Techstrong TV July 22, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices
Transcript
Hey everyone, what's the catalyst for the biggest drive towards modernization in tech? It might be Broadcom's, acquisition of VMware. You are watching Techron Gang.
Hey everyone, it's Alan Shimo. Happy Tuesday. We have done, we're gonna do something we've never done before, right?
And if you could do that in your life, it's always nice. I think we're gonna do a special edition of our Textron Gang. And, um, in this edition, rather than doing our normal three sort of segments, we're going to take our whole gang, uh, episode and we're going to dedicate it to one subject.
And I, I, we're trying it out. We hope you're gonna like it. Let me, I'll give you the subject off the top.
It's, as I said in the beginning, it, the largest drive or the biggest catalyst for the modernization that we've seen may in fact have been Broadcom's acquisition of VMware. Prove me right or wrong. Let me introduce you to our gang who's gonna discuss this with us today.
Uh, some of them you are familiar, some not so familiar. Let me go to the familiar folks first. We've got, you know, from Tech Field Day, he actually knows a thing or two about this stuff, uh, fr.
Steven FoST. Hey, Steven, how are you? Very good.
It's nice to be here. And, um, also, of course, uh, yeah, nice to be working with Broadcom on the launch of VMware VCF nine, uh, or at least sharing info about it. Absolutely.
Also joining us, uh, she's the CEO of Deploy hub and knows a thing or two about modernization as well as open source, our friend Tracy Reagan. Hey, Tracy. Hey Alan.
And thanks for inviting me to this special edition of the Text on Gang. Getting to spend time on one topic, like 30 minutes is awesome. Yeah, Yeah.
Better than the usual 10 or 15 we usually do. Last but not, well not last, but, and certainly not least either. Our Chief Content Officer, Mike Ard.
Hey, Mike, welcome. Happy to be here, as always. And yeah, I've been hanging around VMware for three decades now.
So here we go again. Here we go again. And then our very special guest today, I want to introduce you to, and I hope I get her name right, I apologize in advance, Sabina Anya.
Sabina is Senior Technology product Lead at VMware Cloud Foundation. Sabina, welcome to Textron Gang. Hey, thank you.
As speaking of viewing something new. Here's my new thing for, for at least this week, so thanks for having me. Looking forward to Absolutely this conversation.
Hey, you never know. You may like it so much. You want to come back again and again.
Have a good time. Alright. Um, Sabina, since you're the new person on the block, let's hear a little bit about your role in, you know, your technology product lead at VMware, uh, for cloud, for VMware Cloud Foundation.
What do you, what exactly does that? Uh, you know, it's, it's interesting you ask because I think it's, the role is very much a, a product of all of the change that we've seen as a result of the acquisition of VMware by Broadcom. And, um, for, for about I, let's say seven or eight years now, we had this product called VMware Cloud Foundation.
And if, you know, it says version one, oh, well, things were a lot different back then. But basically we had these roles as either pre-sale specialists and basically folks that were looking at the platform as a whole, kind of figuring out kind of how does it integrate together? How, how do we go to market as one platform.
Now, back in the days of VMware, this was one of, I wanna say, many, many roles we had in, in the environment. And, you know, you're kind of competing with vSphere, you're competing with the likes of VS. Sams.
You can imagine that the wine light was very, very narrow. Uh, I've worked with VMware for about five years now, and it basically went from one of hundreds of roles that we had as part of VMware to one of the central roles. I've seen my own role change in the past two years dramatically, where myself, my team, our leadership basically focuses on VCF only.
Our job is to make VCF easy to adopt, is to take what our engineering team is building, what our product management team is kind of shepherding and making sure that, uh, it hits the market in the cleanest, easy to comprehend, easy to adopt, working directly with customers, getting feedback kind of way. So it's, it's very much a reflection of the times and of the change. Excellent.
Thank you. Thank you for that. Alright, gang, let's jump into it.
Mike, I said my piece, right? Yeah. Who, who knew?
0 and, um, Broadcom and VMware before and has been making a case for an integrated platform for a while and post merger. It seems like VCF is at the core of that whole proposition. But, uh, Sabina, what's changed on the customer side that they wanna have this conversation now where they're gonna have a single integrated platform covering compute, storage, networking, and security elements as well.
It feels like something has happened on the way the customer thinks about all this stuff. And what are they telling you? I think this is definitely a, a, a two part answer at the very least, where platform maturity meets market momentum.
I mean, we've all, I think everybody on this call has been for about at least two decades, if not three I've heard earlier in this industry, and we've all seen the same things. I come from basically doing infrastructure at customers, and over time you saw the same points of friction, whether the year was 2005, 20, 20, 20 15, right? You, you wanna deploy a workload, which is kind of what the businesses care about.
They don't care about your network infrastructure or your virtualization engine. They care about does my app work? Can I make money from this?
Right? But a lot of what goes in the kind of the, the kitchen and deploying this was who deploys, what, what's, why the architecture of the app? How do I put all of this together?
And for the longest amount of time, it just, you know, infrastructure got bigger, but also very deeply siloed. And there was always a game of hot potato of whose fault is it if something breaks? I used to be a network engineer, so it was absolutely always my fault no matter what, right?
It's you, it doesn't matter. Storage breaks down somehow. We haven't provisioned the VLAN correctly on the interface, you know the story, but all of these things incur delays, incur challenges, downtime that costs millions depending on the industry that you work in.
And every company, uh, due to current economical times and so on, you get all of these requests for do more with less. Like you have these themes that have been 5, 6, 7 people teams for years now, but the infrastructure has grown a hundred percent, 500%, and they're still asked to manage all of it. So at one point there was a point of convergence, how long can you go managing switch by, switch server by server, VM by VM and not think of more of an integral approach when you have like two pizza boxes and a switch?
Yeah. That kind of works to do it manually timestamp as well. So I think VMware Cloud Foundation isn't new.
What we've done to make it work a lot better is you can't see the seams anymore. It used to be that it was kind of a bundle of products and customers saw through that and they're like, well, look, we don't need five different products so that we can pretend we have a private cloud, either get it together and make it work as one platform, or we'll continue in our own way. So what changed as a result of the acquisition was basically bring the product together, have this one interface to do operations on a daily basis, have one interface to do automation.
I can tell you that from customer momentum, and again, I spent a lot of time with customers. One of the pieces of information I got recently was, you know what, we used to use your automation products, but at one point we had to work so many of the flows ourselves and spend so much time trying to understand it that we figured that's your job. You fix the platform and we'll just deploy on top of it.
0 with any number of scripts and so on, with a more mature, solid product. Adoption is so critical. Adoption is so critical in all in any cloud modernization that you're looking at.
You know, whether it be like Linux and Kubernetes or you know, HPC systems, the adoption is the problem. And Sabina, you said something very important. Most application teams are less than 10 people, and they're asked to be doing so much.
You know, we, you know, we think about an application team of seven or 10 programmers, and they're coding out there, they're generating code, not doing any work at all. But that's not true. They're managing so many pieces.
And the adoption is the one thing I hear the biggest complaint from customers in terms of cloud modernization is the difficulty to implement a high performance computing system because these teams have so much on their plate that a centralized dashboard, a centralized solution, is more important to them than building their own. So adoption and is really is the key to success in this area. No, and I, I 100% agree because again, you you sit on too much, too much software, it becomes shelfware.
And then each customer kind of gets challenged with this, how can I make best use of what I have? And the first temptation is a little bit like how public cloud used to be, right? The, the reason why Public cloud got so popular is was it was easy to adopt.
The friction was minimal, the credit card swipe was easy. And then at one point it kind of blew out of proportion and, uh, it went beyond the credit card swipe and well into the millions. But it also started creating certain challenges, budgets, uh, oversight, sovereignty, security, right?
So I do think that adoption is one of the s strong, strongest points we can offer going forward. Like, okay, you have all of this under the hood, think about how you can use it best. So in my mind though, one of the, the nice things about Cloud Foundation nine I know is, um, the idea of multi-cloud, right?
So I, I will tell you, I I was around when the cloud first kind of came out and, you know, I looked at it kind of skeptically and I always felt that we weren't gonna move everything to the cloud, right? There'd be some stuff in public cloud and some stuff you wanna call it private cloud, you wanna call it your server closet, your data center, I don't care. Some would be up in the public cloud, some not.
I didn't see where I'd be keeping some on AWS and some on Google and some on Microsoft and maybe some Oracle or what have you. And then some in my own private stuff as well. And, and that to me, that, that always kind of surprised me that it, it caught on that multi-cloud sort of view of things.
But again, a small team having to manage these platforms, the idea of having to manage five different platforms, four or five different platforms is, is scary. I mean, it's downright, you know, scary, wasteful, you know, to me, one of the nice things here about Cloud Foundation is I need to go deep on Cloud Foundation. What runs underneath it is, is a lot less important to me than what runs on top of it.
And I think that is a huge piece of this. Steven, I see you wanna say something? Yeah.
And, and I think that, that you're really onto it there. And I think that the, a lot of people listening to this, you know, to be honest, are gonna be saying, yeah, yeah, I've heard that before. That's exactly what I've heard from literally every company modernization.
Yeah. Whatever. But the thing about VMware as a product is that VMware is the platform of choice for basically the, the, the big bulk of big IT shops out there.
And VMware Yes. Has been working on various different ways of helping customers to modernize their platform for many years. And yes, this is the latest in a series of such products.
I mean, it's called vSphere nine. Um, you know, they, they did skip a couple numbers, but they certainly didn't skip a lot of learning in terms of, um, getting up to speed with how to do this thing, right? What I wanted to point out is that throughout when we've been looking at this, this release and when we've been hearing about it, um, as part of our textron our tech field day events, what we are hearing is a very practical and pragmatic approach.
It's, it's all well and good to say rewrite everything to modernize it, but nobody's gonna do that. It's also all well and good to say lift and shift and call it a day. But that's not modernization either.
What I hear from Broadcom with the VCF nine release is basically for the biggest companies with the biggest needs, here's a really practical framework that you can deploy your applications on that achieves the goals of cloud. Even if, you know, it doesn't have the cloud weenies out there saying, you know, oh, you know this and this and that. You know, I mean, it, it's, it's practical.
It's like, let's do the thing. And, and that, that has extended even to the point where some of the features have been reduced, some of the capabilities have been kind of refactored and refocused to make things kind of work the way, um, come, operators want the cloud to work, as opposed to sort of meet the needs of those people who are, have their head in the clouds and, and either the cloud purists. Mm-hmm.
I love point. So to Steven's point about that, um, one of the things also about VCF nine, it's interesting, is the way you approach Kubernetes. And if I went back in time, there was everybody thought Kubernetes would be the death of VMware.
And if I look at it now to the modernization point, the Kubernetes cluster is embedded in the virtual machine. And I use the same core management infrastructure to manage that alongside all my legacy monolithic stuff. Um, as I kind of think that whole thing through, are you seeing more work cloud native workloads starting to show up on BCF nine and has that whole motion of, uh, monoliths and microservices just meld it together into one management motion?
You know what's interesting? If, if you look at, um, kinda what the desire for Cloud Foundation was for the longest time, it was basically a platform ready for anything. Because un, unless you're a a day old startup that's kind of starting some crazy AI, whatever, ML based, you're gonna have a mix of legacy and new applications.
There's any number of large enterprises that say the magical words, like for tram based applications, which, you know, hearkens back all the way to the seventies, if you think about it, and you still need to support things like mainframes. You still need to support things that were written. Like there are pieces of code in there that are, you know, quite from a different decade at this point, but not from a different millennia, right?
So you need to be able to support both. You can't say we're gonna marginalize that somewhere at the edge of the data center. We're not gonna look at the energy footprint, we're not gonna look at how we secure it because some of the most precious data in finance runs on that kind of code, for example, right?
But then you have all of this newness in goodness, right? There's a lot of discussions around, um, AI being used for risk management for research and development, right? So you, you need to bear to marry both an infrastructure that is able to carry on and, and support all these older applications.
More legacy style, more monolithic first design in 1982, and also this kind of like new microservice based, lots of database interactions, very, um, storage intensive and network intensive, right? So how do you build for both? First of all, you need a strong hardware layer to kind of support anything, but then get the software layer to be in the service of this.
And that's where we accelerate because we build the features. And you don't have to constantly change you, you as the vi admin, you as the infra admin. The person that used to know and love vSphere now has basically a similar interface regardless of what you want to support going forward is your beloved vSphere interface that you've known since 1998 at the end of the day.
So, I know I didn't answer your question on the repatriation, but that's kind of, I was, I was trying to go for, for Steve Steven's question from before, but for the repatriation, we've definitely seen, um, an entire trend of certain applications moving from the public cloud. Like I've mentioned AI apps, there's definitely a concern from our customers of how much does it cost as my application expands in the cloud. 'cause they're very storage hungry.
They're, they, they require a lot of cloud operations as well. And with all the cloud environments taxing you for ingers and ris, then it becomes a little bit more difficult to control the cost because you want your application to run properly. You're not gonna look at it and go like, we can only do this much on it.
So private cloud becomes more interesting that way. Yeah. So I feel like we gotta adjust the, the elephant in the room, right?
A lot, a lot of people, when Broadcom first acquired VMware and, and you know, rumors and then the announcement of licensing changes, a lot of people were thought that was what a mistake. Everybody's gonna move, you know, each 'cause each cloud platform has their own in-house hypervisor, let's call it there, right? And a funny thing happened on the way to, uh, on, on the way to the cloud is people began to realize license licensing prices or license prices were not the most critical factor in people's decision on number one, are they moving to a public cloud or at least some, some infrastructure to a public cloud.
And number two, do they take, as you say, Sabina, that vSphere that they've been using since 1998 with them, right? And that I think is one of the big haha moments, right? That people are voting with their feet and their pocketbook and their moving vans to take that vSphere with them to the cloud, as well as upgrading what they're doing in the private data center right now.
Steven, I I know you follow this space really closely. It's kind of near and dear to you, but I mean, did you see that coming? You know, it, it, it's interesting because like you said, I mean, the elephant in the room here is everybody wants to, well, not everybody, but there's been sort of this sentiment that, oh, this is all selfish and this is not about the customer.
But that's not what I'm seeing from my friends in the VMware side. I, I'm seeing them very much focused on their customer's needs and very much focused on what, uh, you know, like I said, what, what is a practical way to move forward here rather than what is the, um, sort of the, the, I don't know, expected, uh, you know, app modernization approach? And, and, and the point is that, like you said, Alan, and, and your recent article on text on it, this was a catalyst for a lot of companies to get moving on modernization and to get real on modernization.
And instead of sort of continually being stuck in that, you know, well, we've gotta redo everything, uh, phase or just sort of being stuck in, well, we're busy with everything else, we can't modernize right now. It was an opportunity for people to, um, I think move forward and say, you know, what makes sense? Like, like, uh, you know, what, what Sabina was just saying, what are the goals?
Like, what do I want from a private cloud? Not sort of like, what does cloud, you know, with a capital C do, but what do I want? What are the essential elements that I need there?
I need flexibility. I need, you know, the ability to, to grow and to contract and to, to work in multiple areas, but also restrict from working in certain places. You know, geographically, I need to have the ability to be much more dynamic and programmatic and software defined in how, uh, infrastructure is deployed.
But I don't wanna just set everything on automatic and let it roll. I need to have this be something that is modern and yet managed. And, and I think that that's the flavor that's coming through with this release.
And, and frankly, it's maybe the flavor that was missing from, you know, some previous solutions and also some previous solutions from a lot of different companies. And in this space, which I think focused too much on modernization. And, you know, we have to look at who the customer is really, you know, we, when we do these text on gigs, we're always talking about the newest technology.
Um, all the, the cool stuff that's coming out from, as Sabina put it, startups, but who's really doing the hard work. If we look at the public sector, if we look at the financial sector, we look, look at, uh, telecoms, there is a huge, um, that that is, that is the core of, of software, to be quite honest. It is where software is, and Broadcom is always service that, that those sectors, and those are the sectors that tend to be more careful, more, um, more risk averse and maybe running to the cloud wasn't their first, um, goal.
Uh, but they're, they're now getting there. And to be able to do it safely within the construct, the, the kind of the constructs that they need to, to maintain in terms of how their software is built, how secure it has to be, and who's, who's there, who's using it, which is an important aspect of this conversation. They needed a better way to manage the ability to move to the cloud.
