Techstrong TV – March 12, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, have I got an AI agent for you? You're watching Textron Gang. Hey everyone.
Happy Wednesday. Welcome to Techron Gang, man. If you've got an AI agent, I got someone who wants to buy it.
What a time to be in the AI agent broker business. Um, a lot going on around that. Of course, a lot going on in the world in general.
Our stock market is in correction territory, uh, a lot of uncertainty and feared and loathing, uh, and a lot more than that. But we've gonna bring it to you all here, our Techron gang. Let me introduce you to our gang for this fine Wednesday he is out at sea where he's, he's a laptop short, but still able to join us through some premier hacking.
He's our security expert. Chris Blast. Hey, Chris, how are you man?
I am good. Good to be here with you, Alan, and everybody else. I am in, uh, near Summerland key today.
So we can look that up on your Google Maps and follow, follow the bouncing ball. Where is Chris moving from Summerland key to West Texas, a newly hot data center territory as, as evidence on yesterday's gang show. She's our, uh, managing editor, Amanda Ani.
Hey, Amanda, how are you? Hello. Good.
Happy to be here. As always. Good to see you sharp too.
Not fuzzy at all. Looking very sharp. Amanda, uh, moving up from Texas.
We'll head over to Colorado where we're not sure he could see himself, but he could see us. He is a DevOps expert, pretty renowned analyst, and just all around Greek guy from down under living in Colorado, expat in Colorado. Andy Mann.
Hey, Andy. How are you Alan? I am doing fabulously well, Mike, good to see you again.
Good to see you. And then, uh, last but certainly not least, the dean in Harrison, our chief content officer, Mike Ard. Good to Mike.
No, no call for the year. I don't mean cold. I mean Derrick, Jerry Cole, I'm aware.
Tommy John, and I think we have to pay him and then he becomes a free agent. So it's insult injury, right? Um, no, I think we have one more year after that, but I read that the Yankees have a tremendous insurance policy on him.
And this, you know, not that we care about the Steinbrenner's wallet, but Yes. Well, I Think I'm going to go in the AI agent insurance business. That sounds like a great idea.
Yeah, I just wish I had some more AI agents to sell. Which leads us kinda to our first, uh, story. Mike, why don't you take it away?
All right. Well, AI agents continue to be all the rage. 85 billion, which sounds like a lot of money, but I think that's chump change in the AI era.
But this company move works, helps you orchestrate your agents. So you ain't gonna, ServiceNow is maintaining its classic position here where it's helping orchestrate workflows. And now we'll extend that to AI agents.
Meanwhile, though, the Chinese are out there saying that they've created an AI agent that is, uh, much less expensive, perhaps not as smart as some of the AI agents that are out there, but certainly not as costly to implement. And then there's a report from SnapLogic talking about how large enterprises are all in on AI agents, and they're gonna invest about a million dollars on average over the next 12 months to build these things out. And it seems like there's a bit of a frenzy going on here, Andy, so what's your take on all this?
Well, I'm, I'm loving this for these businesses, by the way. Um, yeah, the, the move work was really move works. You gotta watch out, which, uh, you are on, you Google there.
Uh, you might end up in workforce automation. It's not that one. It is agentic AI for CRN, this makes a whole lot of sense.
For 20 or 30 years we've been trying to automate some of the simplest stuff within the customer service C-R-M-I-T-S-N kind of space, right? Things like password resets or provisioning or anything like that. And automation is good, but intelligent automation's gonna be even better.
And so for ServiceNow, I certainly see this as a really positive opportunity to drive that level of automation further. They've got a lot of orchestration already built in. This is gonna work out really well, I suspect.
Look, it's gonna cause a little bit of concern, I suspect for some of it's, uh, prior customers who it may now compete with. Let's see what happens to, you know, for example, a a Microsoft, for example, using that software. Um, the valuation's pretty crazy, but I think you are right, Mike.
It is. It's just this is, it used to be a billion dollars was the entry fee to cloud. I think 2 billion might be the entry fee to, to ai.
Their last valuation was about 2 billion LA in June. I think 21 was their last funding round. Um, so that's a big number.
So we'll see whether there's actual ROI, but I love this because it's a good use case that's aligned to what they're already doing that gets them into a market they desperately need to start dominating. I'm, I'm excited to see how this all plays out. Go ahead.
I would say their, their valuation in 2021 had nothing to do with ai, nut, nut, sand lake. I was on the streets in New York. Again, nothing to do with, uh, AI agents.
Right? Yeah. 85 billion, is that the value of the agent over and above that 2 billion mark that they got in 2021?
I don't know, but it is a big fat number and I, I, I suspect it's not all based upon ag agentic ai. Amanda, I'd love to get your opinion on this. 'cause buried in that SnapLogic report that I mentioned was a, a question about whether or not the senior IT folks who were surveyed trusted AI agents as much or more than people.
And when you added it all up, about 40% or so said they as much and 44% more said more. They don't trust the people execute these things. Um, you know, what's your emotionally, intellectually, how does that kind of grab you?
Yeah. So this remains an issue. Um, yeah, we're seeing more and more, uh, trust in AI and AI adoption.
Um, so I think the goal, and I, I've had conversations with people, like right now we're talking about, oh, AI agents, like it's a thing. But I think the goal is in the future, that's just gonna be something that's integrated across everything. It's just gonna be expected.
It's just gonna be there being used by everyone, just, um, like other technology in the past. Mm-hmm. I feel though, Chris, I don't know your thoughts here, but I feel like we still have to supervise these things and there's gonna be a tendency to maybe trust them too much.
And we are gonna have to supervise these AI agents much like any other employee, as far as I can tell, Right? Yeah. The, the risk as always in outsourcing any security function is that you're not doing it right.
So yeah, pondering that, uh, that, that, uh, trusting more or as much, and I think it's probably justifiable, right? Because we know how humans are, and this is a machine, you know, if it's wrong, it is probably predictably wrong. But, you know, we, we have to have the human in the, in the process.
Otherwise, you know, the, the, the agents don't know what to do. I mean, the, the risk of corruption, uh, of corrupted use needs to be on all our minds. Um, because the, the benefits are, again, just so large from a security perspective, having, and I like that we're actually talking AI agencies, not Skynet.
This is not the AI out there. We're all using this technology embedding in things. What does that mean?
Right? A lot of good, uh, work we can do with security, but to your point, if we just start trusting and walking away, that's, that can't work out well. All right.
So, so Andy, let me walk you through this concept a little bit here. So we have all these AI agents, they clearly need to be observed. They need to be tested, they need to be governed, you know, are, are we essentially about to create agent AI ops here?
Ha Oh, you, you from your word mouth to God's lips, I reckon, uh, God's ear, isn't it, Mike? Uh, well probably 'cause the next step is obviously we need AI managers to supervise the AI agents. Um, look, I actually think that over time this gets a lot easier.
We've seen this before with automation, virtualization, and cloud, right? We've seen it with DevOps and straight through process. We've seen it with things like RP Yeah, trust, but verify, right?
And absolutely, Chris, we've gotta have governance, compliance, risk management. Um, these things can go haywire and cause immense expense and trauma, um, in, in very short amount of time. But this was always true of automation and orchestration as well.
And so I just think we get to the point where we have to click that button that says, don't ask me anymore. Um, and that's the point where we're going to get to, and that's when the ag agentic AI ops manager will take over. I think you're absolutely right, Mike, ag agentic, AI ops, it's an extension of where we've been with AI and ml and advanced analytics and automation and orchestration.
This all comes together and makes a lot of sense to me. Mm-hmm. Do we think, though, do we think though, eventually it is gonna be so ingrained that it's gonna just be, become more of a, a, a standard cybersecurity roll in issue?
And maybe to Mike's point, we'll just have insurance covering any issues, anything that goes wrong, we'll have, uh, a whole insurance industry for it. I, in, in short, yes. Right?
You, you know, this, this, You know, as you, you know, go back to that trust thing. We know right now, uh, uh, I, if you really wanna get into cybersecurity, you can get red teams and blue teams and green teams. You can do a lot of work and you learn a lot of things you can advance a lot, right?
But we always know, you know, there could be missing things, right? You get a vulnerability, uh, uh, a test, you'll find a certain amount in some left. So just the sheer power of building this in, and to your point, insurance, yes.
When insurance can get predictable, the insurance market has to, you know, has for centuries and will continue to exist. Cyber risk remains, you know, a difficult to quantify risk. This may, through sheer empirical power provide some of the basis for predictable insurance risk for the remainders.
We've talked about this in the past, but I still don't understand how I'm gonna manage all these agents. And if every app has an agent and I've seen some agents out or apps out there that have six or seven agents that they're popping up in my screen. And so do I need like a super agent at some point to reign in all these different agents?
Is that how that's gonna play out? Alan, you have any thoughts? Yeah, no, it sounds like a job for Kubernetes.
You know, the ultimate orchestrator. I mean, I do think you will need a management tool, though. A system, though.
This is true. You know, we started with automation. We started with scripting, right?
So we had a library of scripts, then we had script managers, then we had a library, virtual code managers, right? Then we put it together and we started to do orchestration. Um, then we started to do virgin control on our orchestration routines.
This is where we're going. It makes sense. It's not gonna happen straight away because we're in the middle of the revolution.
We're excited. Everything is just a $2 billion entry fee. We're gonna get there.
But we absolutely gonna need some kind of orchestration manager, automation manager, AI manager, agentic manager. We absolutely will. And I would just point out that in terms of the risk, this is like another employee.
Now, this is not just a tool. This is doing work. And if our biggest risk is insider threat, which I believe it continues to be, why wouldn't agents be that risk?
They're going to definitely need automated management. So I I have a theory, I'm sorry, gag Chris. I was just gonna say, you know, Mike, you know, the short answer is yes.
And it's, when you say, I, I mean you, Mike, you know, I think, you know, the risk to you is not the same as risk to you performing your job. The risk to you is you performing your job wrong and you don't have a job, right? So I think we all end up with that personal manager, you know, Arthur c Clark's last book there, you know, the, the, you know, the main character has a AI manager, right?
And I think we get that. That reminds us, me, Chris, the person to, when I go to work, make sure I have, you know, to Andy, to your point, that governance layer to do my job so that my real manager, my real ai, my personal ai, you know, keeps getting its monthly subscription paid. And I, and I live indoors.
So I, I have a theory on this. We're really early in this AI agent and everybody's rushing to market. 'cause they wanna have their own AI agent.
Every app has to have their own AI agent. Everybody wants to have an agent. And we all know that that is not practical.
I think where we're going to, and, and most of these agents, by the way, are relatively one trick ponies. They do one thing, right? They do one thing.
They, they, they schedule this, they find that they, you know, they check a box. Those agents are going become ephemeral, right? 'cause they don't need to be running necessarily all the time.
It's just when you're going to do something, I think where we're, where we're going to go to is we are gonna have, Chris, you want to use the Arthur Clark, or not Arthur Clark analogy. A an AI agent manager, an AI that manages our agents. And that manager spins up ephemeral instances of different, let's call them sub-agents, that do a particular job and then dissolve back into the woodwork, right?
And that master agent, if you will, is smart enough to know when to spin up these alter egos that do it a particular thing. So that we don't need to have two dozen different agents. Someone like, and, and all of us are power users on computers.
We work in tech, right? We don't need two different, two dozen different agents for the, the, I mean, how many apps do you have on your phone? If you're like me, you have probably a hundred apps on your phone.
So you need a hundred agents on your phone. No. How often do you use those apps?
So we're gonna have a master agent that spins up, ephemeral, subagents, disposable agents, one time use agents, Harry Shavers, whatever you want to call 'em. And they do, they do the job and they go back and they go away. And the next time you need it, it spins it up again.
That's probably a gen two or gen three thing right now where in the, I can't get enough agents mode, but that's gonna quickly pass too, right? As we're overwhelmed with too many agents, All the marketing people are gonna object to the word master. But I get your point.
One's gonna be kind of the senior head butler maybe, and the other one's are all kinda working. Well, it's one agent to rule them off. But, but you won't have all of these agents, because I'm sorry, I'm begging a lot of noise.
You, you won't have all of these agents because not all the tasks that these agents are doing are worthy of a standalone agent. We let, let's call, I don't know if you want to call 'em sub-agents, ephemeral agents, disposable agents. I, I don't care.
But you, you're not going to need an a, an a, a, a permanent agent for most of the things that the agents are doing. You, you spin 'em up and down. I, I wanna be clear about like, responsibility here.
So if the company gives me an agent to perform a task and the agent screws it up, is it my fault or is it the company's fault? It's still your fault. Never the company's fault.
It's always your fault, Mike. You've been here at text for how long? It's always your fault.
No, seriously. Uh, it, it's the same thing at the cloud. The cloud gives you an instance that you spun up, but when, when your data gets breached, it's your problem, right?
And, and, you know, then, so falling back on my, my legal background, an agent is an agent, hence the word agent creating agency. And when, when you in indu employ an agent, whether it be a digital agent or a people agent, you bear liability for that agent's actions. So yes, it's your fault.
So do we think we're gonna see more to that point? Do we think we're gonna see more upper level leaders getting insurance on themselves in the job? Like that's gonna be something they ask for.
If they take a CEO position of some big tech company, or they're using a lot of ai, they're gonna ask for insurance for themselves. Well, so like boards of directors and officers always already have e and o insurance for the most part, right? Errors and omissions.
Um, and that's pretty standard. I, I don't know if we'll extend EO to include, um, um, agent or agentic malfeasance or what have you, but, um, or negligence. But I mean, you know, why not?
So it might be an easier conversation though, because when something does go wrong and it's actually Andy's fault, I won't say it's Andy's fault. I'll say Andy's agent screwed up and therefore, you know, it's, it's, it's less tense conversation, right? Yeah.
It's it's gonna have to happen though, isn't it? I mean, the responsibility for automation has always been with the automator. Um, and you're absolutely right, Alan.
You talk about cloud, we think of cloud as someone else's computers, but ultimately you are always responsible for your own actions in the cloud or on premises. And we've seen this before as well. Clouds providers go down and your general consumer is not angry at Amazon or Azure.
They're angry at you for not providing the service you said you would. So look, it doesn't really matter where the agent lives or the responsibility. We are gonna have to be responsible for our actions.
'cause we're gonna be responsible to our customers who will blame us anyway. So sure, take it on the chin, get ready, get insurance, maybe up your insurance. I know when we went to cloud, a lot of people did up that EO insurance.
A because of the extended risk, we're gonna face more extended risk with ai. Why wouldn't you up your insurance on that if you can? Uh, it's 'cause we're gonna find breaches.
We're gonna find insiders, agentic, breaches. This is just the start of all sorts of stuff, Alan. Not just the management, but also the penetration vectors.
I'm sorry, I can no longer provide you with insurance 'cause you're too much of a risk. So we're just pulling it, you know, Again, Mike, I I just gotta say Alan, with your ephemeral agents as me thinking. And I think we probably need to start thinking about agents as a service, which on the one hand, you know, maybe an actual thing.
On the other hand, it's an acronym that, uh, once you pronounce it will be fun. Yes. Well, well, I I don't think we're going to go with that particular acronym, Chris, something tells me.
But, um, we'll, we'll, we'll see where we go from there. Anyway, hey, we've spent 20 minutes on this one. We gotta jump to our next block.
Let's take a quick break here. Our Techron gang, we'll come back with more Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're moving on to talk about what's going on with Apple, which has, uh, indefinitely delayed.
Its, uh, upgrades for Siri and everybody's kind of scratching their head what that means. 'cause maybe Gen AI and Siri are incompatible, who knows? But Amanda, what's your take on what's going on here?
Yeah, it seems, we we're hearing about them a lot lately. They seem to be struggling with their AI offerings in general, kind of the last to come in with their AI offerings in the first place. So I wonder what is their approach?
Uh, why is it so different? Uh, I know it's gonna require more power. According to the article, what they're trying to do with their AI is gonna require more power.
That's part of this struggle. Um, but either way, they seem to have been struggling to compete in the AI offerings in general. And I wonder if we're gonna see this in phone adoption with their, their new phone if people are gonna be switching to another phone that already has all the cool AI features.
Mm-hmm. I wonder if this will also be an issue for other people like Samsung, because maybe to your point, there isn't enough horsepower on the phones to run this stuff locally, so it doesn't work as well as it should and can't make everything a call the cloud. So have we reached some sort of, uh, technical impasse here that just needs another generation of processors?
Andy, your guess is as good as mine? Yeah, look, I think, I'm not a consumerist, I'm obviously an enterprise person, but from my perspective, what I see is, uh, they don't wanna repeat the Apple Maps fiasco, right? Um, they want to get it right.
If you remember when they brought out Apple Maps to compete with Google Maps, all of a sudden people were driving off freeways into driving off overpasses and into canals and so forth, right? Uh, apple can't afford to do that. Now.
They've gotta have trust. And you know, Amanda spoke about this earlier on today. You know, your trust in AI is super important.
And so for, at the consumer level, especially, you know, at the enterprise level, we can try things out and iterate and so forth and so on. At consumer level, we don't have AB testing. We buy devices and use them.
If they're no good, we throw 'em away and get something else. So I think they've gotta get it right. And I think there's a lot of challenges.
I think you're really spot on when you talk about the processing power on system. You know, I'm working right now on some things around voice control with local response using an LLM, and it requires pretty significant processing for some very basic command structures. If you wanna get real ai, gen, ai, gen ai, whatever it is into a phone, yeah, you're gonna have to do some pretty interesting stuff.
So maybe as they continue to develop their chip set, by the way, the M1, M two, that these are amazingly fast and powerful chip sets doing some of that work on the phone, maybe that's what we're looking for in the next jam. So look, I'll, I'll remind you all that. Siri doesn't just work on iPhone.
Siri works on Macintosh, on your MacBook Pros on your Mac studios and, and there's plenty of horsepower on those machines. So I, I don't know if it's a horsepower issue. I think the bigger issue, and I'll, I'm going to call the elephant in the room out, you know, the knock on Apple is, since Tim Cook came in, they, they, they're not innovating.
And quite frankly, they've been late to the AI game. Quite frankly. They have been other people's ai, right?
They deal with open ai 'cause they were using the open AI stuff. They've been, they out of the, you know, you look at the Mag seven and, and you know, in my mind the big four of that Apple competes with its Apple meta Google, Microsoft or Big Five Amazon. I think Apple, apple has trailed the, their competitors there in a, uh, in native AI adoption.
And now they're trying to build it into Siri because look, Siri should have been in AI to begin with. We thought it was, I guess at the time. And, and they're stumbling with it.
They, they were late to market. They were late to do it, and they continued to have trouble. Let's not, I don't blame this on horsepower.
I I don't, this is gonna take some innovation and some new new ways of looking at things for Apple, doing different things, maybe outta their box and they're not doing it well. Plain and simple. And I think it's a pretty interesting point, Alan.
Um, you know, the, the, the idea that Apple is an innovator has always been, I'm gonna get in trouble in a moment now. Uh, 'cause I don't think they've been an innovator since, was really, I mean, the iPhone was late to the market. Siri was late to the market.
Um, they were already late to market with ai Maps was late to the market. Um, they spent a lot of money trying to do, drive self driving cars, and then sold that unit off. Um, I would posit that Apple is not designed as an innovator.
Apple is designed as a fast follower and has been super successful in that mode. So that's actually a really interesting idea, Al and maybe not a bad thing for them. Yeah, you know, I've, I've been, you know, we've been in an Alexa household rather than a Siri household, you know, in, in this generation.
And as you know, I mean, I, I run, I control lights and pumps and water cannons on boats and so forth. And I think there's, I think you're probably, you know, what you're saying, all saying about, uh, apple is probably true enough. But Andy, what you're saying, you know, these devices, you know what we talk about as AI these days, you know, the last segment we're talking about agents, you know, what does it actually take?
And whatever the answer is, I think, you know, our experience, and I know my experience with these devices over these last, what it five, seven years, what, what not, and our expectations now are that it acts like chat GPT, and it does not. It's dumb as a stump. And if Google and Apple with all their resources can't make these devices, those of us who embedded smart, there's a reason.
And then, you know, maybe it's incompetence at some level, but I think we we're going to have expected more out of our little local devices, um, than we do, than we have. I think we're starting to expect that now, right? We're suddenly in the six 40 K world, it's like, you remember when we just had the six 40 k and we thought that was great?
Yeah, I think that's the Syrian, uh, Alexa sort of infrastructure we have right now. We're gonna look back as, as eight bit eighties, you know, stuff. Are you telling me that Apple intelligence is the latest oxymoron?
Is that where we're going with this? Big corporations and big governments and, you know, big organizations. I, I agree with Andy.
It's hard for them to innovate. You know, that's not really their job so much. Um, and they can screw up what remains their job.
And I think they, they all do that with alacrity as well, but I think this is a more fundamental sort of shift. Yeah. So Amazon is supposed to be rolling out a big Alexa upgrade.
Speaking of Alexa, that has a lot more ai. I think it'll be interesting to see if they fumble that one as well, or if that goes a little smoother here. And what's going on with Apple?
No, I I, here's what's gonna happen is that there'll be an dedicated Apple watch. It'll be a co-processor for the al workloads that will sit on your other rest, and you'll have to buy both of them And the chain between them as well. Or is that optional?
You know, And your master agent will control it all. Maybe we need a, you know, we'll call him Hobbes or something from, from the Arthur movie. Uh, anyway, all right, well, you know, I, I think the Apple AI conundrum though is bigger than Siri.
And it's funny, as I said this, looking over at my iPhone, I'm getting those pretty, uh, neon lights sliding up when Apple Intelligence kicks in. It hears me talking about it. It doesn't zap me with a laser or something.
But, um, the fact is, apple, apple has to show their chops in ai. If you believe AI is where we're all going. And, you know, that's the, the, the, the indi indispensable element.
It's more than AI in Siri. It's AI and Apple. Where is it in the os?
Where is it in their apps? Where is it in everything they're doing? And, you know, apple Intelligence may not be in oxymoron just yet, but I don't see any, you know, I, I've been running the betas since they came out with this Apple Intelligence, and I run it on my Mac, I run it on my phone, I run it on my iPads, I run it on my Apple TV and my watch, and I haven't seen a damn thing.
So I don't know. Well, I, I think, you know, ball's in their court. And I wonder, Alan, if we're running up against use cases and validation and product market fit for Apple as well, right?
They've been running these ads about Apple intelligence for the longest time. Is no one getting excited at the use cases they're showing? Are they trying to find product market fit?
You know, Google's running ads as well for, you know, set up my appointments for me with my friends that go to dinner. I, we know that doesn't work. So maybe we're looking for product market fear.
Well, but, But so that's not just an Apple issue though, right? That is. So what is the killer app for ai?
Right? Question. I, uh, if give me funding and I'll find out.
Uh, this is the sort of thing you, well, I Think right now you just gotta make an agent and you can get funding. But what is the killer app for ai? This is something I, you know, I I, I did a YouTube shirt on this about a month ago now, where Mark Cuban says that the world's first trillionaire, if, if you believe that the Saudi family is not already trillionaires and everything else, um, that the world's first trillionaire will not be Jeff Bezos or Elon or, or, or Zuckerberg.
But it'll be the, the person who makes the killer app for AI uses it in a way we, we haven't quite figured out yet. And they'll make a trillion dollars. 2 million views.
So people are definitely interested in that. I think they're more interested in billionaires. Anyway, hey, let's take a break here on Textron.
We're gonna come back and, uh, you know, how's your 401k doing? com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. Hey folks, we're back for Steve Locke and we're gonna talk now about, well, what's going on on Wall Street. And as anybody has seen this week, it's been a bit bumpy, shall we say, at least in the wrong direction for a lot of folks.
And who knows if it will recover or not. But, um, Alan, what's your take on what's going on here? 'cause it seems like outside of the fact that we had some, you know, sharp downturns this week, the whole trend has been in the wrong direction.
My game, I may never be able to retire at this rate. My 401k is becoming a 2 0 2. Uh, so it, it's, it's, it's kind scary.
But, but here's the thing, right? Market people tell you, you can't watch it day to day. You gotta look at trends you gotta look at, you know, and the traditional rule of thumb is if you have a fall of more than 10%, it's truly a correction.
If you have a fall of more than 20%, it's, it's, it's a downright crash. Well, you know, since our glorious leader came into power at the end of January, uh, we're in correction territory. And you know, this is from the guy who promised us that the eggs are gonna go down, your stocks are gonna go up, and everything else is gonna be willy-nilly and happy.
Happy. Mm-hmm. So, Andy, does this kind of cycle perpetuate itself a little bit?
Because, you know, what happens is companies pull in their horns, then they stop funding new projects, and then it all starts to cascade downwards. And, um, do we need to take a pause here at some point? Or how do we, you know, what's your sense of how this might all kind of maybe reverse itself?
Well, I hope it does reverse itself. 'cause I'm not about, you got my, my 401k is becoming a 4 0 4 K, right? It's just investment not found.
Uh, this is definitely gonna have to correct at some point, but look, I don't know that this is fundamental. It's certainly not within tech stocks. Yes, there is some fundamental pressure around, uh, there's been layoffs in order to retool for ai.
There's been, we've seen from so many of the, from the fangs we talked about earlier, uh, and many, many others, there's been a lot of retooling to gear up to free up the opex for AI investment. And that's not insignificant. We're literally seeing hundreds of thousands of tech workers in Silicon Valley and related industries out of, obviously New York, Chicago, Boston, et cetera, coming out in the streets.
And that's dropping spending power, it's dropping confidence. Um, and, you know, there's a lot of administrative action happening at federal level as well, obviously causing uncertainty. And, you know, you talk about, uh, administration leaders being comfortable with the word recession.
Uh, that's sort of a new attitude. So look, is it gonna correct? I it always does.
When will it correct is probably the big thing. And what will drive that correction? I don't think this is fundamental, certainly within tech, but there are some fundamentals that are not helping, uh, certainly in terms of employment and spending power of those tech workers.
Guys, this is not just tech. Let's be clear. This is not just tech.
This is the entire market. And, and here's the reason I, I've said this before I think on the show, but I'll say it again here. Do you know what the market hates the most uncertainty?
And do you know what the very definition of a Trump administration is? Chaos. Chaos is uncertainty.
And when you have uncertainty the market, it gets real skittish, real skittish. So it's not, yes, the, we, we get hurt in tech and, and look the magnificent seven, and, and the Nasdaq is such a big part of many of our portfolios for 401k and and so forth. But the fact of the matter is the entire market abhors uncertainty.
And you've got an administration that is the very definition of uncertainty, day to day, minute by minute, moment by moment. And if the market doesn't feel secure, it, this is the, this is what happens. And you know, hindsight is usually 2020, but unfortunately in this country, and during the last election cycle, people put on rose colored nostalgic glasses thinking about what the economy was under the first Trump presidency.
