Techstrong TV January 20, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. We're back here with our day three last day coverage of, uh, our time at AWS Reinvent. Uh, this guy's no stranger to our tech strong audience.
He's always either on a webinar showing him how to use Kubernetes, trying to make Kubernetes easy. Some say that's an impossible dream. Um, or on Techstrong TV, talking Cloud native And Kube with me.
He's my friend Andy Suman of Fairwinds. Andy, it's great to see you. Good To see you.
Thanks for Having me. You know, for people who haven't caught you before on either tech drunk TV or any of the webinars, give 'em a little bit of your background. Yeah, Sure.
So, I'm a long time infrastructure guy. I've spent, well, my entire career working in infrastructure. I've spent the last nine years working exclusively with Kubernetes.
Uh, now I'm the CTO at Fairwinds, and we help people run Kubernetes. We try to make it easy, like you said, And like I said, in some cases it could be a bit of an impossible task. But, you know, it's, it's funny, Andy, we, you know, we're, we're sponsored by ser uh, you're Sudman we're sponsored by suse.
You're at, it's the last day. I'm getting a little punchy. It's Oh, it's a Long, Uh, you know, we're sponsored by Susa at, at, at here at AWS reinvent, and we've been spending a lot of time talking to the, uh, rancher guys about multi cluster Gotcha.
Kubernetes management. I'm sure that's something that's near and dear to you. Yeah.
I mean, we manage quite a few clusters for all of our customers. We're familiar with rancher, lots of, um, lots of multi cluster stuff. I think, you know, the one question we all have to ask is, um, where's the data live?
Right? Yeah. Everybody was say like, we wanna go multi-region.
We wanna go multi cluster. And I say, that's great. Where's your data gonna live?
Because that's the thing that's harder to move between clusters. I, I agree with you, and especially in a world of data sovereignty and, and all of those things that you're dealing with, right? Absolutely.
But you know, what I found, and, and maybe, and I might be wrong 'cause I'm not the expert you are, but a lot of time, multi cluster Kubernetes happens quite by accident, right? You're, you are doing a Kubernetes project over here, and you spin up a cluster. I'm, we're in the same company, we just don't talk.
Yeah. I spin one up over here. Jill spins one up there, Bob and Harry over there.
And before you know it, damn, we got four Kubernetes clusters we're managing, but they're all kind of standalone. But, you know, okay, now we gotta get efficient and we wanna bring 'em together. Yep.
So I, I call that like the accidental multiple Kubernetes cluster. Yeah. We have a name for it.
Uh, our sales team knows this term. It's cluster proliferation problem. CPP.
Yeah. Yeah. So, okay.
We run into a lot of folks that have that, mostly large companies, lots of teams, different business units. They end up with a vast number of clusters. The cost gets outta control.
Um, and usually when we work with those folks, we work with them to consolidate into a platform. And so their end goal is let's get down to a manageable number of clusters managed by us at Fairwinds, hopefully, um, and build a platform on top of that so that all of these developers aren't managing all of their own clusters. And the goal is let's make it easy for them while also getting control and governance and policy in place.
Um, it's a lofty goal, but, uh, it's can be very successful for folks. Absolutely. Wow.
Um, you know what, this was a good way though, of introducing what Fairwinds does, and, and that You take me right up. I I did not even realizing it, but, but that is the kind of the, the bread and butter of Fairwinds, right? You've got people who have these, uh, proliferating clusters Yep.
And you have people who are saying, Hey, I wanna modernize and move over, you know, from to a mo, you know, maybe I'm going from VMware and I'm, I'm moving to another virtualized environment, but I want to go cloud native. I, you know, I want to go to a microservices architecture. Yeah, yeah.
Any architecture really, but microservices one, one way. Um, I had something I was gonna say and I lost it. It's okay.
We're live, so we just gotta keep rolling. So I'm gonna come up with something here for you that, um, you know, I just recorded or played our shi my shimmy says that I do every week, a little 10 minute video on LinkedIn and X. But one of the, the, the theme of this week was, Hey, man, DevOps cloud native and platform engineering are alive and well here at AWS reinvent.
And, and my thought was, you know, when I first got out here, I was just like, bowled over with all the agentic AI announcements. It seems like all AI all the time, right? Yeah.
And, um, but in talking to people and having conversations, you know, I'm hearing, well, one of the agentic AI agents Amazon came out was with the DevOps. They're calling it a DevOps agent. Mm-hmm.
I don't know if I'd call it a DevOps agent just yet, but, but they have plans. They have big plans for it. Yeah.
But hearing a lot about DevOps, a lot about cloud native, right? Cloud native is the choice. If you're looking for transformation modernization, you wanna move maybe from on-prem to the cloud.
Not all the way you wanna do a hybrid, you want to, you know, um, cloud native has had a strong showing here at the show and, and platform engineering is no longer a fad or a niche. It's, it, I think it's taken its place alongside the other two and, Hey, this, this is how we build software. Yeah.
How we run software. Absolutely. Absolutely.
You know, I, I think at Cube Gun we talked about, we've launched a product to help people build those internal platforms, and it's entirely based on cloud native software. Yeah. Because we really believe that is the future of platform and where it's going.
And I think we could see it from Amazon as well with the announcement of the managed ar o CD and Crow Yeah. Act or a CK, um, you know, they're doubling down on Cloud native as well. And so it's not going anywhere.
It's here to stay. And it will be, you know, the future of platform and DevOps engineering as we as we know it. You know, thinking back to the rancher announcement, what you just said is, is managed cloud native, the future, I mean, you guys manage for your clients, but you also, you could come in, set 'em up and parachute back out, right?
Yeah, Absolutely. Um, now, I, I had a similar experience in the cyber. We didn't call it cyber the InfoSec space when I was there, which was after about 15 years, 10, 12 years, I realized that most organizations just weren't capable of managing their own security.
It was, they didn't have the, they didn't have the budget, they didn't have the expertise. And quite frankly, they didn't have the stomach for it. Uh, are we at the same place and cloud native?
I think so. With the larger companies, that's absolutely true. You know, a lot of our customers, it's, it's one of one or two of those three things.
It's either they don't have the time or the budget or the people that all generally rolls back to budget, or they could do it, but they don't want to because they'd rather focus on business impacting things. And that's what we enable is, you know, let us do the things that you don't have the stomach for or don't care about, or don't have the time for, uh, and you can focus on your business. Right.
I've always had that philosophy of, you know, outsource what isn't your core competency. Yeah. I learned, I also learned that the hard way, the dot coms, I had helped start a company.
We wound up going public. Uh, we were what they call an A SP application searcher. So there's no cloud, there's no like T three lines of your internet, the gets meow internet.
I remember those. And, um, we're, we're offering hosted Lotus Notes, Oracle, PeopleSoft. And, and the lesson we learned is if it's not core and critical, those are the two things, right?
Yeah. Something could be core to your, to your DNA, in your case, Kubernetes expertise, cloud native expertise or critical. Your business can't run without it.
It, you don't give up things that are core and critical. Right. If it's core or critical, you might give it up.
Right. If it's not core or critical, you absolutely should give it up. Yeah, absolutely.
Right? Because otherwise you're just wasting money. Yeah.
And I think for a lot of companies, the, the intricacies of managing a cloud native environment, managing any IT environment, if you're not an IT company, you know, it, it's hard. But Cloud native in particular, because, you know, Kubernetes really never came with a chimey uneasy kinda button. No.
No. Batteries were never included. No batteries.
Security never included. There never included. No.
Uh, crazy false was never included. So what, what kind of, uh, you, you guys have a presence on the floor and everything. Yep.
Yep. What, what kind of, what are you hearing from people? You know, one of the biggest surprises to me, um, this is the first time we've had a booth at Reinvent.
Mm-hmm. Um, and, uh, in the past it's always been, you know, I always just kind of assumed that we'd get about 10, 15% of people using Kubernetes that has changed, um, in, at this. Oh, absolutely.
This show, it's 85, 90% of people really, you Think it's that high That I talked to, are using Kubernetes. And maybe that's 'cause they're stopping by a booth that says Kubernetes on it. Well, but, uh, go figure.
But I'm talking to so many more people that are using Kubernetes or planning to move to it from some other container orchestration or something like that. So it's a huge number. Uh, it's, it's good to see That is, that is, you know, I, so now you got me curious.
I'm gonna have to ask everyone I talk to. 85 sounds really high. Yeah.
Uh, like you said, confirmation bias on my part. Yeah, No. You know, the big picture number I always am told is that about 15% of payloads on the cloud are cloud native.
Hmm. Now, a lot of that is because it's legacy stuff, right? Yeah.
Yeah. I'm sure there's quite a lot still that, you know, people aren't talking about. Um, and it's also that, you know, I've said this in the past, is that they're probably using Kubernetes, the company is, but what percentage of their workloads are Running are running it That's a smaller, and that You're right.
That's a, that's a real distinction because I think what it is, is Greenfield products very well may be 85%. Cool. Yeah, absolutely.
I think So. Brownfield, again, people may not have the stomach to do that transformation. Right.
Or the need, I mean Right. Don't break what's not, If it's not broken, don't fix it. Yeah.
Don't fix what's not broken. Exactly. Absolutely.
Um, So this was your FI didn't realize this. This was Fair Wind's first time exhibiting here. Yeah.
Yeah. Coming back next year Probably. Yeah.
Yeah. Worth it. Good.
Good conversations. Good customers. Yep.
Yeah. Good show for you. All the right people are here.
Yeah. Really good, good conversations. And, you know, the parties are fun too.
The par, you know. Yeah. We did a, uh, a thing at the Sphere last night with you.
A wizard of ours was pretty cool. That's cool. Yep.
Um, wanted to talk to you a little bit about, forget the AWS for a second Fairwinds. Yeah. Anything new coming down the pike you want to share?
Um, nothing that we didn't talk about at CubeCon, but I'd love to share, you know, our new product to IDP Quickstart. So we are, I talked about a little bit a minute ago, but we are putting together with AWS, um, they've built an ATM mod blueprints repository that helps you build a platform from open source. Uh, they did a couple of sessions on it this week, A couple of workshops.
Yeah. We're gonna be running another one with them, uh, next week, I believe. com if anybody's looking.
Um, and we will show you the, the product that we're going to be building, which is get you started with a platform faster than you could probably build it yourself. 'cause the biggest problem with platforms is that people spend two, three years building a platform because it's such a complex task. And so AWS and Us together have made that much simpler, uh, kind of prepackaged it up for you, and then we can customize it to your business needs, and then you can build on top of that to, to serve your developers.
So, I love it. Yeah. Anything else you want to share?
No. Alright. Come to reinvent.
It's a long week. It's fun, but, Uh, it's a long week, but I, yeah, it's worth it. You, you're heading home today?
Tomorrow. Tomorrow. Good for you.
Yeah, me too. Yeah. All right.
Hey, you know what? We didn't mention Fairwinds website. com.
There you go. Andy. It's always good to see you, man.
I don't know when, uh, well, I'm not doing you, you guys don't do Q Con in Europe, do you? Uh, we will sometimes we'll have a person there, but we won't have a booth. No, I'm actually, I'm not.
Mike ards gonna cover Q Con Europe first. It's the same week as the RSA conference, so I'm out in San Francisco that week. Gotcha.
But we'll talk, and you guys are always on with your webinars and everything else around, Or we'll do something. All right. Sounds good.
Hey, we're live, we're at AWS reinvent on day three. We still got some great content coming up for you. Great interviews.
Stay tuned. Hey guys, thanks for the throw. We're here with Abinov Astana, who's CEO of Postman, and we're talking about an acquisition they made recently of an outfit called Fern.
That well, is gonna help everybody hopefully create better API documentation and SDKs. I enough. Welcome to the show.
Thanks for having me here, Mike. So, walk us through a little bit, what is the problem you guys are trying to solve here? And, um, you know, documentation I feel like has always been a problem, but hey, some people are thinking it might even get better in the age of ai, but what do you think the issues are and what are we gonna do here?
Yeah, so we've been spending a lot of time with our customers. Mike, you know, Bozeman is now a full, uh, API platform. We cover everything from design to collaboration, to testing to monitoring.
And I think one of the recurring themes that I was hearing from our customers was that they still are not satisfied with, uh, their developer portals that often come bundled in with their existing platforms. And, uh, you know, when we looked at the market, we saw that the phone team had done a fantastic job of, you know, both SDKs, which allow developers to consume an API. And lately they had expanded into the dev portal space, and they were getting a lot of traction with the likes of Square, um, and then Twilio and a bunch of others.
And, uh, we thought that, you know, this could be a great, uh, win for Postman customers and a great thing for foreign customers, as well as the whole market for these two companies to come together, where Postman, uh, offers a fantastic developer experience to build those APIs and share those APIs. And, uh, once developer portal and SDK offerings help extend that, um, and, uh, you know, bring consumers for those public APIs, uh, as a service to public, API, you know, publishers. Mm-hmm.
I think part of the problem that a lot of organizations have is that they have no shortage of APIs, but nobody really understands what to use them for, or what it is they do, or what those capabilities are, which I think comes back to the documentation. And yet nobody really enjoys creating the documentation. So how automated can all this get?
So, you know, we've been, uh, investing a lot in, uh, uh, AI capabilities within Postman. And over time, I would say that actually the importance of documentation, as you say, has actually improved over time. Like both for human and ai, you actually need good documentation as context, you know, whether it's a human developer or it's, uh, the AI agent.
And, uh, I think creating good documentation is not just like generating whatever comes out of an LLM, it's actually also these iterative cycles of trying to understand like how an API behaves, um, communicating that certainly. Um, and then eventually like publishing it. So, uh, I think we, we will, we are seeing like this, uh, resurgence of sorts, uh, of, uh, people wanting to have, you know, good engineering practices.
Uh, and, and some of it I think is also driven by just like this act of coding, just getting more and more like automated. Now, developers used to spend a lot of time like just writing like lines of code, but now when they're just like, you know, kind of hitting the generate button with LLMs, what goes into generating that code becomes more and more important. So I think there are these two sides to it, like the publishing process needs to improve.
I think Postman provides a lot of that with existing AI capabilities and the rest of the tooling that we offer. And then on the consumption side, we'll see more and more, uh, uh, importance there. I think with fun, I think what they have done is create a very exciting, very, very, uh, you know, beautiful like developer experience with dev portals, like, with a lot of customization capabilities, with a lot of configuration.
Uh, they have some AI capabilities embedded in that, uh, uh, uh, portals as well. And, uh, I think, uh, you know, we just, we just expect that this will, uh, you know, in the future be the default for like, you know, all a p publishers out there. Mm-hmm.
How do you envision all this playing out? 'cause you mentioned, uh, AI agents, and as I understand it at least, or I think I understand it, um, those AI agents are looking for the metadata that describes which the metadata is based in turn on the documentation. So ultimately, if we want these AI agents to be successful invoking various services and being autonomous, um, you know, for want of a nail, the horse might be lost, and it all comes down to the documentation, right?
Correct. That's true. That's true.
I think, uh, what, uh, has happened over the last year is that, while I think we probably talked about this in our last conversation, is that, um, while the agents have improved in capability, they're still limited around the context window and what goes as context into, uh, these l LMS and, uh, uh, the difference between like demos and working products or, uh, you know, kind of a cool hack to like actual workflows, uh, is, is how you put that context together. How do you take what is available about a system, uh, especially it's documentation and feed it to get like the right outcome. So, you know, yeah.
I'm, I'm like a full believer in, in this. I would say that most companies, uh, uh, you know, still have hundreds of thousands of APIs that are not documented well. Uh, some of that is due to just lack of time, but sometimes it's also just due to the legacy that's built up over time, you know, in these systems.
Um, and, uh, there's still like a huge opportunity for companies to update, update them, and, and frankly, they need to, like, uh, I think what I'm hearing customers, uh, say is that, you know, for people who are interested in building agents, now these agents need to talk to their APIs, so need to, you know, buffer up their APIs and make, make these agents, you know, functional. Uh, so, uh, all of that is, is very critical for the modern edge. So how many APIs do you see the average organization kind of creating and actually maintaining?
And is there a life cycle to this process? Because I think a lot of times APIs get creative and sometimes forgotten about. And, um, yeah.
How should we kind of think more holistically about managing these APIs? Yeah, I've seen like everything, you know, from each developer owning, uh, you know, five APIs or services inside an organization to, I would say roughly a team owning, you know, at least one. I think, uh, uh, every organization that, uh, you know, we work with has hundreds to, you know, thousands or hundreds of thousands of APIs.
It's very, very hard to actually remove an API. It's very easy to build one. And I think with the rise of like microservices, serverless, all this over the last like, decade, you know, the prevalence of the cloud, there are just more and more APIs out there.
Uh, I think with every platform shift, we also see net new APIs being created. So in the last platform shift, when people went from, uh, desktop apps to mobile and cloud, I think now we are seeing like that with ai, where again, you know, people want to create more and more services. They wanna create new form factors, uh, for agents.
So they're creating more APIs there. So the net number of APIs in an organization, you know, kind of always goes up. The hard part is actually maintaining, like, uh, technical integrity of the system, ensuring reliability of qualities of these APIs are well governed.
Um, you know, there we see like a gradation between, uh, you know, I would say technology companies who are much more prone to foster development, and they're like, yeah, we're just gonna like, you know, kind of keep going, just keep shipping fast. Versus I think more traditional sectors like banking, finance or, uh, uh, you know, telecom, et cetera, where depending on the amount of regulation that exists or what other constraints that are there on the industry, you know, they, they wanna make APIs a much more governed process. So, you know, in a nutshell, like, uh, hundreds of thousands of APIs at, at any sizable company, if you're a startup, like the moment you get to 10 developers, you will have, you know, at least one or two APIs, and it just keeps on growing from there.
But the management of those APIs varies from sector to sector, depending on, you know, how, uh, fast you want to go to production, uh, and, and how regulated you, you are as an industry. We talk a lot about, well, APIs need to be managed by somebody who treats it like a product and not some sort of add-on. And that the, if you're gonna manage it like a product, well, all products have good documentation, so they have to start with a thing.
But how many folks are actually managing their APIs as a product versus kind of still treating them as some sort of random software artifact that somebody granted? Yeah, I wish I had the state of, uh, API report numbers top of mind, but we'll, you know, make sure that we, uh, uh, you know, we, we share that in the next update. Uh, I think the number of companies that, uh, mentioned their API first, I believe is like somewhere between, you know, uh, 30 to 35% is, uh, if I remember right, and what, uh, you know, API first, uh, the label qualifies them as they, they think of APIs as first last citizens.
Uh, so we categorize companies between, you know, like API first, API aware, and API last. You know, I think still a lot of companies are in the API aware bucket. I think that percentage has increased over time.
Uh, many companies do treat especially like their top, uh, uh, you know, monetizable APIs or revenue generating APIs as, you know, big first class like citizens. Uh, you know, sometimes, uh, money to the tune of hundreds of millions of dollars is spent on probably just one API, uh, from there on, I think, uh, you have all these monetizable APIs at the top, and then you have your services that, uh, kind of, uh, are at the bottom. You know, especially microservices where developers can spin up and, uh, uh, you know, change their architecture kind of over time.
So I think that's the level of investment that goes from, you know, like very heavy to very low. Uh, in general though, because like, you know, when you're building APIs and services, they're all connected to each other. We believe they all need to be managed in a central place, which is what we have built postman for.
Mm-hmm. Um, so ultimately we will, we all just have an AI assistant that will create the documentation for us automatically, and we'll all get better at that. We may have to maybe have another AI agent that validates the whatever the first AI agent created, but are we entering some sort of era where we're about to have, well, better documentation all the way around, starting with APIs?
I would definitely say that agents will help you, you know, with the documentation. But I still, you know, uh, I think humans in the loop are gonna stay at each step. I think the role changes to be much more of a reviewer, uh, and, and coordinator of agents versus being, you know, like, uh, totally handing it off over to an agent.
We have seen that people, you know, like, don't like reading just, you know, the same type of, uh, language, you know, it, it, you know, it doesn't really, and, and the hall hallucination problems still can not solve, right? So it's like the agent, if it doesn't really get the right answer, it, it doesn't have like an understanding of what is right or wrong in the first place, but it tries to please, uh, people. So it kinda ends up hallucinating.
So because of that reason, until like a more fundamental breakthrough happens, you know, humans are gonna be there, but they'll definitely be using agents to write more. They'll be using agents to, you know, uh, orchestrate more of these tasks. I think one interesting area where I do see, uh, especially with API design and API documentation agents play a big role is like consistency, like across APIs and across different systems.
That's generally been very hard, where every team, every product, you know, feels a little bit different. And I think one of the areas where we are investing is in making sure that agents are available for, you know, engineering teams to deploy, to make sure things are more consistent. Uh, so I kind of feel like, uh, right now, you know, people will definitely opt to use agents in areas that they did not want to do before, you know, versus areas that, uh, uh, they, you know, that are really challenging and require, like, the specific skillset that a human has.
But over time, I think, you know, it'll be much more like of an orchestration of different agents working together. Mm-hmm. Um, is there any correlation between documentation and consumption of the API we create these APIs in the hopes that people are gonna use them, but yeah.
From your perspective, have you seen any trends where in the APIs that are better documented are just that much more widely used? Oh, absolutely. I think, uh, I, I would say that I underestimated it, you know, starting out, like when I was a developer, like, uh, I think the amount of time I've seen people spend on just make if, if an API is relevant, like people spend a lot of time on these activities and, uh, um, if you don't have a well-documented API, you know, people just end up creating a net new API.
That's what kind of happens in engineering organizations. So, you know, part of the reason why a PS for all exists is that just people don't know that an existing API is available to do the exact same thing. And we have, like, you know, lots of customers who have said that they were midway through a project, the project was falling behind, and then suddenly they stumbled upon like an API or, or documentation of an API that some, some other team created.
And their project just went, you know, way faster, um, with, with very critical consequences. So documenting your API, making sure it's discoverable, making sure it's available for consumers, they can actually hit the API call and actually incorporate at all, like, relevant things. If you don't do any of these things and you just expect, you know, people to, you know, use, uh, uh, the API on their own, I think, uh, they're just gonna fail.
You know? And even in the AI age, you see like how much effort, like, uh, AI companies are spending, uh, on, on their documentation. You know, it's not just like, Hey, here is, here is chat, GPD, just go figure it out.
You know, there are developer portals, there are SDKs, there are videos. A lot of work goes in in making sure that people actually eventually incorporate APIs into their workflow, and it all goes, you know, uh, it all flows back to documentation. Hmm.
So going into 2026, what's that one thing you see people doing with APIs that still makes you shake your head a little bit and go, folks, we need to just be a little bit smarter about this? That's a, that's a great question. Um, you know, I would have said that, uh, giving, uh, you know, like your entire API to agents and expecting them to figure it out is, is still kind of happening.
People are still trying to figure out like, okay, how do these agents work? How do I manage context windows? And right now, people are still using, uh, APIs that they're designed for humans.
They kind still feed it in, into, uh, agent apps and expect it to work. I think people need to focus a little bit more on how their API design, how their a p architecture works. We have done that a lot at Postman, kind of as we have rearchitected a lot, a lot of our platform to work with, you know, ai.
I think people are still kind of, uh, you know, trying to ignore like the API problem a little bit and expecting agents work, and, and I think that's how they just, uh, uh, you know, end up having failure modes, uh, whenever they ship like agents. All right, folks, you heard it here. Our little digital world revolves around APIs, and yet maybe we don't give them enough thought.
So be resolved in 2026 to hopefully fix that issue. I've been off. Thanks for being on the show.
Thanks For having me here, Mike. All right, back to you guys in the studio. Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group.
Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platforms. Before we jump into today's episode, let's meet the panel starting with Fernando.
Hey, Fernando, it's good to see you. Hello, everyone. Fernando Montero.
I lead cybersecurity research for, for doing the, our research arm. And it's always a pleasure to be here and, and chatting with you all. I just came back from a trip to South America, and I'm, uh, uh, I'm still a little jet clack, but it'll be fine.
Well, we're glad to have you back. Famous us Last words. It'll be fine.
It'll be fine. And, uh, on league guitar always is Mitch Ashley. Mitch, good to see you as well.
Thank you. And turn it to 11. You know, if you got 11, it's gonna be louder than 10.
Shout Absolutely out to Rob. So anyway, Mitch Ashley, I lead the software lifecycle engineering practice, which crosses over into some security areas. And so I get to work with Fernando real closely, and of course, Tom on the podcast and other activities.
So great to be here. And of course, I'm Tom Hollingsworth event lead for all things related to security at Tech Field Day, which is a part of the Futurum Group. Let's jump into today's episode.
Now, depending on when you're listening to this, it might be old news by now, but, uh, vibe coating is real, folks, because Linus Torvalds actually used Vibe coding to check some things in to the Linux. Colonel, uh, now he had some comments about it. He said it did probably a little bit of a better job than I could have on some of the things, but I still had to go back and remind it to do some other stuff, which has led to a little bit of a discussion as we're recording this, as to whether or not vibe coding is a real thing, or if it's just, uh, something that advanced programmers can use to kind of help lay the groundwork.
But what really matters is the fact that no matter whether it's real or not, the security implications of what Vibe Coding offers are, I'm not capable of telling you exactly how deep they go, but luckily, one company that is, is Palo Alto Networks, and Mitch brought this up for our discussion today. It's something they're calling the Shield Framework. Now, I imagine that it is a, uh, distinctly different round shield with a star in the middle that, uh, in no way can be traced back to Disney or Marvel, because that would be wrong.
And we, we, we can't infringe on anybody's copyright, but I'm sure that, you know, some of the things they're talking about when it comes to separation of duties and keeping humans in the loop are things that we have preached quite a bit here at the Security Boulevard Podcast. So Mitch, I wanna let you kind of introduce what SHIELD is all about, and then we can kind of, uh, talk about whether or not it really is the, uh, the optimal way to do things. Great, great.
Well, I think as long as they steer away from, uh, agents of Shield, they probably, I was gonna make the joke. That's okay. Oh, oh gosh, I didn't mean to steal the joke.
No, that's Totally fine. You, you go, you go with it. Tom did, Tom did such a nice setup.
I couldn't let it hang out there too long. Oh, God. Yeah.
So, well, first of all, kudos to, uh, Palo Alto Networks for putting this out there. You know, uh, vibe coding is a real thing. It's not, you know, not all codes gonna be created through Vibe Coding, but a lot of, um, citizen developers, if you will, uh, are using of course, vibe coding.
But so, so we're a pro code, so we're pro professional developers, and you mentioned Linus, who, uh, we no doubt about his coding skills. So it's, it's a real thing, and it's gonna be with us for, I think, for a long time. So, SHIELD stands for, lemme just kind of run through the letters.
S is separation of duties followed by human in the loop input and output validation, enforced security focused helper models. Long one, there least agency defensive, which I think is like least privileges, right? Just from a, from execution standpoint.
Defensive, tactical controls. And then, let's see, oh, that's the last one. Shield got 'em all.
So it's, you know, and my my just take on it is, is this gonna take over the world? And everybody's gonna say, oh my God, this is what's missing. Now we can let vibe go, vibe, coding, go, you know, uh, on its own journey into the organization and not worry about security.
Of course not. But a lot of these are, I think, just mapping what we know is, uh, security principles to an agent kind of world, to a agent led development type environment. You could apply this to, whether it's AI assisted or not vibe coded, but still AI centric development too.
I, I wanna jump in here, Mitch, because I think you bring up a really interesting point. Nothing in SHIELD is different than any of what we would consider to be best practices, right? Least privileges, giving people the minimum amount necessary to do their job, validating inputs and outputs so we don't get eaten up by them.
These are all very good things. I don't necessarily think that they only a apply to Vibe coding and stuff like that. Now, is vibe coding probably the biggest risk that we face right now?
Yeah. Yeah. I would say that it is, because one of the things that we're gonna have to deal with over the course of the next several months, years is what happens when people with no programming background try to program.
Because that's really what we're dealing with right now. It's like, I, I, I have a, a 16-year-old daughter a couple years ago. She's like, dad, can I learn how to drive?
And I said, sure, but there's a process, right? I'm gonna teach you, sit behind the wheel where all the controls are, then we're gonna do it in a controlled area, like a parking lot that's empty. Then we're gonna start building up.
You would not give my daughter access to Gemini and say, figure out how to drive, how hard can it be? Drivers do it all the time Now. Yeah.
So many thoughts floating right now. I think that the, the, I agree with you that this is something that, uh, it's, it's coming. It's something that, uh, you know, in a sense it's already here.
And yes, we should do it in a, in a controlled manner. I would like to shift, no, not shift the conversation, but I would like to point out something that there is a deeper philosophical discussion, right? I think it was Corey, who, who, who talks about, uh, code is a liability, right?
Every code that you write is something that you have to maintain later, right? And the other, uh, and I mentioned this because I came across an article the other day that talks about AI can write code AI can't do software engineering, right? And that is a, is a, is a phenomenal point that I think, uh, uh, we should keep in mind when we, when we look at the expectation, what we expect out, the vibe coded, deluge, deluge of, of, of stuff that's coming, right?
Yes, it can be extremely helpful in some, uh, scenarios. Like, I think, I think that it's revolutionizing things like prototyping and whatnot. Um, I, I, I shudder to think of production where, which is why I think some of the stuff like, like, like the SHIELD framework is interesting because it's, it's catchy and, and it touches on the things that yes, they're not, uh, novel, right?
But just let's, let's keep them, let, let's keep the problem contained as much as we can. Well, it's, it's a good point. I definitely agree with you.
It's, you know, software is about software engineering. Now we have low-code, no-code solutions today that people create great applications from. Many of them, they don't go to it to work with, but a vast majority of them involve it.
Even it is using a lot of those low-code, no code tools. Same thing here. Um, the, the issue with, by coding, if you've, you know, we're talking to a security audience here.
So many people may not have messed around with writing code with, with ai, but it's much like a session that you would have with Claude or, um, with OpenAI, with kind of chat pt where you hammer on that session, you have a se series of prompts. After a while, it tends to drift because the context window is now too large to contain all of the conversations, especially when you're dealing with code, because you're generating a lot of text. And so it's, it's, it's a bit problematic just to go through a session and vibe, code something from scratch all the way to the end in a session.
And that's why you see vendors coming out with things like intent based development or spec based development. We're kind of going back to realizing that you have to do a lot of, uh, really good prompt work. And I don't mean prompt engineering, I mean, specifications kind of prompt defining requirements, limitations, what the tech stack looks like, et cetera, to drive that.
Now if, you know, if you know that already, that could be input to your coding, but that's that part of that process of engineering, which is the upfront requirements design and, uh, how you want the code to behave and look, And Absolutely. I I just wanted to interject thing. Like I, I, I was chatting, uh, I think Mitch, just before on the pre-recording here was, was, uh, chatting with the guy and I, I mentioned I was, I was coding something over the weekend and, and, um, I can read JavaScript really well.
I can't write JavaScript really well, but, um, um, I vibe coded my way through something that I needed. And one of the things that always struck me when, when vibe coding with is that if you don't tell the, the system in, in what software engineering instructions, you end up with a mess because, uh, um, not to make the, this thing too long, but one of the things we were doing is we're writing some, some, some JavaScript code. And then at some point I stopped and said, look, shouldn't we be refactoring this into separate modules?
And, and, and so on. And, and of course they're very ous and they, oh, yes, you're absolutely right. And then they recommended that, that we break it apart into different modules and so on, so forth.
And then at some point they said, I said, look, shouldn't this thing here be hard coded here? Shouldn't it be an environment environment variable somewhere? Or, or, oh yes, you're absolutely right.
And then do the same thing. I'm not saying I'm not a great, I'm not a software engineer by any means, but like these little things and that, and, and to your point, um, we need to help organizations understand this and then develop the right guardrails for, okay, if you're going to code, right, this is what you should expect. And, and, and you're an expert at this.
So, uh, uh, yes, this is very much the, the, the, the issue of letting this thing run am make mistakes practice. I haven't followed up on so much on the reports yet, but I think there is a significant number of people indicating code generated still vulnerable, code vulnerable at scale. Now, again, why this SHIELD framework is interesting?
Yeah, I think that, you know, and some of the models are getting better about that, but it's still very much an issue around vulnerabilities. I'm thinking about the, the shield framework, the, the kind of what they've set up here at Palo Alto. Yeah.
Um, the one that really jumps out at me is enforce security focused helper models. Um, and there's a good article that Mike Ard put up on, uh, security boulevard com. So check it out.
We'll, we'll include a link in the description, um, about invoke and external and independent helper modules to perform SaaS testing, secret scanning, security control validation, blah, blah, blah, blah, uh, to identify vulnerabilities and hardcoded secrets prior to deployment. So you could, you could say that's true for any kind of code, right? Um, and probably is, hopefully people are invoking, uh, routines or, or processes in their tool chain and their workflows that they do with software already.
Same applies with, with vibe coding and using AI tools. Now, I think it's gonna evolve to be a different little bit of a different form where security, uh, and things like observability really are, are baked in through more security guardrails that are part of the development process is just another linear step in the development process. But to their point, we really need some very good agents, very good mod modules, AI models, excuse me, uh, that are really good at security, not just testing, but generating and verifying code as it's being generated, uh, so that it comes out relatively secure.
There's fewer things for scanners and other things to find. I think an important point that everybody listening to this podcast needs to mark a note is what Mitch just said. They come out secure, not, we eventually make them secure, not we think we figured out how to get this working.
Is that one of the advantages of having something that is generated by an agent or, or an algorithm, is that the things that we would normally do in a system to deal with error handling or deal with security issues are baked in when the prompt or the guidelines say that we need to do that. Like, I can remember, you know, taking intro to programming, well, more years ago than I care to mention, um, and the fact that we went and learned how function calls worked, and we went and we learned how to iterate through loops. And then, and only then did we learn, oh, yeah, and you have to wrap all of them in exception handling, right?
You know, if this fails, shel this message or something like that. And I remember the person who was teaching me this was a programmer for the Air Force by day, and she flat out said, she goes, most of your code is gonna look like this. Like when you write the actual code, you're gonna have so many wrappers for exception handling that it's just gonna, it's gonna blow your mind because we have to be ready for everything that could possibly happen.
And I think that that's one of the advantages of this is that by giving it a narrow focus, like you guys have said by telling it, I need you to go in and iterate on this function, or I need you to iterate on this block of code. 'cause I mean, in, in what I mentioned at the top, that's exactly what Linus did, is he had it go over his code and say, okay, make this look better. And then it was having problems with the selection algorithm, and then it was like, I need you to work on this thing specifically.
And that's a lesson that we've been teaching people in computer science for a lot more years than I've been programming, is don't try to eat an elephant, you know, all at once. You've gotta break it down into sections. You've gotta figure out how to solve that problem.
