Techstrong TV January 29, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. Welcome back here to Techstrong tv. You know, we recorded this on the Snow Apocalypse Day, and a lot of, a lot of people, well, we were late getting this done because we had some people not able, not this one, but previous interviews we had people without power, without heat, without internet.
But my next guest has no problem. He's out in beautiful Honolulu, Hawaii. That's right.
Living the Life. Let me introduce you to Dan Cole, SVP of Product Management at Sophos. Hey, Dan, welcome to Tech Drunk tv.
Uh, Little Hi, Alan. Yeah, I'm coming from Honolulu Live. Um, yeah, yeah, look, it's, it's really nice to be out here and the weather is 76.
Nice and cold for us here. I put on a sweater, but, um, you know, we do have some stuff in Monolo. Occasionally you can snowboard that Yes, you do as a beat.
But, uh, the, the, one of the parts of living on a, the sad part is I do get up earlier than the morning, three or four of them, or it's actually six 30 here. Sun's not out yet, but you get a lot done that way. But, um, yeah, it's, it's been great.
Um, you know, um, being in Hawaii a lot of times you get both sides of the spectrum. You get a lot of folks. Um, my, my India team and Germany team, by the time they're up and I get up already halfway through the year, the day.
So yeah, lot, lot to get used to there. You know what I, I'll I'll admit, I, as I was talking to you off camera, I've been to Hawaii many, many, many times, and I have fantasized about moving to Maui, actually. And I, and I figured that's exactly what I do.
I'd have to get up at about two, three in the morning, put in a day, but by noon the day, the rest of the day's mine. Yeah, Yeah. I guess Beach and all that.
Yeah, no, absolutely. Of course, as I said, it was a fantasy. Um, though my wife, my wife lived it with me.
She'd do it too in a heartbeat, but, you know, so we settled for Bo Herts on Florida, where it's also about 70, 60 degrees. Hey, Not a bad spot. A beautiful location.
Not a bad, yeah. On the water. But anyway, we we're just, of course, saying this to rub it into all you poor souls out there.
We're, we're snowed dead. Dan, how did you get to be SVP of product management at Sophos? Tell us a little bit about your journey.
Yeah, I know my journey here. So I've been here for about nine years. I've definitely seen a lot of changes even at Sophos, but in the security business in general.
But I rewind back to 1998, that's kind of where I really packed my teeth into security. I worked that at telecom here in San Francisco, in California when I lived there, um, during the dotcom era. So my first experience, I think it was like day week one, where the Melissa virus hit and we were Oh, yeah, for the, for the SOC and the NOx for the, the Sun Spark Systems that ran all the exchange systems, right?
So my first week was balancing servers and then kind of fast forwarded a couple months later, then I love You virus, hit again, another issue there. And I quickly realized that it, telco is probably, although it's a hot spot, you kind kind of run up to move up the stack. And our first job after that was in security working for a company called Sonic Walt.
And, um, you know, they're still around. They're still around. Yeah.
Yeah, I definitely, I have my roots there, but, um, code Red hit around that time. So, you know, it's just my, my, my experience in cyber has always been the reaction of all these different types of events happening, and me just kinda like drinking from a water hose and figure out what is causing all these issues and how do I get a customer's back on the right foot. Um, yeah, so, so Sowa was kind of my first area.
Then kinda moving up the rank, we, I, I worked at a couple startups in, in Silicon Valley where we did some embedded chips where, and how do we make the chips power be fast enough to run on these next generation of appliances and systems in there. Um, and then you kind of fast forward about a decade later, moving in from, uh, sales into more of a PM role where I figured kind of going upstream, let's go fix the root of the issue, build the product the way we want to feel, build it. Um, and I worked out a couple other different competitors in that mar that space there.
And, um, you know, I think what I learned quickly is that as you kind of move up the stack and up the ranks from, you know, an SMB to the enterprise, it probably just gets even more difficult, more interesting to go south. So I went from just having network security becoming kind of my, my main, my main forte to kinda expanding that and talking about the solution as a whole. How does it integrate with the, the interactive system that's out there, whether it be Sims or Jason Layer two technology or even going up second to cloud.
You know, that's kind of been the last 25 years of my, my journey being at Sophos. Um, the reason I came over to Sophos was to build a firewall from scratch. And, you know, in 2015, there wasn't a lot of firewall vendors that are building things from scratch.
If, you know, a lot of times you're just kind of taking over an existing business. And so the exciting thing about Sophos is they acquired P two companies called Starro and Cyber, and we were trying to get those two technologies and build something new out of that. And, um, you know, Joe's, our CEO where I worked for in previous roles, um, was like, Hey, why don't you come over and go, go build this the way we wanna go build it.
And so my last eight years here, my journey has been rebuilding the data plane to the management plane, the control plane. And so now we have this new product called XGS that now it's in our second generation of hardware. So I'm really happy about, about that.
But through that whole process and that, that exploration, we realize that as you move up from just the UTM you mentioned to next generation firewall to network security clients, that it's not just that system that has to work with endpoint and has to work with adjacent technology. So the last two, three years from that next, that next generation of technology we built, how do we now hook that into the rest of the ecosystem that so has, right? And so, uh, I'll tell you a quick story.
So during COVID when we got hit with a lot of the different threat actors that were hitting the different vendors, you know, we're one of 'em, we actually have a great research pay product called Pacific Graham, where we documented how these, these, um, poor national threat actors actually invaded our, our products and, and got into it through, through, through some very complex attacks. And I think that w that's the point in time where we realized that, hey, we some service that capability that can react to that. You know, we had those, we had a 24 7 bridge going on for weeks as we were responding to that.
So the, the, the, the birth of MDR really came from that experience that we had. Uh, we called it MTR, the not solid MDR. Um, so yeah, it's just been a really great journey last 25 years.
Just the, the evolution of where, where, where, where it all started to where we're now, You know, Dan, my my my security, oh, sorry, my AirPod came out. My security experience is probably similar to yours in terms of times and what we went through. I also got into managed firewalls in 19 97, 98.
Of course, checkpoint was like the only ones you, you know, with the OPSEC and all that stuff. And, you know, and I was also protecting Sun Ultras, spark machines, and Ultra Spark tens and twenties. And I remember the Melissa and the I love you and, and all of these other things.
You, you look back on those days, Dan and is as hectic and frantic as it was as yeah, almost baby stuff compared to what we deal with today. You, you didn't have Nation, well, maybe you did have Nation State stu as threat actors then, and we just didn't realize it. Right.
But, you know, I mean, it was, it was kitty scripters and it was, you know, I did it because I could Yeah, yeah. Script kitties and just Yeah, Right. That kind of stuff, not I, not cyber warfare.
Yeah. Yeah. Which is stakes has definitely been leveled out since that time, for sure.
Yeah. Well, the stakes, right? The stakes are higher, the attack surfaces are bigger.
The threat actors are more sophisticated with ai. The technology is, you know, they use it as good as we can. And, and that's also been, I think, a, a constant during my career in security is, you know, don't think we're smarter than the bad guys.
'cause they, they, they ain't dummies, right? They're, they're well funded, they're well organized, they're well compensated. Mm-hmm.
Right? Yep. They're, they're a formidable, formidable opponent.
And we, you know, and, and almost by the nature of the beast, sometimes they're always one step behind just by design. Yeah. You know, I think for me, the philosophy of preventing stopping threats all the time, you know, it, it, it, it was kind of the, the goal in the 2010s, 2000, you know, you, you find 'em, you stop 'em, you build out your signature database, you find a way to just court that attack.
And I think what we're realizing now is that, well, it is gonna come in and then how do you medic, how do you mitigate that time to reaction? How do you mitigate the actual amount of the out spread of the breach? How do you know something came in?
And then, then how do you ensure that you can quantify that value and that cost so that way you're, you're building it into your budget. That's still what our customers are partners most concerned about, is like, I think we're kind of in that, that that inflection point of like, okay, yeah, an accident will happen just like in a car, right? And eventually you'll get an exit.
So what's your insurance policy? You know, what is your remediation step? How do you kind of react to that?
I think a lot of, um, board level, um, meetings are kind of in that, that top discussion point. So no longer like whether or not gonna be attacked, but when it happens, how do you do then react to it? I think that's why products like services like MDR have really popular nowadays because we, we realize that that's that extra layer that you need.
It's really kind of that additional insurance policy you have. Um, but just let the car knowledge in that Absolutely. Look, to me, this all falls under resilience.
Yeah. Right. Absolutely.
Yeah. We, We, we, we, we had a shift from prevention to resilience. Not that we abandoned prevention that that's not it, but really, if you didn't have your resilience kinda planning built in and layers, you're, you're in a bad place.
Dan, you mentioned it a few times. MVR, is that what it was? What does that stand for?
Energy detection response, which is exactly what we're just talking about, right? It's really about Yep. Managing that process.
And, and you know, with, you mentioned AI earlier, and that's, that's really kind of what's changed us at inflection point there as well, where it's just, you know, how do you ensure that as you have your systems that are really complex and hierarchical or sending that information, that data in, and there is some type of an attack or a breach, you know, do you have the personnel, do you have the AI augmentation that you need to first find that incident? And then how do you go react on it? Right?
And so, um, you know, at Sophos where we quickly realized as we have these products and customers installing it and deploying 'em, that when you have these type of events, what is that extra layer of, of personnel that we can actually provide to you at a, at a scalable level? And then how do we then use AI to ensure that, detect and find those things faster? You mentioned that, that, you know, the attackers are getting, they're getting faster, they're using those tool sets, so how do we then, you know, respond in kind?
So yeah, it's managed detection response. Absolutely. Um, probably read the news.
We, we recently bought a company called SecureWorks where we, you know, we were able to kind of scale up with that new platform that they brought in. And SecureWorks actually been around for a very long time servicing various US customers and government institutions and banks. And so by getting that technology, that core capability and that human intelligence, we're able to snap that in into the Sophos ecosystem, into our product database.
And, um, that just gives us that extension that we need, which is been really great. You know, I, I, I, so my own, again, back to my own personal journey in security, I, I was the co-founder of a company called Still Secure. We did, uh, intrusion prevention, vulnerability management, network access control around 2007 or oh eight.
I came to the realization that security was just too hard for so many, most organizations. Yeah. And that MSSP was, was the way to go.
You had to have, you know who you gonna call, right? It, it Ghostbusters isn't helping you. Right.
And so you needed, you needed that managed security service provider. And we bought one down here in Florida, and we were, you know, plans were to do more. And then, you know, the oh 8, 0 9 kind of economic downturn came and mm-hmm.
Actually I left, still secure then I've been doing this ever since. But, um, I, you know, SecureWorks of course was probably in the US anyway, uh, probably the biggest of, of the MSPs, you know, that, that brought that in. Dan, if you don't, if you're okay there, I'd like to pivot over on January 20th, Sophos announced something called Sophos Workspace Protection.
Yeah, yeah. That's, that's, That's WP Workspace. Yeah.
You know, you know, really pointed, uh, the naming convention there. It's like, well, what do you do with this product where it's, it's really to protect your workspace. Um, actually, you know, good story.
During, during COVID, um, my wife and I decided to, you know, kind of roam around the country a little bit. You know, things were, you know, being in, stuck in a house. My son went off to college and we're like, Hey, let's go explore the country.
We actually stayed in Florida a little bit as well. And, um, I was remote quite often. And so the idea came to me where like, Hey, we're, I'm always, we're, you know, remote and, you know, our, our technology has us, you know, either V VPNing our Z ting, and to the infrastructure to access all the different things.
And, um, some locations we didn't have good internet. So, you know, what happens in those circumstances? Some things, uh, require a little bit more deeper investigation that maybe A VPN doesn't, just doesn't cut it for you.
So, you know, this idea came up of how do we kind of embed technologies into, you know, what you're working on. And, and the, the core part of workspace protection is really, you know, using a, a kind of a, a bro, a browser, a browser extension, using our, our, our ZTNA platform using DNS extension, using email extensions, and kind of hooking that all together and having that consistent user experience. Um, for people who are looking for, you know, suffic for the, those hybrid workers, folks who may be come into an office a little bit or maybe are remote a hundred percent of the time, how do we ensure that their security experience is consistent wherever they go?
And so, you know, there's been other different, different technology acronyms throughout this sass ESSE that kind of came about in the last, you know, this decade has been pretty popular, but you know, that, that has a lot of big up upfront infrastructure costs, requires you to tether to an infrastructure that's processing the data in the cloud. And you've been in the industry as long as I have. So we, we've done variations of that back in the day.
Cloud web security Yep. IES and stuff. And they have your own set of limitations and caveats and stuff.
So we didn't want to go down that route. We wanted to go down something that's gonna be a little bit more specific and pointed into the user experience. And, you know, one of the power, power pull play of Sophos is, you know, we, we were an endpoint company from 1980s back in the day when it's on Flocky Drive back in those days.
So, um, we have a really big endpoint presence. So we have an advantage a lot of these other SASS CSSC vendors that they didn't have, which is we have footprint coverage, right? And so, like, well, why don't we use that as a leverage point?
You know, we already have endpoint agents. What if we were to extend web control, web behavior function, which, you know, most of our activities done through web browsers, we most, I even the SaaS applications just all piped in through your web browser experience. You know, very rarely are using thick clients anymore, right?
So, um, so yeah, the workspace protection was like a, a, a elimination of all those different technologies presented to our customers using kind of our endpoint footprint. And then, um, and on top of that, we, we hooked that into So central, we just kind of a, the single source of truth that's sort of cloud management platform. 80% of our firewall customers use, use central management.
So that's pretty powerful. It's, it's been adopted pretty worldwide, and our endpoints only managed on Central. So by doing that, we're able to harmonize the policy configuration of endpoint firewall and now the workspace protection, uh, suite.
So that way you get that universal experience, whether you're on network or off network. And so, really beautiful. We're elegant, we're super excited about it.
Um, we went EAP last week. We have over a thousand people signed up in one week. And so, and we're gonna go ga this thing in February 26th.
It's been about a year and a half in the making. Um, we don't wanna just, um, it's actually powered by Island, who's our partner for this. And, um, island has been doing, uh, enterprise browsers for a very long time.
They're well, well respected, renowned, um, in the enterprise space. And so we struck a deal with them where we wanted to kind of collaborate and we wanted make sure that it's not just us providing the code and to our customer, because we and our customer is a little bit more sophisticated in the sense that we have to kind of scale up and down in organization sizes. Um, they're used to using SOFO Central and they're also missing some other critical pieces like DNS Protection and ZTNA.
And so we thought, hey, let's get that stack from Mylan, let's combine it with our stack and make it all presented to Central and make it a really easy to use experience. So that's kinda what we did in the last past year and a half. So super excited about the launch.
Um, we're really looking forward to it. Yeah. Very cool.
So, GA on, this is February 26th, about a month from the day you and I recorded this. Yeah, Yeah, yeah. That's, um, we've been about EAP for the last two, three months.
So we've been having a lot of already beta testers and the, the, so far the feedback has been awesome. Amazing. Um, a lot of folks are gonna getting this feedback as to how they plan to deploy it, how they're trying to augment their, their cus users with it.
Um, a lot of the use cases are stemming around, uh, that, that hybrid workforce, right? We have a lot of, um, customers who have offices that are now back online and they're mandating two, three days a work week, or they're still keeping some of their hybrid workers remote. So they're trying to fi figure out, how do I go to address this now that we have customers coming Yeah.
Users coming in and out of the network, how do we ensure that we have our, our security policy system? So that's the use case that we're driving for, so that we think that's, that's gonna resonate really well. Very cool.
Hey, Dan, we're about out time. What would, you know, for people out there who's saying, wow, Sophos, this ain't grandpa's Sophos, right? There's so much going on.
How do I stay on top of it? What would you tell 'em? What's the best way to stay in the know on Sophos?
Oh, you know, some of us like to use Chate or Gemini or whatever. You can always search that and see what's new. But, um, you know, the traditional way is just, uh, you know, we have a great LinkedIn site.
Also, our webpage have all been updated. com, check out workspace. Um, you'll find all the details that you just talked about there.
And, um, yeah, uh, we're, we'll, we'll, we'll make sure we propagate this video and anything else on different social media platforms as well. Very cool. Hey, Dan.
Enjoy. Enjoy Hawaii, right? So you both worked up as, uh, I won't be out there this year, maybe next year.
I'm waiting for them to rebuild the haina, but it's gonna be a while. Um, anyway, though man, keep up the great work at Sophos, this Sophos workspace protection sound. Sounds great.
Uh, MDM also sounds great. There's so much going on. It's, you know, look, this is an exciting time.
It's always exciting insecurity, but the stakes have never been higher, so Yes, sir. Thank you Simon stuff. Appreciate It.
All righty. Dan Cole, SVP product management at Sophos here on Techstrong tv. We'll be right back.
Now, you, you've made some decisions architecturally product selection. Um, you now have a real network. You not, you don't get to build a Greenfield.
Um, you know, we're just gonna build this fresh and new with no legacy. You have the historic brownfield migration scenario here, so you had to take this very carefully. Why don't you talk us through what, what did those Brownfield migrations look like, knowing that, you know, you weren't directly on the ops team.
I'm sure you had, uh, uh, a lot of involvement in designing the process and being sensitive to what could go wrong here. Nokia is, is a group of many companies that have merged into Nokia. Sure.
Yep. So, so, so that's why you find that those different companies are, are not, were not using the original Nokia rafter equipment. Sure.
So you might be, they might be using other vendors because they were not related to us. And I think you had at least two different vendors in the legacy environment, correct? Yes.
Yes. We, yes, we do. To non Nokia, two different non Nokia vendors.
Yep. Two different non Nokia vendors, two different non Nokia vendors. And, um, and so, so we have existing data centers with existing applications.
Mm-hmm. And they're running, and we, we needed to move them into like this common modern data center architecture, you know, based on NetOps and stuff like that. And, and based on Ida Andr Linux.
So we had to migrate all these different data centers from their original equipment and original management platforms to, to ED and Azure, Linux. Mm-hmm. Without, without outages, without, uh, without, without causing any outages.
So we had to, we had to, to our data centers were at some time, and they are still in some cases, interconnected to different vendors. Sure. At the same time.
So some, some of the servers in, in the, in our SR Linux, in the, in the environment, are actually on the same subnets, for example, on the same network as the servers in the other vendors, uh, environment. And they're talking with each other as if, as if they, they're, they're just as if they're together in one data center. Excellent.
And so, so, so we've developed this, it, of course, the first time it was very, uh, interesting and challenging, but we, I think we mastered this to the extent, now it's like, become routine, you know, oh, we, there's another data center we have to migrate, therefore we, we connect our SR Linux e the data center to it, and we begin migrating. And then we go through a process where we build, you know, a, a network across the two data centers and move servers one by one without, even the application team shouldn't really, I mean, we're not telling the, we're of course, we tell them we're migrating, but we, we really tell them, we, you shouldn't see any disruption. You shouldn't, your application shouldn't be affected in the Hmm.
So we move their service from one environment to other another without them actually seeing effect. So this is one kind of, of Brownfield, you know. Sure.
Where, and there's, there's another kind of brownfield, there's another kind of brand where we had to replace, you know, legacy, legacy mm-hmm. Uh, uh, management platform from prior, uh, Nokia companies to, to, to, and we had to do this in one shot, in one shot, because we thought, okay, why don't we have the opportunity we have, it was running SR. Lin Sr.
Linux by itself, but what the management platform was complete was different. Mm-hmm. So we took that and we actually, in one maintenance window, moved all the data center from one management platform, which actually required, you know, reconfiguring every single node in the data center Wow.
To look for the new, and we did this with no hits as it's really, of course, the digital twin here, the migration with the digital twin is very important. Why? Mm-hmm.
'cause the digital twin enables you to look at specific, uh, now you need to go down to the node level, the, the CLI level, and make sure that every port, every subnet, every vlan in, in what it was in the, you know, previous life mm-hmm. Is actually this gonna be, that has exactly the same configuration, eh, of course. Different, different type of configuration.
But the same, same members, same subnet, same everything in the new data center. So the, the digital twin enabled us to make this comparison. And we did some automation, of course, to, to compare them together.
But the digital twin was very critical in that, because we couldn't make mistakes in any node. And, uh, you know, every single node had to have the, the correct configuration, otherwise you get an outage. Have you ever thought about, how did I get along, you know, for years or decades doing all this stuff without digital twin support.
Um, it's one of these, you know, pieces of tooling that is just a game changer. It's fascinating to me. I, I mean, you see, you're saying it's fascinating, but go to a, a common network engineer and Sure.
I'll tell you, I'm confident with CLI, I like, I like CLII, I can understand. I, I know what I'm doing, you know? Mm-hmm.
I can see what I'm implementing, what I'm, they're, they're not used to this idea of hiding the complexity, hiding the complexity from you complex, or, or, or using modern techniques. Like, oh, let's, let's put it like a, like a software development cycle. So it actually wasn't, so e you know, you're thinking back now, we were thinking, oh, that's great.
You know, how did we live without it? But when we started, when we started, it was, there was, we got a lot of, you know, opposition. You know, sure.
You guys are gonna mess up. We've never done this before. This has not been done be before.
Uh, it is gonna be disaster. This is our factories, uh, uh, you know, our product lines don't do it. You know?
Right. 'cause they're used to do it in a, in a certain way. And we, and architecture was completely, you know, a revolution to what, to everything that it, what, what, what it was in, in the previous life.
So, sure. So thinking backwards, it makes sense, but when, when you are beginning, it was a lot of resistance, you know? Yeah.
No, totally understood. And I think so many of us, you know, have been trained to, like, just like you said earlier in our conversation, I've gotta go get the equipment in the lab and test it in the lab before. I'll believe that this before I'll trust putting this into production.
And, uh, you know, this digital twin functionality in EA now brings you to that much higher level where I, I don't need to invest in that equipment in the lab. I don't need to go physically cable that up, or make sure somebody's there to do it for me. So, Hey everyone, this is Alan Shimmel, CEO of Techstrong.
Welcome, welcome to this very special virtual event that we are producing in partnership with our friends at Microsoft. The event is titled, unlocking the Future of Agentic Experiences. And it's gonna be a series of videos in, in this virtual event that you're gonna be able to, you know, take a look at and, and interact maybe with some of the analysts and speakers here.
I really think you're gonna enjoy and get a lot out of these videos in this event. And look forward to hearing your feedback. I'd like to kick things off with our keynote, and it's our keynote.
'cause I think we've got two terrific speakers in this one. And it's around the future of apps, right? And it features future CEO and principal analyst Daniel Newman.
If you've ever seen Daniel on either many TV shows or, or conferences that he keynotes, you know, he what a dynamic thought leader he is. I think you'll enjoy it. And Daniel is gonna be speaking with none other than Ryan Cunningham.
Ryan of course is corporate VP for the power platform at, uh, Microsoft. And, you know, Ryan is gonna share with Daniel and with you the all up vision. The, you know, the all around vision for power platform.
We're going to connect the dots between apps, agents, and interfaces. Right? Ryan, and, and you know, with Daniel are going to illustrate how Microsoft is leading automation in this AI era.
He's gonna articulate how Microsoft is enabling every organization to build, govern, and scale intelligence solutions with unmatched speed and trust driving the future of ag agentic apps. It's a great discussion, and I think it's a great learning experience. So here's Daniel Newman and Ryan Cunningham.
Alan, thanks so much for that introduction. And to introduce myself, I'm Daniel Newman, CEO of Futurum. Very excited to be here today with all of you and even more excited to introduce my guest for this conversation.
Ryan Cunningham from Microsoft. Ryan, why don't you say hello to everybody and give a little bit of background on the work you do at Microsoft. Uh, Thank you, Daniel.
It's awesome to be here with everybody today. So, I'm Ryan. I'm the corporate Vice President for Power Platform here at Microsoft.
So, uh, look after all the teams of, uh, uh, product people and engineers and designers that are building, uh, really our low-code application platform and the future of where that is going. Uh, you know, really excited to talk to you about that today, Ryan. I've been working, uh, with and around your team for many years as an analyst.
It's been great to follow. Of course, the change that's been going on in this market is extraordinary. And I think that everyone out there is gonna gonna leave this, uh, conversation knowing a little bit more.
And hopefully maybe you'll give us a little bit of that, uh, secret sauce about all the stuff Microsoft's doing. Nothing too secret though, you know how that goes. Oh, I know.
So let's, Let's start big. Uh, I mean, when we talk about the future of apps, connecting agents, interfaces, applications, you know, what is the kind of the North star for Microsoft? What are you, what are you guys heading towards here?
Yeah. Uh, look, it's a, it's a crazy time to be alive in a business application platform, uh, environment, right? Because, uh, this whole world is, uh, being turned upside down in actually two dimensions at the same time.
Uh, one is how we build software, uh, radically changing in a world of agents and, and vibe coding and everything that is filling up our LinkedIn feeds as technology professionals. What's really interesting right now is the dramatic expansion in efficacy of what I can build and the dramatic expansion of who can participate. At the same time, You have to be evolving the platform even more and even more quickly, right?
To, to get them what they need and what they're trying to do to accomplish the, the future that they're trying to build. Yeah, a hundred percent. And, you know, I I would say to, to even build on your last comment 'cause it's relevant here.
Um, it's not just an opportunity for more people to tinker and build things. It's actually really an imperative. Like, if, if we're really gonna accept the premise that every company that wasn't born yesterday is operating inefficiently and needs to, to rapidly advance in a world of agents, then the expertise you need is not just the AI technology expertise.
You actually need to go get all of the process expertise, you know, all the humans who know what it really means to run a more efficient HR department or finance department, or, you know, whatever it is, they're sitting with a real job in that department today. You gotta go figure out how do I harness that expertise and bring those tools right to the, to the point where the process is actually happening today. And that's where you need a higher abstraction platform that has agents built into it that help do the coding, that help do the work.
Microsoft does have some really unique approaches in this space. And, and particularly if you look at this broader world of how software is getting built and code generation and agent swarms and every other term we're coming up with right now, you know, where we're really focused right now, particularly in the space of business applications and productivity, is really make that relevant to the way companies run and operate. You know, we're not out there to, to, uh, you know, serve any possible whim of any possible developer on the planet.
There's lots of great tools for that. Microsoft makes some of them in other places. But here we're really focused on the, the core operating system of a company.
And by, by that I don't mean windows. I mean sort of all the business applications, business processes, specialist teams of people that today make a company tick. We're seeing consolidation in this era.
Customers have a ton of choice. Yep. Everyone kind of says, use our agent thing, right?
Um, what we're gonna wanna see is, you know, the orchestration is gonna be super important. And then of course, the, the speed, flexibility, access to all the tools, data, cloud, and of course Microsoft's in a very small group, right? Companies that has pretty much all of those things, right?
Um, not all, not the only, but one of a very small number. And I think that makes you competitive. I wanna go to the, the pragmatic side because a lot of the, uh, viewers here are probably thinking about, you know, how do I do this?
How do we do this in our firm? You know, we hear some of those stats about AI ROI and the enterprise and, and, uh, let's just say that I'm a, I'm a absolute believer, but I do think there's some hurdles, you know, what are those kind of key enablers you're seeing fundamental enablers, enterprises, you know, need to get right now, right? To make sure that those, those POCs and those production, uh, AI projects start to work and really show value.
Yeah. We're seeing customers, um, adopt exactly the mentality you're talking about. You know, not just how do I run the current process faster, but what if I fundamentally changed the process itself, um, to really great effect.
Um, you know, we've, uh, we've shared some stories of retailers, um, that are starting to use agents and apps and automation together to totally change how they do things like fraud detection and, uh, even refunds and returns management. Um, you know, if I go contact an online retailer and say, I want a refund, uh, you know, traditionally that's a human going and vetting, is that a real customer? Did they buy something?
Or is this fraud? Does it meet our return policy? Which is by the way, usually like a 50 page PDF that changes once a quarter.
Um, you know, and then do I want to issue the refund or can I save them as a customer? And that's super slow, it's super inefficient and it's really expensive, and often it's outsourced to vendors. Um, you know, can I go implement an agent that does that instantaneously, or at least does major parts of it instantaneously, um, you know, really starts to change my operating and my risk profile and my customer relationships.
And so, you know, even in use cases like that, starting to see, you know, millions of dollars of value unlocked really quickly and just better customer satisfaction, actually the balance of value is really shifting towards that process expertise. Um, and I think part of the challenge though is just, you know, very few people with real Jobs woke up this morning and said, God, I want to build a business application, or I want to automate a process. That's just not a thing that happens to most regular people.
Um, but a whole lot of people woke up this morning and said, man, this part of my job sucks. That could be better. You know, I wish we didn't have to burn so much time doing X.
Right? And, and really harnessing that energy, that value those skills and those people, and bringing great tools to them. That's part of the whole thesis behind why a platform is, is critical right now.
You know, what does it mean to totally change that interface into a human and agent collaboration space? What does it mean to go see the activity of what agents are doing on your behalf when they need your input? Let's talk a little bit about Plan Designer.
