Techstrong TV June 6, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices.
Transcript
Hey, everybody. Are you ready for the Microsoft Security Dome? It's coming soon.
We'll be back in a minute. Hey, folks, welcome to the Textron Gang. We've got an interesting conversation today with a lot of heavy doses of security everywhere, but you know what?
Security's on everybody's mind these days. So let's dive in. We have our, some of our usual assortment of gang members, and then we have a new member we're gonna introduce in a minute.
But let's start with John Schwartz. Who, John, are you home? You're still in Las Vegas?
I'm home. I got back last night, so I, I survived another trip to Vegas, but I think it was a productive one. And you mentioned this show's mainly about security, and I think that's a, a good timing, um, given, um, what's going on in this world.
There you go. Mitch Ashley, of course. Mr.
DevSecOps. DevSecOps, guitar man. You know, I have lots of names.
Not all of them I can use on air, but yes, glad to be joining. I, I, of course, I can tell by the guitars in the background that you're home in Denver. I am.
I need to make a fake background, so just once in a while I can kinda keep it interesting. Am I home Where even Adam just, I just moved the guitars around and that'll mess me up alone. So there you go.
All right. Fred Wilman, how are you? Are you, I think was Atlanta that you're in Seattle, keeping it sunny Seattle.
That's where it is. Okay. Keeping it sunny.
Good to see you again, sir, as well. Fred, is this your second, third show? Where are we on this?
We're number three. Alright, this, this Friday. So you are now officially a veteran.
So here we go. And then joining us for the first time is Ira Winkler, who's also a cybersecurity expert and spends a lot of time trying to figure out how to make humans kinda wanna do the right thing in cybersecurity. But Ira, explain to us where you're, and then welcome to show.
Currently I'm in my house trying to fight my cat and my dog for the couch. Um, true story, but, um, so anyway, people asked to give, I was asked to give a little intro. So just at a high level, I have been, I'm currently the CISO for Size Security, which focuses on the CE market at the moment.
Um, I'm also the inventor of Cruise Con and just cheap plug, but it's for Techstrong as well. We're doing Cruise. Cruise Con.
Virtual is airing on the 17th, which will be an awesome event for everybody. The sessions were totally awesome. com and sign up very quickly.
Um, that aside, my background includes being Chief Security architect at Walmart, chief security strategist at hp. I started and sold two companies, wrote eight books, keynoted, black hat, RSA, events like that. And I don't know what else, you know, you guys want, but, uh, we have a lot of show, so I'll leave it there.
Well known, well respected. I'd say you're illuminary I great to have you on the show. Yeah, I actually was a source for John Schwartz.
I think. I know. I was gonna say Ira, it's been a long time.
I I we didn't have time at the beginning, but you were like one of the people we talked to along with Mitch all the time for the book with the, the buyer and I did years ago. Yeah, it was the book I think you were with. I mean, people, I guess they see you with Techstrong now.
I don't re I think you were with the Wall Street Journal and Well, I've, I, well, I was a USA today then, and then I went to Dow Jones and I did write some stu I did write for the journal, but it was USA Today era. This was like 2006, 2008. You know, the irony is when we did, we, you were, you and Mitch and many other people were great sources for that book.
You know what I always, my takeaway was that we did it too early. Like it was too, it was, I mean we, we, our timing was just, we should, we should have waited a little bit longer, but, uh, you were invaluable. You were a legend legends.
Ah, I'm, I'm honored. It's true. Yeah.
I just wish corporate espionage and spies among us. Two of my books came out, now I gotta update it. But it's just such a pain to find publishers these days.
Unless you write for USA today and everywhere else. Nobody wants your books. Uh, hey, we got, we go like rejected by like 30 publishers.
Yeah. Feel, feel free to update those things and we'll publish them serially on Security Boulevard. So consider that a standard.
Well, It actually might not be a bad idea, but just to give you an idea, I talk about like espionage and just, it's like, so like, 'cause I wrote Spies Among Us, which people have called the Bible of the field for a while, and it doesn't even include the, the, the phrase a PT or advanced persistent threat. Even though I talk about China, Russia, Iran, North Korea, and everybody else. So needs a little bit of tweaking, but the concepts are evergreen.
I'm proud to say. I'll Bet. Right.
It's a great book too, by the way. I've read it. So, Excellent.
Great. Sounds like Ira not only knows where the bodies are buried, but maybe his fingerprints are on the shovel. Who knows.
Yeah, I think he may have put a few of them there himself, but, okay. Anyway, Yeah, just Google Ira Winkler and Syrian electronic Army and you'll find a lot of fun. Oh yeah.
Throw in the word cockroach. That's relevant. All right.
Well that may not be the perfect transition between Cockroach and Microsoft, but we're gonna try it anyway. Um, so Microsoft has announced that they're gonna provide free security services to all the governments in the eu. It's an expansion of a program and effort, effort they've been doing.
And they're also gonna do it with any government that seems to be loosely affiliated with the eu. Are, you've been in this space for a long time, we've established that, but what's your take on this? 'cause for me, I don't wanna use the word unprecedented, but it sure is unusual.
I'm a little bit more stoic than that. I mean, 'cause frankly, why haven't they been sharing this data is more of a concern for me than now that they are going to share the data. You know, they're giving it to like, because here's the thing we have, I hate the expression weakest link when it's applied to humans.
That's just such an inappropriate use. They mean, and actually this is an appropriate use because to me, the weakest link in one of my books was, you can't stop stupid. Stupid.
Isn't the user stupid? Are the people who put together systems that enable users to cause harm. Now, in this case, and actually tying back to the whole cockroach thing, it is relevant because Microsoft has this infrastructure that provides threat intelligence.
And it's been helping, you know, European EU countries, specifically, I guess not European countries have to use my Dr. Evil quotes now for this. But, you know, all of a sudden the problem is, it's like, how can you go ahead and give data, for example, to like Athens, but, and forgive my I but not like Montenegro.
I, I don't know if they're in the eu. I I apologize for my ignorance, but I'm using that as an example because when you're sharing threat intelligence in a world where everything, especially Europe and Europe, yeah, there's a slight distinction between EU countries and not EU countries. And I was just, for example, in Croatia a couple weeks ago, the borders are open when the borders are so open.
And I'm not saying that's a bad thing. 'cause you could drive through, you can enjoy the beautiful scenery, but then likewise, the Internet's open and giving threat intelligence to one country, but not the country adjacent to it, which is as tied, has so many interactions is, is damaging. And going back to why the Syrian electronic army is relevant, if you see an organization that is nation state sponsored to a large extent that is, or even not, that is actively attacking one country, you gotta assume that they're gonna use the countries next to it as a source to launch over.
Because people go to work from one country to another, they live across the borders and come into work and just limited it to the EU is so ignorant. So I think this is a long time in coming that has left a major, well, I shouldn't say it left a major hole because hopefully the way it happened was it started organically like, we should share intelligence with these people. Let's start here.
It works now let's grow it, which would be good. But I don't see this as such a major breakthrough. I think why wasn't it done sooner?
Sorry, I, that is my soapbox That, that that is a perfectly legitimate point of view. Fred, what's your take here? You're in the security space a long time as well.
I mean, as you look at this, is this the beginning of something? Maybe it'll go global. Uh, I, I think there's a couple of important points here.
Uh, Microsoft released a couple of things, maybe somewhat less noticed a few weeks ago. European digital commitments, five pillars by which they'll support Europe and adjacent countries. And I think what's important about that is, number one of that is they will help build a broad AI fabric and cloud ecosystem in Europe.
It's not shocking that this sort of democratization is happening. It's more than intelligence. It's also, I want to be at the center.
If I'm Microsoft, I want to be at the center of this AI revolution. And I also want to have access to all the data that's transiting across all these countries, as Ira talked about, where it gives me more insight as to what's happening. But also they want to, you know, be in the, in the center stage for dealing with AI threats specifically around, uh, AI weaponized threats.
So I think there's a lot of IM impact that this is going to have. And I think the free part of it is pretty revolutionary. Uh, it's more than just, I think in intelligence sharing and the outcomes.
The upshot of this will be, I'm sure it gets global. But also the important part here is if you look at some of the way that these pillars are written, it's very clear this is, uh, something that will be above what we'll say US policy might state. So there's an interesting set of implications around information sharing that might or might not be in the best interest of the United States during the course of the exercise.
So I think those are interesting things to take away from this. Yeah. Fred, can I ask you a quick question?
Because when you described it your way, 'cause I I focused in on this, you focused in on that when you're describing it your way, there's an old phrase that if you're not the customer, you are the product. So when Microsoft is giving this away with the chance of collecting, analyzing all this other data, how much can be perceived as for the benefit of mankind versus the benefit of MSFT stock on the stock market? Absolutely right.
How, how to serve mankind. It's a cookbook, right? To go back the years.
So that, that's exactly the case. Uh, this is a productization exercise. It's a brilliant work to be honest, because the impact they can have on the market, but also so the perceived value, but also their ability to step across the US into the, the rising sort of market for AI and the specifics and take control of it, right?
They have, have created this AI forge environment, which is the same sort of marketplace as you would find at AWS. You want to gain popularity there, democratize the access to it, democratize the cost for people to use it, and then use all the Microsoft AI models plus, uh, you know, for improvement there. Plus the, uh, access to everyone else's models and, and step over, you know, the marketplace segmentation that's happening today in the us You know, I would add a third, third pi pillar, third uh, uh, leg to this stool, if I can use that analogy, because I agree with what you both said.
I think there's also another reason, which is I see signs of Microsoft, no, they're not turn turning into an altruistic company and doing it for the good of mankind, the Twilight Zone episode to serve man. Um, but they are recognizing they can't own it all anymore. You know, you, there was a long, long time of which, you know, we're Microsoft, you play by our roles and we'll own it all and we don't really care what else goes on in the world.
And that's certainly evolved over time. Um, but they're being much more open, I think, about what, who they work with. For example, at the Microsoft Build conference, they were talking about the MCP server spec and that they were gonna work with Anthropic to help upgrade the open spec, if you will, open standard to make it more enterprise ready so that everybody can use that.
Now I'm saying all this as a setup to say I think we're in a regulatory framework. We're in a nationalism, um, context of, of companies and what the US relation is with everybody else. I think this is also a, a step, it's not the only reason of Microsoft trying to do things with other governments, other countries, other organizations to support their initiatives, to share things.
So when they do get called on the carpet, you know, they're just not an imperialistic American country company trying to own it all again. But maybe they are doing some good for that country and, and that might help get some relief in those situations. I'm not gonna say it's gonna prevent it, but I think there is that part of it as well.
Feel free to disagree, but I think that's part of the Reason there's a practical side of this to Microsoft. So, you know, let's not get past the altruism here for two seconds, but think about it. If they want people to use Microsoft products, great, but then they don't want to be called on the carpet when some government in Europe finds out that their Microsoft products have been hacked by the bad guys because the security configuration was screwed up somehow or other.
And Microsoft is kind of, you know, as I read it, is basically saying, Hey, let us manage all that stuff bore you so that if there is an issue, we'll take responsibility for it and then don't yell at us when your guys suck. So, you know, we'll, it's kind of a cover your butt kind of move in my mind. But once you're to, I was gonna say, Mike, I was just gonna jump in.
This is like a preemptive concession from Microsoft, which they're very good at doing this by the way. They've learned their lesson through dealing with the federal government in the US that if you take a little proactive approach, not only do you try to present yourself as a good guy, which is Brad Smith's big message has been the last couple of years. They, they're the, they're the wide knights, so to speak, but it's also about self preservation.
And I think we've actually reached the point in terms of AI use, especially generative ai, where now these companies realize the damage that can be done, but they also wanna assure people beforehand, before they start installing what have you from Microsoft, whoever else that, that they're taking some sort of precautionary measures. And I also think they're also kind of sensitive to a lot of the criticism about them being somewhat reckless and throwing the stuff out and trying to sell as fast as possible. So I think it's a, it's, it's, it definitely, it's like a self preservation, um, almost preemptive concession, especially in Europe where there is regulation.
