically they ask feedback for, um, the individual, the employee, the some peers, and the manager. Then the manager takes all of that feedback, try to get a sense of it, ask, follow up question and try to, to make his smile on that.
The manager does a review. The review is, is validated by the organization in the big scheme of thing, and then you meet your, with your employee to, to discuss those results. And, uh, and that, so this is a process where a lot of pieces of information and a lot of, uh, some bias as well, but a lot of, um, potential error, uh, can happen during the analysis.
And obviously the ultimate, uh, outcome of that is most of the time a salary review for the employee, which is one or the most important things for every employee. So the whole process designed to review a salary, it's, it's kinda critical to most org or organization. So I believe AI and, um, adding access to, uh, the, the, the full digital, full f footprint of each employee will help bon this process in a lot of ways.
Let's say we'll be able to, uh, get facts around people rather than impressions. Uh, we'll be able to go, um, a year, let's say a 12 month history instead of, uh, uh, relying on your memory, uh, of let's say a couple of weeks, a month max. So basically you'll be able to have a full picture of, uh, the timeframe of your, uh, performance management.
You as a manager, when you manage 5, 10, 15 people, and then you have, let's say a hundred feedback to analyze and digest and things like that, it takes a couple of hours per person if you want to do the, the job properly. But with ai, uh, AI is very good at looking at the different point of view from employees to, uh, to peers, to manager find the problem, the difference, the difference with the, the rest of the team. So, uh, being able to, to assess like these insights instantly will really save the problem where will, will really save some time to the managers.
And ultimately, and I think this is the most important part. So when you meet an employee with all the work that you did, I think the discussion, this is where you can have the most impact on your business, like having a, a good performance discussion at the end of the day and, and having the backup and the tools and everything to support that discussion. This is where like, uh, employees, uh, can, will either that go against the business, but either be mad or happy and move forward and help your business to, uh, to grow.
So this is one example. I could reapply, like the same type of logic for employee engagement, recognition, uh, learning experience, things like that. But this is one thing that, uh, I truly believe that can be completely changed with AI and data.
Wonderful. Well, if there was one key takeaway you could leave our audience with today, what would that be? Yeah, that, that's a great question.
Um, I would say that, um, I think that the business in the future will drive if you start like looking at the best, uh, the best way to change the way you operate and you, you do your business today. So I think it's, it's more like, I don't want to be that, that a bad profit, but like the, uh, I, I feel like business that will drive in the future are the one that are get, are getting started to really change how they work today. So this is, uh, for me, it's, uh, this is what I'm building a set of work leap and, uh, I truly believe that, uh, AI is about to really change our, let's say, uh, knowledge worker type of business or department, let's say within business, uh, work and will be, uh, performing in the future.
Absolutely. It will be interesting to see how the future unfolds. Well, thank you so much for coming on our show and sharing your insights with us today.
Yep. Thanks Amanda. All right.
And thanks to our audience, stay tuned. There's more. Welcome back to Textron Unplugged.
My name is Cassandra Chen and today we're here with Mohammed Abu. Thank you for having me. Can you introduce yourself?
Uh, of course. I am Mohamed. I am originally Moroccan, lost in Stockholm, Sweden.
Um, much different count country in terms of culture and weather obviously, but uh, it is what it is. Uh, I work as a backend engineer in Spotify. I'm also one of the Java champions, hunter to be part of, and also Google developer experts in Google Cloud technologies and also a community member of different communities.
So how did you initially get into technology? Um, it wasn't actually planned. I wasn't one of the kids, like you for example, that is really into tech and got involved in an early age.
Uh, I was just like a, a normal kid following school, uh, the Moroccan system. And uh, then, uh, there was like, kind of my study path was either mathematics or software engineering. And then I ended up in software engineering because like mathematics was too much theoretical for me.
Too much. Yeah, concepts, um, software engineering was much more fun 'cause like you can have hands-on experience, build stuff, play with it. And then when I tried it first that Sparkle started where it's like you build your first's.
Hello, your first, your first hello or demo, your first HTML website and that like sparkle joy, and it was like, yeah, this is, this is probably where I want to be. And, uh, here I am. That's a lot of fun.
Yeah. How was your experience with communities? Uh, so that part I got, uh, involved at an early age and, uh, my first involvement was while I was civil students in Morocco, Java user group together with Bodi, which you already know, and Faisal, which are the f both of them are founders of the infamous Devox Morocco conference.
Uh, so I got involved at an early stage, right when I was, uh, a student. I was attending some, the meetups that they had. We had monthly meetups, and then after graduation, I sit still kept involved after a few years, they, um, had I, I, they gave me the great honor to be a ju leader, so I joined them as a JU leader.
I'm still am a Morocco Jug ju leader. So yeah, so it was an early career move from my side to be part of the community and eternally grateful to bother Fi. And also another guy who, it was called Hassan, who basically, so I worked with him in my, probably the first company that I worked at.
And we were trying Docker before even the first release. 0 release. And then we kickstarted the Docker community and he supported us to kickstart that work.
So I'm eternally grateful for those three guys, for the mentorship, the community involvement, all the guidance that they gave me throughout the years. I think it's really great you had people like that supporting you. Exactly.
I think mentorship or finding the people that could mentor you, especially in your early career can, it's a decisive and very important moment in your early career. So find a mentor that you trust that is supportive, that you can always go to, to ask for advices, both personal and career advices. What is, uh, discussed with them?
What's your next move? Where, what's bad? Discuss with them technologies, discuss with them everything.
And having that mentor, uh, person that you trust or could be not only one person. I had three mentors basically, which each, each one of them, uh, I went to for a specific, uh, type of questions, but eight of them help with me in a specific way, in a different way to be the person that I am today. So having a mentor, especially in early career is really important.
Do you ever feel like you give back today? I'm trying to, uh, by staying involved in the community, um, both Morocco Drug and Devox Morocco. Um, I'm also very proud of a project that I started together with, uh, Moroccan based community guys, which we call gigs, blah, blah.
Um, so basically this is an initiative that discusses, uh, for, uh, new joiners or early or beginners in IT industry. Everything in tech, uh, DevOps, Java, backend front and ai, you name it, and Moroccan dialect and Moroccan language. Uh, when I started 11 years back, maybe more, all the resources that I had to learn was either in French or in English.
So it was not that entry level. The entry level was a little bit complex. You need to learn the things, especially in the beginning with a for real language.
'cause like it's a second, third language for us both for us and English. Uh, so behind gigs, blah, blah, me and a couple of folks, we said how we can change that, why we not provide a platform for the Moroccan youth, especially the one interested in software engineering, to have a platform where you can tune in every week. Now it's like, it's a weekly podcast where we discuss everything around technology, uh, livestream.
We allow them to ask questions in specific topics. We cover wide areas of topics. We are almost in, our 200 episodes are going week in, week out to discuss with the Moroccan community, especially the youth ones around everything intake.
So I feel like that's one way of me giving back to the community for all the things that I've learned got from it. And, uh, saying a small thank you to the, to the community, especially the Moroccan community that's helped me so much. How long has this platform been in development?
I think it has been more than five or six years. Uh, it started around 20 18, 20 19, and the idea was basically to have, as I mentioned, this, uh, monthly on dvu. So we started as a monthly cadence once a month, and then we gained a lot of Memento, a lot of people got interested, then we started to have it every other week.
And then we turned out to be weekly. And a lot of people got involved, a lot of people joined. A lot of people went because that's live, people come and join.
But it still, since four years or three years at least, were week in, week out, we took August off because we want to have a break. And then we have that every week, week in, week out, uh, discussion around, uh, everything in think in Moroccan dialect. So it's been almost five years, maybe more, uh, in, in the making.
Is this closer to like an open source project or a made up? Uh, so we started online and we stayed online because the impact is bigger. Uh, Morocco is a large country, not as large as the US for example, but it's still as a large country and moving from one city to to another, it's quite challenging.
So if you have a physical meetup, the maximum GA is 2050, let's say 100, let's say 1000. But you still limited for the impact you make to the local community within that city. Uh, and then you need either, some people need to travel and travel can be cumbersome or we need to move around different cities to share the knowledge and make it, uh, yeah, do the stuff that we want to do.
And both ways are almost ideal. They are kind of limited online is offering us this scale, even if before lacking the, uh, face-to-face hallway track discussion or so allowing us that you can tune in online from the convenience of your living room and join us in the discussion. Or if you missed the episode, then we publish it the next, it's selling YouTube in Twitch and then you can follow it from your favorite podcast platform.
Apple PO Apple Podcasts, Spotify, uh, Google Podcasts, but that's scaled now. So we offer different mediums where we can listen to the podcast. So online is definitely, uh, the way that's helping us to grow.
And that's mainly from an impact and scale, uh, point of view. We organize, we use to organize maybe less now because some of us went different ways, but we used to organize meetups just for that to meet the community. And every year we organize an conference, which is online.
It's the same concept, but it's just like five days, five days of specific topic. We have five tracks full day of, uh, a discussion around a specific topic, we call it blah black home. And then we have another day, which is offline.
So we gather the whole community during one day in that community conference where we meet everyone together. So we try to mix and match best of both words. Having that all experience allows us to scale and reach as much people as possible, but we're all also trying to keep that, uh, face-to-face discussion, meeting the community where they are, uh, and having those lats and brilliant moments in real life as well.
I think It's really great that you can scale and reach a lot of people while not losing that face-to-face time. Exactly. I mean, there are pros and cons for both options, but yeah, we, we try as much as we can to have the best of both words.
I believe you also helped run the Devox Morocco conference. Yes. How was your experience with that?
Um, I'm very proud of that project and how it grow. Uh, kudos to the founders, uh, bother and faisal for the amazing work they did during the last 12 years or so. So it was originally called Reb and I, the first ever gre I was an attendee there, so I was an attendee, uh, in the two or three editions, and then I joined as part of the team in 2014 or 15.
And that was a great experience for me. Uh, and then Devox Morocco is, is a Devox brand, so you have all the great stuff from all the devoes around the world in Morocco. Uh, all the speakers you included, you are giving a keynote in their sneak peek.
So it's, it's gonna be, it's one of the greatest technology conference, not only in Morocco, but in the Middle East region and North Africa at probably to say the whole Africa as well. So we have a variety of tracks, uh, six tracks, so maybe more covering a variety of things, backend, front end, DevOps, ai, now everyone is speaking about AI from technology experts to share their knowledge. So I think it's a, it's a really important, uh, conference and that's added a lot of value to the tech ecosystem, not only in Morocco, but in Africa as a whole.
I think you've really given back to a lot to the developers of Morocco. I am trying to, I, I, as I told you in the beginning, I love being part of the community. I feel like the community gave me a lot, uh, and I've tried to give back and help as much people as I can from the community work that I do.
'cause like at the end of the day, what people remember is the legacy that you left and leaving that good legacy, uh, as small as it can be, is something that I'm always looking forward to. And I hope that, uh, through that work, through that diversity and variety of work that I'm getting involved with, that I can try to leave a good legacy for the Moroccan youth and the Moroccan ecosystem as a whole. Thank you for all you've done for the Moroccan community.
Thank you for having me. And uh, it's been such a great discussion. Thank you.
Thank you. Thank you very much. Cheers.
This is Textron tv. Hey guys, thanks for the throw. We're here with Nick Klowski, who's the senior director for Research for Islands.
And we're talking about CSO salaries and compensation and what's going on with, um, the money as they say, Hey Nick, welcome to the show. Hey Michael, great to be here. Thanks for having me.
They say, with great responsibility comes great compensation, or at least that's the theory. So what are we seeing here for CISOs? They're clearly under more stress than ever, but are they getting rewarded Incrementally, but not necessarily to a degree that reflects the level of pressure that's been added to the role over the past year or so?
We are seeing significant compensation increases when CISOs change jobs, but the market's been fairly stagnant. And so overall compensation has been increasing at a declining rate compared to some past years, And yet the responsibilities are increasing. Is that gonna continue or do we need to kind of break up the job a little bit more?
We ci CISO's kind of becoming almost digital risk problem solvers. They're the folks in the org who are really best equipped to solve a lot of digital problems. So they're getting pulled into more and more processes.
We don't see that changing anytime soon. We do see CISOs looking to add more functional department heads to their team in areas like AI data governance, particularly around data actually, and getting some more support systems around them to balance out some of those responsibilities. But what we see really interestingly is the CISOs who have taken on a new job that has a dramatically larger scope are generally really happy about it.
They're excited to have that new opportunity and they're going into a new org with a chance to kind of build from scratch and solve some key problems. The CISOs who are just having new responsibility thrown onto them without a huge compensation bump, without a change in org are just kind of getting all the problems dumped on them, is kind of how they end up feeling. And this having a significant downward impact on satisfaction.
So finding ways to support those CISOs more effectively is gonna be key for orgs to keep them happy and retain them over time. You know, I, I looked at their report and that was one of the things that leapt out at me a little bit is that, uh, it felt to me like the new responsibilities were enabling the CISOs to be much more proactive rather than reactive and made me, one of the reasons they're happy about it is they can actually do something about preventing a problem versus always being in the fire bucket brigade. Oh yeah.
A lot of these developments are great for the ciso. There's a bigger seat at the table, there's a larger voice to influence the organization. There are more opportunities to solve problems at the ground level rather than being, having a fire thrown over the wall at them.
There's just more opportunity across the board for CISOs, it's just a question of growing pains to how much time it takes for the support systems around the CISOs to build up to help them keep up with the stress and incremental challenges that come with all those opportunities. How big is the talent pool for cybersecurity leaders? I mean, we hear that the overall pool is small and the percentage of those folks that are able to maybe have a conversation with the business is even smaller.
So you would think that given the relative amount of expertise that's available, that the salaries would keep going. So what's mitigating factors? It's really just the lack of movement.
We're seeing in general a lot of economic uncertainty across 2024, election season, geopolitical conflict, et cetera, leading to a situation where companies are generally not hiring a lot and folks aren't trying to move a lot. We start that to change in 2025. We've had 75% of CISOs are interested in a job change and we expect companies to start opening up more opportunities.
Right now it's been a little flat solely for the reason of lack of movement. We do believe that that movement is coming and that we're gonna see changes next year. What is the overall turnover rate like for CISOs these days?
I mean, is it high, medium, low, or about the same as it's always been? What's your sense? Retention has been very strong historically.
It's been a very quick turnaround role, often as short as average of 18 to 24 months. We are seeing that change and shift in CISOs are sticking around for longer. But we want to caution folks who are looking to hire CISOs that that's not because everyone's happy and really pleased with their jobs, it's because the opportunities and the movement in the market aren't there.
And once we, once that movement picks up again, we expect to see a lot of change. Is it your sense that CISOs are getting better at being able to talk to the business? I mean, one of the things we heard for so long was that CISOs needed to get a seat at the board, but when they got there, it wasn't clear that they understood how to communicate in a way that the board could understand.
So are we making any improvements There? Definitely it's, it's a long road and everyone's in different places, not just CISOs as individuals but organizations as well. There's a bit of everyone having to kind of come together and find a middle ground boards and executives need to start getting a little bit conversant in cyber and technology just because digital tools are such a critical part of the business and CISOs need to be able to translate up to those or to that part of those parts of the organization more effectively.
We see both things happening. Some orgs have gotten really good at it at this point. Some CISOs are excelling there, others are starting to catch up and get better.
We're seeing competence overall becoming stronger though How we perceive the relative happiness of a CISO and their investments in ai. Are there gonna be some correlations there? Because I think one of the issues that has always been troubling is there's just a lot of paperwork and a lot of toil in the whole profession.
So you know, maybe we're on the cusp of where this becomes more manageable. We are seeing automation growing as a talking point heading into 2025, but AI is still at a stage of promising way more than it can actually deliver. And for the most part we hear CISOs at a place of frustration of everyone's rushing to use ai, but it's not delivering the business value commensurate with the risks.
When we can find the right use case, it's great, but the number of use cases where AI can really help us are still fairly narrow, but looking for more ways to automate more ways to become more efficient and distribute some of that work is becoming critical. How is the accountability changing for this position? We heard a lot of, um, discussion about these issues when the SEC law was being debated last year and the year before.
I'm, you know, is the job just the definition just dramatically expanded? Yeah, it's very complicated right now because the CISO role is so different from organization to organization, there still isn't a defacto, this is what a CISO does. This is always what they're responsible for.
This is always what's under their jurisdiction. Therefore, everyone knows, okay, if something went wrong in this area, it's on the ciso. There's a lot of navigating who actually has the direct signature responsibility for this risk decision?
Is it the ciso? Is it a line of business? Some folks want to share risks, some CISOs want to be risk influencers, but not the decision makers.
And some are starting to take ownership of more areas of risk that wouldn't traditionally fall under cyber because they're the most knowledgeable person to do so. There isn't a defacto best practice at this stage. I think the emerging ideal scenario is one in which the CISO is an active participant and leader in the vast majority of digital risk conversations.
But the business unit leader who is closest to the actual process is still the one ultimately owning that risk in partnership with the ciso. What does it take to be a CISO then, for all the folks who are watching this who kind of are already in cybersecurity and are thinking about, um, maybe, you know, moving up the ladder, I'm assuming there's a lot of soft skills, but other than the fact that maybe after improve my golf game, what does it take? Start building cross-functional relationships and getting involved in business projects?
We see what happens a lot. If you talk about, think about the development of a typical sales leader or marketing leader or organizational function, the nature of their work exposes them to a variety of executives and a variety of lines of business in a way that helps them build the relationships and the varied knowledge of how the business works and how the business makes money to impact the org. Whereas a lot of security leaders, as they call it through the engineering ranks, the analyst ranks, they get siloed in the technical side of the business and then they get into the more executive ranks, the leadership roles and they're asked, okay, start impacting the organization and how it makes money.
And they just haven't been exposed to it by osmosis and they've had to try to catch up on what other folks have been doing gradually for years. Take the time to get involved in some of those cross-functional side projects that might not be directly under your jurisdiction. That might be, you know, volunteering for broader risk committees, things of that sort serving on nonprofit boards that will help get you exposed to governance issues and how governance leaders think about things.
Those kinds of side projects can kind of start helping you build those soft skills and those influencing skills that become more important in the CISO role. How Do we get the business folks to buy into that? 'cause they'll be blunt about it a lot of times.
You know, they see the security people coming and they just clam up and they're trying to do some projects somewhere and they're hoping that it'll pass down the road, but they don't wanna share early. So how do I get the security people into that conversation when it might make a difference sooner? Ultimately, it's kind of the same as most business relationships on some level are transactional.
What can you do for them so that they'll do something for you? Go in looking for ways to help them to make their lives better, to solve their problems, understand what they need and what they want from an interaction with a business partner and do what you can to help them. And then when you show them that you can offer them value, they're gonna be more interested in bringing you into conversations earlier and having you involved.
What's your crystal ball telling you about 2025? Is demand for CISOs gonna increase? Will there be more salaries?
Should CISOs go higher their own agents like a ball player? I don't know how much demand on the high level will increase, but movement from CISO role to CISO role will we expect fully to increase dramatically? We think our real recommendations for CISO is to kind of figure out what is their unique superpower, what is the thing that makes them special?
And look for the roles that are with orgs that need that specifically. There's a lot going on scope wise, but ultimately what's driving business expansion and business growth is gonna be what makes them excited for a specific CISO in a role and help you differentiate from the other CISOs in the industry. I think it's fair to say that um, CSOs have a lot of stress.
Have you seen anybody do anything or kind of master any techniques for managing that stress? 'cause stress equals burnout. The CSOs that I see who are most balanced are able to find ways to take ownership of their calendar and not get pulled in so many different directions and kind of choose where they go.
That's usually comes from a blend of building strong leadership teams below them so they can delegate more and take on more strategic tasks themselves and not be as in the weeds and building executive partnerships so that they have the respect and influence in the org to kind of own their calendar and own their priorities because they know the rest of the org knows that they're balancing and aligning with the business. One of the things we've seen in the last year, and I wouldn't call it a major massive trend, but it's, uh, showing up more often. You're seeing CISOs maybe take over the entire IT department, um, and sometimes they become the CIO.
Is that a viable thing or, um, ultimately should I always have the CISO and the CIO be separate functions because maybe, you know, it's too much of, uh, the Fox Garden, their own in house. Yeah, we see about 30% of CISOs have ownership of some elements of it. As we speak to the community about this, they're pretty excited about this transition as an opportunity to kind of have more synergy between what's going on in the technology side of the shop and the security side.
Ultimately what's happening is there more and more orgs are putting most of their technology in the cloud. There's less infrastructure to manage, there's less business value to be gained by being better at managing the technology and there's more business value to be gained by getting better at managing the security and the digital risk. And so the CISO is being positioned to own the technology, maybe having ahead of technology reporting into them while they're kind of a CISO and CIO role and we expect this to continue becoming more common.
And we see this both in very large orgs and very small orgs. It's not, it's not a phenomena that's just for smaller orgs that are very resource constrained. I almost feel like there's a separation now between security ops and the actual threat hunting and being an analyst and, um, some of that security ops is being managed by an IT team that may or may not report up into the ciso, but it feels like we're getting more into separation of concerns with our limited resources.
Yeah, a lot of traditional lines in security, whether it's between security and tech security and privacy security and data governance are all getting blurred and responsibilities are shifting over to the places where it just ends up making sense for that business. Um, I don't know if you have children or not, but if they were in college, would you at this moment recommend them to get into the cybersecurity field and become a cisa? Yeah, it's funny, I was, um, one of our faculty, Steve Martino was just talking about this yesterday, if he, his, his language is something to the effect of, if I was talking to a young professional or someone heading into college and they were deciding do I wanna go into it or go into security, I would wholeheartedly recommend they go into security.
Alright, well folks, you heard it here. Hey, as always, with security, it's the best and worst of times then no matter what year it's gonna be. But the good news is, hey, compensation's worth it.
Hey Nick, thanks for being on the show. Thanks for having me, Michael. Guys, Hey everyone, I'm Alan Shival and welcome to the last great cloud transformation.
