Techstrong TV January 26, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone. Welcome back here to Techstrong tv. You know, I had the pleasure of meeting this fellow right here.
We were out in, uh, in Vegas for RSA reinvent in December, and he came up to our, uh, suite that we had up there. We did a, a quick interview if it's available on Techron TV and Techron O TT if you go to industry events. But I wanted to follow up with him 'cause I, I love the story.
I love the energy, I love the passion he brings to his role as CEO at Zest. Let me introduce you, my friend Sneer, Ben Shimo. Sneer is coming at us from Tribeca today.
My, one of my favorite places, old Haunting Grounds. Um, sneer, welcome back. It's good to have you on Tech Drunk tv.
Good To be back, Alan. Thank you for having me. My pleasure.
So for people maybe who didn't catch the, uh, reinvent interview, give, let's do, you know, let's reinforce, give them a little bit of your background, kind of how you got to be CEO of ZE security and, and more importantly, maybe not that you are not important, but more importantly, what, what is that security about? Yeah, definitely. Uh, so I'll do it short.
If you want to hear more, definitely go to the previous episode, as you mentioned. Uh, so sne al, uh, CEO and co-founder of the security, um, long, long, long, um, journey in cybersecurity, uh, from offensive research and so on. Uh, recently, uh, before, uh, building zest, uh, uh, build cyber security with a few of my friends, uh, to solve the application security, uh, problems and sold the company to Palo Alto Networks.
Uh, that was in 2022. And before that, uh, built from the ground up and heads up all cybersecurity at Varonis public traded company in charge of, uh, product, product security, incident response, forensics, uh, security research and everything against insider threat and data tests. And before that, again, different type of security roles, CSO roles and so on.
So I like to solve problems, and this is like Veronica, we solve the data problem cider resolved the application security problem. And at zes we're solving the vulnerability and exposure management problem, which turned to be the number one problem today. Uh, like as, as you can tell, since 2024, it was the first year that vulnerability exploitation, uh, suppress, uh, phishing in, um, uh, initial access in attacks.
Uh, you have so many vulnerabilities. And today with the ice, so easy to use AI as a researcher and find zero days and then publish vulnerabilities in 2025. We just started 26, but you can look on the previous year, just 2025 alone, there is an increase of over 22% of new vulnerabilities introduced to the market, which over 60% of them are critical, like CVSs nine.
That means that, um, low, um, complexity of exploitation, high impact, and how probability, which is crazy. So if we're thinking about it, um, the most attractive way to hack your organization is by exploiting a vulnerability or misconfiguration, uh, the number of vulnerabilities increasing year over year for over 20 or 30%. And most of these vulnerabilities are weaponized and exploitable.
And you take that and you add to it the problem that we experienced, uh, my co-founder led vulnerability management at Akamai, uh, and we experienced that it's not only millions of new vulnerabilities coming in and increasing the backlog, uh, triaging and remediation of these vulnerabilities, 100% manual. So imagine you have these amazing security tools that you, uh, purchase that gives you all the great visibility to your problems, a lot of vulnerabilities. Hey, we scan this, scan your AWS, we scan your Azure, we scan your service on-prem, and we have all these crazy vulnerabilities.
What should I do now? What can I do with millions of vulnerabilities data from different tools? Uh, orchestration started and it's nice, but it is just like a one list, really one big list of problems.
Uh, what about remediation? What about prioritization? We realize you cannot automate it.
Every vulnerability is different. Every remediation is different. Every, every service is different.
Every service is different. It's like you can't automate vulnerability management and vulnerability remediation as the world chief and organization kind of asking, how can I reduce risk, not only manage it, um, there is that problem. It's like, hey, we realize we cannot handle the numbers and we cannot automate.
So what can we do? We're stuck like that for 15 years until AI came in, and this is exactly what the security is. Uh, we're taking vulnerability management that turned into exposure management that basically failed Everyone have backlogs, right?
So that means that we're doing something wrong. And, uh, we introducing for the first time, uh, in 2025, we introduced iGen exposure management platform. That means that you can now leverage AI agents to do all these scalable un deterministic analysis of millions of vulnerabilities your organization needs to handle in a very smart way.
No more scoring, no more guessing, no more manual work, manual labor, no, no more. I need 20 or 30 more people to throw over the problem using this agent to actually look into this vulnerability and to give you one answer. Do I need to fix it or I don't need to fix it.
And that's exactly the AI sweeper agents we announced today at Zest. So the way we're helping our organization that we're working with and our customers is we're removing unex exploitable unreachable vulnerabilities from their backlog automatically. And we're simulating remediation to find the best path to actually remediate the vast majority of the vulnerabilities.
Um, I think today we reached a really, really big milestone at this that we can sweep the unex exploitable vulnerabilities all across cloud and on-prem autonomously. And that's a big thing to say, no human action, no human in the loop is needed. Our agent will go and we'll give you one or zero.
Do I need to fix it? Or I don't need to fix it. The results are really, really interesting.
Absolutely. You know, Steve, I'm listening to you talk about it, right? Started a company in 2001, still secure vulnerability management space.
Hard to believe 25 years. We're still talking about the same problems. This this pattern you've described of there's more vulnerabilities this year than last year.
The fact of the matter is, most of these vulnerabilities, they're not necessarily sophisticated, you know, in, in terms of, of what you have to do to exploit them. They're, you know, and, and, and still year after year, you read the Verizon data breach report and you read, you know, these, all of the vulnerability and security reports that come out around RSA every year, right? Um, something like 75, 80, 80 5% of the, of the incidents aren't even zero days.
They're not unknown vulnerabilities. They're actual, like garden variety vulnerabilities that, or misconfigurations that people just like sloppy, sloppy. And, and you know, I'm hoping that is much of a tool that AI is in helping the bad guys to find new vulnerabilities to find zero days.
It'll also, at the very least, help us clean up sloppy, right? Because if we could clean up sloppy man, that's a, you know, hundreds of times better than where we are now, and then we could worry about the, the really bad stuff, right? That sloppy isn't, it's not sloppy, it's just, you know, really bad stuff.
Um, before we jump to the next portion of this, for people who want to get more information about Zest, where can they go The best? Like we have two places that we're really active and always updating. io.
Uh, this is where we're publishing our webinar blog posts, research product announcement and so on. And you can read about the AI sweeper agents there. And our LinkedIn page is pretty active as well.
We are building communities. We have a lot of, uh, a round tables security executive events, uh, mostly in like New York, Boston, San Francisco. So our LinkedIn page is really, really, so just look for the security in LinkedIn and look for me in LinkedIn if you have questions or you think AI is a fairytale and it cannot solve their problem.
So I'm happy for you to challenge me. That will be great. Absolutely.
All right, sir, let us turn now to something. You guys are calling ai sweeper agents. Talk to us about that.
Yeah, I think, you know, before you, you're starting to fix things and before you're starting to remediate your problems, uh, would it be nice to kind of like clean up the, the table? Would it be able to just remove everything that is not relevant? And, uh, this is something no one was able to do until now.
It's like when we thought about it and it was like, okay, is it guest woke? Is it something weird? It's like, hey, if we can have infinite amount of security engineer, just infinite amount of security engineers, and ask each and every one of them to go per each and every one of the vulnerabilities are scanners identified, if it's in the cloud, and if it's on-prem, if it's in the product, and ask these, each and every individual security engineer if that specific vulnerability, it's even a risk based on our environment content, right?
So that can be a very bad vulnerability. The vulnerability can be kind of existing in my environment because the scanner identified that I'm running a vulnerable version of something or a vulnerable service or a vulnerable configuration. So it's there.
Now the question is, is anyone remote, local insider can do anything about it to weaponize that vulnerability? And that question is the first, I will say the first stage of eliminating false positive or kind of like reducing that battle. This is what security engineer is doing.
And of course they cannot do it for minutes, but let's assume that we have no number problems. We have security engineer per vulnerability. So our AI sweeper agent, their sole purpose is to clean up, is to remove, is to sweep out everything that is not relevant.
And they're not doing it by looking on, oh, this is only medium. So in our, in our company, medium is not that important. Let's whip it out.
No, they're not looking into it. They're looking on pure facts. What does it mean?
Facts. You have a vulnerability. In order to anyone to exploit his vulnerability, he needs to have some kind of requirements.
The vulnerability of requirements for exploitation. You need to have this type of permission, or the vulnerable asset needs to run in a specific way, or the vulnerable, uh, asset needs to sit in a network or environment that's allowing some specific things. If one or many of these things are not present, there is no way this vulnerability can be weaponized and exploitable to answer this question.
You cannot just scan and say, I have a vulnerable, uh, a vulnerable version of this and that, that's what the scanners doing, giving you visibility. Now you need to do the analysis. So what are AI sweeper agent are doing?
Are mimicking a person, a really senior security engineer that takes that vulnerability, understand from the vulnerability information, what the vulnerability require to be exploited, and then take that requirements and compare this requirements with your environment. Is this requirement being met? Yes.
You probably need to fix it or prioritize it in the next stage. If this requirement's not being met, let's sweep it off. So that sounds like pretty straightforward, right?
It's kind of complicated because there is no automation. Every vulnerability is different. You need to understand which vulnerability is it, what's the vulnerability required?
And then you need to look on different type of things in your environment, like network and permissions and, and, uh, the policies, and then understand if you can sweep it or not. And what we realized, and we published it last week, we, this specific agent so far all across our customers, and now it's like fully ga sweeped out over 11 million vulnerabilities that most of them are high and critical for the organization. They just told the security team, don't worry about them.
You see all these things that you worry about. You don't need to worry about it anymore. This is the fact, this is the truth.
They're not exploitable. It's all good. Don't focus on them, don't look at them, sweep them out.
So just imagine you run this agent and you wake up in the morning and 90% of all your vulnerabilities, the things that you are about 90% are gone. So you left with couple of hundred of thousands. If you're an enterprise, 10% is pretty, it's still a lot, right?
That's The next thing. But it's only 10%, But it's, it's better than than millions, right? Yeah.
It's like really good first step. And that's exactly what the agents are doing. We're moving and cleaning up the sweeper agents specifically just cleaning up 90% of things you think that are important for you to look at.
But they're not Excellent. You know, this is something, uh, over the years, I, I've seen companies try to do this, right? Because you used to have, is it exploitable?
Is it reachable? Is it, you know, is it real? And these kinds of things.
The, the, it's, it's a question of scale, right? In the past, yes, we could do that analysis, reachable exploitable, is it truly a vulnerability, if you will? But to do that, as you say, on a million vulnerabilities, you don't have that kind of bandwidth.
I mean, this, this really is a job that calls for ai, right? That could do it at scale in a, in a, in a good timeframe, right? In the timeframe to make it useful.
Um, these are available now, they're just coming out. What's the story? They are, they were available to our customers for over three months.
And right now we just published that specific, uh, capability that is a complete GA enterprise ready AI sweeper capability that everyone can enjoy. And, um, thanks to our kind of early adopters of the AI sweepers, uh, we wanted to announce about it because most of our customers are highly regulated, mostly PCI, for example. Uh, and you have different level of regulation when the auditor is coming.
And it's like, who, who is this? Who sweeped out 90% of these problems? Like how dare them?
You need to fix them. And, uh, we announce about the AI sweeper agent only after these auditors kind of ask us, can you please tell everyone that there is a tool that can make our life better and the customer's life better? Because at the beginning they're kind of like, how you remove all these backlog of vulnerabilities?
And when you, they looked on the reasoning and facts, they're like, this is, this is genius how it's not existent. Like, it, it saves so much time. It saves so many fights between us, the regulators and the auditors with the securities.
It's like, you need to fix it. And the security, no, we don't need to fix it because it's like, right now they just need to look in our platform and we share like a small kind of screenshot of that specific, uh, feature how it looks like. So the auditor clearly see that this is the vulnerability, this is what required to be exploited.
This is the evidence from the environment that one or two or three of the requirements are not there. And there is no argument, there is no conversation to be made. There is just, there are just facts.
So once we got this very strong validation also from third party auditors that, that our customers send them, it's like, Hey, this is why we sweep them out. Then we realize that this is the time that we're 100% comfortable to tell everyone we can actually sweep and clean up these vulnerabilities. Absolutely.
Excellent. io, correct? Right?
Yes. That's the best place to go. Also, the LinkedIn page.
Sneer, I love what you're doing, right? This is a space I know. Well, I, I hoping to see more and, and, you know, your success is the success that we need in the market to solve this problem.
So keep up the great work, man. Come back. Maybe I, I don't know if you'd go into RSA maybe we'll get together in person there.
Definitely. Like everyone needs to go to RSA, even if they want to or they don't want to. But yeah, we're going to be there with the entire team.
We have some meetings. We have events. And actually I'm excited to meet people like you, Alan, like people that can be doing conferences.
So Yeah, Definitely. Absolutely. Well, we'll be, so Monday we put on, it used to be the DevSecOps event at Moscone Center This year it's AI native or securing ai native deaf.
Mm-hmm. So it's, it's more focused. Well, it's focused on vulnerabilities, pre-deployment, but with feedback loops and everything else.
So we're doing that Monday and then all week we're at, uh, broadcast alley, doing live all Week. Amazing. Yeah.
Let's talk, Let's meet. I'll make sure I, You definitely, I didn't think so much. Thank you.
Are we good? From Shamal to shiel? What can I say?
We'll see you next time. Good seeing you, ssir. We'll see you.
Good to see you. Good luck. You too.
Thank you so much. Cheers. Alright, Bye-bye.
We'll be back with more on text drug TV here in a minute. I am Mitch Ashley of the Futurum Group. I'm Scott Roon with solutional.
We're here today to give you an overview of the Nokia Data Center Fabric reliability study, a survey that addresses some key issues in modern data center networking. We ran a future research survey of a hundred IT infrastructure leaders from large enterprise IT organizations with the goal of understanding how data center network reliability is decided it's delivered and measured today and into the future. Mitch and I wanna cover three main takeaways in this video.
First, reliability is the number one decision criterion. Second, operational challenges, especially human error, still drive incidents. And third teams claim meaningful automation, AI ops, adoption.
And we wanna unpack that a little bit. Yeah, three important messages. Number one, though, reliability is not a nice to have.
It anchors the design, the design, the operations, and ultimately in the business outcomes. Resilience is the end game. Yeah.
Not a huge surprise, right? That reliability was the top priority. Um, there's some interesting supporting stats that go around that.
Mitch, can you talk us through 'em? I think first of all, 86% of the respondents ranked reliability as a top decision criterion. So it wasn't just, uh, just above the midpoint.
It was well almost, you know, get, you don't get 86% in, in responses for very many questions. Uh, and the things that, that it was sat on top of were the ease of integration operations. We know those are also challenges.
So why does this matter? A single hour, hour downtime is a widely expected to hit service levels and also revenue. So 47% foresaw a major service disruption risk, a 68 expected direct revenue loss.
So it's a big deal. 74% of organizations said they had greater than one incident of an outage in the past 12 months. So it's not a rare occurrence, um, when we see that many organizations saying they're having at least one out one outage a year, and that can be due to hardware failures, human error.
Those are common top causes. So now regarding human error, let's talk a little bit about that. We saw that amongst, um, multiple operational challenges, um, that drive those, uh, that drive the outages and incidents that we're seeing.
What, um, more is underneath those statistics, Mitch? It's a significant factor. I mean, the, the respondents rated it 80% said that human error impacts service 17 point half percent, called it a frequent top cause, things like that.
So it's certainly just more than a factor. It's an important aspect of when there is an outage, but it's also more than that. Um, there are often other failures that come alongside with human error at some point in that process.
They can be things like hardware or software failures. So how do we address this? When we asked the respondents, 35% said that they emphasize strict process and training.
25% said focus on resilience and recovery. Recovery, and only 12% said they aim to eliminate errors via automation. Meaning we know that errors are gonna happen, but we have to be able to handle those, respond to those we wanna resilient architecture, implementation, and also as well as the implementation or the automation that we're doing.
So, you know, teams are struggling to meet the evolving needs of the business because we know those are under constant change and also limit the scope or, or run extra planning cycles. Those are things that, that they're struggling with. Oftentimes, they'll even postpone important tasks due to confidence levels, uh, when they're not sure if that's something they're ready to implement or if this is the right timing to do that.
Last but not least, of course, skills always come up, but it's a significant gap. 54% said that that was skill gap was an issue, and several in incited cited that state versus desired monitoring limits were a factor as well. So on the implementation and use of automation in AIOps and the actual adoption, um, versus interest in automation in AIOps adoption, what did you find in the, in that bucket of responses?
Well, they, they said that here's what they're using today. Uh, a 67% said that they're using automated monitoring. 50%, actually 58% said they're using infrastructure's code.
I particularly found that interesting. And of course, that's, uh, you know, followed by things like ticketing, auto failure over, but ai ML based incident prediction was pretty significant if 54 4%. So I think this says that we're investing in A IML as part of the, the solution set, but also I think we know that, you know, tooling does not necessarily equal positive outcomes.
Only 36% reported dedicated AI ops tooling as of now. And many, uh, advanced practices are still in the maturing stages. So, you know, adoption is both planned and underway, but separating tool and use from operational reality gains is still key.
Yeah, that separation, uh, and, you know, that fine, fine grain understanding of are we just interested in automation and AIOps versus we're really, you know, going full force. We're gonna see that journey continuing, I think for years with many enterprises really just getting started in earnest. Definitely tracks agree with you So much that you covered in, uh, in this survey.
We're only touching the tops of the trees here. Where can people go to get the full report and, and plow through this and understand the fuller picture? com and download the report from there.
There's a section for analyst reports and the latest analysis that we've done. We'll also include a link with the video to make it easy to go right to the report, it's free, download it in seconds. You'll be looking at some really compelling and interesting information.
Definitely agree, Mitch, thanks for the pointer and for the readout. You bet, Scott. Thank you.
Hello, and welcome to the latest edition of the Techstrong AI Leadership Insight series. Today we're with Mike Miller, who's director of AI product management for Amazon Web Services. And we're talking about well trustworthiness when it comes to ai, which can be automated with some math apparently.
Hey, Mike, welcome to the show. Hey, Mike, thanks for having me. Glad to be back with you.
All right, so explain if you would, I mean, we're all talking about trustworthiness when it comes to AI and everybody's concern, especially with AI agents, but I think we have, uh, thought in our heads that somehow rather this can be done with some other external magic thing, but maybe it just requires good programming and some old fashioned math and reasoning. So can this be done and how can it be done? Yeah, I, I would say kind of all of the above and, uh, you know, I I, I'm super excited about this because as, as you or your listeners may know, uh, yesterday was World Logic Day.
And, uh, logic is really the foundation of, uh, a lot of the kind of tools and techniques that we're gonna be chatting about today, uh, about how you can, uh, improve the trust awareness of AI and of AI agents. Uh, and, and if you, you're kind of thinking like logic, like, wait, like high school geometry, what is, what, what do we mean by logic? And, uh, logic actually like kind of imbues our life every day.
And we, we use logical, uh, deductions, um, and logical inferences all the time. So if you think about like, uh, it rained yesterday and overnight, it's gonna drop below freezing, therefore I need to watch out for, you know, ice on the sidewalk, right? That's deductive reasoning.
It's kind of taking these sort of logical statements and putting them together and then reaching conclusions, uh, that, you know, are true because of the sort of inference capability. And so that's kind of the same approach that we take, um, with this, uh, technology called automated reasoning. It's this new, it's, it's actually not a new field.
It's actually been around for, for many years. Um, and it attempts to use mathematical logic to provide assurance about what a system or a computer program will do. And that assurance is based on mathematical proof.
I get the concept, but, um, how much skill does it require to implement this? And do I have to be a rocket scientist or is this something that a mirror developer or your average data scientist can wrap their head around? Yeah.
Well that's actually, uh, one of the really, uh, interesting, um, implications of AI and machine learning that we've seen, and that in the past, um, you know, AWS has embraced, um, automated reasoning for, you know, the past decade. And we've had to bring on board, uh, PhD scientists who, you know, spent their lives sort of diving into this mathematical logic and reasoning and understand how we can represent computer programs in this mathematical format. And one of the things that we've seen is with the advent of, uh, LLMs and sort of generative AI, is that that task has now become a lot easier putting this technology within a reach, uh, of your common developer.
And so what we're working on are capabilities that start to imbue, um, our products with automated reasoning. And this combination of, uh, generative AI machine learning and automated reasoning we call neuro symbolic ai. 'cause it combines the two sort of elements, the statistical sort of prediction kind of elements of AI and these mathematical sort of symbolic reasoning elements of AI and, uh, and coming together to kind of enhance, um, the capabilities and, and drive truthfulness, right?
Because if you think about the world is moving to AI agents, um, you know, and these AI agents are becoming more complex. They're handling, uh, more independent tasks, they're taking actions. And so we're gonna need to feel a high level of confidence that these agents are operating according to, like policies or rules or guidelines and making the right decisions or preventing them from making sort of, uh, the wrong decisions.
And this is where neuros symbolic AI can kind of come into play. Did we just simply forget about this AI discipline? It sounds like symbolic ai, I, I seem to remember hearing about this before, and I, I certainly know that reasoning's been around for a while and mathematical proof.
So did we just overlook all this and are now rediscovering it, or where Well, no, it's, you know, it's actually been used for quite a while, but because of the sort of specific detailed skills needed through the science application, it's really only been useful for the sort of most high risk kind of, uh, tasks like, you know, constructing software for the space station or managing rail networks, things like that, where the cost of a, you know, mistake was very high, where it was worth investing all this time, um, bringing these scientists on board to build these mathematical representations and make sure that we could prove the correctness of these systems. But generative AI has allowed us to really massively accelerate that, um, and create these sort of mathematical models in a much easier way. Um, and, and that's kind of what we're doing here at AWS now is taking that decade of experience, um, determining where the right places are, where we can apply this automated reasoning and then getting those into the hands of our customers.
Mm-hmm. So how do we know or validate something? I mean, I get that we can do it with the reasoning and, and programming, but at some point, will a third party need to validate the math?
Or how does that kind of work? Yeah, like, let me give you maybe a, a a quick analogy and then we can talk a little bit about how, how you can sort of audit these things, right? So if I think about, um, you know, back to geometry, your right triangles, right?
Euclid 2000 years ago, sort of reasoned about right triangles, and what he did was he proved, uh, the Pythagorean theorem, A squared plus B squared equals C squared, right? The lengths, the, the, the lengths of the two shorter sides of your right triangle when, you know, squared and added together equal the length of that longer side. Um, and what he did was he proved it in a way that allowed us to, uh, understand that that was applicable to the infinite number of right triangles.
Uh, because you could have gone about this and said, well, let me examine, you know, hundreds or thousands or tens of thousands of right triangles and kind of estimate what the relationship is between these sides. And that's kind of how machine learning works today. You give it a bunch of training data and it sort of starts to generate, um, you know, predictions about, about sort of, well, the questions that you're asking, whereas reasoning in mathematical logic basically says, Hey, over the infinite number of sort of scenarios here, this output is gonna be guaranteed the same time.
And so when it comes back to sort of auditing, how do we know? Well, automated reasoning is really interesting because it doesn't operate like a black box. It's, it's open when we, when it performs a proof, uh, we can sort of print out that proof and use that as sort of an audit trail to validate the behavior of the system that it's being proved correct.
So there is a built-in sort of visibility, um, and explainability that comes into play when we use automated reasoning to validate programs. Will this solve the following issue? I mean, I talk to people about this and they all like generative ai, but they realize that the outcomes are probabilistic, and a lot of the workflows that we're trying to apply it to are deterministic in the sense that we want them done the same way every time.
So does this give us a mechanism to kind of marry the two in a way that is reliable? Yeah, you, you hit the nail on the head, Mike, and that's why we're so excited about using automated reasoning, uh, to help customers, you know, use generative AI in these trustworthy applications, uh, and know that when they're building agentic systems, um, you know, we're validating or constraining or sort of making sure that the behavior of those age agentic systems, um, is, uh, according to our policies. And in fact, we kind of do that today at AWS already.
Um, you know, we have a couple of products. So one product that we just recently announced is called Policy in our Bedrock Agent Core Product. So Agent Core is a set of tools to allow customers to build these agentic solutions and policy.
And combined with another one of our products called, uh, gateway allows you to define in natural language policies that you want to restrict the behavior, uh, or constrain the actions that your agents can take. Um, and these policies are then applied and validated through, uh, formal reasoning and automated reasoning to make sure that, uh, you know, that generative AI isn't gonna sort of slip through the slip through a crack and kind of perform an action that wasn't, uh, according to, uh, the policy that you've defined. Mm-hmm.
How will this manifest itself at the end? Will there be some sort of output with a little check mark next to it that says that this has been validated, certified? Or how do you envision us understanding when this has actually been completed?
Yeah, I think we, I think we work with our customers, um, you know, to help them kind of find the right way. If they're building an innovation and they're using these techniques to, uh, provide higher assurances to their customers, you know, we'll work with them on sort of how we do that. One of the ways that we did it is through a couple of our tools.
So when customers are building solutions on, on AWS, they have to define policies and kind of access controls. And so we actually have a tool called the IAM Access Analyzer that allows customers, uh, to, um, plug in what kind of policies and access controls or details they've got. And we use automated reasoning to validate them.
For instance, ha, if I make this change, does it become more or less restrictive, right? Because let's say I only want my admins to be able to modify this database. If I create a policy, I can kind of validate whether that policy is more or less restrictive than needed.
And we use automated reasoning to do that. So it kind of depends on the particular application, um, and the type of assurance that you wanna provide, you know, the end users, whether there's like a check mark or a validation or, you know, uh, sometimes we've talked about customers about just providing like a, Hey, explain this to me, or sort of like, you know, show me where this answer came from. And that's where we get back to our auditability and explainability and we can kind of detail, uh, the proof or sort of the reasons that were used for this, uh, for this kind of answer.
In fact, we have one product, uh, called Automated Reasoning Checks for Bedrock Guardrails, which kind of does exactly this. It's a product that helps to detect and remediate hallucinations when you're interacting with a chatbot. So where there's like a defined policy, let's take for example, like an airline ticket refund policy.
What we can do is we can ingest that and then build out sort of a, a formal set of mathematical logic that defines the terms and conditions, if you will, of that refund policy. And so, when I'm chatting with a chat bot about getting a refund for my airline ticket, uh, bedrock Guardrails can be used as a guardrail to validate the LMS output. And so we can be certain then that when it sells me, like, Hey, yes, you can get a refund on that ticket because you bought it within the last 30 days, and it's unused and you live in, you know, this US state, uh, we can know that that's a valid answer, and the, the customers can see that in the, in the, uh, chat bot experience based on what, what the customer wants to do.
Yeah. Curiosity for a technology that's been around, you would think I would've seen or heard more, uh, providers offering similar capabilities. But, um, is there something here that's unique about the way AWS went after this?
Or, um, yeah. How come I just don't see this as a broad-based capability? Yeah.
These techniques? Well, so there's a couple AWS products, um, that already leverage automated reasoning, and we didn't necessarily make a big deal about the fact that automated Reasoning powers these things. So I mentioned the, you know, access, the, the Policy Analyzer, the IAM Access Analyzer.
We have a network reachability analysis tools. There's a tool, which you might have heard of, called S3 Block Public Access, uh, which we actually use automated Reasoning. So we mathematically validate that when you turn that on, uh, there's no way that somebody from the public internet can access that S3 bucket.
So a lot of times these capabilities have just been ingredients in, um, you know, sort of security, um, and related sort of high risk kind of capabilities or, or products that we've released. Um, I think one of the reasons why you don't see this, uh, proliferating across a lot of other providers is that, uh, AWS really has the deepest bench of this automated reasoning science experience, right? We've been building it up over the last 10 years, and really right now, uh, we're starting to see that come to fruition with the Bedrock guardrails, the Agent Core policy.
Um, you know, we have a number of other products related to, uh, internal validation. So, um, you know, uh, so in our, in the work that we do in building our own chips, right? For Graviton five, for instance, automated reasoning played a key role in some of the, what's called the Nitro Isolation engine, to validate that when multiple customers or, you know, multiple tenants are using the same server, that there's no possible way that they can access each other's data.
So we've been using the automated reasoning, but a lot of times it's kind of behind the scenes and it's just an ingredient to drive, uh, you know, the security and the reliability and the trust in, in AWS products. So, the way I, maybe I should start thinking about this. I mean, we've all been obsessed with generative AI since it came out, but, um, maybe the future of AI is using multiple types of AI models alongside each other, and they'll be predictive and generative and causal, and now symbolic.
And it's all about mixing and matching these things when needed. That's right. There's a whole, um, kind of universe of techniques that companies can use to drive trustworthiness of their AI solutions.
Uh, and, you know, you need to apply them, uh, sort of gingerly, if you will, right? So there's automated reasoning, uh, there's machine learning, there's guardrails, there's fine tuning. Uh, there's a whole range of techniques that all can kind of be put into play to improve the trustworthiness, um, you know, of the solutions.
Uh, and I think in 2026, we're really gonna see, uh, that start to come to fruition and kind of trustworthiness, especially as we get more into agentic, um, development and agentic tools are gonna be operated on your behalf. Uh, that trust, that trustworthiness is gonna be, you know, a key element of these solutions for, you know, uh, people to adopt them All. Folks, what you heard in here, they used to say back in the day, you know, don't trust anyone over.
Uh, try that again. Lemme try that again. Well, folks, you heard in here, they used to say back in the day, don't trust anyone under 30.
Now we're saying don't trust any AI agent that hasn't been validated. Hey, Mike, thanks for being on the show. Absolutely.
That's a great one, Mike. I appreciate your time. All right.
ai Leadership Insight series. You can find this episodes and others on our website. We invite you to check them all out.
Until then, we'll see you next time. Hey everyone, I'm Alan Shimel. And I am Mitch Ashley.
And you're listening to Still Cyber. Cyber After all these years, baby. Yeah, baby still cyber.
Yep. Still cyber. Mitch, it's good to have you back on here.
Well, I'm glad to be on here with you. Um, always, you know, I'm having fun doing this one. It is.
Well, we always had fun doing these, rich. We did. I think we, we laughed as much as we talked Yes.
Back in the day. Maybe. Still do.
Yeah, we do. We do. We're gonna have to do one live in RSA Yo.
Which stone Cold sober this year, please? Stone cold. Um, okay.