Yeah. Uh, you know, we're seeing, we go from manual to automated to, you know, to agentic level orchestration, which is great. One of the key things too is gonna be trust.
We gotta trust our systems. We gotta be sure that, you know, the agent, uh, workflows we're building, that they're inspected, that they're constantly modified to be sure that they're right, that they're traceable. Like talk a little bit about kind of how Plan Designer can help companies.
'cause that's a lot of work, by the way. Yeah. That's a lot of work.
Yeah. You can automate or, you know Yeah. Streamline some of that outta the process.
Yeah. com. You can try it today.
But, uh, what it really is, is of a different kind of AI centric development experience. Um, you know, you go type into that box a business problem. We do not assume that you just want us to spit out a thousand lines of JavaScript that you, that you need an app.
Um, like a lot of vibe coding platforms today, we actually do what a real software team would do. In fact, we've built in a digital software team, we've trained a requirements agent, a process agent, a data agent, a solution architect agent. It's a highly collaborative environment.
This is not a sort of throw a paragraph over the fence and watch magic happen. It's really sort of training and teaching people with process expertise, how to think like software architects and solution architects so that they can know up ahead of time, why do I want AI to do certain things? Where do I want it to work?
How do I want it to interface with humans? And that's really the foundation of that trust in the system. Have you seen, uh, some examples out there of Plan Designer being sort of delivering promise?
'cause it sounds super optimistic, people using this? A hundred percent. We have started to see really interesting sort of challenges thrown at it.
Um, you know, we have, uh, customers in highly regulated financial services context that are taking decades of old homegrown, uh, non-compliant software that was built over, whether it's, you know, hacked in Excel or built one off and sort of saying, can I use this to rapidly modernize what I had before in a way where, you know, traditionally going and turning all that old stuff into full stack software was just incredibly costly and, and cost prohibitive. Um, you know, starting to bring those things into plans and generate a more robust plan for modern software moving much faster. Um, we've even seen huge extremes of that.
I've, I've, I've seen a customer take, you know, 50-year-old cobalt code and just paste it into plan design and say, what the heck is this program doing? And can you help me build a better version of it? Um, and actually the results were pretty promising.
So, um, you know, people are getting really creative with, you know, bring the problem, bring the challenge, bring you know, sort of the business area that you want to improve, and then start working with these agents and on this digital software team to, to design a solution. So, you know, we're doing all this work. We are trying to train people to think differently, remove constraints, whatever's possible.
But the UI is, that seems to be the next frontier. Like the old enterprise software. It's like, these are the things you can move and these are the things you can't, and what you can customize and here's what you can't and here's your dashboard.
And it's like, great. But in the future, like Right, I might just wanna say, Hey, you know, Microsoft, whatever. Yeah.
Uh, this is what I wanna know today. Right. And then I wanted to obviously learn based on my behavior over time, what I wanna know.
Right. And then I want it to continuously Yeah. Like things like that, like Right.
How does the, how do you see being in, in this space so much, the kind of UI evolving? Yeah. Um, you know, I think, um, specifically chat as a UI is super compelling and natural for a lot of things.
Um, I do not believe that we're gonna go regress 40 years of a, of UI innovation and go all back to chat in the command line though. Like, there's a lot of things for which text is actually a terrible modality. Um, you know, in which, uh, you know, just paragraphs are, are not great.
Um, and, and I think there's, there's a more underlying thing here that you're touching on, which is a lot of traditional experiences, whether it's text-based or, or visual. Assume a human shows up knowing an intent, right? As opposed to, you know, an agent being really proactive and taking care of something for me, or pushing me an update or a notification when I need to know it.
Um, and so I think those experiences start to evolve a lot. What gets really interesting is where they meet, you know, and we really see a lot of this, uh, you know, task-based data entry, repetitive stuff, increasingly getting delegated to agents on your team. But that means you'll need to work with that team in a totally different way, right?
And, and where a, you know, traditional CRM system or HR system or, uh, you know, whatever, you know, pick your business application was, you know, previously, like we talked about people typing into boxes and then other people viewing reports. You know, what does it mean to totally change that interface into a human and agent collaboration space? What does it mean to go see the activity of what agents are doing on your behalf when they need your input?
You know, when they're blocked on something or they've noticed a trend or, uh, you know, there's a form they tried to fill out but didn't complete, then that's an important meeting space to go, go have experiences and user experiences. Um, and a lot of times those do need to be structured in a visual way. A lot of times they could happen, you know, ephemerally or, or with a chat message.
But how do you route people to the right place at the right time? Um, you know, we're working across all of those fronts, you know, that's why we have a robust set of tools in copilot studio for, for building the agent part of, of, uh, all of those things. It's why we have a ton of evolution in power apps, you know, sort of becoming this new agent centric experience where I can see a feed of that activity.
I can have agents help me, uh, do the work in the applications. Um, and those two worlds will just continue to evolve together as we start to bring things into the future. Okay.
So you heard me talk a little bit earlier, Ryan, about governance. Um, governance is part of the, the critical, uh, constraint. And one of the things that differentiates software, right?
The reason we can't just use open AI for everything would be because it doesn't know how to handle the data. Be like, oh, let me talk about, you know, help me do a job offer or help me do a compliant healthcare notice to somebody. Like it doesn't how to do that, right?
So building applications that do know how to do that is the key you gotta build up with. I mean, of course we wanna go fast, right? So fast is the new, the new role, right?
But the trust and scale are, are, uh, the other words. I know you often use these words, but like, you know, what do you think and where are companies sort of struggling with governance, uh, and scale here with automation and, you know, kind of how do you think what you're building an agent oversight can help them? Yeah.
So I'd say there's a couple dimensions to governance and scale. You know, there's the breadth dimension. We have a whole lot more people who now can build a whole lot more things.
How do I make sure that all that stays on the straight and narrow when I can't centrally top down code review every single thing that every single person an agent is doing. And then there's sort of depth scale. You know, when I do wanna roll out a mission critical solution to a hundred thousand employees that has AI in it, how do I make sure that that AI is not just functioning, but actually continuing to get better every single day?
Um, and, and you know, the, the good news is we're not inventing any of that from scratch. You know, breadth scale and depth scale. Were a challenge in the first generation of power platform.
Um, and something that we've built a ton of capability into the platform over the last couple of years to really, uh, tackle at huge scale. And we call that, uh, the managed platform set of capabilities. And within it, there is managed governance, managed security, managed operations for lifecycle a LM management, stuff like that.
Um, and may managed availability even. How do I go ensure high availability run disaster recovery drills for critical workloads. All of that is built into solutions baked, uh, on the power platform.
Um, and all of that value accrues to this next generation of components being built as well. You know, an agent built in copilot studio benefits from all of those managed capabilities. Um, a new app built in power apps with intelligent capabilities in IT benefits from that entire stack.
Um, and so that's why, you know, you start to see even highly regulated financial services firms, government agencies, um, et cetera, really trusting Microsoft here, as opposed to a 20 person startup that was founded yesterday. Um, you know, to, to really take the bet on standardizing for this, this segment of, of software. Um, then you get into the operational oversight.
Okay, I have agents doing work. How do I have humans managing the work of those agents? That's not a developer role anymore.
That's really an operational role. You know, what does it mean to be an agent manager or an agent boss in a claims department at an insurance company or in a supply chain, uh, operation? You know, that's where we need these new interfaces.
And that's what power apps is building in with concepts like the agent feed. You know, how do I build a, a purpose built oversight experience for really high volume activity of, of agents? This is one of those things that like, right, there's so much doubt across the industry about being able to do this in a sort of, when you give up the human in the loop or even just have one maybe guiding, but you're moving so fast, it's like, um, you know, are they safe?
Are they auditable? 'cause when you're in a business, everything you just to be traceable and trackable. Yep.
Uh, is it predictable the outcome? Like, hey, you're gonna have an agent interfacing with your customers, or you're gonna have an agent, uh, doing a bunch of accounting work, which by the way, it's like a spiral one mistake. It's just, you know, how that goes.
Yep. Like, how are you guys overcoming that doubt, you know, through the guardrails you're putting up, through the oversight, the accountability that you're kind of baking into your platform? Because I think you get over that hurdle, Ryan, we move a lot faster.
You know, I think what's interesting here is actually a lot of our customers have had to build these systems already. You know, a lot of our customers already operate critical processes across massive employee bases and even larger vendor teams that operate at arms length already today, right? And we've already had to go build in a, in a world of a whole lot of variability of, of who's doing a task.
How do you create an audit trail? How do you create rules? How do you create data policies?
How do you create oversight? A lot of those concepts exist today because there is variability in the human system, right? And so a lot of the way we, we approach this, okay, how do you adapt those existing concepts, policies, features, capabilities?
How do you adapt that to a world where it's humans and agents doing the work? And what are the sort of incremental, you know, sort of 10% shifts that you need to make in those systems to accommodate agents, um, but not completely, you know, pave them and re re rebuild them from scratch, right? Because a lot of these sort of trust concepts, uh, or zero trust concepts in a security concept are already built into to the system.
Um, and so there's a ton of work we're doing there in the managed platform in, uh, you know, a lot of the ways that, uh, you know, a lot of the Microsoft security governance and oversight concepts apply to agents. Um, and, and that's again, one of the benefits of building on a mature platform and a mature system in Microsoft is, uh, you know, we're not having to recreate all that stuff from scratch, like a, like a point solution startup would have to do. Yeah.
So the, the last thing is just on, specifically on security. Um, security is a super hot topic. Yep.
What do the customers, how do you want them to think about the approach? Because in the end, like you can get it all governed and right, but you have to keep your doors closed, locked. And, you know, that's an increasingly large problem.
AI is, is much, uh, enabling it, uh, as it is fixing it, right? Well, look, I mean, we could probably spend an entire hour on, uh, uh, security and threat model approaches in the, in the AI era. It is absolutely critical.
And like any security challenge, there is no silver bullet. You know, every customer needs to have a defense in depth strategy and needs to think about what am I doing from a data security perspective? What am I doing from an exfiltration perspective?
What am I doing from an access perspective? Uh, you know, the good news is we have a lot of that built into the platform today. You know, even a customer building their first copilot studio agent and using the managed power platform to roll it out.
We'll see a security score in the power platform admin center, we'll see AI driven recommendations about what to do to improve that security score. Um, you know, it has a whole bunch of capabilities in there that, that go all the way to operate this in the cloud. But with a private vnet, with your own managed encryption keys, um, you know, again, we have a lot of highly regulated, very security conscious customers that are working with the platform today.
Um, I would say though, to Zoom way out and look at that, um, and maybe connect it to some of the rest of the conversation we've had, it is absolutely risky to go too fast. It is also very risky to go too slow, you know, and the rest of the world is evolving, including threat actors and competitors, right? And so the cost of standing still is probably the most costly positioned to be in.
So let me, let me, you know, as an analyst, uh, I have to ask you 'cause uh, I've got a few things, uh, but, uh, what kind of in this whole evolution, this, this exciting moment for the future of apps and automation, uh, and agents, like what's kind of keeping you up at night, the biggest concerns that you see out there? And then what are the kind of upsides for you? Like what do you most kind of think could be the biggest surprise in, into the future?
Give us that big yeah. Visionary moment here, Ryan, to take us home. Look, I think, um, I'll start, I'll do that in reverse order.
I think there's a ton to be excited about right now. Um, and you know, I, I think, um, there's just so much potential and creativity that we can still unlock. net code in their life.
Um, you know, what unites that community is this sense of we can make something better. We can, this can be better, let's do it better. And, you know, I feel like we're at the precipice of just blowing a huge lid off of the ceiling of what you can do there.
Um, and there's a whole lot to be excited about. Um, I mean, you joke about a night job. I stayed up last night vibing a power app that's just a Tetris game because it was awesome and fun and so much faster to create it than it would have been in the last generation of the technology.
And I think that's a tiny, tiny microcosm of, you know, go take that creative energy and apply it to everything that's inefficient about every aspect of every customer organization today. You know, we're really standing on the precipice of completely rewiring how companies work, um, and doing it with people who, who have deep expertise in that process and a deep desire to make it better. And that's just incredibly exciting to me in this, in this moment.
Um, and then to flip it around, okay, so what stands in the way of that? You know, it really is all about speed and pace of iteration and, and really it's about time to wrong. You know, there's, there's so much that we need to go invent and co invent with customers and experiment with, um, and try, and nobody out there is perfect right now.
What, you know, what will define winners and losers for technology companies, for customers, for operations, is how fast can you be wrong? And then how fast can you get less wrong and more, right? Um, so that's, that's the journey we're on.
That's the hill we're climbing. Um, but it's just a super exciting time to go think about what the, the top of the mountain can be. Brian, this was a lot of fun.
It was a great conversation. Appreciate you sharing a little bit about where all of this is heading. There's so much potential for companies to really start reimagining Yeah.
Realize just how big of a leap forward we, we are having right now with, with ai, with Ag agentic and the work that you're doing in power platform. So, Ryan, thank you so much. A hundred percent.
Really, really enjoyed the conversation. Daniel. Thank you for the time.
Everything About the way we work is changing very quickly. Thanks to the advancements in applications and of course, agents automation and what interfaces may look like in the future are all gonna continue to change and they're gonna enable, and they're gonna power businesses to be more efficient and of course to be more productive. It was a great conversation over the last hour.
We really did reflect across not just power platform and how they are thinking, how Microsoft is thinking about building its future, but really about how businesses should be thinking about developing their future, removing constraints, being able to look at problems in new ways, and then being able to apply software and then being able to utilize resources in new ways that can deliver more value to your business and of course to the customers that you serve. And this is not gonna be easy. It's gonna take some time.
There's gonna be some effort, but it is something that can be done today and companies can start to extract value right now. And moving quickly is gonna be more and more important. That's something I'm seeing as an analyst, and that was clearly something that Ryan had seen as well.
We talk a lot about that is the customers that are moving fast are gonna be the customers that get the biggest results, and of course, are able to benefit the most from those efforts. And lastly, we still have to keep all of those considerations that have existed with enterprise applications, with software that runs our businesses. And that's gonna be the governance, that's gonna be the controls, that's gonna be security.
And that, of course, is going to be putting people in the right roles and enabling them to do the work. All those things remain similar, but of course, with a new bend, we're gonna upskill the talent. We're going to think about problems in new ways.
We're going to move more efficiently, and together we're going to drive the future. Great conversation. Appreciate everybody spending the hour with me.
See you all soon. Control. This is agent dev.
I'm in position. Copy that. Dev.
Stand by for go. Standing by. Hi everybody.
Welcome to the agents of Deb podcast. I'm Mitch Ashley and I, I'm with futurum. I lead the software lifecycle engineering practice, and my co-host Brad Shiman, who also is with futurum.
Hey, Brad. Hey there, Mitch. How's it going?
Good. Good. It's, um, another week.
Like, we're kind of getting on a roll here. 2026 just kind of keeps on coming. Kinda like ai, it just keeps on going.
Yes. Well, we did just enjoy the winter break wherein all of the major frontier model makers, you know, bestowed their gifts upon us, uh, did they not? And philanthropic was, was certainly one of those vendors.
Mm-hmm. Um, over the break, I'm gonna call it, uh, introduced this lovely little tool called Claude Cowork Cowork. And, uh, I imagine everyone that's listening to this is, is, you know, aware of it if they haven't been able to use it yet, because it is a little bit, uh, cordoned off right now.
But it's a fascinating tool, um, for a couple of reasons. And, and the first one is, doesn't even have anything to do with what it does. Uh, it, it, it's, it's how it was made.
Um, there is Oh, that's a great story. Yeah. Tell us that story, isn't it?
Uh, so mm-hmm. So a, a man named Boris, um, who, you know, everyone that, that follows AI appreciates because he typically opens up, you know, and shares with us a lot of his best practices and how he builds software using Claude Code. And, um, he apparently, uh, over the course of 10 days used Claude Code to build this product called Cowork.
And this 10 day product, uh, meaning conception to deployments and, and realization, uh, is, is like this nuclear, you know, explosion, uh, in the marketplace. And I'm gonna argue of more importance than, than, um, MCP was also also invented by Anthropic. Mm-hmm.
Simply because of, of what it does philosophically, which you and I are gonna gonna talk about at, at length today. But at, at any rate, I, uh, tipped my hat to Boris, uh, for, um, you know, basically recognizing a, a, a value proposition and executing on it, using the tools, uh, available to him. So, love it.
Yeah. And, and this isn't just like another vibrating message, right? This is like real, real, you know, Boris, you don't know.
No, I'm just think is his, he's very legit. Let's just say it that way. That's a gross understatement.
Street cred. Yes. Street cred.
He's got the receipts for sure. Um, but you know, he, he created a tool and like in many cases, a lot of companies, people create tools sometimes for themselves and they productize it, or they have an idea and they created tool and it becomes a product. And some of those don't, some of 'em do.
Um, but if you kind of, I dunno about the, the name cowork, it, it kind of, yeah, it's a, it's a partner. It does work for you, is essentially inside the cloud interface and your agent interaction with agent creating agents and subagents and plans and scheduling them and doing all that kind of stuff. But you could do, essentially what you could do in cloud code, you could now do in the, in the web interface, in the, the, if you wanna call it the prompt interface.
Um, but it's another mode that you go into and now you're in, in cowork, and it has some predefined here, go check my email, summarize this for me, send that to me once a day, kind of things that are already there. Analyze this data, put it in a spreadsheet, et cetera. So give you some ideas of how it works.
Um, but it really, what, what it really does is it leverages a lot of what I appreciate about philanthropic especially, um, four, five is sonnet four, five is all of the subtask that it will do for you. It doesn't just prompt and run it, it prompts and puts together a plan and it creates a bunch of substeps. Sometimes subagent, sometimes it's just multiple steps.
But now that can be essentially your agent headquarters and you don't have to know how to code. You can't, it, it'll write code. It'll sit there and say, here I'm doing step five here, here's some Python code that does this.
It stores it in a, if you're in the web interface, it stores it into a virtual machine in online. And that's where it runs. If you run it locally, um, if you're using it like the desktop application, it will, it can have access to your file system.
It'll store the files there, it will run it there, uh, whatever it's creating. So it's, you know, it has some portability issues. It's not exactly the work the way, same way across mobile, desktop and, and web.
But the idea is pretty much anybody can do what you would do in cloud code in terms terms of creating agents to do work for you on things that you have access to, either inherently you've given permissions through the app or the web interface or MCP or whatever it might be. It's, it's, to me, it's a big deal. I think it's a huge deal.
It's, and it's shockingly simple, and it's something we already had because, uh, everyone who's been using Cloud Code, Gemini, CLI, and Codex at all in the command line has access, has had access to these same tools. You, you have an agent framework that is a four while loop that is gonna execute on a set of tasks that either you bring to the table or it give, uh, deduces from your intent and executes on those using the tools that are available to it. And those tools quite usually are command line tools, copy a file, move a file to lead a file, uh, or, or directory.
And, uh, all of those things that, that you had a command for. Okay. Alright.
Right. That's right. Right.
So be careful kids. Um, but, but, uh, it's, it's interesting because, um, it is such a simple idea and one that we already had available to us, but as you just said, it's, it's taking that idea and giving it to those who don't like the command line, that don't work in the command line. Uh, and it's this recognition that, well, you know, you said it's the same thing.
Why is it the same thing? Well, we work on machines, we work on PCs, we work on desktops, we work on phones, et cetera. And all of those have a number of things in common.
Uh, and, and that is a substrate that is, uh, what I would call non-adversarial. Um, because most of the world we've been living in for the last, uh, few years is chat bot driven. And it's, you know, typically you have a long running conversation trying to steer a model toward an output that you want.
Then you take that output and put it into practice somewhere. And by somewhere, I mean, usually, you know, on your file system, you know, to, to use it in some, some capacity. And, um, that's not, you know, how people work.
People work on their machines, they work in applications that access files on their desktop, and those files are of known formats. Um, and so put two and two together and maybe, you know, instead of working in an environment where you're doing this constant chat chat, trying to do it, get something done, you can pivot that to a task oriented, uh, engagement or relationship in which the, you know, as you just mentioned with Claude, um, cowork, you have these sub-agents that can be kicked off to do specific tasks. Like one might be, uh, looking for duplicates in your downloads folder.
Another one might be, uh, renaming those duplicates. So in a consistent way, another one might be parsing a video looking, uh, for transcripts, and then another one that analyzes those transcripts. All of that is work we do day in and day out.
And what Claude Cowork is doing is saying, you know, you don't have to use a command line for that. I mean, ultimately it is using the command line for that, but you and I don't have to, you know, stand that up to, to take advantage of it. Mm-hmm.
Yeah. It, it, so, so the metaphor, the, the experience I thought about is this is a user experience paradigm. Meet user, meet the customer where they are, right?
In other words, you're not gonna drag everybody, uh, to the command line. Not gonna drag everybody into an IDE. Maybe even getting them into a prompt session is, is a bit of a challenge.
But, you know, you wouldn't, lemme give you an example. You wouldn't store your Excel formulas in a document somewhere and then go back and plug them in every time you use them, right? That's essentially, yeah.
That's, that's the metaphor that we're taking on now with, with AI and agents, is those things live where you need them to live so that they can run and execute. Either you decide you want them or other agents, you know, call agents for you. And so the, the, the prompting thread to me is a transitionary interface.
It's, it's the kind of beginning way of conversing, and then we invent ways of writing it down, and then we invent ways of publishing and sharing it, and then we invent ways of distributing it and amplifying it. You know, kinda we're on this progression of the user experience for it skills is the same way in in cloud, uh, which has been kind of replicated. Or you can replicate it yourself in different environments because, uh, can I take a tangent?
I'll tell you about a project that I worked on this weekend, just it taught me a lot. So probably like you, I'm sure like you, I'm bopping between Gemini and Hitachi PT and Quad Code and Codex and you know, it's, it's, you're going back and all the time wanna are what's happening, what is Yeah. How they, how they are different from one another.
Exactly. And how does this new thing work, right? Um, the problem is you lose con now that we have memory and things like that across these different models, you lose that jumping between models, right?
So now I'm back over suddenly doing working Claude and I don't have all the recent things that I've been doing in another environment. And, uh, hold on, hold on just a minute. Okay.
Go get them. Sink them. Oh.
Oh. So you have to like restart it. Oh, sorry.
Yeah, yeah. Send them a note. Send them a note.
So I'll pick back up. Alright, so carry on. So switching between those models, you lose fidelity of the investments that you've made, right?
And yeah. You know, here's how I write or here's what my preferences are, here's the gaming things that I do, what whatever you're doing with them. And so I, I wanted to, to really do a lot more in clads.
I wanted to catch it up. So two things is, one, I created this context operating context model that I can move between that is kind of everything about what I've trained about how I want things done, and how I work. Everything from what I do for living.
It's Claude md, your agents MD file. It's, and it, and then you can kind of plug it into whatever projects that you're working on across those and update it and redistribute it to another environment. Someday that'll be automated.
Just simply link it across all your projects. Sim link it. Exactly.
You got it. So it's, now I have sort of a, a one brain of what, of what my part of the brain is, if you will. Uh, my preference is, if you wanna think of it that way.
Um, and then the next thing I ventured into was, um, I was asked by, um, our leadership at Futurum of, Hey, would you send us that prompt that you used to generate that report to get ready for a meeting? And what it was is taking some, uh, notes from a, uh, earnings call and doing some analysis on it and pulling some quotes at it and doing things like that. Well, the problem with sending somebody that prompt, that prompt started about 12 different interactions before, there's not one prompt that generated that, right?
It started through a whole chain. So I had this idea of I'm gonna create a toolkit to reverse engineer prompts based on the output and the input. So I use this as my test case of here's the, here's the result, here's the response I got from this model, actually different, different, uh, LLM and here's all the input files, and here's the session that I had that created that.
Now synthesize that and create me a reusable prompt so that anybody could run that on any earnings call that's brilliant. And then refine it until it's good enough. It needs to be, you know, at least 90%, uh, accurate if not more consistent.
It doesn't have to be literally the same thing, but it has to ha the fidelity of it needs to be accurate. And, uh, it's one of the nice things about Claude is it, it will do those iterations for you. It's very good about kind of refining and getting you better output sometimes even without asking.
And it was great. So I got this really nice prompt that I shared with the other folks, and then I said, okay, take that and create a prompt reengineering toolkit that I can use for any prompt. The same process we just went through probably won't work for every situation, but now I've got a, a tool that I can use, solve that problem.
Got that tool created, this memory context. Yeah, I actually did other things on the weekend, but there were so many cool innovations. That was like the morning Sunday morning.
Yes. A lot of that was yesterday. Awesome.
Yeah. Nice. So that, that to you Cowork model, that's what we're trying to do is use ai, AI as a coworker, whether it's through the cowork feature or create these things for us that'll do work for us.
Right? Yeah. I'm sorry to to talk over you there, Mitch, at the end but's.
So cool. md and hey, that would be great as a skill that you could document, uh, and publish that for use across your different agents. Because like you said, everybody's using what philanthropic came up with, with the, with the skills, uh, format, which I mean, my goodness, it's just a YAML file.
People, you know, it's not, it's not a new paradigm, but take it all together. And it kind of is a paradigm shifting innovation we're talking about with cowork here, because as, um, you and I were talking about before we jumped on the call, and as you you just mentioned with, you know, cowork taking what we take for granted in the, in a in a prompt and sorry, in a terminal, and exposing that to the broader context of work. And I, I'm like, yeah, there are two kinds of people in the world.
There, there are, you know, ones that are, uh, I'm not gonna use the binary joke, I'm not. Um, but there are, there are those who, you know, um, are noun first people, and there those who are verb first people. And, um, noun first people are those who grew up with, you know, the Windows XP and beyond.
And what the, when they think about doing something, they're like, oh, I'm, I'm gonna work on a Word document. So I open Word and I wanna open this file and do something with it. And that is, you know, great, because you don't have to remember all of the different tools you have available to you.
You basically think about the thing and then the action comes seconds. And the verb first people are those who grew up, you know, plaguing, uh, star Trek on a mainframe back in the the seventies that, that are like, okay, you know, I, I wanna do something to something. I want to find this file.
Um, they don't open a file and then find something, uh, or open a file system, then find something, they're just verb noun and, um, move my Starship to sector six. I adored that game. Um, but, uh, it, it's, it's interesting to me that, you know, with Cowork and with Claude code before that, uh, did I just say co cowork or work?
Because No, you got cowork. I like you. It should just be work.
It's not cowork. Yeah. It's, it's just work.
Uh, but, but anyway, um, what that does is, is gives us the opportunity to sort of bring those two worldviews together and to see them not as separate, you know, oh, that person's a terminal person. Oh, that person's a Microsoft Ribbon bar person, uh mm-hmm. To realize that it's, it's just work being done and work is being done Two things on a machine.
Like it always has, nothing has changed there in a few years, but it is something that is accessible, much more accessible to, to those that are used to the noun first, uh, mentality, uh, or, or worldview of, of getting business done. And does that not sort of collapse all of the, um, sort of markets that you and I have been writing about and thinking about with how companies automate software and build, uh, workflows, you know, and, and do things, you know, in the workflow, um, within, you know, a payment system within an ERP system, within an HR system, whatever. Um, if at the end of the day it's, it's just doing work with a certain set of assets, whatever those are, a Slack channel, uh, a PowerPoint presentation, uh, you know, doesn't matter if it's, if it's, if it lives anywhere, you know, it, it can just be me working with my computer to state my intent, and then that intent gets executed, uh, in whatever modality is most efficient to, to get that done.
It's really good point opening you're in your whatever, uh, AI tool and saying, here's what I want. Create this now, put it into these forms. I want a PowerPoint, I want an email message, I want a social media campaign.
I want, you know, a checklist, you know, I want a podcast script. Now the, the forms that it can take, you know? Yeah.
Uh, to your point, the modality of it really can, the outcome can shift and change and be adapted to whatever. You're not gonna, you're not gonna do a podcast the same way you're gonna write a document or a social media campaign. So can it be adapted to each, you said, one of the words you said that I really relate to is system.
And that is, I think that's, for me, these are all systems. There's a system. This why the games that I like to play this, uh, civ six things like that.
Um, there's a system to it, right? And me figuring out that system, how to make it work. And so part of the work now is understanding, well, we're creating the system that we're doing on top of what AI is giving us today.
And that I think, does what the work really shifts to is I have a system of work that's happening. I'm doing some of it. I have AI do doing some of it, I'm working with other people that are doing some of it, but all that fits together for some kind of orchestrated type of outcomes.
Um, interconnected things that are dependent upon each other. Um, but I can't go to my prompt library every time I need the next step, right? So we're starting to cross this chasm back into what's the new ui, what's the ribbon bar of what AI looks like, what's the, the, uh, the menu bar look like?
I'm not saying that we'll have ribbon bars or menu bar. What's the equivalent of that from user interface today? And, and it's still, still not there yet.
