Techstrong TV – January 23, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everybody. I'm Mike Vizard. We got a whole lot of new AI rules, not to mention $500 billion in funding.
And we're gonna talk a little bit about a new report from the Futurum Group about AI adoption. And finally, what's the latest in AI coding tools? You're watching Text on here.
Hey, everybody. We're back and we got a full house today. We're gonna start from the, uh, left hand side of the country and work our way back as usual.
Jon Swartz is in Silicon Valley, and of course, tracking all things coming outta DC these days. John, good to see you. Good to see you.
We're gonna have our hands full the next couple years, I assume, and kind of fear, but yeah, it's, it's, uh, we're gonna start. We started off the day one of the administration with a lot of stuff to talk about today. So glad to be with you.
All right. I'm not entirely clear, which is further West Ohio or Alabama, but since Ohio State won the championship, I'm gonna go with our friends in Ohio. First, Stephen Foskett get good to see you again.
As always, It is great to be here. I, uh, unfortunately I missed a Textron gang, uh, earlier this week, so I'm glad to join the gang today. See that?
You, you just can't live without us. So you, you missed a day and you had to show up for the next one. Not, not, well wait an entire week.
You had to be right there, so we're impressed. Of course, also in Ohio is Lan Neha, who works on Tech Field Day with Steven. They are longtime colleagues and Langa also running tech, drawing AI for us.
So Langa, good to see you. Good to be back. Thank you.
And finally, John Willis, who I'm assuming is in Alabama and where it allegedly is snowing. Is this true, John? This is true.
And all right. And just, uh, I feel like, uh, I've got my picture on the cover of Rolling Stone. I've been Tech Field Day, so is that next week?
It is. And, uh, how Often you there? Yeah.
Yeah. Actually, we got, uh, we got three of us, uh, on this call. That'll be there.
Uh, maybe we should do the gang from there. Oh, That'd be fine. Yeah.
And I think we have to maybe on Wednesday and it'd be Thursday. Um, I was, uh, I, I'm from San Jose, so welcome back. I think, Steven, you've been there.
I'm not sure about you, John, but a couple times to San Jose. I there a couple of times, Jeff, I think. I think, I think that's an awesome idea.
I'm gonna pencil that in right now. Um, I would love to get into what's going on though in the world, because, you know, there's this new administration and they seem to be, you know, kicking out these executive orders at about a rate of about one every two minutes. The one that we're keeping an eye on at the moment, though, is what are they saying about ai?
They seem to have, first thing was scrapping the Biden rules. And now the second thing is lining up all these folks for this massive investment in ai. So, and of course, one of the first things they said was, Hey, and this investment will not be subject to as many reviews because John, who needs stinking regulations?
Yeah. Who does? Hey, um, yes.
So, uh, first I'm gonna start with a visual presentation. I, I don't usually do this on the show, but I think it's important because in a sense, yes, you know, they say a picture says a thousand words. This one might tell us about a couple hundred billion.
So here we have on this side behind Trump lined up several executives. He might remember them or recognize them. There's Jeff Bezos, Bezos, there's Mark Zuckerberg, Tim Cook, Elon Musk, Sundar pka.
Evidently, uh, Sergey Brynn was around. I don't see him in the photo, but he was around, and I know that Sam Aldman was around in Washington dc. And, uh, basically after the inauguration, uh, Trump signed an executive order, as you said, Mike, to scrap a 2023 executive order by President Biden, our former President Biden, that, uh, that would, uh, kind of held hold companies and developers of AI as some sort of safe safety standards, or look at its potential harm to national security consumers and workers.
So that's out of the way. On Tuesday, later in the day at the White House, Trump hosted Larry Ellison, the soft bank, CEO, Mr. Son and Sam Altman, as part of a announcement of up to $500 billion in private sector AI infrastructure investment in the us.
There's also a, uh, joint venture between OpenAI, SoftBank, and Oracle called Stargate, which is a little ominous sounding, but nonetheless, so in a sense, yes, unfettered AI development as fast as you possibly can. Uh, these companies, I guess, will be entrusted to self-police themselves, just the way social media. So, uh, self policed itself, going back to Zuckerberg, that didn't work out very well.
But then again, Congress can't pass any legislation invol regulating any type of technology. So now we have this new kind of golden age of America as it's been termed, or even the intelligence age, or the intelligence race. And, um, it's gonna be interesting to see what happens.
I, I anticipate, in addition to what we just talked about, even more actions spilling out, um, it's, it's, it really is a land rush and a land grab. And it will be interesting to see where this all goes. There's also even a report this morning I saw from a Wall Street analyst about this bate of TikTok, which is, uh, was extended 75 days on the ban, or from the ban in which the speculation is that Musk, and he, perhaps even Ellison, might end up owning the US operations at TikTok.
So never dull moment. Well, that's, that's a whole separate story. But John Willis, how are you feeling about all this?
What's then, well, first off, runs on, right? So that's, you know, there's, there's a little interesting tidbit there, right? TikTok, the US implementation of TikTok runs on Oracle, Oracle's infrastructure, Oracle sort of class.
So anyway, that, um, yeah, I mean, there are pluses and minuses, right? Like, um, you know, the, I, you know, I did some analysis yesterday on that, 'cause I wanted to write my own blog article about what do I think about this? And, and, you know, the, the, the pluses were that, um, you know, regulatory burden, you know, the trade-offs, right?
The, uh, federal outreach, right? Like, you know, that there are things that were in the executive order that there were not everybody was happy with, right? Like they, you know, there was some definite, um, you know, um, and then, you know, and, but then there are things that like, now we have no roadmap.
To your point, John, like, I, I don't think allowing OpenAI Sam Alman to worry about me. Like I'm, I'm a little worried about that, you know? Um, you know, or can have any concern for what he's doing when it comes to me, right?
Like, so, and then on the Stargate thing, right? Like, I think I'm, I'm more interested in like, how is that gonna play out? Because I smell lawsuits all over the place by the ones that weren't invited, you know?
Right. Look what happened with the cloud and Federated Cloud, right? Look how long it took for to, to get that whole thing cleared up, right?
So, um, you know, I didn't hear any mention of Google in there philanthropic or, and so I, I just wonder like, is this just gonna get stall? It's, it's gonna be a lot of noise because it's gonna be stalled for the next year, because there are gonna be tons of lawsuits. Well, I want to, I wanna bring in, um, the, uh, news about the, uh, framework for artificial intelligence diffusion, which was revealed last week, uh, under the Biden administration.
Uh, one of their last, um, efforts to tighten up the restrictions on export of AI chips. Um, the framework is actually pretty impressive. Uh, if you read through it or if you read the analysis, uh, on semi analysis by Dylan Patel, um, it's really interesting what they've done to really kind of fill in the holes in the Swiss cheese of restricting exports.
And on the one hand, and on the other hand, it's really interesting what it does sort of from a forward looking stance in terms of requiring major AI model development to be in tier one countries, and specifically US companies have to develop AI in the United States. In fact, 50%, according to the framework of their, uh, AI chips have to be, develop, have to be situated within the United States. Uh, if you look at this Stargate announcement, uh, and you read between the lines through the filter of the framework on AI diffusion, one of the challenges from that framework was that Oracle invested heavily in offshore AI infrastructure.
And that would be drastically reduced and restricted by the framework for AI diffusion. Stargate actually fixes that problem for Oracle. And another aspect that's interesting here is that, from what I'm hearing, Oracle has already built out too much, uh, AI infrastructure outside the United States, um, previous to this.
And they're gonna have to basically reshore a lot of that infrastructure. So much of this investment might actually not be investment so much as reshoring of hardware that Oracle has already purchased and reshoring of capabilities that Oracle already has, potentially now, if, um, the framework stands, and we have no reason to believe it won't. Um, for what it's worth, the, uh, Trump, uh, rescinding biden's executive order wasn't a specif specifically, uh, directed at this particular ai, uh, initiative.
In fact, um, it was part of the overall, um, executive order called initial rescissions of harmful executive orders and actions that revoked well, dozens of executive orders all at once. And this one was just sort of part of what was swept up in there. I'm wondering if anyone in the Trump administration even knows what they've done in terms of rescinding this executive action.
And furthermore, I'm wondering if anyone knows what they, that, that the, uh, actions of the Biden administration are part of the reason for this big, uh, Stargate announcement. But who knows? I mean, who, who cares?
Frankly, it's better if they don't know, because then they won't knee jerk to kill it, because the, uh, framework for AI diffusion makes a lot of sense. Yeah. But it's an interesting, you know, perceptive.
It was a very perceptive point by you, John, earlier about, uh, the, uh, the executive order and how it was written, because I did talk to a couple of people who had a hand in crafting it, and they acknowledged there were flaws in it. Their only concern was that now there's no real oversight or a roadmap, as you pointed out. The other thing, um, Steven, that, and I, I was thinking about this, and I'm gonna ask Mike as well, you know, I always have a bit of a skeptical eye around these major investments or these plans that Trump announces, like this goes back throughout his career.
Well, especially with SoftBank. Yes. Yes, exactly.
That's where I was going. And, and, and I'm thinking, I'm not thinking Foxconn, I'm thinking SoftBank. I'm even thinking back to Trump's earlier, you know, massive projects that he was gonna build in New York City that he talked about for years, and they just never came to fruition, even with the, the latest announcement in the Middle Eastern investment, which where there were projects that that didn't, didn't develop into anything.
So I have a, a bit of a skeptical eye. Maybe this is a bit of a repurposing around Oracle and, and SoftBank and OpenAI, but I, I just, I'll believe it when I start seeing, uh, real action or, or, or tangible evidence. Mm-hmm.
And there's a lot of speculation in the real estate side. We talked about this on a show earlier, but, um, a lot of the folks involved in this seem to be more interested in buying the land and hoping to sell it to somebody and maybe, you know, mark that up, then they aren't necessarily in solving the AI compute challenge. But Lanman, what's your take on all this?
Yeah, Trump himself has said that the, this target venture is going to help build more data centers and create more jobs and, uh, in the, in United States, but it really remains to be seen how it all pans out. Um, there are a lot of ifs and buts, really. Uh, so I think it just, it's something that we'll have to wait out and see.
Well, and isn't it kind of inconsistent? Like I read that like a hundred thousand jobs. Well wait a minute, because Facebook has a model now, you can build data centers in months.
They have models where they can be operated with less than 15 or 20 people, right? And AI is supposed to reduce head count. So like, why, why is this AI initiative now?
They're magically gonna, you know, 10 x jobs, um, for what is traditionally being done now in, in data centers. So, and well, there's, there's, there's gonna be two guys managing the robot, building the data center. Yeah.
Not there yet, but like, I, you know, oh, I, yeah, for now, at least until we have a new super intelligent AI agent that runs everything, it, the one last thing I'll say is if, if anybody's read the fifth Risk by Michael Lewis, that was, that was baby steps compared to what we're going into right now in every sort of level. The fact that AI is so pervasive, the technology of ai, we know of what, you know, how pervasive and how impactful this is. We've all been doing this for years.
This, there's nothing been this impactful and to just completely fifth risk. It just seems awfully scary to me. Hey, Steven, have you heard the one about the future of the data center?
It's, it's, it's gonna be managed by one guy and a dog, and the dog is there to keep him from touching anything. That's funny. Alright, what do John, so what do you expect to see Jon Swartz in the future here?
It seems like this is just the beginning of, of series of things, but what's your speculation? Oh, I was gonna, I think we already are starting to see like this, like a chain event or domino principle. I mean, I don't know how it's all gonna work out, but we, we we're seeing a, for instance, Google just invested a, a billion dollars in anthropic in which Amazon's already invested $8 billion.
We're gonna see all sorts of vaccinations, people moving in crazy speed, you know, the interest. One interesting thing is, um, you know, it's, it's, it is open, open game, open track. My interesting thing was there was no presence of Nvidia that I know of at the inauguration, or that we didn't hear anything from them.
Um, or for that matter, even Microsoft, which I found was kind of interesting. I'm not sure if anyone has any thoughts on that, but, uh, perhaps those are two companies that really don't really need the help of the administration or have to cozy up to it. But I found that kind of interesting, the absence of those two companies.
Yeah, I found that interesting too. And I, I heard the same thing, John, that, um, you know, Jensen Lang and, and, and, and Nvidia were nowhere to be seen, uh, with the inauguration funding at the inauguration, et cetera. I believe Microsoft did contribute some money, but, uh, again, I didn't hear about, uh, you know, the presence of the, uh, you know, Microsoft execs or anything like that.
Um, you know, it, it, it does seem, you know, you could, I guess say that vm you know, Nvidia doesn't really need, um, you know, the government's help, but frankly, Nvidia is another one of the companies that's gonna be really, um, impacted by the framework for AI diffusion. If it con continues through, If I was, and they push back on, they pushed back on that immediately. Oh, Yeah.
They pushed back strongly and strongly. One reason that we heard about it was because Nvidia was pushing back so, and, and got so much publicity. Um, I'm surprised that they're not, um, well in their, um, uh, let's say, uh, to be nice, uh, pressing the flesh, uh, in order to try to change, uh, the, uh, administration's goals.
Maybe they don't trust anybody. Jon Swartz, though, I would love to get your opinion on this. Where does all this money come from?
Because, you know, in the state of New York right now, they're trying to scrape quarters off the floor. Yeah, that's a good question. Cops in somewhere.
So, I mean, going back, going back to, uh, I don't need to make this personal, but going back to Trump and this based on, on his projects, and I've read a, a number of Lucky Losers, a very interesting book about him. And it, it just kinda looks at his career as kind of a microcosm of where the political side goes. And they're, they would just create numbers on projects.
And when I see 500 billion, it's a nice round number. I, you know, I will believe it when that money actually comes to fruition. I, I just think it's, it's a pumped up almost imaginary number that just threw out there just to get our attention.
It has to be, he had no inference with OMB. Like, how does he even start Yes. Throwing numbers out on day one when there's been no discuss discussion with OMB.
I mean, it's probably from the, from the get go, it's, it, yeah, it's the total, you're right, John. It's a total mo. It's, it is just, this is the method of operation.
You throw out an outlandish number. This hap this has happened for decades with him. And, and it goes back to this first administration.
And again, I mean, this is all, a lot of, a lot of bluster, a lot of, a lot of, uh, you know, these, these plans are written in, in two paragraphs. There's no due diligence as far as I know. It's just pie in the sky for now.
You know, I'll give them credit if something does come to fruition, but for now, I'm very skeptical about it. That was my point about the lawsuit. It hasn't even gone through the office management budget yet, right?
Like, it hasn't gone through any economics reviews. It hasn't. And then we're not even talking about the lawsuit.
So it's all just fantasy. Now, I, I will say, if they create a hundred thousand jobs in Texas and they build data centers and they insource infrastructure, um, yeah, great job buddy. But, but like, but just, you know, throwing your finger in the air and saying it will happen.
Um, you know, And This is like, this goes, yeah, this goes back to all the manufacturing jobs that were promised in the first administration. And how did that work out? This is the point where I, I'm, I'm expecting Alan to show up, you know, out nowhere and talk about Foxcon and talk about the con of foxcon.
And I, and I, I, I suspect that we're seeing history repeating itself again to, to a bigger extent in a more pumped up extent because it's ai and AI has to be bigger and more hype than anything else. Alright, Steven, I'm gonna give you last word on this, but I kind of feel like we're just watching an episode of AI Game of Thrones here. Yeah.
I'm, I, with all of this stuff coming outta the administration, I'm really trying to figure out what the reality is. Like, like you all are saying, $500 billion, it's absolute fantasy. Uh, remember SoftBank Maci song was right there with Trump in the first administration announcing a hundred billion dollars investment in the United States.
That never really happened. That a hundred billion dollars was basically the size of the vision fund, which famously became a massive loser, and, uh, lost at least a third of that money. Uh, a lot of those startups closed down.
They didn't amount to anything. And it wasn't like that money actually ever came in 500 billion. Yeah, it's a nice big round number.
It's five times the size of the vision fund. Um, a hundred thousand jobs. Sure.
Nobody's even saying what this thing is gonna be. What we have to do, just like everything that comes out of the Trump administration is we have to read between the lines and figure out what this is gonna do and how it's gonna nudge the industry. Um, you know, just like, you know, the, the, the repeal of the executive order on AI safety, just like the AI diffusion framework, these things can have real impacts.
They can cause the industry to turn, they can change the trajectory. We just have to try to not focus so much on the announced, um, bluster and focus really on the reality of what's gonna happen when these things hit, hit the ground. When, when, when, with, with the news of these a, you know, AI data center build outs and this investment and so on.
No, it's not gonna be $500 billion. It's not gonna be a hundred thousand jobs, but there is gonna be some investment. There is gonna be some reshoring, especially if the AI diffusion framework stays in place.
And that actually will have an impact. And we just all have to try to figure out, kind of push away the noise and try to figure out where's the signal in this. And, and I'm gonna add one last thing, Mike, which is, I talked about this before the call.
I don't think what's gone over the radar is what they've already done with csa. So now you have a perfect storm. You are literally pulling out all the, the, you're basically saying self-regulation and you're basically dismantling csa, right?
Um, it, you know, I mean, I I follow critical infrastructure. It's not like my space, Josh Corman is got me scared to death if anybody knows Josh Corman about the cyber critical infrastructure, right? Water supply, telecom, and like this is doing an amazing job there.
And that stuff's all getting gutted. Alright? We will be coming back to that topic in a future show, no doubt.
But, um, in the meantime, what I learned today so far is if you want the entire AI oligarchy to bend the knee, you just have to point to some imaginary cache and they show up. So there we go. All right.
We'll be back in. Hey everybody. We're back.