Well, I don't know about that, but we'll see. Alright, well, I don't drink, so I don't have a choice, but anyway, Hey, we are really happy to have a guest on, uh, this episode. I want to introduce you to our friend Kate Scar.
Uh, Kate brings over 20 years of experience in cybersecurity and critical infrastructure protection. I'm not reading my bio or your bio. Okay.
Tell the people who you are. Yeah. So I have, I've been doing this for, it seems like just more than, uh, just decades, man.
I was one of the people who went to Radio Shack, so there you go. Um, but yes, Yes. Uh, but yes, I, um, Hey, look, I, I love cybersecurity and it has definitely been a passion of mine since, uh, since identity management, since vulnerability management, since, you know, and I could just keep going, uh, with this, on this role.
But, you know, more importantly, I think in this discussion for me and why I am so excited is, of course, today is about critical infrastructure. Mm-hmm. And as I was telling you earlier, I actually got my master's thesis in securing the North America grid, the electrical grid.
So I love, um, this discussion, and I love where the Internet of things and the industrial Internet of things and everything that encompasses including, uh, what it means for our government. So you're the person that's gonna solve that. I, and you've been here all the time, just right under, you know, right under our finger.
Right under hiding in plain sight. I'll tell you. Yes, yes.
You know, I, I will say that I, um, my thing is I don't wanna retire until this is solved, so, oh. You know, Be careful what claims you need. I know.
Be careful what, I was just gonna say, careful what you wish for, though. You're a lot younger than us. But, um, anyway, guys, today's, today's episode grows out of an announcement Last week, something I wrote about, um, the RSAC folks, the people behind RSA conference, RSAC conference announced that none other than Jen Easterly was gonna be their new CEO.
Fantastic. And I, I applaud it. I thought it was a bold move.
Um, you could go read my article if you want the background, but, you know, Jen Easterly is truly a leader of the, of a, of this community, truly someone who has the chops, the experience, the talent, the skill and the gumption and the relationship, the lead Yeah. And the relationships to lead. Yeah.
You know, she'll West Point grad 20 years in the, in the Army. She was then the director of csar after our Frank Chris Krabs left, um, with the new administration, along with many of the, of the rest of the leadership there. She, she was moved out of Csar as Cesar's budget was, was cut.
And then her chairpersonship at West Point was taken out from under her by the administration. I'm not here to make this a political discussion. What I am here though, is to talk about what's happened to CSA under this current administration.
And, you know, one of the great things about CS a was part of the charter was working with private industry mm-hmm. Forming that public private partnership Yeah. To protect critical infrastructure, because it's too critical.
No pun. It's too critical, right. To go it alone.
No one private company probably has the resources to stand up to some of these nation states. The government itself doesn't have the reach or wherewithal sometimes to do it. I really feel like, or making a grave mistake by not encouraging this public, private in, uh, you know, partnership towards protecting our infrastructure.
Mitch, I know you feel the same way. It, it, um, yeah, there's kind of a hollowing out is, is what is the hard part to accept about it. Um, 'cause so many good people left.
And, you know, the, the mission has, I dunno if I'd say subtly it changed. Um, but it, it, it, I I have less confidence in it than I did at one point. Not to say we can't return and, and build that back as well.
But I think we have to look at it as, okay, that's happened. Now what do we do? Right?
What do we do to help these people succeed? And how can we help influence? And maybe Jen can do some great things.
I know she will as part of RSAC, that might be part of it. But, you know, the security's a community. It's Yeah.
And I know you all agree about with me on that. Yeah, It is. So, So Kate, your, as you mentioned, your masters, you know, you graduate work is in critical infrastructure, specifically around the electric grid.
And that's a perfect example of a private public, uh, right. Partnership. Right?
You have private utilities, private electric companies. And not only that, yeah. It's like the car business.
It's not just gm. It's all the third party suppliers. There's a ton of third party suppliers and supply chain and everything else that goes into the electric grid that we all rely on.
And it's kind of take for granted, can, can it survive without a government private partnership? Is it mandatory? Are we all less because of it?
I think at the end of the day that we're, we're less because of it for a lot of different reasons. I mean, first when you look at, you know, and I know that people in business push back against, um, regulatory bodies. You know, I understand that sometimes regulation seems that it, it just becomes very, um, heavy handed and difficult to manage.
It's unfortunate that we need regulation in order to have people to do the right thing. But for example, the North American Electric Reliability Corporation, nerc, um, you know, they came out really providing guidelines for, for interconnectivity of the grid. And it, it helps, it helps for all of us, for, for this United States to have governing bodies to help us, you know, distribute, um, energy and to be safe about it.
And that's the key word, right? Is, is safe. Um, we want it to be safe for us to use.
And let's not forget, I mean, in order for the lights to maintain, you know, we've all seen what happened in Texas when there was an ice storm. Um, and we've all seen what, you know, even let's not forget nuclear regulation. It's all part of the NERC as well.
NRC. Um, it's so important to have the collaboration. And, you know, one of the things that I saw out in the field and with, um, working with field engineers, uh, in, with the electric company, people care.
People actually care. They want to do things safe. And, you know, by providing guidelines, it helps people not to be like, like just shooting in the dark.
Like, okay, what are we working for? What are we working towards? It really does provide us this structure, this framework, in order to, to, to be safe for all of us, you know?
Absolutely. Y you know, Mitch, I remember 2005, 2006 going with you, some of these NER and ferc, ner, ferc, remember NER and ferc ner and ferc, the NER and FERC meetings and, and not conventions, but conferences. I'm sorry, Nick m sorry.
Those were the days, you know, sounds like ney Ner, right? He was ferc. I was ner, but, but anyway.
Oh my gosh. But anyway, we used to go to NER and FERC meetings, Mitch and I, and we, and we'd listen in and, and you know, and I, I remember that that's when it first dawned on me, my God, with this close away to a disaster. Yeah.
Right? Yeah. Right.
Uh, uh, it, it didn't take much. And this security stuff that we're talking about, 'cause we didn't call it cyber then we called it security stuff. InfoSec, this InfoSec stuff we're talking about is all that standing between us and disaster.
And, and I was so grateful that we had NERC and FERC all getting aside mm-hmm. This, this framework of cooperation between public utility, private companies, the government. And they were constantly saying, Hey, what's the best practices?
What could we do? How do we keep it better? How do we secure it?
And I, and I, I think that was a great model. Um, I was even happier when CSO first came on. I remember at the first RSA where CSO was involved, the RSA conferences.
And it was such a fresh breath of fresh air that it wasn't just the government saying, look, I just gotta worry about an MCI or, you know, some government network that I'm, I'm wor I'm worried about, no, we're gonna worry about public and private networks. We're gonna work with you. And we're not just going to sit up hide like God giving the 10 Commandments to Moses or something.
It, it was truly a partnership where we're gonna collaborate and work together. And if we hear something through the CIA or the NSA or some of our national Intelligence services that's germane to you, we're gonna bring you in on that to make sure you're, you're hardened and protected. And, you know, we're not gonna have a digital nine 11.
How's that sound? No, that's heavy. Boom.
Yeah. In, in fact, that's what, um, my thesis paper was. It was called the a pearl, a Digital Pearl Harbor attack.
Really? Yeah. Yeah.
There you go. Yeah. And, and, you know, with critical infrastructure, one of the things that I make a poor joke about that I'm still in this industry and not a comedian somewhere, is that, um, when I did my, my thesis, it was on this, um, it was about critical infrastructure being taken down.
It was the, it was a diehard, I love diehard. And, um, it's Live for your die hard. It's a Christmas move.
Me. Thank you. Thank you for Yes.
But the idea that if we take down our critical infrastructure, um, you know, in that movie that they did well, is that they took the attention and went over to the financial industry, right. And started to take from the financial, and that was this whole idea about how our grid actually, you know, you take down our grid and how much is impacted, um, and why we need government, um, collaboration is so, it, it, it's imperative to keep us safe. So I connected back to, uh, I'll bet you cited him in your, in your research, in your, in your thesis.
Uh, Richard Clark, do you remember when he came to speak at, uh, RSAC? That was Sure, that was a huge deal. Just happened.
Someone who was, you know, US National Security Official was a, for multiple presidents. For multiple presidents, yeah. Going back 2001, if I remember when that was.
Somewhere around there, close to that is when he started. But he was the first national speaker I know of that was talking about critical infrastructure. Um, you know, that was back in the days of, we did kind of experience our own version of that.
'cause Code Red and I Love You Virus would take down every business, right. Uh, that ran email, I mean, really had things out there that did impact everybody. And you could, you could feel that.
Yeah. And SQL Slammer, I mean, you know, I remember Yeah. What I was doing, you know, when Seql slam or hit, I remember You guys are old.
I don't remember any of that. No. We'll sit on the front porch and, and, uh, take it back.
Yeah. Have a lemonade iced tea, Right? Mar And, but, but here's the thing.
Over the course of the last 25 years, all kidding aside, we have seen this public-private partnership grow, not contract. We've seen it blossom. We've seen it be rich, right?
Mire. Mm-hmm. Which is kind of quasi-governmental in their relationship with private industry.
Uh, NIST does a great job of working with, with private security, with the security vendor community. Um, FBI, right? The FBI, I mean, look at, I remember our friend Tony from NSA, Mitch, I forget Tony.
Oh, yeah. The last name he ran, he ran the red teams at NSA. Yep.
Uh, he's Tony Sanger, I believe his last name. I think it's that sounds right. Yep.
Um, Tony Sanger. So, you know, there's a rich history of not only the public-private partnership between government and, and industry, but between government InfoSec resources and private InfoSec resources. And in them meeting at conferences like RSA conference like Black Hat and Defcon, right.
In regard meeting, remember meetings, all that. Yeah. I, but you go to Defcon and the feds were there, right?
They were recruiting there, right? Mm-hmm. Um, this was, I think, part of, uh, you know, you know what they say about security, nothing happens and it means you did your job.
This was part of why maybe some things didn't happen. Yeah. Right.
Is that part of it? Let me ask you both a question, and I, I'm gonna take a very simplistic approach to this. I realize this, but I think one of the big things that led to the 17% cut or whatever it was in the CSA budget, is because they were, they were addressing election security and things like that, which, you know, is, is a political hot potato.
Um, now that, that's kind of out of their mission, at least made by the Trump administration, do you think CSA can get back to, 'cause they're supposed, they're supposed to protect the federal networks and infrastructure. Do you think we can get back there now that, that sort of, we've laid aside the election security issue from CSA Charter? Kate, do you wanna go first?
You know, honestly, it's a, a great question. And honestly, though, I, I don't think so. I, I think, um, if people don't understand the value that the industry brings, um, then I, I don't think that they're going to invest in it overall.
I, I don't, and I think that there's a lot of people who don't understand what cybersecurity is or, or what we do. And so I think it's sort of like a, that's what I think. Anyway, we're not wrong this, so, Mitch, I'm, I'm, I'm surprised to hear it was only 17%.
I think there might have been 17%, but then there was other money that was shifted from CSA to ice. Yeah, I'm sure that was, it was like a thousand people was the cut. But that may have been just part of the, that was just the headcount.
Yeah. But budget over and above head count, a lot of their budget went over to ice, all under the DHS kind of umbrella. That's just, remember, but, but, but here's the thing.
It, it's not just the amount of money that was taken out. It is the heads. You lost some really good people, like a Jen Easterly, like our friend Alan Friedman, the kind of father, the father of SBOs.
Yeah. Right. I, I'm friends with Alan on Facebook.
I still stay in touch. But man, it's hard to replace those kinds of people. And at the same time, as you mentioned, I think the mission's changed.
The mission is no longer necessarily to work with private industry to protect all of critical infrastructure. It's to protect specifically government networks maybe. And can they do that?
Perhaps, you know, but as, as we said in the beginning, we're all worse off for it. We're all worse off for it. Um, government networks don't exist in a vacuum.
Yeah. You know, the one thing I I think though, about our community, the cybersecurity community, is that you have a lot of people who care. And I think that this caring and, you know, I think it, it will actually take us to a different place that we want to, as you know, wanting to secure people, that you're gonna see some pretty cool things, I think stand up at the end of the day, because I think the people want it.
I think we actually care. And I think because we care, you're gonna see some, some pretty cool things that will be stood up because of, of those pushback. That kind of brings up the second part where I wanted to go, unless Mitch, you, did you have something?
No, no, go ahead. Yeah, I'm just thinking here. You know, shortly after I, um, wrote my article and we spoke about it, uh, there were reports out of the government as a, as a result of Jen being appointed the CEO over at RSA, the government was contemplating pulling all resources.
They weren't gonna let any of the agencies or even the individual employees attend RSA. They were, because of Jen being there, they were gonna basically pull out a RSA, our RSA conference. Excuse me.
And well, you talk about cutting off your nose despite your face. Yeah. Right.
Who, who wins there? No one wins. You just, you losing all around and, you know, nature rapports a vacuum.
Right? And so, in the vacuum of the government pulling out of working across industries to, to protect our infrastructure, our critical infrastructure, who takes their place? Well, it's a big hole to fill.
It's a big gravity sink, right? That's out there. But, you know, you would hope maybe an organization like RSAC that is trying to move beyond just being a, a once a year conference, but to truly be the world cyber community, maybe they can help forge these kinds of partnerships, these kinds of relationships that we're gonna need.
I mean, the threat as, as I'm sure you're aware, Mitch, and certainly you are, Kate, the threat to our critical infrastructure hasn't lessened No, no. You think is greater. Yeah.
It, it really is. Because, you know, something that we don't talk about is the internet of things. Mm-hmm.
You know, cameras and cameras are in critical infrastructure everywhere. So that, that's like one huge pathway. All the, um, systems, uh, IOT systems, uh, entryways, uh, badge access controls.
Again, all systems that are, that are built on free real-time operating systems on free R toss. And I, and as I would walk into, uh, you know, to a place, I mean, as I looked around, I'm like, you know, there's no, there is, there is no agent on these IOT systems. And of course, the IIO OT systems don't have agents, you know, the industrial internet because they're too darn old.
So, and then there, there are 40 billion devices out there, folks that are just, you know, hello. Wild, wild west. Here we are.
And yeah. With no visibility. So, you know, we're, you know, Ro you know, I'm reminded Mitch, remember going up, we, Mitch and I used to spend about a week, a month, every month.
We spend one week up in Chantilly, Virginia and be all around the, the, you know, the beltway area, Marriott, the court. Yeah. That was our home away from home.
Um, and we had a good friend, Stu Mitchell. Stu must, Mitchell retired, right? Steve?
He's retired up there. Yeah, he's retired. I've talked to him.
Yeah. Yeah. Stu was like a deputy Seesaw, maybe the Seeso at the Department of Interior.
Mm-hmm. And Kate, Mitch and I would go up there and meet with Stu, and it was great. He would arrange, we would get like VIP tours of the Lincoln Memorial and Oh, nice.
And Mitch and I would always go to the Smithsonian and, you know, we were like two little kids in a freaking pond. But, um, it was interesting, even back then, this is like 2004, 2005, even back then, you know, talking to the US Geological survey people, now they've got sensors on the top of the mountains. Yeah.
Weather, earthquake, you know, all kinds of sensors. I'm sure there's probably early warning stuff put in there too. They've got sensors on the bottom of the sea also for earthquakes and waves sub also, again, probably submarine sensors.
Mm-hmm. And you would talk to them about, Hey, what are you doing to secure all these senses? What do you mean We're scientists?
We're scientists. We don't secure these things. We want 'em to be open.
We don't wanna lock 'em down. Right. And we had to like really make a case for why they had to build security, even JPL going out and was in New Mexico or Albuquerque, I can't remember where.
No, not JPL That was wasn't Los Alamos. It was White Sands. White Sands.
That's what it was. Yeah. That's Department of Energy.
Yeah. Yeah. You know, talking to the scientists.
Yeah. They, they didn't see the need because they thought that the only people who would ever be interested in those kinds of devices, Kate, were other scientists. Right.
It never occurred to them. Yeah. You know, my what an innocent naive time that was, huh.
Compared to now. I honestly, and, and it's, um, it's, it's not much difference with these iot devices. You know, think about, you know, even, um, cameras that we have, um, for security, whether it's in the, you know, the subway systems or even the, the lights, um, you know, they're all actually connected now.
It is. So Yeah. Interconnected more than ever.
Oh, that true. So it's, you know, if you watch like the Mission Impossible movies or some of these movies where the hacker Yeah. Breaks into the traffic light system and the camera system and there you go.
It can change all the lights, green or red, so you can go and, and get away. You know, it, it is all, but, you know, let me bring it back though. How do we, how do we fill the vacuum?
Or maybe we just don't, lemme throw out an idea. It, it's very, it's highly impractical. It's not the right idea, but just kinda share an experience.
One, one of the things I learned along the way of kind of budgeting software for IT projects or whatever things I was in charge of is in big companies, I learned the lesson of, well, the, the, uh, the, the favored program of whatever we're supposed to be doing over the next nine months will shift in nine months. So whatever it is, it's gonna keep changing. And this, this, right now, it's, let's secure this next month.
It's let's go do that. So I would always tailor my budget presentation to how my things helped us accomplish whatever the mission of the day was. And people would always be like, how do you have all that capital?
How do you have all that budget? I'm like, it's all how you position it. So maybe that's what we do today, as is, again, simplistic.
But if the watch word of the day is what public private means is really enrichment in hiring, uh, private companies to do these things instead of government agencies. How do we help make that happen in a way that maybe minimizes corruption tilting up one mills there? But maybe that is the answer.
And I know that may not feel good as a security community doing it for the better good through, uh, government, public, private. But maybe that's the model we have to transition to something like that, where we really have to make that happen. Well, I don't know what it looks like, but I don't think we're going back to the way it was.
Even if a new administration came in and said, yeah, we're gonna go back and do that. You're, you're talking a decade at least before we even kind of got back to where we were. Kate, let me ask you a question.
You did your, your thesis in, uh, graduate work on this way back in 2006, you mentioned, right? Right. Here we are 20 years later.
Are you frustrated, surprised, dejected with the progress we've made since then? Or you think it's kind of about what you thought Riter would be? Frankly, I, I am, I, I am, as I've said before on our shows, a Pollyanna, unfortunately.
But in this instance, I, I am dejected. Um, I, I mean, it, it's, it's a lot. And, and it's Groundhogs Day for me.
Um, I always feel like we're still chasing, um, we're still chasing the threat. We're never getting ahead of the threat. And I don't understand when we've had some phenomenal minds.
Um, when we, we, we all, we understand the problem. And this is where I, I get a little bit bummed out because, you know, I, I don't know whether it's when, and to niche your point about, you know, money, sometimes we, I, I think products, you know, so with vendors, I mean, and I worked with vendors. I mean, IBM for, you know, over 20 years, et cetera, McAfee.
Um, and sometimes, you know, it's based on, you know, sales kickoff meetings. You know, what are, you know, what are, you know, what's, the company has to prove a profit and everything else. And so the, so the, so the vendors are talking and trying to sell the products.
But at the end of the day, um, and I was an architect, so I would, you know, bring in, and, and I, and I didn't, I, I was agnostic, um, as far as products were concerned. And, um, but it always seemed that at the end of the day, you know, it's like we have this phenomenal product and we're gonna, you know, crush this CVE, well, now we have 40,000 plus, you know, CDs. And you, I, and I walked into, you know, how many companies that had over 120 different security, cybersecurity products, 80 different vendors.
And I'm like, okay, this is a vulnerability within itself. You know, you have so many different vendors and so many different products. So, um, so I think we have to switch.
Um, and Mitch, you know, I, I do, I, I like the way the thinking is because I don't, I think that this gives us actually an opportunity within the cybersecurity community to look at things seriously. We need to look at this problem differently. And, um, we, we really do.
And, and we have to seriously understand, 'cause look, we have to crush disinformation. We have to, you know, look at large language models. We have to look, um, at, at doing, um, you know, the, the AI and the coding, um, differently.
Because if we humanly look at this, we're not going to, we're not going to win. So we have to look at LLMs and we have to look at how are we going to address this to address these threats for real? And not just singular threats.
I mean, big threats like disinformation as an example. Oh, disagree. Yeah.
I, I'll just chime in one this is, could do a whole podcast about this, but I think we have already surpassed, but certainly reach a, a, uh, a velocity stage where what is happening, whether it's the amount of change, whether it's the tax surface, where there's all the events that are happening are far beyond the, the model of report and human take action. We have to get to a place where, oh, I, I think we passed that Rubicon a while ago. We have to get to a place where we can trust technology to take action for us.
Whether that's AI or something, you know, even generation and, and otherwise, it's, it's just there's not enough people on the planet to respond to every CVE vulnerability that gets reported, or every incident that happens. So that, that to me is we, we have to invest in that. That's where I think the next big, big, big, big innovation in security is that hump we have to get over.
Otherwise, it's, it's not gonna get solved. But that, but that's also the kind of mission where it's good to have the breadth and width of the government trying to solve that with you, because it's, it's really, it's a big mission. Maybe almost too big for any one vendor or one company, or even industry state, nation state is, well, no company is prepared to really Well, and, and there's the flip side to this, which is this whole sovereignty, digital sovereignty thing, right?
Where whole nother, you're not, you know, you used to be able to, one of the, besides dealing with private individuals, would deal with their counterparts in Europe. And, you know, we in the West and Pacific, our allies, well, we don't have a lot of allies these days. No.
Wherever they may be. Well, north, North Korea might help us. Who knows, he's friends with them.
But, um, we count on your Greenland, it's just, it's just a block of ice. Anyway, um, we're not gonna go there though. We're not going there.
Please. But let me, let me, let me wrap this up in a dignified way, Mitchell. Thank you.
I certainly can't do it. I appreciate you in case that up. You, Jack, you dragged us down there on that one.
But, but the national sovereignty issue is a another example of us breaking down partnerships instead of working together to solve a global cyber problem, which is critical infrastructure safety. Yeah. And, and, um, and I'd like to just add that I talk a lot about frameworks.
At the end of the day, a framework is so important. It gives us a vision. And I think if we can invest in a framework and one that we can agree on, I think we can then start to build the components around it that can actually give us this vision that we need for the cybersecurity that we need for today.
Not even for tomorrow. We need it right now. I just wanna add ly one thing, and, and Kate, I mean this, and, and with every bit of sincerity, you are one of the clearest voices in cybersecurity right now.
We need to elevate you and what you're, you're talking about, and yes, you're on Textron Gang with us. You're on Security Boulevard, but I hope you can take an even greater role, whatever that is in. Well, she's also the chair of the CD Foundation Cybersecurity special interest group.
You, you go. I mean, the more we can elevate you and, and folks like you, because you are such a clear communicator, you know, you don't get lost in the gobbledygook of security. Like, it's so easy, easy to do.
And you, you really get to the heart of things. So thank you so much for what you do, and we hope, well, That's very kind of you. And, and I really appreciate being a part of this f and Ner.
I hope to be back. Fe And Ner Burt, Ernie b***h, take us home. Well, I don't know what FRC and NERC stand for anymore, but whatever it was, we used everything back then, and we'll have the future version of it.
So, thank God we have, we have leaders like Kate that, that are helping make progress. And Jen Easterly, good luck to her and RSAC. Yeah, I'm looking forward to, Hey, hey, you know what?
Step out, uh, connect with us 'cause we're gonna be recording an episode at RSAC and we'd love to sure have you on and talk with you. We are having guests like Kate, uh, come on. And, uh, we'd love to have you.
com or myself, m Ashley Group. I thought you're almost gonna say still secure for a second. I almost did.
Almost did. Yeah. com.
And, uh, we'd love to chat with you and thank you for listening. And hey, hit that follow, hit that like button, you know, aren't we supposed to say that? Hit the like button.
Yeah, hit the like button or subscribe, or whatever button you see over there. I don't know. But for now, this, this is gonna wrap up this episode of Still Cyber.
After all these years. I'm Alan Shimo. I'm Mitch Ashley.
We'll see you next time. Welcome everyone. Thank you for joining us.
Today. We're talking about readiness and AI in the mainframe environment. My name is Mitch Ashley, and I lead the software lifecycle engineering practice at the Futureum Group.
Today I am joined by Anthony Desarro, who is Senior Director architecture of ai. And with the BMC, let me try that again. Not the BMC.
Dang it. My bad. Alright, starting at 3, 2, 1.
Hi, and welcome. Welcome to our conversation about AI readiness in the mainframe environment. My name is Mitch Ashley, and I lead the software lifecycle engineering practice with the Futurum Group.
Today I'm joined by Anthony Dero. Anthony is Senior Director of architecture for AI with BNC software. Welcome, Anthony, Mitch.
Thanks for having me. You bet. Great to have you.
Now, this is a three part series. Our first part is talking about AI readiness, and the series is, uh, sponsored by BMC software. We appreciate the folks at BMC, uh, putting this on and putting this together.
So, Anthony, let, let's jump right in. So, we hear a lot about organizations needing to be AI ready, especially for the mainframe environment. Mm-hmm.
At the earliest stage, what does AI readiness really mean? Yeah, Mitch, this question, I can't tell you how many times I get this, whether it's I'm speaking at a conference or customer visit, this always comes up, you know, how do we get going? How do we, we get started with that, and it's so foundational into a successful journey with ai, but yet it's a step that you'd be surprised how many organ organizations just kind of ignore or are not even aware there is a readiness, uh, you know, playbook that, that, that they should be, uh, following.
So it all boils down to, uh, from an organization perspective, you know, how do we roll in AI technology? How do we use AI technology safely within our organization? How do we put guardrails around AI for, uh, you know, for protection against data?
Uh, for example, you know, uh, from a, from a legal perspective, you know, uh, what policies and governance that we need to have in place. Uh, we bring AI into our organization, and there's all kinds of challenges around that. But at the end of the day, you know, that's one part of the organization's gotta deal with that.
And then it comes down to the individual, you know, groups and, uh, departments within an organization on how they want to utilize ai. So the first really good step in that journey is looking at AI as an advisor. Mitch, really look at it as like you would bring in a human into your organization, you know, based on their experiences and, and their background to have a dialogue exchange with them about whatever challenges that you may have.
And you're gonna lean on that person for their insights and guidance based on their experiences. Ai, that's a great first step with AI image. Look at AI as an advisor.
It's there to explain, it's there to guide, it's there to recommend, et cetera. It's there to provide knowledge and insights that you may otherwise miss or not know how to surface. So from that perspective, that is a safe AI journey to start moving your organization to.
But then the other side of that is the skills of your staff itself. When you bring AI into an organization, you wanna make sure that your SA staff is skilled in AI usage. You want to make sure your staff is skilled and understand on where they should be applying AI within the organization.
So there's some education and training that need to be done for your staff. There's guidelines, uh, uh, and policies that you need to be putting in place, guardrails that you need to be putting in place. And that's all very, very, um, very focused on individual organizations and what that means.
But that's the first step, um, to get that, those foundational aspects of AI in place. That's a really good point about having that kind direction you want to take with AI versus it's so accessible. We can use it, try it out, but how are we gonna focus and leverage it for the organization.
And you mentioned the concept of AI as an advisor, using that as your first entree into ai. Talk about how that is different than maybe automation, autonomous ai, gentech, ai, all the terms that we hear about, uh, doing things with ai. Yeah, Yeah.
So what, you know, when you do hear about, uh, autonomous AI and agents that's all around actionability and the AI take, you know, perceiving a situation, making a decision, and taking it in action, jumping into the deep end of the pool, when it comes to AI in that regard, that, that, that's concerning to a lot of, a lot, a lot of folks. So when we talk about the advise the advisor part of that, the advisor takes no action, right? Again, the advisor is there just to guide you, nurture you, and move you along.
But it's up to you, the human to actually take those actions. It's up to the team who's using AI to infuse AI with the right pieces of information to get the right types of guidance that they want from that AI system. But that AI system is benign, right?
That again, the AI system is not going to take any actions on your, your behalf. It's all back to you. And what you want to get out of that, that AI system.
So if you're a developer, I'm gonna use AI as an advisor to maybe gimme code, recommendations, code, explain, um, maybe to do a best practices analysis on my code, et cetera. That's, that, that's really good. Maybe from the AI ops space, Mitch, we're gonna use AI as an advisor to oversee my, my dashboard and maybe surface insights to me out of that dashboard that I would otherwise miss.
But there's no actionability to it in that regard. It's just providing the insights and information so that that is, that is a part that fits very naturally into the advisor part of it opposed to the autonomy part of ai. It's good you mentioned that.
'cause it is a much more comfortable way to kind of enter into the AI space and start to use it. You don't have to jump right into automation and agents and, you know, doing more of the, you know, advanced things. If you wanna think of it that way.
You'll build trust, you'll learn about AI by using it. And we, and we've done that ourselves, right? You know, look over the last 18 months, whoever your chat provider of choice may be.
But that's how we, we all got into the game of ai. When, when, when, when, uh, you know, chat, GPT was released as an example. We all went out there and, and started having conversation with AI at that point, whether it was professionally or personally, that experience was an advisor type experience.
You know, we sent it a bunch of questions and we got responses back and we had a conversation and a dialogue with it, but nothing happened. There was no actionability to it. So that was all of our entries into the AI world.
And for organizations, for enterprises, that's a great first step also in the, in the start of their AI journey To that point, there are plenty of ways to engage with a AI and query it, use it as a tool. But what do you need to have in place to be an effective advisor role in, in the environment we're talking about? Yeah.
So one of the things that we've learned in our journey with AI so far, and I think as an industry, we've all learned just bringing a large language model into the organization, not enough, right? It's like it's, that's just, that's the bare minimum entry that you could do. But the problem with just bringing a large language model into your organization is it doesn't have any context.
Those large language models were trained on huge corpus of information. They were targeting the masses of users, where once you get into an organization and you bring AI into an or into an organization, you're, you're in a particular domain. You're in a particular realm.
So now how do you, how do you utilize this large language model that's general purpose for specific domain that you may be in? Well, the way you do that, and what we've learned o over the past, you know, 12 to 18 months, is you have to augment that large language model. You have to augment it with realtime product data or whatever data, uh, realtime data that your, your organization is playing in.
You also have to augment the language model with additional knowledge, whether that's workflow, knowledge, processes knowledge, best practices, knowledge. It's, it's your enterprise knowledge. Whatever that means to you in your organization, you want to infuse that into your AI system.
So then you have the large language model with your enterprise knowledge, with your real time data access, uh, knowledge. It's a combination of all three of those that brings relevance to AI with an organization because it brings relevant context into your organization and the AI perspective. And when we're using AI advisors, and I agree with you very much about the point of, you know, contextualizing it with information about your organization.