It'll get there. We have like chats in the side panel, which is kind of screwy, but we'll get past that a bit. That's my technical word.
Screwy is, right. It's kinda like, okay, yep, good start. But we could do better.
We can, I mean, we've, we've kind, we kind of end up chasing, um, these ideas and sometimes they're not the best idea. Mm-hmm. And we need to have the courage to just turn around and, and walk back out or just, you know, call it what it is and use it how it is best used instead of just keep forcing it and forcing it.
And I feel like, you know, why I like Cowork is that it to me is that very act, um, if you remember of the film Animal House, when the band takes the turn and goes down the alley and they all collide into the wall at the end because the leader doing the thing, right? And, and, um, it seems like we've been doing that based ai, the, you know what, maybe, uh, everything, you know, being circulating around just using the web, uh, and using the chat interface is, is a method, but not the method to do this. Because I mean, think about it.
And I, and I mentioned it a few minutes ago, with the adversarial nature of, of the non adversarial nature of your own file system. You control it, you own it, you can, um, set up a sandbox. And as you mentioned with, with cloud cowork, you actually have them manage that sandbox for you.
Um, and you don't get that on the web if you're, if you're trying to use agents to go scrape the web with beautiful soup or something, you are in for a world of disappointment. Mm-hmm. Uh, it, it is not easy.
And, you know, because the web wasn't made for agents and probably never will, uh, at least you know, it, it, because I think it's in conflict with how the web, you know, itself grew as a means of, of commerce. So, uh, you know, I think we need to turn the band around sometimes. And this, this is one of those moments of, you know, the leader going, oh wait, there's a brick wall up there.
Let's, let's just pause. You know, we, we talked about this a little bit, a couple things we talked about in our last episode, and that is to me, and that that is at some point, the, the metaphor or the paradigm or something changes, right? You kind of go into a new way of doing it, right?
Like microservices as opposed to let's say a, you know, a monolith application just to pick one extreme. Um, and we're, we're going through this with ai and I think about the web applications. Web applications are pretty much the digital form of what we did manually.
We fill out a form at the available forms. Four humans tells us, or emails us, and we email 'em back and say, I'd like this one. Well, that can do that in an app now.
Um, it, it's still pretty much the same logical or similar logical workflow. Maybe it accelerates it because you've got all that into, you know, one package step set of steps that you can do in an app or mobile, et cetera. Um, certainly is better than not saying it's not better than manual, but it's very much the same kind of the paradigm that you're using with ai.
That paradigm can change because now you don't have to do all those steps yourself. You're to use the word orchestrate. I, I think of, I think of architecting the system.
I think our, our role is architecting how works gets done. How are we gonna do this today? Oh, you have, I have that, I have parts of that already done.
I want you to figure out the rest or Hey, really good, really good agents there, Brad, be, be ashamed if I borrowed those from you. Thank you. But it's a different way of working.
And I think that's what's sort of like either scary or exciting or maybe a combination of both about AI of like, well, what is my job then? Well, I dunno. I think we're figuring that out.
I, I think if anything, you know, we're, we're realizing that domain expertise, um, the ability to reason critically to assess critically, uh, is, is what's going to be the, the main skillset that's, that's gonna be in demand this year and beyond. And, you know, when I think about what cowork does and think about the crisis that we're already kind of building, uh, in for junior whatevers, you know, engineers or analysts or anybody, you know, in which companies are like, why should I hire them when I can just have AI do it? You know, and, and you, it doesn't take a full generation even to find yourself at a company with no ability to, you know, with no domain knowledge and no critical reasoning skills.
And, uh, so I think companies will increasingly wake up to that fact and look at, you know, what, what it means that we have the ability to, to take what was in a command line and expose it, uh, to, you know, the more broad, you know, any workflow because this could be used for anything. Um, and what that means, and what it means is that, you know, we as, as workers, information workers in, in the technology space, you know, have to cultivate those capabilities, those those skills, if you will, if we are to succeed, uh, going forward. And that's going to have its own ladder of, of ascension for, for, you know, building competency within companies.
So it's, it's not gonna be the same job. You're not gonna be having people try to all day chunk through, you know, the SQL standard, but if you can teach them to understand SQL and to recognize for the domain that you're working in at the company that, wow, that's a valid SQL statement. But boy, that is gonna gimme the wrong answer.
That that's what gonna matter most wrong answer the perfect, wrong answer. Totally. Yeah.
It, it, I I think we're entering an age of, we aren't gonna be trained on tools that, that's our training. That's the skill. What do you know, what language do you know tools?
You, okay, okay. Those are the tools we use. And yes, we'll still be using tools, but it, it is more the, you know, it's a systemic thinking is a problem.
It's really problem solving. It's really designing solutions to work. Um, yeah, it, it's really kind of thinking, uh, in a different paradigm about how you're gonna solve those problems with a new set of tools.
Uh, the tools aren't gonna show you how to do that. At least they don't. Now they show you what's possible.
You have to kind of think about that tipping point of, am I, am I, am I gonna do the manual version as I did in a web version that I'm now doing in an agent version? Where am I gonna re-architect this? Because now I can do a lot more or do it differently and accomplish more, or engage different things I never thought was possible, but I now do.
Yeah. Or get myself, you know, if I'm gonna do something more than once, maybe I should turn it into a system, a process. And now we have the ability to do that with, with tools like this.
That's what I did. That was a, that example from this weekend, Hey, I did this, like totally, exactly. Reverse engineering now create tool to do that, because I bet that's not the last time I do it, so probably not.
Well, let's, let's, uh, let's move on to our last segment, the drop. Alright, I'll, I'll, I think I kicked in first last time. Why don't you jump right in, Brad, what's going on for you?
Yeah, totally. So, uh, I, I'm going back to old ideas because the backlog is that big. I'm, I'm going back to 2022 and 2024.
Well, you're reaching back a little bit there. Totally. Yeah.
Uh, this, this idea, because you know how I, I talk a lot about, you know, it's context engineering and intent engineering, et cetera, and you're not prompt engineering. It's not where the sweet spot is, or the only sweet spot. And so this idea of, um, it's, it's like a bidirectional attention hack within a prompt that's, that's called re two, which is basically just rereading.
And what it, what what it's about is you can take a non reasoning model, meaning a non-thinking model, um, that's just, you know, your straightforward, you know, um, one directional no, yeah, it's one directional, um, and transformer. And, um, just tell it what you want it to do twice, uh, once at the outset and once at the end. And, and the example I'll give is, um, you know, if you're, if you're telling it to read a legal document and, and look for exposure to, you know, some sort of threat or, or whatever, and you, you don't state that the outset, it's just gonna read the document.
It's, it's a, it's called a triangle of attention in which the model, when it starts to look through the, um, the input tokens, uh, that first token doesn't, doesn't see anything in front of it. It only sees itself and what's behind it. So if you can give it sort of like another basic one is, you know, I want this in JSON, uh, logical, but if you just put it at the end, it's gonna go through all that work and the prompt and, and processing the tokens that go, oh, he wanted it in JSO, that idiot.
Why didn't he tell me that? Um, so it, it's, it's just like a, a hack that I want to sort of systematize, um, where appropriate and, and put it into some, uh, a test environment this week to see, to see if that improves some of the, the work that we, we have, uh, to, to, you know, for long context, uh, inferencing. Is that a bit like, um, we may have, I dunno if we talked about this, but defining success criteria, what success looks like, the end state, Hey, stop.
Yeah. Hey, my dogs are going crazy. Stop.
Hold on. They wanna be on the podcast. They're like, here, something is going on in there.
Well, hold on. I'm let them out here. Okay.
Demanding puppies. Yeah. That's, is this like, uh, the, uh, there's the idea of defining success or defining what the instate not just what you want.
So, and when you have a multi-step reasoning model, then you can iterate until it gets what you're asking for. Right, exactly. Um, is that sort of in similar idea what you're talking about?
Yeah, but without the cost, without the latency and the token cost of doing the, the reasoning, you, you just are spending pre, you know, input tokens, which are vastly cheaper than output tokens to do this. So you don't have to spend all that money, um, you know, on a huge reasoning model. You can get the same level of performance with a non reasoning model, just with basic, you know, hack attention hacking.
It's the, um, okay, we have a great way of doing this now, let's find efficient way of doing this. Right. Yeah.
That's why I like, that's why I like spec driven development, even, even if, uh, it, it does become idiotic from time to time. Okay. Well that sounds like another PO podcast episode.
Um, well, great. I'm, I'm, I, I mean, very interested to see where you'll go with this. So, um, yeah.
Whatcha thinking about right now? Yeah. You know, it's, um, I had this sort of flurry of generating a whole bunch of reports last week.
'cause a lot of stuff happened, um, right the beginning of the year. Yeah. GI GitLab came out with their release and their duo platform for agents and, um, Dynatrace did an acquisition.
You know, all those kinds of things and projects that we have going on. So I'm, I'm really thinking about how to lean into, we have something called the future of Intelligence platform, which is our, in, it's not our internal, but it's our internal and external platform that we use where all our data lives, all our reports lives. But more, I think more importantly, it's where our AI lives.
And today I do a lot of the AI things external to it, because it's being developed, but it's coming along. Uh, and they made some impressive strides. Agreed.
And those things will be available to our customers as well. Um, to the point where, you know, when I have AI co-write with me, let's call it that, when I use it to do writing with me, um, you know, is that akin to AI slot or is that akin to, um, no, it's just like if I hired a writer to write stuff for me in, in my name and then instruct them, okay, that's not quite what I want. This is what, this is the idea.
It's not firm enough on what I'm looking for strong enough. It doesn't lean in like I am looking for, and it doesn't make these connections. Okay, good.
We're getting there. We're getting there. Um, great.
Now I'll tweak it and add some more to it, and then I have a finished product. And I think that's where, you know, AI slap, we always look for ways to, you know, downplay and call something stupid and say, oh, that's just AI slap. Well, it's not, I think that we're, we're emerging into an environment where AI is, is a writing assistant.
I mean, yes, it can write stuff for us, and you can push the publish button and we never touch it. Um, and there may be cases for that, but for us, it's a very much an interactive partner in how we do our work. And what's nice about it is, is there is added information, added ideas that I can pick out and say, had not thought about that.
Or, what about this, you know, Hey, I didn't Microsoft do something similar like this two years ago. Okay, let's make a reference to that. Say this paradigm continues, or whatever.
That I've each so busy writing it that I wouldn't have time to kind of think about making it improving it better. So we're just like, we're talking about changing the interaction model for, for ai, for coding or tasks or agents and all that stuff. Like, the content model is changing, and it's not binary.
It's either AI written or it's not. Um, so Billy Bob Thornton is not leaving Landman that is AI lop, but other than that, found that out this weekend. So, um, as I'm working on content more and more, I'm trying to figure out how does, how, what is role does AI play in and how can I leverage it to the best to amplify what I wanna do, not replace what I wanna do?
Yeah, I love that. And we should, we could do an entire episode just, just on those, you know, ideas and, uh, some of the learnings that we've had and, and continue to have mm-hmm. Every moment to moment.
Uh, uh, it, but you know, like you, uh, I look at it, uh, very sim very similarly, and, um, you know, I, I see, you know, the ability to not, not just, you know, speed, not just to gain speed, but also to, like you're just talking about, to build a, you know, better outcome, uh, build build something that's more useful to myself and to our customers. And if expanding your, um, uh, knowledge, uh, what would you call it, uh, horizon, let's say like you're talking about with did Microsoft do that? You, that in and of itself is, is a tremendous step forward for us.
That makes us better at our job as an analyst. And that is, that is a tool I will use every day. Yep.
Absolutely. Well, it's been fun, Brad, as always, thanks to Corey, our, uh, our podcast engineer for helping us make this happen and doing a little edits here and here when my dogs get outta control. And thanks, everybody's patience with that as well.
Hope you've enjoyed this episode. Uh, we do this weekly, uh, from wherever the world Brad and I and Corey are, and we hop on and talk about what we're working on and what's going on in our world, but really what's going on in the larger world, because that's what we do as analysts kind, is work on those things and, uh, try to understand where we think that's all headed, which is why we post the content that we do. So be your sure and check out Brad's fantastic research.
You can go to futurum group com slash brad Shiman shiman, same thing for me slash Mitch, excuse me slash mitch dash. I said that, right? Um, check out our stuff and we appreciate you following.
Send us a comment, send us a note, uh, like us, follow us, share us with your friends. Uh, if you don't like us, tell us too. You can put it on a comment or send us a note.
We're happy to, uh, improve what we're doing, whether it's a podcast or our analysis. So, Brad, on behalf of yourself and Corey, thanks everybody for joining. We'll be back next, another episode.
This agent dev, I'm in position. Hey everyone, welcome to another episode of Still Cyber. After all these years, I'm Alan Chimo, and there is no Mitchell Ashley today.
Unfortunately, Mitchell is stuck in the snow co snowpocalypse up. He's up in Colorado. He has no power in his house, and we made the, we made the, uh, the decision go.
No, go. We're going. So Mitchell will be on the next one, but I'm really happy to have someone else on here.
Otherwise you'd have to listen to me talk for 25 minutes by myself. We've got Brian Pac Pec. That's right.
You got it. I've interviewed Brian before, but I'm just terrible with names. Brian is the SVP of product at our friends over at DigiCert.
And, uh, we're gonna talk a little bit about some things that really revolve around digital certificates, post quantum encryption, and we're gonna talk about Quantum. And as Welton, I want to introduce you all to something we call Quantum Security 25, which is something we're doing with DigiCert, but we're gonna talk security and Quantum and everything else. Brian, welcome to Still Cyber.
It's great to have you on. Thank you. Um, you know, let me just, I think everyone, well, not everyone, people are not gonna know DigiCert, just real quick, let's get that out of the way.
Who's DigiCert? Why should they know you? Yeah, so DigiCert's been around for quite some time.
We, uh, started out really as a ca a publicly trusted certificate authority, you know, providing trust between browsers and servers and connections and medical devices and everything that's on the internet, right? Um, we have extended all of that to really provide an ecosystem around that digital trust where we could manage, you know, all the workflows, all the connections around documents, around, um, you know, networks around, uh, IOT devices against software, uh, and now even into ai, right? So there's some really interesting things that the foundations of what we do with PKI and DNS, um, you know, spreads out to even the, the things we're doing right now with AI that seemed quite new.
So it's, uh, very interesting. Absolutely. You know, we we're gonna come back to the AI piece first.
I, I wanted to, I wanted to touch on a lot of my friends out here. You know, digital certificates have been around, as you said, Brian, a long time. Um, primarily Google has been a big instigator, a mover in this about your shortening the lifespans of digital certificates, right?
It, and there's a lot of reasons for it. It's not just to raise more money on certificate fees, right? It's about security.
The, you know, the longer that certificate's out there, the more of a chance there is that something could go wrong. Yeah. Right?
That something could be compromised. So the latest, I, I think it's the latest sort of expiration date that's coming on fresh certificates is 47 day. First of all, why'd we pick 47 days anyway, Brian, That, that, I wish I, I wish I knew a succinct answer to that one.
The powers at be in these consortiums came up with, uh, with that date. But yeah, 47 days probably has some mathematical magic to it that I don't understand. Is that what the thing is?
I'm thinking? I think so. I said 45, you said 50.
I said, let's meet in the middle. We can't do 47 and a half. Let's go 47.
No, I want 48. All right. I'm gonna let you have this one in 47.
It, it feels like something like that. Yeah. Yeah.
I mean, it's just random, random stuff. And maybe that is part of it, that it's random. Of course, we're not, or, uh, some players like Google don't wanna stop at 47.
They wanna, they wanna get down to 30, they want get down to weekly. I mean, you know, what, what holds us back? Why, why?
Well, let's talk about, first of all, Brian, why do we want to make certificates, lifetimes, you know, more fungible, more ephemeral, if you will. Yeah, I mean, I think it, it comes down to a couple kind of market driving initiatives, if you wanna think of it that way. You mentioned Quantum as we, we talked earlier, right?
So anybody not aware, right? The threat of quantum computing shores algorithm, the ability to reverse RSA algorithms and, uh, you know, be able to effectively kind of crack. Modern crypto is looming out there.
And I think NIST has said by, uh, 2029, you know, they wanna deprecate RSA as a, as a major algorithm. That's, that's a big thing, right? That's not even really what's driving 47 day.
I mean, when you look at networks and, um, you know, some of the other things, right before you even get to the 47 day, they've introduced, um, this kind of multi-point inspection that we've been deploying that looks at, uh, you know, from different DNS endpoints across the internet to ensure the routes to domains are validated. So there's no BGP attacks in between. We're concerned with things like that, right?
So we're layering all these things together to provide security around the certificate, the network, the identity of the operator of that website, 47 days, kind of the next thing, right? That looks at it and says, we don't want these long lived keys. We don't want the kind of harvest now decrypt later attacks that exist with Quantum to, to be sitting out there.
Um, we, we want to also advance automation, right? So if you have certificates that are currently 398 days is what's allowed. Um, you're not really incentive incentivized to make that thing automatic unless you're maybe in like a cloud workload environment or something that is already automated itself.
So you have this huge disparity between some customers who do a ton of automation, and then others who are like, well, you know, I get an email, I'm gonna renew a cert, and it's 398 days. Um, so I think that push towards greater automation on networks just makes the entire ecosystem more resilient. Because you gotta remember in the event that something happens where there's maybe, uh, a compromise in the chain or validation, you know, uh, compromise or even network like BGP, we talked about compromise or something like that.
If you can automate the replacement of those certificates in, you know, very quickly, the risk of that event has been reduced significantly. And so I think we really drive towards that automation and replacement and, you know, kind of good crypto hygiene around the networks. Absolutely.
Absolutely. You know, to me, the, the, it's two things. Number one is if, if my certificates are so long lived that I gotta worry about it once a year, once every year and a half, I don't have a strong incentive to, to, uh, automate it.
But, but here's the other thing that I think drives certificate automation. It's the amount of certificates. You know, there was a day when I had a company, I had one website, one domain, maybe two domains.
Yeah. You know, but today, you know, the average enterprise is managing there, I say hundreds if not thousands of certificates, right? Yeah.
And it, it's, and it's not just the digital, the SSL certificate on your website. It's the identifiable, you know, the certificate of authority, like the identity certificate. And it's not even people, I mean, I guess every person Yeah, right?
Is is authenticated that way, but it's the machine certificate every That's right. Every container has a certificate, every device has a unique certificate, every instance of a cloud, every server. And now you with AI is a, it's every AI agent, every, every, uh, API.
Yep. They all have, you know, you may know this better than me, Brian, the average enterprise, how many certificates are they managing? Oh, it's, I mean, so step back one second.
So as you go into that number, what's fascinating is people, when they generally think about certificates, they're thinking about those kind of publicly trusted certificates, I think you were trying to outline there. So the things that they kind of pay for and that they issue, right? To protect the outside of that network, that number has grown astronomically as services have scaled.
But like you were alluding to, when you look inside that network, you look into Kubernetes or containers or cloud systems or things like this, that's where now you get to your question, enterprises typically have about, uh, 50,000 certificates that they're measuring or are managing on that internal network. And that's kind of, you know, we've heard other enterprises that have many, many more than that, right? So to your point about, um, scalability, um, you know, it's, this number has just grown, gone, grown so huge and, and out of control that when you take those external certificates and you take those internal certificates and you're interconnecting APIs and workloads and all these sorts of things there, you know, I, I always like to say it, and I maybe shouldn't 'cause I'm, you know, kind of in the ca world, but it's, it's like they're little ticking time bombs, right?
They, they literally have a clock on them and they will stop working at some point. And if you don't have a way to know where they are and you don't have a way to get to them and replace them, and you have an environment that has, you know, maybe 50,000 in these containers that are kind of ephemeral, it's an even harder problem to keep track of these things. And they're just ticking away, right?
And, and we hear time and time again, unfortunately from customers where something will expire somewhere down deep in some deployed infrastructure and the chain of events of what it brought down, where then felt by a customer externally. Um, and that's really, you know, kind of a, a mission of ours at Dig Cert is just providing the tooling and technologies to, to add rich automation around this so that we can prevent those outages for people. Absolutely.
So, you know, first was the, the length of the, the life of these certificates, right? Yeah. As they grow shorter, automation becomes more imperative, but that pales in comparison to having to manage 50,000 of these suckers, right?
Yeah. Now, automation is no longer a nice to have automation's a must have. Now, of course, the whole, our whole certificate world, our whole encryption world, which so much of the internet rides on so much our privacy is based on, is is based on sort of the RSA algorithms.
Yeah. You know, 1 28, 200, even 256 bit encryptions. And, and for those of you who don't know what that means, you can go look it up or ask your ai, they could explain it to you, but the real monster lurking on the horizon or has been lurking, has been, you know, post quantum encryption.
Because when quantum is real, what would take thousands of years of our best computers right now to, to crack will take maybe minutes. Uh, of course, you know, for the last 15 years, I've always heard Quantum's five years out, Quantum's, five years Out, it's always right there. Yeah.
And it's always five years out. I go five years later and it's still five years out. But now, but now stuff's getting real, right?
Q day. Yeah. You know, IBM swears it's gonna be 2028 maybe, but sometime in that timeframe, 20 28, 20 29, we're in 2026, right?
Q day, Q days is coming Q days that is coming. And, and the thing about Q days is everything I've read is, you know, it's not gonna be like happy New Year where we watch the ball drop in Times Square or something. It's gonna be kind of sneaky, right?
Well, all of a sudden you're gonna look around and say, holy mackerel, quantum computing is real. People are really using it. Now we already have sort of models and there are a few folks who are, you know, have models of quantum computers that are working to a certain extent, quantum networking and you know, a lot of quantum technology.
Yeah. But, um, but when Q Day comes, all these certificates could be rendered obsolete. That's right.
And I, I think if, if you, you maybe take a macro view of the whole situation. The certificate is a very small part of the quantum equation, right? Yeah.
So like you said, when, when the algorithms become compromised and you could basically, you know, run a certificate through a quantum computer and get the private key and get all the traffic, right? That's kind of the promise of quantum. Um, that's the risk, right?
But the mitigation for it, Alan, is, is complex, right? When I talk to customers about this, they come to us and say, Hey, dig, sir, you guys understand certificates. How do I replace those certificates?
Do I just need to automate everything on my network? Well, it's a good start and that'll help with the certificate. But that certificate is probably on a server.
That server has a crypto stack, there's software on that server that's providing cryptography that needs to be updated, is probably working through some sort of network, maybe load balancers, maybe, you know, different network infrastructure. It also needs to support those algorithms and quantum the technology, uh, flowing through there, uh, post quantum algorithms flow flowing through there. Um, and then you start to, you go through that like are using, uh, accelerators, right?
There's RSA acceleration hardware that people use. Well, that isn't gonna work anymore when you're not using RSA. So now your whole network slows down.
So now you need to buy more stuff to scale, right? Like, this problem really starts to unpack. And, and I don't think people kind of get that.
There's a lot of depth there. You're replacing software, you're looking at networks, you're looking at your certificates, you're looking at automation, you're looking at, um, you know, the various components. And, and God forbid if the organization is running their own hardware security modules for encryption, those all need to be updated to support these algorithms, right?
And then any downstream technology supported on that. Um, you know, I was talking with a bank, uh, a a couple weeks ago, and they're using, um, you know, uh, smart card like UB tokens and things like this to authenticate those all need to support these algorithms. Yeah.
You look at your Mac, you, the Mac that maybe you're using right now, your desktop, it has the little touch ID thing. Well, you know, Macs that are, I think six months and older, none of them support post quantum algorithms with your touch id, right? You can't even store it in a key chain.
So there's all sorts of hardware, there's all sorts of network, there's all sorts of ecosystem that needs to go the certificate. Yes, of course we gotta replace those and provide automation around those and do that, but there's this infrastructure that needs to be supported that we're, you know, that's the one single biggest thing when we talk to customers is if they come to us and they think it's a cert problem, we're like, there's a lot more you guys are gonna have to do. And now when you're putting your CISO hat on, are you budgeting this?
Are you planning for this? Do you have time to even go endeavor to figure this stuff out? And and I think that's where, you know, maybe two and a half, three years ago, Alan, people kind of were like, well, it's always kind of coming.
It's, you know, we're not gonna have to do anything. But with this NIST announcement that said, Hey, you know, we're looking at 2029 to, uh, kind of correlate with the 47 day, uh, certificate lifetime for RSA to be, uh, effectively deprecated, that really got people to say, whoa, hold on. Now we need to figure this out.
Let's get a plan together and let's figure out how we can address this quantum thing across the entirety of our network and infrastructure. So Brian, I, I, look, I, I agree with you a a hundred percent over on this, but I'm an optimistic kind of guy, right? And so what I always, what I believe is that when it comes to this quantum cryptography, post quantum world's, one of the few times where I've seen both the government and industry partnering together to get out ahead on this, right?
Yeah. And the fact that NIST did come out and, and the industry did come out and say, Hey, we're gonna deprecate RSA in 2029. They did approve, you know, post quantum algorithms that are, you know, theoretically quantum proof or whatever you want to call it.
Um, you know, we, we didn't handle Y 2K that well, and even though that turned out to be a bit of a nothing burger, but still remember what it was like back then. Yeah. People were kind of freaking, um, I think, you know, there's reason to freak here that it's not just about post quantum algorithms.
Yeah. Quite frankly. Yeah.
As you say, there's a lot that goes into making sure all our equipment can handle these new algorithms. Right. But we, we shouldn't be freaking out about it.
We should just be diligent about it, I think. Yeah. Yeah.
And, and I think, you know, to that point, like it's, it's, it's fascinating too, 'cause that the, the way I just talked about it was kind of focused on the network, right? But when you look at cryptography and you look at a quantum computer being able to attack just generalized cryptography, cryptography is used everywhere. Right?
So we kind of dissected the network problem there just a moment ago. But what about all your databases that have row level encryption? What about all your backups that are encrypted and stored somewhere?
What, like, all of these things, as you look at trying to become quantum ready as an organization, well, you'll need to re-encrypt those things. You'll need some new keys. You'll need to store them differently.
Like there's a whole downstream piece there. 'cause when you look at, you know, the attacks right now that you can't prevent are harvest. Now decrypt later attacks.
People are literally capturing network or traffic or backups or whatever hackers can get their hands on that are encrypted that they can't read right now. But it's valuable enough to store, put it on a hard drive. And once a quantum computer is there, now I can get the contents of that.
And you can use your imagination for the kinds of things you could use if you knew in three years you can gain access to it. There's probably some things you'd want access. So I think that's why you have an organization and a collaboration between governments and institutions and, uh, you know, uh, commercial vendors to try and solve this.
Because the risk is, is so, so high across all of that plane of data that we use for commerce globally. I mean, imagine if the internet was all HTTP right now, you would never send a message to anybody. Certainly not a credit card like the, so there's no way any of these things in systems would function.
And if you look at the global economy and how much is pinned on that, it's a pretty big deal that we make sure that keeps working, let alone anything else that goes into secrecy and privacy and all these. And I think, you know, you gotta measure that against you. You know, you're not putting quantum back in the box like it, it's gonna happen, and why is it gonna happen?
We focus on the negatives here. But the positives are, there's huge supply chain problems. There's huge, um, pharma problems, genome problems.
There's all these kinds of computationally, um, intense tasks that would take hundreds of thousands of years to do with computers today that they're building these computers and these algorithms to do in moments, right? Yeah. And so that's why this will happen, is we're trying to solve incredible Problems with these computers.
It's gonna be change. And, you know, not to mention that they say AI won't really hit its potential until it we're running quantum. Yeah.
Right. And vice versa, AI will enable, you know, once you have functioning quantum technology, AI will enable breakthrough breakthroughs using that quantum technology and quantum technology will enable breakthroughs on ai. So it's kind of a very symbiotic, almost relationship.
Yeah, definitely Crazy stuff. But, um, you know, I I wanted to mention Brian, right? DigiCert has been, I mentioned this and, and staying outta ahead, DigiCert's been one of these partners in that effort and has been a company that has really tried to take the lead as we move to a quantum future.
I don't know if I agree with the word post quantum Brian. Right? It's quantum, it's not post quantum.
It's not like Q Day happens and, and then Quantum goes away. It's from that day on, it's quantum. So it's not really, Well, I, we're just After Quantum.
Yeah. We're just trying to mark that there's a day when those computers and algorithms become real. Right?
Right. They, they attack all the things you just talk about. Yeah.
Right. Yeah. But, you know, but DigiCert, as I mentioned, DigiCert has been taking the lead in this, and one of the initiatives they're working on that we're, we're actually working on, right?
With, and in partnership with DigiCert is something we're all calling the Quantum security 25. We would get, we're trying to stay out ahead of this thing. We're trying to publicize, hey, who are the top 25 or so leaders in this quantum space.