And VM started that, and that's where we started talking about high performance computing, but they couldn't get there that fast because of all the things we've just talked about. It is really hard to manage these environments really hard. So you get down to that one dashboard and you get to a place where you can actually have, you know, multi vendors, if, as, as Alan talked about, it makes it a reality for a public sector or a high risk, uh, financial application that they're not gonna break into microservices in the next six months.
So this is why I think that it is a catalyst, because it makes it a reality for these types of applications and the, in the, not only the, the developers, but making sure the end users are protected as well. That's the goal. And, you know, you know, this new platform and what the direction Broadcom is taken, uh, in, in the, in VMware is making it real.
Mm-hmm. Yep. So AI was gonna force the issue anyway, because if I look at the way it is gonna evolve, I'm gonna see a bunch of AI agents and they'll be handling networking, task storage, compute, whatever it is, but it will flatten the IT organization anyway.
So, um, isn't this, at least to me, it feels like the natural progression of things as we were gonna see this consolidation anyway, I 100% agree where in a lot of, uh, private equity, um, groups, these conversations are basically old. So there was a need for something like this for 10 years, almost like something that's a platform wide spans, and the future is in the intelligence of it, the right now, or for actually a reasonable amount of time. You know, you were stuck with doing things like troubleshooting, particularly manually, right?
You have to connect the dots, you have to know where to go into the platform to get the information. So a lot of the, um, what, what, what made an S-M-E-A-A subject matter expert incredibly important is when they had like that quick thought about where do I need to look? What do I need to configure?
What are all the best practices? But what makes infrastructure incredibly lean is when you can move a little bit past the kind of like nitty gritty day-to-day linking, you know, errors on an interface and more into what am I trying to achieve here? How can we get more efficient?
And then you can do a more agent way of running infrastructure. Like you're, you're asking your agent, Hey, give me the outputs on this interface. What does this mean?
How should I go about it? And then you get a bunch of choices on how to best manage and elevate your infrastructure. So we're seeing like the, but the first thing that you need to have is a continuous infrastructure.
You can't do this when you're running 160 products to run basic application infrastructure. It's, it's just too hard. And linking all of that manually, like we've seen customers try, and the the biggest challenge is it's all constantly moving.
So you're basically now stuck with trying to automate outputs between your different environments and, uh, software stacks to manage it. Like just, just log management. And I, you know, I, I can hear any number of my engineering peers go, like, don't start with log management and kind of prioritizing between all of the, um, P one alerts and so on.
And is this an important log? Just all of this is so incredibly hard and massive infrastructure that there is an absolute need for one, a platform that's kind of all encompassing, and two, something that helps you get insights from it. 'cause one of the things we've heard from customers is this is changing so quickly, right?
VCF is a, is a whole, it's an opportunity and a challenge at the same time, because I'm used to my vCenter environment, and this is just so much more, and we've put a lot of tools at the disposal of our, of our customers, like, Hey, here's how you learn, here's how you align with your business priorities. But that still requires a bit of a mental change of thinking, how do we operate going forward? What is the best way?
How can I be better and more efficient? And for an infra admin, that should 100% be an opportunity to kind of be with the next thing. Yeah.
I, I agree. You know what, and that's a actually a great segue, Sabina. It's a day of doing things first, you know, new, new things.
So in addition to this special edition of Techstrong Gang, we have kind of a first, a, a combined tech field Day tech strong sort of joint production. Spike Lee's not involved, but it is a joint production of, uh, of a Broadcom virtual event. Steven, you probably know the name of it better than me.
I, can I pass this over to you? Sure, you can, Alan, thank you very much. Yeah.
So we're gonna be doing, as you said, a uh, virtual Tech Field Day event. This is basically Tech Field day, except that rather than using the Standard Tech Field day scenario where we're basically presenting in the room kind of behind closed doors, we're actually gonna be live streaming it right here on Techstrong. So we're gonna be using the Techstrong virtual event platform, uh, which you can register for, you can join in.
Uh, we're gonna have a day basically of deep dives into various technical aspects of VMware's Cloud Foundation as part of what we're calling a, a VMware Cloud Foundation, VCF nine Showcase, uh, focused on the modern private cloud. So that is something that I've been looking forward to doing for quite a long time. You've seen me here on the on Techron gang, you've heard me talk about Tech Field Day.
I've really wanted to try to do, um, like a mashup of Tech Field Day and techron, and that's exactly what we're doing. So, so check it out on, on July 29th. Yeah, You can get to it, by the way.
com, it's the first one on there. You can click on it, register, and as I said, all the, the full day, and I forget there's five or six different sections, is Sessions, isn't, there's even, are all available streaming one after the next. They'll be on demand as well.
If you can't make it on July 29th, it will be a, uh, available for a few days after, and then eventually it will be available on the Tech Field Day YouTube channel, on the Tech Trunk TV network, uh, stations and so forth. But, uh, it is a virtual event, and I believe Steven, that some of the, uh, VMware Broadcom presenters will be live that day to answer questions and interact with the audience, which is always nice, right? We're gonna interact with a, a real not studio audience, but a real live audience.
Yeah. And that's what I've really always wanted to try to do with Tech Field days. Somehow give the audience, the people who are watching these videos, the ability to, to ask a question and to be part of it.
Now, the delegate panel, that's their job. They sort of stand in for those, for that audience. But in this case, as you said, they're actually going to be, um, made available.
So a lot of the presenters from, uh, that, uh, from those presentation sessions, including also some of the delegates as well, will be available to, uh, ask questions and answer questions and basically have discussions with the audience live. Uh, we're, we're trying this out. Uh, I can't wait to see, uh, if this becomes a New Tech Field Day gig, a new Tech Field Day Tech strong, uh, let's call it Techstrong Field Day.
How about that? I'm good with it. I, I like the joint production.
I feel like Spike Lee, I should be front row at a Knicks game or something. com, and you could register right from there. We're about outta time on this special edition of the Gang, though.
Sabina, I wanna thank you for coming on here into the Lion's den and joining us, so to speak. But you're now an official gang member, and you have an invitation anytime you'd like to come back. And we, we talk about this kind of stuff pretty often, so we'd love to have you on here.
Just come on down. Um, Mike, Tracy, Steven, thank you for joining. Thank you for watching us here on Textron Gang today.
As you know, after this, we'll go back to our Textron TV schedule for the rest of your Tuesday. Enjoy it. But, uh, we hope to see you on the 29th.
If, if you've used VMware, you, you think about thinking about using VMware, you're just thinking about modernization, moving from pri private to public cloud, or upgrading your private cloud. There's a lot you can learn on this Tech Field Day virtual event. Check it out.
But until tomorrow, this is Alan Shimel on behalf of Techron Group, have a great day. Hey, everyone, welcome back here to Tech Trunk tv. My next guest is Jimmy Mea.
Jimmy is co-founder and CTO of RAD Security, RAD Rad Security. And Jimmy's pretty well known within the cybersecurity world. I've, I've known Jimmy for years.
It's great to have you back on Tech Drunk tv, Jim. How you been, man? Good, Alan?
Yeah, I think the last time we hung out was in, was in Singapore at, uh, at, I was at RSA. Oh, that was An RA, uh, apac. Yeah, that was a while ago.
Yeah, right before COVID, I bet, right? Yeah, Yep. Right around that time.
Yeah. So could have Sworn I saw you in RSA. Yeah, it probably ran India there, but I think we actually, uh, yeah, that's sort Have A One of these.
Yeah. Yeah, that was pretty cool. Yeah, I wish RSA would do that again, like do the, the worldwide Maybe they will, you know, they, they, they're on this new trajectory now to be the community and I, I hope they'll start expanding again in, into, uh, Asia, Europe.
Yeah. Anyway. Hey, but enough about them.
Let's talk more about you, Jimmy. Tell people a little bit about kinda your background and your journey. Sure thing.
Yeah. Um, I, I've had a long, long tenure in cybersecurity, so, uh, 16 or so years. Uh, fun fact, I had the, the first cybersecurity degree from Penn State.
So I was NSA sponsored, um, you know, kind of computer science switch over into offensive hacking and CISO roles. Uh, worked a lot at AppSec. And then all, all the roads led to infrastructure security.
And, um, then about four years ago, uh, you know, joined up with, with Brooke, my co-founder, and we started what was, what called KS O. And now, uh, we've been RAD security for, you know, a little over a year. And, uh, yeah, it's been, it's been a journey.
So, done a lot, um, still a lot more work to be done now. Agreed. Agreed.
Um, talk about rad security a little bit. Yeah, so, uh, we, we started with the mission of, um, kind of rethinking how, how cloud security and container security, you know, are done. Um, the evolution of rad security was, uh, always, always meant to be, you know, real time solving real problems with all of the context that you need to, you know, secure, um, highly ephemeral, fast moving, um, cloud workloads and, and cloud assets.
And that has, uh, been kind of snowballing into, uh, what we are today, which is still, you know, those, you know, solving those problems at our core. But, you know, helping teams do more with less. Uh, the big, the big thing are sort of AI offering these days.
Um, and our AI native tooling and detection offers is, is really that, that team extension. Um, so we have a lot of different, uh, you know, we call them rad bots, uh, that, you know, act as, as independent autonomous agents that can, you know, take on complete tasks, um, from start to finish for security teams. Um, so that's what the platform does.
Uh, and, uh, we've been hard of work just, just trying to solve those problems, um, and using AI in the process. Very cool. Very cool.
We all seem to be using AI in our process, Jimmy, right? That's right. And we, uh, you know, you, you can't walk three feet without tripping over ai.
And now, of course, agen, I had a guy tell me today that, uh, you know, the whole generic AI experience was sort of ephemeral a halo, and it's all about agentic ai, and that's what, you know, where it's at. And of course, today that it is, maybe yesterday it wasn't, and tomorrow it probably won't be again. But right now anyway, it's, you know, not the age of Aquarius.
It's the age of agentic ai. So talk to us about, now, I've always, well, I have thoughts about how much of a agentic AI is just dressed up APIs, right? API integrations, how much of it is just, uh, generative ai, you know, wrapped up?
Tell us, you know, gimme your thoughts on this. Yeah, there's a lot of, uh, yeah, mar marketing, uh, speak circulating on a GI AG agentic ai, and it is hard to kind of differentiate what's real, what's not. Every, if you don't have an AI offering in your product, you're, you're behind.
Um, and I think for us, the, we started using, well, I'll say LLM inference for core detection capabilities, um, a while ago. So we never, our runtime product, you know, has always been, you know, AI centric. So we, we kind of learned the ins and outs of how to do that at scale in very high throughput environments.
And then, um, we, I guess, saw the light because it worked and continues to work really well for that use case. But it's not as easy as kind of slapping an LLM on top of a, you know, data or, you know, just summarizing a finding that existed prior. It is different, um, when you're, you know, deeply embedding ai, we'll say like AI infrastructure or, you know, agents into the, into the, into a product or a workflow.
Um, so, you know, an AI agent itself, things that we do, um, you know, if we check every box of an agent, but we do, uh, a lot, and a lot of that is, is the ability to, to plan, right? And, um, be autonomous. So run and execute based off of triggers or conditions, passing data from one agent to the next one, bringing a, a human in the loop when necessary.
Um, integrating with other systems where it's, you know, you know, uh, external third party SaaS products or databases or, um, things like that. So you really have more of a goal oriented autonomous AI enabled workflow versus the chat GPT one shot prompt experience, right? Right.
Where it's like, you can get a lot out of that. You could paste your logs in, you know, file and send it to chat PT and ask it to do things, but it stops there, right? It's not, it's not doing that in a autonomous fashion.
So, um, I think a lot of cybersecurity tools have just done the, like, I'm gonna summarize my findings with, you know, an LLM and have a little, you know, magic wand next to it, and we're gonna call that, you know, we're AI native, it's useful, but it's not really leveraging AI to its fullest extent, um, to get tasks done, which is what we're, we're trying to accomplish with our product. You know, I, I'm a, after I'm done in this studio or in this setting, our studio, I, I'm heading over to our shimmy said, set over there, and I'll be talking about AI and Microsoft, you know, announced this thing this week, a study, but AI being four x more accurate with diagnosis for doctor, you know, for medical conditions than human doctors. The fact of the matter is, as it relates to generative ai, it seems like, excuse me, all of the attention is being focused on how well it could write, which is kind of what you were talking about, right?
You give it a bunch of stuff and say, write me a summary. Mm-hmm. And it, it's good for that.
Uh, marketing writing is, it's good for, but then you get like, um, uh, you know, what else? Is it good for coding? People are using it for coding a lot, right?
Yeah. Like, there's an outsize amount of attention spent on that, it seems, I don't know, Jimmy, um, where, you know, it, it, it, it's, it's, there's a magical element to it. I'm not like, I, I don't want to be, I'm not crapping on it, you know what I mean?
Yeah. But how much better is the a true agent AI experience gonna be? I think we're in the biggest boom that of, you know, technology boom that I, through my lifetime, um, I, I, it's the experience, it almost sounds dis dystopian, um, is, you know, we're, we're go, we don't, not gonna need to hire, you know, instantly think of hiring somebody when we have a problem or a project or, you know, a long-term, um, goal.
We're going to think, can I, you know, and, and should I deploy an AI agent to own this task and have it report back to me? Only one appropriate? And I think we're headed in that direction pretty quickly, where yeah, it's not perfect, right?
But humans have never been perfect in, in their assessment of large data sets and, you know, noise, and the people make their own level of hallucinations. So I, I think what AI is gonna be really good at for security practitioners is, is just distilling and contextualizing the volume of data that you have to deal with on, on a day to day. Um, and just knowing where to look for those things that, you know, getting, getting tasks done that you typically would've planned for a quarter, uh, a year.
It, it, it really is, you know, heading in a direction where, yes, you need expert security engineers to know how to interact and prompt and ask the questions, where to get the data, but a lot of that heavy lifting of, you know, just boilerplate, um, you know, stuff is gonna be taken care of by ai. And I, I think we're way closer to that than a lot of people think. I, I don't disagree with you.
I don't disagree with you at all. Um, let's talk specifically about security, though. What does this mean for security?
Well, it's ev it's, it's everything it feels like in security is always a, a, a trade off or like a double-edged sword, right? On one side, I think the efficiency gains that we'll get, um, for compliance, security, engineering, the traditional roles, uh, they're, they're huge, right? And, um, they can't be ignored.
But on the other side, now we have to protect this new extremely sort of volatile morphing infrastructure that is ai, um, you know, we have to protect ourselves from that, right? We're, we're, we're now unleashing new technology that we don't really know how it's gonna respond. Uh, MCP servers and, uh, you know, vector databases and RAG and all this stuff is like, becomes yet another data problem.
Um, so we have to protect the tool that we have to protect the ecosystem that's giving us all these efficiencies also. So it means security teams have, um, in one side, you know, maybe some of the boring stuff that we've been doing for years gets automated. On the other side, we have to level up in how we actually protect AI workloads and, and the usage of, of this kind of infrastructure, which is still very nascent.
Got it. Um, Jimmy, I wanted to just mention another term. You get your GTP wrappers.
Mm-hmm. What do we mean? Yeah, I think when people say, yeah, GPT wrappers, it's, it's a, it's a way to leverage, you know, a a a popular frontier model.
You know, like, uh, you know, four oh or something kind of the chat GPT experience, um, leverage that inside of a product to kind of say that you are doing ai and we see this all the time, right? It's like, um, it's, it's the, the generic chat bot that comes up in the product and you can ask it questions or the intelligent summary feature, right? These are useful things, but they're really just throwing your traditional hard-coded finding text into a GPT wrapper and giving you like, you know, a better overview.
Um, and, you know, there's, there's, there's nothing wrong with that inherently, it's just, it, it know, it shouldn't be confused with actually building AgTech workflows that Right. Are autonomous, right. Very different.
Well, think missing thing is autonomy there, right? Yeah, exactly. I mean, to me, the, the classic GPT wrapper is, you know, when you do a Google search now and it comes up with the little Gemini think first.
Mm-hmm. Yeah. It's a little bit of a better mouse shot for search maybe, but maybe if it's accurate.
But, um, yeah, I mean, I, I'm, I'm, I'm glad Google's embedding Gemini somewhere at least, so it's not, you know, it's a step in the Right direction. Well, so they changed the name and do something else. Who the heck knows?