So Ira come back to you for a minute. Do you think we might see more vendors kind of step up and say, yeah, we're gonna take responsibility for securing our products that you use, not just in the government, but maybe even in the private sector. And the nature of the conversation is changing around who's gonna be responsible for security?
The, if you ask me what the monetization strategy is, I don't think they're giving this away for free because fundamentally we're paying for it. There's not like a donation, like this is the Microsoft Foundation and the Microsoft Foundation is making all of this available, what you are talking about and everything else that's going on, what are fundamental things that Microsoft does that are built into the cost of their products? And so when you look at giving it away, it's like, well, when you're already using billions of dollars of Microsoft and they throw in a new feature that kind of helps them, helps you at the same time, is this something that is a corporate donation to the world?
Not really. I mean, this is something that, yeah, there's a new line item perhaps somewhere buried in budgets, but this is something that they're giving away frankly, to support their internal systems that are already paid for by the customers in paying. Sorry, I don't want to complain about, I I, I don't like complaining about licensing fees because fundamentally we wouldn't be using it if there was no value.
So I'm not saying it's overpriced, but I'm just saying, let's say something like this is already priced into what they're doing. So saying this is like an altruistic thing. I really don't see Microsoft coming out on their 10 k document and saying, well, we took a loss because we have this program we've implemented in Europe or in the EU that we expanded to Europe.
So therefore this is giving a hit against our profitability. Until I see that, I'm gonna just gonna assume I've paid for this already. All right, folks, I'm gonna leave this conversation here, but think about it for a minute.
Is security something we pay extra for? Or is it a fundamental expectation of the products we bought? There's a big decision right there.
We'll be back in a minute. Hey folks, we're back talking a little more security this time. It's SBOs software, bill of materials.
There's a report out talking about how, well, I can't really understand for sure as I'm, I'm conflicted here. This glass may be half full, it may be half empty, but it basically says people are struggling putting together SBOs and they're not making as much progress as they had hoped. Uh, Mitch, I know you tracked this area deeply.
SBOs are core to securing our software supply chains. What's your read here? Are we, is this, you know, progress or is this kinda like, oh man, this is gonna take forever?
Well, anytime you have to do something because there's some external requirement, unless there's a drop dead serious penalty by not doing it by this day, like we will get fined. Um, you know, there, there is a, and we have to do that too, right? It's not like suddenly that moves to the top of the priority list and, but I think people generally wanna implement some type of an automated bo sbo m process anyway to better understand and software con uh, decomposition or composition analysis with this, this, this particular survey was, was by a company called, I think it was Lineage, if I remember right.
Had a hundred responses. So it's not like it's a, you know, it's a, it's a deep survey of any kind, but it's a point, it's a point in time and you know, I, I expect, I think we probably all do, whenever there's a requirement coming up because of Dora in the EU or whatever it might be, PCI, it oftentimes gets pushed off because it takes companies a while to get those things implemented, especially the larger, um, if, if you were sending me a report that said people are rejecting this idea and pushing back and not implementing this 'cause they don't believe it's valuable and they want the, want this, the, uh, requirement to be changed. I think that would be real news.
I don't think this is big news, Fred. What makes it hard to kind of build out an SBO m and challenging to implement and what are the, because you know, on the face of it, it's like I got a list of ingredients in my software. What could be so hard here?
Uh, there's a couple things. SBOs aren't hard. Uh, I, I think, uh, anybody, um, that's using Docker, right?
Can type docker, sbam and get a list of the bill of materials of what's happening in their particular container. So it's not a hard problem from the standpoint of how do we do this? 10 years ago it was a hard problem Five years ago it was kind of a hard problem.
But, uh, one of the things I think is really interesting about this is there's a lot of ways people gather a bill of materials for what they build with the harder parts of some of these problems are the open source technologies, right? And the ability to, to deal with them Things when we use, like, uh, Golang for example, right? You, you get to import everything that comes with this and you can't take anything out.
So you're inheriting vulnerabilities and then, you know, that finds its way into an SBO from the conversation. It's not really relevant to what your security posture looks like because you're not shipping core, you know, core libraries or things you built with. But the, the big thing that I think is interesting here is, uh, ask an auditor about SBOs, right?
Tell me the validity of an SBO m with an auditor. Oh, you have one? Okay, great, thank you.
And so the question is, is what good does it do when you have one, but no one's looking at the context of what it means across all your software? So, and I would say that this, this survey here, uh, I mean a hundred people probably doesn't even blip on the, you know, the distribution, uh, of a curve to say that that's a, a reasonable expectation of, of an assessment of the market. But, uh, if you said 50% of the people have implemented some sort of containerization strategy and then used that in production and they're all using SBOs, I'd probably buy that.
If you said the other half of the audience doesn't use containerization or you know, Kubernetes or anything of the like, then I would probably buy, that's why 50% of them don't have SBOs because they don't have the tool chain and they're not shipping software that way. That's really more of the issue, I think. But that's just my opinion.
IRA is an sbo, you know, something nice to have or do security people really need this to go find out where components are. 'cause we all saw the log four J example and people are still looking for log four J. So how critical is this for security people?
It's cri it, it's frankly really, really, really critical because the, the underlying principle a lot of people have missed for many places is that software developers aren't writing code the way we used to back in the good old days, whatever it was, they're basically pulling together pieces of software from all over the place and packaging it up to somehow do this. And now with AI or generative AI tools that are writing software, they're just pulling all these packages in to achieve the end goal and essentially putting together library programs. And lemme give you an, and this is actually a true story.
I was, um, back a while ago I was doing threat intelligence as part of my career for banks. And we were scanning the internet in different forums, looking for references and things like that. We saw one bank employee, and this is gonna date me, but it's like, so some, some employee wrote on a forum like for like Sun developers, which again dates me for the most part.
4, you know, right on this, we have these applications we're using that, does anybody have any library programs that would be useful for me? And I'm like sitting there thinking if do, am I, do I have a pen test coming up? 'cause I could really put in some malware embedded in the library that I'll give him.
'cause I knew where he was coming from because the IP addresses were in the, the posts and everything like that. And I could target them specifically. And so this is one example of getting malware embedded through these library programs.
It was, I forgot what it was bit, that I think was a case where somebody was fundamentally able, and this is a recent case, this isn't a Sonos case where some criminal was able to take over the library or data store that this developer very common system created because the guy just said, screw it. I'm not, I'm tired of running this freeware he was giving away and some criminal took over the domain was able to repurpose the email, went through a whole bunch of stuff to essentially take over the data store and implant malware knowing Bit Wallet pulled in malware and I'm sorry if it's not Bit Wallet. And then was able to go ahead and basically clean out people's Bitcoin because they implanted this and uploaded this.
And knowing where the developers are pulling in software, which itself pulls in software, which itself pulls in software, which itself pulls in software is critical because you don't know where this malware is gonna come from. And even if it's not malware, even if it's a flaw in the software, you have to understand whether it's there. And these SBOs are trying to find like software that is like being pulled in from five layers down or more.
And that's critical to understand because you don't know where your malware's coming from. You don't know where the vulnerabilities are coming from if you don't track this. And like I said, with generative ai, generative AI was pulling in, they were inventing library programs and criminals were going ahead understanding what was the most common library program, the hallucination, the generative AI was coming up with.
And they created library programs with that name, with malware embedded in it and installed it. And so without an sbo om in place to understand all the details of what's being pulled in, how it's being pulled in and so on. You don't know where your vulnerabilities are when something's announced.
You don't know where the software is. I could go on for a while, but the way software is created today without an SBO m it's a crapshoot the way we're running it. So Mitch, can the SBO keep up with the pace, right?
Because I talked to people even before ai, they were saying that the software is being updated faster than I can keep the record in the sbo and now we have AI tools and that's just gonna get faster and faster. So do I need like an AI SBO to keep up with the AI coding tools? Correct.
How's that be able Actually a spec for AI sbo. But yes, I think the key thing is that it's, it has to be automated because we're in this highly iterative process and not just, you know, you're trying to debug things and someone updated a package of your source wherever you're pulling it from, whether it's coming from docker hub or docker hardened images or your own internal repo that you're storing those things on. Um, you ultimately have to know what you've shipped.
Um, I, I like, I I wanted, if I, if you don't mind, I'm gonna do a little analogy 'cause I like IRA's explanation of software. As you know, you was talking about me as the guitar man having guitars and one of my guitars as one that I actually built, this is a guitar that I built and I show people and they're like, wow, you built that guitar. We're we have saws in your garage, how did you do that?
I'm like, no, I didn't cut a single piece of wood. These are all parts that I got from different places. And then I wired customs, some of it myself and I rewired other parts that I liked and I kinda shaved down the neck to the way I like.
And some of 'em are genuine fender parts and some are licensed part for fenders and there might be a logo on there that isn't an authorized logo, you know, come from, you know, who knows where a nefarious place. But anyway, that, that's kind of what happens with software and how it gets built, right? You know, I might've stuck in some code, nobody really knew where it came from and that could be the problem that we're gonna get called on the cart before on an bum or it could be a source of a vulnerability.
So now we're not doing that at that, at the pace. I don't build guitars at the pace we build software, but that's really what software is. It's an amalgamation of a whole bunch of components from a lot of places.
And most of them are not what the developer wrote themselves. Fred, you know what gave me pause though was, um, at least in my experience, only about three to 5% of the known vulnerabilities are actually exploited, at least historically. But now we're looking at a world where chat GPT can come up with an exploit for 70% of the vulnerabilities that are known.
So is the nature of the attacks against our software supply chain about to just fundamentally change and exponentially increase? I completely agree with that. I think some of the concerns are, and there's some value in, in suggesting that AI models can come up with o days in a preventive way.
But, uh, it, it's also pretty clear to understand that, um, if you can come up with o days for the benefit, right? Clearly also for the detriment and whether it's licensing concerns, right? Uh, you know, Mitch talked about a software composition analysis.
Uh, it's regulatory concerns. It's, you know, do I know whether or not I'm grabbing something from, you know, whatever AI model that's, you know, Gemma or, or, or you know, Gemini or somebody else's model and generating some code that I use, right? There's a licensing potential there.
There's also a malware potential there in the future, right? Because folks that are grabbing this code may not be your standard software engineer. And so I don't know whether, I agree that AI is going to remarkably settle the debate about vulnerabilities being remediated quicker or improving software code from the standpoint of build securely, uh, uh, secure by design.
Uh, but I think there's an awful lot more risk here without an AI SBO to Mitch's point earlier and whether or not there's some level of accountability for what happens with respect to that. And, and I think that's probably the very real concern is that we've taken software development out of software developer's hands in that case. And so all the strictures we normally adhere to for a software development lifecycle or sort of out the window.
And then we have to figure out sort of a new methodology around, you know, how do we understand what we've implemented and where do we source, you know, the the vibe coating, uh, you know, Python something or other that this guy wrote or that UI here that this this gal wrote or, or so on so forth. And I think that's the real concern we have. You know, just a point about that jump, just wanna make one point about that, uh, where we are today, if, if we're fairly limited in what code gets changed, when you use something like a Microsoft or could GitHub co-pilot to go, uh, do a poll request and make a change request implementation for you, it's pretty restrictive about what it does and makes its own clone of the repo, all that kind of stuff.
But I think the more and more that gets used, the amount of code that could change in implementing that and how much that's controlled, I think we're gonna see a lot more software changing, um, that aren't under the control of developers. So we've got to have better models, better guardrails, better systems to be able to make sure what's being generated is secure. So we're just at the beginning stages of this and it's, it's not really addressed yet either.
Yeah, I would say this, Mitch, what, let's imagine for a second that I wanted to prototype a particular type of, uh, vulnerability scanner for this type of thing. And I'm not a developer, but I am somebody that has IRA's level of threat intelligence and my level of understanding, uh, adversary behavior. Uh, so we, we say, okay, we're gonna go ask chat GBT to write me a Python script that does this and build me a UI and light or whatever to, to allow me to interact with this and then incorporate economies of scale, right?