Yes. And, you know, and it's still early, there's still time for people to make the top 25. But I, I will tell you here at, at Techstrong, we have been, you know, we've been talking about reporting on Quantum for a while.
Um, you know, tech Strums part of Futurum Group now, and I, I had the chance through FU to meet, um, what was a former chairman of fu, but he had to step down when he became the CEO of a company called Ion QA guy named Nicolo, Nicolo, Desi Nicolo, you know, ion Q is a big company out there in Quantum. Yeah. So, and then I live, we live in Palm Beach County here in Florida.
That's where our offices are. And you know, Palm Beach County itself has this big push on to be called, uh, quantum Beach. I know it sounds corny.
It sounds corny. It wasn't my idea. But nevertheless, that we, we've had some conferences down here around quantum technology, and they're, or they're putting together all kinds of incentives to get quantum companies to move down here.
Hey, at least we wouldn't have six degrees where you are in Austin. So I I would love to be at the Quantum Beach right now. Yes.
Yeah, exactly. Exactly. Austin, Texas is like six degrees right now, so Yeah.
And Austin's not known for its tough weather. It's usually too hot. But anyway, quantum Beach, go figure.
Um, but so, you know, there, there is this growing momentum across the industry, and it's not just security. It's not just the post quantum algorithm crowd, it's, it's quantum in general, all of, of what Quantum's gonna mean. I, I had a chance.
None of, actually, she lives in Miami. She's the CEO of Q Secure. I don't know if you ever heard of this company Q Secure, she's got a PhD in ai and now she's working on, on Quantum as well.
There, there are amazing people as so many very, very, IBM's and other company's been working on this, right? Yeah. These are all companies that we need to get involved in this Quantum Security 25.
Yeah. Um, people that we need to get in here. But Brian, if you can, and I don't know how much you're keyed into all this, I may even be more keyed into it than you, but once we picked the Quantum Security 25, what, what, what's the idea?
What's the reasoning? Where do we go from there? Yeah.
I mean, I'm, to be honest with you, I'm not keyed into the whole Quantum 25 largely. I did a All Right. Let run with it from, that's why I love doing these podcasts.
Yeah. So the idea here is let's identify 25 or the top 25 leading personalities. People.
I don't think you can have an ai, it has to be a real human, um, you know, who are, who are thought leaders who are pushing the, the, the rope here on, on, on quantum technology and quantum security. Right. Because yeah.
I think the thing we need to be clear on is you really can't let quantum computing out in the wild without quantum security. Right. Without all hell breaking loose anyway.
Yeah. So, um, you know, but who are the leaders in this? And then I think for the rest of us, it gives us some people to follow, if nothing else.
Yeah, yeah. People to follow on LinkedIn or X or wherever you follow your, your folks. Yeah, yeah.
As we watch the countdown acute day into a post quantum world, you know, come about. Yeah. Uh, so if you're watching this, listening to this, whatever, and you know, someone who you think is a quantum security 25, a quantum 25, uh, personality, you can nominate them.
Uh, I don't, I don't have the URL infirmary, but it'll be in the notes on, on our podcast, and you could get it off on Techstrong as well, uh, on Techstrong ai, techstrong it, any of the tech sites. I'll have it as well. Um, but Brian, it's, it's because it's getting real now.
Yeah. We're running low on time, but let me bring it back full circle. Yeah.
Go. The 47 day certificate is, we want us to get into the habit of refreshing our certificates because as two day gets closer, and as this becomes real, we want everyone to be able to have muscle memory Right. If you will.
But the 47 day, uh, standard goes into effect, I think just in another month and a half or so. March four, 15th March, yeah. The hides of March.
Um, what could people do? You know, I hope no one's sitting here saying, oh my God, I never heard of that. Right.
I, I better get busy. But there probably is. There probably are.
Uh, yeah. What, what should people do there? Well, I think there's, you know, some pragmatic things, right?
So a lot of the customers we have, you know, it's January, what, 26th right now? Yeah. They're, um, very much gi like, especially if you have a large fleet of certificates.
I mean, even if you just got a, a few and you're short staffed, people are preis issuing now, right? So they're saying, Hey, I can still get 398 days for, you know, another month or so, let me just, you know, if I'm close to expiration or if I've got things, let me just get those now. Lemme buy some time Load up and buy some time on that network.
Um, so I can sort out the harder problems, like, how do I automate this stuff? How do I make sure my DNS works properly with the automation? How do I make sure, like all the kinda laddering of, of executing on it?
So I think that's probably the most simple advice I give people right now is, you know, kind of preload, get yourself moving, so you give yourself some time, and then this is your last warning, because the timelines are only gonna get shorter. You know, this year, 2026, we go down to 200 days, 20, 27, we go down to a hundred days. 20, 29 we go down, or I'm sorry, 20, 27, we go down a hundred days.
20, 29, we go down to 47 days. So it's only getting less time. You will have to automate.
Um, so this is really the last shot. Yeah. I mean, look, quite frankly, by 2029, we may have had Q Day already, right?
And yes, man, if you didn't change it, Go home, you're not automated by then. Oh, Goodnight. You got trouble.
Yeah, yeah. You got trouble. That's gonna be trouble.
Yeah, absolutely. Hey, Brian, where can people find out more about all that stuff on DigiCert? com.
We've got, you know, all the, the blogs, the events, we've got our World Quantum Readiness Day, which we didn't talk about, uh oh. But kind of stitches into your 25. So we've been leading on that for the last, uh, couple years now.
And, and, you know, we do awards in there for industry leading companies that sound very similar to the Quantum 25 here. Um, you know, just trying to push that forward and get that thinking right. com.
Love it. Brian, I appreciate you coming on. Poor Mitchell.
Stuck somewhere in Colorado in the snow with no power. Yeah. But you and I, well, you had six degrees in Austin, but you made lemonade outta lemons.
You went tobogganing and sledding. We did, Yes. One day your kids will grow up and say, you remember when we, we went sledding here in Austin?
And they're like, no way. Yeah. Yeah.
They'll be like, who's the crazy guy that had a toboggan in Austin, Texas? You Know what? That's why you keep it there for 50 years for that once every 50 year thing, man.
Um, but thanks for coming on still Cyber, appreciate it. Say hello to all my friends. Thanks having Alan, sir.
Alrighty. I will. Hey, you've just listened to still Cyber, it's Alan Shiel.
No, Mitchell Ashley today, but he'll be back next time. Until then, everyone take care. Hey, everyone, welcome back here to Tech Drunk tv.
You know, we recorded this on the Snow Apocalypse Day, and a lot of, a lot of people, well, we were late getting this done because we had some people not able, not this one, but previous interviews we had people without power, without heat, without internet. But my next guest has no problem. He's out in beautiful Honolulu, Hawaii.
That's right. Living the Life. Let me introduce you to Dan Cole, SVP of Product Management at Sophos.
Hey, Dan, welcome to Tech Drunk tv. Uh, A little Hi, Allen. Yeah, I'm coming from Honolulu Live.
Um, yeah, yeah, look, it's, it's really nice to be out here and the weather is 76. Stay some cold for us here, put on a sweater. But, um, you know, we do have some stuff in Monolo.
Occasionally you can sober that. Yes, you do. But, uh, the, the, one of the parts of living on a, the sad part is I do get up earlier in the morning, three, four them, or it's actually six 30 years.
Sun's not out yet, but you get a lot done that way. But, um, yeah, it's, it's been great. Um, you know, um, being in Hawaii a lot of times you get both sides of the spectrum.
You get a lot of folks. Um, my my India team and Germany team, by the time they're up and I get up, they're already halfway through the year, the day. So yeah.
Lot, lot to get used to there. You know what I, I'll I'll admit, I, as I was talking to you off camera, I've been to Hawaii many, many, many times, and I have fantasized about moving to Maui, actually. And I, and I figured that's exactly what I do.
I'd have to get up at about two, three in the morning, put in a day, but by noon the day, the rest of the day's mine Yeah. And all that. Yeah, Yeah.
No, absolutely. Of course, as I said, it was a fantasy. Um, though my wife, my wife lived it with me, she'd do it too in a heartbeat.
But, you know, so we settle for Bo Herts on Florida, where it's also about 76 degrees. Hey, not a bad spot. A readable location, Not a bad Yeah.
On the water. But anyway, let, we we're just of course, saying this to rub it in all you poor souls out there. We're, we're snow in.
Dan, how did you get to be SVP of product management at Sophos? Tell us a little bit about your journey. Yeah, know my journey here.
So I've been here for about nine years. I've definitely seen a lot of changes even at Sophos, but in the business in general. But kinda rewind back to 1998, that's kind of where I really packed my teeth into security.
I worked at, at telecom here in San Francisco, in California when I lived there, um, during the dotcom era. So my first experience, I think it was like day week one, where the Melissa virus hit and we were Oh yeah, for the, no, for the SOC and the NOx for the, the Sun Spark Systems that for ran all the exchange systems, right? So my first week was balancing servers and then Kind I fast forwarded a couple months later, then I love You virus, hit again, another issue there.
And I quickly realized that it, telco is probably, although it's a hotspot, you kind of run, have to move up the stack. And my first job after that was in security working for a company called Sonic Walt. And, um, you know, they're still Around.
They're still around. Yeah. Yeah.
I definitely, I have my roots there, but, um, code Red hit around that time. So, you know, it was just my, my, my experience in cyber has always been the reaction of all these different types of events happening. And me just kinda like drinking from a water hose and figure out what is causing all these issues and how do I get a customer's back on the right.
But, um, yeah, so, so Sowell was kind of my first area. Then kinda moving up the rank, we, I, I worked at a couple startups in, in Silicon Valley where we did some embedded chips where, how do we make the chips power be fast enough to run on these next generation of appliances and systems in there. Um, and then you kind of fast forward about a decade head later moving in from, uh, sales into more of a PM role, where I figured kind of going upstream, let's go fix the root of the issue, build the product the way we wanna feel, build it.
Um, and I worked with a couple other different competitors in that, that mi that space there. And, um, you know, I think what I learned quickly is that as you kind of move up the stack and up the ranks from, you know, an SMB to the enterprise, it probably just gets even more difficult, more interesting to go south. So it went from just having network security becoming kind of my, my main, my main forte to, and expanding that and talking about the solution as a whole.
How does it integrate with that, that interactive system that's out there, whether it be Sims or Jason Layer Chief technology, or even going up second to cloud. You know, that's kind of been the last 25 years of my, my journey being at sofos. Um, the reason I came over to sofos to was to build a firewall from scratch.
And, you know, in 2015, there wasn't a lot of firewall vendors that are building things from scratch. If, you know, a lot of times you're just kind of taking over an existing business. And so the exciting thing about Sophos is they acquired a p two companies called Starro and Cyber, and they were trying to get those two technologies and build something new out of that.
And, um, you know, Joe's, our CEO who I worked for in previous roles, um, was like, Hey, why don't you come over and go, go build this the way we wanna go build it. And so my last eight years here, my journey has been rebuilding the data plane to the management plane, the control plane. And so now we have this new product called XGS that now it's in our second generation of hardware.
So I'm really happy about, about that. But through that whole process and that, that exploration, we realize that as you move up from just the UTM you mentioned, to next generation firewall to a network security clients, that it's not just that system that has to work with endpoint and has to work with adjacent technology. So the last two, three years from that next, that that next generation of technology we built, how do we now hook that into the rest of the ecosystem that Simple has?
Right? And so, uh, I'll tell you a quick story. So during COVID when we got hit with a lot of the different threat actors that were hitting the different vendors, you know, we're one of 'em actually have a great research pay product called Pacific Graham, where we documented how these, these, um, four national threat actors actually invaded our, our products and, and, you know, got into it through, through, through some very complex attacks.
And I think that w that's the point in time where we realized that, hey, we some service that capability that can react to that. You know, we had those, we had a 24 7 bridge going on for weeks as we were responding to that. So the, the, the, the birth of MDR really came from that experience that we had.
Uh, we called it MTR, the announced all MDR. Um, so yeah, it's just been a really great journey in the last 25 years. Just the, the evolution of where, where, where, where it all started to where we're now, You know, Dan, my, my, my security, sorry, my AirPod came out, my security experience is probably similar to yours in terms of times and what we went through.
I also got into managed firewalls in 19 97, 98. Of course, checkpoint was like the only ones you, you know, with the EC and all that stuff. And, you know, and I was also protecting Sun Ultra Spark machines and Ultra Spark tens and twenties.
And I remember the Melissa and the I love you and, and all of these other things. You know, you look back on those days, Dan and is as hectic and frantic as it was as yeah, almost baby stuff compared to what we deal with today. You, you didn't have nation, well, maybe you did have nation state as threat actors then, and we just didn't realize it.
Right. But, you know, I mean, it was, it was kitty scripters and it was, you know, I did it because I could Yeah, yeah. Script kitties and just, yeah, No, that kind of stuff.
Not, not cyber warfare. Yeah. Yeah.
Which is stakes has definitely been leveled out since that time, for sure. Yeah. Well, the stakes, right?
The stakes are higher, the attack surfaces are bigger. The threat actors are more sophisticated with ai. The technology is, you know, they use it as good as we can.
And, and that's also been, I think, a, a constant during my career in security is, you know, don't think we're smarter than the bad guys. 'cause they, they, they ain't dummies, right? They're, they're well funded, they're well organized, they're well compensated.
Mm-hmm. Right? Yep.
They're, they're a formidable, formidable opponent. And we, you know, and, and almost by the nature of the beast, sometimes they're always one step behind just by design. Yeah.
You know, I think for me, the philosophy of preventing stopping threats all the time, you know, it, it, it, it was kind of the, the goal in the 2010s, 2000, you know, you, you find 'em, you stop 'em, you build out your signature database, you find a way to just sort that attack. And I think what we're realizing now is that, well, it is gonna come in then how do you medic, how do you mitigate that time to reaction? How do you mitigate the actual amount of the out spread of the breach?
How do you know something came in? And then, then how do you ensure that you can quantify that value and that cost so that way you're, you're building into your budget. That's the what our customers are partners most concerned about was like, I think we're kind of in that, that that inflection point of like, okay, yeah, an accident will happen just like in a car, right?
And eventually you'll get an accident. So what's your insurance policy? You know, what is your remediation step?
How do you kind of react to that? I think a lot of, um, board level, um, meetings are kind of in that, that top inspection point. So no longer you're like, what?
Not gonna be attacked, but when it happens, how do you do it? React to it. I think that's why products like services like MDR have really popular nowadays because you realize that that's that extra layer that you need.
It's really kind of that additional insurance policy you have. Um, but just let the car knowledge of I have Absolutely. Look, to me, this all falls under resilience.
Yeah. Right? Absolutely.
Yeah. We, we, we, we, we had a shift from prevention to resilience. Not that we abandoned prevention that that's not it.
But really, if you didn't have your resilience kinda planning built in and layers, you're, you're in a bad place. Dan, you mentioned it a few times. MVR, is that what it was?
What does that stand for? And detection of response, which is exactly what we're just talking about, right? It's really about Yep.
Adding that process and, and, you know, with, you mentioned AI earlier, and that's, that's really kind of what's changed us at inflection point there as well, where it's just, you know, how do you ensure that as you have your systems that are really complex and hierarchical or sending that information, that data in, and there is some type of an attack or a breach. You know, do you have the personnel, do you have the AI augmentation that you need to first find that incident? And then how do you go react on it?
Right? And so, um, you know, at Sophos where we quickly realized as we have these products and customers installing it and deploying in that, when we have these type of events, what is that extra layer of, of personnel that we can actually provide to you at a, at a scalable level? And then how do we then use AI to ensure that, detect and find those things faster?
You mentioned that, that, you know, the attackers are getting, they're getting faster, they're using those tool sets, so how do we then, you know, respond and kind that, so yeah, it's detection response. Absolutely. Um, probably read the news.
We, we recently bought a company called SecureWorks where we, you know, we were able to kind of scale up with that new platform that they brought in. And SecureWorks actually been around for a very long time servicing various US customers and government institutions and banks. And so by getting that technology, that core capability and that human intelligence, we're able to snap that in into the Sophos ecosystem, into our product database.
And, um, that just gives us that extension that we need, which been really great. You know, I, I, I so my own, again, back to my own personal journey and security, I, I was the co-founder of a company called Still Secure. Yeah.
We did, uh, intrusion prevention, vulnerability management, network access control around 2007 or oh eight. I came to the realization that security was just too hard for so many, most organizations. Yeah.
And that MSSP was, was the way to go. You had to have, you know, who are you gonna call? Right?
It, it, Ghostbusters isn't helping you. Right. And so you needed, you needed that managed security service provider.
And we bought one down here in Florida, and we were, you know, plans were to do more. And then, you know, the oh 8, 0 9 kind of economic downturn came and mm-hmm. Actually I left, still secure then I've been doing this ever since.
But, um, I, you know, SecureWorks of course was probably in the US anyway, uh, probably the biggest of, of the MSPs, you know, that, that brought that in. Dan, if you don't, if you're okay there, I'd like to pivot over on January 20th, Sophos announced something called Sophos Workspace Protection. Yeah, yeah.
That's, that's, that's WP workspace. Yeah. You know, you know, really pointed, uh, the naming convention there.
It's just like, well, what do you do with this product where it's, it's really to protect your workspace. Um, actually, you know, good story. During, during COVID, um, my wife and I decided to, you know, kind of roam around the country a little bit.
You know, things were, you know, being in, stuck in a house. My son went off to college and we're like, Hey, let's go explore the country. We actually stayed in Florida a little bit as well.
And, um, I was remote quite of often. And so the idea came to me where like, hey, we're, I'm always, we're, you know, remote and, you know, our, our technology has us, you know, either V VPNing, our ZTNE, and to the infrastructure to access all the different things. And, um, some locations we didn't have good internet.
So, you know, what happens in those circumstances? Some things, um, require a little bit more deeper investigation that maybe A VPN doesn't, just doesn't cut it for you. So, you know, this idea came up of how do we kind of embed technologies into, you know, what you're working on.
And, and the, the core part of workspace protection is really, you know, using a, a kind of a, a bro, a browser, a browser extension, using our, our, our ZTNA platform using DNS extension, using email extensions, and kind of hooking that all together, having that consistent user experience. Um, for people who are looking for, you know, suffic for the, those hybrid workers, those folks who may be come into the office a little bit or maybe are remote a hundred percent of the time, how do we ensure that their security experience is consistent wherever they go? And so, you know, there's been other d different technology acronyms throughout this sass ESSC that kind of came about the last, you know, this decade has been pretty popular, but you know, that, that has a lot of big up upfront infrastructure costs, requires you to tether certain infrastructure that's processing the data in the cloud.
And you've been in the industry as long as I have. So we, we've done variations of that back in the day. Cloud web security Yep.
And stuff. And they have your own set of limitations and caveats and stuff. So we didn't want to go down that route.
We wanted to go down something that's gonna be a little bit more specific and pointed into the user experience. And, you know, one of the power, power pull play of Sophos is, you know, we, we were an endpoint company from 1980s back in the day when it's on Flocky Drive back in those days. So, um, we have a really big endpoint presence.
So we have an advantage a lot of these other SAS ESSC vendors that they didn't have, which is we have footprint coverage, right? And so, like, well, why don't we use that as leverage point, you know, we already have end pointing agents. What if we were to extend web control, web behavior function, which, you know, most of our activities done through web browsers, where most, I, even the SaaS applications just all piped in through your web browser experience.
You know, very rarely are you using the clients anymore, right? So, um, so yeah, the workplace protection was like a, a elimination of all those different technologies presented to our customers using kind of our endpoint footprint. And then, um, and on top of that, we, we hooked that into So Central, which is kind of a, the single source of truth that's our cloud management platform.
80% of our firewall customers use, use central management. So that's pretty powerful. It's, it's been adopted pretty worldwide, and our endpoints only managed on Central.
So by doing that, we're able to harmonize the policy configuration of Endpoint firewall and now the workspace protection, uh, suite. So that way you get that universal experience, whether you're on network or off network. And so, really beautiful.
We're elegant, we're super excited about it. Um, we went EAP last week. We have over a thousand people signed up in one week.
And so, and we're gonna go ga this thing in February 26th. It's been about a year and a half in the making. Um, we don't wanna just, um, it's actually powered by Island who's our partner for this.
And, um, island has been doing, uh, enterprise browsers for a very long time. They're well, well respected, renowned, um, in the enterprise space. And so we struck a deal with them where we wanted to kind of collaborate and wanna make sure that it's not just us providing the code and to our customer, because we and our customer is a little bit more sophisticated in the sense that we have to kind of scale up and down in organization sizes.
Um, they're used to using Sofo Central and they're also missing some other critical pieces like DNS Protection and ZTNA. So we thought, hey, let's get that stack from Mylan, let's combine it with our stack and make it all presented to Central and make it a really easy to use experience. So that's kinda what we did the last past year and a half.
So super excited about the launch. Um, we're really looking forward to it. Yeah.
Very cool. So, GA on, this is February 26th, about a month from the day you and I recorded this. Yeah, yeah, yeah.
That's, um, we've been about EAP for the last two, three months. So we've been having a lot of early beta testers and the, the, so far the feedback has been awesome. Amazing.
Um, a lot of folks are getting this feedback as to how they plan to deploy it, how they're trying to augment their, their cus their users with it. Um, a lot of the use cases are stemming around, uh, that, that hybrid workforce, right? We have a lot of, um, customers who have offices that are now back online and they're mandating two to three days work week, or they're self keeping some of their, their hybrid workers remote.
So they're trying to fi figure out, how do I go to address this now that we have customers coming, yeah. Users coming in and out of the network, how do we ensure that we have our, our security policy consistent? So that's the use case that we're driving for.
So we think that's, that's gonna resonate real well. Very cool. Hey Dan, we're about out time.
What would, you know, for people out there who's saying, wow, Sophos, this ain't grandpa's Sophos, right? There's so much going on. How do I stay on top of it?
What would you tell 'em? What's the best way to stay in the know on Sophos? Oh, you know, some of us like use chat Shipe or Gemini or whatever.
You can always search that and see what's new. But, um, you know, the traditional way is just, uh, you know, we have a great LinkedIn site. Also, our webpage have all been updated.
com, check out workspace. Um, youll find all the details I just talked about there. And, um, yeah, uh, we're, we'll, we'll, we'll make sure we propagate this video and anything else on different social media platforms.
Well, Very cool. Hey, Dan. Enjoy, enjoy Hawaii, right?
So you both worked up as well. Uh, I won't be out there this year, maybe next year. I'm waiting for them to rebuild the I, but it's gonna be a while.
Um, anyway, though man, keep up the great work at Sophos, this Sophos Workspace protection sound. Sounds great. Uh, MDM also sounds great.
There's so much going on. It's, you know, look, this is an exciting time. It's always exciting insecurity, but the stakes have never been higher.
So Yes, sir. Thank you, Simon. Good stuff.
Appreciate It. All righty. Dan Cole, SVP product Management at Sophos here on Techstrong tv.
We'll be right back. Hey everyone, this is Alan Hummel, CEO of Techstrong welcome, welcome to this very special virtual event that we are producing in partnership with our friends at Microsoft. The event is titled, unlocking the Future of Agentic Experiences.
And it's gonna be a series of videos in, in this virtual event that you're gonna be able to, you know, take a look at and, and interact maybe with some of the analysts and speakers here. I really think you're gonna enjoy and get a lot out of these videos in this event, and look forward to hearing your feedback. I'd like to kick things off with our keynote, and it's our keynote.
'cause I think we've got two terrific speakers in this one. And it's around the future of apps, right? And it features Fu CEO and principal analyst Daniel Newman.
If you've ever seen Daniel on any, either many TV shows or, or, uh, conferences that he keynotes, you know what a dynamic thought leader he is, I think you'll enjoy it. And Daniel is gonna be speaking with none other than Ryan Cunningham. Ryan, of course is corporate VP for the power platform at, uh, Microsoft.
And, you know, Ryan is gonna share with Daniel and with you the all up vision. The, you know, the all around vision for P Power platform. We're going to connect the dots between apps, agents, and interfaces, right?
Ryan, and, and you know, with Daniel are going to illustrate how Microsoft is leading automation in this AI era. He's gonna articulate how Microsoft is enabling every organization to build, govern, and scale intelligence solutions with unmatched speed and trust driving the future of ag agentic apps. It's a great discussion, and I think it's a great learning experience.
So here's Daniel Newman and Ryan Cunningham. Alan, thanks so much for that introduction and to introduce myself, I'm Daniel Newman, CEO of Futurum. Very excited to be here today with all of you and even more excited to introduce my guest for this conversation.
Ryan Cunningham from Microsoft. Ryan, why don't you say hello to everybody and give a little bit of background on the work you do at Microsoft. Uh, Thank you, Daniel.
It's awesome to be here with everybody today. So, I'm Ryan. I'm the corporate Vice President for Power Platform here at Microsoft.
So, uh, look after all the teams of, uh, uh, product people and engineers and designers that are building, uh, really our low code application platform and the future of where that is going, uh, you know, really excited to talk to you about that today, Ryan. I've been working, uh, with and around your team for many years as an analyst. It's been great to follow.
Of course, the change that's been going on in this market is extraordinary. And I think that everyone out there is gonna gonna lead this, uh, conversation knowing a little bit more. And hopefully maybe you'll give us a little bit of that, uh, secret sauce about all the stuff Microsoft's doing.
Nothing too secret though, you know how that goes. Oh, I know. So Let's, let's start big.
I mean, when we talk about the future of apps, connecting agents, interfaces, applications, you know, what is the kind of the North star for Microsoft? What are you, what are you guys heading towards here? Yeah, Uh, look, it's a, it's a crazy time to be alive in a business application platform, uh, environment, right?
Because, uh, this whole world is, uh, being turned upside down in actually two dimensions at the same time. Uh, one is how we build software, uh, radically changing in a world of agents and, and vibe coding and everything that is filling up our LinkedIn feeds as technology professionals. What's really interesting right now is the dramatic expansion in efficacy of what I can build and the dramatic expansion of who can participate.
At the same time, You have to be evolving the platform even more and even more quickly to, to get them what they need and what they're trying to do to accomplish the, the future that they're trying to build. Yeah, A hundred percent. And, you know, I would say to, to even build on your last comment 'cause it's relevant here.
Um, it's not just an opportunity for more people to tinker and build things. It's actually really an imperative. Like, if, if we're really gonna accept the premise that every company that wasn't born yesterday is operating inefficiently and needs to, to rapidly advance in a world of agents, then the expertise you need is not just the AI technology expertise.
You actually need to go get all of the process expertise, you know, all the humans who know what it really means to run a more efficient HR department or finance department, or, you know, whatever it is, they're sitting with a real job in that department today. You gotta go figure out how do I harness that expertise and bring those tools right to the, to the point where the process is actually happening today. And that's where you need a higher abstraction platform that has agents built into it that help do the coding, that help do the work.
Microsoft does have some really unique approaches in this space. And, and particularly if you look at this broader world of how software is getting built and code generation and agent swarms and every other term we're coming up with right now, you know, where we're really focused right now, particularly in the space of business applications and productivity, is really make that relevant to the way companies run and operate. You know, we're not out there to, to, uh, you know, serve any possible whim of any possible developer on the planet.
There's lots of great tools for that. Microsoft makes some of them in other places, but here we're really focused on the, the core operating system of a company. And by, by that I don't mean windows.
I mean sort of all the business applications, business processes, specialist teams of people that today make a company tick. We're seeing consolidation in this era. Uh, customers have a ton of choice.
Yep. Everyone kind of says use our agent thing, right? Um, what we're gonna wanna see is, you know, the orchestration is gonna be super important.
And then of course, the, the speed, flexibility, access to all the tools, data, cloud, and of course Microsoft's in a very small group, right? Companies that has pretty much all of those things, right? Um, not all, not the only, but one of a very small number.
And, and I think that makes you competitive. I wanna go to the, the pragmatic side because the, uh, viewers here are probably thinking about, you know, how do I do this? How do we do this in our firm?
You know, we hear some of those stats about IROI in the enterprise and, and, uh, let's just say that I'm a, I'm a absolute believer, but I do think there's some hurdles, you know, what are those kind of key enablers you're seeing fundamental enablers, enterprises, you know, need to get right now, right? To make sure that those, those POCs and those production, uh, AI projects start to work and really show value. Yeah.
We're seeing customers, um, adopt exactly the mentality you're talking about. You know, not just how do I run the current process faster, but what if I fundamentally changed the process itself, um, to really great effect. Um, you know, we've, uh, we've shared some stories of retailers, um, that are starting to use agents and apps and automation together to totally change how they do things like fraud detection and, uh, even refunds and returns management.
Um, you know, if I go contact an online retailer and say, I want a refund, uh, you know, traditionally that's a human going and vetting, is that a real customer? Did they buy something or is this fraud? Does it meet our return policy?
Which is by the way, usually like a 50 page PDF that changes once a quarter. Um, you know, and then do I want to issue the refund or can I save them as a customer? And that's super slow, it's super inefficient and it's really expensive and often it's outsourced to vendors.