But yeah, but I, you know, it, it's interesting, you know, so from where I sit, right, it's not just security, it's development, it's cloud, it's infrastructure, it, and ai of course. And it's just, you know, you see, like you said, it, it's hitting everything, but some of it sticks and some of it doesn't. That that's kinda my, you know, and a lot of it is more hype than real.
But here, I think what you said is true though, too. Like every, all of these kinds of things when it comes to security, it's a double-edged sword. 'cause the bad guys are doing using it really well too already.
That's true. Yeah. That's, uh, we were talking about this yesterday, like when a new CVE comes out, um, and that CVE could actually have been discovered by AI coding analyzers also, but it used to be the turnaround time from like discovery publication to exploitation.
You maybe had a little bit of time. Right now, I think it's changing quite a bit because if you have a little bit of information on the package that's vulnerable, where it's used, like the attackers can literally supercharge their, their methods on deploying that, finding those issues and exploiting a CD like, that's just one example. But yeah, they're moving fast for sure.
Agreed. All right, Jimmy, we're about outta time. Did we mention Rads website?
Yeah, we're not yet. ai of course. Um, of course, yeah.
As, as, as one does. Um, yeah, and I'm, I'm, you could find me on LinkedIn. Easy to find Jimmy Mea, uh, happy to chat.
Uh, um, we're at all the conferences. We'll be a black hat and, um, you'll Be a black, we'll be there, actually, we're gonna be doing video on the show floor there. Okay.
So if you see me come over and say hello, I'll, I'll definitely come, come, uh, say hi. Yeah, we have a booth and we have a bunch of new team members. We're growing.
Um, we're hiring engineers, so if you like building AI agents also, um, definitely let me know. Very cool. I I'll see you in, uh, summer camp.
It's gonna be hot. Yeah. Oh man.
I'll be, I'll be inside out there in August. Me too, man. Don't look for me outside.
All right, Jim, it's great seeing you. Good luck with Rad. Keep us posted it.
It's gonna be an exciting time. For sure. Yep.
Thanks Alan. Good to see you. Alright, Jimmy Mess, the co-founder CTO Rad Security here on Tech Trunk tv.
We're gonna take a break. We'll be back. Hi everyone.
Um, thank you very much for joining the Techstrong AI Summit. Um, my name is Dr. Katie Paxton fair, and I'm gonna talk about, um, kind of where I see some of the big AI threats coming from.
Quite often in the media, we've really heard about AI being like a force multiplier, maybe hack bots you've heard of, and a lot of people are worried about AI really coming to hack Queue. Um, now I don't know whether or not AI is really gonna hack you, but I think it might just get you hacked because there is a real growing challenge of securing the AI slash ml supply chain that I think not enough organizations are really thinking about and talking about as they kind of go into the new AI era. So my name is Dr.
Katie Paxton, fear, I'm a principal security researcher at Traceable by Harness, and this is my AI threat top five. So these are the five risks. So when I speak to organizations and how they're adapting to the new AI era, um, this is kind of some of the threats that I can see as a hacker myself.
So the first one is really on de rely developers relying on AI generated code. So this could be your developers using tools like maybe windsurf. You've probably heard a lot about vibe coding.
So that's non-developers being able to use, uh, things like cursor in order to actually generate entire applications from scratch. Uh, a lot of the time now we're actually seeing that developers are not even professional developers. They're maybe just, you know, they can be your sales staff, they could be your marketing team.
They're not professionals. And with that, we're seeing a lot of threats being reintroduced into Cobas. The second risk we've got is about data platforms.
Now, a lot of organizations nowadays really understand the value of data, and perhaps even more so in today's AI era that we've got, there are these platforms that ingest data and can give you a lot of insights into what that data shows and how you might wanna change your business based on the results. Unfortunately, with so much customer data, it makes it a real target for attackers. Uh, these platforms are often targeted.
Um, they are often, you know, people are getting things like phishing emails. It's one of the key ways attackers are actually targeting organizations. Thirdly, we've got AI tooling within organizations.
There's a lot of tools that organizations can now use in order to be more efficient or to really get the benefits of ai. And it's important to recognize that these two can be a risk of both. A security risk, also a business risk for my, for my favorite, fourthly here is suppliers and suppliers and suppliers of suppliers using ai.
You know, nowadays your security is not restricted to the brown bounds of your organization. It encompasses a ton of different, um, products and services that you use. And while you may not be using AI in these ways, there is no guarantee that one of your suppliers isn't using AI generated code or using a data platform.
And your customer data or your data as a company may be in there. And finally, it's how organizations are implementing AI into their products. So thinking about, you know, nowadays every application has AI in it.
What does that actually look like? What data is being set? So let's start with number one, developers relying on AI generated code.
Look, it's fairly obvious. Developers don't wanna write tedious code, right? Developers often say they think AI to be kind of like a calculator.
It's a tool that makes their job easier. It allows them to kind of automate very simple tasks that are just time consuming. Or as someone on Reddit, put it, use it like an intern.
Let it do all the work. You don't, don't feel like doing, but check its work. And if you look at the stats, you know, people are using AI generated code more and more and more.
Um, this is becoming really, really common. So what can we actually do about it? I think everyone's first reaction is to go ban AI generated code like ban ai.
Stop it. You're not having cursor, you can't have windsurf, you can't have anything. I think it's wrong because I think that just leads to developers using AI kind of unpermitted by their organization.
Instead, I think you have other options. Invest in basic SaaS scanners in the build. Um, really make sure that you have got that in the pipeline with developers.
Give developers the tools they need to work. You know, give them the ability to use AI generator code. Give them ideas.
Now, developers shouldn't be using AI to write code a language they're not familiar with. Um, but at the end of the day, if they are, we can encourage the use of prompts that feature security and make sure when we are actually deploying that code that, you know, it's, it's going through a proper peer review process. A lot of people will say they do, um, you know, your, your typical reviews, code reviews, but in fact that's just someone seeing you looking over it and go, eh, it looks to go out, right?
So really encouraging, you know, developers to take a step back and actually read their code and make sure they understand that. Number two, data platforms ingesting all of your data. I think this is very, very attractive for a lot of organizations because it allows you to put all of your data in there and connect and then get those insights from that data by just uploading it.
Instead of needing to hire a data scientist or an entire data team or having to buy expensive software. Instead, you can put everything into the platform and then use, create or use interactive dashboards, prepare reports, and they can really start to understand the trends. And one of the kind of key advantages here is that many of them are low-code, no-code systems.
They are do not require, uh, experience. They do not require expertise. They require an understanding of the data.
And unsurprisingly, with so much data, attackers specifically target these. Um, whether or not that's something like we saw Snowflake recently and it's gonna be your more typical, um, you know, malicious download link, run it, and then the malware gets executed. Or it's in a traditional kind of like phishing attack where people will explicitly looking for API keys for things like Snowflake.
Data ingest platforms in general are huge targets. They contain so much sensitive data and because they're used by a lot of different teams within an organization, often it's not gonna have a lot of security oversight or it may be completely invisible to security teams. You know, with infos dealer malware, this is where we're seeing things, right?
We've got malware that specifically target these data platforms, API keys, um, or even the accidental commit of API keys to these platforms. These are all being used as a way to get into data ingest platforms. Three AI tooling within organizations within an organization.
There is lots of different, uh, ways that people use ai. In fact, I would hazard to guess that most people listening here have had a meeting where an AI has joined in order to, um, take notes really common. So things like note taking applications, but also, you know, if you do a lot of long documents, a lot of people will throw it into chat GPT and say, Hey, summarize this.
Some people will use speech generation or they'll use it for content writing. And it's really important that when we're actually thinking about these tools, we want businesses to be more effective. We want to give people the tools that they can have.
And then it probably won't be surprising for you to hear that I'm saying don't ban ai. Again. I think, you know, it's very tempting to outright ban.
It's very tempting to go, you are not allowed to use this stop. The problem is, is that if you ban people, they're probably gonna do it and just not tell you. And that's far worse for your security.
As we say at traceable, one of the best things you can have is visibility into what your applications are doing. And the problem is if you ban people from doing it, they're just gonna do it sneakily. They'll do it in a way you don't have visibility on.
So set limits on things like AI note takers. You know, you should not have meetings where customer data is being shared or intellectual property is being shared. Um, and ensure that really whenever you're using a third party tool, that you have those, um, SLAs in place to figure out what happens if there's a breach.
How are you gonna protect your customer's data? Next up, we have suppliers and suppliers of suppliers using ai. Look, no application lives in a vacuum.
It doesn't matter what you work in or anything. A lot of people still kind of have this perspective that applications are monoliths and they just exist on their own. This is not the case.
No application lives in a complete vacuum. Every single one has dependencies, they have containers, they have builds. And you need a continuous solution that really understands not just, you know, a single application, but an entire suite.
And this is particularly true for integrations. You know, when we talk about API security, APIs are used everywhere. This is not something where you can just do a search for API and just find it, you know, there are huge lists of public APIs that anyone can use and take advantage of, and APIs will use other APIs.
You've got this API supply chain. So even if you go, well, I'm not using ai, this isn't important to me. You don't know that maybe you are using one of these like APIs and they're using ai, you know, you have got a risk of that third party and it's really, really important that you know that third party and you are aware of that risk.
Um, and that's partly, you know, why having third party API visibility so important. And finally, we've got implementing AI into your products. It is so easy to add ai.
You know, you choose your preferred ai, maybe you go for philanthropic, you go to chat, GP t you go to pilot, you top up your account with some credits and, uh, you implement like a really easy to use restful API. You can even get AI to generate it for you. You don't need to know how to do that either.
Or you can use an existing library built into the language. Um, one thing that we're really seeing is obviously the rise of agent ai. This is the idea that AI is not just a chat bot anymore.
Now it's able to act autonomously. It's able to say, okay, you know, you ask, Hey, sorry, bye. Like, I wanna fly to the us right?
And it will go and look at flights, it will look at hotels for you. And then it will go and be able to actually go there and pay for it. And really, the intention here isn't to do this securely, it's to do it really well.
And that's a very difficult attack surface because you have so many different components. You have the AI chat bot that you are using. You have your AI agents that are going and accessing, you know, the website for, um, uh, the, the, uh, airline or the hotel.
Then it's using maybe their APIs in order to connect to, um, and actually make payments. It's connect to a payment provider. Like this is not a simple attack surface.
And certainly I think most organizations are very quick to jump on the, okay, we wanna have ai, we have AI everywhere. We really understand the value of this. But it's not that easy when you do handle AI input into applications.
Just do not trust the input. Um, look, if you look at kind of the sensitive data that goes through, you know, I think customer data, right? It is crazy how many people just trust it.
And if you look at the stats, the majority of people say, part of what they use AI for is literally just understanding data. Um, which is crazy to me because the AI can't necessarily do that in the way that, you know, a human can. So my advice, um, is, you know, perhaps unsurprisingly, uh, really look for when you see restricted data types.
So this is like a screenshot from the traceable product. So we do this automatically, um, but look for things like prompt injection, look for things like sensitive data. Uh, there's the OS LLM top 10, which is a fantastic project that really helps you understand the risk of, uh, LMS and applications.
But you've gotta always validate inputs, right? You cannot trust what an AI gives you the same as you can trust a human. So TLDR zero trust is a philosophy is gonna be more important than ever in the next few years, right?
It is more important than ever that not just you are secure, but your third parties are. And it is a must that you should include third party attacks in your risk assessments and security policies. If your security tool doesn't give you visibility into those third parties, it is not the security tool you wanna be using.
AI isn't going away, it's not a phase. It's here to stay and we need to figure out how to use it. This is not something we can sweep under the rug anymore, right?
We need to jump on this and make sure that we are being proactive. If we get too caught up in AI security like jailbreaks, we're really not seeing the bigger picture because it's not just about jailbreaks, it's about the entire AI ecosystem. And five, ai AI infrastructure is gonna be targeted more in 2025 and beyond.
And I'm gonna leave you on that really cheery note. Uh, thank you very much everybody. I hope you have a great rest of the conference.
Hey guys, thanks for the throw. We're here with Alex Lawrence, who's director of cloud security Strategy for sig. And we're talking about a community SIG is launching around a, a, a gaggle of open source tools, shall we say, that they have released over the last year or so.
Alex, welcome the show. Hey, thanks for having me. Michael, Walk us through what's going on here.
I know that there's a bunch of these tools that you guys have put out and over time, and now there's each one, I guess is its own little community, but maybe you're bringing 'em all together. How's this plan coming together? Yeah, yeah.
So, uh, at sig, um, we basically believe the future of cloud security is open source. Um, and so we're kind of doing what we say, right? Trying to build a community around that to grow it.
Um, so we've got four projects we're pretty heavily involved in, right? There's, there's Falco, which is the one that people know cystic associated with the best. Um, there's cystic open source, not to be confused with the cystic commercial product.
Um, and then there is a wire shark, which everybody knows about, right? Um, and then a new project coming out from the Wire Shark Foundation that's called Strato Shark. Um, and so those, those four are coming together into a brand new community that we're building and pushing out.
Hmm. Which of these communities is the strongest right now? And is there a cross pollination between them all?
Yeah, so the strongest by far is the Wireshark community, right? Um, it's been around for a very long time. Um, people have been using it for, for decades.
It's a, it's an amazing tool. Um, and the way this kind of starts coming together is this new iteration, this thing called Stratos Sharkk. Um, it actually is the wire shark interface with Falco Guts, is the, the best way to put it.
Um, and so it, it uses Falco libraries to understand a new dataset. So historically, we know Wireshark has always been about packets, um, you know, intercepting packets, reading packets, uh, sniffing packets, doing everything with packets. Uh, Falco is allowing Wireshark to be able to intercept system calls from hosts from Linux kernels, uh, from cloud logs, like AWS Azure, Google things.
Um, and so it's bringing the Wireshark, uh, forensics power to brand new data sources that are heavily used in the cloud, uh, to look at cloud workloads, containers, things like that. Alright. Are you looking for folks to contribute to these projects?
I mean, what's that process look like? And, 'cause, you know, not all open source communities, or shall we say, equally open? Yeah, yeah, no, that's, that's the goal here, right?
Um, all of these projects are, um, either, you know, backed by SIG or the Wireshark Foundation or the CNCF, um, open Contribution super welcome. We encourage anybody and everybody to, uh, to get their hands on it in some way, shape, or form. Um, and that's one of the reasons behind building this community.
So we can bring these kind of brains together, these groups together, right? Because, you know, Falco is part of the C ncf f um, Stratos, sharkk and Wireshark are part of the Wireshark Foundation. Cystic OSS is part of cystic, uh, um, and so we're trying to build a spot where all these folks can come together, collaborate, come up with new ideas, work together, submit prs, whatever it might be, um, but come up with new novel ways to leverage this stuff and work together across these different paradigms.
Um, open source has had mixed success in different segments. It's huge in application development, um, maybe not as widely embraced in the security space, and IT management is probably somewhere in between those two. Where are we on this journey?
Is open source gonna become more pervasively used and what kind of is holding everybody up a little bit? Yeah, no, it's a great question. Um, basically, uh, open source is the thing that powers the internet, right?
Like, uh, you think of Apache, you think of Nginx, you think of all the different ways that we present, uh, data on the internet. It's all derived from open source. Um, this new generation of infrastructure is all on open source, right?
Docker, uh, containers, Kubernetes, um, all of these things are powering what this next version of the internet is looking like, and it's all open source. Um, and so one of the things that cystic views is that as we are shifting more and more into an open source technology stack, um, so are the surrounding tools, which includes security. Um, in particular, if you think about the way, um, our adversaries are working these days, right?
They're collaborating, they're sharing code, they're sharing findings. Um, if we treat our security program as a private competitive differentiator, we are putting ourselves on the back foot, so to speak, right? Like we are starting behind the game.
Um, and so a way to be better about that is to collaborate more in the open work more together, um, use standardized, um, things like these open source tools to help get ahead of the game, um, and keep up with, with our adversaries. So it's, it's one of those things that we see the future of security in particular, cloud native is derived in open source, right? Open source is powering the movement, it's going to power security as well.
To your point about that, um, you can't walk down the street these days without somebody leaping out to tell you about their great new AI thing. But we've been trying to meld IT operations and security operations for a while, and we want more of the IT guys maybe to manage those functions because we don't have enough cybersecurity people. Um, does this present an opportunity to kind of help drive that conversation?