And then once that problem's solved, then you move on to the next problem. And I think that that's one of the things that people who try to jump feet first into coding don't understand, is you've gotta break it down and you've gotta secure each of those functions. Because how many times have we heard that, you know, there was a security breach because one module of an overall program had a hole in it that we got away from us.
Like we, we cannot, we, we, if we try to boil the ocean, so to speak, we will forget something that is just human nature. It goes back to the point I made earlier. Code is a liability, right?
It takes an experienced software engineer to know when they need code to fix something, right? Uh, uh, there, there is a, um, uh, of course I'm gonna bring in economics at some point, right? The, uh, there is a, uh, it's in economic, it's known as the Jevons paradox, right?
Which is this notion that when something becomes cheaper, right? We actually, we, we would expect that, uh, uh, when, when something becomes more efficient, we would expect less usage of it. But actually, no, we have more, right?
Because now you can do more things more efficiently, and it's being shown all over the world. I think the original definition started with coal in 1860s, but it definitely applies to code now, right? In this age of vibe coding, it's not that we're gonna need fewer software engineers, we're gonna need more software engineers suggest that those software engineers are now doing higher level, more efficient things, right?
But I think you brought up a phenomenal, uh, point, like when you were teaching what to do and, and you were saying like Linus was, was iterating over a function, Linus is an experienced, very experienced software engineer, right? Give that software engineer a tool like vibe coding, and you get tremendous amount of things. Give someone who is an, who's not a software engineer, the expectation of, Hey, I'm gonna code my way through an entire application, and I'm gonna post that, and it's gonna be something that, uh, I eventually is gonna have.
Uh, it's gonna have, uh, users and it's gonna have passwords, and it's gonna have credit card details and, and, and whatnot. And you can see what this is going, right? So, uh, it's very, very important for us to get this right.
We're not gonna get this right completely, of course, but it's, uh, uh, it's, it's so, so critical that we do, sorry, I'm ranting as user. No. You know, one things I would recommend, Fernando, is, and I said to our audience for listeners, you know, maybe many of the folks are not developers or, or have done a lot of development, this is a good chance to get exposed to it.
You know, I'm, I'm very much kind of a do it learner, right? About 50% is like going and researching it, and the other 50% is doing it and figuring out how things work and how to secure it. And you could pretty easily do, do some vibe coding, you know, with Gemini, if you have a, a Google account or with Microsoft Tools, visual, uh, visual, uh, studio code is, is free.
And you can use a number of, uh, models to do this. Either Claude or you could use the open AI model that they're all, they're very good. Um, go, go write some code.
Do do kind of a function, create a little utility for yourself. Maybe it's processing some files on your file system. Maybe it's, it's, um, you know, taking, uh, flagged emails or labeled emails and doing something with it or sending you an email summary of it.
Something like that doesn't have to be super sophisticated, but the point of it is, is you'll see the process of, oh, well, I, I know it's not only just writing the code that that's gonna be generated by the model. It's I need to set up an API to get to this service in my mail system or in Google, or, or the director or whatever that I'm using. How is that being secured?
What, what kind of settings are are available to that? Because if end users are doing this, non-technical folks, hmm, okay, that might, might be interesting, might be a problem, might be something we wanna know more about and dig into further. Um, what are some of the privileges that, uh, are inherited just because you're using your own account, your, your company account as part of the vibe coding system that you're building together.
In other words, take the whole in context of what it means to create an application, not just generate code. Uh, you'll learn a ton and you may never pick it up again. You may say, Hey, this is really handy, I might wanna do it, do some things with this.
But you'll start to see for yourself where some of those exposures are And, and pick picking up on that. I, uh, if you are a cybersecurity professional who is not as, as Mitch said, I've involved in, in coding, there are many examples within what you do on a day-to-day basis where you can apply some of this, perhaps your, uh, sim uh, already have an enrichment function, but if it doesn't, would it help you to write one, hey, like can go in, learn how to query from an a p query the get the data, or then potentially query what your, what your threat source is gonna be. Pick that up, mumble them, send it back or, or whatever.
If you are in GRC, can I automate the collection of artifacts that we're gonna use for validating compliance or, or can I use even better? Can you take the, the, uh, can you take the artifacts that you're, that you're using, and then you can play around with large language models to perhaps interpret that. And, and, and then you'll see what the, that the output of that large language model may not be exactly what you wanted, but that's fine.
Like you're experimenting with that. Uh, so I don't, I cannot think of an area of cybersecurity where there isn't some little function, some little, uh, use case, uh, where you can't, you as a professional, uh, experiment with it, right? Like perhaps it never sead the light of day, but it got you a little bit further.
Lifelong learning people lifelong Your head in the, in the head space, for sure. And one of the sort of fallacies about agents, quote unquote, is that the agents aren't just prompts, most agents are actually have a lot of code involved in your regular software code along with some prompting into the LOM. So a lot of the processing still happens in regular code.
Um, so when you hear people are developing agents, don't assume that's just a prompt that you've gotta worry about prompt injection and how to make that more secure, efficient, et cetera. There's code involved. There's code, and there is a spectrum of things, right?
I mean, there are things that are workflows and there are things that are agents, right? And, and they're different and, but all of them involve code. Absolutely.
I think that, uh, and, and Mitch has done phenomenal work on, on, on tracking how some of these things should be secured. Like, uh, uh, he's done some work on, on on the agent protocols and so on. So I highly recommend people.
So if you, as, as you, as you listen to us, as you, as you watch us role check out the stuff that Mitch has put out on, on agent protocols, for example, it's top notch. Well, I'm firing my publicist in hiring you. Thank you, fer.
You're great Colleague. I, yeah, I get, listen, I get the pleasure of reading or sometimes peer reviewing that stuff. Oh my god, yeah.
We Do peer review each other's stuff a lot. It's Awful. Which is great.
Same back to you YouTube. You're doing great work. Thank you.
Fantastic work. Yeah, speaking of putting things out there, uh, recently we had, uh, tech Strong TV's Predict 2026. Uh, if you didn't get a chance to tune in, make sure you had over to Techstrong TV and, uh, check it out.
It, it was great. But now that I have two of the people who were involved in the making of that, I wanted to give you guys just a few minutes here at the end of the episode to give me one of your security predictions for 2026, because I'm kind of, I'm fascinated to see where people think security is headed in the next 12 months. Mitch, I guess I'll start with you.
Uh, what was one of the things that you think, uh, people are gonna be seeing in 2026 from a security perspective that they need to be on top of? Well, I think the DevSecOps folks will be pleased to hear, and this is both the security and the software side of it is shift left is gonna give way to something called continuous guardrails. So we've really struggled with shifting left.
Um, it makes a lot of sense to do things earlier in the process. Um, but we still kind of are left out of the code writing process and we're, we're leveraging scanning to actually perform a lot of the security for us. The, what's happening in the market, because AI is moving so quickly, everybody wants to be part of the new stack, the platforms that, that AI and agents are being built on.
So you see observability companies, security companies, creating agents, um, or specifications, things that can be added, uh, even into like when AWS announced their security agent, other, other companies were partnering along with that so that you could implement rails as part of the, uh, development and execution environments. And I think that's our hope for the next evolution of DevSecOps Shift left. We probably won't say shift left that much anymore, but I think that's where we're headed.
Yeah. I, oh, yeah. Uh, I have, I have a, uh, a love hate relationship with predictions in the context that, um, it's great fun to do them.
Uh, we should always be checking to see where, how did we get them right? Did we not get them right? Okay.
That's, it's, it's a fun exercise, but I always think that part of our role as analysts is to help understand these broader trends and then just highlight, okay, you know, what this kind of thing is more, is happening more often. Is that a prediction? I'm not so sure.
Like, uh, uh, uh, anyway, I think that the, the ones I, I, I, if you, if you watched our session, you saw some of these, but I think that besides the ones around, yes. More ent, ai more, uh, uh, particularly particular focus on identity in 2026. I think that 2026 is gonna be a very identity centric year.
But, um, outside of that, I, and this, this comes up a lot in conversations, is I think that we are seeing, and even ties back to our vibe coding conversation, is that the pain that organizations are, are, are feeling like when, when, when we talk to them is, yes, all of this is going on and all of this is important, but all of this has to work together, right? It, uh, so one of the things we're calling out is that, okay, great, we're doing all of this effort in relieving new functionality in whatever field or whatever format it, it has to integrate well together, right? So I I I'm hoping that 2026 is the year where we do focus a little bit more on the integration effort between things, right?
Uh, I, I, one of the visuals that stays with me is, um, I'll, I'll give props here to, um, uh, F five. They have that, that visual, not sure if ever thought the ball of fire, right? Which is the, the overwhelming complexity of a modern planetary scale application that touches content delivery networks, that touches, uh, uh, uh, serverless functions, that touches, uh, actual VMs and, and containers and Kubernetes, and, and all over the place.
Supporting that complexity requires tremendous amounts of integration work. And I think that, uh, one of the things that, uh, that we're calling out is, is this notion of how are we gonna support that kind of integration? I'm sorry if I sound fluffy, but, uh, it's the, um, it's the, the, one of the things I like, the other one I'll just, uh, is that as we focus on iden, the two things most important that I see are identity and data, right?
And as we focus on data security, right? We, we called out this, this change from backup and recovery to cyber resilience. And I think that we're moving more towards more integrated data security platforms and those data security platform, data security platform functionality, right?
And that functionality is covering structured data that ties to the API that ties to the code that ties to unstructured data. Again, we can tie LLMs and so on with, uh, resilience, like what we, what we used to call backup and recovery, right? So we're seeing this, this merger of, of support for unstructured data support, for structured data support for, uh, um, primary storage and backup storage.
We're, we're seeing these things kind of merge together. And, um, it's interesting. I mean, uh, whether that be, uh, whether that be coming from people like, uh, like, uh, Fiera or, or Veeam or, or Commvault and, and, and, and, and others, right?
That's, um, that's a really interesting evolution for 2026. I think that how, how this is, is merging a little bit more. So I'll jump in because I didn't actually get to give any predictions for the Predict show, but, um, I, I'll be a little more concrete than Fernando.
Um, I think that 2026 is gonna be a banner year for security startups related to ai because companies are, that are bigger, are too busy trying to figure out how they're gonna use it instead of how they're gonna integrate it, it into their products. So they're gonna overlook a lot of things, and small startups are going to make bank when that time comes. Because the other thing I think that's gonna happen is sometime in the middle of the year, we are going to have some kind of AI data leakage situation that is so massive, and also so legally far reaching that a lot of companies are going to have to make some hard choices about how they secure their data and how they've integrated AI into all of their products.
And, uh, that may not sound like a, a concrete thing, like, I'm not putting names to faces, but I think that we are definitely neglecting a lot of the pieces that are important for us to keep everything safe at the, um, behest of trying to make the, the line go up. And, and once that happens, it takes something really earth shattering to make people realize that line go up is not the only purpose of a business. And so, I, I think we'll see that this year because we've, we've missed it too many times in the last 24 months.
Uh, the, the, the odds are not in your favor there. Um, speaking of which, we Should, we should do an, we should do an episode on that, by the way. We should talk about.
So, uh, when asteroid, when the asteroid is going to hit the earth, then everybody will do something about what security, right? And do it. Does those, those things ever happen, or they rarely do?
I'd love to do a, an episode on that. That'd be fun. Well, Let's, let's leave it up to the audience.
Do you guys wanna see an episode of about what happens when disastrous imminent, and now it's suddenly time to do security? If you do leave a comment on this episode, and we'll put it on the, the lineup, but it'll, it may have to be a couple of episodes out, because my two co-hosts are super busy with a lot of stuff that they've got going on. Uh, Fernando, what are you working on that people should check out?
So my, I am, I'm writing a report right now. Uh, it's a little, it's a little later than I thought, but I'm writing a report on cyber physical systems, right? This, uh, I think that there is something to be said here on the, the evolution of I what we used to call iot or OT security.
I think it's evolved, and I think it's the perfect, I shouldn't say perfect. I think it's the, the, the final level boss, if you'll, of securing a lot of things. It brings in the complexity of regulatory frameworks.
It brings in the complexity of a massively complex supply chain. It brings in the complexity, complexity of, uh, severe constraints on operating environments and end user behavior and, and, and all of those things. So I think it's a, it's a very important area for people to grow their, their, uh, uh, their familiarity with, support, those kinds of use cases.
So that's my next report. I'm, I'm, I'm deep into it. And there have been some massive acquisitions in, in the space.
I mean, uh, uh, Mitsubishi and NA and ServiceNow and arm. So it's, uh, um, it's really interesting to see, uh, what's going on here. And Mitch, what have you got going on?
Well, well, juggling lots of things, but the thing that's, uh, foremost in my mind is we're putting the final touches on the, uh, first half of 2026 data set for the software lifecycle engineering practice. All that to say, it's the latest data that we've gathered from decision makers around people who were investing in AI to using, using IT organizations as well as development tools, operational tools, uh, some of the security tools, not, not as in depth that, that, uh, Fernando covers, but it touches on that a bit. Observability is a big aspect of it.
It, it's, you know, exciting time to be in the industry. And this is one of the biggest shifts I've seen in spending in the IT realm. And I can't remember, I mean, it, it's kind of like the cloud era, but we're compressing three years into three months.
It's really been a pretty, pretty remarkable change. Alright, well, we wanna thank everyone for listening to this episode of Security Boulevard podcast. Remember, if you like this conversation, we'd love it if you'd subscribe on YouTube or in your favorite podcast application so you don't miss any of our episodes.
We'd also love it if you'd leave a rating and a review and a comment, because all of those things help the show grow and reach new audiences. com in the Future Room Group. com, the Textron TV website, or our new favorite Textron TV app, which is available on Apple tv, Roku, and smart devices all over the world.
Make sure you're following Security Boulevard on our socials, like X, Twitter, and LinkedIn. Just look for security. BLVD.
We thank you very much for tuning in and we'll see you all next week. Hey, everyone, welcome back here to Techstrong TV and our continuing coverage of AWS Reinvent. You know, one of the great things about Techstrong being part of FU is we get to kind of pick the brains of some of the futurum analysts, you know, the industry, well-known analyst, uh, about what's going on in the world of tech.
And especially when we're at an event like this. We're gonna do two segments here, each with two of the Futur analysts. The first segment is gonna feature Brad Shiman and Fernando Montenegro, uh, of you, Cher.
I'm gonna give, I'm gonna let each of them kind of introduce themselves though. Brad, if you wouldn't mind, why don't you kick it off. Introduce yourself.
Thanks, Alan. Hi, everybody. Brad Shiman.
I am an analyst with futurum, as you noted. Uh, I, I look at data intelligence, analytics, and infrastructure. And I, I'm a software guy.
I love software developments and all things databases, so I'm hoping we can, we can chat about that a little bit today. Absolutely. And I'm Fernando Montenegro.
I lead our cybersecurity and resilience practice. And, uh, the gray hair comes from being around cybersecurity for many, many, many years. There was A time I had gray hair in cybersecurity too, when I had hair Fernando's just outta high school.
Yeah, oh Yeah, exactly. Yeah, exactly. And, and, and, yeah, I've been covering cloud security for a long time and, and, and it's been a pleasure to come to AWS reinvent for, for a few years.
Not the, the full 14 that they've had it, but It's a good show. It's a, it's an amazing show. Yep.
Well, you know, an observation, I'm glad you brought it up. Let's just jump in. Of course.
Sure. An observation I had today, and I wrote about it in an article I put up on one of the tech trunk sites. Think about coming to AWS reinvent five years ago.
What would you be talking about S3 Lambda serverless? You'd still be talking about security of bit, but you would be talking about cloud. Yeah.
Cloud, yeah. Nitty gritty, cloud native, managing my Kubernetes EKS. Right.
Securing that stack. How much of that do you spend about here today? So if I transported you from five years ago to today Yeah.
Would you believe it's still the same company? The same industry the same? Absolutely.
I, I feel, I feel like we're still in that era because honestly, all of those concerns are still here. They all inform what AWS is doing. They are all, they are still all in in the cloud.
And you can hear that in Matt Garmin's, uh, keynote today. 'cause he, he did not mention when he said, if you wanna get the most out of ai, you're going to need to bring data to the ai and to do that properly, you need to bring it to the cloud. You know, that's Loud and clear everything.
Yeah, yeah. No, I mean, it's kind of funny in that we haven't, I just feel like there's less of an emphasis on cloud or it's abstracting behind the ai. That's It.
So, so, so here's the thing. Point of order. Five years ago, we were in the middle of the COVID pandemic, So we were Right.
So We would not be doing maybe Four. Yeah. But, but, but point taken.
Uh, I think that, um, to, to, to Brad's point, the cloud is foundational to do this. Yes. And it's funny that you brought up abstraction.
I have a, I have a thing that I talk about that, uh, go back to high school calculus, like high high school math. Mm-hmm. The limit, like the limit for cybersecurity as time goes to infinity, to me, is anti-fraud.
Mm-hmm. And what I mean by this is that we abstract away technology. We abstract away a lot of this, and then we help businesses and buyers and sellers and whatnot talk about higher level, uh, constructs.
Right. And what, and it's kind of what we're doing here. It just so happens that I'll be, am I the first one to bring up the AI words?
I think I am right? So, uh, uh, I dance Won't be the last. I Didn't, but, but, but that's the point.
I think that we are abstracting away some of it, but to Brad's point, it is always there. And actually, one of the security announcements had to do with, uh, uh, ECS, not the agenda points had to do with ECS and C two. Mm-hmm.
Right? Which was the, the, the, the, the, the guard duty, uh, support. Right.
So it, I agree with you that that's not what we're talking about as much, but it's here, it's always, it's always there. It's, it's always there. And, uh, whether it's, whether you're figuring out instances that you need, whether you're figuring out what kind of database do you need, there were announcements around S3.
There were announcements around S3 tables, I think. Right. Uh, and so yes, you are correct that, that the topic has shifted, but the technology is underlying, I always Hear, you know, the thing that powers our, our little market is that Race to Zero, trying to beat Zeno's paradox to, to always go a little bit further closer to getting there.
And we never get there. And that's why it works, because we're always inventing new ways to abstract away problems. Yeah.
And to find new, interesting ways of applying this technology to solving problems. And I, I feel like that was really, um, on display today when we talked about Amazon Nova Forge. Yes.
Which I would love to spend some time talking about. We, We've spoken about it a bunch today. I'd love to hear your thoughts on it.
Yeah. I, I have Some thoughts. It's, it's a renaissance here for, for the, you know, more traditional foundational large language model.
It's like a re a return to form. I'm calling it. Because instead of, like, we, we've spent so much time over the last year in investing in frontier scale models, uh, like Gemini, like Claude, et cetera, and, you know, they do a wonderful job.
And when they first came out, if, if everyone will recall, we used them for POCs, and that was about it, because they were very flexible. They could do a lot of different things. They had a great knowledge base they could work from.
Um, but you, for production, you went with an actual model that you fine tuned that you built. Yes. And we kind of went away from that, and we said, let's just make them do it all.
And, and I think what we learned is that that costs a lot of money. Yeah. And so, you know, if you're gonna do ai, right, like, like Matt said, you want to bring the data to the ai, and that's what they're doing with Nova Forge, is they're really trying to make it so that we actually do what we started doing a few years back in fine tuning these models to bring the data to the ai.
So I, I think it's a, it's a return to forum and I, I applaud them for focusing on that. No, I, I, so it's not anything I've seen before, which is interesting. No.
And, but I'll tell you something. Two, two and a half years ago, we're gonna have Mitch Ashley on, in the next group. Mitch came to a hackathon.
We did down at Techstrong around what we called operationalizing ai. Yeah. Yeah.
And we had people like Patrick dubois, who's founded the DevOps, who came up with the word DevOps, uh, uh, John Willis. Oh, he's great. We had a lot of great people who were very, you know, early on in the DevOps movement, and they were working back then Yeah.
On, on Rag and on vector databases and SLMs and stuff like that. And to me, it be, I'm not an analyst, but I did stay at a Holiday Inn Express last night. To me, it was obvious that not every job in AI required it of truly frontier size LLM No.
As a matter of fact, it might be the wrong tool In a lot of Cases for a lot of jobs. It's the wrong tool. I need.
Yeah. I need a scalpel or a, or a rifle, not a shotgun. And I, I, I, I'll, I'll go one deeper.
And that's one of the things that I was looking forward to coming here and having conversations and, and we are having those, is that I would argue that the, the lms, right, the language models in many cases, fine tuned or not right, may not be what people need. And this is one of the areas that, yeah. Uh, this is one of the areas where, like, I, I, I, I was really excited, I'm really excited about the field of neuros symbolic ai, right?
Mm-hmm. Which is the, you're, you're bringing the, the, the neural component that, that from the LLMs with the symbolic reasoning. Right?
And, and AWS has been doing a lot of work on that. So it was really interesting to come here and see that. But anyway, but the, the, the point being that the way that we are going to, to improve those models is by the fine tuning, and in some cases, by using these more neuros, symbolic components.
And so one of the things that I was excited about, the announcements that, that, that they now have a, uh, a verifiable policy language on the agent core stuff. Yeah. Right.
That's a step in the right direction. I really like that It's responsible AI and ML lops as you're, you're talking about. Yes, yes, yes.
It's part and parcel to that. And so I, I feel like they have to, they have to do that. And if you look at all the components of the agent core, you can see it starting to look like an ML ops platform more and more.
That's for agents, not just for select models here and there, but for orchestrated, Let me, let me ask you a question on this. Have you guys seen the letter that was circulated last week? Like a thousand AWS employees signed on to calling for responsible really moral Yeah.
Ai. Wait, this was Amazon, or was it meta? No, I believe it was AWS Okay.
Interesting. Interesting. Yeah.
Well, you know, it's, it's, uh, it's very much, and we saw it actually the beginning of the keynote this morning. The very first words on the screen were why, and the, the response was, why not? And that's the era I feel like we're in right now, is, well, let's just dam the torpedoes and see what happens.
And I, I don't think we can do that. No, it's, it's, we should not be doing that yet. I agree.
We have been, because it's all about time to value. And we've found with transformer models in particular, that we can shortcut that time to value, but we can't shortcut the hard work. And that's why things like fine tuning are so important because it's another tool in the toolbox that gives you, at the end of the day, a model that actually, as you said, has a scalpel to do what you wanna do, do it performance, do it in a secure, safe manner, and do it in a way that you can actually make some money.
Absolutely. Let me bring up another thing. You know, coming in yesterday at the airport, I was reading all the, the electronic billboards.
Yeah. I'm a sucker for them, but I saw one from Databricks that really caught my eye. I don't know if you saw this one.
Our AI agents don't suck. Remind me of the old, you know, we suck less philosophy. Suck the software alive and well today.
Exactly. Yes. Yeah.
Well, now it's called suck list. Agentic ai, maybe. Oh, Come on.
That's never gonna happen, but, okay. It's like agentic AI is the antithesis of Suckus software. It's like whatever you want it to do, it'll just, It'll do it for you.
Yeah. Just do it for you until it doesn't. Yeah.
Until it doesn't, until you check clears. Anyway. Um, but you know, we, we certainly are in this, Brad, you're right.
You want, we could, we you want an agent? I got an agent in New York. It's like that.
But I got an agent for you. But we're also seeing s kind of a, a Cambrian explosion, if you will. Mm-hmm.
Sure. Right? Like, I, I had a, a fellow we interviewed up here this week, or today rather, who comes from, um, uh, s uh, Egen AI for S se not for SEO.
For SRE. Okay. Yeah.
Sounds great. What a great idea. We need that, that's something we could do.
Of course, he's one of six agent AI for SREs that are here. Uh, may I say seven? Because, Because you know of what too?
No, no. Because one of the Announcements today was AWS themselves, AWS themselves. And now check Your watch, because we might have another one, another One.
But, but, you know, but that's not unusual for, that's their model. Look, we're gonna give you 80% for 20%. Yep.
That's right. That's a lot of the AWS model. But I, I do think we are in a, you know, a Cambrian explosion of life, if you will, of ai that some will, some will make sense three to five years from now.
Yeah. And some will say, what were we thinking about 12 eyes and six legs? It just, you know.
Well, a lot of it's gonna disappear because as we saw early on, when we had a lot of wrappers, as you'd call them Yeah. Around chat GPT, are they in business anymore? No, because you don't need Them.
I'll tell you what else I think might disappear. Hmm. Everybody and their mother has an MPC server.
I have one right now. Yeah. Yeah.
I mean, do we, why can't we have an open source one that we all kinda standardize on? Kind. And this is the open source model.
Right. And then build on top of that, build functionality. Like that's on top of, but that's What MP is, right?
MCP is by itself, like an open, It will evolve into what you're talking about, Alan. Yeah. I I think we don't need 10 different MCP servers.
No, there's an X-K-D-E-C, sorry. XKD. Yes.
I, I know exactly. We need a standard next panel. We have another standard.
Yeah. We have 13 standards. We can't do it.
We need another one. We need the single one. Now there's 14.
That, that is the way it goes. Is it not? Yeah.
Yeah. I, Fernando, I gotta talk security with you a little bit. Of course.
So I had another fellow I interview today, smart guy, zest security. Okay. I don't know if you heard of these guys.
The founder there came out of, uh, oh, they sold to Palo Alto Cider, remember cider? Yes. Yes.
Security. Yes, yes, yes. He claims zero.
They could get you down to zero vulnerabilities using ai, agentic ai. That's bold. I, I I, I, I told him, I, I said, say that again.
For the people in the back who Don't hear me. Yeah. I think that there are, um, there's multiple ways to interpret zero vulnerabilities.
Right? Okay. In the context, like when we have conversations about vulnerability and security, the first question I want to ask is, okay, am I talking to an ops team or am I talking to a dev team?
Very different measures. If I'm talking to a dev team, zero vulnerabilities means one thing. If I'm talking to an ops team, zero vulnerabilities means something else.
So in the context of, I think they may more on the development. No, he, so I agree with you. I mean, you and I both know, yeah.
I have security background. He was talking about the security team in ops, like tra not AppSec vulnerabilities. Like True, True vulnerabilities.
That's true. And, and, and, and, and that, and that is, uh, um, like, again, I, I applaud the, the, the, the, the, the gusto. But I, I struggle with it because this is the trick that, that security teams are learning the hard way.
There are vulnerabilities that you don't fix because it's too expensive. Yep. Right?
Because given the risk, Well, it's a manage, it's a risk management. It's a, it's a risk management conversation. And then, like, like here, for example, here we are having a wonderful conversation.
Uh, some of these doors are open. That open door is a vulnerability, right? Should we say Windows 10 at the moment?
Should we talk about that? Oh, Yeah. We talk Windows.
We might as well talk Windows 98, but that's a whole nother story. But, but, but, but I, but you know what your reaction, he said, that's exactly what we hear from CIOs and CISOs. And then we show them.
I'm going to introduce you to this gentle, I'm happy to chat. Yeah. And I'd love to hear you talk.
I'm happy to. Yeah. Guys, I gotta wrap this little portion up 'cause we've got more analysts waiting.
Sure. Hate to keep analysts waiting. But let me, let me pose question to each of you, and, and, and we'll go with that.
Brad, if I had to ask you for one story, that's the big story at Reinvent this year. And we've, we've skirted on all of them. Yeah.
But for you, what, what's the, what's the, you know, the key takeaway? Well, for me, uh, I would say that it is, you know, the, um, Nova. Um, but I'm not, I I, I want to actually instead pre pre, you know, get ahead of what I know Mitch is gonna talk about, uh, when it comes on.
And, and that is Kero, and that is a agentic development. And the fact that on stage today we heard from Matt that the company has committed itself to using this platform to develop their software in-house. That is very much, you know, a bold statement.
Yeah. Because I, I, I feel like a lot of these companies try to sell us on Yeah. Yet another agentic, IDE blah, blah, blah, blah.
But if they really put their money where their mouth is, well, AWS is trying to do that. So, we'll, I wish them luck, and I, I think it's, it's gonna be interesting to watch. One last thing for you.
What wasn't on your Bingo card coming out here? Uh, well, you know, I wanted to hear more about data, honestly. Uh, and I, we, we didn't have a lot of of announcements about that.
So my Bingo card was all filled with, with like slots about what's happening with their various databases. I didn't get too much Of that. No, I haven't, I actually haven't heard much at all.
No. I would've loved to have heard something about a semantic layer, for example, because every other vendor, we mentioned a couple of them with Databricks, and, uh, right now, if you're gonna do a lot with ai, you're investing in a semantic layer. Yeah.
But we're not really hearing that from AWS So I, I would encourage them to, to really kind of rethink that in their go-to market coming up in the next couple of months. Fair. I wonder, well, I don't want to be Doctor Evil, but I wonder if that means AWS is working on their own semantic data layer.
They have been known to build internally. Yeah. Yep.
Fernando, let me come to you. What's your big story? My big story comes in two pieces.
Uh, you know, how we always talk about security for AI and ai mm-hmm. For security, yeah. Third one being security from ai.
Uh, I think that we saw the announcements today, the security for Agentic and the agentic for security. For security. And the big story for me is that on the security for Agentic, it's how they've woven the conversation of Bedrock has security, bedrock has it built in, bedrock has it, and, and then, and then you take the policy agents from, uh, the, the, the policy language.
Now an Asian core. So I think that I, I encourage my security colleagues to, as you are thinking about Gentech, you are, you have to look into what security is coming from the platform. Yeah.
And the other big story is Gentech for security. So just like the DevOps agent there, there is now an announcement for a preview for a security agent that is going to be doing a lot of the, Hey, let me fix that code for you. Now the devil is in the details, right?
Uh, but what kind of things is it going to fix? And what kind of things is it not going to fix? But importantly, what's the, the, what's the play, the interplay between a true security, uh, uh, professional doing a pen, because it's going to automate pen testings, theoretical, uh, theoretically.
Theoretically. Sorry, forgetting English. Uh, where do you draw the line?
So if you're, if you're a developer and I'm a security, uh, engineer, what have you, and then do I now code my policy at my company to say, look, as a developer, you are, um, uh, you are going to do multiple things for security, and you are going to already run a pen test, and then I'm just going to test the results of the, of that pen test. Right. Or am I going to it?
It's great that you run a pen test, but you know, like trust, verify, Trust. I'm gonna do it. I'm going to do it too.
So I think that that's the next level of conversation. I Think there'll be a human in the loop conversation there. Let play devil's advocate a little bit, though.
Sure. The DevOps agent to me, is an alert monitoring tool. That's what it sounded like from what I heard.
Oh, I don't know. The, the advertisement we saw, The advertisement was one thing, but when you read, when you read, yeah. It sounded like alert logic to me.
But, okay, we'll, we'll go with that. Well, actually, let me ask, lemme tell you, uh, what I feel that is going on there is that they're not gonna deliver it today. 'cause they're gonna build for preview.
It's A preview. Yeah, exactly. And, and what we do see them doing is working on long running agentic processes.
They talked about that a lot today, as a matter of fact. Yep. And what else is, you know, building safe software than a long running process of monitoring your code base, testing your code base.
That seems like what it ought to do. Yes. That is what it ought to do.
You know, there's an old saying, I learned in law school about what you do do and what you ought to do. That's the difference. You do Not gonna get caught doing Your comment on security there.
I gotta tell you the truth. I had a deja vu to 2007, the cloud, I can't put my stuff in the cloud. It's not secure.
Don't worry. We built security into the platform. We keep we Didn't, didn't buy it then.
I don't know if we buy it now. Yeah. We keep moving the layers up.
I Think that, that, it depends who you are, right? If you're a big company, maybe you question that. If you're a small company, you're never going to have provide that Until, until well start that, and then it Gets a little bit better.
And, and, and I go back to my thing about abstractions, right? We've now given developers more capability to do more things. So instead of, you know what, that budget for a pen test that was going to find 50 vulnerabilities, and out of those 50 vulnerabilities, 35 of them could have been found mm-hmm.
Automated in an automated fashion. Now, perhaps that same budget can focus on more critical Vulnerability. Just those 15.
Yeah, Exactly. Because we've asked you to do this. I'm optimistic, Always the optimist.
I, I'm, I'm, I'm, I'm optimistic. We, we are. It's, it doesn't have to be perfect, right?
It doesn't have to Be zero. Nothing is perfect. It's never, we're never gonna get to zero.
We're never gonna get know That. Right? That's Risk management.
Risk Management, and said zero. I almost fell outta my chair. Yeah.
Anyway, Brad, Fernando, thank you so much for coming up here on Text Drug tv. Thanks for having us. Appreciate pleasure.
We'd love to have you, you know, we do these remote. You don't have to come to Vegas to see Us. And, and may I remind you that we are kind of halfway through, so there's, there's still, There's still there.
And we'll be here tomorrow and the next day, there at least six more keynotes. Yes, there Are. Yes.
And, and, and there are, and, and, uh, just, just to, uh, sidetrack a little bit, one of the things that I was really interested in is this whole age and, and, and, uh, and the neuros symbolic stuff. But coming alongside that, there's other things going on. Like, one of the areas that's super interesting is like confidential computing, right?
Yeah. Mm-hmm. Oh, that's, we, we are seeing some A AWS do some interesting things there.
So let's keep talking about this. And, and, Well, now, now you invited yourself. You know where we are.
I have no excuse. We can do this remote. Yeah.
All right. Hey guys, let me just remind y'all, Futurum does a thing called the Futurum signal. It's, it's the report that we put out in, in different practice areas.
Fernando's done one. Brad's done one. The next two folks that we're gonna have on have done one, unlike a lot of other analyst firms, these reports are available to you.
You could go see the whole, I think, virtually the whole report, right? Yes. Yeah, yeah, yeah.
And It's an amazing look at using ai. If you looked at our live coverage earlier, Daniel Newman and I had a great discussion on this. I encourage you to all go look at Futurum signals, check out what's in there.
This isn't last year's information given to you six months after the fact, right? It's, it's the, it, it, I don't want to say it's up to the minute. It's not continuous yet, but it's a lot more current than the 18 month old stuff you may have been used to.
So go check out fu term signals. These are the guys behind it. We're here at AWS Reinvent for Tech Trunk tv.
We'll be right back. We've got two more great analysts I want to introduce you to. Welcome everyone.
Thank you for joining us. Today. We're talking about readiness and AI in the mainframe environment.
My name is Mitch Ashley, and I lead the software lifecycle engineering practice at the Futureum Group. Today I am joined by Anthony Desarro, who is Senior Director architecture of ai. And with the BMC, let me try that again.
Not the BMC. Dang it. My bad.
Alright, starting at 3, 2, 1. Hi, and welcome. Welcome to our conversation about AI readiness in the mainframe environment.
My name is Mitch Ashley, and I lead the software lifecycle engineering practice with the Futurum Group. Today I'm joined by Anthony Desaro. Anthony is Senior director of architecture for AI with BNC software.