Um, you know, can I go implement an agent that does that instantaneously, or at least does major parts of it instantaneously, um, you know, really starts to change my operating and my risk profile and my customer relationships. And so, you know, even in use cases like that, starting to see, you know, millions of dollars of value unlocked really quickly and just better customer satisfaction, actually the balance of value is really shifting towards that process expertise. Um, and I think part of the challenge though is just, you know, very few people with real Jobs woke up this morning and said, God, I want to build a business application, or I want to automate a process.
That's just not a thing that happens to most regular people. Um, but a whole lot of people woke up this morning and said, man, this part of my job sucks. That could be better.
You know, I wish we didn't have to burn so much time doing X. Right? And, and really harnessing that energy, that value those skills and those people, and bringing great tools to them.
That's part of the whole thesis behind why a platform is, is critical right now. You know, what does it mean to totally change that interface into a human and agent collaboration space? What does it mean to go see the activity of what agents are doing on your behalf when they need your input?
Let's talk a little bit about Plan Designer. Yeah. Uh, you know, we're seeing, we go from manual to automated to, you know, to agentic level orchestration, which is great.
One of the key things too is gonna be trust. We gotta trust our systems. We gotta be sure that, you know, the agent, uh, workflows we're building, that they're inspected, that they're constantly modified to be sure that they're right, that they're traceable.
Like talk a little bit about kind of how Plan Designer can help companies. 'cause that's a lot of work, by the way. Yeah.
That's a lot of work. Yeah. You can automate or you know Yeah.
Streamline some of that outta the process. Yeah. com.
You can try it today. But, uh, what it really is, is of a different kind of AI centric development experience. Um, you know, you go type into that box a business problem.
We do not assume that you just want us to spit out a thousand lines of JavaScripts that you, that you need an app. Um, like a lot of vibe coding platforms today, we actually do what a real software team would do. In fact, we've built in a digital software team, we've trained a requirements agent, a process agent, a data agent, a solution architect agent.
It's a highly collaborative environment. This is not a sort of throw a paragraph over the fence and watch magic happen. It's really sort of training and teaching people with process expertise, how to think like software architects and solution architects so that they can know up ahead of time, why do I want AI to do certain things?
Where do I want it to work? How do I want it to interface with humans? And that's really the foundation of that trust in the system.
Have you seen, uh, some examples out there of Plan Designer being sort of delivering promise? 'cause it sounds super optimistic. Are people using this?
Oh, a Hundred percent. We have started to see really interesting sort of challenges thrown at it. Um, you know, we have, uh, customers in highly regulated financial services context that are taking decades of old homegrown, uh, non-compliant software that was built over, whether it's, you know, hacked in Excel or built one off and sort of saying, can I use this to rapidly modernize what I had before in a way where, you know, traditionally going and turning all that old stuff into full stack software was just incredibly costly and, and cost prohibitive.
Um, you know, starting to bring those things into plans and generate a more robust plan from modern software moving much faster. Um, we've even seen huge extremes of that. I've, I've, I've seen a customer take, you know, 50-year-old COBOL code and just paste it into plant design and say, what the heck is this program doing?
And can you help me build a better version of it? Um, and actually the results were pretty promising. So, um, you know, people are getting really creative with, you know, bring the problem, bring the challenge, bring you know, sort of the business area that you want to improve, and then start working with these agents and on this digital software team to, to design a solution.
So, you know, we're doing all this work. We are trying to train people to think differently, remove constraints, whatever's possible. But the UI is, that seems to be the next frontier.
Like the old enterprise software. It's like, these are the things you can move and these are the things you can't, and what you can customize and here's what you can't and here's your dashboard. And it's like, great.
But in the future, like I might just wanna say, Hey, you know, Microsoft, whatever. Yeah. Uh, this is what I wanna know today.
Right. And then I wanted to obviously learn based on my behavior over time, what I wanna know. Right.
And then I want it to continuously Yeah. Like things like that, like Right. How does the, how do you see being in, in this space so much, the kind of UI evolving?
Yeah. Um, you know, I think, um, specifically chat as a UI is super compelling and natural for a lot of things. Um, I do not believe that we're gonna go regress 40 years of a, of UI innovation and go all back to chat in the command line though.
Like, there's a lot of things for which text is actually a terrible modality. Um, you know, in which, uh, you know, just paragraphs are are not great. Um, and, and I think there's, there's a more underlying thing here that you're touching on, which is a lot of traditional experiences, whether it's text-based or, or visual.
Assume a human shows up knowing an intent, right? As opposed to, you know, an agent being really proactive and taking care of something for me, or pushing me an update or a notification when I need to know it. Um, and so I think those experiences start to evolve a lot.
What gets really interesting is where they meet, you know, and we really see a lot of this, uh, you know, task-based data entry, repetitive stuff, increasingly getting delegated to agents on your team. But that means you'll need to work with that team in a totally different way, right? And, and where a, you know, traditional CRM system or HR system or, uh, you know, whatever, you know, pick your business application was, you know, previously, like we talked about people typing into boxes and then other people viewing reports.
You know, what does it mean to totally change that interface into a human and agent collaboration space? What does it mean to go see the activity of what agents are doing on your behalf when they need your input? You know, when they're blocked on something or they've noticed a trend or, uh, you know, there's a form they tried to fill out but didn't complete, then that's an important meeting space to go have experiences and user experiences.
Um, and a lot of times those do need to be structured in a visual way. A lot of times they could happen, you know, ephemerally or, or with a chat message, but how do you route people to the right place at the right time? Um, you know, we're working across all of those fronts, you know, that's why we have a robust set of tools in copilot studio for, for building the agent part of, of, uh, all of those things.
It's why we have a ton of evolution in power apps, you know, sort of becoming this new agent centric experience where I can see a feed of that activity. I can have agents help me, uh, do the work in the applications. Um, and those two worlds will just continue to evolve together as we start to bring things into the future.
Yeah. So you heard me talk a little bit earlier, Ryan, about governance. Um, governance is part of the, the critical, uh, constraint.
And one of the things that differentiates software, right? The reason we can't just use open AI for everything would be because it doesn't know how to handle the data. Be like, oh, let me talk about, you know, help me do a job offer or help me do a compliant healthcare notice to somebody.
Like it doesn't how to do that, right? So building applications that do know how to do that is the key you gotta build up with. I of course, we wanna go fast, right?
So fast is the new, the new role, right? But the trust and scale are, are, uh, the other words. I know you often use these words, but like, you know, what do you think and where are companies sort of struggling with governance, uh, and scale here with automation and, you know, kind of how do you think what you're building an agent oversight can help them?
Yeah. So I'd say there's a couple dimensions to governance and scale. You know, there's the breadth dimension.
We have a whole lot more people who now can build a whole lot more things. How do I make sure that all that stays on the straight and narrow when I can't centrally top down code review every single thing that every single person and agent is doing. And then there's sort of depth scale.
You know, when I do wanna roll out a mission critical solution to a hundred thousand employees that has AI in it, how do I make sure that that AI is not just functioning, but actually continuing to get better every single day? Um, and, and you know, the, the good news is we're not inventing any of that from scratch. You know, breadth, scale and depth scale.
Were a challenge in the first generation of power platform. Um, and something that we've built a ton of capability into the platform over the last couple of years to really, uh, tackle at huge scale. And we call that, uh, the managed platform set of capabilities.
And within it, there is managed governance, managed security, managed operations for lifecycle a LM management, stuff like that. Um, and may managed availability even, how do I go ensure high availability, run disaster recovery drills for critical workloads. All of that is built into solutions baked, uh, on the power platform.
Um, and all of that value accrues to this next generation of components being built as well. You know, an agent built in copilot studio benefits from all of those managed capabilities. Um, a new app built in power apps with intelligent capabilities in IT benefits from that entire stack.
Um, and so that's why, you know, you start to see even highly regulated financial services firms, government agencies, um, et cetera, really trusting Microsoft here, as opposed to a 20 person startup that was founded yesterday. Um, you know, to, to really take the bet on standardizing for this, this segment of, of software. Um, then you get into the operational oversight, okay, I have agents doing work.
How do I have humans managing the work of those agents? That's not a developer role anymore. That's really an operational role.
You know, what does it mean to be an agent manager or an agent boss in a claims department at an insurance company or in a supply chain, uh, operation? You know, that's where we need these new interfaces, and that's what power apps is building in with concepts like the agent feed. You know, how do I build a, a purpose built oversight experience for really high volume activity of, of agents?
This is one of those things that like, right, there's so much doubt across the industry about being able to do this in a sort of, when you give up the human in the loop or even just have one maybe guiding, but you're moving so fast, it's like, um, you know, are they safe? Are they auditable? Because when you're in a business, everything you just to be traceable and trackable Yep.
Uh, is predictable the outcome. Like, hey, you're gonna have an agent interfacing with your customers, or you're gonna have an agent, uh, doing a bunch of accounting work, which by the way, it's like a spiral, one mistake, and it's just Sure. You know how that goes.
Yep. Like, how are you guys overcoming that doubt? You know, through the guardrails you're putting up, through the oversight, the accountability that you kind of baking into your platform, because I think you get over that hurdle, Ryan.
We move a lot faster. You know, I think what's interesting here is actually a lot of our customers have had to build these systems already. You know, a lot of our customers already operate critical processes across massive employee bases and even larger vendor teams that operate at arms length already today.
Right? And we've already had to go build in a, in a world of a whole lot of variability of, of who's doing a task. How do you create an audit trail?
How do you create rules? How do you create data policies? How do you create oversight?
A lot of those concepts exist today because there is variability in the human system, right? And so a lot of the way we, we approach this, okay, how do you adapt those existing concepts, policies, features, capabilities? How do you adapt that to a world where it's humans and agents doing the work?
And what are the sort of incremental, you know, sort of 10% shifts that you need to make in those systems to accommodate agents, um, but not completely, you know, pave them and re re rebuild them from scratch, right? Because a lot of these sort of trust concepts, uh, or zero trust concepts in a security concept are already built into to the system. Um, and so there's a ton of work we're doing there in the managed platform in, uh, you know, a lot of the ways that, uh, you know, a lot of the Microsoft security governance and oversight concepts apply to agents.
Um, and, and that's again, one of the benefits of building on a mature platform and a mature system in Microsoft is, uh, you know, we're not having to recreate all that stuff from scratch, like a, like a point solution startup would have to do. Yeah. So the, the last thing just on specifically on security.
Yeah. Um, security is a super hot topic. Yep.
What do you, the customers, how do you want them to think about the approach? Because in the end, like you can get it all governed and right, but you have to keep your doors closed, locked. And, you know, that's an increasingly large problem.
AI is, is much, uh, enabling it, uh, as it is fixing it, right? Well, look, I mean, we could probably spend an entire hour on, uh, uh, security and threat model approaches in the, in the AI era. It is absolutely critical.
And like any security challenge, there is no silver bullet. You know, every customer needs to have a defense in depth strategy and needs to think about what am I doing from a data security perspective? What am I doing from an exfiltration perspective?
What am I doing from an access perspective? Uh, you know, the good news is we have a lot of that built into the platform today. You know, even a customer building their first copilot studio agent and using the managed power platform to roll it out.
We'll see a security score in the power platform admin center. We'll see AI driven recommendations about what to do to improve that security score. Um, you know, it has a whole bunch of capabilities in there that, that go all the way to operate this in the cloud.
But with a private vnet, with your own managed encryption keys, um, you know, again, we have a lot of highly regulated, very security conscious customers that are working with the platform today. Um, I would say though, to Zoom way out and look at that, um, and maybe connect it to some of the rest of the conversation we've had, it is absolutely risky to go too fast. It is also very risky to go too slow, you know, and the rest of the world is evolving, including threat actors and competitors, right?
And so the cost of standing still is probably the most costly positioned to be in. So let me, let me, you know, as an analyst, uh, I have to ask you 'cause uh, I've got a few things. Uh, but, uh, what kind of in this whole evolution, this, this exciting moment for the future of apps and automation, uh, and agents, like, what's kind of keeping you up at night, the biggest concerns that you see out there?
And then what are the kind of upsides for you? Like, what do you most kind of think could be the biggest surprise in, into the future? Give us that big Yeah.
Visionary moment here, Ryan, to take us home. Look, I think, um, I'll start, I'll do that in reverse order. I think there's a ton to be excited about right now.
Um, and you know, I, I think, um, there's just so much potential in creativity that we can still unlock. net code in their life. Um, you know, what unites that community is this sense of we can make something better.
We can, this can be better, let's do it better. And, you know, I feel like we're at the precipice of just blowing a huge lid off of the ceiling of what you can do there. Um, and there's a whole lot to be excited about.
Um, I mean, you joke about a night job. I stayed up last night vibing a power app that's just a Tetris game because it was awesome and fun and so much faster to create it than it would've been in the last generation of the technology. And I think that's a tiny, tiny microcosm of, you know, go take that creative energy and apply it to everything that's inefficient about every aspect of every customer organization today.
You know, we're really standing on the precipice of completely rewiring how companies work, um, and doing it with people who, who have deep expertise in that process and a deep desire to make it better. And that's just incredibly exciting to me in this, in this moment. Um, and then to flip it around, okay, so what stands in the way of that?
You know, it really is all about speed and pace of iteration. And, and really it's about time to wrong. You know, there's, there's so much that we need to go invent and covent with customers and experiment with, um, and try, and nobody out there is perfect right now.
What, you know, what will define winners and losers for technology companies, for customers, for operations is how fast can you be wrong? And then how fast can you get less wrong and more, right? Um, so that's, that's the journey we're on.
That's the hill we're climbing. Um, but it's just a super exciting time to go think about what the, the top of the mountain can be. Brian, this was a lot of fun.
It was a great conversation. Appreciate you sharing a little bit about where all of this is heading. There's so much potential for companies to really start reimagining.
Yeah. You realize just how big of a leap forward we, we are having right now with, with ai, with Ag Agentic and the work that you're doing in Power Platform. So Ryan, thank you so much.
A Hundred percent. Really, really enjoyed the conversation. Daniel, thank you for the time.
Everything about the way we work is changing very quickly. Thanks to the advancements in applications and of course, agents automation and what interfaces may look like in the future are all gonna continue to change and they're gonna enable, and they're gonna power businesses to be more efficient and of course to be more productive. It was a great conversation over the last hour.
We really did reflect across not just power platform and how they are thinking, how Microsoft is thinking about building its future, but really about how businesses should be thinking about developing their future, removing constraints, being able to look at problems in new ways, and then being able to apply software and then being able to utilize resources in new ways that can deliver more value to your business and of course to the customers that you serve. And this is not gonna be easy. It's gonna take some time.
There's gonna be some effort, but it is something that can be done today and companies can start to extract value right now. And moving quickly is gonna be more and more important. That's something I'm seeing as an analyst, and that was clearly something that Ryan had seen as well.
We talk a lot about that is the customers that are moving fast are gonna be the customers that get the biggest results and of course, are able to benefit the most from those efforts. And lastly, we still have to keep all of those considerations that have existed with enterprise applications, with software that runs our businesses. And that's gonna be the governance, that's gonna be the controls, that's gonna be security.
And that, of course, is going to be putting people in the right roles and enabling them to do the work. All those things remain similar, but of course, with a new bend, we're gonna upskill the talent. We're going to think about problems in new ways, we're going to move more efficiently, and together we're going to drive the future.
Great conversation. Appreciate everybody spending the hour with me. See you all soon.
Hey everyone, welcome to another episode of Still Cyber. After all these years, I'm Alan Chimo, and there is no Mitchell Ashley today. Unfortunately, Mitchell is stuck in the snow.
Cop snowpocalypse up. He's up in Colorado. He has no power in his house.
And we made the, we made the, uh, the decision go. No, go. We're going.
So Mitchell will be on the next one, but I'm really happy to have someone else on here. Otherwise you'd have to listen to me talk for 25 minutes by myself. We've got Brian Pac.
Pac. That's right. You got it.
I've interviewed Brian before, but I'm just terrible with names. Brian is the SVP of product at our friends over at DigiCert. And, uh, we're gonna talk a little bit about some things that really revolve around digital certificates, post quantum encryption, and we're gonna talk about Quantum.
And as well tan, I want to introduce you all to something we call Quantum Security 25, which is something we're doing with DigiCert, but we're gonna talk security and Quantum and everything else. Brian, welcome to Still Cyber. It's great to have you on.
Thank you. Um, you know, let me just, I think everyone, well, not everyone, people are not gonna know DigiCert, just real quick, let's get that out of the way. Who's DigiCert?
Why should they know you? Yeah, so DigiCert's been around for quite some time. We, uh, started out really as a ca a publicly trusted certificate authority, you know, providing trust between browsers and servers and connections and medical devices and everything that's on the internet, right?
Um, we have extended all of that to really provide an ecosystem around that digital trust where we could manage, you know, all the workflows, all the connections around documents, around, um, you know, networks around, uh, IOT devices against software, uh, and now even into ai, right? So there's some really interesting things that the foundations of what we do with PKI and DNS, um, you know, spreads out to even the, the things we're doing right now with AI that seem quite new. So it's, uh, very interesting.
Absolutely. You know, we we're gonna come back to the AI piece first. I, I wanted to, I wanted to touch on a lot of my friends out here.
You know, digital certificates have been around, as you said, Brian, a long time. Um, primarily Google has been a big instigator, a mover in this about shortening the lifespans of digital certificates, right? It, and there's a lot of reasons for it.
It's not just to raise more money on certificate fees, right? It's about security. The, you know, the longer that certificate's out there, the more of a chance there is.
That's something could go wrong. Yeah, right? That something could be compromised.
So the latest, I, I think it's the latest sort of expiration date that's coming on fresh certificates is 47 day, first of all, why we pick 47 days anyway, Brian, That, that, I wish I, I wish I knew a succinct answer to that one. The powers that be in these consortiums came up with, uh, with that date. But yeah, 47 days probably has some mathematical magic to it that I don't Understand.
The thing is, I'm thinking, I think, so I said 45, you said 50. I said, let's meet in the middle. We can't do 47 and a half.
Let's go 47. No, I want 48. All right, I'm gonna let you have this one in 47.
It feels like something like that. Yeah. Yeah.
I mean, it's just random, random stuff. And maybe that is part of it, that it's random. Of course, we're not, or some players like Google don't wanna stop at 47.
They wanna, they wanna get down to 30, they wanna get down to weekly. I mean, you know, what, what holds us back? Why, why?
Well, let's talk about, first of all, Brian, why do we want to make certificates, lifetimes, you know, more fungible, more ephemeral, if you will. Yeah, I mean, I think it, it comes down to a couple kind of market driving initiatives, if you wanna think of it that way. You mentioned Quantum as we, we talked earlier, right?
So anybody not aware, right? The threat of quantum computing shores algorithm, the ability to reverse RSA algorithms and, uh, you know, be able to effectively kind of crack. Modern crypto is looming out there.
And I think NIST has said by, uh, 2029 that, you know, they wanna deprecate RSA as a, as a major algorithm. That's, that's a big thing, right? That's not even really what's driving 47 day.
I mean, when you look at networks and, um, you know, some of the other things, right before you even get to the 47 day, they've introduced, um, this kind of multipoint inspection that we've been deploying that looks at, uh, you know, from different DNS endpoints across the internet to ensure the routes to domains are validated. So there's no BGP attacks in between. We're concerned with things like that, right?
So we're layering all these things together to provide security around the certificate, the network, the identity of the operator of that website, 47 days, kind of the next thing, right? That looks at it and says, we don't want these long lived keys. We don't want the kind of harvest now decrypt later attacks that exist with Quantum to, to be sitting out there.
Um, we, we want to also advance automation, right? So if you have certificates that are currently 398, these is what's allowed. Um, you're not really incentive incentivized to make that thing automatic unless you're maybe in like a cloud workload environment or something that is already automated itself.
So you have this huge disparity between some customers who do a ton of automation, and then others who are like, well, you know, I get an email, I'm gonna renew a cert, and it's 398 days. Um, so I think that push towards greater automation on networks just makes the entire ecosystem more resilient. Because you gotta remember in the event that something happens where there's maybe, uh, a compromise in the chain or validation, you know, uh, compromise or even network like BGP, we talked about compromise or something like that.
If you can automate the replacement of those certificates in, you know, very quickly, the risk of that event has been reduced significantly. And so I think we really drive towards that automation and replacement and, you know, kind of good crypto hygiene around the networks. Absolutely.
Absolutely. You know, to me, the, the, it's two things. Number one is if, if my certificates are so long lived that I gotta worry about it once a year, once every year and a half, I don't have a strong incentive to, to, uh, automate it.
But, but here's the other thing that I think drives certificate automation. It's the amount of certificates. You know, there was a day when I had a company, I had one website, one domain, maybe two domains.
Yep. You know, but today, you know, the average enterprise is managing, dare I say, hundreds if not thousands of certificates, right? Yeah.
And it's, it's, and it's not just the digital, the SSL certificate on your website. It's the identifiable, you know, the certificate of authority, the identity certificate, and it's not even people, I mean, I guess every person Yeah, right? Is is authenticated that way, but it's the machine certificates every That's right.
Container has a certificate. Every device has a unique certificate, every instance of a cloud, every server. And now you with AI is a, it's every AI agent, every, every, uh, API.
Yep. They all have, you know, you may know this better than me, Brian, the average enterprise, how many certificates are they managing? Oh, it's, I mean, so step back one second.
So as you go into that number, what's fascinating is people, when they generally think about certificates, they're thinking about those kind of publicly trusted certificates, right? I think you were trying to outline there. So the things that they kind of pay for and that they issue, right?
So protect the outside of that network. That number has grown astronomically as services have scaled. But like you were alluding to, when you look inside that network, you look into Kubernetes or containers or cloud systems or things like this, that's where now you get to your question, enterprises typically have about, uh, 50,000 certificates that they're measuring or are managing on that internal network.
And that's kind of, you know, we've heard other enterprises that have many, many more than that, right? So, to your point about, um, scalability, um, you know, it's, this number has just grown, gone, grown so huge and, and out of control that when you take those external certificates and you take those internal certificates and you're interconnecting APIs and workloads and all these sorts of things, they're, you know, I, I always like to say it, and I maybe shouldn't 'cause I'm, you know, kind of in the ca world, but it's, it's like they're little ticking time bombs, right? They, they literally have a clock on them and they will stop working at some point.
And if you don't have a way to know where they are, and you don't have a way to get to them and replace them, and you have an environment that has, you know, maybe 50,000 in these containers that are kind of ephemeral, it's an even harder problem to keep track of these things. And they're just ticking away, right? And, and we hear time and time again, unfortunately from customers where something will expire somewhere down deep in some deployed infrastructure.
And the chain of events of what it brought down were then felt by a customer externally. Um, and that's really, you know, kind of a, a mission of ours at Dig Cert is just providing the tooling, providing and technologies to, to add rich automation around this so that we can prevent those outages for people. Absolutely.
So, you know, first was the, the length of the, the life of these certificates, right? As they grow shorter, automation becomes more imperative. But that pales in comparison to having to manage 50,000 of these suckers, right?
Yeah. Yeah. Now, automation is no longer a nice to have automation's a must have.
Now, of course, the whole, our whole certificate world, our whole encryption world, which so much of the internet rides on, so much of our privacy is based on, is is based on sort of the RSA algorithms. Yeah. You know, 1 28, 200, even 256 bit encryptions.
And, and for those of you who don't know what that means, you can go look it up or ask your ai, they could explain it to you. But the real monster lurking on the horizon, or has been lurking, has been, you know, post quantum encryption. 'cause when quantum is real, what would take thousands of years of our best computers right now to, to crack will take maybe minutes.
Uh, of course, you know, for the last 15 years, I've always heard Quantum's five years out, Quantum's, five years Out, it's always right there. And It's always five years out. I go five years later and it's still five years out.
But now, but now stuff's getting real. Right? Q day, you know, IBM swears it's gonna be 2028 maybe, but sometime in that timeframe, 20 28, 20 29, we're in 2026, right?
Q day, Q day's coming, Q is coming. And, and the thing about Q Day is everything I've read is, you know, it's not gonna be like happy New Year where we watch the ball drop in Times Square or something. It's gonna be kind of sneaky, right?
Well, all of a sudden you're gonna look around and say, holy mackerel, quantum computing is real. People are really using it. Now we already have sort of models and there are a few folks who are, you know, have models of quantum computers that are working to a certain extent, quantum networking, you know, a lot of quantum technology.
Yeah. But, um, but when qj comes, all these certificates could be rendered obsolete. That's right.
And I, I think if you, you maybe take a macro view of the whole situation. The certificate is a very small part of the quantum equation, right? Yeah.
So like you said, when, when the algorithms become compromised and you could basically, you know, run a certificate through a quantum computer and get the private key and get all the traffic, right? That's kind of the promise of quantum. Um, that's the risk, right?
But the mitigation for it, Alan, is, is complex, right? When I talk to customers about this, they come to us and say, Hey, dig aer, you guys understand certificates. How do I replace those certificates?
Do I just need to automate everything on my network? Well, that's a good start, and that'll help with the certificate. But that certificate is probably on a server.
That server has a crypto stack, there's software on that server that's providing cryptography that needs to be updated. It's probably working through some sort of network, maybe load balancers, maybe, you know, different network infrastructure. It also needs to support those algorithms and quantum IT technology, uh, flowing through there.
Uh, post quantum algorithms flow flowing through there. Um, and then you start to, you go through that like are using, uh, accelerators, right? There's RSA acceleration hardware that people use.
Well, that isn't gonna work anymore when you're not using RSA. So now your whole network slows down. So now you need to buy more stuff to scale, right?
Like, this problem really starts to unpack. And, and I don't think people kind of get that. There's a lot of depth there.
You're replacing software, you're looking at networks, you're looking at your certificates, you're looking at automation, you're looking at, um, you know, the various components. And, and God forbid if the organization is running their own hardware security modules for encryption, those all need to be updated to support these algorithms, right? And then any downstream technology supported on that.
Um, you know, I was talking with a bank, uh, a couple weeks ago, and they're using, um, you know, uh, smart card like UB tokens and things like this to authenticate those all need to support these algorithms. Yeah. You look at your Mac, you, the Mac that maybe you're using right now, your desktop, it has the little touch ID thing.
Well, you know, Macs that are, I think six months and older, none of them support post quantum algorithms with your touch id. Right? You can't even store it in a key chain.
So there's all sorts of hardware, there's all sorts of network, there's all sorts of ecosystem that needs to go the certificate. Yes, of course, we gotta replace those and provide automation around those and do that. But there's this infrastructure that needs to be supported that we're, you know, that's the one single biggest thing when we talk to customers is if they come to us and they think it's a cert problem, we're like, there's a lot more you guys are gonna have to do.
And now when you're putting your CISO hat on, are you budgeting this? Are you planning for this? Do you have time to even go endeavor to figure this stuff out?
And and I think that's where, you know, maybe two and a half, three years ago, Alan, people kind of were like, well, it's always kind of coming. It's, you know, we're not gonna have to do anything. But with this NIST announcement that said, Hey, you know, we're looking at 2029 to, uh, kind of correlate with the 47 day, uh, certificate lifetime for RSA to be, uh, effectively deprecated, that really got people to say, whoa, hold on.
Now we need to figure this out. Let's get a plan together and let's figure out how we can address this quantum thing across the entirety of our network and infrastructure. So Brian, I, I, look, I, I agree with you a a hundred percent over on this, but I'm an optimistic kind of guy, right?
And so what I always, what I believe is that when it comes to this quantum cryptography, post quantum world, it's one of the few times where I've seen both the government and industry partnering together to get out ahead on this, right? Yeah. And the fact that NIST did come out and, and the industry did come out and say, Hey, we're gonna deprecate RSA in 2029, they did approve, you know, post quantum algorithms that are, you know, theoretically quantum proof for whatever you want to call it.
Um, yeah, we were, we didn't handle Y 2K that well, even though that turned out to be a bit of a nothing burger, but still remember what it was like back then. Yeah. People were kind of freaking, um, I think, you know, there's reason to freak here that it's not just about post quantum algorithms.
Yeah. Quite frankly. Yeah.
Yeah. As you say, there's a lot that goes into making sure all our equipment can handle these new algorithms, right? But we, we shouldn't be freaking out about it.
We should just be diligent about it, I think. Yeah. Yeah.
And, and I think, you know, to that point, like it's, it's, it's fascinating too, 'cause that the, the way I just talked about it was kind of focused on the network, right? But when you look at cryptography and you look at a quantum computer being able to attack just generalized cryptography, cryptography is used everywhere, right? So we kind of dissected the network problem there just a moment ago.
But what about all your databases that have row level encryption? What about all your backups that are encrypted and stored somewhere? What, like all of these things, as you look at trying to become quantum ready as an organization, well, you'll need to re-encrypt those things.
You'll need some new keys. You'll need to store them differently. Like there's a whole downstream piece there.