Yeah, absolutely. Right. It's, um, it's a thing that, that we see more and more of these days where you kind of have that, you had like, you know, SecOps, you had DevOps, you had, um, uh, just regular ops people, now you've got titles like DevSecOps, you've got SREs, you've got all sorts of integrative, um, kind of workflows, job descriptions, functions, right?
Um, and a lot of that comes down to the fact that, uh, the way architecture looks today is dramatically different than what it looked like even 10 years ago. Um, and so everybody has to be multidisciplinary. You have to have security be part of that process, um, and more importantly, not necessarily owned by a security person.
Um, and so like that's forcing this function of driving it. And a lot of these operational folks, I mean, their, their, their career is built on the back of collaboration, of open source of, of this type of work. Um, and so it's naturally, you know, finding its way into that area as well.
Um, and so there's, there's lots of reasons why this is starting to happen, and it's an area that we are, you know, emphatically embracing. Hmm. Um, are there things in particular around any of these projects that you guys are working on right now that you kind of need help with?
Is there's, you know, what, what's the the next great thing? Yeah, I mean, honestly, the thing we need more of is just raw contribution, right? Like, we need people to, uh, get exposed to it.
I would love to see folks just playing and experimenting with Stratos, Sharkk, you know, how else can it be used? What are their data sources? Should we be pushing into that thing to do investigations?
Um, I mean, I think the, the most powerful aspect of, of Wireshark historically has been a, a forensics methodology to be able to go and do investigations, right? To look for how this packet traversed the infrastructure, how it impacted this or impacted that. Um, the, you know, right click follow options that you can do inside that interface are, are huge.
Um, there's a tremendous skillset around Wireshark that kind of has lagged behind, right? People don't use it as much in Cloud native. My hope, my aspiration and goal is that as Strato Sharp gets out there, we can kind of revitalize that skillset, bring those people out of the woodwork, and leverage that skillset for kind of the new era of, of computing, um, and be able to find new and novel ways to leverage that and use that in ways, you know, we can't think of by ourselves.
We need the, we need that collective brain, right? Working on this together, In my experience, at least with some of these open source projects. Um, sure, everybody wants someone to contribute code, but there's other things that need to be done from documentation to, uh, heck even raising financing.
So are there more roles for people in this space than just me being a developer? And is, is that something you need help with? Yeah, absolutely.
More than ever. Um, it's easier and easier to contribute to open source projects, right? It's not, it's not just about writing some novel piece of code these days.
Um, even just submitting like, uh, you know, PRS with ideas are, are a viable thing, right? Just getting into the community, contributing to the community. Um, yeah, I mean, it, it could be evangelizing at events.
It could be, um, coming up with this cool idea you want to talk at, like your, your local meetup or something, right? Like, there's all sorts of ways to do this that don't involve having to write any code whatsoever, right? Just being part of it, contributing to it, helping grow it.
Um, it, it's absolutely huge. So right now, what's your best advice to folks is they kind of look at all these projects. 'cause a lot of times I think folks look at this stuff and they go, well, that's interesting, but they're just a little intimidated about where to get started because they, you know, they download something and then they don't know what to do after that.
Yeah. Um, I mean, that's, that is literally the hardest part, right? Like, how do I go and do something worthwhile with this thing?
Um, and so what I generally tell folks is to just, um, you know, again, get involved. Come talk to somebody, you know, reach out, don't be shy. Um, the one thing I can say about open, open source in general is it's a very welcoming community.
And that's one that's built around all sorts of levels of people. Um, you do not need to be an expert to be able to contribute in a meaningful way. Um, and people are not going to disparage you for wanting to learn about something.
Um, and so, coming in, raising your voice, they're gonna share links content. Um, you know, I, I wrote a, a blog article here at Sig a few weeks back about how to get up and running with strata sharkk in, you know, in minutes. Um, and you're gonna find content like that all over the place.
And then as you experiment with it, you know, write your own stuff, um, show how you used it, talk about what you did or what you thought was interesting, uh, people love it, right? It's, you never know how it's gonna resonate. So I guess the biggest thing is be curious, right?
Be be willing to, to go and jump out there. All right, well, folks, you heard it here. There's a bunch of like-minded souls getting together around a couple of open source projects and well, now is the time to join.
'cause a, that's how you learn. And b heck, maybe your next job is there. Who knows?
Hey Alex, thanks for being on the show. Yeah, thanks for so much. Uh, great to be here.
All right, and back to you guys in the studio. Hey guys, thanks for the throw. We're here with Kyle Haner, who's principal architect for Security and Privacy Technologies at Cable Labs.
And we're gonna be talking about, well, what kind of threads does AI represent to our networks? Because, well, we're supposed to be doing penetration testing, but I think the bad guys might be doing it a lot more. And hopefully the good guys will too.
Kyle, welcome to the show. Cool. Thanks Mike for having me.
Yeah. So what is going on here? We've had threats against our network since time began, but how is that threat landscape changing in the age of ai and what should we be thinking about here?
Sure. So, um, I think that the agentic AI is really changing, um, the playing field in a lot of ways, both for the people that defend the networks and those that attack the networks. Uh, it makes things so much easier to do, uh, you know, 24 7, um, pen testing or if you're trying to break into a network too, right?
So a lot of, lot of take, give and take there, You know, I feel like the networks are a lot more dynamic than there used to be. And people would do a penetration testing and then create a report, but by the time they follow the report, it was outta date 'cause the network had changed. Um, there seems to be a lot more dynamic IP addresses, all that kind of other things.
Are we able to keep pace these days with changes to the network? And, um, what is the best practice for penetration testing these days? Yeah, so I mean, I think you're right.
Networks have become far more complex. And as we all know, complexity is the enemy of security. Um, and so if we don't keep up, um, on finding where the vulnerabilities are in our networks, we're never gonna be able to keep up with the, the bad actors that are trying to break into them.
That's one of the things that, um, I think a agentic AI can do really well. Uh, as you mentioned, changes in the network happen all the time. And I think that if we have, uh, you know, agent agents that are constantly trying to find the vulnerabilities in a network, they can work 24 7 and uh, help account for those changes, alert us to when something puts somebody, puts something online that's vulnerable or somebody's credentials, were compromised.
That happens all the time. Uh, and so having this, this, um, intelligent, uh, planning agent that can do this for us is really changing the game. Pen testing typically also happens, you know, you, you hire either some out side firm to come in and, and do the pen testing for you.
And that happens once a year, maybe, maybe twice a year. But we're talking about ongoing basis is, um, is really important. Uh, the other thing to think about is that most networks should be, if they're not already moving towards like a zero trust architecture where you never trust, you always verify.
I think what agents give us in the sense is they add one more thing to that it's always, it's never trust, always verify and continually validate that your zero trust architectures are functioning the way you think they are. Mm-hmm. Speaking of zero trust, I mean, it's one thing to use an AI agent to create and run the penetration test, but there'll also be, um, thousands, maybe millions of AI agents that will outnumber the number of humans attached to that network.
And how do I know which of those agents is, you know, something for good and versus something for evil? Right. Well, I think that one of the important things is not only applying zero trust to your networks, but applying the zero trusts, um, methodology to your agent architectures.
As you build these out, you're right, there's gonna be thousands of agents. They're gonna far outnumber your human actors on a network. Um, it's important to have a good cryptographically verifiable identity for each agent, um, so that you can know exactly which agent is doing what on the network.
And then you're also gonna have to really narrowly scope what your agents are allowed to do as they ev if they do penetration testing, if they're doing HR work, really make sure that those agents are only acting within their very narrow s scope scope. Mm-hmm. To your point about continuous penetration testing, how hard is that gonna be?
Because for the bad guys, they're just going to use AI to create some sort of test and run it. But, uh, on the good guys, it sounds like I have to create something that feels more like an actual layer on the, in the network that's gonna communicate with something that is an AI agent that's running these tests. And, um, it almost sounds like that's a, a far more hercule and complicated adventure than what the bad guy's gotta do.
Well, I think the nature of, of cybersecurity has always been asymmetric, right? It's always harder to defend something than it is to attack something. Um, but I think that a AI agents will help us this.
And let me kind of explain a bit what we did, right? We took, um, the parrot security os, which is related to the Cali, if you're familiar with that. Um, and we took the hierarchical menu structure of that os because it's broken out into, you know, here is a, uh, reconnaissance kind of tools here are post exploit tools, those kinds of things.
And we created our agent architectures following that menu structure. What this gives us is a lot of extra context that we can feed the agents, these large language models behind the agents, uh, to do this penetration testing. Um, and we did several different kinds of architectures.
We did ones where it's kind of like a hub and spoke architecture where there's a central planning agent that can call their different agents that run different penetration testing tools. We broke it up into like how you might form teams to do pen testing, where there was a central, you know, managing agent and they had sub-teams were looking like, here's the reconnaissance team, here's the PO post exploitation team. And we ran different scenarios on that to see which one was the most effective.
And we also did some things 'cause we wanted to know kind of how bad actors would use large language models to do this kind of stuff. And so we tested both highly quantized models, things like LAMA you can download and run locally, um, versus the, you know, very powerful models that you find online from open AI and, and Google. We found that the highly quantized models, uh, were more, far more prone to, um, hallucinations.
Uh, we had some very hilarious, uh, interactions between agents where they would almost get into arguing contests about their, whether they're in a loop, whether they found, you know, the certain flag that they were looking for, those kinds of things. But the very powerful models were really good at staying on track, not hallucinating, and eventually getting to the goal, usually finding a flag or finding an exploit. Mm-hmm.
Um, do we have the skills necessary to achieve this? And I'm asking the question because it's hard enough to find networking people who know something about security and vice versa. But now I need networking skills plus security skills plus AI skills.
Um, where am I gonna get that? I mean, here's where I think AI can kind of enhance those that, you know, have certain, have, have other skills. Um, I think we've seen this in other fields too, but I do see that, you know, in the, in the realm of penetration testing, you'll have, um, people that are human in the loop where you'll set parameters for your agents to, you know, have certain categories of of risk they're allowed to go forward with.
And if they find something that might be above that, then they, they kind of tag the human into the ring, um, say, Hey, look at this. We, this, we found, I found something that's interesting. Maybe we should stop here and, you know, get the human involved.
Um, but I think that, you know, I, I think that agents and AI can hopefully enhance those skills where they're not, uh, necessarily built out. Um, I guess the time will tell. Mm-hmm.
Have you seen the bad guys actually using these techniques yet? I mean, is there evidence that they've un understood that they can use AI for this? Or are we just trying to get ahead of them because we know it's almost inevitable at this point?
Yeah, there, there's actually a whole list of, of hacking as a service. Large language models that are already out there that bad actors are using. Um, you know, they're probably built off of one of the open source models, um, and hosted somewhere in the world.
But yeah, we're seeing things like, um, you know, creating malware, using LLMs, um, I think pen testing another one of those things that's is happening and there's, there's bad actors that for sure are, are looking at this. It, it just, you know, in our general lives, we've found that AI increases productivity. That also is true for bad actors.
Uh, they're able to do more with fewer skills and less time. So yeah, it's definitely out there. So pen testing has always been one of those things where it's a double-edged sword.
The good guys use it and the bad guys use it. But, um, in, but the rise of ai, are we not maybe involved in some sort of new AI arms race for security? And this is kind of the thing we have to come to terms with?
Yeah, I think that's, I think that's definitely true. I think that, um, fortunately I think that, uh, the, the biggest, most powerful models have some, I mean, it's harder to access them, right? There's costs involved, there's, they're centralized.
So those companies are doing extensive monitoring on how their models are used. Uh, I think the bigger concerns are, um, you know, the open source models where you can download them and use them with relative anonymity. Those are concerning in, in this sense.
Um, they're not, I mean, so the, the larger the model is, the more, um, useful it is for this kind of thing. Uh, so those, some of those large, like deep seek, the very large versions of deep seek are concerning to me for this particular thing. Uh, especially the change of thought models.
Those reasoning models have really made pen testing, um, more effective, uh, in for, for AI anyway. Right. Um, So what role will your organization play in all of this?
So you gonna become essentially a, a clearing house for research in this space. Are you guys maybe gonna help folks build some of the models that the good guys might need? I mean, what's your ambition here?
Yeah, well, lemme tell you a little bit about Cable Labs. Uh, first, I guess, so Cable Labs is a, a research and development firm for the cable industry. Um, we're a small lab, we're about 225 people, but you know, we've, we've had some big impacts overall.
I think that, uh, a stat I read was that a half a billion people use Cable Labs technology every day. And there's like a little over half a billion devices that are, have been shipped that use our cable modem specifications. So, you know, small lab.
But we, we try to do big impact work. Um, and, you know, working with these large ISPs in the world, um, really helps us gain, uh, knowledge and, and access to these large networks that we can, we can help, uh, protect. Um, so yeah, but I think that, you know, we do, we try to do some research in AI that, um, we look at is, you know, it's hard to, our goal is five years out, but AI five years out is, is like, you know, so impossible to predict.
'cause three months ago everything has changed, right? So, uh, the big things in AI we're looking at are, of course, how do we secure agents? Um, how do we secure, uh, MCP servers?
Those are the model context protocol servers. Uh, we think that these are gonna be used in networks and by our members. And so we're really looking at how we secure those, how we do access control on all of this.
Um, there, it's moving so fast, uh, that I think we need to make sure we proactively plan that built in from the very beginning. Um, so yeah, there's, in AI in general, we've also done some research on, uh, on adversarial ai, which you've seen probably where you can, you know, usually those examples are, are, are visual. So you an AI will look at a picture and completely misinterpreted.
The famous example is a few stickers on a stop sign can change it to a speed sign. But we've done some research on that, on how does ai, if you were to use this within the network to do, um, you know, automated services, what, what possible things could go wrong with that, how could it be deceived on network traffic, for example? And so we've done some research there, which I think is kind of interesting.
But yeah, our whole goal is to do, uh, look a little further out on how, how security will play within these AI driven and smart networks. So what's that one thing you keep seeing folks doing over and over again when it comes to network security that just makes you shake your head a little bit and go, folks, we need to be a little bit better than that. Yeah, I, I mean, um, poor access control continues to haunt, uh, you know, the whole industry, not just cable, but everybody.
Um, I think that when we add AI agents into this, making sure that we have strong access control, strong identity on the network is going to be really, really important. I think that as we start to plan out how we do, how we deploy these agents, as I said, a cryptographic identity is super critical and a narrow scope for their access. Um, I think that there's some basic things we're gonna learn that, uh, you know, we're going to segment what humans can do on the network versus ai, I think, and making sure that we don't share credentials between, you know, our human entities and our agent entities on the network.
Um, be very prescribed in what we allow the agent entities to do on a network. Um, having guardrails in place, uh, making sure that, you know, as these agents use, you know, all, all large language models have a bit of entropy, a bit of redness built in, which is good. It makes them flexible in their productions and everything, but we also have to make sure that those edge cases, we have some guardrails in place so that those edge cases, uh, don't come back to haunt us.
All right. Well, folks, I heard it here. It's still early days as far as AI and networks and security is concerned, but even in the age of ai, you know, a and ounce prevention is still worth more than a pound cure, right?
Hey, Kyle, thanks for being on the show. Thank you very much, Michael. All right.
And back to you guys in the studio. The six five summit is back in its sixth year. We are in the first day at our for opening day one speaker here, Daniel.
I'm looking forward to the summit, and we are talking about everybody's favorite topic, and that is ai. Yeah, we will cover a little bit of AI here, and it is the open for day one, pat, and this event each and every year. I just continue to be blown away at the amazing contributors and the people that we have as part of it.
We hope everyone out there is tuned in. Yes, you can catch these on demand, but we would love if you'd hang out with us because we are gonna be talking about AI and we do have some of the foremost experts, CEOs, business leaders, people that you want to hear from, and people that we're lucky enough, pat to get to spend time with here at the summit. Yeah.
And aside from ai, our second favorite topic, maybe it's our first favorite topic, our semiconductors in Silicon. Daniel, I always like to say that, uh, okay, I get the software was eating the world, but it doesn't run on air. And if I look at the valuations of companies, uh, a lot of them are hardcore in infrastructure right now.
And one of the big innovators in this space is Arm. And I am very happy to introduce, uh, Renee Haas, a friend of the six five. We're gonna talk about AI native compute in an AI native era.
Renee, welcome to the show. Thank you, pat. Daniel, good to see you.
Yeah, I mean, it's great. You have your own podcast now, and I just can't tell you how much I appreciate you coming on on another podcast to do this. Wonderful.