Where do you see the fastest value that can be delivered by using, uh, AI advisor in the mainframe teams today? It's definitely in the DevOps space by far that it, it's the DevOps community that has really opened their arms and embraced ai. And the mainframe environment is no different, whether, you know, from the cloud environment to a distributed environment in that realm, the developers have accepted AI in the mainframe space.
There's a, you see a lot of interest, a lot of adoption AI in the, uh, mainframe space. So that is, to me, has progressed us as an industry in the a those working in the AI space, the work that the development com community has done over the past year, 18 months has really accelerated our journey, uh, with ai. Now, you also starting to see other areas starting to get really interested in that.
The AI ops space, as an example, is getting, getting a lot of traction now when it comes to, uh, to ai. And we're heavily looking into that within our portfolio, in our AI ops, uh, part of it. But it's the knowledge capture that is what's gonna play the biggest game here, why we're in this massive transition within the mainframe community.
We have a lot of folks heading out towards retirement on the tail end of their careers. How do we capture that knowledge and how do we infuse that into our AI system so that next generation coming in has that experience? They can lean on that they otherwise would not have that person they would go to, you know, Bob, Bob is not here anymore.
But if we were able to capture Bob's knowledge in some way, shape, or form, and put that, infuse that into the AI system so that next generation can lean on the AI system and get access to the information that Bob had, that is game changer in our mainframe space. It's really, it's not only helps get that next generation up to speed, Mitch, but here, he, I I just had a conversation yesterday with someone about this AI on the mainframe is making the mainframe sexy and attractive to that next generation coming outta colleges and universities. We're in the conversation, just like the cloud space and the distributed space when it comes to AI and technology advancements in general.
That is really cool. It very much is a sense of excitement in the mainframe environment, particularly with ai. And I, and, and you have a really good point about that knowledge loss, you know, as folks retire, move on, whatever it might be.
So the next generation of people work in a mainframe, have got that information contextually available to them. And ai, I can't think of a better application of ai. Yeah, absolutely.
And we hear that from our customers. Our customers are like, you know, we got decades worth of white papers. We got years and years worth of, uh, video recordings, training material, et cetera.
How do we capture that? How do we, how do we get that into an AI system? And that's something with B-M-C-A-E, uh, assistant that we, we, we took very, very serious, right?
So it's like, well, how do we do this? How do we allow our customers to capture this knowledge that they have and get it infused into B-M-C-A-M-E assistant? And we're delivering to our customers a tool that makes that really easy to do, uh, where they can, uh, manage documents, they can manage videos and build out their own knowledge base that B-M-C-M-E assistant would be totally aware of.
Now, when we ship our solution, we have the large language model. We have an a knowledge base that we ship, the customer can build their knowledge base, and then we have access to all of our product data. So we got all this information that's available to BMC Amy Assistant, that goes back to what we talked about before about what's relevant context to a customer.
Yeah. We can't talk about AI without talking about trust, and I've heard you discuss the importance of explainability. Yeah.
Talk more about that. Love to hear your thoughts about why that's so important. Oh, Yeah, yeah, yeah.
So with, with ai, of course, you know, trust always comes up in the conversation from the very beginning. When we all started working with generative ai, that was the, you know, everybody was talking about trust in that regard. It's multiple ways to answer this.
You know, we have some responsibility in the solutions that, um, that we provide our customers. We gotta give the customers insights into what our AI system is doing. We have to connect our AI system into their workflows and processes around auditing, logging, tracing, et cetera, observability in their organization.
So how do we do that? So as an architect, from the very beginning, foundational, we have to be able to capture everything that is happening through our, uh, our AI system through BMC and E assistant. From a user typing a prompt to us formulating a response, not only did it has to be auditable, but as much insight as we can provide on why we came about a response has to be clearly articulated.
And some of that is clearly articulated back in the product experience. So when we give a response back, we may cite in that response where we, why we came to this conclusion and what pieces of information led us to the, to this conclusion. But it also has to be totally, uh, traceable and auditable behind the curtain so that the administrators of the AI system have full optics into everything that is happening in that system.
It cannot be treated as a closed door system. So it, it, it's the optic optics into the AI system. It's the auditability, traceability, logging, everything has to be done.
So if you go into the system, Mitch, and you are working with BMC Amy Assistant day in and day out, the system administrator has, you know, full trans full transparency into all the things that you've done with the AI system. And when, and, and customers have asked us for that from the very beginning, we started working with our customers in this journey that was foremost right at the top of the list. They need to understand what's happening in the system and why.
And we've done that. That's foundational for us. That was something we had to put in at the lowest level of the architecture.
That's not an afterthought. If, if, if you go with that approach as an afterthought, you'll miss things. It has to be done at the ground level of the system.
Yeah. That explainability of transparency is fundamental, that that builds that experience that you start to build that trust with very much so. And is that trust that's gonna lead us to, to, to the next part of the AI journey beyond the advisor where you look at AI as a true partner in your daily journey.
You look at AI agents and agent AI as a digital workforce, do and work, and, but we gotta take those steps and build that trust. Speaking of taking those steps, steps for organizations that maybe just starting out thinking about AI readiness, what do you think are the smartest first steps to take? We went through this journey ourselves.
So, so we have a pretty wide and deep portfolio, which with done our BMC Amy, uh, product area. So we had to go through this exercise. Where do we find true immediate value that we can deliver to our customers?
The AI journey was new for us too. We had to be very careful, very systematic on how we approached it. So the, the way we approached it was, let's just start looking at the low risk, but high value returns that we can give our customers with our AI infusion within our products, within our portfolio.
And we've been very, very successful at that. But one of the key things, even though it's, you know, it may be a, a low risk, high reward type, um, AI enhancement, we want to be able to also capture and measure that. You have to be able to measure and capture that to make sure you're truly getting your return on your AI investment.
This model worked very well. I, I I, I, I spoke to other architects about this model. I spoke to customers about this model, and this is a really good entry point model.
Start small. Don't try to drink the ocean, as they say. Start small.
Identify those low risk impacts. You don't want anything that's gonna disrupt your business, uh, you know, a day to day. But then just start taking those steps.
And before you know it, when your organization gets more and more comfortable with AI and you start building the trust with AI and you start to get a good feel of what you can and cannot do with ai, before you know it, you're starting to take on bigger and bigger and bigger challenges with AI and be, when you look in the mirror, you'll see yourself progressing pretty far pretty quickly with AI when you start that way. Those are some great insights, some very sage advice, I think. Anthony, thanks for joining us today.
Thanks for being part of this. We really appreciate the BMC software team for sponsoring this kind of event where we can share this information, share some of our experiences, and bring up some of these important questions. So this concludes our first segment that we're doing in the three part series covering AI readiness.
In our second segment, we're gonna be talking about infusing intelligence with ai, using AI as a partner, using generative AI in the mainframe environment. Thanks for joining us. We look forward to seeing you on our next segment.
Digital sovereignty is an abstract anymore. It's national and it's personal. Hey everyone, it's shimmy, and welcome to this special Friday edition of Shimmy.
Says, you know, if you caught my shimmy says yesterday, it was rather tame. It was geeky. It's about DevOps, the never-ending story.
Something near and dear to me. But I wanna speak today about something maybe a little spicier. It is near and dear to me too.
I call this Shimmy says, episode digital sovereignty is national sovereignty, and digital sovereignty is personal sovereignty. So let me tell you something here. If you were paying attention to the news lady lately, especially coming outta Davos this week, so much coming outta Davos, so much of it was nonsense.
But there was one phrase that kept coming out over and over, and one topic that kept being harped on digital sovereignty. Whether we were talking about sovereign AI or sovereign cloud, sovereign data, sovereign semiconductors, digital sovereignty, and really digital sovereignty has become a code word for independence, for not being reliant on any one partner. You know, I, I thought the, uh, the prime minister of Canada, his speech on, on sovereignty and independence and building fortresses and variable geometry was probably one of the speeches.
It should go down in history as a great speech. But it really at its heart was about sovereignty. National sovereignty.
Every country needs to be able to be self-sustainable and not dependent on any one other country. They've gotta be free to make their choices that's best for their own country, but working together for the good of the world. You know, a few years ago, the whole digital, so sovereignty thing sounded like policy speak, but today, I'm telling you my friends, it's kitchen table conversation for world leaders.
And it's kitchen table conversation for you. Because digital sovereignty is national sovereignty. And digital sovereignty is personal sovereignty.
It's about your freedom, about your privacy, about who controls you. And this didn't happen by accident. What we're seeing going on right now in this world is a reckoning.
Countries are waking up to the fact that their digital future and their digital future is their, is their future there. There is no separating digital future from the rest of your future. It is your future.
They're realizing that they can't sit entirely in someone else's house anymore, frankly, especially when that house is halfway across the world and there's a crazy landlord that keeps changing the rules. You know what I'm talking about and who I'm talking about? AI isn't some science project anymore.
It's in production. It's running economies. It's shaping defense strategy.
Data isn't just data. It's leverage. It's the lifeblood and the cloud.
The clouds become something more strategic than oil shipping lane or who ships and missiles controlled to the damn straits of hor moves or wherever our oil's coming from these days. You know what Davo, a Davos, no one was asking whether digital sovereignty matters, that ship sailed, that train left the station. They were asking, how fast can we get there?
How fast can we be independent? How soon can we not be at the, at the beck and call at the behest of some master we don't want to be serving? And what happens if we can't get there?
What happens if we can't get there? Europe is rethinking its dependence on hyperscalers, it's rethinking, its dependence on AI models. It's dependence on on foundries and and chip makers.
It's very digital independence is what's its stake. It's not just Europe. It's the whole world.
Governments are very, are suddenly very interested in where their data sleeps at night and AI that's gone from innovation, nice to have to existential, must have. That's the moment we're in right now. That's the moment we're in right now.
I am going to open up here, you know, like not that shimmy isn't always opened up, but I'm going to get personal and vulnerable with you right here. I get it. I understand why digital sovereignty is necessary in today's crazy world.
I do. I really do. I think you do too.
But it makes me incredibly sad. It makes me sad. It makes me sad for the world order and the stability that I grew up believing in that gave so many people rise above poverty, rise above hunger, created the biggest middle class and probably the most peaceful, peaceful time in the history of humanity.
I'm sad that we are look, seem to be losing that I'm sad for the internet that I saw blossom before my eyes as this big beautiful equalizer that let me talk to anyone anywhere in the world. From China to Australia, to Singapore, to Europe, to my friends in Marrakesh, Morocco. It made the world smaller.
It made the world better. It made the world not meaner. You realize it really was a small world after all.
It made the world better. I'm sad that early dream, maybe it was naive. Sure, right?
As a child of Star Trek, that we could actually reach out for the stars together. That technology would help us bridge culture, help us bridge differences, build something bigger than just borders and flags for a little while there. You know what?
It sure felt real. Had me fooled. Probably had you fooled too.
We grew up believing this. If you're at that age, gen X boomer, but let's not kid ourselves from the in, from the moment the internet went commercial, some governments knew exactly how dangerous it was. It wasn't dangerous to their people.
It was dangerous to them to themselves. 'cause if your citizens can see how other people live, if they can compare notes, if they can realize that things don't have to be the way you tell them they do, then that's a problem. Especially if you're a tyrant.
Because once people see what's possible elsewhere, tyrants don't last very long. I'm reminded of Thomas Friedman in his flat earth book. Everybody wants to live an American lifestyle.
They may not want to be an American, especially today, but they wanna live the American dream. And there's nothing matter with that. So what did these tyrants do?
They built walls. They did what tyrants always did. Today, those walls are firewalls and filters and walled gardens, call it whatever you want.
But they locked it down to hold onto power. And soon as people rise up, the first thing they do is they lock it down even tighter. We see it in China.
We saw it in Iran this past couple weeks. But you know what other countries, they didn't lock it down. And when their people saw what was possible, when they saw the freedom, the opportunity, a different way of life that could be possible, governments fell.
And history changed. I was a child of the Cold War. I saw the Berlin Wall come down.
I saw it. I saw the new world order come together. And you know who brought it about regular people, individuals yearning for what we all yearn for.
Food, freedom, privacy, safety, freedom. And for a brief shining moment, it seemed that this changed the internet and this stuff. It changed everything and it made all of that within the grasp of the seven or 8 billion people in this world.
But those days, they seem to be fading fast right now, I'll be honest. And that makes me sad. As the world pulls back from a shared global order and we slide into something that seems more fragmented, more balkanized, our digital lives, excuse me, our digital lives are getting chopped up right along with it.
We've got different cloud, we're gonna have different clouds, different AI stacks, different rules, different internets. Even if nobody wants to say this part out loud, here's the uncomfortable truth. And I can't say the reasons they're doing this are wrong, but we're on, we're gonna be, we're gonna be lesser for it.
Worse for it. Some nations are doing this because they don't want their supply chains held hostage. I can't blame 'em.
Fair enough. Others want to protect their citizens from foreign laws that don't reflect their values. Again, makes sense to me.
And some look at this and say, this is about national security. This is about our very survival as a people, as a nation. And they're not wrong either.
However, it doesn't make me any less sad for what we're losing in this bargain. But I'm not blind to the what's going on and why, why it's happening, it's history. It's more this is humanity.
So I accept it in this new era. Era. Every nation has to have the right to build its own digital fortress.
As I said before, Mark Carney, the PM of uh, Canada. He said it straight sovereignty now means resilience. But let me put it even play planer.
Digital sovereignty today is national sovereignty. You can't be a sovereign nation if you don't have control over your digital sovereignty. But wait, I'm not done.
'cause there's more. Because here's the part that doesn't get said in all of this. Digital sovereignty, national sovereignty talk as important it is as it is for the nations of this world to control their ai, to control their infrastructure, to control their data is just as important for you and me to control ours.
Digital sovereignty isn't just national. Digital sovereignty is personal. And that's why I say digital sovereignty is national sovereignty.
And digital sovereignty is personal sovereignty. 'cause it is personal. Every individual, it's a human right, deserves control over their digital footprint.
It's their data, their privacy, their independence. You shouldn't be under constant surveillance unless you actually have done something to warrant it. Period end.
If you decide, if you decide, and it has to be, you decide to give up some of that sovereignty for convenience because of some apps or services or shiny features you want to use. Hey, that's your call. I may not like it, I may not agree with it.
I think you're making a mistake, but it'll be your decision, not anyone else's. It should never be someone else's decision. Not your government, not a foreign government's, not some platforms decision, certainly not some algorithms decision in this fractured digital future that we seem to be speeding off to.
Sovereignty can't stop at borders. It has to extend all the way down to an individual, to a bubble around each individual. So yes, digital sovereignty is national sovereignty, but don't let it get you that twisted.
Digital sovereignty is personal sovereignty too. And every single one of us is entitled to it. And that's what Shimmy says.
Have a great weekend, everyone. Oh my God, I think, did they, do I get? Good Lord, why couldn't you lower the bar at all?
Something. So I'm in data center and I believe in redundancy and I brought every possible device I could to remember. I could tell you what I do, but then I'd have to kill you.
Alright? That just tells you that I'm boring. I wear black because I like to think that I'm cool and infallible when in fact I'm probably not.
But I'm gonna make you think that today. We'll see how it goes. Alright, thanks a lot for that roll on too, by the way, IRA, I, I, I gotta let you know, IRA and I have been speaking on stages for a long time, for many years.
Probably upwards of about 10 now. And, uh, and he taught me a few roles along the way. We'll talk about one of them a little, a little later on.
But, uh, one of them was always make sure that he has the clicker. So it only took me 10 years. I finally got the clicker and it, and it, what's not even his.
So whoever's clicker it is. Thank you so much. Appreciate you.
All right. So project management. Let's take a look now for, I think it was Dan, this is AI gen.
You're gonna notice my AI generator. I am skilled at prompting not, um, but these, these are not. Now Dan has to sue you.
These are not my images. I am under no circumstances making any kind of money around these images. Um, but what do these guys have in common?
Zero. Zero. Yeah, that's, that's a, that, that that wrong one.
I took the wrong drama mean today too as well. So there's that. Um, that's, yeah, the heroes espionage.
You guys are, you guys are, you know, making some really great comments, but that's, that's not true. Um, what they all have in common is they don't have the last presentation of the day on the, probably the most boring topic of the entire conference. Project management, which I push, you know, probably the excitement akin to, you know, accounts payable, but we'll, we'll work on that.
Um, I blame Ira for my fabulous position in this presentation. And that's okay. You probably did it on purpose.
Um, because nobody wants to do anything else, right? Nobody wants to do anything else out there. I'm gonna leave this picture up so that you can associate me with fun.
Alright, so my name's Dr. Uh, Dr. Tracy Brown.
Um, I'm chief of staff at Stream Data centers and VP of our newly established project management office. Uh, we do a lot of really cool things along the way. Today I'm talking to you about project management, uh, what project management is, why it's important, how we can collaborate in various permutations of the theme project management.
And, uh, hopefully we'll keep it exciting along the way. I'll skip in a couple of action verbs and, uh, keep you awake for the next few minutes. I hope.
Um, let's just say for the sake of argument, to save a little time that my wisdom is akin to a natural wonder and, uh, that is timeless. And we can go ahead and agree to that and just, you know, accept all of my wisdom with without any judgment or, uh, or questions. I'd appreciate that.
And, uh, and we'll get along just fine. Anyway, so Ira and I spoke together for a long time. We, he stole my thunder earlier.
And, uh, we had a, we had a book together that was called, uh, we Can't Stop Stupid, right? You Can't Stop Stupid. And it is, you know, shameless plug available on all of your outlets online and some of the Barnes and Nobles that still exist.
Damn you, Amazon. So, uh, in the spirit of, of moving on, uh, I, I got a lot of lessons from Myra along the way. And one of those lessons that he taught me, which was actually pretty useful, is that if you ever get a slot at the end of the day, make sure that you let them out a little bit early.
Give them all of your content right up front. And uh, and at the end of the day, they're gonna give you brave reviews, brave reviews, and they're gonna think that you're absolutely brilliant and they get a few minutes extra. So here I've done my AI generated photo of all of my talking points.
We'll be talking about project management strategy that spun governance, Tracy Brown, myself, I'm pretty interesting sometimes agile. And, uh, we can probably just kill it from here and call it for the day. But alas, I won't be allowed to do that.
Here's my next one. This is what I had given him originally. I said, project management for CSOs just isn't exciting.
I feel like I'm gonna, I'm gonna recruit everyone on a quest to save the world through a fabulous collaboration between project management and security. And so, like the superheroes you saw earlier, I thought that makes me akin to Wonder Woman, I think. And so the title of this should be I Am Infallible and I can teach you to be the Same, right?
Sure, why not? Let's give it a shot. So this is what my brain looks like most of the time.
I am knee deep of 25 years in project management filled with spreadsheets and raid logs and schedules and priority lists. And it can be a little crazy and a little bit intimidating. And the CSOs that I've worked with will often get stuck on a lot of these charts and it can get frustrating and extremely tedious.
And that is one of the main reasons why it's so important to work with a project management professional who can help you along the way. Not just translate this, but help you play the Tetris game of meetings in your calendar. That way you don't have to worry about that and your SMEs will have time in their day to do what it is that they do.
Now, if you're not gonna listen to me, which is absolutely perfectly fine, it happens every once in a while, especially when folks are prioritizing. Uh, we can go along and try and figure out what's gonna be the most important thing that we'll do. They don't always listen.
And so I just look at them and say, okay, well just keep reprioritizing your projects and hope that you pick the right one and that it goes well. And it kind of feels like looking at a menu at a restaurant that has this expansive selection. And so you wait to be the last person to order so that you can hopefully miraculously leave mouth the words of the right selection.
And sometimes it goes right, and sometimes it doesn't. That's what prioritization often looks like in project management with security. But let's go back to here.
Um, I like these guys 'cause one, they are some of my favorite action heroes, but even more they can teach us really quick ideas on how we can approach project management. 'cause believe it or not, they actually work on projects in their movies. So if we think of, you know, John Wick, he teaches us that all we need is a little bit of focus and maybe a pencil, but focus.
And then Indie teaches us that we need to pick the right thing, the one that has the most value, do it quickly, pick the right project, pick the right artifact, and leave the other trinkets behind. And then Jason Born teaches us that we need to be quick, we need to be fast, we need to be agile, nimble. And then Mission Impossible tells us that we also have projects and initiatives that probably are worthy of self-destruction.
So we need to know when to do that. And then Star Wars is teaching us to stay focused and not go after every tie fighter in the sky. Just like we don't wanna go after every project.
Now let's get a temp for the room. How many of you guys work with project management in, in getting your strategy out there? Okay?
And do you have PMOs in your organizations? Okay, some of them don't. We're acting as a PMO for the Organization.
You're acting as a PMO for the organization. And what happens to your SMEs when you're doing that? They, they feel like they're chicken with no heads running in all Directions.
Absolutely. They're over allocated, they're stressed out and they're not necessarily the project owner, right? They don't have the opportunity to make the decision.
A lot of times they may get confused. They sure as heck don't wanna deal with all of those spreadsheets. And so when it comes to them to try and make a priority list, they may not have all the information that they need or the visibility that they need to make a priority list that's actually gonna work for you and your organization.
And so what does your priority list look like? It looks like this. Everything is number one.
That's a top priority, that's a high priority that is hot for our organization. And everybody has their own idea of what needs to be a priority. It doesn't think the same as security.
Doesn't think the same as operations is legal, is compliant, is design and construction or any other organization that you have within your company. And so, okay, they come up to you and they say not everything can be a number one. Fine, fine.
So we do that. I love it And I've worked on a ton of different ways. And how do we figure this out?
How do we know which ones to pick? Well, we can try sticky notes. I've tried above the line and below the line.
But really we need to figure out which metrics are gonna help us get to where we need and want to go. What is our organizational strategy? How does that bump up against your security strategy?
And what are the numbers associated with that that are gonna drive us forward and make the board happy at the same time? This way when someone comes up and gives you another shiny thing or another top priority, you're not looking at them like this. Alright, so let's get serious.
We're gonna run through, uh, a quick framework and uh, and hopefully I won't take up too, too much time, but this is why it matters. As CISOs, you guys own the strategy, right? You're saying this is what our risk posture is, this is how we stay compliant.
These are the metrics that are important for us. And as PMOs, we're helping you with execution, governance and letting you know what's repeatable, what we can track. And we have a visibility across functions where we can let you know, here's what's working and here's what's not.
So together we have fewer failed initiatives, we have faster results, and we have a sense of security that maybe we wouldn't have had before because we can now prove it and bring receipts. So quick framework overview. We want to translate our strategy to initiatives, establish governance and prioritization, make sure that we have the right approach when we're delivering a project.
Conduct change and risk management. And that's important because everyone will have their idea of what change management is versus risk management. And then make sure that we are showing the right metrics for security and the business and how they relate to one another.
We are going to manage our resources and vendors deliver incrementally and then have continuous feedback and improvement. So first we translate the strategy. So we wanna decompose your strategy into programs and projects.
And for those of you who understand a program is an over our chain initiative with multiple projects underneath it. This is an overarching initiative that says this is the direction that we're gonna go. These are the benefits that are going to happen with the business.
And these are the projects underneath it that are gonna get us there from projects, we develop work streams. That work stream can be akin to a particular functional group. It could be delivering a certain thing as part of the project, but we can decompose that down to make them very simple and task related.
So we go from strategy to tactics. We can help you align with your business objectives. So if the business is saying, we need to lower our click rates by X percent, then we can help you identify what else is gonna help you get there.
And those are using your metrics, your KPIs and your OKRs, or your key, your key, um, numbers. So for example, rather than saying we're gonna implement some kind of an antivirus or a malware, uh, software, we're not saying that we're going to reduce phishing risk by 40%, and these are the numbers that they wanna see, rather than we're gonna deploy an email gateway. So when it comes to looking at strategy, goals, outcomes, et cetera, sometimes it gets a little bit confusing.
Uh, overarching outcomes. These are our strategy or our organizational goals and end results that we want to achieve. Whereas our strategy is the broad approach or a plan of the desired outcomes that we want.
Our tactics are actionable tasks that we're going to take on a daily basis for practical execution. And then finally, we have our objectives. And these are our measurable steps that we'll be able to let everybody know.
This is how we connect our strategy to our projects. But which metrics do we look at? This might give you some anxiety with all those things that I'm sure many of you have to report on, but which ones are the most important, and they're gonna change all the time.
What's important for your board? What's important for the leadership of the organization? What's the biggest threat?
And with an ever changing threat landscape, we need to pick the ones that are most important and focus on those, which leads to governance and prioritization. In my organization, we have a governance program that is the COO, the CFO, the CTO, and then myself. So we'll go through all of the initiatives that are proposed and determine which ones are gonna get us our bang for the buck, what's most important.
And we have a rating scale along with it. So what is the business impact? How much are we going to reduce risk?
What is the urgency? How much effort do we need to put into each one of these initiatives? And then we give it a score.
We'll hand that back over to our executive leadership team, even to the board, and we make a determination about what's gonna be best for the organization, and we'll use this risk and impact scoring model for prioritization. The other thing that we do with the governance committee is make sure that we have a charter. And what that charter is stating is that everyone on the governance committee commits to doing these activities.
We agree that when we come together, we're prioritizing in this way. This is the model we're using, these are the standards we're committing to, and that's the charter that we all sign. Next step is identifying a delivery approach.
And there's some different ways to do this. We've seen waterfall, so it's very linear, very phased approach. One step at a time.
Um, construction is very waterfall. You do this first and then this, and then this, and then that. Whereas with Agile, we have iterative releases.
We understand the business requirements, we go through a development process, and then we, we design, we develop, we release, and then we go back into a feedback loop and make changes as needed. So we can deliver more frequently, but also make changes as needed In a scaled agile approach, where you have a lot of cross-functional teams or multiple functions that are working together, we can use a hybrid model where in some cases you're delivering waterfall, but you also have some agile and iterative delivery in the mix. So for example, if you have an incident response project, you may deliver that in an agile, in an agile way.
However, if you have a heavier project like a construction, then you have waterfall. 'cause agile's not gonna work. Iterative development is bad idea in construction.
However, if you have a larger enterprise organization and they have multiple teams, like maybe a data lakehouse that's getting implemented, so now you have operations in there as well, then you can work at a hybrid model and deliver both. And your project manager will help you select which model is gonna be the best for your initiative. And then with change in risk management, one of the biggest things that can happen here is that when we're implementing something, it might not get adopted.
For example, if you've released say, A DLP effort, but it wasn't used because nobody knew how to use it. Uh, one time I was working at an organization and people were leaving their passwords on sticky notes under their keyboards, you know, all of that. And so they released a password locker, but they didn't tell anybody that it was gonna be released.
You just got an email that said, Hey, use your password locker. And there was no training behind it. Nobody knew what to do.
And if there would've been some project management behind it, we would've incorporated communication as well as training and then behavior afterwards. So we have a follow up to make sure that they've adopted that particular platform, that particular process, and then off they go. Now, one of the things you may wanna consider when it comes to human behavior is performance management.
And this is something we take for granted, and not a lot of people like to think about it. Um, we heard later or earlier someone mentioned who likes year end reviews, nobody, because a lot of times it's a surprise that something went wrong, right? But if you work with the project manager and they're doing a good job, then they can actually work with human resources and your management level to include performance management as part of your plan.
So now you're implementing a particular initiative and you have a follow-up plan with the management to make sure that that behavior change has actually taken place. And then maintain a risk register for both your delivery and your cyber risks. So you have project risks.
If this happens, then this could happen, and we need to figure out how we're gonna mitigate that. But we also have the cyber risks. So what percentage of, you know, phishing emails are actually coming through?
How many people are clicking on something they shouldn't click on? And we, we need to understand what that cyber risk, we can probably use that number generator that, uh, was it Dan had and understand what that potential risk could be in, in different numbers, money, time, et cetera. And from our book, if you get a chance to read that, which I highly encourage you to do because I think it's fabulous, is, um, culture champs or security champs and a few different organizations.
I actually implemented this and it was fantastic. We had one person at different locations who was actually the security champ. And so they worked with cybersecurity to understand, hey, some of these are some of our initiatives, these are the benefits for you.
And they would spread that message. Each of those locations, they were also a point of contact for those folks that were on the front line and security, kinda like a mini translator. And they would help with little nudges and all of that and help reinforce that security culture that we all want.
So secure champs or culture champs have been really helpful along the way. We wanna make sure that we have the right dashboards that are giving the right message. So if we're prioritizing correctly, we've associated metrics to our initiatives, we're doing this particular initiative to increase our, what does it mean to detect, right?
Um, meantime to detect, we wanna be able to have that faster. So how much are we going to increase it? We're gonna do that by 10%.
Our meantime to respond. What have we done? We've decreased that by 10% by implementing this particular thing.
And now our risk has lowered by this amount. And this is what we wanna show in our dashboards Along the way. We also wanna make sure that we are going for our quick wins, because many times your executive sponsors are not gonna be okay with waiting three years for a roadmap to get implemented.
They need to know that there is something happening right now. So let them have exposure to what your benefits are. For example, um, data Lake House project we were implementing, there were only three groups within the entire organization that were ready to have reports in the data lake house and then have those generated because they had everything that they needed in their platforms where the data was gonna be collected.
However, the rest of the organization didn't. There was a lot of work that still needed to be done. So rather than wait a year for us to figure out all of the data sources, we went to those three mature groups, had them fixed and sent into the data lake.
We created their dashboards and reports, and were able to easily come out one and a half months later with a connection to the proper data source, anonymization of the right data that needed to be. And then they had their reports ready for the executive team. And it was quick.
Once the executive team saw that we were delivering and they saw the progress, they were totally cool with letting us continue, and we were able to get the rest of the organization done. Mind you, it took a year and a half, but because we did our stuff right the first time, they were cool with it. So this is herding cats.
This is what our job feels like most of the time, trying to figure out how are we gonna get everybody on the same page and how do we get everybody together despite calendars and holidays and anything that else that might be frustrating with pulling people. Um, but in addition to herding cats, uh, we wanna help your SMEs have capacity so that they're, like I said earlier, not playing Tetris with their calendars and a lot of meetings that they don't need to attend. So when you assign a pm, we're actually your superpower because we act as a force multiplier.