'cause when you look at, you know, the attacks right now that you can't prevent are harvest now decrypt later attacks. People are literally capturing network or traffic or backups or whatever hackers can get their hands on that are encrypted that they can't read right now, but is valuable enough to store, put it on a hard drive. And once a quantum computer is there, now I can get the contents of that.
And you can use your imagination for the kinds of things you could use if you, you knew in three years you can gain access to it. There's probably some things you'd want access. So I think that's why you have an organization and a collaboration between governments and institutions and, uh, you know, uh, commercial vendors to try and solve this.
Because the risk is, is so, so high across all of that plane of data that we use for commerce globally. I mean, imagine if the internet was all HTTP right now, you would never send a message to anybody, certainly not a credit card. Like, so there's no way any of these things and systems would function.
And if you look at the global economy and how much is pinned on that, it's a pretty big deal that we make sure that keeps working, let alone anything else that goes into secrecy and privacy and all these. And I think, you know, you gotta measure that against you. You know, you're not putting quantum back in the box like it, it's gonna happen.
And why is it gonna happen? We focus on the negatives here. But the positives are, there's huge supply chain problems.
There's huge, um, pharma problems, genome problems. There's all these kinds of computationally, um, intense tasks that would take hundreds of thousands of years to do with computers today that they're building these computers and these algorithms to do in moments, right? Yeah.
And so that's why this will happen, is we're trying to solve incredible problems With These computers changes. Yeah. And, and you know, not to mention that they say AI won't really hit its potential until it we're running quantum.
Yeah. Right? And vice versa, AI will enable, you know, once you have functioning quantum technology, AI will enable breakthroughs.
Breakthroughs using that quantum technology and quantum technology will enable breakthroughs on ai. So it's kind of a very symbiotic, almost relationship. Yeah, definitely Crazy stuff.
But, um, you know, I, I wanted to mention Brian, right? DigiCert has been, I mentioned this and, and staying outta ahead, DigiCert's been one of these partners in that effort and has been a company that has really tried to take the lead as we move to a quantum future. I don't know if I agree with the word post quantum Brian, right?
It's quantum, it's not post quantum. It's not like Q Day happens and, and then Quantum goes away. It's from that day on, it's quantum.
So it's not really Post, I think we're Not after Quantum. Yeah. We're just trying to mark that there's a day when those computers and algorithms become real.
Right? Right. They, they attack all the things you just talked about.
Yeah. Right. Yeah.
But, you know, but DigiCert, as I mentioned, DigiCert has been taking the lead in this, and one of the initiatives they're working on that we're, we're actually working on, right? With, and in partnership with DigiCert is something we're all calling the Quantum security 25. We would get, we're trying to stay out ahead of this thing.
We're trying to publicize, hey, who are the top 25 or so leaders in this quantum space? Yes. And, you know, and it's still early, there's still time for people to make the top 25.
But I, I will tell you here at, at Techstrong, we have been, you know, we've been talking about reporting on Quantum for a while. Um, you know, text Strum iss part of Futurum Group now, and I, I had the chance through FU to meet, um, well, was a former chairman of futurum, but he had a step down when he became the CEO of a company called Ion QA guy named Nicolo, Nicolo, Dessi Nicolo, you know, ion Q's a big company out there in Quantum. Yeah.
So, and then I live, we live in Palm Beach County here in Florida. That's where our offices are. And you know, Palm Beach County itself has this big push on to be called, uh, quantum Beach.
Okay. I know it sounds corny. It sounds corny.
It wasn't my idea. But nevertheless, that we, we've had some conferences down here around quantum technology, and they're, or they're putting together all kinds of incentives to get quantum companies to move down here. Hey, at least we wouldn't have six degrees where you are in Austin.
So I I would love to be at the Quantum Beach right now. Yes. Yeah, exactly.
Exactly. Austin, Texas is like six degrees right now, So Yeah. And Austin's not known for its tough weather.
It's usually too hot. But anyway, quantum Beach, go figure. Um, but so, you know, it, there, there is this growing momentum across the industry, and it's not just security, it's not just the post quantum algorithm crowd, it's, it's quantum in general, all of what Quantum's gonna mean.
I, I had a chance another, actually, she lives in Miami. She's the CEO of Q Secure. I don't know if you ever heard of this company Q Secure, she's got a PhD in AI and now she's working on, on Quantum as well.
There there are people is so many very, very, IBM's and other companies been working on this, right? Yeah. These are all companies that we need to get involved in this Quantum Security 25.
Yeah. Um, people that we need to get in here. But Brian, if you can, and I don't know how much you're keyed into all this, I may even be more keyed into it than you, but once we picked the Quantum Security 25, what, what, what's the idea?
What's the reasoning? Where do we go from there? Yeah.
I mean, I'm, to be honest with you, I'm not keyed into the whole Quantum 25 largely a digital, all Right, let me run with the demo from the side then. That's why I love doing these podcasts. Yeah.
So the idea here is let's identify 25 or the top 25 leading personalities. People. I don't think you can have an ai, it has to be a real human, um, you know, who are, who are thought leaders who are pushing the, the, the rope here on, on, on quantum technology and quantum security, right?
Yeah. Because I think a thing we need to be clear on is you really can't let quantum computing out in the wild without quantum security. Right.
Without all hell breaking loose anyway. So, um, you know, but who are the leaders in this? And then I think for the rest of us, it gives us some people to follow if nothing else.
Yeah, yeah. People to follow on LinkedIn or X or wherever you follow your, your folks. Yeah, yeah.
As we watch the countdown acute day into a post quantum world, you know, come about. Yeah. Um, so if you're watching this, listening to this, whatever, and you know, someone who you think is a quantum security 25, the Quantum 25, uh, personality, you can nominate them.
Uh, I don't, I don't have the URL infirm me, but it'll be in the notes on, on our podcast, and you can get it off on Techstrong as well, uh, on Techstrong ai, techstrong it, any of the Techstrong sites. I'll have it as well. Um, but Brian, it's, it's because it's getting real now.
Yeah. We're running low on time, but let me bring it back full circle. Yeah.
Go. The 47 day certificate is, we want us to get into the habit of refreshing our certificates because as two day gets closer, and as this becomes real, we want everyone to be able to have muscle memory, if you will. But the 47 day, uh, standard goes into effect, I think just in another month and a half or so.
March 14th. March, Yeah. The heights of March.
Um, what could people do? You know, I hope no one's sitting here saying, oh my God, I never heard of that. Right.
I, I better get busy. But there probably is. There probably are.
Uh, yeah. What, what should people do there? Well, I think there's, you know, some pragmatic things, right?
So a lot of the customers we have, you know, it's January, what, 26th right now? Yeah. They're, um, very much gi like, especially if you have a large fleet of certificates.
I mean, even if you just got a, a few and you're short staffed, people are preis issuing now, right? So they're saying, Hey, I can still get 398 days for, you know, another month or so, let me just, you know, if I'm close to expiration or if I've got things, let me just get those now. Lemme buy some Time, load it up and buy some time on that network.
Um, so I can sort out the harder problems, like how do I automate this stuff? How do I make sure my DNS works properly with the automation? How do I make sure, like all the kinda laddering of, of executing on it?
So I think that's probably the most simple advice I give people right now is, you know, kind of preload, get yourself moving, so you give yourself some time, and then this is your last warning because the timelines are only gonna get shorter. You know, this year, 2026 we got down to 200 days. 20, 27 we got down to a hundred days.
20, 29 we go down, or I'm sorry, 20, 27, we go down a hundred days. 20, 29, we go down to 47 days. So it's only getting last time you will have to automate.
Um, so this is really the last shot. Yeah. I mean, look, quite frankly, by 2029, we may have had Q Day already, right?
And yes, man, if you didn't change it, Go home, you're not automated by then. Oh, okay. You got trouble.
Yeah, yeah. You got Trouble. That's gonna be trouble.
Yeah, absolutely. Hey, Brian, where can people find out more about all that stuff on DigiCert? com.
We've got, you know, all the, the blogs, the events, we've got our World Quantum Readiness Day, which we didn't talk about, uh Oh yes. Kinda stitches into your 25. So we've been leading on that for the last, uh, couple years now.
And, and you know, we do awards in there for industry leading companies that sound very com similar to the Quantum 25 here. Um, you know, just trying to push that forward and get that thinking right. com.
Love it. Brian, I appreciate you coming on. Poor Mitchell.
Stuck somewhere in Colorado in the snow with no power. Yeah. But you and I, well you had six degrees in Austin, but you made lemonade outta lemons.
You went to bargaining and sledding. We did, Yes. One day your kids will grow up and say, you remember when we, we went sledding here in Austin?
And they'll be like, no way. Yeah. Yeah.
They'll be like, who's the crazy guy that had a toboggan in Austin, Texas? You know what? That's why you keep it there for 50 years for that once every 50 year thing, man.
Um, but thanks for coming on still Cyber, appreciate it. Say hello to all my friends. Thanks having Alan, sir.
Alrighty. I will. Hey, you've just listened to Still Cyber, it's Alan Shimo.
No, Mitchell Ashley today, but he'll be back next time. Until then, everyone take care. Hey everyone, happy Thursday and welcome to the Gang Live on this Thursday.
I know a lot of us are cold. It's even a little cold down here in Florida, though I'm not, I'm not, uh, going to complain because cold here is not cold maybe where you are. Um, we've got a great gang for today.
We've got some really cool stuff to talk about. But before we started, I wanted to acknowledge someone who's not part of Techstrong at all, but saw a post from him yesterday, my friend Alex Williams, right? Mm-hmm.
Many of you out here probably know Alex. I know Mike Ard knows him a long time. John, I, you probably know Alex.
Mm-hmm. I don't know who else does. Alex is a long time tech journalist, and he was, he's the founder of the New Stack, oh, a com, a competitor to Tech Stunk, quite frankly.
But Alex and I, he started New Stack and I started Tech Drunk like within two months of each other. And we've watched each other come up and we've competed over the years, but always respectfully and with friendship. He's a real professional journalist, much like John Schwartz or Mike Ard are, I don't consider myself a professional journalist.
Anyway, Alex left a new stack yesterday. I don't know if he's retiring or he is gonna do something new, but he put in 12 good years over there and did great work at it. And I, I just wanted to call him out and say, good luck no matter where your next stop is.
He lives in Portland. He might be retiring, I know his wife retired, but it, it's not gonna be the same without Alex Williams on the, uh, on the horizon. So with that being said, let's, let's move into our, uh, channel gang for today.
Really happy to have on our friend Ann Aho award. Fred Wilmont, Gina Rosenthal. Fred, you keep sneaking earlier in the week.
He used to be the, well, actually it was 'cause we used to record it Thursday for Friday, but you're still the Thursday guy. We have Gina Rosenthal, or if you are looking on Twitter, I found out it's G Rosenthal, but, uh, I don't know, that's not Twitter. Excuse me.
There is no Twitter. It's XI met LinkedIn, but um, also another imposter that was yesterday's show. We have our man in the Valley, John Swartz, and of course Mike Vard.
Um, gang, it's, it's an interesting Thursday. There's so much news going on now. I was trying to pick what to do for Shimmy says today, and I, I was, it was what we call a target rich battlefield.
I mean, there's so much happening. Mike, what do we got for today? Well, let's start with this whole thing and what's going on with AI in the workplace, because there's all kinds of surveys and a lot of interest in this topic these days.
There's a new Gallup report talking about how there seems to be a split between the AI proficient and those who are not. And it also suggests that people are maybe starting to use AI a little bit less in certain sectors of the jobs and vertical industries, depending on how you look. 5 hours a week cleaning up what they call AI work slop, because, well, the AI is wrong, or the data's wrong, and people are, have to go back in and review that.
And they're doing a lot more proofread, which, you know, if you've ever done proofreading for a living, is not a whole lot of fun. It takes a certain amount of mindset to go do that. And a lot of folks don't have that.
And so they start to grumble. Um, and I'm gonna start with you on this whole topic, but, um, do we have some sort of, you know, cultural technical disconnect at work here? Well, I think that the, the poll data is just showing us, the Gallup poll data is showing us that it, it's not spraying much further than we'd anticipated.
Frequent users are using AI tools more that the people who aren't using it aren't really rushing to use it. Um, the adoption has basically stalled with about 46% doing at least occasional use. But what I thought was interesting is that leaders and managers are the ones that are tending to use AI more because they feel safer experimenting, staffers and non-managers worry about looking replaceable.
So this is actually a cultural problem, not a technical problem. It's not a tooling problem, right? So, while the article flame frames things as plateauing, I think the data shows something sharper, which is that people who get it, really get it, and they're doubling down.
Everyone else is gonna be left behind. Um, as a futurist, I put out predictions every year, uh, and one of them was, you know, the rich versus poor divide is going to be sort of a lesser thing that we're concerned about as a society, because you are either going to be someone who shapes these systems or someone who is shaped by them, um, which this to me, starts to help prove. So it's not a hesitation, it's an organizational paralysis.
So I have to think, what was our expectation here, uh, that AI in a year or two years max was going to become omnipresent as email? Was that really a realistic expectation? Um, or, you know, maybe the divide here is permission versus fear.
Maybe the workforce at large is still fearful, and are they wrong? I mean, there, there's as many questions as answers for me out of this. Oh, go ahead, Al.
Well, I, if other people wanna jump in, I I'd more than happy to, to seed my time. You go ahead, Alan, then I'm gonna say, I'm gonna bring something up that happened yesterday. Well, You know, Fred, you know this, but Ann, I don't know if you'd be familiar with this concept in, in security.
Our friend Wendy Nather coined the phrase 10 or more years ago about security below and above the poverty line, right? That the fact of the matter is, you know, most organizations just don't have the resources and they live below the security poverty line. It's not necessarily a dollar poverty line, but it's a capability poverty line, if you will.
Mm-hmm. Resource, poverty line, poverty line. I think we're seeing a similar thing in ai.
You're going to see people in organizations that live below the AI poverty line, and like all people who live in poverty, their lives are a little less rich. And again, I don't mean necessarily money. Their lives were a little less rich, a little less full, a little less capable, maybe even a little less happy.
Or maybe they'll be happier, I don't know. But we're definitely gonna have a, have and have nots of people who use AI well, and people who for whatever reason, don't, well, the thing go, go ahead and jump. That's What I was saying with my prediction this year.
I did, I did a bunch of segments on tech predictions, was it's going to be you are shaping the system, or you are shaped by the system. You are an active participant. You are, uh, someone who is shaping and using these tools, using them to improve your life, using them to enhance processes, or you're someone who's being shaped by them.
It's, that's a divide that I'm already seeing because I, I have people on my staff who are anti ai, they don't wanna use it. Me Too. And, But we have clients that use it, right?
And, and so, you know, I think that it just, my, my thing is always transparency. I always disclose if I use it. Um, but I do spend a weird amount of time correcting AI written language that someone hands me and tries to, and I've had to fire writers for passing off AI or trying to as real human writing.
So I don't have to, I now have to run score test tools on, on writing. So is that an improvement? I don't know.
But we're getting there, right? Let's jump into, let's jump into what the folks who are using this, who are grumbling or trying to say. And I think when you go talk to them, you'll get the following vibe.
It's like when you're working on something, whether it's art article or whatever, you're in a, you're in a mindset, you're in a groove. You're kind of like, you know, there's a, there's a thought process you're trying to do. And every time AI injects something that looks like an error into that, they get frustrated.
They basically say, you know, uh, I've lost the flow. Or this is kind of, you know, I, I, I, you know, if I just did that myself, I would be, then the whole flow would work better in their minds. And so I think there's some folks out there at least who aren't afraid of ai, they're using it, but they're not happy with the way it kind of inserts itself into their workflow and their processes, and that's what they're struggling with.
But Gina, You're absolutely correct. Right? So that's, I'm, I'm here in Santa Clara this week, um, with AI infrastructure field day.
So we're talking to companies that are building the tools or the infrastructure around the tools on, um, that people are, are, are using. And, and let's be specific, we're talking about generative AI here. If we're talking about the word tools, we're talking about generative ai.
And so that's a very specific thing. And I'm a writer and I use it, but I go back and forth with it as I'm writing sometimes just to, to have somebody else to throw it against the wall before I pass it off to a client or work with a client more on it. And one of the things that's really hard is, and we talked about this with one of the companies yesterday, is one of the things they're trying to work with, um, with their clients on, is that context totally collapses.
After a few turns, after a few asking about this and asking the generative this, it co it, it collapses. And if you don't catch it before it collapses, it's useless. That whole, you have to start over and start with a new conversation with a generative AI to work on documents.
So you, you're telling the absolute truth. The tools are not ready. A lot of times the data is not ready.
So if you're working with tools and you, they don't find the thing you needed in your organization's documents, which you were promised it would, then you have to go bind it yourself anyway. Why am I gonna waste time with a tool that is eventually going to spit out garbage? Because that is how it works.
It loses context after a few turns, then just why would I use it? And, um, I, I just fundamentally don't, don't agree that people don't wanna use ai. They do.
I mean, my mother uses AI to do stuff every, my, my, all my, both of my kids in their thirties do. So, like the ai, everybody wants to use it. The problem is we cannot trust it.
Generative AI only will give you correct answers for a certain amount of turns before it can't. It can't because it's a mathematical, um, equation behind the scenes. Very, very complex.
One, figuring out how to put the words in the right order. So we can't, and number one, I don't think we should talk about AI is ai. We're talking about generative AI specifically, and the work tools.
Yeah. And number two, we have to think about how they fit into the workflow. They don't fit, and they, they, they cause a delay in workflow, then no one's gonna use them.
They're gonna wait until they get better. So it's just a wait and see thing versus I'm not gonna use these things. It reminds me so much of the early days of blockchain about 10 years ago, where it was a solution for problem.
In some instances, I have seen this where we're stuffing it down people's throats and it maybe isn't solving an actual real business problem, which by the way, blockchain didn't in 95, 90 9% of cases, but everybody was hell, Ben, on using it. Um, and now we've got maybe one social network on the Fedi verse. But, you know, hey, I, I would like the idea, I Want to put John in here 'cause I know he has his story Now.
Well, here, so anecdotally, I was talking to Taylor in, in the green room before we started, and one of the things I do, and Mike mentioned it, and it it happens to me, is like, when I write, I sometimes try to stimulate myself with art. So I listen to music, or I'll sometimes just have like pictures that I'll, that I'll look at sometimes while I'm writing. So you get into a sort of rhythm and flow.
So as an experiment, I tried using Claude to edit one of my stories, and I purposely did a, uh, what I thought was an original lead in my experience. And Gina, this kind of pars to what you're saying, it not only eliminated it, it, it took out the, the paragraph and substituted with this, this very generic formulaic thing, which to me was very frustrating. So I, I think from the ground level, people maybe are reluctant to use it, and maybe they, in a sense, they think it's, it's kind of hurting their work.
But I'm gonna go back to one other thing that, that Anne said about culture. And I think management loves this. They love the whole idea of AI efficiency.
And without kind of going down a dark road, I'm just gonna say that the companies that are at the forefront of using AI in terms of an efficient tool are putting it to use. And boy, are they putting it to use. Amazon just is up to 30,000 layoffs now as part of this product That that wasn't because of ai, that's to pay for it.
No, well, No, pro project Dawn is an initiative that is aimed at streamlining operations and integrating generative AI into their corporate framework. So they're getting rid of middle management. So corporate jobs are being limited to about 10%.
So I, I, we, we can argue about that, but, but I, I just think that it is inevitable we don't have a choice that we're at their resistance stage among employees. Um, they're always, people are always afraid to adopt new technology. They're going to don't want to like it.
Don't blame the tool, blame the tool user. Well, in Amazon's case, I'm blaming them as a tool user. Yes.
So, because lemme tell you something, my experience is very different than Gina or John, right? I, and Mike knows this. 'cause I, I discuss it with him quite a bit and I, I discuss it with our team here yesterday as I encourage them to use AI more.
I have tricked my setup out. You know, I, I, you know, I go back to when I first got in computers, I had a badass computer setup at home. This is before I got into tech.
I, I was running my own little network. I had Xena 3 86 machines back then with some hard disc, you know, hard external hard drive kind of things. I think about 30, 40 megs who would use all that space.
But, um, I, I've done the same thing with my ai. Fred's laughing, he remembers those days. Oh, yeah.
Uh, So I, so I know what you do and, and I use some of those tools myself, but I'll, let's be honest, you know, the percentage of the overall population that can think that way and do that, it's less than 3% maybe Today. It is. I agree.
I agree with, with Alan on this though. The, it's not the tool, it's not the wand, right? It's the wizard as they say.
Sure. The focus, if you look at the successful projects, uh, is going to be by folks that have training, understand what they're trying to do as a use case, and then also have, uh, enough data and enough rationalization to use it effectively. But I agree the converse of that is if you don't have training, and I believe that's probably the major inhibitor in this particular set of occurrences for adoption, and also, you know, when you get inaccurate results.
But let, let, because I think, uh, both Gina and Ann talked about inaccurate results. The challenge that you have, and I love, like Mike and John, you guys have dubbed this thing maybe, uh, vibe writing, which is different than vibe coding, but nonetheless there's a vibe writing Yeah. The philosophy of how you arrive at that conclusion.
And Mike, uh, you know how you guys have to do this stuff every single day. There has gotta be optimization places where you use AI to grapple with feeds and, you know, pull in more data and do these things. I mean, but the challenge is when you wanna say the words you want to say, does that happen every single time you utilize ai?
And the question I would ask is, uh, do you have, and are we collectively helping folks understand the appropriate way? And we're still talking about this problem that we're talking about right now is just prompt engineering problem space. Yeah.
That, that's trivial work. That's trivial work. But what we really should be talking about is, you know, when we look at the context of a business problem that we're trying to solve with ai, it's no different than any other tool we've tried to apply to a specific set of problems.
And my question around that is, I would say that having a dedicated group of folks to work on this particular set of problem space. And we've done this in other ways, in other organizations, uh, when adopting technology and bring that to the masses in order to support that with the context of the organization, not bring your own context of how I use ai, what I read on the internet, these types of things. Plus my own, you know, inference about what's happening here based on my home usage.
I think there's a number of ways that we could dramatically reshape this, and it might be too early for all of this to manifest, but contextually speaking, I think every organization that is not fully, fully embracing every optimal way to utilize this in their business processes is gonna get left behind. Your employees are missing out. And in the end, right, it's going to be a defining moment on whether or not that business survives in five years.
So what I wanna say to that, maybe we're all, yeah, maybe we're all right, or I mean, in a sense, we're, it's a, it's a, it's a learning process. And, uh, I'm, I'm gonna say, and I agree with what Alan, I, I am never gonna be, I'm gonna be more productive than ever because of ai. I'm using it as a research assistant.
I'm using it to, to bat ideas back and forth with, to summarize things, to get an idea. I don't trust. Its, its output of what it, its end result, but it's gonna get better and I'm gonna get better with it as I learn how to use it.
So I, I see nothing but positive, but for now, I see some hiccups. That's All. So I wanna say there's a systemic problem as well as how it's being implemented, right?
That is the roadblock. So I don't think it's fair to put this on employees who are handed a blank slate. Yeah.
Training is part of it, but also making sure that the data that's going into it from a, from a corporate perspective, is data that's going to be useful isn't going to be, like I talked yesterday to somebody about one of his reports, a technical marketer, no, a product manager actually handed this to that, that team and, um, had used the ai that he had used AI to write it. One of the reasons they knew is because one of the products it referenced was something that was a dead on arrival product that was never released. But it was.
But, but, but Gina, is that a proof reading? No, no. That, that's why they caught it.
Thankfully, somebody did proofread it. But what I'm saying is there's all, I am not anti ai. No, no.
I'm not saying you are. But what I'm saying is that product manager, your shame on him. But wait a minute.
Yeah, that's right. But also, let's say sha shame on this is a systemic problem that makes, that puts blocks in front of the adoption to the normal everyday users that are trying to get their things. So yes, I've resorted to, because I've had so much trouble with the, the context, this context slipping my old school trick of reading everything out loud before I submit it to anybody for even review to make sure that it doesn't get outta context.
That's what my self check is. And we should do that. But let's put this in the context of things that they are told that it's going to do.
Just use this, use it. Make sure you keep it inside the corporate guidelines with the corporate documents and everything's gonna come out fine. So yeah.
Should that product manager have read, reread it? Absolutely. But if you're somebody two years in Tilly Wool and you don't know the DOA projects that got out, they don't know that their DOA, if they just got hired, it's in the documentation.
AI found it like it's supposed to integrated into the whatever he was writing, and it was fine. What I'm seeing is there's a systemic part of this as well. There's training part of this, but the adoption isn't coming from people not wanting to use it.
Everybody wants their job to be easier. The adoption is not come coming 'cause they're afraid it's gonna lose. They're gonna lose their jobs.
Everybody realizes it's here and they need to learn AI to fix, to keep their jobs and to, to promote. There is a systemic problem with us thinking you could just plop down whatever tool vendor gives you and point it at a data lake and everything's going to come out the way it should. That data is dirty.
And if, and that's gonna end up with lots of issues like a, a debt on arrival product being brought up by a brand new product manager who doesn't have any, any background to know that it's not right or true. And then, Hey guys, I I gotta pull the plug though. We're at 21 minutes on this One last thing, on that point though, 98% of the general public thinks that the AI tool is being, and they're being told that this is some magical thing that will automatically do all this stuff.
And then they get involved with it and they go, this thing doesn't work as advertised. And they get frustrated. Life is in unicorns and rainbows, my friend.
Let's talk about something really important, the Super Bowl. How's AI gonna do? What do with the soup?
What does the AI have to do with the Super Bowl? Other than the silly, uh, we used Amazon, AWS AI to tell you what the probability of of him throwing of Tom Brady throwing it to Kroners, right? Mike, what do we do in here?
So Every year, of course, there are the, you know, how it is being applied to the Super Bowl and football stories and plays out in World Series and whatever it is. But we have a story from John here about how AI is being applied by the NFL to make players safer and prove the and experience. And we'll see how all this plays out.
John's gonna explain that, but it has a lot to do with those funny puffy helmets you see on the field, John. Yeah. Yes, yes.
So, uh, the Super Bowl's gonna be, uh, I about 10 days away, or 12. I, I, I can't, I can't count, but it's a week and a half away. It's near where Gina is right now in Santa Clara.
Uh, so the NFL reached out to me as, uh, they wanted me to talk to a guy named Jeff Miller, who's their executive Vice President of Player Health and Safety. And they, they really are pushing this narrative that the league has never been a safer place to play. And now this led to a spirited conversation I had with Jeff, because I don't necessarily agree with, with their statistics.
Their statistics show a, a significant reduction in concussions because of the helmets. And that's in, in and of itself is very interesting. And I'll start with that.
Now, the, the, there are different types of helmets that some are very light, some have new material within them. They are designed specifically for certain players now. So a wide receiver would wear a different helmet than an offensive lineman.
And that ties into the second thing I'm gonna mention. The helmets have gotten better because of data they've gleaned from a ai, what, what they're doing the league is doing through training and even through games. They have these GGPS sensors on players to look at the speed at which they move the, uh, their posture, uh, their, the certain angles that they, that they exhibit, um, when they're hit, how they're hit.
Um, which kind of leads to my quandary for the NFL. They've never been better about analyzing data about players and, uh, how fast they are and how they move. But they've also found out the players never been faster, never been stronger, never hit harder.
So it's, it's creating, uh, more issues for them. So consequently, in addition to using AI and, and changing equipment, they're looking at things like then they already have addressed this field surfaces, um, training regimens like mandatory versus, uh, minimizing that, uh, minimizing n amount of times people practice. They're, they're looking at a lot of, of different things.
Um, they, they claim that, uh, soft tissue injuries are down. Uh, in a sense, the reason why they're doing this, the reason why they're pushing this narrative is not only because this ai, but because the league has had a black eye for many years over its approach, or I would say it's, it's ignoring of concussions and that whole issue, uh, which led to a multi-billion dollar settlement with the players union former players. So overall, AI is being used, uh, for the benefit of the players, but I also think it's because the league has to address this.
And I don't know about the rest of you, but when you watch a game, I'm, I'm gonna, I'm gonna surmise that every seven or eight plays, there's an injury time out. Now it has become rampant and there's a 49 er fan. I can attest to injuries because this talk about a team that we, they Share, Right?
So, um, again, it it's, it's in, it's interesting. And with, and with the Super Bowl coming up, uh, to me it's very significant that the NFL would push the AI safety angle versus we have more cameras. We, we can show you what AWS can do for you.
I, I found that at least a bit refreshing. So let, let me preface what I'm gonna say by saying that, you know, I, I coach football for many years, not not at the NFL level, not even at the college level, but Pop Warner football, but I was the NFL player safety coach. So I, I went to, every year I had to go to a, a, a full day, I think some years it was two days a work camp on, on concussion, head injuries, safety, proper fitting of equipment.