Welcome, Anthony. Mitch. Thanks for having me.
You bet. Great to have you. Now, this is a three part series.
Our first part is talking about AI readiness, and the series is, uh, sponsored by BMC software. We appreciate the folks at BMC, uh, putting this on and putting this together. So, Anthony, let, let's jump right in.
So, we hear a lot about organizations needing to be AI ready, especially for the mainframe environment. Mm-hmm. At the earliest stage, what does AI readiness really mean?
Yeah, Mitch, this question, I can't tell you how many times I get this, whether it's I'm speaking at a conference or customer visit, this always comes up, you know, how do we get going? How do we, we get started with that, and it's so foundational into a successful journey with ai, but yet it's a step that you'd be surprised how many organ organizations just kind of ignore or are not even aware there is a readiness, uh, you know, playbook that, that, that they should be, uh, following. So it all boils down to, uh, from an organization perspective, you know, how do we roll in AI technology?
How do we use AI technology safely within our organization? How do we put guardrails around AI for, uh, you know, for protection against data? Uh, for example, you know, uh, from a, from a legal perspective, you know, uh, what policies and governance that we need to have in place.
Uh, we bring AI into our organization, and there's all kinds of challenges around that. But at the end of the day, you know, that's one part of the organization's gotta deal with that. And then it comes down to the individual, you know, groups and, uh, departments within an organization and how they want to utilize ai.
So the first really good step in that journey is looking at AI as an advisor. Mitch, really look at it as like you would bring in a human into your organization, you know, based on their experiences and, and their background to have a dialogue exchange with them about whatever challenges that you may have. And you're gonna lean on that person for their insights and guidance based on their experiences.
Ai, that's a great first step with AI image. Look at AI as an advisor. It's there to explain, it's there to guide, it's there to recommend, et cetera.
It's there to provide knowledge and insights that you may otherwise miss or not know how to surface. So from that perspective, that is a safe AI journey to start moving your organization to. But then the other side of that is the skills of your staff itself.
When you bring AI into an organization, you wanna make sure that your SA staff is skilled in AI usage. You want to make sure your staff is skilled and understand on where they should be applying AI within the organization. So there's some education and training that need to be done for your staff.
There's guidelines, uh, uh, and policies that you need to be putting in place, guardrails that you need to be putting in place. And that's all very, very, um, very focused on individual organizations and what that means. But that's the first step, um, to get that, those foundational aspects of AI in place.
That's a really good point about having that kind of direction you want to take with AI versus it's so accessible. We can use it, try it out, but how are we gonna focus and leverage it for the organization? And you mentioned the concept of AI as an advisor, using that as your first entree into ai.
Talk about how that is different than maybe automation, autonomous ai, gentech, ai, all the terms that we hear about, uh, doing things with ai. Yeah, so what, you know, when you do hear about, uh, autonomous AI and agents that's all around actionability and the AI take, you know, perceiving a situation, making a decision, and taking it in action, jumping into the deep end of the pool, when it comes to AI in that regard, that, that, that's concerning to a lot of, a lot, a lot of folks. So when we talk about the advise the advisor part of that, the advisor takes no action, right?
Again, the advisor is there just to guide you, nurture you, and move you along. But it's up to you, the human to actually take those actions. It's up to the team who's using AI to infuse AI with the right pieces of information to get the right types of guidance that they want from that AI system.
But that AI system is benign, right? That again, the AI system is not going to take any actions on or your, your behalf. It's all back to you.
And what you want to get out of that, that AI system. So if you're a developer, I'm gonna use AI as an advisor to maybe gimme code, recommendations, code, explain, um, maybe to do a best practices analysis on my code, et cetera. That's, that, that's really good.
Maybe from the AI ops space, Mitch, we're gonna use AI as an advisor to oversee my, my dashboard and maybe surface insights to me out of that dashboard that I would otherwise miss. But there's no actionability to it in that regard. It's just providing the insights and information so that that is, that is a part that fits very naturally into the advisor part of it, as opposed to the autonomy part of ai.
Uh, it's good you mentioned that. 'cause it is a much more comfortable way to kind of enter into the AI space to start to use it. But you don't have to jump right into automation and agents and, you know, doing more of the, you know, advanced things.
If you wanna think of it that way. You'll build trust, you'll learn about AI by using it. And we, and we've done that ourselves, right?
You know, look over the last 18 months, whoever your chat provider of choice may be. But that's how we, we all got into the game of ai. When, when, when, when, uh, you know, chat, GPT was released as an example.
We all went out there and, and started having conversation with AI at that point, whether it was professionally or personally, that experience was an advisor type experience. You know, we sent it a bunch of questions and we got responses back, and we had a conversation and a dialogue with it, but nothing happened. There was no actionability to it.
So that was all of our entries into the AI world. And for organizations, for enterprises, that's a great first step also in their, in the start of their AI journey To that point, there are plenty of ways to engage with a AI and query it, use it as a tool. But what do you need to have in place to be an effective advisor role in, in the environment we're talking about?
Yeah. So one of the things that we've learned in our journey with AI so far, and I think as an industry, we've all learned just bringing a large language model into the organization, not enough, right? It's like it's, that's just, that's the bare minimum entry that you could do.
But the problem with just bringing a large language model into your organization is it doesn't have any context. Those large language models were trained on huge corpus of information. They were targeting the masses of users, where once you get into an organization and you bring AI into an or into an organization, you are, you're in a particular domain.
You're in a particular realm. So now how do you, how do you utilize this large language model that's general purpose for a specific domain that you may be in? Well, the way you do that, and what we've learned o over the past, you know, 12 to 18 months, is you have to augment that large language model.
You have to augment it with realtime product data or whatever data, uh, realtime data that your, your organization is playing in. You also have to augment the language model with additional knowledge, whether that's workflow, knowledge, processes knowledge, best practices, knowledge. It's, it's your enterprise knowledge.
Whatever that means to you in your organization, you want to infuse that into your AI system. So then you have the large language model with your enterprise knowledge, with your real time data access, uh, knowledge. It's a combination of all three of those that brings relevance to AI with an organization because it brings relevant context into your organization and the AI perspective.
And when we're using AI advisors, and I agree with you very much about the point of, you know, contextualizing it with information about your organization. Where do you see the fastest value that can be delivered by using, uh, AI advisor in the mainframe teams today? It's definitely in the DevOps space by far that it, it's the DevOps community that has really opened their arms and embraced ai.
And the mainframe environment is no different, whether, you know, from the cloud environment to a distributed environment in that realm, the developers have accepted AI in the mainframe space. There's a, you see a lot of interest, a lot of adoption AI in the, uh, mainframe space. So that is, to me, has progressed us as an industry in the a those working in the AI space, the work that the development com community has done over the past year, 18 months has really accelerated our journey, uh, with ai.
Now, you also starting to see other areas starting to get really interested in that. The AI ops space, as an example, is getting, getting a lot of traction now when it comes to, uh, to ai. And we're heavily looking into that within our portfolio, in our AI ops, uh, part of it.
But it's the knowledge capture that is what's gonna play the biggest game here, why we're in this massive transition within the mainframe community. We have a lot of folks heading out towards retirement on the tail end of their careers. How do we capture that knowledge and how do we infuse that into our AI system so that next generation coming in has that experience?
They can lean on that they otherwise would not have that person they would go to, you know, Bob, Bob is not here anymore. But if we were able to capture Bob's knowledge in some way, shape, or form, and put that and infuse that into the AI system so that next generation can lean on the AI system and get access to the information that Bob had, that is game changer in our mainframe space. It's really, it's not only helps get that next generation up to speed, Mitch, but here, he, I I just had a conversation yesterday with someone about this AI on the mainframe is making the mainframe sexy and attractive to that next generation coming outta colleges and universities.
We're in the conversation, just like the cloud space and the distributed space when it comes to AI and technology advancements in general. That is really cool. It very much is a sense of excitement in the mainframe environment, particularly with ai.
And I, and, and you have a really good point about that knowledge loss, you know, as folks retire, move on, whatever it might be. So the next generation of people work in a mainframe, have got that information contextually available to them. And ai, I can't think of a better application of ai.
Yeah, absolutely. And we hear that from our customers. Our customers are like, you know, we got decades worth of white papers.
We got years and years worth of, uh, video recordings, training material, et cetera. How do we capture that? How do we, how do we get that into an AI system?
And that's something with B-M-C-A-E, uh, assistant that we, we, we took very, very serious, right? So it's like, well, how do we do this? How do we allow our customers to capture this knowledge that they have and get it infused into B-M-C-A-M-E assistant and we're delivering to our customers a tool that makes that really easy to do, uh, where they can, uh, manage documents, they can manage videos and build out their own knowledge base that B-M-C-M-E assistant would be totally aware of.
Now, when we ship our solution, we have the large language model. We have an a e knowledge base that we ship, the customer can build their knowledge base, and then we have access to all of our product data. So we got all this information that's available to B-M-C-A-E Assistant.
That goes back to what we talked about before about what's relevant context to a customer. Yeah. We can't talk about AI without talking about trust, and I've heard you discuss the importance of explainability.
Yeah. Talk more about that. Love to hear your thoughts about why that's so important.
Oh, Yeah, yeah, yeah. So with, with ai, of course, you know, trust always comes up in the conversation from the very beginning. When we all started working with generative ai, that was the, you know, everybody was talking about trust in that regard.
It's multiple ways to answer this. You know, we have some responsibility in the solutions that, um, that we provide our customers. We gotta give the customers insights into what our AI system is doing.
We have to connect our AI system into their workflows and processes around auditing, logging, tracing, et cetera, observability in their organization. So how do we do that? So as an architect, from the very beginning, foundational, we have to be able to capture everything that is happening through our, uh, our AI system through BMC Amy Assistant.
From a user typing a prompt to us formulating a response, not only did it has to be auditable, but as much insight as we can provide on why we came about a response has to be clearly articulated. And some of that is clearly articulated back in the product experience. So when we give a response back, we may cite in that response where we, why we came to this conclusion and what pieces of information led us to the, to this conclusion.
But it also has to be totally, uh, traceable and auditable behind the curtain so that the administrators of the AI system have full optics into everything that is happening in that system. It cannot be treated as a closed door system. So it, it, it's the optic optics into the AI system.
It's the auditability, traceability, logging, everything has to be done. So if you go into the system, Mitch, and you are working with BMC Amy Assistant day in and day out, the system administrator has, you know, full trans full transparency into all the things that you've done with the AI system. And when, and, and customers have asked us for that from the very beginning, we started working with our customers in this journey that was foremost right at the top of the list.
They need to understand what's happening in the system and why. And we've done that. That's foundational for us.
That was something we had to put in at the lowest level of the architecture. That's not an afterthought. If, if, if you go with that approach as an afterthought, you'll miss things.
It has to be done at the ground level of the system. Yeah. That explainability of transparency is fundamental, that that builds that experience that you start to build that trust with very much so.
And is that trust that's gonna lead us to, to, to the next part of the AI journey beyond the advisor where you look at AI as a true partner in your daily journey. You look at AI agents and agent AI as a digital workforce, do and work, and, but we gotta take those steps and build that trust. Speaking of taking those steps for organizations that maybe just starting out, thinking about AI readiness, what do you think of the smartest first steps to take?
We went through this journey ourselves. So, so we have a pretty wide and deep portfolio, which within our BMC Amy, uh, product area. So we had to go through this exercise.
Where do we find true immediate value that we can deliver to our customers? The AI journey was new for us too. We had to be very careful, very systematic on how we approached it.
So the, the way we approached it was, let's just start looking at the low risk, but high value returns that we can give our customers with our AI infusion within our products, within our portfolio. And we've been very, very successful at that. But one of the key things, even though it's, you know, it may be a, a low risk, high reward type, um, AI enhancement, we want to be able to also capture and measure that.
You have to be able to measure and capture that to make sure you're truly getting your return on your AI investment. This model worked very well. I, I I, I, I spoke to other architects about this model.
I spoke to customers about this model, and this is a really good entry point model. Start small. Don't try to drink the ocean, as they say.
Start small. Identify those low risk impacts. You don't want anything that's gonna disrupt your business, uh, you know, day to day.
But then to start taking those steps. And before you know it, when your organization gets more and more comfortable with AI and you start building the trust with AI, and you start to get a good feel of what you can and cannot do with ai, before you know it, you're starting to take on bigger and bigger and bigger challenges with ai. And people, when you look in the mirror, you'll see you yourself progressing pretty far pretty quickly with AI when you start that way.
Those are some great insights and very sage advice, I think. Anthony, thanks for joining us today. Thanks for being part of this.
We really appreciate the BMC software team for sponsoring this kind of event where we can share this information, share some of our experiences, and bring up some of these important questions. So this concludes our first segment that we're doing in its three part series covering AI readiness. In our second segment, we're gonna be talking about infusing intelligence with ai, using AI as a partner, using generative AI in the mainframe environment.
Thanks for joining us. We look forward to seeing you on our next segment. Hello, I'm Scott Roam with Al, and I'm here today with Ahmed Abu of Nokia Enterprise IT to talk about some of the very interesting network migration issues that they've been through over the last, uh, year or so.
I'm not gonna steal any of Ahmed's Thunder, and we'll let him speak to at all. Ahmed, please introduce yourself to the audience. Hi.
Um, my name is Ahmed Abbu. I'm the lead architect for the on-prem, uh, data centers inside Nokia it. And, um, I had the privilege of course, of, uh, doing this exciting transformation where we moved a lot of data centers from legacy to modern, modern techniques, modern data centers, migrating from different types of vendors to, to Nokia equipment migrating from Nokia to Nokia.
So, um, those two or two and a half years have been very exciting for me. I've been working in data centers for a long time, but this is like something I've never seen before, so. Awesome.
I'm excited to share this with you. Yeah, no, happy to dive into this. And let's just set the context for, for people who aren't aware, you know, Nokia is just this tiny little company with just a few hundred users on the network, right?
Yeah, sure, sure. We've got like 88,000 people. Yes.
Yeah, Yeah. And a wide diversity of different departments and functions. Do you support, you have manufacturing operations that you have to support, of course.
Finance, accounting, yes. Hr, all sorts of, you know, software developers, people in sales, people in marketing. Probably one of the most complex enterprise network environments that I've run into in my time in networking.
How about you? It, it, it, I think it's, it's different types. There is a variety of applications, applications that are very sensitive to disruptions Sure.
Applications that are, you know, factories, uh, you know, that that could, you know, a brief disruption could, could throw off, uh, the software of the factory. It has to be restarted, things like that. So it's very critical.
Very interesting. And the different variety. Different variety.
Some are very sensitive to, to delay. Some are very sensitive to outages. It's very interesting.
So you've given a little hint at kind of the first, um, category of things that we want to talk about. You know, some of the pain points and the issues that you, you had to think about and had to say, what does my next gen network architecture need to fix? So what were some of those original pain points?
If you think back, you know, two, two and a half years now, um, to when you actually started down this path, what were some of the motivators that, um, got you thinking about we need to go to new network infrastructure and new tooling? Well, when I started really with Nokia, it, uh, I saw it a diff all sorts of problems. You know, I wasn't, I wasn't in the, in the IT world, I was in the product world, right?
And everything, there was like more rosy, you know, you're dealing with labs, concepts, architectures, blue playbooks, sure. Blueprints. But when you move to it, it really hits, you know, the real world part.
And there I was exposed to all sorts of problems. You know, we have operate our operational model, you know, where we have to do a lot of intensive work, uh, very resource intensive. We really dunno what is deployed.
Uh, if it's, if what we intended to deploy is actually on the network or not. We don't have a feedback loop from the actual, from the actual deployment to the intent. Um, we had operational problems where, where the operations team were dealing with different types of toolings that don't cooperate with each other, that don't tell you really what, what, you know, what is wrong with your network at any time.
You have to do a lot of brain power and correl, you know, manual correlation. Hmm. Um, also our designs, our designs, it was a lot, oh, well, let's go to the lab.
Let's try and simulate as much as possible production. Let's bring in, you know, expensive equipment, expensive, uh, low balances fire, et cetera, into the lab just to, to test something small because we are worried that when if we go in production, it'll have a, a very negative effect. So lots of variety like that.
And also, and also human aspect, uh, of the thing. It's like, I, I think of it as a journey. This is not only a technical part, you know, sure.
People are, you know, see excited about automation, AI, and stuff like that. And they, they wanna be part of it. They, they wanna get exposed to it, but not, not, not just for the sake of AI and automation, but where it makes sense for us.
And so all that made made us think of completely rearchitecting the way we do everything. Sure. From design to, to implementation to operations, everything was completely different.
Did you see any, like, not to be overly reductionistic, but any, like, specific pain points? Was there overload due to alarms or tickets generated? Um, were there communication issues on some of these complex troubleshooting issues?
Does anything specific come to mind there? Uh, of course, uh, I'm, I'm not an operations team. I'm a, I'm a design team, so, sure.
Uh, I wanna comment on the design part because, uh, that affected me the most. Sure. Uh, is, is when, when, for example, when I got exposed and we had a network audit, and we found alsos of problems, you know, the thing is, we really don't know if, if what we're dealing with is, is a design intent.
It's intended to be like this or, or drifted through time to be like this. Sure. So, uh, the common thing, the common thing is I always was told, go back.
Let's see the designer that did it two years ago, let's talk to him. Let's talk to him. Is it really this or not?
Hmm. So it wasn't like very consistent and, and, and drifting. And we don't know if, if reality is good or bad.
So, uh, all sorts of problems there in the design and also in the implementation. Lots of people doing CLI, where, where one node has a completely different configuration than another. Not completely, but drifted away from another and they should be identical.
And we never understood why. So I, I, I really need, uh, I really thought, thought about this when, when starting the architecture that we consistency has to be there. Yeah.
Automate, you know, something at a higher level should be the, the engineer shouldn't be going to that low of a level to deal with things. See, they should, they should be dealing with a high level and let some tooling, some automation, some templating, do the, the real hard work. You know, the con you know, consistency check work.
Sure. Sure. So, uh, IRA, nicely pointed out that I was here last year.
Uh, anybody have any questions on what the Cruise con experience can be or is? Please feel free to stop by. Um, his introduction made it seem like what I said was nice, but he actually told me to ask questions and not talk.
So we'll see how this actually plays out, because we have the stars of the show to the left of me. Uh, he actually did introductions already, but I do want to give them at least one minute to just describe, uh, their role and what they do, and then we'll hop right in. Sure.
Hey, everybody, my name is Sean Harris, and I'm currently the deputy CISO at Chipotle Mexican Grill. I was also Deputy CISO at Starbucks Coffee Company in Seattle, Washington. Uh, been in cybersecurity now for 29 years.
I know that one last year. I just got one more year. And, and then whenever I'm talking to you, I can just say is three decades.
Uh, but, uh, been worked in, uh, quite a few different, uh, industry verticals, uh, with the federal government, um, with nasa. Worked in financial, in the financial industry with Progressive Insurance, Lionsgate Studios. And, uh, now I found myself over in retail.
So working both at Starbucks and now at, uh, Chipotle, Mexican Grow. How everyone, my name is Kathy Lee la Um, I've been in Cyber Secure. I work for a company called Skywork Solutions.
Uh, I tell everyone we're the largest semiconductor company nobody's ever heard of. Uh, but who here has an Apple product? Yeah, well, we power all of those.
Um, so we are in, we're very big in the RF market, but we're an aerospace defense. Um, IOT, anything and everything you think of that requires a semiconductor chip. Um, I've been in this industry for over 25 years.
I may not look like it, but I am. And, uh, I've, I've been primarily in financial services. Um, that's it.
Hi, I am Angelique, Napoleon. I go by q. I've been doing this about 28 years.
I've worked in oil and gas and defense. I'm currently the Deputy CSO for GDIT Intelligence and Homeland Security Division. And I think I've got a pretty interesting background working in different industries, and it's an honor To be sitting here with you guys.
Good afternoon, everyone. Uh, my name's Lauren Timble. I wanted to first thank IRA and the sponsors, uh, and everyone else for coming out.
Um, Lawrence Amble. I've been with Miami-Dade County for 20 years now. Uh, my, I manage the teams that handle, uh, incident response, security, architecture, and governance and compliance.
Uh, anything that goes over the air in Miami-Dade County to under the ground. Uh, my team is involved in making sure that it's secure. Um, before that I was with Florida Power and Light, uh, where I got my teeth, uh, cut on, uh, critical infrastructure.
It's something that I love talking about and, uh, love working on. And I did a stint as a global SecOps, uh, director for, uh, another company. All right.
Let's get started. Uh, let's get to the good stuff. Who makes more money?
All right. Um, no, seriously though. Uh, what's the biggest difference between, uh, what you are, what you do, and what your CISO does?
I'm sorry, I Didn't hear that. What's the biggest difference between what you do and what your CISO does? Um, you want, I, I guess I can start.
Um, I say I do most of the work. Um, uh, you know, so underneath my purview, I have all of GRC, uh, third party risk, data privacy, uh, incident response, uh, B-C-P-D-R, as well as now AI governance. Uh, so if you look at that whole spectrum, everything's, and even security architecture at this point.
So everything except for security operations is all under my purview. And so my head is usually, my hair is usually on fire most days. And, um, he, I think at the Cecil level, in my opinion, he's much more strategic.
It's all about executive alignment and messaging. Um, whereas I think our lieutenants are the ones that play a strategic role, but were also responsible for the execution piece of it. For my role, uh, it was a direct succession hire role.
So, uh, there's, uh, we worked very closely together. So my CISO is, uh, many of you may know him, Dave ick. And, uh, we, we worked very closely together.
We worked together when, whenever I was at Starbucks as the chief strategist there, as well as the, the deputy for Andy Kirkland. Uh, but at, uh, at Chipotle, we, uh, we have a really great relationship. And, uh, we can, we, if one of us is out, the other one is stepping in from, uh, from operations or what, uh, we actually have eight different, um, functions.
And those eight different functions we have, uh, we've split some of the day-to-day operational management of those up a little bit, uh, just because, uh, to, to basically, uh, handle some of the, the day-to-day operations. I think for me, may, uh, CSO is more aligned for the strategic side. He's focused on corporate goals.
For me, I, I run our security operations center, and I also run all of the security operations along with some other special programs. I wouldn't say it's like an error apparent, but he handles the financial side and I make sure that I am, he's the rigor, I'm the trigger, if you will, Are ciso, uh, typically handles the strategic or the political aspects of it, making sure that there's a good communication to the board of county directors. And, uh, working across the other di uh, departments, uh, for my team and for my peers, we make sure that, uh, we're either implementing the new technologies, making sure that any SLAs are being met, and also helping to keep the budgets in line.
So all of you guys said your CISO does the strategic things, but you guys are successors to your ciso. How are you preparing to be able to do those strategic things when the time comes? So, uh, for us, uh, Dave and I work to work very closely together on, um, our three year and our yearly strategy.
So we develop that in tandem together. Uh, so it's not a, it's not a matter of, uh, a lot of times when you hear about a, a, a deputy role, what you hear about is, well, you're going to do, uh, kind of all of the operation stuff. You're gonna manage the soc, you're gonna manage all the operations, the cybersecurity engineering.
Um, that's not really, in my opinion, that's not really preparing you for that, uh, that succession role. Let's, uh, let's be very, very open about what, what a, what a succession role is. You need to be in, in the mode of preparing to, to do everything that the CISO is doing.
So a, uh, a deputy, a deputy should be, uh, if not already doing some reporting to the board, getting there, helping to build the deck, and, uh, and practicing with the CISO on how you're going to deliver that. So those, these are all the, the strategic views. So deputies definitely have, uh, quite a bit of responsibility from a strategic perspective, in my opinion.
I totally agree with that. So in my role today, I do a lot of the things that aisa would do. Um, I help build our board slides.
I determine our annual plan along with our three year plan, and I send it to him to roll up. Uh, I also do things like review our SEC disclosures, align on SEC incident response requirements. So I do do it in conjunction with our cso.
Um, so in essence, I'm doing, I'm being strategic right along with them, and we just get alignment on what's presented. Mm-hmm. We do the same thing.
We have to back each other up. So if he's on vacation, and I'm on vacation this week too, it's kind of interesting 'cause nobody's manning the store, so all the kids are running around. I bet that's going well.
Um, but we, we try and back each other up to the point that if something happens, he decides he wants to go sell tacos on the beach, he can, where I think I get maybe sometimes frustrated is I want to learn more. And he's got this corporate knowledge. He's been with the company 13 years.
So I always tell people, if you wanna bring someone up in the ranks with you, take 'em with you to those board meetings, take 'em with you to those executive meetings so that we're not awestruck when you meet somebody. And we know what their expectation is of the role. So that's one of the things that we're working through.
And it's about the personality. You have to be able to compliment each other because if you don't have that chemistry together, and I think that's one thing we don't teach in college, and you can't teach in a certification, is that chemistry. Do you two gel?
You know, can you pick up? And it almost becomes a comedy hour with us, because I try and make things as light as possible. 'cause cyber really is depressing.
So we try and make it fun. Sorry, I just have one other thing. I think a lot of this is, is having your ciso, um, give you the opportunity to present across the executive, right?
Right. Mm-hmm. And so, even in my role today, I'm presenting to all of our C level execs.
And so, and I think what I'm finding as you grow higher is not so much about iq, it's really about EQ and how you're reading the room and responding to those in the room to see if they're jelling with the message as you present to them or not. The EQ and the soft skills part is right on target. A lot of, uh, what I would see, uh, I had a very good, uh, CISO to work with.
He just recently retired. Um, he, he would always bring me in, uh, when our CIO challenged us to come up with a plan, he said, make a five year plan and then make the subsequent five year plan. And it, it's daunting knowing how fast this industry changes and how the threats evolve and, uh, everything's changing so quickly.
Uh, when I heard make a 10 year plan, I, I was awestruck. But, uh, working together, uh, and getting me, getting me in front of the CIO, getting me in front of the, uh, board of county commissioners, uh, was a huge help. It helped me know what the audience was gonna be and develop those soft skills that would be needed.
Um, deputy CSO in the past, uh, deputy CSO maybe about five or six years ago, uh, pivoted into the CSO role about five years ago, I guess. Um, and everything that they're saying really, really resonates with me. And there's something that, that I have to ask, though.
You guys all acknowledge the soft skills are necessary, but you guys all named very technical roles that you guys are in. And so you're asked to be a unicorn, it almost seems like. And so I guess my question is, how are you guys staying technical but also developing your soft skills at the same time?
So, uh, is it cutting in and out on me? No, I'm good. Alright, good.
It's just me. I can also speak really loudly. So, uh, I, I've always been a very technical person.
So I came up, um, through some engineering, but primarily, uh, I really, really, uh, hit my stride in security architecture. So, uh, I learn through architecting new systems, and that's, that's how I, how I got into cloud, working with the Cloud Security Alliance, um, developing, okay, developing, um, the, the CCM with the Cloud Security Alliance, I architected that. I architect my, the, the program that I'm in right now.
Um, and by architecting it, I stay very current in technology, currently architecting how, uh, how a company like mine could deploy a secure, a secure MCP, uh, conclave, uh, for ai. So I stay technical by doing that. Now, at the same time, I, I, I really work all work, uh, a lot on, um, there's the EQ side, also, being able to understand the cultural differences between the, the people on your teams.
Super important, right? Because, uh, one thing that I've always felt is that, uh, I grew up in, uh, on a sharecroppers farm in South Alabama where I grew up. I looked at risk a whole lot differently than say my GRC manager that grew up in south side of Chicago.
I look at risk very differently. And let's be clear, everything is about risk. And so understanding that and understanding other people's, um, where they're from and what they're, and where they are, is one of the most important things that we can do as leaders to grow our people.
So I feel like I'm in a never ending battle to keep up, especially with ai. So I do spend hours reading every day. Um, a lot of it is just getting my hands early, uh, dirty on some of the latest technologies.
We do constant POVs. We look at the newest industry players, what other companies are doing at these conferences. I talk to people say, I mean, I just had a conversation, how are you, you know, deploying sayir?
What are the, what are the drawbacks of this tool? What are the great things about that tool? I talk to people in the industry all the time through these type of events to find out, you know, their experiences with the tools, what they're doing, right?
What, you know, get feedback on what, you know, what, what could be improved. And so I take these all back and I try to take a little bit from every conference that I go to see what I can incorporate into my own program at work. Um, so it's a little bit of both just going to these industry events, learning about what's out there, and then reading every night.
I think for me, it's the vendor relationships. So I was blessed last year to lead three of our digital accelerators at GDIT. We're investing in post quantum cryptography.
And I led our zero trust and our defensive cyber operations. So it was building those relationships with the vendors enough that they gave me the tools so that I could bring back and not just learn myself, but you become, teach the teacher. We learned that in, um, the military.
We have to instruct others. We don't always have the budget to bring in an instructor. So it was learning it enough that I could teach others.
And it's a lot of reading. It's a lot of homework, but I keep my vendor relationships tight because you have the best white papers, you have the best information, and you're my source of information. I don't have time to read 50,000 articles, and I wish I could answer every single vendor call, but I look at strategic relationships with my vendor as how I'm keeping current and talks like this, meeting you guys, and learning what you're doing.
And, you know, as we socialize, what works for you and what doesn't work, because I don't wanna waste my time going down a path that I'm gonna only end up drinking and losing more hair. I don't need to do that. We've lost a lot of it already.
Yeah, it's fun. What happened? It was the stress.
A dude, I'll be there next year. Oh, what, uh, briefly, uh, for me, it's always been a, a passion to be in tech in whatever's new. Trying to stay, you know, three, a few years ahead of the curve, and being the one that brings that to my team, uh, I want them to, uh, see me as an example, uh, staying on top of it, staying on top of AI or whatever other, uh, new thing is right around the corner.
I want them to chase knowledge with that, uh, constant learning, uh, passion that I, I try to instill in them. So, outta curiosity, which one of you think you're ready to be a CSO right now? Which one of you thought that before you took the deputy CSO role?
So why'd you take it if you thought you were ready for more? So when I took this role, I had, uh, I had two CSO offers on the table. I went and had a conversation, um, with who is my current boss?
My CISO as a trusted advisor. By the way, if you guys don't have a trusted advisor in the industry, not in your company, get one, get one now. And, uh, so as I talked to him, uh, he gave me some great advice about the roles.
Um, so, you know, the two, there were two of them. And, uh, he, he basically said at the very end, he's like, so I've given you some good, some good things to think about. I'm like, absolutely.
Took notes. He says, okay, before you make a decision, I wanna have one more conversation with you. And that's when he, uh, started the conversation.
33 hours of phone calls later, I actually applied for the role under him. And here's why. When you, when you look at some of the people that you, that you have, like even here, um, you've got, uh, someone like jerick, someone like Tim, you've got some, some really great CISOs every now and then, you, you have that, that inflection point of, can I go to a, a smaller organization and be CSO right now?
Absolutely. It's not a, it's not a question, right? If you don't think that you can, you wouldn't be, you wouldn't even be like necessarily thinking about becoming a deputy.
But is there something you can still learn from some of the greats in this industry? And I felt at that moment that, you know, what, there is, there's still, there's still some things that I can learn so that I'm not going and working at, say, like a Fortune 1000 company, but I'm going and, and becoming something at a Fortune 200 company, right? Um, I looked at the people that, uh, that my boss had worked with.
One of them is the current CISO at Nordstrom's. One of them is the current ciso, uh, global CISO for Disney, the, the Walt Disney Company. That's, that's lightning to catch.
And so I knew that, and I'd worked with him, but I'd worked levels below him. And we had a really great, um, technical, technical, uh, relationship. And I knew that I, there was still some, there was still some things that I knew that I could learn, and I have, and that was, it's been a, it's been a great experience for me.
I think at the end of the day, you have to determine what matters to you most, right? Some people, it's money, some people it's recognition for your job. Some people it's more work-life balance time with your family.
Some people, it's culture, company culture. And so you have to weigh all of those things, right? So, although I potentially could become a CISO at a smaller company or another company, you know, I always value all those things.
I have a great boss today. He's the primary reason why I'm still with my company today. Uh, I get so much empowerment, and I, my confidence has grown so much.
A lot of my growth has been to him. We have, so have a great team. How many people here work with companies where your infrastructure and InfoSec don't get along well, at our company?
None of that, right? We all work gel really good together. We have executives of support.
We worked over the last six years to build a culture where basically when I ask for something, I get zero pushback. So for me, that's golden, right? Where you have a, a finally, we finally got the company to a place where security has so much influence that when we ask for something and we make sure we work with our stakeholders to make sure it's reasonable, that we get very little, actually, almost no pushback when we ask them to do something.
And so I know that if I go somewhere else, that's not gonna be the place I know I'm well compensated. So those all think I get the flexibility to go home to my kids when I want, you know? So I have a lot of flexibility.
So all of those weigh into my decision to stay where I am. And the fact is, you know, there's, you know, what weighs in the back of my mind too, is, is the liability with the CISA physician. We all heard about what happened with Joe Sullivan, right?
Am I willing to take that additional step and face that personal liability and be the scapegoat for another company where if you don't have that top level support, you're gonna be the scapegoat, and now you're personally held liable? I don't know if I'm ready for that either. And so that's another reason why I decided to stay where I am today.
For me, I think it was creative control. My boss said, you can build what we need within our infrastructure. You know, you need a security operation center.
You can build it in your likeness. And for me, that was an ego thing. I was like, it will be great.
So I, I took a chance. I was a CSO before, and I've been a CTO and a CIO. For me, it was a chance to take that step back.
I've gone through some health issues because I think that's not a secret for us. As CISOs, deputy CISOs, I've beat heart attacks and strokes and diabetes, and I tell myself how lucky I am, but we give so much and we leave it on the field. And for me, I just wanted a chance to maybe step back and help someone else shine, help build his reputation and help build him.
Because sometimes, I hate to say this, sometimes as a woman, we think we can change men. I can help build him into something better. So for me, it was building not just the security operations center, but help build him into a good ciso because he's listening.
And it takes some time and it takes some patience. But I've gotten a lot of creative control. I like to say I'm the Yoko Ono of my own soc, but I've helped train.
He's let me hire who I want and build the team that I know we need, because we have an important mission in the intelligence community and homeland security. And it takes a different type of person. I can't just bring these people off the street.
I just can't hire them out of college. I have to train what I need, and they have to have a certain persona. So for us, it's all about personality.
Yeah. For me, uh, finding the, the work life balance, being close to home, being close to the family, that was a significant, uh, thumb on that scale, on that balance scale, uh, being able to hire and build the right people, uh, helping them, making sure that they understand that this is a mission. Um, there's people who depend on what they are doing.
Uh, going back to that CSO personal liability, that's, that's a big thing to take onto your shoulders. So, uh, I don't envy anyone who is doing that. That's probably the, uh, the biggest, uh, weight against, uh, taking that CISO role.