That's an hour or two hours of exercise that has nothing to do with source code repositories and nothing to do with my source code as a software engineer. So I completely agree with you, but the, the, the part here that's the worrying part is when we're not using the strictures. And that's the part where anybody can do that now, right?
Even, uh, I was on the phone yesterday with a good buddy that used to work at the fort and uh, you know, he's like, yeah, I'm totally vibe coating my way to a prototype for this risk analysis technology. And, uh, you know, these are the kinds of things that, that we look at and go, okay, the real risk here is what's outside the bounds of our controls. And that's, that's what I'm, uh, that's what I'm most worried about.
All right folks. Well, I think Dickens had it right. It is truly the best and worst of times we'll be back Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research and more.
Join our satisfied clients, let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right folks, and we're gonna end the week with a field report from John Schwartz who spent a good couple of days with Zscaler in Las Vegas at their annual event.
There's a lot going on with ai and earlier in around the previous week anyway, they bought a red canary and entered into the MDR space. But John, give us your sense of what's going on with these guys. 'cause you know, it's funny, they're not completely security.
They're also very much like, let me run everything in your IT environment and I'll secure it as a add-on bonus. Almost They're expanding their empire, right? I mean, in a sense the takeaway from here as you boil it down to kind of a marketing phrase is they want to be the jet GPT of zero trust, security, and in a sense, as part of their presentation, and it was a really interesting presentation, was compelling for a couple of reasons that I'll mention later.
That the, the keynote in particular from the CEO and then the keynote from the chief security officer were both, I thought, fascinating and, and in terms of, again, it's a security show, the way they presented it. And the CEO has has been talking about this concept that I think, I think we re refer to this at, uh, blackhead and RSA, this whole idea about how, uh, a security is more evolutionary than revolutionary and how we're at a stage, the CEO says of ai, we're at a wave now where security now is going, moving to the forefront. It's not no longer like a, a late decision.
It's, it's become key and, and and incredibly important. And I think that the context of what Zscaler is saying and what they're doing is interesting. And I think it's, it's really good timing in, in a sense, one of the concepts they talked about, and this is again the, the CSO, he, he mentioned this idea of a series of AI agents in a sense, which act is it become a breach predictor.
And, uh, they're these specialized agents that work in tandem. There's a triage agent, a detection agent, context agent, response agent. Basically the goal is to predict potential breaches before they move along in the environment and map out the attack path that a threat actor may take.
So the reason why I think in context this is interesting to me is that Silicon Valley has kind of reached this point where it is listening to a lot of the criticism about their move fast to break things, attitude and what it could meet in terms of AI and then long-term implications. So that's why we're seeing a lot of these companies trying to take more of a, uh, proactive approach in terms of security. And I think that's it.
It's interesting also because there is research coming out. Uh, Palo Alto Networks came out with something Thursday morning about gen AI traffic, how it surged 900% in the past year, and how AI agents are executing workflows autonomously. And these security incidents tied to gen AI are, are doubling, especially around data loss incidents.
So I know Zscaler is a public company, it's doing extremely well because it is selling fear, that's part of what security companies do. But I think the timing in the context of what they did and what they presented at the show makes for a compelling argument that we have to be more responsible about. What we're gonna do with AI use, and I think is these, i it managers start actually putting plans into place.
They're gonna pause and say, you know, wait a second, let's see what's gonna happen in the short and the long term. And companies like z Zscaler are appealing to their deepest, darkest fears, but also to their, their, their hopes and dreams. Ira, you know, every vendor you talk to says the same thing.
Now we're gonna have a small army of AI agents, they're gonna manage security, they're gonna manage it, and we are gonna evolve into supervisors of these AI agents and all the tasks will be automated and we'll just get our little batons out and orchestrate this whole thing. Is that a reasonable expectation or do you think we're kind of like hyping the crap out of this? So in large part, I think it's reason, but let's take a step back.
'cause I hate the over-hyping of ai. Like a every, I throw up a little bit in my mouth every time I, I say AI because the concept is AI is just really a set of mathematical formulas. At the end of the day, they're algorithms, there are different sets, there's machine learning, you know, there's a gen ai, but you know, there's generative ai.
And people need to understand it's not just ai, generative ai. The reason generative AI is a threat, and this needs to be understood. It's not because it's ai, but because people are taking data, putting, asking generative AI questions that involve data that they should not be sharing outside the company.
And that's where these data breaches are coming from. And yes, if you can stop generative AI disease, scalers not unique in this, you know, I mean you have layer X, you have talon and whatever else, all that can pre prevent generative a sending data through generative ai. So you need to understand what is the threat ag agentic ai, which is kind of what you're referring to, where people where essentially software programs are acting autonomously.
The way the software programs have to act autonomously is like first you have to put it through machine learning engines, which are basically categorizing incoming data to give you a likely opinion of what is happening. So you need a machine learning algorithm embedded first, which is deciding whether or not there's something going on that needs an action. And then you take that data point and you combine it with a few other machine learning algorithms, and then with another machine learning algorithm, you basically say, if A is happening and B is happening and C is happening, the appropriate action is to take this or to do this.
And then a agentic AI is basically then going the further step to doing that action because all of the other algorithms have determined this. And so is it a natural progression? The answer is yes, because we are finally able to use, and, sorry, this is, I'm on a soapbox again, sorry for this.
But the other part that it, you need to understand about why is AI happening now? AI is not, and again, I am throwing up in my mouth as I say that AI is not happening now because it's a major breakthrough. AI has, these algorithms have been in place for decades or even back through the 1970s or so.
They're just able to start using these algorithms now and applying them because we're now able to gather significant data and to process significant data, which is why Nvidia is worth like $3 trillion because their chips enable the use of these advanced algorithms that require lots of data. So to answer your question, again, yes, given the amount of data we have, given all the algorithms and the training of these algorithms, which people forget, we're now able to combine the algorithms to enable agentic AI to take actions. And again, it's an evolution.
Much like John was saying, it's not a revolution and we have to understand why we're evolving to this point because this is where we have to understand the actual threats, not say, oh my God, it's ai. It's like, no, oh my god, users are sending data into a prompt, into some system we don't control. And then getting back data, which is going through systems we don't control and hopefully using it in ways that are legal and ethical.
Okay. I'm off my soapbox. Thank you, Brent, what's your take on that?
Because you know, what IRA is describing is essentially AI backwash enabled by hardware, and it's just, you know, part and part of what we do. Uh, I have a slightly different perspective on that, but I don't disagree with anything that Ira said. I think the, let's talk about Zscaler for a second and sort of reframe what the AI picture looks like.
Uh, as Ira said, right, there's an awful lot of, we can't control what users are doing with our data. That's a huge thing. There's a fleet of startups that has started developing things.
Anything from an AI secure browser as a proxy to, you know, proxy behavior in the company. It's only natural for Zscaler to do that. Uh, and, and I think actually there is some good purpose for that.
The, you know, a agentic part of that. I mean, I, I'll talk about it in a second, but I don't quite throw up in my mouth, but I certainly have to eye roll a little bit, right? When, when we talk about it, not just because of what the implications of that are, but also the, the current value versus the potential.
And so if you're, if you're Zscaler and you're, you don't know all the pipes, but you are in essence the preeminent zero trust, uh, broker of network traffic, then Palo Alto might disagree with me there, but the, the, the value behind that is now I already have inspection of all the network traffic I have. Wouldn't it be nice if I could predict whether or not that's a malware C two channel that's now exiting the building from directly from the server. You know, a as Ira pointed out, right, that data loss kind of a problem is not just now with, uh, an acquisition of, of Red Canary.
Now I also have a bunch of technologists that do that work as tradecraft that I can then build into, you know, in a agentic workflow. And so the EENT workflow might look like this. Um, it's interesting that I see this particular set of segments of network traffic that are outgoing to potential malicious actors.
I would like to make sure that we look to see where that source of data comes from, look at the network traffic, then run an agent that does a specific set of analysis to see if there's any, uh, malicious code there and so on and so forth. And work in, in essence an IR process. And to the other point of that is really about the segmentation part, right?
And, uh, Zscaler, uh, you know, blue Coat proxies have long been, you know, the bedrock of saying, uh, I wanna make sure that when we classify the traffic, I can say this category of traffic is not allowed from a policy perspective. Well, you can't do that with AI really today. And so, you know, this allows some instrumentation on how to classify some of that infrastructure in an auto magic way.
Uh, you know, ag genetically to say that, uh, basically on the context of this without, you know, apriori knowing what the category is, this looks like it's probably not going to fit into the thing. And the the difference between say, you know, machine learning algorithms and, and ai, uh, ag agentic approach to this is saying, let me give you the strictures or the reduced instruction set I want you to operate with, right? And then execute set operations for me.
And where this gets different and you know, we've had a bunch of experience with this at, at the tech team is also you're sort of saying to the model, Hey, uh, I I want you to do this. And then because you're smart, mostly you're gonna figure out how to do this and you're gonna iterate through it, what'll be, and, and get to the right answer eventually, right? And what's gonna be interesting to me, uh, is the amount of costs and the amount of churn, the amount of bandwidth and the adjacencies around what that type of informed activity is gonna look like because it isn't for free and it is expensive.
And it's going to be interesting to see how they parlay that out to their customers. Like we were talking about earlier. Uh, respective to Microsoft is none of that's for free either.
So Here's the part that I kind of and left scratching my head about. So let's imagine you're a cyber criminal and you're watching all of this and you're saying, uh, let me see if I understand this correctly. You guys are gonna build these agents that automate all these tasks and the agents are gonna have all these interesting privileges.
So all I gotta do is hack into that agent and then I can take care of your 'EM and take over all these other things that you have built out there and these workflows. And I can maybe even take control of an entire business process. And, you know, I'm gonna sit there and say, you guys are frigging awesome, man, thank you for making my life easier.
So is, is there kind of some silliness here? Or Ira, I wonder we, you know, They, they acknowledge that, they acknowledge that, that that actual possibility of happening, and I, I give them at least credit for, for saying that. But I was like, you know, we talked about this yesterday.
What happens when you, you compromise you're own the AI agent, then you're in charge. So yes, they, they, they create, they, they issue a, a possible solution, but they also create a a possible huge problem. Yeah, but here's the thing.
And we got in cybersecurity, everybody's like, oh my God, people can now do that. Cybersecurity is about risk management. It's not about perfection.
These agent, uh, I said agent ai, so I don't have to throw up again in my mouth, but these agentic ais are taking a, improving the ability and speed to act, assuming they're programmed correctly. Let me say that they are helping security infinitely more. Well they're right now significantly helping security to act quicker, to detect things quicker, which has been like dwell time has been a major problem that our industry has had.
So maybe a agentic AI especially built into all the data sources, will stop well time from months to hours to minutes, hopefully. That aside, yes, there is a risk to it. And are we gonna throw, you know, again, are you gonna throw out the baby water baby with the bath water analogy?
And that is accurate here. Yes, these are a threat, but assuming companies are doing this correctly, and it's nice to hear John say that they acknowledge this is a potential threat. So it means that they will be watching for it.
You know, I don't wanna say it's an arms race 'cause it's a cliche, but it is an arms race. And yes, we have to accept that these things provide a lot of benefit and we do have to acknowledge there is the potential risk of misuse and abuse and it's a trade off. All right, I'm gonna end the conversation here and I'm gonna suggest that maybe I'll buy a round of AI mouthwash for everybody.
But, um, the next thing we're gonna have to kind of think through here though is, you know, hey, every new thing that happens creates a, a counter effect, right? And so insecurity is no different than that. Hey, I wanna also highlight again, IRA, your cruise con.
Give us the date on that and the virtual event. So Cruise con virtual is June 17th, I believe it is. And then awesome sessions.
Admiral Rogers was our keynote. We have the CISOs from Waste Management, we act I can, sorry, um, Kirsten, sorry. Kirsten Davies is on the panel along with Renee Guttman.