They, they were working on this helmet stuff, John, way, way before we, we were talking about AI here. Yeah. Right.
And I really appreciate, you see a lot of the players, not a lot, but some of the players now wearing those, I forgot what, not Zodiac, but there's a name for the, it's like a, a foam rubber On top of the helmet on Top. And then they put like, and they Actually have three on top. They have 3D pretty padding within the helmet.
Yeah, no, but those things are great. Those things are gonna stop because when you get a, most concussions come from that either hitting the back or you're going down, or the side to side, the quick boom, you know, to the ground on the side of your head. And that those, those cushiony things really do help.
But none of this is ai, this, this, you wanna call it machine learning, maybe, you know, it's gathering all the angles and, and comparing that. That's a type of, it's a type that's a type of AI technically. Okay.
Alright. It it, to Gina's point earlier, right? It's not generative of ai.
There's, there's more machine learning. I, I commend them for doing it. I do think concussions are doubt.
I I think part of it also is that we're a lot more aware about traumatic. So It's also about, uh, tackling technique. It's Also about, and the heads up tackling it's called and, and everything else, K to helmet.
I wish they used some of this technology to help make the referees make better calls. The buffalo bills should be in the Super Bowl. Yeah, Right.
They got robbed, Maybe only in lieu of the Patriots, but, uh, Yeah, well, they would've take the Seahawks place, right? They were playing Denver and it should have been a Patriot Bills game in a hellacious snowstorm in New England. That would've been a great game.
But, uh, Is it, is it, is it the AI that's making the difference here or is it that the ref is calling the penalty more? Because when I have head-to-head interactions, it's 15 yards in. It's, it's all of the above there.
There're a lot more sensitive to head injuries. There's a lot more research going into what causes these head injuries. And as a result, we're now seeing second, third, fourth generation equipment that is optimized to minimize head injuries.
Doesn't stop you from tearing an ACL you know, when you slip on the turf. And, you know, we've seen a lot of stadiums move away from astro, I call it astro turf, artificial turf back to natural right? Because of, you know, less knee injuries and, and stuff like that that you get on the, on the artificial turf.
So, you know, the NFL's doing their job. There's another aspect to this though, and that is the fan experience. And I'm not just talking about the degenerate gamblers who can't wait to see which player, you know, they bet on which player goes out with a concussion first or something.
Right. But, um, but the fan experience, especially at that Santa Clara ballpark, which was designed to be a tech marvel from the get go. And so now with, you know, some of the AI kind of stuff, it's pretty cool to yeah, to do that, to be there using this as well as the at home Folks.
I really wish we could, um, take a, a press tour of the AI stuff they have at the stadium that we're not doing that, that that would be kind of cool. I would love to see that. I know one Thing, I know one, one benefit from that.
Uh, I know the, the Sony Hawkeye system, uh, with all the, you know, incredibly, uh, high capability cameras with incredible accuracy and precision. Uh, I know they are using some vision models to do analysis on what, you know, for things like when they do a, a film review for these particular things. I know that they're doing that.
Now. I don't know if that's the mainstay process, but I think, you know, when there is something that is, uh, you know, a reviewed by the booth call or something like this, they have a model of vision models working on whether or not that's something that really does, uh, relate to the call that they necessarily need to review as an additional source of input, which I, I think is cool. Uh, I do wonder, you know, at what point in time are gonna replace referees on the field, uh, versus, you know, having somebody make a judgment call on the judgment call, be part of the game.
But, um, it's interesting to see, aside from the, you know, sort of the digital, uh, the digital health part of, of player, uh, the NFL player analysis, uh, where else it might be used effectively, uh, instead of just all the angles for every TV coverage. Yeah. Well, they, well, the, the strike zones go, I'm sorry, go ahead, Anne.
Oh, Sorry. Didn't that happen with Wimbledon? They were looking at replacing line judges with Ai?
They have, they have. Yeah. Not only Wimbledon US Open too.
Yeah. Yeah. And it's that same system that they're using the mark, like first down calls where the ball is to to Age to age mar to age.
Some of us, um, they don't use the sticks. They don't bring 'em out on the field anymore. No, they don't even bring the sticks out.
They, they use the same thing when book uses. So baseball, Why not look at passing interference? Baseball, I think does a good job of, of video review.
No, no. But baseball's going into a, to an AI strike. You want to call it ai, I don't care what you call it, but the strikes though, no more umpires calling balls and strikes, Right?
Because vampires have different, I Look at their helmets though. I look at those helmets and I say, what's next? Are we gonna have 24 guys dressed up like the state puff marshmallow, man?
Is that how this is all gonna play Out? You know, what if it, if it means someone doesn't kill themselves and they're, when they're 45 because they have CES or whatever it's called God bless, Remember CTE so Junior say, I mean, he committed suicide by ct. Yeah.
There's plenty of Mike Wester the, you know, the poster child Junior say, but surprisingly as marshmallow men, like as those helmets look like, they supposedly don't slow you down. No, they're lighter in some cases. Um, you know, it's what's heartening to me is that they did talk to some of the players, and some of the players are, are advisors.
I think Tony Romos one. There are certain current players like Cam Cameron, Jordan is another, Caleb Williams with the Bears. They're working with some of these helmet makers to, to figure it out.
I remember years ago interviewing, uh, Colin Kaepernick during that whole controversy. And the thing he really wanted to talk about was helmet safety. He said the biggest issue with the league was with these people being beaten, senseless in their, in their brains.
Well, I, I would tell you, if you ever go to Canton to the Hall of Fame, or you go to any kind of displays at, at the various stadiums, and they have the old locker rooms with the equipment these guys wore, even in the seventies, eighties, nineties, you look at the helmets, you look at the shoulder pads, they look pretty flimsy, really. I mean, they're, they're not kind of the kind of stuff they wear today, which is more like body armor and, um, it's interesting. But anyway, we, we've, we've gotta move on, guys.
I'm sorry we spent so much time on track one that we, we didn't really leave time for a good discussion. But Gina, I will note you are in your Patriots jersey taste, so I'm assuming you're going for the Pats. Um, I know Fred's a Seattle guy.
I'm gonna assume he's, he's here for the Hawks Longhorns. That's who I cheer for And says, I don't care what it is, I'm going for the halls. No, I mean, f**k.
Said, am I gonna cheer for the Texans? I don't care about pro pro football. I only cheer for Texas.
That's me too. This is my son's jersey. And I wore it to try to get a picture for me and it in front of the stadium.
So when I found this, Aww, that's, That's a good mob. Good for you, Eugene. That's Very, he's a fanatic because he, his teenage preteen college years we're all in New England and when they won the first time, so he is, I also, I'm a college football girl, Florida State.
I'm gonna watch the game with guys that I grew up with. So I'm, I'm rooting for double overtime. Did you bet on that?
Like some crazy parlays. All right, Mike, what else we got for today? All right, we are gonna return to this conversation about what's going on at RSAC now that they have a new CEO.
Who is Jen Easterly. And, well, surprisingly, the federal government says that they're not gonna show up at this year's conference. Well, I don't know what to make of all of that, but Fred sounds, shall we say, petty, what do you think?
1 billion, uh, cyber operations and defense budgets for 2026, the National Defense Authorization Act. 1 billion for core cybersecurity operations, strangely, which is massive, uh, strangely, uh, CSA has been downgraded to some degree, uh, losing 300 million in budgeting. And this is a bedrock foundation for a public private partnership.
CSA is as a program. And, uh, first started by, uh, the first Trump administration and, uh, Jen appointed, uh, for CSA had dramatically turned the corner on the actual public private partnership and the collaboration efforts around that. All that to say that when that person steps into a role as an executive for a sac, which is becoming much more than just the largest security conference in the world, that leadership role is also something that that organization has designed to become more prevalent in.
The integration of all of the public private collaboration that happens by bringing more training and doing a number of other things is absolutely, uh, asked none to decide that the federal government, N-S-A-F-B-I, cisa, are not going to participate. And as Alan put it, take their toys and go home. Because of that, the notion of democratizing the problem space and the collaboration and understanding what adversaries are doing at a nation state level, the presentations, uh, the training and the in informing of the general public of what's happening, uh, as a nation is under siege.
We've already seen what the siloed effect of this has had, not only on the vulnerability, uh, database and the ability to support that. And the regionality of the, of the thinking around our global infrastructure, uh, is creating something that is quite provincial, uh, from the standpoint of a global cyber policy. So for me, uh, it's not only, uh, completely ridiculous that that's the case.
Uh, I wonder how many other things in other ways will the federal government step out of doing its obligatory job to its nation in reasoning that can't be understood by folks who've been in the industry for 20 plus years. And in a way that hurts both the folks doing the work and also the folks that are reciprocates of the work. Fred?
Well said, my friend. I'm sorry. That Was really succinct.
I read that and I was like, okay, a bunch of dudes are scared of a lady, a powerful lady. That's, that's just how I, I I have, knowing nothing else. That's just what, like a bunch of boys scared of a powerful woman.
That's literally what it looked like. That a lot. Yes, it's there is there is that, but there's more, Anne, you may not be aware of, right?
So Jen Easterly is a West Point grad, 20 years in army intelligence. Tons of, uh, private industry cyber experience as well. As Fred said, once they fired Chris Krebs for saying that the 2020 election wasn't stolen, they put Jen in and she did a marvelous job.
She was purged. And I mean it in the very best Stalinist way, she was purged when the new, when this administration came back in power, along with a lot of the CSA leadership, my friend, a lot of the CSO folks like Alan Friedman who did the S Bon, a lot of the leadership there has gone, in addition to the budget cut, money got shifted to ice, they got downgraded. Jen Easterly was then awarded a chairperson, uh, position at West Point.
And when the Trump administration found out she was getting that chairpersonship, they pulled it from her and said, Nope, nope. Can't be in West Point, even though she's a graduate, she's eminently qualified. Let's call this what it is.
It's cheap political theater. They took their ball and they went home. It is a powerful woman.
And you know, they don't have a big history with powerful women. But here's what it really says, though. We are gonna put our own political adolescent crap above this security for the critical infrastructure of this country.
And that my friends is not political theater. That's not tit for tat, that's not schoolyard bs that's putting us all in danger. 'cause you better bet over in Iran and North Korea and China and Russia and other places, they're rubbing their hands saying, boy, let this all fall apart.
Let it all fall apart. Give them enough rope to hang themselves, as Mark said, right? Because that's what we're doing here.
That that is what we're doing here. Let me just give you a little personal story. I've been going to the RSA conference for 25 years.
One of the nicest gentlemen I ever met in all of cybersecurity, Fred, you probably know Tony. Tony Sanger for, from NSA Red led their red team stuff. Yep.
Tony did more for the, for the NSA and their, and their ability to work with the private cyber industries and, and making a positive image for the NSA, which, let's face it, it's a bunch of spooks, right? They're, they're spies. They're, they're doing electronic surveillance, they're doing all kinds of crazy stuff.
But Tony Sanger was the human face of the NSA at RSA. I couldn't wait to see him every year. And he'd tell us, you know, what he could and, and help.
And as a result of that, man, I've been to Fort Mead. I, I had a chance when I was at still secure to do business there and, and some of the other agencies, RSA and Black hat was where Defcon was, where you, you this borderland the border opened and you were able to, to share information and collaborate and build relationships and protect our country. That's the thing that I think is funny because I was reading an article, 'cause I was like, well, why do they hate her so much?
Like, what is going on with this? Who are the, the lady and shortstop? Well, it's, it's bigger than that because, um, she's targeted, she was targeted by Laura Loomer.
Yes. And targeted. Particularly because, Like Laura Luer a big feminist icon.
Exactly. So, so she was targeted because she, the first targeted because she appointed somebody else that they didn't like to head up a department of disinformation that Biden set up. And of course, that all led to proving that the, the what happened with the election.
So for me, on the disinformation side, I think that's huge. And when you think about that and security, that's more than the spying and all the rest of it. And then bits and bit and, and bytes of how people get in, that's changing people's minds, changing the culture by lying to everybody in their face, which we're seeing, you know, we're seeing thankfully enough people speaking out about things we're being lied to, to our face.
Not enough from the press. Not enough, of course, from our government because they're doing it. So it's, it's pretty, it's more than her being a woman.
It's her being an effective, um, An effective woman affecting us. An effective woman, Let's say it. Well, that seems to me like a redundant, Okay, I'll let, I'll give you that one.
Ed, Let me Share a couple other things here. So, uh, the, here here's the impacts. Okay?
We can talk about the, it's interesting problem, space and all that. But here are the impacts. 85% of critical infrastructure is owned by private industry, 85%.
And when we don't have collaboration, we lose threat intelligence. We lose incident response capability. We lose the inability to deal with catastrophic, uh, incident response failures and infrastructure.
This is all true. And in this time and in this place where that infrastructure is more under siege than ever before, likely, you know, a hefty amount of that infrastructure has been compromised as illustrated by any number of the, you know, asterisk, typhoon, you know, activities and national infrastructure, the grid, et cetera. Um, and service providers.
This is a critical time to be moving into the forward direction of this type of partnership. When that is at risk, these things that we, we, we don't clearly understand, the everyday person doesn't understand. This equates to the federal government not being concerned with and or providing oversight to stop things like the supply chain breakdown or water contamination, or healthcare disruption or power outages.
We're not talking about like, uh, this company not making a hundred billion dollars. We're talking about the critical services. The fabric of the rule of law depends on go dark.
So how much of this is different though than, you know, if you study history, you will notice things like, you know, politics was a factor in the appointment of George Washington as commander in chief of the Continental Army. And there was politics in there, and there's been politics in every facet of defense and military, and now cybersecurity since they began. So some people would just say, you know, this is par for the freaking course.
Unfortunately, Mike, I think you're right. Uh, as far as the politicization of, of all of these types of decisions, it, it's a political office. Uh, administrations are meant to be political.
And I think in some sense that is the good boundary line to draw between the military, uh, provisions that happen there. But you use George Washington. Why was George Washington not president for longer than he was?
Because he gave that power back, His choice, his decision, right? For the betterment of the good of the nation. In this particular case, taking out the commander in chief conversation about it, the challenge isn't whether or not that's the right decision.
The challenge is whether or not we adopt and understand, uh, the level of service required to actually protect the nation. And here we're ignoring that, right? This decision is a c***k in the armor, right?
Of those of those types of statements. So I think if we asked a bunch of people that normally go to RSA and do they get value outta the conference? Uh, irrelevant to me, right?
What they get value out of is a collaboration with peers in the industry. An opportunity that's rarely, you know, something where West Coast and East Coast can get together. Global operational folks can get together.
It's that reason why this is a, you know, a a, a travesty in my mind, if there's something that replaces this, okay? Make that clear, make that known, share that information. Allow people to participate.
But this just doesn't feel like that. It feels like, especially you wouldn't, you know, you figure, you hear that people like Laura Loomer are involved in it. This is this another incident of we don't like this.
We gotta stop these people from figuring out, you know, this information. We've gotta, we've gotta close that right down or shut that down right now without realizing what her position and how non they don't, I don't think they can understand the nonpolitical part and just service to the country. They don't Understand.
Gina, you're So, that's the sin. That's the sin, right? To Mike and Fred's point on what you're saying, Gina, we've been blessed as the a nation in the United States that at key times in our history, whether you believe in a God or not, people arose the right moment, the right person for the right moment in time.
George Washington not staying more than two terms in setting that precedent. Abraham Lincoln, saving the union right through Civil War. Unfortunately, Teddy Roosevelt, Woodrow Wilson in World War I, Franklin Roosevelt going against what Washington did and and serving four terms, or died in his fourth term, right?
There comes a point at certain points in history, where you gotta put country above politics, country above party, right? You gotta do what's right for the country. And in this moment in time with critical infrastructure being what it is, and the threats that are out there, playing politics and taking your ball and going home.
Not just csar, CSAR didn't come. Csar isn't much today anyway. But pulling the NSA and the FBI out of it is just, it's, it's reckless.
It's gross negligence. And unfortunately, we're all gonna suffer. I hope not, but that's the deal.
Anyway, we're way over on today's text Junk Gang. Fred, thank you for, for taking the yeoman's work on that one. 'cause I didn't, I wrote this story, but I wanted to hear someone else talk about it.
And it's been a popular thing up on LinkedIn. And, uh, you can check it out there, but you wanna read the whole story. You go over to Security Boulevard and Fred, Gina, John Mike, thank you for joining us on this great Thursday Text on Gang Live.
I hope you've enjoyed it out there. Hey, I've got a shimmy says, coming up at 2:30 PM Eastern Time today. I'm not talking about RSA, I'm talking about, uh, AI and what it can, what a surprise.
And is it, you know, Dr. Jekyll and Mr. Hyde, uh, what, what's the future look like there?
We also have Tech Field Day today, I believe, right? Gina AI Infrastructure Field Day. Yep, absolutely.
They're starting, we're starting at about 10 minutes. You can go to, um, the Tech Field Day page. And it's live, It's actually live right on Tech Drug tv.
Oh, hey. So you, yep, you can watch it there. Um, or on the Tech Field Day, YouTube channel.
Um, and, you know, we've always got more. We'll be back tomorrow with even more text on gang, but for now, this is Alan Hummel, we're out. Thanks, everyone.
Control, This is agent dev. I'm in position. Copy that.
Dev. Stand by for go Standing by. Hi everybody, welcome to the Agents of Deb podcast.
I'm Mitch Ashley and I, I'm with futurum. I lead the software lifecycle engineering practice, and my co-host Brad Shiman, who also is with futurum. Hey, Brad.
Hey there, Mitch. How's it going? Good.
Good. It's, um, another week. Like, we're kind of getting on a roll here.
2026 just kind of keeps on coming. Kinda like ai, it just keeps on going. Yes.
Well, we did just enjoy the winter break wherein all of the major frontier model makers, you know, bestowed their gifts upon us, uh, did they not. And was, was certainly one of those vendors, uh, introduced this cowork cowork. And, uh, I imagine everyone that's listening to this is, is, you know, aware of it, uh, if they haven't been able to use it yet, because it is a little bit, uh, cordoned off right now.
But it's a fascinating tool, um, for a couple of reasons. And, and the first one is, doesn't even have anything to do with what it does. Uh, it, it, it's, it's how it was made, um, that there is Oh, oh, that's a great story.
Yeah. Tell us that story, isn't it? Uh, so, mm-hmm.
So a, a man named Boris, um, who, you know, everyone that, that follows AI appreciates because he typically opens up, you know, and shares with us a lot of his best practices and how he builds software using Claude Code. And, um, he apparently, uh, over the course of 10 days used Claude Code to build this product called Cowork. And this 10 day product, uh, meaning conception to deployment and and realization, uh, is, is like this nuclear, you know, explosion, uh, in the marketplace.
And I'm gonna argue of more importance than, than, um, MCP was al also invented by Anthropic, simply because of, of what it does philosophically, which you and I are gonna gonna talk about at, at length today. But at, at any rate, I, uh, tip my hat to Boris, uh, for, um, you know, basically recognizing a, a, a value proposition and executing on it, using the tools, uh, available to him. So, love it.
Yeah. And it, and it, this isn't just like another vibe message, right? This is like real, real, you know, Boris, you dunno know, I think is his, he's very legit.
Let's just say it that way. That's a gross understatement. Street cred.
Yes. Street cred. He's got the receipts for sure.
Um, but you know, he, he created a tool and like in many cases, a lot of companies, people create tools sometimes for themselves and they productize it, or they have an idea and a greater tool and it becomes a product. And some of those don't, some of 'em do. Um, but if you kind of, I dunno about the, the name cowork, it, it kind of, yeah, it is a, it is a partner, it does work for you.
It's essentially inside the cloud interface and your agent interaction with agent creating agents and subagents and plans and scheduling them and doing all that kind of stuff. But you could do essentially what you could do in cloud code, you could now do in the, in the web interface, in the, the, if you wanna call it the prompt interface. Um, but it's another mode that you're going into.
And now you're in, in cowork and it has some predefined here. Go check my email, summarize this for me, send that to me once a day, kind of things that are already there. Analyze this data, put it in a spreadsheet, et cetera.
So give you some ideas of how it works. Um, but it really, what, what it really does is it leverages a lot of what I appreciate about philanthropic especially, um, four, five is Sona four five is all of the sub tasking that it will do for you. It doesn't just prompt and run it, it prompts and puts together a plan and it creates a bunch of substeps.
Sometimes sub-agents, sometimes it's just multiple steps. But now that can be essentially your agent headquarters and you don't have to know how to code, you can't, it'll write code. It'll sit there and say, here I'm doing step five, here's, here's some Python code that does this.
It stores it in a, if you're in the web interface, it stores it into a virtual machine in online. And that's where it runs. If you run it locally, um, if you're using it like the desktop application, it will, it can have access to your file system.
It'll store the files there, it'll run it there, uh, whatever it's creating. So it's, you know, it has some portability issues. It's not exactly the work the way, same way across mobile, desktop and, and web.
But the idea is pretty much anybody can do what you would do in cloud code in terms terms of creating agents to do work for you on things that you have access to, either inherently you've given permissions through the app or the web interface or MCP or whatever it might be. It's, it's, to me, it's a big deal. I think it's a huge deal.
It's, and it's shockingly simple, and it's something we already had because, uh, everyone who's been using Cloud Code, Gemini, CLI and Codex at all in the command line has access, has had access to these same tools. You, you have an agent framework that is a four while loop that is gonna execute on a set of tasks that either you bring to the table or it you, uh, deduces from your intent and executes on those using the tools that are available to it. And those tools quite usually are command line tools, copy a file, move a file to lead a file, uh, or, or directory.
And, uh, all of those things that, that you had so r the command for. Okay. Alright.
Right. That's right. Right.
So be careful kids. Um, but, but, uh, it's, it's interesting because, um, it is such a simple idea and one that we already had available to us, but as you just said, it's, it's taking that idea and giving it to those who don't like the command line, that don't work in the command line. Uh, and it's this recognition that, well, you know, you said it's the same thing.
Why is it the same thing? Well, we work on machines, we work on PCs, we work on desktops, we work on phones, et cetera, and all of those have a number of things in common. Uh, and, and that is a substrate that is, uh, what iad, um, because most of the world we've been living in for the last, uh, few years is chat bot driven.
And it's, you know, typically you have a long running conversation trying to steer a model toward an output that you want. Then you take that output and put it into practice somewhere. And by somewhere, I mean usually, you know, on your file system, you know, to, to use it in some, some capacity.
And, um, that's not, you know, how people work. People work on their machines, they work in applications that access files on their desktop, and those files are of known formats. Um, and so put two and two together and maybe, you know, instead of working in an environment where you're doing this constant chat chat, trying to do it, get something done, you can pivot that to a task oriented, uh, engagement or relationship in which the, you know, as you just mentioned with Claude, um, cowork, you have these sub-agents that can be kicked off to do specific tasks.
Like one might be, uh, looking for duplicates in your downloads folder. Another one might be, uh, renaming those duplicates. So in a consistent way, another one might be parsing a video looking, uh, for transcripts, and then another one that analyzes those transcripts.
All of that is work we do day in and day out. And what Claude Cowork is doing is saying, you know, you don't have to use a command line for that. I mean, ultimately it is using the command line for that, but you and I don't have to, you know, stand that up to, to take advantage of it.
Mm-hmm. Yeah. It, it, so, so the metaphor, the, the experience I thought about is this is a user experience paradigm.
Meet the user, meet the customer where they're right. In other words, you're not gonna drag everybody, uh, to the command line. Not gonna drag everybody into an IDE.
Maybe even getting them into a prompt session is, is a bit of a challenge. But, you know, you wouldn't, lemme give you an example. You wouldn't store your Excel formulas in a document somewhere and then go back and plug them in every time you use them, right?
That's essentially, yeah. That's, that's the metaphor that we're taking on now with, with AI and agents, is those things live where you need them to live so that they can run and execute. Either you decide you want them or other agents, you know, call agents for you.
And so the, the, the prompting thread to me is a transitionary interface. It's, it's the kind of beginning way of conversing and then we invent ways of writing it down, and then we invent ways of publishing and sharing it, and then we invent ways of distributing it and amplifying it, you know, kind of we're on this progression of the user experience for it skills is the same way in in cloud, uh, which has been kind of replicated, or you can replicate it yourself in different, because, uh, can I take a tangent? I'll tell you about a project that I worked on this weekend, just it taught me a lot.
So probably like you, I'm sure like you, I'm bopping between Gemini and chat, BT and Quad Code and Codex, and you know, it's, it's, you're going back and forth all the time because you wanna know what's, what things are, what's happening, what is Yeah. How they, how they are different from one another. Exactly.
And how does this new thing work, right? Um, the problem is you lose con now that we have memory and things like that across these different models, you lose that jumping between models, right? So now I'm back over suddenly doing work in Quad and I don't have all the recent things that I've been doing in another environment.
And, uh, hold on, hold on just a minute. Okay. Go get them.
Oh. Oh. So you have to like restart it.
Oh, sorry. Y yeah. Yeah.
Send them a note. Send them a note. I, alright, so carry on.
So switching between those models, you lose fidelity of the investments that you've made, right? And yeah. You know, here's how I write or here's what my preferences are, here's the gaming things that I do, what whatever you're doing with them.
And so I, I wanted to, to really do a lot more in clouds. I wanted to catch it up. So two things is, one, I created this context operating context model that I can move between that.
It's kind of everything about what I've trained about how I want things done and how I work. Everything from what I do for a living. It's Claude md, your agents MD file.
It's, and it, and then you can kind of plug it into whatever projects that you're working on across those and update it and redistribute it to another environment. Someday that'll be automated. Just simply link it across all your projects.
Sim link it. Exactly. You got it.
So it's, now I have sort of a a one brain of what, of what my part of the brain is if you, you'll, uh, my preferences if you wanna think of it that way. Um, and then the next thing I ventured into was, um, I was asked by, um, our leadership at Futurum of, Hey, would you send us that prompt that you used to generate that report to get ready for a meeting? And what it was is taking some, uh, notes from a, a, uh, earnings call and doing some analysis on it and pulling some quotes at it and doing things like that.
Well, the problem with sending somebody that prompt, that prompt started about about 12 different interactions before, there's not one prompt that generated that, right? It started through a whole chain. So I had this idea of I'm gonna create a toolkit to reverse engineer prompts based on the output and the input.
So I use this as my test case of here's, here's the result, here's the response I got from this model, actually different, different, uh, l lm and here's all the input files and here's the session that I had that created that. Now synthesize that and create a reusable prompt so that anybody could run that on any earnings call that's brilliant. And then re refine it until it's good enough.
It needs to be, you know, at least 90%, uh, accurate if not more consistent. It doesn't have to be literally the same thing, but it has to ha the fidelity of it needs to be accurate. And, uh, it's one of the nice things about Claude is it, it will do those iterations for you.
It's very good about kind of refining and getting you better output sometimes even without asking. And it was great. So I got this really nice prompt that I shared with the other folks and then I said, okay, take that and create a prompt reengineering toolkit that I can use for any prompt.
The same process we just went through probably won't work for every situation, but now I've got a, a tool that I can use, solve that problem. Got that tool created, this memory context. Yeah, I actually did other things on the weekend, but there were so many innovation.
That was like the morning Sunday morning. Yes. A lot of that was yesterday actually.
Awesome. Yeah. Nice.
So that, that to me, you publish cowork model. That's what we're trying to do is use ai, AI as a coworker, whether it's through the cowork feature or create these things for us that will do work for us. Right?
Yeah. I'm sorry to to talk over you there, Mitch, at the end, but No, no problem. That's so cool.
And um, it, it's funny when hearing you talk about that experience, I'm thinking, oh yeah, well, you know, obviously you'd seem like your, your agents MD and hey, that would be great as a skill that you could document, uh, and publish that for you across your different agents. Because like you said, everybody's using what philanthropic came up with with the, with the skills, uh, format, which I mean, my goodness, it's just a YAML file people, you know, it's not, it's not a new paradigm, but take it all together and it kind of is a paradigm shifting innovation we're talking about with cowork here because as, um, you and I were talking about before we jumped on the call and as you you just mentioned with, you know, cowork taking what we take for granted in the, in a in a prompt and sorry, in a terminal and exposing that to the broader context of work. And I, I'm like, yeah, there are two kinds of people in the world.
There, there are, you know, ones that are, uh, I'm not gonna use the binary joke, I'm, I'm not. Um, but there are, there are those who, you know, um, are noun first people and there're those who are verb first people. Mm.
And, um, noun first people are those who grew up with, you know, the Windows XP and beyonds and what the, what they think about doing something. They're like, oh, I'm, I'm gonna work on a Word document, so I open word and I wanna open this file and do something with it. And that is, you know, great because you don't have to remember all of the different tools you have available to you.
Mm-hmm. You basically think about the thing and then the action comes second. And the verb first people are those who grew up, you know, playing, uh, star Trek on a mainframe back in the the seventies that, that are like, okay, you know, I, I want to do something to something.