Describe your worst day on the job as a deputy CSO swot. Be at my current company. It was the, the one previous where I was also the deputy for, uh, for about a year and a half.
Um, we, uh, we had a really great bug bounty program. Uh, we discovered through the bug bounty program that someone was able to enumerate quite a few things. Um, and, uh, I ran the cybersecurity incident response plan and the team at that company.
And, uh, by the time, uh, it was all said and done, and we had, uh, we had confidence that we were at containment, and that we did not have broad exposure of the, of the specific API that was able to be enumerated. Uh, we were, uh, it was basically, I think I was, I had slept, uh, about six hours out of 33 and, uh, had had a great team that was backing me up. But, uh, you know, those are the, those are the moments.
And it's really important to understand, as a deputy, my job is to protect my ciso, number one, right? And so they do have that personal responsibility and personal liability. And, um, you know, uh, c and d insurance goes just so far, and not everyone has, you know, right.
Of, of legal defense. So you're there to protect that ciso because you are friends. You're, you're, that's your job.
And so as you, as you're running an incident, you have to understand that every single thing you do has to stand up in a court of law. And I don't know how many people here who have testified in court cases for cybersecurity, but, uh, you know, that was my first incident I ever did in my life. I had to go to Germany and testify against the guy.
So, and that was with the federal government, it's tough stuff. Like you learn a lot by, by that fire. But the main thing, uh, when that I just wanna stress, is that as a deputy, your job is to protect your ciso, um, and his responsibility and liability.
Um, I can't think of an incident really. Luckily we've never been through a major incident. I mean, the biggest incident I can think of is the CrowdStrike outage.
And I, but I think for many of us here, I think we all went through the same thing. So, I'm sorry, I don't really have a big story to tell it, you know, I, I, for the CrowdStrike, I think everyone was feeling the same hates. Yeah.
We were suffering with the CrowdStrike thing too. I think it teaches you patience and you have to use that EQ in the room, and you have to tone people down. So, yeah.
Mm-hmm. Not really a big incident. It doesn't have to be an incident.
There's a lot of things that can make a day hard. Yeah. Those, uh, subpoenas for investigations that your incident response team has, uh, has participated in, whether it's employee malfeasance or something that came in from outside, uh, I always hate getting those, uh, those subpoenas.
So, So let's talk about the future of the Deputy CSO role. How do you guys see that role evolving? Do you think AI is gonna have any impact on it?
Do you think regulation's gonna impact it? I'm curious what your guys' thoughts are on it. Uh, absolutely.
It's, it's going to affect all of us, uh, whether it, it's, um, helping you get through compliance requirements faster or analyzing third party risk. Uh, the other aspect where I see it helping or, uh, is helping your teams be, uh, respond faster. Obviously, we all know it's helping our adversaries, uh, come at us faster too.
They're crafting perfectly worded emails. They're crafting, uh, very basic attacks into something that's scripted and adaptive. Uh, there was a, I think it was a, an, I think there was an MCP that came out a few weeks ago, and it was really fully automated.
My, my team was, uh, playing with it in a sandbox, and it, it, it takes all the hard work out of it. I think I see the deputy CSO role, we're gonna have more responsibility as more organizations have to do more with less, less money, less people, um, less availability. I think we're gonna have to put more of our own personal time.
It's not just working remote anymore. A lot of us have had to go back into the office. So you've gotta con your staff.
They've gotta put pants on and they've gotta come back into the office. So the challenges are people, it's finding, for me, finding those right people, the way I said, it's about personality, and it's getting people who wanna come to work, but not just come to work. Work.
Because you can sit there and you can collect a check, but it's different when you actually have to contribute. So those are some of the challenges, is finding people who actually wanna do the work and learn from you. I always tell people, I'm gonna show you whatever you wanna learn, but you have to come with that attitude.
So making sure that people wanna be there. For me, that's been my biggest challenge. So I think I would layer on top of that.
I think, and at least maybe it's just my role, but I feel like I always have to do more with less. And so now with the advent of ai, I think because there's so many AI, potential AI security issues that your attack surface just grew exponentially, right? From prompt injection to model hallucinations to API, threats to NHI to, you know, it's just, it's constant new threats that were always expected to keep up with.
And then they look to us for everything. And honestly, AI is the big reason why I'm so underwater most days. 'cause everybody in our company wants to do a POV with the latest new AI vendors, and they're like, has to go through security review for us.
And now I'm looking at a hundred AI vendors all at once. And so it's just, it's endless. And it's just putting your hat on for like, you know, whether it's, and it's not, it's, it's cybersecurity, but it's just like, you know, with all these different things that they can do with LLMs, how do you control the agents?
How do you monitor that access is right, right? How do you keep an inventory in agents? It's never ending.
And so I feel like Deputy Cecils, and especially now, they're like, well, how are you using AI to, to secure our company more, right? Make it more efficient. So I think the responsibilities and the expectations will just continue to grow.
Well, I think that, uh, first of all to, to just speak about like the, the evolution of the role. I'm starting to see more, think of it as whether it's CISO assistants or CISO successors, not necessarily named deputies. Uh, you know, from, from my view, uh, you should probably have a, you should probably have a deputy when you have an exit plan.
Um, and, uh, when you, when you're ready, you already, you're now you've got someone who is a name successor and all of your colleagues already know who that is before you leave. Um, but as, as it relates to ai, um, something that, that strikes me is that it, it's an arms race, number one, between us and our threat actors, right? Um, you know, the, the adversarial intent here definitely tracks in, uh, it's an arms race, right?
I'm, I we're seeing you see attacks all the time that are much, much better. Well, well termed, um, James will see what, what happens with, with phish testing, because, you know, we always, we always did our best to, to spot 'em because of the lack of grammar, Grammarly, it's done, we're done. Um, but what I see in AI is not a, it's not a technology shift.
It's a terrain shift. Much more so than cloud was. Cloud was a technology shift for us.
This is, the entire terrain is changing. So think of, uh, having a business, uh, before technology really started coming into business in the late seventies, early eighties, right? You had all of these paper processes and people were like, ah, of, we've got that one computer in the back room and there's that one guy that knows how to use it, and then all of a sudden everyone's got a computer.
What I see in AI is that monumental of a shift. It's going, it's changing everything. Every single one of our, uh, capabilities, every one of our functions is being changed by it.
Now, some of those functions are going to be, become a lot easier to do because we're going to be able to rely on, on agents, provided we can get to the point where we feel comfortable enough to give those agents agency to be able to make changes in our environment on the fly. If we're not ready to do that, then like, it's, you know, it's gonna kind of be the, the, the, the people who said that that cloud thing's gonna not gonna be our round very long, and they're gonna come back to our, our on-prem data center. But it's a terrain shift completely.
And so everything that we know about it is changing. Everything we know about this role, about our industry is changing right now. And I'd say in the next 18 months is going to be one of the wildest rides that I've seen in my 30 year career.
Yeah. Thank you for that. I, I was one of those people that held onto my blackberry as tight as possible.
'cause I didn't believe iPhone would actually take over. And I think there are people like that with ai, and we're seeing that really happen. So one of the things I tell my deputy is, you can't replace me until I have somebody to replace you.
So what are, because you guys have articulated that you're, you don't say it out loud, but you're the most important person in your security team. You're not, you're not saying it, but I can pick that up, right? And so the most important person needs someone to replace them.
If you're gonna take a step up, what are you guys doing to develop your successor? Because that could be something. And I've seen multiple CISOs leave and an outside person came in because the deputy did not have a, a deputy.
So I'm curious what you guys are doing about that. Oh, oh, Go Ahead. Uh, I, I have a small team, but, uh, they're very good.
They're very dedicated. So I'm kind of focusing on, on one individual to try to build them up. Uh, they have that natural curiosity.
I think that they will be somebody who will always pursue technology and the latest thing. So making sure to give them, um, my thoughts, give them kind of my experience distilling it in so that they can absorb it. And even though they're kind of a juniorish position, uh, just to help them try to rock it, rock it up, um, just transferring that, that wisdom, I guess.
I started doing group training. So my internal group, I am training each one of them. There's some that wanna learn policy, there's some that wanna learn leadership, and I'm trying to scratch their itch so that I can convince them on them to stay and grow into the position.
Because as the mission evolves for us in homeland security and in the intelligence community, I need people who are forward thinkers. So I'm teaching them to think again and how to think to meet our mission, to propel our mission forward. So I've trained four potential successors.
So we're a very lean team. I was actually looking for a person with the same intention to succeed me. So we were looking for someone, and the goal is, once we hired this person, it's really to groom them, teach 'em everything I do today.
Um, have them present, teach, you know, so I think that person will be groomed to be there. And so we, with we, so as we interview people, we interviewed them with that thought in mind. Um, and our CISO says, Kathy, can you envision this person as their successor?
If not, they're not good. They're not good enough. And so that's always been the thought process.
I recently hired a CISO who's underneath me now, um, who was looking for an opportunity in a larger program, a more structured program than the one that he had developed for his retail organization. And, uh, he had never worked in, uh, he had never worked for another cso. He had moved up and had built his own program.
And as, uh, and as I was talking to him at several CSO events, um, I noticed that he was really, really interested in how we were doing things and what we were doing, the way that, the way that we, we run the program and the portfolio, uh, being a little bit more of almost a microservices architecture in the program. And he was super interested in that. And so I started having the conversation.
So he is, he's, uh, currently leading my cybersecurity, engineering and operations teams. Yeah, that's a good point. There is no linear path to, to deputy ciso.
I personally went from being a CISO to a, from a deputy ciso to a ciso to a divisional ciso. To a ciso, right? And so it just, it depends size of organization, complexity, salary, right?
All those things kind of are are factors. One last question for you guys, and we're gonna leave it to the audience to ask, ask any questions. What's one thing that you know today that you wish you would've known when you took the role?
Enjoy the ride. Have fun. Don't forget to enjoy.
You get opportunities like this to meet different people, and it's great to meet each and every one of you. Have fun, meet, meet people, help grow them. And I never stopped learning.
So before, uh, while I was deputy at Starbucks, I, I never, uh, presented to the board learning, learning about how that act being in that room, different world, um, different world of a public company. Okay? So, uh, I mean, just, it is, right.
And the thing is, there's, there's very few CISOs that have the, uh, the courage to bring you in to present part of that deck. You have to, you have to gain a lot of trust in order to be able to do that. Um, and so, uh, presenting, you know, having, I presented to executive leadership teams all over, you know, all over the place.
I presented to, you know, back in my NASA days, to Sean O'Keefe, the, the NASA administrator. But when you walk into and you're presenting to that board, it's a little, that's a little bit of a different game. And, uh, and, and that's something that I, that I, you know, I, I knew I could, but the first time having that, having that, uh, tutelage, having that mentorship was, was great.
Um, you know, and, and just being able to, to understand it, right? When you're at a CSO level, you are, when, and, and like, to be honest, we're, we're both kind of like in that, in that same mode, right? Looking at the business outcome is the most important thing that you can learn.
It's not, it's not always about securing, it's not always finding a way to say yes. Um, you know, you've heard all of the tropes on LinkedIn. You, you can go in and hear tons of people who are trying to, to tell you who've never done the CISO role, tell you everything that you need to know how to about how to be a CISO on LinkedIn.
But, you know, learning how, learning how to find a way to say yes and getting into those rooms and being able to present to the board is, is some of the, the biggest learnings that I've had. I'm one of those people on LinkedIn, by the way. Follow me.
No. Alright, let's take it to the audience, unless you guys want to answer that question. Let's take it to the audience.
Do you guys have any questions that you have for the panelists? What was the one resource, habit or ritual that was critical to your success? Or just your sanity?
No, uh, at least for me, uh, getting out and we never really disconnect, but being able to spend time with family, being close to them, being close to my in-laws, being close to my parents, uh, that, that was what really helped me, uh, stay grounded and not, not lose all my hair. I guess It's all, for me, it's all about prioritization. Every day I get 50 new things I have to look at, but you have to know from a business priority, which has the impact, biggest impact, right?
So it's all about prioritization. What needs to come first. Everything can wait.
So when I go through my emails state, I read them, I check, I flag every single one I have to respond to, and then I go through the week and I start responding to them. But without that prioritization, I wouldn't be able to function Community. It's the biggest thing that, uh, that was the biggest change in my career.
Uh, like it was in, you know, I was a, I was a cybersecurity architect and engineer up until probably around 20 16, 20 17, met a great group of people who, uh, who I kept in touch with. We still, we still go to each other's birthday parties, divorce parties, weddings, engagement parties. We still do that.
And we all show up at conferences together. And we, uh, we, we get to know each other's, uh, significant others. We, we are family.
But whenever there's a big decision to be made, you know, we, you know, just the rage song, we rally around the family. And that's huge because when, um, when someone, you know, one of, one of the people in that group, uh, works for a, for a pretty big security, uh, organization and had to, had to really get through a lot with the sales drift problems. And like being able to have someone to talk to that you trust and is part of your, part of your family is huge.
So for me, it's community. I'll say for me it was, uh, learning the art of storytelling. Um, people don't trust what they don't understand, and they don't open up their pocketbooks if you can't open them.
Understand why they're opening up the pocketbook. And so being able to use metaphors and analogies, that was a game changer for me. And, uh, it's made life a lot easier as a result.
And you get trust at that point. I know there were a lot of questions, so let's try to get, so this one might be directed primarily at Sean, although interested in other folks, but you'd made a comment that your current CISO was your non-company, that you were working for advisor, that you were having conversations, curious and you mentioned, you know, network, et cetera. How has your relationship changed or shifted now that you're working for them?
And how has that, how have you seen that and how have you built, you know, either the relationship with that or how did you replace that as you, as you moved into a construction? So, uh, absolutely. Uh, so the relationship does change a little bit, right?
It has to, um, it moves to a, a professional mentoring, um, relationship. It's a, it's a leader and, uh, and being able to align with your leader is super important. And yes, I, I replaced, uh, replaced that, um, that trusted advisor relationship, uh, with, with, uh, with another CISO who also is about to retire.
Uh, but, uh, I, I replaced, I replaced him with another really great CISO that I can have really open, honest, commu uh, honest conversations with. Um, and that's, I mean, that's a, it's a hugely beneficial relationship that I, I suggest every single one of the people that work for me do that with some, some of my peers in the industry. Don't ever tell me what you say, I don't care.
I'm good. You're there to, to get mentoring from someone outside of your command structure. One of the biggest reasons is you can't complain to your command structure about your command structure.
So you gotta have somewhere else to go with it. Hi, I just wanna first say that I'm pretty sure that your bosses have told you you can't take vacation, so you're here on your own. So thank you for doing that.
Same, um, my biggest question, as the host of the Las Vegas Cyber Breakfast Club, which has 16 chapters that are all free, you're open to join any of them, by the way. Thank you, Eric, for the nonprofit plug, I really wanna know, and most of my listeners wanna know, what are the last two steps that you took to get where you are? Did somebody help you?
Did you claw and fight? Did you punch somebody in the throat? Like, what happened?
So my, my boss has been a huge advocate for it being, right? So we always talk about in this industry about having mentors and sponsors, right? Your mentor is someone who you can go to as a friend outside of your company, get to go for advice, a shoulder to cry on whatever.
It's, whereas your sponsor is, you're someone who's gonna speak on your behalf behind closed doors advocating for you constantly, right? Saying, Kathy deserves this. Why aren't you putting her in this project?
That's a huge portion of where I am today. The other portion is constantly raising your hand to take on more. And so I think as you rise the ranks, there's always an expectation of increase in scope.
And so, you know, I always approached my boss and say, Hey, I had this idea that I'd like to take on this. And he'd be like, okay, I'm gonna go ahead. And he'd pitch it to the ea and before he knew it, I was responsible for all of it.
So I think a lot of it was just raising your hand when you see a gap, um, and then making sure that whatever you raise your hand for, you continue to execute and meet your commitments. From a business standpoint, how do you guys handle personal care? Reason why, because of stress and whatnot, there's a lots coming in and going, you guys been a, right Now you mentioned earlier, you rather stay where you are than dealing with all the headed.
But from business standpoint, how do you handle the personal care to maintain your blood pressure or sanity? Keep coming from all the hands. I have a great pool and a great hot tub, and I get in that hot tub every night with some whiskey.
Um, one of the, one of the things that's, uh, that's super important is, uh, to, to remember the CSOs move in and out of organizations on average at a right around two years right now. Uh, I know we've got, we've got a, we've got a couple of football players out there. So think about, think about that head coach that comes in, um, and is only there for two years.
He's not playing with his players, he's not playing with his playbook and he relies on that deputy to keep everything going right. It takes about four to six years to actually be playing with your own players and your own playbook. And so that, that can be some, that first two years can be very stressful on in here from E plus.
I'm a field ciso. I'm, I used to work for Silicon Valley Bank, you know, uh, sort of a deputy CSO role, but it wasn't well defined. So if you all have a formal Deputy CSO title, that's a rarity.
Give, give it up for that. I really want to know what's the best way for somebody who is in a more of a operational role. It's usually a, a glass ceiling.
They might be a head of engineering, they might be head of GRC operations, and they don't have full visibility even at their level, right? It's usually the CISO or the, the, the chief of staff or the exec admin who has all the visibility. Somehow there is no cross pollination the way I've seen in the, in practice.
So what, how, how do you navigate that kind of situation? You've been long enough in your role, but you are not getting that CISOs uh, right kind of delegation to learn about your peers functions and get cross pollinated. That's the question.
So I'll answer that as someone that hires Deputy CISOs. Um, first and foremost, if I'm looking for a successor, I'm looking for someone that's well-rounded. So if you're in a certain type of role, seek a job in another role, show me that you can be well-rounded and then that is the next step.
'cause everyone described a different set of responsibilities. You can be in an operational role and be a deputy ciso, but you can't become a CISO if you've just done operations. And so they need someone that is well-rounded and well-versed And make the opportunity for yourself.
For me, I had to make the opportunity the deputy, so, so didn't exist. You have to convince them that you're worth the investment. Yeah, sometimes raising your hand, uh, you might, maybe there's no GRC component or it's weak.
Uh, maybe you can raise your hand, take that on. Same thing with incident response or any other, any of the other disciplines within cybersecurity. Differences between a SANS malware certification and A-C-I-S-S-P mile wide inch deep versus very deep in one area.
I've worked with people who have been LDAP administrators for over 20 years. They're not, they're not moving into a role. 'cause every meeting I go to is I have to contact Switch.
And you have to be able, and as a ciso, you've gotta be able to walk into a meeting. You're talking about identity, you're gonna talk about Jots, you're talking about OAuth grants. And then the next meeting, you're gonna go and you're gonna start talking about, uh, strategic directions of being able to secure MCP proxies.
So it's having that context switch, and you get that by, by working through a lot of different areas within your organization. So go make friends. Um, but anyway, really want to thank the panel.
It's greatly appreciated because again, getting this insight is really, really critical because, I mean, you don't see people opening up like what people were saying. It's like, so, and this is a true story. Like one of the things I really like about this event, like last year, so one of my sons is here now.
I had another son who was there and he walked over to me at the first day and he was like, I was talking to this guy at the bar. And he was like, really cool. And then you introduced him as the CSO of Royal Caribbean.
And I was like, and, and he was like, I was shocked. He was like a nice guy. And I was like, yeah, that's Hiro.
Hiro's a nice guy. And people don't get to like, experience people like these and everybody else who's here, many of you here. And that's really why I appreciate how open they are, how friendly they are talking and meeting people and everything like that.
So I want to thank everybody here. Hey everyone. We're back here with our day three last day coverage of, uh, our time at AWS Reinvent.
Uh, this guy's no stranger to our tech strong audience. He's always either on a webinar showing him how to use Kubernetes, trying to make Kubernetes easy. Some say that's an impossible dream.
Um, or on Techstrong TV, talking Cloud native. And Cooper with me, he's my friend Andy Suman of Fairwinds. Andy, it's great to see you.
Good To see you. Thanks for Having me. You know, for people who haven't caught you before on either Tech drunk TV or any of the webinars, give 'em a little bit of your background.
Yeah, Sure. So I'm a long time infrastructure guy. I've spent mo my entire career working in infrastructure.
I've spent the last nine years working exclusively with Kubernetes. Uh, now I'm the CTO at Fairwinds. And we help people run Kubernetes.
We try to make it easy, like you said, And like I said, in some cases it could be a bit of an impossible task. But, you know, it's, it's funny, Andy, you know, we're, we're sponsored by Suitor. Uh, you're pseudo man.
We're sponsored by Susa here at, it's the last day. I'm getting a little punchy. It's, it's A long, Uh, you know, we're sponsored by Susa.
At, at, at here, at AWS reinvent, and we've been spending a lot of time talking to the, uh, rancher guys about multi cluster Gotcha. Kubernetes management. I'm sure that's something that's near and dear to you.
Yeah. I mean, we manage quite a few clusters for all of our customers. We're familiar with rancher, lots of, um, lots of multi cluster stuff.
I think, you know, the one question we all have to ask is, um, where's the data live? Right? Yeah.
Everybody was there. Like, we wanna go multi-region, we wanna go multi cluster. And I say, that's great.
Where's your data gonna live? Because that's the thing that's harder to move between clusters. I, I agree with you, and especially in a world of data sovereignty and, and all of those things that you're dealing with, right?
Absolutely. But you know what I found, and, and maybe, and I might be wrong 'cause I'm not the expert you are, but a lot of time, multi cluster Kubernetes happens quite by accident, right? You're, you are doing the Kubernetes project over here and you spin up a cluster.
I'm, we're in the same company, we just don't talk. Yeah. I spin one up over here.
Jill spins one up there, Bob and Harry over there. And before you know it, damn, we got four Kubernetes clusters we're managing, but they're all kind of standalone. But, you know, okay, now we gotta get efficient and we wanna bring 'em together.
Yep. So I, I call that like the accidental multiple Kubernetes cluster. Yeah.
We have a name for it. Uh, our sales team knows this term. It's cluster proliferation problem.
CPP. Yeah. Yeah.
So we run into a lot of folks that have that, mostly large companies, lots of teams, different business units. They end up with a vast number of clusters. The cost gets outta control.
Um, and usually when we work with those folks, we work with them to consolidate into a platform. And so their end goal is let's get down to a manageable number of clusters managed by us at Fairwinds, hopefully, um, and build a platform on top of that so that all of these developers aren't managing all of their own clusters. And the goal is let's make it easy for them while also getting control and governance and policy in place.
Um, it's a lofty goal, but, uh, it's can be very successful for folks. Absolutely. Wow.
Um, you know what, this was a good way though, of introducing what Fairwinds does, and, and that You took me right up. I I did not even realizing it, but, but that is the kind of the, the bread and butter of Fairwinds, right? You've got people who have these, uh, proliferating clusters.
Yep. And you have people who are saying, Hey, I wanna modernize and move over, you know, from to a mar, you know, maybe I'm going from VMware and I'm, I'm moving to another virtualized environment, but I want to go cloud native. I, you know, I want to go to a microservices architecture.
Yeah, yeah. Any architecture really, but yeah, microservices one, one way. Um, I had something I was gonna say and I lost it.
It's okay. We're live, so we just gotta keep rolling. So I'm gonna come up with something here for you then.
Um, you know, I just recorded or played our shim. My shimmy says that I do every week, a little 10 minute video on LinkedIn and X. But one of the, the, the theme of this week was, Hey, man, DevOps cloud native and platform engineering are alive and well here at AWS reinvent.
And, and my thought was, you know, when I first got out here, I was just like, bowled over with all the agent AI announcements. It seemed like all AI all the time, right? Yeah.
And, um, but in talking to people and having conversations, you know, I'm hearing, well, one of the agentic AI agents, Amazon came outwards with the DevOps. They're calling it a DevOps agent. Mm-hmm.
I don't know if I'd call it a DevOps agent just yet, but, but they have plans. They have big plans for it. Yeah.
But hearing a lot about DevOps, a lot about cloud native, right? Cloud native is the choice. If you looking for transformation modernization, you wanna move maybe from on-prem to the cloud.
Not all the way you wanna do a hybrid, you want to, you know, um, cloud native has had a strong showing here at the show and, and platform engineering is no longer a fad or a niche. It's, it, I think it's taken its place a long side, the other two in, Hey, this, this is how we build software. Yeah.
How we run software. Absolutely. Absolutely.
You know, I, I think at Cube Gun we talked about, we've launched a product to help people build those internal platforms, and it's entirely based on cloud native software, because we really believe that is the future of platform and where it's going. And I think we could see it from Amazon as well with the announcement of the managed ROCD and Crow Yeah. Act, or a CK, um, you know, they're doubling down on Cloud native as well.
And so it's not going anywhere. It's here to stay. And it will be, you know, the future of platform and DevOps engineering as we as we know it.
You know, thinking back to the rancher announcement, what you just said is, is manage cloud native, the future, I mean, you guys manage for your clients, but you are also, you could come in, set 'em up and parachute back out, right? Yeah, Absolutely. Um, now, I, I had a similar experience in the cyber.
We didn't call it cyber the InfoSec space when I was there, which was after about 15 years, 10, 12 years, I realized that most organizations just weren't capable of managing their own security. It was, they didn't have the, they didn't have the budget, they didn't have the expertise. And quite frankly, they didn't have the stomach for it.
Uh, are we at the same place in Cloud native? I think so. With the larger companies, that's absolutely true.
You know, a lot of our customers, it's, it's one of one or two of those three things. It's either they don't have the time or the budget or the people that all generally rolls back to budget or they could do it, but they don't want to because they'd rather focus on business impacting things. And that's what we enable is, you know, let us do the things that you don't have the stomach for or don't care about, or don't have the time for, uh, and you can focus on your business.
Right. I've always had that philosophy of, you know, outsource what isn't your core competency. Yeah.
I learned, I also learned that the hard way, the dot coms, I had helped start a company that wind up going public. Uh, we were what they call an A SP application search. So there's no cloud, there's no like T three lines of your in the gets meow internet.
I remember that. And, um, we're, we're offering hosted Lotus Notes, Oracle, PeopleSoft. And, and the lesson we learned is if it's not core and critical, those are the two things, right?
Yeah. Something could be core to your, to your DNA, in your case, Kubernetes expertise, cloud native expertise or critical. Your business can't run without it.
It, you don't give up things that are core and critical. Right. If it's core or critical, you might give it up.
Right. If it's not core or critical, you Absolutely. You should give it up.
Yeah, absolutely. Right? Because otherwise you're just wasting money.
Yeah. And I think for a lot of companies, the, the intricacies of managing a cloud native environment, managing any IT environment, if you're not an IT company, you know, it, it's hard. But Cloud native in particular, because, you know, Kubernetes really never came with a chime me uneasy kinda button.
No, no. Batteries were never Included. No batteries.
Security were never included. There Included. No.
Uh, crazy default was never included. So what, what kind of, uh, you guys have a presence on the floor and everything. Yep.
Yep. What, what kind of, what are you hearing from people? You know, one of the biggest surprises to me, um, this is the first time we've had a booth at Reinvent.
Mm-hmm. Um, and, uh, in the past it's always been, you know, I always just kind of assumed that we'd get about 10, 15% of people using Kubernetes. That has changed, um, in, at Oh, ly show.
Absolutely. It's 85, 90% of people really, You think it's that high that I've talked to, are using Kubernetes. And maybe that's 'cause they're stopping by a booth that says Kubernetes on it.
Well, but, uh, go figure. But I'm talking to so many more people that are using Kubernetes or planning to move to it from some other container orchestration or something like that. So it's a huge number.
Uh, it's, it's good to see That is, that is, you know, I, so now you got me curious. I'm gonna have to ask everyone I talk to. 85 sounds really high.
Yeah. Uh, I said confirmation bias on my part. Yeah, no, but you know, the big picture number I always am told is that about 15% of payloads on the cloud are cloud native.
Hmm. Now, a lot of that is because it's legacy stuff, right? Yeah.
Yeah. I'm sure there's quite a lot still that, you know, people aren't talking about. Um, and it's also that, you know, I've said this in the past is that they're probably using Kubernetes, the company is, but what percentage of their workloads are running Are running.
It's a smaller, and That you're right. Absolutely. That's a, that's a real distinction.
Yeah. Because I think what it is, is Greenfield products very well may be 85%. Cool.
Yeah, absolutely. I think so. Brownfield, again, people may not have the stomach to do that transformation.
Right. Or the need, I mean Right. Don't Break what's not, if It's not, don't fix it.
Yeah. Don't fix what's not broken. Exactly.
Yeah. Absolutely. Um, So this was your FI didn't realize this.
This was Fair Wind's first time exhibiting here. Yeah. Yeah.
Coming back next year Probably. Yeah. Yeah.
Worth it. Good. Good conversations.
Good customers. Yep. Yeah.
Good show for you. All The right people were here. Yep.
Really good, good conversations. And, you know, the parties are fun too. The party, you know.
Yeah. We did a, uh, a thing at the Sphere last night with you. A wizard of ours was pretty cool.
That's cool. Yep. Um, wanted to talk to you a little bit about Forget, uh, AWS for a second.
Fairwinds. Yeah. Anything new coming down the pike you want to share?
Um, nothing that we didn't talk about at CubeCon, but I'd love to share, you know, our new product, IDP Quickstart. So we are, I talked about a little bit a minute ago, but we are putting together with AWS, um, they've built in app mod blueprints repository that helps you build a platform from open source. Uh, they did a couple of sessions on it this week, a couple of workshops.
Yeah. We're gonna be running another one with them, uh, next week, I believe. Um, so check that out at, at Fair Wind's website, uh, fair wind's dot com if anybody's looking.
Um, and we will show you the, the product that we're going to be building, which is get you started with a platform faster than you could probably build it yourself. 'cause the biggest problem with platforms is that people spend two, three years building a platform because it's such a complex task. And so AWS and Us together have made that much simpler, uh, kind of prepackaged it up for you, and then we can customize it to your business needs, and then you can build on top of that to, to serve your developers.
So, I love it. Yeah. Anything else you wanna share?
No. Alright. Come to reinvent.
It's a long week. It's fun. It is A long week, but I, uh, it's worth it.
You're heading home today? Tomorrow. Tomorrow.
Good for you. Yeah, me too. Yeah.
All right. Hey, you know what? We didn't mention Fairwinds website.
com. There you go. Andy.
It's always good to see you, man. I don't know when I, well, I'm not doing you, you guys don't do K Con in Europe, do you? Uh, we will sometimes we'll have a person there, but we won't have a booth.
No, I'm actually, I'm not. Mike ards gonna cover Q Conn Europe first. It's the same week as the RSA conference.
Oh. So I'm out in San Francisco that week. Gotcha.
But we'll talk, and you guys are always on with your webinars and everything else around. We'll do something. All right.
Sounds Good. Hey, we're live, we're at AWS reinvent on day three. We still got some great content coming up for you.
Great interviews. Stay tuned. Hey, everyone, welcome to our Textron Gang Live, which is all about 2026.
We're live in 2026. Guys, we've got an interesting show for you today. A little different than our usual.
Um, we're calling it DevOps Appreciation Day. I know Hallmark probably imprint a lot of cards for DevOps Appreciation Day, but for all my DevOps people out there know you're appreciated. Let me, uh, introduce you to our gang for DevOps Appreciation Day.
We've got up north Chris Blak, also up north, Kate Scarsella High up north. Anyway, you want to take that Mitch Ashley, and of course, the dean, Mike Ard gang. Welcome.
You know, you know what I love about DevOps? Smells like victory in the morning. No, no.
That's an old movie. Like what I love about DevOps is it has evolved, shifted, changed, pulled, pushed, stretched, that it encompasses so much today, whether we're talking about DevSecOps and security, or AppSec, whether we're talking about platform engineering, cloud, native, GI ops, of course, CICD, observability, all of these things are SRE. All of these things are kind of within the DevOps culture, within the DevOps bubble, if you will.
And, um, it, it keeps it interesting, right? There's, in spite of the, the DevOps is dead stuff that we saw a few years ago. It is bigger and better than ever, the community and the, and the market are vibrant.
And, and as proof of that, you know, this year for 2025, we announced on our predict show last week, the winners of the 2025 DevOps dozen awards. I think it was the ninth maybe. I think it's the ninth year of the DevOps dozen award.
You know, Mitch and Mike May know this, and you may not. We kind of started the DevOps Dozen awards nine years ago, a little bit, not tongue in cheek, but a little audacious to think that there was, or even a dozen different categories for awards in DevOps, right? We, we, and I'll admit, we made some categories up that weren't really fully baked back then, but it, you know, as I sit here now, nine years later, I'm afraid we don't have enough awards to cover all the different flavors and varieties and places that DevOps touches on.
And so we, you know, we, we've had a, we've had a change and evolve, right? A couple years ago we went to the DevOps dozen awards squared, which is actually DevOps doesn't too. So we had a dozen community awards and a dozen tools and service awards to kind of break out those things that were sort of open source or community based, and those things that were more on the commercial side of the house to help cover the wide range of different things going on in DevOps.
We've stuck with that a little bit, though. We've had to modify that year to year as well. Look, we've seen things like AI come in here and change things, and, you know, we, we've tried to keep the DevOps award, the DevOps does an awards relevant.
And up to up to the minute, I think we did a great job this year before we even get started, gang, I gotta give a shout out to Andre Pino on our team. You know, Andre is a marketer, extraordinaire, analyst. We we're Andre's a semi-retired.
We're grateful for any time he gives us, but year in and year out. He really sort of takes the DevOps dozen awards under his wings and, and runs with it. So, shout out to Andre and helping us again, make this year's award award a success.
One last thing. com, register the actual presentations and announcements as well as all of the finalists were, were, uh, announced there. Mitch, Mike, I'm gonna ask you two guys to kick off here, because you've been involved with us with the DevOps Dozen awards now for all these years.
What is the DevOps Dozen awards mean to you, Mitch? You know, it, it's, it's a bit of a rallying cry to just to talk about what are we doing in the community? What are we doing as a vendor community?
What are we doing as participants, advocates, people that move the ball along, people that challenge us and say, Hey, we're not doing enough here. We need to step up as well as people to say, Hey, let's celebrate some things that are happening. So it's great to recognize what people have done in DevOps, and as you said, the the categories really kind of expand, not because we're trying to just give everybody a participation award.
No, there's so many elements of DevOps these days. DevOps really is the term doesn't mean what DevOps meant. You know, nine years ago when we started all this, and I think I've been a judge for a number of, maybe, maybe most of those years too.
So it's, it's a lot of fun to participate in it, but it's even more enjoyable to see what people are doing and see that they're getting recognition for it across the board. Yep. Mike, to me, To me, I look at the journey has been rather incredible.
