Techstrong TV July 15, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices
Transcript
Welcome back. Uh, let's talk networking a little bit. So last week on Textron TV and Tech Field Day, you might have seen our networking Field day stream, and I wanted to bring up some of the contents of that networking, not in terms of the companies that pre presented in the products that they talked about, but in terms of what it means for the overall enterprise networking space.
So my colleague, uh, Tom Hollingsworth, who is our networking Field day lead here, uh, organized that event, uh, brought in those companies in those delegates and gave me some ideas here about what we should take away from Networking Field Day in July of 2025. So first off, uh, this event saw two companies talking about the new open source network operating system called Sonic. Now, those are a vis and the aptly named, yes.
It's called Sonic. The company is called Hedgehog. Yeah, yeah, yeah, you can laugh Now.
Um, both of those companies are using this open, open source network operating system. But what Tom found interesting, and what I found interesting as well, is that they're not focused on the capabilities of Sonic so much as the features that they can bring on top of that. In other words, open Source has provided them a platform, and they're taking that platform and doing interesting things with it in terms of offering higher level applications and platforms.
This is, I think, what we see as well. Uh, you know, I mean, we like to talk about Linux, but what we really, we don't really mean the kernel. We really mean all of the cool things that we can do with that kernel by having a powerful open source operating system for servers.
Well, Sonic is that for the network. So that was Tom's first takeaway. Uh, the second takeaway was, of course, the elephant in the room.
HPE was there with, uh, their Aruba networks. Now they're not yet, I think, ready to talk in too much detail about what they're gonna do post Juniper acquisition, but I think HPE is, uh, a little bit on the upswing here in networking. They're pounding their chest a little, uh, Gartner just put them at the top right in the Magic Quadrant, uh, for enterprise networking.
They actually moved Cisco into the Challengers box. They moved them out of the, the leaders, uh, HPE is essentially the networking company to beat, and Juniper was right behind, and now they're one company. So I, I think HPE is feeling pretty good.
Uh, they showed off at Networking Field Day, uh, what they're doing with, uh, Aruba Central. Uh, they talked a lot about, uh, optimism for the future, of course. Uh, now that they're gonna have access to some more incredible network operations and networking technologies, maybe, maybe HPE is the one to watch in networking.
And then finally, uh, the other big takeaway was service assurance. Uh, when it comes to networking, network operating systems, it's not enough to know if something's gone down. You have to have a platform that allows you to see it and react to it and bring it back up.
And that's been the goal, of course, of a lot of the AI based platforms out there. Also, a lot of the IT service management stuff that, uh, you know, you might read about here on, uh, various tech strong sites. Uh, all of these capabilities were really in focus at networking field day.
So let me throw it to the group here. Um, I saw Alan make a little, a little grin here, so I I'll throw it to you first. What's your reaction to the three things that I just brought up?
You know, look, first we saw hardware getting cool again, and now in this age of cloud, all of a sudden network's getting cool again. You know, what's old is new, what's coming next? Elephant bell bottoms, you know, near collared shirts.
I, I don't know, but you know, Stephen, I I, I thought it was interesting in that this was, I think, one of the very first events post the, uh, approval for the Juniper acquisition where HPE got a chance to open the kimono at least a little bit. Yeah. Right.
Absolutely. I'm, I'm, I'm not a hundred percent sure, but I think this might have been the first post-approval public appearance, uh, for HPE. And, you know, there's a little swagger in their step.
Mm-hmm. And, and deservedly so. Right?
I mean, you know, Juniper always represented quality to me. And for as long as I've been involved, and I've known of Juniper, and I, for me, Juniper probably burst on the scene, 98, maybe, something like that. And, you know, they were always the high end, just high end quality.
You know, they, they, their routers, I mean, I always thought their routers were higher end than Cisco's. Those Cisco's would, you know, the bread and butter, you know, if, if if Cisco was Chevy Pontiac Oldsmobile, uh, Juniper was a little bit of a Ferrari, right? So, we'll, we'll see how it goes.
I think the rebranding gives HPE sort of a little bit of independence. It's got its history if you were a Packard, but it isn't saddled with Colin itself. He a Packard.
It's HPE, it's a, it's, that's sort of the, the lift that seems that they've got. I was really fascinated, this UBA has cache in the market, right? Oh, do too.
I mean, when you have wireless wirelessly, well, now it's a great one. Well, yes, Wireless space. They're the, they're really the, the, the leader, um, in terms of features and functions, especially in the campus wireless space.
Yeah, Absolutely. Access management handoff, handoff of signal across the campus. How much is, How much is ai, uh, you know, fabric like hedgehog is pronouncing, like, you know, HP's obviously gonna start to heavily talk about how much this is whitewashing because AI is popular.
How much of it's really needed, uh, in order to, to make this effective. I mean, there's a, you know, there's a lot of, I, I, I, I look at this as a, the way we've always looked at infrastructure, right? There's a handful of, uh, you know, uh, Hogwarts leaders that kind of get this stuff really, really well, and everybody else is kind of like scratching the head going, I have no idea what this stuff is.
I network and storage has always been for me. Those a bastions of, there are people, I, I, I get it a little, even for me, I'm like, you know, I can only go so deep, right? And, and there are people who just live in it.
And so it's easy to kind of express these use cases. Like, oh, if you're training, you need this new fabric. Or if you're doing, you know, um, uh, you know, hosting the inference you need, how much of that is actually real?
And how much of that is, oh, it makes a nice story and nobody understands networking anyway that would buy this. Yeah. Well, you know, I think that what you're hitting on there is, is an interesting aspect.
I think when you look at the data center, networking and storage are a lot harder than they seem. I think a lot of people, uh, that are outside these spaces look at it and they say storage, you know, hard drives, SSDs. How hard could it be?
It's just storage, you know, in networking, you plug in the cable and it works. You know, that's, that's networking, right? And, and these things have proven incredibly difficult, like you said.
I mean, it's hard for somebody to build a challenger to a Juniper or a Cisco without having, you know, all of the engineering that goes into the, the real nuts and bolts that, that are happening below it. That's where the Sonic operating system is coming from. I mean, I really would liken it to Linux except for networking.
And it opens the door to the possibility that some of these challengers could come out with actually competitive products without having to build the entire stack underneath it. You know, we haven't really seen that in storage. I mean, a lot of storage systems are built on Linux, um, and, and, and built on some exist.
But, you know, we really haven't seen a, a dedicated storage operating system in, in that way. And I think that's one thing that has caused storage to be sort of this monoculture. Whereas, you know, in networking, I think there's a lot more excitement.
And then, and then also in networking as well, you gotta think about all the other things that you could do on top of it. So it's not enough just to push packets. You really have to think about what are you doing with this?
How are you building something that's reliable, that's supportable that, that can change and adapt, that can, you know, address problems and, and be secure? I mean, Mitch, to, to the point of, of what you all worked on previously, you know, security in many ways can be seen as an offshoot of networking, or at least a, a cousin of networking, because so many of the problems that were exposed by inter networking have become sort of the defining security issues of our day. Well, you know, I'm, I think there's gonna be a ton of innovation that will happen because of Sonic.
If you feel back, you know, Sonic was created by Microsoft, I think it was the open compute foundation, and now part they donated to the Linux Foundation now, but it, like, like AWS like Google, Microsoft built its own network operating system fabric. They needed something to build Azure data centers, right? All the way down to the switch levels and managing, you know, very large, uh, data centers.
There just wasn't software to do it that level at that capacity. And of the three, I think Jupiter, excuse me, I think, uh, Google's was like Andromeda and Judi Jupiter or something like that. They had some their own versions of this, but Microsoft donated to the Linux Foundation and like Linux, like Kubernetes, like other things, I think we'll see a lot of innovation put on this, because this takes the idea of software defined networking from a vendor solution to an open source solution that now I can build routing, I can build, build switch management, I can build management system monitoring, et cetera.
On top of this nos, the sonic nos. And I, I think we'll see a lot of products build on top of it. Um, including, including storage solutions, including anything you need to manage physically in a data center can be managed through something like a nos.
Hmm, interesting. What, but what, who's going to use it? What is this?
Do you think we'll get a public cloud provider that they all have invested in their own proprietary? Does this become the os for private cloud networking, private cloud? Think about AI networks, you know, if you wanna extend what you can do in the, in your network fabric, um, you know, not, not just the big guys are building big data centers.
Still enterprises are building big data centers too. Not same size of course, but there's still a lot of opportunity for this, especially in a, in a hybrid cloud sense. And I think the degree that that Sonic would work in that environment would be especially valuable.
I don't know that it does, but I think that would be interesting. And yeah, I think that the, the big interesting thing though, as Tom says is, is not sonic itself. It's what people are doing with Sonic.
And the fact that they take this stack and then they, they come out of the gate, instead of having to prove the nuts and bolts capabilities of their platform, they come outta the gate with a proven, uh, proven winner in terms of a network operating system. And then they, and then they do interesting things with it, and then they, you know, they build, you know, advanced features and functions. And it's the same with a lot of this other stuff.
You know, you, you, you build, you know, service assurance and, and security on top of some of, of a platform that is already proven. And you don't have to then spend a lot of time trying to argue that people can trust you with their packets. But that's the beauty of the Linux Foundation type model, right?
It lifts all the, that rising tide lifts all the boats to the same level, right? Table stakes are already done. Everybody's aned in, it's done.
It's what you do from on top of that that separates winners from losers. And, you know, it, it's the same thing, as I say, with a lot of the LF projects, right? The, the competitors, they all start at the same point in the race, right?
They're all, and where they go from there is, you know, Darwinism at play. Uh, and It makes all of us richer. That's the thing about the Linux Foundation that I love, and about the Linux, these Linux, these projects, all of us benefit because the industry is able to work together.
We're all able to get a better product that does more things that does th that, that it's, it's better, but, But the basic things are quality done, and everyone contributes to that basic, so your basic level is solid, right? And you go from there anyway. Hey, well, so Sonic, just one of the things, Sonic is built on a lot of other things.
It's not just by itself. It's built on w and Opera operating system, but it uses containers, it runs Docker, it also runs, uh, Redis for database, or uses Ansible, chef Puppet, a whole bunch of different things that we know in the software world. So it's a different kind of network operating system than we might have seen a networking company build five or 10 years ago.
Cool. Steven, you wanna say something else? I, I guess one more thing that I'll say too is that one of the things that I love about, uh, the Linux Foundation as well is that, you know, it's easy to, to say like, oh, now, you know, standards, the greatest thing about standards is that there's, you can always pick a different one, or, you know, uh, you know, camel is a, is a horse that's built by a committee, you know, those kind of things.
You know, they're very focused on actually making things that will work and function, not just sort of dreaming up some new pie in the sky thing. They're, they're interested in building something that works. And I love that aspect specifically of things like Sonic and Linux.
It's all about making it work, not, not just making another standard that nobody's gonna adopt. Fair enough. Hey, I just wanna mention before closing out that Networking Field Day is available on the Tech Field Day YouTube site, I imagine.
