Techstrong TV – January 21, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everyone, do I have a tech job for you? You're watching Techstar Gang. Hi everyone.
Happy Tuesday. It's a new dawn in America. I guess maybe it's snowing in most of the country, though, at least the three outta four locations we have, uh, here on our show today.
So we hope you're well and enjoying this, this fine Tuesday. Um, Alan Shimmel, of course, here for Text on Gang. We've got some good stuff to talk about and we've got some good people to talk about it with.
Let me introduce you to our, our gang for today. First of all, joining us from snowy. That's right, snowy Austin, Texas.
Guy Courier FU analyst, vis visible impact, CTO Co-Founder. Hey guy, how are you warm over there? Uh, well, I'm wearing a sweater, which I don't do too often here.
It's not snowing at the moment, but we got over an inch last night, which is not quite snowpocalypse of a couple of years ago, but could be enough to send Ted Cruz back to Mexico. Who knows? It's quite unusual for Frost.
We, we, we could hope. We could hope. Um, all right, well stay warm and dry and safe, and we're glad to have you on.
Speaking of snow wear, it's minus something and still snowing our man in the Rocky Mountains. Mitch Ashley. Hey, Mitch.
Hey. It's the, it's the juxtaposition of more snow, but it's minus something, so it's hard to ski very long. It's when it's really that cold, you know?
Yeah, I know you people in Colorado, you'll ski in hell if you could. I mean, well, we're, we'll ski in shorts in minus whatever, but you know, that's Colorado. Yeah.
Good to be here. Absolutely. Good to have you here.
I'm glad you're warm and dry. Also, speaking of snow, they got some snow up where he lives too, and they all wanna move and make fun of Florida. Our chief content offers.
So Mike Ard. Hey, Mike. How you doing?
I'm doing well. And you know, I'm getting all these usual summer, you know, kind of cruise packages, but one caught my eye. Somebody's out there marketing a four year cruise package with internet connection, so you could spend the next four years just cruising the wall.
Don't think I haven't looked into it. Uh, I think that's just another way of saying you're gonna drive in circles for four years. That's okay.
As long as it's in international waters, I'm fine. Mm-hmm. Um, but it's good to have you on mic and thanks for being here.
And then the only sane one in the bunch joining us here in our Boca Ratone studio. She is the Echo Insights Analyst and editor, our very own Bonnie Schneider. Hey, Bonnie, how are you doing?
Well, Alan. Not in snow and not cold. Yeah.
Happy To be in Florida. Yeah, Eric, you know, look, there's a trade off in everything, but we're here, um, and you are here watching us. So let, let's jump right into today's text on gang.
You know, Mike, I a sense of all, all getting aside about the inauguration yesterday, new administration, um, I feel a sense of Optima optimism building in the tech industry. I don't know if it's a result of all those million dollar checks they've written to the Trump Inauguration committee, or it's the good economic news that kind of followed Joe Biden out of office in terms of unemployment and interest rates and inflation and, and what have you. But it, it's not just me.
People I'm talking to, people I'm reading seem to be saying, Hey, maybe, maybe, maybe the pendulum is swinging. We're gonna return. I'm not gonna say boom town, you know, but to a more normal footing.
Yeah, there's some early data, and I do stress early, but, uh, the folks at COMT have put out a report saying that, um, based on their analysis of the Department of Labor statistics, that unemployment rate among tech folks is down, uh, about 2%, which is half the national average, and it's the lowest it's been all year in 2024. Anyway, we're all kind of on pins and needles about 2025, simply because we're not entirely sure if we're about to have a trade war and what the impact that might be. But, you know, to your point about optimism, I mean, what are you hearing from folks?
There's a lot of folks who we all know who are still outta work, but one of my theories is a lot of people are moving from big tech companies, maybe to, you know, average companies that couldn't hire good IT folks in the past, and now that transitions occur Could be, well, I, I'll tell you, let me give you a couple of data points, and some of them are kind of random, but when I put 'em together, I, that's why I feel the way I do. First of all, my friend Jody Bonsai, I don't know you guys know Jody. Jody of course, is the co was the founder of AppDynamics.
He's also the founder of Harness Traceable ai. He has a his own incubator. This is what happens when you have a couple of billion dollar companies.
But, um, you know, Jody wrote something interesting on LinkedIn the other day where he says he senses in his conversations with VCs and starter startups and founders, that the pendulum is swinging. That, you know, traditionally startups are very top line focused, right? And I've spent 25 plus years in the startup world, and I can verify that it's all about the top line, growing your revenue as fast as you can, establishing your place in the market.
And what we saw over the last two to three years, certainly with the interest rate Jack, is people didn't care about the top line anymore. They wanted to know if you were gonna be profitable, and if not, when would you be profitable? Companies started, tech companies started being sold for multiples of EBIT or not revenue.
Unheard of, unheard of in the tech world. And Jody, Jody says that we're now starting to see companies not, not disregard profitability, but focused more on top line. And what does that mean?
That means growing your business. That means marketing, that means product marketing. That means guy, take it easy.
Don't get too excited, but it means that people are gonna spend money on these things. And when we look at where the tech job bubble has been, yes, some IT folks got laid off, and how many software, real software developers, QA folks got laid off when you look, I think at most of the layoffs in the tech world, they were in what I call the softer areas, right? Tech vendors laying off marketing and product marketing and developer dev rail people and biz dev.
And, but not your hardcore tech tech. You don't see many data scientists on the breadline or on the unemployment line or stuff like that. And so with a return to going after revenue with a return of investment by VC saying, Hey, I need you to grow.
Here's money. I think you'll see the excess folks in that area, in those areas who have had a hard time finding jobs, getting jobs. And I, I think, I'm not saying happy days are here again, but what I'm saying, I think you're gonna see a, a, a distinct uptick in, in the tech hiring world as more AI projects come in.
We're gonna be building data centers. Yes, there'll probably be some sort of trade war tariffs situation with China. But let's face it, how much tech do we really sell in China?
Not even Apple. Is is that exposed anymore? I think most of our tech companies have cut their exposure there, Nvidia.
Yes. But the Chinese are gonna buy what they wanna buy, either directly or indirectly. So that money's gonna flow.
I think we're gonna see a big investment here. I think Europe, I think uk, right? I, I saw a recent report, actually Daniel Newman put it it up on LinkedIn about data center distribution around the world.
Look, I think there's 11,000 data centers in the world according to this chart. We have about 5,200 of them with more on the way the UK is like right behind. Well, not right behind it's, but it's right up there with the leaders.
So that's the good news. It's not Sunday morning. I'm not knocking on your front door, but I do have some good news to tell you.
And, and that's kind of where I think about it. You know, I think Alan, in 2024, we saw some of the big, big layoffs, right? But, uh mm-hmm.
Facebook and people like that. And, and, but other companies did quote unquote tech layoffs, um, citing both over hiring because of Covid times, um, and, but also because of the promise of AI that's gonna replace people's jobs. So we're kind of pulling back on the number of people.
I think many of us thought that's premature, right? And that's been born out. We're not quite at the place where, you know, AI is replacing lots of jobs, at least not yet.
Um, when, to your point about who's, who's getting hired, it, it's interesting, there's two trends. One is very much around, of course, ai, ml, generative AI skills and, and data science, as you mentioned, of course, cloud skills. Cybersecurity is still up there.
I'm just looking at data from, from some different hiring companies. But also there's a real focus on, on, uh, Python because of its integration so well into ai, ml, you know, PyTorch and everything else that, that it does very well. But also a big push for automation, uh, in, in the development SDLC, right?
Trying to continue the DevOps, continue the improvements that we're making on the other end of the pendulum swing is at the same time, instead of looking for that purple unicorn with, you know, gray spots, we're looking for people who are flexible in their skills. 'cause we're in a time of transition, right? There's a lot of things happening all at once, doing more cloud development environments.
We're working on ai, starting to do AI agents. We're trying to figure out what AI projects to work on is still keep the, you know, keep the engines running in the steam room. So there's a lot of emphasis around, I need some people who can be flexible and adaptable as, as things change.
So, you know, my, my advice to folks can, in the job market or, or working, is yeah, pick one of these areas that, that are in high demand. But also, you know, one, one of the best things my, my toughest college professor in computer science told me was, the one thing that you need skill, you need to always have is your ability to learn and a thirst for learning. And if you do that, you'll stay up with tech and you'll always, you'll always have work because you'll be in, you'll be in the center of what's happening.
And I think that was pretty sage of ice, at least it's helped me. This is interesting. Um, uh, what you are describing, both of you, I think is a transfer of labor out of marketing and into engineering, roughly.
And that is an idea of, I mean, one could cynically say, I would cynically say that four or five years ago, there were a lot of competing similar, listen, I made a lot of money doing this. Going to everybody and saying like, your, your solution seems so similar. They sound so similar.
You're describing them. So, uh, kitty soccer, everybody jumping on particular areas, whether it was security or digital transformation, eventually ai. And so what would you naturally do?
You would invest in marketing in order to find ways to distinguish what is actually a different, they're all different products. They just sound similar. I, I actually have a different theory to propose though.
Um, it, so, so this, this, my understanding of this analysis is it comes from the Bureau of Labor Statistics. And CompTIA is doing, doing, you know, intelligent expert analysis on it around the unemployment rate, the unemployment rate from the Bureau of Labor Statistics. There are several unemployment rates.
And the usual one is the number of people looking for work who do not currently have work. So when you stop looking for work, even if you're self-employed or you've decided to retire, you're no longer counted. Now, one of the interesting economic stories, since the pandemic has been the jump in new business formation, that's entrepreneurship.
It went up by, it's at a, it's at a rate a hundred thousand, uh, new businesses formed per year above trend. I think it's per year, a hundred thousand above trend. This is unprecedented and unexplained.
And it started in the pandemic. And it's one of these things that actually endured after the pandemic. My belief is that it, it had become steadily easier and easier to start your own business and to get funding for it.
But when the pandemic hit, suddenly everybody tried it. They hadn't been, been too scared to try it before. And so we have a permanent change a little bit more towards, you know, maybe a little bit gig economy, but maybe a whole lot new business formation.
And a lot of these folks laid off. A lot of the folks in the tech industry, there's so much opportunity to do that sort of thing that could lower the unemployment rate as well. Um, I also wanna, you think It was, it was, it was the TikTok creators come on, man.
Yeah, that's true. They're happy. Now, I was gonna say that in the sustainability and tech space, that's opened up a lot of jobs.
There's, um, a group called the Climate People that I, I met the founder a few years ago when it was just him and one other employee. Now he has several employees. He has tons of jobs I see all the time in the IT space for climate tech solutions.
So that's opening another venue for jobs. I, I, I think just to put a hundred thousand in context, by the way, I'm sorry. 'cause I'm, I always, you know, fault other people for doing this.
You're talking about a rate that was roughly 300,000 a year and is now roughly 400,000 a year growing at the same rate as it was before, but a hundred thousand higher. So that is a jump of like 35%. That's Huge.
Yeah, that's huge. Huge. That's what I mean by unprecedented.
I Wanna, I do wanna address the elephant in the room, right? So you got Benioff and Zuckerberg and, uh, Amazon folks running around saying, you know, ai, they're not hiring tech people. They're gonna be like expecting their existing tech people to do more.
And I, I, I'm not quite clear, do we think that that's actually going to happen? Or, you know, are we still gonna need all these tech folks? 'cause there's noise in the systems that says in the contract.
I think that's more directional than it is reality today, right? I mean, you can't turn off hiring people or turn off the people that you have now and flip it over to ai. We're just not at that place yet.
Maybe there's a few areas where that's possible. You know, I think to me that's more of a signal where, where they think we're heading and what we're investing in that either supplement or augment or replace those kind of jobs. AI is gonna create more jobs than it takes.
Yeah. It's usually what happens. You're gonna have net net more people in there.
Uh, alright, Wait, wait, are you suggesting that some people just say things in the hopes of moving their stock price on Wall Street? I'm shocked. No.
I I I think they, they mean what they say, but I think you're oversimplifying what they're saying. Mm-hmm. What, what I heard Zuckerberg say is that they're gonna replace some mid-level engineers or mid-level developers with AI this year.
That doesn't mean they're gonna hire more higher level engineers with developers or more lower level or net net new people. I, I think the key here is growth overall. And, and that, that's, that's the point.
And, and guy that is, you know, you look at, you know, Israel fences itself, the startup country, Dublin in Ireland, huge tech centers. You look at places that are happening around the world. Austin, Boston, they, we Used to, I was just in West Africa.
DA Dakar in West Africa has a little, well, They, they call culture happening there. Call it the tech horn at the Horn of Africa now. Yeah.
But, um, the, the fact is entrepreneurship, you know, necessity is the mother of invention. And when people don't have jobs, they look to make a living. And they'll, and many of them do start off with as gigs or consultants, some percentage, you know, more of a traditional startup thing that you look to raise money into.
But even the gig and consultant jobs, some of them will go away when those people get reabsorbed into the workforce. Some of them will remain consultants, lifestyle businesses, some of them will create new jobs. Don't forget that the real engine for jobs in this country is not Google and Facebook and these large enterprises, the real engine for jobs in this country are mid-level companies, small and medium con companies who are out hiring two and three people here and four people there.
But there's a lot, 400,000 of them a year. And that's where jobs come from in this world. It's not historic.
Agree. We, we've lived that. I mean, you and I have lived that certainly.
Absolutely, Mitch. No doubt. I I, I would just point out one thing that I, You, I, sorry.
I would just point out one thing, and I hope everybody's predictions come to be true. But in my experience, everybody starts out the new year with a significant amount of optimism. So let's cross your fingers and toes and hope it all plays out in way.
No, Those are all those people who also are gonna lose weight work out every day. I'll be the micro imagine for a moment. We always say, we aren't gonna need X people anymore because y is gonna replace them Cloud, listen, don't please na name it, it, it rarely ever happens.
And those jobs just evolve and we need more of those people, And nobody needs to worry, because our next segment will bring all the doom and gloom. Mike Watts. Yeah.
All righty. Hey, we're gonna take a break here on Text Drug Gang. And this guy says, we're coming back.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of security Bloggers network.
All right, folks, we're back with our second block and we're talking about whether or not there is this data center time bomb that's gonna explode in the back half of this decade because of AI and all of its demands for energy as a report out from JLL detailing the fact that it's not so much the number of data centers as much as it is just the simple movement of power to a new data center and the construction of transmission lines. Uh, the report seems to be indicating that we might see a 15 to 20% increase in capacity in data centers, but that wouldn't be nearly enough to meet the demands for ai. But at the end of the decade, guy, I know you've been following this space, what's your take?
Uh, well, uh, here we go, everyone. Um, this is a really, um, not the first, but a really new and clear, uh, report. Thanks Mike.
Um, about the coming, uh, uh, energy crunch. Um, our colleague Dave Nicholson and I discussed this maybe six months ago when we were trying to talk about when the shoe will drop. I mean, Dave's a great curmudgeon for us all talking about when's the shoe, when's the other shoe gonna drop on ai?