Jared Beason, Tim Brown from SolarWinds is also on like the, you know, one of our keynote panels and outstanding content on social media production users, generative AI security, and a whole bunch of other stuff. com is how to get there. And then we also have another cruise con going out that you guys will be recording as well on October 2nd.
com. Anyway, I'll leave it there 'cause I know you're outta time. All sounds great guys.
Hey everybody, thanks for watching. Thank you to our guests for sharing their knowledge and their expertise, and please stay tuned for all this awesome content that's coming up right now on Textron tv. We'll see you Monday.
Hey guys, thanks for the throw. io and we're talking about giving observability capabilities to, well, AI agents. Turns out that they're gonna have to check out our infrastructure, our applications, and all kinds of things that maybe we don't wanna do anymore ourselves.
Hey Tomer, welcome Michelle. Thank you. Thank you for having me.
Alright, so you guys just rolled out this new platform and it's designed for AI agents rather than people. What's the thought process that went into that and and what is different about observability being provided to AI agents versus humans? Yeah, for sure.
It's been, it's been quite a journey. You know, it's been a little bit more, probably a year and a half almost, you know, since we started with LLMs and like everyone else, we said, oh yeah, we have an observability platform. Let's duct tape, uh, a chat bot so people can ask a question.
You see it on every product you go to, right? Whether it's Kayak or whatever product you use. And we did the same.
It was pretty cool. It was not very accurate. And then, you know, we, we, we realized a potential in it and, um, late last year we moved into AI agents.
So you, you know, you send, ask a question, you send it to do research, it wakes up at night and does handle alerts for you. It's pretty amazing. But then we realized we're still duct taping.
We're taking, you know, a UI that is designed for humans and we're trying to duct tape an AI agent to start and imitate what a human does. And, and, um, late last year we took a decision that we're gonna look at AI agent as the first tenant in this future platform and we're re-platforming the entire, uh, product to be AI agent first. And I can talk more about what it means that this was the, the, the notion behind it.
Well, let's do that. And what does it mean to re-architect the platform? What's required?
So you think about whatever tool you use as a user. Uh, you know, our users come to log over, they use to having something and it's designed for someone with a mouse and a click or a keyboard to ask question. And then I'll give you a simple example.
If you were to take the UI that we have, the dashboarding technology and try to fit it to the ai, it'll be very hard for the AI to feed it because it's a lot of data, a lot of numbers. The context window is very small. So what we've did, we've done is said, okay, let's redo the, the dashboarding technology first.
Let's make a great one. That's always good. But, but beyond that, let's make sure it's designed to be compact, to be designed to be API first.
It's designed to be created by AI versus created by a user and designed to be read by ai. So now when an AI wakes up at night and handles an alert, it'll go to a dashboard. It's very easy for the AI agent to read the dashboard like a human read the dashboard.
It's very, I easy for you to generate a new panel when it does investigation. So we're, we're kind of announcing a big part of that, this new dashboarding technology to be, to be AI first. AI first doesn't mean human exclusive though.
'cause if I understood you correctly, it is human readable, whatever the output is. So how will these AI agents and humans kind of collaborate in the age of observability? Yeah, a hundred percent people pe the people are not going anywhere anytime soon.
Uh, they still need to, you know, do all the work, the dashboarding, the workflow. So it's absolutely human readable. It's just designed from the, from the, from scratch to be AI first and then, and then we, we think they're gonna collaborate a lot.
And you know, if you see in every product we look, hey, AI is gonna have a magic wand, it's gonna be amazing. Gonna solve all your problems, it's gonna write your code, it's gonna order your flight. You know that US engineers who are a little bit, you know, skeptic and, and, and we, we take a very much a crawl, walk, run approach.
So I'll give an example how we collaborate. So we tell customers, Hey, one day this can wake up at night and take care of your alerts and do automation and it's gonna be awesome. But today, let's start with a simple model.
Let's take the alerts that you're just very familiar with. Hey, this issue always happens. I know what to do.
Let's have the AI agent wake up at night, take care of this alert, but not do anything. Just tell the operator, the user, the junior engineer, Hey, this is what usually you do here with the playbook. I've already looked and investigated.
And I think that's the issue and it's a recommendation. And once you feel comfortable with recommendation, it takes the most mundane one and automate them. And only then we go step by step and get confidence and we improve the AI and make it more accurate and you improve.
So it's kind of a journey and a lot of collaboration ahead of us. How will these agents get orchestrated or managed or supervised somebody? A human, I assume, but who knows?
Maybe it's another AI agent is gonna need to interact with these things. So how do I kind of, um, ensure that they are automating some sort of process that makes sense? Yeah, it's all today done by humans.
You'll have to say, Hey, if I get too many error, like let's say there was a deployment and AI wakes up after every deployment and it looks, Hey, was this a good deployment of code? Did I break anything? Do I have too many exceptions?
Now do I have too many error messages? If the AI thinks you have to, uh, do something, it'll tell the user. So me as the user, I can say, Hey, I want an AI agent to do deployment validation.
I can turn it off. I can turn it on. It's fully controllable.
It's not gonna conquer the world just yet. So it's, it's good. Are these AI agents ones that you have trained specifically on the platform, or can they be any AI agent that just wants to invoke the observability platform for some reason?
So, so we use cloud as, as our infrastructure and, and we calibrated in that lot of work or cloud to make sure it fits what we're trying to do. So yes, we will have the ability in the future to, so customers can bring their own AI agent, it can work on others. Specifically with Claude, we have worked a lot to optimize it and to do all the work to, and, and, you know, one of the biggest issue in observability is, and it's, it exists in other markets.
There's a lot of data like terabyte and terabyte of data. Every hour, every two hours or every day. AI agent has a very narrow window of context.
So how do you take all the world and all this telemetry and, and push it into an AI agent? And that's a lot of where our unique technology, so the work is actually done not in the agent as much as it is done in how you prepare the data to make sure the AI agent has the full view of the system. And this is where we, we feel like we, we made the most impact.
We also hear a lot of excitement about things like, uh, the model context, protocol, MCP, and then there's talk of these agent to agent protocols that might sit on top of that. Um, how will we achieve the level of interoperability we're looking for and, and just how, uh, integrator will everything get? It's a great question.
Uh, we are actually, um, have a, have a session in, uh, in, in a week where we, and another company, pager duty, we're gonna show how agent to agent works together, how our agent talks to their agent, how all it all works together. It's, it's pretty good. It's very innovative.
It's really the cutting edge when it comes to MCP. Yes, all the protocol exists, and we're gonna launch our MCP soon. That, that, the real issue is that you don't see many of them actually interacting.
And it's still very, very early in the market. And I think they can integrate. But there is a, there is a race in the market, in our market, and I think in every market, who is gonna be the agent to rule them all?
And who's the gonna be the one serving the information? Everyone wants to be the agent to, you know, to look at all the other pieces and tell you, Hey, this is where the problem is. And they don't want to be the one just serving the data.
So there is always this, this, uh, this, uh, question is where is the right place in observability to really match and correlate all the information to find, you know, what you're looking for. So I, my my, this was a sh a long answer to say, you know, yet to be seen how they're all gonna integrate. It's in theory they're all going to, but let, we'll have to wait and see, Will we be thinking about observability in a larger context?
'cause most of the conversations we've had so far are very, pretty much, you know, software development, DevOps specific, but I need to observe a lot of things including security business processes. So as this evolves, will observability platforms kind of expand their number of use cases? Uh, a a hundred percent.
We already see that. Literally today, I was talking to one of our customers and they said, Hey, our business people, because they can look at the BI that will be ready in the week, and they don't have the ski, the BI takes time, but they go to log Zion now they ask a question and they get an answer, Hey, how many people from, you know, went to our app from, you know, uh, this country using an iPhone versus an an, uh, you know, um, an Android. So that's a question that you can use log to us today.
But if you're a business user, you don't know how to run the queries and it's complicated. So suddenly it exposes other things to, uh, exposes the platform to other, uh, users. And what I think also will happen in the future, in, in, if you kind of go another level up, what is observability?
You take a bunch of data, you integrate into all these system infrastructure. You, you bring the data into one place, you organize it, and then you have all these UI and alerts and dashboards that can be used, as you said, to cyber, to business intelligence, to finops, to various use cases. And I think in the future, these are all going to converge.
And the the strength will be how much can you integrate, bring all the data? Can you do it in a very cost effective way? And how good are your AI agent to be able to, you know, solve and answer the question and do the automation I need to do as a user.
So I can see a lot of, um, convergence. It's maybe five or 10 years from now, but I'm, I'm sure it'll happen. You talked about being AI native.
Um, one of the things that has struck me about AI in general is the amount of telemetry data being kicked off is phenomenal. And so do we have the ability to actually process all of that and make sense of it and store it? 'cause well, storage still isn't free.
Last time I checked, so, so, you know, how will we handle all this high cardinality data that we're gonna have on our hands real soon? I think the data is only going to grow. We've been saying it for years.
Everyone has been saying it, and they're right. I think the, the, the strength of the, of a good platform would be the ability to process a lot of high cardinality data at a very, very low cost. Because AI needs a lot of data.
It needs the right data. So, so I think one, you need good platforms, then yeah, in the market, there are 20 other platform, they're all good. But I think they need to be very, very cost efficient because AI is gonna demand more data to be able to make thoughtful decisions.
So I think cut, uh, platforms that are very expensive are gonna suffer because people cannot get the value of ai. That's number one. Number two, the second largest use case for our AI is actually to solve this problem.
And people use our AI and they ask it, Hey, can you do some research and tell me which data I actually don't need? I never search for, I'm not using a dashboard or alert. And the AI is actually doing fantastic job in scanning and telling you, Hey, you know, actually 40% of the data you're shipping us is actually, you don't need to ship it.
Just put it some in a, some S3 bucket so you won't be charged for it. And that helps them cut the cost. So I think on one, one edge, you want to increase the value with AI agent.
On the other hand, you want reduce the spend on these, as you said, storage is not for free. So it's, it's a, it's a common use case. Ultimately.
How will our user experience evolve? 'cause we're so used to kinda looking at dashboards all day long. Are the dashboards gonna go away?
Are they gonna be replaced by AI agents and or, or what will the actual user experience be like? I honestly am not sure. I'll tell you what I don't think will happen three or two or five years from today, you're gonna see these big screens and you know, the knock people on the DevOps or platform engineering, whatever, they're gonna look at all these dashboards and try to say, oh, I see the spike here, and that spike there.
And that is not going to happen anymore. No one knows how the future interaction will happen. Um, my gut, and again, I'm not sure, is the dashboard will go away completely the way AI agents will work.
They will do the correlation analysis and they will generate a dashboard for you for this specific incident right now, Hey, I wanna show you something right now. Have a look at that. Our AI agents right now, and again, we're early in the journey, this is only getting started, is already you ask it the question, Hey, there was some too many error 500 or unable to log into system error messages, do some root cause analysis, and it'll go into start to create panels and dashboards for you to, as part of the reasoning process to show you what it went through.
So it's, it's pretty powerful. And I think the time of like the day that you, we have customers that do 10,000 dashboards, that this is gonna go away. As you kinda wonder about all this new AI capabilities and experience that we're gonna have, um, how autonomous will these AI agents actually be?
Because I can envision a world where I have a AI agent for observability that is connected to, uh, some ITSM platform that then the two of them go execute something. But am I gonna trust them to do that? Do I want to have that be permission or over time will I just increasingly rely on them?
It's a good question. I think I still think even in five years from today, a lot of these things will still have ma like human supervision in the most critical systems. You still want to have some change management before you make changes and before you automate things completely.
But I would focus on the mundane stuff, the 80 20 rule, the 80% of the alert, the 80% of the incident, the 80% of the noise. I think we are gonna get to a place of autonomously and it's gonna take some time. Um, we wrote a, uh, we wrote a, a, um, a story about autonomous observability.
It's a little bit like, you know, cars, you know, getting the, the first level and the second level where it helps you drive and maybe it does the, the FSD and, but the, the the last type of full autonomously is such a big leap. But I think we are gonna get up the scale of autonomously and assisted and, you know, only supervision very, very, I think faster than we think probably in the next two to three years. Well, folks, you heard it here, observability, AI agents, they're gonna be pervasive.