Yes, Steven. Yep. Absolutely.
And as well, it, is it on Techstrong TV in OTT, or Yes. Yep. Yep.
Grab it there as well. OTT on the Textron TV app. By the way, that app is in Google Play and Apple iOS store and stuff.
It's, I mean, we're watching it on TV here. Absolutely. It's also available on Apple TV and Roku and Amazon Fire.
So have a, have a, have a go at it. Alright. Hey, that's gonna wrap our show for Textron Gang, this fine Tuesday.
Steven, JP Mitch, thanks for joining. Thank you for joining. We have a full text Drunk TV lineup coming up immediately following today's show, as usual.
And we'll be back tomorrow with some more gang members and some great stuff to talk about. Until then, know this Alan Hummel. Have a great day, everyone.
We're out. Hey everyone, it's Alan Hummel for another Techstrong TV interview. I have a first time guest on my show or on our show today.
He's actually the CEO of a company called Cy, that's spelled CYE. His name is Ruben, a Ron, if I mispronounce, I apologize. We're gonna call him Ruby.
Anyway, Ruby, welcome, welcome to Tech Drunk tv. It's great to have you on here. Oh, thank you for having me.
My pleasure. So, as I mentioned, you are the, the CEO, uh, founder of, of, uh, s you know, I've interviewed, I've been a founder four or five times, co-founder, and, um, it's been a long career, but, you know, and I've interviewed hundreds, if not thousands, everyone I've ever interviewed who's a founder, is passionate about what they're doing, why, why they found it. No one wakes up in the morning and says, eh, I feel like finding founding a company today.
Right. You're driven. Talk to us about kind your journey and where your passion came from, from to, to found Sai.
That, that's a very good question. So, you know, I grew up in a small city in Israel, uh, called aco. If you ever been in Israel, then that's the, you know, Aco Sure, The best place to eat humus in, in Israel.
So, uh, definitely to visit, um, they're coming from a, let's say, a very tough neighborhood. You know, you, you need to use your capabilities, dedication, um, discipline, and, uh, let's say the will to succeed in order to move out from there and take yourself to, let's say, a success journey that changes something In order to do that. I was drafted, uh, to one of the technology units in the, of the IDFA cybersecurity unit.
Um, and I was in an academic journey specific journey that, uh, is actually for excellent, uh, let's say students in the high school. They take you for the university first. I've done my b science and m science.
They, again, computer science and math joined the cybersecurity unit. And there I got really, uh, the mission that, uh, I was privileged to get and that to build the Israeli red team. That was the first time that the Israeli army decided we are going to consolidate capabilities and going to do that as a strategic capability to use offensive defense, meaning offensive capabilities to defend ourselves by actually testing as adversaries our own systems, infrastructures and so on.
So, I actually developed a red team capabilities and build this specific team at the, at the time, uh, the name was Section 21, actually, it's still the name, section 21 in the Israeli army, the Israeli Red Team. The passion that I started to build from there was really based on how impactful you can be by just providing visibility to the organization or to the, the relevant unit by understanding where the weaknesses are. That's sounds like a basic step, but that's a very important step in the process.
Spending seven years of, uh, of my time in the Army, that was an amazing journey, right? I really, I've done things there that, you know, you couldn't even imagine to do in an environment that is outside of Army or playing with toys, let's call it this way, that are so expensive, you know, F 35, for example, right? That's a very expensive toy to play with, but it's absolute, yeah, you still need to test that.
This, uh, this toy, as I mentioned before, is, is cybersecurity resilient, right? How, how do you know that, uh, that that's something that, uh, uh, that can be, uh, let's say resilient in case of, um, of a need like we recently had, uh, in the Iranian situation that we had in Israel. So that's, that's of course important.
Now, from there, in 2012, um, I left the army. I, after finalizing my duty and a little bit more than that, um, and I decided to continue to earn more private route from my point of view. And, um, this visibility concept came back over and over again.
If I thought that in the Army, that was a big problem in the commercial world, that was a huge problem, right? Because everything in the commercial world was really lagging behind. I'm talking the he 20 12th.
So I founded sai, started as a professional services company. At the beginning, started to learn the industry, and here's the point, hearing the feedback from customers on a continuous basis, and they managed to work with the, the largest and greatest companies worldwide. And you hear continuous feedback first, great.
Now we know, we understand where is our risk? Then you're starting to get questions that you don't really have answers for. How do we know what to prioritize?
So it's great now that we, we know what's, what's wrong, what is more important to mitigate? Is it our application? Is it our network?
Is it our cloud? That's a good question. In those specific environments, what is more important there?
How do we know that our money that we invest is really going to the right places? By the way, one of the things that you, you see in the report that, uh, we just, uh, uh, um, share the, uh, the majority report you see there very clearly that more budget doesn't necessarily mean more security. How can it be?
It's very, I mean, it sounds simple, but we found that, uh, that that's something that really requires real understanding of the situation and contextualized understanding of the organization. From there, we built a platform. That was the first time that we decided to build a platform.
That was the year that, I'm talking about 2019 already, right? Seven years we've decided to build our platform. So here is the thing, the platform was built from mainly customer feedback.
So we had a lot of feedback being a professional services company, and we started to build a platform that will serve our customers with their needs. We started to think about the concept of visibility translated to business impact communicated to management and different stakeholders, because I think that's key in what we do. And above all, we wanted to put a lot of emphasis on how you do that, not only in qualitative, uh, manner, but also to do that in quantitative ways.
So at the moment, this is the side promise. What we do at the moment, we provide you with a platform that gives you the option to understand where your risk lies. What is the threat profile of your organization, meaning what types of attackers are relevant to your organization, what do you need to protect, and how those are connected with your own vulnerabilities, weaknesses, gaps, and so on.
That creates a very clear map for your organization. This map is then being quantified, meaning we put dollar value around each and every one of your risks. Meaning, if you are going to have a ransomware attack, it's going to cost you X.
If you are going to have SQL injection and your environment is going to steal data from your databases, it's going to cost you. Why? Now when you understand it and you are able to articulate that in this way, you are able to communicate it to your management, and you are able, the most important thing, you are able to make smart decisions based on the data.
So our platform today allows you, as I mentioned before, to get organizational avail visibility around risk and threat, then quantify that to business, the, uh, to business risk in dollar value terms and likelihood analysis, of course. And on top of that, we are optimizing, and that's maybe the most important thing. We are optimizing the mitigation plan based on a mathematical algorithm that we've developed to really get the highest return on investment on every dollar that you invest.
And this is the concept of either platform today, we call it continuous exposure management platform. Uh, that's, uh, the new buzzword, buzzword out there. That's exactly what we did.
Excellent. You know what, we didn't mention the website name. Yes.
com, this is our website, uh, more than welcome, uh, to visit there. And you are always able, uh, to, uh, uh, reach out directly from the website or to us in any other way, LinkedIn or anything. Anything works.
Excellent. Very good. And, And Ruby, you know, congratulations.
Uh, what a, what a, a career, a background. Of course, we look, I, I've been in security myself, how we call it cybersecurity. I've been in cyber 25, 30 years myself, right?
And met a lot of people from 8,200 and, you know, the other Israeli, uh, cyber commands, you know, they do great work. But really, you, you took what you learned there. You applied it here to the commercial and to the commercial space.
And as you said, if it was bad in the military, I, I, I sold to the US DOD for a very long time. One of the companies I started, I know what goes into what we call military grade. Yes, right.
Or information assurance. Uh, good for you. Um, you guys recently came out with a maturity report for 2025, and look, cybersecurity, maturity, resilience, you know, the, the world is such a different place from when you first went into the army from when you first left in 2012.
We didn't have ai, you know, staring us in the face at the time the way it is now. Maybe we had ML kind of stuff. Yep.
Mm-hmm. You know, with everything with AgTech and, and, you know, it's a double-edged sword, good and bad. Yeah.
Fibers come a long way. Talk to us about this year's report and maybe some key trends or findings that our audience should be aware of. So, first of all, I think that, uh, this is a must read rep, right?
Because it really encapsulates a lot of the information that we've collected from different parts of the industry. Uh, you have it, uh, per vertical, you have it per country, your location, and a lot of insights. But here are the key takeaways.
Number one, from my point of view. And that's maybe if there is one thing to remember from this interview, is that the basic hygiene of the organization is still the most important thing. Account management, passwords, multifactor authentication, um, um, patch management, um, access control in the, in the basic environment to the internet.
Those are basic items, the basic items that you expect most organizations to already have in place. And it's still not there. Most of the items, most of the weaknesses or actual incidents that we've see, uh, we've seen out there either started or leveraged one of those items as part of the process.
And that's something that is extremely important. Second thing that I will say, and this is extremely important, higher budget doesn't necessarily mean more security. It sounds maybe logical or it sounds clear when you, when you hear that, you say, oh, okay, that makes sense.
But we say that the correlation between smart decision making or let's say data decision making to more security is much more, it's, it's much higher than the budget itself. And then you find situations like the US where there is no doubt that the US invest maybe the most worldwide in cybersecurity. It's the most developed economy and most mature market from cybersecurity tooling perspective.
However, it's very clear to see that the investment there is not always that effective. So a lot of investment not necessarily effective. Of course, we need to, I, I Would go one further, Ruby.
Yeah. I think, I think throwing money at it is the solution, right? And it, and, and quite frankly, this has been this way in cyber for as long as I've been in cyber, I wanna buy it.
There's a new magic bullet out. This year's magic bullet is only a hundred thousand. Next year's magic bullet is 250.
But at some point, the board gets tired of paying for the magic bullets. Yep. Because these magic bullets don't work, because there is no magic bullet.
And, and I would, and this is based on my own experience, I would say forcing people to do with less, to be more creative, to be more innovative, to be more, have more dirt under your fingernails of, of the cyber, because you don't have money to just buy magic bullets might be a better, a better solution, a better method, a better way of looking at it. That's spot on. Because from my point of view, you know, one of the, the things that you see in the report as well is that we've seen that the number of tools in the organization increased significantly in the last years.
And today, the average number for a mid-size organization is 76 cybersecurity tools in the organization here, the number 76, it's crazy. I know Now, as you mentioned, tool is not a capability. So the fact that you have another tool doesn't mean that the capabilities of the tools are really fully, let's say, leveraged or utilized.
And that's something extremely important to mention. So, yeah, I, I'm totally with you there. And that's something that we see as a trend in the industry.
And you know, the point is that sometimes it's the easy solution to buy another tool, but it's not always the smart solution. So definitely what you just said, understanding, and it all starts with, again, I'm going back to visibility. If you understand where the risk is, you are able to understand what the solution should be, right?
And the solution is not always a tool. Sometimes it's capabilities, sometimes it's a skill, sometimes it's a process or utilizing an existing, an existing tool already. You don't need a new one.
You just need to change configuration in existing one. That's something that happens quite a lot. Yeah.