And, um, one of the, uh, likely sources of that, um, is lack of capacity. And most people think, oh, that's a lack of capacity in compute. You know, you need more GPUs or you need, you know, new ways to use, uh, uh, CPU or, you know, other chips.
That's a physical capacity of compute capacity. Um, but you gotta power 'em. And man, like we have, we have a thousand watt GPUs now, um, starting to come online very shortly, put four of those or eight of those on a sled.
Um, now you're looking at a 20 kilowatt rack. Um, and you need 20 of those in order to either, uh, do inference and scale or more likely training. Um, there's a huge space race right now going on.
Um, this is not news to anybody around training AI models. There's also tuning of AI models. Um, and it's not just the big four or five, depending on how you count them doing those foundational model trainings.
Um, so yeah, uh, where are you gonna put all of this compute? How is gonna compete with Bitcoin? Uh, or I should say crypto, which is another, uh, big, uh, uh, uh, compute and power sucking workload that looks like it's only gonna expand at least in 2025.
Um, a lot of the, the solutions have been to place these, uh, data place new data centers next to natural power sources like, uh, like, uh, uh, water. Um, they're sustainable. Bonnie, I think that should warm your heart.
Um, a lot of them. Um, but, uh, they take time to go online. Listen, the science of data center construction, um, is deep.
It's been going on for a while. You don't just need power, of course. You need space.
You need connectivity. You need to be able to cool, um, you need to be able to cool within the data center. Uh, you don't necessarily have tons of space all over the place.
You need proximity sometimes to switches or to the network. Um, all of this comes to a head such that you have, of course, I mean, we've heard stories about, or we know about, uh, Amazon and Google and others making deals with, uh, uh, local power utilities to get preferential power delivery. I, I don't know how that's gonna play out politically.
Ultimately, uh, listen, we just had a mini snowpocalypse here in Austin. Everybody's still smarting from the power outages two years ago. Um, and talking about the Texas data grid, which, uh, power grid, which is, uh, it's own power grid, unusually from the United States.
Um, so all of these, this is just the beginning in my opinion. These things are going to mount, um, as the racks become more dense, more power hungry at this point, or an AI workload. Um, 20 kilowatt racks are not really that big of a deal.
There's additional power needed to keep them cool and keep them operating. And all of these, like I said, they, they, they, they are beginning, I think, to come to a head. And that is what ultimately is going to, uh, create confusion and worry.
And maybe a little bit of backsliding in ai. That's what's gonna start it. Six months ago we said, is it gonna take six months, 12 months, 18 months?
We don't know. But we do think that's gonna happen. And that to me is what this is indicative of.
And it's not just ai. We have to remember that, uh, crypto got there before. Crypto is a huge power user, and I think arguably of limited, you know, sort of utility in the world.
So those two are gonna butt heads with each other. 'cause there's lots of people with lots of money riding on lots of crypto. Mm-hmm.
I'll add a couple of points to that. There's speculation in this business as well. And so when you hear about somebody talking about a $20 billion investment in land that they're gonna buy, they're betting that they can sell that land, but turns out the electric company doesn't agree and won't give them a connection to a transmission until they actually build the data center and have workloads to drive it.
So, um, there's some unusual activity in the system as one of the guys who we interviewed in the story put it. And that's adding another factor to this whole equation. But Alan, I know you think that this isn't gonna happen.
What's your take? Yeah, I say poppycock. Let me tell you something.
First of all, here's some more good news. And I'm the good newsman today. I just read an article about a, a breakthrough, uh, in, in the fusion nuclear fusion we've achieved the next, uh, another kind of milestone of, of along the way to commercial fusion, which could ultimately solve a lot of these issues.
Our alternative, you know, Stephen Foskett couldn't make it here today. He's our usual Tuesday gang guy. But yeah, I'll, I'll channel Stephen Foyer.
Solar keeps getting cheaper every year, right? And we're doing more and more in solar, but all getting aside, we missed Steven today, but alternative energies, well, you are here, guy, we don't miss you. But alternative energies, uh, tuning up existing energies, energies increasing.
Look, if there's a dollar to be made, people will make a dollar or a dollar and a half if they can. Now it's, but it's not a question of being able to generate enough power, it's being able to transmit it to the right places. Sounds like Nick, sounds like you're talking about building many nuclear power plants next to data centers now so that they're completely Self Yes.
And, and exactly. Let's give that a shot. We haven't built a nuclear power plant in this.
Yeah. I'm not against, I'm not against nuclear. I'm not against micro nuclear.
We, We, we are not gonna build a nuclear power plan and bring it online in the next, within a five year window. It's Just not gonna happen. So then there's the data transmission that has to get there.
All of this stuff takes time. And it is, you know, I, I spoke about My poppycock is thrown at the, at, at, at the, at the, you know, all bubbles and unicorns and rainbows. People saying that, uh, we're just gonna be able to do this because The there No, but you know what is what guys?
com boom and bust, right? com bust, the internet will never take off if we don't have enough fiber. We need higher speed internet.
We can't use DSL. We need broadband. We need broadband.
We need broadband. Korea has crazy broadband compared to us. The US is gonna fall behind in the broadband.
And then, you know what happened? You had companies like level three and these other companies that were just sitting on oodles of dark fiber. 'cause we overbuilt our capacity for fiber to what was needed at that time after the dot-com bubble burst and nine 11 and and so forth.
And we, we just, we just started lighting up a lot of that fiber recently, right? Mm-hmm. You get, it's the same thing here.
I still still think get a fiber optic connection to my house in Westchester County, York. We, we notice it every, I'm in Austin. I can't get the, I can't get it either.
Um, I was Gonna say, I think that That's that last month. I'm Sorry. No, that's fine.
I think the effort obviously with leaning into renewal, new renewables and nuclear is growing for sure, for, for data center demand. And another movement that isn't going to offset the power need, but is trying to at least, um, mitigate some of the impacts is the efforts within the AI itself to be more Efficient, More efficient to operate on, on smaller models, to be more localized. That's something a trend I've been seeing through my interviews.
So there's that, and then there's the uncertainty factor of, um, as guy mentioned, it coming to a head, you know, from when he predicted it six months ago and then it happening again because there's an uncertainty in actually measuring this AI energy use and debate on, well, how much energy is it really using? So that hasn't been agreed upon by all the parties considered as well. So I think that's something that's going to involve Necessity.
Yeah. And and to be clear, you know, I think, I think, and to be a peacemaker, I think we're both right, Alan, we're just talking about different time windows. I'm talking about that, that, that, you know, when the bubble bursts, so to speak, and then reality starts to set in, so to speak.
And then I think I'm overstating that, and I think that's coming. I think there is a backlash coming, but I think you're absolutely right. I mean, listen, people didn't stop using the internet because the bubble burst.
They just stopped using some dumb internet, Or they stopped funding dumb internet. I'm sorry, go ahead, Mike. More To the point.
Yes. The One area of the report did not address, which I think may be more feasible, is, you know, if we can move more of this AI workload off of those GPUs onto things that are more energy efficient, that will buy us a lot of time. And, but right now, most people don't seem to wanna do that because when you have Necessity, Necessity is the mother of invention.
Yeah. Yeah. But the problem is, is those chips aren't faster than GPUs, even though whatever claims there are.
'cause you go talk to people and they're like, the training and the performance of those new processors as alternatives to GPUs is not nearly good enough to make sure that the models perform accurately and at the level of performance required. So they're still investing in GPUs, so something's gotta happening on the chip side. So let's talk about small language models for a second.
Where did this, where did the small language models idea come from? My opinion is that it came from a recognition among the CPU vendors. The both the vendors most heavily invested in CPUs that, uh, they, they, they wanted the solution to the problem, their problem of all the attention going towards gp, small language models.
The usage of small language models requires a level of sophistication in the use of AI that is largely absent currently. And will, we will get there, but one of the things that will help us get there is the pain and problem of not, or of using models that don't seem to work right. Even though they're large language models or other more sophisticated models of not getting the capacity that you want and need to run the new service that you've been banking your business on.
That's based on ai. Like that kind of backlash that will be the mother of the invention of not just the technology of the, I'm just using small language models as an example, but knowing how to use it properly. We have been banging the drum on this particular show that AI does not replace people.
It helps them to be more reliable and better, but they need to know how to use it. And the general sense is still AI is gonna replace people. We will, We, you know, that'll play itself out in the market.
These will all play out with market forces pushing and pulling and stretching and compressing. And somehow we'll find a way. You're really not letting me make this tomb and gloom Like I want to Allen.
No, I, because I, you know, look, until the sea rises up and swallows us here in Florida, I'm just going to keep preaching the good news. And I, I do think we, you know, smart people find a way it forces efficiencies in the market, which is a good thing. And look, I, I think, you know, beyond the CPU uh, folks, there's a lot of people who see good in small language modules, right?
The LLM isn't the perfect tool for every job. Oh, absolutely. And it was the mother of invention in a sense of the creation of the small language model, which has, I'm just, what I'm saying is you need to know how to use them.
Small language models have limitations. They're not just, you know, you know what, what, what's the economy versions of large language models? No.
That's not how you should use No, no. I, I think of them as the specialists. Hmm.
Right. That that's what I think of them. Anyway, let's take a break here.
We're gonna come back. We've got a, a, a, a Bonnie, uh, echo Insights mm-hmm. Uh, video to, to go over or report.
Yes. All right. You're watching Textron Gang.
I'm Bonnie Schneider, sustainability contributor to the Textron Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry.
Position your company as a leader in the industry and differentiate from your competitors with the sustainability pulse meter offered exclusively from Techstrong Research. Welcome back to the Techstrong gang. You know, we talk a lot about cloud computing on, on tech strong, and I thought it was interesting to kind of take a closer look at the impact of cloud computing when it comes to sustainability, because it started off as more of a cost effective measure, but in the end, it's really helping to reduce carbon emissions.
So let's take a look at some of the numbers and how this whole movement is evolving into something that is a big part of sustainability in tech. Hi everyone. I'm Bonnie Schneider with your Ego Tech analyst Insights cloud computing is delivering a surprising environmental victory.
What started as a cost saving technology has emerged as one of the most powerful tools for corporate sustainability with companies slashing their carbon emissions by up to 77% after migration. What's the secret behind this? Dramatic reduction.
Instead of running their own data centers, companies share computing resources in highly efficient cloud facilities. Think of all the power wasted. When traditional corporate data centers run servers around the clock, most operate at just 15% capacity while consuming full power Cloud services, by contrast, automatically scale resources to match actual needs.
Eliminating inefficiency, the impact is far reaching. As more businesses migrate to the cloud, their collective energy savings adds up. Cloud adoption has already prevented over 600 million metric tons of carbon emissions.
This single technological shift can also result in a 50% reduction in it costs. What's fascinating is this environmental achievement is already transforming business metrics. Cloud efficiency gains have become crucial performance indicators as sustainability reporting becomes standard practice for major corporations worldwide.
So one of the reasons that this is important, and it's really, um, important specifically for 2025, because this is the first year that we're seeing so many regulations come, uh, from Europe. We're measuring carbon emissions. So cloud computing is going to be, uh, something that'll be mentioned and talked about more as we're getting this reporting that'll be coming in globally for large tech companies.
I think it's an interesting evolution for cloud computing. I, I don't disagree. Um, you know, it's funny, we were just talking about we don't have enough energy, we've gotta be more efficient, we need more energy, we need more energy.
And now we're talking about, well, this cloud computing makes a lot of carbon emissions, something's gotta give there, right? You, you, do you wanna drill baby drill, right? And, and emissions be damned, or, or do you, you know, try to thread the needle here with a higher efficiency and, and guy, guy, I, I'm interested, you know, you're, you're the resident Texan here.
What do you think about that? Well, I, it's, it's what we saw all year last year at, uh, especially at the public shows, right? Like, uh, like super compute.
Um, the, uh, and I, and I think it's a trend I didn't really notice in the, in the silicon, um, a lot of emphasis on, uh, but maybe for, for, you know, reasons that were not so altruistic, uh, because fitting a lot more compute into the same kind of thermal power design that, uh, the server manufacturers or system manufacturers had been using before. Maybe that was more of a, just a technical challenge they had to address. But I do think that, um, there has been maybe a change in an understanding, um, a recognition that, uh, one of the things that, uh, cloud is driving is a whole different way to, you know, build, host, deliver, and manage these workloads that people need to do stuff.
Um, that is also cost re cost reducing. One of AMD's big stories at, um, at it was the, it was the show before Super compute, uh, open compute. Um, one of their big stories was, you know, you could take a data center, a current standard data center with, uh, you know, 10 kilowatts per rack or eight kilowatts per rack, um, and reduce the number of servers by a factor of something like eight and get more compute, or get the same compute rather, um, with much denser configurations and using less power.
And I think that that, um, and that relies on the, it's not just density in terms of physical density, it's density in terms of how much processing, how many workloads, how many threads, how much you can do on a single chip, on a single server, on a single rack. And so I do think that that's some, it's just, uh, Bonnie, I'm really, uh, you know, enthusiastic about, uh, your, your, uh, work here because it's sort of an unintended consequence. And I guess I'm starting to get your sunny disposition, Alan.
It's, um, it'll All be good in the end guy, don't worry. Yeah. It seemed so much like marketing for so long.
You know, the sustainability discussions seemed so much like marketing, not that they were untrue exactly, but they were just self-serving in that way. And I think between, um, the, the serious drive in Europe and the beginnings of a similar movement in Asia, um, I think that it's, it actually is more of a phenomenon and ba and more the basis of business decisions than it used to be. And every compute now is cloud compute for the most part in one form or another.
So, yeah. Yeah, I like it. I'm curious as to the degree to which this will be achieved, right?
Because not all cloud computing is the same. I have cloud computing where I've shared infrastructure and it's a public cloud, and naturally I'm gonna see a lot less energy consumption and better sustainability rates. It seems though, when I look at a lot of the numbers, most of the growth in the cloud is around these virtual private clouds, which are kind of more dedicated services.
So while I, I have no doubt they're more energy efficient than an on-premise environment. It's not like everything in the cloud is the same, and not everything has the same level of sustainability rates as a result. Well, we talked about this yesterday, Mike.
Um, uh, we talked about how, um, there's increasing diversity, um, and that, you know, maybe in a lot of ways these still are, are like, it's almost like we're maturing as a user base, and we're understanding better that you can place things in a lot of different places. Um, and there's a little bit of mobility and like, so, but my point ultimately being that, um, it, the, the overall technology supporting, whether it's a small provider in the UK for example, or a big hyperscaler, um, I think the trend generally is still in that positive direction, both on, because the demand of the customers and just, you know, because it solves a business problem for the provider. Yep.