The only question is now is are we ever gonna be surprised again by these complex IT environments or will everything be known that today is all too often unknown? Hey, Tomer, thanks for being on the show, Juan. Thank you for having me.
Appreciate it. All right, and back to you guys in the studio. Hey guys, thanks for the throw.
We're here with Ron Desai, who's the CEO for SIR Ro. And they've just picked up $21 million in funding to develop an a i team made for SRE and DevOps engineers. And we're gonna get into what that means and how maybe DevOps is evolving.
Ronak, welcome to the show. Thank you very much, Mike. Great to be here.
First time on. Thanks, uh, tech strong TV here. Everybody of course by now, unless you're living under a rock, has heard about something about AI and AI agents and how that might be, uh, changing the way we build and develop software.
But, um, how do you see all this coming together and, and where are we on this journey? Yeah, so Mike, um, if we just take a sort of step back and look at the, where the industry is, right? And especially looking at the IT operations, uh, in a bigger enterprise today, the investigations when you have outage on applications takes a long time.
Hundreds of experts has to get involved. You know, you are to go through a whole bunch of dashboards. It takes hours on an average, uh, to resolve the incidents.
And so that's basically where we are coming from, right? So cyros ends all of that. We want to mitigate and really build a teammate for our SRE and DevOps teams.
It's a multi-agent tech system, uh, built with a model of experts so we can really target different, um, domains, which your application depends on. So if you think about like today's modern applications, right? It depends upon a lot of different components.
It's not typically people would talk about saying, oh, it's a Kubernetes based applications, but it's deployed on-prem or deployed in the cloud. Uh, it has dependency on internet, it has dependency on your infrastructure, right? So now if you have outages on the application, it depends upon all of those components.
So that's basically where we are building this capability, which is allowing you to sort of reason as a human would reason across all of those domains and really find out those insights. That's basically where we are focused on it. Um, as an industry, I think every domain is getting disrupted.
And as you know, right, every, uh, I think there is a talk and a lot of CEOs of the big public companies have talked about it, that we would have 10 to hundred agents helping us do our regular day-to-day mundane task, which we should delegate it. Those are tasks which nobody wants to do it. So that's basically how we sort of view it, and that's where we got started There.
Of course, there's a lot to unpack there, but one of the core questions people seem to have about these AI agents or teammates or whatever we wind up calling 'em, um, is do I need to have that come as part of the platform that I'm using or will there be more of a horizontal approach where it's an an over life or lack of a better phrase of, and I don't have to change any of my underlying platforms to take advantage of it. Yeah, I think great insight there, Mike. Like, so the way we kind of look at this is you enterprises has already deployed a whole bunch of SUL tools.
So the way approach which we are taking it is you don't need to replace any of your observate tool, any your, your cloud monitoring tools or your, um, um, ticketing systems or your incident management system. What we do it is think about your human SREs and DevOps teams. What do they do?
They use all of those tools including collaboration tool like Slack, right? So when you have teammate, think about it that you've got this experts who has expertise across all of those domains, works with all of those tools, extracts the right set of informations reasons, like the way your human SREs would reason it, and kind of get to the root cause. That's basically how we kind of think about it.
So you're, you're sort of, think, think about it, you're sitting just into all of those tools, which you already have it, and really trying to sort of get to the really the important aspect of how do you reduce meantime to repair, how do you, uh, help your SRE team to really reduce that toil, uh, because there's tons of work they do today, which is just tedious and manual, and nobody should be doing that work, right? So that's basically how we kind of think about it. Do not replace the tools, sit next to it.
Is there one agent that's kind of an expert in all these things, or is it really a bunch of agents that each knows a particular tool? And then there's something that feels like a planner that kind of manages all these other agents. Only Cyros has built this capability where we have expert in all of those domains, which we talked about.
One agent for Kubernetes, one agent for cloud, one agent for your network, one agent for security, and then all of these agents are sort of working together to really figure it out. Because anytime when you have a application outage, the biggest problem talking to hundreds of enterprises, what I've heard is they may have expertise in one particular domain, but if somebody made a change in another domain, they're completely blindsided. They don't even know where to start, right?
So this is where that cross domain ability to go across all of that, investigate that vast amount of data, uh, and really figure it out. Where the problem is, is where the crux of the, uh, problem here is. And so you, to your point, right, it's multiple agents working together, uh, for this cross domain and multi-domain is something which is so critical, uh, for, uh, bigger IT organizations.
Will these agents wind up talking to other agents outside of your platform? And will there be some sort of collaboration and interoperability across all these different agents? Yeah, so, uh, you, you I'm sure heard about a to a agent to agent and MCP.
Um, and so what I've seen, Mike, and this is a very interesting phenomena, which is happening in every company out there, um, which is building agent for their own set of capabilities, they have it, right? So take take an example of if you have a network vendor, they're building agent for networking. If you have security vendor, they're building agent for security.
If you have a storage vendor, they're building agent for that, right? So we are literally creating agent silos, right? And this is where we come into the picture.
We believe that we need to be building this ecosystem where if somebody has built a, a agent, uh, for a specific domain, we should be able to easily integrate with a two A internally. Of course, we use MCP to talk amongst our own agents, right? So we build agents for our own, uh, set of capabilities.
We will build it across all the domains, but we will easily integrate with a two, a interface if somebody has built a much more deeper capability for their particular domain, right? So that's how we kind of think about it. Um, it's agents working together to really solve the problem, uh, for our operations teams.
So will this become the primary mechanism which, which we engage various DevOps platforms? And I'm asking the question because today, you know, there's all these pipelines and they kind of span a bunch of different tools, and each of the tools has a slightly different user interface or sometimes a CLI and am I gonna get to like just one consistent natural language interface now and all those other things become, you know, backend services? Yeah, no, and I think the, um, uh, the whole, uh, we used to talk about UI and ux right now.
People talk about ax Yeah. AI interfaces, right? So this is where, you know, in reality, uh, we as a human best communicate, uh, by talking or by answering what our exact questions are in a natural language, right?
What has happened in the industry because of the lack of technology, we developed this bunch of dashboards, well, very pretty looking dashboards, but we put the burden on the humans to really click through those dashboards, right? So really one is to sort of build and the interface, which is very easy for humans, but also sort of elevate it instead of giving them very fragmented view of your infrastructure, your application landscape, really ask higher layer questions to get to where you need to be, right? And so we look at it from the whole, uh, AI usage perspective.
There's a part of augmenting the functionality of, um, uh, SREs and DevOps, and then there's a part about autopilot, right? So because SREs do a lot of work where they're doing proactively investigating it and just making sure that those low signal alerts don't get, get unnoticed. So there's a part of augmentations AI can help by a natural language, but then there's a part of autopilot.
And I think I kinda really like this Tesla analogy, uh, because if you think about it, uh, 2015, I was one of those early, uh, adopter of Tesla, uh, autopilot. And then the vision was it's going to be a full autopilot, but it was a mere, uh, auto cruise control and a lane change, right? Uh, still human in loop, still human has control, right?
After 10 years, we've got to this full self-driving, right? Where human is still in charge. You still have to be in driver's seat, but it takes care of a lot of those things where if you're super tired, it really helpful, right?
There's a places where way more like, uh, operation operations make sense. So the way, if you look at it from a, a way, uh, enterprises are thinking about, um, really adopting the IT tools. One is the interface, but then also how you sort of place them in, in terms of augmenting the functionality.
That's why we really love this teammate concept. It is really somebody you sort of onboarded it and think about a expert who has a million hours of training on some of this domains. So like having that kind of expertise, uh, is going to be super helpful, right?
So there's a, um, human in the loop, there is a full self driving, and then there are segments which is low impact environment. You would do a full autopilot, right? So that's basically how taking that pragmatic approach is very critical for the AI adoption.
How will those AI agents continue to be trained? 'cause the environments will continue to evolve. So how do I keep them up to speed?
Yeah. So, uh, the way we look at it is, um, outta the box when we deploy SRE teammate in our customer's environment, it starts to sort of behave like as if you onboarded a SRE teammate has a access to your collaboration environment. So if the investigation fires, it's actually picks up that investigation, starts investigating it across this domain.
So there is no learning loop per se. So at the time of inferencing, it already has the capability, but then human in the loop, right? So human can say, look, I think you investigated this correctly, you eliminated those domains, which was perfect, uh, because it helped me avoid bringing another 10 set of people on the war room call.
But this is the area where I would love to investigate, have you investigate in this particular direction or this particular domain, right? So getting that hu human feedback is something which we will continue to incorporate it as we go forward. Uh, and as we build the capability but outta the box, it'll start to deliver the value which customers are adopting us for, uh, in order of minutes, right?
So there's no learning loop from that perspective. Are we kind of finally moving beyond scripts and plugins here to where the AI agents are gonna take care of a lot of these functions that historically, uh, DevOps engineers spent time writing these scripts and then the carrying and the feeding of said scripts? And of course, uh, you know, this is one of the issues that people have with DevOps, and then it doesn't scale because it's dependent on all these brittle scripts.
So script are, are we counting entering a new phase here? Yeah. So, uh, runbook and static runbooks, I kind of call runbooks and preface it with static because, you know, once it's written, it's outdated because your infrastructure continues to you all, you add more capabilities in your applications, and nobody goes back and reviews those runbook.
Like not many organizations have that discipline. Um, but what if, what if, if you had a system which was thinking like the human had understanding of your environment, you wouldn't need those static runbooks, right? And this is where we come up with this patented technology, what we call it behavior pattern, right?
This is the behavior pattern is think of it like if you all got the best experts for all of the component your application depends upon, and it has the ability to sort of eliminate and reason like the way your all the experts will do it, you don't need those runbooks right? Now. You've got the system which is able to reason like the humans, right?
So in this hu uh, systems can watch your environment 24 by seven by 365. So think of it, you got a superhuman SRE who's watching your system and able to do what your experts are able to do it. Why would you need static runbooks, right?
So I think my take is those era of building those static runbooks era of keeping those up to date things that have been gone, right? I mean, you've seen this across coding agents as well, right? People are using a coding agents to write some of the software documentations and keeping them up to date.
So that's how I think we would evolve, uh, even in the ops era. So you raised the 21 million, what's the priority for that? What are you guys thinking?
What needs to be done next? So, uh, 21 million. So super exciting.
Uh, it was oversubscribed round. Uh, absolutely we are, uh, inviting all the talent across all the groups. Uh, whether it's, uh, talented engineers go to market, uh, product managers, we are inviting them to join us on the journey here.
And then of course, we wanna really double down on our GTM accelerate inviting customers to join, uh, us on this journey. Um, early feedback has been amazing. Uh, so the goal is to accelerate, uh, the journey here.
So when you show this to people, what's kind of the reaction you get? I mean, because you know, on the one hand I can imagine that there's a fair amount of excitement and then there's also a certain amount of, well, you know, who's moving my cheese, right? Yes.
So, um, and then this is where the teammate concept is super critical, right? So let me just take a step back and kind of describe, right, what all, uh, has happened. The pace of innovation on the application perspective from a developer's perspective is going through the roof, right?
We ourselves get 90% plus coding using some of the AI assistance, right? Uh, when we are building the product. So that pace has started to go up.
So things coming at the SRE are a lot more than what it used to be because now our developers are more productive. Before this phenomena happened, first of all, environment was very complex because the very distributed nature of applications. But when we enterprises, we noticed that there were, for every one SRE, you had 15 to 20 SREs of developers, right?
So one SRE, 15 to 20 developers. So there was an imbalance in terms of the amount of work, amount of alerts which were getting generated, and this team's ability to kind of take care of it, right? So they were already sort of falling behind and we, we were talking to one of our enterprise, uh, financial enterprise customers.
8 million alerts, we are a team of 10 SREs. There's just no way we can deal with that, right? That's today, now just apply that exploration, which is happening.