You get a lot of shelfware, they buy stuff, and then three months later, I look in my time, I've seen they, they've spent significant money and then decided not to use it before they even used it. It never, you know, it never got unwrapped. Yeah.
It's Crazy. That's something, something that we see. And by the way, you know, our statistics shows this is our, uh, our investigation that we've done.
More than 70% of organizations are actually reporting themselves that they are very incon uncomfortable with the level of visibility that they have into the organizational risk and third profile, and how they are actually covering for that. There are other statistics out there, uh, uh, Vanta, for example, is saying 75%, but that's more or less aligned to what we are doing. Another thing that I would say, and uh, that's also something that we found very concerning, uh, and that's going, that's going a little bit more to the resilience part.
Let's assume that something already happened in your organization, which, you know, statistically, world Economic Forum just published 29%, uh, likelihood for every organization worldwide to be attacked. That means every three and a half years, more or less, you should expect some kind of cybersecurity incident in your organization. What do you do about it?
That's a good question. But we've seen that more than 50% of the organizations, they don't have, let's say, a strong or any business continuity plan in place. Not how to react to an incident.
What is the playbook? Who needs to do what? Who is communicating the basic thing, the business continuity plan for recovery in case of a cybersecurity related incident?
That's basic. It's much cheaper, by the way, than buying another tool. And still it's not in place.
And that's something that we see that the correlation between this capability to more resilient is really, really there. Um, there are other, um, interesting insights there. For example, third party risk is still a big thing.
We need a paradigm shift there, because I think that the scoring concept that we have out there, Hey, we are evaluating all of our, uh, vendors in a way, uh, that is, uh, on some kind of scaling. Uh, okay, this is a 10, this is a nine. That's not good enough.
You need to understand how those vendors, what the risk from the vendor is, what is the risk that is relevant to you? What is the impact to your organization coming from the vendor? Those are important.
And we've seen also maybe less thing that I say, a very strong correlation between, um, CO in the organization, someone that is the owner, let's say. It's not the CSO all by definition, but the ownership of, of cybersecurity that is now also going to the board level. That's something that changes a lot.
Um, those are the main insights, but the other things Very interesting. No, no, I get it. I, and we're gonna mention, let me dig into those two, then I wanna give the URL for this.
Look, there is, as you know, there are Sue CISOs in there is CISOs. Yep. Right?
Um, some CISOs, some CISO's job is to translate security to business, right? So that the board understands the risk, the impact and, and what all those bits and bytes means, right? Other CSOs, they're glorified security architect admins, right?
Mm-hmm. And they're really, though, they may have a seat at the table, they're like a junior seat at the table, if you will. Right?
Right. And, and then there are some CISOs, I see it, especially in, in security vendors, it's almost a marketing position. Yep.
You talking to customers about their security, and I, I, you know, it, it, it's a, it's a hard thing. I I do think, you know, it always comes down to people, process and technology, right? And in security, we've spent a lot of time on technology at the, at the expense of people and processes.
So I'm not, to me, these, these findings are, you know, what we see out in the real world out here, right? So I, I should mention that if anyone who wants the report, the, it's the 2025 Global Cybersecurity maturity report. com/resources guides dash eba.
It's a long URL, we'll put it in the thing. But Ruby, I'm sure if someone Googles the 2025 Global Cybersecurity maturity report from s it'll come up. And there's probably In our homepage, you, you have a link directly from The home.
I, right off the homepage is the easiest way to do it. com. Ruby, thank you for what you're doing.
Keep up the great work. Don't, don't wait till next year's report to come back on here. Keep us, keep us posted to come in and give a report.
Okay? Would Love to speak with you again. Thank you so much for your time.
All righty. S cy Security, CYE here on text drum tv. We'll take a break.
We'll be back. Hey guys, thanks for the throw. We're here with JP Salinas, who's vice president of business Development for Yala Soft, and he's joined by Rolando Laura, who's a staff engineer and software engineer who's also leading up their agentic AI push.
And we're talking about the impact that AI is gonna have on the need for junior developers. JP, welcome the show. Hi, Mike.
Thank you for having us on. All right, Rolando, you too. How are you?
I'm good, thank you, meek. All right, jp, let's start with you because there is this ongoing debate about, um, well, just how much are we gonna need junior developers going forward? 'cause the old guard will say that I don't have to assign out tasks to junior developers.
I'm just going to give that to some sort of agentic ai. And I also know that you're the CEO of your company's university program. So you see some of this firsthand, but what's going on?
Yeah, I mean, we have to confront this, uh, this truth. Now, the junior developers are gonna soon become obsolete, and, and we understand it. I mean, uh, coming from a 20 year, um, uh, company in the industry, we, we understand the significant impact that AI is gonna have in, in junior developers.
It has always been difficult for junior developers to get into their, uh, first jobs in the high tech industry, but now it's gonna become even, even worse. Um, it was mainly difficult for them because there's a huge gap between the academy and the industry in the educational models. So, uh, engineers graduating from college where maybe like 20, 30% job ready when they graduated.
And now the same agents that they're using to help them in their assignments in, in the university, these agents are gonna compete for their first, uh, jobs as well. So if you think of it, um, when you get a junior developer in your team, you give them tasks, I mean, clear instructions, low risk tasks, uh, things that they can start, I mean, uh, working on without creating, uh, much impact. And that's exactly what, right now people are dedicating to AI agents.
So that's gonna be a tough situation for junior developers. Now, Rolanda, you are neither too old, nor too young. So you're kind of in the middle of this conversation, but you're working on these projects.
But I will talk to some junior developers and they'll say the exact opposite. They'll say, this stuff is great. It enables me as a young developer to do all kinds of things that I probably wouldn't have been able to do on my own without some sort of specialist.
And basically they're saying, Hey, boomer, move over. Yes. Um, absolutely, Mike.
Um, well, I'm, um, we were having like, uh, a lot of experience, um, with the real teams, uh, that are using artificial intelligence. And, uh, we can see that a lot of the buzz, for example, around vibe coding, um, it's, uh, real, uh, it is a time when you can actually, uh, do a lot of stuff without, uh, uh, the need of grasping, uh, language skills and, uh, learning how to code. And, um, we, for example, in larger projects, sometimes legacy projects, we use a lot of five coding, like, uh, product owners and, uh, people that are not exactly, developers are, are using it, uh, to communicate ideas because they can prototype something, um, that maybe does not work at a hundred percent, but they can communicate an idea.
But, um, in our case, uh, I'm looking at senior developers that are using and, uh, not necessarily pipe coding, but, uh, agentic ai. And, um, they are able to grasp like, uh, really complex tasks and features, but the way they, they are using the AI is completely different. Uh, they, they spent like, um, most of the time reviewing code, but, uh, they are able to generate, uh, different kind of solutions per day.
So it is a tool that allow them to explore the solution space and, uh, pick up the best solution. So in, in that case, for senior developers, we are not looking like at, uh, productivity gains in terms of, uh, how much they can do per day. But, uh, there is an improving quality because they can deliver maybe the same feature, one feature per day, but, um, with a lot more quality because they are able to prototype a lot of ideas and solutions.
And, um, in order for junior developers to do that, um, they, they do need to have a bit more of experience, and they need to have the skills. So that's what we are trying to figure out how we can, um, teach those skills to, to the students. Jp, do you think that maybe there's room for junior developers in this sense, to Rolando's point, we're gonna see a lot of vibe coding, or that may not be done by professional developers or people with any kind of developer training, so I don't think the senior developers want to clean up that mess.
So maybe the junior developers can go in and clean up that mess. Yeah, potentially. But I think we're taking it from a different angle in, I mean, this is an opportunity for us to really try to graduate mid-level developers from college.
So the junior tag is just gonna be removed completely if we train them well in the university, I mean, they will graduate, uh, as mid-level developers with the maturity and experience and the software development lifecycle exposure, right? In college. So, and they're gonna be exposed to AI to use it effectively, efficiently, and responsibly and safely for their teams.
So that's kind of our approach. I mean, okay, we're junior developers are gonna become obsolete. Okay, we take it, but we're gonna graduate mid-level developers then right from college.
So, Rolando, going back in time to when you were a student, um, what did you learn in college and then when you came into work, how big a gap was that between when you could actually be useful for the company that was hiring you? There was actually a, a big gap. Uh, I, I spent a lot of time programming in college, and, uh, my thesis also, um, was related to a problem that was really difficult to solve.
So when, when I get to the industry, and actually my first job was, uh, a jealous of, so I, I was like, um, very confident that, uh, my skills were, were going, going to be enough for, for the job. But, um, when I started to deal with real world problems, that's what where my perspective, uh, shifted a bit because, uh, and, and I think that is happening now because, uh, people, uh, is, um, judging all these AI tools mostly on, on a small or, or hobby projects, and they perform extremely well. But, um, if you look at the, at a company that has a legacy project that has huge code base and a very complex infrastructure and deployment, um, actually these tools are, are not able to perform that well in that kind of environment.
And I, I think the same happened to me when, when I came for my first job, that, uh, it took me a while to understand everything and, uh, and make sure that, for example, uh, a small fix that I could enter as a junior developer did not end up, uh, breaking something critical. So it was really difficult, but I think that now it is a lot easier for, for this new junior developer to join a company that is working on large projects because a, actually these tools are very good for that. They can help you understand a large code base and, and the inception and the put strap, uh, time in a project, I think it's much, much faster.
So it, it's a, a great opportunity that we have, um, to actually, uh, change the, the role of the junior developer a little bit and, uh, and make, make them fit in, in this kind of projects. They, they will perform much better that we did at that time. So jp, how does the university program need to change then to turn out more mid-level developers versus junior developers?
That's a great question. We take this, this approach, we have a PBL, which is very common project-based learning, but the problem we're seeing is who's designing these problems? When we get interns from throughout South America or even the us, we get senior students that never work in, uh, in a team, really with a common code repository or using methodologies.
So they, they work in several projects, but on their own. So we also take the approach of PBL, uh, from the start, but we have a close connection with the industry thanks to JA of, so really we really mimic, uh, real case scenarios and challenges. We create these projects for them that will expose them to the complete software development life cycle incrementally throughout the terms in the program.
But they will get to experience the whole software development life cycle that is learning to work in teams communication with which is overlooked, uh, uh, fairly enough in, in the, in, in the education industry, um, methodologies, problem solving judgment, um, is starting to create more challenging pro uh, projects as they go as well. And having active engineers teaching them on how to resolve this problem, guiding them on how to resolve this problem is, is key. Our faculty model has professors, uh, of record that have their masters and years of years of experience in the academy, but it's also mandatory to have faculty practitioners, which are active engineers in the industry, given their time to train the future, uh, developers as well.
So I think this point for us was really key. And also the curricula was designed, but uh, by an architect as a software architect, uh, closely monitored by our chief academic officers as, uh, as well. But I mean, this combination of academy and industry throughout the program, I think is key.