I mean, even So, it's pervasive, Even taking the, the do good green aspect out of it, if you can be more efficient, and really that's what this car cutting carbon emissions comes down to, right? Is a higher level of efficiency. If you could be more efficient, it helps on all kinds of fronts.
It, it helps on the AI power crisis. It helps on your bottom line. It it, it does help the environment and, and that aspect of it.
I mean, there's, there's a lot, there's millions of reasons, billions of reasons why we want to be more efficient in our use of energy, which leads to a reduction in carbon emissions. And, um, I think that'll continue. Right?
And the, the, I think if anything, the rewards will just be higher. I agree. Higher.
All right. Hey, I think that's gonna call a wrap on today's text on gang guy. Stay safe.
Stay warm down there. You know, people aren't used to driving in the snow in Austin, Texas, so be careful, Mike. They, They, they called, I just wanna say in my area they called a school day.
Yeah. On Sunday for Tuesday, Just because it might Step the forecast was an anxious snow. Yeah, Well look A little different.
And they were completely correct because little different, the infrastructure here does not Yeah, Different, different in New York or Boston or Colorado. But hey, you know, when it gets cold here, people freak out. It gets down into the forties, they're breaking out, you know, there's a run on milk at the grocery store.
Um, we will be back tomorrow. We have a full day of text drawing TV following this. So stay tuned.
But until then, this is Alan Shimo for Textron Gang, we're out. This is Textron tv. Hey everyone, welcome back here to another techron TV interview.
I've got a new company and a first time, uh, guest here on Textron tv today to introduce you to, his name is Eric Gelman. Eric is the CEO of a company called Code Intelligence, and he joins us today from beautiful Cologne, Germany. Great background out there.
I don't know if that's a real background, but it still looks pretty. Hey Eric, welcome to Techstrong tv. It's great to have you on.
Hey, Alan, thanks for having me. Very happy to be here. Thank you.
So, Eric, as I mentioned it, it's Brueggeman, you are the CEO of Code Intelligence, and you, you're based in Cologne, but you've had a, you know, you've moved around in your life, you've had an interesting journey to get here. Share, if you don't mind, with our audience, a little bit about your journey. No, please.
All, no hap happy to do so. I'll try to keep it short. So, hey guys, it's really great to be here.
Um, my name is Eric. I, I am basically on these days, but I, as you might be able to tell, from a little bit of a bachelor at Accent, I used to live in the States. So I did my masters at MIT up in Cambridge, um, and then actually started working in a non-tech field.
So I'm not a techie, let's say by a background, but I used to work as a consultant for BCG for eight years in total before I then started basically dipping my toes into the, it into the tech world, starting in a construction tech company, uh, down in Munich called Think Project, a lot of, let's say building information modeling, spatial AI being used. And then two years ago, roughly, I switched over to Co intelligence initially as a COO. And, um, yes, since then I've been, uh, basically working on helping the company scale, helping the tech basically be made accessible to a broader audience and just get the word out there in all honesty, because we've always had a great tech, we've always had a lot of smart people developing the tech, being experts in their field, but we've initially struggled a little bit to, let's say, make that digestible for a broader audience and really get people to realize the value that that tech can provide in their daily lives.
Excellent. So let me get it to Steve from Germany, grew up there, studied there, then came to, uh, Boston, MIT for your masters mm-hmm. Then spent eight years kind of in consulting.
Was that here in the US or back in Germany? Um, that was all over the place, to be honest. So, uh, I worked mostly in London and Johannesburg.
So basically on vertical axis, because what always fascinated me was to innovate industries or processes that need innovating. And most of the time actually spent on international expansion for, uh, let's say resource heavy companies, mining, industrial, something like that. And specifically on digitizing those processes, because as you can imagine in that industries, there are a few processes that need digitizing.
Yeah. Talk about transformation. Right?
Exactly. And so you were originally the COO of code intelligence. That is correct.
Um, So give us like, what was the, what was the reason for code intelligence to come into being, if you will? Right. Every, Eric, over the years I've interviewed hundreds, if not thousands of founders mm-hmm.
Of, of entrepreneurs and everyone, no one, no one does a startup lightly, right? No one says, yeah, maybe I'll do it. There's nothing else to do.
You, you jump in with both feet, your both hands, your head, your body, your guts and everything else, right? It's a, it's a commitment as they said. What, what was it about Code intelligence that say that made you make that commitment?
So I think initially it was the first launch that I had with the prior CEO and co-founder Sergei, who basically was able to, to paint me a picture of the reason for basic co sales having coming into existence, but also the vision that it wants to achieve. And that is really having a premium security testing solution that is not just thorough and basically gets you to basically find anything that there might be in your code, but also do so in a way that's really accessible for people. Because, I mean, I've worked in a strategy consulting for a long time, right?
So basically what I always saw, what bucked me out to no extent is to have a great strategy or idea in place, but then not be able to execute on it because there resource constraints, budget constraints, just you and you're not being able to translate it into reality to not make it happen. And I think code intelligence for me was this basically beautiful example of a great idea being born of the University of Bon, uh, let's say professor with three of his PhD students were all still involved in code intelligence to this day who just saw the potential of something from the academic world and wanted to basically bring it into the, let's say, business world to really make it accessible and make it used across the globe. And this is what fascinated me, because this is also how I as a basically non-techie saw a purpose of me being here because basically they had all the tactical expertise in the world and had a great product and a great idea, great vision, but what they didn't have, in my opinion, was someone who helped them translate it and make that digestible.
And I think this is also where I see my role here to say, I won't basically be able to tell them what the vision for software testing is, because this is basically where they already excel at. This is where while we have customers such as Google, such as Volkswagen, such as, uh, woven out there who work with us on these topics, but what we've seen is that scaling that solution, making that accessible to not just experts, but really at scale to get to the value that it can create, this is something we need to get better at. And this is something where I felt I could help code intelligence and our customers in doing so.
Got it. Excellent. So, you know, it's funny, right?
2001, I started a security company out in Boulder, Colorado called Still Secure In 2003 oh four, we launched a product called v Vulnerability Assessment and Management. And this is when I first really got really involved in the whole vulnerability space, you know, and the world was very different than Eric, right? No one, almost no one did a vulnerability scan on code pre-release.
Almost all of vulnerability scanning was scanning your existing infrastructure and mm-hmm. Code and fixing it, I was gonna say in real time, but no one fixed it in real time, fixing it over time, you know, while it was out there, it was like changing the engine while the car was driving around the track. Not a great way of doing things.
Not exactly. Uh, and then the whole sort of AppSec shift left the idea of fixing vulnerabilities in code re-released. Mm-hmm.
You know, it started with, well, pen testing was, was was before, but you know, it, but using those pen testing tools, pre-release AppSec testing, my friend Jeremiah Grossman at White Hat Security early, early on, uh, uh, AppSec as a, as a service basically. Uh, and we, and that's become, you know, today, I always, this always makes me laugh today, 75 or 80% of code is scanned before it's released or deployed. It makes you say, what about the other 20%?
What are they crazy? I mean, how do they release it without scanning it? But nevertheless, most code is scanned.
Mm-hmm. Why is code intelligence better different than other, you know, pre-release vulnerability tests out there? So for me, I would always try to divide the, let's say, current approach that exists to two categories, right?
I mean, you have those fully automated, let's say SaaS solutions, static nozz approaches that do go through your code line by line, but at the end of the day, they don't test your code in execution, right? So they won't, will never be able to, let's say, get out to the, to the high complexity vulnerabilities that then only might become present when actually the code has been deployed and when things are too late at the end of the day, right? Or you do, you do have those, let's say, high quality premium security solutions, such as fast testing, such as penetration testing as well.
But they come with their drawbacks. And the biggest one for me is that there are just a lot of effort and they, a lot of, let's say, time and money that needs to be spent to adopt them and to continue to, to, to leverage them. And where I see the gap here is that we need, again, to have some that isn't just good in theory, but that also creates the impact that it can potentially create in practice, right?
And this is why I think basically having code intelligence as an, as a startup that combines deep security testing knowledge with artificial intelligence and thereby makes it accessible to a broader audience, that in times of resource constraints, in times of budget, constraints in time, in times of a tech world that is no longer just going up, up, up without let's say any, any end in sight. I think this is what's needed to also make sure that we can keep up with the times, right? Because lines of code being created every year is exponentially growing every year as well.
Complexity of code and vulnerabilities within that newly created code is also exponentially growing. If you multiply those twos, you just need to change your test strategy, in my opinion, because you will just not be able to keep up with the times if you don't. And this is, I think, where we come in to help companies keep up with that, those developments, and actually be able to sleep at night and confidently tell themselves and their customers that A, our product is safe because we haven't only basically run it through the typical, let's say, traditional automated approaches, but we've employed deep security testing in a manner that basically can't really guarantee, because you can never guarantee, right, this is how, it's the issue here, but that's, that's security close.
Exactly. That, that's as close to guaranteed guarantee that there are no, uh, vulnerabilities in the code as possible. Excellent.
I, I know you guys recently launched something called Spark, and we're gonna hit on it in a second, but I just want to tie a few loose ends up. Um, who, who is the average cu? You mentioned some, you know, household names mm-hmm.
Earlier as customers, but who's the average customer of Code Intelligent? Is it intelligence? Is it the large enterprises or anyone, or, you know, how would you describe that?
Yes. So large enterprises tick, but for, I always present it as we want focus on word holds most, right? We wanna focus on the industries where the downside of having undiscovered security vulnerabilities are the highest.
So we work a lot of, with automotive customers, match tech customers, critical infrastructure aviation companies that traditionally might not have been in the software space to such an extent, but for which software continues to play a role that is almost as central as the hardware, uh, one used to be. And I think helping them basically keep up with the times and really ensure the highest level of security possible, I think this is where we want to spend our effort and time. And for people who wanna find out more about Code Intelligence, what's the website?
com. Simple as that. Easy.
Good. Alright, let's jump into Spark. Yes.
So you guys recently released a new, uh, product service called Spark. Tell us about it a Hundred percent. Well, this is basically embodying what I've been trying to explain the last couple minutes to really make premium security testing accessible, right?
Combining artificial intelligence. So large language models, genetic algorithms with testing approaches such as static analysis, such as fast testing, white box, fast testing, and really making sure that you don't only find anything there is to be found in your code, but you also do so without the typically required manual effort. So, for example, we always, let's say better test our product with code base of roughly a hundred thousand lines of code because we feel that's a good estimate.
That basically is tangible and let's say, digestible for people and represents, let's say, at least a small part of a typical company's repo. And what we've seen is that typically our people spend roughly a thousand hours of manual efforts testing that code, really at a depth that we felt, look, this is something that we feel comfortable with with Spark, that we're now launching to the market end of this month, and that's already being used by our key customers. We reduce that down to one single command in your CLI.
So basically all you need to do is you need to point our tool as your code repository and our tool does the rest for you. So it scans the code, identifies the most critical areas where, let's say the most potential threats might lie. It automatically builds and runs the fast tests required to really thoroughly test your code, make sure it runs in your local build environment, your local infrastructure.
And then obviously also adds the benefits from fast testing by generating thousands of different unique test inputs per minute that are automatically refined and smartly generated. So basically they learn from previous iterations and try to discover all unique, uh, let's say paths in your code that might lead to crashing input. And uh, that's what it does all at the push of a button, Really.
Now, um, so it's an agent that runs though in, in your infrastructure. Exactly. So for example, what a lot of our customers do, they plug it right into their CI ICD, let's put it simply put, right?
'cause what I've learned in my time in tech in the last couple of years is that especially for security testing, if you talk to the developers who build the code, if there's one thing that I can avoid doing and like to avoid doing, it's basically writing security tests, right? Because they wanna focus on what they're good at is what they're we're hired to do. And that's built code, right?
Not test code, not right security tests. And I believe that you will only be able to have a fully scalable test strategy if you will almost go beyond shift left, right? Because if you still need to con continuously involve the developer who built the code, you will never be able to scale with the, let's say, uh, demands of the, let's say, modern world of the demands of the, let's say size of the code basis.
You won't be able to deal with legacy code, which continues to make up an even bigger and bigger portion of company's code bases. And this is why we said yes, obviously having the developer involved in that process has no downside, but you no longer need them because you can basically do this automatically by having it in your CICD. And then, and this is our, uh, let's say, tar for 2025.
Not only identify the critical vulnerabilities in your code, but also provide an automatic fix for those vulnerabilities that has been proven to work. Because basically we can just rerun the fast test with the new code that we've been, that includes the fix and make sure that it actually fixes the issue that it found. And even more important, in my opinion, also doesn't create any new issues that hadn't been there in the first place.
So I think this is what we're trying to aim towards, to really basically try to provide a central C-S-C-D-A central security team with an AI test agent that helps them focus on what they are good at doing. And that also frees up the developer's time to allow them to focus on what they're good at doing. And that is building code and actually moving the company forward.
Love it. Or is it sold? Wait, God, is it a service monthly, yearly, or It's a license model?
So basically you only need our license, and that typically is sold on an annual basis, uh, for companies to profit from it, from it. But shorter timeframes certainly have happened in the past and longer ones as well. Um, initially, basically, we typically have a proof of value phase of in between two weeks and, and six weeks where we do spend some time with the customers trying to understand their requirements, trying to understand their infrastructure.
But the good thing is that typically on day one, we make sure that it runs in their system. Day, day two, we start finding the first vulnerabilities. So, um, it is quick to implement, because again, if it's only good in theory, no one's the wiser.
At the end of the day, it does need to work and does need to be easy to access. Absolutely. So, Eric, let's assume for the moment, spark and code intelligence discovers vulnerabilities without human interaction.
Of course, the question becomes what's next? Right? Who's fixing them?
When are they fixed? How are they fixed? Do we automate the fixing of them?
Do we have to let people approve fixing them? The, the whole remediation piece of it, how does, how does code intelligence interact with that? Yeah.
So I do believe that remediation needs to be part of this, let's say test strategy because only a fixed bug is a good bug. Let's, let's put it simply right. That's Bug is the fixed bug.
But I do believe that, especially let's say with the developments in ai, and AI is still, let's say, being in its, let's say early days, right? And people still being for good reason, distrustful of AI and wanting to make sure that basically it does what it's supposed to, uh, but not anything beyond that, that the final fix does need to lie with the, let's say, person in charge with the security professional, right? So what we working on in 2025 is to say, look, you provide a pull request right in your COCD and be it GitHub, GitLab things that I think this is basically something we are quite agnostic of, but it only provides, provides a pull request with a proven fix.
But it still needs, there needs to be a human element accepting that pull request and saying, yes, this is something that works because we don't wanna take the control out of our customer's hands. Quite the opposite, right? We just wanna make sure that we focus their time on where it's best spent.
And that is basically reviewing the pull request, making sure that everything has been considered. If it's a complex vulnerability to be fixed, maybe actually check in with the developer who built the code to triple check that nothing can can go wrong, but not get into an automation mode where basically things are happening that go beyond the control of the individual user of the individual company employing code intelligence and employing those, let's say, a automatically generated, um, let's say security tests and remediation fixes. Got it.