So they're falling behind. So we really need to sort of focus on really bridging that gap and give them the same sort of capability, which our development team has it so that they can start to really focus on the critical work in terms of architecting, building, the reliable system, thinking about and proactive so that they can add the bottom line to the business, right? So we really believe that this is a part which is augmentation and help, uh, the SRE teams where they feel comfortable to let it run in autopilot environment.
This is not about productivity gain. There is already things which are so manual and tedious tasks, which we want actually want to take it away from their plate and let the system do that work. Um, who wants to sort of query logs, metrics, traces, try to figure it out across four different domains.
I mean, it's just too painful. And to your point, we're already struggling, but as far as I can tell, the amount of code that's being created is also accelerating. So we may be looking at a tsunami of applications that are coming that, um, and we're not adding more SRE bodies to the equation.
So the only thing to do is to lean more into ai it would team. Exactly. Exactly.
No, I think, I think it's, it's all of those things coming together. We really need to build this team mate, uh, for the SRE. And I think you raise a very interesting point, which is in 2025, if anybody was going to build SaaS application, it's going to be based on agentic ai, right?
So there is a aspect of modernizing the practice of monitoring even those applications, right? Which are native agentic applications. So monitoring them needs a different set of capabilities.
And I think building that out of the box from day one is super critical, right? So that's something which absolutely something which we would attack, um, as, as, as we, uh, sort of get into this journey. All right, folks, while you're heard in ear, hey, DevOps at scale equals a gentech ai.
That's one way of thinking about it. Ron, thanks for being on the show. Thank You very much, Mike.
All right, and back to you guys in the studio. It is the Tech Field Day podcast with Catchpoint. We are going to be looking for the unknown unknowns.
Have you got links to external websites that maybe your vibe coders have linked to? Or maybe one of your developers found a really useful tool that links to some other website. Maybe it's a service that's running on a cloud provider like AWS.
If you don't know it's there, it might cause you pain later. Stay tuned for this episode of the Tech Field Day podcast of Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea around key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often recorded in association with one of our events.
Tech Field Day is part of the Futurum Group, and this podcast is also published on our sister company site Techstrong tv. On this episode presented by Catchpoint, we'll be discussing how your internet application is full of unknown unknowns. Before we get started, let's meet who's on the panel today.
Hi everybody. My name's John Meyer, chief content creator at Meyer Media. And, uh, my name is Eric Wright.
I'm the co-founder of GTM Delta and also the head podcaster at the Disco Posse podcast. And joining us from Catchpoint, fresh off their presentation at Cloud Field Day 22 is dirty. Welcome.
Thank you, gentlemen. So, hi everyone. My name is me, I'm the co-founder and CEO of Cash one, and coming to you live from New York.
Excellent. Well, we're spreading all around the place. Uh, we've came up with this unknown unknowns because we were discussing a little beforehand, as, as you often do, uh, how incredibly interdependent we end up with with internet based applications, because everything, every kind of service you can imagine is available over the internet.
We up building our applications to use bits of this and bits of that, and we may not even realize in the same way that on premises, we used to occasionally end up with a developer machine, which was running some vital service in our production application. Now, our internet applications can be dependent on all kinds of things all over the internet. And maybe this leads to people experiencing outages when they really don't think they should be experiencing outages.
I like what you just said. They're experiencing outages where they should not be experiencing outages. Um, so when you think about it today in 2025, an average web, an average website or web application has about two to 300 calls to, to objects that are, that make their webpage, right?
So that can be ads, that can be CDNs, it can be tracking pixels, capcha services, payment gateways, you name it. But on average, it's two to 300 requests that needs to happen in milliseconds for you to have a good user experience. That's true for mobile apps as well.
Out of those two to 300 requests that needs to happen and fire up immediately, you're probably talking to about 50 to 60 different host names that are hosted by different organizations, whether it's cloud services like Amazon, Google, et cetera, or your own data centers. And those calls also rely on a DNS lookup that is hosted by either ultra DNS and NS one dime Oracle, or your own DNS services and all of that rely on a spaghetti of networks, uh, of ISPs. And all of this stuff needs to happen in real time.
I mean, when you think about it, it's like a human body, right? My head is thinking, it's talking, telling my toe to move, and I'm not even thinking about it, right? All of this needs to happen in milliseconds.
The problem is, uh, you, the company, for example, have great service, uh, great services. You bought the best servers, you have the best third party, uh, hosting. You have the best CDN, you have the best of everything.
You have the best SREs, you have the best engineers, you're top-notch. But there is a third party pixel that is called by some unknown other pixel that is called by another unknown pixel that comes out of nowhere that is hosted in Cambodia or Vietnam. Uh, and that thing is unre unreachable, and that is going to bring your house down, literally the house of card.
So, uh, so this is why I like the unknown unknown, uh, famously introduced by Rumsfeld during the Gulf War, for those that remember, but in many times, we're dealing with an unknown unknown. So why, what is the unknown unknown in the observability monitoring space is you don't know you have a problem and you, and worst, you don't know how to deal with it. So again, you don't know you have a problem.
So then you get to rely on down detector or our own version or, or something like that. Or maybe even worse, your CEO coming down, it's like, Hey, what's up with, with this? Uh, I'm in a meeting and I couldn't close this deal because our website was done, or our web application was done.
So first you don't know you have a problem. So you're relying on Twitter down, sorry, X down detector, uh, an angry sea level person that is telling you what you should have known in the first place, which is you're, you're dumb. Then you look at your playbook and it's like, you've never seen this error.
So you, you don't know how to act with it. And that is doing what? That is going to prolong the time it takes you to respond and get back in online.
So that's the unknown unknown we are dealing with. And, and believe it or not, it happens a lot more and we're not seeing that problem go away just because, hey, let's add the chat GPT uh, piece on our website, right? I mean, what can go wrong?
It's ai, it's it's self, self working, right? Or self debugging itself. Well, if a open AI has a problem, you, your website is going to have a problem, and then you get to have angry customers.
So, uh, so we're constantly adding stuff to our websites and our web applications because we want to reach your things. We want to reach your applications, we want to reach your visualizations. We want to richer experiences.
Well, what, when we want that, we want complex and we, we add complexity, and the complexity just keeps feeding this unknown unknown little monster of ours. One of the things that I hear a lot of times medi is, uh, you know, a PM is obviously like better telemetry, better instrumentation. We've got lots of people trying to solve the instrumentation challenge.
So I'd love to let people know and like, think of like, what, where does a PM end off and IPM come in? Where does the interconnectedness of those things? So where are you winning by a PM and where does IPM really, you know, come in where a PM can't?
Sure. Um, so it's not one versus the other that I don't think that's the best way to look at it. So for the viewers and listeners, so I'm not, I'm not advocating one or the other.
I think it's usually it's a stereo vision, so you need both. So it's A plus B. And here is, uh, here is why.
So again, going back to the example we talked about you, the company A has the best engineers, the best servers, the best, best, best. And you go and buy yourself the best a PM tool out there. Dynatrace, Datadog, you name it, they're all amazing tools out there.
That's great. So your house is protected, right? You, you, you have all the telemetry about that window in the north, that the door on the right, the roof, the water leakage, you have everything great, you're safe.
Except that, except that you invite two, 300 people every day to your house, and they're not going to necessarily put Dynatrace or Datadog or whatever you pick you, they're not going to put your smoke detector in their house. And so that's why it's important to have that, that end user view. Uh, that is, uh, the monitor, the monitors, basically, we, we are above all that stuff.
We're looking at it from a satellite view. So, uh, again, you can put your, your smoke detector in your house. I can look at it from a, uh, from space, and I can zoom in.
I can say, yes, your house is on fire because, uh, that third party that you, uh, uh, that you've let in is having a problem. And you, you don't know because you're not going to put an a PM tool agent on that third party vendor that you use. So, uh, the other thing is where a PM is very good at understanding your infrastructure, your systems, your application, your code, your, your relationship between that piece of code and the database lookup and whatnot, it's not very good at telling you.
Well, you know, in Boston, on at and t right now, there is a BGP issue that is preventing all the users from getting to you. And you, if you just rely on a PM, somebody's going to call you and say, Hey, people in Boston are having a problem. And you're going to go and blame the, you're going to blame the developer, you're going to blame the database guy.
You're going to maybe look and see, was there a change? Did we make a rollout yesterday that broke something? So you're going to go and spin your, your wheels in trying to maybe try to see if the problem is in your house versus the problem being, again, a third party.
And again, the unknown unknown. So you don't know you have a problem and you don't know how to deal with it, right? And that's again, where we come in.
So it's not one versus the other. It is just one covers the inside of, of your house, and the other one looks at it from a different perspective and just makes sure that even if, by the way, most of those a PM vendors that are great, uh, they're all hosted on the cloud, right? So by the way, if AWS goes down, you're completely blind because all of them are hosted on AWS We're not, we're not hosted on any cloud vendor on purpose.
And I, it cost me a lot of money to not be hosted on AWS or one of those vendors. But we're on purpose because ultimately our job is to watch over those things. Medi, I love how you use the analogy of a house, and I wanna walk through that analogy just a little bit more here.
I have a house, right? And if I invite somebody into my house, I know where they're at, I know they're coming into my house, and I can validate that, hey, listen, they're into it. But here's the other thing that happens is that what if that person invites another person into a house and another person in a house?
I can't monitor them. I don't know. I didn't know that they actually invited him into a house.
And if for something goes down, something happens, I have no way of tracking it. Now I translate that to your traditional, your IT infrastructure, uh, building an application where I am the, you know, IT manager, and I know that they built this application and the database guy connected to this. Now that guy left, and, uh, I didn't know that he connected it to, you know, say Facebook meta to pull in some data and APIs behind the scene.
Now I have tribal knowledge. And now they're pulling in that. And when that goes down, we're running around with our heads cut off trying to figure out what, why, why am I pulling meta information?
Why is that, wait, why did I build my application around it that is totally unknown, that I didn't know my application was tied to this backend pulling this data that now critically handles it off to my customers. You know, those are some of the things that are totally unknown to in organization or an application until something goes wrong. And, and the other thing, John, what what we see a lot is, well, it's not my problem.
I didn't build it, so why should I like, Hey, that wasn't my problem. Don't yell at me, but I'll go fix it for you. Correct?
And, and that is, you see, in the unknown unknown equation, the biggest factor in my opinion is the, I don't care and it's not my fault. And, or, you know what, Hey, we have, we, we bought an a PM tool or we bought this other tool or whatever. So I'm covered.
And, and, uh, and so I think we have to rethink a little bit, right? When, when, when you buy a, when you buy a, a, a an, an alarm system for your home, you want to protect your family, you want to protect your valuables, you want to make sure that if there is smoke, you can catch it before it goes everywhere. You want to catch carbon monoxide, you want to catch wa water leaks, and it all needs to work in tandem to protect you.
There is no, well, I don't care, or I didn't do the plumbing, or, Hey mom, dad, I'm, uh, you know, I, I just did my bedroom. I'm not going to care about flushing the toilet. It, it is just like, it, it's, it's almost like a sense of responsibility that companies need to, or the, the people that work in companies need to take on and say, we are all ultimately responsible for the assets that actually pay our paychecks, and we have to think about it holistically.
And therefore I need to put in place the right monitoring system so I can catch things as quickly as possible. Because the sooner you can catch something, the faster and cheaper it is to fix. Always.
There's, there's that crucial thing of, of it. It doesn't matter how the business you are in fails, you are gonna be affected by it failing. And so that it's, it's not, you know, I, I've done my bit that's, that's, uh, part of dealing with this, the solution isn't enough.
And sooner or later you gotta make sure that the business is able to continue to operate. You've gotta have that system level thinking of, I'm contributing to this, but, uh, the story is not complete if I just do my part of it. And having that awareness that we may be unaware that there may be dependencies, and particularly there may be dependencies on third parties who have their own dependencies on other third parties that we are totally unaware of.
Um, that collection And Is scary Here, here is, here is the biggest first party, the biggest third party is your cloud provider. I mean, you, when you think about it, we have, we have decided to put all of our eggs in Amazon or GCP or Azure. You don't know how those guys run their stuff.