Rolando, what is the future of application development in the age of AI agents? And I'm asking the question because some folks say, we're gonna have this small army of AI agents that are just standing by, and every time I wanna do something, one of them will pop up and say, pick me, pick me, pick me. And other folks are saying, I'm gonna have some sort of master, super agent that manages all the other agents, and it's gonna be more like the head butler, and I might even give this thing a name.
What is this gonna look like? Yes. Uh, I, I think it, it'll be a combination of both.
But, um, what I'm looking at is that, um, there has been like, like a lot of talk about prompt engineering, but um, there is a term that, uh, it, it, it's gaining traction that is, uh, context engineering. And, uh, I think that, uh, senior developers are starting to work that way. And that is basically, um, try to get an agent or, or a set of agents to, to solve a difficult problem in one shot.
So in instead of iterating through instructions and, and, and trying to get to a goal, um, through many iterations, they are, uh, trying to think in terms of, uh, what is the best context I can give to my agent or my agents to solve this problem? And, uh, this is very related to, uh, systems thinking and, uh, and, and abstraction in a way that, uh, future engineers will abstract a lot of the information that needs to be needed by the agent to solve the problem. And they will, uh, let the agents work.
Uh, in our case, uh, we are usually working with, uh, one agent or maybe two, or maybe conducting like deep research on other topics, uh, that we also send agents to do deep research. And it's very useful. So in the, in the future, you, you will, you will have that, but there, there, there will be like other use cases that, uh, maybe we'll be more, um, targeted towards non-technical users that are trying to, um, promote an idea like innovators that want to release an idea to the market.
And maybe that idea is not that complex in terms of, um, implementation. So these, uh, creative people, innovators will, will probably have like one master agent that will take care of everything and come back with the result. So I, I, I can see both, uh, of the things happening.
Jp, last question. What's your best advice to developers and the people who are trying to hire him these days? 'cause nobody's quite sure what the future look like.
Uh, sure. I mean, uh, there's obviously, um, gonna be room for developers for, for a long time, so don't, don't get scared about AI and, and losing, I mean, um, the, the, this profession in, in the short term, I mean, that's, uh, not gonna happen. I mean, they need to start educating themselves about AI and really understanding AI's capabilities.
I mean, there's a lot of buzz around, um, productivity gains like, or, or Orlando was saying, but is it really that much of an impact in the productivity or is it more like in the quality of the code that you're gonna be able to produce thanks to AI as well? And there's different levels of AI that you can be exposed to, like augmentation, collaborating with AI in resolving problems, understanding problems and concepts, discussing about solutions, and then automation, delegating pieces of tasks to these, uh, agents, like cool reviews, debugging, creating the release notes and things that take time from you. And then lastly, when could you really use agency, which is when you delegate entirely a whole prototype to the agent.
So it really depends on what task you are, um, confronting. And, uh, you need to be smart on how you're gonna use the different levels of ai, uh, to, to do your, to do your job. Yeah.
All right, folks. Well, the one thing that is for certain is there's no going back. So we might as well all go forward together and see what happens next.
Exactly, yes. And guys, thanks for being on the show. All thank you, Mike was a pleasure.
And back, you guys in the studio. My name is Leslie Grande, and I am not a cybersecurity expert, so you all wonder what the heck are you doing here? Talking to me, listening to me.
Uh, I am, however, an expert on creative problem solving and creative thinking techniques. And I spent the last year and a half writing the book that Mark was telling you about doing, uh, a lot of research on what cognitive research has been done, and also really understanding how to help people access their creative capacity to solve problems. And I think a lot of us, uh, suffer from lacking, uh, confidence in our creative abilities.
And so my mission is really to inspire people to see that everyone is creative. Creativity is everyone's superpower. And the real question is how do you leverage it?
How do you expand it, right? And how does it help you solve problems in your daily life, whether it's personal or professional. A little just about my background, besides being an author, I, uh, spent over 25 years as a product executive at companies like Apple and Amazon Best Buy, discovery Networks and T-Mobile, where I launched the first Android phone with Google.
And, uh, through that process, I, uh, really gravitated towards zero to one products where really there's a lot of ambiguity and a lot of difficulty in understanding the, the market and the customer need. And so really sourcing the right opportunity and creating a product that really excels on product market fit. But that skill, that technique is also really important for any kind of problem that you face.
And that's what I'm here to tell you today, are some techniques that you can use when you're really doing some risk planning to really expand your capacity to think big around what could prevail and, uh, what you might face. Uh, my, uh, relationship with the University of Washington is that I, uh, co-created an executive education program called the Product Management Leadership Accelerator. And our next cohort starts in June.
And, uh, it's really a, a, a pleasure at this stage in my career to, to inspire and hopefully, uh, inspire people to reach their full creative capacity. I wanna kind of give you a, a little bit of why are we talking about the stoic premeditation of evils as it relates to risk planning? How many of you are familiar with the premeditation of evils?
Oh, good. This is the best answer I could hope for, because hopefully you're gonna walk outta here learning something new. Now, the stoics believe that the best way to prepare for success is to imagine failure cases, to understand the things that are improbable and unlikely to occur and what might cause them.
And not so much to imagine the things you know and what could happen with the known, but to explore the unknown, the place that you're most uncomfortable, the place where you have least information to really consider your expertise, the thing you lean into when you lean into expert, think you avoid those things that are uncomfortable, you are more likely to stay in the zone where you can perform well, but you will also overlook those things that creative hackers and attackers are looking to do, which is find their way in, in a place you don't expect. So this is a famous quote from Seneca, and if you keep this in mind, you remember, the things you don't pay attention to are the things that could be most catastrophic. And that's what the premeditation of evils is, is meant to support in your planning.
So when you think about it, these are the kind of questions that you would ask. And why do you ask these questions? Well, you wanna be immune to surprises.
You wanna actually believe that anything could happen. And unless you think about it and explore it, you won't be prepared for it. And the stoics really believe in robust preparedness.
This is not about rumination. This is not about catastrophizing. This is really about believing that you will not be surprised when something occurs and you are not prepared to attack it back.
And so this is really important. These are the things where when we talk about what does a premeditation of evils do, it explores the worst case scenarios in a way that gives us confidence that we're ready for them. So the value of a premeditation of evil's experience is that it's a structured form of foresight.
It's giving you a way to look forward without actually worrying about what you have or what you've done. It creates this idea that the model today may not be adequate for things you hadn't considered. So when we think about considering intentionally contradictory ideas, that's a place where most of us get uncomfortable when we have to believe that something could be secure and insecure at the same time, it's very concerning.
How is that possible? How will I ever know we're protected? If I can believe that something that is secure can also be insecure?
But unless you think that way, you will not be prepared should someone find a vulnerability in what you think is a secure system. So your strategy has to intentionally include things that seem like they contradict your basic assumptions. And the best part of the premeditation of evils is that it really gives you the confidence that you can be cognitively flexible when something you didn't expect arises.
Most people are so rigid and rigorous that it's hard to leave room for the unexpected. But what's really healthy is when you acknowledge the unexpected could exist and you have strength and confidence in your capacity to handle it, right? The idea of stoic is, I've seen this before and I'm not helpless, or I've considered this possibility and I'm prepared.
So that's why premeditation peoples work so well for cybersecurity. 'cause even the most hardened security can go sideways if you're limiting your focus to what is known. Some pessimism kind of can circle around this topic, and people can think that they're dwelling on the negative, they're catastrophizing, they're imagining the worst case scenario.
But instead, this exercise is really about the action that occurs when something bad happens. It's really meant to inform and trigger behaviors that are emotionally controlled and really robust in how much of you is available to attack the problem. If you're worried about what you don't know, if you're concerned about the constant ideas that you have of way things, the way things can go wrong, you're more than likely not going to act in a healthy manner when that happens.
And so what you wanna do is stay aware of the possibility that something could go south at the same time that you're managing your expectations, that these things are, are, are plans that we need to make to, to really create obstacles from them having the impact that we don't want them to have. So the negativity gets controlled by us facing our fears head on. There's a lot of, uh, concern that when you spend time wondering about what could go wrong, you waste time in the corners in the fringes.
And the thing about that is with the premeditation of evils, you wanna start with the broadest lens possible. And then you wanna ask, when you've captured all of those things, what could have the greatest impact? And it's the impact that will help you prioritize.
And it may be that thing on the fringe that only once in a blue moon happens, but when it does, everything goes down right? And that ca that is a catastrophe you want to avoid. So one of the things that's really important is that you focus on the assumptions around that catastrophe, and what are those assumptions that you can control and what can you manage against The idea that it's broad is only in the start.
Because if you let yourself ramble around and, and look at all of these things and don't have a structure for framing up which ones you attack, which ones you prioritize, which ones you investigate and explore, second and third level consequences of, then it will be a useless exercise that will rapidly turn into rumination of the, of the evils that could befall you without taking action. And what you have to remember is that premeditation of evils is about taking action. So what makes generative AI such a good partner for this type of risk planning?
Well, the best thing about generative AI is it's not attached to any of your ideas. And by the way, not attached to any of its own ideas. Either the idea that generative AI can provoke some thoughts is actually the point.
Even if they're outrageous or outlandish or unbelievable, the idea that they're bringing forth ideas, these tools are able to get you to think about these things, is likely to overcome the group in consensus thinking that happens within an organization. You're gonna have a voice that isn't worried about getting promoted, that isn't worried about being wrong. It isn't worried about being unpopular, it isn't worried about its career.
So it's going to give you the impression or the idea with the least amount of baggage, giving you the opportunity to assess it without any emotion. Humans have a really hard time doing cross-cutting to find patterns. It's really hard for the human brain to see patterns and things that are not obviously associated.
This is where gener generative AI excels, right? Being able to connect the dots between how something in biodynamics works and how it might actually help manufacturing, right? That's hard for people to make those connections as humans, but it's easy for generative AI to do it.
We all know generative AI is nothing if not speedy, right? It's, it's always feeling like it's cutting, getting back to you with a wealth of information in a short amount of time. And, and what's great about that is when you're going broad and your lens is broad, you want the largest amount of things to come back for you to prioritize and consider.
But then you also want the depth. You wanna be able to, to mine the depths of one of those, those ideas, and look at second or third consequences and go deep to see whether there's a, there, there, or whether it just on the surface looks like it's a problem you should solve. And so, again, generative AI won't be offended if you ask for explanations, if you challenge its thoughts, if you actually come up with a contrary opinion and ask it to debate why your thoughts are not as strong as the, uh, proposal it made.
It's a fabulous thought partner from that standpoint. And the best part of it is we all come with learned experiences, lived experiences, intuition, history, all of the emotions that we have, all the goals that we have. Generative AI has none of that, right?
It doesn't have the bias of what was done before, and it doesn't have the bias of what your boss said, and it doesn't have the bias of what's considered normal. In fact, in many cases, that's what's problematic about generative ai, is it doesn't always have context as to what's culturally normative or what's socially acceptable. But in this scenario, this is a, this is an asset.
This is a really valuable asset for creative thinking, is to be less attached to the idea in order to be more open to the prospect of what it brings with it. And I think that's the thing that really makes generative AI the best partner for a premeditation of evils exercise. So how do you look for threats that you don't expect?