Alright, Eric, we're about outta time. I just wanna remind people mm-hmm. com Yes.
Is the website Spark is the new AI test agent service. Eric, thanks for joining us. I appreciate you jumping in from Colon.
Best of luck with Code Intelligence and keep us posted. Thank you so much, Ellen. It was great being here.
Happy to talk again. Pleasure. All the best.
All righty. Good. Next time.
Bye-bye. Yes, Eric Brueggeman, CEO code Intelligence and spark their AI test agent autonomously. Uncovering vulnerabilities here on text drunk tv.
We're gonna take a break. We'll be back in a moment. All right.
Welcome to episode 67 of Infrastructure Matters because it does matter. Join me today are the usual cohort, Kimberly Diane, uh, somewhat of a slow Newsweek with, unless you're a big fan of enterprise storage, AI data center, power cooling infrastructure matters. Folks, welcome back whole.
You are a fully in the swing of things. This is the second full week of work as we're recording this. Uh, hopefully it's been a productive work week for you.
Who wants to start off the conversation? Well, I can get started with the big announcements that happened. Um, not to complain too badly about it, but they got me up at, like, I'm already up at 5:00 AM but I'm usually working out.
But the call was at 5:50 AM my time. Yesterday was two days ago. On Wednesday, I think it was, um, Lenovo hosted a call to announce that they ha are going to be intent to acquire Infinidat.
And so for those GU guys who don't know who Infinidat is, INFINIDAT is a, the third company, is it the second company? Second company, no, third or second company. Moshe started.
So Moshe, it was, uh, the originator of something we all know and love if you're in the data storage business called Symmetrics. Um, he is, he was the lead on that. He left, um, EMC many years ago, started a company called XIV that got sold to IBM.
Um, and after that one, he started this company called Infinidat that was specializing at the time in hard drives, fronted end by, um, a big cash SSD, and then eventually whatever, but super high end system, um, targeted the big enterprise companies. And if Lenovo has done very well with their storage environment over the last, whatever years it's been since we've been tracking them on the storage site, all of their relationships up to this point have been OEM. So they, OEM people like Nutanix, they, OEM, the low end of, uh, NetApp's Systems, um, there's an agreement with NetApp that they're selling it into China, et cetera.
Um, they've done well and they've taken over some number one spots according to the IDC counters, um, and the lower end levels of the storage. Um, we've had lots of conversations with them about, you know, what is it gonna take to claim the, the higher level ones and a, you need the products, um, so here would be the likely suspect for you to purchase. Not that we, we influenced that or anything.
Um, in fact, I didn't even pitch Infinidat. I should have, um, to them. Um, and so here, the, here we are, you know, how many months later that they're acquiring Infinidat, which is a very high end, um, storage system that is primarily sand block as well as, um, the system also runs a very large, high-end scalable, um, backup target.
So location, et cetera. So they're really super solid product. Um, but as you can imagine, competing against the cor crown jewels and the most profitable of the data storage infrastructure is very difficult to do.
They are a profitable company. They're not, you know, not some fly by night kind of company. Um, Phil Bollinger, who, um, has been in the industry forever, took over the CEO waves, um, five years ago and got them to that profitable cashflow positive space.
So very, very cool to see some of the movements, some of one of the first movements that are coming in for the, for 2025, expect to see a whole lot more. Yeah, this Kimberly is very interesting. Um, you know, we continue to see consolidation in all these spaces, but I, I don't track storage that closely.
I'm wondering what you think about, you know, the, uh, the CIOs I work with, they're really don't like to see this, this, uh, consolidation across the infrastructure sector. 'cause it reduces their choice to being beholden to one big vendor, which they have absolutely no, no leverage over. Uh, are are, are we worried about consolidation or concentration of, uh, of vendors in that space?
No, because Lenovo hasn't really been in that space except for the low end. And what I call the space that they've been playing in is the entry level market, um, what I call the server led storage sale where bar goes in pushes that you attach, you want fries with that, here it goes. Um, and that happens there.
So Lenovo, this is entering a new market. It's one of the challenges of this purchase because they don't, while they have storage sales people, the guys that go in and these are multimillion dollar transactions that go down, um, the guys that go in and sell this stuff, they, they're focused very much so on this heavy duty technology. High super high availability, you know, never go down kind of technology.
Um, you know, highly, this is where your secure data is gonna be residing, et cetera. So Lenovo's gotta spin that up and bring that to the, to the United States. And so what we're gonna see now is you'll see in that space competing pure will compete there.
Although there may not be at the level of Infinidat, NetApp will definitely be there. We'll see. Um, PowerMax from Dell is there, IBM's DS 8,000, 8,000 series, as well as IBM's, um, flash system will be up there.
And definitely Hitachi who is back in gear. So that's, that's a lot of companies I just rattled off that are in that space. And there's big enough, enough there to keep that competition going and, um, the pricing, um, situation, uh, under control.
So yeah. And what, what enterprise architects do like about these types of moves is that you get more pods, you get more engineered solutions, and the name of the game is in engineered solutions. Lenovo will now be able to sell, even CIOs may not like this, uh, that no Lenovo can now sell, you know, Lenovo server for more money.
'cause it's more value when you come with a completely engineered Lenovo deci, uh, the Lenovo engineered system. From a IT op operations perspective, there is a lot of advantages in engineered solutions. They reduce the overall cost of delivering services because you don't have to spend the engineering time taking the best of breeds engineering them together.
This is, uh, a obvious, uh, I thought was a obvious hole in Lenovo's offering, not having truly in-house engineered systems. I fully expect them to at some point fill their networking gap. Uh, as we're looking at challenges around building pods for ai, Lenovo doesn't have a full stack to offer in-house, and I expect that to change over a period of time.
Who's available from a networking perspective for them to go out and acquire, you know, we'll, we'll see. So the other piece to the value proposition of Lenovo Infinidat is where some of the engineering is gonna go into is Infinidat has been doing off the shelf hardware. Um, they don't have the supply chain negotiation capabilities because they're not that big.
So we're gonna see Lenovo be able to, you know, bring that muscle into there as well as bring their capabilities of what they have for engineering and design for the infin, that system. So I think what we'll see is improvement. Um, the guys in Israel, which is where this came out of, are super good, super good engineering.
So you combine that with the smarts of what Lenovo is. And I think this is just, just as an all, all over is a good move and really brings another offering to the high-end environment. I know Eric Herzog is gonna get p****d off at me for talking the only high-end stuff because they do kind of go, they go down to the smaller sizes, but, um, that's where they played the best.
All right. So that, that, that, that's one story down. Uh, you have another one, cam, Kimberly, what else, uh, did you notice this week?
Yeah, NetApps spun off something called Spot, which is a finops offering for managing your financial, the cost of the cloud. Um, they bought them, I don't know, seven years ago maybe at that time, NetApp was really focusing on this cloud strategy, cloud operational strategy. Um, that's where they were going and thinking that that is what was what's going to grow their TAM into that space.
And Anthony l was the lead on that, and they acquired a whole bunch of companies at that time, spot being one of the lead, one cloud checker, et cetera. So they've spun off both of these cloud checker and spot to Flexera who specializes in finops and those, uh, um, operational efficiencies. Um, and what this is basically saying is that NetApp is going back to core, which is data infrastructure and some of the key core issues around data infrastructure, which are ai, cybersecurity, you know, also all the rest of the stuff, hybrid, hybrid cloud or whatever.
But that frees up, it just, it, given what we have with AI and what's gonna happen with AI over the next, you know, 12 to 18 months, um, and the capabilities out there, this has raised up a whole lot of, uh, cer engineering to be able to focus on their core, really the core business. And I think it's be gets them better aligned for the market space. Yeah, the, I follow the SPOT cloud checker, that part of the bu, uh, or that part of the business for NetApp for quite some years.
'cause that's my space. And NetApp was never really able to tell a cohesive story around how they can do, uh, workload management. Ontap everywhere on all the public cloud providers has been a wonderful story for NetApp.
The ability to do distributed management of all of your data assets across multiple clouds. I'd argue NetApp has the best story of all the MA major cloud providers. They have per first party solutions with both, uh, GCP, Azure and well all three, uh mm-hmm.
First party solutions. And, and it, it's really important to, to, to note that these are first party solutions. I can buy NetApp ONTAP directly from a WSI can assign access control, uh, rules directly from, uh, my AWS account into the NetApp services.
So there are natural services and no other storage provider can, uh, claim that it's unfortunate that they haven't been able to create a cohesive message. And I guess it's better to just give it up than try to play it a game that they just couldn't figure out. Yeah, and I'll add to that first party, one of the biggest values on that first party, um, position is that they are in the sync of that role of the security, all the security issues.
So they're right in the middle of, it's almost, it's, it's their engineering, if you will, um, when you're a first party. And so that when they do an update or a major update, you know, NetApp is right there, stop, you know, lockstep with them. All right, Diane, let's, uh, move on to your, uh, news of the week.
You're, you, you, you've become our resident, uh, follower of all things that are executive orders. The, were nearing the end of the Biden administration, and with the end of area administration comes a flurry of executive orders. Which, which of any stood out to you this week?
Well, there is, uh, several, uh, but the one that was, uh, I, I kind of raised eyebrows was a last minute, uh, cybersecurity, uh, executive order. Um, it was, you know, they called it sweeping. Um, and it did have a lot of things inside of it.
Um, now we, we do need to always increase our posture with cybersecurity. And, you know, my, my initial read is none these individually are, are bad. It's just the, the burden it puts on vendors and to some extent, uh, end users is, is very interesting.
So the, the first part of it is, is that really, uh, beefs software, supply chain security, so that, uh, uh, security companies are required to submit machine readable attestations of secure development processes. And it looks like it's not just security providers, it looks like it's all software providers. Now, this, just Do that again, machine readable Attest of secure development practices so that they know that they don't, they're not buying or using technology, uh, from vendors.
They haven't thoroughly audited to make sure that, that they're, you know, it's not, they're not from China and putting malware inside, you know, some, some library or framework they're using, uh, you know, or, uh, or a software development team that's in, in, you know, Eastern Europe that might be corrupted by Russia, uh, and that they're placing back doors in the software. Uh, you got to, you have to say, here's what I've done to prevent, you know, sure. I don't do that.
And the machine readable part is interesting, but, but more and more software is now enterprise software is bought through cloud marketplaces. Uh, I, you know, I've did, uh, a bunch of, uh, uh, videos recently with the heads of AWS marketplace, and they did $40 billion in sales last year. They're gonna do over 50 billion this year, billion.
I mean, that's a large, that's a significant part of the software market. And what's nice is now, um, you can go in and you can set your dials on what policy and say, here's here's the level of compliance I want to have for, uh, my, you know, uh, uh, uh, software by providers and their development practices to make sure they're secure. And then it can filter out all the vendors that don't meet that because it's machine readable attestation.
So it's interesting. Yeah. And if you have in-house developers, this puts a burden upon you because you're, uh, providing software services.
It, this is not, again, I don't, I agree with you that I don't think these are necessarily bad things with, uh, the what happened with SolarWinds a few years ago and, uh, having, you know, the right hygiene around software bill of materials, this is super critical. If you have open source practices, if you're taking down, uh, stream distributions and then adding value upon them, you need some level of assurity that the software, especially the open source software that you're using, is free of these types of malicious defects. And this codifies it to some extent, whether or not you are, uh, under, or whether or not this executive order falls under your burden or not, probably irrelevant.
These are just good things you should look at and determine on whether or not, you know, uh, your software development practices are following, you know, best Practices. Yeah. Oh, no, I, and if that was it, it would, it would be, you know, I think really good is just that, that was just the very beginning of the executive order.
It also covers, uh, things like, uh, uh, mandates federal agencies to adopt phishing resistant authentication methods to move to post quantum, uh, cryptography standards immediately. Yeah. To, so that they have, uh, the federal government uses quantum resistant cryptography across the board, um, mandates AI and cyber defense, uh, has a whole bot say about cybersecurity in space, which is getting critical given, uh, you know, there's launches now every two and a half days on average, putting new satellites, uh, data satellites in space.
You have kuer coming online soon. Um, the, the Chinese government's putting their own, uh, constellation up the EU is putting their own constellation up. So, uh, there's a bunch of things that, that say, how do we make all that safe so that, you know, hackers don't, don't, uh, take that over and control it.
Um, open source software management. And then to really round out the whole thing. There's a new requirement for vendors, which I like personally.
Uh, it establishes a cyber trust mark for our, our consumer Internet of Things devices, which is one of the worst vectors for, uh, security instance. Uh, since, uh, most of these are small vendors. They barely get their product together.
They haven't done the, the full pass for security. And, you know, I remember, um, I was talking to the, the, uh, CIO of, um, uh, Experian when they had, it was a printer driver, uh, an IOT printer driver that, that took their kaiser, their whole data breach, you know, so it's a real thing. Yeah.
I, I, uh, used to advise customers, uh, one, don't use IOT in your production network because you're asking for trouble. These are super small vendors. They're security practices, as you mentioned, are, uh, minimum at best.
But you know, this whole ideal of isolation and, um, uh, satellite networks of not being able to reach your production network without, uh, at least some significant, significant effort to get from the IOT networks into your production Network. Microsegmentation becomes so important is you put, put all those devices in their own little play pan that you can't get out of. Right.
You know, then yeah. If You've ever had to, to battle, uh, the early stages of like cold red on Xerox machines, you'll understand why this is important that, uh, these devices have unli, basically unfettered access to your client, uh, networks and potentially your data center network. So again, good hygiene stuff, but another burden upon vendors and businesses.
Uh, I think, uh, my only piece of news is IBM and Core Weave partnered together, and Core Weave would be providing IBM with a supercomputer, which seems kind of weird, right? Right. IBM going to another vendor for a supercomputer, specifically a AI supercomputer to train their granite models on you need Nvidia chips.
Nvidia chips do not work with power processors. This is a simple math. IBM can either choose to go out to cloud providers and, uh, rent CPU, they can choose to do it slower on IBM mainframes and power based servers, which is not a option.
Or they can partner with someone, I'm sure it's not going to be HPE Dale or Lenovo, uh, their friends at Lenovo. So they chose Core Weave to build the first supercomputer with GB two hundreds. But does Core, core Weave is not a, They're they're a provider.
They're provider. They're A provider. So they're using somebody underneath there.
Right. And who, who we who? They're EE either they're building it from bits and pieces, uh, custom or they are using someone, but that's obs, ob, I think is the word, obscured.
The, uh, we're abstracting the way. So maybe it is Dale, uh, or HPE under the hood, but IBM doesn't have to say. So the, I don't know how much of this is the waving of the hands versus, you know, legit engineering work outside of selecting a vendor to basically be the vendor for, uh, uh, Nvidia.