Uh, this is a video series that we do about every two weeks. Um, every two or three shows though we actually do it with a live studio audience where we ask you to participate and help lead the conversation. Unfortunately, this isn't one of those episodes, this is just a, a recorded episode with our panel here.
But nevertheless, it's a great conversation, especially if you're interested in what we call or actually what CloudFlare has come to term, the connectivity cloud and what do we mean by the connectivity cloud? You're gonna find out all about that during the course of today's show. In today's shows.
In today's show, we're gonna be talking about multi-cloud security. You know, multi-cloud is, is, is is quickly becoming the dominant, uh, format in, in cloud usage among enterprises, actually even in small businesses today. But, um, securing multi-cloud had has its own set of challenges.
We have two other people besides me to discuss this today and I think we're gonna have a great conversation. Let me introduce you to them. First of all, I wanna introduce you to Annika Garbers.
I hope I got that right, Annika correct. You did. Thank you.
Annika, tell us a little or share with our audience a little bit about yourself. Sure. So happy to be here.
Thanks for having me. I'm Annika, I'm on the product team at CloudFlare. I'm a director of product for our network services team.
So my job at CloudFlare, the past, oh, a little bit over four and a half years has been talking to customers to understand the journeys that they have been on in digital transformation, cloud transformation, and then the challenges that they have experienced in, uh, connecting and securing their multi-cloud environments. Um, so super stoked to be here and to get into that more today. Absolutely.
We're super stoked that you're here. And Ha and joining us, joining Annika myself is, is my partner Mitch Ashley. Mitch is the CTO here at Techstar, as well as CTA and analyst with RUM Group.
Hey, Mitchell, it's great to have you on again. I I know you are. Just back, was it from Barcelona?
Barcelona For a conference out there and you lost your voice. So we, we try, we'll try not to tax you too much today. Well, it's coming back.
It's coming back. Not fully there. I I'll have my radio voice next week.
Okay, good enough. So, so guys, let, let's talk multi-cloud a little bit. You know, I'll, I'll be honest, I, I have a confession to make.
I didn't see multi-cloud coming. You know, I, I've been involved in security since the cloud first came on the scene 2005, 2006, and I always thought we'd have hybrid cloud, right? Organizations that run some of their, uh, uh, infrastructure in a private cloud, private data center, and some in a public data center.
But I never thought that the multi-cloud, uh, model would be dominant. But yet, you know, I think it's a recent, uh, a recent, uh, Oracle survey, something like 98%, virtually every single 98 out of a hundred enterprises are either currently or planned to have multi-cloud deployments. You know, we were talking off screen, Oracle themselves now has partnerships with Amazon, Google, and Microsoft, as well as having the Oracle cloud itself.
Those are probably the four major clouds, you know, public clouds in, uh, in the, in the western world. Anyway, um, you know who, who saw this coming on ground, Warren? I'm thinking, I mean, cloud Flare.
Did, did you guys sort of anticipate that we'd move to a multi-cloud world quite as quickly as we have and then of course anticipating what challenges that brings? Yeah, I think, um, when we talk to customers, so I have that opportunity occasionally to present to large groups of people at conferences and things like that. And I always trying to ask an audience question to gauge this because I think it is really interesting understanding the different path that people have taken to multicloud.
And so I'll ask as a starting point, you know, how many of you here are dealing with multicloud in your environments? And like you said, you know, this bears out in the data, but then also anecdotally, it'll be the vast majority of hands in the audience go up. Almost everyone has a multicloud environment.
And then I'll ask, okay, for how many of you was that, uh, on purpose an an active choice that someone in your organization made an architect or someone doing a cost analysis or someone doing a capability analysis where you were like, yes, this makes sense for us intentionally, and almost all the hands will almost go, always go down. So people have ended up in multi-cloud environments sometimes because of mergers and acquisitions, sometimes because, uh, one cloud had a feature like that was very specific and needed for some use case that another one didn't and you had to use it. Um, but then now security and network and IT teams are really grappling with this, uh, situation that maybe was not necessarily like, thought through or intentionally designed or planned or architected, um, at the front end of an organization starting on their cloud journey.
And now they're dealing with sort of the, okay, what do we do about it moving forward? Agreed. It it is, uh, so I'm not alone.
That makes me actually feel better in some twisted way because, well, I also feel validated a bit too, Alan, because it seemed to me the thing that drags everybody into it is m and a. You can't help that. You know, it's just like any other, we now have three CRM systems and two ERPs, and which ones do we consolidate and what do we live with or what can we take advantage of, right?
So it seemed almost inevitable that we're gonna be multi-cloud just for that reason rather than there was a day. I think, I think, um, it'd be appreciate your FedEx perspective on this. I remember the day when we were saying, you know, we should have multiple clouds so that we have vendor diversity and can compete on price and, you know, so that AWS or Google or or Azure doesn't kind of get too full of themselves and charges too much money.
'cause we'll just move to the other practicalities of that are of course much more complex. That seemed to be the thought when we coined multi-cloud, but now that's not really the reality. Do, do you agree with that?
Yeah, absolutely. I think, you know, for the few people whose hands remain up when they say, yes, this was an active choice and not just something that I'm dealing with as sort of a, a consequence of m and a, the reason that they, uh, made this active choice within their organization really break down to one, uh, not getting locked into a single vendor for storage and compute, right? Having that ability to shift applications around if you want to in some cases because of cost.
Um, and then in other cases, because of redundancy and resiliency, like maybe, maybe they have really business critical applications that have to be able to stay available regardless of what is going on with the cloud provider. And either internally or because of pressure from like a regulatory body, they've made the decision, okay, we're going to, um, we're gonna have the same application redundantly operating in multiple clouds. The other reason that we hear is because of, um, essentially feature parody or specificity or requirements.
Um, and increasingly with developers that are working on, uh, workloads that include ai, we're seeing this as a reason, um, that, uh, folks might choose to go with one cloud provider versus another. So I think we see a variety of reasons, um, but then the challenges that are then present again for it, uh, and network and security teams, um, look the same regardless of sort of the reasons you ended up in that boat. Right?
It doesn't make a difference how you got there. Exactly. Issues then.
But I I, I agree with you. I look, I've spoken to a ton of people who, you know, for whatever reason they thought GCP had the best Kubernetes, right? Mm-hmm.
Support AWS serverless, right? If you were looking to do serverless, you the AWS and, and then, you know, Azure, believe it or not, Azure DevOps was a, was a big draw for people and for, you know, teams that were doing that and the get hub IT stuff And integration with the rest of your Microsoft stack, right? You Microsoft Work, Microsoft shop, and if you're an enterprise, Microsoft has a lot of enterprise customers, you know, and, and absolutely.
But as you said, regardless of what journey or what path they took to multi-cloud, here we are, right? And, and, okay, now we're here. Now what?
Well, there's a couple of things. Connectivity, moving data among a multi, and let me throw another wrinkle. Not only are they multi-cloud, they still have stuff on prep, they still have private cloud, right?
So, and that's, I I think that's sort of a, a soft white underbelly that we don't talk about. You still gotta secure that. You still got, you still got data there, especially large enterprises.
They have their mainframe, they have their, you know, on-prem stuff. So, you know, this brings up this whole connectivity cloud as, as CloudFlare has, has labeled it the idea of we need yet another cloud, if you will, or at least a service that ties these together, especially as it relates to connectivity and security. Right?
And, you know, Mitchell and I, our backgrounds are in security. We've been in security 30 years. You know, let's talk about specific security challenges within multi-cloud environments and, and maybe some of the ones that connectivity cloud is, is hitting head on.
Annika, I don't mean to throw it on you, but hey, you are the expert. Sure. What do you see?
Yeah, I mean, I think, uh, when we talk to customers that have been through this journey, which is pretty much everyone is somewhere all along the, along the journey of moving from, um, some on-premise data center where there's a traditional castle and model for security to, uh, multi-cloud or hybrid cloud. Um, you mentioned the existence still of the legacy stuff on-prem. We totally see that.
We also are increasingly seeing more organizations, um, move toward repatriation projects, at least for some small percentage of their application that move to public cloud. And then they realize, oh, actually for cost reasons or control reasons or whatever, I need to shift it back. So there's, there's all this mess.
I think the, the biggest shift that we've heard people articulate is really, um, in insecurity at least, uh, the shift from a very centralized model for security, where you used to be able to sort of draw this neat perimeter around your corporate network and say, okay, everything inside of here is trusted. Everything outside of here on the public internet is scary. And then I'm gonna put my big stack of defense in depth tools, my firewall, my intrusion detection system, my VPN concentrator, uh, my data loss prevention service, et cetera.
Like put that big stack sort of at the, the Castle Moat, watch every packet coming in and out. Um, and then, uh, and then I, I'm sort of good now. Uh, applications and users are no longer within that defined corporate perimeter, and the lines are not clear anymore at all.
Everything is super blurred. And so we think that, um, this has, has, is going to result in a fundamentally different approach or a different architecture model that security and IT teams need to take the how they connect and, and secure their endpoints. Because if everything used to be centralized and now everything is distributed, it's not enough to just sort of shift, um, uh, approaches that worked in the context of data center security and say, Hey, we'll just deploy those in the public cloud as VMs now I'll deploy a virtual firewall and manage it.
Or maybe I'll backhaul traffic, you know, from a cloud environment through my data center security stack. Those kind of architectures made sense as sort of a middle state band-aid solution. Um, but don't for organizations anymore that are dealing with really, really distributed models, um, for where their sources and destinations of traffic can be, that's users and applications literally anywhere in the world.
Yeah. Here, you know, one of the differences, Alan, and how we think about cloud today used to be we, we built clouds, you know, connect things together, kind of like at a erector set, you know, connect A to B and C two B and all the different paths of our different places that we need to connect or network or we need to interconnect. Uh, is a company like CloudFlare in full disclosure, we're a CloudFlare customer also.
We use it for tech strong services, but it isn't just, um, you have connectivity to hyperscaler clouds. It's also you, you've already worked with those providers of what their security control plane looks like, what their load balancing and, and uh, kinda management control planes look like. So it's not all left on the customer to go figure out, well, if they're working with CloudFlare, it is not all left on the customer to go figure out.
Now how do I manage all this across multiple hyperscaler cloud vendors? Correct? Yeah, exactly.
The idea essentially with the connectivity cloud is that you can, can sort of put Cloudflare's distributed global network in between the users wherever they are on the internet. And that could be like public users that are trying to get to your public facing websites or applications. It could also be your employees working anywhere in the world.
Um, but you, instead of sending all the traffic from those users to some centralized location where you apply all of your security filters through maybe that traditional stack of hardware firewalls and things like that, instead of doing that, you can enforce security at a location that is super close to them, like just milliseconds away from wherever they are in the world. And then CloudFlare network or our connectivity cloud can help accelerate that traffic from that point close to the user where reinforce the security controls all the way to wherever the traffic's destination is in the world. And that could be somewhere in a data center, it could be somewhere in one of multiple public clouds, it could be somewhere else on the public internet in the case where we're helping secure a SaaS app.
So that's, this is kind of like a, the, the, as the, um, the way that we think about compute and security has been flipped on its head from this centralized to distributed model, fundamentally we're approaching security from a really distributed, um, sense as well. And it's not just deploy a bunch of virtualized firewalls and different clouds. It's actually this fundamentally different like edge security based way to think about it.
You know, I I, I agree with that a a lot. We, um, when you, when you think about that whole old model of backhauling traffic back, you know, to the central place, I think Covid spelled the death nail of it, right? All of a sudden no one was in the office anyway.
So what, what sense did it make to back haul all that traffic there, to run it through those big honking machines when no one was there? 'cause we was just sending it back out. You wanna talk about waste and, and so, you know, like the movie, anything from anywhere, anytime or whatever, that, I always got that movie's name wrong, but it, that's the model today we're, we want to do anything from anywhere at any time, Everything everywhere, all in once.
Totally. That is how our customers want it. And I think you're so right that Covid was kind of like the last nail there.
Yeah, I mean, the shift of storage and compute to the public cloud certainly led the charge. And I think a lot of organizations have been, um, resistant or kind of lagging in their approach to moving networking and security also to the cloud. Because from a feature, a feature perspective, the public clouds invested primarily in the experience, developer experience and the features around the storage and compute capabilities.
But then with users also now moving to, uh, an ability to be distributed anywhere, the, the, um, the chips have kind of started to fall and people are recognizing, okay, we need this different model now. But, you know, the way of the world is maybe for those laggards who were late like that, it actually worked out for them because they didn't have a connectivity cloud two, three years ago to do this. That's a good point.
We, we talked to some organizations that are, uh, able to kind of skip a little bit of those middle steps where they've deployed a bunch of the sort of band-aid solutions, they didn't pay taxes and actually taking the opportunity to reimagine it. Yeah, yeah. Right.
Trying to put this together, you know, point by point and finding out, you know, and we, I call it idiot taxes, right? You're paying 'cause you just learned those lessons over and over. Um, so I mean obviously a big part of it is having a CloudFlare like, uh, point of, you know, point of contact network where you are never too far from any edge or any end user.
And then of course, going back to these hyperscaler centers, um, security's only one piece of this though. It's basic connectivity as well, right? I might be running my, my Kubernetes stack in one cloud, but you know, or maybe it's my, uh, systems of engagement is in one cloud, but my system of record is back at my data center and my front end web servers are somewhere else, right?
That, to pull that off, giving latency the way it is, right? You need a connectivity cloud, right, to optimize the A to B2C to the end user experience. How, how do you guys do that?
Ika? It seems like, you know, either a lot of AI or black magic or a little of both. What do you think?
Sure. I mean, uh, cloud's mission overall is to help build a better internet. And this started with a focus on public facing application.
So things that are already on the internet, public facing website or other, other apps that you might use as an organization to serve like your end users. How do we make those things faster, more secure, more reliable? And then as we started learning from larger and larger organizations about the challenges that they're having, not just on the public facing infrastructure side, but also the internal infrastructure, everything kind of within the remit of like the CIO or the ciso.
Um, they were articulating many of these same challenges with security, connectivity, reliability, and the desire to use the public internet for more of the path. Like you've heard maybe the phrase like the internet is the new corporate network, but the internet wasn't built to be a corporate network was not built with the kind of security and reliability requirements, um, in mind for really, really business critical traffic. And so we think about it as how can we help, uh, act as sort of an, an overlay for the internet in many ways.
Um, not building a separate internet, but helping make the internet as it is, uh, today, uh, high quality enough, reliable enough, secure enough, performant enough in order for companies to trust even their most business critical workloads, um, to send over that traffic. And that looks like things like having lots and lots of different connectivity options. Every one of those points of presence on the map.
And so if one upstream transit provider is having a bad day, there's some congestion, there's a route leak, there's some other problem, no worries. There's tons of redundancy and other options for how to route traffic around. Um, and it's, it's the depth of connectivity, like all of those different interconnections, a global backbone that connects them as well, which is just sort of another tool in the toolkit to use, um, to, to help accelerate traffic performance.
But then also the intelligence that sits on top of that, of, uh, how do we not just pick the best path based on sort of default BGP routing, but actually apply, um, smarter ways of making traffic steering decisions based on the intelligence that we have across the view of the global network. Um, so connect at all of the places have lots of different options for how to get traffic from A to B, but then make smarter decisions for how to route it. And that's based on both sort of synthetic and then real information about the traffic routing across the network and Do all that in real time, right?
With near no latency L and everything else. It's gotta be, That's, that's the black magic part, But, well, I think, I think too, also you have to deal with it in two worlds, right? You want the sort of simplicity of it, right?
I won't have to worry about all the details of what interconnects with what I just want my bot management done this way, or my web application firewalls set up this way. And if I want to take it more detailed, I can say this is, I want it done differently in different locations. But then you also, if you take it a layer down, well, okay, well what if I wanna do application security, I wanna be able to do API management across all these locations.
I don't wanna have to do it different in every cloud provider I'm interconnected with. So are there some ways that I can, it may not be centralized that, but but do that in one consistent way across a connectivity cloud like with, with CloudFlare. And then the other is, well, I do wanna get into the detail.
I do want to put workers out on the edge of the network that are gonna do these kind of things. They're gonna be running my code as part of the network as well as in the, in the hyperscaler environments. So you, you want the connect and go sort of the simplicity of it, but when you need the detail, when you need the control and you need to get into the depths of it, like every enterprise is gonna do, I'm sure I doubt there's any enterprise customer says, yeah, just connected it up and we're good.
Right? They're always worrying about performance of this and that and security and this data, uh, data sovereignty and localization and what has to be where and what network, how we do production. That's where the rubber meets the road is you've gotta handle all of those use cases at an enterprise level, but not make it so that, well, it's just easier to do this myself.
Right. You know, now that you're not doing any, managing any of the complexity for me, but you, you do, you are, you have to do that for your customers. Yeah, absolutely.
I think, uh, uh, our goal is to provide an abstraction layer that simplifies management and configuration for customers as much as possible. Like it should come out of the box super easy to set up logical defaults that make sense for all the things. So the abstraction is there, but not, um, uh, a black box in that you don't, uh, have the controls if you want them and you need the visibility to, to understand what's going on.
So you should be able to connect and have sort of like logical, um, uh, uh, you know, smart controls in place for your traffic and for security as a baseline. But then you're right, enterprises need and want the deep visibility into everything that's going on, the ability to get packet captures of all of their traffic as it's distributed across their network, the ability to see logs of all the information analytics reporting, and then also dig in and, and kind of tune all the little buttons and their knobs for the places where they want customization that is there for their environment. So it's a balance for sure.
Um, but we know that it's really important to be able to do both of those things in order to again, build that trust that organizations lacked today or have lacked in the past about shifting those really business critical workflows to use the public internet as their underlay. Yeah. You mentioned logs and that brings up incident management, incident response kind of things, right?
Where I'm, if I do all that connectivity myself, I've gotta intersect with everything and what went where to which provider and can try to trace that back down versus if I'm going through clear of a common cloud that's doing my interconnectivity, I've got a way to pull that together more easily. Not saying it's always gonna be easy right there, there's some challenging situations to really kind of put it all back together, but I'm not tracing down every place it might have touched just to begin, starting to put together an incident management, uh, you know, what the kill chain was for a particular attack. I've got a place to start where it might have traversed across one or multiple clouds.
Yeah. And that's something that we hear customers really struggle with a lot with this shift from the, the very centralized to distributed model for security is, okay, maybe I've put some band-aid solutions in place where I have one secure web gateway solution to help with internet traffic filtering. I've got another solution that replaces my VPN, I've got another solution over here that does some data loss prevention for me.
And when you zoom in on any of those individual points in the architecture graph, like maybe those solutions make sense, but then when you zoom out and look at the full picture and as an IT or security or network admin who's just trying to troubleshoot a problem. You have like eight or nine or 20, or actually, I talked to a CISO recently that said 80 different security tools to contend with, um, to just even try and start understanding what went on in a situation. And hopefully you're not at the point where you're, um, investigating like a, a breach scenario, but, um, maybe even something that's as simple as just a, a connectivity loss.
A user says, Hey, um, zoom's really slow for me today. Where do you even start at, uh, at, at solving that problem? We think that the way to do it has to be this fundamental rehaul of the architecture where you're thinking about security and connectivity in a distributed sense, but then the visibility is still centralized, right?
All of those different nodes that are, are enforcing the policy and making the connectivity citizens have to sort of report back to one place where you can actually go and see all of the things. Um, 'cause otherwise it is just impossible to actually control or manage in, in, um, you know, in a practical scenario. A I've got another question for you, and I'm sorry that we, we, it's only me, you and Mitchell.
So, you know, you, we got you on the hot seat today. I apologize. But let me, let me ask you another question.
One of the things that I've always valued is I wanna choose my partners, right? Maybe CloudFlare is my partner, you know, for connectivity cloud, but I like company a's identity security company b's, other security company, c's, uh, you know, I like to pick my own vendors. How, how hard is it?
So do I give that up when I say, Hey, CloudFlare, I need your help with, I I need a connectivity cloud. I'm, I'm all over the place and I want to kind of centralize things. Oh, but by the way, I do have maybe not 70 or 80 vendors, but I, and I got a dozen How?
Yeah, totally. Uh, so our intention is not to even attempt to be all things to every single company. I don't think that there is a, a world where, except for maybe very, you know, niche scenarios, small, small startup companies that only have some, some very specific security needs where you're managing less than, you know, three or five security vendors.
We actually view ourselves as enabler, um, for, uh, customers who want multi-vendor environments for redundancy and for resiliency, especially for the components where that makes a lot of sense. So we think, um, connect, uh, or excuse me, cloud environments, so public clouds, we wanna be an enabler Absolutely. For organizations that are pursuing a multi-cloud or hybrid cloud strategy.
The idea there is you can use CloudFlare as sort of a, a unified control plane for the security controls for all of those public clouds, so that you have consistent web application firewall rules, DDoS protection policies, maybe bot management strategy, et cetera. But then you can actually shift around the storage and compute that lives in the different public clouds and or your on-premise environments. Um, use the best of breed capabilities in those clouds, as we were talking about earlier.
Um, but your security team doesn't have to worry about sort of like the, the attack surface looking different depending on where you deploy your applications. So that's one example. Um, but I think even within the internal connectivity context, you know, we, we partner really deeply with, uh, lots of different identity providers.
If you have a one or multiple and you wanna integrate those in, we play nice with all of those providers. If you wanna keep your existing on-premise gear and use that to connect into us, you've got, you know, investment in an existing SD WAN provider, you wanna continue to use it, that's cool too. So we recognize it's super important for us to, uh, to not just say, Hey, you're gonna, you know, burn down everything you have and, and start fresh.
That doesn't work for anyone, especially large enterprises. And so it's really about where do we invest deeply in strategic partnerships with, uh, tech providers that we view as sort of, um, working with us in the, in the way that we wanna help customers adopt this new architecture that we're helping them shift to. Um, and then where there places that having a multi-vendor strategy actually does make customers' lives harder.