We give them the opportunity to do what it is that they do best because they're the Smee. And as a project manager, we don't have to know everything because we have them and they have the time to go ahead and focus while we're working on everything else. Keeping things together, coordinating not just within your team, but across your teams and also with your vendors, speaking of vendors, your PM can also help you ensure that you have proper vendor management and give you metrics on cost and delivery and make sure that things are coming along.
Because as many of you probably know when you're working with vendors, is they can be at a 90% complete for a really long time until the contract is ready to renew. And then maybe it'll be complete. So they can help you with vendor management as well.
Deliver incrementally, as I mentioned earlier, you want quick wins for quick value to make sure that your sponsors are excited about what you're doing and continue to support you along the way. And then focus on measurable risk reduction per release, right? These are back to our metrics.
What are you doing? What have you done so far, and how is it getting us better? Alright?
Continuous feedback. If you have a roadmap, a strategy roadmap that hasn't been updated in the last six months, but we have an ever changing landscape that probably changes on a daily basis at this point. Um, your, your roadmap is probably an, you know, old and not aging well, like wine or me, no, I'm just kidding.
Um, but more like sour milk. And that's what I thought when I, when I put this gif up here. Um, the other thing you wanna do is you have continuous feedback.
In, in the book you'll see a concept where, yeah, we have defense and we detect and we, uh, respond and we recover. But we need that feedback loop at the end to be able to come back and fix anything holistically across the organization, whether it's technical solution or a process. And so allow your, your project managers who are used to doing a lessons learned, help you along that way as well.
Where do you have gaps? And let them give you the feedback loops that you need to make your processes better. So create a lessons learned library, but don't just shelf it.
Actually go back and take a look at your processes and make sure that they're improving along the way because your roadmap is a living document given all the changes that are happening all the time. So you want to just like Jason Bourne, pivot fast and be agile. So in summary, um, your CISO as you guys and your PMO should be a solid partnership.
We should be working together for you to say, here's the play, and now we go and execute the play. And we work across your teams to make sure that everybody's in alignment, everyone's in agreement, and we have the right metrics and the right numbers that you need to show that you're actually making progress. So for example, if you're gonna give somebody a burn down chart because you're using Agile on a particular project and you say, we've met our velocity, we're doing great, what the hell does that mean?
It doesn't mean anything. We need the metrics behind it to say, okay, we've done, we've done this work, this is what we've accomplished, and this is what it's done for you, the benefit to the business. And that's what your board is gonna want to hear.
So translating strategy into those projects, using the metrics that you need, maintaining visibility so that your executives understand exactly what it is that you're doing and why it's benefiting the business. Um, being adaptive and a risk driven execution so that we are actually implementing projects that are driving down risk and then providing measurable outcomes in the end. Quick overview of framework eight, easy steps.
And then there's plenty of tools and templates. Um, this could actually be a couple hour workshop, but the first thing you want, as I mentioned earlier, a governance charter so that there's agreement for the governance group that you put in place, ah, a project prioritization template where you're looking at the risk and the effort and the cost so that you can make the right decisions. A basic project charter.
And this starts with the problem statement. And this is the part that's most important. What is the problem?
The problem is this. And because of that, this is happening. If you can't put a problem statement within one to two sentences, it's too, it's too big, it's too broad.
You need to crunch it down even more. A problem statement should never be more than two sentences, and that is the basis of your project charter, because that will always be your north star. If you can't break it down to one to two sentences, you will absolutely have scope creep all the time.
And so now you have more time, more cost, and probably less quality for whatever it is you're trying to implement. And then make sure that you maintain a risk register one for the business so that the business understands the risks that are associated there. And one for security.
So we know how we're benefiting security as well. Your RACI is gonna tell you who's responsible, accountable, consulted and informed so you know who your players are in any particular project. And then your metrics framework, what are you doing to better the organization, how are you benefiting?
And then of course, we have these again, how they can easily help us out, right? Focus, pick the right projects, stay agile, move fast, pivot quickly. Know what your kill criteria are for any project that needs to self-destruct.
And then make sure that you stay on target. Here's our book again. There you go.
Ira, I win my $10. I'm Tracy Brown. Um, this is me.
I would love to help you. I hope that this was helpful for you. I think I kept us on track and 10 minutes early.
Nicely. Good. So time back in your day.
Oh my gosh. Thanks you guys. You made me a little nervous.
Oh, you have questions? Yeah. So hiring a security project manager, if anybody's looking by the way, uh, forgot to stand up.
Um, do you think that domain expertise or industry expertise is more important for a security project manager? Excellent question. As a security project manager, I would want to have a little bit of both.
So in my background, because I came in from IT as a network administrator, I understood a little bit about it in the military, which was running years ago. Um, I had a little bit of background there from electronic intelligence. So it was very helpful at American Airlines that I had some security background.
It was able to come in with my project management background and help Dan Glass, who was the CSO at the time, implement quite a few things that helped out the airline. And we worked on all kinds of stuff from implementing MFA to Shaw two on aircraft. Thank you.
Yeah. But for the most part, a lot of times you'll find that as long as somebody is excellent and has mastery around project management principles, being a generalist is fantastic, which is how I wind up getting into a chief of staff. We know a little bit about a whole lot of crap.
Yes, ma'am. Yeah. Just one question about mm-hmm.
Um, we were talking about the feedback loop. Yes. And haven't worked in consulting for a lot of years.
I've noticed that certain organizations are really good at blameless postmortems, whether it's, uh, incident response type situation or if it's a long term project. The one thing that everybody seems to have a challenge with is like taking the lesson and documenting it. Mm-hmm.
So it actually goes, you know, into policy or, or changes some aspect of what we're doing. Like we learn something. Yes.
Nobody wants to really document and even sometimes very high in the organization, lawyers are like, about, about it. What are your recommendations for that? Um, that's actually built into the plan.
So we set the expectation right off the bat, that is part of our change management and behavior or adoption of whatever we're putting into place. We let them know right off the bat, this is part of the plan. This is something that we're going to do, these are the players that are involved that way.
They already expect it when we get to that point. And whether or not it's something that they want to do or prefer to do or not to do, they already have that expectation set and so they're ready for it by the time we get there. What I found is that in a lot of organizations where we don't have that available or they feel a little anxious about doing it, there's a lot of problems with accountability.
Mm-hmm. And so we have to address that along the way. Thanks.
Yeah. Um, I think most of what you mentioned is pretty much fantastic in terms of in principle, right? Most organizations that I've worked with, um, are actually, uh, let me take it back to your previous statement right.
That you talked about having a person who has a fundamentalist of project management. Correct. And getting that person's role mm-hmm.
Is very critical. Yes. Most organizations that I've worked in, um, I've seen it turns out to be a bureaucracy mm-hmm.
Prevent that. You can't prevent bureaucracy. We have to typically work around it.
But again, a lot of this happens in the planning stage, which is why it's important to have a project manager. We set those expectations right off the bat. One of the very first things we need to have is a raci.
We need to know who's gonna be involved and who's responsible for what. Right off the bat, we need to know who the decision makers are, and we can observe who our people will be that could potentially block us along the way. And we make those those known right off the bat.
So if we know, oh, well this person over here in legal is probably gonna try and block what it is that we do, however, this, these two are the sponsors and they're the decision makers. So they have the ability to override. Now at this point, here's what's going on.
Decision maker, sponsor of this initiative, this person is a blocker. And as the decision maker, that's your responsibility to handle it. If not, this is the risk associated to it.
Sign here. Yes. So one thing I've seen at a number of places I've been is that there's a debate on whether or not cyber really needs a dedicated project management.
Oh, you'll get one assigned from the broader IT organization or you know, you're gonna get a loan or maybe it's just one project that you're gonna get it because it's a bigger initiative. What are some strategies that you've seen to help both the CISO and the security organization as well as the broader organization see the value and dedicated project management? From the security perspective?
We bring it back to metrics. Every single time. They have to understand the risk associated to it and the cost associated to it.
So if they're not doing something and it costs them this much and this much time, then they understand that. And if they don't do this, and that's the most important part of it, is if this then that, if this and not this, then this, this is what's gonna happen. If you don't, and you accept that risk and you accept the cost associated to it, and that's typically how will it, what will address that?
But what I've done also is train a little bit with project leads to work with project managers so that they can communicate. And when the PM isn't able to translate the, the technical side of it is best or is, you know, better than they have already established a level of communication that lets them know like, Hey, I, this is where my expertise stops and I need you. And they can, they can have better conversations.
But the metrics, the metrics right off the bat. Yes. So, uh, as part of your, uh, secret staff role, obviously you, you deal with a lot of processes that is repeatable, I assume.
Mm-hmm. And, uh, now we are in the agent AI world, and you are probably gonna be, uh, uh, like sitting down with some founders coming and saying, Hey, I, I can automate most of your grant work with like, whatever, like the sim the sim automation space. Mm-hmm.
Your like PM work is also pretty much Right. For disruption in terms of taking the, Ah, So what is your reaction to that? Like if somebody says, you're gonna build a tool, We can automate your project management, we don't need you, we have AI that can look at our calendars and set our meetings for us.
Absolutely. You most certainly can. We have co-pilot, it already takes notes and all of our action items, we don't need you.
Yeah. Okay. That's fine.
That's fine. Let's see how you do. Because there's still a human factor com, uh, a human component that's associated with it.
And believe it or not, what I've found most, and, and I'm just gonna tell you with a lot of CSOs that are not confident, what I've find that they do is they throw a bunch of spaghetti at the wall and hope that something sticks rather than having faith in their team knowing that they hired the right people and that they have the SMEs in place to actually do the job that they need to do. Rather, they pick up the ball themselves, throw everything at the wall that they can, and hope that it sticks and not hold their people accountable. Right.
Unfortunately. So part of that is also ensuring that you hire correctly, and that is always a human factor. And your project managers will be able to see they have that level of visibility to see how people are working, how they're working together, or how they're not working.
But more importantly, is fire the ones that Fire fast. I believe in that. Other questions?
Yes. Uh, well, just a comment on the, the AI replacing, I mean that my entire, on the federal side had a PM assigned to me. Mm-hmm.
Most of the time they were not really technical expert. Right. I really didn't need it.
Mm-hmm. I need somebody who's highly disciplined Yes. Taking a multimillion dollar project from beginning to end track Kevin, Manny, were late here mm-hmm.
To get, you know, get engaged. Yeah. And in that thing of the, the person getting a hold of the other person, I mean, hey will be able to do that.
Like, Hey, this is Jenny and I'm, you know, that action that sometimes you gotta put, you know, rease on the skin Right. To, to get things going. You Do.
Yeah. I think it's gonna go away. It's gonna be different.
I absolutely agree. I don't think it'll go away at all. It'll absolutely be different.
Will AI help? I've found that AI helps tremendously and so do my project managers. We use it all of the time.
However, that human factor always, um, makes a play. So for example, uh, we don't have an AI right now that can monitor all of the risks that come up in a project. Right.
Or all of the risks that are associated with security across the organization. However, we do have project managers that know how to look at these documents and say, I foresee a problem. Let me escalate this as quickly as possible.
And so, until we can find someone or an AI that can help do that plus be able to understand human behavior, then I, I think I'll have a job for at least another year and a half. Some people are not comfortable with the ai. So if it's an old, I don't wanna say an older guy, I mean, that group AI resemble that remark.
They wanna deal with a person, not some automated stuff. So that's true. You still have to, you know, angle.
Yeah. Yes. Yes ma'am.
Recommendation for how you approach a C-level person who, uh, usurps the priority and doesn't really get that everything can't be at number one. How do I approach a C-level person who ERPs a priority level one? So I'm thinking of an example.
Um, what I've done, just real quick that comes off the top of my head is what I've done is really hold them accountable to the decision that they're making and let them know if this is really how, what you wanna do, then fine. But these are again, the risks associated to it. And then hold them accountable for making that decision.
So like the opportunity cost Of Absolutely. Yes. 100%.
Yes, sir. So how do you strike violence between a purchase risk and the superior risk conflict? 'cause sometimes the risk is risk register themselves A, B, C, or whatever mm-hmm.
On the line put risk timeline, what the conflict regards to completions. Mm-hmm. How At that point, it comes to the business sponsor and it's up to them to determine what their risk tolerance is.
If we have a project risk that def that directly impacts a security risk. So for example, if we don't implement this faster, then our risk for this particular metric is going to increase. I can bubble that up and escalate it as, as quickly as I understand that it's happening.
But then at that point, it's, it's up to them to determine what their risk tolerance is and then we can make the changes. Do we need to put more people at it? How can we crunch the schedule?
How can we make this happen faster? Do we, do we discontinue doing other projects so that we can all hands on deck for this over here? And if they're not willing to make that, then sign here.
Yes. Uh, you talked about security champions somewhere in one of the slides. Mm-hmm.
Um, I've done this in multiple places and get to come up with metrics which we can say are indicative of success for that program. Is that some metrics that you recommend for That that depends on the project that you're trying to get them to? Just the security champion to support?
Uh, just, Just the security champions program itself. Mm-hmm. Oh, okay.
For security champions program, um, I really didn't have metrics associated to security champions. Those are very qualitative. Right.
They're not quantitative. So it was more, we had more engagement. They asked more questions.
People are coming up and, and asking for this, or they're, they're coming to a meeting or they're, they wanna know more about a particular message that's sent out. So very qualitative a good question. Or we can look at the outcomes.
I mean, you cannot attribute only to the, the particular program, but there's the general trending is all that matters. Yeah. You could do that.
But he's saying with security champions, like, how do we know they're doing a good job? Yes. Just a comment, uh, based on your workflow.
Mm-hmm. I didn't see his, uh, sports project operational support, which is, if you're bringing new technology or you're bringing in the process, what's gonna happen after it become a creation that is enough people that we have round books that we have support of. You're absolutely right.
However, that is also part of the project plan that should be included right off the bat. So that's part of the feedback loop. Um, that's, you build that into the project so that you are refining processes, you're building your playbooks or your runbooks.
You are getting ready to operationalize this. A lot of times I have people in operation say, well, what if we wanna run this program? We wanna put a program into place.
Don't we need a project? Okay. I understand.
We're mixing up what you see as a program versus what I see as a project. We're gonna run this thing that you wanna do one time that is a project and we're gonna set you up to operationalize it. That includes all of your training, that includes your behavior adoption, that includes playbooks, et cetera.
So that's part of the planning process. Yes, sir. I just wanna say thank you for the cultural influencer part.
'cause that's a big piece in our area. Yeah, yeah, absolutely. Same.
I've seen great success using culture champs or security champs along the way. Tha thank you. I think you had, uh, you had your own framework for how you are, uh, looking at the, uh, uh, program.
Mm-hmm. Subscribe to any best practice pro like standards like COVID or, uh, like what is your take in general for having a framework that everybody like lives and breathes? Um, I try and keep it as simple as possible.
When I was, when I set up the slide that said tools to use, that's my basics. Absolute basics is agreement with governance and prioritization and using those simple tools, the problem statement on a charter so that we know what our North star is and we can't deviate from that. And we don't have scope creep.
We understand what our risk registers are, we have our races and know the players, and we know who the decision makers are and everything is set up upfront. That's the very basics is what I, is what I are the lifeblood of it all. You Have something specific for security that's, No, you don't need anything specific for security.
We use the same things and, and the the same methodologies. It just really depends on which one's the most appropriate for the initiative that you have. Yes, sir.
Um, any your risk framework or your risk table look like, maybe it was a spreadsheet. You had a bunch of different factors, but none of them were cost. Mm-hmm.
When you were determining your prioritization, is that because cost is not a factor? You Cost is one of the Whatever business case. Yeah.
The time you get to the prioritization, somebody's already asked for the money. Yeah. By the time we get the, we've already done quotes and all of that.
Well said. But that's because you also directed a PMO, so you go, girl. All right.
IRA's giving me the look, which means shut up now. Tracy. Thank you guys.
I hope it was helpful. Hey, everyone, good morning. Happy Monday to you.
I, I love doing these live and I could say the day and it's the right day. I used to hate having to say Happy Tuesday on Monday. I felt, I don't know, it made me feel dirty, but, um, anyway, happy Monday everyone.
We've got a great Textron gang today. Let me introduce you to our, it's really our Monday morning gang, but you've probably been used to seeing them on Tuesdays. We've got our, and our friend Hope Lynch, who is, says she's starring from mostly rain and sleet down her way.
We've got JP Morgenthal, who didn't hesitate to say it was in the eighties at his house near Cape Canaveral and, uh, Stephen Foskett who said, Hey, it's January in Ohio. And of course we've got the Dean Mike Ard. The weather doesn't bother him.
He's, he stays up in his man in the Hightower outfit, uh, set up up there just broadcasting away writing scaries. I Gotta hand you to the crews, man. The roads are clear already, and I'm just waiting for the guy with the plow to come and deal with the driveway.
It's all good. It's all good. It's all good.
I used to, you know what, I used to make a living being that kid who had a Jeep with a plow dealing with the driveways. We used to go to the towns next to, or jp, you know? Right.
You grew up near me. We used to go into North wood mirror, right. I'd ring the doorbell and say, do you need your driveway done?
I thought it was just me with a shovel. Then I'd call my friend down the plow with the, you had a little jeep with a flower on it. 15 minutes later.
It was some good money to be made there. Um, interesting times. Anyway, speaking of interesting times, we live in interesting times, Mike Apple is, I think, maybe rushing out to market.
And I think I know why with, uh, a new wearable for ai, an AI pin. I feel like I've heard this story before, but what's up? That's true.
Other people have talked about this. I think there was a startup that got acquired by somebody, but the notion's been kicked around. I think, you know, this is our first step towards, you know, the, the little communicator on Star Trek where you asked Scotty to beam you up.
But Steven, is there a market for this? What do you think? I mean, are we all gonna wind up wearing these things and will it be, you know, my opinion, we'll talk to your opinion.
How does that work? Well, I I think it's important to know that this, uh, product doesn't exist and, uh, this is all rumors and speculation. Um, so to say that Apple is rushing to market with an AI pin is kind of, um, I don't know, uh, kind of like saying that, um, you know, Trump is, uh, moving too aggressively with his Gaza rebuilding plan.
Um, I think that try to Bring politics into it. I Just had to say, um, you know, yes, there is speculation that such a thing exists. However, just like the, uh, I, okay, how about this, the Republican healthcare plan from 2016 Uhhuh, um, it, it, it's merely speculation at this point that such a thing exists and mm-hmm.
Frankly, um, apple does have the tech to produce a, an AI pin of some sort. Um, but even, even the most juicy rumors suggest that the extent of this AI pin is more of a peripheral for your phone or your watch than anything else. And I think that that actually does make some sense.
Many of us wear, you know, a real watch instead of an Apple watch and might actually benefit from having some sort of wearable device that could be an extension of our phone. Um, I like the idea of putting, you know, a camera in other devices other than glasses and, and, and phones. I think it could be useful.
I think that there's, you know, usefulness to having sort of a network of personal sensors and things like that. So frankly, um, I am absolutely torpedoing the idea that Apple is gonna create basically the humane AI pin, except Apple. I am absolutely boosting the idea that Apple would create a peripheral that would allow your phone to do more and see more and help you more if, if we've learned anything from Apple.
It's that they're not leaders in technology on a bleeding edge, that their followers and that they look to see what works and they try to bring to market something that's actually gonna sell. I think it's important also to remember that Apple is already the leader in peripherals. These guys, if this was a separate company, would be, you know, one of the biggest tech companies out there in terms of revenue because, and, and, and these actually are already a very similar peripheral to what we're hearing from this pin.
In other words, it is a, uh, personal network. It has sensors, it augments what you can do with your phone, the new iOS supports, live translation. All of these, I think, show us the sort of thing that Apple might deliver with this pin.
And no, it's not just gonna be the flopped on its face humane AI pin with an Apple logo. I think it's go ahead, hope. But one of the advantages that you mentioned is it's part of the Apple ecosystem, right?
Humane AI had former Apple execs, but you were outside of any ecosystem, new AI knew everything with a subscription. This makes adoption really easy. So I think they actually can make it work because it is, you know, already hooked in, so to speak.
That's an excellent point, right? I think that was one of the problems with Humane. They had to recreate the whole ecosystem.
Wait, wait, Wait, wait. How is that a Problem? Excuse me, from somebody who's on the Google Android side of the house.
I mean, Need I need I say more. There's still an ecosystem over there a bit, right? There's something.
Well, and, and, and, and I have to, and I have to say, you know, I'm an Android person, but I'm like Android, Samsung, right? Between the two of those, it covers everything. That is true.
Well, there is that, you know, I I, I applaud your fomo being an Android person. I, I'm an, I'm an Android Samsung person too, but I, you know, I remember us thinking back, uh, when to the, you know, when, uh, iPhone first came out and, and thinking about why do you want a, you know, you're using a, a single device to play your music, take your pictures, have your phone calls, and I'm like, and the one limitation to what all these devices is battery life, okay? I'm like, why do you want to limit it?
Why do you want to de, you know, deplete your battery to do all these functions? And I always wondered why a personal area network approach hadn't been created where you just carry around the core of the transmitter in your pocket with a wifi or a Bluetooth connection and your, all the other devices connect to that on your body, A personal area network, right? And you have a separate device like the camera, right?
You know, and I get it. Nobody wants to carry all these things, but eventually they do get smaller. You have glasses now, the video and the, and the pictures, right?
Your music could fit literally on a, you know, credit card thin level device, right? And so I got years ago, but I still always said, it's a stupid concept to deplete your battery, right? Doing all these functions.
And when you, when, when it could have been discreet and you could have specialized, I think we're starting to see the advancements in technology finally saying, yeah, that is stupid. Think about how long your transmitter could go if its whole life was just connecting to the ma ymax and servicing all these other devices. I mean, you would have, you could get anybody else's phone, borrow it, connect it to your pan, and now boom, I have, I I'm still communicating, right?
I'm not, oh my God, I have no cell phone and I have no way to communicate. Right? I am not receiving my mail anymore.
Just so jp, you are the pen man. Go Ahead. If I could jump in on that, man, that is a, an awesome idea, JP.
And I actually do think that that's the direction we're headed. I think you're right that the, the, the, the idea of the personal area network, we were a little early for it back in the, as you said, the ymax days. But now that we have, um, you know, all these low powered devices, low powered sensors and so on, you know, people keep saying like, what's gonna come next after the smartphone?
Like, is the smartphone sort of the naus ultra of technology, of personal technology? I think, no, I think most of us would agree that no, there's gonna be another thing. What is that thing gonna be?
And I think it's what JP ISS describing a decomposed device consisting of a number of independent devices that act together. And like you suggesting jp, I mean, if you had a brick that could sit in your, in your backpack or purse, that was the transmitter and you know, basically the high powered, uh, and the processor, maybe the storage, and then you had all these other devices that could be much, much lower powered. I mean, already these things can last, you know, all day long.
I think that it would be a much more, uh, you know, a, a cool personal vision. It would also open up the doors to new innovation. And frankly, it makes a lot more sense than trying to put everything, fit everything into one device.
Now. Now, I will raise one, one particular risk to why this might not happen. And I, and this may not even be a factor anymore, but when I was an analyst years ago, I toured IBM's, uh, lab up in upstate New York where they do all advanced work.
And, uh, they demonstrated a pan network personal area network, uh, device network. And it's very possible that IBM owns the patents on this concept, which could limit other companies from having done it. And maybe we're past the point where they, the co the, the patent is, you know, uh, defensible or not, I don't know.
Or other companies are now saying, well, I'd have to license technology from I bm Could be. So look, couple things. First of all, you know, do I want 12 different devices doing everything my smartphone does?
'cause let's face it, whether you are on Samsung or, or Apple, how much, how much of time and effort and computing that goes on on your phone on these little super computers we walk around with in our pocket is actually related to phone calls. I right video Calls now, video calls, Video calls, but it, this, I'm tracking my health and my sleep and my blood pressure and my O2 and, you know, a lot of health stuff, a lot of new stuff. It's my connection to the world.
The, I think the, it, this is an age old question. Do I want one throat to choke one device that does all those things? Or do I wanna have 12 different things tattooed to my body somewhere?
But I think you guys are missing the real story here. The real story isn't about Apple trying to get humane, right? The real story is OpenAI announced that the Johnny Ives collaboration, they're gonna have something out shortly.
And I think Apple's tired of being the, the, the, the, the, the la last in the pack on the AI story front. And this may be a way or some sort of ploy to kind of steal the thunder to get out in front of this thing. This is a pattern that Apple has had for years.
I mean, every time they think somebody's gonna get a jump on something in the market that they care about, there's suddenly this magical leak that shows, oh, well, Apple's building something in this area. I mean, they do it all the Time. I, I think that's, that's what's driving this, and I can't wait to see what opened Thing, and, and certainly losing Johnny to a competitor has gotta hurt double.
Yeah. I mean, but who knows what, what's gonna come outta the open AI Johnny Ice thing, you know? So I have a question for hope.
You know, do we think we're gonna get to a world where, you know, well, let's face it. Yeah, you got the wrong pen and you're not compatible with me, so I can't hang out with you, and I certainly can't. Your, your, your pin is the wrong color.
I, I think if, if pens catch on, right, and there is not interoperability, uh, I, I think there could be some snags, right? Um, we, Android users know the, um, implied but not accepted shame, right? Of the green bubble.
So there, there is, you know, maybe there will be some, uh, some social overlay. But I, I just wonder, you know, is, is this the rocket ship that's gonna make it actually work? One thing we haven't discussed is, um, meta, right?
Meta, they've sold millions of units of their glasses. They partnered with Luxottica, so the glasses looked, you know, more cool. So Apple did not say, you know what, let's copy meta, right?
They were like, no, not doing that. Well, It didn't work out so well the last time they did that with the virtual reality things either. So I don't blame 'em.
Exactly. Exactly. They want metaverse.
Great. Right? And what was that, $76 billion, I think, uh, something like that out the window.
But, uh, but I think it is interesting, but I also think it will be a great enabler for people who are not really tech people. Let's say, if it is very easy and you just need to clip on a pen, um, the one thing we do need to worry about then is people walking around even more speaking to themselves out loud. You know, um, people talking to earbuds now, it's, it's not even, it's not even earbuds, you know, just, just speaking to the air, um, as you're going, but everyone is talking to the pin instead of each other.
So we already kind of assume this, but if we all have pins, will we just assume that everything we say is being recorded somewhere, and there's no such thing as privacy outside of the four walls of my house, and maybe not in my house. I make that assumption now, You know, given where we are in this country, I don't think that's a bad thing, and I'm gonna end it right there. Let's come back.
We'll, uh, let's jump to our next, uh, uh, segment, which is around, uh, a new AI constitution. No, not that constitution, Mike. What's, what constitution are we talking about?
Well, philanthropic put out a statement saying that they revamped their constitution, and I wasn't even aware that they actually had one. So I was pretty pleased to see that, their general idea. But I think what they're trying to say is they, they're gonna train their AI to be less, shall we say, obsequious.
They're gonna be a little more helpful in the sense that, uh, they're not gonna suggest things that they, that they think we wanna hear. And that's also leads to some harmful content and some other things here. But jp, is there some real thing here, or is this kind of just public relations?
No, I, I read through the Constitution. It's a, um, think about how far the technology has changed since t they wrote that in 2023. I mean, they probably should have, uh, updated it annually and not the had the gap.
It's the baseline for the guardrails for their ai. And the interesting thing is, there's so much meat there. It's almost like the guardrails themselves are a whole other AI inference before it responds to your AI inference, right?
It a hundred checks. Uh, is it doing this? Is it doing that?
Uh, I use philanthropic. I can tell you that it's gotten better at being more Socratic and not assuming things and just answering you. It is, uh, it, it has improved on its, uh, sycophantic nature.
Uh, it is, but it's still, it, it can stop itself from saying, yeah, you're right. Um, but, uh, but again, it, it's, it's, uh, about, it's about learning. I think it's about all the new models and watching how they behaved and how what kind of, um, risk foxes they're providing and provide some guardrails around that to limit harmfulness, right?
They want, they want, uh, you know, Claude to be more helpful to humans. By the same token, they also wanna limit some of the downside that they've seen of the advancements in the models as they've progressed, and how users can, um, bypass some of the prior guardrails by, you know, tricking the, the AI into answering and responding to things that they shouldn't. You know, I, I applaud anthropic for having a constitution for updating their constitution, you know, all of those things.
But in reading this, I just can't help think to myself, what could go wrong? You know? And that's scary, I suppose.
Can you, and I don't know if you can, but can I adjust these baselines that they've created so theoretically I could tailor Claude to respond differently for my particular preferences? I don't know, gp, is that possible? No, this is the, this is the core of their LLM, right?
So you are, this is about using their inference engine, their LLM, and how it's going to respond. If you wanna do what you're saying, then you need to create your own model and host that and use that to, to get the answers and the type of responses that you're looking for. And I actually think that, you know, over time more, we will see more and more of that.
I mean, we have hugging face, which has, uh, thousands now of baseline models for people to use in order to achieve the outcome. So as LLM start to lock down more and more, we'll probably begin to see people start to leverage the deployment and use of their own models to get the type of responses that have been blocked by the major LLMs Hope. Do you Think that'll happen?
Because, you know, sometimes, at least early on when I was talking to people, they were like, you shouldn't build your own LLM because, you know, by the time you build it and maintain it, the frontier models will be so advanced that you won't be able to keep up and nothing good will come of that effort. And yet, to GPS point, maybe I do need more control over this stuff and be able to customize it. I think it depends on your use case.
What are you using it for, right? If you want an LLM that knows everything about your life, your daily habits, um, that is controlling your home and knows the name of your children and their faces maybe, so, right? Um, that way you have all of those things, um, within your control and within your home.
But if you have larger use cases, those that are more scientific for medicine, deeper research where you are actually benefiting from, uh, the information and the breakthroughs that other people are making, then yes, you are, you are putting yourself, uh, more and more behind. Um, but one thing I do want to, uh, mention that ties into the, to the prior topic. I hate to backtrack, but I must, um, this whether, you know, we can still jailbreak claw the way people have by asking the AI something in a slightly different way.
I think it's interesting, um, that in this constitution, there's actually a four tier, um, hierarchy for Claude, right? Number one, be broadly safe. Broadly safe.
So that is saying don't undermine human oversight, then broadly ethical, then follow anthropics specific guidelines, and then be genuinely helpful to the humans that are involved. This has shades of, uh, films we've seen before, you know, the, the three pets principles, um, for, for robots, but now it's broken down into fork. Um, and what Claude understands about those principles and how it chooses to interpret it over time.