And my, my, my life, my life is podcasting. Um, but yes, no, super happy to, to be joining you guys. Yeah, That room looks like it was built for you to podcast in Actually, uh, it, it, it is a podcast dedicated room, but, um, we have made good use of it.
Well, one of these days what you'll need to do, Renee, as you'll need to have the six and the five, you can pick which one, come on, we're gonna come on your pod. We're gonna, we are going to wax poetic on all things AI and chip making and everything else that's going on, but we really appreciate you joining us. Uh, I know our audience is excited for this, uh, this keynote session.
So let's start off talking a little bit about AI because that's what the event we're unleashing, you know, we know AI Renee is driving transformations from data Center to device. Start with just giving us kind of the arm perspective on how it is enabling AI everywhere from hyperscale data centers to the edge. And kind of what role does AI play in your growth strategy?
Yeah, so the way to think about ARM is we are the most ubiquitous compute platform, you know, ever invented. Uh, 70% of the world's population uses arm, we're in the, the largest of data centers, but we're in the smallest devices like, like earbuds. And we run all of the quote, legacy software application software, whether it's an operating system, the apps, the hypervisors, all, all that compute stuff, you know, runs on ARM and it's run on ARM for years and decades.
As we think about AI going forward, uh, what we see happening is that increasingly the compute obviously still needs to take place on, on these devices. You're not replacing the operating system, you're not replacing the apps, you're not replacing the hypervisors. But what you are doing is you're adding AI payloads, AI acceleration, AI workloads on, on top of all that.
Uh, whether it's training in the cloud, whether it's inference at the edge that that's all happening. So for arm, uh, it's a, it's a very unique, I would call it, and opportunity where the general purpose compute that we've been known for, whether it's plugged in the wall or not plugged in, and actually not plugged in, is a, is really the sweet spot for ARM in terms of power efficiency. What we see is AI is now gonna run in conjunction with those standard compute workloads in some use cases more, in some cases.
How does it get optimized? So it's a gigantic opportunity for us, and, and what we're seeing is already, uh, at the data center, Nvidia Grace Blackwell, which is all arm, it's really accelerated a transition away from Legacy X 86 to ARM being the processor choice in the data center. But for us, we think the opportunity for AI is much more broad, uh, because AI will find its way literally into any of those devices I mentioned, and it will run on arm.
So what we're spending a lot of time on is how do we optimize that hardware experience and back to the software, make it seamless for developers to, to run the software on the, on the arm platform. Yeah, it makes sense. And Renee, when you said, I, I think you said 70%, um, I'm thinking that's probably a hundred, but I'm sure there's a good reason.
Um, you know, you can, you know, have a microwave oven with an arm, arm IP inside of it. Uh, but, but I, I understand it. It's a really big number.
It's pervasive, it's a really big number. Arm is pervasive. Yeah.
Um, I've really marveled at the way that you have added more value for your customers. Okay. I think 10 years ago, right, I was thinking to myself, ARM is such a valuable company to its customers and to society, um, seems like it would be bigger.
It seems like you could do more, uh, for those for, for those customers. Uh, and under your leadership, uh, you brought out what was called compute subsystems, um, A-K-A-C-S-S, uh, which, you know, a lot of people have described as, as a game changer. I mean, essentially, uh, you're taking on a lot of the, the systems, um, responsibility, uh, that would normally be up, up to other, other people.
Uh, can you talk about, first of all, um, how does this play into your platform first company strategy? Um, and, you know, you and I have, we've personally talked about, and, and I've seen in the press releases companies that have adopted it. But, you know, how is it, you know, how is it looking in the future?
Yeah. So, so let's maybe kind of start about with CSSA little bit at the, at the, at the lower level and then, and then maybe talk about it at the platform level. So, arms have been around 30, 35 years.
And when, and when we started, uh, the concept of delivering IP to a company in an RTL form and using Common EDA tools and third party manufacturing was quite foreign. And, uh, and kudos and credit to the armed founders to, to really start something that at that time was incredibly, um, novel and ambitious. And then what we saw happen over the decades is, um, the industry got really good at it, and tools got better, fab processes got better, and you could essentially take a piece of RTL, whether you're in 14 nanometer or 10 nanometer geometry and end quote, throw it over the wall to a customer, and they'd be able to take that RTL and, and deliver a very efficient design.
But what we've seen happen as we've gone from seven nanometer or five nanometer to three nanometer, a couple things has happened. Number one, people are putting a lot more compute down on these chips. Um, we've gone away from two core four core designs to mobile phones have 12 to 18 cores.
Auto chipps have 32 cores, server chips have 128 cores. Uh, putting all those cores together, that's, that's real work. Then.
Then secondly, when you start getting into the geometry, such as seven nanometer, five nanometer, three nanometer, squeezing every ounce of performance out of that technology is also a lot of work. Uh, so we looked at that and said, it's probably the time for us to think about delivering something that is going to create a big advantage for our customers in terms of not only developing ships faster, but guaranteeing that you're gonna get the highest level of performance. Because candidly, at the end of the day, ARM will be in the best position to know exactly how an arm processor is gonna behave on a given library on a given process.
So we kicked this off, uh, a few years ago, not long after I, I took over as CEO, and three years later we're starting to see the first products hitting the marketplace, uh, mobile. We've had a few out in servers already, and the proof points are there. Uh, the fastest processors on the planet now are being delivered via CSS and, and what that does for the customers.
Uh, obviously you've got the fastest product on the planet, but equally you've shaved a lot of time to market off of the, uh, the chip developments time. So that's, that's, that's just huge. Now, it's also important for us from a platform standpoint, because at the end of the day, any CPU ISA is only as good as the software and the developer community.
By delivering these platforms and getting products out faster, we can engage developers earlier, we can take advantage of the features faster, and we can essentially accelerate time to market. You know, a great example of this is everything going on with ai. When you think about, uh, Gemini, when Gemini was, when Gemini Nano was introduced and it got put on last generation's, uh, mobile phones, none of those mobile phones knew that they had to run Gemini at the time that they needed to run it.
So the, the software links were not there, hooks to the hardware not there. And that just gives us a, a big, big, uh, mandate to say at the pace of which these workloads are moving, we have to be involved in the system design because it, the software relies on it. So it's been, it's been something that, as I said, we, we started three years ago, it's now everywhere for our business.
We've had a lot of success in servers. Uh, we've had a lot of success now with Mobile, uh, very timely that I'm on, on this, uh, on this podcast or view cast, whatever we're calling it, because we just announced our, our automotive, uh, CSS, uh, and, uh, all of that is, is hugely beneficial. So, Renee, you're, you're also in a fairly significant transition to platform the companies.
One of the probably leading indicators is just how you've kind of re re uh, configured your naming strategy, right? It was very product focused for a long time, and now you're very platform focused. You have data center platforms, personal computing platforms, smartphone platforms, vehicle platforms, and kind of your small device edge embedded sensor platforms.
Uh, I wish I could memorize 'em all, but we'll start with Neo verse. That's probably one of the very, very well known and very popular, uh, um, Xena on automotive. Yep.
But the, the, this has been a fairly big pivot, and of course, the market's making a lot of kind of assumptions about how you evolve. I think this is a really great opportunity here for, you know, our, our audience to talk about kind of how is that evolution taking place. Maybe a little bit about why you evolve from product to platform, which I think some people probably it's very obvious, others maybe not so much.
And then kind of how does this evolution fit with the strategy of the additional value that you and Pat just were speaking of? And of course, the future, which many people continue to speculate that you'll become more and more critical in terms of full, uh, end-to-end involvement in, in chip design and innovation. Yeah, tha tha thanks for, for, for asking this question because I think it's a, it's an important one relative to ARM strategy.
When you think about what the essence, again, of, of a compute IA is at the CPU level, in, in of itself, it is a platform, uh, because it attracts such a large community of developers, again, whether it's around operating systems, applications, hypervisor, ai, payloads, by its definition, it is a platform. And I don't think we made it easy for our, uh, ecosystem partners to understand how everything stitched together. I don't think we did a very good job in the past of clearly communicating exactly how all the elements fit together, uh, because we were actually providing a lot of those solutions.
Now, CSS accelerated that for us, because it gave us, again, a, a methodology to be much more, uh, prescriptive in terms of how to put together these systems. So the naming, uh, to some extent for us was just a natural next step. Uh, we are very vertically market oriented, because the solution you need for something that is very low power that runs on battery for a few weeks is not the same as something that's running at hundreds of megawatts inside a data center.
So the solutions are different. Uh, the software platforms are similar, uh, so we wanna be very, very, uh, specific about that. But I think it's all a continuation of really, really making it clear to the ecosystem, the developers, that ARM is the compute platform for ai.
And, and I can pretty confidently say there, there's nobody on the planet who can provide that solution if you're running from milliwatts to megawatts. That's, that's unique to arm, and that's really the space where we intend to play. So, Renee, um, there's been a lot of, I don't know, industry debate on, you know, what are the things that drive ai?
Oh, it must be the GPU, it must be the accelerator. Uh, and then we, you know, we find out that most AI is actually run on a CPU, um, even on broadcast news shows. I get the question, Hey, how does ARM intersect ai?
And, and we have this conversation, but, um, when it comes to helping to solve, um, for widespread adoption, 'cause I think that's where we're at right now. Um, how are you helping developers and and customers overcome some of these, these challenges, especially, uh, on the software side where you can make a, an incredibly huge difference? Yeah.
So a ai, uh, there's lot, a lot, a lot of mystery kind of associated around AI from a software standpoint at times. And, and there are companies that will describe it as a, a brand new way of processing, a brand new way of computing. Uh, but to some extent, it, it is, uh, yet a different way of computing, another way of computing, but it's very reliant on a few things.
It's, it's, it's reliant on, on compute, obviously, but also also memory bandwidth. But again, because ai, that workload is not exclusive to the domain of the cloud, uh, people are gonna have to figure out how to ways to solve it inside conventional compute solutions. So back to the, uh, back to the, to the arm roll in this, the edge devices, the earbuds, the cameras, the automobile, the cell phone, they still have to run all that legacy software.
They still have to run it, and they still wanna do it in a power efficient way. They wanna run it in the cost efficient footprint, in a thermal footprint that matters. So then they look and say, okay, I, I've got, I've got a CP that's there, are there things that can be added to the CPU, whether it's around implementations in the micro architecture that accelerate AI from the instruction standpoint, and or are there things in the GPU or an accelerator?
So what role do we play? Kind of twofold. One is putting the hooks in the hardware that allow for acceleration, but probably equally important is make it easy for software developers through libraries.
And this is what we're doing with our c cloudy AI libraries to be able to abstract away what's inside the hardware. So the developer doesn't really need to know exactly what that NPU is, it's inside it. Um, if it's standard, it's much easier, and that's what we intend to do.
So, uh, that's probably the best way to think about it, pat, is that the, the AI problem is not a, a unique software problem from our viewpoint. It's a different problem. Uh, it's gonna have to run in addition to what's already there, and then you're gonna want to do it in as power efficient.
A way as you can, particularly with, with, with inference training is its own problem. People are not gonna do training on small devices, obviously, but training is the teacher and the world knows that we have way more students in the world than teachers. And, and inference is the student and inference is what's going to run everywhere, uh, o over for everything going forward now.
Yeah. So the TLDR is, is ARM has the ability to help not only you're running CPU on the, sorry, AI and the CPU, but also on the NPU, uh, to help reduce friction on, on the device itself. Yeah.
And be, and because it sort of starts with a CPU and you start thinking about, well, how do I solve this creatively in terms of memory, bandwidth, custom implementations, different types of solutions in terms of interfacing on and off the chip or the chip lit that all runs through us. So, you know, without tipping my hand in terms of our future products, I'm not announcing new products today. Um, we are, we are in a very, uh, unique position to help architect this in terms of, uh, where it all goes.
And, and for people who are, you know, who work for ARM in our, in, in our, our space, it's incredibly exciting for our engineers because engineer engineers love to solve hard problems. AI is a very hard problem, uh, because people want to be able to figure out how to do it inside of existing interfaces and existing workloads. So it's, it's a place that we're very focused on, but I think we're in a very unique spot to, uh, to address it.
I won't, uh, put Renee on the spot, pat, but you know, I love to editorialize. I've maybe been on the record a few times suggesting that I think, uh, while ARM has had a incredible role in AI through its cpu, small cores, things, it's enabling with, like you said, students and, and versus teachers. Um, I would not be surprised to see you become more directly involved in, in the near future, just watching how you evolve.
Again, not asking you to comment, uh, uh, but I think everybody out there is probably keep an eye on, on this company. Um, so speaking of keeping an eye on this company, um, let's do the future moment, the flash ahead to 2030 as analysts, pat and I love to predict at least five years out so that people never hold us accountable when we're wrong. Um, but in all serious, to further out we go, the less likely people remember.
Uh, and you only have to be right once, you know, to really permanently become and, and inflamed as a superstar analyst. Right. But Renee, as you look five years ahead to 2030, what, how are you thinking about success and what does that mean for, for ARM and, and you, how are you sort of defining it?
What goals and metrics are you setting to be where you want the company to be at the turn of the decade? The, the stuff? You know, it's interesting question.
Um, I was, uh, meeting with a, with a group of analysts, uh, yesterday, and they were asking me about, you know, what, what the smartphone is gonna look like in, in 2030, and, and how we viewed the growth of that market and, and et cetera, et cetera. And I said, look, there's no way, there's no way to predict what a smartphone looks like in 2030, whether it is still at the growth rate that it's at today, or it's something that looks completely different. You know, I'm, I'm older than you guys, but we're all of a similar vintage.
People will talk about the cell phone, such as it can never, the smartphone, that it can never be replaced. But this is a device that was just invented in 2008, so, uh, it's not actually been around that long. The way I think about ARM in 2030 is less about the physical device, um, because it may be, uh, a type of ambient computing device that we don't know what it looks like today, or a very, very different interface into a physical device where agents are running, et cetera.
So the physical, I, I can't really think about the physical too much in terms of what it is, but what I can focus on is that there's gonna be two domains, uh, plugged in, not plugged in, uh, running off batteries, uh, or running, running off of power. Uh, it is unquestionably gonna be running an increasing, uh, AI workload. That AI workload may be the dominant workload relative to traditional compute, because you may have things obfuscated away, such as apps and operating systems where agents now be talking to other agents, and everything runs kind of over the top.
So what I have to be sure of for, for Arm is that that all runs through us in, in some way, shape, or form. And that's why we're very, very focused on the developer community. Uh, we're very, very focused on, on the wide breadth of, uh, of devices that we can enable.
And we want to be sure that we are providing that solution, that value. I think we're in a great position to do that, uh, because again, legacy software, uh, hangs around for a long, long, long time. Fortunately, unfortunately, there's a lot of stuff that you need to carry and continue to run.
Uh, so I think that actually positions us pretty well for this. But to your question directly, what does success look like for five years? Uh, Pat's number of greater than 70%, uh, I have my number.
We're still running that vast majority of software, uh, on Arm. Uh, whether it's AI or non-AI or something even different and providing the best, uh, solution for the customers, That is the right answer for the CEO of Arm a hundred percent. And, uh, you know, we definitely, we definitely do appreciate, uh, Renee, that, you know, you've always been so, uh, you know, open, uh, at least within the constraints of someone that has a role that you have and sort of giving us, uh, your views and the vision.
It's been really pretty remarkable to watch the journey and even just the past few years, um, the company, and of course we didn't even really get to it, but projects like Stargate, um, yep. Watching all the things you're doing with your partners within SoftBank and the ecosystem that's being built and how this is all gonna play out. And of course, there's probably not a single person that's watching this right now, that isn't being touched in some way by arm on the device that they're using, um, you know, uh, in a car that they're driving, uh, in some sort of appliance that they're using.
So it's been a pretty remarkable and incredible journey. Thank you. Um, so congratulations.
We look forward to having you back in 2030 where we're gonna hold you accountable to everything you just said. Um, you know, for, for everyone out there, uh, you know, Renee, uh, definitely is out and about a bit in the, you know, across the social platform. So make sure you check it out and follow his, his comment and his podcast.
'cause he is got one, he is got that great room, he is got his own podcast. And if you're not watching the six five, that's probably a good one to watch as well. So thanks so much for helping us open up day one.
Hey, everyone out there subscribe for the rest of the event, stick with us. We've got so much more great content, we'll send it back. Stick with us.