And I look at it and I go back in time and early on, like DevOps was the rebellion against those idle folks who were a little too overly dictorial in their approach to it. And the DevOps guys were basically saying, you know, we needed more freedom to create and drive stuff. com talking about, well, you know, what is the relationship between DevOps and platform engineering?
And to me, that's kind of like us stumbling towards something that feels like a middle ground, where we have some structure where we're not just kinda loosen together all these tools and telling people go for it. But we're also trying to preserve the flexibility and the freedom that goes with DevOps. And so, I don't know, Alan, your article's up there, but what's your take on, where are we on this journey?
You know, it's, it's kind of the never ending journey. And, and I wish I knew exactly where we are. We're here, you know, how's that?
Right now? We're here where we'll be tomorrow. There.
Um, I, I think, you know how people think that the US Constitution is somehow the word of guard, that the founding fathers were modern day prophets that are infallible, and therefore, everything you know, is, is, is like, you know, biblical in, in, in the, one of the beautiful things about DevOps is there is no bible, there is no manifesto, there is no definition, there is no right wrong path. I, I think the best way to describe it is something I heard Andrew Clay Schaeffer say, once the DevOps you get is the DevOps you deserve. I've heard him say it more than once.
Mm-hmm. That's the closest thing you've got to a creed in, in DevOps. So where is it?
Yeah. Platform engineering's here and Platform engineering's great. com, it, it helps DevOps because I think the platform engineering community recognized that for DevOps to truly succeed, it needed that platform.
It needed the guardrails. You know, it's funny, when Platform engineering first came out, it was about Kubernetes. If you can get your Kubernetes platform under management, hey, you've got a great platform there.
But no, it, now it's more about IDPs and setting up CICD guardrails, which allow DevOps engineers to do, or DevOps teams to do their things. And so again, that's the beauty of, of DevOps the way it's set up, it morphs, it embraces, it extends all of these other ancillary technologies and frameworks that come down the pike. Chris, Kate, we haven't got you guys involved.
I'm interested you both, you actually both come from a, a security background, right? So I'm gonna imagine your answer is gonna be more security centric maybe than Mike's or even Mitch or I, what is, what does DevOps mean to you today? Okay, Well, you know, one of the things that I find is we're still leaving out security.
And at the end of the day, um, and it's concerning when I look at, when I personally look at platform engineering, I understand we're basically putting a structure, um, to DevOps. But we're still, that doesn't mean that we're putting security as a part of it, and meaning that, let's say, you know, so we have structure, um, if you're building a house, you have a foundation, but do you want that foundation to crumble as you start to, you know, build your house? And, and so for me, I still find that security is being bolted on, and I don't understand that, but, and it's concerning, especially as we talk about AI and, and the idea that it's just going to be going so fast that if we don't start building presently SEC with DevSecOps, we're just gonna end up having another platform a couple decades from now, and it's gonna be some brilliant new term and still not give us the actual secure foundation that we need to build what we need to build safely.
Chris, You know, I, I came to security early in my career, but really second, my, my first epiphany that set this path was everyone's gonna get on this internet thing. And then it was all the all needs security. So I spent, you know, all, you know, these decades focusing on that.
However, it's not about that. It's about the story. And we go back to the beginning.
In the early nineties, the story was, everyone's gonna get on this global network. And Bill Gates himself went on TV and said, no one will use the internet. That's a silly academic thing.
What they'll all do is they'll pay me for the Microsoft network. And the story back then was you could divide the glo the world into camps that everybody believed one or two things. Either that the big brother was going to sell us this monitored surveillance system that we'll all submit to, or that the hippies are gonna win, and this internet thing's gonna work.
And in, for example, 20, 25, people would be arguing about phrases like DevSecOps that nobody knew back then, but still trying to navigate this space where it's not all just dictated from the top. So you guys, as you say, you, uh, people on this screen have spent way more time in specifically DevOps and DevSecOps and, and Kate, you know, uh, I've been more on the margins of that. But what I see is our ability to have conversations with technical terms, it never existed.
And we're coming up with these terms and all their implications and all the conversations we have here, because we keep building succeeding to build a system that is not monolithic and centralized. And it seems to be the only way to do it. And I think everybody on the screen here, most people watching would we we're concerned.
We have some fear that it ends up being centralized. So can we, every day, every week we talk about this, can we solve all these individual granular problems in DevOps and DevSecOps? And I don't know either, but we continue to do so.
And that's, that's what I find comforted, You know, let's, we added a dash of Hope this, and, and I, I come to it from a, uh, like I recently started describing myself as an engineering operator, 'cause building, building products and building software. And in some points in my career, also operating, run, running those things. Now, being an analyst is, it was about 2014 when Alan, uh, rang me up and said, Hey, Mitch, what do you, what do you know about DevOps?
I'm like, I think you miss said that. It must be something else. I've never heard of it.
To your point, Chris, about new terms. And that sort of launched down my path of, well, what is this and how and can we use it? And, and today, I think where we are, Kate, to your concern about it, I'm not gonna paint this as, oh, good, it's all rosy.
We figured it out. But what's changed today is, is we're pursuing at breakneck speed, AI and agents and all this stuff, um, co-generation, all these things that we're all concerned about the security of which I am as well, but also coming along with it, our vendors and the standard open standards to a, to a, to a degree, they're a little bit later than that of adding in security guardrails, behavioral guardrails, um, observability, building it into the platform of where we develop agents and we operate agents. That wouldn't happen.
That didn't happen when we started on DevOps. It didn't happen two years ago. Um, so I'm, I'm, I'm hopeful, I'm optimistic that because we've made it part of the conversation security about developing software that we are taking, you know, some steps to help secure more parts of AI that we're building, agents that we're building than we have traditional software before.
It's not relying strictly on scanning after the fact somewhere down the pipeline. Um, and, and it, it's gonna be, it's gonna fall short, I'm sure, and we're gonna have to do some things to really aggressively fix problems that we haven't addressed yet. But I think we're thinking about it more holistically of software at least starting to, and the vendors recognize that their customer base, especially enterprises, can't deploy this AI stuff at scale without addressing security.
Um, and that's increasingly part of the conversation. So I'm hopeful that we're gonna do much better than we've done, and we're gonna figure out where else we've fallen short that we've gotta do a lot better. Yeah.
And Mitch, you brought up, um, two key words that I love as a security person that is, um, behaviors and, um, observability observations, because I always talk about indicators of compromise, indicators of behavior. If we see in indicators of be of compromise, it's already too late. It's already for us, the right of boom.
As we talk about when we talk about behaviors, we're still talking about elective boom impact. And that is extremely helpful to me. So thank you for bringing up that word behavior.
So I think that's the key going forward. You're Welcome guys. I wanna transition to acknowledge and recognize some of the DevOps dozen award winners this past year.
Unfortunately, we don't have the time to really go through every single one of them, but I'm gonna cherry pick ones that I think are important or I wanna just acknowledge. And we're gonna start off with the community section of the awards, which is a little less than half the awards this year, but they're, they're not less than half important. They're very important.
And there's some great ones out here. I'm gonna start off with the best DevOps related video or audio podcast, maybe call it a webcast or whatever. You know, the modern mainframe from BMC one this year.
And a lot of people say mainframe DevOps. What do you mean? Again, that's one of the secret sauces of DevOps.
DevOps has done wonders, wonders for the mainframe world. It's really allowed the mainframe to run the latest stuff and whether, you know, and whether you're bifurcating system of record, right? And all of these things.
But there's so much good going on there around DevOps and mainframes. Good to them. Um, the next one I wanted to pull up is the best DevOps book of the year.
And this was a book that comes out of it, revolution, our friend Jean Kim. It's called Progressive Delivery. Build the Right Thing for the Right People at the right Time.
It's by James McGovern if I, it's cut off on my teleprompter, but James Governor, James governor, excuse me. James Governor from Red Monk, um, Kim Harrison and, and Heidi Waterhouse Waterhouse and Adam Ziman. Great book.
And, and it really captures, you know, we talk about the evolution of DevOps. This book really captures that. Even that title is exactly what DevOps is today, right?
It's built the right thing for the right people at the right time. So shout out to that book. If you haven't read it, add it to your library.
The next one I want to break out, and then I'm gonna ask you all to jump in on this, is Best DevOps community evangelist. DevOps has always been a community of evangelists, right? We've had from my friend John Willis, Andrew Schafer, I mentioned, there's been so many great evangelists in the DevOps world, whether they were doing devel or what have you.
This year's winner was Nathan Harvey. Nathan is, is kind of a pied piper of DevOps, right? He started out at Chef, he was the chef guy who was out there preaching in the wilderness early on.
He left chef like many did, and went over to Google. And I thought, well, I don't know what he is gonna do about DevOps at Google. But then of course, Google bought Dora, right?
Which was a company started, of course, by Dr. Nicole Forsgren, Jean Kim, and J Humble, and they're the people who came out with the first sort of surveys, maybe not the first, but the biggest DevOps surveys every year that showed how high performing IT teams are performing, you know, utilizing DevOps or not. And we call it door is DevOps research and analysis, I believe.
Mm-hmm. Google took that, you know, gene Nicole and, and Jez are not as involved or not involved anymore, but Nathan's kind of taken that over and Nathan won for top DevOps community evangelists this year. And the 2025 door report, one for best DevOps survey researcher report.
Mitch, Mike, I know we all talk to a lot of companies who will often tell you, and they cite the Dora metrics, right? In terms of, that's the measuring stick they use to how they're doing the DORA metrics. And Nathan is still out there.
He appears on our events, he on and text drunk tv, but he's all over spreading the gospel of DevOps. Mike, I know you've met them. You've, you've met Nathan, interviewed Nathan, what do you think?
I was, I like the idea of Dora, and I like the fact that we're tracking some metrics, I guess other folks and myself included there. One criticism people have is the metrics don't always correlate to a business outcome. So it's wonderful that we are, you know, turning over more code and fixing it faster and generating it more.
And that may be what the DevOps engineers can control, but I sometimes wonder if we get a little overly obsessed with that particular set of metrics without connecting it back to something where, you know, DevOps teams can go to the business and say, this is the value of the ROI and the return on this whole methodology. And I don't know, Mitch, am I asking for too much here? Or what do you think?
Well, um, just like the, the DevOps you deserve is the DevOps you get, DevOps doesn't stand still. And I think the Dora reports under Nathan's leadership have progressed significantly. Not that they weren't progressing, but they were very focused on how many, how many, uh, deliveries to production are you doing that that is a primary, uh, uh, uh, metric that Doro people use to, to measure themselves against Dora.
And I always criticize that and said, but yet, if it's the wrong delivery, why does it matter? We've, it's, Nathan's really turned the page and said, we need to think forward more of where we're going. That's why this report was, was talked about, uh, gen generative AI assisted development.
And he's really taken on the mantra of let's really look at how we're developing software and how that's fundamentally changing. How, how developers really are becoming the engineers of how software is created, not create, just creating software. And that process is gonna fundamentally change and transform like, like it can under DevOps.
And I think that's the good news. So to your point, I think DevOps has been, or excuse me, Dora has been sort of the easy metric for all of us to rally behind, but the environment's changing. And so Nathan's challenge, and I think he's up to that challenge, is to really identify, so in the world of where we can generate software as fast as we want, maybe we can push it to, to, to, uh, production as fast as we want.
Yeah. But what are we pushing? How are we pushing, how are we creating it?
And how are we creating value for the business? I've heard him talk more about business value in the last two years than any of us talked about business value in the previous Dora Reports, which is a great sign of, um, evolution and maturity. Yep.
Kudos, kudos to Google and the whole Dora team. And Nathan, of course. Um, I wanna make a quick mention about the DevOps event of the year.
It was DevOps days for in Zurich. You know, for those not familiar, not from the DevOps world. com.
Um, the first DevOps days was in ENT, Belgium with Patrick dubois. The first DevOps days in the US was in Silicon Valley with my friend Damon Edwards and John Willis. And since then, I forget how many like a thousand DevOps days have taken place around the world.
What was interesting here is this was the only DevOps days nominated for DevOps event of the year. All the other events of the year were, uh, vendors user conferences, which are great. There was some great user conferences in here that were made in the finals, including jfr Swamp Up and Grafana and, and some others.
But it was nice to see the vote. People still like that DevOps days format, that unconference that, you know, it's not run by a single vendor, truly is the community. So shout out to the folks at Zurich.
They are a great example of the best of DevOps days. Also, I wanted to call out best DevOps open source project. This wasn't the project you were looking for.
A lot of people were looking at, you know, traditional open source projects, but our friend Garima Garima, Bo Powell, right, did a, an event. John Willis was a big help to her with it, um, called DevOps for Gen AI Hackathon. And so it was a series of projects that was spawned out of this hackathon and Garima, you know, Garima's a great community organizer in the mold of, of Obama or something, right?
She really does a great job with organizing communities both in Canada. She single-handedly has built that, but worldwide. And, and this was a a, a great project.
All open sourced, open, you know, open everything, not just the code. It was open and, and kudos to her. I wanna mention, you know, this year more than ever, it, it's amazing.
So we have judges, right, for these awards, but then there's also the public voting and you know, the judges of 60% voting is 40%. But this year, more than ever, last year I saw it too. Basically there were one or two out of maybe 24 awards where the judges picked did not line up to the voting.
I think the community recognizes value and quality. And so I'm happy to say that the over over 99% of these awards represent what the community voted for. So congratulations to Emer and the whole team there.
Next up, I wanted to talk about DevOps industry leader of the year. And I think now we, we are moving away from community and into more of the commercial awards. Um, well, it's still technically community, I guess, but these are more commercial.
So DevOps industry leader of the year was Ti Al. And you know, you know how in the Oscars guys usually best director is the best picture. And oftentimes it's the best actor too that we had that we had some of that going on here today.
This was a, a year for harness, right? Jodi, of course is the CEO founder of Harness, technically harness ai. Um, and they had a good year.
They had a good year, Chris. And, and, and part of that good year was around security, right? They absorbed, traceable another security company Jodi had founded to give it their, the security, you know, chops in, in harness a boost, AI security.
I don't know, Chris or Kate, if you've had a chance to look at what Har Harness has done this year, Mitch, I know you have, and Mike, I assume you have as well, but to me, I think you take a look at those three awards together. Geo is best DevOps industry leader Harness for best end-to-end DevOps, uh, solution. And then also I believe Harness one for best DevOps platform engineer Award for their harness IDP.
They actually came out with their own IDP. So, you know, first of all, congratulations to Harness, but Yang, um, any thoughts anybody wanna contribute or speak about that? I, I'll jump in just to kind of kick things off.
Um, what I think is notable about Harness, and of course, you know, I followed them for, for a long time before you being an analyst, is they're very much are a platform company, but they lean to the right. They're very much after code has been their strength and they continue to do that, including in the age of ai. So they're, they're very much a software delivery platform.
And now they're, they've pursued an added more agentic automation. They've really invested in knowledge graph technology to bring contextual information into AI and also some of the other parts of their offerings. Um, really deep DevSecOps integration.
Um, they've really continued to innovate and not just stayed where DevOps was or Dev SecOps was three years ago. They're continued to really take in leading, leading stance. Um, I'm very bullish on what they're doing in many areas.
Um, they've got some, they've got some places to shore up. I'm not gonna focus on those things today. But, um, Jodi has really done a great job and he's recognized as a, as a, as a great leader in the industry and he's done really well with Harness.
And so I think they're gonna continue to do great, do great things. Yeah. And you folks know more about DevOps than the side of it, but you know, what I've seen from this is that, that they're making platform engineering, not theoretical, remove removing friction instead of putting gates while doing the, doing the security threat of it.
So I've, I, you know, I've liked that, I've seen that along, but I again, don't have the, the depth of understanding. And on the DevOps side of that, that just seems logical and that, that's where we've been going with this. I think, you know, the one thing they do really well is they strike that balance between I want to choose my tools and I want an integrated platform.
Because theoretically you can buy their entire stack. They also let you swap out things more easily and they don't necessarily dictate the platform to you. So I think there's a natural tendency where DevOps shops don't wanna necessarily buy that fully integrated platform.
They kind of want some choice, but they want it to feel like a platform. So it's one of those, I want my cake and eat it too, kind of scenarios. And the reason why that becomes important is that then you prevent this, um, this hacking, for lack of a better word, that then makes things less secure.
So that's why that piecemeal is good. You know, right around the end of the year, harness announced a major new funding round with like a $5 billion valuation. Yep.
com article I did with it. I also embedded a podcast, a DevOps chat podcast I did when Harness launched, I think eight or so years ago. Um, what's interesting is for those of us who've been around, like when I first started DevOps, right?
CloudBees GitLab later on Jfr, they were the three big DevOps end-to-end platforms. And they focused on C-I-C-D-C-I-C-D. I remember interviewing Jodi early on and he said, well, I looked at this the same way I looked at the, uh, application management a PM market when I started AppDynamics.
And I said, what's missing here? What doesn't work? And the problem from Jodi's point of view is all of these CICD platforms were CI first and then cd, but Jodi thought that the emphasis should be on cd.
And he made harness a cd, a continuous delivery platform more than a CI CD platform was the first time I saw a CD decoupled from ci, right? In DevOps. And that was the mantra early on.
ai before we, you know, be, this is eight, nine years ago, eight years ago, whatever. Before AI was cool. He had the vision of maybe he was talking more about machine learning truthfully, but he had the vision then of doing it.
Um, and so as we sit here today, you know, we looked at best end-to-end of ops platform harness really stood out. They really built that platform, including the platform engineering, the IDP piece of it, including Mitch, the observability piece of it, including Kate, the cyber, the security piece of it. They really got some great security chops in there.
So again, just kudos to the harness, Jody and the whole harness team. Greg can have one more thing about Sure. Harness two, and I think this sets the stage for the broader industry is, um, yeah, they had, I think it was 240 million series E, um, but they've got 250 million in, in A A RR at right, 50% I think year overgrowth, if I remember right.
So it, it, it's, it's humming. It's moving really well. And I think there's a couple reasons why that have implications for the broader industry is, like you said, they're not just leaning into the cd.
The, they're, they're going down a path that you might call the, uh, kind of the AI control plane for what happens, um, from the delivery point on. And that's a lot of the investment in this, um, delivery knowledge graph, which of course can be used not just in in delivery, but pre pre-delivery as well. So they've invested in technologies and taking an approach that I think set the stage for where we're going, not where we've been in CICD.
And at the same time, um, to your point, they recognize like kind of the AI vendors is they can't be everything to everybody and everybody's gonna have 20 different tools and different things. They may consolidate, but they're still gonna have four or five of everything and they've gotta work with the tools that people have. So you have to meet people with where they are, customers with where they are and where they're going.
And I think all of those are key elements of any successful strategy looking forward. Yep. Gotta move along here a little bit guys.
I want to next call out the good folks at Octopus Deploy, right? They want for best application of gen AI and a DevOps tool or platform Octopus Deploy. You know, I remember first meeting these people, they, they're down in Australia.
I felt terrible. They were up at 12 one in the morning to do their tech drop TV interviews with me. They of course bought, uh, acquired codefresh, the people really behind, uh, what became Argo, one of the biggest open, I think it's the third largest open source project in, uh, the CNCF.
Um, fantastic, right? They've really made their, their mark on the space and they've really kind of taken the lead when it comes to AI using generative AI and, and even agentic now too. So I I, I, you know, I think this is an up and comer.
If I had to pick who's the next harness, it's octopus interesting perspective, I'm happy to jump on on them. Them as well. You know, they have, you know, they're still kind of framed as the CD part of specialist in, in terms of what doc, what, uh, octopus is doing.
But they've invested not just in MCP, you know, access to, to what they're doing, but they've also created, I believe it's, uh, some kind of, I think it's the AI recovery agent if I recall about, and where we can look at where failures are, what's happening, root cause analysis in the pipeline itself, right? Not just leading into production. Um, so, so you can also recover earlier in the, the deployment cycle as well as once you move into production.
And we see a lot of investments right now, um, where companies are making investments in, for example, um, feature flag capabilities that push all the way up into the deployment cycle, as well as what gets deployed into production. And tying that to observability, that was a company that Dynatrace acquired. So I think Octopus got a bigger vision for what's happening in the c CD pipeline.
And that's part of why you have that sense, Alan, as of an up and comers, they've got a vision for where this is headed. One of the things I like about what the, that whole community is doing is that they give you an option for cd, right? Not everything has to be programmatically addressed.
You can use a graphical tool to manage CD and that makes the whole thing more accessible to a larger number of people who may not have the programming skills and they're just mere mortal IT administrators that wanna do continuous deployment. This is a good thing. Absolutely.
Hey, let's jump to a security thing, right? Best supply chain security solution, right? And this is something, look, you know, every year at RSA we do the DevSecOps days on Monday, and certainly supply chain security has become the focus of security, you know, pre-deployment.
So best supply chain security solution was our friends at Jfr, the Jfr platform. And Jfr, I think more than any of the other big DevOps platforms who've talked about becoming a security company, has become a security company. They've acquired more than several security startups that they folded in for, uh, for security, DNA and their, their supply chain security solution.
Everything from X-ray to the, they have ai, supply chain AI security, they've really become a security solution. I think it was recognized here as such. Yeah.
For me, um, you know, if you can't prove where it came from, you shouldn't trust where it's going. Yeah, I think that's, that's a fair comment. It's A fair comment.
King, I wanna ask you this question though. 'cause we talked about security earlier and you know, you hear the phrase security by design all the time. But I wonder if just like as humans, we're conditioned not to think about security after the fact.
I mean, you basically, you build a house, you then you put the windows on, and then you put the doors on, and then you figure out where the locks go. So, you know, that may not be the best approach for software engineering, but is this just kind of like, have we brought forward something that we are mentally conditioned to do after the fact? Yeah, it's a good question because I believe that, um, my hope is that security gets to the point where as a consumer, you can walk into your house and turn a lock and voila.
And I know, you know, that's, you know, crazy talk. But you know, my hope is if I'm looking at, um, you know, secure by design, I also think it has to take in, uh, agency, agency of the person. So like who, you know, just goes back to what I just said, you know, you know, where is this coming from?
And, and so maybe the house is not the best example. Um, although the only thing I would add to that, um, house example is that when we're building, like you're doing cement or whatever, you definitely are putting in elements that make the foundation strong. So it's not just windows and doors that we're thinking about, it's also the components of the house that matter, the foundation.
I mean, you know, the foundation, foundation foundation is everything, you know, and it gives you not only hope, but it provides, um, the framework. And that to me is very much security. Um, is is framework, you know, and that should help us build, um, our security into, um, into DevOps, right?
Is the components just like a house. So I'm gonna go back to the house. I'm sticking with my house, I'm sticking with the foundation, this Whole house.
Well That's right. Well that because it's all about story over time. Like I can geek out, you know, last six years I've gotten deep into supply chain.
I can tell you more about why there are eight fields and SPDX versus like, but what I really care about is that something seems to make sense and it continues to be coherent over time, right? And I guess gotta say this out loud, DevOps, for those who don't know it, is the idea that developers and operators should speak to each other, the basic, right? And oh, we should ask the security people, DevSecOps.
And you know, as we move through time with these things, somebody will say something, it's like, we should have it that way, Kate. You know, I should be able to walk into my house with a key. And then, well, you can't do that because that requires all these things.
And as I said at the beginning, we've been competing since the early nineties in does someone build this thing and tell us what to do or do we build it and we continue to go down the storyline of we should do this. Somebody says that it turns into a working group and we come up with a solution move forward. And that gives me a lot of hope.
The specifics of it, you know, failure states and things breaking out, that happens all the time, working out better or worse, that's a big deal. But we keep going down this path where, no, we don't need a big, we don't need someone to tell us the answer may be impossible, but things like developers and operatings just speaking to each other, the whole industry, You know, Chris, it's so funny that you mentioned that because I feel like, you know, and I've said this before in the show, at some point those two should actually marry. I feel like it's been like this contentious sort of divorce.
And like, are we, you know, we're gonna be separated. No, no. Wait, we're married.
No. You know, right. Yeah.
No, we're friends. We're benefits. What are you talking about?
Alright, on that note, that's the key to move on to the next category here. Yeah. Hey, I wanna talk about best observability solution.
You know, in many ways, 25, 24, if it were not for ai, observability would be the story. 'cause we've made tremendous star strides, observability, post-deployment, observability, pre-deployment observability, moving information, feedback loops from post pre. And really the good folks at Grafana Labs and their Grafana Cloud product in a very open source friendly way, right, have led the charge in many ways on observability.
Of course, Tel Open Telemetry mm-hmm. Is the, you know, the king of the hill when it comes to open source observability, second largest CNCF app. But right behind it you have Prometheus, uh, which Grafana is a big, uh, uh, a promoter of contributor to as well as to hotel.
And then, uh, uh, Loki is actually a Grafana project that's also in there. But they, they, I, I just want to shout out to them, they really have not single handedly perhaps, but in a big way help move the needle to make observability as integral as, as it is to the whole DevOps way of doing business. You know, you highlighted the open source, which is, uh, super important.
I think their m and a strategy has really picked up too. They just announced the acquisition of Tail Curl. Yeah, excuse me, Cal Control, that's what it's yeah.
Tail control in, uh, this month actually. And, um, that's all about, you know, AI assisted tracing and sampling, um, across their existing, um, they acquired a company, I think it was pyro scope in 2024 or 2023 that they're building upon. I would surprised to see them doing some more m and a across this.
So they, they've kind of got, they've got a multi-pronged strategy. You know, we used to think of Grafana as what dashboards, right Alan? Yep.
That was, oh, and, and you tacked on Grafana to whatever open source tool, um, or product for your dashboards. And they've, you know, really become a much different company today with Grafana Labs. Yep.
Guys, we're almost outta time. I wanna speed ahead. One last there, there's some great, I, I should call it Sona type one for best DevSecOps solution for their SCA, uh, tool.
So Brian Fox and the Sona type team, good for them. Rookie of the year, as I call this one best new DevOps tool. Goba ai.
I met them up at Platform Engineering Con, um, another old security guy, you know him. Chris Ian. Ian Amit, right?
Smart is a whip oh yeah, security guy, but really using AI to, to help secure code. I, I'd want to give him a shout out over there and gone back. That's G-O-M-B-O-C.
Um, guys, we're outta time doing this live format. We we're locked in 'cause we can't edit it later. Um, Mike, I appreciate you coming up with the idea of DevOps Appreciation Day here.
Next year we'll do greeting cards, but it was a great idea to highlight the winners of this year's DevOps Dozen awards. com to get more information there. As I said, you could also go to predict 2026 to see the, uh, presentations as well as the finalist.
Kate. Chris, I know this wasn't exactly a hundred percent in your wheelhouse. I appreciate you coming on though and contributing valuable input into our discussion.
Mitch couldn't have done it without you and Mike, of course. Um, that's it for today's DevOps gang show, though. We'll be back tomorrow back to our regular format.
So stay tuned for that. Uh, we've got tech drunk TV coming up though. Check that out.
I gotta go run to a webinar on what else, DevOps and security. But until tomorrow, this is Alan Shumer, we're out. Hey guys, thanks for the throw.
We're here with Abinov Astana, who's CEO of Postman, and we're talking about an acquisition they made recently of an outfit called Fern. That well is gonna help everybody hopefully create better API documentation and SDKs. Abinov, welcome to the show.
Thanks for having me here, Mike. So walk us through a little bit, what is the problem you guys are trying to solve here? And um, you know, documentation I feel like has always been a problem, but hey, some people are thinking it might even get better in the age of ai, but what do you think the issues are and what are we gonna do here?
Yeah, so we've been spending a lot of time with our customers. Mike, you know, Boman is now a full, uh, API platform. We cover everything from design to collaboration, to testing to monitoring.
And I think one of the recurring themes that I was hearing from our customers was that they still are not satisfied with, uh, their developer portals that often come bundled in with their existing platforms. And, uh, you know, when we looked at the market, we saw that the phone team had done a fantastic job of, you know, both SDKs, which allow developers to consume an API. And lately they had expanded into the dev portal space, and they were getting a lot of traction with the likes of Square, um, and, and Twilio and a bunch of others.
And, uh, we thought that, you know, this could be a great, uh, win for Postman customers and a great thing for foreign customers, as well as the whole market for these two companies to come together, where Postman, uh, offers a fantastic developer experience to build those APIs and share those APIs and, uh, Juan's developer portal and SDK offerings help extend that, um, and, uh, you know, bring consumers for those public APIs, uh, as a service to public, API, you know, publishers. Mm-hmm. I think part of the problem that a lot of organizations have is that they have no shortage of APIs, but nobody really understands what to use them for or what it is they do, or what those capabilities are, which I think comes back to the documentation.
And yet nobody really enjoys creating the documentation. So how automated can all this get? So, you know, we've been, uh, investing a lot in, uh, uh, AI capabilities within Postman.
And over time, I would say that actually the importance of documentation, as you say, has actually improved over time. Like both for human and ai, you actually need good documentation as context, you know, whether it's a human developer or it's, uh, the AI agent. And, uh, I think creating good documentation is not just like generating whatever comes out of an LLM, it's actually also these iterative cycles of trying to understand like how an API behaves, um, communicating that succinctly, um, and then eventually like publishing it.
So, uh, I think we, we will, we are seeing like this, uh, resurgence of sorts, uh, of, uh, people wanting to have, you know, good engineering practices. Uh, and, and some of it I think is also driven by just like this act of coding, just getting more and more like automated. Now, developers used to spend a lot of time like just writing like lines of code, but now when they're just like, you know, kind of hitting the generate button with l lms, what goes into generating that code becomes more and more important.
So I think there are these two sides to it, like the publishing process needs to improve. I think Postman provides a lot of that with existing AI capabilities and the rest of the tooling that we offer. And then on the consumption side, we'll see more and more, uh, uh, importance there.
I think with fun, I think what they have done is create a very exciting, very, very, uh, you know, beautiful like developer experience with dev portals, like with a lot of customization capabilities, with a lot of configuration. Uh, they have some AI capabilities embedded in that, uh, uh, uh, portals as well. And, uh, I think, uh, you know, we just, we just expect that this will, uh, you know, in the future be the default for like, you know, all a p publishers out there.
Mm-hmm. How do you envision all this playing out? 'cause you mentioned, uh, AI agents, and as I understand it at least, or I think I understand it, um, those AI agents are looking for the metadata that describes which the metadata is based in turn on the documentation.
So ultimately, if we want these AI agents to be successful invoking various services and being autonomous, um, you know, for one of a nail, the horse might be lost and it all comes down to the documentation, right? Correct. That's true.
That's true. I think, uh, what, uh, has happened over the last year is that, while I think we probably talked about this in the last conversation, is that, um, while the agents have improved in capability, they're still limited around the context window and what goes as context into, uh, these l LMS and, uh, uh, the difference between like demos and working products or, uh, you know, kind of a cool hack to like actual workflows, uh, is is how you put that context together. How do you take what is available about a system, uh, especially its documentation and feed it to get like the right outcome?
So, you know, yeah. I'm like a full believer in this. I would say that most companies, uh, uh, you know, still have hundreds of thousands of APIs that are not documented well.
Uh, some of that is due to just lack of time, but sometimes it's also just due to the legacy that's built up over time, you know, in these systems. Um, and, uh, there's still like a huge opportunity for companies to update, update them, and, and frankly, they need to, like, uh, I think what I'm hearing customers, uh, say is that, you know, for people who are interested in building agents, now these agents need to talk to their APIs, so need to, you know, buffer up their APIs and make, make these agents, you know, functional. Uh, so all, all of that is, is very critical for the modern age.
So how many APIs do you see the average organization kind of creating and actually maintaining? And is there a life cycle to this process? Because I think a lot of times APIs get created and sometimes forgotten about, and, um, yeah.
How should we kind of think more holistically about managing these A ps? Yeah, I've seen like everything, you know, from each developer owning, uh, you know, five APIs or services inside an organization to, I would say roughly a team owning, you know, at least one. I think, uh, uh, every organization that, uh, you know, we work with has hundreds to, you know, thousands or hundreds of thousands of APIs.
It's very, very hard to actually remove an API. It's very easy to build one. And I think with the rise of like microservices, serverless, all this over the last like, decade, you know, the prevalence of the cloud, there are just more and more APIs out there.
Uh, I think with every platform shift, we also see net new APIs being created. So in the last platform shift, when people went from, uh, desktop apps to mobile and cloud, I think now we are seeing like that with ai, where again, you know, people want to create more and more services. They wanna create new form factors, uh, for agents.
So they're creating more APIs there. So the net number of APIs in an organization, you know, kind of always goes up. The hard part is actually maintaining, like, uh, technical integrity of the system, ensuring liabilities of qualities of these APIs are well governed.
Um, you know, there we see like a gradation between, uh, you know, I would say technology companies who are much more prone to foster development, and they're like, yeah, we're just gonna like, you know, kind of keep going, just keep shipping fast. Versus I think more traditional sectors like banking, finance or, uh, uh, uh, you know, telecom, et cetera, where depending on the amount of regulation that exists or what other constraints that are there on the industry, you know, they, they wanna make APIs a much more governed process. So, you know, in a nutshell, like, uh, hundreds of thousands of APIs at, at any sizable company, if you're a startup, like the moment you get to 10 developers, you'll have, you know, at least one or two APIs, and it just keeps on growing from there.
But the management of those APIs varies from sector to sector, depending on, you know, how, uh, fast you want to go to production, uh, and, and how regulated you, you are as an industry. We talk a lot about, well, APIs need to be managed by somebody who treats it like a product and not some sort of add-on. And that the, if you're gonna manage it like a product, well, all products have good documentation, so they have to start with the thing.
But how many folks are actually managing their APIs as a product versus kind of still treating them as some sort of random software artifact that somebody granted. Yeah, I wish I had the state of, uh, API report numbers top of mind, but we'll, you know, make sure that we, uh, uh, you know, we, we share that in the next update. Uh, I think the number of companies that, uh, mentioned their API first, I believe is like somewhere between, you know, uh, 30 to 35% is, uh, if I remember right, and what, uh, you know, API first, uh, the label qualifies them as that they think of APIs as first class citizens.
Uh, so we categorize companies between, you know, like API first, API aware, and API last. You know, I think still a lot of companies are in the API aware bucket. I think that percentage has increased over time.
Uh, many companies do treat especially like their top, uh, uh, you know, monetizable APIs or revenue generating APIs as, you know, big first class like citizens. Uh, you know, sometimes, uh, money to the tune of hundreds of millions of dollars is spent on probably just one API, uh, from there on, I think, uh, you have, uh, these monetizable APIs at the top, and then you have your services that, uh, kind of, uh, are at the bottom, you know, especially microservices where developers can spin up and, uh, uh, you know, change their architecture kind of over time. So I think that's the level of investment that goes from, you know, like very heavy to very low.
Uh, in general though, because like, you know, when you're building APIs and services, they're all connected to each other. We believe they all need to be managed in a central place, which is what we have built postman for. Mm-hmm.