You don't. We are taking it face value that, I mean, thank God they are right, but they also buy third party stuff. They also, you know, sometimes are not their data centers.
The electricity is not from them. The water supplies from the city, the generator, the diesel comes from, I mean, Amazon does not have petroleum yet, right? So, so it is just like, this is how people need to think about this to do risk, risk mitigation and understand what can go wrong versus this mentality that we've had since the cloud happened, which is like, oh, it's easy.
I push a button and poof. And it is easy. You can just consume a service.
But what happens when the service isn't working? I mean, one of the, the elements in this is a lot of this dependency on third party is if you code your application for all of the loose coupling and, uh, being able to cope with delays along the way, then you minimize the impact on the end user application. It's just that doing that is a lot of hard work for developers.
And developers are usually incented to go and get new features out, not to spend all of their time ensuring the, the highest uptime. And don't get me wrong, there are plenty of developers who do an awesome job of that, but often the business driver, we need to get this new feature out. We need to get it out as rapidly as possible.
And that's the sort of thing that leads to that scenario. Yeah, And you're so spot on, and we do a terrible job at explaining to the business that the number one feature, feature nu metal Uno is performance. That is the most important feature in my opinion.
I mean, there was this venture capitalist guy, Fred Wilson, you can Google him. He said that it was brilliant. He said that in 2008, 2009, the, the most important feature is performance.
And that hasn't changed today. It, it doesn't, that's why we keep buying new iPhones or new and why, because the processor is more performing because we want speed. We are so driven by this damn speed and reliability.
One of the things midi that I think more and more of us are seeing is the abstraction away from, like, the whole idea is like, can I get ideas to production? Whether it's no code, low code, we're seeing things like versel and we're seeing vibe coding, and what you, we end up with these is a lot of, you know, less bespoke solutions, but they're also incredibly opaque. Uh, so how, how are you seeing the rise of paths actually getting great success in my view?
Like, you're seeing Heroku coming back to the for, again, where you're seeing a lot of that happening, but then what's the impact on application builders and, you know, where do you see your, your role in, in helping people to really get the most outta those platforms? I, I, so yes, there is a rise of all these applications, all these platforms. Uh, I think we're going to see even more of that.
I mean, when you think that chat GPT can start generating code and prototype for you and stuff like that, I mean, it's, it's, it's unbelievable the world we're going to live in, right? Where it's just like the ideas are going to just like, it's explosion of ideas and creativity. I'm, I'm, I'm, I'm jealous to some degree, right?
Um, I do think that, uh, this opacity that you mentioned is good for us, uh, because at the end of the day, that doesn't take away the fundamentals of reliability. Again, it's still a computer, right? It's still a network, it's still a service, it's still an infrastructure.
It's still CPUs and memories and things like that. And that stuff still breaks. And we keep breaking, I think, uh, where we're going to.
And you showed that. You saw that, uh, uh, when we presented, that's why we keep investing on this internet stack map, being able to visualize and understand the dependencies. Uh, that's why we keep investing in some of our AI capabilities to be able to detect and connect the dots.
Because what this, what this is going to do is just like more opacity, more complexity, and then understanding what happened is, is going to be more crucial. That unknown, unknown is still there. Bigger, worse.
We just need to shrink the amount of time to detect and, and, and help customers. But yeah, I don't see any change. I just think that things are going to get worse from a complexity perspective.
Medi, are we our own saboteurs when it comes to the unknown? When you're implementing things and you're trying to be efficient, you're trying to get the most out of it in the performance, and we go and attach to a website or a database that's public out there just because we wanna provide something to our customer, but ultimately not realizing that we don't know as much about them as we should. Yes.
And I will add, I think we need to live around that. So we shouldn't stop that because I think that's stopping progress to some degree. That's stopping creativity that, listen, I love the risk taking that people take, otherwise we wouldn't be here, right?
Uh, I think risk taking is important. I think risk taking with some mitigation is even better, right? So I think I, I don't think we should say that disconnect from the internet, you know, know that's the safest thing.
Let's unplug and, uh, you know, we can all sleep well at night, all that stuff. Uh, but I think we need to put the boundaries and the systems and procedures to detect and, and do all that stuff. Uh, and, and even if you wanted to, uh, to certify third parties, this then becomes, again, problematic process red tape, and people go around red tape anyway, so it'll be a cat and mouse game.
So I think what we should, I would rather do is like, hey, put in place the system to detect the smoke, uh, as quickly as possible. Uh, I know sometimes it's more expensive, but I think the, uh, the red tape and the risk, the risk aversion is I think very bad from a business perspective. Your competitors might say, you know what, let John be risk averse.
We we're going to go and do other things and kick his behind by coming to market with something better. I think, uh, as we're coming to the end of this podcast, and, and as as always, when we gather together, it's such an interesting group of people. We could go for hours at this, and I, for one, could probably do with a drink.
Um, I think also one of the things I, I really pull out of this is that there is no nirvana state. Nothing is going to become perfect. And so getting the ability to see the imperfect, to understand the imperfect understanding that there is a tension between business requirements at different phases and, and this conflict is natural and norm, not something to be avoided, uh, is, is an important aspect of not just this conversation, but any conversation where we're talking about innovation and building things.
Since we are running out of time, it would be great if, uh, listeners out there would like to catch up with people some more and carry on the conversations. Uh, we can we carry the conversations on with you all. com, also follow it at Meyer Media and hit me up on all the channels, LinkedIn, Twitter, oh, sorry, X I'll never get used to any of that.
But anyway, you can follow us at John Meyer And, uh, I'm Disco pae and all social media. com and find out what I do. org.
One of my favorite tools that I promote to everybody thank you is Catchpoint gives back to, you know, in free ways to the community. It's incredible help for me as a developer to learn. And, uh, but anyways, that was my last, uh, shout out.
But, uh, with that, over to you. Thank you so much, Eric. org.
So that's one way of, of getting to understand a little bit your unknowns. com. We have a great blog.
You should, uh, read it on LinkedIn, X, et cetera. So thank you so much. com website.
You can find me also writing various places my own, um, writings. Typically at the moment. co nz, uh, or NZ for those of you in America.
And, uh, you'll also find me on some of the other TUM properties, uh, writing content out there as well. So thank you for listening to this episode of the Tech Field Day podcast. If you enjoyed the discussion, please subscribe on YouTube or your favorite podcast application so you don't miss an episode.
Do consider giving us a nice rating and if a review and other people find us this, uh, great content as well. This podcast was brought to you by, uh, Catchpoint and Tech Field Day, a part of the Futureum Group. com/podcast or review.
Uh, review us on Techstrong tv. Thanks for listening, and we will see you next week. Amazon Internet from Space Palo Alto Networks buys protect AI and four out teams up with Nvidia for operational technology.
Cloud costs are higher than expected, but value to businesses, even higher chat bots, are they giving you good health advice? And Huawei, I've got AI chips to take on Nvidia and beat the US restrictions. While we're on ai, AI growth is driving cloud provider investment.
Join us on the tech field day rundown for all of the news that is hot this week. Welcome to the Tech Field Day rundown, where each time we meet, we run down the news of the week with variable degrees of snarkiness. I'm your host Alistair Cook, and joining me today is my guest co-host Chris Reman.
Chris, welcome to the show on National Tourism Day. Yeah, thanks, some glad to be here. So I'm touring the, uh, the, the news.
Excellent. Well, we must also acknowledge National Packaging Design Day and make sure we wrap this up with a beautiful bow, uh, and be very careful on National Barrier Awareness Day. Do not crash through the barriers and end up over the side of the bridge.
That does not end well. Jeff Bezos says there's plenty of room for winners in space to live at internet. The first 27 of Amazon's project, satellite satellites launched into low earth orbit to be joined by 1600 more in the next year.
The Star Link already taken this market, or is there still room for Cooper? Yeah, I think it's an interesting question and, and Jeff went on to say that, um, Amazon is more focused on unserved and underserved communities around the world. I I do note though, that it's not just a two horse race, right?
ViaSat and HughesNet are out there when the traditional, um, geo geospace tesat up in Canada has geo and middle Earth orbit satellites. Uh, one web is out there with 648 low earth, uh, orbit satellites. Um, they mostly partner with telcos though, so that's not, so not a service you can just buy at home, like you can with, uh, starlink.
And there's others too. Iridium is out there doing, um, narrow band, uh, LB band service for backup often to other satellite providers, which is super interesting. And then of course, yeah, there is starlink and it's, it looks like a tough row to hoe for Bezos.
And, and these guys, because, you know, 27 satellites is great. The total that they think they're gonna launch is over 3000. Um, and they think they're gonna get half of that up by mid 2026 with as many as five launches this year.
But starlink already has 8,000 plus, uh, low Earth Orbit satellites out there. They already have 5 million users, and they got that through 250 launches. Uh, and of course, they have an advantage in the launching space because, uh, launch delays, um, can cause big problems as they already have for, for Amazon service.
Uh, so it'll be really interesting to, to see how this plays out. I I do think that there's, you know, not a, a, you know, winner takes all in the satellite, uh, communication space, but I also think that there's a big headstart for starlink. Palo Alto Networks announced that the RSA conference that they have acquired AI Intelligence startup protect AI reports in April, suggested the price would be around $700 million.
Although Palo Alto isn't disclosing the terms, it seems security is increasingly being handed over to AI products and the announcements were thick and fast at RSA. Is this AI washing or does AI make a difference in the arms race between attackers and defender? I think AI is going to be a, a really important part of building a defense strategy for fast changing environments.
We know that attackers are using AI tools to actually, uh, generate new types of attacks, and clearly defenders need to be moving as fast as they can. The fun part here is that protect AI is not really about putting AI into a, a solution into a security solution, so much as protecting the AI itself. Uh, we had discussions, uh, the week before last at AI Infrastructure Field Day around the safety and security of AI infrastructure and AI applications.
And this is the, the safety part, sorry, the security part, not the safety part. The security part is where protect AI plays. It's around scanning the models to make sure that there are no vulnerabilities in the models that are being deployed out, uh, identifying where there are vulnerabilities and reporting those back for correction.
So, uh, the Protect AI is expanding the coverage that Palo Alto Networks has for protecting your applications to specifically protecting the AI and the generative AI components of your application. So I think this is very much an awareness that generative AI applications are another attack vector that can be used against you. And we've seen through things like prompt, uh, poisoning of models and prompt engineering and prompt escape that there are definitely some challenges with AI applications and with securing those applications.
It's definitely a specialist skill that needs to be built into core mainstream security products. We don't really want to have this collection of point solutions for just the, the developing security issues in ai. We do want to see this comprehensive view of security across our organization so we can have a consistent security stance on the entire organization.
So I think we'll continue to see this. We have already seen some acquisitions of niche AI startups by larger organizations to build out that portfolio approach to securing and operating AI infrastructure. While we're on announcements from the RSA conference, ForeScout Technologies announced an integration to NVIDIA's Bluefield dpu, formerly known as smartnick.
The ForeScout on-premises sensor runs directly on the Bluefield DPU to offload things like deep packet inspection or anything else that requires a lot of compute work. Uh, offloading those from the CPU, the announcement particularly highlights operational technology and and IOT use cases. Is there more pro, uh, proliferation of hardware offload at the edge, Chris?
Yeah, I think so. I, I remember when the DPU first got announced by Nvidia, uh, at, at that, at the tech field day, at least at the first time I saw it. And there was a lot of conversation around what are the use cases here, right?
I mean, it looks neat. It's whizzbang, this is really cool. We've had smart nicks before.
What, what's new here? It turns out there has been a lot, but, you know, one of the questions was in a data center environment, you know, can't you just throw more compute at it? Why not just rack another server or put an appliance in there?
You're not saving a ton by just moving stuff to the NIC because you are adding cost, you're adding, you know, uh, power, uh, things like that. And so in that context, yes, I mean, the edge makes a lot of sense and especially where IT and OT are converging, right? Which is where this is focused at on that critical infrastructure where you've got operational technology, um, and it's a place that ForeScout plays really, really well.