The six five Summit is back in its sixth year, and we are talking about unsurprisingly ai. AI has moved from science projects to POCs to full scale infrastructure and platforms around ai. Our important, uh, companies focusing on what they do best and leaving the driving to other people.
Uh, many are making this choice and I can't imagine a better guy to talk about this than Dave Brown with AWS. Dave, welcome back to the show. Well, pat, thanks for having me.
It's great to be back. I think I've done these a few times before, but six years. That's amazing.
You have, you know, you're a friend of the, uh, friend of the six five and we appreciate everything that, uh, that you bring to the table. I know you don't do, uh, a lot of these, so it's been, it's been very, very special. Um, AI has just been, uh, incredible.
And it's interesting. AI didn't start two years ago. Uh, in fact, uh, you got the first jump on this with machine learning about seven or eight years ago, uh, and ended up being the leading provider, uh, for those, for those workloads.
Uh, things have changed though. Uh, you're putting significant investments all the way from Nvidia GPUs to your own, uh, silicon. So can you talk to us, uh, maybe do a, a double click, uh, maybe even talk about the strategy of how you're not just delivering the raw performance.
'cause there's, you know, there's a lot of people, uh, that can do that inside of, you know, the chip itself, uh, but also, uh, the usable compute power with the stability that, that you provide the security, uh, and also the scale as, as I said, enterprises are scaling ai. Yeah, absolutely. Well, well, pat, it's been an incredible journey.
Um, you know, I was, I think it's 14 years ago now that we put the first Nvidia GPO in the cloud. Um, and 14 years ago was actually a negotiation to convince Nvidia that it was a good idea to put one of their GPUs in the cloud. And, and boy, you know, how things have actually changed.
It's, it's pretty incredible. And, and, and that's been amazing. You know, we're, we've, we've had the hopper GPUs.
We, we just went live last week with the, the latest Blackwell, the B 200 gpu. So this, this very close relationship we have with Nvidia is, you know, just continuing to grow. And it's, it's been a lot of, uh, uh, very, very successful.
Uh, at the same time though, you know, we know that one of the most important things for our customers, um, is to find ways to innovate on their behalf. And specifically in this space, we've seen that if we can find ways, um, to reduce the cost, um, of machine learning, um, and to give them more performance for every dollar spent, is how we think about it. Customers typically do more.
And, um, you know, we started to see that in 2017, very early days of, you know, machine learning. And folks were starting to think about deep learning. This is long before generative ai.
Um, but we saw that the inference workload, we could unlock more innovation for customers if we could find a way to do more. And as you know, there's nothing that stops AWS from innovating. Um, we've been at the hardware and custom silicon level, you know, with our, our processor on graviton, and we thought we could do the same thing in the AI space with, uh, in and our cranium.
And so, as you say, we are building our own custom silicon. Uh, we are trying to find ways to give customers that better performance, um, for every dollar spent or price performance while, while supporting customers on Nvidia. And that'll always be the path.
Long term customers need choice when they come to the cloud, and we're very happy to give it to them. On, on the specifics though, you know, if you think about, uh, you know, you can go anywhere and, you know, a lot of cloud providers provide you with Nvidia gpu. So what are the things that we at AWS think really differentiate ourselves?
Um, and one of 'em is stability. And so, you know, when you're running a very large cluster, any sort of node failure, any sort of networking issue causes you to lose time. And these clusters aren't cheap.
So any lost time leads to lower utilization, which leads to increased costs and just not using those resources. So, you know, we have teams of people at AWS working on stability. Um, we design our servers differently from anybody else with our Nitro system, which we've spoken about before.
Um, you know, where it's, it's custom silicon that's actually running all of the management layers and networking layers and storage io, um, to really give you the best performing and most stable server, um, available on the market. And we hear from our customers all the time that AWS is the place to be if you want that stability. Um, you know, we, we always say security is our priority zero.
Um, and I tell you, we live it every single week at AWS. Um, you know, I attend a number of meetings, um, in our proactive, I'd say paranoid security. Um, and we wanna bring the same level of security we've given to customers with our gp, with our CPUs and our normal compute, um, to the GPU space as well.
So that starts with Nitro. Um, we have zero operator access. We've actually gone as far as putting in our terms and conditions that we have no access to customer data.
We've had folks like the NCC group in the uk, um, validate that AWS has no access to customer data. And we just think about it very, very differently. We also working on a product called Secure ai, which we've, we've announced, which actually brings that level of security all the way into the GPU or into the training and processor to ensure that as a cloud provider, we have no access to model weights, and we also have no access to customer data.
And that really resonates with our customers from the smallest startups to the largest enterprises where they're saying, we want to be on AWS because of the level of security they provide. And then finally, scale. Uh, you know, um, one thing about this space is the scale is, is, um, you know, I would say larger than we've ever seen before, whether it comes to power data centers, network processes, GPUs, whatever it might be.
And, um, you know, we have a long history of scaling in this way, um, and doing many, many deployments, um, at, at really large scale. Uh, one of the places we've rarely invested in is our, our network with high elastic fabric adapter, um, where we are able to provide the, the level of latency, low latency, and high throughput, um, you know, with very, very consistent performance in the cloud. Um, and so for very large training clusters, we call them ultra, ultra clusters, um, we're able to give customers that we're actually building a cluster at the moment with Traum.
Um, you know, actually on both Nvidia, we're building Project Saber for Nvidia, which is 20,000 Blackwell GPUs. Um, and then we're doing many hundreds of thousands of traum accelerators for philanthropic for their next training cluster, which we call Project Rainier. So being able to scale once customer start small and go large is something we really specialize in.
Yeah, you specialize in it. You also have a long, uh, track record, uh, for it. You know, I have talked to some, uh, in end users who just weren't finding the stability that they needed, uh, with the Neo cloud.
And, uh, the, the entire system matters when it comes to this, uh, cooling networking, uh, the supply chain, the suppliers, you pick, uh, the levels of quality that, uh, that, that you put, that you put into that. And, you know, some people have to try the stuff, uh, before, you know, they, they, they realize that, but it's pretty known, pretty known, uh, fact down here, um, uh, on, on your reliability. So it's pretty good.
Good to see. Uh, you know, uh, you talked a little bit about, uh, optionality, and we've talked on the show about your opt optionality, uh, with silicon, right? Your, your own silicon, uh, to merchant players like, uh, like Nvidia and even even folks like a MD.
Uh, but this also goes across the way, uh, that, that you consume ai. If I look at your entire stack, right, you can go all the way, uh, from, I'll call it piece parts to fully manage solutions. Can you talk a little bit about the thinking, uh, that that went into?
Is it as simple as, Hey, we're AWS we provide optionality and these are the different ways that, that people wanna consume from us, so we deliver that? Yeah, it is that, you know, we do talk about choice a lot, right? We like the fact that when customers come to AWS, whether it comes to custom silicon or whether they're gonna run their own service, be it a database or training cluster, or whether they're gonna use one of our managed services at some layer, uh, and we have different layers of those as well.
They get to choose what's right for their business. And I think that is so important for customers. And you see customers making a choice when they start.
They may change their choice over time, but they have the freedom to move around. And that is so important from a cloud provider. Um, it drives competition as well, which we think is excellent, uh, in the markets.
But, you know, one of the things, um, you, when customers are looking to run their own training clusters, uh, one of the hardest things about running a training cluster is actually the distributed systems side of it. And it's not something you would normally think about, but just keeping it stable, making sure you can recover quickly from, uh, you know, from any sort of GPU or accelerator failure or hardware failure is so, so important. So, you know, one of the services, you know, we provide a number of them.
SageMaker is a great example of a service that has job level understanding of what you're trying to do. And we have a new feature there called Hyper Pod, which we launched a few years ago, that really makes running a training cluster very, very easy. A lower below a layer.
Below that, we have our Elastic Kubernetes service, EKS. Um, you know, Kubernetes has really sort of come to the foreground as the underlying architecture that most of the model providers are using for training. Um, and we have a service there that we're, we're also spending a lot of time, um, you know, optimizing that to ensure that any sort of node failure and also cluster size or Kubernetes is not gonna be able to naturally scale to the size of clusters that we, that the provider's gonna need.
So we've invested a lot in scaling Kubernetes as well, and making sure we can support hundreds of thousands of nodes in the future. Um, and then things like parallel cluster as well, that provides, you know, just better management of things like slum and whatever you might want to use. So there's this at various different layers, um, customers can choose.
Now, you know, we've seen customers like Perplexity, um, that have actually chosen SageMaker Hyper Bot that was the right choice for them. Um, and they liked, they liked what it gave them and liked how they managed the job. And they were able to make, most important thing is obviously make progress in training their models make progress in fine tuning whatever they would would do.
But customers like Adobe, um, you know, they've chosen EKS, um, where they've said, Hey, we want be at that layer below for us as an engineering team. You know, that's the layer we wanna be at. And, um, we, we really, you know, for us it's a customer choice and we'll support them at whatever layer, um, they they wanna be at.
So really across the portfolio, um, you know, I'm sure we'll talk more about Bedrock and inference, but customers that say, Hey, I don't wanna manage anything, I just, I just wanna get the value of AI in my application. You know, bedrock is great at giving them the inference capabilities that they need. Are, are there core variables that, that customers you've seen should consider with knowing how to make these decisions that, uh, sophistication might be one, uh, the amount of resources might, might be another?
Is there a, a cheat sheet for this, Dave? Yeah, you know, I think, um, yeah, it's, it's so true in the space. One of the things Andy, Jesse has often said is, there's no compression algorithm for experience, which is such a great thing 'cause it's so geeky as well.
But I think a lot of it is just customers learning. I think customers and, and it's, it's what, what, what, you know, what is your core value like, and I think a lot of engineering teams, I see, they do wanna start layer lower down the stack, um, but very quickly they start to realize that a lot of their time is actually spent, you know, managing underlying GPUs or managing the, you know, the, the, the, the container e ecosystem or dealing with failures. And normally what we see is they'll start to move up the stack if they aren't already there.
So, Sage mark, make IODs has been just so incredibly successful. You know, we use it internally as well with our, with our Nova team that's doing training. So they're a big part of that feedback loop with a very, very large frontier size cluster as well.
So, you know, a a customer that's just looking to get that, you wanna move quickly, you wanna get the value out of ai, you don't wanna spend all your time worrying about a node failure and how you recover SageMaker is really where you want to be. Yeah. No, I love that.
Different strokes for different folks. Um, definitely, uh, impressed. I mean, I'm impressed with a lot of the stack bedrock, uh, to me is the farthest that she went essentially saying, okay, we're not really great at the tech, but we know what we want to do with it.
Make it easy for us. We don't have to pick all the different factors for, um, for everything below it. So that, to me was a, was a step up, uh, for you when you introduced it that I thought was, uh, unique and valuable.
Um, so kind of joke that, okay, AI didn't start two years ago. Okay. It, it's been going on for a long time.
But if I do look at my top 10 enterprise challenges with adopting, uh, ai, some of them have gone down in the list, some of them have gone up in the list, and some of them have just stayed, stayed constant. I mean, cost is, has, has, you know, has been an, has has been a, a, a stated challenge and fear, uh, of, of enterprises diving into that. I mean, they just have to look at, you know, the price for, uh, A GPU, uh, as example, and they're doing the multiplication, uh, on their own and, and it pretty much scares them.
Um, uh, what are some things that you are doing, uh, to maximize the value of these enterprise AI investments? Uh, things to maybe a lay their, a lay their fears that, hey, once they get in, it's not gonna, not gonna go crazy. Yeah, I mean, I think, you know, uh, the, the biggest impact that we can have, um, you know, for generative AI today is to lower the cost.
Um, for, for enterprise customers and startups alike. I, I think there are many, many proof of concepts that don't find their way to production today. Um, because they just can't justify the cost, right?
The cost of, of doing the inference, uh, or training the model exceeds the savings. And I, I, I strongly believe that in the months and years ahead, many of those POCs will be deployed as costs come down. Now those costs are gonna come down, um, in several ways.
So one of the ways is, is model innovation. We saw that, um, you know, with some of the things we recent model innovations like with the deep seek thing that surprise the world, honestly, it shouldn't surprise the world. I hope we see many more of those.
I think the investment that's happening in models, including what we're doing with our own Nova, um, are gonna bring cost improvements for customers in significant ways. Um, and so that's one of them. The other way is gonna be, um, through hardware innovation.
And so, you know, it is incredibly important that we have more competition in the market, more solutions in the market, more options available, um, you know, more innovation in the hardware that's gonna allow us to, we always talk about price performance, and, you know, for every performance, for every dollar you spend, how much performance do you get? And it's a little bit like the re-imagining of Moore's Law. Nobody's made any statement about how it's gonna improve, but I think that same thing's gonna play out is the cost of inference from a hardware point of view or training has to come down.
It just has to come down. It has to come down significantly. Our big investment there is obviously what we've been doing with training, um, on our second generation of that now, which, you know, today offers up to 30 to 40% better price performance.
And for us, that sort of 40% price performance number has been so important for the growth of things like graviton. Um, we just announced that reinvent that, you know, with Graviton, we now land more graviton every year than all of our other processes combined in our data center, which is an incredible statistic and really speaks to the ability for us to go and innovate a custom silicon and give customers better cost and cost just means they do more and they do more innovation. And so we're hoping that the same thing happens with Tanium over time as we're able to bring that to market.
Uh, you know, one of the other things is just being more efficient with the GPUs that you do have. Um, and so we're talking about SageMaker iPod, you know, we've seen customers save up to 40%, again, I said magic, 40% number using iPods just because they're driving better utilization, um, about the cost of a large cluster, even a single percentage point in utilization can save you millions of dollars. Um, and so, you know, the, those are the things that you're, you really want to think through.
So how do we, you know, how do we make sure we have the latest models available through Bedrock, so you get those Ben benefits? How do we make sure SageMaker makes you more efficient? And then how are we building custom silicon that's gonna drive that cost down?
But, uh, we know when we lower cost customers innovate more. Um, and that's what we really wanna be able to see in this space. Yeah, listen, I mean, I'll going all the way back to S3 and the price reductions on, on that, right?
I mean, people just, you know, really gravitated. I know that was just, that was the start of AWS and then EC2 and, and the rest was history. Uh, I, I do like the way that you expanded almost the definition, uh, of, of cost.
It's not just this lower price, but it's, it's, it's being more efficient at what you're already paying for. Yeah. Um, you know, there, there's a rule of thumb that, you know, in a standard configuration, the GPUs are sitting around 30% of the time, right?
Yeah. That's not good. Um, yeah, the other, the other part of is on, on-prem versus, versus AWS, um, you are sharing, uh, these services across as opposed to this sunk cost that you're paying for, whether they're doing something for you or, or they're not doing something for you.
And my final comment is, uh, been tracking, um, uh, graviton, uh, forever. Um, I feel like I was, you know, part of, at least, uh, the group of analysts who were trying to educate, um, enterprises and other companies, uh, about them. And that really is the, uh, the poster child, uh, for, for how, how to, to do this and also do it again with the option of, okay, if you want Intel and a MD, hey, we got that too.
Uh, you know, you want Graviton for this. Uh, it's, it's good. And, uh, one thing I did on that too is you didn't oversell it, right?
Yeah. You, you said exactly what the different generations of Graviton did. Well, yes.
Uh, and then you added to those workloads as you rolled it out there. And I can't tell you how much trust that, that, uh, um, that got you in the industry and, and, and with your, with your customers. And yeah, it, it, it's pretty phenomenal.
Yeah. It, it's been an incredible success story. It's, um, and, you know, we, we are very careful with benchmarking as well to ensure that we really, we use real world workloads to try and benchmark, and we wanna make sure if we say something, customers are likely to see that.
And that's been a lot of the success behind graviton, is it's relatively easy to get to the numbers we've quoted. Um, and then it sort of snowballs as, you know, one team in an organization sees this big one, another team wants to do the same thing. And so, you know, that that's really what's driven the adoption.
There is one other thing as well, in which I didn't mention in the AI space that's been interesting. And, and that's just, you reminded me of it when you're talking about on-prem versus the cloud, right? So the sunk cost to spend upfront to get the GPUs versus being able to get them in an on demand like fashion.
Now, we haven't been able to maintain on demand for GPUs. It's been in incre. That's been one of the ways we've sold in the cloud, in the history of AWS and it just didn't work when the, you know, when the Hoppers came out and, and really, because if I had a GPU on demand, it was there for maybe one second and it was gone.