Um, so ultimately, we'll, we all just have an AI assistant that will create the documentation for us automatically, and we'll all get better at that. We may have to maybe have another AI agent that validates the, whatever the first AI agent created, but are we entering some sort of an era where we're about to have, well, better documentation all the way around, starting with APIs? I would definitely say that agents will help you, you know, with the documentation, but I still, you know, uh, I think humans in the loop are gonna stay at each step.
I think the role changes to be much more of a reviewer, uh, and, and coordinator of agents versus being, you know, like, uh, totally handing it off over to an agent. We have seen that people, you know, like, don't like reading just, you know, the same type of, uh, language, you know, it, it, you know, it doesn't really, and, and the hallis hallucination problems still cannot not solved, right? So it's like the agent, if it doesn't really get the right answer, it, it doesn't have like an understanding of what is right or wrong in the first place, but it tries to please, uh, people.
So it kinda ends up hallucinating. So because of that reason, until like a more fundamental breakthrough happens, you know, humans are gonna be there, but they'll definitely be using agents to write more. They'll be using agents to, you know, uh, orchestrate more of these tasks.
I think one interesting area where I do see, uh, especially with API design and API documentation agents play a big role is like consistency, like across APIs and across different systems. That's generally been very hard, where every team, every product, you know, feels a little bit different. And I think one of the areas where we are investing is in making sure that agents are available for, you know, engineering teams to deploy, to make sure things are more consistent.
Um, so I kind of feel like, uh, right now, you know, people will definitely opt to use agents in areas that they did not want to do before, you know, versus areas that, uh, uh, they, you know, that are really challenging and require, like, the specific skillset that a human has. But over time, I think, you know, it'll be much more like of an orchestration of different agents working together. Mm-hmm.
Um, is there any correlation between documentation and consumption of the API we create these APIs in the hopes that people are gonna use them, but yeah. From your perspective, have you seen any trends where in the APIs that are better documented are just that much more widely used? Oh, absolutely.
I think, uh, I, I would say that I underestimated it, you know, starting out, like when I was a developer, like, uh, I think the amount of time I've seen people spend on just make, if, if an API is relevant, like people spend a lot of time on these activities and, uh, um, if you don't have a well-documented API, you know, people just end up creating a net new API. That's what kind of happens in engineering organizations. So, you know, part of the reason why a PS sprawl exists is that just people don't know that an existing API is available to do the exact same thing.
And we have, like, you know, lots of customers who have said that they were midway through a project, the project was falling behind, and then suddenly they stumbled upon like an API or, or documentation of an API that some, some other team created. And their project just went, you know, way faster, um, with, with very critical consequences. So documenting your API, making sure it's discoverable, making sure it's available for consumers, they can actually hit the API call and actually incorporate it at all, like, relevant things.
If you don't do any of these things and you just expect, you know, people to, you know, use, uh, uh, the a p on their own, I think, uh, they're just gonna fail. And even in the AI age, you see like how much effort, like, uh, AI companies are spending, uh, on, on their documentation. You know, it's not just like, Hey, here is, here is chat, GP d just go figure it out.
You know, there are developer portals, there are SDKs, there are videos. A lot of work goes in in making sure that people actually eventually incorporate APIs into their workflow, and it all goes, you know, uh, it all flows back to documentation. So going into 2026, what's that one thing you see people doing with APIs that still makes you shake your head a little bit and go, folks, we need to just be a little bit smarter about this?
That's a, that's a great question. Um, you know, I would have said that, uh, giving, uh, you know, like your entire API to agents and expecting them to figure it out is, is still kind of happening. People are still trying to figure out like, okay, how do these agents work?
How do I manage context windows? And right now, people are still using, uh, APIs that they're designed for humans. They kinda still feed it in, into, uh, agent apps and expect it to work.
I think people need to focus a little bit more on how their API design, how their a p architecture works. We have done that a lot at Postman, kind of as we have re-architected a lot, a lot of our platform to work with, you know, ai. I think people are still kind of, uh, you know, trying to ignore like the API problem a little bit and expecting agents to work, and, and I think that's how they just, uh, uh, you know, end up having failure modes, uh, whenever they ship like agents.
All right, folks, you heard it here. Our little digital world revolves around APIs, and yet maybe we don't give them enough thought. So be resolved in 2026 to hopefully fix that issue up enough.
Thanks for being on the show. Thanks for having me here, Mike. All right, back to you guys in the studio.
Welcome to Security Boulevard, the cybersecurity podcast from the FU Room group. Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard, YouTube channel, Textron tv, and all of your favorite podcast platforms.
Before we jump into today's episode, let's meet the panels stirring with Fernando. Hey, Fernando, it's good to see you. Hello, everyone.
Fernando Montero. I lead cybersecurity research for, for doing the, our research arm. And it's always a pleasure to be here and, and chatting with you all.
I just came back from a trip to South America, and I'm, uh, uh, I'm still a little jet black, but it'll be fine. Well, we're glad to have you back. It'll be back.
Save us last words. It'll be fine. It'll be fine.
And, uh, on lead guitar always is Mitch Ashley. Mitch, good to see you as well. Thank you.
And turn it to 11. You know, if you got 11, it's gonna be louder than 10. Absolutely Out.
So anyway, Mitch Ashley, I lead the software lifecycle engineering practice, which crosses over into some security areas. And so I get to work with Fernando real closely, and of course, Tom on the podcast and other activity. So great to be here.
And of course, I'm Tom Hollingsworth event lead for all things related to security at Tech Field Day, which is a part of the Futurum Group. Let's jump into today's episode. Now, depending on when you're listening to this, it might be old news by now, but, uh, vibe coating is real, folks, because Linus Torvalds actually used vibe coating to check some things in to the Lenox Colonel, uh, now he had some comments about it.
He said it did probably a little bit of better job than I could have on some of the things, but I still had to go back and reminded to do some other stuff, which has led to a little bit of a discussion as we're recording this, as to whether or not vibe coding is a real thing, or if it's just, uh, something that advanced programmers can use to kind of help lay the groundwork. But what really matters is the fact that no matter whether it's real or not, the security implications of what Vibe Coding offers are, I'm not capable of telling you exactly how deep they go, but luckily, one company that is, is Palo Alto Networks, and Mitch brought this up for our discussion today. It's something they're calling the Shield Framework.
Now, I imagine that it is a, uh, distinctly different round shield with a star in the middle that, uh, in no way can be traced back to Disney or Marvel, because that would be wrong. And we, we, we can't infringe on anybody's copyright, but I'm sure that, you know, some of the things they're talking about when it comes to separation of duties and keeping humans in the loop are things that we have preached quite a bit here at the Security Boulevard Podcast. So, Mitch, I wanna let you kind of introduce what Shield is all about, and then we can kind of, uh, talk about whether or not it really is the, uh, the optimal way to do things.
Great, great. Well, I think as long as they steer away from, uh, agents of Shield, they'll probably keep that. I was gonna make the joke, but that's okay.
Oh, oh gosh, I didn't mean to steal the joke. No, that's totally fine. You go, you go away.
Tom did, Tom did such a nice setup. I couldn't let it hang out there too. Oh, God, yeah.
So, well, first of all, kudos to, uh, Palo Alto Networks for putting this out there. You know, uh, vibe coding is a real thing. It's not, you know, not all codes gonna be created through Vibe Coding, but a lot of, um, citizen developers, if you will, uh, are using of course, vibe coding.
But so, so we're a pro code, so we're pro professional developers, and you mentioned Linus, who, uh, we no doubt about his coding skills. So it's, it's a real thing, and it's gonna be with us for, I think, for a long time. So, SHIELD stands for, lemme just kind of run through the letters.
S is separation of duties followed by human in the loop input and output validation, enforced security focused helper models, long one, there least agency defensive, which I think is like least privileges, right? Just from a, from execution standpoint. Defensive, tactical controls.
And then, let's see, oh, that's the last one. Shield got 'em all. So it's, you know, and my my just take on it is, is this gonna take over the world?
And everybody's gonna say, oh my God, this is what's missing. Now we can let vibe go, vibe, coding, go, you know, uh, on its own journey into the organization and not worry about security. Of course not.
But a lot of these are, I think, just mapping what we know as, uh, security principles to an agent kind of world to a agent led development type environment. You could apply this to, whether it's AI assisted or not vibe coded, but still AI centric development too. I, I wanna jump in here, Mitch, because I think you bring up a really interesting point.
Nothing in SHIELD is different than any of what we would consider to be best practices, right? Least privileges, giving people the minimum amount necessary to do their job, validating inputs and outputs so we don't get eaten up by them. These are all very good things.
I don't necessarily think that they only apply to Vibe coding and stuff like that. Now, is vibe coding probably the biggest risk that we face right now? Yeah.
Yeah. I would say that it is, because one of the things that we're gonna have to deal with over the course of the next several months, years is what happens when people with no programming background try to program. Because that's really what we're dealing with right now.
It's like, I, I, I have a, a 16-year-old daughter a couple years ago. She's like, dad, can I learn how to drive? And I said, sure, but there's a process, right?
I'm gonna teach you, sit behind the wheel where all the controls are, then we're gonna do it in a controlled area, like a parking lot that's empty. Then we're gonna start building up. You would not give my daughter access to Gemini and say, figure out how to drive, how hard can it be?
Drivers do it all the time Now. Yeah. So many thoughts floating right now.
I think that the, the, I agree with you that this is something that, uh, it's, it's coming. It's something that, uh, you know, in sense it's already here. And yes, we should do it in a, in a controlled manner.
I would like to shift, no, not shift the conversation, but I would like to point out something that there's a deeper philosophical discussion, right? I think it was who, who, who talks about, uh, code is a liability, right? Every code that you write is something that you have to maintain later, right?
And the other, uh, and I mentioned this because I came across an article the other day that talks about AI can write code AI can't do software engineering, right? And that is a, is a, is a phenomenal point that I think, uh, uh, we should keep in mind when we, when we look at the expectation, what we expect outta the vibe, deluge, deluge of, of, of stuff that's coming, right? Yes, it can be extremely helpful in some, uh, scenarios.
Like, I think, I think that it's revolutionizing things like prototyping and whatnot. Um, I, I, I shudder to think of production where we, which is why I think some of the stuff like, like, like the SHIELD framework is interesting because it's, it's catchy and, and it touches on the things that yes, they're not, uh, novel, right? But just let's, let's keep them, let, let, let's keep the problem contained as much as we can.
Well, it's, it's a good point. I definitely agree with you. It's, you know, software is about software engineering.
Now we have low-code, no-code solutions today that people create great applications from. Many of them, they don't go to it to work with, but a vast majority of them involve it. Even it is using a lot of those low-code, no code tools.
Same thing here. Um, the, the issue with, by coding, if you've, you know, we're talking to a security audience here. So many people may not have messed around with writing code with, with ai, but it's much like a session that you would have with Claude or, um, with open AI with kind of chat pt, where you hammer on that session, you have a se series of prompts.
After a while, it tends to drift because the context window is now too large to contain all of the conversations, especially when you're dealing with code, because you're generating a lot of text. And so it's, it's, it's a bit problematic just to go through a session and five code something from scratch all the way to the end in a session. And that's why you see vendors coming out with things like intent based development or spec based development.
We're kind of going back to realizing that you have to do a lot of, uh, really good prompt work. And I don't mean prompt engineering, I mean, specifications kind of prompt defining requirements, limitations, what the tech stack looks like, et cetera, to drive that. Now if, you know, if you know that already, that could be input to your vibe coding, but that's that part of that process of engineering, which is the upfront requirements design and, uh, how you want the code to behave and look, And Absolutely.
I I just wanna interject thing. Like I, I, I was chatting, uh, I think Mitch, just before on the prerecording here was, uh, chatting with the guy and I, I mentioned I was, I was coding something over the weekend and, and, um, I can read JavaScript really well. I can't write JavaScript really well, but, um, um, I vibe coded my way through something that I needed.
And one of the things that always struck me when, when vibe coding with if that, if you don't tell the, the system right in, in what software engineering instructions, you end up with a mess because, uh, um, not to make the, this thing too long, but one of the things we're doing is we're writing some, some, some JavaScript code. And then at some point I stopped and said, look, shouldn't we be refactoring this into separate modules? And, and, and so on.
And, and of course, they're very OB and they think, oh, yes, you're absolutely right. And then they recommended that, that we break it apart into different modules and so on, so forth. And then at some point, they said, I said, look, shouldn't this thing here be hard coded here?
Shouldn't it be an environment environment variable somewhere? Or, or, oh, yes, you're absolutely right. I'm not a great, uh, I, I'm not a software engineer by any means, but like these little things and that, and, and to your point, um, we need to help organizations understand this and then develop the right guardrails for, okay, if you're going to code, right, this is what you should expect.
And, and, and, and you're an expert at this. So, uh, uh, yes, this is very much the, the, the, the, the issue of letting this thing run amok. It'll make mistakes, it'll make, it'll use bad practice.
I, I haven't followed up on so much on the reports yet, but I think that there is a significant number of, uh, people indicating that the code that this has generated, it's still vulnerable code, it's vulnerable code at scale now. So, again, why this SHIELD framework is interesting. Yeah, I think that, you know, and some of the models are getting better about that, but it's still very much an issue around vulnerabilities.
I'm thinking about the, the shield framework, the, the kind of what they've set up here at Palo Alto. Yeah. Um, the one that really jumps out at me is enforce security focused helper models.
Um, and there's a good article that Mike Ard put up on, uh, security boulevard com. So check it out. We'll, we'll include a link in the description, um, about invoke an external and independent helper modules to perform SaaS testing, secret scanning, security control validation, blah, blah, blah, blah, uh, to identify vulnerabilities and hardcoded secrets prior to deployment.
So you could, you could say that's true for any kind of code, right? Um, and probably is, hopefully people are invoking, uh, routines or, or processes in their tool chain and their workflows that they do with software already. Same applies with, with vibe coding and using AI tools.
Now, I think it's gonna evolve to be a different little bit of a different form where security, uh, and things like observability really are, are baked in through more security guardrails that are part of the development process is just another linear step in the development process. But to their point, we really need some very good agents, very good mod modules, AI models, excuse me, uh, that are really good at security, not just testing, but generating and verifying code as it's being generated, uh, so that it comes out relatively secure. There's fewer things for scanners and other things to find.
I think an important point that everybody listening to this podcast needs to mark a note is what Mitch just said. They come out secure, not, we eventually make them secure, not we think we figured out how to get this working. Is that one of the advantages of having something that is generated by an agent or, or an algorithm, is that the things that we would normally do in a system to deal with error handling or deal with security issues are baked in when the prompt or the guidelines say that we need to do that.
Like, I can remember, you know, taking intro to programming, well, more years ago than I care to mention, um, and the fact that we went and learned how function calls worked, and we went and we learned how to iterate through loops. And then, and only then did we learn, oh, yeah, and you have to wrap all of them in exception handling, right? You know, if this fails, shel this message or something like that.
And I remember the person who was teaching me this was a programmer for the Air Force by day, and she flat out said, she goes, most of your code is gonna look like this. Like when you write the actual code, you're gonna have so many wrappers for exception handling that it's just gonna, it's gonna blow your mind because we have to be ready for everything that could possibly happen. And I think that that's one of the advantages of this, is that by giving it a narrow focus, like you guys have said by telling it, I need you to go in and iterate on this function, or I need you to iterate on this block of code.
'cause I mean, in, in what I mentioned at the top, that's exactly what Linus did, is he had it go over his code and say, okay, make this look better. And then it was having problems with the selection algorithm, and then it was like, I need you to work on this thing specifically. And that's a lesson that we've been teaching people in computer science for a lot more years than I've been programming, is don't try to eat an elephant, you know, all at once.
You've gotta break it down into sections. You've gotta figure out how to solve that problem. And then once that problem's solved, then you move on to the next problem.
And I think that that's one of the things that people who try to jump feet first into coding don't understand, is you've gotta break it down and you've gotta secure each of those functions. Because how many times have we heard that, you know, there was a security breach because one module of an overall program had a hole in it that we got away from us. Like we, we cannot, we, we, if we try to boil the ocean, so to speak, we will forget something that is just human nature.
It goes back to the point I made earlier. Code is a liability, right? It takes an experienced software engineer to know when they need code to fix something, right?
Uh, uh, there, there is a, um, of course I'm gonna bring in economics at some point, right? The, uh, there is a, uh, it's in economic, it's known as the Jevons paradox, right? Which is this notion that when something becomes cheaper, right?
We actually, we, we would expect that, uh, uh, when, when something becomes more efficient, we would expect less usage of it. But actually, no, we have more, right? Because now you can do more things more efficiently, and it's being shown all over the world.
I think the original definition started with coal in the 1860s, but it definitely applies to cold now, right? In this age of vibe coding, it's not that we're fewer software engineers, we're gonna more software engineers that those software engineers are now doing higher level, more efficient things, right? But I think you brought up a phenomenal, uh, point, like when you were teaching what to do, and, and you were saying like Linus was, was iterating over a function, Linus is an experienced, very experienced software engineer, right?
Give that software engineer a tool like vibe coding, and you get tremendous amount of things. Give someone who is an, who's not a software engineer, the expectation of, Hey, I'm gonna vibe code my way through an entire application, and I'm gonna post that. And it's gonna be something that, uh, eventually is gonna have, uh, it's going to have, uh, users and it's gonna have passwords, and it's gonna have credit card details and, and, and whatnot.
And you can see where this is going, right? So, uh, it's very, very important for us to get this right. We're not gonna get this right completely, of course.
But it's, uh, uh, it's, it's so, so critical that we do, sorry, I'm ranting as usual. No. You know, one things I would recommend, Fernando, is, and I said to our audience or listeners, you know, maybe many of the folks are not developers or, or done a lot of development, this is a good chance to get exposed to it.
You know, I'm, I'm very much kind of a do it learner, right? That 50% is like going and researching it, and the other 50% is doing it and figuring out how things work and how to secure it. And you could pretty easily do, do some vibe coding, you know, with Gemini, if you have a, a Google account or with Microsoft Tools, visual, uh, visual, uh, studio Code is, is free.
And you can use a number of, uh, models to do this. Either Claude or you could use the open AI model that they're all, they're very good. Um, go, go write some code.
Do, do kind of a function, create a little utility for yourself. Maybe it's processing some files on your file system. Maybe it's, it's, um, you know, taking, uh, flagged emails or labeled emails and doing something with it, or sending you an email summary of it.
Something like that doesn't have to be super sophisticated, but the point of it is, is you'll see the process of, oh, well, I, I know it's not only just writing the code that that's gonna be generated by the model. It's, I need to set up an API to get to this service in my mail system, or in Google, or, or the directory or whatever that I'm using. How's that being secured?
What, what kind of settings are are available to that? Because if end users are doing this, non-technical folks, hmm, okay, that might, might be interesting, might be a problem, might be something we wanna know more about and dig into further. Um, what are some of the privileges that, uh, are inherited just because you're using your own account, your, your company account as part of the coding system that you're building together.
In other words, take the in context what it means, an application, not just generate code ton. And you may never pick it up again. You may say, Hey, this is really handy, I might wanna do it, do some things with this.
But you'll start to see for yourself where some of those exposures are. And, and picking up on that, I, uh, if you are a cybersecurity professional who is not as, as Mitch said, involved in in coding, there are many examples within what you do on a day-to-day basis where you can apply some of this, perhaps your, uh, sim uh, already have an enrichment function, but if it doesn't, would it help you to write one, Hey, I, like Mitch said, I can go in and learn how to query from an API query the sim, get the data, or then potentially query what your, what your threat intel source is gonna be. Pick that up, mumble them, send it back or, or whatever.
If you are in GRC, can I automate the collection of artifacts that we're gonna use for validating compliance? Or, or can I use even better? Can you take the, the, uh, can you take the artifacts that you're, that you're using, and then you can play around with large language models to perhaps interpret that.
And, and, and then you'll see what the, that the output of that large language model may not be exactly what you wanted, but that's fine. Like you're experimenting with that. Uh, so I don't, I cannot think of an area of cybersecurity where there isn't some little function, some little, uh, use case, uh, where you can't use a professional, uh, experiment with it, right?
Like, like, look, perhaps it never see the light of day, but it got you a little bit further, right? Lifelong learning people lifelong Your head in the, in the headspace, for sure. And that one of the sort of fallacies about agents, quote unquote, is that the agents aren't just prompts, most agents are actually have a lot of code involved in your regular software code along with some prompting into the LOM.
So a lot of the processing still happens in regular code. Um, so when you hear people are developing agents, don't assume that's just a prompt that you've gotta worry about prompt injection and how to make that more secure, efficient, et cetera. There's code involved.
There's code, and there is a spectrum of things, right? I mean, there are things that are ag workflows and there are things that are agents, right? And, and they're different and, but all of them involve code.
Absolutely. I think that the, and, and Mitch has done phenomenal work on, on, on tracking how some of these things should be secured. Like, uh, uh, he's done some work on, on on the protocols and so on.
So I highly recommend people. So as, as you, as you listen to us, as you, as you watch us road, check out the stuff that Mitch has put out on, on protocols, for example, top notch, Well, I'm my public in hiring you, you're Get the pleasure of reading or sometimes peer reviewing that stuff. Oh my God.
Yeah. We do peer review each other's stuff a lot. It's awful.
Which is great. Same back to you YouTube. Thank you.
Doing great work. You fantastic work. Yeah.
Speaking of putting things out there, uh, recently we had, uh, text Drunk TV's Predict 2026. Uh, if you didn't get a chance to tune in, make sure you head over to Techstrong TV and, uh, check it out. It, it was great.
But now that I have two of the people who were involved in the making of that, I wanted to give you guys just a few minutes here at the end of the episode to give me one of your security predictions for 2026, because I'm kind of, I'm fascinated to see where people think security is headed in the next 12 months. Mitch, I guess I'll start with you. Uh, what was one of the things that you think, uh, people are gonna be seeing in 2026 from a security perspective that they need to be on top of?
Well, I think the DevSecOps folks will be pleased to hear, and this is both the security and the software side of it is shift left is going to give way to something called continuous guardrails. So we've really struggled with shifting left. Um, it makes a lot of sense to do things earlier in the process.
Um, but we still kind of are left out of the code writing process, and we're leveraging scanning to actually perform a lot of the security for us, the what's happening in the market, because AI is moving so quickly, everybody wants to be part of the new stack, the platforms that that AI and agents are being built on. So you see observability companies, security companies, creating agents, um, or specifications, things that can be added, uh, even into like when AWS announced their security agent, other, other companies were partnering along with that so that you could implement guardrails as part of the, uh, development and execution environments. And I think that's our hope for the next evolution of DevSecOps Shift left.
We probably won't say shift left that much anymore, but I think that's where we're headed. Yeah, I, oh, yeah. Uh, I have, I have a, uh, a love hate relationship with predictions in the context that, uh, it's great fun to do them.
Uh, we should always be checking to see where, well, did we get them right, did we not get them right? Okay. That's, it's, it's a fun exercise, but I always think that part of our role as analysts is to help understand these broader trends and then just highlight, okay, you know, what this kind of thing is more is happening more often.
Is that a prediction? I'm not so sure. Like, uh, uh, uh, anyway, I think that the, the ones I, I, I, if you, if you watched our session, you saw some of these, but I think that besides the ones around, yes, more agentic, ai, more, uh, um, particularly particular focus on identity in.
But, um, outside of that, I, and this, this comes up a lot in conversations, is I think that we are seeing, and even ties back to our vibe coding conversation, is that the pain that organizations are, are, are feeling like when, when, when we talk to them is, yes, all of this is going on and all of this is important, but all of this has to work together, right? It, uh, so one of the things we're calling out is that, okay, great, we're doing all of this effort in releasing new functionality in whatever field or whatever format it, it has to integrate well together, right? So I I I'm hoping that 2026 is the year where we do focus a little bit more on the integration effort between things, right?
Uh, I, I, one of the visuals that stays with me is, um, I'll, I'll give props here to, um, uh, F five. They have that, that decision, the ball of fire, right? Which is the, the overwhelming complexity of a modern planetary scale application that touches content delivery networks, that touches, uh, uh, uh, serverless functions, that touches, uh, actual VMs and, and containers and Kubernetes and, and, and all over the place supporting that complexity requires tremendous amounts of integration work.
And I think that, uh, one of the things that the, that we're calling out is, is this notion of how are we going to support that kind of integration? I'm sorry if I sound fluffy, but, uh, it's the, um, it's the, the, one of the things on my mind. The other one I'll just, uh, is that as we focus on ident, the two things most important I see are identity and data, right?
And as we focus on data security, right? We, we called out this, this change from backup and recovery to cyber resilience. And I think that we're moving more towards more integrated data security platforms and those data security platform, data security platform functionality, right?
And that functionality is covering structured data that ties to the API that ties to the code that ties to unstructured data. Again, we can tie LMS and so on with, uh, resilience, like what we, what we used to call backup and recovery, right? So we're seeing this, this merger of, of support for unstructured data support, for structure data support for, uh, um, primary storage and backup storage.
We we're seeing these things kind of merge together. And, um, it's interesting. I mean, uh, whether that be, uh, whether that be coming from people like, uh, like, uh, or, or Veeam or, or Commvault and, and, and, and, and others, right?
That's, um, that's a really interesting evolution for 2026. I think that how, how this is, is merging a little bit more. So I'll jump in because I didn't actually get to give any predictions for the Predict show, but, um, I, I'll be a little more concrete than Fernando.
Um, I think that 2026 is gonna be a banner year for security startups related to ai because companies are, that are bigger, are too busy trying to figure out how they're gonna use it instead of how they're gonna integrate it into their products. So they're gonna overlook a lot of things, and small startups are going to make bank when that time comes, because the other thing I think that's gonna happen is sometime in the middle of the year, we are going to have some kind of AI data leakage situation that is so massive, and also so legally far reaching that a lot of companies are going to have to make some hard choices about how they secure their data and how they've integrated AI into all of their products. And, uh, that may not sound like a, a concrete thing, like, I'm not putting names to faces, but I think that we are definitely neglecting a lot of the pieces that are important for us to keep everything safe at the, um, behest of trying to make the, the line go up.
And, and once that happens, it takes something really earth shattering to make people realize that line go up is not the only purpose of a business. And so, I, I think we'll see that this year because we've, we've missed it too many times in the last 24 months. Uh, I, the, the, the odds are not in your favor there.
Um, speaking of which, um, yeah, we Should, we should do an, we should do an episode on that, by the way. We should talk about, so, uh, when asteroid, when the asteroid is going to hit the earth, then everybody will do something about what security, right? And do does those, those things ever happen, or they rarely do?
I'd love to do a, an episode on that. That'd be fun. Well, Let's, let's leave it up to the audience.
Do you guys wanna see an episode of about what happens when disaster is imminent and now it's suddenly time to do security? If you do leave a comment on this episode, and we'll put it on the, the lineup, but it'll, it may have to be a couple of episodes out, because my two cohosts are super busy with a lot of stuff that they've got going on. Uh, Fernando, what are you working on that people should check out?
So my, I'm, I'm writing a report right now. Uh, it's a little, it's a little later than I thought, but I'm writing a report on cyber systems, right? This, uh, I think that there is something to be said here on the, the evolution of I what we used to call IOT or OT security.
I think it's evolved, and I think it's the perfect, I I shouldn't say perfect. I think it's the, the, the final level boss, if you will, of securing a lot of things. It brings in the complexity of regulatory frameworks.
It brings in the complexity of a massively complex supply chain. It brings in the complexity of, uh, severe constraints on operating environments and end user behavior and, and, and all of those things. So I think it's a, it's a very important area for people to grow their, their, uh, uh, their familiarity with support, those kinds of use cases.
So that's my next report. I'm, I'm, I'm deep into it. And there have been some massive acquisitions in the, in the space.
I mean, uh, uh, Mitsubishi and the film and, and ServiceNow and Arm is. So it's, uh, um, it's really interesting to see, uh, what's going on here. And Mitch, what have you got going on?
Yeah, well, juggling lots of things, but the thing that's, uh, foremost in my mind is we're putting the final touches on the, uh, first half is 2026 data set, set for the software lifecycle engineering practice. All that to say, it's the latest data that we've gathered from decision makers around people who were investing in AI to using, using IT organizations as well as development tools, operational tools, uh, some of the security tools, not, not as in depth that, that, uh, Fernando covers, but it touches on that a bit. Observability is a big aspect of it.
It, it's, you know, exciting time to be in the industry and this is one of the biggest shifts I've seen in spending in the IT realm. And I can't remember, I mean, it, it's kind of like the cloud era, but we're compressing three years into three months. It's really been a pretty, pretty markable change.
Alright, well, we want to thank everyone for listening to this episode of the Security Boulevard podcast. Remember, if you like this conversation, we'd love it if you subscribe on YouTube or in your favorite podcast application so you don't miss any of our episodes. We'd also love it if you'd leave a rating and a review and a comment, because all of those things help the show grow and reach new audiences.
com in the Future Room Group. com, the Textron TV website, or our new favorite tech strong TV app, which is available on Apple tv, Roku, and smart devices all over the world. Make sure you're following Security Boulevard on our socials, like X, Twitter, and LinkedIn.
Just look for security. BLVD. We thank you very much for tuning in and we'll see you all next week.
Hey everyone, welcome back here to Techstrong TV and our continuing coverage of AWS Reinvent. You know, one of the great things about Tax Trunk being part of futur is we get to kind of pick the brains of some of the futur analysts, you know, the industry well-known analyst, uh, about what's going on in the world of tech. And especially when we're at an event like this.
We're gonna do two segments here, each with two of the FU analysts. The first segment is gonna feature Brad Shiman and Fernando Montenegro, uh, of fu I'm gonna give, I'm gonna let each of them kind of introduce themselves though. Brad, if you wouldn't mind, why don't you kick it off.
Sure. Introduce yourself. Thanks, Alan.
Hi, everybody. Brad Shiman. I am an analyst with futurum, as you noted.
Uh, I, I look at data intelligence, analytics and infrastructure. And I, I'm a software guy. I love software developments and all things databases, so I'm hoping we can, we can chat about that a little bit today.
Absolutely. And I'm Fernando Montenegro. I lead our cybersecurity and resilience practice and, uh, the gray hair comes from being around cybersecurity for many, many, many years.
There Was a time I had gray hair in cybersecurity too, when I had hair Fernando's just outta high school. Yes. Oh yeah, exactly.
Yeah, exactly. And yeah, I've been covering cloud security for a long time and it's been a pleasure to come to a Ws reinvent for a, for a few years, not the, the full 14 that they've had it, but, uh, It's a good show. Yeah, It's an amazing show.
Yep. Well, you know, an observation. I'm glad you brought it up.
Well, let's just jump in, of course. Sure. An observation I had today, and I wrote about it in an article I put up on one of the text drunk sites.
Think about coming to AWS reinvent five years ago. Mm. What would you be talking about S3 Lambda serverless?
You'd still be talking about security of bit, but you would be talking about cloud. Yeah. Cloud nitty gritty, cloud native, managing my Kubernetes EKS.
Right. Securing that stack. How much of that do you spend about here today?
So if I transported you from five years ago to today Yeah. Would you believe it's still the same company, the same industry, the same? Uh, absolutely.
I, I feel, I feel like we're still in that era because honestly, all of those concerns are still here. They all inform what AWS is doing. They are all, they are still all in in the cloud.
And you can hear that in Matt Garmin's, uh, keynote today. 'cause he, he did not mention when he said, if you wanna get the most out of ai, you're going to need to bring data to the ai and to do that properly, you need to bring it to the cloud. You know, that's Loud and clear everything.
Yeah, yeah. No, I mean, it's kind of funny in that we haven't, I just feel like there's less of an emphasis on cloud or it's abstracting behind the ai. That's it.
So, So, so here's the thing. Point of order. Five years ago, we were in the middle of the COVID pandemic.
Yes, you were right. We we would not be doing maybe four. Yeah.
But, but, but point taken. Uh, I think that, um, to, to, to Brad's point, the cloud is foundational to do this. Yes.
And it's funny that you brought up abstraction. I have a, I have a thing that I talk about that, uh, go back to high school calculus, like high high school math. Mm-hmm.
The limit, like the limit for cybersecurity as time goes to infinity, to me, is anti-fraud. And what I mean by this is that we abstract away technology, we abstract away a lot of this, and then we help businesses and buyers and sellers and whatnot talk about higher level, uh, constructs. Right.
And what, and it's kind of what we're doing here. It just so happens that I'll be, am I the first one to bring up the AI words? I think I am right.
So, uh, uh, dance Won't be the last I, but, but, but that's the point. I think that we are abstracting away some of it, but to Brad's point, it is always there. And actually, one of the security announcements had to do with, uh, uh, ECS, not the agent one.
Oh. Had to do with ECS and EC2. Right.
Which was the, the, the, the, the, the guard duty, uh, support. Right. So it, I agree with you that that's not what we're talking about as much, but it's here, it's always, it's always there.
It's, it's always there. And, uh, whether it's, whether you're figuring out instances that you need, whether you're figuring out what kind of database do you need, there were announcements around that. S3, there were announcements around S3 tables, I think.
Right. Uh, and so yes, you are correct that, that the topic has shifted, but the technology is Underlying, I Always Hear, you know, the thing that powers our, our little market is that Race to Zero, trying to beat Zeno's paradox to, to always go a little bit further closer to getting there. And we never get there.
And that's why it works, because we're always inventing new ways to abstract away problems. Yeah. And to find new, interesting ways of applying this technology to solving problems.
And I, I feel like that was really, um, on display today when we talked about Amazon Nova Forge. Yes. Which I would love to spend some time talking about.
We, We've spoken about it a bunch today. I'd love to hear your thoughts on it. Yeah, I, I have some Thoughts.
It's, it's a renaissance era for, for the, you know, more traditional foundational, large language model. It's like a, a return to form I'm calling it. Because instead of, like, we, we've spent so much time over the last year in investing in frontier scale models, uh, like Gemini, like Claude, et cetera.
And, you know, they do a wonderful job. And when they first came out, if, if everyone will recall, we use them for POCs. And that was about it because they were very flexible.
They could do a lot of different things. They had a great knowledge base they could work from. Um, but you, for production, you went with an actual model that you fine tuned that you built.
Yes. And we kind of went away from that and we said, let's just make them do it all. And, and I think what we learned is that that costs a lot of money.
Yeah. And so, you know, if you're gonna do ai right, like, like Matt said, you want to bring the data to the ai and that's what they're doing with Nova Forge, is they're really trying to make it so that we actually do what we started doing a few years back in fine tuning these models to bring the data to the ai. So I, I think it's a, it's a return to forum and I, I applaud them for focusing on it.
No, I, I, so it's not anything I've seen before, which is interesting. Yeah. And, but I'll tell you something.