It sucked. It sucked. And then Covid really made it suck.
And we, we got outta there with net losses of jobs and everything else. And you could say what you want about Joe Biden and how old he was, but he, he did what he could to restore it. And it was handed over in a solid inflation back down to 2% joblessness down low, even the deficits, they were trying to do some things with, let's, let's, let's rip off the rose colored glasses and call it what it was.
This man's a menace, this administration's a menace. And let's, well, and this is what the market is reacting to, and it's a worldwide market. It's not just the us.
Well, and let, let me, you know, think through some fundamentals of that. 'cause you, you, you're, you're exactly right, Alan, you know, the, yeah. Markets are, as we know, they're emotional.
Like how comfortable do I feel? But there are reasons for that, right? And just, uh, I just wrote a piece this, uh, this morning about the, uh, some changes in ISACs, the information sharing analysis centers, and since the nineties have been public private centers to share threat intelligence and protect, you know, uh, uh, the nation in various ways.
But in many ways it's by lowering the cost, you know, because, you know, the, in, in this case, the multi-state isac, which was con congressionally funded, um, has had his funding pulled. And that most ISACs are the private sector. So, you know, you have members who are, you know, for-profit companies, they pay some dues.
You fund the whole thing. The multi-state isac, uh, was unique, you know, you know, past tense now was unique because it had the, you know, state, local, tribal, you know, if you, the mayor of some small town, you know, you can belong to this. And you can find out that there's, for example, you know, active cyber threats that are attacking, you know, infrastructure that you have so you can plan in advance and save time, money, yeah, you has be more secure, but also, you know, reduce your, your odds of needing the insurance and the recovery.
And if you are, you know, your traffic lights suddenly start working. You had somewhere to go to say, Hey, you know, is that a thing? And find out, yes, it is a thing, here's what you do.
So again, save time and money in getting your traffic lights working again after being hacked. So we have this combination of uncertainty, as you say, was a characteristic of the current administration and actual losses, you know, actual costs introduced into the systems that that cost, that take money away from other activity. Hmm.
You know, what needs to be called out to though is all these folks who are announcing layoffs and then attributing it to ai. There's just no way that the AI has that advanced that yet to really justify that level of layoff. So what you're really saying is, yeah, AI has probably had a, some impact here and there, but we really just screwed up and we're hiding it behind ai.
So let's just call it as it is. I will say though, I just wanna point out that, as Andy mentioned it, the market always corrects itself, and eventually we always see an upward line over a period of time. So now I'm not a professional, you know, financial advisor, but I'm saying, bye bye buy at a low rate.
Well, that, you know, that there's a theory of you buy on the dips and you buy low and you dollar cost average your stuff. Here's the problem, Amanda, if we were all your age, I'd say Yeah, yeah, Yippy, yeah, yeah. But when you look at the demographics of the us, more people are closer to Andy, Mike, Chris, and I, and those people don't have five to 10 to 15 years for this correction to correct itself.
Okay? And, and so it's important to them. And, and yes, when we look at the s and p market over the last, let's say the s and p over the last 80 or a hundred years at averages, I dunno, 3% a year or three and a half percent a year, something like that.
We had a great four years this, these past four years in the market for the most part. Um, but I don't have 80 years for this to, to, you know, what you're losing now is really gonna hurt people. And then you have the twin concern of how are we gonna pay for our social security, Medicaid, Medicare, giving government, the current government here.
And then, you know, things start getting real ugly, real quick, real ugly, like, take to the streets, ugly. Take it to the streets. And I will say, Amanda, it's a good, it's a good plan.
And Alan, you're right. Buy on the dip. The one thing that I'd point out, you know, and certainly the oligarchs are gonna do that, right?
The one thing I'd point out is if you're not making the market, you're at the whim of the market. So yeah, you can try and buy on the dip. Um, and you know, if you're gonna do that good on you, you could potentially make out really well, like you say, Alan, if you've got time to let that fester and, and grow, uh, over time and correct, but you gotta pick the right winners.
And if you are not making the market, uh, I don't know that I'm gonna pick the right women's. So what I heard Alan say is that the Textron gang will be broadcasting for the next 20 years, even if it's from a nursing home. Is that what you're saying?
Well, No, what I think I may have to do is just upload my consciousness to an AI and, and it'll be out there in perpetuity, you know, earning money, whatever. Um, it's, it's, it's a scary thing. Look, you know, let's be realistic.
Some of us have done well, but the majority of Americans, you know, who are invested, I mean, pensions aren't, unless you're a government worker and there's fewer and fewer of them every day thanks to feelers leader, um, you don't have a pension. You have, if you're lucky, you have a 4 0 1, a 401k if you're lucky, maybe your employer matches your contribution and so forth. And most 4 0 1 Ks, you're not playing individual stocks, you're making broad bets.
You're betting, you're investing in QQQ, right? The, the NASDAQ Index Fund, you're investing in an s and p fund, you're investing in, uh, in a small cap fund, a large cap fund, aggressive, you know, but they're general, their funds. And, and so you don't, you, you are, you are betting, you're in this, you're in the zebra herd, right?
And your, and your investment goes as well as the herd goes. You're not a maverick, right? And, and so as Andy says, if you're not a maker, you're a sheep and, and you're, you know, some sheep gets slaughtered.
Wait, it's only a matter of time before all those manufacturing jobs come back to the US and we're fully employed again, and consumer sentiment will just skyrocket back up again. Come on. That's right, Mike.
That's right. Yeah. I didn't know we were doing standup.
Oh, man, I haven't got my Tight Five, Mike. That's right. Yep, yep, yep.
But look, you know, one thing about the market, it is fickle. It is fickle. Maybe, maybe you get a, some peace deal in the Middle East or, or the Ukraine and Russia situation.
Uh, I don't know. China does something. I, I mean, there are, you, you never know, right?
And, and that's part of living in chaos. So if you're sitting in Canada, China, and you know, and, and then as the president describes it, this is the biggest market and the most coveted market in the world. But if consumer sentiment is down, the market is down, people are spending less than you have less leverage to negotiate on tariffs, right?
So individually, it's a very big market. My fear is that Europe says, you know what? We don't need this.
We'll go do deals with China, Canada, Mexico, Brazil, we don't need this. We'll go do deals with China. It don't take much China plus to, to, it's not even close.
What's a big market, right? Because one could say China's a bigger market right now anyway, but you do China plus Europe, China plus Canada, Mexico, Europe plus Canada, Mexico and Brazil, Europe plus India. I mean, we're, it, it's a global, we are way past, this isn't 1953, and Eisenhower isn't the president where the US dominates the world market anymore.
It doesn't, we, that's not who, that's not what the world is anymore, right? Everyone in this world wants to live an American lifestyle in terms of being a consumer. And every, almost every country tries to give their people that consumer lifestyle, right?
They don't want to be America per se, but they want that American lifestyle, right? This, I, I've, Thomas Friedman in his flat Earth series writes about this a lot. And you know, there's a lot of countries in the world that are giving people that American lifestyle Plus.
And Alan, I'll tell you all from a global perspective, there's a reason I am here. Uh, you know, I listen to my accent. This is my Colorado accent, right?
I've come a long way to be here and enjoy that American experience, right? I'm sacrificed a lot and hopefully contributed some, but I will tell you, you're exactly right, but Asia especially is no stranger to China. Australia has been trading with China as our most favored nation for the longest time.
I, I believe for a long time, China was actually our biggest export partner, especially around coal, steel resources. And you look at, uh, Asia Pacific generally, and look, this is a game of brinkmanship that could end up very, very poorly, exactly as you say, because star, I would start in Asia where there are already somewhere like two and a half billion people, and you talk about markets, India, Indonesia, China, that's like half the world's population right there. And if they align with China as they already are, there's a lot of sentiment there, which is that China is a positive influence in the region.
We don't always look at that from our perspective here in the States. And so there's a game of brinkmanship that could end up very, very poorly already, China has been pressuring trading partners to not use US dollars. Now, if we start to talk about petro dollars and Euro dollars and uh, uh, petro euros or whatever you'd call it, ooh, wow.
If America stops becoming the reserve currency of the world, then we're in a whole different perspective. Wow. I've been, I've been tracking Bitcoin long few days.
If you think your portfolio's bad, just track Bitcoin the last week and a half. Oh my goodness. I'm glad I'm not long.
Crazy. Anyway, hey, we've got a call, a break. I, I, I'm not in the studio, as you could probably tell.
I'm up in Orlando at Scon, and I've gotta go hear what's going on in the world, world of Linux and AI and Cloud Native. So, um, I'll be here all week, but I'll be on the gang. I'm gonna try to get Mitch's here with me.
Mitch Ashley, we're gonna try to do a report from Suka for gang either tomorrow or Thursday. Um, but until then, Andy, always a pleasure. Chris, great to see you.
Smooth sailing, as they say, may, that wouldn't be at your back. Amanda, Mike has always thank you. Thank you for watching.
We've got a full text drunk TV schedule immediately following, so stay tuned for that. But for now, this Alan Shimel for Text Drunk Gang. We're out.
This is Text Drunk tv. Hey everyone, welcome back here to Text Drunk tv. Our next guest on Text Drunk TV today is Ravi Circus.
Ravi is the co-founder, chief product officer at a company called Simplicity, SEEM, simplicity. Hey, Ravi, welcome to Text Drug tv. Man, it's great to have you on.
Hey, uh, nice to be here. Thank you so much. Good.
It's, uh, it's a, my pleasure. Just fixing my button here. Um, so Ravit, let's start off with a little bit about you.
If it's okay, I said you're the co-founder, chief product officer at Simplicity, but what, give us an idea of your journey. Well, so I, I'm on the cybersecurity market for like 25 years. All, all of them is both on the side, but I also been a practitioner for many years in global 2000 companies.
My entire career is, uh, around network security, vulnerability management, cloud security. Um, some people know, uh, will say that I know to do only one thing, but I think I know it, I know it's very good. Um, so, so, so, yeah, and, and a lot of those experiences and, and learnings that, that I had over the last, uh, 20 years are the things that kind of, uh, make me co co-founder with my, with my team and, and build the simplicity, uh, as we are trying to, to solve old problems in, uh, in, in a new and very effective, uh, a very effective way.
Absolutely. You know, vulnerability management, remediation is something I've been involved with, uh, since like 2003, I guess, is, you know, a company I had helped start, we came out with a product called Van Vulnerability Assessment and Management. Back then, Nessus was still open source.
Everyone had Nessus, you know, under the hood, you know, writing Nale scripts or what have you. But what I remember back then reviewed was, it seems so natural to us that finding vulnerabilities in and of itself was nice, but not perfect. Remediating vulnerabilities was the game.
And even back then, we were trying to automate remediation, and we ran into such resistance, right? From people who said, whoa, whoa, whoa, whoa, whoa. You can't just patch, or you just can't shut something down, or you can't reroute something.
You know, we've gotta make sure it doesn't break something else, because what you break is a lot more valuable than what can be attacked via the vulnerability, right? And it was, it was frustrating even back then. I, you know, and I was there.
This is a company I also helped co-found, and I was there for 10 years, and it was, or maybe eight years, but it was extremely frustrating. Um, I'm, I'm sensing that maybe Simplicity has a, a new approach, a better approach that breaks down that resistance. Tell us a little about the company.
Yeah, I, I think that's a great point. I think that if you look at it, the security team is responsible to discover vulnerabilities, but they are not authorized to fix that, right? The people that can actually are add other guys, the it, the developers, the DevOps, the operations, and the reality is that the security team sits in the mi in the middle, responsible for the process, but cannot execute the process.
So they are all day trying to, what we call drive remediation, or in other words, making other people work for them. And throughout the many years of the practices of Vulner aerobic management, everyone was too focused on the, on the security team as the one which are responsible for the process, rather than to be focused on the fixing team or the remediation team are the ones that actually executing the program. And one of the things that we did when we started Simplicity is actually go and interviews those DevOps guys, those, it Gs those, uh, network operations guys, and kind of understanding their perspective to this process and how we can make it easier for them.
Because if we will make it easier for them to fix, we will make it easier to the security team, the security organization. And by doing that, we actually developed a platform that takes all that huge data, but prepare it better for remediation, make it available in the way that those remediation and fixed teams wants it, as opposed to, as opposed to just throw another list of big problems that only security team understands, uh, and expect them to do the most out of it. Uh, absolutely, and you're right, that that was the problem, right?
It's the, you know, the, the responsibility without power, if you will. And, and quite frankly, in the cloud, it was even worse at some level, right? Because I, you know, some vulnerabilities were beyond your, your company's even ability to remediate.
Um, yeah, I think Cloud, by the way, got it much worse because one of the things that happens on the cloud is that the modern cloud team actually got full stack responsibility for the networking, for operating system, for infrastructure, just not for security. Those security guys keep their things close to their chest, don't tell anyone, and once every while they give you two vulnerabilities that you need to fix today, right? Of course, this will create friction.
So, so cloud and the dynamics and doing things much faster actually accelerate and, and accelerate this problem and, and, and increase the friction very between the teams very dramatically. Absolutely. You know what, we've done a great job of what we call setting the table here, right?
So tell me about simplicity. So we in simplicity actually look at the problem as so, so traditionally people looking vulnerability management problem. As a prioritization problem.
We actually look at this problem as a process productivity, uh, problem as a communication and collaboration problem. Part of it is to prioritize, of course, if you want to be more productive, more effective, you want, you want, you need to prioritize what you're doing. But it doesn't end only there.
We are, we have bit of platform that we call remediation operations that actually takes the data from all those different scanners, whether it's Code cloud, on-prem, SaaS, ILT, all the different misconfigurations vulnerabilities, application security issues. We put them into the platform and using different technologies that involve, involve data scientists, that involve ai, that involve our best practices and knowledge. We have built a platform that transform the findings into solutions, into list, list of action items.
And then we have built an a, a a workflow platform and automated, uh, uh, um, dispatching platform that actually manage the security backlog for each of the remediation team. So no more, uh, Excel reports, no more PDF reports, no more status meetings, just a rolling backlog of security issues. Just like you have your bugs, your features, you now have a backlog of security issues that manage itself.
And you don't need to go through that motion of, here is a list of problems, go figure out. And, and, and next month we will review that list again to, to try and understand what we do. We have reduced dramatically the friction, we improve the efficiency, and we are getting to a point that our customers report five or six times more remediation in the organization comparing to, without simplicity, we are getting to the point where three or four people can handle remediation processes with team of 200 or with 200 or 250 development teams in a very large organization, which otherwise won't, uh, won't scale.
Sounds like Nirvana, man. I, I, you know, I, from back in my day, it's like, wow, okay, so what, what's the special sauce, if you will? What, what is, what, what was the game changer here?
So I think, I think there are a couple of, I, I think there are a couple of, uh, things that, that we are doing that, uh, that make the difference. There are three main things. I think the first one is that we are transforming findings into fixes, into remediation items.
'cause many problems has the same solution. Many problems are effectively can be remediated better in, in the same way. If you have a piece of code that have three other problem, three problems, it doesn't make sense to get one problem today, one problem next week, one problem the week after, because you will have to curate that piece of code three times.
Actually, it'll be much more efficient to the organization to get everything together now, so you can test it only once. Uh, and in very similar way to vulnerabilities and others. So what we are first doing is that we are transforming the list of problems into remediation items.
That's actually reduced the amount of things that you handle in about 70 to 8% in average on our, on our customer, uh, base. Uh, the second thing is a set of algorithms, which we call find the fixer. One of the ma main problems of, uh, of many organizations is that, you know, who you have a problem, you know where the problem is, you just don't know who can fix it.
So we have developed, uh, different algorithms that use data science, science algorithms, a AI capabilities and, and, and other, and other techniques that actually allows us to look on data that already exist in the organization. Activity, all tickets and what have you, to actually understand who is the fixer, who is the owner of that, uh, resource or asset. And then to be able to automatically assign that, uh, remediation item, uh, uh, to those.
And the third part is really our, uh, our workflow engine, which actually makes the data remediation data available to each and every one of the remediation teams in any way they want. Because if you will go to the organization today, one team will want tickets in Jira. Others will want alerts in in Slack.
The third one will want an API to pull it to their platform. And the fourth one will come and say, I want to look into a web UI and just mark all the things that I, that I did. And the security team cannot scale to deliver different type of remediation plans to each of the remediation teams.
So they're going to the lowest common dominator, which is a spreadsheet. So what we actually do, the third piece is our remediation router that actually make the data available. However, the remediation team, uh, wants to look at that.
So less, uh, significantly less amount of findings, knowing who the fixer is, and make the data available, uh, for the fixing team in any way that they will want to help them remediate faster. I love it. Good stuff.
Now, of course, we live in a world where it just seems there's, every day there's more, more and more like the, the pace of vulnerabilities is increasing, right? No matter how you want to slice and dice it, it just seems almost like shoveling sand against the tide, right? Where we, for every one we fix three more pop up, right?
How can you, and, and given this environment and all of the things you cited, everybody has their, every team has their own way of fixing these, their own way of approaching it. How do you build a enterprise level efficient strategy here? I mean, obviously say use simplicity, but, you know, beyond using simplicity.
So, so I, I think, I think, again, I think it includes many different things. I think one of the things that you need to focus that is actually not is what my current risk, but actually how quickly I recover from it. So, to stop thinking on how secure my organization is, but start thinking about how resilient my organization is.
And as you start to thinking about resiliency, you can count and say, okay, though there are set of things of those, uh, tons of, uh, findings of tons of vulnerabilities that want to be fixed within 30 days. There is a bunch of things within a quarter, and there is a big backlog that, uh, may be within a year. And start to measure that the things that are important for you actually get into the hands of the right person at the right time at the, with the right data so he can fix it in 30 days.
Then to make sure that there is a good plan for that quarterly things, and then, uh, what to do with all the rest when you're doing technology refresh. The, if, if you start, if you stop thinking about how do I protect myself now and start thinking about how I build organiza, uh, an organization that helped me to recover from a zero day that was identified right now, and I know that within a week my organization is secured against that, it actually make a, a big difference because you are starting to find the inefficiencies in the process, rather than a big pile of vulnerabilities that you try to sort what will be next. And by putting process automation into place, putting a lot of prioritization into place, putting a lot of, uh, uh, uh, reduction of the noise into place, that's what actually allows you to, to build the process that allows you to make sure that the organization is effectively fixing to measure that, to identify bottlenecks.
And by doing that, uh, building a more resilient organization. Excellent. Ravi, we're, we're, we're running all on time for people who want to engage with simplicity, first of all, a website.
Second of all, like, how, how did they get started? Did they, you know, gi give us, you know, an on ramp? So, so it is very easy.
Of course, you can go to the website, you can reach out to me in, uh, in LinkedIn or any of my, uh, of my, uh, my team members. Actually, many of the customers just come and ask us, guys, let's, let's run it through our organization. Let's see what the efficiencies that, that, that that we get.
And we are going go, going with them for a quick test trial when we onboard three or four different, uh, data source of vulnerabilities or application security or cloud security issues. And almost immediately you see that reduction in 70 and 80% of the, of the findings. Almost immediately.
You see that one finding that you know about for two or three weeks that you don't, but you don't know who should fix it. And, and, and then, and suddenly simplicity is showing you what is that? So, so I think that the, the best way is let us prove that, uh, that it works the way that, uh, that we claim it is.
Okay, just engage with us, with us. We will be more than happy to do a test, uh, test drug together, uh, with the customer, with his data just to prove that things can be better. You can actually manage that at scale and not manually one by one through through a spreadsheet.
Generally. How long does it take to get sort of a, a, a, uh, trial like that set up? Uh, the, the setup is like, uh, two to three days, and customers are kind of playing with the platform for two weeks just to make sure that they see data over time, uh, that, that they're getting their feedback.
We are recommending the customer is to involve non-security people in the, in the, in that test Sure. To get developers, those IDOs, DevOps into the place so they can give their feedback, they can see the benefits. So, so should, so it can take technically to take two to three days, but organization usually play with the tool for two or three weeks just to get, say the error around it.
It's very easy, uh, in that sense. It doesn't require any agency installation or something more complex than that. So it is more, it is very easy to, to try and see the benefits yourself.
Excellent. Ravi, thanks for coming on Tech Drug TV and TA telling us about simplicity. Um, continued success.
Are you guys gonna be at RSA conference? Yes, for sure. Well, we'll be there live.
Stop by, say hello. We'll be our broadcast alley all week. I will looking Forward, alrightyy Ravi Circus, co-founder, chief product officer at Simplicity.
Uh, they might have cracked the nut on getting remediations for your vulnerabilities. io. We're gonna take a break on Text Trunk Gang.
We'll be back in a little bit. This is Textron tv. Hey guys, thanks for the throw.
We're here with Nick Schneider, who's the CEO for Arctic Wolf, and they just completed their acquisition of silence, which they picked up from Blackberry. And silence has been around for a while, but I'm gonna let Nick explain what it is and what it does and where it fits in their portfolio. Nick, welcome to the show.
Yeah, thanks for having me. Uh, Michael, we're super excited about, uh, the acquisition and, uh, we think it's gonna be a, a monumental shift here for Arctic Wolf, but also for the market wholesale. So, Exactly.
For those that are uninitiated, what does Silence do and why did you guys decide to pick them up? 'cause Well, there's a lot of players in the security space. Yeah.
So Silence has been a, uh, pioneer in, uh, AI based endpoint protection, uh, and detection response, uh, for quite some time. Uh, they had and have a really strong customer base, a really strong, uh, channel ecosystem, uh, and bring with, uh, you know, the, the team a, uh, long track record of, of strong, uh, you know, technical acumen. So we, we got a great team, uh, a great product, uh, with global scale.
And when you combine that with what we're doing, uh, at Arctic Wolf, uh, with regards to security operations, it gives us an opportunity to bring, uh, some additional prevention capabilities, uh, to our customers, as well as some detection and response capabilities, both from a product standpoint, but also a managed standpoint. And when you combine that with our broader security operations platform, we can provide, uh, multiple different outcomes to our customers, uh, in a way that is, uh, unique and allows them kind of choice with regards to what their security stack looks like. We're kind of in a state of transition when it comes to cybersecurity, and I think a lot of people are trying to figure out how to navigate it.
We're going from a world where I think we had more tools than we knew what to do with, and now we're trying to get to something that feels like a platform. But the platform itself seems to be maybe augmented with managed services provided by somebody else. 'cause I can't find enough skills and talent to drive it myself.
So from your perspective, how does all this come together? Yeah, I, I think you're spot on. I think we've, uh, been living in a market that was built on, you know, thousands and thousands, quite frankly, of point solutions that solved for individual use cases or outcomes that a customer would look for in their soc.
Uh, and then you have some vendors that, uh, worked to kind of put those, you know, tools or capabilities together, if you will, at some level for the customer onto a platform, typically in a closed, you know, manner. Uh, and then you need to operationalize, you know, those tools and those platforms. Arctic Wolf has, you know, always focused on the operationalization of cybersecurity.
So we've built a concierge security team. We've built what we call our security journey to help customers kind of understand and make security work within their organization. And now we're adding, uh, some pretty significant platform capabilities along with tools or point solution capabilities natively, that will allow our customers to kind of get the experience that I think that they've expecting, been expecting from cybersecurity for quite some time, uh, which is just to make sure that their business is protected.
Make sure that they're aware of, you know, current or, or emerging threats and have the ability to respond, uh, to anything that might be taking place within their environment in an expeditious way. You know, time is the enemy, uh, in cybersecurity. And I think when you combine, uh, really strong tools and capabilities with an open platform and an open architecture, which allows customers choice and allows customers to be able to benefit from some of the investments that they've already made.
And then you couple that with a really strong, uh, security operations acumen, uh, and team, you, you can deliver these outcomes in a way that gives, uh, the customer better protection, uh, and better ability to detect and respond to threats than, than they would've had. They tried to put them together themselves. And one of the things we are seeing is that not only are the threats increasing in volume and sophistication, but it feels like the whole battle is now being fought in real time.
'cause to your point, um, if I'm five seconds makes all the difference in the world between the amount of damage that might be inflicted or not inflicted, how do I kinda align my defenses in that world where basically the attacks are happening faster and the defenses for that matter than any, uh, human can possibly keep track of? Yeah. That, that's where the marriage of the tools, the integration of those tools, both native and third party onto a, uh, platform that can, you know, give the customer real-time visibility along with this operational expertise really comes into play.
And I think what you're seeing is a bit of an evolution of tools being combined on a platform, and then those platforms and tools looking to help customers operationalize the technology. And, uh, more and more, I think what we're gonna see here is that in order to do that appropriately, and in order to be able to respond to threats in a timely manner, or at the speed with which the, the threats are taking place, you're gonna have to have some marriage of human and, and technology or, or AI or automation kind of within your platform. And I think, uh, Arctic Wolf's spending a lot of time and energy on that to deliver, you know, those outcomes to our customers.
Um, uh, but I don't think it's gone fully automated or, you know, or remains, you know, fully human. So it's gonna be this marriage of bringing the customer the right outcomes in the manner that allows, uh, them to get the re response and, and detection, um, uh, you know, efficacy that they've been looking for, uh, while still have the ability to pick up the phone and, and talk to somebody if they need to. I remember when silence first came out and there was a lot of skepticism about ai.
Um, and yet it seems like our thinking about AI is evolving quickly. So, you know, when you talk to customers, what is their attitude towards ai? How does it compare to today versus a few short years ago?
Yeah, I think AI has been a part of cybersecurity, as you mentioned, for, for quite some time. Um, I think typically AI had been used, um, you know, more as a, a backend mechanism to automate certain workflows or processes or to perform certain tasks within the platform or, or the operation. I think now you're seeing AI kinda rise to the forefront of the way in which a security operation operates, but also the way in which a security practitioner, uh, can make themselves, you know, more efficient or can give themselves the ability to detect and respond to threats in a more expeditious way.
So, I, I think what you're seeing is certain levels of cybersecurity, uh, practitioners kinda leveling up, if you will. They're able to do tasks that maybe used to take a day in a matter of minutes or tasks that used to take, you know, weeks, uh, in a day. So they're able to respond and react much faster requires, uh, that you're leveraging ai, both for your ability to detect and respond, but also for your ability to kind of understand the threat and its impact on your en environment and ecosystem.
And I think as, uh, the automation and AI come together with human expertise, uh, you know, thankfully, I think we're gonna start to see, uh, that the defenders here, uh, are gonna have a, a, a better chance of, uh, protecting against, you know, what the attackers are throwing at them. Now, the, the converse of that argument is the attackers are also leveraging ai. So, um, you know, both sides of the, uh, equation here are gonna have to stay on top of, uh, how to leverage ai, uh, from a, from a defensive mechanism, but also make sure that we understand how AI can be used, uh, offensively, uh, as well as, uh, understand how AI actually could potentially become a, a new, uh, attack surface as it, as it is starting to become, As you think about it, uh, clearly there's always been a lot of talk about whether AI was gonna take anybody's job, et cetera, et cetera, et cetera.