And we're talking about some research from the Tuum group, the Parent of Techstrong. And it points to, well, what is the level of adoption among larger enterprises of ai? And it seems to suggest that this whole notion of a fear of missing out is maybe going away.
People are taking their time a little bit and maybe being a little more thoughtful about how they're planning to use ai. So log, and this is on text drawing ar the site you run now, give us the hind points. Um, so yeah, it appears that the speed of AI innovation and success is a much slowing down, at least in the early stages for some companies.
Um, this is owing to a number of factors such as, uh, disconnect from the realities of implementation. Uh, adopters expectations are not well managed. Uh, poor ROI focus expectations for quick gains, integration issues, and most important lack of hands on strategy from CEOs.
Uh, the future on groups, uh, state of market survey, which, uh, recently released, uh, shines slide on this. Uh, some of the stats say that, um, 62% of CEOs view AI as a powerful force of, uh, change. But 38% just see it only as a hype.
And, uh, only 46% of the surveyed, uh, said that they were very prepared for AI adoption. And 31% were only moderately, uh, prepared. And, uh, only 48% prioritize rigorous ROI measurement.
So, and John Willis did an article on this. So I feel like that, uh, there are some takeaways from this. Uh, it feels like, uh, to re all the benefits of AI companies need to have some things in place, such as, uh, for, to start with, uh, they should be preparedness, which is crucial.
And, uh, sort of internal training, the ability to accommodate and manage the growing purpose of data, making sure that people are trained to handle the technology at a professional level, um, putting in place best practices and guard rails and slowly and steadily incorporate the changes, sort of shoving it down, employees. Alright, what, what, what? You had me at CEOs and disconnect from reality, so I've been laughing ever since.
But Yeah, that was another, that was another interesting thing to read between or read in this study, um, was that incredible disconnect. Um, 78% of CEOs strongly believe in their own ability, their personal ability to guide AI for their companies, but only 28% of mid-level managements agreed with that. Oh, I mean, the people actually in the, in the trenches, right?
Yeah. What there's the one thing I I was there was, I think there was a takeaway, uh, I'll get outta the way because I talked too much in the last segment. There's a takeaway that, um, from the CEO sentiment study that the analysis of reveals, as you said, Stephen, a striking disconnect.
The most successful companies are those where top leadership deliberately steps back from hands-on AI strategy. That kind of stuck with me. I know, right?
It's incredible. I mean, if, if, and, and the disconnect with customers as well. You know, the, this, this whole idea that, um, CEOs are all jumping in there, but according to this study, only 24% say that customers are specifically asking for AI based solutions.
That's wild, because that doesn't say 28 4% of customers, it says 24% of CEOs say their customers, which means that that could be much less in terms of customer demand, because that's only the ones that are going up to the ceo. I, it, it, it is incredible. Um, but it kind of matches.
I mean, do you know of anybody who's like out there, like going to their, I don't know, their main, you know, software as a service supplier or whatever, and saying, you know, show me your AI strategy. I need more ai. You need to put some more AI in here.
No, customers don't want ai, customers want solutions. AI is a way to give to, to make solutions. It's not the solution, Right?
It's investors who are screaming about, show me your AI strategy, right? At the end of the day, John Willis, I know we have talked about this subject in the past with you, and it it rankles you because you see so much the eye progress, I think wall. Yeah.
I hate the Wall Street view on this, right? Because, um, what I'm seeing in the companies that I'm visiting, well, first off, if the CCEO says it's so, it will be so all right. Like, that's just the reality of the, like, so saying they're disconnected and you know, like, um, but there are, there are incredible projects going on.
A lot of 'em, I can't talk about that. And, and what I do know is there's a lot of reluctancy to actually promote what they're actually doing because of the competitive advantage. I mean, they're created, they're creating so much innovation internally now how it all winds up.
And I, you know, we'll go back to the, what's the famous quote that if, you know, Ford, if I asked the customers what I want, we'd still be driving, you know, horse and carriage, right? Like, um, you know, I, I don't, I don't think that's a, a really, to me, that that doesn't stick right? The organization, like I know companies that have incredible amount of data.
One company has credible amount, you probably figured it out, but they have incredible amount of data on every restaurant on the planet. Like they're figuring out how to do something with that data, right? If they know every transaction of like 70% of all the humans who eat out in America or maybe even in Europe, right?
Um, like there's gold there. So it's the data stupid. Um, it is that organizations are not actively telling you what they're doing.
I've, I, on a previous Textron, we talked about, I had one client, Lily made me sign a second, NDA, not only that was I under NDA with the client I was working for, but I literally had to create, do another NDA to not discuss what they were doing specifically. Um, you know, they're very, you know, like, rightfully so, like if you're in a co competitive space and you believe you have, um, an innovative idea. So I, I don't, I don't know what the right answer is.
You know, wall Street are usually better at this stuff than I am. But, but I do know, you know, my ground level knowledge of what's going on with some of the large corporations that I've been talking to, I, you know, one I can talk about publicly is what John Deere's doing. John Deere is across the board, um, figuring out how to use this stuff strategically.
You know, like a transformational, you know, and that's the thing, wall Street's not looking with. They're looking for like, where's the money? Where's the budget?
What they, their organizations that are completely transforming their talent and innovation strategies based on this. You know, that's interesting that you said that, John, because I was in, uh, Pittsburgh last week at Carnegie Mellon, and I went through the robotic robotics lab and I talked to some folks in agriculture, especially ai, agriculture and John Deere's, that name kept cropping up and they, so to speak, no pun intended, but that, that was one of the, the key case studies actually something we should look into. I'm just, but the fact that you brought that up is, is really interesting to me.
They are gonna transform and they're somewhat a little bit more transparent than others. That's always the, the key, as you said, you, a lot of these companies are reluctant to say what they're doing. So where's the hype and where's the reality is somewhere in between.
Steven, I'd love to get your opinion on this though. When I talk to people, they're in a quandary. They cannot fund every AI project, and about half the AI projects are rapidly becoming table stakes, right?
They're not competitive advantages. They're things I need to do to stay competitive. And then they're trying to figure out, well, what are the things that are gonna really make a difference for us to be competitive?
And it turns out everybody's kind of working on very similar things. And so what is that window of opportunity around ai? Well, that's an interesting, uh, aspect of this study as well, is that it does show a real differentiator between sort of these, uh, younger digital native startup companies and the more established companies to the extent that at least I, I'm still working through my way through this.
I'm still trying to really digest it because this is an incredible data source. Lemme tell you that I, I've never seen it this much information direct from these CEOs. Um, it seems like established companies are smartly focusing on how they can use AI to transform their existing businesses, how they can use it to, um, yeah, as, as we were just hearing, to ingest existing data to come up with novel uses and novel applications for the existing market they have.
Whereas, um, the more, uh, digital native, smaller, you know, scrappier companies, they're looking for transformative business models and they're looking for ways that they can use data in a way that nobody has thought of yet. And that I think is really what we're gonna be looking out for here. We've already seen a divergence.
I mean, you know, John, uh, Willis and I, you know, we were at the early stages of cloud. There was that incredible divergence between sort of the cloud native companies and the cloud followers. We're seeing that 10 x with ai, the, the AI native companies, the data native companies, they really understand the capabilities of this, of this technology.
They're looking for novel ways to use it. They're looking ways that, that can serve as accelerators and differentiators. What has to happen for the rest of the market is what happened with cloud technology, which is where they look for the most useful tools, the juiciest morsels, the really, the things that can really transform what they're already doing and adopt those things, embrace those things.
That's what we're seeing with cloud technology. I think that's what we're gonna see with AI technology in the coming years. John, what do you think, John?
Oh, I mean, I was just gonna pipe in 'cause I do talk a lot, but I, you know, I talked about this Mike on a previous call, you know, the Friday y if you will. Um, but the, um, you know, I talked to CIO um, uh, nitty in the last year, and, you know, he said something really insightful about, like, John, I'm not in this for the ROI, I mean it, what I have to do in my organization is create a sort of seamless, horizontal, um, you know, sort of talent and innovation transformation, right? And, and like, like you listen to that and say, oh, it's just CIO speak.
But he knew like this whole question of like, what's gonna happen? This comes up a lot, right? If, if we don't need junior developers, how do we create apprentices, right?
This comes up all the time with ai. Well, the, the, the savvy business, or CIO or the, the executive team who understands your business are realizing that they're going to have to create a talent like from the 30 year Java developer to the two months out of Carnegie Mail and AI expert student. They're gonna have to create a seamless innovation strategy.
And again, I, if I knew that I'd be making, you know, $7 million a year for a corporation, but like, you know, but that, that I think the organizations that are thinking alike that way, you know, again, I don't wanna be careful about John Deere. I I'm talking about the stuff that's public out there, but, but like, like those are the type of things I'm looking for when I'm interviewing, when I'm hanging out with Jean and Kim's crowd. And, you know, I, I want to hear how you think.
Are you just like letting people go off and create pilots and co-pilots and chat bots and like, because you can, or are you setting sort of an across the board, or at least attempting and, and back to your Steven, like that was the, the haves and have nots and cloud, right? The haves understood this was a technology transformation and they, they, they step back and some of them, you know, capital One, capital One is a great example of a company embraced it strategically in the financial sector, probably one of the earliest ones to truly take advantage of cloud. And they did it, you know, head to toe.
And so that's what I'm looking for is the organization. CI talk like this. So, so let me ask you this question.
What do you think the odds are the next great thing in AI that a company does is gonna be driven from the top down? Or is it really gonna be driven from the bottom up by the people who are closer to where the AI is gonna make a difference? Um, bottom up is how ideally it should be, but oftentimes, uh, like you mentioned, there is, uh, this strange disconnect between, uh, the Csuite executives and the people that are working at the ground level doing the real work.
So, uh, as long as that, uh, there's a bridge between the two of them, I see it's very difficult for companies to really implement that kind of a systemic change where, uh, it is done in a discipline sort of way. Um, uh, but, uh, surely these smaller companies, and it's actually really following the cloud trajectory where companies are at first, like they're overwhelmed with, suddenly there's this AI rush and then with all of the aggressive strategies and, uh, stuff like that. And there's that myopia that, you know, if I can embed AI into my organization, I'm, it is my ticket to success.
So I think we are we'll slowly get out of that phase, uh, to a point where companies start to see more clearly and see how it can be actually implemented step by step in a way that works. Um, so I hope to see that kind of change happening in the future for Sure. Here's my bet, my bet is that the middle managers are gonna wind up being the heroes that implement this stuff working from the folks at the bottom up, and they're gonna become the next people taking the CEO survey.
'cause they're gonna replace all the guys that couldn't figure out how to make it work because they're too far removed from the actual thing that the company does. Steven, am I crazy? I think you're not crazy.
And I think that that's what we've seen in the past as well. Um, and, and, and one more thing from the study. Uh, it, uh, once again shows companies are desperate for people with this kind of knowledge and skill.
And I think that, uh, if those of you listening are, uh, interested in, uh, what to get involved in, uh, well, uh, I know, uh, this is not gonna be a news flash to you, but, uh, hey, maybe learn a little bit about ai. Ai. There you go.
Hey, I think that goes for everybody. If you learn about ai, you're gonna write your own ticket because as they say, it's not AI that's gonna make you lose your job. It's the person who knows how to use ai who's gonna take your job, right?
Alright, we'll be back in a minute, folks. We discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey everybody, we're back and we're returning to one of our favorite subjects, which is just how smart are these AI coding tools?
And we talked about in a previous episode about a survey from folks that suggested that, that the amount of bad code being generated by these tools was high because they didn't understand enough context about the deployment environment. So developers were spending too much time debugging code written by the AI tool. Since then, we have seen some advances, uh, Devon's talking about a new version of their tool that's smarter and has more reasoning capabilities.
And then there's even a startup that's, uh, I'm gonna butcher this, uh, RA or something of that effect, which design their tool to keep the developer engaged. Their argument is, is that developers, if they're engaged, well understand the code and it won't be so hard to debug it. 'cause part of the problems with some of these other tools is they're just black boxes and they generate code and nobody knows how they did it.
John Willis, you cover this space more closely than any of us. What's your take on, where are we? What's going on?
Yeah, I mean, it's a mess just like everything else, right? Uh, I think, you know, I, my personal opinion to Devin, it was dead on arrival. We've gone through that.
You know, the, um, they don't even show up on the benchmarks. They don't even try to show up on the benchmarks anymore. Uh, the sweet benchmark, which is good or bad, it is the litmus test for a coding agent.
Um, you know, they, they, they, they hover in on their last peak was about 14 to 20%. The benchmark now is a 55% resolution to 60%. Um, and there's just a lot of players since, uh, you know, even the Open Devon team is now called, uh, all Hands.
They renamed themselves, right? They were basically current, literally about a week after, uh, Devon announced you, you know, their sort of fictitious resolution capabilities, um, which were just chopped up by the industry. And open Devon was a response to, um, like, Hey, like, this is not that hard.
The, the AI engine does most of the work, right? Um, and so, you know, uh, I find that two simple open source tools, ADA and Klein literally do everything I need to do. I mean, you've heard all about Cursor.
There's just a lot of players. Guy Pur Purdy that sneak founder. It's got something called te.
I mean, it, it, you know, Amazon queue developer shows up really high on benchmarks, uh, you know, um, copilot workspace, which still I don't think has been released by Microsoft. So it's a very competitive space. But the key thing that you said there, which is when these things first started coming out, the context windows weren't as large as they are now.
And what, what a lot of people are realizing, and I think eight is the first one I've seen do this, is they allow you to take all the non functionals, like your, your Jira tickets, your um, your documentation. And, and this has been sort of the biggest problem with these tools is if you just ask it to generate code, um, it really doesn't have any strong context of all the other resources that are related to the code's generated. And so now these context windows are so big, like you can literally, I mean, some cases you just load a repo into these, uh, engines and just say, start explaining this to me.
So there's the two worlds. There's organ, there's tools that are staying far ahead of everybody. So like, pull in all what I'm gonna code now.
I want to take all the documentation, I'm gonna take the terraforms, I'm gonna take, I'm gonna take everything I possibly can and throw it in the context window when I ask to create a service. Patrick Debar talks about this elegantly in some of his latest presentations about, like, the world has to be this massive context of not just code, code is such a small part of the operational cost of an application. We all know that.
Um, and, uh, so I, I think, you know, again, I, and, and the balance then is the technologies. I mean like all of the major, you know, sort of LMS or models now have their own agentic capabilities. A lot of the early Devon, uh, open hands, all those things, uh, were that they were implementing agentic capabilities on platforms that didn't have it right.
Built in. Um, and so the, you know, the, I think the, the message is, you know, learn, learn how to create agent-based solutions. Learn how to let a AI understand the full context of your service and then, you know, don't get locked in right now to anyone solution because it's moving so fast.
I mean, I, you know, I I mean just what's happened in the last quarter, or not even the last four months between GPT-4 oh going all the way into oh three. I mean, it's just mind boggling what's happened in the last four months of the reasons. Hey, John?
Yeah. Check. Can I ask you a quick question?
I, I don't, this might be a non sequitur, but what you, I mean, you know this so well, what about operator from OpenAI? This might be coming up, some version of it, or early version might be coming up soon. I've read to the point where it has ability to autonomously code or even Jew, Jew functions without any human interaction.
Is that, is that kind of play into what you're mentioning? Yeah, no, I, again, they, they've already sort of created the ent, you know, capabilities and now, yeah, I mean like, again, the point being, well that goes back to a bigger picture. And I always felt this, I've been surprised that, and I'm gonna sort of wiggle around this and get to the point to your question, which is, I thought when, um, when Microsoft co-pilot workspace, which I think is still in beta, um, they were gonna win it all.
'cause all if the big providers provide a high percentage of resolution or ability to sort of create code autonomously, then I don't see any of the little players surviving, right? Um, and so, yeah, I mean, you know, if, if OpenAI can take, you know, what they're doing and, and create, you know, sort of an operator level of efficiency, I'm still waiting to see what Google's publicly gonna come out with in this space. They have it, you know, it's, it's internally I've talked to people, they use it internally.
Um, so there's one element of that question, which is I think the big players are probably gonna dominate. If you've gone all in on, on Google and Vertex and they have a reasonable solution that that benchmarks pretty well, then you're probably not gonna jump over to the operator or, or, um, philanthropics or, or certainly not like Tesla or, and then again, I think the, the, the interesting then becomes the open source edge players, and I, I'm probably the only one that calls it, but Eighter and Klein and these tools that are really effective is instead of big picture, $500 a month or a thousand, $2,000, all you can eat Devon Solutions. So John, lemme ask you a question here about all that context, because one of the things I'm starting to hear from folks is do I need an AI coding tool that is tightly integrated with the rest of my repositories in my DevOps platform to get that context?
Or can the AI coding tools be, are they more disposable in that sense where I can just swap them in and out as I feel like No, I, I think in, in fact, I, you know, I I, the first time I heard it, it's Pius soer, so I'll, I'll, I'll replicate your, uh, like destroying the name. Uh, but like, I think that's interesting 'cause that, you know, one of my arguments that I get a lot of pushback from, you know, the sort of all the sort of AI kids and is that the, the, the, the main repositories are GitHub. Like all the engines that are coding, Susan all been trained by open source GitHub libraries, basically, right?
Or gi you know, gi, right? And, and there's a big difference between, for the last 10 years, capital One with 18 to 20,000 Java developers and how you build services in an organization like Capital One on, you know, probably, you know, certainly hundreds of millions of lines of code, maybe billions of lines of code and code that's been generated in open source projects. So they, you know, my argument, there's gotta be a difference.