I never saw it again. And so I realized I actually couldn't maintain on demand. And so we came up with a new construct called Capacity Blocks.
Um, and it's something that we're seeing a lot of our customers, um, including very large enterprises use. You think of it as sort of hotel room bookings. You know, you wanna book a hotel room, you want a cluster of a certain size, maybe for a few hours or a few weeks.
Um, I think we can do it now up to six months. Um, we can give you the capacity immediately if it's available, or you could book it a few days out if you knew you were gonna be ready with it. And so the great thing about that is you really only need the cluster for the time that you want it, and then you give it back to us.
And so it's a, it's a sort of new form of on demand that we've actually had to innovate around to ensure that we've allowed customers to get access to that. And what we've seen is customers then share these g GPUs between different businesses. Um, and so you get that next level of cost saving and the next level of utilization improvement, um, by using the cloud as well.
So we're excited about where that's being going. Yeah, I appreciate you, you bringing that up. Uh, so hey, I wanna talk about, uh, I wanna talk about inference.
Um, it's, it's, it's kind of funny, Dave, uh, people are all, uh, surprised that like inference is growing, and I mean, training's still going, but inference is, is just rocking. Uh, I mean, you and I had a conversation, I'm pretty sure five years ago, uh, when we went from 80 20 training and inference to 80 20 inference, inference to training. And, uh, I'm curious at, at how are you thinking about this today?
I mean, things like, uh, reasoning models that make, make a difference on inference as well. Yeah. Uh, it, it is so true, actually.
I, I remember that conversation with you in 2017 when we decided to build Infra, um, which is our inference chip. The reason we chose inference is inference was actually 90% of the spend. And so 10% was training, 90% was inference.
And, uh, that was like, remember when you, your phone could show you pictures of dogs? And we were all surprised at how did ML do that? That's incredible.
Um, and things like Bert and resnet and those are the models and very little training and a lot of inference. And then generative AI changed the whole thing because the big frontier model providers, there was just so much being spent on training, and the inference workload hadn't caught up yet. And what we're seeing right now is that inference workload is actually catching up.
And I wouldn't be surprised if we got to a 80 20, 90 10 again in terms of inference versus, um, versus training. 'cause you know, it's just for it to give its value really inferences where the value is. Um, and so, you know, bedrock is, as you mentioned earlier, the space that we've been, the service we built specifically for inference.
And so it is a serverless service. It means you don't have to run any infrastructure yourself. Bedrock runs all the infrastructure managers, the GPUs or the accelerators behind the scenes manages the complexities of running the model, manages the performance, whether it's output tokens per second, whether it's latency or, you know, geographical locations and regions around the world.
All that is managed for you, um, by Bedrock and, and you as a developer or customer just as to call the API. And you get access to the latest models. Obviously Code four is available on Bedrock, along with LAMA four and all of the other models, Nova our own model as well.
Um, and so you get to play around and pick these models. That's the other thing, pat, is we, in most applications, they don't use a single model. Um, they normally use either different variants from the, from a single model, or typically they'll use many different models for different use cases as well.
So that choice on that selection, um, is so important. And, um, you know, it, we're just seeing great growth, um, on, on inference. And, um, I think, you know, all of the vast majority of that is in Bedrock today.
Um, and we're expecting that to continue to grow and, and, and get back to sort of numbers we've seen previously. Dave has reasoning and agents changed core infrastructure, uh, at all. You know, I remember back in, back in the day, right, a tiny card, uh, that didn't require any fans.
Uh, you know, you could do object recognition, uh, you could do, uh, speech to text, you could do some basic types, uh, of things. And now we have reasoning that that seems to take, you know, multi-term agents that take a tremendous amount of compute. Yeah, absolutely.
Uh, we are absolutely seeing, you know, reasoning and agents and, and specifically in the coding space, you know, code four is so good at coding and a number of these startups out there that are using quote today to just provide, you know, brand new coding experiences that are, um, changing the way that people code and significantly improving, uh, ability to code and speed at which we're able to code and innovate. Um, and I think those agents are gonna make their way into other use cases as well. We're seeing that.
Um, and it, it has, you know, the demand for inference is obviously increased significantly. The size of the models and the reasoning models typically a lot larger. And so we have to think about, can I fit the entire model into a single server, right?
A normal server back in the day with eight GPUs. Um, and that's probably not enough anymore for some of the larger models. And that's where we're deploying the GB two hundreds.
And that'll actually have, um, you know, 72 accelerators in a single, what we call Ultra Server. Um, we've done the same thing already with training where we have 64 accelerators now within a single ultra server, and they're all memory coherent. They have access to each other's memory.
And the thing you rarely avoid in there is the network trip time, because if you did it on the GPUs with h you would've to do a network, you know, you'd have to use multiple machines. And now these network time, and no matter how much we optimize the network, you always gonna have lower latency and lower tokens per second. So the scale up domain, as they call them, all these ultra servers, is really the next generation of, of inference workloads, but also training workloads.
And so we're excited to be taking that next step. And there's a lot of complexity, you know, from water cooling to different types of communications within the CER in the server through PCIE, a lot of complexities for us to work through, but we've made a lot of good progress, um, together with Nvidia and then on our own training and accelerators as well. Uh, so Dave, you know, we've talked about the, uh, the good old days of machine learning seven or eight years ago.
Uh, and we're talking about the workloads today, but you have to plan many, many years in advance, uh, to intercept the needs of what you think is gonna happen in the future. Um, building out, uh, a new data center or filling up, uh, space that you already have is not a, a fast, uh, endeavor. So what are some of the key infrastructure challenges that you see, uh, on the horizon as AI continues, uh, its evolution?
Yeah, I mean, the, the first one is obviously just, you know, the scale and performance demands, um, of infrastructure. And, um, you know, I think, uh, if you look at sort of, you know, 20 18, 20 19, you know, was the, the world was the probably the most stable. Like we, we learned to run the cloud really well.
We had a great forecast, uh, capabilities in knowing what our customers demand. I always call it the illusion of infinite capacity. You know, how are we actually delivering the illusion of infinite capacity to customers without actually having infinite capacity, which is incredibly expensive to do.
Um, and so AI has introduced just a whole lot of new challenges, uh, in that area. So making sure that we have the right power available, we're building the right data centers years out, you know, that's something as cloud providers we've had to do for our entire history, but something we've had to get a whole lot, um, more focused on, uh, with generative ai, um, you know, helping customers, uh, to be able to onboard. Um, one of the things we see with customers is, is data is so important in ai.
Um, you know, you can use a model and, and it's just a model that somebody else trained. But when you bring that model together with your data, suddenly it becomes something that can change your business, um, literally put you on a new trajectory. So how are we giving customers that data foundation, and how are we helping them process that?
Now, a lot of customers today have already put all of their data on AWS with Data Lakes or S3 or whatever it might be, and we've got a suite of analytical tools that help customers make sense of that data, and now allow them to use it with our AI tools. So whether it's things like SageMaker for training or bedrock for inference, but even higher level tools like q you know, Q4 business and Q4 developer, deep integration with customers, data that allows 'em to really get the value of ai. You know, security and governance is always gonna be a priority.
And, and we're gonna have to maintain and always be paranoid around security and say, what is that next thing? What's the next type of attack we might be seeing? How do we wanna build our architecture to ensure that customer data is secure?
Um, and all the way through their entire life cycle? We've got guardrails on Bedrock as well, which allows customers to ensure that a model isn't responding in a way that maybe they don't want their business to be, you know, represented as. Um, and so that allows customers to really fine tune, um, that, uh, you know, those options, uh, just infrastructure flexibility as well, right?
So, you know, we've spoken about a lot of different services, multiple different layers of the stack that is so important where we can really meet customers where they're at, and then as they go in their AI journey, you know, some of them might decide right now to fine tune a model, but in the future, they might just say, Hey, Bedrock's gonna be the way to go. I'll do fine tune today. I'm not gonna use H Makers.
So that flexibility to move, the flexibility to, you know, use different types of accelerators or processes or chips is so important. Really put themselves in a place where as the, as competition continues in the market and innovation continues to happen, you're very well positioned to get onto the next thing without even to do another large CapEx investment like you were talking about earlier. Um, and then finally, just cost and efficiency.
We've spoken about that, you know, uh, we've so focused right now on just how do we get the cost down? How do we improve the models? How do we improve the infrastructure?
Um, because we know that's the largest thing we can do to unlock the next wave of innovation, uh, for our customers by allowing them to use all of the services and models that are available. Um, so yeah. Yeah, I appreciate explaining it.
And I like the way you answered it. It was more than, Hey, what new hardware am I gonna be putting in? Uh, it's even getting more out of your current investment that you have in onboarding.
Um, sometimes I forget, uh, just how hard, uh, some of the stuff, some of this stuff is. Uh, but with ai, I mean, complexity is just, it's high, high in the radar. Uh, but, but well worth the investment.
I mean, the, you know, 10 Xing, uh, what can be done I, I think is a conservative view of, of what companies are gonna be able to do, uh, with, with, with ai. And it's going to be a, a workload after workload. You just don't turn on the switch.
And my Fortune 500 company is ifi and everything is ai, right? Uh, this is gonna be a multi-year, multi-year buildout. Uh, we're gonna see companies who didn't get on it quickly enough.
by the way, uh, watching Echo up and down. And there's just a string of companies that just don't exist because they didn't get into the technology, they didn't get into the web, they didn't get into e-commerce. Yeah.
Uh, quickly, quickly enough. And, uh, I think that we will see the same thing. So any enterprises out there, if you're not starting your, uh, AI journey, you, you are too late.
Uh, you need to pile on the resources and get, uh, get serious, uh, uh, about that. And, and, and Pat, I'd I'd add, I think that's a great point, and I'd add to it in saying, um, you know, one of the things that's, when you try some of these things early, you may not get the results you want. Um, and what's important for these companies is to, to find a way to stay at it, to find a way to stay in the experimentation, to find a way to try the new model, to try the new silicon that comes out to work with the cloud provider.
Like AWS as you know, we work very closely with customers. We're always looking for feedback. That's how we get better and how we innovate.
Um, but stay, stay in it. Don't write it off, um, because it is gonna change things significantly. You know, you talk about, I I can't remember a time where we said 10 x or something and feel like that's probably the, the low, the low end of, of the estimate.
Like, and, you know, we've been saying that for a while, and I think, you know, folks who are struggling to believe it, but we've seen so much improvement just in the last six months, and the pace of innovation. I've never seen a time where, you know, there's something new every single week that just surprises us in what customers are building and how the world's moving. And, um, you know, the, the pace of innovation is, is, is quite honestly astounding.
So you do need to be in it, stay in it, give feedback. If you're using AWS you'd love to see something. We always, we always love to hear that feedback from our customers and see how we can innovate on their behalf.
So, um, very, very exciting times. Yeah. Dave, thanks for the time.
I appreciate you've been very generous, uh, as well. I think, uh, you know, I probably talk too much, but I love this stuff. I get excited about this stuff and I know you do too.
So thank you for coming on the show, Dave, Also, it's a fantastic conference, so thank you very much, pat. It's great to be here. Thanks for having me.
Thank you. And thank you for joining us here for the Cloud infrastructure track opening keynote here in the six five Summit in its six year stay connected with us on social, which I'm on way too much, I'm sorry. com, more infrastructure conversations to come.
Thank you. As Tech Field Day heads to share in Cleveland, we're considering the many ways that the mainframe has been reimagined and rebuilt for the AI era. This episode of the Tech Field Day podcast features Cynthia Overby of Rocket Software and share Derek Britton and Jeffrey Powers discussing the Modern mainframe with me, Steven fst, in anticipation of Tech Field Day at Share.
Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day community, and is often recorded in association with one of our events. Tech Field Day is part of the Futurum Group, and this podcast is also published on our sister company Site Techstrong tv.
In this episode, as we prepare for the Share conference here in beautiful Cleveland, Ohio, we're talking about the new IBM mainframe. That's right, there's a new generation this year and it was engineered for the AI world. But before we dive in, let's meet who's on the panel today.
Hi, I'm Cynthia Overby, and I am, uh, the director of Strategic Security Solutions at Rockford Software. Hi, I'm Derek Britton. I am a mainframe industry commentator and advisor.
I've been in the industry for over 30 years now, and I was lucky enough to be at the Last Tech Field Day and share, uh, meeting, uh, in Kansas City this time last year. So I'm looking forward to going to the next one. My name is Jeffrey Powers.
I run, uh, a couple different websites, uh, primarily gee zine, which is, uh, more, uh, consumer tech, but also run a website called, uh, build Day Live, which where we dive deep into enterprise technology and building the perfect enterprise. And I am Steven Foskett organizer of the Tech Field Day events, and of course, uh, president of the Tech Field Day business unit here at the RUM Group. I am very excited to be returning to share, uh, not least of which, because it is in our home city of Cleveland, Ohio, but also because I loved Cher last year.
The thing that I, that I really enjoyed about it, number one, was that it was such a cool group of, a diverse group of people. It was not just, you know, sort of the, what you might think would be at a mainframe conference. It was a very exciting group of people who are excited about technology.
And number two, the thing that I love about it is seeing, it's kind of like visiting another culture, you know, where you go and you see how they do everything differently. 'cause I come from the Open systems side. I was a Unix systems administrator, and, um, and I talk a lot about open systems, but I also run an AI podcast and a security event, and networking and storage, and all of those topics are obviously incredibly relevant in the mainframe world as well.
And it was very eye-opening to learn just how all of those things are being implemented and the many ways that the mainframe is way ahead of the open systems world and in, and, and in other ways where the mainframe is sort of catching up in terms of DevOps and AI and so on. Um, Derek, I wanna start with you because I feel like you've, well, number one, you were there for the tech field day, uh, presentations last year. Uh, you were sort of one of my guides atcher.
Um, what is your interpretation of how the mainframe is advancing and, and where it fits in the modern world? Well, that's a nice simple question to start with, Steven. So thank you for that.
Um, I think, um, I've always observed it this way that, um, there's, there are basically two very well plowed parallel tracks just going off into the distance at, at, at, at breakneck speed. Um, one is the mainframe world, and the other one, which is very, very adjacent to it, is, let's call it the open world. Everything that isn't on a mainframe.
And actually, if you look, uh, if you look at it through a blurred lens, you can't, you can't see the difference. There's so many points of intersection, uh, uh, potential join points. And I, and so, although the mainframe space is unique, it has its own vocabulary, obviously, its own systems.
They're solving very, very similar problems to how everything's happening, you know, away from the mainframe. And in fact, I think the term, the connected mainframe, talking about the synergy between that platform and, and anything not on that platform, that was coined a long time ago. And we've been talking about the interconnectedness of enterprise systems where there's mainframe or non mainframe for some time now.
And I think with every passing year, you see greater convergence as those two worlds meld together. Um, and I think none more so now with the advent of ai, which I think has as a catalyst calls the mainframe innovation to accelerate even faster. And you only have to look at the announcement that IBM has made, but also as many other vendors have made in the space, um, leveraging and, and trying to leap ahead using AI technology, um, that is fresh on the mainframe and, you know, is, is very likely to cause that platform to accelerate even faster.
I, I totally agree. What, what, with what Derek is saying specifically, um, there's, you know, that the, the interconnectivity between the mainframe and open systems has become very sophisticated. Um, and I I truly believe that, um, organizations are beginning to really clarify the best of both worlds.
You know, where does, where do, where should your data live? Um, where is it most resilient? Um, where do you get the, the, the, the best overall security in many cases that's on your mainframe.
Um, where is data fluid? Where is it easy to be able to manipulate? Um, where are the best app tools to be able to, to do what you need to do, um, with the data that's on open systems?
So, uh, most organizations that I talk to today are looking at a, at a really cohesive enterprise, um, picture. Um, and whether you call that modernization or not, you know, that's, that's up to you. But, um, but you know, the mainframe, uh, definitely, um, from a, you know, from a processing perspective is, is really, um, the place as, as Derek said, you know, the 17 and, and, and what they've done to be able to process AI transactions, um, and to do the manipulations and the evaluations that you can do with AI and get the responses, the 17, uh, was engineered to be able to do that specifically.