What are the ways that you go about it? Well, part of the way that you do it is you look sideways. You don't look linear.
You don't look at cause and effect. You look at other things that are to the left and to the right. You look inside as much as outside you look forward, but you also look backwards to forwards, right?
The idea that there is no linear approach to how you solve this problem is core to working with ai, because it can be a crutch for you to let go of that standard way of thinking, cause and effect problem solution. Because what may happen is the problem may not be the problem. It may be a symptom of a problem.
And with generative ai, you can mine the depths to see whether that symptom actually has a root problem that's bigger than the thing you see or observe. And, and, and with no offense for you challenging whether or not that's actually the most important thing. So there are three types of contradictory thinking that really support a premeditation of evils exercise.
So paradoxical thinking, we've all heard of things like bittersweet. My kids go off to college, and it's bittersweet. That means both things can be true.
It, it can be sad, and it can be happy. I can be depressed and I can be proud, right? Things can exist.
Both things can be true. So balancing tensions is where you find some interesting moments because not everything is clean. Not everything is black or white.
The idea that both things can be true can muddy the waters of your view, and it allows AI to say, oh, I have boundaries now, so I have to believe this is true, and I have to believe this is true. And then I have to navigate within those boundaries. Again, that's a little bit difficult for the human brain to do.
Opposite thinking is one of my favorite. If you're a Seinfeld, uh, fan, you probably remember the fabulous episode where opposite George did everything the exact opposite way, and everything worked out beautifully as a result, right? The thing is, doing things the other way does result in different outcomes.
So working from back to front might actually cause you to think about an obstacle that could actually prevent you from being successful. So opposite thinking is really important. This is where you flip your assumption if, if I think white is black and now I think black is white, what does that mean?
Why would I change how I think about it? Well, partly because to some people who don't see the problem the way I do, they may be navigating it that way. And it helps me to recognize that everyone doesn't approach a problem the way I do.
And so, opposite thinking is a really helpful tool to actually flip my assumptions. And again, premeditation of evil really focuses on faulty assumptions, assumptions that could lead to your failure. Inversion thinking is really awesome because it's what what does failure look like?
How do I create a failure scenario? I'll give you two quick stories on this. One is, uh, um, Charlie Munger, who is the COO of Berkshire Hathaway.
He tells the story that this is what his life, uh, strategy has always been. And he learned it when he was a weather forecaster in World War ii, trying to keep pilots from crashing. And he didn't know anything about flying, and he didn't know anything about weather.
But in World War ii, you got assigned a job and you just kind of had to go figure it out and do it. So what he decided to do was go ask all the pilots the conditions that would cause 'em to crash. Just tell me those, and those are the only things I'm gonna look for, because everything else means you're okay.
So if I can go figure out what failure looks like to the pilots, I will actually then plan for success because I will avoid all of those circumstances. When I started my career, I started in the film industry before I moved into technology, and I moved to California and moved to Hollywood, and I didn't know anybody. And I was not an EPO baby, and I had no idea how to get a job done, but my parents thought it was gonna be the worst idea ever.
And in order for them to be proven wrong, I just had to avoid failure. I had to look at the circumstance where I would fail and do everything opposite of that to succeed take jobs I didn't want in order to get the next job. I did meet people that I didn't think on the face value would give me a connection, who ultimately were two connections away from somebody who got me a better job.
The idea that I was open to things that would avoid failure really gave me a key to success. And ultimately, I made it to the Director's Guild and, and worked on films like The Abyss and Terminator two and Tremors. And so I had a career, but I built a career on the back of not wanting to fail, not wanting to have a case where I couldn't get a job or I couldn't find someone who could hire me.
So three practices to to consider when you're doing this, uh, kind of an exercise. One of them is, you know, we, we've all been trained to do prompt engineering. And prompt engineering really forces us to be more specific and put in a lot of context and a lot of detail, and be really helpful to our AI partner by giving them as much information as we can.
That's actually the opposite of what you should be doing in a premeditation of evils exercise. You should really start as broad as you possibly can. And how do you do that?
Well, you think of things that you wanna keep out of the prompt to make sure that you're not overly focusing the AI output on the actual part of the solution you've already implemented. You want everything to be on the table. And one of the ways to do that is to use hyper NIMS versus hypo nims.
And what does that mean? Well, a hyper nim would be a word like attach, and the hypo nim would be staple clip glue paste. And now all of a sudden the prompt is telling AI, I only wanna glue paste.
I only wanna look at those things when in fact, you can add those in layers later. But you've opened the door for thinking at the most, uh, broad altitude, what you could possibly do with, with a set of problems. You don't wanna add in all of the elements that are in your system or all of the things that you think are given too early, because you will navigate two solutions.
You already know you wanna look for the ones you don't know, and you wanna be as broad as possible. You also wanna look at second and third level consequences. You really do have the opportunity with gen AI to go again and again and again till you see where that road takes you.
And the idea that these second and third level consequences could actually be more severe than the initial breach or the initial vulnerability is what's really important in this exercise. You wanna step through the, the, the initial pain to see all of the pain that can be caused by that mistake, because in that light, something looks a lot bigger than it does perhaps when somebody just broke into your system, right? If somebody gets into the system, okay, that's a problem.
We wanna stop that. But what can they do once they're in the system? And how do we stop all the places that they could wreak havoc?
And then the last part, which is really important too, because you wanna look at the third parties as well as internal actors, because while bad actors might have nefarious agendas, sometimes hairless employees are just as dangerous. And to be able to look at all the parties who interact with the system and all of the places where they can touch it, you're going to be much more thorough in thinking about when something happens, what the risk of that axis is. So if I'm just careless, how much power do I have to create chaos?
If I'm nefarious, how deep into the system can I go? And how much havoc can I create for the agenda that I have? And both of those would be completely different paths down a premeditation of evils exercise.
But you'd wanna take all of those paths to make sure you've covered the ground. So I'm gonna give you three examples, one for each of these types of thinking. So paradoxical thinking, as I said, it's balancing the tension between different ideas.
So here you think about, I have a really restrictive security system, but how am I so vulnerable with internal employees? Well, one of the ways that you might imagine that is it's so restrictive that there's a subculture around the company of ways that people avoid it. People navigate through different things.
They share passwords and credentials. They have figured out ways to not be slowed by the extra security that you've imposed, right? And so how can the most rigorous system be also the most risky because of what we created is so difficult for our employees to use, right?
So balancing the idea that it's really great for perhaps for external hackers, but it may not be as great for internal employees who are doing things like sharing credentials, right? So that's a good example of, of where a user experience changes the security of the system that was designed for external hackers to prevent breaches opposite thinking. So the the same problem, you might say, well, what if we actually made things less secure?
What would that look like? How might we change the authentication process to facilitate a less secure system? And what would that create for us?
Because in that scenario, that's kind of what credential sharing is doing, right? It's actually making a less secure system out of a secure system you have. So when you think about what would I do to design a system that would actually not protect my, my business from my own employees, you have to think about the opposite of what you wanna achieve.
And that in, and in that, can you still maintain the goals that you have for compliance and IT security? Lastly, in the inversion thinking example, you wanna think, what's the worst thing I could do? This is my, how do I not get a job in Hollywood?
Like, what's the thing I do? Well, I sit there and I send out paper resumes to people. That is not how you get hired in Hollywood, right?
That is not the way it works. It's a network thing. It's a, it's a being at the right place at the right time thing.
So what does a security solution right look like when it fails on all fronts? What are the elements, the, the traits, the attributes of that kind of a system? And one by one, what do I have to do to negate those, right?
Working backwards from the worst to the best helps me see all the places where I have holes to plug. So the premeditation of evils is a really powerful risk strategy with generative ai, because it expands your field of vision, it gives credibility to things that you're easy, easily dismissive of, because in the context of the bigger picture, it could be a cascading series of things that actually cause the catastrophes that we might face. And so, by looking broadly, we can also look at the patterns and associations across those things that actually could connect one small problem into something that becomes a larger problem.
And so this idea that these edge cases that we dismiss because they don't look as severe on the face, may actually be more severe when we look at them in the context of a premeditation of evil's exercise, the fringe actually becomes the vulnerability that you most need to protect, because it may only happen once in a, in a blue moon, but when it happens, there's no recovery. If you haven't planned for that failure case, you won't be prepared if it happens. So with that, uh, I'll talk to you just for two seconds about my book.
It does come out on Tuesday. I'm super excited about it. Uh, the, the thing that I think is really important for people in any field, whether it's finance or cybersecurity, is to recognize these techniques exist in a way to help you structure your thinking, especially when you feel stumped or blocked by the things that you know today.
And by giving yourself permission to explore the edges and also use these frameworks to ask questions that don't, um, belie your own biases, or don't present a conclusion within the prompt, you're more likely to uncover the things you hadn't thought about. But moving from prompt engineering to this type of structured framework is important. Not that prompt engineering is bad, but when you're really looking to go beyond your own cognitive boundaries, these techniques can really help you ask questions in a different manner to really unlock the potential that you have inside your, not only your experience, but inside your own creative capacity.
So if you wanna, uh, look at the QR code, you can go up to my website. You'll learn more about the book, you'll learn more. Also, the book is really, uh, a kind of a playbook because I, I provide exercises in the book.
So to practice some of these techniques that you might not be familiar with, there's some, some exercises there. And every chapter has a section on how to partner with generative AI on that technique. So whether it's these three techniques or seven other ones that are in the book, they're all useful when partnering with ai.
But how you use them with AI is really the key, because different benefits accrue when you have AI as your partner, and you're going through the process of problem solving with no anticipation that you know the outcome, but with a great idea that you have, you wanna solve a problem that you know is the right problem to solve. And even AI will challenge you that maybe that's not the right problem to solve. And so, one of the reasons I wrote this book is to give people the confidence to use AI as a collaborator and a co-creator, and a solution prompter, and a Provo Provo provacator around ideas that you wouldn't necessarily come up with yourself.
It's an exciting time in the world of networking because the US Department of Justice has finally cleared the acquisition of Juniper by HPE. However, there are some conditions. One of them didn't really make the news.
One of them was all the news. In this episode of the Tech Field Day podcast, the DOJ just devalued nist. Welcome to the Tech Field Day podcast, where we bring together a group of influential IT experts to discuss a single idea about key concepts in the enterprise IT industry.
This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often recorded in association with one of our events. Tech Field Day is a part of the FU and group, and this podcast is also published on our sister company's website on Textron tv. Before we jump into today's episode, I'd like to take a moment for our guest to introduce themselves, starting with Ed.
Hi, ed Whedon, uh, roaming ETT engineer, uh, mostly focusing on routing and switching. Uh, Sam Clements. I am a mobility focused engineer.
I currently, uh, am employed over at wwt my day job. So this is not their opinion. This is mine.
Uh, you can find me on Blue Sky at Samuel dot Clements. Uh, hi, I'm Jake Snyder. I'm a wireless focused, uh, engineer at Google.