And then how can we make that easier for them over time? Love it. I get another sort of conceptual question for you and then, and you know, you've got your CloudFlare hat on, so you're speaking on behalf of CloudFlare now.
Um, so we look at the cloud landscape. I mentioned AWS, Google, Microsoft, Oracle, right? Those are the four big ones for most of us.
How do, how does cloud flare think of connectivity cloud? Is it a fifth cloud or is it something that just sits on top of these other clouds? Mm, big question.
Uh, so we are increasingly seeing organizations build more and more of their applications actually directly on Cloudflare's network. So we initially built out the global network infrastructure primarily, again, for connectivity and security for, uh, our customers public facing applications. Then sort of extended that into the quote unquote internal facing, but is increasingly becoming public facing, um, the sort of era.
And then, uh, as we explored more and more of those use cases too, we kept finding these places where customers are like, Hey, I actually want to run part of, or in some cases, my entire application on the edge close to users. Um, AI inference is a really great example of this, where you have to make a trade off sometimes as a developer of how much of that workload can you run on the user device versus sending back to a centralized cloud and then sacrificing like the latency in the application. And so CloudFlare sits in this kind of great Goldilocks place to be able to do that specific kind of of application.
So I think we think about, um, you know, what, what we're doing is different. Fundamentally, if you just look at the picture of the, the dots in the map, the connectivity, the types of services that we offer, um, is not a one for one copy or intended to be of the folks that you listed as sort of the four major public clouds. And again, we view ourselves as actually an enabler of multi and hybrid cloud environments for our customers.
But we are seeing increasingly places where customers are like, yeah, actually that computer storage workload makes a ton of sense to deliver super close to users wherever they are in the world. And we're really excited to work with, uh, developers to continue to enable those kind of use cases. Um, and I think we'll see more of that moving forward.
Yeah. I know your, your offering there has evolved a lot in the last three or four years. Absolutely.
Yeah. It's been interesting to, to watch it too, because when you talk about working with developers, um, I mean, there are, can, can be some basic things you might be able to allow or enable them to, to build or run in the cloud, but you're, you know, you're talking about supporting frameworks, you know, things like react, uh, or, uh, you know, no JS or things like that, next JS pages, whatever it might be. Um, so the more you can provide a familiar environment, not saying it's exactly the same as you're gonna run in your own, you're gonna cloud instance inside of a hyperscaler, but to build applications to run in, in Cloudflare's environment, um, you have to offer some of those same capabilities.
You gotta offer storage, you gotta offer some serverless options, things like that and frameworks that they can operate in. So, uh, that, that takes some thought. You don't just jump into that, into the pool and say, Hey, we have developer support.
'cause developers say, say, no, you don't because you're missing 25 things I need. Well, you got 20 of 'em, so you're close. Let me get started.
Mm-hmm. I mean, that talk, talk about that journey, especially the security of apps that you build in a, in a cloud flare cloud. Yeah, I mean, it's the long game for sure, but I think we're really encouraged seeing the number of developers that continue to build full stack applications on the CloudFlare platform or really critical components of their applications.
Again, with things like our, our AI for developer stack. Um, but you mentioned, you know, security and connectivity, that's sort of like the baseline if you're a developer that's working on, uh, building an application that leverages some or all of our developer stack security and connectivity and, uh, and traffic performance is just built in, like that should be, uh, not even a, a, um, a thought process that you have to have of like, okay, then how do I add this to my application? It's already there.
And that includes, that's, uh, in addition to things like the visibility, the multilevels of controls, um, and then the guarantees around sort of performance and user experience, again, of delivering those pieces of the application as close as they can possibly be to users. So if your developer, um, uh, uh, working on a new application that that uses our stack security and performance, um, are, are essentially just built in, that's sort of the guarantee from, from moment one. And then it's really about, okay, how, uh, how creative can you get?
Like what are the types of really exciting things that you can then build, um, knowing that some of those constraints are free or you get that time back in your developer experience. Fair. Yeah.
Guys, we're almost outta time here, but, um, time goes quick. 'cause we were just, I mean, I think we've ran through a hundred different things. I lightheaded swimming from everything we discussed.
One last question for you, Ann. How's that? Sorry.
Security never gets easier. It, the security seems to be, yeah. You know, as much progress as we make, and, and I'm talking as a security person, as much progress as we make, it always seems like there's more in front of us than there is behind us.
Uh, security never gets easier. Ai, all these new technologies, you know, with double-edged swords is good and bad. That comes with the not, you know, what have you done for us lately?
What do you, what do you see coming down the pike here, maybe with connectivity cloud type of operationally that, that will help us going forward, right? What, where's the cutting edge? No pun intended.
Where's the cutting edge for you? Yeah, sure. Um, yeah, I think you make a great point.
We have seen this shift, right? From really centralized to distributed, uh, users and, and applications and requirements for security. We think that that's only gonna get more complex.
So more and more distributed worlds, more threat vectors to be worried about everyone is being asked to do more with less. Um, and so then how do we enable that? That's the big question.
I think for us, uh, we're doing a good job if we're helping security teams spend less time on just day-to-day operations and management of the stuff they already have. Like if they spend, you know, a hundred hours a week managing their tool stack, how can we help dramatically reduce that? Spend 10 hours a week on managing the things that you already have and the rest of your time on actually engineering on, uh, the full list of things that you have, uh, demands from the organization, um, about all of these new types of threat vectors that people don't even have the chance to get to today.
I've never met a single CISO that said, yeah, my team has free time. Like, everyone always has a list sleeping, maybe many more items long than there's hours in the day. And so there's so much opportunity, we think, to, to reduce the operational overhead just by consolidating, removing that complexity.
And again, thinking through this architecture from a perspective of what are the actual challenges that we have now and where do we need to be in the future? And what are the aspects of the ways that we've thought about security for a long time that just don't make sense given that reality. And so the distributed nature of the approach that we've taken to everything we build, we think is really core to that.
Very cool, very cool. Annika, thank you. We, as I said earlier, you know, it's just you, I and Mitchell.
So unfortunately we, we kind of sitting here grilling you with, you're the person with the answers, but man, it's great. Just fine. You too.
Great. That was great. We loved it.
Um, I hope our audience out here appreciated it. Where's the one to go get more information on this? Where would you send them?
com. Tons of public facing resources in both of those places. Um, and also you can feel free to reach out to me too if you've got questions, wanna connect with someone at cloud play that can help you, uh, talk through or solve a problem that you've got in the network connectivity or security space.
It's very kind to you. Thank you Annika Mitchell, thanks for joining me on here. We hope you've enjoyed this, uh, episode of the last great cloud transformation.
And make no mistake, it is a great cloud transformation, right? There's a lot going on here, and we'd love to hear from you about what you are doing in your last great cloud transformation. And the best way to do that is to join one of our live sessions of this show where you'll have a chance to, to do that.
Uh, we'll put the information in the notes here for our next episode. But until then, on behalf of Textron Group at Cloud FLA and Annika and Mitchell and myself, have a great day everyone. Thanks for joining us.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Hi everyone, welcome to the Skill Up Days, uh, talk on observability. And today we are going to look at our topic from cap chaos to clarity. So what we're going to talk about in general is observability and how it helps, uh, organizations and how it leverages, uh, productivity in terms of microservice and Kubernetes.
Uh, so we have two speakers, uh, for this event. One is, uh, Amit. Hi Amit.
Uh, please introduce yourself. Hey, Faruk, Um, am Amit, I've been working in, uh, development and DevOps space for more than 13 years, and, uh, love being part of the open source space. Cool, thanks.
Uh, and, uh, so I'll introduce myself. My name is Faruk Kari. I've been into DevOps for around 17 years, mainly into, uh, banking and the financial sector, focusing more on, uh, containerization and DevSecOps.
Uh, and I like to teach. Uh, that's, that's all, I guess. Uh, let's move on, right?
So, uh, a quick, uh, overview of what we'll be covering today. So the first, uh, thing is we look at what exactly is observability, because we hear that word a lot. Uh, so we just try to break it down a little and, uh, look at what observability is, and then we'll talk about why we need observability in, in organizations and how it helps organizations to get business objectives, right?
And then we look at the landscape, uh, which is really washed, and Amit will help us walk through the different tools that are there in the ecosystem and how you can use them to leverage productivity and, uh, troubleshoot more, uh, effectively. And then we'll wrap up with a few keynotes. Okay?
So the first thing that, uh, when you hear observability, it's, it's kind of like an umbrella. It's a big thing. And then you can break it down into three, uh, separate streams.
So the first one is logs, uh, which we'll look at more detail, uh, later. And then you have metrics, and then you have traces. So think of it like an umbrella, which has three, uh, pillars.
The first is logs, metrics, and then traces. So let's see one at a time and see, you know, how, how this, uh, ties into the whole observability, uh, system. And why we need observability is, um, yeah.
So the, the reason we need observability is the first, uh, reason is easy identification of issues, right? So a lot of us have applications systems which are spread across regions. They are really, um, isolated in nature.
So what observability does, it helps us to identify where exactly the issue is originating from. And that in turn helps to resolve issues quicker. Then that's what makes business happy, right?
And, and the other thing that it does is, so once you find out, uh, where the issue is coming from, it also helps us to, uh, find out the root cause. Like if the server is down, why exactly is it down, right? Is there a memory?
Uh, constrained is the storage full. So those kind of things are very, uh, useful when you have observability, otherwise, you're kind of shooting in the dark. And then the, the last thing is you, if it observability, if you do it right, you can also go ahead one step and find out issues even before they happen, because these are generally, uh, there are indicators of issues which you can, uh, uh, find out through effective observability, right?
Cool, right. So let's look at logs. Uh, what is logs?
So logs is basically, uh, a stream of data or anything that's been generated by a system, an application, or any kind of infrastructure. So it could be a server, it could be a container, it could be a serverless, uh, resource that you're using on the cloud. So these kind of things are basically, uh, anything that's a resource that's running is capable of generating logs.
And generally logs are timestamped and they're sequential in nature, which helps to troubleshoot, like, and correlate. Like, if you go in and check, you can go into a particular timestamp of the log and then check it over there. Uh, logs also have different levels of, um, uh, uh, granularity.
So there are informational logs, which are just for information. Then there is also errors, and then you also have debug logs, uh, which kind of give you a pretty detailed, uh, logging, which is useful when you are troubleshooting, right? And so the source is generally the resources that we mentioned, like servers, containers, and, uh, app, uh, operating systems as well.
And logs are generally in text format, but you can also have, uh, different formats like JSON and XML also in certain scenarios, right? So logs are, are generally the starting point when you want to get started with observability. And the, the challenges that you might face with, uh, logging, uh, implementing logging are, uh, threefold.
Uh, so the first would be volume. So, uh, it's, it's sometimes very shocking the amount of logs the system can generate. So you have to kind of plan ahead that what kind of volumes you're looking at for each application or each system.
And you have to kind of do that capacity planning if you want to do proper logging. The other is also the speed at which these logs get generated, and how do you rotate these logs and how, what do you, uh, you know, how do you manage this, uh, huge resources that are generating logs every second, every minute, and just pushing them out there. And the third is, uh, the variety, because all systems have a slightly different way of, uh, you know, structuring their logs and their formats might be different.
How do you handle this? And then, uh, inspect these logs to make sets out of it, right? So to, to handle this, you generally have, uh, best practices that, uh, you need to do if you want to get the most value out of your, uh, logging solution.
The first would be centralized logging, because the, the last thing that you want to do is, uh, be running around and trying to figure out where your logs are. So the first, the first thing would be to centralize your logs in, in a central place, and then you can build on top of that, and you can do storage optimization and then visualization and all of the other stuff, which adds a lot of value. The other thing would be having some kind of log rotation.
Uh, so it could be based on time, so for example, every day. Uh, but the recommended one is based on size, uh, where, you know, you have a certain size when you're a log file, which is a certain size, uh, maybe one gb, and then you start creating a new log file. So that's the recommended way that you would want to look at, uh, loggings.
And the third is, uh, like I mentioned, that there are a lot of different type of, uh, loggings that happen. You have informational logs, which generally are only useful at a point of time, and they really don't have any, uh, retrospective value. Uh, so you kind of want to drop those logs, and there are solutions that help you to do that.
So the only logs generally would be then, uh, you know, debug and error logs, and then you have different ways of handling them. So the way the logs that, uh, are labeled would also, uh, uh, influence the way that you're going to treat these logs and, uh, store them, right? So that's logging in a nutshell.
So the next, uh, stream, uh, under observability is metrics. And metrics are kind of like, um, uh, uh, a data point, uh, or, uh, a space of time. So that's how you kind of think about metrics.
So for example, what is the performance of this server at this particular time? Uh, so what's the average for the past 24 hours? So that's, so metrics can then further be broken down into system metrics, which is mostly the hardware or the use resource usage, like the servers or the operating systems.
And then you have application metrics also, for example, latency and how, how slow is the page loading. So those would fall under application metrics. And then last, you also have business metrics.
So business metrics would, uh, basically mean that, you know, what is the SLA, how much uptime do we have? Is the application going down? So these are basically SLAs that the business really needs to adhere to, and these would fall under business metrics.
All right? Right. So the third one is, uh, tracing.
And this is generally the, uh, the harder not to crack among the three. So tracing is something where you try to create a user story where the user comes into your application, and then he goes through a certain journey in your application, right? So that's where, you know, uh, you try to map that.
And what this does, it gives you a lot of information about how his experience was, where he's navigating, what, what, what are the bottlenecks that he faces. So, for example, a user app and today's applications are all microservices, and they're all different applications within applications, which is microservices. Uh, so you want to be able to find out if a user had an issue and you want to be able to do that fast so that you can tell that this is exactly where he faced a slowness in the issue.
So was it, uh, a microservice microservice, was it a database or was it just across the application? Why is there latency, right? So the, the ability to do that, uh, and uh, look at issues like with through an x-ray lens is what tracing enables you.
And this is more towards performance optimization also. Alright? And, and when you have all this information, what it does, it helps you to correlate these data, right?
Okay. So some of the use cases, like I mentioned, is, uh, why observability is really important in today's time is because you, a, a, a single application would be talking to multiple different resources, multiple different, uh, components within a single application, right? And debugging, this could be a nightmare.
So the first thing is that it helps you whenever you need to debug and find out issues, which is, um, uh, you know, where issues happen, you want to do this. Another thing is you want to monitor transaction, right? So if you're into banking or finance, and you want to understand that this application or this transaction failed, right?
So you can't really afford to have a failed transaction. So you want to be able to highlight and immediately, uh, look into this or look at transactions, which are, you know, anomalies which are outside of the general behavior. Those are things that you know, you can do with, uh, tracing.
And then the third one is failure. So why did the transaction fail? And if it failed?
So there would be alerts that you can configure and, and catch that with tracing. So it gives you the ability to go back, uh, in the journey where the user was and, uh, fix that or monitor that, uh, transaction. Okay?
Right. So now that we know, we went through, uh, what is observability and why we need absorbability and what are the three general streams that we have under observability, uh, Amit will help us to walk through the different tools that we can use for these, uh, metrics, uh, tracing and, uh, logs. Over to you, Amit.
Thanks, Faruk. That was fantastic insight into observability. Uh, so for now, what we are gonna do is we are gonna walk through Prometheus.
Uh, protheses is one of the oldest open source projects, which has been used for metrics. It has more recently been adopted, uh, by CNCF and is guided by the CNCF in order to make it better and stronger and ensure it's always open source. Uh, so one of the main things which pros is used for is collecting and storing time series data, uh, more specifically metrics from everywhere, whether it's applications, containers, servers, so on and so forth.
Uh, all of these metrics are gathered and then finally stored in a specific type of storage. We then enable it to be queried using ProQ so that we can perform different types of analysis and aggregation. And finally, we are going to use all these metrics in order to alert DevOps engineers or SRE engineers in case of any issues, um, any specific issues that the metrics highlight.
And finally, it all comes together with visualization. So what is the Prometheus use cases? It's all types of system monitoring, whether it is resource usage monitoring, such as CPU memory, uh, you wanna find out the performance and availability, which is like uptime latency of your issue, um, or anomaly and bottleneck detection.
But again, it goes back into latency of your application. This gives you real time insights into all sorts of metrics that your application ensures to export. So how does all of this get visualized?
Uh, you are going to visualize all this metrics and information in a tool called Grafana. It is second, another open source tool for visualization, which specialize for monitoring metrics logs. Uh, it all comes together in one single GUI where you can visualize whether it's bar graphs and charts, uh, whether it's uptime and downtime.
Uh, all of it comes together within the setup, including your logs, which generally people tend to use by leveraging Loki. So how does a Grafana dashboard look on an average? So on the right, you can see whether you want bar graphs, you want dials, you want numbers, you can get it all.
You can pick and choose what is your preference based on your end users, and decide what type of visualization you wanna provide them. Whether it's monitoring infrastructure, whether it's application performance and latency log analysis. Everything can be done here in one single setup.
We then go to Yeager. Yeager is an open source distributed tracing tool. So this has been more recent of a tool, uh, in terms of versus Grafana and Prometheus, and this helps us in tracing and troubleshooting transactions in complex microservices architectures.
So what does exactly Yeager do? Yeager is going to try and trace a request all the way from the beginning or your first microservice all the way to the backend or your database system. It helps you to understand exactly how your transaction correlates from microservice one to two, to three, to microservice end.
What does this help with and why do we need to do this? This is so that we can visualize dependencies, we can ensure that we can find out which microservices taking the maximum amount of time or in case of failures, exactly which microservice caused this failure. It helps in the planning for better resource optimization or ensuring that each microservices receives whatever resources are required for it.
And lastly, but finally, it all comes down to improved reliability, improved monitoring, helping in debugging your systems and improving your SLOs. So all that you want to do finally is ensure that your MTTR is really low. Your MTTF is really low.
And how do you ensure all of this? It's by ensuring that it's very easy to identify issues in case of a failure, and you can resolve it fairly quickly as well as you can monitor every single microservice so you can identify a microservice, uh, when it starts showing symptoms of failure, not before it actually has a complete outage. And lastly, and not, uh, it's, it's now come back to ai and we have a new tool called KH HT pt, which has very recently been adopted by CNCF as well.
And what does K HT PT do? It's a operator, which is driven by an AI engine. You can pick and choose your AI engine, whether it's open AI, cloud, so on and so forth in order to manage, troubleshoot your Kubernetes clusters, your logs, et cetera.
So this diagram shows you a very well explained example where it analyzes your clusters, configurations, it processes all your logs, it evaluates all this data and information, which would be more complex for a human to, uh, kind of go through and analyze. A machine, on the other hand, can take all this information inside and process it in a very understandable manner and provide you proper outputs and insights along with recommendations of how you can improve some of your, uh, performance, as well as in case there are certain logs which are constantly throwing errors, it'll provide you recommendations of how you can permanently fix these issues. So as we were saying, it's a single Kubernetes operator that you install within your cluster, and it performs all the respective actions that it needs to do, whether it's understanding the complex problems, diagnosing all the different issues, and then finally going and recommending potential solutions or optimizations.
Right? So Amit, just, uh, I think, uh, with this information, if you look at this, uh, so you have for logging what, what, uh, the tool that I think is the industry standard is Prometheus, right? And, and then you have, uh, for, uh, metrics, uh, sorry.
So, so for metrics, uh, uh, for visualization, you have Grafana, and then you have, uh, Yeager, which is for tracing. Is that right? Yes.
And generally for logging, we tend to use Lokey, which is again, under the Grafana suite. So you, you are absolutely right. So basically the key takeaways as you can see is metrics collection, which is mainly Prometheus visualization, which is mainly Grafana distributed tracing, which can either be, which is, uh, managed by CNCF or RAF's, uh, version of tracing tool.
And centralized logging, quite a few of us use Lokey and AI management is completely new in this whole realm of things where case g PT is now the new tool, which a lot of companies have started leveraging, but there might be a lot more to come. Yeah, I think it's very interesting because, uh, you always had observability for a while and you had these three things, but now there is kind of a merger of ai and then you can leverage AI with observability. So that kind of puts observability on steroids, and then you can explore more with, um, power of, you know, ai, uh, models, right?
Absolutely. So one of the things previously is a lot of proprietary vendors used to sell you the idea that we have specialized, um, intelligence in the background where we can analyze all your logs and provide you these great insights, which would be very difficult for you to analyze. This has now been democratized and it enables a lot of people using open source to, uh, use similar such logic, um, along with which there are even formulas nowadays, which can help with anomaly detection, where you can add that formula into your Grafana dashboard.
And what that does is it compares your current week with the past week and checks for deviation from the norm. And if there is a deviation more than X percentage, it'll send you an alert saying that, hey, something looks different within your systems. Right?
Right. And also with, uh, yeah, I think, uh, Kate, GPT, you also have the option not only to use open ai uh, models, but you can also use Claude and any other models that you choose to. Yeah, You can even use a model you choose to deploy on your own.
So it also supports your, um, lama, if I'm not mistaken, which is currently, you can set it up yourself on your local machine or on your respective server and run it by yourself if you want your data to stay with yourself, and you do not wanna send it anywhere. Right. Right.
Great. Yeah, makes sense. All right, awesome.
Thanks Faruk. That was a great session. Yeah, thank you.
Thanks a lot Amed for your time. I think this was good. And generally when you want to start off with observability, I think, which one, which far do you recommend the most?
Like, uh, logging metrics and traceability, how do you recommend, uh, somebody just getting started should get into this? I would probably, uh, jump between metrics and logging. So I find that you need metrics or tools such as Prometheus in order to understand anything that you have.
And the second thing is logging. You want one single location where you can read all your logs, understand what's going on in case of any failures, so on and so forth. Yeah.
Yeah. I think, yeah, that's generally the way to go about it because I think tracing is generally the, the second phase where you want to get more mature in jobs, observability, then start with tracing, uh, because it takes a little more hands-on, uh, getting and implementing tracing. But you have a lot of tools that are making it easier now, right?