So organizations that are helping, and there's a few of these happening, helping go in and understand your libraries, your code, uh, I don't have any data on it. I think they're gonna be far more efficient. You know, you think about what Capital One or a large bank or Goldman Sachs has to do for their code base to work it, it's just the, the, the decision and the training and all the, the sort of code generation is just gonna be significantly different.
Yeah, I wanna jump in on that, John, Because I think that you're really onto something there. What you've been saying a lot here makes a lot of sense to me. And that's that essentially if, if the code generator is just generating code, that's not all that interesting.
If it's generating your code, then it's much more interesting if it's helping you to generate what you want. One of the interesting things about this Pyra product is that it doesn't just spit out code. It's a conversation with the developer.
Um, I'm not sure that that's the right way to do it, but it's a good way to do it or better way to do it. To your point on Microsoft copilot, I had the same opinion that copilot was gonna be radically successful, mainly because it's right there in your IDE, it has access to your code. I mean, Microsoft has GitHub, the same with Vertex.
I mean, if you're a Google developer then you know, Google can do a lot with what's already there with, with the rest of your, your corpus of of, of code, a lot of these open source, what you're calling edge, uh, copilots or edge products. I mean, that's kind of what they're doing too, is they're watching you, they're helping you. It, it's kind of like, you know, when you're, when you're working with, uh, an AI writing tool, uh, there's a big difference between one that actually knows your writing style and one that's just spitting out words, right?
Yeah, absolutely. Um, I personally do not put a lot of, try to not put a lot of faith on, uh, tools like that that do coding. 'cause you know, I keep hearing from a lot of people that, you know, sometimes the coder earns there are bugs and it takes away a lot of time to really fix them and get them in shape so that they can run it.
So what I personally think is it, it's wiser to actually take it with a grain of salt, really. And, uh, see that the, it is these tools are basically meant to help you than to just, you know, do your job for you. So you can maybe use that code as a template and do your changes.
And even if they're tying in all the context and all that information and personalizing it to your needs, it's still important that, uh, there is a human in the loop who's like actually looking at it and making sure that it's on well and good to run. 'cause it's code after all the smallest mistake and make the biggest, uh, difference. Bob Willis, last question on this.
Um, I also wonder if we're overly obsessed with coding and if I look at a developer's job, coding is maybe 15 to 20% of what they actually do. And so do we need AI to do all the other stuff? Because, you know, we're not really gonna drive productivity just 'cause we can.
Well, that's the point, right? Like coding is a lot of copy and paste. It's going, finding routines.
It's like most coders, if you write, you write 10 lines of code, it basically turns into a thousand, 5,000 lines of code anyway because all the libraries, right? So like, so, so I I I don't really adhere to this sort of idea that AI tools are gonna make worse code when you've got 20,000 developers in your organization. There's a lot of those.
I ask those people like, oh, I can't use, you know, copilot or I can't use this. I'm like, how many of your, you know, that that base of Java developers you have, you think actually writes Eric free code? And, and the truth of the matter is, these tools are gonna do better than they average coder.
They already approving it on benchmarks. So the argument that AI generates better, every, every implementation of coding will have bugs and errors. The question is, will these things get better?
Are they, uh, like at a point where they are better? I do. They are.
And then to your point, Mike, like coding an application is a lot more than just sitting down and writing code. It's design, it's requirements. The, it's like the same thing.
I use a lot of tools for, uh, writing. I don't let the AI write my, my articles, but what I will do is I will feed every concept and idea and all the things I want into it, right? So I think, you know, when you talk about a service that's being built, the, the human in the middle is the design.
You don't just say, Hey, I, I am a business that sells cars. Go ahead and figure out how to write software that will, you know, that will do a better job. You know, like that's not how it's gonna work anytime soon.
It's gonna be, we have this business campaign, we have this idea, and we're gonna go through design and we're gonna require, it's gonna be humans all a part of it. But the point of where somebody just sits down and literally 80 to 90, uh, 90% of what they're actually doing is using reusable libraries. You know, I, I've said this before.
Topo Powell talked about a Capital One where he was asked one time to find how much of their, um, code base was open source and it was it like, it was not open source. How much of their code had they actually written? It was 1% 99% of their code.
He's publicly said this, 99% of their code was libraries. So like, so now we have AI tools that literally are doing the same thing on that 1% or 5%. It's definitely never more than 10% in any modern organization.
So like, like what are the decisions that are going wrong by that, that AI is doing worse than human picking, the wrong libraries, putting in the wrong configurations. Those are things that you just do ter pretty terribly. So I dunno, some folks I guess, you know, we're not gonna miss copying pasting code ultimately, which may account for why a lot of these repositories are seeing a, a decline in overall traffic.
'cause people are just taking it from the OpenAI tool. Hey folks, thank you all for being on the show as usual. You guys were awesome, shared great insights.
And with that, I'm gonna point everybody to the rest of the lineup coming up right behind this show. Textron TV is coming up. Stay tuned and we'll see you guys tomorrow.
This is Techstrong tv. Hey everyone, welcome back here to another tech strong TV segment. Our guest for this segment is the co-founder and CEO of latent ai.
His name is Jags Kandasamy. Uh, Jags, welcome to Text Strong tv. It's great to have you on here.
Thanks Ellen. Thanks for having me. So exciting, Ben.
Fantastic. So Jags, I mentioned you were the co-founder and CEO over at Latent ai, but you know, there was life before co-founding, right? Latent.
Let's hear a little bit about your life pre latent ai. Absolutely. Um, right before, uh, founding latent ai, I was running, uh, another startup called AutoSense, where we had automated human hearing, imagine this, right?
Listening to sound and then identifying events from it. He, uh, took the company towards, uh, manufacturing and the predictive maintenance applications. So li you know, if you know a good mechanic before they touch a machine, they listened to it, then figure out what's wrong, and then they, they approach it, right?
So that's basically what we had automated. So we were in, uh, in uh, uh, working with Delta Airlines, with, uh, Ford Motor Company with Airbus and several power plans in, in Japan, right? So being sound to identify things.
One of the, the issues that we, we had, you know, this was the first Edge AI component, right? In the mid 2010s, uh, uh, everybody was thinking about AI and we had taken AI to the edge, right? Running it on the, uh, on near devices where, which makes sound.
And that's where, uh, uh, you know, I got my start. And prior to that I was at H-P-H-P-E, started as an engineering manager, and then ran customer success, customer support, and did several things. Uh, at HPE, my first company I started when I was 21 back in India.
So really been here for 20, 25 years now. And, uh, you know, that's my journey. Don't have a lifelong entrepreneur.
Very cool. So interesting with the company, with the sound, it was sort of machine learning where you matched patterns of this sound sounds like this. And when it sounds like this, this is what the, the situation usually is or this is what Absolutely.
You know, the status is. Yeah, we, we actually, uh, took every chunk of sound you could. Uh, the chunk could be one millisecond or five seconds.
However, however, uh, granular you could go, uh, you wanted, you can do that. And then we, uh, went around, uh, analyzing each chunk in three domains. Frequency, domain, domain, amplitude, domain and time domain.
And then, and we extracted some features. That was our core algorithm, our, our proprietary algorithm, and we extracted features, and then we did the pattern branching on those features. So you got similar sounds to group together, and we were able to easily visualize and, and, and, uh, tag them and, and push them out into the model.
So, Excellent. So you went from that to founding latent ai. What was, you know, as I, I spoke to you off camera, no one founds a company lightly, right?
We all put our heart and soul into it, blood, sweat, and tears as well. What was driving you that latent AI was going to be a, a must have a game changer. What, you know, what was, where'd that passion here come from?
So, a couple of things, right? I have to go back to the Artan story. When we started AutoSense, um, imagine collecting sound, you know, we put a sensor out there, collected sound, and then, you know, you started collecting everything in the cloud.
We were using a hotspot early. In the days when you use a hotspot, there is a bandwidth limitation. We got a notification from our telco provider that after two days of collection, your bandwidth for the month is done.
So that kind of brings, like, okay, you need to move things to the edge to, to analyze. That's one. The second issue that we hit was, uh, the company was ultimately acquired by analog devices.
When analog devices came to us and they, they invested in us. One of the, uh, uh, the memorandum for us was to run the algorithm, which we were running on an arm processor to be run on their blackfin DSP, their digital signal processor. We literally had to rewrite every line of code from arm to DSP took us seven months.
Once we finished that, a DI said like, alright, we are acquiring it. Right? They wanted to make sure that it ran, That it would work.
Yeah. Yeah. So after the exit, I, you know, the things that was, uh, bothering me was that one, why did it take so long?
Why do we not have a universal compiler to bring AI models to different hardware devices? You know, uh, in GCC compiler, we, we basically switched the flag and we are able to compile quickly, right? For, for regular application.
Why can't we do that on the ML side as well? That was one problem. The second one was, we kept increasing our bandwidth from, you know, 3G to 4G to 5G from a, from a telco perspective.
And then we went from, you know, a coaxial cable with, and the broadband to, to fiber and stuff. But still the applications and the demand kept going increasing, right? We, we are never happy with what we get, right?
The, the, the theory of induced demand kicked it. So those things came into my mind, like, if you want to process these things, your processing needs to happen at the source of data. Whenever and wherever analog to digital conversion happens, that is where processing needs to happen.
That is where AI needs to run. That was a, a, a, uh, a nirvana moment for me in the, in the mid 20 fifteens, right? And I wanted to, uh, ensure that we kept that and I, I was solving for that problem in a continuous manner.
And that was what the origin of leading AI was. When I joined SRI International and Stanford Research Institute is the, uh, birthplace of c nuance communication. And it is a place that internet terminated, uh, back in the seventies, right?
When, when, when Darpanet, uh, started out, I, I I, I went to SRI as an entrepreneur in residence and met with my co-founder. SS had worked on technology that compressed neural networks, right? So, okay, the compression is required to push things to, to the edge.
And, and my idea of building a compiler backend, we put that together and, and we, uh, built an SDK to launch the company. So that is the origin, and that is the reason is, you know, AI cannot always be running in the cloud. And I'll, I'll I'll end.
Uh, this, uh, part, right when I went on my first fundraising, right? We are a VC funded company. My first fundraiser, our seed round, and, uh, the seed round was invested by Steve Json from Future Ventures.
Steve has backed Elon, uh, companies like Hotmail and, uh, uh, you know, Commonwealth Fusion all, uh, leading, uh, edge companies in, in, in this, uh, uh, respective industries, right? When I pitched to the group of investors that day, I pulled out my iPhone, I called Siri, asked for time. Siri promptly answered me the time.
Then I put the phone on airplane mode, called Siri again and asked for time. The response was, sorry, Jags, you are not connected to the internet. So when Siri said, you're not connected to the internet, and I turned to the investors and I ask them the information, the time is available locally on the phone, right?
And the command is very small. Why can't we have selected commands and selected intelligence available locally on the device? Why does it have to always go to the cloud?
This is the reason we need edge ai. And that secured my first seed round. Good for you.
What a great start. I'd love. Look, I, unfortunately, well, not unfortunately, I've had the pleasure of, of doing several, you know, venture backed startups and, you know, you always got that moment where, you know, you got 'em right where the VC sit.
This is something, this is a must have, this is important, not just nice. Um, so here, here's my take on it. I got kind of three different areas.
I, and by the way, we're gonna come back. I want to tell people, you know, late in AI's website, how they get involved product wise and all these things. But three things.
Number one, in my mind, I, I have this like diagram in my head of I've got my core hypervisors own data center in the cloud, probably, right? Then I have edge computing on the edge somewhere, and that, that takes a lot of d everything from like a, a container, not a docker container, like a aircraft container with equipment by a cell tower or something. Or, you know, somewhere along the edge, some computing resource, and then on device resources, which to me is the edge isn't the edge, you know, it's kind of mushy right there.
Yes. But we're here talking really about on local device computing or not, Not. So we introduced the term called the edge continuum, right?
I will, I will take you back to your chemistry class in high school. Do you remember the distillation tower? Crude oil gets heated up and you basically go through different layers and you extract products out of it.
I was reading, uh, the Economist article about data is a new oil again in mid 20. Uh, I think the article came in 2016, right? So that is when, like, you know, some synapsis pied inside and I started to work on that edge then.
Okay. So the way we position it is that data gets converted analog to digital at the sensor level. From there, data travels through different networking nodes, different computing nodes along the pathway, either to the destination in a hypervisor or whatever that destination may be.
Travels through that. Along this layer, computing is distributed heterogeneously, okay? Our thesis is that how do you define AI for this heterogeneous environment?
So you extract the right level of intel along the pathway. Okay? So, uh, um, we have done extreme, uh, extensive business in the de Depart Department of Defense.
And I, uh, co-authored a paper with, uh, retired vice chairman, joint Chiefs of Staff General Cartwright, uh, for the Atlantic Council, which is a, a leading think tank in, in defense, familiar. We co-authored paper and we actually applied a similar strategy for defense, whereby we are calling it the, uh, uh, uh, tactical edge, operational edge, command edge and strategic edge, right? Four layers of the edge.
And how do you process information accordingly? I love it. Is there a diagram or something of the edge continuum on latent ai?
Yes, there is all of it. I, I would recommend, you know what, to our audience go, we should get this outta the latent. ai or is it latent?
com. com? Yes, That is correct.
Okay. com. So, so Jags, let me ask you the next question then.
You know, I was reading an article today, a new survey out 75 or 74% of organizations say their AI initiatives are being delayed because of access to GPUs, right? We need these GPUs, which I don't, I get how good GPUs are, and I understand their role in ai. I just don't know if I buy into the whole 75% of AI stuff is being delayed because of access to them.
Uh, but that being said, one of the issues is a lack of that kind of horsepower at the edge in on devices. Now we are seeing I PCs, the so-called a i IPCs, we are seeing, you know, apple and Google Android phones, uh, you know, with AI built in, and they've got, you know, the M four chip and all this kind of stuff, not the M fours from a Mac, whatever the latest chip is on the iPhone eight 20, whatever. Um, what about do we have the horsepower along this continuum to truly perform the kind of AI that, you know, the AI we want?
Let's say the, you know, the, the kind of stuff that's game changing. I'll give you one example, right? This is something that we've already done and, and we actually demonstrated with the telco.
We talk about the edge continuum, right? Uh, we did a doorbell as an example, okay? A doorbell today, if you think about it, it's motion activated.
Anything that moves in front of it, you are gonna get a notification. It could be, I had a buddy of mine, uh, he had a b that was trying to enter the camera, right? So he got 800 some notifications in one.
Oh God, Imagine the, the frustration there, right? So let's say we build a low, low power battery operated camera, doorbell camera, right? It could be a forbit processor.
We actually built it on a forbit processor, and the only algorithm that's running on that FORBIT processor is a human non-human detection. Is the object in the frame are human or not human. Okay?
So now once a human is identified in that frame, then the next layer of compute, it could be a set up box in your home, or it could be the MEC environment, let's say a multi access edge compute unit from a telco perspective, it could be a 5G connected, uh, um, device. So that server could be running facial recognition at that point. Is that Allen at the door?
Is that jags at the door? Do they have permission to come in? What, you know, what is the next set of rules that you need to follow?
You could do that. Let's say you're not able to identify that person. There is a human, but I don't know who that is.
Then we can pass that information. That same frame can be sent up to the third layer. Could be a CDN, could be a little bit more, uh, uh, compute heavy, uh, Part of the continuum.
Part of the continuum. And at that level, you're looking at it and saying like, okay, is that person wearing a uniform? U-P-S-U-S-P-S, FedEx, is that person wearing a hat?
And, and, and, and covering their face? Is their face occluded? Is that a security issue?
Right? Third one, is that person carrying something in their hand? Is their hand hidden?
You know, is it a delivery or something, right? So you're able to identify in your car, able to run these d different models at that level. So the Math, I, I get it.
So it's almost a just in time system where, you know, if you have the horsepower, if you view this continuum Yes. Bottom to top, let's say right from the extreme edge all the way back to core, you, you, if you have the, you, you make the decision where the, where you have the horsepower. Yes.
And if you don't have the horsepower, it gets kicked back one until, you know, finally at the floor. But you only have to do it at the core if that's the only place where it could be done. Exactly.
So it's alm it's like efficiency built in. What a true that that concept alone is the money, right? I mean, at some level.
Exactly. Right. And we are building and putting the logic in place for that.
Exactly. We are building the tools to so that you can rightsize that logic, rightsize the model, and you can deploy it on these different hardware. We are on hardware, hardware agnostic and model agnostic tools.
So we are, I get it. It's just a question of building that just in time system. Exactly.
I love it. Uh, you mentioned to do a lot of work with DOD. Uh, how, how long has late na AI been in business?
We've been around for six years now. Oh, so you're, you're an old tire. Another, another overnight sensation.
Exactly. Good for you guys. And I know you, you've, you've got some tremendous talent over there besides yourself.
You know, you're an accomplished, uh, tech person yourself, but what about the rest of the team, Jacquelyn? Oh, um, uh, I am blessed to have an, uh, extremely talented set of individuals packing me here. Um, I would say my, my CTO, right?
He's a celebrity when we go into AI conferences, he's a, he's a well-known chair for, for different events. So Sec Cha is my CTO. He, he's amazing.
My head of compilers is a guy who did his postdoc work with Dr. Bill Dally. And Bill is the father of GPUs, right?
And, and a chief s at, at Nvidia. So Ado worked personally and closely with, uh, uh, with, with Bill at, at Stanford. So ADO is helping run the compiler show for us.
And then Jan, um, our ML guy, he comes from Siemens and, and, and, and a historic career from Germany to the us and he is well known in the ML and CV space, computer vision space. And he's pushing us into different, different sectors that, that we've never even thought of and, and drawing results, uh, crazily, right? So, and then we have, uh, almost close to, uh, 15, 20 PhDs in the organization.