But I cannot help but wonder, have we reached a point now where, as I look at it, I'm like, who would wanna do these jobs without ai? It's a lot of toil and a lot of manual effort, and it's not a lot of joy. Yeah, I think, I think that's spot on.
I, I don't view AI as a, uh, tool that is going to, you know, remove the need for cybersecurity professionals or expertise. I think what it's gonna do is remove some of that toil, um, from the day-to-day of security practitioners and take tasks that maybe used to be a little bit more tedious, uh, and make them, uh, able to be completed in a much shorter time, which frees up time, uh, to do, you know, some of the more strategic cybersecurity work, which I think is what most security practitioners are, are after. So, uh, I think the only folks that'll probably struggle a, a, a bit, uh, as a security practitioner are actually those that don't embrace ai.
Uh, those that do embrace ai, I think, uh, will be at the forefront of, of, uh, the kind of new wave of, uh, security operations in the manner in which these platforms and tools kind of combine to provide these outcomes to, uh, to either their organization or the organizations that they're working to protect. So what's next for you guys? It's still early in 2025, I'm sure you got a roadmap from the coming year, but, um, there's of course no end to competition in this space, but what should people be looking for from Arctic Wolf?
Yeah, I, I think, uh, the silence acquisition is a good indicator of the direction we're headed. We've spent, uh, a lot of time, uh, and energy in building out our security operation. Um, we have one of the largest, um, most sophisticated security operations in the world.
Uh, we've built out a robust platform that's now operating at massive scale. You know, we're processing north of 8 trillion security events a week, um, with the magic being that our average customer is really only having to action, you know, one or two, uh, of those events per week, uh, through the magic of the platform and the work that our concierge team is doing. And now we're starting to add, uh, additional native capabilities, uh, endpoint, uh, we just released a threat intelligence skew.
Uh, we have some, uh, identity, uh, skews and, and products that have come to market recently on top of what we do for vulnerability management, you know, awareness training and incident response. Uh, and I think, uh, the market should expect to see continued evolution, uh, of kind of our core competencies, but also the addition of, uh, some additional capabilities to the Arctic Wolf platform. What, what will be unique, I, I think about Arctic Wolf, uh, you know, other than obviously specific features or manners in which we engage with the customer will be, uh, our ongoing commitment to being an open platform for the customer base.
So even though we'll have native capabilities, uh, on top of our platform, uh, we will still support, integrate with and leverage, uh, third party tools, even if they're aligned to some of the native capabilities we bring to the market. We just feel that's really important. Uh, as customers, you know, work to kind of shore up their overall security posture, that they're able to do that, you know, kind of on their timeframe, uh, with the budget and investments that they've already made being used, uh, but still be able to kind of work their way into a platform that that solves the broader, you know, cybersecurity challenge for them.
Organizationally, You've of course been around this block more than once, so what's that one thing you see organizations still doing that makes you shake your head a little bit and go, folks, we need to be a little bit smarter than that. Yeah. You know, um, there's still a surprising amount of organizations that don't, you know, bite off, uh, the low hanging fruit first, right?
So simple things like MFA, uh, patching, uh, or, uh, you know, training of employee base, uh, are still a lot of the common ways that a threat, you know, occurs. Obviously there's more sophisticated manners in which threats occur, uh, but kind of the opening of the door still happens quite frequently with, with things that are very easily, you know, solved for. So, you know, we work hard, uh, as a partner to our customers to help them understand what their security posture looks like, uh, where they potentially have, um, some vulnerabilities, how they should prioritize those vulnerabilities, and then make sure that we work with them to ensure that those vulnerabilities are, are closed up, but also that we're able to detect and respond, uh, to anything that might be happening in their environment, you know, in real time.
Um, and I think as you know, customers look to ensure that they're protected. Uh, I would always start, uh, with the basic blocking and tackling, um, and the low hanging fruit, uh, of the, the common, you know, threat vectors, uh, and then work, uh, towards the more sophisticated use cases, uh, as they kind of build out and shore up, you know, the, the, the foundation Folks, you heard it here. There's no substitute for fundamentals.
And hopefully, well, it'll help from AI and platforms. More and more of that stuff will get automated. Hey, Nick, thanks for being on the show.
Great to be here. Thanks for having me. Alright, And back to you guys in the studio.
This is Techstrong tv. Hello and welcome to another episode of the Inevitability Curve. My name is Chris Blas, I'll be your host for this.
And with me today is a good friend. Rakesh, how are you doing today? I'm doing awesome.
How are you doing, Chris? If I was any better, I'd be twins, right? So, as we were just talking about, wow, that's amazing in the green room, right?
We, you know, you've led a, a sort of fascinating life, and you and I worked together at Cisco in the late nineties, right? You were, they were just performing, I think, right? In 96.
Yeah. Yeah. I, I I, I, I came to Cisco in 96.
I was brand new outta college, and I got into this thing called cybersecurity before we called it cybersecurity. Right? Um, and yeah, no, it was, it was, it was good times though, the early firewalls, early hackers, early viruses, which seemed so quaint by, by, by our modern standards, but, but certainly seemed interesting in novel back then.
It really was. And as we're talking about in the green room, right? You know, there are these transitional times, and I think, you know, on our topic today, uh, you know, amused, uh, emergency response, humanitarian efforts and so forth, um, we can get into your background, uh, in context as it makes sense.
But I think along with a lot of other things, like the late nineties, you know, like the turn of this entry for you and I, and cybersecurity and the internet as a whole, I think this period, I think the twenties, you know, going into the thirties is an extremely pivotal time. And I think this topic is another example. Yeah.
I think, I think we are, you know, there's the, the old saying about what may live in interesting times, I think we absolutely are living in interesting times and, but interesting manifests in many, many different ways. There are, you know, so many challenges, so many challenges that seem very, very big. But there are also a lot of opportunities.
And I think that one of the challenges of being a human in this time is being able to see both, to have the, the cognitive dissonance of saying, yeah, things are really, really hard and things are really, really challenging. But at the same time, there's all these really amazing things that are also happening. And two, recognize that one does not cancel out the other, but they kind of coexist simultaneously.
And how do you walk and hold those things at the same time? Right? And, you know, uh, we'll see how the conversation goes, but I'd like to, you know, put this in the context.
You and I are parents, right? And your kids are, are maybe 10 years younger than mine. My kids are in their twenties.
And, uh, uh, we get a lot of, uh, people our age, you know, gen x Boomer type of folks, you know, typical for our age class. We do a lot of this kids these days stuff. And I look at my kids and your, you know, people, uh, people at your kids' age, and I couldn't be happier, you know, like, Yeah, no, it, it, it's pretty amazing.
And in fact, it, it, it was, it, it's something that's stunned me, and it's not just like my kids as an outlier, but what I've noticed is that all of my kids' friends, the entire cohort of children, uh, and you know, I have a sixth grader. I have a fourth grader right now. And so in, in that age bracket, the emotional intelligence of these kids, uh, is just incredible.
The the awareness and the empathy, um, the, the social emotional context that they are in right now is so much richer than what I recall having when I was that age. And my friends. I think that there is something fundamentally different and, and honestly better about how they're engaging in the world and how they're, how they're going to be activated.
And like, and, and it shows up not in big ways, right? Like, I'm not talking about like how the kids will go off and make some big change in their community or what have you, but I'm talking about like how they interact with each other, how they call each other out when someone is being unkind, how they, uh, reach for each other when someone's having a hard day. There's just some basic human empathy stuff going on, and it seems to be, at least in my view, like, it, it, it seems to be very cross-cutting.
It seems to be cross-cutting across gender and age and, and all of the little ways that we might, uh, put people into buckets or these kids into buckets. It seems to be very cross-cutting. And, and I think there's something very fundamental going on, and I'm really, really excited to see who these kids are gonna be as adults and what sort of movement they're gonna make in the world.
And, and I wanna put this out at the beginning because I think it's important to looking back and, you know, really understanding where we are and, and having a reasonable chance of, you know, forecasting some of the path we may take. But it's, it, it is that I think it, you know, we, we, you know, one of the things that that's, uh, that seemed like a problem to me from earlier in my life was population overpopulation, right? 54 billion people.
52 billion people, that's why a hundred million Americans would starve to death in the 1970s. And I'm four, right? You know, and I was a smart little kid, and I knew, you know, knew more about math than I should have, but that was just this horrible thing.
And we have somehow, despite all the problems we've had between now and then, uh, we make 30% more food per person with 8 billion people than we did with three. And I think that applies in many ways to the topic at hand. You know, the interconnectivity of all people, this whole internet thing that you and I and others have, have worked on, and the results of that, you know, leading to long-term potential, very, very positive outcomes.
Um, that may not always be obvious as we're struggling through, you know, the stages, but I think come out as we consider the whole thing. So let's let, let me jump back to the beginning. Where would you like to start as we're discussing?
What's is a root Sure. Uh, worth, uh, digging up? Well, I think, I think one of the main themes that I wanted to, to, to kind of share with you is the, the role of adaptation, right?
So when you think about the, the example you just provided, the, uh, the challenge of feeding everybody. 'cause I remember a time when people worried about a population explosion. And, and obviously we have something north of like eight and a half billion people on the planet right now.
Um, what allows us to do that? And of course, we obviously know that there's sustainability challenges. We obviously know there's carbon challenges and there's, there's challenges with that population.
But what has allowed us to grow that population and keep people fed and seeing this extreme reduction in, in the worst kind of poverty, uh, especially since the year 2000 has been this notion of adaptation, right? So this notion of, hey, there are challenges that we are faced with, right? Like, like when we say that we are optimistic, it's not from a place of being naive, right?
Like, like we, we, we, we try and see with clear eyes what is ahead of us and what we are faced with, but then we say, what can we do about it? Right? And I think that one of the big challenges that people have is they go from no awareness of a problem to suddenly the problem is so big that they can't, um, do anything about it, right?
They can't do anything about it. And so what we wanna do is adapt. We need to encourage people to have this value of adaptation and basically stop in the middle of that, of that, of that freak out and say, look, you're now aware that X is a problem, but before you say it's too big of a problem and I can't do anything right?
Before you remove your own agency, you go from having no awareness to suddenly you have no agency, we gotta stop and say, what can I do about it? What can we do about it as an individual, as a community, as, as, as a tribe, whatever, whatever your, your slice and dice is gonna be. And so I wanted to really spend some time and really dig into the notion of adaptation today, uh, with you and, and what it means for humanitarians, for public safety, for how we're going to deal with the inevitable crises that are going to emerge, uh, in, in this time, right?
So we know that there's gonna be crises, but how do we respond to that, right? And when we look back, I mean, you, you used the word tribe. And I, when I say look back, I mean all the way, I mean, we're here for a lot of reasons, you know, a lot of them happened a million years ago with among Homoerectus, you know, forming cultures and so forth.
And it is built into us. And in the last, you know, four or 500,000 years that, you know, we've been here, homo sapiens, you know, there's a lot of repeating structures and, and social, you know, mimetics, you know, thoughts and, and social structures evolve just like genetics. And we're actually wired to deal with this.
You know, to your point, adaptability, you look back over human history, that is the defining trait. You know, that's what sets us apart from everything else, is that, you know, whatever the bloodies situation is, we end up figuring it out. And one of the benefits of, of overpopulation, of, of population that occurred to me early in my life was that, you know, back in the day, you know, 400 years ago, there were a dozen people, um, in the world thinking about things and talking about it, and documenting.
I mean, you know, maybe a little, little bit more of that, but not much. But one of the emergent benefits of the internet that I always, you know, thought was pretty fundamental, was sort of a cliche by the early nineties, is just imagine if every human being is communicating, connected, uh, able to communicate with every other one, you know, and, and that one of the artifacts is you have 8 billion people with some possibility to contribute to an issue, whatever. It's, and just on aggregate, you know, is that more or less useful than having 10,000 dedicated people?
Quite often it's, it's much more useful. And this is taking, you know, historical heritage, cultural traits, you know, supporting each other and healing the communities and adapting to, you know, emergencies and disasters and climatic things. And we build infrastructure around it.
Um, so it's built into us. And yeah, I, I think one of the really cool things about the internet, and, you know, i I come from that same time as you in the industry where we had a very sort of noble and almost utopian vision of what the internet was gonna be, where once we got everyone talking to each other, we would be able to solve so many of human's problems. And there is a truth to that.
Like, we've been able to solve a lot of problems. We've been able to connect, um, the, the, the gen genomic sequence for COVID-19 was sequenced and shared within 72 hours with research scientists around the world. And so literally, the mRNA vaccines from Moderna and from Pfizer were actually designed over a weekend.
Um, and, and they were, you know, this was a very short timeframe from detection of a disease to actually having a proposed vaccine candidate for those diseases in, in just a matter of days. And, and so, yes, the, the internet was fundamental in that, in, in enabling that kind of thing to happen. Um, you know, obviously I think where we might have missed a little bit was the idea that the harms wouldn't also be accelerated, but we have to take the good with the bad and, and try to hopefully make sure that there there's more good than bad, right?
And we gotta think about like, what are the harms? How do we minimize the risks so that people can actually maximize the benefits? And I think that we have a much more nuanced and hopefully mature process or mature landscape thinking about this now.
Um, and at least we're not approaching it with, with such a naive view. But I think that it's absolutely essential that we recognize how the internet has been a catalyst for, for empathy too, right? So, um, you have things like, like the ice bucket challenge where people wanted to raise money for a LS Yeah.
And suddenly it became this meme that people were raising tons of money off of. And that wouldn't have happened without this kind of instant visual rich communications that the internet provides, um, in, in disasters and emergencies. We see this from even like going all the way back to the Haiti earthquake in 2010, where we saw the emergence of crowdsource communities, people sitting at their home who saw the thing happening on television, and they really want, they, they, they had, you know, people naturally have empathy when they see something happening, when they see some crisis happening.
Many people will just have naturally have an empathetic response. But the next challenge has always been how do we get them to take meaningful, impactful action? And for most people who don't do what I do, who haven't done the things where they've been in disasters and emergencies, um, making meaningful action is, has been hard.
But the internet enabled thousands of people to actually make a meaningful impact on the ground in Haiti, even if they'd never been there before, uh, back in 2010. And that's where we saw this emergence, you know, what, roughly 14 years ago, and now that's only continued today where it's kind of a given that when something happens in the world, entire communities of like-minded people can get activated to go do something about it. And we see the decentralization of mutual aid, right?
Where, where people will say, oh, hey, look, let's, let's do a fundraiser, or let's get equipment to somebody who needs it in this time of, and they don't have to go through those 10,000 people you referred to. They don't have to go through some central authority. They have their own agency and they have empowerment to go do.
And so they do. And let me use that as a, as the pivot to the present because, and to throw the last bit of the past in there, you mentioned the, the covid response, and I think it was the second or third, uh, company I sold a firewall to in 1992. It must have been, uh, was the Canadian, uh, cancer Society.
And as the person was driving over, you know, to our little office, to, you know, talk to me, I did a little gopher search and I said, I'm a can. I worked at, uh, a cancer agency. What do I, what's my day like?
Well, I'm searching for something. I put in a couple of keywords, drilled down to something, pulled up a a list of, of fresh papers on a certain type type of, uh, cancer. And the person got got there.
And I said, uh, let me, I've, I've been thinking about who you are and how this matters to you. And I explained, you know, my thoughts that someone who works there drives in, they park, they go in, they, you know, looks at their files, they find out that there's a paper. And the University of Minnesota, for example, they contact the person there and asked it to be, you know, FedEx or whatnot.
And, and the, the net was that was about correct. And I said, would it change anything if they could do this and click, click, click, and got to just that level. Right.
And you touched on that, and as you and I know in epidemiology and dealing with a disaster like, like covid Yeah. I mean, in 1991, the world would've been an ENT entire, the response would've been un, you know, not comparable. But here we are today where we have things like agency ability, you know, just as, just as well in, in this sort of thing.
You know, we're creating content here that'll go on certain channels and get a certain amount of views. We're not making, I love Lucy, we're not getting 78% of the American population to watch anything. Right?
But, but we have thousands of of people who can take agency to make their own content for educational purpose, try to make a living out of it, whatever it is. And in the same way we can respond to the kind of kind of disasters you've been involved with, including covid over the, over your, you know, current phase of your career. So I don't think anybody else could give us a better view under where we are right now.
Sure. And, and just by, you know, way of setting background, I've been doing humanitarian response and public safety response for about 30 years. And so my very first emergency I ever responded to was a wildfire in Los Angeles called the Old Topanga Fire in 1993.
Um, I used to have a lot more hair than I do now, uh, back in the day. And so certainly I've been able to see and witness and actually be a part of the transformation of modern emergency response, where it was very, very analog back in the day through sort of the nine 11 Hurricane Katrina timeframe, where people realized that without modern technology, they certainly couldn't scale to the level of these major emergencies, these catastrophes. And now we almost take it for a grant.
We almost take it for granted now that every crisis, now every emergency, every disaster has a digital component to it. Every, every emergency has some sort of connection to the internet. Now in 2024, we take that as a given, but certainly when I first started seeing this transition happen around 2001, 2002, that was not yet, uh, a given.
That was not, that was an unproven statement. And people would say, why do you need to bring the internet into this emergency? Why do people need cat videos right now?
You know, things like that. But the, the fact that it made emergency response more responsive, more agile, and more efficient was not yet proven. And, and so we take these things for granted now, but, but certainly for those of us who were around for the transition, um, we remember what it was like beforehand.
And certainly what's happened afterwards. And to be fair, I can't imagine responding to a modern, uh, crisis without having these digital tools at our, at our fingertips. I mean, I can't, I I can't see how we would be anywhere near as effective by going back to the way things were.
It it is, it's, uh, I'm thinking as you're talking there, I'm trying to map those two experiences. 'cause as you say, we both lived through it. But it's one of those things that, you know, even though we were there, I can't picture it, you know, what, what exactly What we do, no.
And, and, and to be. Yeah. And, and, you know, the way I got involved in this, the way I got involved in emergency response and the intersection of emergency response and technology was actually on nine 11 where I was at the Red Cross headquarters in San Jose, California.
And I was, um, you know, we were as a Red Cross volunteer, I was basically given a telephone, a pad of paper and a pen, and I said, and they said, uh, people are going to call in with missing persons, take their information down so that we can try and reunite them later. And this is like maybe two or three hours after the towers had fallen. So, um, people were still very much in the emergency and shock mode of, of that day.
And my very first call was a woman whose adult daughter had worked, uh, in one of the offices in the Twin Towers. And she was calling to report her daughter missing. Um, and I remember very distinctly this conversation where she was describing her daughter in the present tense, you know, like, she works in such and such a floor, she works at this all organization.
And then in the middle of this conversation and telling me about her daughter, she pauses and she started to cry. And she says, I guess she's never coming home now. And suddenly she went from talking about her in the present tense to talking about her in the pa the past tense.
So the realization that her daughter was likely dead and likely never coming home hit her on the phone with me. And I remember feeling really, really, really out of my depth in that moment, because I was just given a pad of paper and a pen, and I was being entrusted with this mother's hope. And I knew that this late, this paper was likely gonna get lost.
It was going to go nowhere. It was like, like this huge hope of the worst moment of her life was being entrusted to me. And I knew that it was, nothing was gonna come from it because we didn't have systems.
We didn't have a way to make sure that there was closed loop communication or anything there. And that's just the system. That's not even the human loss of losing her daughter.
Right? Um, and so I felt a shift in myself in that moment where I, I wanted to really dive into this intersection of technology and emergencies, because this couldn't be the best that we could do. Like, like, like this, the emotional burden of that moment.
And even as I'm talking to you, I can still very distinctly remember this conversation. Imagine, um, has really stuck with me and driven me. You know, it's, it's, it's that stuff and it's, it's individual human moments.
We talk about disasters in the aggregate, but they're really, you know, you, you may have a thousand people affected by a disaster and emergency, but what you actually have is a thousand emergencies. Each one unique, You know, and, and the, I know we're still talking about the past, you know, but, uh, but at that time, you know, the turn of the century, you know, folks may not quite understand. Cisco was an interesting thing at the turn of the century.
You know, we, you know, we built the, you know, huge chunks of the internet. There was a, you know, about that time you, you could say that there isn't anything on the internet that's not going across one of our boxes. Our infrastructure is somewhere.
And as you're saying, you know, the opportunity to do things with it, you know, the firewalls team, we built this big massive thing, you know, so, you know, you know, myself and others are trotting around the world, and, and you get down to emergency response, you, that I experienced at the time was more the cyber thing, right? You know, nine 11, you know, I, anyways, we, we had have that. But on the, on the cyber thing, you know, you get a vulnerability.
You work, you know, put together an ad ho ad hoc team around the world and deal with it in real time and have a, make a difference. And this is, I, I think, you know, why we can feel reasonably positive that, that the future is, is going to continue improving on this. We put these things together.
We've been talking about, we have a generation generations growing up now who've lived with this, you know, all of their lives, who understand the downsides that have the ability to, to capitalize on the upsides, including the agency we're talking about that have developed, I, I believe generationally better understanding and empathy. You really just can't, you know, it's like not traveling, right? You and I have traveled the world.
The old cliche, if you don't leave your little town ever, which three, four generations before us, no one literally ever did. It's kind of impossible to understand it all. Well, now we have ev most everyone on earth exposed to most everyone on earth.
And for all the, the problems we see the opportunities to not only address those problems, but to our topic today, to respond incrementally and holistically to emergencies large and small in all of our lives. You know, there's, you know, the mental health, you know, crisis as, as a population, but as you say, every mental health crisis is an individual, uh, disaster. And getting support, the kind of support you need that really can help and solve all the problems, lower, nearly eliminate suicide and so forth, is just so hard to logistically get.
But it, you know, where we are today and looking forward, you know, whether, you know, any one of the, the, the crises and, you know, uh, emergencies we wanna respond to, I think we have better opportunities to solve all of it. Yeah. And I think, I think one thing that you're, you're touching on here is really important.
We, we talk about this term, poly crisis, right? Multiple crises that kind of intersect and catalyze each other simultaneously, right? And this could be, uh, you, you can slice and dice this any way you want.
So if you're thinking about it locally, you might think about the intersection of the fentanyl crisis, homelessness, and, and some of these other social and economic challenges that are in our cities, for example, and how they actually intersect each other, and how it's impossible to pull on one thread without pulling on all the other threads in the fabric, right? And so we, or internationally, when you look at the intersection of things like climate change and modern conflicts, where the destabilization of the, the ecology also feeds into reasons why, uh, shooting wars break out, right? So, so again, you can't pull on one thread in those areas without pulling on all the other threads.
And I think that like, one of the, the, the elements that is really, really interesting here is that people say, well, if I can't pull on one thread without pulling on all the other threads, why should I pull on just the one thread? And it's because you're actually having the second order and third order effects on these other areas. Now, sometimes they can be good, and hopefully they are, sometimes they can be bad.
And you gotta think about like how to minimize that harm, right? But I think that we have, like, one of the amazing things is just our language. We talk about harm mitigation and harm minimization.
We talk about intersectionality. And I gotta admit, when I first heard the term intersectional, like 15 years ago, I hated that word. It sounded so academic.
But what really connected it for me was when I realized that we do have intersectionality all around us and how we work. So I was on the ground during Hurricane Katrina, and maybe for the first time, I really realized how how we dealt with race and class in the United States really had a massive impact on who got helped, who recovered from the crisis better than others, right? And, and all of these other factors.
And so, um, we moved from this language of like, natural disaster. We now say like, things like, well, there are no true natural disasters, right? The, the, the hazard may have been natural, right?
The, the storm may have been a natural occurrence, but the human impact and the human response to that impact are choices. There, there, there, there are the product of agency at one level or another, whether we choose to acknowledge it or not, right? So we might not realize we have agency, and so may neglect to take action, which has its own consequence, right?
So, so not acting is, is an action. Um, but, but I, I think that we certainly have a deeper language for describing these re relationships, both the challenges, but also the responses and the opportunities. And I think that it starts there.
And I think about the fact that my kids, for example, when I was, when I was a sixth grader, I would hear, why do I need to study for history? Why do I need to study science? Why do I need, I'm never going to use these things, right?
Something to that effect. And, and I don't hear that with these kids, right? They, they immediately connect why they need to learn science with, um, climate change.
They learn history and geography because they need to understand. I mean, like, I think they understand that they're gonna come into this world and they're gonna be need needing these skills to navigate it. And, and I think that for those of us who are older and who are in our careers and who've been through these transitions and these crises, um, the, the real challenge is actually a little bit different for us, which is how do we be, how are we informed by our past but not encumbered to our past?
And what I mean by this, I have responded to more than 50 disasters and emergencies, everything from, you know, nine 11 and Katrina to more recently things like Ukraine and Gaza and, and all these other things in between. So I've, I've done the range of natural and, and, and conflicts and all sorts of emergencies, and very, very easy for me to just sit back and say, well, back in the day, we used to do blah, blah, blah, blah, blah. But the trick of adaptation is to recognize that maybe what you did in Haiti in 20 20, 20 10 is not what Turkey needed in, you know, 2023, right?
Um, and that if you responded exactly in, you know, 2024, what you did in, in 2 0 0 9 or 2 0 0 5, or what have you, then even if it was an innovative back then it would be missing the mark now. So, so you wanna be informed by all your past and your experiences. But, but the start point is to realize that we are in new territory now.
We are in new territory that may looks like the old territory sometimes, but there's these other elements that are novel and that you are gonna have to feel and think and innovate your way into those spaces. And so, and I think that's a really hard thing to do because, um, you and I are both old enough to realize that there are a lot of grizzled old veterans of industry or of service who are very much locked into the, the good old days or the, you know, the big win back in the day, right? Their, their, their, their funda, their worldview is fundamentally locked in the past.
And so while they may have been a rockstar hero in that moment, and, and deserving of all honor and, and recognition for those things, that doesn't necessarily translate to being ready for what is going to happen tomorrow or three years from now. And so I think this notion of adaptation and having the plasticity of mindset to say, okay, challenge is fundamentally new. How do we think our way through it?
And how do we learn from the past, but like, don't just carbon copy and copy and paste from the past. Well, And I think we can look from the present into the future to in certain extents, you know, because, you know, my focus, you know, has stayed on cybersecurity all these years. You know, I've been very involved in supply chain and so forth.