And a place where minimizing the footprint of whatever you're putting out there makes a ton of sense, right? You don't have infinite rack space, you don't have infinite power. You can't just load appliances up when you're out on a factory floor or wherever else.
These things may be happening in a plant, uh, water treatment facility, whatever it might be, right? Uh, and so ForeScout taking that leadership in it, I ot, IIO, ot, IOMT, uh, ot, kinda all, all of the, uh, the, the edge applications where you're dealing with a lot of data and in different, um, protocols, right? So being able to do deep packet inspection of industrial network protocols is something that they specialize in.
And I note that that's been shown and recognized, uh, giga Ohm's most recent operational technology security report listed ForeScout as a leader and a fast mover in the platform play quadrant. You know, seeing that this is a comprehensive play there, and I think combining that with the DPU at the edge makes a ton of sense for critical infrastructure. All of that said, you know, kind of going back to what I said earlier, you know, this isn't the only place that DPU are gaining traction.
There's a ton of tools and frameworks out there. Um, the partner list is a laundry list of kind of all the other players in, uh, networking and storage and security. Uh, and to some of our earlier points, AI applications are becoming a big place where this offloading makes a ton of sense.
So, so yes, the edge is hot for, uh, um, this offload, but I think there's lots of other places where it plays as well. Speaking of other places, uh, spending more money than you expect, yet still feeling like you are saving money, seems odd. Yet that is what a survey of public cloud providers revealed.
The CIOs surveyed reported spending an average of 30% more than they expected, and more than half would still get approval for more increases. Clearly, these organizations are seeing value from their public cloud spend, should they be looking for better financial governance of their cloud costs. I think the survey was really interesting because they surveyed 3000, uh, CIOs at enterprise organizations.
So not small organizations. They, they're larger organizations, and they found that overwhelmingly these customers were spending more than they expected on cloud. Now, that doesn't really come as a surprise to anybody who's been around for a while.
The bit that was surprising was that they still felt they were getting more value than they were actually spending on, they're getting bitty better value for their money in the cloud. And that, again, four out of five were, were going to be able to get an increase in spend through their governance, within their organization fairly easily, provided they could show that it was gonna continue to deliver more value. There were a few, about 30% who was saying that those increases were dependent on market conditions, which we know are a little uncertain at the moment and hopefully will resolve out.
But I think this highlights something that we've seen is that there's a, a maturity coming through in the way organizations are using public cloud, and that the financial operations ops movement is hitting public cloud. And what we're seeing here is the link to spending more money might deliver more value in our organization, but we need to know where to spend that money. The idea of finops is to be able to do that identification.
If we spend money here, we're gonna get more revenue there. If we spend excess money in another place, we're not gonna get more revenue, so why are we spending more money there? This mature approach to the cloud, the public cloud is a really good tool set.
Uh, you only have to pay for what you use, but you pay for everything you use. So managing that, so we spend the amount of money we need to, to get maximum value rather than just trying to spend as little as possible. I think this maturity and understanding that there is huge business value to be received from using public cloud technologies for the sorts of use cases where it has beneficial.
And then rolling back, we've definitely seen some rolling back from everything should be in the cloud to, we use the cloud as one of the tools that we have in our, our, uh, in our workshop and other tools like on-premises, environments, software as a service and co-located, uh, data centers are all tools we might choose to use. Um, definitely speaks to maturity that these are being made. These decisions are being made on a value to business basis.
Healthcare advice from humans is expensive, and waiting lists for specialists are only getting longer. AI chatbots on the other hand, are widely available and faster response. So naturally we ask chatbots like CHI Chat, GPT for health advice, an Oxford led led study that showed that people aren't necessarily getting good outcomes from consulting AI experts.
Have we confused the certainty of an AI chat bot for the education of a healthcare professional? I think the answer there is yes and no, right? I did see another survey that said about one in six American adults are already using chatbots for health advice at least monthly.
And when you combine that with the results of this, uh, study from Oxford, it's perhaps a little concerning, right? So the survey, uh, talked to, they had 1300 people involved in the uk and they had them use chat, GPT GPT-4 O, uh, as well as coheres command, R plus and Meta's LAMA three. Uh, what they found was that the folks who were using the LLMs that were, that were using these chat, uh, these AI chatbots were actually less likely to identify a relevant health condition, and they were more likely to underestimate the severity of the conditions that they did identify.
Um, so that's really bad that that doesn't sound great at all for the chatbots. Now, um, a a commenter from the survey did say that the participants often omitted key details when querying the chatbots, uh, or they received answers that were difficult to interpret. And so some of this isn't the M'S fault, it's the user's fault, which we can all understand.
That doesn't change the outcome though, that you're misidentifying or not identifying health issues. And then, um, fi, you know, ranking them as lower, uh, problematic than they, than they would be. So, you know, these standard, um, chatbots like chat GBT have even been recommended by the American Medical Association not to use them.
Um, now all of that said, though, I think there is a difference here between, you know, throwing the baby out with the bath water and, and maybe not relying on a open model or, or, you know, accessible consumer model to do all the specialized things. There is work underway by Apple and Microsoft to build, um, specifically trained models and applications for healthcare analysis and, and, and things like that. And I don't know that those are necessarily going to be inherently bad or wrong, uh, in that they're trained on more specific data, right?
Because remember all the models that we mentioned that are being used in this survey were trained on internet data. And so it's a little bit of the garbage in, garbage out problem that I think we all need to be aware of, that not everything on the internet is reliable, and therefore, um, even a perfect LLM using that data can't ever be completely reliable. So, um, yeah, be careful when you're using it yourself at home right now, but, uh, I think there's gonna be advance advancements in this space that we all should pay attention to In other, in other AI news, the rundown has covered some ways that the US government is trying to limit China's access to high-end AI hardware.
Now, Huawei is close to shipping their own AI chip, the Ascend 9 0 1 D, which is being produced by the Chinese state owned SMIC foundry. Uh, Huawei expects the 9 1 0 D to be more advanced than NVIDIA's H 100. Although the earlier nine 10 C failed to live up to the hype, China may well end up self-sufficient for AI processors making the US restrictions irrelevant.
Will we see Huawei AI chips coming to the us though? I think this is, um, got a couple of interesting dimensions to it. So one of the things is that whenever you restrict somebody's access to, to something they want, well, they'll find ways around those restrictions, whether it's the, uh, as we've seen some of the, the smuggling of AI chips to places that are restricted, uh, but also domestically produced.
So the US policies are about the US being, uh, self-sufficient. Well, this is clearly China making moves to be self-sufficient as well. And Huawei has seen this opportunity, they've seen it for a while, since of course the, the nine 10 C chip was released a little while ago.
It was supposed to be close to the performance of the H 100, and now this nine 10 D is due sometime this month. And whilst it's hard to see Huawei rapidly overtaking Nvidia, you can imagine that there's a second mover advantage here that Huawei is in a position to develop more rapidly from a standing start than maybe, uh, Nvidia did 20 years ago. But Nvidia has an awful lot of expertise and an awful lot of money coming in to fund more development.
And so it'll be hard work for, uh, Huawei to catch up and to exceed what's being delivered by, uh, Nvidia. So seeing the Huawei chips coming into the us, possibly not other parts of the world quite possibly. See, again, if there's, uh, restrictions on export or tariffs on export of chips, uh, we may see some desire to second source, but I think it is gonna be a long time.
Uh, it's gonna be a while before the Huawei chips actually are competitive with the newest Nvidia chips. On the other hand, China can't get the newest of Nvidia chips, so you only have to be faster than the ones that, that are accessible in China. Uh, Huawei will probably find a large market domestically in China, and it is a huge market, uh, whether it comes overseas.
Well, Huawei doesn't necessarily need to send all of their technology overseas with a huge domestic market, but I think we will see in particularly developing economies, uh, cost effective, uh, solutions coming out of China, being shipped into developing country countries, including potentially these Huawei processes. It's now time for a closer look, and we can take a closer look now at how the demand for AI services is driving more growth in public cloud platform. Amazon, Microsoft and Google have all continued massive investment in public cloud platforms to keep up with the generative AI demand.
Andy Jassi highlighted triple digit growth in AI revenues, and Microsoft has committed to 40% more capacity in Europe alone. Google is investing $17 billion in cloud infrastructure. Is this still the beginning of the AI cloud build out, or are we in the middle?
This is a really interesting question. I think we're still towards the beginning, and I think it's gonna bleed beyond just the big cloud providers. I think this may be an opportunity for upstart folks that are focused on AI to maybe, you know, I don't know if they're actually gonna get, you know, to compete with these, uh, really, really big companies, but maybe get snapped up by them, right?
Uh, I do think it's interesting if you dig into the numbers that Google seems to be the ones spending the most, and that would make sense, right? I think that their cloud position is probably third in rank behind those other two as far as the percentage of the market they're picking up. But o you know, over the course of the year, they're talking about increasing CapEx by 40%.
Uh, so they spent a little over $50 billion last year. 3 billion for the quarter. Um, so they're gonna outspend their revenue this year.
Um, it seems like they think there's some runway here. There's definitely some catching up that Google's trying to do to the other big guys, but, uh, but like I said, my interest is in these other folks that are coming in AI specific, uh, that might be able to give the bigger guys a run for their money. What do you think else there?
Well, I think it was interesting that at AI infrastructure field day a week before last, one of the presenters was a company called Caruso, and they build AI data centers where there is disposable or excess power. And so they're building these data centers where the power cost is low, and therefore the calling cost is low. And this addresses one of the, the issues that I see in these massive buildouts, that there's an environmental risk here for building these massive data centers on more power required more, uh, essentially more concentration of power means more, more heating of the, the country or the, the planet.
Uh, I like this movement of these, uh, uh, clouds towards where there's waste energy or low environmental impact energy and the, uh, sustainability focus for some. So definitely I, I like this smaller clouds, what's sometimes referred to as neo clouds, new clouds being built for specific purposes, and AI is one of those purposes. But we do definitely see huge growth and innovation going on in the main cloud providers because the public cloud is a good place to experiment with these massive workloads that you may only need for a transitory period of time.
Building out an infrastructure to fine tune a massive, uh, large language model on premises is very expensive. And if you only need it for maybe two weeks every three months, then that's not a very good use of your money. This is why we're seeing a lot of cloud experimentation and cloud development happening in public cloud.
We may see a movement back to on-premises, uh, for the inference stage where you're actually using the AI to build, so to deliver some business value inside your application at inference stage is more often closely coupled where your data lies, whether it's on-premises or, uh, sitting out in the public cloud. But yeah, continuing growth in investment in public cloud infrastructure. And, uh, we saw quite a lot of the innovation from Google and their, their build out and uh, uh, their, their desire to own even more of the space of AI where AI infrastructure failed as well.
Uh, I think we still are in the middle. I hope we're in in the middle if we're just at the very beginning. The AI build out and the cloud is gonna be huge and, uh, all consuming.
So hopefully we're in the middle of it as we're looking to the rest of the month. Well, today, in fact, is the first day of Mobility Field Day. Uh, you can find Tom Hollingsworth our partner on this here, rundown, uh, we'll be hosting Mobility Field Day right now.
Tom, I hope you're having a great time with, uh, the huge number of companies and delegates that you have for Mobility Field Day next week, Tom gets to take a bit of a rest as the tech field experience at Qlik Connect rolls in and Steven will be hosting a different group of delegates at Click Connect. But after another week off at the end of the month, security Field Day rolls in and Tom will be back on deck again. He will be leading the charge for Security Field Day, and again, uh, some great presentations from maybe even some of the companies we've covered in this rundown.
Uh, following that, I will be back in Silicon Valley for Cloud Field Day at the start of June. So thank you for watching this episode of The Tech Field Day Rundown. Catch a new episode every Wednesday as a YouTube video or in your favorite podcast application.
The rundown is streamed on Techstrong TV as well. You can watch us over on Techstrong and FU Group program. We'll be back next week Wednesday to talk all of so from myself and the team at Tech.
Thanks for joining us and have a great.