Uh, we are growing continuously and, and we've doubled our size, uh, last year, grown over about 200% in revenues, uh, uh, year over year. So it's, uh, What a great story. Extremely lucky, uh, uh, uh, to be in the space.
Uh, What a great story. Congratulations to you for putting this all together. It, it's a, it's a feel good story.
I like it. Thank you. Hey, we're about outta time, but first of all, again, congratulations on, on the success.
I, I love what you're doing. Do come back, keep us posted and, and best of luck to you and latent ai. That's fantastic stuff.
Jag's k co-founder and CEO of latent AI here, ontech strong tv. We're gonna take a break. We'll be back in just a moment.
This is Textron tv. Hey guys, thanks for the throw. We're here with Josh Taylor, who's the lead security analyst for fortria, and we're talking about how social engineering attacks are evolving 'cause well, the bad guy's, getting a little more clever these days.
Hey Josh, welcome to the show. Hi, Mike. Thanks for having me.
You've been following this space for a while. What are you seeing? How are these tactics changing?
Because we've certainly come a long way since, you know, those Nigerian princes were sending us faxes, right? We sure have. Um, what we're seeing is an uptick, especially in the last, I would say six months or so with, uh, these particular types of attacks.
Uh, some of that is just the fact that the person is always the, or the user is always the weakest link in the security chain. So you're seeing attackers still focused on, on focusing their efforts there, but you're also seeing the iteration of these attacks going through multiple rounds of ai. And so they are becoming better at crafting these attacks to trick users.
So what do they look like? Do they have patterns or are they so good? We can't even distinguish them anymore?
They're definitely getting better. There are definitely some patterns though that are out there. Um, some of the more common ones are things like capcha attacks that they're doing that look like they're trying to verify whether or not you're a human.
Uh, we're seeing some of those particularly lately. And then we're still seeing ones that are presenting themselves as things like security updates and other things that, that represent authority on, on your system that you might be used to seeing already. And they're really making them look a lot like those types of, of fields when they're presenting them to users.
Will you start to hear a little bit about phrases like scam yourself or We basically being fold into fooling ourselves pretty much. That is the, that is the whole idea behind these is that the attacker plays on the user to actually participate in the attack themselves. And so therefore they are kind, the user is kind of scamming themselves instead of everything having to be done by the attacker, the user plays a part in these, in these types of attacks.
I'm assuming that's unwillingly, but part of the issue, I think, is that the end user doesn't realize that they are a means to another end, and so they're just happily doing whatever it is they're doing. And then I'm assuming that cyber criminals are then using that access to move laterally into the organization and cause all kinds of havoc. Definitely it's a point of entry for them.
And from there they're able to do things like reconnaissance or establish, uh, persistence on either the device or in the network. And from there, do things like download other tools or set up command and control and further their attacks into, into corporations or just on your personal device. Is it getting harder for us to distinguish that?
And are these attacks essentially seems like they're slow moving and lasting maybe a lot longer? I think it is getting harder to attack. There's, if you look at things like phishing emails, we now have a lot of spam filters and other types of filters that scan for this type of activity.
But when a lot of these things are being presented to the user, it's being done through things like their web browser, it's, it's not as easy to detect on the front end. What we're seeing is a lot of secondary detection. So the actual first attack and the scammer cell portion will get through to a user because there's not very good filters for detecting that.
But then when we see secondary things like a PowerShell script execute or something like that, that's when we're able to, to notice the activity and, uh, start an investigation. So do you think that these attacks are more lethal than they used to be back in the day? I mean, um, are they deeper into our organizations and are the dollar values and the impacts, and for that matter, the, uh, um, entire scope of the breach getting larger?
That's a good question. Uh, um, I think it really depends on how high up typically the user that they're able to compromise. Um, so it's, it's different every time, but of course as the attacks get more sophisticated, the attackers will feel more emboldened about reaching out to higher level people, maybe executives, uh, your C-suite people.
And if, and if they're fooled than of course the attacks can be, can have a, a very dramatic impact on the organization. Will maybe AI save us from ourselves one day soon, or is it already, I I think it's gonna play a role. I think attackers are using AI to craft these attacks, and I truly believe that in the future we will leverage that as defenders as well to scan things like behaviors and, and what is going on, uh, at user endpoints and look for these types of attacks.
Is it your sense then that we're kinda, uh, involved in some sort of AI arms race here then? I think that most organizations will wind up utilizing this in the future against attacks? Yes.
I, I would say that it is, that is a term I would use. It is, it is an arms race. Attackers are going to leverage this, so then defenders must as well, and, and we just need to be ahead of, of ahead of them at those, at those steps.
The part about all this that, uh, your average business executive is gonna, uh, shake their head about is, do I need another full round of investments in cybersecurity platforms to combat these threats? Or will the ones that I have kind of evolved to combat them? 'cause the former implies, uh, forklift upgrades of some type, and the latter sounds more like, uh, features are gonna be added over top, right.
And I think those things are all great down the road potentially, um, for users in organizations and, and people in those, you know, decision making spots right now. I would say that a lot of this just starts with having a culture of healthy skepticism at your organization, taking a second look at, uh, workflows and, and what's going on with them, and really ingraining that with users. And then to take it even a step further, which doesn't have to be something that, you know, you're investing a lot of money in, is just making simple checklists for critical tasks.
So if you have a critical task, you can do the things like create these checklists. It, it happens a lot in engineering. And then when something is outside of those checklists, you're able to have somebody, you know, raise that skepticism, raise their hand, and, and ask what's going on there.
And that can a lot of times detect a lot of these things that are going on in these organizations. And then also reach, reaching out to users and letting them know that, you know, if they're going to be doing things like surfing the internet or going to sites maybe that, you know, they should not be, and things like that, that just shouldn't be done at, they're on their corporate device. Mm.
As much fun as that is to enforce, are we getting better at collaborating with each other to combat these threats? I mean, back in the day when there were bandits in the desert, we had caravans, and the reason we had caravans was for mutual defense. So, um, does that same concepts there to apply here or people get it?
I certainly think we're getting better at it. It needs to be a continued effort though for sure. We're always trying to stay one step ahead, and that requires a lot of collaboration and forward thinking.
As a group, as an analyst, how much of this stuff is driven by, uh, cyber criminal syndicates that are just trying to steal money? And, and how much of it is driven by nation states that are maybe collaborating in some way with those syndicates? That's a good question, and I, I really wouldn't have a numbers answer for you, but I can definitely tell you that this is being utilized by both groups of those, of those.
So you have the small time who are just looking for a quick win, but you also do have those advanced persistent threats that are in nation states that are leveraging this for long-term objectives in inside companies and networks. So you've been doing this for a while. What's that one thing you see organizations doing that kind of still makes you shake your head and go, folks, we gotta be better than that.
I think if I had to pick one, I, I would just, in this environment, it's, it's about embracing change and, and really trying to be proactive in thinking, um, cybersecurity is not a reactive game, at least it shouldn't be. And, uh, that typically is one of the things that I'm driving home at, at my organization, is for us to be proactive and think outside the box about these solutions. And to that end, it seems like to me, the amount of time we have to discover and respond has been compressed greatly in the last year or so, maybe two.
Um, are people kinda aware that we're kind of fighting these games now in, uh, real time, essentially, versus almost seems like, you know, if I think back three or four years ago, it was a much more genteel sport? I, I definitely would agree. I think our timelines have accelerated, and I don't know how much the, you know, average user, I, I live and breathe this every day.
So for me, it's top of mind all the time. Um, I certainly hope people would understand that the internet is evolving quickly as it as it always has, but it, it is always a place to approach with skepticism and always a place to approach with just that, that extra sense of caution and having a good security mindset now, now more than ever. All right, folks.
You heard it here. Trust Noah. Hey Josh, thanks for being on the show.
Thank you very much, Mike. All right, and back to you guys in the studio. Hello and welcome to our digital CXO Leadership Insights series.
I'm Amanda Razani. I'm excited to have Jeremiah Woodford here today. He is the Chief Revenue Officer for verus, how are you doing today?
I'm doing well, how are you? Doing well, thank you for coming on the show. I have to be here.
So can you share a little bit about verus and what services do you provide? Yeah, so verisin, we are a, uh, an ai, uh, software company. We're, uh, we've been in business for about eight years now, operating and, and working mainly with Fortune 100, fortune 500 big industrial asset companies.
Um, all the way from food and beverage to pharma to oil and gas, to mining power generation utilities. Our software is, uh, plugs in, uh, to their ERP and EAM software, and it pulls out all their procurement, their master data catalogs, and ultimately what we're doing is, is optimizing maintenance, spare part, stocking strategies. Um, so big customer may have a mid max on a bearing in a warehouse of 10 and 11.
Our, uh, AI models will look at all the historical, uh, movements, determine how critical that spare part is, and then make a, ultimately make a stocking recommendation. Wonderful. Well, our topic for today, we're gonna be discussing a recent survey that y'all put out.
It's called the Future Strategies for MRO Optimization. Uh, so with that, first of all, can you share a little bit about who did you survey? What key things were you trying to find out from that survey and a little bit of just overall information about it?
Um, we put it out to a number of big industrial, um, um, target accounts and customers and, uh, from procurement to materials management to supply chain, um, analysts who maintenance and operations people, all the sphere of people that touch and buy and stock and use the, uh, MRO inventory. Great. And so what were some key stats that you can share with our audience today that really stood out to you?
Um, I think the biggest one was, I think 71% of the respondents felt that the, uh, MRO procurement operation should be treated as strategic initiatives versus, and, and continuous improvement versus potential innovation source as an innovation source versus, um, it's kind of an afterthought in a lot of, uh, industries that we go into and a lot of the accounts we go into. Um, you know, a lot of these organizations that we come in that, that haven't bought a system like ours, um, are treating this like any other inventory or service that they would go buy. And, uh, they'll, they'll arbitrarily stick, have a MinMax or they won't have a MinMax at all.
And, uh, and in the maintenance it's a very emotional, um, review, meaning that the only time they look at how much inventory they have or what their current min-max is, is when they stock out, uh, and they don't want that to happen again. And typically they just double the number without any type of scientific or mathematical approach to it. Yeah, absolutely.
That's definitely something they wanna avoid. So from your experience in, in working with these different, uh, business leaders in this industry, what advice do you have, um, to help them with making that more of a, uh, first thought instead of a afterthought? Well, I think for the longest time a lot of people looked at this problem as too complicated a problem, meaning that data sets were dispared master data catalogs, poor naming conventions.
So 90 probably 8% of people we demo our software to and meet with on the first case think, this is fantastic, it's really cool technology, but our data's not ready for something like this. And, uh, so our go to market is give us your data and we'll put it into the solution and we'll show you what we can do. Um, there has been a few cases that where, you know, their data is so bad, there's nothing we can do to it, but nine times outta 10, we do find that they actually do have, uh, we can make sense of their data.
Um, and that one of the neat things about the technology that we've built over the last eight years is the joint venture with, uh, Georgia Tech to build a large language model specifically around, um, maintenance spare parts. And what it does, that large language model is really, really good. And it's built on vector graph database at normalizing poor data sets.
So if you imagine you've got multiple plants, they're all buying the same thing, but you call it all something different. So a bearing, uh, at this one plant may be a different abbreviation for the size of that bearing and the tolerance of that bearing. Um, and it may be misspelled, our large language model is that has been trained on 40 million plus individual skews and actually been trained on all the abbreviations, the misspellings, the, you know, point point, uh, five is a half inch versus one dash two, uh, is a half inch.
It knows all those are the same thing. So it has a, a, a really cool ability to normalize those data sets. So we are really getting to a point now where these problems are no longer real problems.
How important do you think machine learning and AI is gonna be to the manufacturing industry? I mean, we're seeing it advance quite rapidly. I, I would say, yeah, I would say it's huge.
Um, it, you know, if we're going industries want to stay evolving, want to be, uh, profitable, um, a lot of the ways that we've been doing things for the last 20, 30 years using legacy systems, most of your ERP and EA provider, uh, providers and software, uh, companies out there, what I would say are legacy software providers. And what I mean by that is, is that when they look at a problem, they're still looking at it from a legacy lens and how they can build software to collect the data to, into a relationship database and then report that out. And that's why that's one of the biggest problems we're solving for most people hate those software systems hate using those software systems 'cause they're clunky and old, not user friendly.
And, uh, what large language models are and AI is bringing to the table is the ability to normalize that data and then automate. So anytime we look at, uh, an initiative or a problem a client comes to us with, we're looking at, we wanna look at it as an interaction with an AI agent that automates the process versus collecting more data so you can report on it. And then another thing you said earlier, you said it's, it's rare, but every once in a while there's a company whose data is just so boggled that you, you can't help them.
Uh, for those companies, what advice do you have for them as far as what to do to get, to get in front of this data problem that they're struggling with? Yeah, so in that, in those examples, it is implementing better processes. So just, you know, we do run into some companies that say that they, they may not have a, a master data catalog, they're just free text purchase orders or they're buying their materials off of pcards.
And, uh, and the, and the recommendation, you know, we have partners, we're partners with most of the big sis from Accenture to PWCs of the world. And, uh, and then let them come in and implement a master data catalog so they can start locking down how their procurement and not have rogue buying. Uh, and then that, and then we can help them.
So one of the things we do with our partners is they can use our large language model to ingest all those free text purchase orders to tell the customer what are the, the common parts that should be cataloged and stored in a warehouse. So we still do add value, it's just, you know, you don't need to buy our software for a multiple year subscription until you get that catalog created. Yeah, absolutely.
Well, if there was one key takeaway you could leave our audience with today, what would that be? Um, well there's a number of key takeaways that came out of it, but I would think that the biggest is that getting your organization aligned. One of the problems that we solve for, and that we see time and time again is procurement knows that they probably are overbuying some of this inventory and, uh, supply chain is just serving the maintenance operations teams to make sure they have what they need when they need it.
Uh, maintenance operations, their job is out turning wrenches and keeping the assets up and running. They don't have the time to go do some complicated math to figure out what they should be stocking and how often it should be bought. So it getting those three groups to align and agree, that's what we do.
So we, we ultimately, it's not a black box. Our system is, is very straightforward, but ultimately helps you determine that you have the right amount. So we reduce surplus, but we also help identify the critical spare parts so you don't have enough of, so for better planning and execution for your maintenance organization.
So getting them all trusted and bought into the system is, is is the crucial takeaway and getting them aligned. And then is this survey available to the general audience if somebody wanted to go and look at the full survey results? It is, yes.
Where could they find it? On, on our website. Okay, great.
Thank you so much for coming on the show, on sharing your insights. Happy to be here. All right.
And thanks to our audience, stay tuned. There's more. Welcome back to Textron Unplugged.
My name is Cassandra Chin, and today we have Roos Do. Thank you. Can you introduce yourself?
Yes. Uh, I, my name is, I am, uh, living and working in Norway, in Oslo. I speak quite often at the conferences.
I am a Java champion, I'm a Google developer expert for cloud technologies. And, um, well, like, that's what I usually talk about at conferences nowadays. So how did you get into technology?
Oh, that, that's a fun question. So it all started when I was a kid. So I was, I was a teenager in my like early teens.
And then we would, uh, we, we we, we found that magic room called the computer science room with all the computers and stuff. And then we would just go there as, as often as we could and just do some coding and everything. And back then it was, uh, it was quite old machines we had for a very short time in the beginning, but they were quite old and they were, you could only think you could do on those was basic, basic programming language.
And that was, that was very fun. But yeah, so that's how it all started, but it very quickly switched to much more modern and cool machines and everything. But we kept on doing that so that Computer can only do basic programming.
Yeah. But there was a language called basic, so whatever, like later, there was a versions of that that was called Visual Basic and you know, all this kind of stuff. But this was actually basic, if I remember that correctly, that was either fully or somehow supported by Microsoft.
So it was like kind of the, one of the first languages that I was, well, it was the first language that I was exposed to basically. Uh, how did you learn the language? Like, did someone have to teach you?
No, I, no, no, that didn't work like this. It worked. That was fun.
So we would, um, our teacher teachers there were like several, but they were smart people, so they would just give us a, a book or a something with different pieces of code. Sometimes it would be even like a printed thing or even handwritten thing or something like that. It was like different versions of it.
But they would give you a piece of code and say, look, try this. And then you would try, and then you would be like, huh, that works. Okay, what if I change something and then if I change something else?
And then you kind of started doing that, and then after a while you got your own ideas. So then we would create even gly graphic games and stuff with that thing. And that was, that was pain.
That's not today's programming doing graphic things. Like now it's, you have processing, you have things like, kind of like this, that's much easier to do that. Right.
Back then it was crazy too. You had, imagine you had a screen and on those machines there were like seven of layers of a screen and if you wanted to move to two things towards each other, they cannot be on the same screen because the whole screen was moving. So you put one thing on screen, one the other thing on screen two, and then they could just move towards each other, for example.
That's like some illusion effect. Yeah, basically there was a lot of like pixel moving and stuff like that. But that was, that was fun.
That's how I learned stuff. That's really cool. Uh, you say you're involved in teaching kids today?
Uh, kind of, so I mean, I've been doing it quite a bit. I've been doing it at work. Uh, so every Christmas we do this, uh, session for, uh, kids, for employees, kids.
So they bring their, uh, like my colleagues bring their kids and then we teach them. So what I usually do is, uh, it, it, it can be several things, but very often it ends up being, uh, processing that I mentioned already because it works very well for kids. It's a, it's a kind of two, two-sided thing, right?
So one is, it's technically it's a subset of Java, so technically you are teaching kids Java and the other thing, it is also very visual. So it's, uh, it's actually you can, you know, draw circles, draw squares, make things move, make colors, and you know, it's, it's very easy for kids to see very, uh, quick response or results of what they're doing. Are you teaching them like, on the computer?