And I think this highlights one of the things in the industry that we don't always recognize Nvidia, choose the customer chooses which vendor Nvidia is going to sell chips to Dell, Lenovo, HPE for all their plus, or don't get to choose how many bits and pieces they get from Nvidia. The cus large customers say, I want you to sell, I want to buy chips from Dell. And that's how Dell is allocated chips.
Little inside, uh, analysts talk there on how these decisions are made. So I'm sure IBM knows who's, who's actually building the, uh, the underlying infrastructure that core we will provide. Interesting.
All right. So we are going to go with our second round of predictions. This is the beginning of the year.
Diane, you had a massive blog post on your predictions. They, it was a little bit non-traditional. I enjoyed it.
It wasn't like, oh, watch these three technologies. You really took at it from a, uh, you looked at it from a strategic perspective. Recap for us your predictions for 2025.
Yeah, You bet. Uh, you, well, I think it's gonna be an interesting year for some reasons. Um, uh, and, uh, so I'm, I'm gonna go, go over my, my top predictions because there's not time to go over all of them.
Uh, and to keep it lively or you guys keep me honest, poke holes in them, make comments on 'em as they go through each one. Um, the, uh, so I, I predict that AI will continue to drive both the tech stock market, um, uh, and growth, uh, for tech companies, uh, until it doesn't. So at some point this year, there, there is likely to be an inflection point where people say, look, the $400 billion you guys are spending on AI isn't gonna pay off.
You're not gonna get ROI in time soon. And we might see a, we might see a bubble burst in the, in the tech stock market. Uh, so far there has been some hope though, uh, uh, late last year, both Lenovo and Palantir became the poster children for, uh, tech companies that are making money off ai.
Uh, and, and they're actually turning in net profit. Uh, so, uh, Lenovo with their AI infused PCs has got a good sales bump. Uh, and, uh, Palantir attributed their big sales rise entirely to their, their AI services.
And so those are, those are the bright spots. And if we see a half dozen more of those this year, showing some signs that some vendors are getting, uh, returns, uh, uh, that stock market likes. 'cause you know, the, the risk is we end up with a situation like we did with AWS, remember their stock was depressed for years.
'cause Bezos said, I have one chance to become number one. Uh, I'm going to put all, plow all my profits into growing AWS and until we dominate the industry, and then I'll take my profits. And of course, that's not the 90 day returns that the stock market wants, and their stock price was punished for, for like a half decade.
Uh, and that's the risk with AI stocks 'cause that 400 billion. And that's just, that's just so far, Microsoft's thinking another 80 billion this year. How are they ever gonna get that back?
Is what people are starting to ask. And so I think there, there is a chance that we'll see the AI bubble burst this year, at least deflate a little co comments on that. So I love the perspective that, you know, and I I generally agree that AI bubble, if it is a bubble, is not gonna burst this year.
I think that this is going to be a another year of it. And we'll get into, I, I think I only have one prediction this year that I'll sh uh, go into some detail next week on, which is that this is the year that enterprises try ai and that long tail will hit us and, uh, will continue to see kind of this pumping of the market, uh, from the, uh, perspective of preparing for enterprise adoption, which I think will start in earnest this year. I would agree with that, and I, I think we will see some sort of hiccup here and there.
Um, but I think there's other up and comers that will be the investment part of it. Um, part of that reason is because we have seen, you know, whatever percentage, not a whole lot of these AI initiatives make it out the door. I mean, the number I've seen is anywhere, anywhere from 10% to 30% of the initiatives are actually successful and do some sort of, are making it out.
Um, that will probably increase in success over time. Um, the second piece of that is what we're seeing is that a, the software companies might take an SAP or Salesforce or Marketo or, or some of those folks are developing AI tools themselves. So you're gonna, I think, and you probably know about this because you talked to 'em, if I was A-C-I-O-I pause on some of my initiatives and say, what are my vendor software vendors coming out with that I can don't have to build from scratch.
I can take what they have, add my data to it and push it out. So that, and then getting some of the smaller language models that will be coming out that are very focused will also change how this trajectory goes. So all of that, and maybe that the enterprise doesn't need all this gear, so that where some people are projecting that they would need, um, but it would be purchased by the big Software.
Yeah. Maybe go onto the vendor side. Yeah, very in the, uh, uh, in the, on the hyperscalers as opposed to, we'll see that.
I have a prediction about that. So I, I, I only, I'm pulling 'em only in my top three predictions, and one of 'em actually covers that a little bit, which is interesting. Um, so the, my next prediction is that we're gonna see at the high end of the AI market, we're gonna see this, this really bruising competition, um, around achieving, uh, what's called a GI or artificial general intelligence, or, or other people call super intelligence or so AI models that, that are smarter than humans.
So, uh, is right now, right now, no AI model has, they can, they have more access to knowledge, but they don't, they can't outperform humans at the very, very high end until very recently, we're starting to see some models cross that benchmark, but that's talking about general intelligence, many people would argue. And so there's a big debate in the industry what that is. And there's now, uh, benchmarks being developed to measure a GI.
So the, uh, the ARC Prize Institute, um, uh, launched a series of benchmarks to see, to try and validate what, which models are closing in on the traits that they consider are, are artificial dental intelligence. And this is important because you wanna hook up with an AI vendor that has the biggest vision that will generate, create the most powerful ais that you can then use for your business. And that's the proposition of open AI and anthropic.
And those are the two big vendors that are, that are, that are talking a GI in a big way. And they're, and they're saying that's their primary goal is, is to, to reach that. And they, they wanna do that same reason.
Uh, the a uh, that Bezos way back in the day was sinking all that money into now Amazon, they wanna be the best, they wanna have the grandest vision with the most superior sweeping products that will attract the buyers is if, if AI is going to, you know, transform my business, I better use the vendor with the, the biggest vision, the most powerful products. Um, and, and, and that's what they're betting on. And of course, there's a, most people are concerned about, we're developing things that we don't know yet know how to fully control, uh, of course is the big risk.
Uh, but, uh, you're gonna see that, uh, those two vendors, that there's a few others there, but there're, they don't, I don't think they have a likelihood of having great industry impact. They're giving it their all. Uh, Altman says, you know, they're sinking tens of billions of dollars into a GI every year.
Um, and they expect to, to, to have, you know, significant product announcements around this in the next year or two. So, um, I think we're, we're gonna see that the high end of the whole AI conversation increasingly go talk about these, these smarter than human, uh, models and ones that, that, that act very much like, uh, humans do in terms of how they, how they think. So it's gonna be fascinating to watch, um, and we hopefully we'll all better confront it.
Yeah, I, I, I've spent the past two weeks deep diving with, uh, actual end users and helping them through AI and leverage what's out here today. And I have to say, I'm, I'm, I'm a bit skeptical on this whole idea of a GI, uh, from where the state of the art of the technology is today. I, I, I think I can fairly say with confidence, it's not gonna be here to this year, but I love the idea of coming up with standards that we can all agree upon.
I've been, uh, frustrated with the, uh, lack of definitions around technical capabilities that have been overtaken by marketing. I'm, I'm hopeful that the industry can get in front of a GI so that end users really understand, uh, the different levels, uh, and can quantify the different levels of AI that they're using. So Maybe we should get the Department of Education involved with the standards, and so they can issue a standard test like we give to our, our high scholar.
Anyway, go on. Just ignore me. Well, no, that, that's not, that's exactly what's gonna happen.
We see the same thing happening with agents. We're actually seeing, you know, uh, hiring marketplaces, uh, pop up that, that, uh, list digital labor, uh, you know, Salesforce with Asian forces doing that. We're gonna see labor standards around, around digital bots here soon.
It's gonna be interesting. See, so yeah, it's a brave new future, uh, everyone. So, uh, to round out my last, uh, major prediction, um, uh, we're seeing, uh, I just completed it and I, we even did an episode around my CIO insight, um, uh, for the, for 2025.
Uh, we did, we surveyed some of the top CIOs in the world, and I asked them what they think is gonna happen this year. Uh, and one of the signals that came out of that is 71% of CIOs says they are seriously recon, wanna reconsider where they're putting their cloud workloads. That's the, by far, the highest number we've ever seen of, of, of, of CIOs saying they're really gonna rethink where they're gonna gonna put their workloads.
And that could be in another cloud provider or another type of cloud provider that could be going, that could mean going from public cloud traditional to, um, serverless. But, uh, uh, there's a strong undercurrent where a lot of 'em are saying, we're gonna put certain workloads that, that, that run best that way, we're gonna put them back in our data center. So, um, it, uh, using a private cloud model, so same, same cloud technology is just that if it's always on, uh, for example, if workload's constantly running, uh, or if it's, you know, it uses a lot of capacity.
Like you're, you're doing this training that's gonna run for weeks or months, why would you pay that cloud markup? Uh, because not only do you have to pay for them to, to, to run it, you know, a provider to run your workload, but you have to pay for their cost of sales, their marketing, their r and d, and then their profit margin. Uh, for every minute you're running a workload, you gotta pay, pay that bill in addition to what it actually costs for that provider to run it.
They used to be economies of scale would offset a lot of that, and, and they could, the provider could still, um, extract most of that, of that extra cost inside the economies of scale. But that's not necessarily the case with the AI's contract everything on its head. So we're, we're not seeing broad based repeat repatriation, but we're seeing like this real will saying, we gotta, uh, now that our cloud bill is getting so big, we really have to think smart about where best to run each one of these workloads.
And so far it's only on a work workload by workload basis. So we're not seeing people saying, we're gonna recon we're gonna go back and reevaluate every workload we have. That's not what we're seeing, but we're seeing more willingness now to think outside the box.
The thing of cloud is a broader spectrum that it's, it's private, it's edge, it's hybrid, and it's public cloud, and it's these new models, things like, uh, serverless, uh, we, we need the, if we're, if as we're doing the finops and discovering how much this really cost, we have to get smarter. And that was so, uh, my prediction is CIOs will extensively rethink their IT supply chains, uh, with respect to cloud in 2025. You know, I looked at your data, looked at your data, which was really, really good, um, the other day.
And the other flip side to that though was this piece that said, are you investing in your cloud? And the answer was yes. So it's not like it's going away at all.
No, not at all. Not at all reevaluating how, what's, where's the best place and how's the best place to deploy what we're doing? So really, really great data.
Yeah, I talked to a customer that's spending a hundred million dollars a year in AWS not just on public cloud, but AWS Wow. And that's not even the largest of cloud spends out there, but this is, you know, a enterprise Fortune 100 and their priorities are right sizing that AWS bill, they're not looking to exit AWS, but it's like what I like to call, I've created a new acronym, uh, latter part of last year, RT dc return to the data center and, uh, uh, it is happening. But I absolutely agree with you, Diane.
No one is saying they're going to abandon the value that Cloud provides, but there is absolutely this movement that cloud first is over, uh, uh, from a, we must move all of our IT to the cloud to thinking about where they're positioning the cloud. It also hearkens back to our first story or, or our second story around, uh, NetApp and abandoning their spot and, uh, that ability, uh, they're doubling down on understanding the relationship between data in the workload and positioning the most important asset, which is data. Folks, this has been a wonderful conversation.
What seemed to be a really slow Newsweek. I, I think it speaks to the two of your deep experience and my ability to put people to sleep with this soothing voice. This is why you need to have your spouse listen to the podcast.
It doesn't matter whether or not they're in it or not. A good friend told me, uh, that his wife likes to listen to my podcast because it puts her to sleep at night. So this is a great sleep aid for those of you not in it.
For the rest of you, please join us again next week where I don't know either. I think I'm gonna get my predictions or my prediction for the next week. We'll stay tuned next week.
Until then, have a great week. This is Textron tv. Hey guys, thanks the throw, we're here with Melissa Zi, who's director of AI for App Omni, and we're talking about some of the inherent security risks that go along with AI ops because, well, we might be automating things, but maybe we're not thinking it all the way through as much as we should be.
Hey Melissa, welcome to the show. Hey, thanks for having me. Everybody's kinda looking into AI ops and folks who are at different levels of progression, no doubt.
But from your perspective, when it comes to security, what do we tend to overlook? I think the one thing that we forget is that the core of machine learning, ai, anything is data, right? We tend to focus a lot on the models, uh, even when people are talking about LLMs right now as well, right?
So we focus so much on the models and we forget that it's like, hey, there is no ai, there is no machine learning without data. And actually the most precious part of AI is the data. So the first thing that we tend to overlook is how, how much security we need to put around data.
So when we hear about data breaches, everyone is aware of that and it seems that we tend to forget that that is also connected to mops. So one of the big problems on mops continue to be security breaches around data, either injecting data to change the model or extracting data through the model in different perspectives. And another thing that we tend to overlook is that we think like, hey, if it's running in the cloud, we're all safe.
Well, it is safe as long as we put the correct configurations in place, right? So if you put the correct configurations in place, your cloud provider will assure that it's safe, but he can't assure that whoever is doing that is doing the proper configurations. So the two big things is around the data, and the second is around configuration.
And then the configuration goes into everything that is running in the cloud from the data to the model itself. Mm-hmm. Third part that we look into the machine learning models itself.
That's the other thing that sometimes we tend to overlook. We want to do things too fast. So sometimes people want to reuse models that are out there that someone else developed.
And it's very important to know, okay, what are the other libraries, the other pre-trained models that the company's using to know that they are also safe? Are the bad guys targeting these AIOps platforms and, and going after this data? I mean, I think part of the assumption is that, you know, these are too sophisticated for them to actually crack.
Yeah. And I think that's the part that we overlook or a lot of people overlook into because they focus on the machine learning part and may happen that you put a lot of safety around the model itself, but not the data because the data is being moved around, right? So we have kind of like, let's say the raw data that needs to be treated in order to go into the model, and then the model is using it to then give some output.
So there is data moving around there. So there's a lot of little places or different places that the attacker can go into, almost including, and unfortunately we know about that, that it happened is like reverse engineering based on the output of the machine learning model or through an LLM, you can try to extract the data that was used by the model to give that answer. So there's different ways that that attacker can try to get in to get a hand on either the model itself or the data and then to either change the model.
So that's one type of attack, uh, that happened I think with Tesla that some, uh, hackers hacking to the Tesla. So the uh, autopilot of Tesla was start doing things that was not supposed to do long time ago, um, has been fixed since then. And the others were to extract the underlying data that's been used by the model.
Is this two separate motions then do I need to figure out how to secure the model and then also secure the data or can I unify that? You can unify that. Um, there's two big important points to think about it, right?
But if you're running everything within the same cloud provider, for example, is the same approach. You can think about the model as being just different type of data and take the same approach into it. And the idea is really what's going out to the world.
Every time that you have an interface to the world, you need to be careful of that, you know, we know about that even outside machine learning that with misconfiguration you can get even internal data exposed to the normal's world, then anyone can go and find it is not different with the machine learning. So you can unify that for sure, but you cannot forget that there are two different fronts or two different things to look into. How do I kind discover this stuff?