Um, if it swings too far in one way, then maybe someone will say, you know what, um, Claude Open ai, everyone else buy, I need my own personal LLM at home. Mm-hmm. I don't know.
We also hear more about small models. So if I'm gonna go build a smaller model, is that getting easier, jp, and then I can customize it to that end, or I don't really need the big giant frontier model, do I? I I, I, the only thing that's ever gonna make building small models easier is access to data.
The more samples that I can have, gain access to in order to train my model, and the simplification of that process is the only thing that makes building a model easier. You, you, you're not gonna get to a drag and drop model builder, because ultimately what makes the model is the samples and the sample data that trains it. So the fact that there, the availability of, uh, data and the ability to download or access that data through APIs is the, is what's necessary to create and simplify.
Now, you may have your own, one of the things that I came to mind was that I read specifically in, as an example in the Constitution, was that they want to limit things like, uh, complex chemical processing that could lead to development of dangerous and harmful, uh, products byproducts, so bombs, uh, poison gases, stuff like that. But if you're in that business that, and you want to, to use a AI to help you to identify the, in the creation of new products, guess what? You shouldn't be using Claw.
You should be using your own model anyway. And now you're gonna probably lose any access. Claude's is gonna turn that off on you.
You're not gonna be able to use Claw for that. You're gonna have to go and train your own model. And here I was gonna start a new AI company developing nuclear, chemical and biological weapons.
And, and, and, you know, anthropic has just torpedoed that entire effort. I am so disappointed, but I know that IX AI to not have any control on, on That, just Right. Hey, thank you, Elon.
Hey, um, Steven, does it warm your heart at least that, you know, it seems like all this stuff about AI keeps coming back to the same thing data. Well, it comes back to the data, yes. Absolutely.
And I agree with, uh, I agree with y'all that, um, well ultimately, you know, there's different, uh, aspects of AI here, and I think that's kind of what we're all dancing around here. The idea that these frontier models, that we are trying to build a thinking machine, uh, an an art, you know, a general intelligence machine, and that general intelligence is going to need to have guidelines like this constitution to keep it in line. But at the same time, like, like JP ISS saying, like you just asked Mike, you know, um, there's gonna be most, I I think one of the most used aspects of AI is not gonna be these big frontier models, but smaller, more fine tuned, more data-driven models.
And those are the things that we're gonna interact with on a daily basis. And ultimately, I think those are the things that are gonna have more benefit on, on a, on a given day. They're still gonna need guardrails though.
Yeah, but my concern is that, um, well, let's just be very clear. These are not thinking machines. They don't think, they can't exercise judgment because they don't judge.
And so to have anthropic build a constitution that says that their, that Claude should exercise good judgment makes me wonder if perhaps these people are drinking their own Kool-Aid and believe that Claude actually has judgment. Because it doesn't, it is a stochastic parrot who is repeating statistically generated things. It is not thinking, Wait, I gotta end this segment right there, because that was the drop mic moment for Steven.
Excellent. Let's move over to, uh, to, uh, segment three then. Guys in blockchain we trust Mike, what do we got?
The folks who own the New York Stock Exchange and a couple other ex exchanges around the world, or have a pilot project at least to use blockchain to enable people to actually trade any time of the day they want. And I think, you know, we think of the markets today as being 24 by seven, but they actually still open and close. And there's even a, a, a ceremony still in New York that means something to somebody at four o'clock thereabouts usually.
Um, but I wonder if we're moving to a different era here, Alan, and you know, it's starting to feel like, well, you know, wall Street feels like gambling, so what the hell? We might as well have the same kind of experience and we can gamble anytime we want. So why not buy stocks anytime we want?
Well, there a couple things here. First of all, look, you know, a lot of people hear the word blockchain, and they, and they get like a creepy look in their eyes. Their hair stands up because it's been so closely, um, associated with, with cryptocurrencies and so forth.
Blockchain is rock solid, good technology. There's nothing a matter with blockchain other than that. It was associated with crypto.
But the underlying, if you wanna do something in a secure manner that you can trust in blockchain's pretty damn good. And, and at this stage of the game, it's hardly a new kid on the block. It's been true, tried, true and tested.
So I don't think it's anything a matter with developing some blockchain technology to prevent fraud, uh, you know, document these things so that they can't be played with, right? Or, or manipulated. That being said, look, we, we've been doing kind of 24 7 trading, not officially on the New York Stock Exchange, but, you know, with the, the after hours markets and stuff like this for a long time, and I think the big exchanges like a NASDAQ and like a New Yorker, American, they, they, they, they look at that as leaving money on the table, right?
That's money falling out the sides of the wagon. That little guys are just scooping up, you know, gold on the streets by picking up these after hour market, you know, after hour trading markets. But in order for them to go do this, they had to have rock solid security, rock solid, you know, technology there.
And blockchain's the perfect, perfect thing for it. My question is though, won't they need SEC approval for this? You know, I mean, in the current government, it's a bit of the wild west anyway, right?
As long as we keep those crazy people out or whatever. But, you know, is, is this something as a, forget the technology? Yes, we can, but as a society, do we want to have 24 7 stock markets?
I don't think we have a choice. It's gonna be there in other markets, so they have to compete. I just wonder, and I don't know, JP maybe you have some insights to this, but does blockchain really scale?
I mean, you know, historically the challenge has always been the performance and it's okay for Bitcoin, but I don't know if it's good enough for the markets yet. What do you think? I I, I, there are ways to manage performance.
You can pre allocate blocks, so you're not doing block allocation in real time. Um, so there, there are ways to make this technology scalable. I just don't understand why blockchain all of a sudden provides them something that they didn't provide before, or the connection, the, the banks that are connecting to the network to, in order to invoke the trades already have, you know, a, a secure process.
These, they are the ones who, uh, manage and validate accounts. So the only thing, and I'm like, all right, if I, if I doing this, um, I am I allowing in, uh, potentially new, uh, you know, exchange partners who are not banks who could be an individual. I mean, why do I need this?
Now? The system I have works. Why, why does this all of a sudden gimme 24 hour trading?
Whereas before I didn't have it. Um, because all those, all, all my partners that are connected to the New York Stock Exchange today are already validated Trading partners. And remember too, that a lot of those partners are already providing after hours trading.
I mean, you know, I, I've got an E-Trade account and I can trade 24 7 already. I mean, you know, what is blockchain bringing to the table here? I I Think it's the back end of the exchange itself.
It's their records. It's not their partner's Records. I don't Think that's what's being proposed here.
I don't think they're saying that they're gonna put the New York Stock Exchange on blockchain. I think what they're saying is that this partner, which is ironically named ice, I'm sorry, You're right, it Is, if you get a memo about 20, 26 people anyway, um, this partner, um, it is, is going to enable, it's basically another outlet. And at least, and as far as I can read from it, uh, this, the, this ICE company also offers, uh, trading of other assets, uh, apart from the stock exchange.
And they're essentially bringing it, uh, you know, I, I agree with you, Alan, that blockchain is solid technology. It, it, it does do things. It is useful, but what it does is it is a cryptographically secure, um, record of transactions that it doesn't rely on a single actor to authorize and authenticate all of these activities.
Well, what is that? You know, I can see that that would be useful in a stock exchange scenario. Is that what this is being used for?
Or is this actually just a centralized version of that? And if it's centralized, then what is blockchain bringing to the table? Nothing.
Yeah, my, well, like He said, we could do this with a freaking SQL server. We don't need a blockchain to do it. The thing that this could and would make sense to bring to the table is immediate settlement versus t plus three or T plus one.
Okay? And I don't know if they feel like that's a requirement in order to move to 24 hour trading is immediate settlement. So there's no loopholes and, uh, that people can take advantage of as, you know, like, uh, I just did a trade in, uh, Tokyo and now I'm gonna flip back and do it in the us and before Tokyo can even settle, I've now taken that money out kind of stuff.
Maybe the fact that they realize that that loophole might exist, this would give them immediate settlement. That's the only thing I could imagine as to why this technology would be valuable. But I, I agree because from, from the bit that I read, right?
Um, multi chain support, which means they're building in abstraction layers, right? Decoupling the settlement from trading. And then, um, bank of New York and Citi, they're involved in tokenized deposits.
And for them it's about solving the money movement problems. So if you have traded a security, you still need the cash payout portion, right? The New York Stock Exchange is not the one actually settling and giving you your money.
So if the trade is settled at 3:00 AM on a Sunday, regular banks are closed. This now enables you to get tokenized, um, deposits, stablecoin funding, and it, and it solves that problem for you. So, um, this, I I think you're dead on.
What's That? I said, I think you're dead on. Yeah, well, yeah, it's been years since I've, you know, done, uh, securities operations, but, and, um, I actually built systems for securities operations back in the day, and somewhere in here, the Depository Trust corporation used to be involved.
I don't know if they're still involved anymore, but I would imagine that clearing it, that DTC has to be part of this. The DTC has to be included in this blockchain for verification of that settlement in order for it to be valid. Unless things have changed beyond my knowledge, I don't mean, well, that's What you're getting at, is that basically the stock exchange is supposed to be something special.
If it's just trading stuff like anything, then, then who cares anymore? And we might as well just get rid of the SEC. And you know what, Steven, that was exactly my thought.
You know, Mike, Mike Ard, you'll appreciate this. I, I'm old enough to remember in New York City when OTB came out, Remember OTV Off you remember too, Joe? Oh, Yeah.
I loved them. Yeah. They were off track betting all of a sudden, instead of getting on the phone with Angelo or Nick or someone and saying, Hey, I wanna, you know, I wanna put $10 on the number four horse in the second, an aqueduct or something.
Right now, we went to some storefront where you had a bunch of degenerates with pencils in their ears. The racing forms always cigarettes with long ashes. Like it was, it was disgusting in there, let's face it, right?
With clients sports coats. Yeah. But, but you could go up at any time in the day that it was open and you didn't have to call Angelo or Nikki no more.
You went on the windows. I wanna, I wanna do a trifecta on this or whatever over there. And, and, and some people thought this was the greatest thing to civilization.
We're gonna put the organized crime out of business. Isn't this great? You could bet on, on horse races around the country, not just Belmont or Aqueduct anymore.
And it was a blight on civilization, right? I'm wondering if this isn't, maybe not quite that bad, but is this, is this the same thing? Well, Somebody made a point earlier about, you know, trading different types of assets.
I, I, I got a note yesterday from Rob Robin, I haven't touched my account in a long time. It need to verify that I'm still alive and that my, you know, I guess they wanna steal whatever small funds I left in there. So I log in, and now the big thing is, and I've seen this in other places like DraftKings, and as such, the big thing is prediction markets.
But Robinhood sells them as contracts. So for 63 cents, you, uh, uh, you can buy a contract that says that the Seahawks will win the Super Bowl, and then, then that contract is then traded on the open market, people can buy and sell it. Um, that's how we, that's what gambling has now become, where we're tokenizing the, uh, gambling people are buy, you know, buying contracts to which side of the, uh, bet they wanna be on.
And then they're trading those. And frankly, it's, it's gambling. It, it's, It's o TB over again As meta gambling.
I think JP has come to it. This is the point, the quote Mark Twain, you know, a lie travels halfway around the world before the truth gets its boots on. This is gonna play out time and time again.
Or if we're gonna have constant training, there's no moment to anybody to take a breath and go, well, is this true or not? So there's just gonna be more b******t circulated, trying to move stock prices left, right, and center, and things are gonna spin outta control. I, I have a question.
So the New York Stock Exchange, they're building a separate tokenized platform, right? So blockchain-based platform that is trading alongside, but separate from the traditional exchange. Nasdaq, though they have filed a proposal to integrate tokenized securities into their existing exchange.
Same order book, same execution, priority, everything. Which one do you think is gonna win Nasdaq? Because it preserves the status quo.
Mm. Is it, it fails quite often in this market when you try to do something new and unproven. Whereas the old guard likes the way that things work today.
They know it, they feel comfortable with it. Integrating in and making sure that it flows alongside the way things are done today, I think have an advantage over something completely new and different. Mm, Fair enough.
Guys, I gotta pull the plug. What a great, because, you know, until we implement some blockchain here at Dextron gang, I don't know if we can go 24 7. I I will.
Let me add one last thing, Alan, go ahead. Tokenization of assets is huge. Um, I did a lot of this work, uh, when I was, uh, a, a, a magistrate consultant, uh, helping out digital assets group, right?
The, uh, thing about, uh, digi digitization or tokenization of things like mortgages, okay? Where I I, it allows, um, you to take, uh, a rental property and allow a group of people to then buy a piece of it very easily in a way that's controlled, right? That these are things that are very, very difficult to do today.
You can't have just a, you, I mean, you could create an LLC and a bunch of people put money into that LLC and then, you know, the LLC buys the building. Um, but this is a way that a, uh, group could say, uh, you are buying into funding, uh, you know, this particular rental property. Here's the, uh, here's the information about the property, our expected rental rates.
How much? So yeah, I wanna buy two shares of that, right? And I get paid back monthly based upon, uh, the rent getting paid.
I think it tokenization of assets paint. Our artwork is being tokenized this way. Mortgages are being tokenized this, but I think it opens up the opportunity for more individuals to get into and play in an arena that has typically been shut out for Middle America.
Fair. Fair. All right.
Hey, Steven, don't you, do you got something going this week on Tech Field Day, don't you? I do. And it's actually going here, uh, right here on the Techron channels as well.
So we've got our AI infrastructure Field day, uh, this week. So please do check that out. Wednesday through Friday, we're gonna be live during, um, basically 8:00 AM to 5:00 PM Pacific time, uh, with a bunch of different presentations.
We've got Cisco Fabrics on Wednesday, along with, uh, the Futurum, uh, group presenting some of their, uh, research findings on, on on Wednesday, on Thursday. We've got Hammer Space, uh, ex site labs, uh, forward networks, and, and, uh, another presentation from within the Futurum group, uh, from the Signal 65 Lab Group. And then on Friday we've got solid I, and we're gonna hear from the delegates.
So do check out, uh, the tech field day presentations, streaming live on the Textron TV app on YouTube, and of course, uh, LinkedIn. Excellent. Good luck with that.
All right. Hope Great seeing you. Stay warm, safe there, jp.
Keep the AC on. I guess, Mike, we won't have to after tonight, I hear. Yeah, It is also true.
Well, us too, Mike. I'll see you hopefully here tomorrow. Absolutely.
All right. Hey, we're getting closer to pitchers and catchers reporting baseball seasons here, though. We've got a Super Bowl coming up.
We'll be talking about that maybe. But until then, stick still with the Yankee. There you go.
That's absolutely right. All right. I hope you've enjoyed Text and Gang today, everyone.
Take care. Bye-bye. Hey everyone, welcome back here to Techstrong tv.
You know, I had the pleasure of meeting this fellow right here. We were out in, uh, in Vegas for RSA reinvent in December, and he came up to our, uh, suite that we had up there. We did a, a quick interview.
It's available on Techron TV and Techron Ott if you go to industry events. But I wanted to follow up with him 'cause I, I love the story. I love the energy, I love the passion he brings to his role as CEO at Zest.
Let me introduce you, my friend Sneer, Ben Shimo. Sneer is coming at us from Tribeca today. My, one of my favorite places, old Haunting Grounds.
Um, sear, welcome back. It's good to have you on Tech Drunk tv. Good to be back, Alan.
Thank you for having me. My pleasure. So for people who maybe who didn't catch the, uh, reinvent interview, give let's, you know, let's reinforce, give him a little bit of your background, kind of how you got to be CEO of ZE security and, and more importantly, maybe not that you are not important, but more importantly, the what, what is ze security about?
Yeah, definitely. Uh, so I'll do it short. If you want to hear more, definitely go to the previous episode, as you mentioned.
Uh, so sne al, A CEO, uh, and co-founder of the security, um, long, long, long, um, journey in cyber security, uh, from offensive research and so on. Uh, recently, uh, before, uh, building zest, uh, uh, build cybersecurity with a few of my friends, uh, to solve the application security, uh, problems, and sold the company to Palo Alto Networks. Uh, that was in 2022.
And before that, uh, built from the ground up and heads up all cybersecurity at Varonis public traded company in charge of, uh, product, product security, incident response, forensics, uh, security research and everything against insider trade and data tests. And before that, again, different type of security roles, CISO roles and so on. So I like to solve problems, and this is like in Varonis, we solve the data problem cider, we solve the application security problem.
And at z we're solving the vulnerability and exposure management problem, which turned to be the number one problem today. Uh, like as, as you can tell, uh, since 2024, it was the first year that vulnerability exploitation, uh, suppressed, uh, phishing in, um, uh, initial access in attacks. Uh, you have so many vulnerabilities.
And today with the ai, so easy to use AI as a researcher and find zero days and then publish vulnerabilities in 2025. We just started 26, but you can look on the previous year, just 2025 alone, there is an increase of over 22% of new vulnerabilities introduced to the market, which over 60% of them are critical, like CVSS nine. That means that, um, low, um, complexity of exploitation, high impact, and how probability, which is crazy.
So if we're thinking about it, um, the most attractive way to hack your organization is by exploiting a vulnerability or misconfiguration, uh, the number of vulnerabilities increasing year over year for over 20 or 30%. And most of these vulnerabilities are weaponized and exploitable. And you take that and you add to it the problem that we experienced, uh, my co-founder led vulnerability management at Akamai, uh, and we experienced that it's not only millions of new vulnerabilities coming in and increasing the backlog, uh, triaging and remediation of these vulnerabilities, 100% manual.
So imagine you have this amazing security tools that you, uh, purchase that gives you all the great visibility to your problems, a lot of vulnerabilities. Hey, we scan this, scan your AWS, we scan your Azure, we scan your service on-prem, and we have all these crazy vulnerabilities. What should I do now?
What can I do with millions of vulnerabilities data from different tools? Uh, orchestration started and it's nice, but it's just like a one list, really one big list of problems. Uh, what about remediation?
What about prioritization? We realize you cannot automate it. Every vulnerability is different.
Uh, every remediation is different. Every, every service is different. Every service is different.
It's like you can't automate vulnerability management and vulnerability remediation as the world chief and organization kind of asking, how can I reduce risk, not only manage it, um, there is that problem. It's like, Hey, we realize we cannot handle the numbers and we cannot automate. So what can we do?
We're stuck like that for 15 years until AI came in, and this is exactly what the security is, we're taking vulnerability management that turned into exposure management that basically failed everyone of backlogs, right? So that means that we're doing something wrong. And, uh, we introducing for the first time, uh, in 2025, we introduced iGen exposure management platform.
That means that you can now leverage AI agents to do all these scalable deterministic analysis of millions of vulnerabilities your organization needs to handle in a very smart way. No more scoring, no more guessing, no more manual work, manual labor. No, no more.
I need 20 or 30 more people to throw over the problem. We using this agent to actually look into this vulnerability and to give you one answer, do I need to fix it or I don't need to fix it. And that's exactly the AI sweeper agents we announced they exist.
So the way we're helping our organization that we're working with and our customers is we're removing unex exploitable unreachable vulnerabilities from their backlog automatically. And we're simulating remediation to find the best path to actually remediate the vast majority of the vulnerabilities. Um, I think today we reached a really, really big milestone at Zes that we can sweep the unex exploitable vulnerabilities all across cloud and on-prem autonomously.
And that's a big thing to say, no human action, no human in the loop is needed. Our agent will go and we'll give you one or zero. Do I need to fix it?
Or I don't need to fix it? The results are really, really interesting. Absolutely.
You know, Steve, I'm listening to you talk about it, right? Started a company in 2001, still secure vulnerability management space. Hard to believe 25 years.
We're still talking about the same problems. This, this pattern you've described of there's more vulnerabilities this year than last year. The fact of the matter is, most of these vulnerabilities, they're not necessarily sophisticated, you know, in, in terms of, of what you have to do to exploit them.
They're, you know, and, and, and still year after year, you read the Verizon data breach report and you read, you know, these, all of the vulnerability and security reports that come out around RSA every year, right? Um, something like 75, 80, 80 5% of the, of the incidents aren't even zero days. They're not unknown vulnerabilities.
They're actual, like garden variety vulnerabilities that, or misconfigurations that people just like sloppy, sloppy. And, and you know, I'm hoping that as much of a tool that AI is in helping the bad guys to find new vulnerabilities to find zero days, it'll also at the very least, help us clean up sloppy, right? Because if we could clean up sloppy man, that's a, you know, hundreds of times better than where we are now, and then we could worry about the, the really bad stuff, right?
That sloppy isn't, it's not sloppy, it's just, you know, really bad stuff. Um, before we jump to the next portion of this, for people who want to get more information about Zest, where can they go The best? Like we have two places that we're really active and always updating.
io. Uh, this is where we're publishing our webinar blog posts, research, product announcement and so on. And you can read about the AI sweeper agents there.
And our LinkedIn page is pretty active as well. We are building communities. We have a lot of, uh, uh, round tables, security executive events, uh, mostly in like New York, Boston, San Francisco.
So our LinkedIn page is really, really, so just look for ze security in LinkedIn and look for me in LinkedIn if you have questions or you think AI is a fairy tale and it cannot solve their problem. So I'm happy for you to challenge me. That will be great.
Absolutely. All right, ssir, let us turn now to something. You guys are calling ai sweeper agents.
Talk to us about that. Yeah, I think, you know, before you, you're starting to fix things and before you're starting to remediate your problems, uh, would it be nice to kind of like clean up the, the table? Would it be able to just remove everything that is not relevant?
And, uh, this is something no one was able to do until now. It's like when we thought about it and it was like, okay, is it guest woke? Is it something weird?
It's like, Hey, if we can have infinite amount of security engineer, just infinite amount of security engineers, and ask each and every one of them to go per each and every one of the vulnerabilities are scanners identified, if it's in the cloud, and if it's on Preem, if it's in the product, and ask this each and every individual security engineer, if that specific vulnerability, it's even a risk based on our environment content, right? So that can be a very bad vulnerability. The vulnerability can be kind of existing in my environment because the scanner identified that I'm running a vulnerable version of something or a vulnerable service or a vulnerable configuration.
So it's there. Now the question is, is anyone remote, local insider can do anything about it to weaponize that vulnerability? And that question is the first, I will say the first stage of eliminating false positive or kind of like reducing that be this is what security engineer is doing.
And of course, they cannot do it for minutes, but let's assume that we have no number problems. We have security engineer vulnerability. So our AI sweeper agent, their sole purpose is to clean up, is to remove, is to sweep out everything that is not relevant.
And they're not doing it by looking on, oh, this is only medium. So in our, in our company, medium is not that important. Let's sweep it out.
No, they're not looking into it. They're looking on pure facts. What does it mean?
Facts. You have a vulnerability. In order to anyone to exploit his vulnerability, he needs to have some kind of requirements.
The vulnerability of requirements for exploitation. You need to have this type of permission, or the vulnerable asset needs to run in a specific way, or the vulnerable, uh, asset needs to sit in a network or environment that's allowing some specific things. If one or many of these things are not present, there is no way this vulnerability can be weaponized and exploitable to answer this question.
You cannot just scan and say, I have a vulnerable, uh, a vulnerable version of this and that, that's what the scanner is doing, giving you visibility. Now you need to do the analysis. So what are AI sweeper agent doing?
Are mimicking a person, a really senior security engineer that takes that vulnerability, understand from the vulnerability information, what the vulnerability require to be exploited, and then take that requirements and compare these requirements with your environment. Is this requirement being met? Yes.
You probably need to fix it or prioritize it in the next stage. If this requirement's not being met, let's sweep it off. So that sounds like pretty straightforward, right?
It's kind of complicated because there is no automation. Every vulnerability is different. You need to understand which vulnerability is it, what's the vulnerability required?
And then you need to look on different type of things in your environment, like network and permissions and, and, uh, the policies, and then understand if you can sweep it or not. And what we realized, and we publish it last week, we, this specific agent so far all across our customers, and now it's like fully ga sweeped out over 11 million vulnerabilities that most of them are high and critical for the organization. They just told the security team, don't worry about them.
You see all these things that you worry about. You don't need to worry about it anymore. This is the fact, this is the truth.
They're not exploitable. It's all good. Don't focus on them, don't look at them, sweep them out.
So just imagine you run this agent and you wake up in the morning and 90% of all your vulnerabilities, the things that you were about 90% are gone. So you left with couple of hundred of thousands. If you're an enterprise, 10% is pretty, it's still a lot, right?
That's The next, but it's only 10%, But it's, it's better than, than millions, right? Yeah. It's like really good first step.
And that's exactly what the agents are doing. Removing and cleaning up the sweeper agents, specifically just cleaning up 90% of things you think that are important for you to look at. But they're not Excellent.
You know, this is something over the years, I, I've seen companies try to do this, right? Because you used to have, is it exploitable? Is it reachable?
Is it, you know, is it real? And these kinds of things. The, the, it's, it's a question of scale, right?
In the past, yes, we could do that analysis, reachable, exploitable, is it truly a vulnerability, if you will? But to do that, as you say, on a million vulnerabilities, you don't have that kind of bandwidth. I mean, this, this really is a job that calls for ai, right?
That could do it at scale in a, in a, in a good timeframe, right? And the timeframe to make it useful, um, these are available now, they're just coming out. What's the story?
They are, they were available to our customers for over three months. And right now we just publish that specific, uh, capability that is a complete GA enterprise ready AI sweeper capability that everyone can enjoy. And, um, thanks to our kind of early adopters of the AI sweepers, uh, we wanted to announce about it because most of our customers are highly regulated, mostly PCI for example.
Uh, you have different level of regulation when the auditor is coming. And it's like, who, who is this? Who sweeped out 90% of these problems?
Like how dare them? You need to fix them. And, uh, we announced about the AI sweeper agent only after these auditors kind of ask us, can you please tell everyone that there is a tool that can make our life better and the customer's life better?
Because at the beginning, they're kind of like, how you remove all these backlog of vulnerabilities? And when you, they looked on the reasoning and facts, they're like, this is, this is genius how it's not existent. Like, it, it saves so much time.
It saves so many fights between us, the regulators and the auditors with the securities. It's like, you need to fix it. And the security, no, we don't need to fix it because it's like, right now they just need to look in our platform and we share like a small kind of screenshot of that specific, uh, feature how it looks like.
So the auditor clearly see that this is the vulnerability, this is what required to be exploited. This is the evidence from the environment that one or two or three of the requirements are not there. And there is no argument, there is no conversation to be made.
There is just, there are just facts. So once we got this very strong validation also from third party auditors that, that our customers send them, it's like, Hey, this is why we sweep them out. Then we realized that this is the time that we 100% comfortable to tell everyone we can actually sweep and clean up these vulnerabilities.
Absolutely. Excellent. io, correct?
Right? Yes. That's the best place to go.
Also, the LinkedIn page. Sneer, I love what you're doing, right? This is a space I know.
Well, I, I hoping to see more and, and, you know, your success is a success that we need in the market to solve this problem. So keep up the great work, man. Come back.
Maybe I, I don't know if you go into RSA, maybe we'll get together in person there. Definitely. Like everyone needs to go to LSA, even if they want to or they don't want to.
But yeah, we are going to be there with the entire team. We have some meetings, we have events. And actually I'm excited to meet people like you, Allen, like people that can be during conferences.
So yeah, Definitely. Absolute well, we'll be, so Monday we put on, it used to be the DevSecOps event at Moscone Center this year it's AI native or securing AI native dev. Mm-hmm.
So it's, it's more focused. Well, it's focused on vulnerabilities, pre-deployment, but with feedback loops and everything else. So we're doing that Monday and then all week we're it, uh, broadcast alley, doing live all Week.
Amazing. Yeah. Let's Talk, let's meet another, I'll make sure I see you Another, definitely.
I thank you so much. Thank you. Are we good?
From Shial to shiel? What can I say? We'll see you next time.
Good seeing you, Nia. We'll see. Good to see.
Good luck. You Too. Thank you so much.
Cheers. All right, Bye-bye. We'll be back with more on text drug TV here in a minute.
I am Mitch Ashley of the Futurum Group, And I'm Scott Roon with solutional. We're here today to give you an overview of the Nokia Data Center Fabric reliability study, a survey that addresses some key issues in modern data center networking. We ran a research survey of a hundred IT infrastructure leaders from large enterprise IT organizations with the goal of understanding how data center network reliability is decided, what's delivered and measured both today and into the future.
Mitch and I want to cover three main takeaways in this video. First, reliability is the number one decision criterion. Second, operational challenges, especially human error, still drive incidents.
And third teams claim meaningful automation, AI ops, adoption. And we wanna unpack that a little bit. Yeah, three important messages.
Number one, though, reliability is not a nice to have. It anchors the design, the design, the operations, and ultimately in the business outcomes. Resilience is the end game.
Yeah. Not a huge surprise, right? That reliability was the top priority.
Um, there's some interesting supporting stats that go around that. Mitch, can you talk us through 'em? I think first of all, 86% of the respondents ranked reliability as a top decision criterion.
So it wasn't just, uh, just above the midpoint. It was well almost, you know, get, you don't get 86% in, in responses for very many questions. Uh, and the things that, that it was sat on top of were the ease of integration operations.
We know those are also challenges. So why does this matter? A single hour, hour downtime is a widely expected to hit service levels and also revenue.
So 47% foresaw a major service disruption risk, a 68 expected direct revenue loss. So it's a big deal. 74% of organizations said they had greater than one incident of an outage in the past 12 months.
So it's not a rare occurrence, um, when we see that many organizations saying they're having at least one out one outage a year, and that can be due to hardware failures, human error, those are common top causes. So now regarding human error, let's talk a little bit about that. We saw that amongst, um, multiple operational challenges, um, that drive those, uh, that drive the outages and incidents that we're seeing.
What, um, more is underneath those statistics, Mitch? It's a significant factor. I mean, the, the respondents rated it 80% said that human error impacts service 17 point half percent, called it a frequent top cause, things like that.
So it's certainly just more than a factor. It's an important aspect of when there is an outage, but it's also more than that. Um, there are often other failures that come alongside with human error at some point in that process.
They can be things like hardware or software failures. So how do we address this? When we asked the respondents, 35% said that they emphasized strict process and training.
25% said focus on resilience and recovery. Recovery, and only 12% said they aim to eliminate errors via automation. Meaning we know that errors are gonna happen, but we have to be able to handle those, respond to those we wanna resilient architecture, implementation, and also as well as the implementation or the automation that we're doing.