Yeah, So what we do is basically we have a room, we borrow bunch of computers, uh, give it to them and then just tell them, explain very, very basics of like, well, this is a variable, this is thing and this is a loop and this is that. And now you're on your own. Try to draw a face and a screen, try to do this and well, basic faces, right?
So two circles, something for a nose, something for the mouse, and then you have a face, like Do you have them do this in an IDE? Yeah, so processing comes with its own id. If you've done any Android programming, it's very similar.
It's basically the same id but with a different engine in the background. So, no, sorry, not Android, uh, Arduino, my bad. So it's this little simple bluish idy kind of thing, but you can also do it on, on the web.
So you can also do it in different ways, but it's still, it's not like scratch or anything. So it's not graphical programming in a sense. So it needs a little bit of understanding.
So you need, the kids must be a little bit older. So that's, that's the thing. And I've been doing also the same things for, uh, different events at different conferences and things like that.
Also for the participants and things. And that, that was really fun. It's really, really fun.
Uh, what events have you taught this at? Oh, uh, it's quite a, so, okay, lemme think. So I've done it, uh, I think quite a few years ago.
I've done it at NDC, uh, I've done it at j on quite a few times. I've done it at our internal stuff quite a few times I've done it. Uh, where was that?
Uh, I've done some other places. I was also supposed to do it at the first edition of a KOTs conference in us. Uh, but that got canceled during to Covid, so we didn't get to do that.
But we had like really fun set up there, ready and everything. Uh, what else? There were, there were a few places as well that I can't really remember right now, but yeah, it, it's been, it's, I've been doing it over quite some time, so it's kind of hard to remember all it place.
Is This like a kids' workshop format? Do you do this for a few hours? Yes.
So it's a kids' workshop format. You do it for a few hours, but I've done it for kids in different ages. Oh yeah.
By the way, we also did it at, uh, uh, me and a colleague of mine, we did it for, uh, uh, a library, like local library or main library in Oslo. So the kids would come and we'll do that thing as well. But what we did was, uh, I've also done it for a bit older kids, so more, uh, like, uh, well late teens, right?
So, but then it was a different thing. So then I would teach them, uh, command line tricks. So just give them a Linux or a virtual box or whatever that has a line interface, and then I'll teach them what they could do.
And a lot of them back then were, would have some experience because they would be like, oh, I'm running my own, uh, server for some kind of game, or I'm running something, I'm doing this, uh, for, uh, you know, for different things. But they kind of didn't know what they were doing. They were just copy pasting things.
But when I was explaining and explaining how things work in a combined line and all that, they would be, oh yeah, this is really cool. This, you can do this and you can do that. So I did the, I did pretty much all ages from like six, seven to, yeah, 18, like 17, 18 or something like that.
Surprised you can get like six to seven year olds typing codes. It's, it's, it's fantastic. It's, it's amazing how much stuff they catch up.
So as long as they can read and write, you can do that. It's fantastic. You just tell them.
So what I usually do is like, I show them a cup and I say, well, think of it as a variable. You can put stuff into it. You can take stuff out of it.
It might be empty, empty, it might be fall. And you know, it can contain different things. And then I tell them like simple things like, oh, this is a loop to repeat things, or this is something to like, to check if else or something.
And after that you, maybe you give them a little piece of code that they can copy, maybe that you don't even really need to do that. And after that they'll just go crazy. They will have so much fun.
And, uh, yeah. And the, the, the most important task usually is to keep the parents a little bit on a distance. 'cause they get excited and they wanna code.
So then you're like, no, no, no, don't touch the keyboard. Let the kid do the work. You know?
And that's, that's always fun to, I mean, people, people and kids react differently. So some needs one kind of encouragement, some other needs, different stuff, but it's, it's really fun. Yeah, I think that's all really cool.
And I can see how like the parents could be, uh, a little too hands-on. Yes. I mean, I totally understand them.
They get excited, they really mean well, but, but then you're like, no, don't touch the keyboard. Let let your kid do the work, you know? And I like the Cup analogy.
I never thought of like having a variable where you just like fill the Cup. That's, uh, that's very easy be. I, I, I also came up with that, that's some time ago, long, long time ago.
And I keep on reusing it because usually those cups are made of some kind of glass or, or like, you know, anything that you can basically write and arrays with, uh, whiteboard marker. Yeah. So that's also how I explain the names for the, for the variables.
So it's like, you know, this is a cup, I'll call it, um, an A or a, uh, you know, or a cat or a dog or whatever, and I can put whatever inside. So you can also have the variable contents and you also have variable names. That's really cool.
So that's, uh, yeah, that's, that's really, I, I enjoy doing it, but it's also very different because I speak a lot at a conferences. I do a lot of workshops and, and all this kind of stuff. But it seems very different from, from the way you teach grownups to the way you teach kids.
It's What are some of the differences there? Uh, sometimes you take a lot of things for granted with a grownup. I mean, if I come to, to you and start talking about like, objects and variables and loops and stuff, I, I kind of, well, I mean, I will do a bit of, uh, like I will probably rephrase if I see that person does not understand me, but there's a lot of things you take for granted, uh, because you're like, oh, well, you probably have done some programming.
I probably have done some programming. We kind of have some common language to speak, uh, with the kids, you really need to explain things that you yourself take for granted than you never thought of. And then sometimes you see funny things that are kind of generational thing, because most of the kids nowadays are used to writing, typing, and playing on iPads.
So when I gave them a laptop, they, it took me a while to understand why they were doing that, but they would do like, and I was like, yeah, type your, let's say your name with the capital letters. They would hit shift once and start typing. And they were like, it doesn't capitalize.
And then they would do the same thing, hit shift and start typing. And they were like, no, no, no, you have to hold that and type. And they will be like, what?
Because, you know, iPads, you just turn on the shift thing and then you can type, right? So there is a lot of things that you, like for me, I never even thought was a thing, right? And then you end up like, oh, right, yeah, okay.
I did not learn how to type on an iPad. You did cool. Uh, but yeah, I mean, there is also other, other things, but this is the kind of the most basic and all the thing Yeah, the good activism.
Yeah. Yeah. It was, it was fun.
I laughed quite, I had a good laugh after I realized what was actually going on. But yeah, it's, it's cool. I mean, I, I really enjoy it because it's very, um, it gives me a lot of energy as well, because when I see them being excited about things, when I see them being happy about things and how much and fast they learn is just amazing.
It is just you, you, you, you're getting very happy. I also teach a lot of kids workshops and I get that form same sort of energy and feeling. It's, it's, it's, you give some energy and you get some energy, right?
Yeah. Yeah. I think we've had a really good chat today, so thank you Yusa.
Thank you so much. Thank you. Hey everybody, thanks for joining us for another episode of Techstrong Women, where we feature amazing women doing amazing things in tech.
I'm Jodi Ashley, executive producer here at Techstrong, and I'm here with my co-host, Tracy Ragan, creator, and CEO of Deploy hub and busy, busy lady working with the Linux Foundation. Before I introduce today's guest, I just wanna give you a quick update about what's going on on Techstrong. com, so be sure to go check that out.
We have some virtual events coming up. We're gonna be at RSA, we're gonna be at CubeCon in London, so we got a busy start to the year. So please be sure and check us out there, stop by and say hello, or reach out to our team and maybe we can do an interview with you.
com, and be sure to tune into Techstrong TV every day for great shows and interviews. All right, Tracy, what's on your mind today? Well, first of all, I think the platform engineering is gonna be a very interesting topic.
So, uh, I think I'll be watching that, um, for a while. Now, this, you know, we get new topics all the time, but I think the platform engineering one's an interesting one, but that's not what's on my mind. Um, I, this is from an article that was on DevOps, um, I think Mike Vizard may have written it, and it's about fake stars on GitHub.
So I can't tell you from being a, being a, an open source, uh, contributor and a community organizer around TIUs, we worked really hard for the, you know, just shy of 400 stars that we have really hard, every single one of them we worked for. So it's really irritating to think that somebody would just buy stars and that there's ways to buy stars. So what I wanna say about that is sometimes if you look at something and it's too good to be true, it probably isn't true.
So if there's a, if there's a open source project out there that you're thinking, well, this would be really cool to use or download and use this package in my code, and it's got thousands of stars on it, and one or two, uh, contributors, it's probably not real Buyer beware. So we have fake news now, we have fake stars. And it really makes me sad that this, this culture that we find ourselves in has infiltrated into the open source world because the open source world is, in the past, has been a place where people are sincerely writing code that they want to share, and the stars are like likes.
And it gives us an idea of if maybe we should or shouldn't use that code. So buyer beware, download or beware, fake stars exist. Oh wow.
That's crazy. It's like people buying views on YouTube and all that kind of stuff and Exactly. And you jump on something 'cause you think everybody else liked it, and then you get in there and you're like, meh.
Yeah. And in the case of open source, you download it and all, there's a bunch of nefarious code in it. Well, Yeah, that's the thing.
Nefarious code. Yeah. Yeah.
Alright, well we got that in for today. I agree. That's, that's sucks.
It sucks To whoever's doing it. If you have, if you're doing fake stars, you suck. You suck.
Alright. Uh, I'm ready to introduce our guest to all of you today. We're really excited to have Caroline back.
She's been with us before, but we're gonna have a great, uh, kind of start of the year conversation that I think is really important for us to have. And, um, I'm looking forward to it. Caroline Wong, why don't you go ahead and introduce yourself to us and, and we'll get started.
I'm Caroline, I'm a cybersecurity person. I've been on in-house security teams, vendor security teams, startup consulting product. Um, and that's given me a really sort of well-rounded view on cybersecurity and the problems that we face.
I think the most important and most interesting part about cybersecurity is the people. Um, I have hosted a, a podcast called Humans of InfoSec. Um, and yeah, I'm also a writer.
I wrote a book called Security Metrics, A Beginner's Guide. That book was inducted into the cybersecurity Canon Hall of Fame in 2022. And I'm currently offering a new book with Wiley about AI and cybersecurity resilience.
Ooh, that sounds Awesome. Tracy, you gonna be putting that on her to read the her share? So When, when are you gonna get that finished?
So tentatively scheduled for publishing in the spring of 2026. So beautiful. Just A few short months away.
And by the way, Textron is picking up Caroline's podcast. I'm gonna be producing that for her shortly. We're in the process of getting that rolling, so I'm pretty excited about that.
We're all pretty excited about that here, so, yay. More fun stuff coming. All right, ladies, let's dive in.
Caroline's had a fun end of year, start of year. You wanna tell us a little bit about what happened? Sure.
I have been job searching. I have spent about three months or so at the end of 2024, job searching. And you know, Jody and I were talking the other day and I was saying I am the primary breadwinner in my family.
Um, I've got kiddos, uh, the way that our household constellation works. I've got in-laws, um, and we've got dogs and cats and chickens, and there's a lot of literal mouths to feed. Um, and I take my role in our family as a provider very, very seriously.
Um, and so naturally job searching, there's a lot of anxiety, there's a lot of stress, there's a lot of pressure. Um, and for folks who work in cybersecurity, for folks who work in tech, the experience is you see a job posting and within 24 hours there's 500 applicants. Within three days there's 1500 applicants, and they've shut down the job posting because it's just full recruiters literally cannot go through that many resumes.
Um, and it's tough, you know? Um, and I think that for me, going through an experience like that, it taught me so much about myself. It gave me some really important time to reflect and think about what's truly important to me.
Um, getting a break is also a gift. Um, and yeah, so I'm, I'm thrilled to be here sharing my story. Um, I think that fortunately and unfortunately, jump searching is something that many of us, uh, can relate to.
Um, and so I'd also really like to share some different practices that I used during my job search to try and take care of myself. You know, this is an interesting time for this topic. Um, just at the end of the year, last year at our last, uh, ORUS outreach, um, meeting, we talked about what we might wanna do in 2025.
And the number one thing that came up was a job seekers webinar series that goes what it's like to be a job seeker in this climate that you just described. The tooling, how to use keywords, how to try to basically beat the system. And I feel like as you described, there are so many people applying for these jobs that they use AI to filter it out.
And basically they're just doing, you know, matching on keywords. So people are having to add keywords to try to make it work when they shouldn't be. There's gotta be a better way to do this.
We heard a little bit about this when we had the woman from manpower on, um, we chatted in a little bit, and that was early last year. But I think over the course of this la this, this year, more people have complained or more people have struggled with that. Can, can you tell us a little bit about when you first started, uh, noticing this trend and you were sending out resumes, what were the kinds of jobs that you were sending resumes to, you know, at what level you know of, and do you think that you, that you maybe targeted jobs that were under what you were able to do and you were overqualified, did that come into the play?
Because certainly a person with your skills, I would've thought would've been picked up almost immediately. Thank you so much, Tracy. You know, I, I am so fortunate to have had such an incredibly rich career.
And my most recent role prior to the new job that I just started, I was a C-level executive with 20 years of cybersecurity experience. And even so, it's tough, you know, and I felt so fortunate. I was able to engage in a lot of different interviews.
Um, at least five of the interview processes that I engaged in, several of which I made to the last round. A recruiter or a panelist or a hiring manager would just look at me and say, Caroline, let's just address the elephant in the room. Why are you applying to this job?
You are overqualified. And the actual reality is my first responsibility as to my family. And I also, I don't have a ton of ego about the work that I do.
One of the things that I admire in people that I've worked with, that I really respect is that when stuff's gotta get done, stuff's gotta get done. And who cares? Who's got what sorts of title.
You know, as long as you're delighting customers, creating value, making a positive impact, whatever needs to get done, I'm happy to do. The, the way that I phrased it in a lot of these conversations though, was I said, and this is true as well, I said, you know, it's been a little while since I've been and on keyboard and really close to solving the problem. Um, and I really got into a mindset where I thought I could do this.
You know? Um, and sometimes I'd go through an entire, uh, series of interviews and make it to the end, and then you kind of wait, you know, to get a callback from a recruiter. And if it doesn't happen sort of right away, then you wait another day.
You wait another day, you know? And, and it's just tough. You know, at the end of the day, there are thousands of people, many of whom are extremely qualified.
I can't tell you about the number of friends and colleagues and people that I've met who are extremely qualified and on the market right now. It is a simple, the supply and demand situation. There just are less jobs on the market at this moment.
I spoke with the recruiter in Q2, Q4 of 2024, a Csar recruiter. Um, something that happened to work really well for me, which I know is hard for others, is that I never wanna be a ciso. That's a job.
That's a job that I'm simply not interested in. Um, I'm very interested in all sorts of adjacent jobs to the ciso, but CISO's not the job for me. I spoke with a recruiter and this person said, Caroline, typically in Q4, you'll see 20 to 25 big CISO jobs on the market.
And this person said to me, and this was for Q4 2024, right now there's 10 to 15, significantly less than usual. And I had been in my previous role for eight years, which in tech is like multiple lifetimes. I mean, we're talking like Mesozoic era, time of being at the same company.
Um, and it was actually so much fun because one of the things that I love to do is I love to learn. And so for each and every single company that I was interested in, I did so much research and I watched so many videos and I learned so much about what these organizations are doing. Um, in some cases, you know, a lot of my search was gonna be in cybersecurity, was gonna be in tech, but I also branched out to pharmaceutical and healthcare and, um, energy, uh, renewable energy.
Um, and there was just so much to learn. And that was really fun. And I actually really did enjoy the exercise of imagining what my next career chapter could be.
That was really, really fun. And did you, when, when you were going through that imagining, um, did you work with a, a recruiter that helped you imagine that? Sometimes it's hard to see ourselves.
It is so hard to see ourselves, and I just celebrated my 10th wedding anniversary, and I remember when I was dating on the AppSec, and I think it's really hard to write a profile for oneself on a dating app. Similarly, I actually think it's kind of hard to write a resume. I think it's kind of hard to write one's LinkedIn, uh, page.
Um, and as far as these things go, I have throughout my career in been intentional about my brand and about my sort of external presence. And even so, I knew that I wasn't quite hitting the mark. Um, and I spoke with many different recruiters, um, and I happened to come across one extraordinary recruiter.
His name's Darren. And if anyone's interested in being contacted with Darren, uh, just shoot me a note on LinkedIn and I'll connect you. He helped me to really refresh my LinkedIn page in a way that I felt was very meaningful.
He also helped me write my resume. Writing a resume can be, there can be these emotional and these, um, mental blocks to doing that type of an activity. It's a hard thing to do.
Um, and I really found, and I'm the type of person whom I just love coaches. I've worked with personal trainers, I've worked with nutrition coaches, I've worked with finance coaches. You know, why not work with a resume coach, a LinkedIn coach?
Um, I've been in therapy for more than 10 years, you know, so I'm all about the coaching. Um, and for me that helped enormously because I was in a position where I could tell my story to this person that I trust, and they could help me tell my story to others. Well, and we don't, we don't, as women, you know, lift our own self up when we write resumes and, you know, talk ourselves up necessarily like we see our counterparts in the world do.
And I also think it's, it's really tough to to be you don't, like, I, when I kind of looked at mine last year and I was like, wait, there's this, I talked with, with someone that I knew, and it was like, well, you could be doing this and this and this. And they were things I never even thought about. I'm like, wait, I guess I'd, oh, wow, I could do that.
I do have qualifications for that. And it, it was super duper eye-opening and as, as part of just kind of evaluating what that would look like. So I think we also, it's always good to get someone else with a clear picture of us into the conversation, to, to give us, you know, a very objective look at things, both positive and negative.
And I would imagine after nine years, I mean, resume writing is totally different. It's different. It's totally different.