So I'm really excited to see, you know, some of the presentations at, at Share in Cleveland, specifically around, um, around the 17 and, and, uh, the seventeen's gonna be on the floor so people can take a look at it and ask questions. Yeah. And, and as Cynthia's saying, the the 17 that you're referring to, that would be the Z 17, which is the, the, the new generation of the IBM mainframe just introduced, uh, released, uh, in April of 2025.
Um, you know, the headline from IBM is the first mainframe fully engineered for the AI age. And Jeff, I wanna throw that to you because what do you think about IB BM choosing that specifically as the headline for the next generation mainframe? You know, as opposed to all the other things, and I mean, that, that they could have chosen, they specifically said it's engineered for the AI age.
Well, of course, AI being a power word, a key word that, uh, that perks people's ears up. I could see this, uh, just basically as, you know, hey, we've got a new mainframe here, but for the most part, it's also about saying the mainframe is not something that you see in Mad Men TV episodes where, uh, tapes are flying around and, and, uh, and people are trying to use punch cards or anything like that. Uh, the bigger, bigger question though is will people start to migrate to that?
Because, uh, there's a lot of people, uh, at least in the area that I am in, and, and the people that I talk to mainframe their mainframes are, are longstanding devices, and they've probably, you know, they've probably switched out servers in their server room, uh, faster than they've, uh, switched out their mainframe. And so being able to say AI in the mainframe might be that, uh, push over the edge for people to say, okay, I, it's time to actually do an upgrade on this system, and I am going to stick with mainframe because now I have all these new abilities to it. And I think what might be happening also here, Steven, is the, the reality check that's, I mean, certainly some of the mainframe clients that, that, that I've been lucky enough to speak to that the primary challenge with how ai, uh, the promise of ai, how it would need to be actually implemented, is that most of the data that they'd want to train their models against is on the mainframe.
You know, most of the value of, you know, what AI might promise requires them to spend some time examining mainframe data. So we're, we're better to get the value of artificial intelligence than, you know, as close to the data as possible. So I think to, to a certain extent, this has been, um, you know, it, it's been something that the market has been clamoring for, for some time, because I think now in, in a very practical sense, the promise of AI can actually look, look to be delivered, um, where it is most necessary.
And, you know, whether or not that's true, and of course, you know, that's, that's just a supposition on my part. Um, I think only time will tell, but I think the fact that IBM has invested so much and you know, and, and the chip has been designed with it in mind, I've got a funny feeling that that will accelerate a lot of, a lot of investment. As, as Jeff said, I think it might just be the catalyst for people to really examine it seriously.
Now, Well, you, you, you take a look at data manipulation and, um, and, you know, some of the queries that people want want to, uh, to put towards their massive amounts of data, um, um, the, the being able to do that, um, in an efficient manner, um, really lends itself to the mainframe specifically when you're looking at, you know, a hundred million records, those types of things, to, to evaluate different, different queries, that type of thing. You know, how how many servers would you have to string together for that? And, and that's exactly right.
I mean, you know, it has to run, it makes sense to bring the, the AI processing inferencing to the data rather than try to exactly let the data out or, you know, especially because, you know, the thing can do it. I mean, I, I'm not sure, um, I haven't seen the benchmarks and so on, but IBM is claiming, I mean, they, they, they actually build an AI accelerator into the previous generation as well, but this one is, is much, much faster. They're also promising to have an accelerator available later this year that would, uh, further accelerate, um, machine learning operations.
I think that what they're trying to say, and, and, and it's funny 'cause I hear this as well from many of the companies in the server space, um, in the, the cloud world as well, is that, you know, you hear about these AI supercomputers for training, and that's all well and good, and obviously Nvidia rules that roost, uh, hardware wise. But the next challenge is going to be how do we actually do something with this technology? How do we make some productive use of ai?
And the answer is, it's going to be in inferencing operations, uh, maybe agentic running locally, running locally on a variety of systems. And, and it's very obvious that that's IBM's goal with the mainframe as well, that those processes would run locally because not only have they added the hardware, but of course they've also modified, uh, the ZOS to enable the use of these hardware AI accelerators across applications, right? Yeah.
The bigger thing is, uh, not as much of the fact that we, because the mainframe is very capable of doing a lot of things. In fact, I remember when cameras and AI were starting to come out and they said, we're gonna have millions of points of data, but we only use like 1% of that data. And now we're starting to explore in cameras on how are the other points are going to be used.
And so when we're talking mainframe data collection happens that exact same way, and bringing in AI to kind of understand all of that information. So if somebody's using their mainframe as a customer, uh, face database where, uh, where somebody comes in like a storefront or something like that, and then they're, they're trying to find the right color paint or anything like that, and AI can come in and say, oh, this is Joe. He was here last week and he was looking for something like a different type of paint and, uh, and this is what he's working on, and all that information can be stored and then brought in light when it's needed for any type of situation.
Uh, that's where I see AI starting to really help with the mainframe. The problem and, and maybe the solution with that is the problem is the coders trying to find people to code mainframe, and of course, COBOL being the big language out of it. And then maybe the solution is what I'm calling AI kitties, kinda like script kitties, uh, where you can kind of put in a chat GTP prompt and say, build me a program that will do this for the mainframe.
And then starting to implement those types of scripts or at least, uh, wire frames to an actual script that will work that you can edit. And actually, it's a fair, it's great that you've said that, Jeff, because even at last year's tech field day and, and, and even the wider share conference, actually, there were, um, notable vendor offerings, notable pieces of innovation that were being showcased. And Cynthia, you'll know at least one of the vendors in question, um, that, that were saying we're using ai, uh, machine learning or AI based tech to help with the, um, and I've just, I've just talked about the data side, but this is the application side.
Of course, the, the other thing that happens on the mainframe is the, the gazillion applications that, you know, and the hundreds of billions of lines of production code that still run the global economy that need to continue to be understood, maintained, and then upgraded to support, you know, the new digital age, whatever, whatever that dictates. And of course, most of those systems were built quite some time ago because, you know, the, the, the, the languages that they were used and the, the, you know, it's far out, far exceeded any realistic expectation of its lifespan. So, you know, the knowledge of those systems is, you know, a bit dusty, no one's quite sure how they're constructed anymore.
And AI is coming in to act as the, you know, the, the, the very keen, uh, intern to say, well, I'll go do some digging and, and give you some useful information. It's the, it's the buddy that you've got sat next to you that you've always wanted to show you what a program is doing. Exactly.
On the DevOps side, uh, you know, it's, there's a, the, a lot of things that can be done on the DevOps side specifically, you know, to take a look at those programs that were written 40, 50 years ago, we run into it from a, on the security side, when, you know you're going in and they're saying, we don't have, the resources are gone, we have no idea, you know, why these particular, uh, rules of the road were put in place or where these exits were done or, or why. And, um, you can do a lot with utilizing some of the ai, uh, chat bots now to just go in and, and ask query questions about things. And they'll, it's amazing what what they find in, in the, you know, in the bowels of the applications.
Uh, that was a standout last year at tech Field Exactly. That. Um, you know, the ways that AI is being used to expose how these systems work, um, code commenting, uh, code modernization, um, you know, and, and those are really good uses of, of this, uh, large language model technology.
But of course, um, machine learning goes way beyond that. I mean, security is a huge area as well that can leverage, uh, machine learning technology now, and I'm not talking about having a chat bot be your security sidekick, uh, I'm talking about actually using it to collect more data, process more data and identify more risks. And, and Cynthia, I think that that's, uh, definitely the direction that, uh, we're looking at in the mainframe space as well as open systems.
Yeah. You know, using AI to, um, to look at patterns, um, uh, pattern usages of, of, of particular, you know, your users, um, to be able to, to effectively alert, um, there's all types of, of ways that you can use AI to help, you know, to help, um, just monitor, um, usage, um, of, um, especially now with phishing attacks being what they are. Um, and as sophisticated as they are, I was looking at, at facial, you know, facial patterns and those types of things the other day where it was like, well, this person, this is really an AI bot, this isn't real person.
It was pretty scary to say the least. So yeah, I'm gonna bring in a very touchy subject. Uh, and that is airlines and of course the problems that we saw at the Newark Air Airport and the air control system that is pretty antiquated in itself.
And of course, there's a lot of mainframe that's used in airports and in airline security in, in the airline, everything. So, uh, updating those are going to be key moments and bringing AI into it. They've got a, that's a fine line they have to walk because you can use AI to kind of watch the planes and see if there's a potential problem track and, you know, understand the patterns.
And then of course, you don't want people getting in so they can put, bring in their own AI or bring in their own scripts to go from there. So a big level of securities involved in there, and that could be used in, in a lot of different, you know, not just airlines, but train systems, but bus systems, uh, financial systems, all that Well, uh, you know, most people don't realize that the Sabre system, uh, runs on exclusively runs on mainframes and, and, you know, anything happens to the Sabre system in there are no planes, uh, in the air. So, um, but you're, you're, you're right on Jeff about that.
Um, it's a fine line and it'll be interesting how it evolves over time, And I think that's another great example of the sort of data that lives on the mainframe side that, um, just the world wouldn't be able to get on without. Mm-hmm. Um, you know, transportation, uh, finance, of course, I, I, I don't know what the percentage I, you, you guys probably know what's the percentage of financial transactions that run through the mainframe space still, um, and, um, and of course other applications in, you know, military and, and science and so on.
But, um, yeah, I mean, in all these cases it doesn't really, well, it wouldn't be a good idea to try to bust that data out. It would make sense to, to be doing that processing natively. Right, Right.
The, the mainframe, you know, if most people don't realize the architecture is based upon IBM's statement of integrity and, and, um, there's a separation of function between applications and at the operating system layer. And, and even a lot of security professionals today don't understand that, uh, the architecture as designed originally with, um, MVT, uh, is, is very sophisticated in terms of how it keeps transactions from, from tromping on each other and keeping memory from tromping on each on, on each particular, um, function that's going on. And, and you don't get that in distributed systems.
And, um, and so it is a very sophisticated operating system in terms of security. Um, can it be breached? No.
Yeah, it can be breached. Has it been breached? Yes, it's been breached, but, um, it's, uh, it, it is, it is much more sophisticated.
And the more, and the more you can keep the data, um, from my perspective on the mainframe, um, and do the manipulation you need and just, just send the answers down, um, the better off we are. So everything we've discussed is really what's going to be discussed at Share Cleveland, because this is of course, top of mind for everyone. Um, as expert visitors, as, as folks who've been to a lot of share conferences.
I'm not sure Cynthia or Derek, which of you has been to more, um, certainly more than me. Uh, what, what is there to expect at Share? Uh, well, it's a great question.
It's always a great question to anticipate what might be coming up, Steven. Um, I, I think, um, I, I don't think the book makers will be taking any bets on AI being the most, uh, topical discussion. Um, but you know, you, you were in the room with me last year at Tech Field Day, and we all then were able to get out and, and, and go around the show floor at Share and see some of the sessions.
We were lucky enough to see BMC, uh, broadcast and, and, uh, and my friends at Popup Mainframe, they were all, they all presented to Tech, uh, field Day, but also we saw them all on the show floor as well, as well as many others. Of course, um, throughout that session, even last year, there was, there was a lot of talk about artificial intelligence and, you know, of course the, the mainframe security was a big topic as well. Um, I don't see any change there.
I see that, if anything that just being layered up one notch, I think those conversations will be probably a lot more, um, targeted now, a lot more practically focused, because I think, you know, we've had 12 months of innovation, including the hardware itself, where I think now it's not a case of imagining possibilities. It's a case of actually talking, you know, practical approaches towards, you know, fixing real business challenges. That, and, and where the mainframe and the mainframe tech stack is now has evolved to support that.
So I'm pretty to see what, you know, what will unfold at Sessions, see as, um, as well as GA technology, um, but also in the wider show floor, because I think it might be one of the busiest yet and certainly might be one of the most interesting ones. The number of of sponsors, um, um, that will be, uh, will be in the tech exchange, um, is, is up. It's probably going to be the, the most that we've seen in, in, uh, since the inception of Tech Exchange.
So yeah, I'm, I'm expecting to see some, some really interesting, uh, interesting, um, demos on different products and, and, uh, there's a lot in the DevOps area. Um, so it'll be, it'll be interesting to see, uh, what, uh, what it, what it actually, what what we actually see on the floor specifically. But, um, in terms of sessions, um, uh, just looking through the sessions, uh, a while ago, um, there's a, a lot of diverse, really diverse sessions, um, this year.
Um, so I'm, I'm, I'm excited. I, I'd like to see more user sessions, to be perfectly honest, um, honest, but there's a lot of partner user presentations this time that we haven't seen for a while. Um, so, um, and, uh, a lot of panel discussions also.
So I know on the sec on the security side, um, there's a couple of really good panel discussions where some of the, you know, some of the top, uh, security professionals on mainframe security professionals are gonna be sitting on panel discussions, so that, that'll be exciting. You know, Jeff, uh, it's, it's, I think what you would find is that it's pretty much what you would see topically if you went around at AWS Reinvent or CubeCon or any of these other conferences, HPE Discover, except all the hardware is different and the software is different, but everybody's working on the same things. Um, you know, does it shock you to hear that that DevOps and has come to the mainframe space?
No, I don't think it, no, it's, the head shock is not the word surprise a little bit, but I suppose, uh, it's if if they want to be relevant, they have to have what's coming in there. So I don't know. I, since this would be my first share conference, uh, for me, I, I think I would see a lot, uh, would gravitate towards a lot of the things that the regular people would gravitate towards.
Like, for instance, IBM coming out with the news E 17, so I'm guessing a lot of people will have a lot of interest in it and around that, how to migrate into, uh, newer systems. So you'd have, I know, uh, Broadcom also, uh, is a big name when it comes to mainframe, so a lot of Broadcom in there, uh, being able to do the software, like with, with, uh, something like Rocket Software, um, uh, associating with the cloud. So we'll see a lot of a AWS and, and, uh, and Microsoft, uh, in there.
And then of course, companies like CDW that'll basically say, Hey, we'll just do it all for you. And, uh, and, and, uh, these, these are the things that we see that I'll see in almost any conference. And of course, they'll all have good explanations as to how to do the integration, how to do the migration.
Yeah. And, and actually I'm glad you mentioned AWS because they're one of the companies, um, that I was most surprised to see, um, at Share, but yet they have a lot to do with this. They're doing a lot with the mainframe space.
Um, Zoe, um, big presence with Zoe, um, open, open Source. Um, last year there were, uh, I maybe five or six specific sessions on, on Open source, um, different vendors giving presentations on what they can do with open source. Um, so that was, uh, that was real, very interesting for a lot of people too.
So, Yeah, the Open Mainframe Project, they've done a, a, a great job of building out a range of range of DevOps tools, including Zoe, and I think their sessions on quite a lot of that stuff. So, um, uh, I'm looking forward to seeing some of those guys too. Well, I am, I'm very happy to give our audience a little bit of a sneak peek, uh, about what's gonna be, what, what's gonna be at share also to share, um, if you'll pardon the pun, a little bit of the modern mainframe with them.
Um, if you're listening to this and you didn't realize that, well, there was a new, uh, mainframe announced in 2025 that there was, that it's engineered for ai, that open source and DevOps and AI are everywhere in the mainframe space. Well, you know, maybe check out, share, um, you know, Cleveland's easy to get to, uh, come join us. You'll see me there.
Uh, hopefully you'll see the rest of us there as well. Um, and hopefully you'll learn, learn a thing or two about the state of the Modern Mainframe. Thank you very much, uh, for joining us, all of you.
Um, before we go, um, where can we connect with you and continue this conversation? I'm, uh, I'm very active on LinkedIn, so, um, feel free to query me on LinkedIn. Yeah, do the same for me.
Um, hit us all with the same stone. Yeah, check me out on LinkedIn. Um, and, uh, yeah, I'm happy to, happy to take any dms.
com. But we'll have, uh, LinkedIn's on both Gee Cuisine and Build Day Live. com on our YouTube channel, as well as, uh, tech Strong tv, our sister site, where the sessions will be live streamed and, uh, posted afterward.
Thank you so much for listening to this episode of the Tech Field Day podcast. If you enjoyed the discussion, please do subscribe on YouTube or in your favorite podcast application so you don't mi miss an episode. And do consider giving us a rating in a review.
We would love to hear from you. The podcast was brought to you by Tech Field Day, home of IT experts from across the enterprise, which is part of the Futurum Group. com/podcast or visit us on Techstrong tv.
Thanks for listening and we will catch you next week.