Two, two and a half years ago, we're gonna have Mitch Ashley on, in the next group. Mitch came to a hackathon. We did down at Techstrong around what we called operationalizing ai.
Yeah. Yeah. And we had people like Patrick dubois, who founded the DevOps, came up with the word DevOps, uh uh, John Willis.
Oh, he's great. We had a lot of great people who were very, you know, early on in the DevOps movement and they were working back then Yeah. On, on Rag and on vector databases and s SLMs and stuff like that.
And to me, it be, I'm not an analyst, but I did stay at a Holiday Inn Express last night. To me, it was obvious that not every job in AI required a, a truly frontier size LLM No. As a matter of fact, it might be the wrong tool In a lot of cases For a lot of jobs.
It's the Wrong tool. I need. Yeah.
I need a scalpel or a, or a rifle, not a shotgun. And I, I, I, I'll, I'll go one deeper. And that's one of the things that I was looking forward to coming here and having conversations and, and we are having those, is that I would argue that, that the lms Right, the language models in many cases, fine tuned or not right, may not be what people need.
And this is one of the areas that, yeah. Uh, this is one of the areas where, like, I, I, I, I was really excited, I'm really excited about the field of neuros symbolic ai. Mm-hmm.
Right? Which is the, you're, you're bringing the, the, the neural component that, that from the LLMs with the symbolic reasoning. Right.
And, and AWS has been doing a lot of work on that. So it was really interesting to come here and see that. But anyway, but the, the, the point being that the way that we are going to, to improve those models is by the fine tuning, and in some cases, by using these more neuro symbolic components.
And so one of the things that I was excited about, the announcements that the, that they now have a, uh, a verifiable policy language on the agent core stuff. Yeah. Right.
That's a step in the right direction. I really like that. Well, it's responsible AI and ML lops as you're, you're talking about.
Yes, Yes, yes. It's part and parcel to that. And so I, I feel like they have to, they have to do that.
And if you look at all the components of Agent Core, you can see it starting to look like an ML lops platform more and more. That's for agents, not just for select models here and there, but for orchestrated, Let me, let me ask you a question on this. Have you guys seen the letter that was circulated last week?
Like a thousand AWS employees signed on to calling for responsible Really Moral Yeah. Ai. Wait, this was Amazon?
Or was it meta? No, I believe it was AWS Okay. Interesting.
Interesting. Yeah. Well, you know, it's, it's, uh, it's very much, and we saw it actually the beginning of the keynote this morning.
The very first words on the screen were why, and the, the response was, why not? And that's the era I feel like we're in right now, is, well, let's just dam the torpedoes and see what happens. And I, I don't think we can do that.
No, it's, it's, we should not be doing that. And yet I've been, because it's all about time to value. And we've found with transformer models in particular, that we can shortcut that time to value, but we can't shortcut the hard work.
And that's why things like fine tuning are so important because it's another tool in the toolbox that gives you, at the end of the day, a model that actually, as you said, has a scalpel to do what you wanna do, do it performance, do it in a secure, safe manner, and do it in a way that you can actually make some money. Absolutely. Lemme bring up another thing.
You know, coming in yesterday at the airport, I was reading all the, the electronic billboards. Yeah. I'm a sucker for them, but I saw one from Databricks that really caught my eye.
I don't know if you saw this one. Our AI agents don't suck. Remind me of the old, you know, we suck less philosophy Suck.
Software is alive and well today. Exactly. Yes.
Yeah. Well, now it's called Suck Less Agent ai, maybe. Oh, come On.
That's never gonna happen, But, Okay. It's like gen. Yeah.
It's the antithesis of Suckus software. It's like whatever you want it to do, it'll just, It'll do it for you. Yeah.
Just do it for you until it doesn't. Yeah. Until it doesn't, until you check clears.
Anyway. Uh, but you know, we, we certainly are in this, Brad, you're right. You want, we could, we you want an agent?
I got an agent Streets In New York's like that, but I got an agent for you. But we're also seeing sign a kind of a, a Cambrian explosion, if you will. Mm-hmm.
Sure. Right. Like, I, I had a, a fellow we interviewed up here this week, or today rather, who comes from, um, uh, s uh, agent AI for s se not for SEO.
For SRE. Okay. Yeah.
Sounds great. What a great idea. We need that, that's something we could do.
Of course, he's one of six A AI for SREs that are here. Uh, may I say seven? Because, because you know of what to No, no, because one of the announcements today was AWS themselves AWFs themselves.
Right. And now Check your watch, because we might have another one, another One. But, but, you know, but that's not unusual for, that's their model.
Look, we're gonna give you 80% for 20%. Yep. That's right.
That's a lot of the AWS model. But I, I do think we are in a, you know, a Cambrian explosion of life, if you will, of ai that some will, some will make sense three to five years from now. Yeah.
And some will say, what were we thinking about 12 eyes and six legs? It just, you know. Well, a lot of it's gonna disappear because as we saw early on, when you had a lot of wrappers, as you'd call them, around chat, GPT, are they in business anymore?
No. Because you don't need them. I'll tell you what else I think might disappear.
Hmm. Everybody and their mother has an MPC server. I have one right now.
Yeah. Yeah. I mean, do we, why can't we have an open source one that we all kinda standardize on?
And this is the open source model. Right. And then build on top of that, build functionality.
Like, but that's on top of, but that's What MCP is, right? MCP is by itself, like an open, It will evolve into what you're talking about, Alan. Yeah.
I I think we don't need 10 different MCP service. No, there's an X-K-D-E-C. Sorry.
XKCD. Yes, I know exactly. We need a standard next panel.
We have another standard. Yeah, Yeah, yeah. We have 13 standards.
We can't do it. We need another one. We need the single one.
Now there's 14. That, that is the way it goes, isn't it? Yeah.
Yeah. I, Fernando, I gotta talk security with you a little bit. Of course.
So I had another fellow I interview today, smart guy, zest security. Okay. I don't know if you heard of these guys.
The founder there came out of, uh, oh, they sold to Palo Alto Cider, remember Cider? Yes. Yes.
Security. Yes, yes, yes. He claims zero.
They could get you down to zero vulnerabilities using ai, agentic ai. That's Bold. I, I I, I, I told them, I said, say that again for the people in the back who don't Hear me.
Yeah. I think that there are, um, there's multiple ways to interpret zero vulnerabilities. Right?
Okay. In the context, like when we have conversations about vulnerability and security, the first question I want to ask is, okay, am I talking to an ops team or am I talking to a dev team? Very Different measures.
If I'm talking to a dev team, zero vulnerabilities means one thing. If I'm talking to an ops team, their vulnerabilities means something else. So in the context of, I think they may more on the Developments.
No, he, so I agree with you. I mean, you and I both know, I have a security background. He was talking about the security team in ops, like tra not ec vulnerabilities.
Like true vulnerabilities. That's true. And, and, and, and, and that, and that is, uh, um, like, again, I, I applaud the, the, the, the, the, the gusto.
But I, I struggle with it because this is the trick that, that security teams are learning the hard way. There are vulnerabilities that you don't fix because it's too expensive. Yep.
Right. Because given the risk, Well, it's a manage, it's a risk management. It's A, it's a risk management conversation.
And then, like, like here, for example, here we are having a wonderful conversation. Uh, some of these doors are open. That open door is a vulnerability, right?
Say Windows 10 at the moment. Should we talk about that? Oh Yeah.
It's on Windows 10. We might as well talk Windows 98. That's a whole nother story.
But, but, but, but I think, but you know what your reaction, he said, that's exactly what we hear from CIOs and CISOs. And then we show them. I'm going to introduce you to this gentle, I'm happy to chat, and I'd have to hear you talk.
I'm happy to. Yeah. Guys, I gotta wrap this little portion up 'cause we've got more analysts waiting.
Sure. Hate to keep analysts waiting. But let me, let me pose question to each of you, and, and we will go with that.
Brad, if I had to ask you for one story, that's the big story at Reinvent this year. And we've, we've skirted on all of them. Yeah.
But for you, what, what's the, what's the, you know, the key takeaway? Well, for me, uh, I would say that it is, you know, the, um, Nova. Um, but I'm not, I I, I want to actually instead pre pre, you know, get ahead of what I know Mitch is gonna talk about, uh, when it comes on.
And, and that is Kiro, and that is Ag agentic development. And the fact that on stage today, we heard from Matt that the company has committed itself to using this platform to develop their software in-house. That is very much, you know, a bold statement.
Yeah. Because I, I, I feel like a lot of these companies try to sell us on Yeah. Yet another agentic, IDE, blah, blah, blah, blah.
But if they really put their money where their mouth is, well, a s is trying to do that. So, we'll, I wish them luck. And I, I think it's, it's gonna be interesting to watch.
One last thing for you. What wasn't on your Bingo card coming out here? Uh, well, you know, I wanted to hear more about data, honestly.
Uh, and I, we, we didn't have a lot of of announcements about that. So my Bingo card was all filled with, with like slots about what's happening with their various databases. I didn't get too much Of that.
No, I haven't, I actually haven't heard much at all. No. I would've loved to have heard something about a semantic layer, for example, because every other vendor, we mentioned a couple of them with Databricks, and, uh, right now, if you're gonna do a lot with ai, if you're investing in a semantic layer, yeah.
But we're not really hearing that from AWS So I, I would encourage them to, to really kind of rethink that in their go to market coming up in the next couple of months. Fair. I wonder, well, I don't want to be Doctor Evil, but I wonder if that means AWS is working on their own semantic data layer.
They have been known to build internally. Yeah. Yep.
Fernando, let me come to you. What's your big story? My big story comes in two pieces.
Uh, you know, how we always talk about security for AI and AI for security, yeah. Third one being security from ai. Uh, I think that we saw the announcements today, the security for Agentic and the agentic for security.
For security. And the big story for me is that on the security for Agentic, it's how they've woven the conversation of Bedrock has security, bedrock has it built in, bedrock has it, and, and then, and then you take the policy agents from, uh, the, the policy language. Now an Asian core.
So I think that I, I encourage my security colleagues to, as you are thinking about Gentech, you are, you have to look into what security is coming from the platform. Yeah. And the other big story is agentic for security.
So just like the DevOps agent there, there is now an announcement for a preview for a security agent that is going to be doing a lot of the, Hey, let me fix that code for you. Now, the devil in the details, right? Uh, but what kind of things is it going to fix?
And what kind of things is it not going to fix? But importantly, what's the, the, what's the play the interplay between a true security, uh, uh, professional doing a pen? Because it's going to automate pen testing.
The theoretically, theoretically, sorry, forgetting English. Uh, where do you draw the line? So if you're, if you're a developer and I'm a security, uh, engineer, what have you, and then do I now code my policy at my company to say, look, as a developer, you are, um, uh, you're going to do multiple things for security, and you are going to already run a pen test, and then I'm just going to test the results of the, of that pen test.
Right? Or am I going to it? It's great that you ran a pen test, but, you know, like, trust, Trust, Bud verify.
I'm gonna do it. I'm going to do it too. So I think that that's the next level of conversation.
So I think there'll be a human in the loop conversation there. Absolute. Let me play devil's advocate a little bit though.
Sure. The DevOps agent to me is an alert monitoring tool. That's what it sounded like from what I heard.
Oh, I don't know. The, the advertisement we saw was The advertisement was one thing, but when you read, when you read, yeah. It sounded like alert logic to me.
But, okay, we'll, we'll go with that. Well, actually, let me ask, lemme tell you, uh, what I feel that is going on there is, uh, they're not gonna deliver it today. 'cause they're gonna build the preview.
It's a preview. Yeah, exactly. And, and what we do see them doing is working on long running agentic processes.
They talked about that a lot today, as a matter of fact. Yep. And what else is, you know, building safe software, then a long running process of monitoring your code base, testing your code base.
That seems like what it ought to do. Yes. That is what it ought to do.
You know, there's an old saying, I learned in law school about what you do do and what you ought to do. That's the difference, dude. You're not gonna get caught doing Your comment on security there.
I gotta tell you the truth. I had a deja vu to 2007, the cloud, I can't put my stuff in the cloud. It's not secure.
Don't worry. We built security into the platform. We keep, We didn't buy it then.
I don't know if we buy it now. Yeah. We keep moving the layers up.
I Think that, that, it depends who you are, right? If you're a big company, maybe you question that. If you're a small company, you're never going to have provide That until, until, well start that, And then it gets a little bit better.
And, and, and I go back to my thing about abstractions, right? We've now given developers more capability to do more things. So instead of, you know what, that budget for a pen test that was going to find 50 vulnerabilities, and out of those 50 vulnerabilities, 35 of them could have been found mm-hmm.
Automated in an automated fashion. Now, perhaps that same budget can focus on more critical vulnerability. Just those 15.
Yeah, Exactly. Because we've asked you to do this. I'm optimistic, Always the optimist.
I, I'm, I'm, I'm, I'm optimistic. We, we are. It's, it doesn't have to be perfect, right?
It doesn't have to be zero. No, nothing is perfect. It's never, we're never gonna get to zero.
We're never gonna get Know that. Right? That's risk Management.
Risk Management, and said zero. I almost fell outta my chair. Yeah.
Anyway, Brad, Fernando, thank you so much for coming up here on Text Drug tv. Thanks for having us. Appreciate a pleasure.
We'd love to have you. You know, we do these remote, you don't have to come to Vegas to see us. And, and may I remind you that we are kind of halfway through, so there's, there's still, There's still there.
We'll be here tomorrow at the next Day. There at least six more keynotes. Yes, there Are.
Yes. And, and, and there are, and, and, uh, just, just to, uh, sidetrack a little bit, one of the things that I was really interested in is the, this whole age agent and, and, and, uh, and, uh, neuros symbolic stuff. But coming alongside that, there's other things going on.
Like, one of the areas that's super interesting is like confidential computing, right? Yeah. Oh, that's, we we're seeing from a AWS do some interesting things there.
So let's keep talking about this. And, and, Well, now, now you invited yourself. You know where we are.
I have no excuse. We can do this remote. Yeah.
Alright. Hey guys, let me just remind y'all, Futurum does a thing called the Futurum signal. It's, it's the report that we've put out in, in different practice areas.
Fernando's done one. Brad's done one. The next two folks that we're gonna have on have done one, unlike a lot of other analyst firms, these reports are available to you.
You could go see the whole, I think, virtually the whole report, right? Yes. Yeah, yeah, yeah.
Sign Up. It's an amazing look at using ai. If you looked at our live coverage earlier, Daniel Newman and I had a great discussion on this.
I encourage you to all go look at Futurum signals, check out what's in there. This isn't last year's information given to you six months after the fact, right? It's, it's the, it, it, I don't want to say it's up to the minute.
It's not continuous yet, but it's a lot more current than the 18 month old stuff you may have been used to. So go check out FU terms signals. These are the guys behind it.
We're here at AWS Reinvent for text Trump tv. We'll be right back. We've got two more great analysts I want to introduce you to.
Welcome everyone. Thank you for joining us. Today.
We're talking about readiness and AI in the mainframe environment. My name is Mitch Ashley, and I lead the software lifecycle engineering practice at the Futureum Group. Today I am joined by Anthony Desaro, who is Senior Director architecture of ai.
And with the BMC, let me try that again. Not the BMC. Dang it.
My bad. Alright, starting at 3, 2, 1. Hi, and welcome.
Welcome to our conversation about AI readiness in the mainframe environment. My name is Mitch Ashley, and I lead the software lifecycle engineering practice with the Futurum Group. Today I'm joined by Anthony Desaro.
Anthony is Senior director of architecture for AI with BNC software. Welcome, Anthony, Mitch. Thanks for having me.
You bet. Great to have you. Now, this is a three part series.
Our first part is talking about AI readiness, and the series is, uh, sponsored by BMC software. We appreciate the folks at BMC, uh, putting this on and putting this together. So, Anthony, let, let's jump right in.
So, we hear a lot about organizations needing to be AI ready, especially for the mainframe environment. At the earliest stage, what does AI readiness really mean? Yeah, Mitch, this question, I can't tell you how many times I get this, whether it's I'm speaking at a conference or customer visit, this always comes up, you know, how do we get going?
How do we, we get started with that, and it's so foundational into a successful journey with ai, but yet it's a step that you'd be surprised how many organ organizations just kind of ignore or are not even aware there is a readiness, uh, you know, playbook that they, that they should be, uh, following. So it all boils down to, uh, from an organization perspective, you know, how do we roll in AI technology? How do we use AI technology safely within our organization?
How do we put guardrails around AI for, uh, you know, for protection against data? Uh, for example, you know, uh, from a, from a legal perspective, you know, uh, what policies and governance that we need to have in place. Uh, we bring AI into our organization, and there's all kinds of challenges around that.
But at the end of the day, you know, that's one part of the organization's gotta deal with that. And then it comes down to the individual, you know, groups and, uh, departments within an organization on how they want to utilize ai. So the first really good step in that journey is looking at AI as an advisor.
Mitch, really look at it as like you would bring in a human into your organization, you know, based on their experiences and, and their background to have a dialogue exchange with them about whatever challenges that you may have. And you're gonna lean on that person for their insights and guidance based on their experiences. Ai, that's a great first step with AI image.
Look at AI as an advisor. It's there to explain, it's there to guide, it's there to recommend, et cetera. It's there to provide knowledge and insights that you may otherwise miss or not know how to surface.
So from that perspective, that is a safe AI journey to start moving your organization to. But then the other side of that is the skills of your staff itself. When you bring AI into an organization, you want to make sure that your SA staff is skilled in AI usage.
You want to make sure your staff is skilled and understand on where they should be applying AI within the organization. So there's some education and training that need to be done for your staff. There's guidelines, uh, uh, and policies that you need to be putting in place, guardrails that you need to be putting in place.
And that's all very, very, um, very focused on individual organizations and what that means. But that's the first step, um, to get that, those foundational aspects of AI in place. That's a really good point about having that kind of direction you want to take with AI versus it's so accessible.
We can use it, try it out, but how are we gonna focus and leverage it for the organization. And you mentioned the concept of AI as an advisor, using that as your first entree into ai. Talk about how that is different than maybe automation, autonomous ai, gentech, ai, all the terms that we hear about, uh, doing things with ai.
Yeah, so what, you know, when you do hear about, uh, autonomous AI and agents that's all around actionability and the AI take, you know, perceiving a situation, making a decision, and taking it in action, jumping into the deep end of the pool when it comes to AI in that regard, that, that, that's concerning to a lot of, a lot, a lot of folks. So when we talk about the advise the advisor part of that, the advisor takes no action, right? Again, the advisor is there just to guide you, nurture you, and move you along.
But it's up to you, the human to actually take those actions. It's up to the team who's using AI to infuse AI with the right pieces of information to get the right types of guidance that they want from that AI system. But that AI system is benign, right?
That again, the AI system is not going to take any actions on your, your, your behalf. It's all back to you. And what you want to get out of that, that AI system.
So if you're a developer, I'm gonna use AI as an advisor to maybe gimme code, recommendations, code, explain, um, maybe to do a best practices analysis on my code, et cetera. That's, that, that's really good. And maybe from the AI ops space, Mitch, we're gonna use AI as an advisor to oversee my, my dashboard and maybe surface insights to me out of that dashboard that I would otherwise miss.
But there's no actionability to it in that regard. It's just providing the insights and information so that that is, that is a part that fits very naturally into the advisor part of it, as opposed to the autonomy part of ai. It's good you mentioned that.
'cause it is a much more comfortable way to kind of enter into the AI space and start to use it. You don't have to jump right into automation and agents and, you know, doing more of the, you know, advance things. If you wanna think of it that way.
You'll build trust, you'll learn about AI by using it. And we, and we've done that ourselves, right? You know, look over the last 18 months, whoever your chat provider of choice may be.
But that's how we, we all got into the game of ai. When, when, when, when, uh, you know, chatt PT was released as an example. We all went out there and, and started having conversation with AI at that point, whether it was professionally or personally, that experience was an advisor type experience.
You know, we sent it a bunch of questions and we got responses back and we had a conversation and a dialogue with it, but nothing happened. There was no actionability to it. So that was all of our entries into the AI world.
And for organizations, for enterprises, that's a great first step also in the, in the start of their AI journey To that point, there are plenty of ways to engage with a AI and query, use it as a tool. But what do you need to have in place to be an effective advisor role in, in the environment we're talking about? Yeah.
So one of the things that we've learned in our journey with AI so far, and I think as an industry, we all learned just bringing a large language model into the organization, not enough, right? It's like, it's, that's just, that's the bare minimum entry that you could do. But the problem with just bringing a large language model into your organization is it doesn't have any context.
Those large language models were trained on huge corpus of information. They were targeting the masses of users. Where once you get into an organization and you bring AI into an org into an organization, you're, you're in a particular domain.
You're in a particular realm. So now how do you, how do you utilize this large language model that's general purpose for a specific domain that you may be in? Well, the way you do that, and what we've learned o over the past, you know, 12 to 18 months, is you have to augment that large language model.
You have to augment it with realtime product data or whatever data, uh, realtime data that your, your organization is playing in. You also have to augment the language model with additional knowledge, whether that's workflow, knowledge, processes knowledge, best practices, knowledge. It's, it's your enterprise knowledge.
Whatever that means to you and your organization, you want to infuse that into your AI system. So then you have the large language model with your enterprise knowledge, with your real time data access, uh, knowledge. It's a combination of all three of those that brings relevance to AI with an organization because it brings relevant context into your organization and the AI perspective.
And when we're using AI advisors, and I agree with you very much about the point of, you know, contextualizing it with information about your organization. Where do you see the fastest value that can be delivered by using, uh, AI advisor in the mainframe teams today? It's definitely in the DevOps space by far that it, it's the DevOps community that has really opened their arms and embraced ai.
And the mainframe environment is no different, whether, you know, from the cloud environment to a distributed environment in that realm, the developers have accepted AI in the mainframe space. There's a, you see a lot of interest, a lot of adoption AI in the, uh, mainframe space. So that is, to me, has progressed us as an industry in the a those working in the AI space, the work that the development com community has done over the past year, 18 months, has really accelerated our journey, uh, with ai.
Now, you're also starting to see other areas starting to get really interested in that. The AI ops space, as an example, is getting, getting a lot of traction now when it comes to, uh, to ai. And we're heavily looking into that within our portfolio, in our AI ops, uh, part of it.
But it's the knowledge capture that is what's gonna play the biggest game here, why we're in this massive transition within the mainframe community. We have a lot of folks heading out towards retirement on the tail end of their careers. How do we capture that knowledge and how do we infuse that into our AI system so that next generation coming in has that experience?
They can lean on that they otherwise would not have that person they would go to, you know, Bob, Bob is not here anymore. But if we were able to capture Bob's knowledge in some way, shape, or form, and put that and infuse that into the AI system so that next generation can lean on the AI system and get access to the information that Bob had, that is game changer in our mainframe space. It's really, it's not only helps get that next generation up to speed, Mitch, but here, he, I I just had a conversation yesterday with someone about this AI on the mainframe is making the mainframe sexy and attractive to that next generation coming outta colleges and universities.
We're in the conversation, just like the cloud space in the distributed space when it comes to AI and technology advancements in general, that is really cool. You very much is the sense of excitement in the mainstream environment, particularly with ai. And it, and, and you have a really good point about that knowledge loss, you know, as folks retire, move on, whatever it might be.
So the next generation of people work in a mainframe, have got that information contextually available to them in ai. I can't think of a better application of ai. Yeah, absolutely.
And we hear that from our customers. Our customers are like, you know, we got decades worth of white papers. We got years and years worth of, uh, video recordings, training material, et cetera.
How do we capture that? How do we, how do we get that into an AI system? And that's something with BMCE, uh, assistant that we, we, we took very, very serious, right?
So it's like, well, how do we do this? How do we allow our customers to capture this knowledge that they have and get it infused into B-M-C-A-M-E assistant? And we're delivering to our customers a tool that makes that really easy to do, uh, where they can, uh, manage documents that can manage videos and build out their own knowledge base that B-M-C-M-E assistant would be totally aware of.
Now, when we ship our solution, we have the large language model. We have an a e knowledge base that we ship, the customer can build their knowledge base, and then we have access to all of our product data. So we got all this information that's available to BMC AMY Assistant, that goes back to what we talked about before about what's relevant context to a customer.
And we can't talk about AI without talking about trust. And I've heard you discuss the importance of explainability. Yeah.
Talk more about that. Love to hear your thoughts about why that's so important. Oh, Yeah, yeah, yeah.
So with, with ai, of course, you know, trust always comes up in the conversation from the very beginning. When we all started working with generative ai, that was the, you know, everybody was talking about trust in that regard. It's multiple ways to answer this.
You know, we have some responsibility in the solutions that, um, that we provide our customers. We gotta give the customers insights into what our AI system is doing. We have to connect our AI system into their workflows and processes around auditing, logging, tracing, et cetera, observability in their organization.
So how do we do that? So as an architect, from the very beginning, foundational, we have to be able to capture everything that is happening through our, uh, our AI system through BMC Amy Assistant. From a user typing a prompt to us formulating a response, not only did it has to be auditable, but as much insight as we can provide on why we came about a response has to be clearly articulated.
And some of that is clearly articulated back in the product experience. So when we give a response back, we may cite in that response where we, why we came to this conclusion, and what pieces of information led us to the, to this conclusion. But it also has to be totally, uh, traceable and auditable behind the curtain so that the administrators of the AI system have full optics into everything that is happening in that system.
It cannot be treated as a closed door system. So it, it, it's the optic optics into the AI system. It's the auditability, traceability, logging, everything has to be done.
So if you go into the system, Mitch, and you are working with BMC Amy Assistant day in and day out, the system administrator has, you know, full trans full transparency into all the things that you've done with the AI system. And when, and, and customers have asked us for that from the very beginning, we started working with our customers in this journey that was foremost right at the top of the list. They need to understand what's happening in the system and why.
And we've done that. That's foundational for us. That was something we had to put in at the lowest level of the architecture.
That's not an afterthought. If, if, if you go with that approach as an afterthought, you'll miss things. It has to be done at the ground level of the system.
Yeah. That explainability of transparency is fundamental, that that builds that experience that you start to build that trust with very much so. And is that trust that's gonna lead us to, to, to the next part of the AI journey beyond the advisor, where you look at AI as a true partner in your daily journey.
You look at AI agents and agentic AI as a digital workforce doing work. And, but we gotta take those steps and build that trust. Speaking of taking those steps for organizations that may be just starting out, thinking about AI readiness, what do you think are the smartest first steps to take?
We went through this journey ourselves. So, so we have a pretty wide and deep portfolio, which within our BMC Amy, uh, product area. So we had to go through this exercise.
Where do we find true immediate value that we can deliver to our customers? The AI journey was new for us too. We had to be very capital, very systematic on how we approached it.
So the, the way we approached it was, let's just start looking at the low risk, but high value returns that we can give our customers with our AI infusion within our products, within our portfolio. And we've been very, very successful at that. But one of the key things, even though it's, you know, it may be a, a low risk, high reward type, um, AI enhancement, we want to be able to also capture and measure that.
You have to be able to measure and capture that to make sure you're truly getting your return on your AI investment. This model worked very well. I, I, I, I, I spoke to other architects about this model.
I spoke to customers about this model, and this is a really good entry point model. Start small. Don't try to drink the ocean, as they say.
Start small. Identify those low risk impacts. You don't want anything that's gonna disrupt your business, uh, on a day to day.
But then just start taking those steps. And before you know it, when your organization gets more and more comfortable with AI and you start building the trust with ai, and you starting to get a good feel of what you can and cannot do with ai, before you know it, you're starting to take on bigger and bigger and bigger challenges with AI and be, when you look in the mirror, you'll see you yourself progressing pretty far pretty quickly with AI when you start that way. Those are some great insights and very sage advice, I think.
Anthony, thanks for joining us today. Thanks for being part of this. Thank you.
We really appreciate the BMC software team for sponsoring this kind of event where we can share this information and share some of our experiences and bring up some of these important questions. So this concludes our first segment that we're doing in this three part series covering AI readiness. In our second segment, we're gonna be talking about infusing intelligence with ai, using AI as a partner, using generative AI in the mainframe environment.
Thanks for joining us. Look forward to seeing you on our next segment. Hello, I'm Scott with Al, and I'm here today with Ahmed Abbu of Nokia Enterprise IT to talk about some of the very interesting network migration issues that they've been through over the last, uh, year or so.
I'm not gonna steal any of Ahmed's Thunder, and we'll let him speak to at all. Ahmed, please introduce yourself to the audience. Hi.
Um, my name is Ahmed Al. I'm the lead architect for the on-prem, uh, data centers inside Nokia it. And, um, I had the privilege of course, of, uh, doing this exciting transformation where we moved a lot of data centers from legacy to modern, modern techniques, modern data centers, migrating from different types of vendors to, to Nokia equipment migrating from Nokia to Nokia.
So, um, those two or two and a half years have been very exciting for me. I've been working in data centers for a long time, but this is like something I've never seen before, so. Awesome.
I'm excited to share this with you. Yeah, no, happy to dive into this. And let's just set the context for, for people who aren't aware, you know, Nokia is just this tiny little company with just a few hundred users on the network, right?
Yeah, sure, sure. We've got like 88,000 people. Yes.
Yeah. And a wide diversity of different departments and functions. Do you support, you have manufacturing operations that you have to support, of course.
Finance, accounting, yes. Hr, all sorts of, you know, software developers, people in sales, people in marketing. Probably one of the most complex enterprise network environments that I've run into in my time in networking.
How about you? It, it, it, I think it, it's, it's different types. There is a variety of applications, applications that are very sensitive to disruptions.
Sure. Applications that are, you know, factories, uh, you know, that that could, you know, a brief disruption could, could throw off, uh, the softer of the factory. It has to be restarted, things like that.
So it's very critical. Very interesting. And the different variety.
Different variety. Some are very sensitive to, to delays. Some are very sensitive to outages.
It's very interesting. So you've given a little hint at kind of the first, um, category of things that we want to talk about. You know, some of the pain points and the issues that you, you had to think about and had to say, what does my next gen network architecture need to fix?
So what were some of those original pain points? If you think back, you know, two, two and a half years now, um, to when you actually started down this path, what were some of the motivators that, um, got you thinking about we need to go to new network infrastructure and new tooling? Well, when I started really with Nokia, it, I saw it d all sorts of problems.
You know, I wasn't, I wasn't in the, in the IT world, I was in the product world, right? And everything, there was like more rosy, you know, you're dealing with labs, concepts, architectures, blue playbooks, sure. Blueprints.
Uh, but when you move to it, it really hits, you know, the real world part. And there I was exposed to all sorts of problems. You know, we have operate our operational model, you know, where we have to do a lot of intensive work, uh, very resource intensive.
We really don't know what is deployed, uh, if it's, if what we intended to deploy is actually on the network or not. We don't have a feedback loop from the actual, from the actual deployment to the intent. Um, we had operational problems where, where the operations team were dealing with different types of toolings that don't cooperate with each other, that don't tell you really what, what, you know, what is wrong with your network at any time.
You have to do a lot of brain power and co you know, manual correlation. Um, also our designs, our designs, it was a lot, oh, well, let's go to the lab. Let's try and simulate as much as possible production.
Let's bring in, you know, expensive equipment, expensive, uh, uh, low balances, fires on, et cetera, into the lab just to, to test something small. 'cause we are worried that when if we go in production, it'll have a, a very negative effect. So lots of variety like that.
And also, and also human aspect, uh, of the thing. It's like, like I, I think of it as a journey. This is not only a technical part, you know, sure.
People are, you know, see excited about automation, AI, and stuff like that. And they, they wanna be part of it. They, they wanna get exposed to it, but not, not, not just for the sake of AI and automation, but where it makes sense for us.
And so all that, um, made, made us think of completely rearchitecting the way we do everything. Sure. From design to, to implementation to operations, everything was completely different.
Did you see any, like, not to be overly reductionistic, but any, like, specific pain points? Was there overload due to alarms or tickets generated? Um, were there communication issues on some of these complex troubleshooting issues?
Does anything specific come to mind there? Of course, I'm, I'm not an operations team. I'm a, I'm a design team, so Sure.
I wanna comment on the design part because that affected me the most. Sure. Is, is when, when, for example, when I got exposed and we had a network audit, and we found all sorts of problems.
You know, the thing is, we really don't know if, if what we're dealing with is, is a design intent or it is intended to be like this or, or a drifted through type to be like this. Sure. So the common thing, the common thing is I always was told, go back, let's see the designer that did it two years ago, let's talk to him.
Let's talk to him. Is it really this or not? Hmm.
So it wasn't like very consistent and, and, and drifting. And we don't know if, if reality is good or bad. So, uh, all sorts of problems there in the design and also in the implementation.
Lots of people doing CLI, where, where one node has a completely different configuration than another. Not completely, but drifted away from another and they should be identical. And we never understood why.
So I, I, I really need, uh, I really thought, thought about this when, when starting the architecture that we consistency has to be there. Yeah. Automate, you know, something at a higher level should be the, the engineer shouldn't be going to that low of a level to deal with things.
See, they should, they should be dealing with a high level and let some tooling, some automation, some templating, do the, the real hard work. You know, the con you know, consistency check work. Sure, sure.
So, uh, IRA, nicely pointed out that I was here last year. Uh, anybody have any questions on what the Cruise con experience can be or is? Please feel free to stop by.
Um, his introduction made it seem like what I said was nice, but he actually told me to ask questions and not talk. So we'll see how this actually plays out, because we have the stars of the show to the left of me. Uh, he actually did introductions already, but I do want to give them at least one minute to just describe, uh, their role and what they do, and then we'll hop right in.
Sure. Hey everybody, my name is Sean Harris, and I'm currently the deputy CISO at Chipotle Mexican Grill. I was also Deputy CISO at Starbucks Coffee Company in Seattle, Washington.
Uh, been in cybersecurity now for 29 years. I know that one last year. I just got one more year.
And, and then whenever I'm talking to you, I can just say is three decades. Uh, but, uh, been worked in, uh, quite a few different, uh, industry verticals, uh, with the federal government, um, with nasa. Worked in financial, in the financial industry with Progressive Insurance, Lionsgate Studios.
And, uh, now I found myself over in retail. So working both at Starbucks and now at, uh, Chipotle, Mexican Grow. Hi everyone.
My name is Kathy Lee Lay. Um, I've been in Cyber Secure. I work for a company called Skywork Solutions.
Uh, I tell everyone we're the largest semiconductor company nobody's ever heard of. Uh, but who here has an Apple product? Yeah, well, we power all those.
Um, so we are in, we're very big in the RF market, but we're an aerospace defense. Um, IOT anything in everything you think of that requires a semiconductor chip. Um, I've been in this industry for over 25 years.