It's just different what You know. So to put the right words in and not too much, you know, the right, it's just totally different. And what The things, right.
Do you, do you write it in first person? Do you write it in third person? What 10 do you use?
You know, these are all things that yeah, we spend relatively little time in our careers doing these activities, right? And we don't often have time to, at applying for jobs. It's a different thing.
And I, and I, you know, something's occurring to me that's really important to share, which is that there were people in my network who were so kind and so generous with their time, with their, um, generosity in terms of, sure, I'd be happy to introduce you to this person. I'd be happy to provide a reference for you. Um, and just for me, going through some of those mental and emotional challenges that are natural in a process like this, I will never forget each and every single person who reached out to me and said, Hey, if you wanna talk, I'm here to listen.
That's awesome. That was really meaningful to me. Tracy, what were you gonna say?
So, resumes traditionally have been written to say what we have done in the past. Yeah. It, And it doesn't tell us, a resume doesn't tell us what the person can do, right?
Mm-hmm. It doesn't give a good insight on what they can do. Now, in reviewing resumes, I can say that guys are much more willing to cater a resume to what they can do, where women want to outline what they have done.
Interesting. So for example, first, so for example, let's say that you, um, you were a, you know, you've been outta the market, or you hadn't looked at putting a resume together for eight years. Uh, you've been a, you know, a cc plus plus programmer and you know, you know how to write Java, but none of your jobs ever required it.
'cause you, they had you doing c and c plus plus. Well, you're gonna able, you, you're not gonna get an a job because JavaScript is what everybody's using, or Python. But I can promise you if you have written code in C or c plus plus, Python will be a breeze, right?
So resumes have to be able to reflect what our abilities are, and they don't. And this is the, this is the struggle that so many people are having. So you begin seeing resumes with a lot of bullet points, a lot of keywords, because these new ways of finding, um, you know, going through a job board, which most of us would have to do, they're gonna look for specific keywords, and they wanna get like an 80 to 90% match on the keywords they have in their job description to what you have in your resume.
Yeah. They're using an AI tool. They don't even look at it themselves.
It doesn't even get a human viewing it. They use the ai and then if it's not at like 80%, then poof, it's gone. So, for example, you know, building AI code, right?
How many of us really have out, out there working on LLMs? Not that many people, but how many developers and people who are technical could achieve it if they have the opportunity to work on it most, right? But they, so somehow you have to get this kind of experience on your resume, and you don't have it in a job description.
So how do you go about doing that without embellishing on your resume? This is the problem with the tools. It's not what we have done, it's what we can do.
So bullet pointing and being involved in, um, open source communities, um, putting together, let's say you, you start working on an open source community and you say, I wanna focus on seeing how an LLM will work with orus, for example. Then you can add that to your resume because it's what you are looking at doing, and you're contributing to the community at large. So we have to get a lot smarter about how to present ourselves in resumes.
And it's all about the future, not the past. And resumes reflect only on the past. This is a hard thing for women to get over, is how do you embellish, how do you work on that?
How do you build that, that, uh, that profile and that brand without having to had a wor a job that had you do it? Which is sort of ridiculous to be quite honest, Right? And there's a lot of great people out there you can hire to help you, but not everybody has those resources.
So a lot of people jump in and AI their resume, and you can just tell when you read someone's resume that they threw it into AI and let AI do all the work. So that's not helpful. It's not A Good idea's.
It's gotta be hard. And I think, you know, you can't, can't forget how important networking is. And obviously Caroline spoke to that.
Knowing people is so important, right? Being connected with people and, and, and being willing to, like, I know you Caroline pretty well. I know your story.
I know I know a lot about you and, and you're, you gotta be open to not be like, I don't have a job. You gotta be like, Hey, I'm looking for a job. Because you, and, and that's hard to do when you leave that place.
I've been in that place a couple times, and you just kind of wanna be like, Ugh, I don't wanna tell anybody but you, but you, you gotta, because that's what's gonna get you to the next job. People can only help you if they know that you need help. Absolutely.
And we live in this super weird culture where so much of our identities are tied up in having our jobs. And so if there's a moment where we don't have a job, it's jarring. You know?
And that is not because of any of us as individuals. That is because of the culture that we live in. That is because of the society and what society has deemed to be valuable.
And so this is something that's really, I think, important for any of us to consider. Whether we're job searching, whether we're happily in a role. There's, there's a book that I really like that I listen to quite a lot during this search.
And it's called Strength to Strength. And it talks about, uh, for folks who at one point in their careers have been extremely successful professionally, and then what happens next? And it kind of gives these ideas for other parts of one's life to invest in.
Things like family, extended, family, friends, spirituality of that's your kind of thing. You know, different exercise and nutrition and just all these different parts of our world that are our real lives that exist in addition to work. Yes.
And we know, again, if I go back to the resume, we used to look at some of that, you know, I used to always make sure, um, and I still do, for the most part, that any profile I have, I point out that I have a black belt. Why? Because it makes you a more interesting person, right?
How did I miss that? I'm gonna be nicer to you when I'm in person, You know? Or that I like to ride big horses.
You know, just what is it that makes this person interesting? And you know what? Our resume systems now, they don't even care if you're an interesting person or not, which is horrible.
It's, you know, because it takes the human out of the equation. We have taken the human factor out of the, the, the job, the, um, the headhunter's job. And all we're doing is looking to match keywords.
So Carolyn, did you use any kind of tool to Uh, absolutely. And I have, here's, here's one thing that I recommend for every job that I applied to, I would take my resume and I would take the job description and I would say, chat, GPT write me a draft cover letter. And I would use that as a starting point.
And I would look at it and I would take the bits that I liked and I would change the bits. Um, but I would use it as a starting point. I know that for me, sometimes it's awfully intimidating.
I'm facing this a lot lately, lately. 'cause I'm writing a book about cyber security and ai, but there could be something so intimidating about like a blank word document. Um, but a draft, I can do something with a draft.
I can, you know, get my eyeballs on a draft and immediately iterate. Um, and that's, that was something that I found to be really helpful. I'm the same way.
The blank paper just terrifies me. I have something to, but I could have something to start from. It makes such a huge difference.
Yeah. Yeah. There was a tool that my niece was using and I was watching her use, I didn't, I don't remember the name of it, but you could put in a job description and it would look at your existing resume and enhance it to match the job description.
Now, is everything accurate in what you did in the past? Maybe, or maybe not. But the problem, the point is, everybody's doing this now, right?
Right. So we don't, we, we have to get past what we used to think of as embellishing on a resume. And I'm not telling people to lie, but you've, you have to be able to pivot yourself.
When I first started, you know, when I, I was a California girl and I graduated from college, and five years later I decided I didn't wanna be in California anymore. And I moved to New York and decided to become a Wall Street consultant. I had never, ever, ever worked on OS two before, but everybody needed OS two consultants.
So I sit down and I read the big IBM Red book on OS two, and I put it all over my resume, and I got a job almost instantly. I became one of the IBM's primary OS two consultants as a result. But again, it was what I could do.
And I was marketing myself. And marketing is never completely honest. And I just wanna tell women out there that you, I don't wanna take, I don't wanna say just lie and create up jobs, but you have to be able to express what your abilities are.
And you go ahead and start using those bullet points to say, here are some of the tools that I know I can use. Here are the skills that I have. So that you start matching on those, uh, those jobs.
It is, it is, it's unfortunate that we've gotten to this point, but this is where we are. This is, this is where we are in this world of AI matching, you know, humans to jobs and taking out the human factor. So it's okay to say what you can do, not just what you did, And ask people for references and recommendations.
Um, this time around, I was not shy about reaching out to folks that I'd worked with before and saying, Hey, would you consider taking a few minutes to write me a recommendation? And I would read through them myself when I was having a tough moment or a tough day. Nice.
Um, and it was actually just a beautiful gift to be able to be myself through the eyes of somebody that I know, or somebody that I've worked with. Um, and that was really helpful for me. Um, and I encourage folks to do that, you know, and I think that it doesn't matter how much time has gone by, you know, if you worked with someone 10 years ago and, and the two of you did really great work together, reach out and ask, you know, the worst they can do is say no or ignore you.
There's, there's really no downside. So this is so such an important conversation because, um, when we spoke with the woman from Manpower, she talked about how women really lost a substantial amount of traction in the tech industry during Covid. Yeah.
Because they were the ones who had to leave their jobs because the kids were at home and they had to do homeschooling, or at least babysit them as they sat in front of a, in a Zoom session for school. And they could not do both. They couldn't do a eight hour job and take care of their kids as well.
And what happened was that those, you know, in four years time, or two years time, or even a year's time, our industry changes so quickly that if you're out of work for that period of time, you probably would look at yourself and say, I'm no longer qualified for these jobs. I don't know Python. Right?
I've not had an opportunity to code in Python, so I can't talk about saying that. I do know Python. And that keeps women from going back into the, in even not just a three month break as you had, uh, Caroline, but an eight month break, you know, after having a baby.
How do you get back into work after time off like that? And how do you start pivoting yourself and rebranding yourself as a person who is relevant for today's market? Not the market that you left eight months ago, or even three months ago.
We had another person who, um, Jodi and I loved very much. Um, she was in the dev rail space and lost her job. And I don't think she found another job for Al I think it was close to six or seven months.
You know, we were all just sweating it out for her. 'cause she's also the primary breadwinner in her family. And it was shocking to me that this, you know, that this was happening.
And when I started looking into, you know, watching a a, a college graduate go through the process and how the tools now are matching people to jobs. It is not a, a it is not good. It does not find the best, uh, most qualified person.
It only finds the best match of words. And how is that helpful for anybody? How do you know that person's gonna be decent?
How do you know anything about that person? If you really want to interview them, you don't. So it's, I get, I, it, it's sad to me, it really is that we can't find a better way to do it.
If AI is supposed to be so great, how come in this specific particular area, it's making our lives harder, not easier. There were a few, um, interview processes that I engaged in that I thought the company did a really cool thing. The company said, we're doing a case study.
Caroline hears basically an assignment for you. Um, we expect you to put together, you know, X number of slides, you know, to write, you know, y number of words and to present it. Um, and I thought that was really cool, you know, because in the job interview process, um, in those cases, I, and any of the other candidates would've really been given an opportunity to kinda show our stuff.
Um, so I thought that was pretty cool. And I also wanna say, you know, when you're job searching, of course you want a job, but it's also extremely important to pay attention to what it feels like when you're talking to these people. 'cause say you get the job, then you're stuck working with them, and hopefully you like them and hopefully you respect them and hopefully you can learn from them.
Um, so make sure that you are evaluating the company as much as they are evaluating you, and don't hesitate to ask any questions that you have, Which is so much harder to do remotely. Right? You get pulled into an office, you maybe sit around a table with people.
You, you know, that physical in Personness is very different in an interview situation. You know, It's, I'm curious, Caroline, how many of your interviews were in person? Zero.
Yeah. Zero interviews, you know, and it's really funny because some of the companies, their HR interview processes, they're virtual, but they've got these like, uh, names that were clearly from a couple of years ago. So, you know, such and such organization would say, and for the next stage, you're gonna do a virtual onsite or for the next stage, you're gonna do an onsite.
And I was like, okay, well, you know, do you need me to fly somewhere? Are we gonna do 'em all in one day? And they said, no, you know, it's, it's virtual and we can just space 'em out, you know, depending on people's availability.
And it was just, it was just a fascinating thing, you know? Um, but, you know, one of the things that I think has become very important, uh, is being able to effectively communicate like this, you know, to really be able to, uh, demonstrate, uh, one skill via a Zoom video. Um, and that's not easy for everyone.
That's not natural for everyone, you know? But if, if any of us, um, have any troubles with it, you know, it's, it's worth practicing. It's worth asking for advice.
It's worth, you know, getting a little bit of support, uh, 'cause that that is a really big part of it. Yeah. You don't think about that.
Like the three of us, we do this all the time, so it, it's not a big deal to jump in. But people who are coding all day and, you know, they're doing their thing and their head's down, and they're not interacting on Zoom calls unless it's like a company meeting, having an interview situation would be very different. Absolutely.
I About that. I was gonna say that, Jody, not everybody's on, you know, a text on gang or doing presentations like Caroline and yourself were doing. Right.
Um, it's a, it's a different world, the zoom world, and to be able to come across and be comfortable and be yourself is really, really challenging for some people. Again, the human factors being taken out. I'm surprised you didn't get EE even after your offer.
They didn't have you come in and meet you in person. That's amazing to me. It's wild.
I, I literally thought, you know, I kind of assumed, um, like, okay, like, we're gonna do this. Like, naturally I'll, I'll fly to you or you're gonna fly to me, or we're gonna meet up and we're gonna hang out for a week and we're gonna, and it just wasn't like that, you know? And part of it is travel on expense budgets.
Um, and part of it is, you know, one of the things that I love about my new job is everyone is so remote competent. It is amazing how remote competent these people are. Um, it just, you know, everyone just gets it, it all just makes sense.
Um, and that is, that's really, really nice. And after we've developed all these remote competent skills, you know, we have a potentially a new administration coming in saying, everybody needs to go back to the office. And, you know, I heard, I heard that Amazon was having folks come into the office.
Mm-hmm. And, uh, and then I read a newspaper, um, article that said that the offices weren't ready to accommodate everyone. So I think they had to, I think they had to delay it.
So that's also been a really interesting thing, you know, and I think that for any job seeker, you know, there are ways in which you can broaden your search and you can design, you know, uh, for folks who are really intent on a cso CSO job, you know, maybe consider a job where you are reporting to a CISO or adjacent to a ciso. You know, for folks who are okay with going into the office, you know, if you happen to live near an office and they want folks in the office that will, um, expand, uh, your possibilities. So it, it's really so much about whatever people are looking for in the moment.
And I do think that right now, one of the things that I noticed is they are looking for deep expertise in a particular area. It was, it was interesting for me 'cause I'm a little bit of a generalist. Um, some of my superpowers are not straight engineering, they're not straight sales, they're not 20 years of product management.
Um, but, you know, I just want folks to know, just like, keep on going, keep your head up, keep on going, and, you know, just keep going because, uh, you know, it's, it's worth trying. Um, and just learning along the way. I can't discount though how important your LinkedIn profile is, though.
It's a big one. People, people do look at it. People look at it, that's The first thing they go to.
Mm-hmm. They see your resume and they go right out to LinkedIn and then they Google you. And see, that's why we have to teach our younger generation about what they put on the internet, because employers aren't gonna find it people, and it may not do you any service for them to see it.
So, yeah, I mean, it's, it's super important. I think LinkedIn is, LinkedIn Has become the online resume for so many people. Absolutely.
And the problem because is as you're trying to apply for these different jobs, you're gonna tweak your resume for each of those jobs. So how do you have a LinkedIn profile that matches exactly what each of those different jobs you've applied for represents? Because as for the game we're playing, right?
We don't just have a one resume and a LinkedIn profile that reflects what that resume would say. Instead, what we have are multiple resumes, like the tools that you can use. It says, here was my original resume, here's the job description, rewrite this, uh, you know, to match this and get my 80% or 90% match in order to get my, to get maybe a, a phone call, right?
Because that's what you're hoping for is a phone call. So that, that, that becomes a challenge too. So in your, in your endorsements and, um, in LinkedIn, your endorsements are important.
Your skills are important. If you're looking for work and you're seeing something that continues to come up as potential, um, a a skill that you need, be sure that you reflect that in LinkedIn. So you may have a lot of stuff in LinkedIn that you're like, wow, I, I guess I could say I could do all that, but yes, you can, women, you can do this.
This is something you can do. So Carol and I, I have another question before we, we have to wrap up. But you go through this process and obviously, you know, you and I talked about it while you were going through it, and, um, you know, what do you do for yourself?
What kind of self-care do you do when you're the breadwinner? You have children, you have extended family there, you know, and there's the stress of that on top. What did, what would you recommend as far as just finding a happy place when you're in a really stressful world, especially the holidays on top of it?
Ah, you know, totally. It's a crappy Type of year on top of it. You know, we have to learn how to take care of ourselves and the time.
I think that it's most important for us to learn how to take care of ourselves is when we're going through tough times. Um, one of the things that I've started doing, and I actually love it, kind of just around the same time that I began my job search. My husband installed a cold plunge, uh, in our backyard.
And I love it. It is not for everyone. You know, not everyone is super excited to dunk their body and polar barefoot, 42 degree, you know, water for 10 minutes.
Um, but I, it just, I just love it. It's exhilarating. Um, so, you know, whatever your thing is, if it's spin classes, if you love knitting, if you love journaling, if you love going for walks in nature, like really make sure you're getting what you need.
I really need sleep. So I prioritized my sleep. I also had a really good friend recommend to me, um, that I should, uh, you know, go on a little trip by myself and for myself.
And I'm very fortunate that I have the resources to do something like that. I booked an Airbnb for myself 25 minutes away from where I live, and I just lit some candles and sat in a hot tub and, you know, did some writing, did some thinking, did some reading. Um, and so we really do have to take care of ourselves.
Um, that I think is what's gonna keep us going. I also think that any, any rejection, any time you are ignored, I really wanna encourage people not to take it personally, because there really are just so many factors way outside of your control. And so what we can control is we can keep going, you can keep searching, you can try and apply for the job on the first day that it's posted.
You can, you can just keep on going, you know? Um, but you know, it's, it's okay to be sad and it's okay to be disappointed. Um, but to the extent that we can allow ourselves to feel those feelings and then move through and move on, um, I think that's a really important skill to develop as well.
That is so helpful. Tracy, are you gonna ask her your question? I think she already gave us something to read, but you have to ask it anyway.
Tracy always asks This. I think That's a good question. Did you ever did, while you were going through this, did, were there any books that you picked up on on being a job seeker?