Like open telemetry. Uh, so if if your views you, you have used a lot of it, right? Faruk?
Yes. I think Open Telemetry is kind of creating a standard in the observability space where, you know, you need to have a particular standard and then it kind of abstracts that implementation, um, uh, nightmare, which we had for different vendors. And then you can use any, any solution that you want.
But in terms of transmitting the data and filtering the data and all doing all of that, that, that is where Open Telemetry is for focusing itself for, which is great. That is fantastic. Alright, so I think that's, uh, that's all, uh, we had.
Anything else you want to add on it? No, I, I think we have covered it all on a decently high level where, uh, this topic would be good to discuss between many different peoples on intermediate to high level to bna. Uh, it won't be overwhelming for them.
True, true. Yeah. Thanks.
It was lovely, uh, talking to Yamit. Thanks. And, uh, thanks everyone.
Hey everyone, it's Textron gang. If you don't like this, you could click to cancel. Hey everyone, happy Friday.
It's Alan Shimel for Textron Gang. You know, I mentioned click to cancel in the opening, we're gonna talk about click to cancel, but I kinda like the whole vibe of click to cancel. I wish we had click to cancel in more things in life, quite frankly.
Uh, it's, it's a cool concept. You could tell it's Friday, right? And it's been a hard week, but we've got click to cancel.
We've got more than that to talk about. I've got a great lineup of our gang here to talk to you about it. Let me introduce you to them starting off in Austin.
We've got our good friend Anne, a whole award. Hey Anne, how are you? Good morning.
Great to be back as always. Is that Still those New Year's streamers I see on the fringe there? You know, I think I still needed a little sparkle in my life.
All Right, well then I, I will say Happy New Year. Happy New Year. Thank you.
It's not too late. Thanks. I have to be honest, it'll stay up until Valentine's.
All right. It's a spring thing. My, my friend John Nichols, Johnny Nicholson, and I one, my, my best friend growing up, once he got married and lived in his own house, he, uh, he used to keep his Christmas lights up, like it was warm already.
It was March, it was April. I'd say, Johnny, why don't you taking the Christmas lights down? He'd say, that's a spring thing.
And um, and in the spring, he would take it up. Now, there are some people who say, once you make it past the spring, you're better off just leaving them up. But We, we call 'em Fiesta Lights after February.
After February. They're Fiesta Lights. Okay, we'll go with it.
All right, moving on from Anne to back back to the throne room at the palace in Silicon Valley. It's our, our resident royal person, John Swartz. Hey John, how are you?
Um, I just defrosted from Pittsburgh, so I'm back. And I'm back. And welcome from Silicon Valley home of the tech industrial complex in essential cog in the oligarchy.
Beware the oligarchy. I felt it was sort of like a George Washington kind of warning to beware foreign entanglements. Oh, it just goes, it just blows with the wind politically.
But I will, I'll, I'll keep it at that. But, um, yeah, interesting times here. And they'll only get more interesting and maybe frightening at the same time.
John, it's Friday and I'm not taking that bait. No, don't. Please don't, don't, no, no.
I I I'm gonna get past it. I'm Over it now. I thought I went with John Mar with George Washington, and that was nice and apolitical.
Uh, let's move on from Silicon Valley and move a little west to the guitar man. Our, uh, resident fu analyst and friend Mitch Ashley. Hey, Mitchell.
I'm glad to see you made it home from the cold confines of Boca Raton back out to Denver. Yeah, It was just a little too cold there for me. So it came, you know, to warm, uh, single digit degree Colorado.
At least that's what we have coming here. So, um, still recovering in a good way from an amazing, uh, Greek food dinner. We had a fantastic meal.
Oh, that was the last meal. That was last, well, last night, I, whoever was left, I brought to my house and we made dinner. I, I made dinner.
That's always fun too. Yeah, that was good stuff. But it was good seeing you left 'cause of whatever it was.
Yeah, Yeah. Good. A good all hands, uh, meeting in, in Boca, speaking of traveling home from Boca, he came, he saw, he went back, Um, went back, uh, you know, I, I caught that geriatric express flight and here I am back in New York.
You know what I love about the flights though? Getting on the plane, there's 25 people who need wheelchairs. Mm-hmm.
Getting off. It's like a miracle. A miracle getting off.
Two people need wheelchairs, the rest of them run. So A, Alan, I have some, I have some good news for you though. What's that?
That I was, uh, I wanna say at Carnegie Mellon they are developing, and actually I'm gonna add this to the story. They are developing with the airlines wheelchairs that can be taken straight onto the plane and, and be part of the Stadium, Expedite the process as part of a robotics program. That would be, 'cause PBI, if you guys have ever flown outta PBI airport Palm Beach.
Hmm. You gotta board a half an hour earlier start boarding to get all the wheelchair people in and, and I'm not kidding. When the flight lands, it's a miracle no one needs a wheelchair to get off.
I thought PBI stood for Please. Board Invalids. Isn't that What it is?
Yeah. No. Well, okay, I'm, I don't wanna get political, but you could go see, uh, either the Trump plane or, or, or Air Force one parked out there all the time too, because God, I was to how many days a week the president works.
It Seems to me if this conversation continues, we are gonna get canceled. So maybe we should Jump in. People.
Were clicking the close back. Anyway, Mike, it's good to have you back. It was good to see you in person here in Florida.
And Mike took us to some of his favorite haunts down in the area. We had some good meals and drinking, good, fun, good time. But we've gotta get busy.
As I mentioned when I opened the show, I love the concept of click to cancel. If only it worked. What makes me think the FTC is gonna make it work?
I don't know. But Mike, why don't you kick us off here. So we've talked about this last year, and honestly we were all a little skeptical, but now here comes this actual order from the FTC.
And so Ann, what's your sense? Is this actually gonna happen or will the new administration kind of cut their legs out from underneath them? And this isn't gonna happen at all, but it seems to me a lot of people I talk to, you know, Alan's point, are pretty excited about this capability.
I think it's an amazing thing, the concept being that if you have two, three clicks to sign up for something, it should be the equal amount or lesser to cancel. Um, I think it's a common consumer complaint, um, and they're actually ruling it out or enforcing it as early as May of this year. So I do think that they're serious about it.
Um, I think that the key aspects that I, I think are particularly helpful is the ease of cancellation, the transparency of what you're signing up for. Um, definitely like in in places like the App store, you can subscribe to things and not even know it. Um, and it, it's something that's really meant to protect consumers and help them understand how to get outta things that they can get into so easily.
Um, I think the consent requirements are also really important. But the thing that, uh, I read this week that I hadn't heard about before was the prohibition of dark patterns. So that means deceptive, manipulative, user interface designs, things that make consumers go into unwanted subscriptions.
I would say this is probably gonna get heavily litigated because a lot of companies are gonna lose this. Um, I can remember two instances where this took hours of my time, one of which was, uh, XM radio. I basically had to threaten legal years ago to get them to finally cancel our subscription.
And then Adobe, I fought with Adobe, uh, my subscription there for over a year. I had to actually involve my credit card company because they, they just kept charging me. And so the idea is that this will also save consumers time because a lot of time gets wasted in trying to understand how to get out of these things that you can get into so easily.
So it's a, a very logical and helpful, uh, mandate. And I hope that it, it, I hope they're successful with this. And then we can move on to resort fees because I didn't know about you.
Yeah. But they're working on that too. And, and that particularly grinds my gears because you can book a hotel for less than $200 and then you spend another 50 on a, on a hidden fee.
So I applaud them for doing this. I hope it actually works. So I, I have a rule at, at the very least, if I could sign up for something online, I should be able to cancel something online companies that say, oh no, if you wanna cancel, you gotta call this 800 number, press 1, 3 5, and then seven.
And then wait in the queue and listen to their stupid music for a half hour. And then they're gonna try to, in the case of like a Sirius f uh, uh, the satellite radio, oh, well, we'll, we'll give you, you know, a terrific deal. It's only 9 95.
No, if I wanted, I'm canceling. Well, how about if I give it to you for 7 95, what would you do if I gave it to you for a dollar? No, just get away from me.
I'm canceling. Adobe does that too. I, I, um, I do think it's, it's part of the deceptive practice.
Ano I think it, yes. Think I think it's gonna another, another, oh, sorry. Go ahead.
I think it's gonna be good for them in this sense, right? I think a lot of people got wise to this over the years and don't buy things 'cause they know that they're gonna get beat up on subscriptions. And longer term, maybe more people will actually subscribe to something 'cause they won't feel like they're gonna get ripped Up.
I'm not that optimistic. I think this goes away in the new administration. I think it's gonna be heavily litigated.
But Are you gonna sell all of those Trump gold coins and flags? Oh, geez. I, I'll say I, I hope that it, I think one of the other things was meant to combat was signing up for something online and then requiring an in person.
So like my gym for example, that I haven't been doing it right in a year. They require me to go in person Yes. To cancel.
And it's like, well That's, that's interesting. If I was showing up there, then this wouldn't be a problem. There are health clubs that you demand that demand that, um, members cancel by certified mail or in person.
And then I don't even want to go into cable subscriptions. You know, the time you, you spend on the phone. I mean, this reminded me of a controversy that a OL went through years ago.
Decades ago they were in hot water because it was so simple to sign up for it then yet utterly impossible to unsubscribe because you couldn't find numbers, contact information. This is something that is just an, just analogous for the, the tech industry. And I think they're gonna be a little bit, uh, put off by this and probably fighting and, and whispering to certain officials that they, we need to dissuade and get away from this.
But, um, Do you know, there's one there, one area where we already have this, um, apple, if you subscribe to a service using hide my email, uh, it goes into your subscriptions, like other things you buy through the app store. Yeah. And you can go into your app store subscriptions, any of those.
You can can right from there. I found that very useful too, Mitch. Oh, I love that.
I love that. Me too. And I've used it over and over.
I hope it's less clumsy than the rollout of GDPR. Yeah, no, it is. If you go in, like if you're on Mac and you go in your, to your, you know, apple account and it has your subscriptions there, and you could turn them off as you go.
You know, Michael, Mike, to your point about how consumers get wise to this, now I would do a, a a a variation on this when I was looking at, like, I was a DirecTV customer years ago, and they were, they would give you these great come ons and then six months later your price would double. And what I quickly found out, if I would just get on the phone and say I want to cancel, they would put me to the savor department basically. And they'd say, oh, wait, before you cancel, let us do this for you.
I'd say, I, you know, they'd say, why are you cancel? I said, because you're too expensive. And they would roll out every offer they had mm-hmm.
Until I accepted something. And so I really wasn't looking to cancel, I was just looking to save money. Yes.
That's, my wife does it exactly the same. She does that a annually. Yeah.
She'll threaten to cancel, then she gets a sweetened deal that That's part of the thing. And that, you know, that that's another part of the consumer experience. It's kinda like going to the Shook Right.
And, and bargaining with, with the, with the, uh, people. But If you look at the LE legislation and actually, or legislation F FTCs rules, it has a lot of what we're talking about. It has to be the same medium.
You don't have to talk to a person. Yep. Mm-hmm.
Um, to do that. Um, and you should be able to do it on should, should take the same effort to as it does to sign up as it does to cancel. So, agreed.
If this, if this flows through, I think it's a great thing for the consumer. Certainly good for us. Agreed.
I think Those gaming companies are gonna be in a lot of trouble though, because I can't tell you the number of times that I, over the years that I had to go look at one of my kids' accounts and say, so there's subscriptions or doing subscriptions to this thing. How's that work? Exactly?
Well, but, but you know what, again, apple and Google, when you download an app or a game like that, it'll tell you in-app subscriptions. So, you know, at least it's giving you a heads up. I don't know how many people read What charges are Before, which the average 13-year-old dutifully ignores Well, but not our purpose.
Are you saying dad's problem? You saying I'm 13? Is that what you're saying?
You know what, They're, they're wise to it. They just don't care. But it's not like they don't know.
I've had instances where I've deleted an app and it still charges me, which baffles me as well. Deleting does not mean canceling. No, it doesn't.
And maybe that'll change. Look, there's two sides to all of these things, right? I, I, uh, you know, I mean we, there's a certain amount of go ahead.
There's a certain amount of pleasure in canceling something, right? There's a Certain Absolutely. Yes.
It it is. It releases some end things. It's cleansing.
Yeah. Mm-hmm. Uhhuh.
It's like, but somebody like, who wants to get rid of, get rid of their meta or Facebook account. I mean, that's really hard to do, to scrub it completely. But I mean, psychologically it does feel good.
Well, I always wonder too, is that the FT C with the new FTC chair coming in, does this, is this all moots or That's What I'm saying. We're wasting time talking about it. They're not gonna do it.
But to your point Yeah. With meta and, and our friend, uh, over ZZY, whatever the heck they call that one now, um, what I find interesting is a lot of my friends who have abandoned those platforms have not canceled per se, especially if it's free accounts that don't cost 'em anything. 'cause they wanna preserve their name.
So that exactly I did. That woman comes in and tries to impersonate them with their name and I I and that Is happening. That is, that is actually happening.
I I, I ran across a friend of mine, she has, I don't think she knows this, but she has two other profiles associated with their name, with different birth dates. Yeah. So This is some that called, is, is that called quiet canceling?
How does that work? I guess you would call I, I call it a bit. I like that quiet canceling.
Make sure you credit Mike Ard for that. Well, sure. I I'll put it in Urban Dictionary.
Yeah, That's a good one. Quiet canceling. Anyway, let's take a break here on Textron Gang.
We're gonna come back and talk about one of our favorite topics, AI with AI in healthcare. You're watching Textron Gang Modernize your business to fuel innovation and elevate customer experiences with the builder community. Hub AWS and its partner network provide essential tools for transforming applications and infrastructure to fully leverage the cloud.
Discover free trials, in-depth demos and essential resources to empower DevOps engineers and developers to deliver value faster and more reliably. Visit the builder community hub to learn more. Folks, we're back and we're talking about AI and healthcare specifically some stuff that NVIDIA's doing to help drive research and development in this area.
And I gotta tell you, this story's a little raw for me because, um, close friend of ours in my family passed away yesterday, and it was a long battle with cancer. And part of the issue was it took them too long to discover the root cause of that. It was even there and it became a bigger issue than maybe it should have, who knows?
But John, you're looking into this story and you wrote a couple other things in this area, and I've also talked to AstraZeneca about what they're doing. There's a lot of good work being done here. Yes, there is.
I mean, Nvidia did, made an announcement Monday. It was a pretty ambitious announcement. They had a, they had a briefing, uh, with, uh, Kimberly Powell, who's the vice president of healthcare there.
And they mentioned a, a number of partnerships. Uh, one was with IK via, which I cannot pronounce, to accelerate drug and medical device developments, um, through, uh, I think it's the AI Foundry service and agentic ai. At Nvidia Arc Institute, they're going accelerate computational biomedical research via AI models, Illumina, uh, geo genomic genomics insights with, um, also Mayo Clinic.
They're gonna speed up AI driven digital pathology through computing platforms such as that are powered by Blackwell. And in a sense, they're, they're doing a, a lot of things that I think are, are incredibly important. And they have high ambitions.
They're talking about basically using agen AI and physical AI to revolutionize healthcare, increase access and drive discovery. Um, it's, this is all part of this larger, uh, edict within the company to diversify beyond data centers and position itself as a, uh, leader and, and multiple industries, particularly healthcare. And here's one reason why.
Here's 10, 10, 10 trillion reasons why that's the size of the global healthcare and life sciences industry. So they see this as a huge opportunity, but I also see it as an incredible, great opportunity for us, um, an aging nation where we all have our issues. As Mike mentioned.
Um, I'm sorry for your loss, Mike. And I'm, and I'm kind of going through the same thing with my parents. Uh, this is, there, there is a push, not just among Nvidia, but other companies to go into, um, embracing or medical professionals embracing AI to, um, expedite everything.
There are shortages of medical personnel and there are antiquated facilities. So, um, I look at this as a positive. I also look at it as a huge opportunity for Nvidia.
But first and foremost, I, I think it's something that we, we all have got to do a much better job with. And that's just healthcare in general. What, what also would be good to see John is, uh, AI tackling the insurance and coverage.
Yes. That is a big, And the insurance paperwork, talking About an obstacle to getting healthcare, that's also, if we could, if you could streamline that by 15%, it would be massive. Just think about how much that would improve delivering care to customers.
You ain't kidding. You're not kidding. I'll tell you, I'll tell you what I'm a little concerned about is that I look up and down the landscape and there's a shortage of GPUs.
There's a shortage of data centers and a shortage of energy. So AI is a limited resource. Are we really applying it to things that matter or are we just using it to write better emails?
And, you know, it's Kinda like, you know, what, you, you, where Is there more unstructured data than healthcare? Where is there more opportunity for automation. Where is there more money And also potential to save actual human lives.
Yeah. But I don't believe the hype about data space and energy and data centers, that that's just, what do they call it? Grist for the mill or whatever.
Greasing the skids. Yeah. Something though, something with the mill John would know.
He has a way with our, It's gr for the, it's gr for the mill. You are Correct. It's grist for the mill.
That's right. Okay. Well we had mills and we were milling stuff.
We put grist in there. Right. Anyway, but I'll be back to you on that subject next week with some real data.
Oh, You know what? Show me, show me one AI implementation. That's not happening because we don't have enough data center space, or we don't have enough energy.
They want more and we'll overbuild it. I remember what they used to. If only we had more fiber for the internet.
We can't. If only we had more fiber level three in Interlochen when I used to live there with Mitchell. They had, they were sitting on enough dark fiber for 30 years that they're just starting to use it now.
But that's all you heard. It's only we had more fiber for the Internet. Well, we'll, we'll get back to that.
But We nonsense. There's One thing we've never, we've never underbuilt and that's data centers. I mean, think about Going back ibm I, IBM m is still selling data centers from the Cold War.
If Anything, we'll over rotate on data centers. I think We, we'll wind up with too much. But here's my issue.
'cause I'm a meat and potatoes kind of guy here. Right. And I think we're biting at the edges of what AI can really do in healthcare.
It's not about reducing errors in clinical paperwork. That's a great, I'm not saying it's not a good thing, it's a good thing. But let's talk about where the real shortage is.
Qualified doctors, qualified professionals. Right. When AI hits that head on, then we're gonna be somewhere.
Right. It's, it's getting more beds in hospitals and emergency rooms and urgent care. It's getting more people able to be treated.
That's the, that's the thing here. Jim and Mike. I'm, I'm sorry for your loss as well.
I think unfortunately all of us have suffered in our family, family. Mm-hmm. From a result of people.
It just took too long to get care. It took too long to get the right care. Oh, it looks like you might have a malignancy.
Well, let's schedule an MRI. When can I get that? MRI done, uh, what about two weeks from tomorrow?
Then it's gonna take a week to get the results, and then I'm gonna have to show it to the doctor. And then he's gonna refer you to the oncologist. And then the oncologist.
He's a good oncologist. One of the best. Can't get in to see him for three months.
By the time you do, you're debt. That's the issue. And that's what AI has to tackle, you know?
Right. Has To tackle that too. Alan, I, I wrote about this actually comment on a post that, uh, Keith Townsend put up with future, um, is that, you know, all the focus on general productivity copilot for your pc, et cetera.
Those are all interesting. But that's not the real value of ai. Improving individual productivity is a very hard thing to measure.
How, how much time do you really truly save writing emails? What really matters is, is re is, uh, improving process, eliminating processes. That's the way that you want to get more efficient, not have to do something.
That's another way. And I think that's the big question about AI, is what's the ROI people are asking, mayor, we had that conversation the other day about are we backing off on AI investment? 'cause there's not a ROI for it.
Well, you know, if you're just doing it as, as another Slack or another team or another kind of productivity tool, that's hard to justify. But if you're streamlining processes, if you're making an, maybe even redesigning 'em because you have ai, just to pick one thing more or less, finding the shortage of talent that you can have. Security people.
Let's find more security people. Right. As well as doctors.
So I, I think there's a continuum of value, but it's not just general productivity. Yes, it'll help us, but that's not where the real money is. I think that I agree with everything you're saying, and I think it's not just getting people from being in the hospital, it's getting them from staying too long in the hospital.
Because the longer you stay, the sicker you get is the theory I've had for many years. Uh, one of the early applications I saw of AI in healthcare that I still continue to watch and think is one of the best use cases is the Duke sepsis watch. Sepsis is one of the most common causes of death in hospitals.
And this, this pilot study showed that they were able to detect early signs of sepsis before humans could. And that to me is exactly what this technology can and should be doing that will save human lives. Guaranteed.
Everything else is window dressing, you know, chatbots for chat, getting appointments or triaging symptoms like that to me is not the killer app here. To me, the killer app is literally saving someone, staff Infection, A major infection that would kill them. You're reminding me of, my father used to always tell me, don't go near the hospital.
That's where the germs are. Well, so my grandmother used to say, and she was a wise woman, she used to say, the, the doors to the hospital on the way in are very wise, and they get very narrow on the way out. And, and I think that's still true, but no, I, I, I, I foresee a day where AI is, I'll give you friends.
My wife, I go, I walked the dog this morning. I go upstairs, Barney's getting dressed to go to the gym and she says, my cholesterol, I got my blood work results. You know, because you get that before you go to the doctor.
Right. My cholesterol's back up. I said, when are you going to the doctor?
Oh, not till I think two or three weeks. I said, well, if I were you, I'd start taking the, I take citrus bergamot or bergamot, whenever you call it. It's really good.
I'm not a doctor. I'm not telling anyone to take it, but it reduces your cholesterol. I said, start taking my citrus bergamot.
She says, well, I'm not sure. Maybe I should wait for the doctor. I said, bar, if you start taking this now, by the time you go to the doctor, your cholesterols, it's not sky high anyway, but we need, I mean, it would be so much better.
So much of what we waste people's, like doctors' times with is something like that when he, they should be looking at, so triage is important, right? Triage is prioritizing where we put our time and who gets a bed and, and stuff like that. And that, that, that could be really helped with AI really helped.