And, you know, just to, you know, sort of last, you know, call out to, uh, intersectionality, you know, Douglas Adams is right, you know, Dirk gently and everything is connected. The, uh, the, the what we need to have, the automation, robotics and AI driven manufacturing and so forth that we all, you know, sort of see in the not too distant future, um, is, you know, at, among other things, a supply chain software, supply chain intelligence, you know, uh, uh, IOC SBO and so forth, uh, intelligence artifact sharing system across entire supply chains that is accurate enough to actually be used, right? We need a, a attestation truth, you know, levels of, uh, um, lay layers of truth to a function, you know?
And I think that sort of thing from that limited perspective has positive implications about the future. You know, in our sort of cognitive security, disinformation influence campaign, uh, world we're in today, it's easy to get despondent about that set of emergencies, but you can see some structures, uh, that are, they're gonna go down this path. And a couple with that, with, as you're saying, you know, our experience in dealing with, you know, the myriad emergencies we're already dealing with and the agency and, and, and, and open thinking of these generations coming up, um, it's hard to imagine that we won't, you know, not only continue to do as well, dealing with all these issues, but get a lot better at it.
Yeah. And I think, I, I think that one of the challenges that we have is just that we, we, we have to recognize that the old models may not serve us currently, and they may, they certainly won't serve us well into the future. And so the, the question I think that we all have to struggle with is what are the models that, you know, there's a, there's a saying that all models are wrong, but some models are at least useful, right?
And so I think one of the challenges is how do we establish the models, the, the, the ways of thinking, the ways of acting that we know we're gonna miss things here and there. We know that we're gonna miss things because we're humans, right? We're, we're not gonna get everything right.
But how do we get the things that enable us to self-correct? How do we get us the, the ways of thinking that enable us to say, okay, we got 80% of the way there this time, let's figure out how we can adjust and optimize to get that last 20%, or as close to hundred percent as we possibly can. And when I think about, um, the notion of adaptation, that takes many, many different forms.
So I live, um, in a small island in Washington state, we have about 25,000 people. We have a rural public safety community here. Now, historically in Western Washington, you've never had to really worry about forest fires before.
Um, you know, it's the evergreen state. It's wet up here. That's the cliche, right?
It's Seattle, it's, it's all of that, right? But the reality is that wildfire is increasing here, and it's not the same as it is in California and other parts of the United States just yet. Um, but it's certainly trending in that direction.
And so what it's been really interesting to see here is that people who've been here for decades, people who have, uh, lived here for many, many decades, and who remember how it was going forward, they're really struggling to understand that the nature of the threat is adapting. And so there's a lot of resistance to things like, uh, establishing defensible space perimeters. Like, why would I need to do this if this is, you know, it's, this is, this is silly, right?
But the reality is, is that we have to start these conversations now because by the time that it's actually germane, if you, if you wait until the threat has fully manifested before you can actually deal with it, then you've already missed the key opportunity of, of mitigation, right? The, the key window of mitigation is seeing the harm as it's emerging and trying to get ahead of it, right? Trying to get ahead of it.
Um, and so this is a really key challenge for us as a local community, which is how do we respond to the challenges, the various challenges of climate change as a local community? Um, but I would say that it actually mirrors the challenges of, uh, you know, states and countries and, and as a humanity, how do we, how do we adapt to that? And how do we do it in a way that's fundamentally empowering, right?
Where we decentralize the power and we, we enable the lowest local action possible. And, and I think that this is a really interesting challenge we have to navigate, because every time we've ever had a big revolution, like the industrial revolution or the information revolution, or these other revolutions, um, a lot of times it's been at the expense of the majority of people for the benefit of few, right? It's been a transference of risk, it's been a transference of power from, from the many to the few, which really enables that elite.
But some of our challenges are they, they, they crosscut so horizontally that, that those models of, of, of transference just won't work. We, we have to enable local action, uh, because there just simply aren't enough elite people at the top to, to fundamentally deal with the scale that's necessary, right? So, so, so the old models won't serve us.
So how do we deal with these revolutions in our present and, and our near future in a way that really empowers people to make change where they are and to make systemic change collectively? You know, I wish we had more time because we could unfold that all day long. And, uh, and I, I trying to, you know, think am I'm gonna resist saying this 'cause you know, it lead to more convers conversation.
But honestly, the, the, uh, the, the, you know, the, what you mentioned at the end, you know, the whole thing about the elites and, uh, and the difference in, in al resource allocation, the very common topic, you know, ask anybody in my, in my kids' generation, it's, it's kind of forgivable when you look back over history because, you know, there have not been the resources, right. You know, for thousands of years to have any sort of, you know, the Victorians I think did a pretty good job. You know, were they exploitive and sort of terrible as a culture?
Oh, yeah. Uh, but I think we're getting to that stage where just imagine if you can put those sort of resources on everyone that everyone had, you know, an an assistant who actually knew them well and had their best interest in heart. And if it was an ai, you know, that everybody gets, I think maybe in a couple decades or, or less.
But how does that change everything? You know? How much would it help if, you know, if every person out there had the kind of support that, that what we call the elite today had?
Um, And I think that y you know, where this finds is, we find this in our, you know, I, I we're just calling kindred spirits, right? So, uh, a friend of mine is very much, she, she's the CEO of the executive director of a homelessness organization in Salt Lake City, right? And she and I talk, and she's super passionate about dealing with the unsheltered people in, in Salt Lake City.
I work in disasters and emergencies, very different contexts, very different missions, very different geographies, and people that we're interacting with everything. But when we talk with each other, what we recognize in each other is that the mission may be different, but the mindset is very much aligned, right? And so we, we, we, we, we refer to each other as sort of kindred spirits.
Um, and, and, and what is really, really reassuring is to meet these people wherever you are, whether it's online, whether it's in your real life, however you may meet these individuals. But to just say, to just recognize that, look, there are other awesome people working on other awesome aspects of the problem. Because if you, if you're able to understand the totality of the challenges that the world has, if you can actually just kind of hold some version of that in your head very quickly, you can recognize that, oh my gosh, everything is so big that I'm just one person.
How can I possibly make an impact? Right? Going back to that from a non awareness to being completely overwhelmed.
But what keeps you stuck in the middle where you can have agency is to recognize that other people are out there too, who are just as passionate, just as smart as you are, and they are taking their slice of the pie, and they are running with it. And so you can draw inspiration from them, they can draw inspiration from you. Um, we, we've joked, I've joked among to my friends that it's sort of the mutual admiration society.
Like, I love celebrating my friends as they would do their work in this world. Um, and they celebrate my work in this world, and that's how we keep ourselves going. And so I think that for people who are trying to make that difference in the world, but who are trying not to be completely overwhelmed and depressed about it, um, I would, I would just say, look, look for the mutual admiration society.
Look for the people who are in your life, who are also working on aspects of the problem. Maybe they're just a preschool teacher, uh, working with the next generation, which is the most important thing in the world, right? And I, and I, I mean, I use the word just very loosely here, because it's actually an immensely important job, right?
The people who are keeping libraries open, people who are getting healthcare, people, there are so many really important challenges. So you, as a person who has game, you gotta recognize other folks who have game too, and use that to sustain yourself, to keep that fire going so that you can lean into these problems and, and do what you need to do so that we all do what we all need to do. There's nothing I can say that's going to, uh, cap that all off better than exactly that.
So let me just thank you for taking your slice of the pie, you know, for my opinion. And you, anybody else, you know, who out there in the world who sees this. Yeah, take a little slice of the pie.
That's the best advice you're gonna get. You know, do one little thing in front of you. It'll make you feel better, it'll make somebody else feel better.
It might feed on itself. So, Yeah, no, it's, it, it's, it. That's how we do it.
It's one just step at a time. So thanks very much for the time. Thanks for letting me speak with you.
And to the folks out there who are listening or watching, uh, thank you for spending some time with us. Thank you, Rakesh. Thanks everyone.
We'll see you again on one of these episodes. Thanks for your time. Hey everyone, it's Alan Shimmel, CEO of Techstrong.
Thank you for joining us on our, I think it's eighth or ninth annual Predict conference. This is where, you know, some of us put our next out on the line and make some bold predictions about the year to come. And maybe sometime at the end of next of the end of this year, we will go back, revisit this and see were we crazy or did we know what we were talking about?
This is a keynote panel for Predict This year. We have a whole day worth of predictions coming from, from really smart people. And this panel's no, no different.
I've got some really smart people, much smarter than me to talk about what is the future for DevOps and DevSecOps? What are the big stories to watch in 2025? com 10 plus years ago.
DevSecOps burst on the scene, and a lot of it's become a real thing, as you're gonna hear from our guests. But there's also been a lot of changes, a lot of tumult in the last year, year and a half, as things like AI and platform engineering and software supply chain security have all kind of burst on the scene. And it's, it's pushing and pulling DevOps in ways we probably didn't imagine.
Our panel today is a great panel to discuss these topics. Let me jump in and introduce them to you, first of all, joining us, and we recorded this, and he was kind enough to come on late in the evening. His time is my friend Kobe Reiser.
Uh, Kobe is the CPO at check marks. Kobe, welcome. Why don't you give people a little bit of your background, though?
Yeah. Uh, thank you, Alan. Uh, really glad, uh, really glad to be here.
I'm the Chief Product Officer of, uh, of Checkmarks. I'm leading, uh, within checkmarks. I'm leading, uh, um, engineering, uh, product management and security research, uh, for the last four and a half, four and a half years.
Um, I am actually leading the, the, the building, uh, the development and building of our, uh, check marks one, uh, platform. Um, our legacy product is an on-prem product, uh, and we completely shifted to the cloud, and this is what I'm happily doing. Absolutely.
Thank you. Thank you again for joining us, Kobe. Appreciate it.
Next up is another friend of mine who's a frequent, uh, visitor on our tech drunk TV show. He's Nick Durkin Field, CTO Harness. Hey, Nick, why don't you tell, introduce yourself a little bit Very well, and thank you so much for having me on.
Genuinely appreciate it. And, uh, look, uh, joined Harness is employ number nine, almost eight years ago now. And so watch it grow from, you know, a small, uh, startup in its alpha stage to, to now helping the largest customers in the world solve secure software delivery and, and leveraging ai.
So, glad to be on here helping with this, uh, phenomenal panel. Fantastic. And thank you for being here.
Joining us is a newcomer to our tech strong TV and tech strong event family, but certainly her company is no stranger. It's GitLab. I wanna introduce you all to Sabrina Farmer, who's the Chief Technology Officer at GitLab.
And Sabrina, first of all, welcome. Thank you for joining us. I hope this won't be the last time you, you, this will be a good experience for you.
We'll see you often on Tech Trunk. Why don't you give people a little bit about your background? Yes.
Hi everybody. I am Sabrina Farmer. Um, as you say, I am the Chief Technology Officer at GitLab.
GitLab is the most comprehensive AI powered DevSecOps platform for software innovation. I have been here for almost a year now. Um, prior to that, I spent 19 years at Google doing essentially production engineering and also infrastructure engineering.
Um, really happy to be here, excited to talk about what's the future. Thank you. We're excited to have you here, Sabrina.
Thank you. Last but not least, my friend Paul Davis, who's field CSO at what a collection we've got Field CTO, field, cso, chief Technology Officer, and CPO. That's, that's impressive.
Paul, why don't you tell people a little bit about yourself. So, yeah, really humble to be part of this, uh, this panel. This is brilliant.
So it's a real power players here. Um, so yeah, I am, uh, former Fortune 10, CISO slash soc ir, but also as described myself, I'm a reluctant developer, uh, programmed and had software houses and built software in 12 different languages. So I'm sort of melding that with business risk and everything to help, you know, push forward the vision of a secure software supply chain using jfr and integrating with many of my colleagues here, as they say, to create that secure software supply chain.
So, very much sort of focused in that area. So, thank you. Thank you, Paul, and thanks for joining us as always, and thanks to our friends at jfr.
So, you know, guys, as I said, off camera or before we started, those who don't learn their lessons from history, or doomed to repeat it, 2024 in 20, the last half of 2023 has certainly seen some churn, upheaval, tumult within the DevOps DevSecOps space. Um, if I had to ask each of you, what were your, what were your big stories or big trends in 2024 that we think we should look ahead to going into 2025? What would you say they were?
Sabrina, you are the newcomer here, so I wanted to give you first, first dibs. What do you think were the big 2024 trends and stories that we need to learn from in order to look ahead? I think, you know, obviously the big topic, what everyone's talking about is ai.
And I think over 20, 24 people we're trying to figure out how to roll it out. What does it mean, what does it change? Everyone thought they needed it, but they didn't really know what to do with it.
And I think there was a lot of experiment, a lot of, we spent, um, and a lot of lessons learned. I think what I, I'm excited about mostly is as you come to the close of the year and agents become something that's more of a reality, you really see the opportunity to apply AI to improve how people work, right? And I think that it took us a whole year to get here, um, and to really start to believe that it was possible.
But, you know, we are seeing people look at not just how to develop code, but also how do you operate the systems that you're building. And, you know, having worked in production engineering for so long and, and AI for, you know, even longer, um, I think that to see this reality is really exciting and really trying to get people to really embrace it is, I think what we have to look forward to next year. Pat, what do you think?
Wow. I mean, ai, I think myself personally, it's, I'm starting to see glimmers of hope. Um, as a security person.
I'm a pessimist and paranoid. Um, so, you know, there are gaps there that I, that I, I wanna see better AI in the world of the actual supply chain as opposed to just the developer experience. Mm-hmm.
But I'm seeing now some of those coding agents helping developers and getting to a point where I can start to trust them. Um, but there's still a long way to go. And I think also from the perspective of a regulations, I think we're just starting to see inklings.
Europe is scary because they put teeth and regulations. Uh, I, I'll be blunt, I think we need to do that in the US as well. Um, 'cause there's accountability across the board.
But I, I'll pass it over to Nick. F Fred, I don't wanna ho the mic, but my Nick, for your perspective. No, I, I can, you know, I think you're right on the AI side, I think one of the things also we've seen is that we've seen people not unifying on singular platforms and getting away from point solutions.
And I think it was one of the things that we actually talked about last year, Alan, yeah. Uh, was this was gonna happen, that people are actually starting to unify on platforms and they're, they're getting away from, from, from grabbing all these point solutions. And I think that was something we actually saw.
And, and to good measure, right? We saw people actually gaining a lot of value, gaining velocity, adding security into this, because now it is one, one platform versus, you know, having a bolt and spending the time, you know, bolting together and writing the glue code versus actually being part of a platform. Kobe, That's check marks one, right?
Yeah, exactly. That's check marks one. We, uh, I fully agree, uh, we saw a lot of consolidation, meaning, uh, people are kind of, do not want to run point solution, have multiple vendors, uh, get themselves and their, uh, developers and users, uh, and security people, uh, confused.
We, we solve them. They want to, they want to consolidate. So we saw that we actually, this was one of the, uh, main objectives of check marks.
One, have a one-stop shop for, uh, application security testing. We also connected it with, uh, runtime in order to provide runtime insights. That's actually changing the way security is done on, on the left hand side in, in the pipeline, because you can give, uh, you can give runtime.
You, you can, you can provide runtime context and then give more actionability and confidence in the results, uh, because, you know, it's, it's running in, in right time. Uh, I also agree with Sabrina, like, ai, like 2024 was the year of, uh, okay, what do we do with ai? And, and, and I think that it's, uh, you know, I think that that, that, you know, a lot of our customers kind of came to us and say, okay, we know that we needed ai.
What, what do we do with it? So we kind of, uh, we kind of, uh, put in place, uh, um, a strategy of, uh, protect, um, and we're protecting the code, uh, mainly on, on the developers and side. We have integrations with, yeah, we, we have like integration with, uh, uh, with copilot and, and, and tools like that.
We also have a tool of our own, which, which actually provide best security practices as, as code is being written. Remediation, okay? We're talking about pipelines.
We don't want to run the, uh, we don't want to run the pipelines 10 times until we get the, until we get it right. So Remedi, AI, remediation advice, and also secure LLMs, this is more of a 2025 thing. Uh, you know, we see people going more and more into open source LLMs.
I think that this is going to be the next big thing in 2025, and people would like to, to protect that. And a lot of supply chain, by the way, uh, we invested quite a lot of supply chain, uh, especially in malicious, okay. Kind of the SCA part is, is kind of figured out, but the malicious part isn't, uh, isn't meaning let's say if I'm taking, uh, actually, if you use an open source, you're actually taking code from Stranger.
How do I know that this stranger didn't put anything malicious in it? So kinda, we invest a lot of research in that, and, uh, we're trying to bring this value to, uh, um, to, to customers. You know, what's interesting is, at least two of you up here, your companies are open source companies, right?
And so you're not getting code, you know, is it, is it from strangers? Yes. Is it from it, it's not so much from strangers, but perhaps untrusted sources, right?
Especially if you're maintaining a, a, a, a repo like Artifactory or something. But I wanted to return to AI for a second because that is the big, I think when, when people look back five years, 10 years from now, 2024 will be the year AI went big. It, it dominates.
But I think also when we look at 2024, it'll be the year that Gen AI went big gen ai, right? This whole, the idea of the co-pilot, and I think all of you have some sort of co-pilot type of functionality built into your products now or are coming out with them. But I think when we look ahead to 2025, gen AI may not be the big AI story.
I think, Sabrina, you mentioned it, a agentic AI may wind up being the real story, not just for 2025, but going forward, I totally agree with that. Yeah, I totally that I think that's really the power. I think, you know, the press likes to talk about the code, the developing the code, the code eight, right?
And I think that's true, right? But ultimately, that's still up to the software engineer, whether they accept it or not. I think it's really the agents that are gonna unlock the power and really help us find the next opportunity, free up your people so that they're really thinking about the next innovation that we should have.
I have to say, I'm pretty surprised at how quickly AI has gotten into the DNA of not just tech companies, but the average user. They're very comfortable playing with it. I think that's surprising.
I do think with large LLMs really made it accessible. And so I think we'll see this accelerate a little bit more in, in how people learn how to commercialize it. But really, 2025 is gonna be about the agents and how people put it to use.
And I think to Paul's point, like the regulation is coming, right? Compliance is not getting easier. You can't staff fast enough today because one, this technology's really expensive.
Um, and so I really think this is what's going to unlock the power of what AI can do for companies and the users. If I could Go ahead, Paul, I was just gonna say the, the, I as a geek as a techie, um, agentic AI is really, really exciting for me because I've always won. I, I, I have a personal assistant, people know me.
I wear little gadget on my shirt. This is my personal assistant. It's an AI agent, right?
But it, it's, I don't trust it. But the thing that I get scared about is, um, I think we could see us repeating the same mistakes we did with ai, with Agent ai. The same acceleration path is coming along where people have false expectations around it, have these grandiose ideas, and the reality becomes, oh, actually we need better controls about where I can't trust it.
I remember in one situation where I was doing automation and one particular customer shut down everything because they managed to do a self-inflicted denial of service. Mm-hmm. The agent ai, letting it make decisions by itself scares me.
Okay. I'm, it, I'm paranoid, but I, I think I, I, you know, as you said at the beginning, Alan, if we don't learn from history, we're gonna make the same mistakes. I think we need to apply the same disciplines we talked about, like, um, LLMs being weaponized, I'm marketing weaponizing LLMs sounds more exciting, um, malicious.
Um, but from the perspective of we are now realizing that the data scientists are developers and are being targeted, and that's the, the, the models, the ML SecOps model needs to align with the sort of the traditional SecOps. We also, and we are learning disciplines and stuff like that. And so I'm sure everybody in this call is saying, but I think we need to basically make sure we, we apply some discipline.
We don't set false expectations. And I don't know whether people agree with that, but I am a little bit concerned that I have high expectations, but I'm cautious. Others might read that Magazine and go, oh, let's do this.
And we lose control. I have a, I have a fun take on it a little bit. And, and by the way, like this comes from, you know, when Harness came out to the market, actually in 2018, it came out as the first platform using AI to actually remove the worst part of people's jobs.
And it wasn't about taking the best part. We didn't go after coding, because that's what people love. We wanna, after all of the things they hate doing, so babysitting, deployments, waiting for tests to run, all of those things.
And so what's interesting though is, you know, a lot of people talk about agentic AI actually mirroring human behavior. And I actually think this is, is actually opposite. I think we are actually going to mirror agentic behavior.
And what we're gonna do is we're gonna empower people to do what they love. I know that's the weird one, right? But the reality is each one of these agents dives down and does something specific, right?
But if we're focused that on what we hate doing, right? And all the things that, that, that, that, uh, are the things that we put off till tomorrow, let Theis do that, and now spend our time focusing on what we love. When you get someone who's locked in doing what they're passionate about and not having to focus on writing a Terraform or a groovy or like working on all the extra pieces, let them do what they're phenomenal at.
Now we're actually empowering our people, and it actually brings harmony amongst all this, as opposed to like having it be combatant. So I think it's, it's a huge future. It's a huge opportunity.
Um, and I'm really excited about what we're, what we're seeing in the agentic AI space as well. I think that the main challenge with Ag Agent AI will be to manage all these agents. Yeah.
Yep. You know, you'll, you know, you'll have like, you know, you have an LLNI dunno, tens, hundreds of agents, you know, each developer will put in what, what, what each one of them do. And, uh, what, what do we, the, the sequence of of of, of what, of what they're doing.
I think that this Is, uh, well, you, you're just thinking about one developer to many agents, or one, each developer has their own agents. So you have many developers. Why don't, when one developer has 10 different agents, right?
Mark Benioff, uh, spoke, I think it was just yesterday or last earlier this week. Well, by the time people watch this, it was a few weeks ago, you know, and he said, we're all gonna have all of these virtual employees, he calls them that will, you know, we may have thousands of them that are out there doing tasks for us. Some, some agents will be one trick ponies, right?
They'll do one thing, they'll do it pretty well, but they only do one thing. Other agents will be more general agents that are kind of alter egos for our digital presence. Other agents will be managing agents, you know, agent managers of other, I mean, the, and I, I imagine to yourself, just to troubleshoot an issue that comes from a customer.
Oh, yeah. I was thinking like Between all the, okay, what, what kind of, what, what the hell is going on here? Uh, but I mean, this is, this is, this is the world.
We could be looking at it and we need to, we need to put some order, some order in here right. To, to, otherwise it's gonna run amok. I dunno, if any, I think Kobe, oh, okay.
Sorry, Sabrina, go ahead, please, Todd. Yeah, I think Kobe makes a really good point, right? If you really wanna think about, um, unlocking the power, you should also think about the management of all of these things coordinating together and who's gonna create the controller for this, right?
And to Paul's point, like you still need the oversight, right? Automation has, you know, I've been automating reduction systems for a long time, and I can tell you, like, you can shoot yourself in the foot just as well as an agent could. That's not, that's not new, really.
I think it's just a new way to look at it. Um, but I think that Kobe's highlighting a really big important thing for people to think about as they start creating these agents and automating them, is you do need to figure out how do you coordinate all these things together. Um, I I, I agree.
I it's gonna be interesting, and I'm not even touching on the security implications of having agents running all over the place. This is why, this why I talked about control, not even secure. Yeah.
It, it, it, it is. But on the other hand, I mean the, the, the things that it opens up the, the possibilities, right? Are pretty exciting when you, when you really think about it.
And then, you know, and Benioff, and, and granted, he's a great marketer, right? Give the man credit where credit's due. He is one of the best in terms of marketing.
But when he refers to these agents, he interchangeably uses the word robot. Is an agent a robot? And is, is a robot something that does physical task or is it also just a digital robot?
Right? And, um, and, and once we start marrying AI to robots, what, what does that mean for our, the way of life, right? Um, I mean, it's, it it's a brave new world in many ways, right?
That, that this, And in some sense, you know, bots are kind of a same concept of agents. Okay? Kind of.
I did. I think that's what he's getting at. Yeah.
We, we, we did have it, like we did have these software bots, but I, I, I think that, that the kind of the options are, are kind of the, the, the limit is the sky right now because, because, because of the, uh, gen ai which is behind it, uh, Everyone could be, I, I think you're gonna see an actually, an interesting turn. I think you're gonna see people overuse LLMs and overuse agents where they're gonna use these massively expensive things that, that, that do very basic tasks. It's back to the times when like people's, you know, like using this massive amount of ai when in actuality you could just be doing math, right?
So instead of doing creative, uh, AI doing math, you Do automation. Well, you wind up is a bunch of wallies just fat, colorful people on chairs. And, you know, the ai, we can't do math without a calculator, right?
I, I, yeah. I, I think, I think people actually have to focus and realize, like, do we automate this? Do we do predictive modeling?
Do we use generative modeling? Like, and actually using the right tool for the job. 'cause I think right now, people are just throwing everything at, at Gen AI right now and, and calling it good, but in reality, that could be two lines of Java or two lines go instead of a massive LLM.
And I think that's, that's some of the challenges. Well, well, you remind me of, uh, uh, I, I've met, uh, one of the DevOps leaders a few weeks ago and told me, you know, my job is to watch as much Netflix as I can, meaning the automation dev should, should, should do everything. So, uh, what what you said about the, uh, agent AI reminded me of that.
Absolutely. So, I, I, I think, Nick, you said at the beginning, we should be using it for the, I, I like to say I want people to use to start using their brain, stop doing the boring stuff, right? Yeah.
Um, I think it's really fun that we're all saying the same thing, which is we need control. We need to set our expectations and roll these things out. I remember when I was on a manufacturing plant, there was this one robot, physical robot, and it could make seven different models of car, brands of car without changing anything.
It was so well-defined, but it still needed people at the end to just do the tweaks, to do the things like that. That was God, 15 years ago, right? I think we got the same thing with this stuff.
And I think I, I kind of reassured that we're all talking the same thing, which is we need to have oversight. We need set our expectations, because otherwise it will run rampant. But the trouble is we will see people that are, um, like, um, setting their expectations the wrong way, you know?
Well, I, I think that's the story. That will be the story of 2025, right? E experimentation in excess in, in experimenting with this stuff.
But you know what? Just like in the real world, AI is sucking up our conversation here. We have do have a couple of other things we need to talk about.
One of them, I wanted a big, you know, I think a big emergence in 2024 was sort of the, the legitimate legitimatizing of the platform engineering space, right? And in many ways, I think platform engineering, first of all, it's not replacing DevOps, right? Yeah.
DevOps isn't going anywhere. But platform engineering is a response to DevOps, I think, where DevOps wanted to bust down the silos and have us all working together. That was kind of the original intent, right?
And what one of the outgrowths of that though, is that we just started shifting everything left. Give it on the developer, put it on the developer, put it on the developer. As I mentioned earlier, things we put on the developer was security.
I think we found out that they care about security, but they're not security people, but they wanna develop secure code. Another thing we put on them is build your own platform. They don't wanna necessarily build their own platform.
You know what, maybe having a silo for platform builders is a good thing, as long as they communicate with all of the other stakeholders, developers, testers, security, SRE right? All the, the traditional disciplines in there. And so we saw this whole platform engineering kinda concept rise.