For me, I read a, so, okay, here's another thing actually. So I talked about strength to strength, which I highly recommend. Um, and then another thing that I love doing is I love reading for fun.
I love reading mm-hmm. Fiction. Um, and I came across this great Netflix show.
So here's something I think that is actually equally important as bleep as, you know, if you have a particular comfort food that you really enjoy, give it to yourself, you know? Um, but I, I came across this Netflix show called A Discovery of Witches on Netflix, and I just love it. And then, so lucky for me, there's three seasons.
So there's a ton of really great content. It's a lot of time to relax into, you know, and I happen to have these three enormous dogs. We've got two English Mastiffs and a Rottweiler mix.
And so I'm just chilling on the couch with these dogs. And then even now, the series was based on a set of books. And so I'm actually in the middle of reading, uh, book number two out of three.
So I think that it's also really important just to figure out, like, what is it that helps us to feel good and to also take breaks from the hard stuff, because our brains need breaks too. Our brains need a little bit of fun too. Our brains need a little bit of relaxation.
What great advice, what a great way to wrap up this episode. Thank you so much for being here. I just, I think this is so important.
And, uh, it's, it's a topic we we need to dive into every now and then for sure. And hear different stories. So I really appreciate you being here, trace Caroline, Congratulations on the, the new job.
I can't wait to hear about it. Thank you. I love it so much, and I'm so happy.
Um, and I really appreciate you inviting me here to share my story. Thank you so much. Yeah.
I'm glad you you came. Thank you very much. Hey, everybody, um, that wraps up the, our latest episode of Techstrong Women.
Thanks for tuning in today and be sure and tune in for our next episode. And again, head to Tech strong TV and check out all of our great content every day. Thanks a lot.
Thanks you guys. It was great to have you today. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Hi everybody.
Welcome. We're glad that you've joined us today for another episode of the latest greatest cloud transformation late great cloud transformation. We're talking about really sort of the next generation of how we think about the cloud and the things that we're doing with it.
We're talking about security today, about safeguarding innovation and, uh, strengthening that security, what we jumping into app, app security, and a lot, a lot of things here. But, um, before we get too far down the road, thank you for joining us for this video series. Uh, the, the last great cloud transformation is sponsored by CloudFlare.
We're glad to have them, uh, on board with, with us working on this, uh, helping input with some topics and things like that. And obviously participating on, on our, uh, live editions, which we do on a monthly basis, as well as these recorded episodes. So thank you for being here with us.
My name is Mitch Ashley, I'm VP and practice lead with futurum Group, analyst firm, uh, heading up the analyst area for DevOps, DevSecOps, application development, AppSec, et cetera. So kind of right in, in vain with this, uh, my co-host Alan Shimel is, uh, unattainable, uh, de detained or whatever the word is the phrase is. And, uh, so I'll be, I'm, I'm hosting both parts of the chair today.
Uh, you know, it's a little bit of a coup, but he'll be back next time. We'll see him on our next episode, I'm sure. So let's get to our conversation, to our topic.
Um, let's first start by doing some introductions. I know Chris has been with us on a few episodes here on some different topics. He'd been on other webinars with me and talking a lot about application security and, and, uh, cloud Chris Blas, introduce yourself.
Oh, I've been in Forest Company my way through the security industry for 30 something years. Uh, I inflicted an early firewall in the markets, something called Border Ware, uh, in the early nineties, and ran Cisco's firewall business, the turn of the century. I've been following this inevitability curve, uh, my new series on here on Textron, um, from one spot to another, from firewalls into, uh, sim and network management.
From that, you know, the obvious next step is threat intelligence. So I, uh, chaired an IAC for a while, and, uh, supply chain has been my focus the last five or six years, you know, so, you know, software, bill of materials, hardware, bill of materials. How do we connect all these things, which, and, and currently, so currently I'm, my main role is I'm vice president of strategy for sbe, which is involved in the SBO M space.
And I've been, uh, co-chairing several, uh, cisa uh, working groups on SBO m sharing. So we're currently have a group looking at ISACs, um, as s om distributors. How does that no, in the middle start taking this information and, and propagating it.
Yes. Bonds software, bill materials, absolutely. Great.
Thank you Chris. Um, Katherine, Katherine, welcome. Glad to have you on, I think the first time we've had you on the show.
Katherine Newcombe with CloudFlare, please introduce yourself. Yeah, Great to be here. I'm excited to talk about application security.
Um, my name's Katherine Newcomb. I live in Denver right now. Um, I've been in cybersecurity for about five years at this point.
Um, and I started in the network firewall space, um, and encryption. And now I'm a product marketing manager for Cloudflare, um, for their application security business. Uh, we're a focus on their web application firewall product, um, our software supply chain product, as well as our encryption and certificate lifecycle management products.
Very nice. And, and I do like to say full disclosure, Textron is a customer of cloud flares. We do use their services and joined.
Very much so. Thank you Catherine, and team for that. Uh, last but not least, another newcomer to our show, Kurt Handel, who's with, uh, Teradata.
Tell us about yourself, Kurt. Yep. So I've been working in security probably eight or nine years at this point, uh, but in the software industry for close to 15 years now.
Anywhere from development, uh, into business analysis, product management, even, uh, doing a little bit of red teaming myself. But, uh, I am currently the chief security architect at Teradata. And so I've been focused on architecture mostly for the past six, seven, possibly eight years, and really kind of a generalist.
So AppSec is where I spend the least amount of my time, but we focus on the architecture, the requirements, threat modeling, um, especially compliance. We do a lot of the, the major compliance frameworks at Teradata. So we've been pushing that recently.
Um, and I'm based in the Pacific Northwest, up in the Seattle area, and happy to be here. Very nice. All the weather and fires and it's cold and I'm just glad we all made it.
Maybe it's 'cause we didn't have to travel anywhere, so, so I hang tight. I'm glad we're all here. And you know, our, our thoughts go our, our hearts go out to the folks dealing with the fires and, and, uh, some weather down south and southeast, et cetera.
So, um, let, let's kind of jump in this way. Um, it, it's a big topic when we talk about sort of the kind of current state of the cloud and where it's moving to. Um, but I don't think it's too much news to everyone that application and app APIs, API first kind of design into applications, you know, it isn't just things that sit at the edge anymore.
We think about also the security of the AppSec and the kind of, uh, software we're creating, the innovation that we're making, um, as maybe as part of the cloud. 'cause sometimes application lives within it, you know, like a, like a provider like CloudFlare or certainly at the edge or at the core as well. Maybe Catherine, if you wanna start us out with, how do you, you're, you're, you're managing, doing product management in this space.
How do you look at this, uh, sort of this problem or this space and define it? Um, so looking at application security, um, when we're talking about this at cloud, we're mostly talking about web application and API security. So if you're an OSI person, layer seven model, um, and you know, when people are accessing these external facing web applications, they're doing it from a ton of different devices and in a ton of different ways.
So they're accessing from things like mobile, uh, desktop, laptop, and they're accessing these AppSec that could be hosted anywhere. So on-prem, in public clouds, private clouds, hybrids. Um, so as we're securing, we need to think about how can we secure, um, all of these users and the end servers as they're sort of accessing these web AppSec, right?
So how do we make sure that, um, mobile traffic is protected, user data is protected, um, and sensitive data is not, you know, leaving an app. And then how do we make sure that a web app server itself is protected? Um, so at a very high level, that's about what I think, that's what I think about when it comes to application security.
Um, some new things we're thinking about in this space. Um, I talked about software supply chain. This is increasingly becoming, um, an area of interest as people create more complex AppSec with more third parties in them.
Of course, API first development has also meant we've had to adjust our thinking a little bit around application security as well. Kurt, how about you as a, as an architect, security architect, you may, maybe you don't get into the innards of applications per se, application security, but traffic over there. Obviously our networks are heavily API driven.
Um, you know, when you think about the security architecture, where does this fit into your purview? I think it, it fits in really everywhere, right? So we're, we're building these huge applications, sometimes small applications.
I, we do all sorts of scale at Teradata. And in my previous roles, I've, I've worked with pretty simple AppSec all the way to super complex microservices architectures. And so, like Catherine could have said, you have the mobile aspect, you have the server, there's application code literally everywhere, including on the person's device.
And so how do you secure it as best you can, um, within reason, right? Because if it's too secure, it doesn't work. If it's not secure enough, well, you end up in the Wall Street Journal and you're in trouble.
Um, so we, from an architecture standpoint, we really try to focus on all different aspects of it, where the biggest threats lie, um, and then implement controls and use technologies to, to simplify the implementation and streamline it without making it overly complex. And so it's, it's just becoming more difficult given that, um, the, the kind of classic perimeter is gone, right? I'm sure you can relate to that, Chris.
Oh yeah. Well, it was easy back in the day, right now, you had to get on the internet and you needed a firewall. Get a firewall, right?
And I'm thinking as Kurt and Catherine, your co remind me of these transitions we go through, like there was mainframes before our time, but you know, I, I'm old enough to have seen the end of that where all of your capabilities are just to keep one computer running and run terminals and printers and things off that. And then we get into, you know, sort where I came in, where we're starting to build networks, fractally more complicated, just, you know, how do we do that with, when all of our resources were just keeping one computer running, we figured it out, you know, now we're here, we're talking about web APIs, Catherine, you know, you know, the data going in and out and with being stored 30 years ago, you couldn't have that conversation. Now we're saying, alright, what do we do in this case?
And it's very complicated and I think in, and Catherine you mentioned the supply chain. This is, I think we're filling in the dots. Security has been, is not, is not new, right?
People have been saying you should know your inventory for a long, long time. And we gotten away with not knowing it. Now we're starting to fill it in, need to actually know where the software is, where the data is, and we're working through that.
So it's exciting times, but it's not different in type than other transitional periods. Certainly is an evolution, right? Of what we've gone through.
And to think about, you know, from the baston host days earlier on, pretty firewall, um, Well, firewalls used to be a million dollars a year. I think when I got involved, you know, at least as I tell the story, there were a hundred in the world and they typically were seven computers and a team of people. And my argument at the time was my mom needs one.
Yeah. You know, and so we're at this stage where what used to take so much time in here in the API, uh, world has to take less time a lot. It, It, so let me, let me throw out this hypothesis here.
I think it may be pretty obvious, but maybe it isn't, is I think we live in a world, you know, now we we're thinking about things as zero trust, right? Of, of you, you know, anything is susceptible, being compromised and could compromise other things. How do you pro protect all parts of the network applications, the infrastructure?
But we're also living in a world where if so much is determined by what our applications do, not just connecting users to AppSec, but applications really utilizing the network, being part of the network. It's a dynamic world, right? It, it isn't a good set of firewall rules and an application firewall, and we're all good, kind of set that up.
And it isn't the old days of, if I've got a pizza box in, in my rack for every function that I need, and they're all doing their thing, I'm good. Right? We need it.
It's a much more dynamic environment. So I'm not saying we're reconfiguring our security all the time, but a security has to adapt to, you know, what's happening in the application. Because we may distribute it to a different part of the edge tomorrow with Kubernetes, or we may, you know, uh, acquire business and suddenly a network has looked much different than it did, you know, three weeks ago.
I'm, I'm curious, Kurt, as a practitioner, you know, how do you think about that of, you know, you mentioned microservices and all the things that are being created, you know, in the groups that you're working with. Um, we, we hate for security to be sort of the last thing to be thought of, but you wanna be in the conversation so you can prepare as well as react when you need to react. I think what you just said is, is really important, but you wanna be in the conversation.
You don't wanna be doing this retroactively. And so when you're, when you try to tackle security retroactively, it is infinitely harder to accomplish than if you do it from the beginning. So I have, I do it both ways.
I have teams that we work with proactively where they bring us in at the very start and we're building the design with them shoulder to shoulder, drawing the picture in doing security by design or by default as we like to say now. Or we have legacy applications, which you're doing retroactively and they're quite a bit higher in terms of risk because they've been neglected for so long. Or you find out about something after the fact and it's like, well, how did this get out there?
Well, there's shadow IP in a lot of the world. And so it's, it's hard to, to really kind of put a, a recipe together that successfully achieves it. And then with the, the rapid pace of technology today and how the cloud has just kind of blown this wide open where people can deploy new applications in a hundred different ways faster than ever.
How do you keep up? So you have to implement tooling within reason without doing, without having too much sprawl. You have to have the right personnel partnering with these teams, uh, to ensure that you have coverage and that you, you're really architecting things from the start.
Um, and not just kind of using band-aids and bubblegum per se to, to secure your environment later on. Catherine, appreciate your thoughts on this because, you know, I remember the days of networks for speeds and feeds and points of presence and connecting A to B and kinda looked like this nice diagram that you stitched together and that was a network and you secured it, now it's overlay on top of overlay and it's changing and mm-hmm. You know, it's, it's multiple pieces that, uh, much more complex to, to secure.
How do you, how do you have this conversation with people? Yeah, definitely. So as you were sort of talking about this, you know, obviously there's a need for responsiveness and customizability and security, but I actually also wanna make the argument for unified policy management in application security.
This is something that I've seen actually, for example, um, we have some customers who have protected their SaaS AppSec, like what is traditionally more of a network firewall or zero trust type use case with the same policy they're using for their web applications. And by doing this, they're able to do things like make sure that zero day exploits aren't able to exploit their SaaS AppSec, you know, as well as their, um, web AppSec. And we see a lot of value out of these unified policy managements.
I was talking earlier about, you know, how we have all these AppSec hosted in different places. We see a lot of customers, for example, we'll host, um, you know, an app across multiple clouds for like a resiliency use case. If they're worried about outages, you'll, you'll certainly see that, um, for example.
But then how do you have to, you know, actually secure an app that's stored in multiple places? Do you write different policies for, for wherever those are stored? Um, do you write different policies for APIs versus, you know, traditional AppSec?
Um, so we see a lot of benefit out of like a unified policy for all of those disparate sort of endpoints and all of those disparate, um, locations that they're stored. Uh, for CloudFlare in particular, how this sort of works out is our WAF is like the backbone, the architectural backbone of the rest of our application, um, security portfolio. And this works out really well because you can do things like have a WAF and an API like positive security model protecting your APIs.
Um, so you could do things like detect zero days and volumetric attacks, which are, you know, APIs can also be susceptible to as well as, you know, do the things like Ebola and, and all those API specific attacks all within sort of one, um, control plane, which we find a lot of people get a lot of value out of because of this really, really disparate environment. Okay. Chris, I saw a lot of hand waving head nodding you, I jumped outta your chair on this one, and so I kind of have a feeling you might resonate with this.
No, um, I, I gotta throw out there, I was gonna, uh, before Catherine got into the, the policy thing I swearing, it's been a lot time, but yeah, the concept of an SBO m the software bill of material for the current release version of Adobe Acrobat as opposed to an SBO m as we're look talking about here, some ephemeral web app that one time for five seconds exists in the cloud. You know, think about that. How do we, how do we deal with that?
And I, and, but I think policy is, is the answer all hacking? All hacking is policy hacking. I will figure out how you do things and I will figure out where the gaps are and I'll engineer that gap.
And we live in a world right now where we generally have no idea what policy applies to any of us anywhere, with few exceptions. And in this topic, and because I'm used to the supply chain topic, imagine I needed to get the, the SBO or custody information about a piece of software on his phone right now, I could get it in between five days and six months. Today I need to get it in a half a second.
That means I need to read the policies between me, the person who bought the phone and the first time the company I bought it from, and like their relationship, their contracts, their policies, you know, upstream all the way. And we have to get that done in the next decade. So without unified and, and, and adaptable, you know, transparent policy frameworks, none of this technology is gonna make a difference.
So I think we, we will do that. And there's interesting things going on down that path. It's kinda interesting in a way just connecting dots between what you said, Catherine and you were talking about Chris, there's your own unified policy management, right, of what you're doing.
So you know, you're, you, what you're applying where and how you're applying it, and then that's how that interconnects or interrelates with the people you connect with, work with, use their service product, whatever that is too. And I, and I appreciate what you said Chris, about, think about just serverless technology, like a lambda kinda service, right? That, you know, it's there now, it's gone tomorrow may not be the same thing it was a second ago when it, when it ran.
Um, so it in some ways, Catherine, it's all sort of a dynamic unified policy management, right? It can't be a static thing. Am I, am I on base here?
Yes, of course. You know, you do have to be responsive to the environment, um, you know, threat landscape. Um, this is one, one area where I strongly advocate for actually ML driven, um, detections and policy.
Uh, this is a thing where, for example, if you have a really large data set, uh, you can train your ML models. Um, how we do this at CloudFlare, just 'cause I think it's a little easier if I give an example and it's, uh, we will score each request on a scale of like one to 99. And if something is less than 30, that means like it is very likely to be an attack.
And because we have, um, hundreds of terabytes of requests, or sorry, hundreds of millions of requests every single day, um, we have so much data we could train this on and say a little blog in Malaysia gets attacked by a new attack we've never seen before suddenly, because that tiny blog in Malaysia got attacked that gets feed and fed into our ML model, we don't have to rely on a security engineer to like, go and find and analyze that attack and turn it into a regular expression like firewall rule. Um, the ML will basically just say, okay, like, since it matches something like this, um, we will just automatically block it. And this is why I'd say ml, um, sort of combined with that traditional, um, you know, security analyst looks at the traffic and writes a rule that matches it and then blocks traffic.
Um, you gotta combine I think, these types of approaches. So ML is a really, really great application, um, when it comes to being responsive to the threat landscape. And we have some data around this as well.
Um, we recently, not that recently, like half a year ago, released our annual application security trends report. Um, and we found out that, uh, for example, like zero day vulnerabilities, um, we probably wouldn't have been able to find this out with just security engineers analyzing it. But with our ml, we were able to detect, um, an exploit 22 minutes after the, uh, proof of concept was posted online.