And that will save lives if my doctor's concentrating on the guy who might be having, we have another friend, Mike and I was in the hospital right now with the myocardial infarction. I don't know if you saw this morning. He said it was close.
He wouldn't be alive except his wife made him go to the doctor for chest pains. Um, we, you know, those are the people you gotta prioritize. Not necessarily, you know, and there may be, I'm not, I'm not a doctor, but I do believe that AI's gonna have a profound impact on improving mm-hmm.
The healthcare system up and down. And I hope it's an equalizer because I have to be honest, as a woman, I'm less likely statistically to be listened to and diagnosed properly than a man. And that's not just because women don't get listened to.
Our pain is ignored. It's because statistically more money goes to men's health issues. I I, I'm, I agree with you in studies.
It's a terrible thing by far. And, and that's women. Let's not, let's not go to economically, But could, but could AI equalize that?
Because AI doesn't care if I'm a man or a woman. Absolutely. Right.
And they don't care if you're black or white or Hispanic or Asian. Right? Exactly.
Which goes double if you're A minority. And that's a whole nother, that's a whole nother boogeyman. Boogeyman.
But anyway, don't get me started. It's Friday. We're taking a break here on text on Gang.
Let's come back and talk about something not controversial like the FBI deleting files. You're watching Techstar Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back in.
Yes, it is maybe controversial. We'll see how this conversation works out. But the FBI has been deleting some files that contain some malware that were allegedly distributed by some folks associated possibly with China.
You know how all these legal terms are, but, um, I think this is one of the first times, or maybe they've been doing it, but, uh, now I'd love to get your thoughts here. FBI is actually reaching into people's systems to delete files. And, um, it seems like, uh, you know, you should get some permission maybe, I don't know.
But, um, what's your take on this and are there legal implications here? Yeah, I can sum up my take on this. In one line, the road to perdition is lined with the best of intentions, and I get what they're looking to do.
And, and it's a, it's a noble right? The, the, the end, the goal is, is a noble goal. Like let's get rid of malware.
The means leaves a lot to be desired. Right? And, and so the road to hell is lined with the best of intentions.
Do I trust the FBI to come onto my machine and delete files? That's how I trust, Really. I trust them over the Chinese government.
Yeah. Well, the Chinese government puts files on and then takes, you know, well, exactly. But, you know, but that's, but that's a different thing.
The Chinese government are cl clearly doing that. Not with the best of intentions. Well, maybe it's their intentions.
The FBI is doing it here to do the right thing. But the, you know, this is akin to should the FBI have the ability to crack your iPhone encryption. Well, or are they have, have they already been doing this, Alan?
Yes. Here's what's, here's what's fascinating to me about this, is it's not the FBI deleting the files. They actually hacked into the servers that delivered the plug X code, um, that's been out this, uh, forget it with the panda group, whatever it is that funded this.
So they hacked into the servers and put in their own code that, uh, will go out and, and deliver an instruction that was already there that deletes all of files that were part of this plug x, uh, Trojan and any files it created. So using the, the hackers, the bad guys own mechanisms to do this. It isn't the FBI logging into your system, they actually hacked the hackers.
Um, I'm not sure that's a bad thing. I don't know. That sounded like two wrongs making a right, but I don't know.
Well, but you end up in the right place. Right. But did they do this without notice?
Did they do this undercover of darkness? Oh, did they not server The servers in the us I don't know where the servers are. I have to look at the article and see what, what it said.
You know, I'm, I'm reminded of the case a few years ago during covid, I forgot where, I think, I don't know if it was a Chinese or an Eastern European group hacked some healthcare folks. I think it was Atlanta, Baltimore, one of the towns. And they were paid in Bitcoin.
And miraculously about a week later, the, the, the bitcoin, the, the, the, the malware group got all met and put out sort of, you know, stuff online. How dare that their Bitcoin was stolen. You know, their Bitcoin disappeared.
And that's when I first realized, you know, the NSA can make Bitcoin disappear. Um, and what, you know, that something we've gotta, that's a reality. And I, you know, so again, road to, to perdition, right?
The, the, the, the, the, the intent and the cause is, right. And Mitchell, in this particular case, yeah, they did the right thing. It sounds like the problem is the, the, the potential for malfeasance here is, is bad.
Did they go get some sort of court order for this? Like, what, what was, what was the, from nine 11 Bush, the Patriot Act, they set up the court. We, we, law enforcement would have to go get permission before they did something similar to this.
So this is even more entwined, Alan, because the servers, I just was doing a little search, the servers were actually taken over by the French government servers were located in Tokyo. And so the FBI worked with the, the French, uh, law enforcement agencies to put this, turn this coat on and have it delivered. So it's not just us doing this.
If we actually have a multi government plot here to, uh, delete files, Uh, assuming that the servers are under Japanese sovereignty, did they say Okay. I mean, that's kind of the, I don't know. It's good question.
Kind Of dynamics to this thing get really compelling On know. I don't think the Japanese are gonna come forward and say that. No, I mean, the servers Were taking over, think about it.
Are the Japanese gonna say, yeah, we gave permission to this French and American to come in here and hack in the servers under our jurisdiction. So none of yours just letting you know the French and Americans, if we would decide, we're gonna let 'em come into your servers too, here in Japan. Japan is never gonna say that.
I mean, 'cause they took over the servers to, to basically cur, curtail and block the botnet that was happening, that Plug X was distributing. So there were good reasons why they took it over right now. Okay.
What about this scenario? I Mean, if it's not them, who should it be? Or are we?
Wait, no, no. I'm not saying if it's, I I I'm just saying there needs to be an oversight. There needs to be much is in the Patriot Act they set up, I forgot the name of the court that was set up for Patriot Act Court, The Pfizer court.
What? Yes. I think that was it.
You need to set something like that up to prevent abuse. 'cause this is, this, this activity is prone to abuse depending who you believe. Right?
I, I mean, I think that that's true of any situation where you're dealing with centralized networks and, you know, we've seen Facebook employees getting caught stalking people through the platforms that they mm-hmm. Are supposed to be protecting. This is, this is true of, of anybody that has too much power.
I totally agree with you. And I think we have five watchdog here. If anyone's watching, Maybe we should be the court, not a kangaroo court.
I mean, I'm just saying. Yeah, no, I, I hear you. But that's what you need.
You know, you don't want whistleblowers per se. I'd rather have a court that they go to beforehand and get permission for this kind of thing. I, I think what they did, they very well have been extremely reasonable and good, and I applaud it More real time research.
They got, they went to court to nine different courts in the US starting in August of last year to get explicit permission to delete. So They did have permission. Yes.
Yes. Alright, so then good for them. I applaud them.
Good work story's over. There You go. Congratulations to the FBI and our good friends in the French government, it was probably Interpol or someone.
Right? I, I, I think, I think more transparency is still required here to kind of say, okay, what exactly did the court approve and when and why, and Well, you can make a freedom of information Act on that. Yeah, I'll get that.
Well, hopefully with ai I might get that in a week, but right now I'll get it in nine months if I'm lucky. Good reason. Here's an AI tool I would use, uh, something to expedite the request of documents.
Mm-hmm. So how long though will it be before you think and, and I'm not throwing red meat out there, Alan, just for grins, but, um, you know, so I take over your server, I insert malware and suddenly I'm deleting all the files going to the political opposition because, you know, I've met, oh, I'm sorry. They were all, Are you saying that doesn't happen already?
I don't know. Maybe, Well, Mike, now taking another example, who's being naive now? Mike, maybe they Should delete TikTok for us if they, once they ban it, maybe, you know, what about that scenario, right?
Mm-hmm. That's a real scenario. That's A, that's a really good point.
Yes. Only if Elon doesn't get his hands on it. If he can't have it, no one can.
Yeah. It's one of the reasons, By the way, the head Of the don't, By the way, there's a, there's a headline out that, that the head of TikTok will be, has been invited to the inauguration to sit near the swearing in. Um, Well, he paid a million dollars to the inauguration.
He sure did. Committee too. Why Show it?
Me? We know. Yeah.
Yeah. Beware Foreign entanglements. George Washington, what was it?
1796, Mike. So what are they gonna do? Just flip a coin and give it to one of the cronies for, is that how that's gonna work?
Isn't that how Putin does it? I it's oligarch. You parcel it out.
Uh, that's how land barons, that's how Barons work. Sorry, sorry, sorry. To set this on A back.
Oh boy. We, I Know, I knew to, I I I figured we'd get into TikTok given that there's, you know, we're talking Chinese government, and this is obviously very fresh in our minds. I think Elon running it is a non solution.
Um, I, I just can't see that happening. I think Moreally we'll see an extension Twitter. Oh yeah, that's going awesome.
You know, it all could be, it all could be moot too. I mean, if there's also a trumpet issue, an executive order and just say nevermind. So anyway, I think that that's likely to happen because there's too, there's too much money at stake That one.
So would you, Would you sign up for an FBI service that would essentially do cyber hygiene on your system to delete all these files that, you know, essentially it's a national security issue. So maybe we should all just kind of, you know, subscribe to some service, hopefully one that we can turn off with a single point. What, What could go wrong?
Well, That would make them a commercial interest. I don't know that that would ever happen, but it's on a patriot, it would be, It would be free. It's part of your tax dollars.
It's national security. Look, if you had, if you don't have anything to hide, what difference does it make? Mm-hmm.
That was always Yes, but I'm, I'm kidding. I'm being, I'm never gonna buy a car that has the ability to be shut off externally. I have a very, How do you know That these newer cars have kill switches?
And they do. Yeah. And I will never buy a car that has that.
I'm never gonna be in a my space. So Are you gonna stop walking and biking? What are you gonna do?
I'm gonna keep fixing up My old, my old Mercedes. You can Presume they take over your electric bike too, so. Right.
But, but the point is that I have no intent of ever, You know, I, I'm reminded of, Well, just our principal don't like that capability. Mitchell and I are, it's still secure around 2006, seven, something like that. Six or five.
We get a, we we're doing NAC for the DOD, we get a call from SEC D office if we can write a n test, net network access control test to make sure that the USB port on laptops are, are, um, disabled. Disabled. Yeah.
That's pretty easy enough for us to do what, you know, why you wanna do that, nevermind why you wanna do it. We just wanna know if we can. And if they're not disabled, do not let the machine on the network.
Relatively simple thing, Mitchell has the engineering team do that. We added to the next release for DOD and it goes in right away. We find out about a year later, not through freedom of information acts that, you know, some foreign entity, probably the Chinese government just went into the Pentagon parking lot through USB thumb drives.
Like they dropped a bag drop and the hyper intelligent people over there picked them up off the floor and said, oh, great. A USB driver, I could use one of these and plugged it into their laptops. Hence the Chinese stealth fighter program was born.
Um, so, you know, this is real deal stuff happens. And certainly when you're in the government or affiliated with the, because you know, only 20% of the people in the Pentagon work for the Pentagon. The rest of them work for the, you know, beltway bandits.
Um, but when you are doing work, you, you do give up your right for them to come onto your machine. And I, I don't, so that I don't have a problem with, I, I do have a problem if I'm not, if it's not government affiliated my work or my laptop or my device or what have you. Um, we started with like the, remember Mitch, there was a time at RSA, all the rage was the bifurcated phone systems where really you couldn't, you couldn't pass through that.
It was like a blood brain barrier, A blood brain or brain blood, whatever barrier. Um, versus having two separate phones. I, I don't, you know, I could see us heading that way.
That that's the way of it. Um, I, I do think the gov our governments have a right to make sure that critical infrastructure, national secrets stuff that, you know, we need, if they deem it necessary is, is, uh, protected. It's the same thing during nine 11 or right after nine 11, remember, they wanted to hack in all the phones and, and computers to see if there were plans for more attacks.
And there was this whole debate raging that gave rise to the Patriot Act in the fe of court. Right. Given, Given the level of trust, you know, if you ask the question, do you trust your government, at least to US citizens, I think the overwhelming answer would be no.
Given the climate we're in. So them doing something like this would, I think, would meet a, a lot of opposition. Sure.
What's interesting is the reason for the no. Yes, exactly. Depending if you're blue red here or there.
Right. The, the no has a very different thing. Right.
They're the Blue and who's in office and you know, red and who's in office and you know. Exactly. Exactly.
But that's, I think that's the world we live in. But who knows, in this case, let me just wrap the bow here. In this case, it does appear as if the French government and the US FBI went to appropriate courts, worked with the Japanese government and did the right thing here from a, you know, following the good Dobie rules.
And, and so kudos to them for that. And thank you for doing this. And don't pick up any USB drives in the parking Lot.
No. That, and that's the moral of that story Is airport wifi chargers that are public. My god, arguably do it faster next time then, because it takes too damn long to get it through the court system and Prove Well, but, so, okay.
So maybe we need a fe of court kind of setup where that can be expediated mm-hmm. Easy AI to make it faster. Right.
And I, and I would say, you know, we should set up a red and a blue service. You can sign up to, depending on your Personal, a forum shopping for that. That'll work.
Yeah. Excellent. Excellent.
I think you know what, it's time to start the weekend. Oh, boy. So we can write that, uh, spy novel we're all talking about.
Yeah. This has been, this has been a great Friday edition of Textron Gang. We hope you've enjoyed it.
We had a good time. Um, we've got a full on Textron TV day for you after this. Check it all out.
We'll be back Monday with lots of, lots of good fun here on Textron Gang. But we hope you have a great weekend. Stay away from that Chinese malware.
And until next time, this is Alan Shiel for Textron Gang. We're out. Hello and welcome to the digital CXO podcast.
I'm Amanda Ani. I'm excited to be here today with the Work Leap, co-founder and chief Innovation Officer. Gr, how are you doing today?
Hmm, I'm doing good. Uh, thanks for having me. Can you share a little bit about Work Leap?
What does your company provide? Yeah, that's for sure. So, uh, work Leap, uh, we are a, um, SaaS company.
So basically we do software to help, uh, organization to, uh, build a better employee experience and to make work simpler. So, uh, or software or services, uh, goes all around the employee experience. So from the first day someone is desired, we help them become productive from day one.
And then we do, uh, everything around engagement and recognition. So we, um, analyzing, uh, employee engagement, making sure that people recognize themselves, performance management as well. So making sure that, uh, everyone stays, uh, on top of their game, uh, uh, all along the journey with the company.
And, uh, we have various, uh, and we have the learning, uh, aspect too. So helping every people to keep, uh, developing themselves during their, uh, lifecycle with the business. So it's, uh, it's large.
We have a lot of different product and, and place, but, uh, this is something that, um, we see as mostly small and medium mid-market type of businesses are looking for. And to be a good, let's say, uh, number, we, we, we have to call ourselves the number one add, add-on on top of your, let's say, basic HR system. So payroll benefits and stuff.
So we are the, uh, the all-in-one for everything else to create a good employee experience. Great. Thanks for sharing.
Well, that means you're the person to talk to about our topic today, which is vanishing workplace data. And, uh, HR is losing a lot of data about its employees and you feel that, uh, this is a problem. 'cause there's a lot of great information there that could help companies.
So can you share a little bit about that and what you're seeing? Yeah, for sure. So, um, it's fun because, uh, most of the time I've meet, uh, I meet with HR people.
So, uh, the, um, uh, people that, uh, that, that is strictly focused on people. And now, uh, I know on the pod is more on around IT professional. I have a dual background, so I am an it, well, well, an engineer, uh, uh, from, uh, from my training.
And I've worked a lot, a lot in, in, in that field. But then from, for the last 10 year, I've been building stuff for HR people. So I have a, a specific view, specific view on the topic.
So the way I'm seeing it is that, uh, since hybrid work or remote work for some organization started a couple of years back. So, um, our digital footprint just grow, grew year over year. So just, uh, as a, a key stat, let's say.
So we see that, uh, around 300 million terabytes of data is created every day, uh, in, um, in organization. So that's a lot of, um, of data. Uh, this thing or this context makes it really harder to manage your people, to get a better sense of how they, they are doing online.
They are not always at the office. You don't have all of these small thi small, uh, habits or small, uh, things that people does, uh, as a manager and, and presents with your team, let's say, and things like that. So the, the, the job of knowing your people, uh, managing your people, uh, managing performance of your people became really harder with all of these data.
So second revolution is obviously ai. I won't be the first talking about that in, uh, uh, this year in the, in the, in the, in the upcoming episode. But AI is a good way to analyze a lot of data and get a sense out of it.
So what we do, or what we are, uh, working on is how can we, um, analyze all of these, the digital footprint of every worker. Obviously we specialize with knowledge worker, so people working on the computer that don't, don't necessarily, it's not necessarily true for every type of worker, but let's say for knowledge worker, may you the audience right now. So people that is interested in that, like, how can we look at all of these, uh, documents, this data and get a sense of what's going on in the business?
So from, uh, the employee from the first day someone came in to the last day, let's say, what happened, um, and, uh, and and so forth. So the goal there is to connect to all your, um, your, uh, your internal system. And then with ai, we analyze everything.
We get some insights around people, like employees, their experience, how they collaborate with each other and everything. And then, uh, get some insights and take action on that. So for company leaders who want to implement AI to get these better data insights, what is step one?
Yeah, that's a, that's a great question. And this is something that I've been working a lot, uh, internally as well at work. So, uh, I think that the, the good first step to really, um, leverage ai, uh, to, to get some insights for your, your teams is really, so I, I, I will just explain what, what I'm currently doing, and I think it will help people to understand.
So basically the goal is to have like a clean, clean sources of data. And we know it's not that easy for, uh, every business. So work is a 18 year business.
Uh, we grew, let's say we had, we had two acquisition the past two years. Every time you, you change a business, you have new people, new systems coming in and things like that. So just a basic example.
So we have let, let's say five CRMs inside the business as of today. So if you have five CRMs, the data is a little bit scattered in every system, and it's really hard to, to to, to get a good sense of what's going on. And then ultimately the goal would be to automate stuff based on the, these data.
So, uh, the first step that, uh, that I'm, uh, that I always suggest is to clean up your mess or clean up your, uh, da uh, your data, data, uh, system or data architecture. So consolidating your internal system, uh, making sure, uh, put, put some processes in place to make sure that the data is, uh, actually good because it's not, because you only have one system that the data is good. So making sure that you, you put some processes in place to, uh, to help having like a good quality of data.
Uh, so setting up your business to have a good data quality and then, uh, implementing solution, um, like work leap on top of that would be way better. Obviously there is also some product that can help you, uh, do that. But, uh, this is definitely, step one would be to, yeah, clean up your mess.
But I, I see it in, uh, with a smile in the sense that it'll always, it will never be perfect, but at least having, uh, clear guidelines on how you want to have your data set up. And then you'll, it'll be way more easier to, to set up some tech on top of that. Okay.
And so then once they've started this process and they're in, and they're in that, um, integration phase, what are some things you've seen companies struggle with during that implementation phase? Yeah, I think, uh, like, like we just talked, uh, I think the data quality is definitely the, uh, the ultimate things. We've been talking about it like for 10 years, 20 years, you probably had some podcasts on that subject, uh, a couple years back and things like that.
But I think it's, uh, and this type of project is always hard to, to, to get funded in the sense that, okay, I have a big, uh, a million dollar project to clean up, like data and all of the system, things like that. So it's, it's really hard to, to get, uh, something. But I think the, the yield, what we need to remember is before that, it was mostly for a analyzing data.
So having some good report or, uh, operational report around like the data that you have. But now with ai, you'll actually be able to automate and take real decision and apply those decisions live. So let's say, let's say it's a million dollar investment, so you'll be able to, uh, automate stuff that will probably save you a million dollar in the future.
And we see, we see this, uh, this trend, uh, coming in and a lot of specific, uh, vertical, let's say customer success is a good example of that. Uh, we see a support center, um, starting to, um, to, to analyze, let's say support the tickets and everything and be able to, uh, answer the customer automatically having a better response. And so it's faster.
So it's good for the customer, it's good for your business because you, you don't have, you don't need to do all that repetitive, uh, work. And I, I think it's also good for the customer in the sense that they, they have a, a, um, faster response. And when you escalate the thing, so basically for people that is working behind the these AI thing, they can actually take the time to look at the solution and find like, okay, what's, what's going on there?
So that's one vertical. Uh, on, on our side, we work mostly with the employees, but, uh, this is a good parallel to do, and this is type of thing that, uh, I think we'll see in various, um, type of worker and departments in the upcoming years. Mm-hmm.
So for the future, AI is advancing rapidly. What do you see for HR and the workplace that you envision AI being used for employee, uh, data retention or anything? Yep.
Uh, so I think I will, I will start with the most obvious thing and one of my favorite topic as well. So performance reviews, performance management. This is, uh, in my opinion, it's one example, but this is, I think the, the one that will speak to everyone here.
So doing performance reviews, performance management, it's not that fun and it's pretty hard, uh, a couple of things around that subject. So, uh, when I say that it's, it's hard, it's like, okay, you need to take, you need to gather some information about, normally, uh, companies do the 360 feedback. So basically they ask feedback for, um, the individual, the employee, the some peers, and the manager.
Then the manager takes all of that feedback, try to get a sense of it, ask follow up question, and try to, to make his mind on that. The manager does a review. The review is, is validated by the organization in the big scheme of thing.
And then you meet your, with your employee to, to discuss those results. And, uh, and that, so this is a process where a lot of pieces of information and a lot of, uh, some bias as well, but a lot of, um, potential error, uh, can happen during the analysis. And obviously the ultimate, uh, outcome of that is most of the time a salary review for the employee, which is one or the most important things for every employee.
So the whole process designed to review a salary, it's, it's kinda critical to most our org our organization. So I believe AI and, um, having access to, uh, the, the full digital full footprint of each employee will help vinify this process in a lot of ways. Let's say we'll be able to, uh, get facts around people rather than impressions, uh, will be able to do, um, a year, let's say a 12 month history instead of, uh, uh, relying on your memory, uh, of, let's say a couple of weeks, a month max.