Because I think part of the issue is the cyber criminals, they're getting smarter and they, I guess they don't just smash and grab anymore. They kind of break in and linger and hang out for a long time and then I don't really notice them. Yeah, and that's a, um, a big problem actually.
We deal with that a lot at, at Omni is about the SaaS configuration, right? It doesn't take, uh, too much to click maybe a wrong button and do some wrong configuration or misconfiguration to get your data records exposed. So it's the same approach into a lot of companies are using more and more SaaS and you can think about this machine learning AI pipeline as being another SaaS because you have data there, you are connecting to other parts depending what is in purpose for.
So the core is like how can you extract one configuration, which we call that security posture, into how you have everything configured, and then are there any threat detection alerts happening around that? So to way, the way to think about the machine learning, the ML ops is kind of like is another SaaS. You need to be aware of all the configurations around the whole pipeline, which includes model and data and treat that the same way that we treat pans SaaS security.
I don't think the folks building AI models this data scientists know all that much about security and maybe it's too much to ask them to know that. So do I need to go find cybersecurity specialists that know AI or where am I gonna find the skills and expertise to go address this? Yeah, I think that that's a very good question because if you frame the ai, the M mo ops are being data, it falls under the same way that you treat any other SaaS, right?
I think the key to understand how to handle this is to really to look at the MO ops from a SaaS perspective. Hey, it's like having another SaaS in your environment. So a lot of the big companies that handle with a lot of SaaS, they are starting to look at AI and MO ops on that perspective.
So the key is that to not forget that the ML ops is another security part and you take a look into and definitely yes, the same way that you look from a cybersecurity SaaS cybersecurity expertise on the SaaS, you have to look from that perspective as well into the ai, into the ML ops. So there is definitely this joint combination of teamwork between people that know SaaS security and cybersecurity with the people that are developing the mops. Are there different types of attacks that I gotta think through here?
Because you know, you hear phrases like, uh, jailbreaking and poisoning of models or are, are these threats, you know, are there more and are they classified into what kind of buckets? Yeah, so if we go from a simple definition of the attacks, if I can put it that way, there's two types things coming in and things coming out, right? So there's the attacks trying to jailbreak is data injection.
It could be LLM jailbreak, it could be even data injection for any other type of machine learning visor unsupervised that you can inject data into it. So there's one type of attack, you're injecting data to change the model and that has a huge impact. So depending on what the model is used for, right?
So it can really see companies are using that to make decisions about their products or how to handle things. It can have a huge impact to the company even economically, right? So that's one type of attack.
It's different than a ransomware, but it can almost think as a ransomware, I know how the ransomware, they keep your files and then you can't have access to them anymore. It's kind of that impact until you go and you change the data. So now your models are not working anymore.
And that can have huge cascade problems depending on what you're using the models for. Because let's say if you using the model to approve not a presu insurances in your company, now you may get all kinds of different things approved that you didn't want approved, right? And the economic impact of that is huge.
So that's one type of attack. The other type of attack is really trying to extract data. So if you think about all the ins and outs, there's all kinds of different techniques to try to get that, but really focus on this in and out is the core key to understand that what are all the different ways that data can get in?
What are all the different ways that data could get out? And at the end it goes to all those different techniques that attackers could use out there. Am I gonna need maybe an AI agent or some sort of external AI tool to verify or provide the guardrail for my AI model?
And these things are gonna basically keep an eye on each other. Um, a hundred percent. I think there's always good practice independent of attackers to keep watching the model.
And there's different ways to do that depending on which type of AI machine learning model is being used, right? So data drifting, for example, to watch like has your data being changed tremendously? Because if your data hasn't changed too much, the model won't change too much, right?
And as soon as you see that, hey, there's some data drifting here, then it can go and take a look into why that's happening and find the root cause. Could be an attack, could be just, you know, it happens, right? A benign change.
So if you think about the whole pipeline, again from the data perspective, it's always from the data perspective to understand has the data changed? The other part is hyper parameters and the parameters of the models, right? There's another type of attack that if they come from the libraries directly from the models, they can change those.
So any type of change and tracking that through the pipeline is what can help with that. Then there's a lot of information, there's a lot of data to deal with, right? How can you handle all of that?
That's where an LLM, for example, could help, right? So we have this direct ai, other machine learnings watching the machine learning, and depending on what is finding, you could have an LLM running on top of it to really kind of help, as will be a cybersecurity person and say, Hey, I saw this data drifting here and I noticed that the content of the data is this, that, that and that, that normally you don't have, maybe this thing is happening. So definitely AI can help on top of watching all this.
So ultimately, do you think that these issues are kinda holding up people in terms of their ability to operationalize ai? I think we had a lot of enthusiasm a year or more ago, and maybe the hardcore realities of data management and security are kind of bigger than we anticipated. I think that if you start the development of AI already aware of those, it should not hinder it.
I think the biggest problem is when you develop the whole pipeline, not thinking those things in consideration, and then when you're ready to go to production, you have to restructure a lot of things because you are taking a look. I think that the whole key for it is really to think ahead of, and as you start developing ML ops, as you start the r and d part, the exploration part of the machine learning, if you're already thinking to how we're gonna put that in production, how we're gonna make sure that everything is safe, then it should not impact take into production at all. I think that's the idea, being as proactive as possible, already thinking to taking this to production, exposing it to the real world, and taking all the lessons learned around SaaS security, around how to secure the configurations and the data.
Alright, folks here, you heard it here. It's not necessarily rocket science, it's just that we don't know what we don't know. And the problem with AI is the idiot tax is pretty high, but if you take a minute think about it, you can implement and get to something that well hopefully provide some sort of competitive advantage in the long run.
Melissa, thanks for being on the show. Thanks for having me. All right.
And back to you guys in the street. This is Textron tv. Hello, my name is Chris Blak.
I am your host again for another episode of the Inevitability Curve where we take topics that we're all thinking about and we look at where we've been with them, with that, maybe figuring out a little bit more about where we are today, and, uh, with any luck, get some insight into where we're going. So with me today is a good friend, smart person named Chris as well. Chris Blow.
How are you man? Doing good, Chris. How you doing?
I'm loving life. I'm back on the boats, right? You, you know, we're Facebook friends, you see the sagas, right?
This is the first episode of this series, you know, after the boat sank during, uh, hurricane Milton and got them back up and running, but these solar powered monstrosities and brought to you by Sterling. Glad to see that. It, glad to see that things fared fairly well for you.
Well, they do. And like, and we're talking about in the green room, you know, everybody, you know, we're cybersecurity folks, right? You know, and anybody in cybersecurity, you know, and at your age, I won, won won't out your age, but you're, you know, 15 years younger than me.
And, and like your age and a little bit below that, you know, you, you got here through an interesting path. And I won't say that, you know, somebody in their twenties and thirties, you know, today, you know, hasn't also come into security through an interesting path because that just happens. But there are courses and things these days.
It's all the structures already built. But you know, for a lot of us we're just, you know, hacked our way through it one way or the other and put it together, right? Yeah.
So you some you some Of it quite literally. Yeah. Quick rehash of how you got into security.
What was your horrible life choices did you make over the last number of years? Over the last, the last, uh, last several decades? Yeah.
Yeah. Like I had, I had originally, you know, I originally, you know, got into this stuff, I guess, uh, in like, in, in my youth, uh, being nefarious with a computer. Um, very extremely grateful that, uh, of all people, my grandparents were the ones that saw that I was very, um, adept to doing things with electronics.
And I luckily had a, a cousin who was at college at the time, who was able to get a really great deal on some salvage computers, uh, that the university was cycling through. And so I am forever indebted to my grandparents, my aunt, my uncle, my cousin, my parents who helped make that, I think it was my Christmas slash birthday slash whatever else for the next like year, uh, way back when. But that led to me doing all sorts of fun nefarious stuff, uh, as several other people in this, in this large community can, uh, probably talk about as well.
That led to, like, when I went to college, um, there wasn't a cybersecurity program. Uh, I was actually being pushed to go into English by my guidance counselor because computers, like, you didn't really talk about computers. I took a couple of c plus plus courses in my high school, and that's literally all they offered from a computing standpoint besides typing.
And so like, it's not like they were gonna come to me and be like, oh, so you do, you, you do cybersecurity and you've like played with the phone system and stuff. Cool, well, let's put you on a path of success then for that. Uh, it was like, no, you're, you're, you're, you should do English.
So, uh, I didn't do that at all and ended up cycling through a couple different majors, uh, through college. And that got me to, um, ended up in computer science, which then after I graduated, jobs were hard to come by. Um, due to the timing of it, it was around nine 11.
So, uh, my first job was not immediately, I wasn't immediately placed outta college, the one that I was supposed to do right outta college that ended up, uh, kind of fizzling out in, into the ether. So, uh, I was a line cook for a while and, uh, then ended up getting a job as a doing help desk. And that led from help desk to doing system administration, to network administration to, um, just building, building, building, building, and then moving onto the next company, building, building, building, moving onto the next company.
And then that led to just going between companies, consultancy companies, consultancy, et cetera. But yeah, it's, uh, it, it's interesting now how when we're looking, when I'm looking through resumes, uh, because I have a rec to fill, uh, you know, it's everybody degree in cybersecurity. Uh, and it's like, that would've been nice back then.
But that's a, it's, it's very interesting that even though it's only what, 15, 20 years difference, probably more than that. 'cause I always think I'm younger than I am and I'm not, but so be it. I think we all do, uh, how I Embrace Gage.
Exactly. I'm in bonus rounds now. I mean, I've outlived most my ancestors, Hey, you can't, and you can't beat that, right?
Um, but yeah, it's crazy how much has changed in the past, just 15, 20 years, uh, especially in those type of organizations, You know? It is, and that's sort of our, our, our iterative theme here, right? You know, where we've been, where are we now, where are we going, you know, in, in, in my career, you know, cybersecurity, you know, it was information security.
I, I love the naming parts of it, you know, just how we've changed names over time. You know, there was, in, in, in my, you know, visibility, there's been data processing right before information technology and Right. And there was information security, and then, you know, the, we, the cybersecurity wars, you know, cybersecurity word.
Is there a space, you know, that wa that was a fascinating little, little era. And, uh, you know, anything that goes from anything that, you know, that becomes widely adopted and starts out as something some small group of people are really, uh, interested in, goes through predictable phases. Right.
You know, it's, there's, there's a, a, a fair bit of, you know, there's a lot of the, the folks right at the beginning who don't really fit into to the, as it bros, right? As it all goes corporate and so forth. Um, and it, and it, it fascinates me that, that in the end, it tends to work out like, you know, that the, all the doom and gloom, you know, we're gonna have a cyber Pearl Harbor.
We can, you know, take down, they'll attack the critical infrastructure, you know, and, and this to be clear, all true, right? You know, the things need to be done. There's a lot of people need to do them.
Policies and agencies need to continue evolving and so forth, but the lights are on. I'm sitting in a boat in the ocean talking to you over a satellites, um, on a, on a Microsoft device. You know, this so far, you know, this morning at least, and that hasn't ruined my coffee.
Yeah. Knock on wood. Knock on wood.
Yeah. So you're right though. It's, uh, the, some, you talk about the doom and gloom.
Um, one of the things I'll never forget was my freshman year, uh, my freshman year at college, one of the first classes in like, uh, just general computing that everyone had to take. Uh, the, the professor came into, uh, professor came into the room and walked to the front of the very large, uh, recitation hall, shut off all the lights, and gave this five minute speech on this is what it's gonna be like on December 31st, 1999, uh, after 11 59 59, and this is what you have to look forward to, and we need to be prepared for this. And, uh, just five minutes.
And it, it was, we're all like, I thought this was like, isn't this just general computing? Like, we're not gonna save the world over here. But yeah, you talk about things like doom and gloom like that.
It's that that was, that was the big thing. Um, and it doesn't mean that we shouldn't have, we shouldn't have all had some sense of, are we prepared for this? Um, you know, it wasn't anything, especially at the time, like, you know, mass panic.
Um, one of my, um, one of my colleagues worked at the, uh, worked at the New York Stock Exchange during that time. And, you know, they were going through the same amount of panic there on, like, are we good? Are we sure that we've got everything up to date?
Are we gonna, are we gonna be able to do business that following week? Um, not just that following day, following week, following month, uh, the millions upon millions of dollars that were spent by companies to make sure that everything was good to go. Um, and then we all know it world over, and the world's still here.
So good job. Us, I guess, You know, and I, I, for, for maybe the first 20 years of my life, I considered my myself a baby boomer. So I was tactically a couple years too late for it, but I was the youngest of everything.
And, you know, so I, I grew up with, with that cohort, and, you know, the, I, I, and I look back, one of the things that, that that sort of set me apart, you know, because I just, you know, uh, was that I just wouldn't, I, I did buy into it. I bought into all, you know, all the, you know, what are say common conspiracy theories, basically, right. You know, of either religion or aliens coming to get us, or, you know, it's a, governments and corporations are all, you know, doing the, the wire.
We're all gonna die in nuclear war, and you can't feed enough people. Yeah. And, but it wore off pretty quick because I, you know, started looking forward and back.
It's like, well, actually, we've been around for, you know, tens actually turns out hundreds of thousands of years. And, uh, we tend to be still here. And, uh, we, of the history, we can see over the last, you know, couple thousand, 6, 8, 10, 12, you know, 20, 40,000 years, depending on how you look at it, uh, there's always been vo on, you know, battle cruisers coming to destroy the earth.
Um, and we're still here, right? And I think it does a disservice. I think it causes drag, right?
And this is let you know, let's see if we can turn the, turn the, uh, uh, conversation towards, well, you and I have spent a lot of our, our careers working on, which is sharing information, right? You know, and I think this is right inside the loop, right? You know, companies and technical people and engineers and so forth, you know, have a lot of intrinsic concerns about sharing, oh my God, the, you know, the competitor's gonna find out my thing.
You know, people gonna know I got vulnerabilities or whatever. It's, and I think that this entire exercise that we call, you know, America Western democracy, post Greco Roman, you know, uh, um, uh, democracy, Magna car, you know, this, this free speech open source type of thing. It's, I, while I love it for, uh, for, uh, uh, personal reasons, I think it's mostly just more efficient.
I think it's more competitive and advantageous to speak very, very clearly about what you can and be really clear on what your risks are. Right. You know, does sharing this information does share threat, this threat intelligence cause me more, more problems than it solves.
And just work your way through it until you get clean communications. Um, and, and, and you sort of bouncing around the room on this one, but, uh, there is so much, it, it's hard not to talk about the misinformation disinformation world we live in right now. Right.
You know, because it's such a big part of our daily lives, right? Fake news or who believes, there's no way to tell what, what information is information. But you and I work in worlds where we share information and we know how true it is, or the current working definition of true.
You know, that's how we take threat intelligence and act on it. It's how we take supply chain intelligence and act on it. And we're building systems that it's going to automate this and it's gonna take actions on our behalf in, in reliable fashions.