So, um, really, really great applications there. A lot of interesting stuff going on for sure. Well, that doesn't make the case for dynamic security.
What does, right. Um, I, I'm curious, Kurt, how do you, is, is someone, you know, applying these things, applying security? Are you, are you looking at things like ml?
Are you doing it via yourself? It's something you look for in the vendors, the partners that you work with. How do you leveraging either that or the kind of technologies to help shorten that cycle between when things change and how you can account for it and secure it?
Right. Uh, I think the ML piece of it is, is hugely important because, I mean, humans, we're slow. The, the technologies we use, the computers, and I mean servers process all of this far faster than the human brain and I ever could.
And so we need to augment ourselves with this technology. So anytime we're evaluating new solutions and bringing them in, like I'm currently in the process of implementing a big one right now that focuses on platformization and ai, ml, it's all part of it because in humans with eyes on glass, like it's great to have those guys in the sock, but they'll get overwhelmed very easily with the speed at which things happen today. And so we need to leverage technology and machine learning enables us to do this faster than ever, and it's only getting better, right?
And so augment the human with that technology and you can very quickly pare down all of that information to what matters most and focus on real attacks like Catherine was just talking about. I wonder, you know, there's so much activity around ai, of course, a lot of it because of gen generative ai, um, Chris to, to security engineers have to become machine learning experts to be able to do this stuff. What does it take to really leverage it?
No, but knowing, knowing something isn't gonna, um, uh, causing any problems. But, uh, I, I just couldn't agree more with, with both, uh, with Kurt and Catherine. 'cause you know, and, and you're point Kurt, it's all about time, time to transparency.
How, how long, and again, I've seen this over and over in my career where we get to these points where what we're mostly doing is sharing the war stories. You know, I have no idea it was 72 hours. None of us slept.
There was caffeine. And, and my my question always is, okay, if there was twice as much, what would you do? Because obviously that we're at the limit, we can't possibly work any harder to stay awake any longer.
And, and this, yeah, ai, ml, Oracles, whatever we call it, this, uh, my, a big has been a big part of my, uh, my focus on supply chain before it would, you know, AI became, you know, uh, uh, general, um, uh, generative, what the hell do we call it? I'm sorry, I forgot. Yeah.
Generative Ai. Yep. Generative ai.
Yes. Uh, too many terms to Throw Around. Yeah, because again, we need to, you know, just for supply chain things, I need to read the contracts.
I mean, I can literally call someone up, you know, it's not a security engineer, but it's some administrative person of the company, and I had to get them on the phone and get them to pull A-A-P-D-F and read the contract and find out if the clause allows me to get the information I need. That's not worth a human's time. That's the kind of stuff that computers can do really well, and they're just beginning, but that's obviously the direction we're going.
And if you can't see your policy environment five years from now, by various definitions, your competitors will be so much faster than you are. That don't matter anymore. Cur I'm, I'm curious, without giving us too many specifics about Teradata, I'm not asking you for that, but what's your sense of, what are the, what are the new priorities that are on your, you know, on your horizon or things you're dealing with now and that you've kind of added in the last year or so?
What's changed about how you're thinking about security and that you've gotta address now? I think there's, there's always classic problems that we, we have to deal with and tackle. Like, we can't forget things like identity and network security and the rest of it.
But the, the prevalence in the emergence of generative AI and putting AI and machine learning in everyone's hands has meant that security teams have to be hyper aware more so than ever because these new technologies, people are latching onto them without considering the risks. They're like, that's awesome. I can speed up everything I'm doing.
And suddenly you see a new story about, well, what was it like Samsung engineers leak their code through regenerative AI solution or whatever. So you're, you can quickly lose intellectual property or put it at risk. And so we have to think about securing our environment for those solutions, or putting the guidance out for people to use AI and machine learning.
Um, and I mean, getting visibility of all of this, and another big one that's been getting pretty popular and we're seeing a lot from different vendors and acquisitions and whatever, is data security, posture management. Where is my data? Where is it moving?
How secure is it? Because at the end of the day, that's what the attackers want. They don't wanna sit in your network and use your resources to, to launch attacks as much as they used to.
They wanna grab your data, steal it, monetize it. So need, we're, we're focusing on data security big time in, in the more recent years, especially, um, forward looking because we have more data than ever. Interesting.
Catherine, from your perspective, you know, communicating with so many companies, what are some of the changing priorities from your, from your viewpoint? Yeah, I mean, certainly the gen ai, um, piece is something we're seeing a lot. Um, everybody wants to put in an an LLM on their web application.
Um, and of course that means that you have to think of that as like a data security concern as well. Um, because you wanna make sure your LLM is not gonna like accidentally leak somebody else's social security number, because that's certainly happened before. Um, and so at, at CloudFlare we're thinking about this of like, basically how could you basically just put a WAF in front of an LLM, um, from that perspective, how could you prevent it from exposing sensitive data to the end user?
Um, but then, you know, you gotta think about these more complex issues as well. Like, how do you prevent somebody from poisoning the model? How do you prevent, um, you know, some of these other, like how do you prevent it from hallucinating?
Uh, these are all, you know, sort of adjacent to security concerns. But, um, but nonetheless, we see some security teams focusing on this, um, increasingly. Um, additionally we also think about, you know, the, the LLM sort of security use case is a little bit of a just, um, increased API security use case since a lot of times, um, people are not building these LLMs themself and hosting them themselves.
They're often, you know, bringing in LLMs from third parties, which, uh, necessitates, um, APIs, right, for integration. So how can you make sure that these APIs are staying secure and not leaking them back to the host and whatnot. Um, so that's definitely something we're seeing as well.
Um, I would say additionally, one thing I've been hearing a lot lately is, uh, software supply chain security. Um, I think Kurt mentioned the beginning, um, sort of securing code that lives on the client device as well. Um, this is something that we've been hearing a lot about, especially as it comes with the PCI four, um, compliance, which is gonna be mandated at the end of March, um, in a couple months.
Um, PCI four has a new compliance requirement around client side security and securing, um, the client side, like software supply chain. Um, so this is something we've been getting a lot of questions and inquiries lately. Um, you know, how much are organizations responsible for, um, the code that loads on their end users' devices, uh, when they visit their websites?
Um, this is something we are seeing a lot of people trying to actually actively get control over, um, and make sure that they're not, you know, serving, uh, code to the client devices that could do things like download a crypto mining software onto their phone, which, um, believe it or not, we have seen somebody's trying to make, you know, personal laptops part of a crypto mining network, which is pretty crazy. But, um, so yeah, I would say the client side component is, is something I've been hearing a lot lately as well. I, I just have to say, I, I love living in a world where we can use the term, uh, you know, hallucinating artificial intelligence in a conversation like this.
Seriously, just, we, we understand about that. It's not a sci-fi movie. It's real.
Oh, It's, it's real. Yeah. Hey, so I've, I've kind of a left field question for you, Chris.
So if this, if I throw you too far off the track, I'm guessing you're thinking about this though, is, is there an SBO in our future for LLMs and s LMS and all of these things? 'cause in a way, this is a whole nother part of the software supply chain, right? We're handing off to something that's doing inferencing, either on a chip on our handset or in the cloud, all of the above.
How does that fit into, do we need to be thinking or at least wondering how we're gonna solve this problem And not only not left field, and that's, that's right in the middle of the, the tracks. So in short, yes. You know, there's ano there's another system working group, um, Dmitri Rayman, uh, my colleague CTO at at side beats is, uh, a co-chairing now on, on AI bomb, right?
An AI bomb has been talked about for a long time. So what does that even mean? You know, so AI is code.
So there's this, you know, same sort of standard SBOM stuff about that, but there's also the training data and the models are produced, right? And this sort of goes back to my last comment about ephemeral ephemeral SBOs. You know, we start with the idea that I am a software provider and every 16 years I release new code and I carve a new sbo, you know, on purist graphite.
Um, but we live in a world where code gets compiled and used all over the place. You know, how do we even look forward and say that I can commit to a policy that says I will, if asked, provide the contents of this code without, um, actually going out and printing or saving or producing quadrillions of SBOs forever, you know, in, in exabytes storage. Uh, so this AI is, you know, what we're currently calling AI is just another forcing function of the level of complexity we're at.
So we need to be able to provide the answers to live up to the policies that we've agreed to, um, which is, you know, you know, in the SM case we're talking about a software inventory that I will be able to tell you what code that was running or you know, what data set was used, and we have to get there. And, and, and it's, that is reasonable progress down that path. It's a, it's a complicated one, but is very similar patterns to how we'll do other things, uh, similar complexity.
Um, Kurt is, is that on your radar yet at all, kind of thinking about security of, from a supply chain for LLMs and AI and ML algorithms and all that kind of stuff? No, I mean, it's, it's certainly jumped up on the radar, especially since the whole SolarWinds thing happened. Um, as Chris was talking, it got the wheels turning my mind of, well, if we're gonna be kind of, we're moving towards leveraging a AI in the sense and dynamically generating SBOs and things, is this another attack vector we potentially have to watch out for?
Is how do you weaponize that and, and protect against it? Because I mean, as we see attackers evolve their tactics and techniques faster than ever, they're coming up with new creative ways that defeat the traditional approach in microseconds. And so how, how do you stay ahead of that curve now?
And so I obviously, I don't have the answer right now, but it's, it's really interesting as Chris talked to start thinking about this, this new sort of problem that we're facing. And again, it all falls back to the rapid evolution of technology. Yeah.
Speaking of that evolution, uh, just in the last week or so, uh, Satya Nadal, head of the Microsoft was talking about the death of SaaS, meaning that's kinda the clickbait one-liner. The, what I think he was really talking about is evolving nature of software architecture that I would describe it as Today's microservices or backend code are tomorrow's AI agents, right? We'll see more and more parts of AppSec built through, you know, with or through or maybe completely with AI agents.
And it reminds me of going into the, uh, cloud native era of, oh, how do we secure microservices now that we're gonna do that kind of thing? That's kind of the, that's the next edge that we're, we have to work on and think about how, uh, there are different things we have to do for securing AI agents. How are they orchestrated?
Is it Kubernetes or it's some other thing that's managing all those things. And, uh, given that we're putting AI agent building capabilities in everybody's hands, in many cases, it, uh, could make for interesting. I use that in a nice way, uh, interesting environment to try to secure and manage.
So in some ways, the future is bright, but it may be, uh, pretty intense at the same time, same time. Well, and I think kind of building on that too is the, the technology behind ai, it's backed by machine learning. Like you're, you're making technology autonomous, right?
So it's not as predictable anymore. So how do you secure what, when you don't exactly know what turn it's gonna take next, Non deterministic? Right.
Well, I, I gotta add a note, a note of hope though, because it's easy, you know, to your point, uh, Kurt, the short answer is yes, because there's a new attack vector. Oh, yeah. Um, but you know, throughout my career I've been arguing this one, it's like, we'll probably keep the lights on.
It's like, no, no, if we don't do this and that, then you, we will, you know, the, we're on this, we're doing this call right now. We've managed to figure out everything else over this point. And not only that, but I think that where we've been mowing the lawn, and I think, you know, what we need to do, generally speaking in cybersecurity has been known maybe forever, certainly 50 years, but we haven't gone around to doing the vast majority of it yet.
'cause we haven't had to. But as we do, and I, I will take a risk and, and put a lot of my, my faith in policy, you know, in, in real policy transparency, you know, in, again, in this decade it gets harder to be an adversary because, you know, these are the happy World War II fans out there, you know, or you know, fans, you know, but the, the ubo wars, right? There was the happy days when you could just have a U-boat and sink shipping all day long.
You know, that's kind of most of the world, most of the, the history of the internet to date. It's not necessarily gonna stay that way that long forever, where there's always a new attack service, and there's always a, a, a new way when the last one is, is blocked. I think we will, will keep it running.
We will all be fine. And I think over, you know, at least over a period of decades, being an attacker will become much, much more difficult. I mean, I might argue it already is becoming more difficult.
It 'cause the, while, while the, the technologies we use as practitioners are getting more advanced, that helps make it more difficult for the adversaries of the world. But that's not to say that they can't employ similar technologies, right? So now we're kind of, we're creating that chicken and egg problem all over again and playing a game of cat and mouth.
It's kind of the next arms race, if you will, as technology evolves, everybody has access to it. Well, let's do this. I appreciate all the conversation and we brought up a number of topics, um, just as a kind of concluding thought.
Uh, we, we've been talking about what are the things we need to be thinking about? Maybe they're new on, maybe they're on the horizon, maybe already working on this today. Um, if you had to say, there's one thing you'd really want to emphasize this, if you were, you know, somebody who's listening to this and maybe making a few notes, the thing that sort of stands out to you as something really important to be thinking about in the next, let's say, six to 12 months, if not today.
Um, Kurt, do you want to give us your thoughts and then Kathleen, if you would, and Chris, you can wrap it up for us. Sorry, did I say Kathleen? I mean Catherine, excuse me.
Kathleen. I work with a Kathleen. Sorry if I've been doing that.
All good. Okay. Yeah, I, go ahead, Kern.
I mean, it's, we wanna avoid that situation where everything is a priority, so nothing's a priority, right? I think we, throughout this conversation, we've highlighted the importance of, as ESMO is, we've highlighted the importance of application security and how it's, it's becoming more important than ever because our application code is, is literally going everywhere. And that's, that's kind of the gateway for a lot of the attacks we're seeing in the world today.
And so I think the, the emphasis is on application security, but it's also to say, let's not forget the rest of it, because all of the, the other parts of cybersecurity are hugely important. And we still need that visibility. We still need the coverage, and we need to be thinking about ease of use as well, and avoiding the sprawl.
So I know these aren't necessarily specific cybersecurity things, but they, they help you simplify your approach and, and focus on what matters. And that depend that that changes everywhere you go. Every enterprise or company has different priorities.
And so I think focusing on those things help enable us to, to focus on what matters for where we're at currently. Good. Catherine?
Yeah, so I mean, like Kurt said, you know, we wanna make sure that we're not making everything equal priority. So I think when it comes to application security, which is of course, my area, what I would say is most important in this space is visibility. Um, the attack surface is getting more complex, applications are getting more complex.
Um, you know, where they're hosted is getting more complex. So how do we actually have visibility into our entire, entire application attack service? How do we have visibility into the APIs developers are creating so we can actually secure them?
How do we have visibility into the software they're adding, um, to these AppSec? Uh, that I would say is probably the most important thing for application security and also one of the most challenging things. Excellent.
Chris? Uh, the, you know, Kurt and Catherine both want exactly where I'm going, so I'll just build on that. You know, do do things that save you time to transparency.
You know, if you, you know, don't panic, nothing's on fire. And, and when things are on fire, panic less, right? Just take your time and, uh, getting visibility, you know?
Yeah. Look at how long it takes you to figure out. And anytime you find a, a, a way, you know, in this, in this topic we're talking about here, to spend less time to figure things out, you have all that time back to do things.
And it's easy to just, you know, particularly in transitional periods, to just do more and more and more of what you've been doing, you know? But, uh, understanding the environment you're in so you can apply your resources appropriately is, is everything. And there are lots of ways to do that these days.
You know, there, there's a lot of rush, panic, and there are a lot of, and you know, I will say it, AI and things like that out there who will actually make your life easier, give you some of your time back. Mm-hmm. The, and to feel better knowing what's going on, make, make, and make better plans, that better strategy, Uh, to that point.
Exactly. Chris, and, and Catherine mentioned it around, uh, ml, you, some of the things that I'm really excited about AI is actually just the understandability of what's happening. You know, Kurt mentioned about as things ramped up or, or you did, uh, uh, in, in the, if the tax doubled, right, how would we handle that if we're already maxed out?
So some of it is just handling the volume of things that are happening. But I think one of the things that I think is most exciting about generative AI is it's also so complex. No one person can understand the full system, right?
Or maybe even understand truly what's going on in a case of an attack or where you have vulnerabilities. And generative AI is starting to make some inroads and help us understand systems and, and giving us some insights to some of the complexity. We may not be able to fully get into our head all at once.
So for example, I've been doing some work around how do you modernize mainframe applications? Well, nobody was around that built those things. Well, maybe people that built the network aren't even around, right?
So help us understand what really is happening with all this data that we've collected. And the natural language interface through that is, is a great aid, and I think it's just a real practical thing that we can start to begin to use today. So don't think of AI as just as the next, you know, it's gonna replace all of our software and it's all gonna be different.
And what do we do? There's things today that is already helping us with. So, you know, there's some real things too, not just what's on the horizon.
Well, thanks to all of you. It's been great, Catherine. Uh, we appreciate your perspective and Kurt, you're bringing, um, your experience and perspective.
And of course, Chris, always good to be chatting with you and your connections into the security world. And some of the folks are working, collaborating together, which by the way, is another superpower we have in security. And that's the fact that we work together and collaborate on, on these things.
We're not going at it alone. So thank everybody for their good work that we're doing to help advance. We hope this has been a helpful conversation for you in thinking about the, the last great cloud transformation, what we're doing differently and thinking about, uh, as we move forward.
So as we've got our heads down, getting stuff done, getting our priorities done, getting our plans in place and executing for 2025, but also kind of thinking a little bit about what's next and what we might be considering and learning from others that are working in our space. So thanks to all of you. Thanks everybody for joining us today.
And thank you to the Cloud four team for, uh, for sponsoring, um, our show today. And we look forward to joining us either on another recording or Sure. And check the calendar for one of our live events where folks can ask questions and engage with us in a similar kind of conversation.
We have many of those coming up. We'll talk to you again soon. Take care everybody.