This is also my opinion and not that of my employers. And I am Tom Hollingsworth event lead here at Tech Field Day. And, uh, these are everybody's opinions as far as I'm concerned, because this is, uh, gonna be a very contentious, uh, discussion today.
So let's jump into the premise for today's episode. You may have seen in the news that one of the big blockbuster acquisitions is happening in the networking and wireless space has finally been cleared by the Department of Justice. That's right.
We're gonna be talking about HPE buying Juniper Networks. This was announced in 2024, and it looked like it was going to be, um, you know, moving right along. But late in 2024, we started to hear rumors that potentially there was going to be some kind of, um, pause put on this.
We did later find out that the United States Department of Justice filed a lawsuit against the acquisition, claiming that it would reduce competition in the market. And as of the, uh, what was that? Uh, June the 28th, we received a notification from pretty much everybody that, uh, the Department of Justice had offered remedies for, uh, this particular acquisition.
And as of the recording of this podcast on July the first 2025, the remedies have been proposed and accepted by HPE and Juniper, and we are waiting for an official judge's sign off for these to go forward. That being said, the remedies have caused a lot of conversation in the industry. The premise for this episode is that the Department of Justice just devalued mist.
Alright. I know, I just, I threw that out there. Mm-hmm.
Because I know that people are just gonna light this up. So, so everybody understands one of the remedies that is proposed in the settlement. Well, there's one remedy that everybody just kind of shrugged their shoulders, which is that HP Aruba networking must, uh, spin off their instant on, uh, access point technology, which is basically the controller list technology.
And everyone kind of went, uh, okay, fine. It's the other one that's causing the problem. Uh, and this is the, uh, auction of licensing for Juniper Mist for AIOps.
Uh, it's convoluted. Uh, we'll link to a couple of articles in the show notes that are gonna do a much better job of explaining this than I ever could. But effectively what they're saying is, you're not divesting yourself of missed AIOps, you just have to give other people the rights to buy it and use it and maybe rent some Juniper employees for a while.
With that being said, folks, help me make sense of this. What did the Department of Justice just de uh, do? It, it, it wasn't convoluted to begin with enough, right?
We had, uh, HPE that owns a Aruba and Juniper who owns Mist. And, and I think the writing was probably on the wall with the first response from HPE back to the Department of Justice when they literally said in writing, W what makes you think this is about us acquiring a wireless land company? Um, and, and so I think that we in the industry has all have all looked at this as being, oh my gosh.
It's the, it's the battle of the, the, the biggest entities, the biggest players in the market. This is Aruba versus Mist versus Juniper, versus HPE, who, who, you know, I don't know what the, what the particular cage match looks like, right? But, but the one that gets shaken out is the one that, um, I don't think anybody expected to.
I I think that them setting aside mist, uh, is, is certainly reinforces their statement that they weren't looking to acquire another wireless end company. Um, didn't realize that that was the case when they originally announced the acquisition, though. And, and I think the, the, the challenge was that, you know, DOJ said this is gonna, you know, hurt competition.
And, um, while, you know, licensing out missed technology is, uh, an interesting approach. I don't know that it actually addresses that underlying complaint that, you know, uh, HPE gets to eat their, uh, one of their primary competitors, uh, in a wireless. And I don't know what, you know, we still don't know what that landscape looks like.
To me, it signals that, uh, HPE has a plan of what their wireless portfolio looks like post acquisition. And I don't know that that includes the, the, that that would signal to me that maybe they think it doesn't include missed long term. And that's the part I think that gets people excited, especially given we just saw, you know, Gartner posted their magic quadrant, and who's the, who's the person way up into the right, you know, Ooh, can we, can we talk about the mq?
Because I feel like there is a whole string of events that just occurred. If you, if you rewind the clock back three weeks, it was Cisco Live. If you're rewinding the clock back one week, it was HPE Discover, and it was the release of the Gartner mq.
And by the way, the MQ was, was quite flattering on the mist side of the house, was not very flattering on some of the other manufacturers side of the house. And so you sort of wonder about, or at least I wonder about Gartner's Magic Quadrant taking the the most up into the right person and not realizing that they were essentially on the chopping block. Like, I'm not entirely sure how, how, how MQ puts them up on a pedestal.
And the industry basically says, cut 'em, auction 'em off, feed 'em to the wolves. It almost feels like that the Gartner component is actually a, a couple of weeks behind, right? I mean, if they've already gotten everything into the pipeline actually started, you know, fleshing everything out from the quadrant perspective, right?
And getting, getting that planned out and like, Hey, go, go to publish it. And then suddenly DOJ drops this and you're like, well, wait, what's going on? So, but even before that, yeah, but I, but I think even before that, I think a lot of us, it, at least I'm speaking from myself here, and some, some, uh, other counterparts of mine, um, we all suspected when HPE made the announcement that they were buying Juniper, we're like, okay, cool.
So they're buying mist. They're buying it for ai, for the AI component. That that's the way, that was the read that a lot of people took on it at the time.
Um, and the fact that now HPE is coming on and saying, oh, well we don't, that's fine. We can sell that off. We can auction that off.
Uh, it is very telling to me that actually they actually were trying, they are actually are trying to pick up the rest of the, the portfolio, um, of, of the Juniper portfolio. Um, and I think the one, um, elephant in the room that nobody's really talking about is HPE just bought their way into the service provider market in a very, very big way, uh, by buying Juniper. Lemme circle back to the premise a little bit because you guys have both touched on something that I think is kind of important to think about.
Ed, you just said that one of the things that everybody was talking about when this an acquisition was announced was, oh, HPE is buying mist. Sam, you talked about the fact that the Magic quadrant has Juniper Mist very much up and into the right. They're, if, if you think that upper and writer is, is better, um, they are the leading company in the Magic quadrant.
Um, I I, I've seen it spun a bunch of different ways too, from a lot of companies who are not upst and Rightest, but I think that where that kind of comes into play with the premise of this episode is that for a lot of people in the, in the industry, Juniper Mist was the value of Juniper. They were the ones doing the most aggressive marketing. They were the ones that were pushing the limits of AI and integration.
And, and Lord knows that we've seen enough of those presentations at Mobility Field Day over the years from the Miss team and then the Juniper Miss team. We know that Juniper presents at other events. We've, we've seen them at Cloud Field Day and Networking Field day and AI infrastructure Field Day, but it kind of felt like all of the steam was behind the Juniper Miss team.
And now what we're hearing is that it's not, and honestly, we're hearing that because the Department of Justice just came out and said, Hey, can it get rid of it if that's what it takes to make this acquisition happen? Like, like how can somebody have the wind knocked out of their sails that fast? Well, in addition to it being the Department of Justice, both, both companies have said, okay, that sounds good as well.
Like, it's not just the DOJ, it's like it's a mom and dad said, Hey, yes, you're redheaded and you are a stepchild. Go away. Yeah.
It's, it, it is interesting to, to, to see that everyone has kind of said, okay, we need to do that. All right, fine, we'll do it. Um, and I think, I think the other thing that's under underlying this is that it also really underlies a lot of the change that we've seen just in the last 18 months.
'cause this was announced in, was January of 2024, I think, when they announced it February. So it's been about 18 months. And one of the things I think we're seeing is, is we're seeing a lion's share shift, or not lion's share is the wrong word, but a, a tectonic shift in the AI landscape, and with the explosion of open AI clawed and, and the other major L LMS out there.
And it kind of makes you wonder if we've started to get to a point where maybe a lot of the AI technology is starting to become commodified. Uh, and how's that for an interesting thought? Um, you know, a lot of the secret sauce was in the AI engine, the AI ops component, right?
So how much of that is kind of being devalued, not just from a DOJ perspective, but just from an industry perspective as a whole? Well, I mean, I think it was at the last mobility Field day presentation that they presented at. I think they literally said they drew a timeline and they're like, this is the beginning of the company and this is where we did investments and blah.
And then they marked a line and they said, and this is where we transitioned to commercially available LLMs or something along those lines. And, and scrapped doing all the other stuff that they were doing. And so, and so at some point they did, um, start leveraging more mainstream available AI solutions.
And, and you're right, it's, I I mean, I realize that doesn't just equal, it's now completely off the shelf and you can just go, you know, do a GitHub poll and everything. You're gonna have just as much stuff as they're gonna have, right? But you wonder about the, about the importance of the modifications they're doing to it, and what do they really bring to the table in order to make something like that happen.
I'm not entirely sure there's a good out here because if they go to auction and they end up getting, and, and somebody or some buddies ends up winning them, that just, that just totally devalues what it is they bring to the competitive landscape. And and if nobody bids on them, then they're proven worthless. Well, uh, that, that's a very good point.
I think the other thing to keep in mind is that it's also for a license to use the, use the software. It's not for an actual like auction off as auction off the assets in, in total. Thank you for putting that out because you're right, you are effectively buying a year's access.
Maybe it's, it's, um, something that can be renewed on a yearly basis. But you are buying a license for Juniper, mi, Juniper, AI ops for missed, and you are buying the option of hiring 35 technical Juniper employees who are familiar with the operations of Juniper, uh, AIOps for Mist and 20 people who are familiar with selling that solution. So you basically are buying a license to use it for at least a year, and the option to hire 55 new people to figure out how to make this work, what company out there a has the money?
'cause we, we know for a fact that the DOJ thinks the auction for this is gonna go north of $8 million because they have written a proviso into the contract or the remedy for what happens if multiple companies build bid more than 8 billion, $8 million. And that's M 8 million, not 8 billion. Um, here's the other question that I have.
What company out there isn't already working on an AI operation solution for their platform that would be willing to buy this and then spend the next 12 months trying to figure out how to integrate it into the platform that they've already got? Like, one of the things, having, having worked in, uh, at, at, at Juniper firmware's hard stuff in the cloud is easy, right? And so, uh, when you start saying, Hey, we're gonna, let's license this thing, can you imagine having to go back and rewrite all of your AP firmware to support getting the right data to, I mean, even, even Mist for years said they didn't wanna build an access point.
They built one 'cause they needed good data to feed their ai. And that's the, the question, are you gonna, my experience has been that the, the AP firmware's, the, the really hard part, are you willing to go back and spend, you say 12 months? I would say probably more like 18 to 24 months rewriting your firmware stack in order to support that piece that, you know, is, is out there and, and other folks can leverage.
Uh, But that's a good point, Jake, is if you know it's gonna take more than 12 months, why would you limit the license term to that? And, and I, to, to me, this, this leads me down the, the, the real value of mist to HPE and that is what the DOJ has enabled them to do, which is eat one of their fiercest competitors, right? They get to eat the competitor.
They say it's not about mist, but this, this, you know, auctioning off kind of commoditizes some of that. They're, they're derailing their big competitor. They're also potentially derailing a new competitor to that space for 18 months while they gear up for this, like buying themselves and maybe other competitors like Cisco time to, to figure out the, the strategy and move forward.