And I'm glad to see that in speaking to most of you, your companies are embracing platform engineering. It's no longer, uh, if us or them, it's, we're in it together. If you wouldn't mind let, well, Sabrina, we started with you last time.
I'm gonna start with Nick this time. Let's talk about how do you guys view platform engineering, especially going forward here in 2025? Sure.
I think you, you made a good point. And then the way we actually referenced it, when we talk about shift left, people started shifting, the workload left. And that actually wasn't good.
And what we actually want is we hire really smart people and wanna shift the information left, give them the information, give 'em those, uh, results. The security scans now, not when it's in production and they have to go, you know, get in a backlog, give them cost information now, right? Make sure they understand what that change the infrastructure's gonna do now, not a month later when it gets into production.
So it's about bringing that information at the right time. It's also about making it easy to do the right thing. And it's about making it hard to do the wrong thing.
And I know that sounds super basic, but it was easy to do the right thing. The cloud wouldn't exist 'cause we would've made VMs in our company, right? So you make those easy paths to get people to production, make it extremely simple, but you put policies in place to make sure that everything that you're doing actually meets your security, your compliance, your regulatory rules.
And as a platform, the goal here is actually to create harmony amongst all these teams. Like, although the folks on this phone are on the, on this call, we actually integrate with, right? Because again, you have to, and what we do, what we don't wanna do is we don't want to have security being the team of, no, they should be the ones empowering us by writing the policy.
We don't be finance to be the ones of no, and, and cost, you know, coming back with a big stick and carrot, empower them to write that, to make sure that you're, you're meeting your budgets, make sure the DevOps teams can write the pipelines, but we're all doing it in harmony. So now it's an actual platform to bring people together. If you're buying a tool that's a stick to use to beat a different department, it's the wrong tool.
It's not the platform that you need. You need something that brings harmony. That's, I know it might be like a little controversial.
Mm-hmm. And, and maybe a little hippie. No, I, I, that's genuine.
I Think it goes back to dev, that's DevOps, right? It's about working together, not necessarily that we all, all of us become DevOps engineers or DevSecOps engineers, but it's about, we all have our thing that we do, but we work together. So I I'm, I'm, I'm with you.
Rest of the panel. What do, what do you guys gals think about, about that? Uh, Sorry, did you wanna Go ahead, Kobe?
No, no, go ahead. So the, the thing for me is, is you're right, it is, um, bringing together the teams. We have a lot of siloed, I've heard feedback that the data scientists don't trust infrastructure people to stand up the infrastructure in, in production.
Partly because it's a brand new world. It's, it's in, it's not just standing up a server. We have to have additional tools to see drifting, uh, compromises, new attack forms, et cetera, coming in.
So the whole thing, we actually came with a term called every ops, because, you know, there's DevSecOps, DevOps, machine ops, ml ops, A, it just goes on. I know Saprina, you've got SRE, there's all this stuff and everything, but it rarely, I, I like it because I spend a lot of time working with customers, getting them to overcome those barriers and unify them. So we talked about security.
I'm sorry, Nick. I convert developers into security people, right? Okay.
Bad. In fact, I already disrupted. We were at CubeCon and this poor guy is sitting there, uh, we're having a drink.
And I said, you know, you're a security person. And he went, and by the end of, he says, I hate you, but you're right, because security is everybody's responsibility, but it's not the no thing. It's not the thing.
It's about enabling and understanding the implications. And we talk about streamlining that ability to create a, a, a, a visible view of everything that's going on, and understand, leveraging each other's expertise to create a pipeline that's streamlined, fast, secure, safe. I know, I'm I ideal, but that's what we want, isn't it?
Yeah. Right. Because that's what protect our big customers businesses.
But that model of everything, we gotta stop the silos. And I think for a lot of the leaders, the CISOs and the, the CTOs, the CIOs, there's gonna be change. Right?
Kobe, I saw you get a big smile on your face when Paul said that we've gotta convert them all into security people. Yeah. You know, we, we built a platform like in the first place to be kind of, to unite everyone, like security people, developers, uh, developers, uh, et cetera.
Um, kind of the, the use cases that we see now that, that kind of customers are interesting in is, uh, how to save DevOps people's time and also developers' time providing them a new experience through the platform. For example, uh, you know, there was a kind of a discussion if developers are security people or not, kind of, uh, through platform engineering, you can actually reach a situation, kind of that everything is being done automatically, uh, you know, automatically. And the developers is actually, uh, we just show him a, a Jira case and tell them, okay, you need to fix this, this, and this.
Okay. This is kind of a, uh, kind of a platform engineering together with, combined with, with a bit of, of ai. So kind of, it, it saves time.
It, it also provide a different experience and it also eliminates mistakes. So kind of, these are the main three use cases that, that, that we see now of kind of what kind of our customers and design partners want, want to use, uh, the platform engineering for. I think I agree with what everyone has said.
I think I have a little bit of a different take. So I think platform engineering has always been something that people would argue is a good thing. It was an ideal, but in reality it was an idealistic state, and it was never like a high enough priority to do because people were like, well, I'm gonna choose best in class, and then I'll figure out how to integrate these things together.
And, you know, so we'll delay that idealistic viewpoint. I think maybe what's changed on why platform engineering is such a highlight right now is that there is so much regulation coming. And so all of these integration points that we have done for probably the last decade, because we wanted to choose best in class, and that ended up with many, many solutions that we then tried to tie together.
If you have to do something like GDPR, all these integration points are now a risk to your business. And I think as business leaders, that's why platform engineering is such a buzzword right now and why people recognize that. Like you need to have an already existing integrated platform.
So as we meet our requirements for the different regulations and all the compliance that we are being held accountable today that maybe didn't exist five or 10 years ago, platform engineering helps you unlock that and actually reduces the risk for your business. And I think that's why it's so popular today, this collaboration. It's actually just an added benefit, much more so than the driver today.
Sabrina would, would you say, so I've had some people say to me, the platform eng, the platform engineering team is actually an oversight team. It's almost like a platform architecture where they've got the full visibility across the whole thing, and they're guiding and being the focal point for getting the groups to work together. Does that resonate or not with you?
I think that's how, um, people defined platform engineering in the past, right? They plug all these things together. You'd have your SRE team that SRE team would manage all of these different integrations, and then they were the oversights committee.
I don't think that is sufficient going forward, right? I think that breaks down very quickly. Um, I think that's very expensive way to do it.
And true platforms reduce your cost of ownership, right? And I don't, I think that's something we didn't pay attention to for a long time. But in the current market with the current cost of technology, that line item is actually, uh, not as, you know, available today.
As the businesses are growing and the market pressure is there, Does that mean that should be part of the office of the CTO or part of Dev, or, I don't know. I'm trying to work out how it fits Where it fits. Yeah, I mean, I think that varies by company.
Yeah. Right, right. Yeah, yeah.
In today's world where the CTO is often the CPO as well and vice versa, or the CIO is also the CISO. Yep. It really does vary.
com, our newest site, and we have a new show out there that actually check marks, is sponsoring what that's called, the Platform Engineering show. org, which has two to 200 to 300,000 members involved. So we're gonna be looking hard at platform engineering.
I think the other big story is it's not replacing DevOps, it's part of this whole continuum, right? Platform engineering enables DevOps, it enables DevSecOps, and then, and the only way it works is through open lines of communications with developers, with SREs, with DevOps teams, with security tips, right? And I, I think that's the important thing to remember, guys, we've got one more subject and not a lot of time to do it, and so I want to get it up there.
We, we touched a little bit on software supply chain and software supply chain security. So I, I gotta disagree. We haven't solved the open source security issue.
I, I, I think this is just like a, a snake that keeps coming up and biting us. Um, what makes you think 2025 will be any better? Or will it?
Paul, we haven't started with you. Let's start with you on this one. Wow, that's a hot one.
So, uh, so I mean, securing the supply chain, I think it's, it's, it's be it's, it's something that now that the executives are starting to realize is important, that they're accountable for, they, you know, just like, um, a friend of mine was saying about Sarbanes Ox, it is supposed to sign off, supposed to, so they're best to sign off on supply chains. It's gonna happen more and more. But I think, I think we're still getting there.
I think it's not, it's, it's, we still got a long way to go, I'm afraid to say, because, um, I'm still, we talked about streamlining, consolidation, getting, you know, that traceability. Um, and that's the thing for, for us to have a secure supply chain, we've gotta see everything as it traverses through, um, through its lifecycle of getting into production, um, securing that and getting everybody, you know, a platform engineering, uh, and sorry, Sabrina, I think it's critical and I think it does need to be a focal point. 'cause it's gonna be the one place that can push that story together with the security team to get that going through.
But in 2025, I'm hoping that we're gonna see some new tools, which will help with that consistency and our traceability. I think we still have a long way to go, because I'm still working with customers and organizations who are still struggling of trying, just, just trying to consolidate their tool sets. I spend a lot of time on streamlining exercises.
So from that perspective, I, I'm hopeful I see progress. I don't see all the answers being ai, I'm afraid. And in fact, in some conferences, I dunno if you've, it's almost like it's a groan.
Oh, somebody's doing a presentation on ai. It's like, not another one. You know what I mean?
But I think, oh, I live it. Yes. But I think standardized processes, maturity, actually tying it to better metrics beyond developer velocity.
Um, I always thought talk about the ripple effect. When something goes right, it has a beautiful effect across the whole organization. When it goes wrong, it has a, a ripple effect that hurts everybody.
It's not just dev, it's not social security, it's not just infrastructure ops or whatever. Everybody gets impacted. And I think I'm hoping, and yeah, and I'm gonna be pushing to get different metrics in place so people actually understand the impact and the positive nature of supply chain beyond just getting product faster onto into production radical, I'm sorry, fair panel.
I, I think that in 2025, uh, uh, we're also going to go further down, further down or up in the chain, meaning go into the source and assess how trustable it is in a, like, is the repo that I am taking something from, how healthy that is the con the contributors that are contributing to, to the open source that I'm trying to fetch how, kind of, how reliable they are. Because up until now we kind of, uh, we mainly focused, okay, I'm taking a piece of, of something, a piece of software. Uh, is that specific piece of software?
Is that, uh, is that, uh, a healthy one or not? I think that we're now going to go kind of one step down in, in the chain and, and, and again, and assess how trustable the source and the contributors to that source, uh, are we, we act have a, I'm not supposed to mark it, but we have a solution that acts like a gateway between the public repos to stop the bad stuff coming in. Um, the real challenge is getting the developers to say, go through this way, go through this way to the, to, to get you to your repos opposed to going direct.
Like, don't go home, install the package and then come back, sort of thing. So there's a lot of, there's a lot of challenges about that enforcement. And try to explain to the developer what you're gonna save them time, uh, save them time and money and let them spend less time fixing bugs and more time creative.
I mean, there are still people downloading the wrong log, four J two and Equifax. This is a common, how do you stop them from downloading old vulnerable bug ridden bad components. Sabrina, I Saw you shaking your head though.
I wanted to give you a chance. I mean, obviously, you know, we get hundreds of external contributions into GitLab. It's amazing.
People ask me a lot of questions about that. And you know, look, just because all of your contributors are internal does not mean you don't have risk, right? It's just sort of like if you had a firewall versus not having a firewall, if you're behind the firewall, you're safe.
That's not true. That's never been true, right? We've learned the hard way that that's not true.
I actually think sometimes the number of eyes who are on open source, right? And like checking for that and looking out for that is much more powerful than what you might get. Um, if you're all hidden internal, like having worked for a very large tech company for a long time, not all teams are the same.
They don't all ha make the same assumptions. So even when you're integrating inside your corporate walls, you have the same kind of risks. You need to be on the lookout for that.
You can get malware into your system unknowingly. What you, what you really need to have is like, you need to have policy controls, things that are enforced that are automatically looking for that. So if your employee does do it, it's not like, Hey, you broke the rules.
It's like, Hey, we just stopped what you did. That cannot be integrated into the system we are watching for where this is going. And that's, again, back to the platform.
Like the platform can enable those things for you. Yep. Because it plug, all your system is all plugged in together.
You can look at everything at the same time. And I think that's how you wanna think about it. It's not open source or internal.
The risks are the same for the both. One has consequences, right? Because you, they're your employee, right?
You have, um, you can do something about it, whereas the other person can't do anything about it. But actually it's the same problem in the end. I think, uh, I think this falls in that same thing that I was saying earlier, which is make it hard to do the wrong thing.
And if you put in all that policy in place, like you said specifically, like that's, that's why we built open policy agent into harness. So you can prevent any one of these, right? Make sure that every piece of code is scanned.
Make sure that every piece of code doesn't hold that MIT license. Make sure that it goes through the appropriate measures to block things like a log four J, but also make sure that it has salsa attestation. So it's gotta a bill of materials.
You make sure you're there, but you actually know that it's the actual artifact you're using so you don't fall into like a SolarWinds attack. Mm-hmm. And so now the actual attack vector has grown from just the artifact, just the code.
But now to your point, this is why the platform's so important. This has to be from source code, from the build, from the deploy throughout all the systems. And it's not even just about validating it, finding it, checking it.
You're going to have that zero day now how to remediate it. So that platform should know what you deployed on, which infrastructure with which configuration that were secrets to get you back. Or more importantly, as you update those, uh, artifacts or you, you change those libraries to promote them out to production again.
And so getting you remediated quickly so you don't struggle with those. And I think this is truly where when we start automating all those things, and it gets us back to where we were. Like, if we start taking that burden off of people, uh, and actually focusing them on the areas, now each one of those teams can do what they're great at you.
You empower it. And what's really scary here, you know, the government is actually the first ones who did this. Well, there was an executive order that forced this that said, Hey, you have to have a bill of materials.
You have to have an attestation that proves it. And this is one of the first times we've seen our US government actually leapfrog and actually leave the, the, the public sector behind. And we've been working with those enterprise customers on that specific problem for years now.
And what we're seeing this year, and I think as to get it back into predictions in 25, you're seeing now actually all these, you know, public companies catch up to, we need to have this secure. We need not only for our own software, but to your point, even the people that are our vendors, uh, the people that are co contributing. It actually, it, it, it builds trust amongst the entire community Agreed To Sabr to Sabrina's point that, uh, in internal, you know, internal code is also, uh, not, not secure.
Like we have a whole concept of what we call price packages. Not open, not not only open source package, meaning packages that were actually developed within, within the, uh, within the organization. And we treat, we treat them.
If we treat 'em the same, they're potentially milit Open source packages. Yes, Absolutely. Guys, we are outta time.
I wish we had, as I said in the beginning, twice as much, three times as much. We could talk about this all day. What ama an amazing, amazing panel.
Thank you all. Nick, Paul, Sabrina, Kobe, I, I honestly from the bottom of my heart, thank you so much. I hope you guys out here watching this have enjoyed this panel.
Um, all four of these companies and these folks are kind of frequent guests on Tech drunk tv, so watch for them throughout the year. Um, we have a lot more lined up here for you today on Predict 2025, including the winners of the DevOps Dozen awards we'll be announcing. So for on behalf of everyone and, and here at Techstrong, I'm Alan Shimel.
Thanks for joining us on this great panel. Stay tuned for a lot more here at Predict. Hey, have I got an AI agent for you?
You're watching Textron Gang. Hey everyone, happy Wednesday. Welcome to Techron Gang, man.
If you've got an AI agent, I got someone who wants to buy it. What a time to be in the AI agent broker business. Um, a lot going on around that.
Of course, a lot going on in the world in general, or a stock market is in correction territory. Uh, a lot of uncertainty and feared and loathing, uh, and a lot more than that. But we've gonna bring it to you all here, aren't tech strong gang.
Let me introduce you to our gang for this fine Wednesday he is out at sea where he's, he's a laptop short, but still able to join us through some premier hacking. He's our security expert, Chris Blast. Hey Chris, how are you man?
I am good, good to be here with you, Alan, and everybody else. I am in, uh, near Summerland key today. So we can look that up on your Google Maps and follow, follow the bouncing ball.
Where is Chris moving from Summerland key to West Texas? A newly hot data center territory as, as evidence on yesterday's gang show. She's our, uh, managing editor, Amanda Ani.
Hey Amanda, how are you? Hello. Good.
Happy to be here. As always. Good to see you.
Sharp too. Not fuzzy at all. Looking very sharp.
Amanda, uh, moving up from Texas. We'll head over to Colorado. We we're not sure he could see himself, but he could see us.
He is a DevOps expert, pretty renowned analyst and just all around Greek guy from down under living in Colorado, expat in Colorado, Andy Mann. Hey, Andy. How are you, Alan?
I am doing fabulous. You well, Mike. Good to see you again.
Good to see you. And then, uh, last but certainly not least, the, the dean in Harrison, our Chief Content Officer, Mike Ard. Good to see Mike.
No, no coal for the year. I don't mean Cole, I mean Derek, Derek Cole. I'm aware.
Tommy John. And I think we have to pay him and then he becomes a pre agent. So it's insult injury, right?
Um, no, I think we have one more year after that, but I read that the Yankees have a tremendous insurance policy on them. And this, you know, not that we care about the Steinbrenner's wallet, but yes, I think I'm going to go in the AI agent insurance business. That sounds like a great idea.
Yeah. I just wish I had some more AI agents to sell. Which leads us kinda to our first, uh, story.
Mike, why don't you take it away? All right. Well, AI agents continue to be all the rage.
85 billion, which sounds like a lot of money, but I think that's chump change in the AI era. But this company move works, helps you orchestrate your agents. So you ain't gonna, ServiceNow is maintaining its classic position here where it's helping orchestrate workflows.
And now we'll extend that to AI agents. Meanwhile, though, the Chinese are out there saying that they've created an AI agent that is, uh, much less expensive. Perhaps not as smart as some of the AI agents that are out there, but certainly not as costly to implement.
And then there's a report from SnapLogic talking about how large enterprises are all in on AI agents, and we're gonna invest about a million dollars on average over the next 12 months to build these things out. And it seems like there's a bit of a frenzy going on here. Andy, so what's your take on all this?
Well, I'm, I'm loving this for these businesses, by the way. Um, yeah, the, the move work was really move works. You gotta watch out, which, uh, you are on your Google there.
Uh, you might end up in workforce automation. It's not that one is agentic AI. For CRM, this makes a whole lot of sense.
For 20 or 30 years we've been trying to automate some of the simplest stuff within the customer service, C-R-M-I-T-S-N kind of space, right? Things like password resets or provisioning or anything like that. And automation is good, but intelligent automation's gonna be even better.
And so for ServiceNow, I certainly see this as a really positive opportunity to drive that level of automation further. They've got a lot of orchestration already built in. This is gonna work out really well, I suspect.
Look, it's gonna cause a little bit of concern, I suspect for some of its, uh, pariah customers who it may now compete with. Let's see what happens to, you know, for example, a a Microsoft, for example, using that software. Um, the valuation's pretty crazy, but I think you are right, Mike.
It is. It's just this is, it used to be a billion dollars was the entry fee to cloud. I think 2 billion might be the entry fee to, to ai.
Their last valuation was about 2 billion in June. I think 21 was their last funding round. Um, so that's a big number.
So we'll see whether there's actual ROI, but I love this because it's a good use case that's aligned to what they're already doing that gets them into a market they desperately need to start dominating. I'm, I'm excited to See how this all plays out. Go ahead.
I would say their, their valuation in 2021 had nothing to do with ai, not nut Next Sand Lake. I was on the streets in New York. Again, nothing to do with, uh, AI agents, right.
So, yeah. Is that 85? 85 billion.
Is that the value of the agent over and above that 2 billion mark that they got in 2021? I don't know, but it is a big fat number and I, I, I suspect it's not all based upon ag agentic ai. Amanda, I'd love to get your opinion on this.
'cause buried in that SnapLogic report that I mentioned was a, a question about whether or not the senior IT folks who were surveyed trusted AI agents as much or more than people. And when you added it all up, about 40% or so said they as much and 44% more said more. They don't trust the people that execute these things.
Um, you know, what's your emotionally, intellectually, how does that kind of grab you? Yeah. So this remains an issue.
Um, yeah, we're seeing more and more, uh, trust in AI and AI adoption. Um, so I think the goal, and I, I've had conversations with people, like right now we're talking about, oh, AI agents, like it's a thing. But I think the goal is in the future, that's just gonna be something that's integrated across everything.
It's just gonna be expected. It's just gonna be there being used by everyone, just, um, like other technology in the past. Mm-hmm.
I feel though, Chris, I don't know your thoughts here, but I feel like we still have to supervise these things and there's gonna be a tendency to maybe trust them too much. And we are gonna have to supervise these AI agents much like any other employee as far as I can tell, Right? Yeah.
The, the risk as always in outsourcing any security function is that you're not doing it right. So yeah, pondering that, uh, that, that, uh, trusting more or as much, and I think it's probably justifiable, right? Because we know how humans are, and this is a machine, you know, if it's wrong, it is probably predictably wrong.
But, you know, we, we have to have the human in the, in the process. Otherwise, you know, the, the, the agents don't know what to do. I mean, the, the risk of corruption, uh, of corrupted use needs to be on all our minds.
Um, because the, the benefits are again, just so large from a security perspective, having, and I like that we're actually talking AI agents. It's not Skynet. This is not the AI out there.
We're all using this technology embedding in things. What does that mean? Right?
A lot of good, uh, work we can do with security, but to your point, if we just start trusting and walking away, that's, that can't work out well. Alright, so, so Andy, let me walk you through this concept a little bit here. So we have all these AI agents, they clearly need to be observed.
They need to be tested, they need to be governed, you know, are, are we essentially about to create agent AI ops here? Oh, you, you from your word mouth to God's lips, I reckon, uh, God's ear, isn't it, Mike? Uh, and well probably 'cause the next step is obviously we need AI managers to supervise the AI agents.
Um, look, I actually think that over time this gets a lot easier. We've seen this before with automation, virtualization, and cloud, right? We've seen it with DevOps and straight through process.
We've seen it with things like RPA, yeah, trust, but verify, right? And absolutely, Chris, we've gotta have governance, compliance, risk management. Um, these things can go haywire and cause immense expense and trauma, um, in, in very short amount of time.
But this was always true of automation and orchestration as well. And so I just think we get to the point where we have to click that button that says, don't ask me anymore. Um, and that's the point where we're going to get to, and that's when the ent, ai ops manager will take over.
I think you're absolutely right, Mike, ag agentic, AI ops, it's an extension of where we've been with AI and ml and advanced analytics and automation and orchestration. This all comes together. It makes a lot of sense to me.
Do we think though, do we think though, eventually it is gonna be so ingrained that it's gonna just become more of a, uh, a standard cybersecurity roll in issue? And maybe to Mike's point, we'll just have insurance covering any issues, anything that goes wrong, we'll have a, a whole insurance industry for it. I, in, in short, yes.
Right. You know, this, this, You know, as you, you know, go back to that trust thing. We know right now, uh, uh, I, if you really wanna get into cybersecurity, you can get red teams and blue teams and green teams.
You can do a lot of work and you learn a lot of things you can advance a lot, right? But we always know, you know, there could be missing things, right? You get a vulnerability, uh, uh, uh, test, you'll find a certain amount and some left.
So just the sheer power of building this in, and to your point, insurance, yes. When insurance can get predictable, the insurance market has to, you know, has for centuries and will continue to exist. Cyber risk remains, you know, a a difficult to quantify risk.
This may, through sheer empirical power provide some of the basis for predictable insurance risk for the remainders. We've talked about this in the past, but I still don't understand how I'm gonna manage all these agents. And if every app has an agent and I've seen some agents out or apps out there that have six or seven agents that they're popping up in my screen.
And so do I need like a super agent at some point to reign in all these different agents? Is that how that's gonna play out? Alan, you have any thoughts?
Yeah, no, it sounds like a job for Kubernetes. You know, the ultimate orchestrator. I mean, I do think you will need a management tool, though.
A system, though. This is true. You know, we started with automation.
We started with scripting, right? So we had a library of scripts, then we had script managers, then we had library virtual code managers, right? Then we put it together and we started to do orchestration.
Um, then we started to do virgin control on our orchestration routines. This is where we're going. It makes sense.
It's not gonna happen straight away because we're in the middle of the revolution. We're excited. Everything is just a $2 billion entry fee.
We're gonna get there. But we absolutely gonna need some kind of orchestration manager, automation manager, AI manager, agentic manager. We absolutely will.
And I would just point out though, in terms of the risk, this is like another employee. Now, this is not just a tool. This is doing work.
And if our biggest risk is insider threat, which I believe it continues to be, why wouldn't agents be that risk? They're going to definitely need automated management. So I I have a theory.
I'm sorry. Go ahead, Chris. I was just gonna say, you know, Mike, maybe this, you know, the short answer is yes, and it's, when you say, I, I mean you, Mike, you know, I think, you know, the risk to you is not the same as risk to you performing your job.
The risk to you is you performing your job wrong and you don't have a job, right? So I think we all end up with that personal manager, you know, Arthur c Clark's last book there, you know, the, the, you know, the main character has a AI manager, right? And I think we get that.
That reminds us, me, Chris, the person to, when I go to work, make sure I have, you know, to Andy, to your point, that governance layer to do my job so that my real manager, my real ai, my personal ai, you know, keeps getting its monthly subscription paid. And I, and I live indoors. So I, I have a theory on this.
We're really early in this AI agent and everybody's rushing to market. 'cause they wanna have their own AI agent. Every app has to have their own AI agent.
Everybody wants to have an agent. And we all know that that is not practical. I think where we're going to, and, and most of these agents, by the way, are relatively one trick ponies.
They do one thing, right? They do one thing. They, they, they schedule this, they find that they, you know, they check a box.
Those agents are gonna become ephemeral, right? 'cause they don't need to be running necessarily all the time. It's just when you're going to do something, I think where we're, where we're going to go to is we are gonna have, Chris, you want to use the Arthur Clark, or not Arthur Clark analogy.
A an AI agent manager, an AI that manages our agents. And that manager spins up ephemeral instances of different, let's call them sub-agents, that do a particular job and then dissolve back into the woodwork, right? And that master agent, if you will, is smart enough to know when to spin up these alter egos that do it a particular thing so that we don't need to have two dozen different agents.
Someone like, and, and all of us are power users on computers. We work in tech, right? We don't need two different, two dozen different agents for the, the, I mean, how many apps do you have on your phone?
If you're like me, you have probably a hundred apps on your phone. So you need a hundred agents on your phone. No.
How often do you use those apps? So we're gonna have a master agent that spins up, ephemeral, subagents, disposable agents, one time use agents, Harry Shavers, whatever you want to call 'em, and they do the, they do the job and they go back and they go away. And the next time you need it, it spins it up again.