So basically you'll be able to add a full picture of, uh, the timeframe of your, uh, performance management. You as a manager, when you manage 5, 10, 15 people, and then you have, let's say a hundred feedback to analyze and digest and things like that, it takes a couple of hours per person if you want to do the, the job properly. But with ai, uh, AI is very good at looking at the different point of view from employees to, uh, to peers, to manager find the problem, the difference, the difference with the, the rest of the team.
So, uh, being able to, to assess like these insights instantly will really save the problem where will, will really save some time to the managers. And ultimately, and I think this is the most important part. So when you meet an employee with all the work that you did, I think the discussion, this is where you can have the most impact on your business, like having a, a good performance discussion at the end of the day, and, and adding the backup and the tools and everything to support that discussion.
This is where like, uh, employees, uh, can, will either not go against the business, but either be mad or happy and move forward and help your business to, uh, to grow. So this is one example. I could reapply, like the same type of logic for employee engagement, recognition, uh, learning experience, things like that.
But this is one thing that, uh, I truly believe that can be completely changed with AI and data. Wonderful. Well, if there was one key takeaway you could leave our audience with today, what would that be?
Yeah, that's a great question. Um, I would say that, um, I think that the business in the future will drive if you start like looking at the best, uh, the best way to change the way you operate and you, you do your business today. So I think it's, it's more like, I don't want to be that, that a, a bad profit, but like the, uh, I, I feel like business that will drive in the future are the one that are get, are getting started to really change how they work today.
So this is, uh, for me, it's, uh, this is what I'm building a set work leap. And, uh, I truly believe that, uh, AI is about to really change our, let's say, uh, knowledge worker type of business or department, let's say, within business, uh, work and will be, uh, performing in the future. Absolutely.
It will be interesting to see how the future unfolds. Well, thank you so much for coming on our show and sharing your insights with us today. Yep.
Thanks Amanda. All right. And thanks to our audience, stay tuned.
There's more. Welcome back to Textron Unplugged. My name is Cassandra Chin and today we're here with Mohamed Abu.
Thank you for having me. Can you introduce yourself? Uh, of course.
I am Mohamed. I am originally Moroccan, lost in Stockholm, Sweden. Um, much different country in terms of culture and weather obviously, but uh, it is what it is.
Uh, I work as a backend engineer in Spotify. I'm also one of the Java champions to be part of, and also Google developer experts in Google Cloud Technologies and also a community member of different communities. So how did you initially get into technology?
Um, it wasn't actually planned. I wasn't one of the kids, like you for example, that is really into tech and got involved in an early age. Uh, I was just like a, a normal kid following school, uh, the Moroccan system.
And uh, then, uh, there was like, kind of my study path was either mathematic or software engineering. And then I ended up in software engineering because like mathematics was too much theoretical for me. Too much.
Yeah, concepts, um, software engineer was much more fun. 'cause like you can have hands-on experience, build stuff, play with it. And then when I tried it first that Sparkle started where it's like you build your first hello, your first, your first hello word demo or first H team HTML website, and it like sparkle joy.
And I was like, yeah, this is, this is probably where I want to be. And uh, here I'm, That's a lot of fun. Yeah.
How was your experience with communities? Uh, so that part I could, uh, involved at an early age and, uh, my first involvement was while I was civil student in Morocco, Java user group, together with Bodi Hui, which you already know, and Faisal, which are the f both of them are founders of the infamous Devox Morocco conference. Uh, so I got involved at an early stage riot when I was, uh, a student.
I was attending some, the meetups that they had, we had monthly meetups, and then after graduation, I sit still kept involved after a few years, they, uh, had i I, they gave me the great honor to be a drug leader, so I joined them as a drug leader. I'm still, uh, Morocco drug drug leader. So yeah, so it was an early career move from my side to be part of the community and eternally grateful to Bar Fial and also another guy who was called Hassan, who basically, so I worked with him in my, probably the first company that I worked at.
And we were trying Docker before even the first release. So we were paying with Docker when it was sell, not even the one point or release. And then we kickstarted the Docker community and he supported us to kickstart that work.
So I'm eternally the grateful for those three guys, for the mentorship, the community involvement, all the guidance that they gave me throughout the years. I think it's really great you had people like that supporting you. Exactly.
I think mentorship or finding the people that could mentor you, especially in your early career can, it's a decisive and very important moment in your early career. So find a mentor that you trust that is supportive, that you can always go to, to ask for advices, both personal and career advices. What is, uh, discussed with them?
What's your next move? Where you, what's bad? Discuss with them technologies, discuss with them everything.
And having that mentor, uh, person that you trust or could be not only one person. I had three mentors basically, which each, each one of them, uh, I went to for a specific, uh, type of questions, but each of them help with me in a specific way, in a different way to be the person that I am today. So having a mentor, especially in early career is really important.
Do you ever feel like you give back today? I'm trying to, uh, by staying involved in the community, um, both Morocco Drug and Devox Morocco, um, I'm also very proud of a project that they started together with, uh, Moroccan based community guys, which we call gigs, blah, blah. Um, so basically this is an initiative that discusses, uh, for, uh, new joiners or early or beginners in IT industry.
Everything in tech, uh, DevOps, java, backend, front end, ai, you name it, and Moroccan dialect in Moroccan language. Uh, when I started 11 years back, maybe more, all the resources that I had to learn was either in French or in English. So it was not that entry level.
The entry level was a little bit complex. You need to learn the things, especially in the beginning with a for real language. 'cause like it's a second or third language for us, both race and English.
Uh, so behind gigs, blah, blah, me and a couple of folks, we said how we can change that, why we not provide a platform for the Moroccan youth, especially the one interested in software engineering, to have a platform where you can tune in every week. Now it's like, it's a weekly podcast where we discuss everything around technology, uh, livestream. We allow them to ask questions in specific topics.
We cover wide areas of topics who are almost in our 200 episodes. We're going week in, week out to discuss with the Moroccan community, especially the youth ones around everything intake. So I feel like that's one way of me giving back to the community for all the things that I've learned got from it.
And, uh, say a small thank you to the, to the community, especially the Moroccan community that's helped me so much. How long has this platform been in development? I think it has been more than five or six years.
Uh, it started around 20 18, 20 19. And the idea was basically to have, as I mentioned, this, uh, monthly on dvu. So we started as a monthly cadence once a month, and then we gained a lot of Memento, a lot of people got interested, then we started to have it every other week.
And then we turned out to be weekly. And a lot of people got involved, a lot of people joined, a lot of people went because that's live, people come and join. But it still, since four years or three years at least, we week in, week out, we took August off because we want to have a break.
And then we have that every week, week in, week out, uh, discussion around, um, everything in snack and Moroccan dialect. So it's been almost five years, maybe more, uh, in, in the making. Is This closer to like an open source project or a meetup?
Uh, so we started online and we stayed online because the impact is bigger. Uh, Morocco is a large country, not as large as the US for example, but it's still as a large country and moving from one city to to another, it's quite challenging. So if you have a physical meetup, the maximum we gateway is 2050, let's say 100, let's say 1000.
But you're still limited for the impact you make to the local community within that city. Uh, and then you need either, some people need to travel and travel can be cumbersome or we need to move around different cities to share the knowledge and make it, uh, yeah, do the stuff that we want to do. And both ways are almost ideal.
They are kind of limited online is offering us this scale, even if before lacking the, uh, face-to-face hallway track discussion or so allowing us that you can tune in online from the convenience of your living room and join us in the discussion. Or if you missed the episode, then we publish it the next, it's selling YouTube in Twitch and then you can follow it from your favorite podcast platform. Apple Po Apple Podcast, Spotify, uh, Google Podcast.
But that's scale now. So we offer different mediums where we can listen to the podcast. So online is definitely, uh, the way that's helping us to grow.
And that's mainly from an impact and scale, uh, point of view. We organize, we used to organize maybe less now because some of us went different ways, but we used to organize meetups just for that to meet the community. And every year we organize an conference, which is online.
It's the same concept, but it's just like five days, five days of specific topic. We have five tracks full day of, uh, a discussion around a specific topic, we call it blah black home. And then we have another day, which is offline.
So we gather the whole community during one day in that community conference where we meet everyone together. So we try to mix and match best of both worlds. Having that all online experience allows us to scale and reach as much people as possible, but we're all also trying to keep that, uh, face-to-face discussion, meeting the community where they are, uh, and having those lats and brilliant moments in real life as well.
I Think it's really great that you can scale and reach a lot of people while not losing that face-to-face time. Exactly. I mean, there are pros and cons for both options, but yeah, we, we try as much as we can to have the best of both words.
I believe you also helped run the Devox Morocco conference. Yes. How was your experience with that?
Um, I'm very proud of that project and how it grow. Uh, kudos to the founders, uh, bother and faisal for the amazing work they did during the last 12 years or so. So it was originally called Gma gr and they the first ever gym re I was an attendee there, so I was an attendee, uh, in the two or three editions.
And then I joined as part of the team in 2014 or 15. And that was a great experience for me. Uh, and then Devox Morocco is, is a Devox brand, so you have all the great stuff from all the devox around the world in Morocco.
Uh, all the speakers you included, you are giving a keynote in their sneak peek. So it's, it's gonna be, it's one of the greatest technology conference, not only in Morocco, but in the Middle East region and North Africa. I probably should say the whole Africa as well.
So we have a variety of tracks, uh, six tracks, so maybe more covering a variety of things. Backend, frontend, DevOps, ai. Now everyone is speaking about AI from technology experts to share their knowledge.
So I think it's, uh, it's a really important, uh, conference and that's added a lot of value to the tech ecosystem, not only in Morocco, but in Africa as a whole. I think you've really given back to a lot to the developers of Morocco. I am trying to, I, I, as I told you in the beginning, I love being part of the community.
I feel like the community gave me a lot, uh, and I've tried to give back and help as much people as I can from the community work that I do do. 'cause like, at the end of the day, what people remember is the legacy that you left and leaving that good legacy, uh, as small as it can be, is something that I'm always looking forward to. And I hope that I, through that work, through that diversity and variety of work that I'm getting involved with, that I can try to leave a good legacy for the Moroccan youth and the Moroccan ecosystem as a whole.
Thank you for all you've done for the Moroccan community. Thank you for having me. And uh, it's been such a great discussion.
Thank you. Thank you. Thank you very much.
Cheers. This is Textron tv. Hey guys, thanks for the throw.
We're here with Nick Klowski, who's the senior director for Research for Iron. And we're talking about CISO salaries and compensation and what's going on with, um, the money as they say, Hey Nick, welcome to the show. Hey, Michael, great to be here.
Thanks for having me. They say, with great responsibility comes great compensation, or at least that's the theory. So what are we seeing here for CISOs?
They're clearly under more stress than ever, but are they getting rewarded Incrementally, but not necessarily to a degree that reflects the level of pressure that's been added to the role over the past year or so? We are seeing significant compensation increases when CISO's changed jobs, but the market's been fairly stagnant. And so overall compensation has been increasing at a declining rate compared to some past years, And yet the responsibilities are increasing.
Is that gonna continue or do we need to kind of break up the job a little bit more? We see CISOs kind of becoming almost digital risk problem solvers. They're the folks in the org who are really best equipped to solve a lot of digital problems.
So they're getting pulled into more and more processes. We don't see that changing anytime soon. We do see CISOs looking to add more functional department heads to their team team in areas like ai, data governance, particularly around data actually, and getting some more support systems around them to balance out some of those responsibilities.
But what we see really interestingly is the CISOs who have taken on a new job that has a dramatically larger scope are generally really happy about it. They're excited to have that new opportunity and they're going into a new org with a chance to kind of build from scratch and solve some key problems. The CISOs who are just having new responsibility thrown onto them without a huge compensation bump, without a change in org are just kind of getting all the problems dumped on them, is kind of how they end up feeling.
And this having a significant downward impact on satisfaction. So finding ways to support those CISOs more effectively is gonna be key for orgs to keep them happy and retain them over time. You know, I, I looked at their report and that was one of the things that leapt out at me a little bit is that, uh, it felt to me like the new responsibilities were enabling the CISOs to be much more proactive rather than reactive.
And maybe one of the reasons they're happy about it is they can actually do something about preventing a problem versus always being in the fire bucket brigade. Oh yeah. A lot of these developments are great for the ciso.
There's a bigger seat at the table. There's a larger voice to influence the organization. They're more opportunities to solve problems at the ground level rather than being having, you know, fires thrown over the wall at them.
There's just more opportunity across the board. For CISOs, it's just a question of growing pains, the how much time it takes for the support systems around the CISOs to build up, to help them keep up with the stress and incremental challenges that come with all those opportunities. How big is the talent pool for cybersecurity leaders?
I mean, we hear that the overall pool is small and the percentage of those folks that are able to maybe have a conversation with the business is even smaller. So you would think that given the relative amount of expertise that's available, that the salaries would keep going. So what's mitigating factors?
It's really just the lack of movement. We're seeing in general a lot of economic uncertainty across 2024, election, season, geopolitical conflict, et cetera, leading to a situation where companies are generally not hiring a lot and folks aren't trying to move a lot. We start that to change in 2025.
We have 75% of CISOs are interested in a job change, and we expect companies to start opening up more opportunities. Right now it's been a little flat, solely for the reason of lack of movement. We do believe that that movement is coming and that we're gonna see changes next year.
When is the overall turnover rate, like for CISOs these days? I mean, is it high, medium, low, or about the same as it's always been? What's your sense?
Retention has been very strong. Historically. It's been a very quick turnaround role, often as short as average of 18 to 24 months.
We are seeing that change in shift in CISOs are sticking around for longer. But we want to caution folks who are looking to hire CISOs that that's not because everyone's happy and really pleased with their jobs, it's because the opportunities and the movement in the market aren't there. And once we, once that movement picks up again, we expect to see a lot of change.
Is it your sense that CISOs are getting better at being able to talk to the business? To me, one of the things we heard for so long was that CISOs needed to get a seat at the board, but when they got there, wasn't clear that they understood how to communicate in a way that the board could understand. So are we making any improvements there?
Definitely it's, it's a long road and everyone's in different places. Not just CISOs as individuals but organizations as well. There's a bit of everyone having to kind of come together and find a middle ground.
Boards and executives need to start getting a little bit conversant in cyber and technology just because digital tools are such a critical part of the business. And CISOs need to be able to translate up to those or to that part of those parts of the organization more effectively. We see both things happening.
Some orgs have gotten really good at it at this point. Some CISOs are excelling there, others are starting to catch up and get better. We're seeing competence overall becoming stronger though, How we perceive the relative happiness of a CISO and their investments in ai.
Are there gonna be some correlations there? Because I think one of the issues there's always been troubling is there's just a lot of paperwork and a lot of toil in the whole profession. So, you know, maybe we're on the cusp of where this becomes more manageable.
We are seeing automation growing as a talking point heading into 2025, but AI is still at a stage of promising way more than it can actually deliver. And for the most part we hear CISOs at a place of frustration of everyone's rushing to use ai, but it's not delivering the business value commensurate with the risks. When we can find the right use case, it's great, but the number of use cases where AI can really help us are still fairly narrow, but looking for more ways to automate more ways to become more efficient and distribute some of that work is becoming critical.
How is the accountability changing for this position? We heard a lot of, um, discussion about these issues when the SEC law was being debated last year and the year before. I'm, you know, is the job just the definition just dramatically expanded?
Yeah, it's very complicated right now because the CISO role is so different from organization to organization, there still isn't a defacto, this is what a CISO does. This is always what they're responsible for. This is always what's under their jurisdiction.
Therefore, everyone knows, okay, if something went wrong in this area, it's on the ciso. There's a lot of navigating Who actually has the direct signature responsibility for this risk decision? Is it the ciso?
Is it a line of business? Some folks want to share risks, some CISOs want to be risk influencers, but not the decision makers. And some are starting to take ownership of more areas of risk that wouldn't traditionally fall under cyber because they're the most knowledgeable person to do so.
There isn't a defacto best practice at this stage. I think the emerging ideal scenario is one in which the CISO is an active participant and leader in the vast majority of digital risk conversations. But the business unit leader who is closest to the actual process is still the one ultimately owning that risk in partnership with the ciso.
What does it take to be a CISO then, for all the folks who are watching this who kinda are already in cybersecurity and are thinking about, um, maybe, you know, moving up the ladder. I'm assuming there's a lot of soft skills, but other than the fact that maybe have to improve my golf game, what does it take? Start building cross-functional relationships and getting involved in business projects.
We see what happens a lot. If you talk about, think about the development of a typical sales leader or marketing leader organizational function. The nature of their work exposes them to a variety of executives in a variety of lines of business in a way that helps them build the relationships and the varied knowledge of how the business works and how the business makes money to impact the org.
Whereas a lot of security leaders as they come up through the engineering ranks, the analyst ranks, they get siloed in the technical side of the business and then they get into the more executive ranks, the leadership roles and they're asked, okay, start impacting the organization and how it makes money. And they just haven't been exposed to it by osmosis and they've had to try to catch up on what other folks have been doing gradually for years. Take the time to get involved in some of those cross-functional side projects that might not be directly under your jurisdiction.
That might be, you know, volunteering for broader risk committees, things of that sort serving on nonprofit boards that will help get you exposed to governance issues and how governance leaders think about things. Those kinds of side projects can kind of start helping you build those soft skills and those influencing skills that become more important in the CISO role. How do we get the business folks to buy into that?
'cause they'll be blunt about it a lot of times. You know, they see the security people coming and they just clam up and they're trying to do some project somewhere and they're hoping that it'll pass down the road, but they don't wanna share early. So how do I get the security people into that conversation then it might make a difference sooner.
Ultimately, it's kind of the same as most business relationships on some level are transactional. What can you do for them so that they'll do something for you? Go in looking for ways to help them to make their lives better, to solve their problems, understand what they need and what they want from an interaction with a business partner and do what you can to help them.
And then when you show them that you can offer them value, they're gonna be more interested in bringing you into conversations earlier and having you involved. What's your crystal ball telling you about 2025? Is demand for CISOs gonna increase?
Will there be more salaries? Should CISOs go higher their own agents like a ball player? I don't know how much demand on the high level will increase, but movement from CISO role to CISO role will we expect fully to increase dramatically?
We think our real recommendations for CISO is to kind of figure out what is their unique superpower, what is the thing that makes them special? And look for the roles that are with orgs that need that specifically. There's a lot going on scope wise, but ultimately what's driving business expansion and business growth is gonna be what makes them excited for a specific CISO in a role and help you differentiate from the other CISOs in the industry.
I think it's fair to say that, um, CISOs have a lot of stress. Have you seen anybody do anything or kind of master any techniques for managing that stress? 'cause stress equals burnout.
The CISOs that I see who are most balanced are able to find ways to take ownership of their calendar and not get pulled in so many different directions and kind of choose where they go. That's usually comes from a blend of building strong leadership teams below them so they can delegate more and take on more strategic tasks themselves and not be as in the weeds and building executive partnerships so that they have the respect and influence in the org to kind of own their calendar and own their priorities because they know the rest of the org knows that they're balancing and aligning with the business. One of the things we've seen in the last year, and I don't wouldn't call it a major massive trend, but it's, uh, showing up more often.
You're seeing CISOs maybe take over the entire IT department, um, and sometimes they become the CIO. Is that a viable thing or, um, ultimately should I always have the CISO and the CIO be separate functions because maybe, you know, it's too much of, uh, the fox guard in their own hand house. Yeah, we see about 30% of CISOs have ownership of some elements of it.
As we speak to the community about this, they're pretty excited about this transition as an opportunity to kind of have more synergy between what's going on in the technology side of the shop and the security side. Ultimately what's happening is as more and more orgs are putting most of their technology in the cloud, there's less infrastructure to manage. There's less business value to be gained by being better at managing the technology and there's more business value to be gained by getting met, better at managing the security and the digital risk.
And so the CISO is being positioned to own the technology, maybe having a head of technology reporting into them while they're kind of a CISO and CIO role and we expect this to continue becoming more common. And we see this both in very large orgs and very small orgs. It's not, it's not a phenomena that's just for smaller orgs that are very resource constrained.
I almost feel like there's a separation now between security ops and the actual threat hunting and being an analyst and, um, some of that security ops is being managed by an IT team that may or may not report up into the ciso, but it feels like we're getting more into separation of concerns with our limited resources. Yeah, a lot of traditional lines in security, whether it's between security and tech security and privacy security and data governance are all getting blurred and responsibilities are shifting over to the places where it just ends up making sense for that business. Um, I don't know if you have children or not, but if they were in college, would you at this moment recommend them to get into the cybersecurity field and become a cisa?
Yeah, it's funny, I was, um, one of our faculty, Steve Martino was just talking about this yesterday, if he, his, his language is something to the effect of, if I was talking to a young professional or someone heading into college and they were deciding do I wanna go into it or go into security, I would wholeheartedly recommend they go into security. Alright, well folks, you heard it here. Hey, as always, with security, it's the best and worst of times and no matter what year it's gonna be.
But the good news is, hey, compensation's worth it. Hey Nick, thanks for being on the show. Thanks For having me, Michael.
All right, and back to you guys in. Hey everyone, I'm Alan Shival and welcome to the last great cloud transformation. Uh, this is a video series that we do about every two weeks.
Um, every two or three shows though we actually do it with a live studio audience where we ask you to participate and help lead the conversation. Unfortunately, this isn't one of those episodes. This is just a, a recorded episode with our panel here.
But nevertheless, it's a great conversation, especially if you are interested in what we call, or actually what CloudFlare has come to term, the connectivity cloud and what do we mean by the connectivity cloud? You're gonna find out all about that during the course of today's show. In today's shows.
In today's show, we're gonna be talking about multi-cloud security. You know, multi-cloud is, is, is is quickly becoming the dominant, uh, format in, in cloud usage among enterprises, actually even in small businesses today. But, um, securing multi-cloud has its own set of challenges.