I want to find this file. Um, they don't open a file and then find something, uh, or open a file system, then find something they're just verb noun and, um, move my Starship to sector six. That's right.
That's century century. I, I, I adored that game. Um, but uh, it, it's, it's interesting to me that, you know, with Cowork and with Claude code before that, uh, did I just say co cowork work?
'cause No, you got cowork. I like you. It should just be work.
It's not cowork. Yeah. It's, it's just work.
Uh, but, but anyway, um, what that does is, is gives us the opportunity to sort of br bring those two worldviews together and to see them not as separate, you know, oh, that person's a terminal person. Oh, that person's a Microsoft Ribbon bar person mm-hmm. To realize that it's, it's just work being done and work is being done Two things on a machine.
Like it always has, nothing has changed there in a few years, but it is something that is accessible, much more accessible to, to those that are used to the noun first, uh, mentality, uh, or, or worldview of, of getting business done. And does that not sort of collapse all of the, um, sort of markets that you and I have been writing about and thinking about with how companies automate software and build, uh, workflows, you know, and, and do things, you know, in the workflow, um, within, you know, a payment system within an ERP system, within an HR system, whatever. Um, if at the end of the day it's, it's just doing work with a certain set of assets, whatever those are, a Slack channel, uh, a PowerPoint presentation, uh, you know, matter if it's anywhere, you know, it, it can just be me working with my computer to state my intent, and then that intent gets executed, uh, in whatever modality is most efficient to, to get that done.
It's a really good point because you're not, you don't, you're not opening word to write a document. You're in your whatever, uh, AI tool and saying, here's what I want. Create this now, put it into these forms.
I want a PowerPoint, I want a email message, I want a social media campaign. I want, you know, a checklist, you know, I want a podcast script. You, you now, the, the forms that it can take, you know?
Yeah. Uh, to your point, the modality of it really can, the outcome can shift and change and be adapted to whatever. You're not gonna, you're not gonna do a podcast the same way you're gonna write a document or a social media campaign.
So can be adapted to each, you, you said, one of the words you said that I really relate to is system, right? And that is, I think that's, for me, these are all systems. There's a system.
This is why the games that I like to play this, uh, civ six things like that, um, there's a system to it, right? And me figuring out that system and how to make it work. And so part of the work now is understanding, well, we're creating the system that we're doing on top of what AI is giving us today.
And that I think does what the work really shifts to is I have a system of work that's happening. I'm doing some of it. I have AI do doing some of it, I'm working with other people that are doing some of it, but all that fits together for some kind of orchestrated type of outcomes.
Um, interconnected things that are dependent upon each other. Um, but I can't go to my prompt library every time I need the next step, right? So we're starting to cross this chasm back into what's the new ui, what's the ribbon bar of what AI looks like, what's the, the, uh, the menu bar look like?
I'm not saying that we'll have ribbon bars or menu bar. What's the equivalent of that from a user interface today? And, and it's still, still not there yet.
It'll get there. We have like chats in the side panel, which is kind of screwy, but technical screw, right. Good start.
But we could do better. We can, or I mean, we've, we've kind, we kind of end up chasing, um, these ideas and sometimes they're not the best idea. Mm-hmm.
And we need to have the courage to just turn around and, and walk back out or just, you know, call it what it is and use it how it is best used instead of just keep forcing it and forcing it. And I feel like, you know, why I like Cowork is that it to me is that very act, um, if you remember of the film Animal House, when the band takes the turn, goes down the alley and they all collide into the wall at the end because the leader is like doing the thing, right? And, and, um, it seems like we've been doing that with, with chat based AI for the last three years or so.
Um, and you know, the, the ability to say, you know what, maybe, uh, everything, you know, being circulating around just using the web, uh, and using the chat interface is, is a method, but not the method to do this. 'cause I mean, think about it, and I, and I mentioned it a a few minutes ago, with the adversarial nature of, of the non adversarial nature of your own file system. You control it, you own it, you can, um, set up a sandbox.
And as you mentioned with, with cloud cowork, you actually have them manage that sandbox for you. Um, and you don't get that on the web if you're, if you're trying to use agents to go scrape the web with beautiful soup or something, you're in for a world of disappointment. Mm-hmm.
Uh, it, it is not easy and, you know, because the web wasn't made for agents and probably never will, uh, at least you know, it, it, because I think it's in conflict with how the web, you know, itself grew as a means of, of commerce. So, uh, you know, I think we need to turn the band around sometimes. And this, this is one of those moments of, you know, the leader going, oh wait, is there's a brick wall up there?
Let's, let's just pause. You know, we, we talked about this a little bit, a couple things we talked about in our last episode. And that is to me, and that that is at some point the, the metaphor or the paradigm or something changes, right?
You kind of go into a new way of doing it, right? Like microservices as opposed to let's say a, you know, a monolith application just to pick one extreme. Um, and we're, we're going through this with ai and I think about the web applications.
Web applications are pretty much the digital form of what we did manually. We fill out a form. Mm-hmm.
Look at the available forms for humans and he tells us, or emails us and we email 'em back and say, I'd like this one. Well, that can do that in an app now. Um, it, it's still pretty much the same logical or similar logical workflow.
Maybe it accelerates it 'cause you've got all that into, you know, one package set of steps that you can do in an app or mobile, et cetera. Um, certainly is better than not saying it's not better than manual, but it's very much the same kind of the paradigm that you're using with ai. That paradigm can change because now you don't have to do all those steps yourself.
You're to use the word orchestrate. I, I think of, I think of our role architecting the system. I think our, our role is architecting how gets done.
How are we gonna do this today? Oh, you have, I have that, I have parts of that already done. I want you to figure out the rest or Hey, really good, really good agents there, Brad.
Be, be ashamed if I borrowed those from you. Thank you. But it's a different way of working And I think that's what's sort of like either scary or exciting or maybe a combination of both about ai of like, well, what is my job then?
Well, I dunno. I think we're figuring that out. I, I think if anything, you know, we're, we're realizing that domain expertise, um, the ability to reason critically, to assess critically, uh, is, is what's going to be the, the main skillset that's, that's gonna be in demand this year and beyond.
And, you know, when I think about what cowork does and think about the crisis that we're already kind of building, uh, in for junior whatevers, you know, engineers or analysts or anybody you know, in which the companies are like, why should I hire them when I can just have AI do it? You know, and, and you, it doesn't take a full generation even to find yourself at a company with no ability to, you know, with no domain knowledge and no critical reasoning skills. And, uh, so I think companies will increasingly wake up to that fact and look at, you know, what, what it means that we have the ability to, to take what was in a command line and expose it, uh, to, you know, the more broad, you know, any workflow because this could be used for anything.
Um, and what that means, and what it means is that, you know, we as, as workers, information workers in, in the technology space, you know, have to cultivate those capabilities, those those skills, if you will, if we are to succeed, uh, going forward. And that's going to have its own ladder of, of ascension for, for, you know, building competency within companies. So it's, it's not gonna be the same job.
You're not gonna be having people try to all day chunk through, you know, the SQL standard. But if you can teach them to understand SQL and to recognize for the domain that you're working in at the company that, wow, that's a valid SQL statement. But boy, that is gonna give me the wrong answer.
That that's what gonna matter most. Perfect. Wrong answer.
The perfect, wrong answer. Totally. Yeah.
It, it, I I think we're entering an age of, we aren't gonna be trained on tools that, that's our training. That's the skill. What do you know, what language do you know?
Tools. Do you, okay, okay. No, those are the tools we use.
And yes, we'll still be using tools, but it, it is more the systemic thinking is a problem. It's really problem solving. It's really solutions to work.
Yeah. It, it's really kind of thinking, uh, in a different paradigm about how you're gonna solve those problems with a new set of tools. Uh, the tools aren't gonna show you how to do that.
At least they don't. Now they show you what's possible. You have to kind of think about that tipping point of, am I, am I, am I gonna do the manual version as they did in a web version, uh, that I'm now doing an agent version, or am I gonna re-architect this because now I can do a lot more or do it differently and accomplish more, or engage different things I never thought was possible, but I now do.
Yeah. Or get myself, you know, if I'm gonna do something more than once, maybe I should turn it into a system, a process. And now we have the ability to do that with, with tools like this.
That's what I did. That was a, that example from this weekend. Hey, I did this like engineering do, because I bet that's not the last time I do it.
Probably not. Well, let's, let's, uh, let's move on to our last segment, the drop. Alright, I'll, I'll, I think I kicked in first last time.
Why don't you jump right in, Brad, what's going on for you? Yeah, totally. So, uh, I, I'm going back to old ideas because the backlog is that big.
I'm, I'm going back to 2022 and 2024. Well, you're reaching back a little bit there. Totally.
Yeah. Uh, this, this idea, because you know how I, I talk a lot about, you know, it's context engineering and intent engineering, et cetera, and you're not prompt engineering. It's not where the sweet spot is, or the only sweet spot.
And so this idea of, um, it's, it's like a bidirectional attention hack within a prompt that's, that's called re two, which is basically just rereading. And what it, what what it's about is you can take a non reasoning model, meaning a non-thinking model, um, that's just, you know, you're straightforward, you know, um, one directional no, yeah, it's one directional, um, and transformer. And, um, just tell it what you want it to do twice, uh, once at the outset and once at the end.
And, and the example I'll give is, um, you know, if you're, if you're telling it to read a legal document and, and look for exposure to, you know, some sort of threat or, or whatever, and you, you don't state that the outset, it's just gonna read the document. It's, it's a, it's called a triangle of attention in which the model, when it starts to look through the, um, the input tokens, uh, that first token doesn't, doesn't see anything in front of it. It only sees itself and what's behind it.
So if you can give it sort of like, another basic one is, you know, I want this in JSON, uh, logical, but if you just put it at the end, it's gonna go through all that work and the prompt and, and processing the tokens that go, oh, he wanted it in J song, that idiot. Why didn't he tell me that? Um, so it, it's, it's just like a, a hack that I want to sort of systematize, um, where appropriate and, and put it into some, uh, a test environment this week to see, to see if that improves some of the, the work that we, we have, uh, to, to, you know, for long context, uh, inferencing.
Is that a bit like, um, we may have, I dunno if we talked about this, but defining success criteria, what success looks like, the end state, Hey, stop. Yeah. Hey, my dogs are going crazy.
Stop. Hold on. They wanna be on the podcast.
They're like, here, something is going on in their world. Hold on. I'm gonna let them out here.
Okay. Demanding puppies. Yeah.
That's, is this like, uh, the, uh, there's the idea of defining success or defining what the instate not just what you want. So, and when you have a multi-step reasoning model, then you can iterate until it gets what you're asking for. Right, exactly.
Uh, is that sort of in similar idea what you're talking about? Yeah, but without the cost, without the latency and the token cost of doing the, the reasoning, you, you just are spending pre, you know, input tokens, which are vastly cheaper than output tokens to do this. So you don't have to spend all that money, um, you know, on a huge reasoning model, you can get the same level of performance with a non reasoning model, just with basic, you know, hack attention hacking.
It's the, um, okay, we have a great way of doing this now, let's find efficient way of doing this. Right. Yeah.
That's why, that's why I like spectrum development, even, even if, uh, it, it does become idiotic from time to time. Okay. Well that sounds like another PO podcast episode.
Um, well, great. I'm, I'm, I, I mean, very interested to see where you'll go with this. So, um, yeah.
Whatcha thinking about right now? Yeah, you know, it's, um, I had this sort of flurry of generating a whole bunch of reports last week because a lot of stuff happened, um, right at the beginning of the year. Yeah.
GI GitLab came out with their release and their dual platform for agents and, um, Dynatrace did an acquisition. You know, all those kinds of things and projects that we have going on. So I'm, I'm really thinking about how to lean into, we have something called the futureum Intelligence platform, which is our, in, it's not our internal, but it's our internal and external platform that we use where all our data lives, all our reports lives.
But more, I think more importantly, it's where our AI lives. And today I do a lot of the AI things external to it, because it's being developed, but it's coming along. Uh, they made some impressive strides.
Agreed. And those things will be available to our customers as well. Um, to the point where, you know, when I have AI co-write with me, let's call it that, when I use it to do writing with me, you know, is that akin to AI slot or is that akin to, um, no, it's just like if I hired a writer to write stuff for me in, in my name and then instruct them, okay, that's not quite what I want.
This is what, this is the idea. It's not firm enough on what I'm looking for strong enough. It doesn't lean in like I am looking for, and it doesn't make these connections.
Okay, good. We're getting there. We're getting there.
Um, great. Now I'll tweak it and add some more to it, and then I have a finished product. And I think that's where, you know, AI slap, we always look for ways to, you know, downplay and call something stupid and say, oh, that's just AI slap.
Well, it's not, I think that we're, we're merging into an environment where AI is, is a writing assistant. I mean, yes, it can write stuff for us, and you can push the publish button and we never touch it. Um, and there may be cases for that, but for us, it's a very much an interactive partner and how we do our work.
And what's nice about it is, is there is added information, added ideas that I can pick out and say, had not thought about that. Or, what about this, you know, Hey, I didn't Microsoft do something similar like this two years ago. Okay, let's make a reference to that.
Say this paradigm continues, or whatever, that I'd be so busy writing it that I wouldn't have time to kind of think about making it improving it better. So we're just like, we're talking about changing the interaction model for, for ai, for coding or tasks or agents and all that stuff. Like the, the content model is changing and it's not binary.
It's either AI written or it's not. Um, so Billy Bob Thornton is not leaving landman. That is AI slop.
But other than that, so as I'm working on content more and more, I'm trying to figure out how does, how, what does role does AI play in it? And how can I leverage it to the best to amplify what I wanna do, not replace what I wanna do. Yeah.
I love that. And we should, we could do an entire episode just, just on those, you know, ideas and, uh, some of the learnings that we've had and, and continue to have mm-hmm. Every moment to moment.
Uh, uh, it, but you know, like you, uh, I look at it, uh, very sim very similarly, and, um, you know, I, I see, you know, the ability to not, not just, you know, speed, not just to gain speed, but also to, like, you're just talking about, to build a, you know, better outcome, uh, build build something that's more useful to myself and to our customers. And if expanding your, um, uh, knowledge, uh, would you call it, uh, horizon, let's say mm-hmm. Like you're talking about with did Microsoft do that?
You, that in and of itself is, is a tremendous step forward for us. That makes us better at our job as an analyst. And that is, that is a tool I will use every day.
Yep. Absolutely. Well, it's been fun, Brad, as always, thanks to Corey, our, uh, our podcast engineer for helping us make this happen and doing a little edits here and here when my dogs get outta control.
And thanks for everybody's face patience with that as well. I hope you enjoyed this episode. Uh, we do this weekly, uh, from wherever the world Brad and I and Corey are, and we hop on and talk about what we're working on and what's going on in our world, but really what's going in the larger world.
'cause that's what we do as analysts kind, is work on those things and, uh, try to understand where we think that's all headed, which is why we post the content that we do. So be your sure and check out Brad's fantastic research. You can go to futur group com slash brad Shiman shiman, same thing for me slash Mitch, excuse me slash Mitch Ashley, if I said that right.
Um, check out our stuff and we appreciate you following. Send us a comment, send us a note, uh, like us, follow us, share us with your friends. Uh, if you don't like us, tell us too.
You can put it on a comment or send us a note. We're happy to, uh, improve what we're doing, whether it's a podcast or our analysis. So, Brad, on behalf of yourself and Corey, thanks everybody for joining.
We'll be back next week with another great episode Control. This is agent dev. I'm in position.
Copy that. Dev stand for Go Standing by. Welcome everyone.
Thank you for joining us Today. We're talking about readiness and AI in the mainframe environment. My name is Mitch Ashley, and I lead the software lifecycle engineering practice at the Futurum Group.
Today I am joined by Anthony Dero, who is Senior director architecture of ai. And with the BMC, let me try that again. Not the BMC.
Dang it. My bad. Alright, starting at 3, 2, 1.
Hi, and welcome. Welcome to our conversation about AI readiness in the mainframe environment. My name is Mitch Ashley, and I lead the software lifecycle engineering practice with the Futur Group.
Today I'm joined by Anthony Desaro. Anthony is Senior director of architecture for AI with BNC software. Welcome, Anthony.
Mitch. Thanks for having me. You bet.
Great to have you. Now, this is a three part series. Our first part is talking about AI readiness, and the series is, uh, sponsored by BMC software.
We appreciate the folks at BMC, uh, putting this on and putting this together. So, Anthony, let, let's jump right in. So, we hear a lot about organizations needing to be AI ready, especially for the mainframe environment.
Mm-hmm. At the earliest stage, what does AI readiness really mean? Yeah, Mitch, this question, I can't tell you how many times I get this, whether it's I'm speaking at a conference or customer visit, this always comes up, you know, how do we get going?
How do we, we get started with that, and it's so foundational into a successful journey with ai, but yet it's a step that you'd be surprised how many organ organizations just kind of ignore or are not even aware there is a readiness, uh, you know, playbook that they, that they should be, uh, following. So it all boils down to, uh, from an organization perspective, you know, how do we roll in AI technology? How do we use AI technology safely within our organization?
How do we put guardrails around AI for, uh, you know, for protection against data? Uh, for example, you know, uh, from a, from a legal perspective, you know, uh, what policies and governance that we need to have in place. Uh, we bring AI into our organization, and there's all kinds of challenges around that.
But at the end of the day, you know, that's one part of the organization's gotta deal with that. And then it comes down to the individual, you know, groups and, uh, departments within an organization and how they want to utilize ai. So the first really good step in that journey is looking at AI as an advisor.
Mitch, really look at it as like you would bring in a human into your organization, you know, based on their experiences and, and their background to have a dialogue exchange with them about whatever challenges that you may have. And you're gonna lean on that person for their insights and guidance based on their experiences. Ai, that's a great first step with AI image.
Look at AI as an advisor. It's there to explain, it's there to guide, it's there to recommend, et cetera. It's there to provide knowledge and insights that you may otherwise miss or not know how to surface.
So from that perspective, that is a safe AI journey to start moving your organization to. But then the other side of that is the skills of your staff itself. When you bring AI into an organization, you wanna make sure that your SA staff is skilled in AI usage.
You want to make sure your staff is skilled and understand on where they should be applying AI within the organization. So there's some education and training that need to be done for your staff. There's guidelines, uh, uh, and policies that you need to be putting in place, guardrails that you need to be putting in place.
And that's all very, very, um, very focused on individual organizations and what that means. But that's the first step, um, to get that, those foundational aspects of AI in place. That's a really good point about having that kind of direction you want to take with AI versus it's so accessible.
We can use it, try it out, but how are we gonna focus and leverage it for the organization? And you mentioned the concept of AI as an advisor, using that as your first entree into ai. Talk about how that is different than maybe automation, autonomous ai, agent ai, all the terms that we hear about, uh, doing things with ai.
Yeah, Yeah. So what, you know, when you do hear about, uh, autonomous AI and agents that's all around actionability and the AI take, you know, perceiving a situation, making a decision, and taking it in action, jumping into the deep end of the pool when it comes to AI in that regard, that, that, that's concerning to a lot of, a lot, a lot of folks. So when we talk about the advise the advisor part of that, the advisor takes no action, right?
Again, the advisor is there just to guide you, nurture you, and move you along. But it's up to you, the human to actually take those actions. It's up to the team who's using AI to infuse AI with the right pieces of information to get the right types of guidance that they want from that AI system.
But that AI system is benign, right? That again, the AI system is not going to take any actions on or your, your behalf. It's all back to you.
And what you want to get out of that, that AI system. So if you're a developer, I'm gonna use AI as an advisor to maybe gimme code, recommendations, code, explain, um, maybe to do a best practices analysis on my code, et cetera. That's, that, that's really good.
Maybe from the AI ops space, Mitch, we're gonna use AI as an advisor to oversee my, my dashboard and maybe surface insights to me out of that dashboard that I would otherwise miss. But there's no actionability to it in that regard. It's just providing the insights and information so that that is, that is a part that fits very naturally into the advisor part of it, as opposed to the autonomy part of ai.
It's good you mentioned that. 'cause it is a much more comfortable way to kind of enter into the AI space to start to use it. You don't have to jump right into automation and agents and, you know, doing more of the, you know, advanced things.
If you wanna think of it that way. You'll build trust, you'll learn about AI by using it. And we, and we've done that ourselves, right?
You know, look over the last 18 months, whoever your chat provider of choice may be. But that's how we, we all got into the game of ai. When, when, when, when, uh, you know, chat, GPT was released as an example.
We all went out there and, and started having conversation with AI at that point, whether it was professionally or personally, that experience was an advisor type experience. You know, we sent it a bunch of questions and we got responses back and we had a conversation and a dialogue with it, but nothing happened. There was no actionability to it.
So that was all of our entries into the AI world. And for organizations, for enterprises, that's a great first step also in the, in the start of their AI journey To that point, there are plenty of ways to engage with a AI and query it, use it as a tool. But what do you need to have in place to be an effective advisor role in, in the environment we're talking about?
Yeah. So one of the things that we've learned in our journey with AI so far, and I think as an industry, we've all learned just bringing a large language model into the organization, not enough, right? It's like it's, that's just, that's the bare minimum entry that you could do.
But the problem with just bringing a large language model into your organization is it doesn't have any context. Those large language models were trained on huge corpus of information. They were targeting the masses of users, where once you get into an organization and you bring AI into an org or into an organization, you're, you're in a particular domain.
You're in a particular realm. So now how do you, how do you utilize this lodge language model that's general purpose for specific domain that you may be in? Well, the way you do that, and what we've learned o over the past, you know, 12 to 18 months, is you have to augment that large language model.
You have to augment it with realtime product data or whatever data, uh, realtime data that your, your organization is playing in. You also have to augment the language model with additional knowledge, whether that's workflow, knowledge, processes knowledge, best practices, knowledge. It's, it's your enterprise knowledge.
Whatever that means to you in your organization, you want to infuse that into your AI system. So then you have the large language model with your enterprise knowledge, with your real time data access, uh, knowledge. It's a combination of all three of those that brings relevance to AI with an organization because it brings relevant context into your organization and the AI perspective.
And when we're using AI advisors, and I agree with you very much about the point of, you know, contextualizing it with information about your organization. Where do you see the fastest value that can be delivered by using, uh, AI advisor in the mainframe teams today? It's definitely in the DevOps space by far that it, it's the DevOps community that has really opened their arms and embraced ai.
And the mainframe environment is no different, whether, you know, from the cloud environment to a distributed environment in that realm, the developers have accepted AI in the mainframe space. There's a, you see a lot of interest, a lot of adoption AI in the, uh, mainframe space. So that is, to me, has progressed us as an industry in the a those working in the AI space, the work that the development com community has done over the past year, 18 months has really accelerated our journey, uh, with ai.
Now, you also started to see other areas starting to get really interested in that. The AI ops space, as an example, is getting, getting a lot of traction now when it comes to, uh, to ai. And we're heavily looking into that within our portfolio, in our AI ops, uh, part of it.
But it's the knowledge capture that is what's gonna play the biggest game here, why we're in this massive transition within the mainframe community. We have a lot of folks heading out towards retirement on the tail end of their careers. How do we capture that knowledge and how do we infuse that into our AI system so that next generation coming in has that experience?
They can lean on that they otherwise would not have that person they would go to, you know, Bob, Bob is not here anymore, but if we were able to capture Bob's knowledge in some way, shape, or form, and put that and infuse that into the AI system so that next generation can lean on the AI system and get access to the information that Bob had, that is game changer in our mainframe space. It's really, it's not only helps get that next generation up to speed, Mitch, but here, he, I I just had a conversation yesterday with someone about this AI on the mainframe is making the mainframe sexy and attractive to that next generation coming outta colleges and universities. We're in the conversation, just like the cloud space and the distributed space when it comes to AI and technology advancements in general.
That is really cool. It very much is a sense of excitement in the mainframe environment, particularly with ai. And I, and, and you have a really good point about that knowledge loss, you know, as folks retire, move on, whatever it might be.
So the next generation of people work in a mainframe, have got that information contextually available to them in ai. I can't think of a better application of ai. Yeah, absolutely.
And we hear that from our customers. Our customers are like, you know, we got decades worth of white papers. We got years and years worth of, uh, video recordings, training material, et cetera.
How do we capture that? How do we, how do we get that into an AI system? And that's something with B-M-C-A-E, uh, assistant that we, we, we took very, very serious, right?
So it's like, well, how do we do this? How do we allow our customers to capture this knowledge that they have and get it infused into B-M-C-A-E assistant and we're delivering to our customers a tool that makes that really easy to do, uh, where they can, uh, manage documents that can manage videos and build out their own knowledge base that B-M-C-M-E assistant would be totally aware of. Now, when we ship our solution, we have the large language model.
We have an a e knowledge base that we ship, the customer can build their knowledge base, and then we have access to all of our product data. So we got all this information that's available to BMC AMY Assistant, that goes back to what we talked about before about what's relevant context to a customer. Yeah.
We can't talk about AI without talking about trust, and I've heard you discuss the importance of explainability. Yeah. Talk more about that.
Love to hear your thoughts about why that's so important. Oh, yeah, yeah, yeah. So with, with ai, of course, you know, trust always comes up in the conversation from the very beginning.
When we all started working with generative ai, that was the, you know, everybody was talking about trust in that regard. It's multiple ways to answer this. You know, we have some responsibility in the solutions that, um, that we provide our customers.
We gotta give the customers insights into what our AI system is doing. We have to connect our AI system into their workflows of processes around auditing, logging, tracing, et cetera, observability in their organization. So how do we do that?
So as an architect, from the very beginning, foundational, we have to be able to capture everything that is happening through our, uh, our AI system through BMC Amy Assistant. From a user typing a prompt to us formulating a response, not only did it has to be auditable, but as much insight as we can provide on why we came about a response has to be clearly articulated. And some of that is clearly articulated back in the product experience.
So when we give a response back, we may cite in that response where we, why we came to this conclusion and what pieces of information led us to the, to this conclusion. But it also has to be totally, uh, traceable and auditable behind the curtain so that the administrators of the AI system have full optics into everything that is happening in that system. It cannot be treated as a closed door system.
So it, it, it's the optic optics into the AI system. It's the auditability, traceability, logging, everything has to be done. So if you go into the system, Mitch, and you are working with BMC Amy Assistant day in and day out, the system administrator has, you know, full trans full transparency into all the things that you've done with the AI system.
And when, and customers have asked us for that from the very beginning, we started working with our customers in this journey that was foremost right at the top of the list. They need to understand what's happening in the system and why. And we've done that.
That's foundational for us. That was something we had to put in at the lowest level of the architecture. That's not an afterthought.
If, if, if you go with that approach is an afterthought, you'll miss things. It has to be done at the ground level of the system. Yeah.
That explainability of transparency is fundamental, that that builds that experience that you start to build that trust with very much so. And it's that trust that's gonna lead us to, to, to the next part of the AI journey beyond the advisor where you look at AI as a true partner in your daily journey. You look at AI agents and agentic AI as a digital workforce doing work, and, but we gotta take those steps and build that trust.
Speaking of taking those steps for organizations that maybe just starting out, thinking about AI readiness, what do you think are the smartest first steps to take? We went through this journey ourselves. So, so we have a pretty wide and deep portfolio, which within, within our BMC Amy, uh, product area.
So we had to go through this exercise. Where do we find true immediate value that we can deliver to our customers? The AI journey was new for us too.
We had to be very capital, very systematic on how we approached it. So the, the way we approached it was, let's just start looking at the low risk, but high value returns that we can give our customers with our AI infusion within our products, within our portfolio. And we've been very, very successful at that.
But one of the key things, even though it's, you know, it may be a, a low risk, high reward type, um, AI enhancement, we wanna be able to also capture and measure that. You have to be able to measure and capture that to make sure you're truly getting your return on your AI investment. This model worked very well.
I, I, I, I, I spoke to other architects about this model. I spoke to customers about this model, and this is a really good entry point model. Start small.
Don't try to drink the ocean, as they say. Start small. Identify those low risk impacts.
You don't want anything that's gonna disrupt you business, uh, you know, day to day. But then just start taking those steps. And before you know it, when your organization gets more and more comfortable with AI and you start building the trust with AI and you're starting to get a good feel of what you can and cannot do with ai, before you know it, you're starting to take on bigger and bigger and bigger challenges with AI and be, when you look in the mirror, you'll see you yourself progressing pretty far pretty quickly with AI when you start that way.
There's some great insights and very sage advice, I think. Anthony, thanks for joining us today. Thanks for being part of this.
Thank you. We really appreciate the BMC software team for sponsoring this kind of event where we can share this information, share some of our experiences, and bring up some of these important questions. So this concludes our first segment that we're doing in its three part series covering AI readiness.
In our second segment, we're gonna be talking about infusing intelligence with ai, using AI as a partner, using generative AI in the mainframe environment. Thanks for joining us. We look forward to seeing you on our next segment.