That's probably a gen two or gen three thing. Right? Now we're in the, I can't get enough agents mode, but that's gonna quickly pass too, right?
As we're overwhelmed with too many agents, All the marketing people are gonna object to the word master. But I get your point. One's gonna be kind of the senior head butler maybe, and the other ones are all kinda working.
Well, it's one agent to rule them off. But, but you won't have all of these agents, because I'm sorry, I'm begging a lot of noise. You, you won't have all of these agents because not all the tasks that these agents are doing are worthy of a standalone agent.
We let, let's call, I don't know if you want to call 'em subagents, ephemeral agents. Disposable agents. I, I don't care.
But you, you're not going to need an a, an a, a, a permanent agent for most of the things that the agents are doing. You, you spin 'em up and down. I, I wanna be clear about like, responsibility here.
So if the company gives me an agent to perform a task and the agent screws it up, is it my fault? Or is it the company's fault? It's still your fault.
Never the company's fault. It's always your fault, Mike. You've been here at text for how long?
It's always your fault. No, seriously. Uh, it, it's the same thing at the cloud.
The cloud gives you an instance that you spun up, but when, when your data gets breached, it's your problem, right? And, and, you know, then, so falling back on my, my legal background, an agent is an agent, hence the word agent creating agency. And when, when you in indu employ an agent, whether it be a digital agent or a people agent, you bear liability for that agent's actions.
So yes, it's your fault. So do we think we're gonna see more to that point? Do we think we're gonna see more upper level leaders getting insurance on themselves in the job?
Like that's gonna be something they ask for. If they take a CEO position of some big tech company, or they're using a lot of ai, they're gonna ask for insurance for themselves. Well, so like boards of directors and officers always already have e and o insurance for the most part, right?
Errors and omissions. Um, and that's pretty standard. I I don't know if we'll extend EO to include, um, um, agent or agentic malfeasance or what have you, but, um, or negligence.
But I mean, yeah, why not? So it might be an easier conversation though, because when something does go wrong and it's actually Andy's fault, I won't say it's Andy's fault. I'll say Andy's agent screwed up and therefore, you know, it's, it's, it's less tense conversation, right?
Yeah. It's it's gonna have to happen though, isn't it? I mean, the responsibility for automation has always been with the automator.
Um, and you're absolutely right, Alan. You talk about cloud, we think of cloud as someone else's computers, but ultimately you are always responsible for your own actions in the cloud or on premises. And we've seen this before as well.
Clouds providers go down and your general consumer is not angry at Amazon or Azure. They're angry at you for not providing the service you said you would. So look, it doesn't really matter where the agent lives or the responsibility.
We are gonna have to be responsible for RNA actions. 'cause we're gonna be responsible to our customers who will blame us anyway. So sure, take it on the chin, get ready, get insurance, maybe up your insurance.
I know where we went to cloud, a lot of people did up that e and o insurance. Alan, because of the extended risk, we're gonna face more extended risk with ai. Why wouldn't you up your insurance on that if you can?
Uh, it's 'cause we're gonna find breaches. We're gonna find insiders, agentic, breaches. This is just the start of all sorts of stuff, Alan.
Not just the management, but also the penetration vectors. I'm sorry, I can no longer provide you with insurance 'cause you're too much of a risk. So we're just pulling it, you know, What do you, Florida again, Mike, I I just gotta say Alan, with your ephemeral agents, has me thinking, and I think we probably need to start thinking about agents as a service, which on the one hand, you know, maybe an actual thing.
On the other hand, it's an acronym that, uh, once you pronounce it will be fun. Yes. Well, we'll, I I don't think we're going to go with that particular acronym, Chris, something tells me.
But, uh, we'll, we'll, we'll see where we go from there. Anyway, hey, we've spent 20 minutes on this one. We gotta jump to our next block.
Let's take a quick break here. Our Techron gang, we'll come back with more Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're moving on to talk about what's going on with Apple, which has, uh, indefinitely delayed.
It's, uh, upgrades for Siri and everybody's kind of scratching their head what that means. 'cause maybe Gen AI and Siri are incompatible, who knows? But Amanda, what's your take on what's going on here?
Yeah, it seems, we we're hearing about them a lot lately. They seem to be struggling with their AI offerings in general, kind of the last to come in with their AI offerings in the first place. So I wonder what is their approach?
Uh, why is it so different? Uh, I know it's gonna require more power. According to the article, what they're trying to do with their AI is gonna require more power.
That's part of the struggle. Um, but either way, they seem to have been struggling to compete in the AI offerings in general. And I wonder if we're gonna see this in phone adoption with their, their new phone if people are gonna be switching to another phone that already has all the cool AI features.
Mm-hmm. I wonder if this will also be an issue for other people like Samsung, because maybe to your point, there isn't enough horsepower on the phones to run this stuff locally, so it doesn't work as well as it should and can't make everything a call to the cloud. So have we reached some sort of, uh, technical impasse here that just needs another generation of processors?
Andy, your guess is as good as mine? Yeah, look, I think, I'm not a consumerist, I'm obviously an enterprise person, but from my perspective, what I see is, uh, they don't wanna repeat the Apple Maps fiasco, right? Um, they want to get it right.
If you remember when they brought out Apple Maps to compete with Google Maps, all of a sudden people were driving off freeways into, uh, driving off overpasses and into canals and so forth, right? Uh, apple can't afford to do that. Now.
They've gotta have trust. And you know, Amanda spoke about this earlier on today. You idea of trust in AI is super important.
And so for, at the consumer level, especially, you know, at the enterprise level, we can try things out and iterate and so forth and so on. At consumer level, we don't have a b testing. We buy devices and use them.
If they're no good, we throw 'em away and get something else. So I think they've gotta get it right. And I think there's a lot of challenges.
I think you're really spot on when you talk about the processing power on system. You know, I'm working right now on some things around voice control with local response using an LLM, and it requires pretty significant processing for some very basic command structures. If you want to get real ai, gen, ai, genetic ai, whatever it is into a phone, yeah, you're gonna have to do some pretty interesting stuff.
So maybe as they continue to develop their chip set, by the way they're N one M two, that these are amazingly fast and powerful chip sets doing some of that work on the phone. Maybe that's what we're looking for in the next year. So look, I'll, I'll remind you all that.
Siri doesn't just work on iPhone. Siri works on Macintosh, on your MacBook Pros on your Mac studios and, and there's plenty of horsepower on those machines. So I, I don't know if it's a horsepower issue.
I think the bigger issue, and I'll, I'm going to call the elephant in the room out, you know, the knock on Apple is, since Tim Cook came in, they, they, they're not innovating. They, quite frankly, they've been late to the AI game, quite frankly. They have been to other people's ai, Right?
They had to deal With open AI because they were using the open AI stuff. They've been, they out of the, you know, you look at the Mag seven and, and you know, in my mind, the big four of that Apple competes with its Apple meta Google, Microsoft or Big Five Amazon. I think Apple, apple has trailed the, their competitors there in a, uh, in native AI adoption.
And now they're trying to build it into Siri because look, Siri should have been in AI to begin with. We thought it was, I guess at the time. And, and they're stumbling with it.
They, they were late to market. They were late to do it. And they continue to have trouble.
Let's not, I don't blame this on horsepower. I, I don't, this is gonna take some innovation and some new, new ways of looking at things for Apple, doing different things, maybe outta their box and they're not doing it well. Plain and simple.
And I think it's a pretty interesting point, Alan. Um, you know, the, the, the idea that Apple is an innovator has always been, I'm gonna get in trouble in a moment now. Uh, 'cause I don't think they've been an innovator since, was really, I mean, the iPhone was late to the market.
Siri was late to the market. Um, they're already late to market with AI Maps was late to the market. Um, they spent a lot of money trying to do, drive self-driving cars, and then sold that unit off.
Um, I would posit that Apple is not designed as an innovator. Apple is designed as a fast follower and has been super successful in that mode. So that's actually a really interesting idea, Al and maybe not a bad thing for them.
Yeah, I, you know, I've, I've been, you know, we've been an Alexa household rather than a Siri household, you know, in, in this generation. And as you know, I mean, I, I run, I control lights and pumps and water cannons on boats and so forth. And I think there's, I think you're probably, you know, what you're saying, all saying about, uh, apple is probably true enough.
But Andy, what you're saying, you know, these devices, you know, what we talk about as AI these days, you know, in the last segment we're talking about agents, you know, what does it actually take? And whatever the answer is, I think, you know, our experience, and I know my experience with these devices over these last, what it five, seven years, what whatnot and our expectations now are that it acts like chat GPT. And it does not.
It's dumb as a stump. And if Google and Apple with all their resources can't make these devices, those of us who embedded smart, there's a reason. And then, you know, maybe it's incompetence at some level, but I think we we're going to have expected more out of our little local devices, um, than we do.
And we have, I think we're starting to expect that now, right? We're suddenly in the six 40 K world, it's like, you remember when we just had the six 40 k and we thought that was great? Yeah, I think that's the Syrian, uh, Alexa sort of infrastructure we have right now.
We're gonna look back as, as eight bit eighties, you know, stuff. Are you telling me that Apple Intelligence is the latest oxymoron? Is that where we we're going with this?
Big corporations and big governments and, you know, big organizations. I, I agree with Andy. It's hard for them to innovate.
You know, that's not really their job so much. Um, and they can screw up what remains their job. And I think they, they all do that with alacrity as well, but I think this is a more fundamental sort of shift.
Yeah. So Amazon is supposed to be rolling out a big Alexa upgrade. Speaking of Alexa, that has a lot more ai.
I think it'll be interesting to see if they fumble that one as well, or if that goes a little smoother here. And what's going on with that one? No, no.
I, I, here's what's gonna happen is that there'll be an, a dedicated Apple watch. It'll be a co-processor for the al workloads that will sit on your other wrist, and you'll have to buy both of them and the chain between them as well. Or is that optional a second?
You know, And your master agent will control it all. Maybe we needed, you know, we'll call him Hobbes or something from, from the Arthur movie. Uh, anyway, all right, well, you know, I, I think the Apple AI conundrum though is bigger than Siri.
And it's funny, as I said this, looking over at my iPhone, I'm getting those pretty, uh, neon lights sliding up when Apple Intelligence kicks in. It hears me talking about it. It doesn't zap me with a laser or something.
But, um, the fact is, apple, apple has to show their chops in ai. If you believe AI is where we're all going. And, you know, that's the, the, the, the indi indispensable element.
It's more than AI and Siri. It's AI and Apple. Where is it in the os?
Where is it in their apps? Where is it in everything they're doing? And, you know, apple Intelligence may not be an oxymoron just yet, but I don't see any, you know, I, I've been running the betas since they came out with this Apple Intelligence, and I run it on my Mac, I run it on my phone, I run it on my iPads, I run it on my Apple TV and my watch, and I haven't seen a damn thing.
So I don't know. Well, I, I think, you know, ball's in their court. And I wonder, Alan, if we're running up against use cases and validation and product market fit for Apple as well, right?
They've been running these ads about Apple intelligence for the longest time. Is no one getting excited at the use cases they're showing? Are they trying to find product market fit?
You know, Google's running ads as well for, you know, set up my appointments for me with my friends that, that go to dinner. I, we know that doesn't work. So maybe we're looking for product market fit.
Well, but, But so that's not just an Apple issue though, right? That is. So what is the killer app for ai?
Right? Question. I, uh, if give me funding and I'll find out, uh, this is the sort of thing I think right now You just gotta make an agent and you could get funding.
But what is the killer app for ai? This is something I, you know, I I, I did a YouTube shirt on this about a month ago now, where Mark Cuban says that the world's first trillionaire, if, if you believe that the Saudi family is not already trillionaires and everything else, um, that the world's first trillionaire will not be Jeff Bezos or Elon or, or, or Zuckerberg. But it'll be the person who makes the killer app for AI, uses it in a way we, we haven't quite figured out yet.
And they'll make a trillion dollars. 2 million views. So people are definitely interested in that.
I think they're more interested in trillionaires. Anyway, hey, let's take a break here on Techstrong. We're gonna come back and, uh, you know, how's your 401k doing?
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network.
Hey folks, we're back for Steve Lock, and we're gonna talk now about, well, what's going on on Wall Street. And as anybody has seen this week, it's been a bit bumpy, shall we say, at least in the wrong direction for a lot of folks. And who knows if it will recover or not.
But, um, Alan, what's your take on what's going on here? 'cause it seems like outside of the fact that we had some, you know, sharp downturns this week, the whole trend has been in the wrong direction. Like, again, I may never be able to retire at this rate.
My 401k is becoming a 2 0 2. Uh, so it, it's, it's, it's kind of scary. But, but here's the thing, right?
Market people tell you, you can't watch it day to day. You gotta look at trends you gotta look at, you know, and the traditional rule of thumb is if you have a fall of more than 10%, it's truly your correction. If you have a fall of more than 20%, it's, it's, it's a downright crash.
Well, you know, since our glorious leader came into power at the end of January, uh, we're in correction territory. And you know, this is from the guy who promised us that the eggs are gonna go down, your stocks are gonna go up, and everything else is gonna be willy-nilly and happy, happy. So Andy, does this kind of cycle perpetuate itself a little, little bit?
'cause you know, what happens is companies pull in their horns, then they stop funding new projects, and then it all starts to cascade downwards. And, um, do we need to take a pause here at some point? Or how do we, you know, what's your sense of how this might all kind maybe reverse itself?
Well, hope it does reverse itself. 'cause I'm not about you go, my, my 401k is becoming a 4 0 4 K, right? It's just investment not found.
Uh, this is definitely gonna have to correct at some point, but look, I don't know that this is fundamental. It's certainly not within tech stocks. Yes, there is some fundamental pressure around, uh, there's been layoffs in order to retool for ai.
There's been, we've seen from so many of the, from the fangs we talked about earlier, uh, and many, many others, there's been a lot of retooling to gear up to free up the opex for AI investment. And that's not insignificant. We're literally seeing hundreds of thousands of tech workers in Silicon Valley and related industries out of, you know, obviously New York, Chicago, Boston, et cetera, coming out in the streets.
And that's dropping spending power, it's dropping confidence. Um, and, you know, there's a lot of administrative action happening at federal level as well, obviously causing uncertainty. And, you know, you talk about, uh, administration leaders being comfortable with the word recession.
Uh, that's sort of a new attitude. So look, is it gonna correct? I it always does.
When will it correct is probably the big thing. And what will drive that correction? I don't think this is fundamental, certainly within tech, but there are some fundamentals that are not helping, uh, certainly in terms of employment and spending power of those tech workers.
Guys, this is not just tech. Let's be clear. This is not just tech.
This is the entire market. And, and here's the reason I, I've said this before I think on the show, but I'll say it again here. Do you know what the market hates the most uncertainty?
And do you know what the very definition of a Trump administration is? Chaos. Chaos is uncertainty.
And when you have uncertainty the market, it gets real skittish, real skittish. So it's not, yes, the, we, we get hurt in tech and, and look the magnificent seven, and, and the Nasdaq is such a big part of many of our portfolios for 401k and and so forth. But the fact of the matter is the entire market abhors uncertainty.
And you've got an administration that is the very definition of uncertainty, day to day, minute by minute, moment by moment. And if the market doesn't feel secure, it, this is the, this is what happens. And you know, hindsight is usually 2020, but unfortunately in this country, and during the last election cycle, people put on rose colored nostalgic glasses thinking about what the economy was under the first Trump presidency.
It sucked. It sucked. And then Covid really made it suck.
And we, we got outta there with net losses of jobs and everything else, and you could say what you want about Joe Biden and how old he was, but he, he did what he could to restore it. And it was handed over in a solid inflation back down to 2% joblessness down low, even the deficits, they were trying to do some things with, let's, let's, let's rip off the rose colored glasses and call it what it was. This man's a menace.
This administration's a menace. And that's, well, and this is what the market is reacting to, and it's a worldwide market. It's not just the us.
Well, and let, let me, you know, think through some fundamentals of that. 'cause you, you, you're, you're exactly right, Alan, you know that yeah. Markets are, as we know, the emotional I, how comfortable do I feel?
But there are reasons for that, right? And just, uh, I just wrote a piece this, uh, this morning about the, uh, some changes in ISACs, the information sharing analysis centers, and since the nineties have been public private centers to share threat intelligence and protect, you know, uh, uh, the nation in various ways. But in many ways it's by lowering the cost, you know, because, you know, the, in, in this case, the multi-state isac, which was con congressionally funded, um, has had its funding pulled.
And that most ISACs are the private sector. So, you know, you have members who are, you know, for-profit companies, they put pay some dues, you fund the whole thing. The multi-state isac, uh, was unique, you know, you know, past tense now was unique because it had the, you know, state, local, tribal, you know, if you're the mayor of some small town, you know, you can belong to this.
And you can find now that there's, for example, you know, active cyber threats that are attacking, you know, infrastructure that you have so you can plan in advance and save time, money, yeah. Yes, be more secure, but also, you know, reduce your, your odds of needing the insurance and the recovery. And if you are, you know, your traffic lights suddenly start working.
You had somewhere to go to say, Hey, you know, is that a thing? And find out, yes, it is a thing, here's what you do. So again, save time and money in getting your traffic lights working again after being hacked.
So we have this combination of uncertainty, as you say, which is a characteristic of the current administration and actual losses, you know, actual costs introduced into the systems that that cost, that take money away from other activity. Hmm. You know, what needs to be called out too though, is all these folks who are announcing layoffs and then attributing it to ai.
There's just no way that the AI has that advanced that yet to really justify that level of layoff. So what you're really saying is, yeah, AI has probably had a, some impact here and there, but we really just screwed up and we're hiding it behind ai. So let's just call it as it is.
I will say though, I just wanna point out that, as Andy mentioned it, the market always corrects itself, and eventually we always see an upward line over a period of time. So now I'm not a professional, you know, financial advisor, but I'm saying, bye bye bye buy at a low rate. Well, that, you know, that there's a theory of you buy on the dips and you buy low and your dollar cost average your stuff.
Here's the problem, Amanda, if we were all your age, I'd say Yeah, yeah, yipe, yeah, yeah. But when you look at the demographics of the us, more people are closer to Andy, Mike, Chris, and I, and those people don't have five to 10 to 15 years for this correction to correct itself. Okay?
And, and so it's important to them. And, and yes, when we look at the s and p market over the last, let's say the s and p over the last 80 or a hundred years, it averages, I dunno, 3% a year or three and a half percent a year, something like that. We had a great four years this, these past four years in the market for the most part.
Um, but I don't have 80 years for this to, to, you know, what you're losing now is really gonna hurt people. And then you have the twin concern of how are we gonna pay for our social security, Medicaid, Medicare, giving government, the current government here. And then, you know, things start getting real ugly, real quick, real ugly, like, take to the streets, ugly.
Take it to the streets. And I will say, Amanda, it's a good, it's a good plan. And Alan, you're right.
Buy on the dip. The one thing that I'd point out, you know, and certainly the oligarch are gonna do that, right? The one thing I'd point out is if you're not making the market, you are at the whim of the market.
So yeah, you can try and buy on the dip. Um, and you know, if you're gonna do that good on you, you could potentially make out really well, like you say, Alan, if you've got time to let that fester and, and grow, uh, over time and correct, but you gotta pick the right winners. And if you are not making the market, uh, I don't know that I'm gonna pick the right winners.
So what I heard Alan say is that the Textron gang will be broadcasting for the next 20 years, even if it's from a nursing home. Is that what you're saying? Well, No, what I think I may have to do is just upload my consciousness to an AI and, and it'll be out there in perpetuity, you know, earning money, whatever.
Uh, it's, it's, it's a scary thing. Look, you know, let's be realistic. Some of us have done well, but the majority of Americans, American, you know, who are invested.
I mean, pensions aren't, unless you're a government worker and there's fewer and fewer of them every day thanks to fielder's leader, um, you don't have a pension. You have, if you're lucky, you have a 4 0 1, a 401k if you're lucky, maybe your employer matches your contribution and so forth. And most 4 0 1 Ks, you're not playing individual stocks, you're making broad bets.
You're betting, you're investing in QQQ, right? The, the NASDAQ Index Fund, you're investing in an s and p fund, you're investing in, uh, in a small cap fund, a large cap fund, aggressive, you know, but they're general, they're funds. And, and so you don't, you, your, your betting, you are in this, you're in the zebra herd, right?
And you're, and your investment goes as well as the herd goes. You're not a maverick, right? And, and so as Andy says, if you're not a maker, you're a sheep and, and you're, you know, some sheep gets slaughtered.
Wait, it's only a matter of time before all those manufacturing jobs come back to the US and we're fully employed again, and consumer sentiment will just skyrocket back up again. Come on. That's right, Mike.
That's right. Yeah. I didn't know we were doing standup.
Oh, man, I haven't got my title five, Mike. That's right. Yep, yep, yep.
But look, you know, one thing about the market, it is fickle. It is fickle. Maybe, maybe you get a, some peace deal in the Middle East or, or the Ukraine and Russia situation.
Uh, I don't know. China does something. I, I mean, there are, you, you never know, right?
And, and that's part of living in chaos. So if you're sitting in Canada or China, and you know, and, and then as the president describes it, this is the biggest market and the most coveted market in the world. But if consumer sentiment is down, the market is down, people are spending less than you have less leverage to negotiate on tariffs, right?
So individually, it's a very big market. My fear is that Europe says, you know what? We don't need this.
We'll go do deals with China, Canada, Mexico, Brazil, we don't need this. We'll go do deals with China. It don't take much China plus to, to, it's not even close.
What's a big market, right? Because one could say China's a bigger market right now anyway, but you do China plus Europe, China plus Canada, Mexico, Europe plus Canada, Mexico and Brazil, Europe plus India. I mean, we're, it, it's a global, we are way past, this isn't 1953, and Eisenhower isn't the president where the US dominates the world market anymore.
It doesn't, we, that's not who, that's not what the world is anymore, right? Everyone in this world wants to live an American lifestyle in terms of being a consumer. And every, almost every country tries to give their people that consumer lifestyle, right?
They don't want to be America per se, but they want that American lifestyle, right? This, I, I've, Thomas Friedman in his flat Earth series writes about this a lot. And you know, there's a lot of countries in the world that are giving people that American lifestyle Plus.
And Alan, I'll tell you all from a global perspective, there's a reason I'm here. Uh, you know, I listen to my accent. This is my Colorado accent, right?
I've come a long way to be here and enjoy that American experience, right? I've sacrificed a lot and hopefully contributed some, but I will tell you, you're exactly right. But Asia especially is no stranger to China.
Australia has been trading with China as our most favored nation for the longest time. Uh, I believe for a long time China was actually our biggest export partner, especially around coal, steel resources. And you look at, uh, Asia Pacific generally, and look, this is a game of brinkmanship that could end up very, very poorly, exactly as you say, because start, I would start in Asia where there are already somewhere like two and a half billion people.
And the, you talk about markets, India, Indonesia, China, that's like half the world's population right there. And if they align with China as they already are, there's a lot of sentiment there, which is that China is a positive influence in the region. We don't always look at that from our perspective here in the States.
And so there's a game of brinkmanship that could end up very, very poorly already, China has been pressuring trading partners to not use US dollars. Now, if we start to talk about petro dollars and Euro dollars and, uh, petro euros or whatever you'd call it, ooh, wow. If America stops becoming the reserve currency of the world, then we're in a whole different perspective.
Wow. I've been, I've been tracking Bitcoin like few days. And if you think your portfolio's bad, just track Bitcoin the last week and a half.
Oh my goodness. I'm glad I'm Not long. Crazy.
Anyway, hey, we've gotta call a break. I, I'm not in the studio, as you could probably tell. I'm up in Orlando at Scon, and I've gotta go hear what's going on in the world of Linux and AI and Cloud Native.
So, um, I'll be here all week, but I'll be on the gang. I'm gonna try to get, Mitch is here with me, Mitch Ashley, we're gonna try to do a report from Ska for gang either tomorrow or Thursday. Um, but until then, Andy, always a pleasure.
Chris, great to see you smooth sailing as they say me, the wouldn't be at your back. Amanda, Mike has always thank you. Thank you for watching.
We've got a full Textron TV schedule immediately following, so stay tuned for that. But for now, this is Alan Shimel for Textron Gang, we're out. This is Textron tv.
Hey, everyone, welcome back here to Textron tv. Our next guest on Textron tv today is Ravi Circus. Ravi is the co-founder, chief product officer at a company called Sea Simplicity, SEEM, simplicity.
Hey, Ravi, welcome to Text Drug tv. Man, it's great to have you on. Hey, uh, nice to be here.
Thank you so much. Good. It's, uh, it's a, my pleasure.
Just fixing my button here. Um, so Ravi, let's start off with a little bit about you. If it's okay, I said you're the co-founder, chief product officer at Simplicity, but what, give us an idea of your journey.
Well, so I, I'm on the cybersecurity market for like 25 years. All, all of them is both of the very large side. But I also been a practitioner for many years in global 2000 companies.
My entire career is, uh, around network security, vulnerability management, cloud security. Um, some people know, uh, will say that I know to do only one thing, but I think I know it, I know it's very good. Um, so, so, so, yeah, and, and a lot of those experiences and, and learnings that, that I had over the last, uh, 20 years are the things that kind of, uh, make me co co-founder with my, with my team and, and build the simplicity, uh, as we are trying to, to solve old problems in, uh, in, in a new and very effective, uh, a very effective way.
Absolutely. You know, vulnerability management, remediation is something I've been involved with, Uh, since like 2003, I guess, is, you know, a company I had helped start, we came out with a product called vm, vulnerability Assessment and Management. Back then, Nessus was still open source.
Everyone had Nessus, you know, under the hood, you know, writing nale scripts or what have you. But what I remember back then reviewed was, it seems so natural to us that finding vulnerabilities in and of itself was nice, but not perfect. Remediating vulnerabilities was the game.
And even back then, we were trying to automate remediation, and we ran into such resistance, right? From people who said, whoa, whoa, whoa, whoa, whoa. You can't just patch, or you just can't shut something down, or you can't reroute something.
You know, we've gotta make sure it doesn't break something else, because what you break is a lot more valuable than what can be attacked via the vulnerability, right? And it was, it was frustrating even back then. I, you know, and I was there, it was a company I also helped co-found, and I was there for 10 years, and it was, or maybe eight years, but it was extremely frustrating.
Um, I'm, I'm sensing that maybe Simplicity has a, a new approach, a better approach that breaks down that resistance. Tell us a little about the company. Yeah, I, I think that's a great point.
I think that if you look at it, the security team is responsible to discover vulnerabilities, but they are not authorized to fix that. The people that can actually are add other guys, the, it, the developers, the DevOps, the operations, and the reality is that the security team sits in the, in the middle, responsible for the process, but cannot execute the process. So they are all day trying to, what we call drive remediation, or in other words, making other people work for them.