Yeah, absolutely. I think that, um, it, it's been interesting, especially all the job hopping I've done throughout my career. Um, there's constants and one of the big constants has been around sharing information and what can be shared and how it can be shared.
And it's always very tight lip, uh, even, which is extremely frustrating, especially like what I do now. Like my current role is leading threat intelligence and essentially offensive security. And in doing that, like, there's a lot that I want to share, and there's a lot that I think should be shared, but there's so much that we have to be tight-lipped on.
Um, and I believe my firm belief on it, at least for a lot of these companies I've worked for over the years, is just because they are behind the curve on like what the true benefit is of actually sharing this information. And they're so used to trying to protect their crown jewels, um, and try to make sure that their secret sauce doesn't get out. That it's like, what is your crown jewels anymore?
Like, do you even know what your crown jewels are? Because what they were in the nineties and the two thousands, it is not even in the early 2020s, late 2010s is not the same as it is today. Everyone.
We've talked about crown jewels in cybersecurity, information security, whatever you wanna call it, uh, for so long. And that definition drastically changes, I don't know, quarterly, monthly, uh, depending on what you, what you see. And you have a very big reaction to that.
So I'm dying to hear what you have to say on this. Oh, it's, You know, so, so in the, what was it, 2002 or so, you know, I did a, did a sim startup with a couple friends, right? And one of the big, uh, internal arguments we got was about our, uh, using Salesforce, because Salesforce is brand new, right?
And it's like, no, no, no, we should build our own CRM. This is our customer list. We gotta keep that private because that's part of our crown jewels.
And my arm was, uh, we don't have time or people to build, build and manage A CRM. Our network isn't necessarily any more secure our actual network than someone who's actually providing services for a living and hiring, you know, people to do security staff stuff. And if I had my competitor's customer list, I would, I don't know, mostly start a fire with it.
I don't care. You know, it's not that much use to me. I mean, maybe, you know, okay, don't call them, but it's, they're reference customers anyways.
They're already publishing those. I already know who they are. And it, yeah.
So, so you, you know, I, you, you've made the point exactly right? People don't know what their crown jewels are. And if you don't know that, then from a security perspective and, and, and not even security to address these anxieties and allow you to more freely do business and engage with the world, you have to identify what it is you're actually trying to protect.
What are the risks, you know, intellectual property in, in threat, and tell, and again, in, in in supply chain, you get all this corporate anxiety about intellectual property. It's like, how are you protecting that now? Mm-hmm.
You know, you know, hiring contracts and hope, Right? Right. It, it's, I think, I won't say every job that I've, that I've been at, but most of them especially, uh, like obviously not so much for the, um, consultancy side of things, but any of the actual companies I've worked for in corporations, um, one of the first things I've always asked, like before I take the job, I've always asked the hiring manager is, can I have the f you know, like, obviously let me drink from the fire hose of whatever corporate you stuff you need me to get through as part of my onboarding process, but like, can I have a month to really understand what we're securing?
Not just like, take, take this at, at everyone's word, and you'd think that I like magically grew two new heads, and they're like, you wanna what? And it's like, no, I, I want to understand what we're trying to secure here, or what I'm trying to, you know, break into, if it's me doing something from an off sex standpoint, um, like it's one thing for, you know, for me to look at the, I don't know, like the magic sauce you use to make your widget, uh, but it's another thing where, like, is that the most important thing? Uh, it might be to that section of the business, but if I go and talk to hr, are they gonna say that's the most important thing?
No, they're going to say that their employer records are the most important thing. Um, it, it just goes on and on and on. So like, let me go and talk to different groups.
Please introduce me to those groups and let me, let me absorb in that fashion. Uh, in fact, at one of the places that, that I worked at for a decent amount of time, um, they, they had training that a fairly decent sized group of folks within that company had to go through. Um, it's no surprise I've done work in with like several insurance companies.
So it was underwriter training, and I asked if I could be a fly in a fly on the wall. And it was, I think eight or 12 weeks. Uh, and they reluctantly let me do it, but I learned a whole lot about health insurance during that time, and I learned a whole lot about all the different bits and bobs that they were using as far as their underwriting process went.
And that helped me when it came to security awareness. Um, I helped them develop some things around their, like security awareness, programming, education stuff, especially like for cybersecurity month, which, you know, we're currently in so topical. But not only that, it was, now I have a much better idea of what I need to go and look for as we're doing different offensive security exercises and whatnot.
So, um, or even as we're building things out from an architecture perspective, like me helping these enterprise architects be like, you're forgetting important things here. And yes, underwriting isn't the only thing in this company, but it ties into so much of their whole, like, business process as a whole, that it plays a very large role, uh, especially when you learn like all the different nuances, nuances, uh, and systems that they have to go into to do some of these things. And how it's not just like some magical one-stop shop.
It's like, oh, you have this thing that you have to leave on. That is, you know, it's just like any other large business, any, it's, you have this thing over in the corner that's grossly outta date you can't do anything with, because it's still running like Java version two. 1 machine, um, and, uh, you know, or it's running OS two warp, whatever, makeup, you know, whatever photo as you want to go with at the time.
Um, but it has to sit there in the quarter and do the thing. But these people have to do this because that is part of the, you know, multi-billion dollar chain of events that goes to make the thing work. net that has been around for many, many, many years, run by, uh, Fred Cohen, you know, the great Fred Cohen, if you know the word computer virus is because he wrote it down for the first time in his PhD thesis.
You know, Fred is as detail oriented and of a person as you ever meet. And he and I had a company called Fearless Security for a while that was using the methodology. You know, if you go to all that net and click on the word protection, the upper left, you'll see this, you know, eye chart that you can click on until your brains fall out.
But, you know, Fred and other folks were just Dean and, and some the older analysts, we were the first people to put together security analyst analytics. Well, we see the big, you know, companies, PWCs and Garters and so forth doing today, they, you know, I I, I've been saying this so long and maybe it's not true somewhere, but basically, uh, basically you spend $600,000 and, you know, people will slow down your business for a number of months and give you a 500 page report, um, which is better. Nothing, you know, because it, you know, when you stop and say, I really need to understand who you are before I can even begin to tell you what you need to secure how, and Fred has, uh, has focused on this stuff.
What Fearless did was basically baked that down to a day, but we couldn't get it below eight hours has to be eight hours, you know, walking through this, you know, very large, you know, information system, piece by piece paper. Do you do this? If you do, do, how do you do that?
Do you do this? How do you, well, you, what, who are you? And the few times in our, in my life that I managed to go through that entire thing, everything else just gets so easy.
Right? It's like, here's why we're doing this. Because you see, you see, this is who you are.
And if you stop doing these things, you don't exist anymore. 'cause you know, that's, you know, the things cost money and this is where all the money comes from, right? Or you're, you're a government agency or whatever it is, right?
You know, there's, there's a reason you are here. And without that, I hate to get cynical, but it's, you know, these days it's like, can you help me secure my company? It's like, are you willing to, to, to stop and look at here we are.
No, no, no. We just need to No, no. I mean, no, it's not, yeah, You've got to, that's the thing, is like, there has to be some willingness to share.
There's got to be some willingness. And I even took that, um, I can't believe I'm actually gonna admit this in a public setting, but like, you know, there was two years where I apparently had a brain aneurysm and I was A-P-C-I-D-S-S-Q-S-A, ah. And, um, we still love you.
It was, it was, well, I was already doing, so like You had to embrace your faults, right? And that, that's what, you know, brings healing links. I was, I had already previously within that same company, I was already doing like PCI pen testing.
And because it was, it was there and it was something that we were doing, but they were like, we want someone technical to become a QSA. Do you want to do this? And I'm like, and they enticed me by like, Hey, we'll, we'll go out to, um, we'll be basically do the training out at, well, RSA is going on, so like, go hang out with people at RSA and whatnot too.
I'm like, sure, why not? So here I come this technical QSA, and it was very much a binary, like lover hate when I went to client sites, because I wasn't just taking stuff at face value and just, and like, but I would ask them to actually explain how they do things, even if something is, I won't say that taking credit cards is simplistic. 'cause most of the time it's not, um, depending on what they're doing.
But I would ask them to explain like exactly how they were doing things from a customer service standpoint, how they were doing things from a website standpoint, and where this all came together and where it then like broke apart. And once I understood that, it made the rest of the conversations and it made the rest of like, even just the evidence collection, easy peasy lemon squeezy. 'cause I'm like, cool, I need to see these 10 things.
Can you bring this up and show this to me right now? And they'd be like, yeah, lemme go grab five people. We'll be able to show it to you.
Like at e split, easy to like done. And, uh, yeah, it's the, it's just this whole sharing of information and like, you don't have to share every single thing, but be open, just be a little bit open and that's gonna help us move so much farther. Like we were talking in the green room beforehand about ISACs, like, is stack ISACs still exist?
And they're bigger than ever and they're, it's a such a wonderful, wonderful thing to be a part of. Um, especially for my folks. I will be the first to admit that while I might be, uh, you know, I might be a leader over, um, threat intelligence and my current employer doesn't mean that I am like some super knowledgeable person about threat intel.
Um, no, I'm not. I'm really not. I, I actually, like, I love the fact that, um, I mean there's a, my entire team is blight.
You're smarter than me. But, uh, the folks that I have aligned to threat intel, wicked smart individuals that have taught me so much around what real threat intelligence is, um, and how beneficial it is to, uh, have that curated information and be able to give that curated information to specific stakeholders within your company and using things like an ISAC to, quite frankly, it's, makes it easier for us to share information because you're under that, you're under that TLP stoplight. And we're able to take that, uh, as I'm sure many other companies are, and we're able to have real connections with other companies, um, under the guise of that, that we couldn't do before.
Uh, like similar companies, a similar company, so, you know, financial institution to financial institution, whatever it may be. Uh, we're able to have real conversations under the guise of that. And that's one thing that's continuing to help move that needle in the right direction as far as sharing information and making sure that we're all aware.
The, uh, go ahead. Because I'll, I'll be on the soapbox for the rest of this time if I don't, if you don't stop it. No, We think it's a good soapbox.
And actually we're gonna, we're just gonna, you know, light on fire and stand on top of a dance, I think at this point because, so sex information sharing analysis centers for those years, don't know about that, you know, came out of, uh, 1990, I always get this wrong, six or eight presidential directive that there shall be an information sharing analysis center in the private sector to work with the government. And it turned out there was a dozen, and now there, there's a couple hundred net there should be. And as you say, so the healthcare ISAC is a good example, right?
You, this is a, a relatively significant organization now is, you know, with, uh, you know, close to 50 full-time staff or just working on sharing information with, oh, I just just got these numbers, um, the, the other day. But yeah, a impressive, massive chunk of the healthcare space where they've got the community and information is flowing in, in appropriate times. And you used to, you know, one of the, you you phrased this, I won't get it right, exactly.
But I love that sort of thing. And the way you just said it sort of naturally, you get the right sort of information to the right parts of your company and the right sort of time, right? Information sharing doesn't mean, you know, billboards, right?
You don't have to take, you know, there are things between putting it in the safe and dropping in the ocean and telling everyone. And that's, that those things in the between are, are everything we live with. And we can do that in business too, right?
And the, you know, I think, I, I think everything we're just talking about, you know, indicates strongly that the most likely future is where there's more and more of this, where comp companies and organizations are better able to figure out who they are, you know, so they can make better choices about what they should do among those things, you know, security and, and taking care of their systems, having the right systems. And I think, you know, to our sort of theme today, looking back on that, saying 30, 40, 50 years, you'll see one of the huge benefits was more information flowing more quickly. And I'm gonna use the, the dreaded acronym ai.
'cause this is one of those things I keep thinking that this generation of, of what we incorrectly call artificial intelligence has some fantastic benefits for security. And I think this is one of these, right, as I say, of getting anyone to stop convincing 'em that they do have the time and you do have the time. And then getting 'em to take it and walking through everything, you know, a security professional really knows to do a, you know, diligence job, uh, for them is still really hard.
I think the kind of horsepower, you know, you know, lots of, lots of relatively intelligent pencils, you know, we get out of, uh, uh, AI gives us the opportunity to bring that into scope so you can get an organization and say, look, you know, before I'm gonna, you know, start telling you to encrypt your eyah, you know, we're gonna go through this process that's easier and simpler. It's not that hard. It's not that much, I guess it's not that far from the easiest.
You can make it today too easy enough that most people will actually do it. And once you have that, I think all sorts of systems, like from technical systems to policies primarily about who gets to know what and what you have to worry about sharing and saying to whom just get way, way easier. And the amount of drag that removes from every individual inside an organization and groups, and I, I think, I think it really is transformative.
I think we waste 90% of our effort on things that are not what we're doing. Sure. Absolutely.
We do. Um, a great example, especially from like an intel standpoint and not gonna give like all praise to AI and whatnot, but just, just optical character recognition like OCR as far as the amount of, the amount of stuff that is out there to turn into in some type of curated intelligence. Is it all gonna turn into something that's, you know, worthwhile?
No, but that's why you curate your intelligence. But if you have a much easier way to bring in some of that stuff so that you can get halfway decent summarizations within whatever tooling you're using, and you can have it spit out, like take a hundred page PDF, and it turns it into four paragraphs, that's much easier for an engineer or an analyst to go through and say, yeah, this could be applicable. Maybe I need to go look through the rest of this document some more.
Um, and they can just do mad searches on keywords within that entire a hundred page PDF, maybe they strike gold and it's something that's like, this is pertinent to a part of the organization that they would've never known about this because it was buried deep within something. So trying to find some of those needles in haystacks. Yeah, I think there's a lot of benefit, Darren, we're just at the beginning of some of this stuff, and you and I both know this.
This is like, AI didn't just magically appear 18 months ago. Like, but did it hit mainstream and did, you know, did it take off as far as like, you know, what we see with, with Chad GPT and all the other GBTs and LLMs out there? Sure.
But this, it's not like this stuff didn't exist prior. Um, we're just leveraging it in some good ways. I'm not gonna say a lot of good ways.
Some, it's got a ways to go though. Well, I, I think it's biggest benefit, you know, to me is, is addressing time to transparency. Another one of my, you know, little catchphrases that I've just been obsessed with the last three, four, or five years, because it speaks to so much.
I mean, what you're saying is it makes it easier for an now, could you have done that by hand? Sure. You could always do it by hand.
You know, you don't have the time, you don't have, I mean, time turns into people. How many people do you need to read through all of that and, you know, curate that intel before it gets done to an engineer? And if you don't have control f and find in a, in A PDF, then you actually have that engineer read the whole 145, you know?
So it's all about shorting the time. And I don't, you know, I I, as I look into the future, honestly, I'm, I'm just right on the crux. I kind of think that maybe there is no digital consciousness.
I think the actual artificial intelligence from the movies may be physically impossible, may never happen. I mean, never, never happened. Um, which I'm not not sure if every time I say that out loud, but we're so far from that, or not replacing people, we're replacing a lot of jobs.