So, you know, teams are struggling to meet the evolving needs of the business because we know those are under constant change and also limit the scope or run extra planning cycles. Those are things that they're struggling with. Oftentimes, they'll even postpone important tasks due to confidence levels, uh, when they're not sure if that's something they're ready to implement or if this is the right timing to do that.
Last but not least, of course, skills always come up, but it's a significant gap. 54% said that that was skill gap was an issue, and several incited cited that state versus desired monitoring limits were a factor as well. So on the implementation and use of automation in AI ops and the actual adoption, um, versus interest in automation and AIOps adoption, what did you find in the, in that bucket of responses?
Well, they, they said that here's what they're using today. Uh, a 67% said that they're using automated monitoring. 50%, actually 58% said they're using infrastructures code.
I particularly found that interesting. And of course, that's, uh, you know, followed by things like ticketing, auto failure over, but ai, ML based incident prediction was pretty significant at 54 4%. So I think this says that we're investing in ai, ML is part of the, the solution set, but also I think we know that, you know, tooling does not necessarily equal positive outcomes.
Only 36% reported dedicated AIOps tooling as of now. And many are advanced practices are still in the maturing stages. So, you know, adoption is both planned and underway, but separating tool and use from operational reality gains is still key.
Yeah, that separation, uh, and, you know, that fine, fine grain understanding of are we just interested in automation and AIOps versus we're really, you know, going full force. We're gonna see that journey continuing, I think for years with many enterprises really just getting started in earnest. Definitely tracks agree with you So much that you covered in, uh, in this survey.
We're only touching the tops of the trees here. Where can people go to get the full report and, and plow through this and understand the full picture? com and download the report from there.
There's a section for analyst reports and the latest analysis that we've done. We'll also include a link with the video to make it easy to go right to the report. It's free, download it, you've got, you'll in seconds, you'll be looking at some really compelling and interesting information.
Definitely agree, Mitch, thanks for the pointer and for the readout. You bet, Scott. Thank you.
Hello, and welcome to the latest edition of the Techstrong AI Leadership Insight series. Today we're with Mike Miller, who's director of AI product management for Amazon Web Services. And we're talking about well trustworthiness when it comes to ai, which can be automated with some math apparently.
Hey, Mike, welcome to show. Hey, Mike, thanks for having me. Glad to be back with you.
All right, so explain if you would, I mean, we're all talking about trustworthiness when it comes to AI and everybody's concerned, especially with AI agents, but I think we have a thought in our heads that somehow rather this can be done with some other external magic thing, but maybe it just requires good programming and some old fashioned math and reasoning. So can this be done and how can it be done? Yeah, I, I would say kind of all of the above and, uh, you know, I I, I'm super excited about this because as, as you or your listeners may know, uh, yesterday was World Logic Day.
And, uh, logic is really the foundation of, uh, a lot of the kind of tools and techniques that we're gonna be chatting about today, uh, about how you can, uh, improve trust awareness of AI and of AI agents. Uh, and, and if you, you're kind of thinking like logic, like wait, like high school geometry, what is, what, what do we mean by logic? And, uh, logic actually like kind of imbues our life every day.
And we, we use logical, uh, deductions, um, and logical inferences all the time. So if you think about like, uh, it rained yesterday and overnight, it's gonna drop below freezing, therefore I need to watch out for, you know, ice on the sidewalk, right? That's deductive reasoning.
It's kind of taking these sort of logical statements and putting them together and then reaching conclusions, uh, that, you know, are true because of the sort of inference capability. And so that's kind of the same approach that we take, um, with this, uh, technology called automated reasoning. It's this new, it's, it's actually not a new field.
It's actually been around for, for many years. Um, and it attempts to use mathematical logic to provide assurance about what a system or a computer program will do. And that assurance is based on mathematical proof Hmm.
And get the concept. But, um, how much skill does it require to implement this? And do I have to be a rocket scientist or is this something that a mere developer or your average data scientist can wrap their head around?
Yeah, that's actually, uh, one of the really, uh, interesting, um, implications of AI and machine learning that we've seen, and that in the past, um, you know, AWS has embraced, um, automated reasoning for, you know, the past decade. And we've had to bring on board, uh, PHD scientists who, you know, spent their life sort of diving into this mathematical logic and reasoning and understand how we can represent computer programs in this mathematical format. And one of the things that we've seen is with the advent of, uh, LLMs and sort of generative AI, is that that task has now become a lot easier putting this technology within reach, uh, of your common developer.
And so what we're working on are capabilities that start to imbue, um, our products with automated reasoning. And this combination of, uh, generative AI machine learning and automated reasoning we call neuros symbolic ai. 'cause it combines the two sort of elements, the statistical sort of prediction kind of elements of AI and these mathematical sort of symbolic reasoning elements of AI and, uh, and coming together to kind of enhance, um, the capabilities and, and drive truthfulness, right?
Because if you think about the world is moving to AI agents, um, you know, and these AI agents are becoming more complex. They're handling, uh, more independent tasks, they're taking actions. And so we're gonna need to feel a high level of confidence that these agents are operating according to, like policies or rules or guidelines and making the right decisions or preventing them from making sort of, uh, the wrong decisions.
And this is where neuros symbolic AI can kind of come into play. Didn't we just simply forget about this AI discipline? It sounds like symbolic ai, I, I seem to remember hearing about this before, and I, I certainly know that reasoning's been around for a while and mathematical proof.
So did we just overlook all this and are now rediscovering it, or where Well, no, it's, you know, it's actually been used for quite a while, but because of the sort of specific detailed skills needed through the science application, it's really only been useful for the sort of most high risk kind of, uh, tasks like, you know, constructing software for the space station or managing rail networks, things like that where the cost of a, you know, mistake was very high, where it was worth investing all this time, um, bringing these scientists on board to build these mathematical representations and make sure that we could prove the correctness of these systems. But generative AI has allowed us to really massively accelerate that, um, and create these sort of mathematical models in a much easier way. Um, and, and that's kind of what we're doing here at AWS now is taking that decade of experience, um, determining where the right places are, where we can apply this automated reasoning and then getting those into the hands of our customers.
Mm-hmm. So how do we know or validate something? I mean, I get that we can do it with the reasoning and, and programming, but at some point, will a third party need to validate the math or how does that kind of work?
Yeah, like, let me give you maybe a, a a quick analogy and then we can talk a little bit about how, how you can sort of audit these things, right? So if I think about, um, you know, back to geometry, your right triangles, right? Euclid 2000 years ago, sort of reasoned about right triangles, and what he did was he proved, uh, the Pythagorean theorem, A squared plus B squared equals C squared, right?
The lengths, the, the, the lengths, the two shorter sides of your right triangle when, you know, squared and added together equal the length of that longer side. Um, and what he did was he proved it in a way that allowed us to, uh, understand that that was applicable to the infinite number of right triangles. Uh, because you could have gone about this and said, well, let me examine, you know, hundreds or thousands or tens of thousands of right triangles and kind of estimate what the relationship is between these sides.
And that's kind of how machine learning works today. You give it a bunch of training data and it sort of starts to generate, um, you know, predictions about, about sort of, well, the questions that you're asking, whereas reasoning in mathematical logic basically says, Hey, over the infinite number of sort of scenarios here, this output is gonna be guaranteed the same time. And so when it comes back to sort of auditing, how do we know?
Well, automated reasoning is really interesting because it doesn't operate like a black box. It's, it's open when we, when it performs a proof, uh, we can sort of print out that proof and use that as sort of an audit trail to validate the behavior of the system that it's being proved correct. So there is a built-in sort of visibility, um, and explainability that comes into play when we use automated reasoning to validate programs.
Will this solve the following issue? I mean, I talked to people about this and they all like generative ai, but they realize that the outcomes are probabilistic, and a lot of the workflows that we're trying to apply it to are deterministic in the sense that we want them done the same way every time. So does this give us a mechanism to kind of marry the two in a way that is reliable?
Yeah, you, you hit the nail on the head, Mike, and that's why we're so excited about using automated reasoning, uh, to help customers, you know, use generative AI in these trustworthy applications, uh, and know that when they're building agent systems, um, you know, we're validating or constraining or sort of making sure that the behavior of those agentic systems, um, is, uh, according to our policies. And in fact, we kind of do that today at AWS already. Um, you know, we have a couple of products.
So one product that we just recently announced is called Policy in our Bedrock Agent Core Product. So Agent Core is a set of tools to allow customers to build these agentic solutions and policy when combined with another one of our products called, uh, gateway allows you to define in natural language policies that you want to restrict the behavior, uh, or constrain the actions that your agents can take. Um, and these policies are then applied and validated through, uh, formal reasoning and automated reasoning to make sure that, uh, you know, that generative AI isn't gonna sort of slip through the slip through a crack and kind of perform an action that wasn't, uh, according to, uh, the policy that you've defined.
Mm-hmm. How will this manifest itself at the end? Will there be some sort of output with a little check mark next to it that says that this has been validated, certified?
Or how do you envision us understanding when this has actually been completed? Yeah, I think we, I think we work with our customers, um, you know, to help them kind of find the right way. If they're building an innovation and they're using these techniques to, uh, provide higher assurances to their customers, you know, we'll work with them on sort of how we do that.
One of the ways that we did it is through a couple of our tools. So when customers are building solutions on, on AWS, they have to define policies and kind of access controls. And so we actually have a tool called the IAM Access Analyzer that allows customers, uh, to, um, plug in what kind of policies and access controls or details they've got, and we use automated reasoning to validate them.
For instance, ha, if I make this change, does it become more or less restrictive, right? Because let's say I only want my admins to be able to modify this database. If I create a policy, I can kind of validate whether that policy is more or less restrictive than needed, and we use automated reasoning to do that.
So it kind of depends on the particular application, um, and the type of assurance that you wanna provide, you know, the end users, whether there's like a check mark or a validation or, you know, uh, sometimes we've talked about customers about just providing like a, Hey, explain this to me, or sort of like, you know, show me where this answer came from. And that's where we get back to our auditability and explainability and we can kind of detail, uh, the proof or sort of the reasons that were used for this, uh, for this kind of answer. In fact, we have one product, uh, called Automated Reasoning Checks for Bedrock Guardrails, which kind of does exactly this.
It's a product that helps to detect and remediate hallucinations when you're interacting with a chat bot. So where there's like a defined policy, let's take for example, like an airline ticket refund policy. What we can do is we can ingest that and then build out sort of a, a formal set of mathematical logic that defines the terms and conditions, if you will, of that refund policy.
And so when I'm chatting with a chat bot about getting a refund for my airline ticket, uh, bedrock Guardrails can be used as a guardrail to validate the LMS output. And so we can be certain then that when it tells me like, Hey, yes, you can get a refund on that ticket because you bought it within the last 30 days, and it's unused and you live in, you know, this US state, uh, we can know that that's a valid answer and the, the customers can see that in the, in the, uh, chat bot experience based on what the customer wants to do. Yeah.
The curiosity for a technology that's been around, you would think I would've seen or heard more, uh, providers offering similar capabilities. But, um, is there something here that's unique about the way AWS went after this or, um, yeah. How come I just don't see this as a broad-based capability?
Yeah, these techniques? Well, so there's a couple AWS products, um, that already leverage automated reasoning, and we didn't necessarily make a big deal about the fact that Automated Reasoning powers these things. So I mentioned the, you know, access, the, the Policy Analyzer, the IM Access Analyzer.
We have, uh, network reachability analysis tools. There's a tool, which you might have heard of, called S3 Block Public Access, uh, which we actually use Automated Reasoning. So we mathematically validate that when you turn that on, uh, there's no way that somebody from the public internet can access that S3 bucket.
So a lot of times these capabilities have just been ingredients in, um, you know, sort of security, um, and related sort of high risk kind of capabilities or, or products that we've released. Um, I think one of the reasons why you don't see this, uh, proliferating across a lot of other providers is that, uh, AWS really has the deepest bench of this automated reasoning science experience, right? We've been building it up over the last 10 years, and really right now, uh, we're starting to see that come to fruition with the Bedrock guardrails, the Agent Core policy.
Um, you know, we have a number of other products related to, uh, internal validation. So, um, you know, uh, so in our, in the work that we do in building our own chips, right? For Graviton five, for instance, automated reasoning played a key role in some of the, what's called the Nitro Isolation engine, to validate that when multiple customers are, you know, multiple tenants are using the same server, that there's no possible way that they can access each other's data.
So we've been using the automated reasoning, but a lot of times it's kind of behind the scenes and it's just an ingredient to drive, uh, you know, the security and the reliability and the trust in, in AWS products. So, the way I, maybe you should start thinking about this, I mean, we've all been obsessed with generative AI since it came out, but, um, maybe the future of AI is using multiple types of AI models alongside each other, and they'll be predictive and generative and causal, and now symbolic. And it's all about mixing and matching these things when needed.
That's right. There's a whole, um, kind of universe of techniques that companies can use to drive trustworthiness of their AI solutions. Uh, and, you know, you need to apply them, uh, sort of gingerly, if you will, right?
So there's automated reasoning, uh, there's machine learning, there's guardrails, there's fine tuning, uh, there's a whole range of techniques that all can kind of be put into play to improve the trustworthiness, um, you know, of the solutions. Uh, and I think in 2026, we're really gonna see, uh, that start to come to fruition and kind of trustworthiness, especially as we get more into agentic, um, development and age agentic tools are gonna be operating on your behalf. Uh, that trust, that trustworthiness is gonna be, you know, a key element of these solutions for, you know, uh, people to adopt them.
All right, folks, what you heard in here, they used to say back in the day, you know, don't trust anyone over. Uh, try that again. Lemme try that again.
Write it down. Well, folks, you heard in here, they used to say back in the day, don't trust anyone under 30. Now we're saying don't trust any AI agent that hasn't been validated.
Hey, Mike, thanks for being on the show. Absolutely. That's a great one, Mike.
I appreciate your time. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership Insight series.
You can find this episodes and others on our website. We invite you to check them all out. Until then, we'll see you next time.
Hey everyone, I'm Alan Shimel. And I am Mitch Ashley. And you're listening to Still Cyber Smarter after all these years, baby.
Yeah, baby still cyber. Yep. Still cyber.
Mitch, it's good to have you back on here. Well, I'm glad to be on here with you. Um, always, you know, I'm having fun doing this one.
It is. Well, we always had fun doing these, Mitch. We did.
I think we, we laughed as much as we talked Yes. Back in the day. Maybe.
Still do. Yeah, we do. We do.
We're gonna have to do one live in RSA Yo, but Stone Cold Sober this year, please. Stone cold. Okay, well, I don't know about that, but we'll see.
Alright, well, I don't drink, so I don't have a choice, but anyway, hey, we are really happy to have a guest on, uh, this episode. I want to introduce you to our friend Kate Scar. Uh, Kate brings over 20 years of experience in cybersecurity and critical infrastructure protection.
I'm not reading my bio or your bio, Kate, tell the people who you are. Yeah, so I have, I've been doing this for it seems like just more than, uh, just decades, man. I was one of the people who went to Radio Shack, so there you go.
Um, but Yes, Yes. Uh, but yes, I, um, hey, look, I, I love cybersecurity and it has definitely been a passion of mine since, uh, since identity management, since vulnerability management, since, you know, and I could just keep going, uh, with this, on this role. But, you know, more importantly, I think in this discussion for me and why I am so excited is, of course today is about critical infrastructure.
Mm-hmm. And as I was telling you earlier, I actually got my master's thesis in securing the North America grid, the electrical grid. So I love, um, this discussion.
I love where the Internet of things and the industrial Internet of things and everything that encompasses including, uh, what it means for our government. So you're the person that's gonna solve that. I, and you've been here all the time, just right under, you know, right under our finger, right?
Under our hiding in plain sight, I'll tell you. Yes, yes. You know, I, I will say that.
I, um, my thing is I don't wanna retire until this is Saul, so, oh. You know, be Careful what claims. Be careful what, I was just gonna say, careful what you wish for, though.
You're a lot younger than us. But, um, anyway, guys, today's, today's episode grows out of an announcement Last week, something I wrote about, um, the RSAC folks, the people behind RSA conference or SAC conference announced that none other than Jen Easterly was gonna be their new CEO. Fantastic.
And I, I applaud it. I thought it was a bold move. Um, you could go read my article if you want the background, but, you know, Jen Easterly is truly a leader of the, of a, of this community.
Truly someone who has the chops, the experience, the talent, the skill and the gumption and the relationship. The lead Yeah. And the relationships to lead.
Yeah. Yeah. You know, she West Point grad, 20 years in the, in the Army.
She was then the director of Csar after our Frank Chris Krebs left, um, with the new administration, along with many of the, of the rest of the leadership there. She, she was moved out of Csar as Cesar's budget was, was cut. And then her chairpersonship at West Point was taken out from under her by the administration.
I'm not here to make this a political discussion. What I am here, though, is to talk about what's happened to CSA under this current administration. And, you know, one of the great things about CSA was part of the charter was working with private industry.
Mm-hmm. Forming that public private partnership. Yeah.
To protect critical infrastructure, because it's too critical. No pun. It's too critical, right.
To go it alone. No one private company probably has the resources to stand up to some of these nation states. The government itself doesn't have the reach or wherewithal sometimes to do it.
I really feel like we're making a grave mistake by not encouraging this public, private, in, uh, you know, partnership towards protecting our infrastructure. Mitch, I know you feel the same way. It, it, um, yeah, there's kind of a hollowing out is, is what is the hard part to accept about it.
Um, 'cause so many good people left. And, you know, the, the mission has, I dunno if I'd say subtly it changed. Um, but it, it, it, I I have less confidence in it than I did at one point.
Not to say we can't return and, and build that back as well. But I think we have to look at it as, okay, that's happened. Now what do we do?
Right? What do we do to help these people succeed? And how can we help influence?
And maybe Jen can do some great things. I know she will as part of RSAC, that might be part of it. But, you know, the security's a community.
It's, yeah. And I know you all agree about with me on that. Yeah, it is.
So, so, Kate, your, as you mentioned, your master's, you know, you graduate work is in critical infrastructure, specifically around the electric grid. And that's a perfect example of a private public, uh, right. Partnership.
Right. You have private utilities, private electric companies. And not only that, you know, it's like the car business.
It's not just gm. It's all the third party suppliers. There's a ton of third party suppliers and supply chain and everything else that goes into the electric grid that we all rely on.
And it's kind of take for granted, can, can it survive without a government private partnership? Is it mandatory? Are we all less because of it?
I think at the end of the day that we're, we're less because of it for a lot of different reasons. I mean, first, when you look at, you know, and I know that people in business push back against, um, regulatory bodies. You know, I understand that sometimes regulation seems that it, it just becomes very, um, heavy handed and difficult to manage.
It's unfortunate that we need regulation in order to have people to do the right thing. But for example, the North American Electric Reliability Corporation, nerc, um, you know, they came out really providing guidelines for, for interconnectivity of the grid. And it, it helps, it helps for all of us, for, for this United States to have governing bodies to help us, you know, distribute, um, energy and to be safe about it.
And that's the key word, right? Is, is safe. Um, we want it to be safe for us to use.
And let's not forget, I mean, in order for the lights to maintain, you know, we've all seen what happened in Texas when there was an ice storm. Um, and we've all seen what, you know, even let's not forget nuclear regulation. It's all part of the NERC as well.
NRC. Um, it's so important to have the collaboration. And, you know, one of the things that I saw out in the field, um, with, um, working with field engineers, uh, in, with the electric company, people care.
People actually care. They want to do things safe. And, you know, by providing guidelines, it helps people not to be like, like, just shooting in the dark.
Like, okay, what are we working for? What are we working towards? It really does provide us this structure, this framework, in order to, to, to be safe for all of us.
You know? Absolutely. Y you know, Mitch, I remember 2005, 2006 going with you to some of these ner and ferc.
Nurk. Ferc, remember NER and FERC nurk and the nurk and FERC meetings. And, and not conventions, but conferences.
I'm sorry, Mitch. Sorry. Those were the days, you know, sounds like Ner, right?
He was ferc. I was nerc. But, but anyway.
No, my gosh. But anyway, we used to go to Ner of FERC meetings, Mitch and I, and we, and we'd listen in and, and, you know, and I, I remember that that's when it first dawned on me, my God, we're this close away to a disaster. Yeah.
Right? Yeah. Right.
Uh, uh, it, it didn't take much. And this security stuff that we're talking about, 'cause we didn't call it cyber, then we called it security stuff. InfoSec, this InfoSec stuff we're talking about is all that standing between us and disaster.
And, and I was so grateful that we had NERC and FERC all getting aside mm-hmm. This, this framework of cooperation between public utility, private companies, the government. And they were constantly saying, Hey, what's best practices?
What could we do? How do we keep it better? How do we secure it?
And I, and I, I think that was a great model. Um, I was even happier when CS a first came on. I remember at the first RSA where CSO was involved, the RSA conferences.
And it was such a breath, breath of fresh air that it wasn't just the government saying, look, I just gotta worry about an MCI or, you know, some government network that I'm, I'm wor I'm worried about, no, we're gonna worry about public and private networks. We're gonna work with you. And we're not just going to sit up hide.
Like in God giving the 10 Commandments to Moses or something. We're, it, it was truly a partnership where we're gonna collaborate and work together. And if we hear something through CIA or the NSA or some of our National Intelligence services that's germane to you, we're gonna bring you in on that to make sure you, you're hardened and protected.
And, you know, we we're not gonna have a digital nine 11. How's that sound? No, that's heavy.
Yeah. In, in fact, that's what, um, my thesis paper was. It was called the a pearl, a Digital Pearl Harbor attack.
Really? Yeah. Okay.
There you go. Yeah. And, and, you know, with critical infrastructure, one of the things that I make a poor joke about, but I'm still in this industry and not a comedian somewhere, is that, um, when I did my, my thesis, it was on this, um, it was about critical infrastructure being taken down.
It was the, it was a die hard. I love die hard. And, um, it's Live for your die hard.
It's a Christmas move. Me. Thank you.
Thank you for, yeah. Yes. But the idea that if we take down our critical infrastructure, um, you know, in that movie that they did well, is that they took the attention and went over to the financial industry, right.
And started to take from the financial, and that was this whole idea about how our grid actually, you know, you take down our grid and how much is impacted, um, and why we need government, um, collaboration is so, it, it, it's imperative to keep us safe. So I Connected back to, uh, I'll bet you cited him in your, in your research, in your, in your thesis. Uh, Richard Clark, do you remember when he came to speak at, uh, RSAC?
That was Sure. That was a huge deal. Just having someone who was, you know, US National Security Official was for multiple presidents, for multiple president.
Going back to Richard Clark, 2001, if I remember when that was. Somewhere around there. Close to that is when he started.
But he was the first national speaker I know of that was talking about critical infrastructure. Uh, you know, that was back in the days of, we did kind of experience our own version of that. 'cause Code Red and I Love You Virus would take down every business.
Right. Uh, that ran email, I mean, really had things out there that did impact everybody. And you could, you could feel that.
Yeah. And SQL Slammer, I mean, you know, I remember sql Yeah. What I was doing, you know, when SQL Slammer hit, I remember You guys are old.
I don't remember any of that. Yeah. Yeah.
We'll sit on the front porch and, and, uh, take about salad. Yeah. Have lemonade.
Iced tea Have Lemonade, right. Mars and Jane. But, but, but here's the thing.
Over the course of the last 25 years, all kidding aside, we have seen this public private partnership grow, not contract. We've seen it blossom. We've seen it be rich, right?
Mitre mm-hmm. Which is kind of quasi-governmental in their relationship with private industry. Uh, NIST does a great job of working with, with private security, with the security vendor community, um, FBI, right?
Nist, the FBI, I mean, look at, uh, remember our friend Tony from NSA, Mitch, I forget Tony. Oh, yeah. The last name he ran, he ran the red teams at NSA.
Yep. Uh, he's Tony Sanger, I believe his last name. I think it's a, that sounds right.
Yep. Um, Tony Sanger. So, you know, there's a rich history of not only the public private partnership between government and, and industry, but between government InfoSec resources and private InfoSec resources.
And in them meeting at conferences like RSA conference, like Black Hat and Defcon. Right. Infra regard, remember meetings, all that.
Yeah. I suck. Yeah.
But you go to DEF Con and the feds were there, right. They were recruiting there, right? Mm-hmm.
Um, this was, I think, part of, uh, you know, you know what they say about security, nothing happens. And it means you did your job. This was part of why maybe some things didn't happen.
Yeah. Right. Is that part of it?
Let me ask you both a question, and I'm, I'm gonna take a very simplistic approach to this. I realize this, but I think one of the big things that led to the 17% cut, or whatever it was in the CSA budget, is because they were, they were addressing election security and things like that. Which, you know, is, is a political hot potato.
Um, now that, that's kind of out of their mission, at least made by the Trump administration, do you think CSA can get back to, 'cause they're supposed, they're supposed to protect the federal networks and infrastructure. Do you think we can get back there now that, that sort of, we've laid aside the election security issue from Cissy Charter? Kate, do you wanna go first?
You know, honestly, it's a, a great question. And honestly, though, I, I don't think so. I, I think, um, if people don't understand the value that the industry brings, um, then I, I don't think that they're going to invest in it overall.
I, I don't, and I think that there's a lot of people who don't understand what cybersecurity is or, or what we do. And so I think it's sort of like a, that's what I think. Anyway, we're not wrong this, so, Mitch, I'm, I'm, I'm surprised to hear it was only 17%.
I think there might have been 17%, but then there was other money that was shifted from C to to ice. Yeah. I'm sure that was within, within, it was like a thousand people was the cut.
But that may have been just part, that was just the head count. Yeah. But budget over and above head count, a lot of their budget went over to ice, all under the DHS kind of umbrella.
I was just remember. But, but here's the thing. It it's not just the amount of money that was taken out.
It is the heads. You lost some really good people, like a Jen Easterly, like our friend Alan Friedman kind of father, the father of SBOs. Yeah.
Yeah. Right. I, I'm friends with Alan on Facebook.
I still stay in touch. But man, it's hard to replace those kinds of people. And at the same time, as you mentioned, I think the mission's changed.
The mission is no longer necessarily to work with private industry to protect all of critical infrastructure. It's to protect specifically government networks, maybe. And can they do that?
Perhaps, you know? But as, as we said in the beginning, we're all worse off for it. We're all worse off for it.
Um, government networks don't exist in a vacuum. Yeah. You know, the one thing I I think though, about our community, the cybersecurity community, is that you have a lot of people who care.
And I think that this caring and, you know, I think it, it will actually take us to a different place that we want to, as you know, wanting to secure people, that you're gonna see some pretty cool things, I think stand up at the end of the day, because I think the people want it. I think we actually care. And I think because we care, you're gonna see some, some pretty cool things that will be stood up because of, of this pushback.
That kind of brings up the second part where I wanted to go. Unless, Mitch, you, did you have something? No, no, go ahead.
Yeah, I'm just thinking here. You know, shortly after I, um, wrote my article and we spoke about it, uh, there were reports out of the government as a, as a result of Jen being appointed the CEO over at RSA, the government was contemplating pulling all resources. They weren't gonna let any of the agencies or even the individual employees attend RSA, they were, because of Jen being there, they were gonna basically pull out a RSA.
Yeah. RSA conference. Excuse me.
And well, you talk about cutting off your nose, spite your face. Yeah. Right.
Who, who wins there? No one wins. You.
You just losing all around and, you know, nature rapports a vacuum, right? And so, in the vacuum of the government pulling out of working across industries to, to protect our infrastructure, our critical infrastructure, who takes their place? Well, it's a big hole to fill.
It's a big gravity sink, right? That's outta there. But, you know, you would hope maybe an organization like RSAC that is trying to move beyond just being a, a once a year conference, but to truly be the world cyber community, maybe they can help forge these kinds of partnerships, these kinds of relationships that we're gonna need.
I mean, the threat as, as I'm sure you're aware, Mitch, and certainly you are, Kate, the threat to our critical infrastructure hasn't lessened No, no. You think is greater. Yeah.
It, it really is. Because, you know, something that we don't talk about is the internet of things, and mm-hmm. You know, cameras and cameras are in critical infrastructure everywhere.
So that, that's like one huge pathway. All the, um, systems, uh, IOT systems, uh, entryways, uh, badge access controls, again, all systems that are, that are built on free real-time operating systems on free R toss. And I, and as I would walk into, uh, you know, to a place, I mean, as I looked around, I'm like, you know, there's no, there is, there is no agent on these IOT systems.
And of course, the IIOT systems don't have agents, you know, the industrial internet, because they're too darn old. So, and then there, there are 40 billion devices out there, folks that are just, you know, hello. Wild, wild west.
Here we are. And yeah. With no visibility.
So, you know, we're, you know, ro You know, I'm reminded Mitch, remember going up, we, Mitch and I used to spend about a week a month, every month. We'd spend one week up in Chantilly, Virginia and be all around the, the, you know, the beltway area, Marriott, the court. Yeah.
Well, that was our home away from home. Um, and we had a good friend, Stu Mitchell. Stu must be Mitchell retired now Steve, he's retired up there.
Yeah, he's retired. I've talked to him. Yeah.
Yeah. Stu was like a deputy Seesaw, maybe the CSO at the Department of Interior. Mm-hmm.
And Kate, Mitch and I would go up there and meet with Stu, and it was great. He would arrange, we would get like VIP tours of the Lincoln Memorial and Oh, nice. The Mitch and I would always go to the Smithsonian and, you know, we were like two little kids in a freaking pod.
But, um, it was interesting, even back then, this is like 2004, 2005, even back then, you know, talking to the US Geological survey people, now they've got sensors on the top of the mountains. Yeah. Weather, earthquake, you know, all kinds of sensors.
I'm sure there's probably early warning stuff put in there too. They've got sensors on the bottom of the sea also for earthquakes and waves submarine also, again, probably submarine sensors. Mm-hmm.
And you would talk to them about, Hey, what do you do to secure all these sensors? What do you mean we're scientists? We're scientists.
We don't secure these things. We want 'em to be open. We don't wanna lock 'em down.
Right. And we had to like really make a case for why they had to build security. Even JL going out and was a New Mexico or Albuquerque, I can't remember where No, not JPL That was, wasn't Los Alamos.
It was White Sands. White Sands. That's what it was.
Yeah. That's Department of Energy. Yeah.