We have two other people besides me to discuss this today, and I think we're gonna have a great conversation. Let me introduce you to them. First of all, I wanna introduce you to Annika Garbers.
I hope I got that right, Annika correct. You did. Thank You.
Annika, tell us a little or share with our audience a little bit about yourself. Sure. So happy to be here.
Thanks for having me. I'm Annika, I'm on the product team at CloudFlare. I'm a director of product for our network services team.
So my job at CloudFlare, the past, oh, a little bit over four and a half years, has been talking to customers to understand the journeys that they have been on in digital transformation, cloud transformation, and then the challenges that they have experienced in, uh, connecting and securing their multi-cloud environments. Um, so super stoked to be here and to get into that more today. Absolutely.
We're super stoked that you're here. And Ha and joining us, joining Annika myself is, is my partner, Mitch Ashley. Mitch is the CTO here at Techstar, as well as CTA and analyst with Futurum Group.
Hey, Mitchell, it's great to have you on Again. I I know you are. Just back, was it from Barcelona?
Barcelona For a conference out there and you lost your voice. So we, we try, we'll try not to tax you too much today. Well, it's coming back.
It's coming back. Not fully there. Uh, I'll have my radio voice next Week.
Okay, good enough. So, so guys, let, let's talk multi-cloud a little bit. You know, I'll, I'll be honest, I, I have a confession to make.
I didn't see multi-cloud coming. You know, I, I've been involved in security since the cloud first came on the scene 2005, 2006, and I always thought we'd have hybrid cloud, right? Organizations that run some of their, uh, uh, infrastructure in a private cloud, private data center, and some in a public data center.
But I never thought that the multi-cloud, uh, model would be dominant. But yet, you know, I think it's a recent, uh, a recent, uh, Oracle survey, something like 98%, virtually every single 98 out of a hundred enterprises are either currently or planned to have multi-cloud deployments. You know, we were talking off screen, Oracle themselves now has partnerships with Amazon, Google, and Microsoft, as well as having the Oracle cloud itself.
Those are probably the four major clouds, you know, public clouds in, uh, in the, in the western world. Anyway, um, you know who, who saw this coming on ground, Warren? I'm thinking, I mean, cloud Flare.
Did, did you guys sort of anticipate that we'd move to a multi-cloud world quite as quickly as we have and then of course anticipating what challenges that brings? Yeah, I think, um, when we talk to customers, so I have that opportunity occasionally to present to large groups of people at conferences and things like that. And I always trying to ask an audience question to gauge this because I think it is really interesting understanding the different paths that people have taken to multi-cloud.
And so I'll ask as a starting point, you know, how many of you here are dealing with multi-cloud in your environments? And like you said, you know, this bears out in the data, but then also anecdotally, it'll be the vast majority of hands in the audience go up. Almost everyone has a multi-cloud environment.
And then I'll ask, okay, for how many of you was that, uh, on purpose an an active choice that someone in your organization made an architect or someone doing a cost analysis or someone doing a capability analysis where you were like, yes, this makes sense for us intentionally, and almost all the hands will almost go, always go down. So people have ended up in multi-cloud environments sometimes because of mergers and acquisitions, sometimes because, uh, one cloud had a feature like that was very specific and needed for some use case that another one didn't, and you had to use it. Um, but then now security and network and IT teams are really grappling with this, uh, situation that maybe was not necessarily like, thought through or intentionally designed or planned or architected, um, at the front end of an organization starting on their cloud journey.
And now they're dealing with sort of the, okay, what do we do about it moving forward? Agreed. It, it is, uh, so I'm not alone.
That makes me actually feel better in some twisted way because I also feel validated a bit too, Alan, because it seemed to me the thing that drags everybody into it is m and a. You can't help that. You know, it's just like any other, we now have three CRM systems and two ERPs, and which ones do we consolidate and what do we live with or what can we take advantage of, right?
So it seemed almost inevitable that we're gonna be multi-cloud just for that reason, rather than there was a day. I think, I think, um, it'd be appreciate here perspective on this. I remember the day when we were saying, no, we should have multiple clouds so that we have vendor diversity and we can compete our price and, you know, so that AWS or Google or or Azure doesn't kind of get too full of themselves and charge us too much money.
'cause we'll just move to the other, the practicalities of that are of course, much more complex. That seemed to be the thought when we coined multi-cloud, but now that's not really the reality. Do, do you agree with that?
Yeah, Absolutely. I think, you know, for the few people whose hands remain up when they say, yes, this was an active choice and not just something that I'm dealing with is sort of a, a consequence of m and a. The reason that they, uh, made this active choice within their organization really break down to one, uh, not getting locked into a single vendor for storage and compute, right?
Having that ability to shift applications around if you want to in some cases because of cost. Um, and then in other cases, because of redundancy and resiliency, like maybe they have really business critical applications that have to be able to stay available regardless of what is going on with the cloud provider. And either internally or because of pressure from like a regulatory body, they've made the decision, okay, we're going to, um, we're gonna have the same application redundantly operating in multiple clouds.
The other reason that we hear is because of, um, essentially feature parody or specificity or requirements. Um, and increasingly with developers that are working on, uh, workloads that include ai, we're seeing this as a reason, um, that, uh, folks might choose to go with one cloud provider versus another. So I think we see a variety of reasons, um, but then the challenges that are then present again for it, uh, and network and security teams, um, look the same regardless of sort of the reasons you ended up in that boat, Right?
It doesn't make a difference how you got there Exactly How you were there issues then. But I I, I agree with you. I look, I've spoken to a ton of people who, you know, for whatever reason they thought GCP had the best Kubernetes, right?
Mm-hmm. Support AWS serverless, right? If you were looking to do serverless, you, the AWS and, and then, you know, Azure, believe it or not, Azure DevOps was a, was a big draw for people and for, you know, teams that were doing that.
And the GitHub it stuck And integration with the rest of your Microsoft stack, right? If you're Microsoft, Microsoft shop, and if you're an enterprise, Microsoft has a lot of enterprise customers, you know, and, and absolutely. But as you said, regardless of what journey or what path they took to multicloud, here we are, right?
And, and, okay, now we're here. Now what? Well, there's a couple of things.
Connectivity, moving data among a multi, and let me throw another wrinkle. Not only are they multi-cloud, they still have stuff on prep, they still have private cloud, right? So, and that's, and I think that's sort of a, a soft white underbelly that we don't talk about.
You still gotta secure that. You still gotta, you still got data there, especially large enterprises. They have their mainframe, they have their, you know, on-prem stuff.
So, you know, this brings up this whole connectivity cloud as, as CloudFlare has, has labeled it the idea of we need yet another cloud, if you will, or at least a service that ties these together, especially as it relates to connectivity and security. Right? And, you know, Mitchell and I, our backgrounds are in security.
We've been in security 30 years. You know, let's talk about specific security challenges within multi-cloud environments and, and maybe some of the ones that connectivity cloud is, is hitting head on. Annika, I don't mean to throw it on you, but hey, you are the expert.
Sure. What do you see? Yeah, I mean, I think, uh, when we talk to customers that have been through this journey, which is pretty much everyone is somewhere, uh, along the, along the journey of moving from, um, some on-premise data center where there's a traditional castle and model for security to, uh, multi-cloud or hybrid cloud.
Um, you mentioned the existence still of the legacy stuff on-prem. We totally see that. We also are increasingly seeing more organizations, um, move toward repatriation projects, at least for some small percentage of their application that move to public cloud.
And then they realize, oh, actually for cost reasons or control reasons or whatever, I need to shift it back. So there's, there's all this mess. I think the, the biggest shift that we've heard people articulate is really, um, in insecurity at least, uh, the shift from a very centralized model for security, where you used to be able to sort of draw this neat perimeter around your corporate network and say, okay, everything inside of here is trusted.
Everything outside of here on the public internet is scary. And then I'm gonna put my big stack of defense in depth tools, my firewall, my intrusion detection system, my VPN concentrator, uh, my data loss prevention service, et cetera. Like put that big stack sort of at the, the Castle Moat, watch every packet coming in and out.
Um, and then, uh, and then I, I'm sort of good now. Uh, applications and users are no longer within that defined corporate perimeter, and the lines are not clear anymore at all. Everything is super blurred.
And so we think that, um, this has, has, is going to result in a fundamentally different approach or a different architecture model that security and IT teams need to take the how they connect and, and secure their endpoints. Because if everything used to be centralized and now everything is distributed, it's not enough to just sort of shift, um, uh, approaches that worked in the context of data center security and say, Hey, we'll just deploy those in the public cloud as VMs now I'll deploy a virtual firewall and manage it. Or maybe I'll backhaul traffic, you know, from a cloud environment through my data center security stack.
Those kind of architectures made sense as sort of a middle state bandaid solution. Um, but don't for organizations anymore that are dealing with really, really distributed models, um, for where their sources and destinations of traffic can be, that's users and applications literally anywhere in the world. Yeah.
Here, you know, one of the differences, Alan, in how we think about cloud today used to be we, we built clouds, you know, connect things together, kind of like a erector set, you know, connect A to B and C two B, and all the different paths of our different places that we need to connect or network or we need to interconnect. Uh, a company like CloudFlare, in full disclosure, we're a CloudFlare customer also. We use it for tech strong services, but it isn't just, um, you have connectivity to hyperscaler clouds.
It's also you, you've already worked with those providers of what their security control plane looks like, what their load balancing and, and uh, kind of management control planes look like. So it's not all left on the customer to go figure out. Well, if they're working with CloudFlare is not all left on the customer to go figure out.
Now how do I manage all this across multiple hyperscaler cloud vendors? Correct? Yeah, exactly.
The idea, essentially with the connectivity cloud is that you can sort of put Cloudflare's distributed global network in between the users wherever they are on the internet. And that could be like public users that are trying to get to your public facing websites or applications. It could also be your employees working anywhere in the world.
Um, but you, instead of sending all the traffic from those users to some centralized location where you apply all of your security filters through maybe that traditional stack of hardware firewalls and things like that, instead of doing that, you can enforce security at a location that is super close to them, like just milliseconds away from wherever they are in the world. And then Cloudflare's network or our connectivity cloud can help accelerate that traffic from that point close to the user where we reinforce the security controls all the way to wherever the traffic's destination is in the world. And that could be somewhere in a data center, it could be somewhere in one of multiple public clouds, it could be somewhere else on the public internet in the case where we're helping secure a SaaS app.
So that's, this is kind of like a, the, the, as the, um, the way that we think about compute and security has been flipped on its head from this centralized to distributed model, fundamentally, we're approaching security from a really distributed, um, sense as well. And it's not just deploy a bunch of virtualized firewalls and different clouds. It's actually this fundamentally different like edge security based way to think about it.
You know, I, I, I agree with that a a lot. We, um, when you, when you think about that whole old model of backhauling traffic back, you know, to the central place, I think Covid spelled the death nail of it, right? All of a sudden no one was in the office anyway.
So what, what sense did it make to backhaul all that traffic there, to run it through those big honking machines when no one was there? 'cause we was just sending it back out. You wanna talk about waste and, and so, you know, like the movie, anything from anywhere, anytime or whatever, that, I always got that movie's name wrong, but it, that's the model today we're, we want to do anything from anywhere at any time, Everything everywhere, all in one.
Totally. That is how our customers want it. And I think you're so right, that Covid was kind of like the last nail there.
Yeah. I mean, the shift of storage and compute to the public cloud certainly led the charge. And I think a lot of organizations have been, um, resistant or kind of lagging in their approach to moving networking and security also to the cloud.
Because from a feature, a feature perspective, the public clouds invested primarily in the experience, developer experience and the features around the storage and compute capabilities. But then with users also now moving to, uh, an ability to be distributed anywhere, the, the, um, the chips have kind of started to fall and people are recognizing, okay, we need this different model now. But, you know, the way of the world is maybe for those laggards who were late, like that, it actually worked out for them because they didn't have a connectivity cloud two, three years ago to do this.
That that's a good point. We, we talked to some organizations that are, uh, able to kind of skip a little bit of those middle steps where they've deployed a bunch of the sort of band-aid solutions, they didn't pay taxes and actually taking the opportunity to reimagine it. Yeah.
Yeah. Right. Trying to put this together, you know, point by point in finding out, you know, and we, I call it idiot taxes, right?
You're paying, 'cause you just learn those lessons over and over. Um, so I mean, obviously a big part of it is having a CloudFlare like, uh, point of, you know, point of contact network where you are never too far from any edge or any end user. And then of course, going back to these hyperscaler centers, um, security's only one piece of this though.
It's basic connectivity as well, right? I might be running my, my Kubernetes stack in one cloud, but you know, or maybe it's my, uh, systems of engagement is in one cloud, but my system of record is back at my data center and my front end web servers are somewhere else, right? That, to pull that off, giving latency the way it is, right?
You need a connectivity cloud, right, to optimize the A to B2C to the end user experience. How, how do you guys do that? Ika?
It seems like, you know, either a lot of AI or black magic or a little of both. What do you think? Sure.
I mean, uh, cobbler's mission overall is to help build a better internet. And this started with a focus on public facing application. So things that are already on the internet, public facing website or other, other apps that you might use as an organization to serve like your end users.
How do we make those things faster, more secure, more reliable? And then as we started learning from larger and larger organizations about the challenges that they're having, not just on the public facing infrastructure side, but also the internal infrastructure, everything kind of within the remit of like the CIO or the ciso. Um, they were articulating many of these same challenges with security, connectivity, reliability, and the desire to use the public internet for more of the path.
Like you've heard maybe the phrase like the internet is the new corporate network, but the internet wasn't built to be a corporate network. It was not built with the kind of security and reliability requirements, um, in mind for really, really business critical traffic. And so we think about it as how can we help, uh, act as sort of an, an overlay for the internet in many ways.
Um, not building a separate internet, but helping make the internet as it is, uh, today, uh, high quality enough, reliable enough, secure enough, performant enough in order for companies to trust even their most business critical workloads, um, to send over that traffic. And that looks like things like having lots and lots of different connectivity options. Every one of those points of presence on the map.
And so if one upstream transit provider is having a bad day, there's some congestion, there's a route leak, there's some other problem, no worries. There's tons of redundancy and other options for how to route traffic around. Um, and it's, it's the depth of connectivity, like all of those different interconnections, uh, global backbone that connects them as well, which is just sort of another tool in the toolkit to use, um, to, to help accelerate traffic performance.
But then also the intelligence that sits on top of that, of, uh, how do we not just pick the best path based on sort of default BGP routing, but actually apply, um, smarter ways of making traffic steering decisions based on the intelligence that we have across the view of the global network. Um, so connect at all of the places, have lots of different options for how to get traffic from A to B, but then make smarter decisions for how to route it. And that's based on both sort of synthetic and then real information about the traffic routing across the network And do all that in real time, right?
With near no latency L and everything else. It's gotta be, That's, that's the black magic part. But I think, I think too, also you have to deal with it in two worlds, right?
You want the sort of simplicity of it, right? I won't have to worry about all the details of what interconnects with what I just want my bot management done this way, or my web application firewalls set up this way. And if I wanna take it more detailed, I can say this is, I want it done differently in different locations.
But then you also, if you take it a layer down, well, okay, well what if I wanna do application security? I wanna be able to do API management across all these locations. I don't wanna have to do it different in every cloud provider I'm interconnected with.
So are there some ways that I can, it may not be centralized that, but but do that in one consistent way across a connectivity cloud, like with, with CloudFlare. And then the other is, well, I do wanna get into the detail. I do want to put workers out on the edge of the network that are gonna do these kind of things.
They're gonna be running my code as part of the network as well as in the, in the hyperscaler environments. So you, you want the connect and go sort of the simplicity of it, but when you need the detail, when you need the control and you need to get into the depths of it, like every enterprise is gonna do, I'm sure I doubt there's any enterprise customer says, yeah, just connected it up and we're good. Right?
They're always worrying about performance of this and that and security and this data, uh, data sovereignty and localization and what has to be where and what network, how we do production. That's where the rubber meets the road is you've gotta handle all of those use cases at an enterprise level, but not make it so that, well, it's just easier to do this myself. Right?
You know, now that you're not doing managing the complexity for me, but you, you do, you are, you have to do that for your customers. Yeah, absolutely. I think, uh, uh, our goal is to provide an abstraction layer that simplifies management and configuration for customers as much as possible.
Like it should come out of the box super easy to set up logical defaults that makes sense for all the things. So the abstraction is there, but not, um, uh, a black box in that you don't, uh, have the controls if you want them, and you need the visibility to, to understand what's going on. So you should be able to connect and have sort of like logical, um, uh, uh, you know, smart controls in place for your traffic and for security as a baseline.
But then you're right, enterprises need and want the deep visibility into everything that's going on, the ability to get packet captures of all of their traffic as it's distributed across their network, the ability to see logs of all the information analytics reporting, and then also dig in and, and kind of tune all the little buttons in their knobs for the places where they want customization that is there for their environment. So it's a balance for sure. Um, but we know that it's really important to be able to do both of those things in order to, again, build that trust that organizations lacked today or have lacked in the past about shifting those really business critical workflows to use the public internet as their underlay.
Yeah. You mentioned logs and that brings up incident management, incident response kind of things, right? Where I'm, if I do all that connectivity myself, I've gotta intersect with everything and what went where to which provider and try to trace that back down.
Versus if I'm going through clear of a common cloud that's doing my interconnectivity, I've got a way to pull that together more easily. Not saying it's always gonna be easy right there, there's some challenging situations to really kind of put it all back together, but I'm not tracing down every place it might have touched just to begin, starting to put together an incident management, uh, you know, what the kill chain was for a particular attack. I've got a place to start where it might have traversed across one or multiple clouds.
Yeah. And that's something that we hear customers really struggle with a lot with this shift from the, the very centralized to distributed model for security is, okay, maybe I've put some bandaid solutions in place where I have one secure web gateway solution to help with internet traffic filtering. I've got another solution that replaces my VPN, I've got another solution over here that does some data loss prevention for me.
And when you zoom in on any of those individual points in the architecture graph, like maybe those solutions make sense, but then when you zoom out and look at the full picture and as an IT or security or network admin who's just trying to troubleshoot a problem, you have like eight or nine or 20, or actually, I talked to a CISO recently that said 80 different security tools to contend with, um, to just even try and start understanding what went on in a situation. And hopefully you're not at the point where you're, um, investigating like a, a breach scenario, but um, maybe even something that's as simple as just a, a connectivity loss. A user says, Hey, um, zoom's really slow for me today.
Where do you even start at, uh, at, at solving that problem? We think that the way to do it has to be this fundamental rehaul of the architecture where you're thinking about security and connectivity in a distributed sense, but then the visibility is still centralized, right? All of those different nodes that are enforcing the policy and making the connectivity citizens have to sort of report back to one place where you can actually go and see all of the things.
Um, 'cause otherwise it is just impossible to actually control or manage in, in, um, you know, in a practical scenario. An I've got another question for you, and I'm sorry that we, we, it's only me, you and Mitchell. So you know, you, we got you on the hot seat today, I apologize.
But let me, let me ask you another question. One of the things that I've always valued is I wanna choose my partners, right? Maybe CloudFlare is my partner, you know, for connectivity cloud, but I like company a's identity security company b's, other security company, c's, uh, you know, I like to pick my own vendors.
How, how hard is it? So do I give that up when I say, Hey, CloudFlare, I need your help with, I I need a connectivity cloud. I'm, I'm all over the place and I want to kind of centralize things.
Oh, but by the way, I do have maybe not 70 or 80 vendors, but I, and I got a dozen. How do Yeah, totally. Uh, so our intention is not to even attempt to be all things to every single company.
I don't think that there is a, a world where, except for maybe very, you know, niche scenarios, small, small startup companies that only have some very specific security needs where you're managing less than, you know, three or five security vendors. We actually view ourselves as enabler, um, for, uh, customers who want multi-vendor environments for redundancy and for resiliency, especially for the components where that makes a lot of sense. So we think, um, connect, uh, or excuse me, cloud environments, so public clouds, we wanna be an enabler absolutely.
For organizations that are pursuing a multi-cloud or hybrid cloud strategy. The idea there is you can use CloudFlare as sort of a, a unified control plane for the security controls for all of those public clouds so that you have consistent web application firewall rules, DDoS protection policies, maybe bot management strategy, et cetera. But then you can actually shift around the storage and compute that lives in the different public clouds and or your on-premise environments.
Um, use the best of breed capabilities in those clouds, as we were talking about earlier. Um, but your security team doesn't have to worry about sort of like the, the attack surface looking different depending on where you deploy your applications. So that's one example.
Um, but I think even within the internal connectivity context, you know, we, we partner really deeply with, uh, lots of different identity providers. If you have a one or multiple and you wanna integrate those in, we play nice with all of those providers. If you wanna keep your existing on-premise gear and use that to connect into us, you've got, you know, investment in an existing SD WAN provider, you wanna continue to use it, that's cool too.
So we recognize it's super important for us to, uh, to not just say, Hey, you're gonna, you know, burn down everything you have and, and start fresh. That doesn't work for anyone, especially large enterprises. And so it's really about where do we invest deeply in strategic partnerships with, uh, tech providers that we view as sort of, um, working with us in the, in the way that we wanna help customers adopt this new architecture that we're helping them shift to.
Um, and then where are there places that having a multi-vendor strategy actually does make customers lives harder? And how can we make that easier for them over time? Love it.
I get another sort of conceptual question for you and then, and you know, you've got your cloud flare hat on, so you're speaking on behalf of CloudFlare now. Um, so we look at the cloud landscape. I mentioned AWS, Google, Microsoft, Oracle, right?
Those are the four big ones for most of us. How do, how does cloud flare think of connectivity cloud? Is it a fifth cloud or is it something that just sits on top of these other clouds?
Mm, big question. Uh, so we are increasingly seeing organizations build more and more of their applications actually directly on cloudflare's network. So we initially built out the global network infrastructure primarily, again, for connectivity and security for, uh, our customers public facing applications.