And throughout the many years of the practices of vulnerability management, everyone was too focused on the, on the security team as the one which are responsible for the process, rather than to be focused on the fixing team, or the remediation team are the one that actually executing the program. And one of the things that we did when we started Simplicity is actually go and interviews those DevOps guys, those it gals, those, the network operations guys, and kind of understanding their perspective to this process and how we can make it easier for them. Because if we will make it easier for them to fix, we will make it easier to the security team, the security organization.
And by doing that, we actually developed a platform that takes all that huge data, but prepare it better for remediation, make it available in the way that those remediation and fixing teams wants it, as opposed to, as opposed to just throw another list of big problems that only security team understands, uh, and expect them to do the most out of it. Uh, absolutely, and you're right, that that was the problem, right? It's the, you know, the, the responsibility without power, if you will.
And, and quite frankly, in the cloud, it was even worse at some level, right? Because, you know, some vulnerabilities were beyond your, your company's even ability to remediate. Um, yeah, I think Cloud, by the way, got it much worse because one of the things that happens on the cloud is that the modern cloud team actually got full stack responsibility for the networking, for operating system, for infrastructure, just not for security.
Those security guys keep their things close to their chest, don't tell anyone, and once every while they give you two vulnerabilities that you need to fix today, right? Of course, this will create the friction. So, so cloud and the dynamics and doing things much faster actually accelerate and, and accelerate this problem and, and, and increase the friction very between the teams very dramatically.
Absolutely. You know what, we've done a great job of what we call setting the table here, right? So tell me about simplicity.
So we in simplicity actually look at the problem as so, so traditionally people looking vulnerability management problem. As a prioritization pro, we actually look at this problem as a process productivity, uh, problem as a communication and collaboration problem. Part of it is to prioritize, of course, if you want to be more productive, more effective, you want, you want, you need to prioritize what you're doing.
But it doesn't end only there. We are, we have bit of platform that we call remediation operations that actually takes the data from all those different scanners, whether it's Code Cloud, on-prem, SaaS, ILT, all the different misconfigurations vulnerabilities, application security issues. We put them into the platform and using different technologies that involve, involve data scientists, that involve ai, that involve our best practices and knowledge.
We have better platform that the findings into solutions, into list, list of action items. And then we have built in a, a, a workflow platform and automated the, uh, um, dispatching platform that actually manage the security backlog for each of the remediation team. So no more, uh, Excel reports, no more PDF reports, no more status meetings, just a rolling backlog of security issues.
Just like you have your bugs, your features, you now have a backlog of security issues that manage itself. And you don't need to go through that motion of, here is a list of problems, go figure out. And, and, and next month we will review at list again to, to try and understand what we do.
We have reduced dramatically the friction, we improve the efficiency, and we are getting to a point that our customers report five or six times more remediation in the organization comparing to without simplicity, we are getting to the point where three or four people can handle remediation processes with team of 200 or with 200 or 250 development teams in a very large organization, which otherwise won't, uh, won't scale. Sounds like Nirvana, man. I, I, you know, uh, from back in my day, it's like, wow, okay, so what, what's the special sauce, if you will?
What, what is, what, what was the game changer here? So I think, I think there are a couple of, I think there are a couple of, uh, things that, that we are doing that, uh, that make the difference. There are three main things.
I think the first one is that we are transforming findings into fixes, into remediation items. 'cause many problems has the same solution. Many problems are effectively can be remediated better in, in the same way.
If you have a piece of code that have three other problem, three problems, it doesn't make sense to get one problem today, one problem next week, one problem the week after, because you will have to QA that piece of code three times. Actually, it'll be much more efficient to the organization to get everything together now, so you can test it only once. Uh, and in very similar way to vulnerabilities than others.
So what we are first doing is that we are transforming the list of problems into remediation items. That's actually reduced the amount of things that you handle in about 70 to 8% in average on our, on our customer, uh, base. Uh, the second thing is a set of algorithms, which we call find the fixer.
One of the ma main problems of, uh, of many organization is that you know, who you have a problem, you know where the problem is. You just don't know who can fix it. So we have developed, uh, different algorithms that use data science, uh, science a algorithms, a AI capabilities and, and, and other, and other techniques that actually allows us to look on data that already exists in the organization.
Activity, all tickets and what have you, to actually understand who is the fixer with the owner of that, uh, resource or asset. And then to be able to automatically assign that, uh, remediation item, uh, uh, to those. And, and the third part is really our, uh, our workflow engine, which actually makes the data remediation data available to each and every one of the remediation teams in any way they want.
Because if you will go to the organization today, one team will want tickets in Jira. Others will want alerts in in Slack. The third one will want an API to pull it to their platform.
And the fourth one will come and say, I want to log into a web UI and just mark all the things that I, that I did. And the security team cannot scale to deliver different type of remediation plans to each of the remediation teams. So they're going to the lowest common dominator, which is a spreadsheet.
So what we actually do, the third piece is our remediation router that actually make the data available. However, the remediation team, uh, wants to look at that. So less, uh, significantly less amount of findings, knowing who the fixer is, and make the data available, uh, for the fixing team in any way that they will want to help the remedi faster.
I love it. Good stuff. Now, of course, we live in a world where it just seems there's, every day there's more, more and more like the, the pace of vulnerabilities is increasing, right?
No matter how you want slice and dice, it, it just seems almost like shoveling sand against the tide, right? Where we, for every one, we fix three more pop up, right? How can you, and, and given this environment and all of the things you cited, everybody has their, every team has their own way of fixing these, their own way of approaching it.
How do you build a enterprise level efficient strategy here? I mean, obviously say use simplicity, but, you know, beyond using ity. So, so I, I think, I think, again, I think it includes many different things.
I think one of the things that you need to focus at is actually notice what my current risk, that actually how quickly I recover from it. So, to stop thinking on how secure organization is, but start thinking about how resilient my organization is. And as you start to thinking about resiliency, you can count and say, okay, though there are set of things of those, uh, tons of, uh, findings, of tons of vulnerabilities that want to be fixed within 30 days.
There is a bunch of things within a quarter, and there is a big backlog that, uh, maybe within a year and start to measure that the things that are important for you actually get into the hands of the right person at the right time and the, with the right data so he can fix it in 30 days. Then to make sure that there is a good plan for that quarterly things, and then, uh, what to do with all the rest when you're doing technology refresh. The, if, if you start, if you stop thinking about how do I protect myself now and start thinking about how I build organization, an organization that helped me to recover from a zero day that was identified right now, and I know that within a week my organization is secured against that, it actually make a, a big difference because you're starting to find the inefficiencies in the process, rather than a big pile of vulnerabilities that you try to sort what will be next.
And by putting process automation into place, putting a lot of prioritization into place, putting a lot of, uh, uh, uh, reduction of the noise into place, that what actually allows you to, to build the process that allows you to make sure that the organization is effectively fixing to measure that, to identify bottlenecks. And by doing that, uh, building a more resilient organization. Excellent.
Ravi, we're, we're, we're running all on time for people who want to engage with simplicity, first of all, a website. Second of all, like, how, how did they get started? Did they, you know, give us, you know, an on-ramp?
So, so it is very easy. Of course, you can go to the website, you can reach out to me in, uh, in LinkedIn or any of my, of my, uh, my team members. Actually, many of the customers just come and ask us, guys, let's, let's run it through our organization.
Let's see what the efficiencies that, that, that that we get. And we are going go, going with them for a quick test trial when we onboard three or four different, uh, data source of vulnerabilities or application security, cloud security issues. And almost immediately you see that reduction in 70 and 80% of the, of the findings.
Almost immediately. You see that one finding that you know about for two or three weeks that you don't, but you don't know who should fix it. And, and, and then, and suddenly simplicity is showing you what is that?
So, so I think that the, the best way is let us prove that, uh, that it works the way that, uh, that we claim it is. Okay, just engage with us, with us. We will be more than happy to do a test, uh, test run together, uh, with the customer, with his data just to prove that things can be better.
You can actually manage that at scale and not manually one by one through through a spreadsheet. Generally. How long does it take to get sort of a, a, a, uh, trial like that set up?
Uh, the, the setup is like, uh, two to three days, and customers are kind of playing with the platform for two weeks just to make sure that they see data over time. Uh, the, that they're getting their feedback. We are recommending the customer is to involve non-security people in the, in the, in that test Sure.
To get developers, those itto, DevOps into the place so they can give their feedback, they can see the benefits. So, so you should, so you could take technically to take two to three days, but organization usually play with the tool for two or three weeks just to get the, around, around it. It's very easy, uh, in that sense.
It doesn't require any agents installation or something more complex than that. So it is more, it is very easy to, to try and see the benefits yourself. Excellent.
Ravi, thanks for coming on Techstrong TV and TAG telling us about simplicity. Um, continued success. Are you guys gonna be at RSA conference?
Yes, for sure. Well, we'll be there live. Stop by, say hello.
We'll be our broadcast alley all week. I will, looking Forward. Alrighty.
Ravi Circus, co-founder, chief product officer at Simplicity. Uh, they might have cracked the nut on getting remediations for your vulnerabilities. io.
We're gonna take a break on text Drunk Gang. We'll be back in a little bit. This Is Text Drunk tv.
Hey guys, thanks for the throw. We're here with Nick Schneider, who's the CEO for Arctic Wolf, and they just completed their acquisition of Silence, which they picked up from Blackberry. And silence has been around for a while, but I'm gonna let Nick explain what it is and what it does and where it fits in their portfolio.
Nick, welcome the show. Yeah, thanks for having me. Uh, Michael, we're super excited about, uh, the acquisition and, uh, we think it's gonna be a, a monumental shift here for Arctic Wolf, but also for the market wholesale.
So exactly. For those that are uninitiated, what does Silence do and why did you guys decide to pick them up? 'cause Well, there's a lot of players in the security space.
Yeah. So Silence has been a, uh, pioneer in, uh, AI based endpoint protection, uh, and detection response, uh, for quite some time. Uh, they had and have a really strong customer base, a really strong, uh, channel ecosystem, uh, and bring with, uh, you know, the, the team a, uh, long track record of, of strong, uh, you know, technical acumen.
So we, we got a great team, a, a great product, uh, with global scale. And when you combine that with what we're doing, uh, at Arctic Wolf, uh, with regards to security operations, it gives us an opportunity to bring, uh, some additional prevention capabilities, uh, to our customers, as well as some detection and response capabilities, both from a product standpoint, but also a managed standpoint. And when you combine that with our broader security operations platform, we can provide, uh, multiple different outcomes to our customers, uh, in a way that is, uh, unique and allows them kind of choice with regards to what their security stack looks like.
We're kind of in a state of transition when it comes to cybersecurity, and I think a lot of people are trying to figure out how to navigate it. And we're going from a world where I think we had more tools than we knew what to do with, and now we're trying to get to something that feels like a platform, but the platform itself seems to be maybe augmented with managed services provided by somebody else. 'cause I can't find enough skills and talent to drive it myself.
So from your perspective, how does all this come together? Yeah, I, I think you're spot on. I think we've, uh, been living in a market that was built on, you know, thousands and thousands, quite frankly, of point solutions that solved for individual use cases or outcomes that a customer would look for in their soc.
Uh, and then you have some vendors that, uh, worked to kind of put those, you know, tools or capabilities together, if you will, at some level for the customer onto a platform, typically in a closed, you know, manner. Uh, and then you need to operationalize, you know, those tools and those platforms. Arctic Wolf has, you know, always focused on the operationalization of cybersecurity.
So we've built a concierge security team. We've built what we call our security journey to help customers kind of understand and make security work within their organization. And now we're adding, uh, some pretty significant platform capabilities along with tools or point solution capabilities natively, that will allow our customers to kind of get the experience that I think that they've expecting and been expecting from cybersecurity for quite some time, uh, which is just to make sure that their business is protected.
Make sure that they're aware of, you know, current or, or emerging threats and have the ability to respond, uh, to anything that might be taking place within their environment in an expeditious way. You know, time is the enemy, uh, in cybersecurity. And I think when you combine, uh, really strong tools and capabilities with an open platform and an open architecture, which allows customers choice and allows customers to be able to benefit from some of the investments that they've already made.
And then you couple that with a really strong, uh, security operations acumen, uh, and team, you, you can deliver these outcomes in a way that gives, uh, the customer better protection, uh, and better ability to detect and respond to threats than, than they would've had. They tried to put them together themselves. And one of the things we are seeing is that not only are the threats increasing in volume and sophistication, but it feels like the whole battle is now being fought in real time.
'cause to your point, um, if I'm five seconds makes all the difference in the world between the amount of damage that might be inflicted or not inflicted, how do I kind of align my defenses in that world where basically the attacks are happening faster and the defenses for that matter than any, uh, human can possibly keep track of? Yeah. That, that's where the marriage of the tools, the integration of those tools, both native and third party onto a, uh, platform that can, you know, give the customer real time visibility along with this operational expertise really comes into play.
And I think what you're seeing is a bit of an evolution of tools being combined on a platform, and then those platforms and tools looking to help customers operationalize the technology. And, uh, more and more, I think what we're gonna see here is that in order to do that appropriately, and in order to be able to respond to threats in a timely manner, or at the speed with which the, the threats are taking place, you're gonna have to have some marriage of human and, and technology or, or AI or automation kind of within your platform. And I think, uh, Arctic Wolf spending a lot of time and energy on that to deliver, you know, those outcomes to our customers.
Um, uh, but I don't think it's gone fully automated or, you know, or remains, you know, fully human. So it's gonna be this marriage of bringing the customer the right outcomes in the manner that allows, uh, them to get the response and, and detection, um, uh, you know, efficacy that they've been looking for, uh, while still have the ability to pick up the phone and, and talk to somebody if they need to. I remember when silence first came out and there was a lot of skepticism about ai, um, and yet it seems like our thinking about AI is evolving quickly.
So, you know, when you talk to customers, what is their attitude towards AI and how does it compare to today versus a few short years ago? Yeah, I think AI has been a part of cybersecurity, as you mentioned, for, for quite some time. Um, I think typically AI had been used, um, you know, more as a, a backend mechanism to automate certain workflows or processes or to perform certain tasks within the platform or, or the operation.
I think now you're seeing AI kinda rise to the forefront of the way in which a security operation operates, but also the way in which a security practitioner, uh, can make themselves, you know, more efficient or can give themselves the ability to detect and respond to threats in a more expeditious way. So, I, I think what you're seeing is certain levels of cybersecurity, uh, practitioners kinda leveling up, if you will. They're able to do tasks that maybe used to take a day in a matter of minutes or tasks that used to take, you know, weeks, uh, in a day.
So they're able to respond and react much faster requires, uh, that you're leveraging ai both for your ability to detect and respond, but also for your ability to kind of understand the threat and it's impact on your en environment and ecosystem. And I think as, uh, the automation and AI come together with human expertise, uh, you know, thankfully, I think we're gonna start to see, uh, that the defenders here, uh, are gonna have a, a, a better chance of, uh, protecting against, you know, what the attackers are throwing at them. Now, the, the converse of that argument is the attackers are also leveraging ai.
So, um, you know, both sides of the, uh, equation here are gonna have to stay on top of, uh, how to leverage ai, uh, from a, from a defensive mechanism, but also make sure that we understand how AI can be used, uh, offensively, uh, as well as, uh, understand how AI actually could potentially become a, a new, uh, attack surface as it, as it is starting to become, As you think about it, uh, clearly there's always been a lot of talk about whether AI was gonna take anybody's job, et cetera, et cetera, et cetera. But I cannot help but wonder, have we reached a point now where, as I look at it, I'm like, who would wanna do these jobs without ai? It's a lot of toil and a lot of manual effort, and it's not a lot of joy.
Yeah, I think, I think that's spot on. I, I don't view AI as a, uh, tool that is going to, you know, remove the need for cybersecurity professionals or expertise. I think what it's gonna do is remove some of that toil, um, from the day to day of security practitioners and take tasks that m maybe used to be a little bit more tedious, uh, and make them, uh, able to be completed in a much shorter time, which frees up time, uh, to do, you know, some of the more strategic cybersecurity work, which I think is what most security practitioners are, are after.
So, uh, I think the only folks that'll probably struggle a, a, a bit, uh, as a security practitioner are actually those that don't embrace ai. Uh, those that do embrace ai, I think, uh, will be at the forefront of, of, uh, the kind of new wave of, uh, security operations in the manner in which these platforms and tools kind of combine to provide these outcomes to, uh, to either their organization or the organizations that they're working to protect. So what's next for you guys?
It's still early in 2025, I'm sure you got a roadmap from the coming year, but, um, there's of course no end to competition in this space, but what should people be looking for from Arctic Wolf? Yeah, I, I think, uh, the silence acquisition is a good indicator of the direction we're headed. We've spent, uh, a lot of time, uh, and energy in building out our security operation.
Um, we have one of the largest, um, most sophisticated security operations in the world. Uh, we've built out a robust platform that's now operating at massive scale. You know, we're processing north of 8 trillion security events a week, um, with the magic being that our average customer is really only having to action, you know, one or two of those events per week, uh, through the magic of the platform and the work that our concierge team is doing.
And now we're starting to add, uh, additional native capabilities, uh, endpoint, uh, we just released a threat intelligence skew. Uh, we have some, uh, identity, uh, skews and, and products that have come to market recently on top of what we do for vulnerability management, you know, awareness training and incident response. Uh, and I think, uh, the market should expect to see continued evolution, uh, of kind of our core competencies, but also the addition of, uh, some additional capabilities to the Arctic Wolf platform.
What, what will be unique, I, I think about Arctic Wolf, uh, you know, other than obviously specific features or manners in which we engage with the customer will be, uh, our ongoing commitment to being an open platform for the customer base. So even though we'll have native capabilities, uh, on top of our platform, uh, we will still support, integrate with and leverage, uh, third party tools, even if they're aligned to some of the native capabilities we're bringing to the market. We just feel that that's really important, uh, as customers, you know, work to kind of shore up their overall security posture, that they're able to do that, you know, kind of on their timeframe, uh, with the budget and investments that they've already made being used, uh, but still be able to kind of work their way into a platform that that solves the broader, you know, cybersecurity challenge for them.
Organizationally, You've of course been around this block more than once, so what's that one thing you see organizations still doing that makes you shake your head a little bit and go, folks, we need to be a little bit smarter than that. Yeah. You know, um, there's still a surprising amount of organizations that don't, you know, bite off, uh, the low hanging fruit first, right?
So simple things like MFA, uh, patching, uh, are, uh, you know, training of employee base, uh, are still a lot of the common ways that a threat, you know, occurs. Obviously, there's more sophisticated manners in which threats occur, uh, but kind of the opening of the door still happens quite frequently with, with things that are very easily, you know, solved for. So, you know, we work hard, uh, as a partner to our customers to help them understand what their security posture looks like, uh, where they potentially have, um, some vulnerabilities, how they should prioritize those vulnerabilities, and then make sure that we work with them to ensure that those vulnerabilities are, are closed up, but also that we're able to detect and respond, uh, to anything that might be happening in their environment, you know, in real time.
Um, and I think, as you know, customers look to ensure that they're protected. Uh, I would always start, uh, with the basic blocking and tackling, um, and the low hanging fruit, uh, of the, the common, you know, threat vectors, uh, and then work, uh, towards the more sophisticated use cases, uh, as they kind of build out and shore up, you know, the, the, the foundation Folks you heard in here, there's no substitute for fundamentals, and hopefully it'll help from AI and platforms. More and more of that stuff will get automated.
Hey, Nick, thanks for being on the show. Great to be here. Thanks for having me.
All Right. And back to you guys in the studio. This is Textron tv.
Hello and welcome to another episode of the Inevitability Curve. My name is Chris Blas, I'll be your host for this. For and with me today is a good friend.
Rakesh, how are you doing today? I'm doing awesome. How are you doing, Chris?
If I was any better, I'd be twins, right? So as we were just talking about it, wow, that's amazing. In the green room, right?
We, you know, you've led a, a sort of fascinating life, and you and I worked together at Cisco in the late nineties, right? You were, they're just performing, I think, right? In 96.
Yeah. Yeah. I got, I I I, I came to Cisco in 96.
I was brand new outta college, and I got into this thing called cybersecurity before we called it cybersecurity. Right? Um, And yeah, no, it was, it was, it was good times though, the early firewalls, early hackers, early viruses, which seemed so quaint by, by, by our modern standards, but, but certainly seemed interesting and novel back then.
It really was. And as we're talking about in the green room, right? You know, there are these transitional times, and I think, you know, on our topic today, uh, you know, uh, emergency response, humanitarian efforts and so forth, um, we can get into your background, uh, in context as it makes sense.
But I think along with a lot of other things like the late nineties, you know, like the turn of the century for you and I, and cybersecurity and the internet as a whole, I think this period, I think the twenties, you know, going into the thirties is an extremely pivotal time. And I think this topic is another example. Yeah.
I think, I think we are, you know, there's the, the old saying about what may live in interesting times, I think we absolutely are living in interesting times and, but interesting manifests in many, many different ways. There are, you know, so many challenges, so many challenges that seem very, very big. But there are also a lot of opportunities.
And I think that one of the challenges of being a human in this time is being able to see both, to have the, the cognitive dissonance of saying, yeah, things are really, really hard and things are really, really challenging. But at the same time, there's all these really amazing things that are also happening, and to recognize that one does not cancel out the other, but they kind of coexist simultaneously. And how do you walk and hold those things at the same time?
Right? And, you know, uh, we'll see how the conversation goes, but I'd like to, you know, put this in the context that you and I are parents, right? And your kids are, are maybe 10 years younger than mine.
My kids are in their twenties. And, uh, we get a lot of, uh, people our age, you know, gen x Boomer type of folks, you know, typical for our age class. We do a lot of this kids these days stuff.
And I look at my kids and your, you know, people, uh, people at your kids' age, and I couldn't be happier, you know, like, Yeah, no, it, it, it's pretty amazing. And in fact, it, it, it was, it, it's something that's stunned me, and it's not just like my kids as an outlier, but what I've noticed is that all of my kids' friends, the entire cohort of children, uh, and you know, I have a sixth grader. I have a fourth grader right now.
And so in, in that age bracket, the emotional intelligence of these kids, uh, is just incredible. The the awareness and the empathy, um, the, the social emotional context that they are in right now is so much richer than what I recall having when I was that age. And my friends.
I think that there is something fundamentally different and, and honestly better about how they're engaging in the world and how they're, how they're going to be activated. And like, and, and it shows up not in big ways, right? Like, I'm not talking about like how the kids will go off and make some big change in their community or what have you, but I'm talking about like how they interact with each other, how they call each other out when someone is being unkind, how they, uh, reach for each other when someone's having a hard day.
There's just some basic human empathy stuff going on, and it seems to be, at least in my view, like it, it, it seems to be very cross-cut. It seems to be cross-cutting across gender and age and, and all of the little ways that we might, uh, put people into buckets or these kids into buckets. It seems to be very cross-cutting.
And, and I think there's something very fundamental going on, and I'm really, really excited to see who these kids are gonna be as adults and what sort of movement they're gonna make in the world. And, and I wanna put this out at the beginning because I think it's important to looking back and, you know, really understanding where we are and, and having a reasonable chance of, you know, forecasting some of the past we may take. But it's, it, it is that I think it, you know, we, we, you know, one of the things is that's, uh, that seemed like a problem to me from earlier in my life was population overpopulation, right?
54 billion people. 52 billion people, that's why a hundred million Americans would starve to death in the 1970s. And I'm four, right?
You know, when I was a smart little kid and I knew, you know, knew more about math than I should have, but that was just this horrible thing. And we have somehow, despite all the problems we've had between now and then, uh, we make 30% more food per person with 8 billion people than we did with three. And I think that applies in many ways to the topic at hand.
You know, the interconnectivity of all people, this whole internet thing that you and I and others have, have worked on, and the results of that, you know, leading to long-term potential, very, very positive outcomes. Um, that may not always be obvious as we're struggling through, you know, the stages, but I think come out a as we consider the whole thing. So let's let, let me jump back to the beginning.
Where would you like to start as we're discussing? What's is a root Sure. Uh, worth, uh, digging?
Well, I think, I think one of the main themes that I wanted to, to, to kind of share with you is the, the role of adaptation, right? So when you think about the, the example you just provided, the, uh, the challenge of feeding everybody. 'cause I remember a time when people worried about a population explosion.
And, and obviously we have something north of like eight and a half billion people on the planet right now. Um, what allows us to do that? And of course, we obviously know that there's sustainability challenges.
We obviously know there's carbon challenges and there's, there's challenges with that population. But what has allowed us to grow that population and keep people fed and seeing this extreme reduction in, in the worst kind of poverty, uh, especially since the year 2000 has been this notion of adaptation, right? So this notion of, hey, there are challenges that we are faced with, right?
Like, like when we say that we are optimistic, it's not from a place of being naive, right? Like, like we, we, we, we try and see with clear eyes what is ahead of us and what we are faced with, but then we say, what can we do about it? Right?
And I think that one of the big challenges that people have is they go from no awareness of a problem to suddenly the problem is so big that they can't, um, do anything about it, right? They can't do anything about it. And so what we wanna do is adapt.
We need to encourage people to have this value of adaptation and basically stop in the middle of that, of that, of that freakout and say, look, you're now aware that X is a problem, but before you say it's too big of a problem and I can't do anything right? Before you remove your own agency, you go from having no awareness to suddenly you have no agency, we gotta stop and say, what can I do about it? What can we do about it as an individual, as a community, as, as, as a tribe, whatever, whatever your, your slice and dice is gonna be.
And so I wanted to really spend some time and really dig into the notion of adaptation today, uh, with you and, and what it means for humanitarians, for public safety, for how we're going to deal with the inevitable crises that are going to emerge, uh, in, in this time, right? So we know that there's gonna be crises, but how do we respond to that, Right? And when we look back, I mean, you, you used the word tribe, and I, when I say look back, I mean all the way, I mean, we're here for a lot of reasons, you know, a lot of them happened a million years ago with among Homoerectus, you know, forming cultures and so forth.
And it is built into us. And in the last, you know, four or 500,000 years that, you know, we've been here homo sapiens, and there's a lot of repeating structures and, and social, you know, mimetics, you know, thoughts and, and social structures evolved just like genetics. And we're actually wired to deal with this.
You know, to your point, adaptability, you look back over human history, that is the defining trait. You know, that's what sets us apart from everything else, is that, you know, whatever the bloodies situation is, we end up figuring it out. And one of the benefits of, of overpopulation, of, of population that occurred to me early in my life was that, you know, back in the day, you know, 400 years ago, there were a dozen people, um, in the world thinking about things and talking about it in document.