Yeah. You know, talking to the scientists. Yeah.
They, they didn't see the need because they thought that the only people who would ever be interested in those kinds of devices, Kate, were other scientists. Right. It never occurred to them.
Yeah. You know, my, what an innocent naive time that was, huh. Compared to now.
I honestly, and, and it's, um, it's, it's not much difference with these iot devices. You know, think about, you know, even, um, cameras that we have, um, for security, whether it's in the, you know, the subway systems or even the, the lights, um, you know, they're all actually connected now. Yeah.
It is so interconnected more than ever. Oh, That's true. So it's, you know, if you watch like the Mission Impossible movies or some of these movies where the hacker Yeah.
Breaks into the traffic light system and the camera system, and there you go. It can change all the lights, green or red, so you can go and, and get away. You know, it, it is all, but, you know, let me bring it back though.
How do we, how do we fill the vacuum? Or maybe we just don't, lemme throw out an idea. It, it's very, it's highly impractical.
It's not the right idea, but just kinda sharing experience. One, one of the things I learned along the way of kind of budgeting software for IT projects or whatever things I was in charge of is in big companies, I learned the lesson of, well, the, the, uh, the, the favored program of whatever we're supposed to be doing over the next nine months will shift in nine months. So whatever it is, it's gonna keep changing.
And this, this, right now, it's, let's secure this. The next month, it's let's go do that. So I would always tailor my budget presentation to how my things helped us accomplish whatever the mission of the day was.
And people would always be like, how do you have all that capital? How do you have all that budget? I'm like, it's all how you position it.
So maybe that's what we do today, as is, again, simplistic. But if the watch word of the day is what public-private means is really enrichment in hiring, uh, private companies to do these things instead of government agencies. How do we help make that happen in a way that maybe minimizes corruption tilting up one mills there?
But maybe that is the answer. And I know that may not feel good as a security community doing it for the better good through, uh, government pub, public, private. But maybe that's the model we have to transition to something like that, where we really have to make that happen.
Well, I don't know what it looks like, but I don't think we're going back to the way it was. Even if a new administration came in Yeah. And said, yeah, we're gonna go back and do that.
You're, you're talking a decade at least before we even kind of got back to where we were. Kate, let me ask you a question. You did your, your thesis and, uh, graduate work on this way back in 2006, you mentioned, right?
Right. Here we are 20 years later. Are you frustrated, surprised, dejected with the progress we've made since then?
Or you think it's kind of about what you thought Rita would be? Frankly, I, I am, I, I am, as I've said before on our shows, a Pollyanna, unfortunately. But in this instance, I, I am dejected.
Um, I, I mean, it, it's, it's a lot. And, and it's Groundhogs Day for me. Um, I always feel like we're still chasing, um, we're still chasing the threat.
We're never getting ahead of the threat. And I don't understand when we've had some phenomenal minds. Um, when we, we, we all, we understand the problem.
And this is where I, I get a little bit bummed out because, you know, I, I don't know whether it's when, and to Mitch, your point about, you know, money, sometimes we, I, I think products, you know, so with vendors, I mean, and I worked with vendors. I mean, IBM for, you know, over 20 years, et cetera, McAfee, um, and sometimes, you know, it's based on, you know, sales kickoff meetings. You know, what are, you know, what are, you know, what's, the company has to prove a profit and everything else.
And so the, so the, so the vendors are talking and trying to sell the products. But at the end of the day, um, and I was an architect, so I would, you know, bring in, and, and I, and I didn't, I, I was agnostic, um, as far as products we're concerned. And, um, but it always seemed that at the end of the day, you know, it's like we have this phenomenal product and we're gonna, you know, crush this CVE, well, now we have 40,000 plus, you know, CDs.
And you, I, and I walked into, you know, how many companies that had over 120 different security, cybersecurity products, 80 different vendors. And I'm like, okay, this is a vulnerability within itself. You know, you have so many different vendors and so many different products.
So, um, so I think we have to switch. Um, and Mitch, you know, I, I do, I, I like the way the thinking is because I don't, I think that this gives us actually an opportunity within the cybersecurity community to look at things seriously. We need to look at this problem differently.
And, um, we, we really do. And, and we have to seriously understand, 'cause look, we have to crush disinformation. We have to, you know, look at large language models.
We have to look, um, at, at doing, um, you know, the, the AI and the coding, um, differently. Because if we humanly look at this, we're not going to, we're not going to win. So we have to look at LLMs and we have to look at how are we going to address this to address these threats for real?
And not just singular threats. I mean, big threats like disinformation as an example. Oh, disagree.
Yeah. I'll, I'll just chime in one, we could do a whole podcast about this, but I think we have already surpassed. But certainly we'll reach a, a, uh, a velocity stage where what is happening, whether it's the amount of change, whether it's the tax surface, whether there's, all the events that are happening are far beyond the, the model of report and human take action.
We have to get to a place where, oh, I, I think we passed that Rubicon a while ago. We, we have to get to a place where we can trust technology to take action for us. Whether that's AI or something, you know, even current generation.
And, and otherwise, it's, it's just there's not enough people on the planet to respond to every CVE vulnerability that gets reported, or every incident that happens. So that, that to me is we, we have to invest in that. That's where I think the next big, big, big, big innovation in security is that hump we have to get over.
Otherwise, it's, it's not gonna get solved. But that, but that's also the kind of mission where it's good to have the breadth and width of the government trying to solve that with you, because it's, it's really, it's a big mission. Maybe almost too big for any one vendor or one company, or even industry state, nation state is, well, no company is prepared to really Well, and, and there's the flip side to this, which is this whole sovereignty, digital sovereignty thing, right?
Where whole nother, you're not, you know, you used to be able to, so one of the, besides dealing with private individuals would deal with their counterparts in Europe. And, you know, we in the West and Pacific, our allies, well, we don't have a lot of allies these days. No.
Wherever they may be. Well, north, North Korea might help us, who knows? He's friends with them.
Greenland. But, um, count on your Greenland. It's just, it's just a block of ice.
Anyway, um, we're not gonna go there though. We're not going there. Please.
But let me, let me, let me wrap this up in a dignified way, Mitchell. Thank you. You, I certainly can't do it.
I appreciate you in case digging that up. You, Jack, you dragged us down there on that one. But, but the national sovereignty issue is another example of us breaking down partnerships instead of working together to solve a global cyber problem, which is critical infrastructure safety.
Yeah. And, um, and I'd like to just add that I talk a lot about frameworks. At the end of the day, a framework is so important.
It gives us a vision. And I think if we can invest in a framework and one that we can agree on, I think we can then start to build the components around it that can actually give us this vision that we need for the cybersecurity that we need for today. Not even for tomorrow.
We need it right now. I just wanna add absolutely. One, one thing.
And, and Kate, I mean, listen, and with every bit of sincerity, you are one of the clearest voices in cybersecurity right now. We need to elevate you and what you're, you're talking about. And yes, you're on Textron Gang with us, you're on Security Boulevard, but I hope you can take an even greater role, whatever that is in.
Oh, she's also the chair of the CD Foundation Cybersecurity special Interest group thing. There you go. I mean, the more we can elevate you and, and folks like you, because you are such a clear communicator, you know, you don't get lost in the gobbledygook of security.
Like, it's so easy, easy to do. And you, you really get to the heart of things. So thank you so much for what you do, and we hope Well, That's very kind to you.
And I really appreciated being a part of this FERC and Ner. I hope to be that Bur Ner Ernie Mitch, take us home. Well, I don't know what fricking ner stand for anymore, but whatever it was, we used great thing back then, and we'll have the future version of it.
So thank God we have, we have leaders like Kate that, that are helping make progress. And Jen Easterly, good luck to her and RSAC. Yeah, I'm looking forward to, Hey, hey, you know what?
Step out, uh, connect with us 'cause we're gonna be recording an episode at RSAC and we'd love to sure have you on and talk with you. We are having guests like Kate, uh, come on. And, uh, we'd love to have you.
com, or myself and Ashley at, I feel you're almost gonna stay still secure for a second, rich. I almost did. Almost did.
Yeah. com and, uh, we'd love to chat with you and thank you for listening. And hey, hit that follow, hit that like button, you know, I know we're supposed to say that.
Hit the like button. Yeah, hit the like button or subscribe or whatever button you see over there. I don't know.
But for now, this, this is gonna wrap up this episode of Still Cyber After all these years. I'm Alan Shiel. I'm Mitch Ashley, we'll see you next time.
Welcome everyone. Thank you for joining us. Today.
We're talking about readiness and AI in the mainframe environment. My name is Mitch Ashley, and I lead the software lifecycle engineering practice at the Futurum Group. Today I am joined by Anthony Desarro, who is Senior Director architecture of ai.
And with the BMC, let me try that again. Not the BMC. Dang it.
My bad. Alright, starting at 3, 2, 1. Hi, and welcome.
Welcome to our conversation about AI readiness in the mainframe environment. My name is Mitch Ashley, and I lead the software lifecycle engineering practice with the Futurum Group. Today I'm joined by Anthony Dero.
Anthony is Senior director of architecture for AI with BNC software. Welcome, Anthony, Mitch, thanks for having me. You bet.
Great to have you. Now, this is a three part series. Our first part is talking about AI readiness, and the series is, uh, sponsored by BMC software.
We appreciate the folks at BMC, uh, putting this on and putting this together. So, Anthony, let, let's jump right in. So, we hear a lot about organizations needing to be AI ready, especially for the mainframe environment.
At the earliest stage, what does AI readiness really mean? Yeah, Mitch, this question, I can't tell you how many times I get this, whether it's I'm speaking at a conference or customer visit, this always comes up, you know, how do we get going? How do we, we get started with that, and it's so foundational into a successful journey with ai, but yet it's a step that you'd be surprised how many organ organizations just kind of ignore or are not even aware there is a readiness, uh, you know, playbook that they, that they should be, uh, following.
So it all boils down to, uh, from an organization perspective, you know, how do we roll in AI technology? How do we use AI technology safely within our organization? How do we put guardrails around AI for, uh, you know, for protection against data?
Uh, for example, you know, uh, from a, from a legal perspective, you know, uh, what policies and governance that we need to have in place. Uh, we bring AI into our organization and there's all kinds of challenges around that. But at the end of the day, you know, that's one part of the organization's gotta deal with that.
And then it comes down to the individual, you know, groups and, uh, departments within an organization on how they want to utilize ai. So the first really good step in that journey is looking at AI as an advisor. Mitch, really look at it as like you would bring in a human into your organization, you know, based on their experiences and, and their background to have a dialogue exchange with them about whatever challenges that you may have.
And you're gonna lean on that person for their insights and guidance based on their experiences. Ai, that's a great first step with AI image. Look at AI as an advisor.
It's there to explain, it's there to guide, it's there to recommend, et cetera. It's there to provide knowledge and insights that you may otherwise miss or not know how to surface. So from that perspective, that is a safe AI journey to start moving your organization to.
But then the other side of that is the skills of your staff itself. When you bring AI into an organization, you wanna make sure that your SA staff is skilled in AI usage. You want to make sure your staff is skilled and understand on where they should be applying AI within the organization.
So there's some education and training that need to be done for your staff. There's guidelines, uh, uh, and policies that you need to be putting in place, guardrails that you need to be putting in place. And that's all very, very, um, very focused on individual organizations and what that means.
But that's the first step, um, to get that, those foundational aspects of AI in place. That's a really good point about having that kind of direction you want to take with AI versus it's so accessible. We can use it, try it out, but how are we gonna focus and leverage it for the organization.
And you mentioned the concept of AI as an advisor, using that as your first entree into ai. Talk about how that is different than maybe automation, autonomous ai, agent ai, all the terms that we hear about, uh, doing things with ai. Yeah, so what, you know, when you do hear about autonomous AI and agents, that's all around actionability and the AI take, you know, perceiving a situation, making a decision, and taking it in action, jumping into the deep end of the pool when it comes to AI in that regard, that, that, that's concerning to a lot of, a lot, a lot of folks.
So when we talk about the advise the advisor part of that, the advisor takes no action, right? Again, the advisor is there just to guide you, nurture you, and move you along. But it's up to you, the human to actually take those actions.
It's up to the team who's using AI to infuse AI with the right pieces of information to get the right types of guidance that they want from that AI system. But that AI system is benign, right? That again, the AI system is not going to take any actions on or your, your behalf.
It's all back to you. And what you want to get out of that, that AI system. So if you're a developer, I'm gonna use AI as an advisor to maybe gimme code, recommendations, code, explain, um, maybe to do a best practices analysis on my code, et cetera.
That's, that, that's really good. Maybe from the AI ops space, Mitch, we're gonna use AI as an advisor to oversee my, my dashboard and maybe surface insights to me out of that dashboard that I would otherwise miss. But there's no actionability to it in that regard.
It's just providing the insights and information so that that is, that is a part that fits very naturally into the advisor part of it, as opposed to the autonomy part of ai. It's good you mentioned that. 'cause it is a much more comfortable way to kind of enter into the AI space and start to use it.
You don't have to jump right into automation and agents and, you know, doing more of the, you know, advance things. If you wanna think of it that way. You'll build trust, you'll learn about AI by using it.
And we, and we've done that ourselves, right? You know, look over the last 18 months, whoever your chat provider of choice may be. But that's how we, we all got into the game of ai.
When, when, when, when, uh, you know, chat cheap PT was released as an example. We all went out there and, and started having conversation with AI at that point, whether it was professionally or personally, that experience was an advisor type experience. You know, we sent it a bunch of questions and we got responses back and we had a conversation and a dialogue with it, but nothing happened.
There was no actionability to it. So that was all of our entries into the AI world. And for organizations, for enterprises, that's a great first step also in the, in the start of their AI journey To that point, there are plenty of ways to engage with AI and query, use it as a tool, but what do you need to have in place to be an effective advisor role in, in the environment we're talking about?
Yeah. So one of the things that we've learned in our journey with AI so far, and I think as an industry, we all learned just bringing a large language model into the organization, not enough, right? It's like it's, that's just, that's the bare minimum entry that you could do.
But the problem with just bringing a large language model into your organization is it doesn't have any context. Those large language models were trained on huge corp of information. They were targeting the masses of users, where once you get into an organization and you bring AI into an OR, or into an organization, you're, you're in a particular domain.
You're in a particular realm. So now how do you, how do you utilize this large language model that's general purpose for specific domain that you may be in? Well, the way you do that, and what we've learned o over the past, you know, 12 to 18 months, is you have to augment that large language model.
You have to augment it with realtime product data or whatever data, uh, realtime data that your, your organization is playing in. You also have to augment the language model with additional knowledge, whether that's workflow, knowledge, processes knowledge, best practices, knowledge. It's, it's your enterprise knowledge.
Whatever that means to you in your organization, you want to infuse that into your AI system. So then you have the large language model with your enterprise knowledge, with your real time data access, uh, knowledge. It's a combination of all three of those that brings relevance to AI with an organization because it brings relevant context into your organization and the AI perspective.
And when we're using AI advisors, and I agree with you very much about the point of, you know, contextualizing it with information about your organization. Where do you see the fastest value that can be delivered by using, uh, AI advisor in the mainframe teams today? It's definitely in the DevOps space by far that it, it's the DevOps community that has really opened their arms and embraced ai.
And the mainframe environment is no different, whether, you know, from the cloud environment to a distributed environment in that realm, the developers have accepted AI in the mainframe space. There's a, you see a lot of interest, a lot of adoption AI in the, uh, mainframe space. So that is, to me, has progressed us as an industry in the a those working in the AI space, the work that the development com community has done over the past year, 18 months has really accelerated our journey, uh, with ai.
Now, you also starting to see other areas starting to get really interested in that. The AI ops space, as an example, is getting, getting a lot of traction now when it comes to, uh, to ai. And we're heavily looking into that within our portfolio, in our AI ops, uh, part of it.
But it's the knowledge capture that is what's gonna play the biggest game here, why we're in this massive transition within the mainframe community. We have a lot of folks heading out towards retirement on the tail end of their careers. How do we capture that knowledge and how do we infuse that into our AI system so that next generation coming in has that experience?
They can lean on that they otherwise would not have that person they would go to, you know, Bob, Bob is not here anymore. But if we were able to capture Bob's knowledge in some way, shape, or form, and put that and infuse that into the AI system so that next generation can lean on the AI system and get access to the information that Bob had, that is game changer in our mainframe space. It's really, it's not only helps get that next generation up to speed, Mitch, but here, he, I I just had a conversation yesterday with someone about this AI on the mainframe is making the mainframe sexy and attractive to that next generation coming outta colleges and universities.
We're in the conversation, just like the cloud space and the distributed space when it comes to AI and technology advancements in general. That is really cool. You very much is the sense of excitement in the mainstream environment, particularly with ai.
And it, and, and you have a really good point about that knowledge loss, you know, as folks retire, move on, whatever it might be. So the next generation of people work in a mainframe, have got that information contextually available to them in ai. I can't think of a better application of ai.
Yeah, absolutely. And we hear that from our customers. Our customers are like, you know, we got decades worth of white papers.
We got years and years worth of, uh, video recordings, training material, et cetera. How do we capture that? How do we, how do we get that into an AI system?
And that's something with BMCE, uh, assistant that we, we, we took very, very serious, right? So it's like, well, how do we do this? How do we allow our customers to capture this knowledge that they have and get it infused into B-M-C-M-E assistant and we're delivering to our customers a tool that makes that really easy to do, uh, where they can, uh, manage documents, they can manage videos and build out their own knowledge base that B-M-C-M-E assistant would be totally aware of.
Now, when we ship our solution, we have the large language model. We have an a e knowledge base that we ship, the customer can build their knowledge base, and then we have access to all of our product data. So we got all this information that's available to BMC AMY Assistant, that goes back to what we talked about before about what's relevant context to a customer.
Yeah. We can't talk about AI without talking about trust, and I've heard you discuss the importance of explainability. Yes.
Talk more about that. Love to hear your thoughts about why that's so important. Oh, Yeah, yeah, yeah.
So with, with ai, of course, you know, trust always comes up in the conversation from the very beginning. When we all started working with generative ai, that was the, you know, everybody was talking about trust in that regard. It's multiple ways to answer this.
You know, we have some responsibility in the solutions that, um, that we provide our customers. We gotta give the customers insights into what our AI system is doing. We have to connect our AI system into their workflows and processes around auditing, logging, tracing, et cetera, observability in their organization.
So how do we do that? So as an architect, from the very beginning, foundational, we have to be able to capture everything that is happening through our, uh, our AI system through BMC Amy Assistant. From a user typing a prompt to us formulating a response, not only did it has to be auditable, but as much insight as we can provide on why we came about a response has to be clearly articulated.
And some of that is clearly articulated back in the product experience. So when we give a response back, we may cite in that response where we, why we came to this conclusion and what pieces of information led us to the, to this conclusion. But it also has to be totally, uh, traceable and auditable behind the curtain so that the administrators of the AI system have full optics into everything that is happening in that system.
It cannot be treated as a closed door system. So it, it, it's the optic optics into the AI system. It's the auditability, traceability, logging, everything has to be done.
So if you go into the system, Mitch, and you are working with BMC Amy Assistant day in and day out, the system administrator has, you know, full trans full transparency into all the things that you've done with the AI system and with, and, and customers have asked us for that from the very beginning. We started working with our customers in this journey that was foremost right at the top of the list. They need to understand what's happening in the system and why.
And we've done that. That's foundational for us. That was something we had to put in at the lowest level of the architecture.
That's not an afterthought. If, if, if you go with that approach as an afterthought, you'll miss things. It has to be done at the ground level of the system.
Yeah. That explainability of transparency is fundamental, that that builds that experience that you start to build that trust with very much so. And is that trust that's gonna lead us to, to, to the next part of the AI journey beyond the advisor where you look at AI as a true partner in your daily journey.
You look at AI agents and agentic AI as a digital workforce doing work, and, but we gotta take those steps and build that trust. Speaking of taking those steps for organizations that may be just starting out, thinking about AI readiness, what do you think are the smartest first steps to take Take? We went through this journey ourselves.
So, so we have a pretty wide and deep portfolio, which within our BMC Amy, uh, product area. So we had to go through this exercise. Where do we find true immediate value that we can deliver to our customers?
The AI journey was new for us too. We had to be very capital, very systematic on how we approached it. So the, the way we approached it was, let's just start looking at the low risk, but high value returns that we can give our customers with our AI infusion within our products, within our portfolio.
And we've been very, very successful at that. But one of the key things, even though it's, you know, it may be a, a low risk, high reward type, um, AI enhancement, we want to be able to also capture and measure that. You have to be able to measure and capture that to make sure you're truly getting your return on your AI investment.
This model worked very well. I, I I, I, I spoke to other architects about this model. I spoke to customers about this model, and this is a really good entry point model.
Start small. Don't try to drink the ocean, as they say. Start small.
Identify those low risk impacts. You don't want anything that's gonna disrupt your business, uh, on a day to day. But then just start taking those steps.
And before you know it, when your organization gets more and more comfortable with AI and you start building the trust with AI and you start to get a good feel of what you can and cannot do with ai, before you know it, you're starting to take on bigger and bigger and bigger challenges with AI and be, when you look in the mirror, you'll see you yourself progressing pretty far pretty quickly with AI when you start that way. Some great insights and very sage advice, I think. Anthony, thanks for joining us today.
Thanks for being part of this. Thank you. We really appreciate the BMC software team for sponsoring this kind of event where we can share this information, share some of our experiences, and bring up some of these important questions.
So this concludes our first segment that we're doing in the three part series covering AI readiness. In our second segment, we're gonna be talking about infusing intelligence with ai, using AI as a partner, using generative AI in the mainframe environment. Thanks for joining us.
We look forward to seeing you on our next segment. Digital sovereignty isn't abstract anymore, it's national and it's personal. Hey everyone, it's shimmy and welcome to this special Friday edition of Shimmy.
Says, you know, if you caught my shimmy says yesterday, it was rather tame. It was geeky. It's about DevOps, the never ending story.
Something near and dear to me. But I wanna speak today about something maybe a little spicier, and it is near and dear to me too. I call this Shimmy says, episode digital sovereignty is national sovereignty, and digital sovereignty is personal sovereignty.
So let me tell you something here. If you were paying attention to the news lady lately, especially coming outta Davos this week, so much coming outta Davos, so much of it was nonsense. But there was one phrase that kept coming out over and over, and one topic that kept being harped on digital sovereignty.
Whether we were talking about sovereign AI or sovereign cloud, sovereign data, sovereign semiconductors, digital sovereignty, and really digital sovereignty has become a code word for independence, for not being reliant on any one partner. You know, I, I thought the, uh, the prime minister of Canada, his speech on, on sovereignty and independence and building fortresses and variable geometry was probably one of the speeches. It should go down in history as a great speech, but it really at its heart was about sovereignty.
National sovereignty. Every country needs to be able to be self-sustainable and not dependent on any one other country. They've gotta be free to make their choices that's best for their own country, but working together for the good of the world.
You know, a few years ago, the whole digital, so sovereignty thing sounded like policy speak, but today, I'm telling you my friends, it's kitchen table conversation for world leaders and it's kitchen table conversation for you. Because digital sovereignty is national sovereignty and digital sovereignty is personal sovereignty. It's about your freedom, about your privacy, about who controls you.
And this didn't happen by accident. What we're seeing going on right now in this world is a reckoning. Countries are waking up to the fact that their digital future and their digital future is their, is their future there, there is no separating digital future from the rest of your future.
It is your future. They're realizing that they can't sit entirely in someone else's house anymore, frankly, especially when that house is halfway across the world and there's a crazy landlord that keeps changing the rules. You know what I'm talking about and who I'm talking about?
AI isn't some science project anymore. It's in production. It's running economies.
It's shaping defense strategy. Data isn't just data. It's leverage.
It's the lifeblood and the cloud. The clouds become something more strategic than oil shipping lane or who ships and missiles controlled the damn straits of hor moves or wherever are oils coming from these days. You know what Davo, a Davos, no one was asking whether digital sovereignty matters, that ship sailed, that train left the station.
They were asking, how fast can we get there? How fast can we be independent? How soon can we not be at the, at the beck and call at the behest of some master we don't want to be serving?
And what happens if we can't get there? What happens if we can't get there? Europe is rethinking its dependence on hyperscalers, it's rethinking, its dependence on AI models.
It's dependence on on foundries and, and chip makers. It's very digital independence is what's at stake. It's not just Europe.
It's the whole world. Governments are very, are suddenly very interested in where their data sleeps at night and AI that's gone from innovation, nice to have to existential, must have. That's the moment we're in right now.
That's the moment we're in right now. I'm going to open up here, you know, like that, that shimmy isn't always opened up, but I'm going to get personal and vulnerable with you right here. I get it.
I understand why digital sovereignty is necessary in today's crazy world. I do. I really do.
I think you do too. But it makes me incredibly sad. It makes me sad.
It makes me sad for the world order and the stability that I grew up believing in that gave so many people rise above poverty, rise above hunger, created the biggest middle class and probably the most peaceful, peaceful time in the history of humanity. I'm sad that we are look, seem to be losing that I'm sad for the internet that I saw blossom before my eyes as this big beautiful equalizer that let me talk to anyone anywhere in the world. From China to Australia, to Singapore, to Europe, to my friends in Marrakesh, Morocco.
It made the world smaller. It made the world better. It made the world not meaner.
You realize it really was a small world after all. It made the world better. I'm sad that early dream, maybe it was naive.
Sure, right As a child, the Star Trek, that we could actually reach out for the stars together. That technology would help us bridge culture, help us bridge differences, build something bigger than just borders and flags for a little while there. You know what?
It sure felt real. It had me fooled. Probably had you fooled too.
We grew up believing this. If you're at that age, gen X boomer, but let's not kid ourselves. From the in, from the moment the internet went commercial, some governments knew exactly how dangerous it was.
It wasn't dangerous to their people. It was dangerous to them, to themselves. 'cause if your citizens can see how other people live, if they can compare notes, if they can realize that things don't have to be the way you tell them they do, then that's a problem.
Especially if you're a tyrant. Because once people see what's possible elsewhere, tyrants don't last very long. I'm reminded of Thomas Friedman and Flat Earth book.
Everybody wants to live an American lifestyle. They may not want to be an American, especially today, but they wanna live the American dream. And there's nothing to matter with that.
So what did these tyrants do? They built walls. They did what tyrants always did.
Today, those walls are firewalls and filters and walled gardens, call it whatever you want. But they locked it down to hold onto power. And soon as people rise up, the first thing they do is they lock it down even tighter.
We see it in China. We saw it in Iran this past couple weeks. But you know what?
Other countries, they didn't lock it down. And when their people saw what was possible, when they saw the freedom, the opportunity, a different way of life that could be possible, governments fell and history changed. I was a child of the Cold War.
I saw the Berlin Wall come down. I saw, I saw the new World order come together. And you know who brought it about regular people, individuals yearning for what we all yearn for.
Food, freedom, privacy, safety, freedom. And for a brief shining moment, it seemed that this changed the internet and this stuff. It changed everything and it made all of that within the grasp of the seven or 8 billion people in this world.
But those days, they seem to be fading fast right now, I'll be honest. And that makes me sad. As the world pulls back from a shared global order and we slide into something that seems more fragmented, more balkanized, our digital lives, excuse me, our digital lives are getting chopped up right along with it.
We've got different cloud. We're gonna have different clouds, different AI stacks, different rules, different internets. Even if nobody wants to say this part out loud, here's the uncomfortable truth.
And I can't say the reasons they're doing this are wrong, but we're on, we're gonna be, we're gonna be lesser for it. Worse for it. Some nations are doing this because they don't want their supply chains held hostage.
I can't blame 'em. Fair enough. Others want to protect their citizens from foreign laws that don't reflect their values.
Again, makes sense to me. And some look at this and say, this is about national security. This is about our very survival as a people, as a nation.
And they're not wrong either. However, it doesn't make me any less sad for what we're losing in this bargain. But I'm not blind to the what's going on and why, why it's happening, it's history.
It's more this is humanity. So I accept it in this new ever era, every nation has to have the right to build its own digital fortress. As I said before, Mark Carney, the PM of uh, Canada.
He said it straight sovereignty now means resilience. But let me put it even play it planer. Digital sovereignty today is national sovereignty.
You can't be a sovereign nation if you don't have control over your digital sovereignty. But wait, I'm not done. 'cause there's more.
'cause here's the part that doesn't get said in all of this. Digital sovereignty, national sovereignty talk, as important as it is, as it is for the nations of this world, to control their ai, to control their infrastructure, to control their data, is just as important for you and me to control ours. Digital sovereignty isn't just national.
Digital sovereignty is personal. And that's why I say digital sovereignty is national sovereignty. And digital sovereignty is personal sovereignty.
'cause it is personal. Every individual, it's a human right, deserves control over their digital footprint. It's their data, their privacy, their independence.
You shouldn't be under constant surveillance unless you actually have done something to warrant it. Period. End.
If you decide, if you decide, and it has to be, you decide to give up some of that sovereignty for convenience because of some apps or services or shiny features you want to use. Hey, that's your call. I may not like it, I may not agree with it.
I think you're making a mistake, but it'll be your decision, not anyone else's. It should never be someone else's decision. Not your government, not a foreign government's, not some platform's decision, certainly not some algorithm's decision in this fractured digital future that we seem to be speeding off to.
Sovereignty can't stop at borders. It has to extend all the way down to an individual, to a bubble around each individual. So yes, digital sovereignty is national sovereignty, but don't let it get you that twisted.
Digital sovereignty is personal sovereignty too. And every single one of us is entitled to it. And that's what Jimmy says.
Have a great weekend, everyone. Jimmy says, Oh my God, I think, did they, do I get? Good Lord, why couldn't you lower the bar at all?
Something. So I'm in data center and I believe in redundancy and I brought every possible device I could to remember. I could tell you what I do, but then I'd have to kill you.
Alright? That just tells you that I'm boring. I wear black because I like to think that I'm cool and infallible when in fact I'm probably not.
But I'm gonna make you think that today. We'll see how it goes. Alright, thanks a lot for that roll on too, by the way, IRA, I, I, I gotta let you know Ira, and I've been speaking on stages for a long time, for many years.
Probably upwards of about 10 now. And, uh, and he taught me a few roles along the way. We'll talk about one of 'em a little, a little later on.
But, uh, one of 'em was always make sure that he has the clicker. So it only took me 10 years. I finally got the clicker and it, and it, it's not even his.