Then sort of extended that into the quote unquote internal facing, but is increasingly becoming public facing, um, the sort of era. And then, uh, as we explored more and more of those use cases too, we kept finding these places where customers are like, Hey, I actually want to run part of, or in some cases my entire application on the edge close to users. Um, AI inference is a really great example of this, where you have to make a trade off sometimes as a developer of how much of that workload can you run on the user device versus sending back to a centralized cloud and then sacrificing like the latency in the application.
And so CloudFlare sits in this kind of great Goldilocks place to be able to do that specific kind of of application. So I think we think about, um, you know, what, what we're doing is different fundamentally, if you just look at the picture of the, the dots on the map, the connectivity, the types of services that we offer, um, it is not a one for one copy or intended to be of the folks that you listed as sort of the four major public clouds. And again, we view ourselves as actually an enabler of multi and hybrid cloud environments for our customers.
But we are seeing increasingly places where customers are like, yeah, actually that computer storage workload makes a ton of sense to deliver super close to users wherever they are in the world. And we're really excited to work with, uh, developers to continue to enable those kind of use cases. Um, and I think we'll see more of that moving forward.
Yeah, I know you're, your offering there has evolved a lot in the last three or four years. Absolutely. Yeah.
It's been interesting to, to watch it too, because when you talk about working with developers, um, I mean, there are, can, can be some basic things you might be able to allow or enable them to, to build or run in the cloud, but you're, you know, you're talking about supporting frameworks, you know, things like react, uh, or, uh, you know, no JS or things like that, next JS pages, whatever it might be. Um, so the more you can provide a familiar environment, not saying it's exactly the same as you're gonna run in your own, you kind of cloud instance inside of a hyperscaler, but to build applications to run in, in Cloudflare's environment, um, you have to offer some of those same capabilities. You gotta offer storage, you gotta offer some serverless options, things like that and frameworks that they can operate in.
So, uh, that, that takes some thought. You don't just jump into that, into the pool and say, Hey, we have developer support. 'cause developers say, say, no, you don't because you're missing 25 things I need.
Well, you got 20 of 'em, so you're close. Let me get started. Mm-hmm.
I mean that talk, talk about that journey, especially the security of apps that you build in a, in a CloudFlare cloud. Yeah, I mean, it's the long game for sure, but I think we're really encouraged seeing the number of developers that continue to build full stack applications on the CloudFlare platform or really critical components of their applications. Again, with things like our, our AI for developer stack.
Um, but you mentioned, you know, security and connectivity, that's sort of like the baseline if you're a developer that's working on, uh, building an application that leverages some or all of our developer stack security and connectivity and, uh, and traffic performance is just built in, like that should be not even a, a, um, a thought process that you have to have of like, okay, then how do I add this to my application? It's already there. And that include, that's, uh, in addition to things like the visibility, the multi-level of controls, um, and then the guarantees around sort of performance and user experience, again, of delivering those pieces of the application as close as they can possibly be to users.
So if your developer, um, uh, uh, working on a new application that that uses our stack security and performance, um, are, are essentially just built in, that's sort of the guarantee from, from moment one. And then it's really about, okay, how, uh, how creative can you get? Like what are the types of really exciting things that you can then build, um, knowing that some of those constraints are free or you get that time back in your developer experience.
Fair, fair guys, we're almost outta time here, but, um, time goes quick 'cause we were just, I mean, I think we've ran through a hundred different things. I like headed swimming where everything we discussed. One last question for you, Ann.
How's that? Sorry. Security never gets easier.
It security seems to be, yeah. You know, as much progress as we make, and, and I'm talking as a security person, as much progress as we make, it always seems like there's more in front of us than there is behind us. Uh, security never gets easier.
Ai all these new technologies, you know, with double-edged swords is good and bad that comes with that. Not, you know, what have you done for us lately? What do you, what do you see coming down the pike here, maybe with connectivity cloud type of operationally that, that will help us going forward, right?
What, where's the cutting edge? No pun intended. Where's the cutting edge for you?
Yeah, sure. Um, yeah, I think you make a great point. We have seen this shift, right from really centralized to distributed, uh, users and, and applications and requirements for security.
We think that that's only gonna get more complex. So more and more distributed world, more threat vectors to be worried about everyone is being asked to do more with less. Um, and so then how do we en enable that?
That's the big question. I think for us, uh, we're doing a good job if we're helping security teams spend less time on just day-to-day operations and management of the stuff they already have. Like if they spend, you know, a hundred hours a week managing their tool stack, how can we help dramatically reduce that?
Spend 10 hours a week on managing the things that you already have and the rest of your time on actually engineering on, uh, the full list of things that you have, uh, demands from the organization, um, about all of these new types of threat vectors that people don't even have the chance to get to today. I've never met a single CISO that said, yeah, my team has free time. Like, everyone always has a list of making more items long than there's hours in the day.
And so there's so much opportunity, we think, to, to reduce the operational overhead just by consolidating, removing that complexity. And again, thinking through this architecture from a perspective of what are the actual challenges that we have now and where do we need to be in the future? And what are the aspects of the ways that we've thought about security for a long time that just don't make sense given that reality.
And so the distributed nature of the approach that we've taken to everything we build, we think is really core to that. Very cool, very cool. Annika, thank you.
We, as I said earlier, you know, it's just you, I and Mitchell. So unfortunately we, we kind of are sitting here grilling you with, you're the person with the answers, but man, it's great. I just, you're too great.
We loved it. Um, I hope our audience out here appreciated it. Where's the one to go get more information on this?
Where would you send them? com, tons of public facing resources in both of those places. Um, and also you can feel free to reach out to me too if you've got questions, wanna connect with someone that gladly that can help you, uh, talk through or solve a problem that you've got in the network connectivity or security space.
It's very kind to you. Thank you Annika Mitchell, thanks for joining me on here. We hope you've enjoyed this, uh, episode of the last great cloud transformation.
And make no mistake, it is a great cloud transformation, right? There's a lot going on here, and we'd love to hear from you about what you are doing in your last great cloud transformation. And the best way to do that is to join one of our live sessions of this show where you'll have a chance to, to do that.
Uh, we'll put the information in the notes here for our next episode. But until then, on behalf of Textron Group at Cloud Flare and Annika and Mitchell and myself, have a great day everyone. Thanks for joining us.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security bloggers network.
Hi everyone, welcome to the Skill Up Days, uh, talk on observability. And today we are going to look at our topic from cap chaos to clarity. So what we're going to talk about in general is observability and how it helps, uh, organizations and how it leverages, uh, productivity in terms of microservice and Kubernetes.
Okay, uh, so we have two speakers, uh, for this event. One is, uh, Amit. Hi Amit.
Uh, please introduce yourself. Hey, Faruk. Um, I'm Amit.
I've been working in, uh, development and DevOps space for the more than 13 years, and, uh, love being part of the open source space. Cool, thanks. Uh, and, uh, so I'll introduce myself.
My name is Faruk Kari. I've been into DevOps for around 17 years, mainly into, uh, banking and the financial sector, focusing more on, uh, containerization and DevSecOps. Uh, and I like to teach.
Uh, that's, that's all I guess. Uh, let's move on, right? So, uh, a quick, uh, overview of what we'll be covering today.
So the first, uh, thing is we look at what exactly is observability, because you hear that word a lot. Uh, so we just try to break it down a little and, uh, look at what observability is, and then we'll talk about why we need observability in, in organizations and how it helps organizations to get business objectives, right? And then we look at the landscape, uh, which is really washed, and Amit will help us walk through the different tools that are there in the ecosystem and how you can use them to leverage productivity and, uh, troubleshoot more, uh, effectively.
And then we'll wrap up with a few keynotes. Okay? So the first thing that, uh, when you hear observability, it's, it's kind of like an umbrella.
It's a big thing. And then you can break it down into three, uh, separate streams. So the first one is logs, uh, which we look at more detail, uh, later.
And then you have metrics, and then you have traces. So think of it like an umbrella, which has three, uh, pillars. The first is logs, metrics, and then traces.
So let's see one at a time and see, you know, how, how this, uh, ties into the whole observability, uh, system. And why we need observability is, um, yeah. So the, the reason we need observability is the first, uh, reason is easy identification of issues, right?
So a lot of us have application systems which are spread across regions. They are really, um, isolated in nature. So what observability does, it helps us to identify where exactly the issue is originating from.
And that in turn helps to resolve issues quicker. Then that's what makes business happy, right? And, and the other thing that it does is, so once you find out, uh, where the issue is coming from, it also helps us to, uh, find out the root cost.
Like if the server is down, why exactly is it down, right? Is there a memory? Uh, constrained is the storage full.
So those kind of things are very, uh, useful when you have observability, otherwise you're kind of shooting in the dark. And then, uh, the, the last thing is you, if it observability, if you do it right, you can also go ahead one step and find out issues even before they happen because these are generally, uh, there are indicators of issues which you can, uh, uh, find out through effective observability. Right?
Cool. Right. So let's look at logs.
Uh, what is logs? So logs is basically a, a stream of data or anything that's been generated by a system, an application, or any kind of infrastructure. So it could be a server, it could be a container, it could be a serverless, uh, resource that you're using on the cloud.
So these kind of things are basically, uh, anything that's a resource that's running is capable of generating logs. And generally logs are timestamped and they're sequential in nature, which helps to troubleshoot, like, and correlate. Like if you go in and check, you can go into a particular timestamp of the log and then check it over there.
Uh, logs also have different, uh, levels of, um, uh, uh, granularity. So there are informational logs, which are just for information. Then there is also errors, and then you also have debug logs, uh, which kind of give you a pretty detailed, uh, logging, which is useful when you are troubleshooting, right?
And so the source is generally the resources that we mentioned, like servers, containers, and, uh, app, uh, operating systems as well. And logs are generally in text format, but you can also have, uh, different formats like JSON and XML also in certain scenarios, right? So logs are, are generally the starting point when you want to get started with observability.
And the, the challenges that you might face with, uh, logging, uh, implementing logging are, uh, threefold. Uh, so the first would be volume. So, uh, it's, it's sometimes very shocking the amount of laws the system can generate.
So you have to kind of plan ahead that what kind of volumes you're looking at for each application or each system. And you have to kind of do that capacity planning if you want to do proper logging. The other is also the speed at which these logs get generated and how do you rotate these logs and how, what do you, uh, you know, how do you manage this huge resources that are generating logs every second, every minute, and just pushing them out there.
And the third is, uh, the variety, because all systems have a slightly different way of, uh, you know, structuring their logs and their formats might be different. How do you handle this? And then, uh, inspect these logs to make sets out of it, right?
So two, to handle this, you generally have, uh, best practices that, uh, you need to do if you want to get the most value out of your, uh, logging solution. The first would be centralized logging, because the, the last thing that you want to do is, uh, be running around and trying to figure out where your logs are. So the first, the first thing would be to centralize your logs in an central place, and then you can build on top of that and you can do storage optimization and then visualization and all of the other stuff, which adds a lot of value.
The other thing would be having some kind of log rotation. Uh, so it could be based on time, so for example, uh, every day. Uh, but the recommended one is based on size, uh, where, you know, you have a certain size when your, uh, log file, which is a certain size, uh, maybe one gb, and then you start creating a new log file.
So that's the recommended way that you would want to look at, uh, loggings. And the third is, uh, like I mentioned, that there are a lot of different type of, uh, loggings that happen. You have informational logs, which generally are only useful at a point of time, and they really don't have any, uh, retrospective value.
Uh, so you kind of want to drop those logs, and there are solutions that help you to do that. So the only logs generally would be then, uh, you know, debug and error logs, and then you have different ways of handling them. So the way the logs are, uh, are labeled would also, uh, uh, influence the way that you're going to treat these logs and, uh, store them, right?
So that's logging in a nutshell. The next, uh, stream, uh, under observability is metrics. And metrics are kind of like, um, uh, a, a data point, uh, or, uh, a space of time.
So that's how you kind of think about metrics. So for example, what is the performance of this server at this particular time? Uh, so what's the average for the past 24 hours?
So that's, so metrics can then further be broken down into system metrics, which is mostly the hardware or the use resource usage, like the servers or the operating systems. And then you have application metrics also, for example, latency and how, how slow is the page loading. So those would fall under application metrics.
And then last, you also have business metrics. So business metrics would, uh, basically mean that, you know, what is the SLA, how much uptime do we have? Is the application going down?
So these are basically estimates that the business really needs to adhere to, and these would fall under business metrics. All right? Right.
So the third one is, uh, Tracy. And this is generally the, uh, the harder not to crack among the three. So tracing is something where you try to create a user story where the user comes into your application, and then he goes through a certain journey in your application, right?
So that's where, you know, uh, you try to map that. And what this does, it gives you a lot of information about how his experience was, where he's navigating, what, what, what are the bottlenecks that he faces. So for example, a user app and today's applications are all microservices, and they're all different applications within applications, which is microservices.
Uh, so you want to be able to find out if a user had an issue and you want to be able to do that fast so that you can tell that this is exactly where he faced a slowness in the issue. So was it, uh, a microservice microservice, was it a database or was it just across the application? Why is there a latency, right?
So the, the ability to do that, uh, and uh, look at issues like with through an x-ray lens is what tracing enables you. And this is more towards performance optimization also, right? And, and when you have all this information, what it does, it helps you to correlate these data, right?
Okay. So some of the use cases, like I mentioned, is, uh, why observability is really important in today's time is because you, uh, a a single application would be talking to multiple different resources, multiple different, uh, components within a single application, right? And debugging, this could be a nightmare.
So the first thing is that it helps you whenever you need to debug and find out issues, which is, um, uh, you know, where issues happen, you want to do this. Another thing is you want to monitor transaction, right? So if you're into banking or finance, and you want to understand that this application or this transaction failed, right?
So you can't really afford to have a failed transaction. So you want to be able to highlight and immediately, uh, look into this or look at transactions, which are, you know, anomalies which are outside of the general behavior. Those are things that you know, you can do with, uh, tracing.
And then the third one is failure. So why did the transaction fail? And if it failed?
So there would be alerts that you can configure and, and catch that with tracing. So it gives you the ability to go back, uh, in the journey where the user was and, uh, fix that or monitor that, uh, transaction. Okay?
Right. So now that we know, we went through, uh, what is observability and why we need observability and what are the three general streams that we have under observability, uh, Amit will help us to walk through the different tools that we can use for these, uh, metrics, uh, tracing and, uh, logs over to Amit. Thanks, Faruk.
That was fantastic insight into observability. Uh, so for now, what we are gonna do is we are gonna walk through Prometheus. Uh, protheses is one of the oldest open source projects, which has been used for metrics.
It has more recently been adopted, uh, by CNCF and is guided by the CNCF in order to make it better and stronger and ensure it's always open source. Uh, so one of the main things which prase is used for is collecting and storing time series data, uh, more specifically metrics from everywhere, whether it's applications, containers, servers, so on and so forth. Uh, all of these metrics are gathered and then finally stored in a specific type of storage.
We then enable it to be queried using ProQ so that we can perform different types of analysis and aggregation. And finally, we are going to use all these metrics in order to alert DevOps engineers or SRE engineers in case of any issues, um, any specific issues that the metrics highlight. And finally, it all comes together with visualization.
So what is the Prometheus use cases? It's all types of system monitoring, whether it is resource usage monitoring, such as CPU memory, uh, you wanna find out the performance and availability, which is like uptime latency of your issue, um, or anomaly and bottleneck detection. But again, it goes back into latency of your application.
This gives you realtime insights in, into all sorts of metrics that your application ensures to export. So how does all of this get visualized? Uh, you're going to visualize all this metrics and information in a tool called Grafana.
It is second, another open source tool for visualization, which specialize for monitoring metrics logs. Uh, it all comes together in one single GUI where you can visualize whether it's bar graphs and charts, uh, whether it's uptime and downtime. Uh, all of it comes together within the setup, including your logs, which generally people tend to use by leveraging Loki.
So how does a Grafana dashboard look on an average? So on the right, you can see whether you want bar graphs, you want dials, you want numbers, you can get it all. You can pick and choose what is your preference based on your end users, and decide what type of visualization you wanna provide them.
Whether it's monitoring infrastructure, whether it's application performance and latency log analysis. Everything can be done here in one single setup. We then go to Yeager.
Yeager is an open source distributed tracing tool. So this has been more recent of a tool, uh, in terms of versus Grafana and Prometheus, and this helps us in tracing and troubleshooting transactions in complex microservices architectures. So what does exactly Yeager do?
Yeager is going to try and trace a request all the way from the beginning or your first microservice all the way to the backend or your database system. It helps you to understand exactly how your transaction correlates from microservice one to two, to three, to microservice n. What does this help with and why do we need to do this?
This is so that we can visualize dependencies, we can ensure that we can find out which microservices taking the maximum amount of time or in case of failures, exactly which microservice cause this failure. It helps in planning for better resource optimization or ensuring that each microservices receives whatever resources are required for it. And lastly, but finally, it all comes down to improved reliability, improved monitoring, helping in debugging your systems and improving your SLOs.
So all that you want to do finally is ensure that your MTTR is really low. Your MTTF is really low. And how do you ensure all of this?
It's by ensuring that it's very easy to identify issues in case of a failure, and you can resolve it really quickly as well as you can monitor every single microservice so you can identify a microservice, uh, when it starts showing symptoms of failure, not before it actually has a complete outage. And lastly, and not, uh, it's, it's now come back to ai and we have a new tool called KHG pt, which has very recently been adopted by CNCF as well. And what does KHD PT do?
It's a operator, which is driven by an AI engine. You can pick and choose your AI engine, whether it's open AI, cloud, so on and so forth in order to manage, troubleshoot your Kubernetes clusters, your logs, et cetera. So this diagram shows you a very well explained example where it analyzes your clusters, configurations, it processes all your logs, it evaluates all this data and information, which would be more complex for a human to, uh, kind of go through and analyze.
A machine, on the other hand, can take all this information inside and process it in a very understandable manner and provide you proper outputs and insights along with recommendations of how you can improve some of your, uh, performance, as well as in case there are certain logs which are constantly throwing errors, it'll provide you recommendations of how you can permanently fix these issues. So as we were saying, it's a single Kubernetes operator that you install within your cluster, and it performs all the respective actions that it needs to do, whether it's understanding the complex problems, diagnosing all the different issues, and then finally going and recommending potential solutions or optimizations. Right?
So Amit, just, uh, I think, uh, with this information, if you look at this, uh, so you have for logging what, what, uh, the tool that I think is the industry standard is Prometheus, right? And, and then you have, uh, for, uh, metrics, uh, sorry. So, so for metrics, uh, uh, for visualization, you have Grafana and then you have, uh, Yeager, which is for tracing.
Is that right? Yes. And generally for logging, we tend to use Loki, which is again under the Grafana suite.
So you, you are absolutely right. So basically the key takeaways as you can see is metrics collection, which is mainly Prometheus visualization, which is mainly Grafana distributed tracing, which can either be Eger, which is, uh, managed by CNCF or Grafana, uh, version of tracing tool and centralized logging, quite a few of us use lowkey and AI management is completely new in this whole realm of things where case GPT is now the new tool, which a lot of companies have started leveraging, but there might be a lot more to come. Yeah, I think it's very interesting because uh, you always had observability for a while and you had these three things, but now there is kind of a merger of AI and then you can leverage AI with observability.
So that kind of puts observability on steroids and then you can explore more with, um, power of, you know, ai, uh, models, right? Absolutely. So one of the things previously is a lot of proprietary vendors used to sell you the idea that we have specialized, um, intelligence in the background where we can analyze all your logs and provide you these great insights, which would be very difficult for you to analyze.
This has now democratized and it enables a lot of people using open source to, uh, use similar such logic, um, along with which there are even formulas nowadays, which can help with anomaly detection, where you can add that formula into your Grafana dashboard. And what that does is it compares your current week with the past week and checks for deviation from the norm. And if there is a deviation more than X percentage, it'll send you an alert saying that, hey, something looks different within your systems.
Right? Right. And also with uh, yeah, I think, uh, Kate's GPT, you also have the option not only to use open AI uh, models, but you can also use cloud and any other models that you choose to.
Yeah, You can even use a model you choose to deploy on your own. So it also supports your, um, lama, if I'm not mistaken, which is currently, you can set it up yourself on your local machine or on your respective server and run it by yourself if you want your data to stay with yourself, and you do not wanna send it anywhere. Right, right, right.
Yeah. Makes sense. Cool.
All right, awesome. Thanks Faruk. That was a great session.
Yeah, thank you. Thanks a lot Ameds for time. Think this was good.
And generally when you want to start off with observability, I think, which one, which part do you recommend the most? Like, uh, logging metrics and traceability, how do you recommend, uh, somebody just getting started should get into this? I would probably, uh, jump between metrics and logging.
So I find that you need metrics or tools such as Prometheus in order to understand anything that you have. And the second thing is logging. You want one single location where you can read all your logs, understand what's going on in case of any failures, so on and so forth.
Yeah. Yeah, I think, yeah, that's generally the way to go about it because I think tracing is generally the, the second phase where you want to get more mature in jobs and then start with tracing, uh, because it takes a little more hands-on, uh, getting and implementing tracing. But you have a lot of tools that are making it easier now, right?
Like open telemetry. Uh, so if if your views, you have used a lot of it, right? Faruk?
Yes. I think Open Telemetry is kind of creating a standard in the observability space where, you know, you need to have a particular standard and then it kind of abstracts that implementation, um, uh, nightmare, which we had for different vendors. And then you can use any, any solution that you want.
But in terms of transmitting the data and filtering the data and all doing all of that, that that is where Open Telemetry is for focusing itself on, which is great. That is fantastic. Alright, so I think that's, uh, that's all, uh, we had.
Anything else you want to in on it? No, I, I think we have covered it all on a decently high level where, uh, this topic would be good to discuss between many different peoples on intermediate to high level to, uh, it won't be overwhelming for them. True, true.
Yeah. Thanks. It was lovely, uh, talking to Yamit.
Thanks. And, uh, thanks everyone.