I may not look like it, but I am. And, uh, I've, I've been primarily in financial services. Um, That's it.
Hi, I am Angelique, Napoleon. I go by q. I've been doing this about 28 years.
I've worked in oil and gas and defense. I'm currently the deputy CSO for GDIT is Intelligence and Homeland Security Division. And I think I've got a pretty interesting background working in different industries, and it's an honor to Be sitting here with you guys.
Good afternoon, everyone. Uh, my name's Lauren Timble. I wanted to first thank IRA and the sponsors, uh, and everyone else for coming out.
Um, Lauren Timble. I've been with Miami-Dade County for 20 years now. Uh, my, I manage the teams that handle, uh, incident response, security, architecture, and governance and compliance.
Uh, anything that goes over the air in Miami-Dade County to under the ground. Uh, my team is involved in making sure that it's secure. Um, before that I was with Florida Power and Light, uh, where I got my teeth, uh, cut on, uh, critical infrastructure.
It's something that I love talking about and, uh, love working on. And I did a stint as a global SecOps, uh, director for, uh, another company. All right.
Let's get started. Uh, let's get to the good stuff. Who makes more money?
All right. Um, no, seriously though. Uh, what's the biggest difference between, uh, what you are, what you do, and what your CISO does?
I'm sorry, I didn't hear That. What's the biggest difference between what you do and what your CSO does? Um, do you want, I, I guess I can start.
Um, I say I do most of the work. Um, uh, you know, so underneath my purview, I have all of GRC, uh, third party risk, data privacy, uh, incident response, uh, B-C-P-D-R, as well as now AI governance. Uh, so if you look at that whole spectrum, everything's, and even security architecture at this point.
So everything except for security operations is all under my purview. And so my head is usually, my hair is usually on fire most days. And, um, he, I think at the Cecil level, in my opinion, he's much more strategic.
It's all about executive alignment and messaging. Um, whereas I think our lieutenants are the ones that play a strategic role, but we're also responsible for the execution piece of it. For my role, uh, it was a direct succession hire role.
So, uh, there's, uh, we worked very closely together. So my CISO is, uh, many of you may know him, Dave Slic. And, uh, we, we worked very closely together.
We worked together when, whenever I was at Starbucks as the chief strategist there, as well as the, the deputy for Andy Kirkland. Uh, but at, uh, at Chipotle, we, uh, we have a really great relationship. And, uh, we can, we, if one of us is out, the other one is stepping in from a, from operations or what, uh, we actually have eight different, um, functions.
And those eight different functions we have, uh, we've split some of the day-to-day operational management of those up a little bit, uh, just because, uh, to, to basically, uh, handle some of the, the day-to-day operations. I think for me, my, uh, CSO is more aligned for the strategic side. He's focused on corporate goals.
For me, I run our security operations center, and I also run all of the security operations along with some other special programs. I wouldn't say it's like an error apparent, but he handles the financial side and I make sure that I am, he's the rigor, I'm the trigger, if you will. Our ciso, uh, typically handles the strategic or the political aspects of it, making sure that there's a good communication to the board of county directors, and, uh, working across the other, uh, departments, uh, for my team and for my peers, we make sure that, uh, we're either implementing the new technologies, making sure that any SLAs are being met, and also helping to keep the budgets in line.
So all of you guys said your CSO does the strategic things, but you guys are successors to your cso. How are you preparing to be able to do those strategic things when the time comes? So, uh, for us, uh, Dave and I work to work very closely together on, um, our three year and our yearly strategy.
So we develop that in tandem together. Uh, so it's not a, it's not a matter of, uh, a lot of times when you hear about a, a, a deputy role, what you hear about is, well, you're going to do, uh, kind of all of the operations stuff. You're gonna manage the soc, you're gonna manage all the operations, the cybersecurity engineering.
Um, that's not really, in my opinion, that's not really preparing you for that, uh, that succession role. Let's, uh, let's be very, very open about what, what a, what a succession role is. You need to be, uh, in, uh, in the mode of preparing to, to do everything that the CISO is doing.
So a, uh, a deputy, a deputy should be, uh, if not already doing some reporting to the board, getting their, helping to build the deck and, uh, and practicing with a CISO on how you're going to deliver that. So those, these are all the, the strategic views. So deputies definitely have, uh, quite a bit of responsibility from a strategic perspective, in my opinion.
I totally agree with that. So in my role today, I do a lot of the things that aisa would do. Um, I help build our board slides.
I determine our annual plan along with our three year plan, and I send it to him to roll up. Uh, I also do things like review our SEC disclosures, align on SEC incident response requirements. So I do do it in conjunction with our ciso.
Um, so in essence, I'm doing, I'm being strategic right along with him. And we just get alignment on what's presented. We do the same thing.
We have to back each other up. So if he's on vacation, and I'm on vacation this week too, it's kind of interesting 'cause nobody's manning the store, so all the kids are running around. I bet that's going well.
Um, but we, we try and back each other up to the point that if something happens, he decides he wants to go sell tacos on the beach, he can, where I think I get maybe sometimes frustrated is I want to learn more. And he's got this corporate knowledge. He's been with the company 13 years.
So I always tell people, if you wanna bring someone up in the ranks with you, take 'em with you to those board meetings, take 'em with you to those executive meetings so that we're not awestruck when you meet somebody. And we know what their expectation is of the role. So that's one of the things that we're working through.
And it's about the personality. You have to be able to compliment each other because if you don't have that chemistry together, and I think that's one thing we don't teach in college and you can't teach in a certification, is that chemistry. Do you two gel?
You know, can you pick up? And it almost becomes a comedy hour with us because I try and make things as light as possible. 'cause cyber really is depressing.
So we try and make it fun. Sorry, I just have one other thing. I think a lot of this is, is having your cso, um, give you the opportunity to present across the executive right rank.
Mm-hmm. And so even in my role today, I'm presenting to all of our C-level execs. And so, and I think what I'm finding as you grow higher is not so much about iq, it's really about EQ and how you're reading the room and responding to those in the room to see if they're gelling with the message as you present to them or not.
Uh, the EQ and the soft skills part, right on target. Uh, a lot of, uh, what I would see, uh, I had a very good, uh, CISO to work with. He just retired.
Um, he, he would always bring me in, uh, when our CIO challenged us to come up with a plan. He said, make a five year plan and then make the subsequent five year plan. And it, it, it's daunting and knowing how fast this industry changes and how the threats evolve and, uh, everything's changing so quickly.
Uh, when I heard make a 10 year plan, I, I was awestruck. But, uh, working together, uh, and getting me, getting me in front of the CIO, getting me in front of the, uh, board of county commissioners, uh, was a huge help. It helped me know what the audience was gonna be and develop those soft skills that would be needed.
Um, deputy CSO in the past, uh, deputy CSO maybe about five or six years ago, uh, pivoted into the CSO role about five years ago, I guess. Um, and everything that they're saying really, really resonates with me. And there's something that, that I have to ask, though.
You guys all acknowledge the soft skills are necessary, but you guys all named very technical roles that you guys are in, and so you're asked to be a unicorn, it almost seems like. And so I guess my question is, how are you guys staying technical but also developing your soft skills at the same time? So, uh, is it cutting in and out on me?
No, I'm good. Alright. It's just me.
I can also speak really loudly. So, uh, I, I've always been a very technical person, so I came up, um, through some engineering, but primarily, uh, I really, really, uh, hit my stride in security architecture. So, uh, I learn through architecting new systems, and that's, that's how I, how I got into cloud, working with the Cloud Security Alliance, um, developing, okay, developing, um, the, the CCM with the Cloud Security Alliance, I architected that.
I architect my, the, the program that I'm in right now. Um, and by architecting it, I stay very current in technology, currently architecting how, uh, how a company like mine could deploy a secure, a secure MCP, uh, conclave, uh, for ai. So I stay technical by doing that.
Now, at the same time, I, I, I really work all work a a lot on, um, there's the EQ side, also, being able to understand the cultural differences between the, the people on your teams. Super important, right? Because, uh, one thing that I've always felt is that, uh, I grew up in, uh, on a sharecroppers farm in South Alabama where I grew up.
I looked at risk a whole lot differently than say my GRC manager that grew up in south side of Chicago. I look at risk very differently. And let's be clear, everything is about risk.
And so understanding that and understanding other people's, um, where they're from and what they're, and where they are, is one of the most important things that we can do as leaders to grow our people. So I feel like I'm in a never ending battle to keep up, especially with ai. So I do spend hours reading every day.
Um, a lot of it is just getting my hands early, dirty on some of the latest technologies. We do constant POVs. We look at the newest industry players, what other companies are doing at these conferences.
I talk to people say, I mean, I just had a conversation, how are you, you know, deploying sayir? What are the, what are the drawbacks of this tool? What are the great things about that tool?
I talk to people in the industry all the time through these type of events to find out, you know, their experiences with the truth, what they're doing, right? What, you know, get feedback on what, you know, what, what could be improved. And so I take these all back and I try to take a little bit from every conference that I go to see what I can incorporate into my own program at work.
Um, so it's a little bit of both just going to these industry events, learning about what's out there, and then reading every night. I think for me it's the vendor relationships. So I was blessed last year to lead three of our digital accelerators at GDIT.
We're investing in post quantum cryptography. And I led our zero trust and our defensive cyber operations. So it was building those relationships with the vendors enough that they gave me the tools so that I could bring back and not just learn myself, but you become, teach the teacher.
We learned that in, um, the military. We have to instruct others. We don't always have the budget to bring in an instructor.
So it was learning it enough that I could teach others. And it's a lot of reading. It's a lot of homework, but I keep my vendor relationships tight because you have the best white papers, you have the best information, and you're my source of information.
I don't have time to read 50,000 articles, and I wish I could answer every single vendor call, but I look at strategic relationships with my vendor as how I'm keeping current and talks like this, meeting you guys and learning what you're doing. And, you know, as we socialize what works for you and what doesn't work, because I don't wanna waste my time going down a path that I'm gonna only end up drinking and losing more hair. I don't need to do that.
We've lost a lot of it already. It is fun. What happened?
It was the stress, dude, I'll be there next year. Oh, what, uh, briefly, uh, for me, it's always been a, a passion to be in tech in whatever's new. Trying to stay, you know, three, a few years ahead of the curve and being the one that brings that to my team, uh, I want them to, uh, see me as an example, uh, staying on top of it, staying on top of AI or whatever other, uh, new thing is right around the corner.
I want them to chase knowledge with that, uh, constant learning, uh, passion that I, I try to instill in them. So, outta curiosity, which one of you think you're ready to be a CSO right now? Which one of you thought that before you took the deputy CSO role?
So why'd you take it if you thought you were ready for more? So when I took this role, I had, uh, I had two CISO offers on the table. I went and had a conversation, um, with who is my current boss?
My CISO as a trusted advisor. By the way, if you guys don't have a trusted advisor in the industry, not in your company, get one, get one now. And, uh, so as I talked to him, uh, he gave me some great advice about the roles.
Um, so, you know, the two, there were two of them. And, uh, he, he basically said at the very end, he's like, so I've given you some good, some good things to think about. I'm like, absolutely.
I took notes. He says, okay, before you make a decision, I wanna have one more conversation with you. And that's when he, uh, started the conversation.
33 hours of phone calls later, I actually applied for the role under him. And here's why. When you, when you look at some of the people that you, that you have, like even here, um, you've got, uh, someone like jerick, someone like Tim, you've got some, some really great CISOs every now and then, you, you have that, that inflection point of can I go to a, a smaller organization and be CISO right now?
Absolutely. It's not, it's not a question, right? If you don't think that you can, you wouldn't be, you wouldn't even be like necessarily thinking about becoming a deputy.
But is there something you can still learn from some of the greats in this industry? And I felt at that moment that, you know, what, there is, there's still, there's still some things that I can learn so that I'm not going and working at, say, like a Fortune 1000 company, but I'm going and, and becoming something at a Fortune 200 company, right? Um, I looked at the people that, uh, that my boss had worked with.
One of them is the current CISO at Nordstrom's. One of them is the current ciso, uh, global CISO for Disney, the, the Walt Disney Company. That's, that's lightning to catch.
And so I knew that, and I'd worked with him, but I'd worked levels below him. And we had a really great, um, technical, technical, uh, relationship. And I knew that I, there was still some, there was still some things that I knew that I could learn, and I have, and that was, it's been a, it's been a great experience for me.
I think at the end of the day, you have to determine what matters to you most, right? Some people, it's money, some people it's recognition for your job. Some people it's more work life balance time with your family.
Some people, it's culture, company culture. And so you have to weigh all of those things, right? So, although I potentially could become a CISO at a smaller company or another company, you know, I always value all those things.
I have a great boss today. He's the primary reason why I'm still with my company today. Uh, I get so much empowerment and I, my confidence has grown so much.
A lot of my growth has been to him. We have, so have a great team. How many people here work with companies where your infrastructure and InfoSec don't get along well at our company?
None of that, right? We all work gel really good together. We have executives of support.
We worked over the last six years to build a culture where basically when I ask for something, I get zero pushback. So for me, that's golden, right? Where you have a, a finally, we finally got the company to a place where security has so much influence that when we ask for something and we make sure we work with our stakeholders to make sure it's reasonable, that we get very little, actually, almost no pushback when we ask them to do something.
And so I know that if I go somewhere else, that's not gonna be the place I know I'm well compensated. So those all think I get the flexibility to go home to my kids when I want, you know? So I have a lot of flexibility.
So all of those weigh into my decision to stay where I am. And the fact is, you know, there's, you know, what weighs in the back of my mind too, is, is the liability with the CISA physician. We all heard about what happened with Joe Sullivan, right?
Am I willing to take that additional step and face that personal liability and be the scapegoat for another company where if you don't have that top level support, you're gonna be the scapegoat, and now you're personally held liable? I don't know if I'm ready for that either. And so that's another reason why I decided to stay where I am today.
For me, I think it was creative control. My boss said, you can build what we need within our infrastructure. You know, you need a security operations center.
You can build it in your likeness. And for me, that was an ego thing. I was like, it will be great.
So I, I took a chance. I was a CISO before, and I've been a CTO and a CIO. For me, it was a chance to take that step back.
I've gone through some health issues because I think that's not a secret for us. As CISOs, deputy CISOs, I've beat heart attacks and strokes and diabetes, and I tell myself how lucky I am, but we give so much and we leave it on the field. And for me, I just wanted a chance to maybe step back and help someone else shine, help build his reputation and help build him.
Because sometimes, I hate to say this, sometimes as a woman, we think we can change men. I can help build him into something better. So for me, it was building not just the security operations center, but help build him into a good ciso because he's listening.
And it takes some time and it takes some patience. But I've gotten a lot of creative control. I like to say I'm the Yoko Ono of my own soc, but I've helped train.
He's let me hire who I want and build the team that I know we need because we have an important mission in the intelligence community and homeland security. And it takes a different type of person. I can't just bring these people off the street.
I just can't hire them out of college. I have to train what I need, and they have to have a certain persona. So for us, it's all about personality.
Yeah. For me, uh, finding the, the work life balance, being close to home, being close to the family, that was a significant, uh, thumb on that scale, on that balance scale, uh, being able to hire and build the right people, uh, helping them, making sure that they understand that this is a mission. Um, there's people who depend on what they are doing.
Uh, going back to that CSO personal liability, that's, that's a big thing to take onto your shoulders. So, uh, I don't envy anyone who is doing that. That's probably the, uh, the biggest, uh, weight against, uh, taking that CISO role.
Describe your worst day on the job as a deputy ciso Swo be at my current company, it was the, the one previous where I was also the deputy for, uh, for about a year and a half. Um, we, uh, we had a really great bug bounty program. Uh, we discovered through the bug bounty program that someone was able to enumerate quite a few things.
Um, and, uh, I ran the cybersecurity incident response plan and the team at that company. And, uh, by the time, uh, it was all said and done, and we had, uh, we had confidence that we were at containment and that we did not have broad exposure of the, of the specific API that was able to be enumerated. Uh, we were, uh, it was basically, I think I was, I had slept, uh, about six hours out of 33 and, uh, had had a great team that was backing me up.
But, uh, you know, those are the, those are the moments. And it's really important to understand, as a deputy, my job is to protect my ciso, number one, right? And so they do have that personal responsibility and personal liability.
And, um, you know, uh, c and d insurance goes just so far, and not everyone has, you know, right. Of, of legal defense. So you're there to protect that ciso because you are friends, you're, you're, that's your job.
And so as you, as you're running an incident, you have to understand that every single thing you do has to stand up in a court of law. And I don't know how many people here who have testified in court cases for cybersecurity, but, uh, you know, that was my first incident I ever did in my life. I had to go to Germany and testify against the guy.
So, and that was with the federal government, it's tough stuff. Like you learn a lot by, by that fire. But the main thing, uh, when that I just wanna stress, is that as a deputy, your job is to protect your ciso, um, and his responsibility and liability.
Um, I can't think of an incident really. Luckily we've never been through a major incident. I mean, the biggest incident that I can think of is the CrowdStrike outage.
And I, but I think for many of us here, I think we all went through the same thing. So, I'm sorry, I don't really have a big story to tell it, you know, I, I, for the CrowdStrike, I think everyone was feeling the same hate. Yeah.
We were suffering with the CrowdStrike thing too. I think it teaches you patience and you have to use that EQ in the room, and you have to tone people down, so, yeah. Mm-hmm.
Not really a big incident. Yeah. It doesn't have to be an incident.
There's a lot of things that can make a day hard. Yeah. Those, uh, subpoenas for investigations that your incident response team has, uh, has participated in, whether it's employee malfeasance or something that came in from outside, uh, I always hate getting those, uh, those subpoenas.
So, So let's talk about the future of the Deputy CSO role. How do you guys see that role evolving? Do you think AI is gonna have any impact on it?
Do you think regulation's gonna impact it? I'm curious what your thoughts are on it. Uh, absolutely.
It's, it's going to affect all of us, uh, whether it, it's, um, helping you get through compliance requirements faster or analyzing third party risk. Uh, the other aspect where I see it helping or, uh, is helping your teams be, uh, respond faster. Obviously, we all know it's helping our adversaries, uh, come at us faster too.
They're crafting perfectly worded emails. They're crafting, uh, very basic attacks into something that's scripted and adaptive. Uh, there was a, I think it was a, an, I think there was an MCP that came out a few weeks ago, and it was really fully automated.
My, my team was, uh, playing with it in a sandbox, and it, it, I takes all the hard work out of it. I think I see the deputy CSO role, we're gonna have more responsibility as more organizations have to do more with less, less money, less people, um, less availability. I think we're gonna have to put more of our own personal time.
It's not just working remote anymore. A lot of us have had to go back into the office. So you've gotta con your staff.
They've gotta put pants on and they've gotta come back into the office. So the challenges are people, it's finding, for me, finding those right people, the way I said, it's about personality, and it's getting people who wanna come to work, but not just come to work. Work.
Because you can sit there and you can collect a check, but it's different when you actually have to contribute. So those are some of the challenges, is finding people who actually wanna do the work and learn from you. I always tell people, I'm gonna show you whatever you wanna learn, but you have to come with that attitude.
So making sure that people wanna be there. For me, that's been my biggest challenge. So I think I would layer on top of that.
I think, and at least maybe it's just my role, but I feel like I always have to do more with less. And so now with the advent of ai, I think because there's so many AI, potential AI security issues that your attack surface just grew exponentially, right? From prompt injection to model hallucinations to API, threats to NHI to, you know, it's just, it's constant new threats that we're always expected to keep up with.
And then they look to us for everything. And honestly, AI is the big reason why I'm so underwater most days. 'cause every buddy in our company wants to do a POV with the latest new AI vendors, and they're like, has to go through security review force.
And now I'm looking at a hundred AI vendors all at once. And so it's just, it's endless. And it's just putting your hat on for like, you know, whether it's, and it's not, it's, it's cybersecurity, but it's just like, you know, with all these different things that they can do with LLMs, how do you control the agents?
How do you monitor that access is right, right? How do you keep an inventory in? It's never ending.
And so I feel like Deputy Cecils, and especially now, they're like, well, how are you using AI to, to secure our company more, right? Make it more efficient. So I think the responsibilities and the expectations will just continue to grow.
Well, I think that, uh, first of all to, to just speak about like the, the evolution of the role. I'm starting to see more, think of it as whether it's CSO assistance or CSO successors, not necessarily named deputies. Uh, you know, from, from my view, uh, you should probably have a, you should probably have a deputy when you have an exit plan.
Um, and, uh, when you, when you're ready, you already, you're now you've got someone who is a named successor and all of your colleagues already know who that is before you leave. Um, but as, as it relates to ai, um, something that, that strikes me is that it, it's an arms race, number one between us and our threat actors, right? Um, you know, the, the adversarial intent here definitely tracks in, uh, it's an arms race, right?
I'm, I we're seeing you see attacks all the time that are much, much better. Well, well termed, um, James, we'll see what what happens with, with phish testing, because, you know, we always, we always did our best to, to spot 'em because of the lack of grammar, Grammarly, it's done, we're done. Um, but what I see in AI is not a, it's not a technology shift.
It's a terrain shift. Much more so than cloud was. Cloud was a technology shift for us.
This is, the entire terrain is changing. So think of, uh, having a business, uh, before technology really started coming into business in the late seventies, early eighties, right? You had all of these paper processes and people were like, ah, all of, we've got that one computer in the back room and there's that one guy that knows how to use it, and then all of a sudden everyone's got a computer.
What I see in AI is that monumental of a shift. It's going, it's changing everything. Every single one of our, uh, capabilities, every one of our functions is being changed by it.
Now, some of those functions are going to be, become a lot easier to do because we're going to be able to rely on, um, agents provided we can get to the point where we feel comfortable enough to give those agents agency to be able to make changes in our environment on the fly. If we're not ready to do that, then like, it's, you know, it's gonna kind of be the, the, the, the people who said that that cloud thing's gonna not gonna be our round very long, and they're gonna come back to our, our on-prem data center. But it's a terrain shift completely.
And so everything that we know about it is changing. Everything we know about this role, about our industry is changing right now. And I'd say in the next 18 months is going to be one of the wildest rides that I've seen in my 30 year career.
Yeah. Thank you for that. I, I was one of those people that held onto my Blackberry as tight as possible.
'cause I didn't believe iPhone would actually take over. And I think there are people like that with ai, and we're seeing that really happen. So one of the things I tell my deputy is, you can't replace me until I have somebody to replace you.
So what are, 'cause you guys have articulated that you're, you don't say it out loud, but you're the most important person, your security team, you're not, you're not saying it, but I can pick that up, right? And so the most important person needs someone to replace them. If you're gonna take a step up, what are you guys doing to develop your successor?
Because that could be something. And I've seen multiple CISOs leave and an outside person came in because the deputy didn't not have a, a deputy. So I'm curious what you guys are doing about that.
Oh, oh, Go Ahead. Uh, I, I have a small team, but, uh, they're very good. They're very dedicated.
So I'm kind of focusing on, on one individual to try to build them up. Uh, they have that natural curiosity. I think that they will be somebody who will always pursue technology and the latest thing.
So making sure to give them, um, my thoughts, give them kind of my experience distilling it in so that they can absorb it. And even though they're kind of a juniorish position, uh, just to help them try to rock it, rock it up, um, just transferring that, that wisdom, I guess. I started doing group training.
So my internal group, I am training each one of them. There's some that wanna learn policy, there's some that wanna learn leadership, and I'm trying to scratch their itch so that I can convince them on them to stay and grow into the position. Because as the mission evolves for us in homeland security and in the intelligence community, I need people who are forward thinkers.
So I'm teaching them to think again and how to think to meet our mission, to propel our mission forward. So I've trained four potential successors. So we are a very lean team.
I was actually looking for a person with the same intention to succeed me. So we were looking for someone, and the goal is, once we hired this person, it's really to groom them, teach 'em everything I do today. Um, have them present, teach, you know, so I think that person will be groomed to be there.
And so we, with we, so as we interview people, we interviewed them with that thought in mind. Um, and our CISO says, Kathy, can you envision this person as their successor? If not, they're not good.
They're not good enough. And so that's always been the thought process. I recently hired a CISO who's underneath me now, um, who was looking for an opportunity in a larger program, a more structured program than the one that he had developed for his retail organization.
And, uh, he had never worked in, uh, he had never worked for another ciso. He had moved up and had built his own program. And as, uh, and as I was talking to him at several CSO events, um, I noticed that he was really, really interested in how we were doing things and what we were doing.
Um, the way that, the way that we, we run the program and the portfolio, uh, being a little bit more of almost a microservices architecture in the program. And he was super interested in that. And so I started having the conversation.
So he is, he's, uh, currently leading my cybersecurity, engineering and operations teams. Yeah, that's a good point. There is general linear path to, to deputy ciso.
I personally went from being a CISO to a, from a deputy ciso to a ciso to a divisional ciso. To a ciso, right? And so it just, it depends.
Size of organization, complexity, salary, right? All those things kind of are, are factors. One last question for you guys, then we're gonna leave it to the audience to ask, ask any questions.
What's one thing that you know today that you wish you would've known when you took the role? Enjoy the ride. Have fun.
Don't forget to enjoy. You get opportunities like this to meet different people, and it's great to meet each and every one of you, have fun, meet, meet people, help grow them, and, and never stop learning. So before, uh, while I was deputy at Starbucks, I, I never, uh, presented to the board learning, learning about how that act being in that room, different world, um, different world of a public company.
Okay? So, uh, I mean, it just, it is right. And the thing is, there's, there's very few CISOs that have the, uh, the courage to bring you in to present part of that deck.
You have to, you have to gain a lot of trust in order to be able to do that. Um, and so, uh, presenting, you know, having, I presented to executive leadership teams all over, you know, all over the place. I presented to, you know, back in my NASA days, to Sean O'Keefe, the, the NASA administrator.
But when you walk into and you're presenting to that board, it's a little, that's a little bit of a different game. And, uh, and, and that's something that I, that I, you know, I, I knew I could, but the first time having that, having that, uh, tutelage, having that mentorship was, was great. Um, you know, and, and just being able to understand it, right?
When you're at a CSO level, you'll, and, and like, to be honest, we we're both kind of like in that, in that same mode, right? Looking at the business outcome is the most important thing that you can learn. It's not, it's not always about securing, it's not always finding a way to say yes.
Um, you know, you've heard all of the tropes on LinkedIn. You can go in and hear tons of people who are trying to, to tell you that, who've never done the CISO role, tell you everything that you need to know how to about how to be a CISO on LinkedIn. But, you know, learning how, learning how to find a way to say yes and getting into those rooms and being able to present to the board is, is some of the, the biggest learnings that I've had.
I'm one of those people on LinkedIn, by the way. Follow me. No.
All right. Let's take it to the audience, unless you guys want to answer that question. You, let's take it to the audience.
Do you guys have any questions that you have for the panelists? What was the one resource, habit or ritual that was critical to your success? Or just your sanity?
No, uh, at least for me, uh, getting out and we never really disconnect, but being able to spend time with family, being close to them, being close to my in-laws, being close to my parents, uh, that, that was what really helped me, uh, stay grounded and not, not lose all my hair. I guess It's all, for me, it's all about prioritization. Every day I get 50 new things I have to look at, but you have to know from a business priority, which has the impact, biggest impact, right?
So it's all about prioritization. What needs to come first. Everything can wait.
So when, when I go through my emails state, I read them, I check, I flag every single one I have to respond to, and then I go through the week and I start responding to them. But without that prioritization, I wouldn't be able to function Community. It's the biggest thing that, uh, that was the biggest change in my career.
Uh, like it was in, you know, I was a, I was a cybersecurity architect and engineer up until probably around 20 16, 20 17, met a great group of people who, uh, who I kept in touch with. We still, we still go to each other's birthday parties, divorce parties, weddings, engagement parties. We still do that.
And we all show up at conferences together, and we, uh, we, we get to know each other's, uh, significant others. We, we are family. But whenever there's a big decision to be made, you know, we, you know, just the rage song, we rally around the family.
And that's huge because when, um, when someone, you know, one of, one of the people in that group, uh, works for a, for a pretty big security, uh, organization and had to, had to really get through a lot with the sales drift problems. And like being able to have someone to talk to that you trust and as part of your part of your family is huge. So for me, it's community.
I'll say for me it was a learning the art of storytelling. Um, people don't trust what they don't understand, and they don't open up their pocketbooks if you can't open them, understand why they're opening up the pocketbook. And so being able to use metaphors, analogies, similes, that was a game changer for me.
And, uh, it's made life a lot easier as a result. And you get trust at that point. I know there were a lot of questions, so let's try to get, so this one might be directed primarily at Sean, although interested in other folks, but you'd made a comment that your current CISO was your non-company, that you were working for advisor, that you were having conversations, curious and you mentioned, you know, network, et cetera.
How has your relationship changed or shifted now that you're working for them? And how has that, how have you seen that and have you built, you know, either the relationship with that or how did you replace that as you, as you moved into a reporting structure? So, uh, absolutely.
Uh, so the relationship does change a little bit, right? It has to, um, it moves to a, a professional mentoring, um, relationship. It's a, it's a leader and, uh, and being able to align with your leader, super important.
And yes, I, I replaced, uh, replaced that, um, that trusted advisor relationship, uh, with, with, uh, with another CISO who also is about to retire. Uh, but, uh, I, I replaced, I replaced him with an, another really great CISO that I can have really open, honest, commu uh, honest conversations with. Um, and that's, I mean, that's a, it's a hugely beneficial relationship that I, I suggest every single one of the people that work for me do that with some, some of my peers in the industry.
Don't ever tell me what you say, I don't care. I'm good. You're there to, to get mentoring from someone outside of your command structure.
One of the biggest reasons is you can't complain to your command structure about your command structure. So you gotta have somewhere else to go with it. Hi, I just wanna first say that I'm pretty sure that your bosses have told you you can't take vacation, so you're here on your own.
So thank you for doing that. Same, um, my biggest question, as the host of the Las Vegas Cyber Breakfast Club, which has 16 chapters that are all free, you're open to join any of them, by the way. Thank you, Eric, for the nonprofit plug, I really wanna know, and most of my listeners wanna know, what are the last two steps that you took to get where you are?
Did somebody help you? Did you call and fight? Did you punch somebody in the throat?
Like, what happened? So my, my boss has been a huge advocate for it being, right? So we always talk about in this industry about having mentors and sponsors, right?
Your mentor is someone who you can go to as a friend outside of your company, get a go for advice, a shoulder to cry on, whatever. It's, whereas your sponsor is, you're someone who's gonna speak on your behalf behind closed doors advocating for you constantly, right? Saying, Kathy deserves this.
Why aren't you putting her in this project? That's a huge portion of where I am today. The other portion is constantly raising your hand to take on more.
And so I think as you rise the ranks, there's always an expectation of increase in scope. And so, you know, I always approached my boss and say, Hey, I had this idea that I'd like to take on this. And he'd be like, okay, I'm gonna go ahead.
And he'd pitch it to the a c cm. Before you knew it, I was responsible for all of it. So I think a lot of it was just raising your hand when you see a gap, um, and then making sure that whatever you raise your hand for, you continue to execute and meet your commitments.
From a business standpoint, how do you guys handle personal care? Reason why, because of stress and whatnot, there a lot cys coming in and going, you guys been a, right. Now you mentioned earlier you rather stay where you are than dealing with all the headache.
But from Visa standpoint, how do you handle the personal care to maintain your blood pressure or insanity? You're coming from all the hands. I have a great pool and a great hot tub, and I get in that hot tub every night with some whiskey.
Um, one of the, one of the things that's, uh, that's super important is, uh, to, to remember the, uh, CSOs move in and out of organizations on average at a right around two years right now. Uh, I know we've got, we've got a, we've got a couple of football players out there. So think about, think about that head coach that comes in, um, and is only there for two years.
He's not playing with his players, he's not playing with his playbook and he relies on that deputy to keep everything going right. It takes about four to six years to actually be playing with your own players and your own playbook. And so that, that can be some, that first two years can be very stressful on here from e plus.
I'm a field ciso, I'm, I used to work for Silicon Valley Bank, you know, uh, sort of a deputy CISO role, but it wasn't well defined. So if you all have a formal deputy CISO title, that's a rarity. Give, give it up for that.
I really want to know what's the best way for somebody who is in a more of a operational role. It's usually a, a glass ceiling. They might be a head of engineering, they might be head of GRC operations and they don't have full visibility even at their level, right?
It's usually the CISO or the, the, the chief of staff or the exec admin who has all the visibility. Somehow there is no cross pollination the way I've seen in the, in practice. So what, how, how do you navigate that kind of situation?
You've been long enough in your role, but you are not getting that CISOs uh, right kind of delegation to learn about your peers functions and get cross pollinated. That's the question. So I'll answer that as someone that hires Deputy CISOs.
Um, first and foremost, if I'm looking for a successor, I'm looking for someone that's well-rounded. So if you're in a certain type of role, seek a job in another role, show me that you can be well-rounded and then that is the next step. 'cause everyone described a different set of responsibilities.
You can be in an operational role and be a deputy ciso, but you can't become a CISO if you've just done operations. And so they need someone that is well-rounded and well-versed And make the opportunity for yourself. For me, I had to make the opportunity the deputy, so, so didn't exist.
You have to convince them that you're worth the investment. Yeah, sometimes raising your hand, uh, you might, maybe there's no GRC component or it's weak. Uh, maybe you can raise your hand, take that on.
Same thing with incident response or any other, any of the other disciplines within cybersecurity. Differences between a SANS malware certification and A-C-I-S-S-P mile wide inch deep versus very deep in one area. I've worked with people who have been L DAP administrators for over 20 years.
They're not, they're not moving into a role. 'cause every meeting I go to is I have to contact Switch. And you have to be able, and as a ciso, you've gotta be able to walk into a meeting.
You're talking about identity, you're gonna talk about Jots, you're talking about OAuth grants. And then the next meeting, you're gonna go and you're gonna start talking about, uh, strategic directions of being able to secure MCP proxies. So it's having that context switch and you get that by, by working through a lot of different areas within your organization.
So go make friends. Um, but anyway, I really want to thank the panel is greatly appreciated because again, getting this insight is we really, really critical because, I mean, you don't see people opening up like what people were saying. It's like, so, and this is a true story.
Like one of the things I really like about this event, like last year, so one of my sons is here now. I had another son who was there and he walked over to me on the first day and he was like, I was talking to this guy at the bar, and he was like, really cool. And then you introduced him as the CISO of Royal Caribbean.
And I was like, and, and he was like, I was shocked. He was like a nice guy. And, and I was like, yeah, that's Hiro.
Hiro's a nice guy. And people don't get to like, experience people like these and everybody else who's here, many of you here. And that's really why I appreciate how open they are, how friendly they are talking and meeting people and everything like that.
So I want to thank everybody here.