I, I think that's the real value that, that the DOJ has has given to HPE And, and, and they also just opened up a licensing revenue stream. Well, I don't see anything in the, I don't see anything in the court order that says that it must be a short term license, nor do I see anything that says it must be a perpetual license. Um, although there is, there's a bunch of claims in the, um, in the court order around the instant on licenses, because that's all aos eight based and they need perpetual licenses and all, like all that fun stuff.
But I don't see anything about a duration for the mist for AIOps, um, license. And so that could be them retaining control over it. It could be going out to somebody else.
It could be going out to multiple others. I guess my question is, as I've heard the story from Mist for so long about how Full Stack is better, right? You need to have visibility across every device in your portfolio.
And here they are, they're gonna basically be out on their own looking for a vendor who has everything but wifi. And I don't know that that, I don't know that that home exists for them. Uh, I, I don't know.
I, uh, I I feel there's a little bit of, of, of that. Like, I think, um, is that the message they sent because they wanted to sell you full stack, or is that the message they sent because they felt they needed that? So, um, you know, that, that to me is, I don't know if that's the value, but I feel like if you're saying, Hey, I'm gonna give it to you for the wireless land, that's about the, the the only thing that I, I think from the original DOJ complaint was anti-competitive in wireless land.
And I feel like this is kind of a, um, a kiss the ring moment. Like we're not really gonna get the, the, the com the anti-competitive things out, but if you give up some wireless land things, um, it shows that you gave a concession and, and can move forward. And we have seen the DOJ recently go after other businesses for other reasons, um, to say, we're gonna hold up your, your acquisition unless you do things that we want you to do.
Not necessarily anti-competitive things. But, um, I I, I, I wonder if this is just a, we want concessions out of, out of HPE and Juniper and 'cause the complaint was filed about wireless land. We have two wireless land concessions and, and really doesn't have to do with the value of, of Mist.
It was what HPE was willing to give up. But here's the other thing that people have to understand because this has been the other part of the value of what Mist has delivered to Juniper. If this was just something that was running in the wireless networking space, I, I don't know what I would think about it.
But we know for a fact that the, uh, Juniper missed Juniper AIOps for missed product line has been pushed across all of Juniper when the purchase happened, which one of the things that a lot of people said was, I can't wait for this AIOps stuff to be delivered to campus networking, to routing, to a bunch of other things. I mean, there was even an article that was, uh, published on the Packet pusher's website just a couple months ago about how AIOps was being ported to Juniper's routing portfolio. So for them to kind of hang this on, this is a big wireless problem, and that's what we cited in the complaints.
So all of our remedies have to be around that. The rest of the software is pervasive across the campus networking line. At this point, you can't buy a Juniper switch that doesn't have the capability of running AIOps for Mist.
So what, how is this gonna impact things that are not wireless? I, I think the, the other piece of that is, you know, um, the, the DOJ complaint was specifically around wireless, but that's not the only area of overlap between these two companies. Uh, uh, access layer switching, uh, huge, huge overlap between these two, uh, sd-wan, I mean, HP has Silver Peak and SD branch and, and, uh, Juniper has, uh, the, the one 20 T uh, so, so there's, there's a basically a, a enterprise networking company that you could literally spin out of, uh, in terms of the overlap.
And I, I feel like that when you talk about anti-competition, like if they're not gonna, if if the missed bits really aren't that important, it, it feels like there was an opportunity to keep that competition in the market by spinning, let's buy Juniper for the service provider, uh, and, and business and spin an, uh, an enterprise player back out, such that there we wouldn't have anti-competitive behavior. That was definitely not what the DOJ said. So, um, like that's not the decision they came to.
So my take is, is that's the real value, which was we, we get to, you know, um, um, take a, take a player out of the market and com and, and, and less competition like that. To me, I feel like that's where HPE like hit the, hit the lottery, whether or not they, they keep the missed stuff, whether or not they go out, they, they settle the SD WAN or access layer switching, you know, stuff like, they basically got to eat a competitor and, and take away someone they were struggling to compete in sales with. Well, I feel like maybe there's some relief over on the HP side of the house.
Maybe they, maybe they're thinking now they don't have to deal with it because that was what, that was the number one topic of conversation last year at Discover. It, it monopolized every single conversation. And of course they didn't have any answers to it because they can't.
And so you almost wonder if they're not breathing a sigh of relief right now, oh, thank gosh, we don't really have to deal with that whole missed problem anymore. We can just turn around and license out and we're not gonna use it then. Right?
Well, no, it, it, it also, it also raises a question of, of, um, the perception of value of Aruba Central and the AI component within Central, right? I think there's, I think there's another play to that. Um, you know, ki kind of, Jake, to your point, what you were, and, and Sam, you know, both what you were saying in terms of, well, they're kind of like saying, okay, well fine, we can spin this off.
So that almost feels like they're actually starting to bank a lot more and say, Hey, we have our own solution here that's already baked in across much like mist across the rest of the enterprise networking line that they were starting to build into Aruba's. Done the same thing within campus switching within SD branch, SD access, um, or sorry, SD branch, silver Peaks, SD wan, that's the word I want to, um, and also data center, don't forget, uh, re uh, Aruba does play in the data center space as well. So, uh, it's, there, there, I I, I think, Jake, I hadn't thought about it from the perspective of what you were just saying about the, the antitrust angle, not just outside of wireless, across the rest of the competitive landscape, across the enterprise and data center.
I think it's a really, really good point, um, that it is one that I think a lot of people are glos over. 'cause they're saying, oh, well, a lot of the industry was thinking, a lot of it was focused on wireless, and now we're saying, well, wireless isn't a big deal. We got the rest of it as well.
Well, I mean, let, let me take off my moderator hat for just a second. I mean, the reason why they're not worried about anything other than wireless is because, well, HPE doesn't compete in the carrier router space. They, they literally, and they don't really compete in the data center switching space.
If we're being honest with ourselves. I'm, I'm thinking that, and, and yes, if you are an HP or Aruba networking person, Scott, Nick, all of my friends out there don't hate me for saying this. You guys were not competitive in the data center switching space.
You had data center switches and you sold them usually to people who bought other HPE networking kit or they were going into GreenLake installations that you, you, you, you did the same thing that IBM did whenever they made a switch for their blade centers. We need to have this so that nobody goes to buy somebody else's and, and we lose out on that sale. Like, like the, the, the biggest overlap was in the wireless space and possibly in the campus networking.
So that's why it seems like a lot of the, the Remedy stuff is focused there because you're not reducing competition in the market. I mean, you, you're reducing what, 2% market share in the data center switching space. Okay.
So, uh, you know, I, I came, uh, I was at HP Discover last week and sat in the 75 minute keynote of which approximately 25 seconds was devoted to enterprise networking. Um, all in the rest of it was AI compute data center, um, storage, more ai, more data center, HPE or, or should we say HPC? Isn't that the new logo?
Um, with the e sort of as an afterthought, right? Um, the, the, the, the new company is clearly sending signals that data center is where their focus is at almost to the exclusion of everything else. And, and you could feel it, there were three wireless companies there that were supporting wireless solutions.
Like, it was, it, it was clearly clear, clearly felt deemphasized, I guess this year. And I don't know if that was intentional or not. All right, so we, we've been, we, we've been debating this for quite a while.
Um, but I guess that, that we need to circle back kind of to the premise of this episode so that everybody at home kind of knows. I, I mean, I think we all kind of agree that yes, whatever the Department of Justice just proposed is a remedy that HPE and Juniper seems to have agreed to pending a judge's approval that it has devalued the company. What can mist Juniper Mist mist on its own do to improve its value in the eyes of potential customers in the future, knowing that it's gonna be in a very weird situation?
I think this all just lands very poorly for mist. I'm not entirely sure there is a clean way out, unless there is only one auctioner or auction e and unless they only get, unless they get licensed to a single company and a single company only for, for perpetual, right? That's basically their only way out.
And, and that means they have to rebuild that they have to start from the ground, they have to start from ground zero. They have some traction in the market, they maybe could do that, but it's gonna be a long uphill battle for 'em. I think it's gonna come down to, um, it's gonna come down to what HP comes out and says about, you know, post post acquisition, like once this finishes, um, they're gonna play the, they're gonna play the game 'cause they have Juniper missed customers that they are going to want to not alienate, um, in the short term folks whose equipment they're gonna have to maintain for some period for continuity reasons, right?
It's not like you could just turn all that stuff down tomorrow. Um, and how do you make that transition for those customers into HPE land in a way that makes those customers happy? Like, um, I, I think is gonna be really key for h HP to, to HP to, to, to figure out.
And if they can't, I think it does the exact opposite. It's gonna open the door back for the 800 pound gorilla Cisco to, to go win that business back. 'cause let's face it, the folks that we're buying, you know, ARPA Networks and the folks that were buying Juniper Mist were, were buying those because they wanted alternatives to Cisco.
Um, and, and so I feel like either, either Mist has, uh, has to find some way to continue to exist and that portfolio to continue to, to provide that value or, uh, HPE is gonna concede a bunch of business back to Cisco, which I think is also, uh, the anti-competitive nature of things. So, Yeah, I, I was gonna, I don't think I can add anything else that Sam or Jake has not already hit, hit the nail on the head on. I think, As you can see, this is one of those contentious subjects that is probably not going to pay off anytime soon.
But we knew that as soon as the US federal government got involved in this acquisition, because the gears of the Department of Justice grind slowly and completely to dust, sometimes we don't know what's going to happen. We need to see await the approval of the judge. We need to await the approval of the auction terms and the outcome of set auction to see who the bidders are.
And there's a lot of moving parts, even if the company that prevails in that auction, uh, gets some value out of it. And I'm sure we're probably gonna be talking about this months from now, uh, trying to figure out what the ultimate end goal to all of us is. But one thing is for sure, we know there's gonna be movement on that acquisition and we know that someone's gonna be getting value.
I guess the question is who's getting it and what is it ultimately going to be? That will just about do it for this episode. We wanna thank you all for listening to this episode of the Tech Field Day podcast.
If you enjoyed this discussion, please make sure that you subscribe on YouTube or in your favorite podcast application of choice so you don't miss any of our great episodes. And if you do use us as a podcast, please consider leaving a rating, a review, and a comment. This podcast was brought to you by Tech Field Day, the Home for IT experts from across the enterprise.
com/podcast for the latest episode of the Tech Field Day podcast. You can also check us out on Techstrong TV or in the Techstrong TV app. Thank you very much for listening.
Well we'll see you next week. Hi everyone, thanks for joining us today. Today we're gonna be talking about insights from our 2025 Cloud AI risk report.
Uh, to begin with, uh, quick introductions. My name is Franklin Wynn. I am a product marketer here at Tenable, supporting our Tenable cloud security solution.
Joining me today is Damien Lim. Uh, would you like to introduce yourself, yourself, Damien? Yeah, sure.
Hi, my name is Damien. I am the AI evangelist at Tenable. Um, so glad to be here.