But you know, what we call AI right now is really, really good at brute forcing some things. So you can give people time. And it's not that you're, you know, I can now have five less people.
I mean, again, sometimes yes. But I think what we'll find is that now you can do the thing, right? You never even thought of doing the thing.
I mean, of course you can't do the thing you realize that would take a thousand people sitting there that you can't, it's not even on the table all of a sudden it's like, oh yeah, that doesn't actually take anything anymore, and we can do the thing. And I think, you know, from a global security perspective, right? You know, the, uh, I mean, shout out to the great gentleman Michael Hayden, right?
Yeah. I, I, uh, got a a hour of his time right after the Navy yard shooting, remember that in DC there was a Oh yeah. Navy yard the day after that.
And I was on a, on a, a, a crusade to convince many people inside the beltway that there was this rans, you know, visibility we're moving towards nice sax and threat intel and all that was part of it. And General Hayden got a, you know, incredibly sharp guy, uh, as, uh, better as well, or better than anybody ask really, really good questions, right? But I, I, it's, it's, again, it all takes too much time.
I mean, saying, you and I have lived our careers inside this, let's, okay, the war stories, you know, let's get this group. We had to get authorities to do this thing, you know, it as a public sector or a private sector. And it took six weeks, you know, just to talk about this paragraph and the exact wording of the, imagine we could do this more quickly.
Imagine we can have at the nation state a scale or global scale. You know, the kind of things that, you know, with you focusing on threat intelligence these days that you don't even dream of because it, we, but if you had 10,000 people, you know, analysts, sorting things out, you could then get to the point, and I'm really so boxing at this point, but my vision for supply chain is that I can pick up something and this is my mouse and I'm me, right? So I get to see appropriately if I have the rights, you know, from whoever I bought it from and whatever contract they have with whoever they bought the parts for, all the way back to whoever made the plastic and who, you know, shovel the sand into the furnace to make the silicone chip.
Right. You know, and I can see that right now. I mean, it took way longer to say that than it should take to do that, but that implies that we can take the te because you can do that now, but it would be a six month project.
But we can automate this and we will, I think that's a big chunk of where we're going in the future. And threat intel and security is a rides along with that. Yeah, absolutely.
Completely agree. I think that, uh, what we're seeing, we're just gonna continue to see more of this. And it's funny how you talk about like, that's a 10,000 hour, you know, 10,000 person and a hundred thousand hour job, and we joke about that stuff, you know, 10, 15 years ago.
Some of that stuff in some weird convoluted way could potentially become a reality, um, because you're taking out a lot of the, I need half of those 10,000 people to do nothing but read the thing, the things 24 hours a day, seven days a week, we don't have to, we don't have to do that part anymore. Um, are the summaries that we get for everything perfect? No.
Is anything that we're doing, you know, that would eliminate what a human's doing going to be, you know, like just spotless every time? No, but it's a start, and I've noticed it with My teams and we didn't trust things that much anyways, Right? I mean, and humans aren't infallible.
So like we look at, uh, you know, uh, you look at things with like the, look at the latest Verizon data breach, we preferred, um, continual rise in the amount of human interactions with, uh, when it, when it comes to either ransomware or extortion of some sort. The, the number, I can't remember the exact number now, but again, continues to rise for the human element part of it. So it's not like we're infallible.
So we're just by, by pushing some of this stuff off into things like ai, um, it's better than nothing and hopefully allows us to maybe progress in what we can do and helps us innovate more, helps us push the envelope more on things that used to be just like, wouldn't it be great if all this pie in the sky stuff, Right? Well, with that, uh, before we start talking about pies in the skies, because, you know, pies, I mean, how go that one ramp an hour? Yeah.
But nice to, nice to see that I'm not the only one that thinks things are going to work out. You know, our kids are grow, grow up, the world will go on, the light will stay on, you know, most of the time. And we'll figure out the, the problems and we'll fix 'em.
Yep. Yep. Thank you.
So it's, Thank you. This has been great. Thanks.
Anytime. And, uh, and yeah, when you, when you know, as we're talking about in the green room, uh, Indiana, maybe, uh, one of my trips out to mom's place, we'll have to see if we can, uh, hook up there, share, share more, uh, Indiana stories. And you find, and you are a of course, you're, you're one of my Disney kin.
I mean, there are very few people in more Walt Disney World than I am. Right. And, uh, the you're a Florida guy periodically, so sometime in the, in the wintertime when I'm not up in Canada, come sailing.
Yeah, absolutely. Um, run Disney season, uh, kicks off next week, so I'll be, uh, yeah, I'll be, I'll be down there a lot. Um, waking up at 2:00 AM to go run And I'll be watching, having a smoke, drinking a coffee on Facebook while you do that.
So that's a God, you, everyone. Alright, man. Thank you very much.
Thank you. The world. Have a good day.
Hi, uh, welcome everybody. Well, my name is Alejandro Mercado, uh, rice and born in Mexico City. Um, this is a, my talk is about the intersection about cows engineering, um, a little bit of observability and, uh, DevOps practices.
So, so very honored to be here. So this is a little, a little about me. Uh, I work as a senior DebOps engineer, and I have a lot of experience, uh, well more than 25 years doing that, that activities and like, um, uh, girls engineer practitioner and DebOps, CICD and related things about that.
So, uh, I, I want to start with the end. This is, if you want to take a, a takeaway from this talk is, is this, uh, why do you want to do cows engineering and how does it benefits observability? Because of course you gain visibility, you identify failure modes and of course connected with other tools.
You can, uh, automate remediation and in enhance collaboration. So, so this is like some of the, uh, the both principles that, that we have been practicing this for many years. We can elevate our, the both practices and, and build more reliable, resilient, and responsive systems.
That's the whole point of the, of, of this talk. So it's, so we become a start talking about, a little bit about observability and telemetry and, and why is this important to our current systems? You know, we are gaining complexity, cloud native system, on-premise system, hybrid system databases, network connectivities, uh, container serverless.
We have a, uh, a lot of complexity in our current system. So to observe things is not like a new concept, but it has gained ency in the subway industry recently. So this is just for a cultural observation.
I, I, I think that when Al Elaborates make the first computer programming, uh, I, I am pretty sure that at this precise moment, she has started to think about how to improve the, the, the, the, the programming, the performance and, and detecting errors. So, so I'm pretty sure I, I mean it's, this is something that has been with us and has bothered a lot, but I am pretty sure that, and the definition and ions of, of telemetry, because as I said, it's not a new term. It's, it's quite old.
So we adopted this, this, this term from others in industry, like a lot of other concepts. So telemetry is the process of collecting and transmitting data from remote or in accessible locations. So we can see this, this slide, that, that can be traced back to the late 19th century in this steam era.
So we have this motivation from lot of, many years ago, so to, to collected data to improve our systems. Uh, uh, at that time it was of course another type of system. But this is just like, uh, an example of the motivations of, and the relevance of this, uh, uh, about measure and observe systems.
So this is another example of telemetry in this case is, is, is in the held, uh, territory. So, so that's why it is so important. We have, we, we know we can see a lot of tools that have multidimensional analysis.
So this are just a couple of example examples of telemetry. So we can request tracking and log resource monitoring, latency tracking. So, so the idea is to have all, all, all of this access together, so you can think about a, a root chaos.
So that's very important. So, so telemetry is, is a, is a, I can say this provides data need, needs to gain visibility, I mean to ingest data. So, so we can have these other tools that it's going to help us, uh, to improve many things in our systems.
So if you were a brief tagline, take about this slide. So, I mean, we are talking about a lot of experience that we already have, uh, implementing observability, telemetry, monitoring system observability, and now gas engineering practices. Uh, so, so it's not, I mean, it is it, this, this is due to the, to the evolution of how, how we are doing things right now, um, uh, prospect of, of the, at least a couple of years.
So we, you can see the, the last two, uh, milestones. Uh, we are not, not now doing this, this, this practices, these develop practices with artificial intelligence and new concepts like AIOps and ops. Um, we are seeing now a platform engineer.
So we are gaining complexity. So we need, uh, other tool to, to help us to integrate, um, our practices, uh, in, in current systems like I, I mean this is a, a vendor agno agnostic tool, but you can see open source tools and proprietary tools like, you know, this are lot of, um, these are a couple example of these tools that we currently have available. Um, probably you already know about cows engineer, I mean the fundamentals.
But cows engineering is a discipline of experimenting on assistant to build con confidence on the system's capability. So the idea is, is to, to know about the problems or issues before having it in, in, in production. So if, if we know about it before the user, I mean, we, this is observability.
So, so I mean it is related the, the, the cows engineer practice practices with observability because sometimes we, we don't know, we have several doubts about the, the behavior of our systems. So, so there must be a way of, of testing our systems, uh, and in early stages or even in production. So, so of course there are a lot of cows engineers tools from website.
We have the, the traditional monitoring tools, the observability team tools, and the cows engineer tools. So we are seeing, like the evolution is overlapping in features, but we can see pretty specific, uh, tools for cow engineering, like steady be open source or proprietary tools. It's depends of the business necessities.
Uh, but there are just a few examples of the many cows engineer tools available. Uh, and the decision of course will depend on, there are specific infrastructure and testing requirements. So we have cows, monkey, leadman, cows, uh, Grambling, uh, pba, steady be, et cetera, et cetera.
So the idea is to integrate observability and cow engineer, uh, I mean this is very important because, uh, it's going to be, um, a source of, of, of information that we be, be, will be valuable to our system to know if, if the system is re uh, we, we have this proactive resiliency with, with this integration. So there are a lot of companies that are doing that. So they are, uh, seeing a lot of benefits of, of observability and calcium general, like the, like the incident response time, the maintain to repair, you know, this, these numbers are, uh, decreasing or increasing depends of the, of the, uh, I mean, uh, we reduce the, the meantime to repair, to say something.
The service re reliability, the application performance, the infrastructure utilization, we don't have, um, we, we obviously save money with all these practices. So I mean, if you want to, to think about it in the side of the business, well, this is, are some metrics that we are going to improve adopting these practices. And, and the idea of the whole idea is, is well just make a, a hypothesis or experiment about your systems.
So, so like, like what I mean, uh, when you deploy a a system to production, you, you may have some doubts because you, I mean, it is not in, it's different for, for the traditional testing, I mean for genetic testing or interracial testing. But you maybe want to know about what happen if, if there is, um, uh, a, a latency in the network is it's the whole system going down or, or just acing it is, is, is, is it's the well architected system or we need to do, uh, uh, something else. So we have a lot of, uh, range of experiments like simulate and server failures, uh, injecting neck or latency triggering database error.
What happening, sometimes we, we don't, it takes too long to get a response from a query, uh, or injecting partial failures. I mean, when the system is running for, for, for instance, think about this, evaluating a, a, that scaling well in a contact of Kubernetes, what's happening, maybe we, we have this doubt about it, it's going to scale our system. So I mean, uh, we are not going to wait until, until the, the black Friday, the cyber Monday to, to have a lot of customers in our system.
So to, to know or if, if the, if the system is, is resonant. So maybe you, we can do a testing with, have engineering tools like stressing the CPU, scaling the deployment or, or make a specific deployment to see if everything is, is going well. So is there horizonal, HPA is al output is out scaling.
So, so we can test with these tools, um, integrating with observability tools, uh, we can know we can handle the, the increase of load. So, well, this is why this is important. Of course, you, you can have a lot of questions, a lot of experiments, a lot of doubts.
Um, and we are having this other, um, I I can say another approach with, uh, generate with this new tools like generative ai. So we can also, uh, harnessing the power of, of, of cap engineer in the book practices. So, so we are seeing a lot of integration with, with, because when we do this experiments, we got a lot of information so we can correlate data, so we can get, uh, road analysis.
So maybe you have heard about the dark depth, the dark depth is this concept about, about maybe we have hypothesis, maybe we can do some experiments, we have some doubts, but maybe we didn't know about a problem. It, this is like, um, the technical debt, but you are aware of the technical debt, the, the, the dark debt is that, that, that you don't even, uh, know that they exist. Uh, some, some issues that may appear, but you, how, how can you fix something that you don't know that exists?
So, so well, that's why it's important to the, uh, this, this practices. So cow engineer became a proactive approach to understand system complexities. So unlocking the sec, the secrets of dark debt.
So dark debt issues, dark deb issues, lurking in complex system, making their detection challenging and manifesting as, um, foreign anomalies in people, practices, processes, application platforms and infrastructure. So, well, this is why I think it's so important to, to, if you are not doing calcium engineer and using an observability tool, I think that, uh, you are losing competitive advantage. So what are some benefits of the proactive depth management?
Were early detection of dark depth. I mean, not only, uh, our hypothesis for experiments, even the dark depth, we, we can detect on early stages so we can avoid problems and productions. So obviously this is going to, uh, this is going to be a, uh, a cost savings in the long run.
So I can say, if you are not doing house engineer, you are losing money. Uh, so of course it's going to improve the customer experience. If we don't have any, any problem on production, uh, of course the customer experience will be better.
So enhanced financial visibility, we can save a lot of time, a a lot of resources, um, of course a lot of money doing this practices regularly as at above practice. I mean, in the, in the software developing lifecycle cycle, we can integrate these practices the same way that we are doing the B, so we, we can reduce risk exposure. So yeah, maybe this is like the, the one of the conclusions or my conclusion is like that, uh, if we went to wrestling, the cost of not doing cast engineer, uh, well silent systems, so we can be pretty sure, uh, doing these practices that we are going to have resilient systems, uh, optimization opportunities, faster issue resolution, and of course the competitive advantage.
This is very important. So it's a crucial stepping ensure the long, the long term rest, license and profit feasibility of your business. So by proactively testing and improving your system, you can minimize down time, optimize cost, and stay ahead of the competition.
Yeah, this is like a little resonance. So we, we are going to have this, this, um, takeaways from, from this brief talk. So observability provides visibility, gives you a comprehensive view of your system behavior, uh, allowing you to quickly identify or a solution.
So, so, uh, cow engineers experiments or hypothesis practices improve alliances. So by intentionally injecting failures, we can have fault tolerance systems. So this is an integrated approach drives syn in innovation.
So combining observability and how engineer empowers your teams to continuously innovate and deliver high quality software with confidence and to have better systems, you are having a competitive advantage. You know, if you want, if you are in the business side, and if you want to talk with the, the CEO of the company, uh, you can talk about money. So, so you are going to have this, uh, uh, savings in, in resources, in time, in, I mean, at this time we're talking a lot of about finops practices, but we can improve our finops practices with, with this cow engineer.
I think they are very related. We have a lot of new or not so new practices that are overlapping. So the idea is to have a full, a 360 degree view to have this competitive advantage.
So, well, uh, that's it. And, uh, if you have any doubt of question, comment, you can reach me on LinkedIn or any feedback I, I will be around. So thank you very much.