So whoever's clicker it is. Thank you so much. Appreciate you.
Alright, so project management. Let's take a look now for, I think it was Dan, this is AI gen. You're gonna notice my AI generated, I am skilled at prompting not, um, but these, these are not.
Now dad has to sue you. These are not my images. I am under no circumstances making any kind of money around these images.
Um, but what do these guys have in common? Hero Zero. Yeah, that's, that's a, that that the wrong one.
I took the wrong drama mean today too, as well. So there's that. Um, yeah, the heroes espionage, you guys are, you guys are, you know, making some really great comments, but that's, that's not true.
Um, what they all have in common is they don't have the last presentation of the day on the, probably the most boring topic of the entire conference. Project management, which I push, you know, probably the excitement akin to, you know, accounts payable, but, we'll, we'll work on that. Um, I blame Ira for my fabulous position in this presentation, and that's okay.
You probably did it on purpose. Um, because nobody wants to do anything else, right? Nobody wants to do anything else out there.
I'm gonna leave this picture up so that you can associate me with fun. Alright, so my name's Dr. Uh, Dr.
Tracy Brown. Um, I'm chief of staff at Stream Data Centers and VP of our newly established project management office. Uh, we do a lot of really cool things along the way.
Today I'm talking to you about project management, uh, what project management is, why it's important, how we can collaborate in various permutations of the theme project management. And, uh, hopefully we'll keep it exciting along the way. I'll skip in a couple of action verbs and, uh, keep you awake for the next few minutes.
I hope, um, let's just say for the sake of argument, to save a little time that my wisdom is akin to a natural wonder and, uh, that is timeless. And we can go ahead and agree to that and just, you know, accept all of my wisdom with without any judgment or, uh, or questions. I'd appreciate that.
And, uh, and we'll get along just fine. Anyway, so I ran and I spoke together for a long time. We, he stole my thunder earlier.
And, uh, we had a, we had a book together that was called, uh, we Can't Stop Stupid, right? You Can't Stop Stupid. And it is, you know, shameless plug available on all of your outlets online and some of the Barnes and Nobles that still exist.
Damn you, Amazon. So, uh, in the spirit of, of moving on, uh, I, I got a lot of lessons from Myra along the way. And one of those lessons that he taught me, which was actually pretty useful, is that if you ever get a slot at the end of the day, make sure that you let them out a little bit early.
Give them all of your content right up front. And uh, and at the end of the day, they're gonna give you brave reviews, brave reviews, and they're gonna think that you're absolutely brilliant and they get a few minutes extra. So here I've done my AI generated photo of all of my talking points.
We'll be talking about project management strategy that spun governance, Tracy Brown, myself, I'm pretty interesting sometimes agile. And, uh, we can probably just kill it from here and call it for the day. But alas, I won't be allowed to do that.
Here's my next one. This is what I had given him originally. I said, project management for CSOs just isn't exciting.
I feel like I'm gonna, I'm gonna recruit everyone on a quest to save the world through a fabulous collaboration between project management and security. And so, like the superheroes you saw earlier, I thought that makes me akin to Wonder Woman, I think. And so the title of this should be I Am Infallible and I can teach you to be the Same, right?
Sure, why not? Let's give it a shot. So this is what my brain looks like most of the time.
I am knee deep of 25 years in project management filled with spreadsheets and raid logs and schedules and priority lists. And it can be a little crazy and a little bit intimidating. And the CSOs that I've worked with will often get stuck on a lot of these charts and it can get frustrating and extremely tedious.
And that is one of the main reasons why it's so important to work with a project management professional who can help you along the way. Not just translate this, but help you play the Tetris game of meetings in your calendar. That way you don't have to worry about that, and your SMEs will have time in their day to do what it is that they do.
Now, if you're not gonna listen to me, which is absolutely perfectly fine, it happens every once in a while, especially when folks are prioritizing. Uh, we can go along and try and figure out what's gonna be the most important thing that we'll do. They don't always listen.
And so I just look at them and say, okay, well just keep reprioritizing your projects and hope that you pick the right one and that it goes well. And it kind of feels like looking at a menu at a restaurant that has this expansive selection. And so you wait to be the last person to order so that you can hopefully miraculously mouth the words of the right selection.
And sometimes it goes right, and sometimes it doesn't. That's what prioritization often looks like in project management with security. But let's go back to here.
Um, I like these guys 'cause one, they are some of my favorite action heroes, but even more they can teach us really quick ideas on how we can approach project management. 'cause believe it or not, they actually work on projects in their movies. So if we think of, you know, John Wick, he teaches us that all we need is a little bit of focus and maybe a pencil, but focus.
And then Indy teaches us that we need to pick the right thing, the one that has the most value, do it quickly, pick the right project, pick the right artifact, and leave the other trinkets behind. And then Jason Bran teaches us that we need to be quick, we need to be fast, we need to be agile, nimble. And then Mission Impossible tells us that we also have projects and initiatives that probably are worthy of self-destruction.
So we need to know when to do that. And then Star Wars is teaching us to stay focused and not go after every tie fighter in the sky. Just like we don't wanna go after every project.
Now let's get a temp for the room. How many of you guys work with project management in, in getting your strategy out there? Okay?
And do you have PMOs in your organizations? Okay, some of them don't. Alright, We're acting as a PO for the Organization.
You're acting as a PMO for the organization. And what happens to your SMEs when you're doing that? They, they feel like they're taken with no heads running in all directions.
Absolutely. They're over allocated, they're stressed out and they're not necessarily the project owner, right? They don't have the opportunity to make the decision.
A lot of times they may get confused. They sure as heck don't wanna deal with all of those spreadsheets. And so when it comes to them to try and make a priority list, they may not have all the information that they need or the visibility that they need to make a priority list that's actually gonna work for you and your organization.
And so what does your priority list look like? It looks like this. Everything is number one.
That's a top priority, that's a high priority. That is hot priority organization. And everybody has their own idea of what needs to be a priority.
It doesn't think the same as security. Doesn't think the same as operations, as legal, as compliant as design and construction or any other organization that you have within your company. And so, okay, they come up to you and they say, not everything can be a number one.
Fine, fine. So we do that. I love it.
And I've worked on a ton of different ways on how do we figure this out? How do we know which ones to pick? Well, we can try sticky notes.
I've tried above the line and below the line. But really we need to figure out which metrics are gonna help us get to where we need and want to go. What is our organizational strategy?
How does that bump up against your security strategy? And what are the numbers associated with that that are gonna drive us forward and make the board happy at the same time? This way when someone comes up and gives you another shiny thing or another top priority, you're not looking at them like this.
Alright, so let's get serious. We're gonna run through, uh, a quick framework and, uh, and hopefully I won't take up too, too much time, but this is why it matters. As CISOs, you guys own the strategy, right?
You're saying this is what our risk posture is, this is how we stay compliant. These are the metrics that are important for us. And as PMOs, we're helping you with execution, governance and letting you know what's repeatable, what we can track.
And we have a visibility across functions where we can let you know, here's what's working and here's what's not. So together we have fewer failed initiatives, we have faster results, and we have a sense of security that maybe we wouldn't have had before because we can now prove it and bring receipts. So quick framework overview.
We want to translate our strategy to initiatives, establish governance and prioritization, make sure that we have the right approach when we're delivering a project. Conduct change and risk management. And that's important because everyone will have their idea of what change management is versus risk management.
And then make sure that we are showing the right metrics for security and the business and how they relate to one another. We are going to manage our resources and vendors deliver incrementally and then have continuous feedback and improvement. So first we translate the strategy.
So we wanna decompose your strategy into programs and projects. And for those of you who understand a program is an overarching initiative with multiple projects underneath it. This is an overarching initiative that says this is the direction that we're gonna go.
These are the benefits that are going to happen with the business, and these are the projects underneath it that are gonna get us there from projects we develop work streams. That work stream can be akin to a particular functional group. It could be delivering a certain thing as part of the project, but we can decompose that down to make them very simple and task related.
So we go from strategy to tactics. We can help you align with your business objectives. So if the business is saying we need to lower our click rates by X percent, then we can help you identify what else is gonna help you get there.
And those are using your metrics, your KPIs and your OKRs or your key, your key, um, numbers. So for example, rather than saying we're gonna implement some kind of an antivirus or a malware, uh, software, we're not saying that we're going to reduce phishing risk by 40% and these are the numbers that they wanna see, rather than we're gonna deploy an email gateway. So when it comes to looking at strategy, goals, outcomes, et cetera, sometimes it gets a little bit confusing.
Uh, overarching outcomes. These are our strategy or our organizational goals and end results that we want to achieve. Whereas our strategy is the broad approach or plan of the desired outcomes that we want.
Our tactics are actionable tasks that we're going to take on a daily basis for practical execution. And then finally, we have our objectives. And these are our measurable steps that we'll be able to let everybody know.
This is how we connect our strategy to our projects. But which metrics do we look at? This might give you some anxiety with all those things that I'm sure many of you have to report on, but which ones are the most important and they're gonna change all the time.
What's important for your board? What's important for the leadership of the organization? What's the biggest threat?
And with an ever changing threat landscape, we need to pick the ones that are most important and focus on those which leads to governance and prioritization. In my organization, we have a governance program that is the COO, the CFO, the CTO and then myself. So we'll go through all of the initiatives that are proposed and determine which ones are gonna get us our bank for the buck, what's most important.
And we have a rating scale along with it. So what is the business impact? How much are we going to reduce risk?
What is the urgency? How much effort do we need to put into each one of these initiatives? And then we give a score, we'll hand that back over to our executive leadership team, even to the board, and we make a determination about what's gonna be best for the organization and we'll use this risk and the impact scoring model for prioritization.
The other thing that we do with the governance committee is make sure that we have a charter. And what that charter is saying is that everyone on the governance committee commits to doing these activities. We agree that when we come together, we're prioritizing in this way.
This is the model we're using, these are the standards we're committing to. And that's the charter that we all sign. Next step is identifying a delivery approach.
And there's some different ways to do this. We've seen waterfall, so it's very linear, very phased approach. One step at a time.
Um, construction is very waterfall. You do this first and then this, and then this, and then that. Whereas with agile, we have iterative releases, we understand the business requirements, we go through a development process and then we, we design, we develop, we release, and then we go back into a feedback loop and make changes as needed.
So we can deliver more frequently, but also make changes as needed in a scaled agile approach, where you have a lot of cross-functional teams or multiple functions that are working together, we can use a hybrid model where in some cases you're delivering waterfall, but you also have some agile and iterative delivery in the mix. So for example, if you have an incident response project, you may deliver that in an agile, in an agile way. However, if you have a heavier project like a construction, then you have waterfall.
'cause agile's not gonna work. Iterative development is bad idea in construction. However, if you have a larger enterprise organization and they have multiple teams, like maybe a data lakehouse that's getting implemented, so now you have operations in there as well, then you can work at a hybrid model and deliver both.
And your project manager will help you select which model is gonna be the best for your initiative. And then with change in risk management, one of the biggest things that can happen here is that when we're implementing something, it might not get adopted. For example, if you've released say A DLP effort, but it wasn't used because nobody knew how to use it.
Uh, one time I was working at an organization and people were leaving their passwords on sticky notes under their keyboards, you know, all of that. And so they released a password locker, but they didn't tell anybody that it was gonna be released. You just got an email that said, Hey, use your password locker.
And there was no training behind it, nobody knew what to do. And if there would've been some project management behind it, we would've incorporated communication as well as training and then behavior afterwards. So we have a follow up to make sure that they've adopted that particular platform, that particular process, and then off they go.
Now, one of the things you may wanna consider when it comes to human behavior is performance management. And this is something we take for granted and not a lot of people like to think about it. Um, we heard later or earlier someone mentioned who likes year end reviews, nobody, because a lot of times it's a surprise that something went wrong, right?
But if you work with the project manager and they're doing a good job, then they can actually work with human resources and your management level to include performance management as part of your plan. So now you're implementing a particular initiative and you have a follow up plan with the management to make sure that that behavior change has actually taken place. And then maintain a risk register for both your delivery and your cyber risks.
So you have project risks. If this happens, then this could happen and we need to figure out how we're gonna mitigate that. But we also have the cyber risks.
So what a percentage of, you know, phishing emails are actually coming through. How many people are clicking on something they shouldn't click on? And we under, we need to understand what that cyber risk, we can probably use that number generator that, uh, was it Dan had and understand what that potential risk could be in, in different numbers, money, time, et cetera.
And from our book, if you get a chance to read that, which I highly encourage you to do because I think it's fabulous, is, um, culture champs or security champs in a few different organizations. I actually implemented this and it was fantastic. We had one person at different locations who was actually the security champion.
So they worked with cybersecurity to understand, hey, some of these are some of our initiatives, these are the benefits for you. And they would spread that message at each of those locations. They were also a point of contact for those folks that were on the front line and security, kinda like a mini translator, and they would help with little nudges and all of that and help reinforce that security culture that we all want.
So secure champs or culture champs have been really helpful along the way. We wanna make sure that we have the right dashboards that are giving the right message. So if we're prioritizing correctly, we've associated metrics to our initiatives, we're doing this particular initiative to increase our, what does it mean to detect, right?
Um, mean time to detect. We wanna be able to have that faster. So how much are we going to increase it?
We're gonna do that by 10%. Our meantime to respond. What have we done?
We've decreased that by 10% by implementing this particular thing. And now our risk has lowered by this amount. And this is what we wanna show in our dashboards along the way.
We also wanna make sure that we are going for our quick wins because many times your executive sponsors are not gonna be okay with waiting three years for a roadmap to get implemented. They need to know that there is something happening right now. So let them have exposure to what your benefits are.
For example, um, data Lake House project we were implementing, there were only three groups within the entire organization that were ready to have reports in the data lake house and then have those generated because they had everything that they needed in their platforms where the data was gonna be collected. However, the rest of the organization didn't. There was a lot of work that still needed to be done.
So rather than wait a year for us to figure out all of the data sources, we went to those three mature groups, had them fixed and sent into the data lake, created their dashboards and reports, and were able to easily come out one and a half months later with a connection to the proper data source, anonymization of the right data that needed to be. And then they had their reports ready for the executive team. And it was quick.
Once the executive team saw that we were delivering and they saw the progress, they were totally cool with letting us continue and we were able to get the rest of the organization done. Mind you, it took a year and a half, but because we did our stuff right the first time, they were cool with it. So this is herding cats.
This is what our job feels like most of the time, trying to figure out how are we gonna get everybody on the same page and how do we get everybody together despite calendars and holidays and anything that else that might be frustrating with pulling people. Um, but in addition to herding cats, uh, we wanna help your SMEs have capacity so that they're, like I said earlier, not playing Tetris with their calendars in a lot of meetings that they don't need to attend. So when you assign a pm, we're actually your superpower because we act as a force multiplier.
We give them the opportunity to do what it is that they do best because they're the smi and as a project manager, we don't have to know everything because we have them and they have the time to go ahead and focus while we're working on everything else. Keeping things together, coordinating not just within your team but across your teams and also with your vendors, speaking of vendors, your PM can also help you ensure that you have proper vendor management and give you metrics on cost and delivery and make sure that things are coming along. Because as many of you probably know when you're working with vendors, is they can be at a 90% complete for a really long time until the contract is ready to renew.
And then maybe it'll be complete. So they can help you with vendor management as well. Deliver incrementally, as I mentioned earlier, you want quick wins for quick value to make sure that your sponsors are excited about what you're doing and continue to support you along the way.
And then focus on measurable risk reduction per release, right? These are back to our metrics. What are you doing?
What have you done so far, and how is it getting us better? All right? Continuous feedback.
If you have a roadmap, a strategy roadmap that hasn't been updated in the last six months, but we have an ever changing landscape that probably changes on a daily basis at this point. Um, your, your roadmap is probably an, you know, old and not aging well, like wine or me, no, I'm just kidding. Um, but more like sour milk.
And that's what I thought when I, when I put this gift up here. Um, the other thing you wanna do is you have continuous feedback. In, in the book you'll see a concept where, yeah, we have defense and we detect and we, uh, respond and we recover.
But we need that feedback loop at the end to be able to come back and fix anything holistically across the organization, whether it's technical solution or a process. And so allow your, your project managers who are used to doing a lessons learned, help you along that way as well. Where do you have gaps?
And let them give you the feedback loops that you need to make your processes better. So create a lessons learned library, but don't just shelf it. Actually go back and take a look at your processes and make sure that they're improving along the way because your roadmap is a living document given all the changes that are happening all the time.
So you want to just like Jason Bourne, pivot fast and be agile. So in summary, um, your CISO as you guys and your PMO should be a solid partnership. We should be working together for you to say, here's the play, and now we go and execute the play and we work across your teams to make sure that everybody's in alignment, everyone's in agreement, and we have the right metrics and the right numbers that you need to show that you're actually making progress.
So for example, if you're gonna give somebody a burn down chart because you're using Agile on a particular project and you say, we've met our velocity, we're doing great, what the hell does that mean? It doesn't mean anything. We need the metrics behind it to say, okay, we've done, we've done this work, this is what we've accomplished and this is what it's done for you, the benefit to the business.
And that's what your board is gonna want to hear. So translating strategy into those projects, using the metrics that you need, maintaining visibility so that your executives understand exactly what it is that you're doing and why it's benefiting the business. Um, being adaptive and a risk driven execution so that we are actually implementing projects that are driving down risk and then providing measurable outcomes in the end.
Quick overview of framework eight easy steps. And then there's plenty of tools and templates. Um, this could actually be a couple hour workshop, but the first thing you want, as I mentioned earlier, a governance charter so that there's agreement for the governance group that you put in place, ah, a project prioritization template where you're looking at the risk and the effort and the cost so that you can make the right decisions.
A basic project charter. And this starts with the problem statement. And this is the part that's most important.
What is the problem? The problem is this. And because of that, this is happening.
If you can't put a problem statement within one to two sentences, it's too, it's too big, it's too broad. You need to crunch it down even more. A problem statement should never be more than two sentences, and that is the basis of your project charter, because that will always be your north star.
If you can't break it down to one to two sentences, you will absolutely have scope creep all the time. And so now you have more time, more cost, and probably less quality for whatever it is you're trying to implement. And then make sure that you maintain a risk register one for the business so that the business understands the risks that are associated there.
And one for security. So we know how we're benefiting security as well. Your RACI is gonna tell you who's responsible, accountable, consulted and informed so you know who your players are in any particular project.
And then your metrics framework, what are you doing to better the organization, how are you benefiting? And then of course we have these again, how they can easily help us out, right? Focus, pick the right projects, stay agile, move fast, pivot quickly.
Know what your kill criteria are for any project that needs to self-destruct. And then make sure that you stay on target. Okay, here's our book again.
There you go, IRA, I win my $10. I'm Tracy Brown. Um, this is me.
I would love to help you. I hope that this was helpful for you. I think I kept us on track and 10 minutes early.
Nicely Done. So time back in your day. Oh my gosh.
Thanks you guys. You made me a little nervous. Oh, you have questions?
So I'm hiring a security project manager if anybody's looking by the way, uh, forgot to stand up. Um, do you think that domain expertise or industry expertise is more important for a security project manager? Excellent question.
As a security project manager, I would want to have a little bit of both. So in my background, because I came in from IT as a network administrator, I understood a little bit of it in the military, which was learning years ago. Um, I had a little bit of background there from electronic intelligence.
So it was very helpful at American Airlines that I had some security background and was able to come in with my project management background and help Dan Glass, who was the CSO at the time, implement quite a few things that helped out the airline. And we worked on all kinds of stuff from implementing MFA to Shaw two on aircraft. Thank you.
Yeah. But for the most part, a lot of times you'll find that as long as somebody is excellent and has mastery around project management principles, being a generalist is fantastic, which is how I wind up getting into a chief of staff. We know a little bit about a whole lot of crap.
Yes, ma'am. I have just one question about mm-hmm. Um, we were talking about the feedback loop.
Yes. And haven't worked in consulting for a lot of years. I've noticed that certain organizations are really good at blameless postmortems, whether it's, uh, incident response type situation or if it's a long-term project.
But one thing that everybody seems to have a challenge with is like taking the lesson and documenting it. Mm-hmm. So that actually goes, you know, into policy or, or changes some aspect of what we're doing.
Like we learn something. Yes. Everybody wants to really document and even sometimes very high in the organization, the are like about, about it.
What are your recommendations for That? Um, that's actually built into the plan. So we set the expectation right off the bat that as part of our change management and behavior or adoption of whatever we're putting into place, we let them know right off the bat, this is part of the plan.
This is something that we're going to do, these are the players that are involved that way they already expect it when we get to that point. And whether or not it's something that they want to do or prefer to do or not to do, they already have that expectation set and so they're ready for it by the time we get there. What I found is that in a lot of organizations where we don't have that available or they feel a little anxious about doing it, there's a lot of problems with accountability.
Mm-hmm. And so we have to address that along the way. Thanks.
Yeah. Um, I think most of what you mentioned is pretty much fantastic in terms of in principle, right? Most organizations that I've worked with, um, or actually, uh, let me take it back to your previous statement right.
That you talked about having a person who has a fundamentalist of project management. Correct. And getting that person's role mm-hmm.
Is very critical. Yes. Most organizations that I've worked in, um, I've seen it turns out to be a bureaucracy mm-hmm.
Prevent that. You can't prevent bureaucracy. We have to typically work around it.
But again, a lot of this happens in the planning stage, which is why it's important to have a project manager. We set those expectations right off the bat. One of the very first things we need to have is a racy.
We need to know who's gonna be involved and who's responsible for what. Right off the bat, we need to know who the decision makers are and we can observe who our people will be that could potentially block us along the way. And we make those, right, those known right off the bat.
So if we know, oh, well this person over here in legal is probably gonna try and block what it is that we do, however, these per these two are the sponsors and they're the decision makers. So they have the ability to override. Now at this point, here's what's going on.
Decision maker, sponsor of this initiative, this person is a blocker, and as the decision maker, that's your responsibility to handle it. If not, this is the risk associated to it. Sign here.
Yes. So one thing I've seen at a number of places I've been is that there's a debate on whether or not cyber really needs a dedicated project management. Oh, you'll get one assigned from the broader IT organization or you know, you're gonna get a loan or maybe it's just one project that you're gonna get it because it's a bigger initiative.
What are some strategies that you've seen to help both the CISO and the security organization as well as the broader organization see the value and dedicated project management from a security perspective? We bring it back to metrics. Every single time.
They have to understand the risk associated to it and the cost associated to it. So if they're not doing something and it costs them this much and this much time, then they understand that. And if they don't do this, and that's the most important part of it, is if this then that, if this and not this, then this, this is what's gonna happen if you don't and you accept that risk and you accept the cost associated to it.
And that's typically how we'll what we'll address that. But what I've done also is train a little bit with project leads to work with project managers so that they can communicate. And when the PM isn't able to translate the, the technical side of it as best or is, you know, better, then they have already established a level of communication that lets them know like, Hey, I, this is where my expertise stops and I need you.
And they can, they can have better conversations. But the metrics, the metrics right off the bat. Yes.
So, uh, as part of your, uh, secret staff role, obviously you, you'll deal with a lot of processes that is repeatable, I assume. Mm-hmm. And, uh, now we are in the agent AI world and you are probably gonna be, uh, uh, like sitting down with some founders coming and saying, Hey, I, I can automate most of your grant work with like, whatever, like the sim the sim automation space.
Mm-hmm. Your, like the PM work is also pretty much right. For disruption in terms of taking the Ah, So what is your reaction to that?
Like if somebody says, gonna build a tool, We can automate your project management, we don't need you, we have AI that can look at our calendars and set our meetings for us. Absolutely. You most certainly can.
We have copilot, it already takes notes in all of our action items. We don't need you. Yeah.
Okay. That's fine. That's fine.
Let's see how you do. Because there's still a human factor com, uh, a human component that's associated with it. And believe it or not, what I've found most, and, and I'm just gonna tell you with a lot of CSOs that are not confident, what I find that they do is they throw a bunch of spaghetti at the wall and hope that something sticks rather than having faith in their team knowing that they hired the right people and that they have the SMEs in place to actually do the job that they need to do.
Rather, they pick up the ball themselves, throw everything at the wall that they can and hope that it sticks and not hold their people accountable. Right. Unfortunately.
So part of that is also ensuring that you hire correctly and that is always a human factor. And your project managers will be able to see they have that level of visibility to see how people are working, how they're working together or how they're not working. But more importantly, is fire the ones that Fire fast.
I believe in that. Other questions? Yes.
Uh, only just a comment on the, the AI replacing, I mean, there are, my entire career in the federal side had a PM assigned to me. Mm-hmm. Most of the time they were not really technical expert.
Right. I really didn't need it. Mm-hmm.
I need somebody who's highly disciplined Yes. Taking a multi-million dollar project from beginning to end track Kevin, Manny, were late here mm-hmm. To get, you know, get engaged.
Yeah. And, and that thing of the, the person getting a hold of the other person, I mean, hey, to be able to do that, like, hey, this is Jenny and I'm you interaction that sometimes you gotta put, you know, increase on the skin Right. To, to get things going.
You Do. Yeah. I don't think it's gonna go away.
It's gonna be different. I absolutely agree. I don't think it'll go away at all.
It'll absolutely be different. Will AI help? I've found that AI helps tremendously and so do my project managers.
We use it all of the time. However, that human factor always, um, makes a play. So for example, uh, we don't have an AI right now that can monitor all of the risks that come up in a project or all of the risks that are associated with security across the organization.
However, we do have project managers that know how to look at these documents and say, I foresee a problem. Let me escalate this as quickly as possible. And so until we can find someone or an AI that can help do that plus be able to understand human behavior, then I think I'll have a job for at least another year and a half.
Some people are not comfortable with the ai. So if there's an old, I don't wanna say an older guy, I mean that group AI resemble that remark. They wanna deal with a person, not some automated stuff.
So that's true. You still have to, you know, yeah. Yes.
Yes ma'am. Recommendation for how you approach a C level person who, uh, usurps the priority and doesn't really get that everything can't be at number one. How do I approach a C level person who usurps a priority level one?
So I'm thinking of an example. Um, what I've done just real quick that comes off the top of my head is what I've done is really hold them accountable to the decision that they're making and let them know if this is really how, what you wanna do, then fine. But these are again, the risks associated to it.
And then hold them accountable for making that decision. So Like the opportunity cost Of Absolutely. Yes.
100%. Yes, sir. So how do you strike violence between a purchase risk and the superior risk and there's a conflict.
'cause sometimes the are risk register themselves A, B, C or whatever mm-hmm. Along the line, risk timeline. What's conflict regards to completions?
Mm-hmm. How do you, how do you At that point, it comes to the business sponsor and it's up to them to determine what their risk tolerance is. If we have a project risk that def that directly impacts a security risk.
So for example, if we don't implement this faster, then our risk for this particular metric is going to increase. I can bubble that up and escalate it as, as quickly as I understand that it's happening. But then at that point, it's, it's up to them to determine what their risk tolerance is and then we can make the changes.
Do we need to put more people at it? How can we crunch the schedule? How can we make this happen faster?
Do we, do we discontinue doing other projects so that we can all hands on deck for this over here? And if they're not willing to make that, then sign here. Yes.
Uh, you talked about security champions somewhere in one of the slides. Mm-hmm. Um, I've done this in multiple places and get to come up with metrics which we can say are indicative of success for that program.
Is that some metrics that you recommend for that That depends on the project that you're trying to get them to? Just the security to support, uh, just, Just the security champions program itself. Mm-hmm.
Oh, okay. For security champions program, um, I really didn't have metrics associated to security champions. Those are very qualitative.
Right. They're not quantitative. So it was more, we had more engagement.
They asked more questions. People are coming up and, and asking for this, or they're, they're coming to a meeting or they're, they wanna know more about a particular message that's sent out. So very qualitative, but good question.
Or we can look at the outcomes. I mean, you cannot attribute only to the, the particular program, but there's the general trending is all that matters. Yeah.
You, you could do that, but he's saying with security champions, like how do we know they're doing a good job? Yes. Just a comment, uh, based on your workflows.
Mm-hmm. I didn't see it's a sports project operational support, which is if you're bringing new technology or you're bringing in the process, what's gonna happen after it become operation? That is enough people that we have run books that we have support of.
You're absolutely right. However, that is also part of the project plan that should be included right off the bat. So that's part of the feedback loop.
Um, that's, you build that into the project so that you are refining processes, you're building your playbooks or your run books. You are getting ready to operationalize this. A lot of times I have people in operation say, well, what if we wanna run this program?
We wanna put a program into place. Don't we need a project? Okay.
I, I understand we're mixing up what you see as a program versus what I see as a project. We're gonna run this thing that you wanna do one time that is a project and we're gonna set you up to operationalize it. That includes all of your training, that includes your behavior adoption, that includes playbooks, et cetera.
So that's part of the planning process. Yes, sir. I just wanna say thank you for the cultural influencer part.
'cause that's a big piece in our Area. Yeah, yeah, absolutely. Same.
I've seen great success using culture champs or security champs along the way. Tha thank you. I think you had, uh, you had your own framework for how you are, uh, looking at the, uh, uh, program.
Mm-hmm. Let's try to any best practice pro like standards like COVID or, uh, like what is your take in general for having a framework that everybody like lives and breathes? Um, I try and keep it as simple as possible.
When I was, when I set up the slide that said tools to use, that's my basics. Absolute basics is agreement with governance and prioritization and using those simple tools, the problem statement on a charter so that we know what our North star is and we can't deviate from that. And we don't have scope creep.
We understand what our risk registers are, we have our race's and know the players, and we know who the decision makers are and everything is set up upfront. That's the very basics is what I, is what I are the lifeblood of it all. You have something specific for security That's, no, you don't need anything specific for security.
We use the same things and, and the, the same methodologies. It just really depends on which one's the most appropriate for the initiative that you have. Yes, sir.
Um, in your risk framework or your risk table, it looked like maybe it was a spreadsheet. You had a bunch of different factors, but none of them were cost. Mm-hmm.
When you were determining your prioritization, is that because cost is not a factor? Cost is one of the Whatever business case. Yeah.
The time you get to the prioritization, somebody's already asked for the money. Yeah. By the time we get the, we've already done quotes and all of that.
Well said. But that's because you also directed a PMO, so you go, girl. All right.
IRA's giving me the look, which means shut up now. Tracy. Thank you guys.
I hope it was helpful.