Awesome, thanks Damien. So what are we gonna be discussing today? I did mention it earlier, but to double click on that today we're gonna be, uh, talking about trends.
So AI adoption and some of the challenges that organizations face. Uh, we're also going to share AI risks insights from our report. And in addition to that, share some best practices to better secure yourself against threat actors.
So with that, why don't you go ahead and jump in. So to quickly level set, what are we gonna be talking about when it comes to ai? We're gonna be talking about how to secure, uh, organizations as they leverage AI services in the cloud or AI tools to integrate into their existing products or build their own LLMs.
Uh, we will also touch briefly on how organizations can also secure themselves when individuals in the organization may be using end user AI tools such as chat, GBT. So AI cloud services and related solutions use. So our insights today will focus on risks organizations face and safety measures organizations can take when they use AI and AI related services to build or incorporate AI into their own services.
So what does this look like? Well, at a high level, we're gonna be touching on three different areas. Uh, the first is AI workloads.
So organizations obviously are gonna be leveraging out of box AI services provided by cloud service providers such as a US, Azure and Google. Uh, they're going to be training these models using data that they have stored in SD buckets, for example. And they may also be using, uh, AI software that's deployed on their virtual machines or leveraging ai uh, libraries, right?
So these are three fundamental areas that we're going to be addressing and some risks that we found within all three of these areas. Okay, so with that, first, let's take a look at what are we seeing in the market. So according to McKinsey, organizations across the globe, across industries are beginning to use AI more significantly than in the past.
Um, in 2024, it's grown significantly more, and I believe, and I believe my peer over here believes as well that is gonna continue to move up into the right. Additionally, according to our report, uh, we do see a growing trend, as I mentioned earlier, of organizations using cloud AI services. And as you can see, it's across the board from Google to Azure.
Organizations are beginning to incorporate these tools, uh, out of the box to help them build and deploy AI workloads and services. Uh, anything else you'd like to add, Damien? No, I, I think, um, you know, as we see the adoption of, um, ai, uh, in terms of development, uh, we're gonna see a lot of traction across these different services that, uh, Franklin just mentioned, uh, just because it gets, uh, gets most organizations, uh, quicker to the market.
So we definitely will see, um, those numbers increase, uh, as, as this journey continues on. Great, thanks Damien. So, yeah, a lot of organizations are beginning to use AI more significantly than in the past, but as you can imagine, with great technology comes great responsibility.
Okay, so what do I mean by this? So first, let's take a look at this, uh, Jenga step. Now imagine this is your organization, and as you begin to introduce new technologies such as ai, uh, you are opening yourselves up to new types of risks.
Uh, so what are some of these types of risks? Uh, we see and find critical vulnerabilities, uh, public access, overprivileged access, and misconfigurations as types of risks that organizations face across the board, but become more prevalent with the indirect in, with the introduction of new, uh, technologies such as ai. And as you are using AI and AI services and you introduce yourself to these types of risks, you may begin to potentially open selves up to the risk of attack by a threat actor.
And while taken separately, these risks may not pose a significant threat collectively. Uh, they may become what we call a toxic combination. For example, imagining yourself having a workload deployed with AI libraries, and that workload has a critical vulnerability.
In addition to that, imagine that it has public public access, so it's misconfigured. And finally, it's able to access other types of workloads and services within your organization, let's say, to an S3 bucket that has sensitive data. Now, collectively, this is a prime target for a threat actor.
So if they're able to compromise this workload, uh, they have now access to your organization. They have the ability to exfiltrate data, they have the ability to conduct a ransomware attack. And what does this mean?
This means that your organization can be compromised. Uh, and theoretically, obviously, uh, this can take place, but we'll put more substance behind that when I pass it along to a gay who will provide specific, uh, accounts, uh, uh, vulnerabilities that we found. The next question is, why are we seeing more risks related to, uh, ai?
Well, again, with any new technology, uh, organizations are gonna begin to rush to use it, right? And because of the maturity level of the organization and the maturity level of the solutions themselves, uh, we find that, uh, new types of vulnerabilities may emerge that organizations may not be aware of that the, um, that, that they will need to resolve. Right?
And in addition to that, there's a, there's this ongoing pressure, uh, within organizations to, uh, win market share as it as it relates to ai. So with that pressure and with that rush to the market, uh, speed becomes critical and they may put to the side guardrails being built to secure, um, the AI services and tools that they're beginning to build. Uh, anything you'd like to add to that, Ian?
No, I, I think this is great and, um, you know, I'm gonna spend a little bit more time in discussing how some of these, uh, exposures, if you will, uh, can generate, you know, uh, bigger risk. Great. So with that, I'll go ahead and pass it off to Dam who will, uh, double click on some of the insights that we found, uh, in our report.
Thank you so much Franklin. Um, and what we've found right from the AI risk report that, uh, we've, uh, looked into, uh, from a threat research perspective, uh, we've actually found that 70% of the AI workloads had at least one critical vulnerability versus 50% in non-AI workloads. And why is that?
Because if you look at the AI workloads, uh, they typically rely very heavily on open source components such as, uh, PyTorch or TensorFlow. So that makes them inherently vulnerable to unpatched security flaws. Now, unlike the traditional workloads, AI models often incorporate multiple libraries frameworks and dependencies that if left on patch could expose organizations to significant security risks.
And the consequence, uh, could lead and range from data corruption to the insertion of back doors into AI loads and AI models themselves. If we take a look at coal, uh, what we've found, uh, we, in analyzing this particular, um, vulnerability, CVE 20 23 38 5 4 5, uh, related to a heap buffer overflow, uh, remained on patch for over a year. So this leaves the critical AI infrastructure at risk.
And with that, attackers could exploit this vulnerability to gain unauthorized access, extract, model data, and even temper with AI training pipelines. And if we take another example this time regarding the AI models themselves, and this example is the WAN who chat G-P-T-C-V-E 20 24, 32 34 is actually categorized as a critical vulnerability. Now, this allow attackers to steal sensitive files because the application used an outdated vulnerable iteration of the Grado open source Python package.
Now, the key takeaway here is that AI workloads introduce unique vulnerabilities that organizations must monitor and patch just like any other critical infrastructure, enterprise application, and its, uh, dependencies. When we talk about AI security, we often think of model integrity, but data exposure is an even bigger risk. AI workloads rely on massive data sets, and if that data is not secured, uh, it can lead to inte intellectual property theft, compliance violations and regulatory fines.
But before we dive in, uh, for those who are not familiar, uh, AWS bedrock is focused on generative AI using prebuilt foundation models. Example like llama and through an API, without having to manage any of the infrastructure or train your own models. Now, with that said, what we found is one of the most common risks that we found is storage misconfiguration.
3% of their training data has, uh, public access disabled. So this means that this confidential model training data, um, you know, within this particular storage, uh, could be accidentally exposed to the internet or create an opportunity to poison its data. And furthermore, overprivileged policies are another major concern.
In bedrock, 5% of organizations have at least one over permissive bucket. So if an attacker gains access to an AI storage bucket with weak permissions, they could still training data and use it to replicate, uh, proprietary models inject poison data to manipulate AI decision making processes, delete or modify AI training data sets leading to a skewed model output. And lastly, in AWS SageMaker, we found that 90% of organizations left SageMaker notebook instances with root access enabled.
And with root access, users can manipulate Exfiltrate AI model and ip, and even the data in the S3 buckets. Now, anticipating this question ahead of time, Amazon SageMaker is a fully managed machine learning platform that helps developers and data scientists built train and deploy ML models at scale. Now, keep in mind that AI models are built on sensitive proprietary data.
So whether it's a customer data set, a financial model, or otherwise exposing this data could be devastating. The key takeaway here is organizations must treat AI training data as a critical asset, enforcing strict access controls and ensuring that no data sets are left vulnerable to exposure. Uh, so now that we have identified some of the key risks in AI workloads mentioned earlier, let's walk through five essential best practices to secure them.
Number one, gain unified visibility across AI workloads. Now, that's the saying, right? You can't secure what you can't see so many organizations like visibility into their AI usage and AI development across their environments.
The solution here is to simply deploy a AI security posture management solution, as well as any related security tools to monitor AI specific resources. Number two, applied lease privilege access controls. We've just learned that over privileged service accounts are one of the biggest security gaps in AI workloads.
Now, the solution here is pretty straightforward as well Limit the access to AI models and training infrastructure following the familiar zero trust approach. Third, secure the AI training data and storage because we've learned as well this configured storage is an easy target for attackers. Remember the deep seek data, leak it exposed sensitive information including chat history, security keys, and backend details.
So always enforce strict access policies and disable public sharing of AI related data. Next, prioritize AI specific vulnerability remediation. Now we know that traditional vulnerability management does not cover AI specific threats.
So make sure that you implement AI risk detection to identify unpatched CVEs in machine learning frameworks such as PyTorch. I TensorFlow further use a system that can enable teams to be strategic by prioritizing the mitigation of these vulnerabilities. And then number five, enforce and secure cloud configurations.
Cloud security misconfigurations or default configuration in AI services can cascade into major security incidents, as Franklin mentioned earlier with the Jenga concept. So continuously monitor and remediate non-compliant AI infrastructure discovered in AWS Azure and GCP. Lastly, additional guidelines can be found in the cloud AI risk report.
And feel free to peruse this resource, which will provide a link at the end of this presentation. And I just would like to kind of leave you the key takeaway here is to understand that AI security must be proactive addressing misconfigurations and vulnerabilities and accessing risks before they're exploited. And this is where we believe that tenable solution can help.
Tenable one is an AI powered exposure management platform. One important key aspect is that it provides full visibility into the exposures across the entire attack surface, including emerging ai, whether seamless integrated, uh, vulnerability management and cloud security technologies found in this platform. Now, this unique combination of AI SPM and AI aware capabilities gives you 360 degree visibility to effectively manage risk from both shadow AI as well as a in-house AI LLM model development locally and into the cloud.
Now, as we, uh, wrap up, uh, today's session, I would like to leave you with this, uh, takeaway. Uh, AI is already transforming how we operate in a modern world, best a world and in our lives, but it also introduces a new attack surface in a fast moving risk landscape. So securing these workloads isn't just a technical requirement, it's actually a business imperative and tenable.
We believe that visibility and accountability must evolve alongside innovation. And with the right tools and approach, you can empower your teams to safely innovate and innovate securely. So thank you for spending, uh, time with us today, and we hope this gave you new perspectives and practical next steps for your AI journey.
Now, with that, I would like to also add some of these next steps, uh, for us to consider. Uh, and if you're interested in digging a little bit more into our solutions, please visit our cloud security, um, page. Uh, the QR code is available there as well as accessing the full cloud AI risk report, uh, with the QR code, uh, provided.
With that in mind, I would like to kind of leave us, uh, with some next steps, uh, for you to consider. For example, you can go to our Tenable Cloud security, uh, page to dig a little bit more about our solutions as well as accessing the full cloud AI risk report by scanning the QR codes, uh, that we have provided. And, and with that, I'd like to again thank you, uh, for your time and participation.