I mean, you know, maybe a little, little bit more of that, but not much. But one of the emergent benefits of the internet that I always, you know, thought was pretty fundamental, was sort of a cliche by the early nineties, is just imagine if every human being is communicating, connected, uh, able to communicate with every other one, you know, and, and that one of the artifacts is you have 8 billion people with some possibility to contribute to an issue, whatever. It's, and just on aggregate, you know, is that more or less useful than having 10,000 dedicated people?
Quite often it's, it's much more useful. And this is taking, you know, historical heritage, cultural traits, you know, supporting each other and healing the communities and adapting to, you know, emergencies and disasters and climatic things. And we build infrastructure around it.
Um, so it built into us. And yeah, I, I think one of the really cool things about the internet, and, you know, i I come from that same time as you in the industry where we had a very sort of noble and almost utopian vision of what the internet was gonna be, where once we got everyone talking to each other, we would be able to solve so many of humanity's problems. And there is a truth to that.
Like, we've been able to solve a lot of problems. We've been able to connect, um, the, the, the gen genomic sequence for COVID-19 was sequenced and shared within 72 hours with research scientists around the world. And so literally, the mRNA vaccines from Moderna and from Pfizer were actually designed over a weekend.
Um, and, and they were, you know, this was a very short timeframe from detection of a disease to actually having a proposed vaccine candidate for those diseases in, in just a matter of days. And, and so, yes, the, the internet was fundamental in that, in, in enabling that kind of thing to happen. Um, you know, obviously I think where we might have missed a little bit was the idea that the harms wouldn't also be accelerated, but we have to take the good with the bad and, and try to hopefully make sure that there's more good than bad, right?
And we gotta think about like, what are the harms? How do we minimize the risks so that people can actually maximize the benefits? And I think that we have a much more nuanced and hopefully mature process or a mature landscape thinking about this now.
Um, and at least we're not approaching it with, with such a naive view. But I think that it's absolutely essential that we recognize how the internet has been a catalyst for, for empathy too, right? So, um, you have things like, like the ice bucket challenge where people wanted to raise money for als.
Yeah. And suddenly it became this meme that people were raising tons of money off of. And that wouldn't have happened without this kind of instant visual rich communications that the internet provides, um, in, in disasters and emergencies.
We see this from even like going all the way back to the Haiti earthquake in 2010, where we saw the emergence of crowdsource communities, people sitting at their home who saw the thing happening on television, and they really want, they, they, they had, you know, people naturally have empathy when they see something happening, when they see some crisis happening. Many people will just have naturally have an empathetic response. But the next challenge has always been how do we get them to take meaningful, impactful action?
And for most people who don't do what I do, who haven't done the things where they've been in disasters and emergencies, um, making meaningful action has, has been hard. But the internet enabled thousands of people to actually make a meaningful impact on the ground in Haiti, even if they'd never been there before, uh, back in 2010. And that's where we saw this emergence, you know, what, roughly 14 years ago, and now that's only continued today where it's kind of a given that when something happens in the world, entire communities of like-minded people can get activated to go do something about it.
And we see the decentralization of mutual aid, right? Where, where people will say, oh, hey, look, let's lift, do a fundraiser, or let's get equipment to somebody who needs it in this time of, and they don't have to go through those 10,000 people you referred to. They don't have to go through some central authority.
They have their own agency and they have empowerment to go do. And so they do. And let me use that as a, as the pivot to the present because, and to throw the last bit of the past in there, you mentioned the, the covid response, and I think it was the second or third, uh, company I sold a firewall to in 1992, it must have been, uh, was the Canadian, uh, cancer Society.
And as the person was driving over, you know, to our little office, to, you know, talk to me, I did a little gopher search and I said, I'm a can. I worked at a, a cancer agency. What do I, what's my day like when I'm searching for something?
I put in a couple of keywords, drilled down to something, pulled up a, a a list of, of fresh papers on a certain type type of, uh, cancer. And the person got got there and I said, uh, let me, I've, I've been thinking about who you are and how this matters to you. And I explained, you know, my thoughts that someone who works there drives in, they park, they go in, they, you know, looks at their files, they find out that there's a paper in the University of Minnesota, for example.
They contact the person there and asked it to be, you know, FedEx or whatnot. And, and the, the net was that was about correct. And I said, would it change anything if they could do this and click, click, click, and got to just that level.
Right. And you touched on that, and as you and I know in epidemiology and dealing with a disaster like, like covid Yeah. I mean, in 1991, the world would've been an ENT entire, the response would've been un, you know, not comparable.
But here we are today where we have things like agency ability, you know, just as, just as well in, in this sort of thing. You know, we're creating content here that'll go on certain channels and get a certain amount of views. We're not making, I love Lucy, we're not getting 78% of the American population to watch anything, right?
But, but we have thousands of of people who can take agency to make their own content for educational and purpose, try to make a living out of it, whatever it is. And in the same way we can respond to the kind of kind of disaster you've been involved with, including covid over the, over your, you know, current phase of your career. So I don't think anybody else could give us a better view under where we are right now.
Sure. And, and just by, you know, way of setting background, I've been doing humanitarian response and public safety response for about 30 years. And so my very first emergency I ever responded to was a wildfire in Los Angeles called the Old Topanga Fire in 1993.
Um, I used to have a lot more hair than I do now, uh, back in the day. And so certainly I've been able to see and witness and actually be a part of the transformation of modern emergency response, where it was very, very analog back in the day through sort of the nine 11 Hurricane Katrina timeframe, where people realized that without modern technology, they certainly couldn't scale to the level of these major emergencies, these catastrophes. And now we almost take it for a grant.
We almost take it for granted now that every crisis, now every emergency, every disaster has a digital component to it. Every, every emergency has some sort of connection to the internet. Now in 2024, we take that as a given, but certainly when I first started seeing this transition happen around 2001, 2002, that was not yet, uh, a given.
That was not, that was an unproven statement. And people would say, why do you need to bring the internet into this emergency? Why do people need cat videos right now?
You know, things like that. But the, the fact that it made emergency response more responsive, more agile, and more efficient was not yet proven. And, and so we take these things for granted now, but, but certainly for those of us who were around for the transition, um, we remember what it was like beforehand.
And certainly what's happened afterwards. And to be fair, I can't imagine responding to a modern, uh, crisis without having these digital tools at our, at our fingertips. I mean, I can't, I I can't see how we would be anywhere near as effective by going back to the way things were.
It it is, it's, uh, I'm thinking as you're talking there, I'm trying to map those two experiences because as you say, we both live through it. But it's one of those things that, you know, even though we were there, I can't picture it, You know, what, what exactly what we do, no. And, and, and to be.
Yeah. And, and, you know, the way I got involved in this, the way I got involved in emergency response and the intersection of emergency response and technology was actually on nine 11, where I was at the Red Cross headquarters in San Jose, California. And I was, um, you know, we were as a Red Cross volunteer, I was basically given a telephone, a pad of paper and a pen, and I said, and they said, uh, people are going to call in with missing persons, take their information down so that we can try and reunite them later.
And this is like maybe two or three hours after the towers had fallen. So, um, people were still very much in the emergency and shock mode of, of that day. And my very first call was a woman whose adult daughter had worked, uh, in one of the offices in the Twin Towers, and she was calling to report her daughter missing.
Um, and I remember very distinctly this conversation where she was describing her daughter in the present tense, you know, like, she works in such and such a floor, she works at this all organization. And then in the middle of this conversation and telling me about her daughter, she pauses and she started to cry. And she says, I guess she's never coming home now.
And suddenly she went from talking about her in the present tense to talking about her in the pa the past tense. So the realization that her daughter was likely dead and likely never coming home hit her on the phone with me. And I remember feeling really, really, really out of my depth in that moment, because I was just given a pad of paper and a pen, and I was being entrusted with this mother's hope.
And I knew that this late, this paper was likely gonna get lost. It was going to go nowhere. It was like, like this huge hope the of the worst moment of her life was being entrusted to me.
And I knew that it was, nothing was gonna come from it because we didn't have systems. We didn't have a way to make sure that there was closed loop communication or anything there. And that's just the system.
That's not even the human loss of losing her daughter. Right? Um, and so I felt a shift in myself in that moment where I, I wanted to really dive into this intersection of technology and emergencies, because this couldn't be the best that we could do.
Like, like, like this, the emotional burden of that moment. And even as I'm talking to you, I can still very distinctly remember this conversation. Imagine, um, has really stuck with me and driven me.
You know, it's, it's, it's that stuff and it's, it's individual human moments. We talk about disasters in the aggregate, but there really, you know, you, you may have a thousand people affected by a disaster and emergency, but what you actually have is a thousand emergencies. Each one unique, You know, and, and the, I know we're still talking about the past, you know, but, uh, but at that time, you know, the turn of the century, you know, folks may not quite understand.
Cisco was an interesting thing at the turn of the century. You know, we, you know, we built the, you know, huge chunks of the internet. There was a, you know, about that time you, you could say that there isn't anything on the internet that's not going across one of our boxes.
Our infrastructure is somewhere. And as you're saying, you know, the opportunity to do things with it, you know, the firewall team, we built this big massive thing, you know, so, you know, you know, myself and others are trotting around the world, and, and you get down to emergency response that I experienced at the time was more the cyber thing, right? You know, nine 11, you know, I, anyways, we, we, I have that.
But on the, on the cyber thing, you know, you get a vulnerability. You work, you know, put together an ad ho ad hoc team around the world and deal with it in real time and have it make a difference. And this is, I, I think, you know, why we can feel reasonably positive that, that the future is, is going to continue improvement on this.
We put these things together. We've been talking about, we have a generation generations growing up now who've lived with this, you know, all of their lives, who understand the downsides that have the ability to, to capitalize on the upsides, including the agency we're talking about that have developed, I, I believe generationally better understanding and empathy. You really just can't, you know, it's like not traveling, right?
You and I have traveled the world. The old cliche, if you don't leave your little town ever, which three, four generations before us, no one literally ever did. It's kinda impossible to understand it all.
Well, now we have ev most everyone on earth exposed to most everyone on earth. And for all the, the problems we see the opportunities to not only address those problems, but to our topic today, to respond incrementally and holistically to emergencies large and small all of our lives. You know, there's, you know, the mental health, you know, crisis as, as a population, but as you say, every mental health crisis is an individual, uh, disaster.
And getting support, the kind of score you need that really can help and solve all the problems, lower, nearly eliminate suicide and so forth, it is just so hard to logistically get. But it, you know, where we are today and looking forward, you know, whether, you know, any one of the, the, the crises and, you know, uh, emergencies we wanna respond to, I think we have better opportunities to solve all of it. Yeah.
And I think, I think one thing that you're, you're touching on here is really important. We, we talk about this term, poly crisis, right? Multiple crises that kind of intersect and catalyze each other simultaneously, right?
And this could be, uh, you, you can slice and dice this any way you want. So if you're thinking about it locally, you might think about the intersection of the fentanyl crisis, homelessness, and, and some of these other social and economic challenges that are in our cities, for example, and how they actually intersect each other, and how it's impossible to pull on one thread without pulling on all the other threads in the fabric, right? And so we, or internationally, when you look at the intersection of things like climate change and modern conflicts, where the destabilization of the, the ecology also feeds into reasons why, uh, shooting wars break out, right?
So, so again, you can't pull on one thread in those areas without pulling on all the other threads. And I think that like, one of the, the, the elements that is really, really interesting here is that people say, well, if I can't pull on one thread without pulling on all the other threads, why should I pull on just the one thread? And it's because you're actually having the second order and third order effects on these other areas.
Now, sometimes they can be good, and hopefully they are, sometimes they can be bad. And you gotta think about like how to minimize that harm, right? But I think that we have, like, one of the amazing things is just our language.
We talk about harm mitigation and harm minimization. We talk about intersectionality. And I gotta admit, when I first heard the term intersectional, like 15 years ago, I hated that word.
It sounded so academic. But what really connected it for me was when I realized that we do have intersectionality all around us and how we work. So I was on the ground during Hurricane Katrina, and maybe for the first time, I really realized how how we dealt with race and class in the United States really had a massive impact on who got helped, who recovered from the crisis better than others, right?
And, and all of these other factors. And so, um, we moved from this language of like, natural disaster. We now say like, things like, well, there are no true natural disasters, right?
The, the, the hazard may have been natural, right? The, the storm may have been a natural occurrence, but the human impact and the human response to that impact are choices. They're, they're, they're the product of agency at one level or another, whether we choose to acknowledge it or not, right?
So we might not realize we have agency, and so may neglect to take action, which has its own consequence, right? So, so not acting is, is an action. Um, but, but I, I think that we certainly have a deeper language for describing these re relationships, both the challenges, but also the responses and the opportunities.
And I think that it starts there, and I think about the fact that my kids, for example, when I was, when I was a sixth grader, I would hear, why do I need to study for history? Why do I need to study science? Why do I need, I'm never going to use these things, right?
Something to that effect. And, and I don't hear that with these kids, right? They, they immediately connect why they need to learn science with, um, climate change.
They learn history and geography because they need to understand. I mean, like, I think they understand that they're gonna come into this world and they're gonna be need needing these skills to navigate it. And, and I think that for those of us who are older and who are in our careers and who've been through these transitions and these crises, um, the, the real challenge is actually a little bit different for us, which is how do we be, how are we informed by our past, but not encumbered to our past?
And what I mean by this, I have responded to more than 50 disasters and emergencies, everything from, you know, nine 11 and Katrina to more recently things like Ukraine and Gaza and, and all these other things in between. So I've, I've done the range of natural and, and, and conflicts and all sorts of emergencies, and very, very easy for me to just sit back and say, well, back in the day, we used to do blah, blah, blah, blah, blah. But the trick of adaptation is to recognize that maybe what you did in Haiti in 20 20, 20 10 is not what Turkey needed in, you know, 2023, right?
Um, and that if you responded exactly in, you know, 2024, what you did in, in 2 0 0 9 or 2 0 0 5, or what have you, then even if it was an innovative back then it would be missing the mark now. So, so you wanna be informed by all your past and your experiences. But, but the start point is to realize that we are in new territory now.
We are in new territory that may looks like the old territory sometimes, but there's these other elements that are novel and that you are gonna have to feel and think and innovate your way into those spaces. And so, and I think that's a really hard thing to do because, um, you and I are both old enough to realize that there are a lot of grizzled old veterans of industry or of service who are very much locked into their, the good old days or the, you know, the big win back in the day, right? They're, they're, they're, they're funda, they're worldviews, fundamentally locked in the past.
And so while they may have been a rockstar hero in that moment, and, and deserving of all honor and, and recognition for those things, that doesn't necessarily translate to being ready for what is going to happen to tomorrow or three years from now. And so I think this notion of adaptation and having the plasticity of mindset to say, okay, challenge is fundamentally new. How do we think our way through it?
And how do we learn from the past, but like, don't just carbon copy and copy and paste from the past. Well, And I, I think we can look from the present into the future to in certain extents, you know, because, you know, my focus, you know, has stayed on cybersecurity all these years. You know, I've been very involved in supply chain and so forth, and, you know, just to, you know, sort of last, you know, call out to, uh, intersectionality, you know, Douglas Adams is right, you know, you know, Dirk gently and everything is connected.
The, uh, the, the what we need to have, the automation, robotics and AI driven manufacturing and so forth that we all, you know, sort of see in the not too distant future, um, is, you know, at, among other things, a supply chain software, supply chain intelligence, you know, uh, uh, IOCS bum and so forth, uh, intelligence artifacts, sharing system across entire supply chains that is accurate enough to actually be used, right? We need a, a attestation truth, you know, levels of, uh, um, lay layers of truth to just function, you know? And I think that sort of thing from that limited perspective has positive implications about the future.
You know, in our sort of cognitive security disinformation influence campaign, uh, world we're in today, it's easy to get despondent about that set of emergencies, but you can see some structures, uh, that are, they're gonna go down this path. And you couple with that, with, as you're saying, you know, our experience in dealing with, you know, the myriad emergencies we're already dealing with and the agency and, and, and, and open thinking of these generations coming up, um, it's hard to imagine that we won't, you know, not only continue to do as well, dealing with all these issues, but get a lot better at it. Yeah.
And I think, I, I think that one of the challenges that we have is just that we, we, we have to recognize that the old models may not serve us currently, and they may, they certainly won't serve us well into the future. And so the, the question I think that we all have to struggle with is what are the models that, you know, there's a, there's a saying that all models are wrong, but some models are at least useful, right? And so I think one of the challenges is how do we establish the models, the, the, the ways of thinking, the ways of acting that we know we're gonna miss things here and there.
We know that we're gonna miss things because we're humans, right? We're, we're not gonna get everything right. But how do we get the things that enable us to self-correct?
How do we get us the, the ways of thinking that enable us to say, okay, we got 80% of the way there this time, let's figure out how we can adjust and optimize to get that last 20%, or as close to hundred percent as we possibly can. And when I think about, um, the notion of adaptation, that takes many, many different forms. So I live, um, in a small island in Washington state, we have about 25,000 people.
We have a rural public safety community here. Now, historically in Western Washington, you've never had to really worry about forest fires before. Um, you know, it's the evergreen state.
It's wet up here. That's the cliche, right? It's Seattle, it's, it's all of that, right?
But the reality is that wildfire is increasing here, and it's not the same as it is in California and other parts of the United States just yet. Um, but it's certainly trending in that direction. And so what it's been really interesting to see here is that people who've been here for decades, people who have, uh, lived here for many, many decades, and who remember how it was going forward, they're really struggling to understand that the nature of the threat is adapting.
And so there's a lot of resistance to things like, uh, establishing defensible space perimeters. Like, why would I need to do this? If this is, you know, it's, this is, this is silly, right?
But the reality is, is that we have to start these conversations now because by the time that it's actually germane, if you, if you wait until the threat has fully manifested before you can actually deal with it, then you've already missed the key opportunity of, of mitigation, right? The, the key window of mitigation is seeing the harm as it's emerging and trying to get ahead of it, right? Trying to get ahead of it.
Um, and so this is a really key challenge for us as a local community, which is how do we respond to the challenges, the various challenges of climate change as a local community? Um, but I would say that it actually mirrors the challenges of, uh, you know, states and countries and, and as a humanity, how do we, how do we adapt to that? And how do we do it in a way that's fundamentally empowering, right?
Where we decentralize the power and we, we enable the lowest local action possible. And, and I think that this is a really interesting challenge we have to navigate, because every time we've ever had a big revolution, like the industrial revolution or the information revolution, or these other revolutions, um, a lot of times it's been at the expense of the majority of people for the benefit of few, right? It's been a transference of risk.
It's been a transference of power from, from the many to the few, which really enables that elite. But some of our challenges are they, they, they cross cut so horizontally that, that those models of, of, of transference just won't work. We, we have to enable local action, uh, because there just simply aren't enough elite people at the top to, to fundamentally deal with the scale that's necessary, right?
So, so, so the old models won't serve us. So how do we deal with these revolutions in our present and in our near future in a way that really empowers people to make change where they are and to make systemic change collectively? You know, I wish we had more time because we could unfold that all day long, and I, I, I am trying to, you know, think, am I gonna resist saying this?
Because, you know, lead to more con conversation, but honestly, the, the, uh, the, the, you know, the, what you mentioned at the end, you know, the whole thing about the elites and, uh, and the difference in, in al resource allocation, the very common topic, you know, ask anybody in my, in my kids' generation, it's, it's kind of forgivable when you look back over history because, you know, there have not been the resources, right. You know, for thousands of years to have any sort of, you know, the Victorians I think did a pretty good job, you know, where they exploitive and sort of terrible as a culture. Oh, yeah.
Uh, but I think we're getting to that stage where, just imagine if you could put those sort of resources on everyone that everyone had, you know, an, an assistant who actually knew them well and had their best interests in heart. And if it was an ai, you know, that everybody gets, I think maybe in a couple decades or, or less. But how does that change everything?
You know? How much would it help if, you know, if every person out there had the kind of support that, that what we call the elite today hat? Um, And I think that you, you, you know, where this finds is, we find this in our, you know, I, I, we'll just call 'em kindred spirits, right?
So, uh, a friend of mine is very much, she, she's the CEO of the executive director of a homelessness organization in Salt Lake City, right? And she and I talk, and she's super passionate about dealing with the unsheltered people in, in Salt Lake City. I work in disasters and emergencies, very different context, very different missions, very different geographies, and people that we're interacting with everything.
But when we talk with each other, what we recognize in each other is that the mission may be different, but the mindset is very much aligned, right? And so we, we, we, we, we refer to each other as sort of kindred spirits. Um, and, and, and what is really, really reassuring is to meet these people wherever you are, whether it's online, whether it's in your real life, however you may meet these individuals.
But to just say, to just recognize that, look, there are other awesome people working on other awesome aspects of the problem. Because if you, if you're able to understand the totality of the challenges that the world has, if you can actually just kind of hold some version of that in your head very quickly, you can recognize that, oh my gosh, everything is so big that I'm just one person. How can I possibly make an impact?
Right? Going back to that from a, a non-A unaware to being completely overwhelmed. But what keeps you stuck in the middle where you can have agency is to recognize that other people are out there too, who are just as passionate, just as smart as you are, and they are taking their slice of the pie, and they are running with it.
And so you can draw inspiration from them. They can draw inspiration from you. Um, we, we've joked, I've joked among to my friends that it's sort of the mutual admiration society.
Like, I love celebrating my friends as they would do their work in this world. Um, and they celebrate my work in this world, and that's how we keep ourselves going. And so I think that for people who are trying to make that difference in the world, but who are trying not to be completely overwhelmed and depressed about it, um, I would, I would just say, look, look for the mutual admiration society.
Look for the people who are in your life, who are also working on aspects of the problem. Maybe they're just a preschool teacher, uh, working with the next generation, which is the most important thing in the world, right? Then I, and I, I mean, I use the word just very loosely here, because it's actually an immensely important job, right?
The people who are keeping libraries open, people who are getting healthcare to people, there are so many really important challenges. So you, as a person who has game, you gotta recognize other folks who have game too, and use that to sustain yourself, to keep that fire going so that you can lean into these problems and, and do what you need to do so that we all do what we all need to do. There's nothing I can say that's going to, uh, cap that all off better than exactly that.
So let me just thank you for taking your slice of the pie, you know, for my opinion. And you know, anybody else, you know, who out there in the world who sees this. Yeah, take a little slice of the pie.
That's the best advice you're gonna get. You know, do one little thing in front of you. It'll make you feel better, it'll make somebody else feel better.
It might feed on itself. So, Yeah, no, it's, it, it's, it. That's how we do it.
It's one just step at a time. So thanks very much for the time. Thanks for letting me speak with you, and to the folks out there who are listening or watching, uh, thank you for spending some time with us.
Thank you, Rakesh. Thanks everyone. We'll see you again on one of these episodes.
Thanks for your time. Hey, everyone, it's Alan Shimel, CEO of Techstrong. Thank you for joining us on our, I think it's eighth or ninth annual Predict conference.
This is where, you know, some of us put our necks out on the line and make some bold predictions about the year to come. And maybe sometime at the end of, next of the end of this year, we will go back, revisit this and see were we crazy or did we know what we were talking about? This is a keynote panel for Predict This year.
We have a whole day worth of predictions coming from, from really smart people. And this panel's no, no different. I've got some really smart people, much smarter than me to talk about what is the future for DevOps and DevSecOps?
What are the big stories to watch in 2025? com 10 plus years ago. But DevSecOps burst on the scene, and a lot of it's become a real thing, as you're going to, to hear from our guests.
But there's also been a lot of changes, a lot of turmo in the last year, year and a half, as things like AI and platform engineering and software supply chain security have all kind of burst on the scene. And it's, it's pushing and pulling DevOps and ways we probably didn't imagine. Our panel today is a great panel to discuss these topics.
Let me jump in and introduce them to you, first of all, joining us, and we recorded this, and he was kind enough to come on late in the evening. His time is my friend Kobe Reer. Uh, Kobe is the CPO at check marks.
Kobe, welcome. Why don't you give people a little bit of your background, though? Yeah.
Uh, thank you, Alan. Uh, really glad, uh, really glad to be here. I'm the Chief Product officer of, uh, of check marks.
I'm leading, uh, within check marks. I'm leading, uh, um, engineering, uh, product management and security research, uh, for the last four and a half, four and a half years. Um, I am actually leading the, the, the, the building, uh, the development and building of our, uh, chip marks one, uh, platform.
Um, our legacy product is an on-prem product, uh, and we completely shifted to the cloud, and this is what I'm happily doing. Absolutely. Thank you.
Thank you again for joining us, Kobe. Appreciate it. Next up is another friend of mine who's a frequent, uh, visitor on our tech strong TV show.
He's Nick Durkin Field, CTO Harness. Hey, Nick, why don't you tell, introduce yourself a little bit Very well, and thank you so much for having me on. Genuinely appreciate it.
And, uh, look, uh, joined Harness is employee number nine, almost eight years ago now. And so watch it grow from, you know, a small, uh, startup in its alpha stage to, to now helping the largest customers in the world solve secure software delivery and, and leveraging ai. So, glad to be on here helping with this, uh, phenomenal panel.
Fantastic. And thank you for being here. Joining us is a newcomer to our tech strong TV and tech strong event family, but certainly her company is no stranger.
It's GitLab. I wanna introduce you all to Sabrina Farmer, who's the Chief Technology Officer at GitLab. And Sabrina, first of all, welcome.
Thank you for joining us. I hope this won't be the last time you, you, this will be a good experience for you. We'll see you often on text trunk.
Why don't you give people a little bit about your background? Yes. Hi everybody.
I am Sabrina Farmer. Um, as you say, I am the Chief Technology Officer at GitLab. GitLab is the most comprehensive AI powered DevSecOps platform for software innovation.
I had been here for almost a year now. Um, prior to that, I spent 19 years at Google doing essentially production engineering and also infrastructure engineering. Um, really happy to be here, here, excited to talk about what's the future.
Thank you. We're excited to have you here, Sabrina. Thank you.
Last but not least, my friend Paul Davis, who's field CSO at what a collection. We've got Field CTO Field cso, chief Technology Officer at CPO. That's, that's impressive.
Paul, why don't you tell people a little bit about yourself. So, yeah, really humble to be part of this. Uh, this panel is brilliant, so it's some real power players here.
Um, so yeah, I am a former Fortune 10 CISO slash soc ir, but also as described myself, I'm a reluctant developer, uh, programmed and had software houses and built software in 12 different languages. So I'm sort of melding that with business risk and everything to help, you know, push forward the vision of a secure software supply chain using jfr and integrating with many of my colleagues here, as they say, to create that secure software supply chain. So, very much sort of focused in that area.
So, thank you. Thank you, Paul, and thanks for joining us as always, and thanks to our friends at jfr. So, you know, guys, as I said, off camera or before we started, those who don't learn their lessons from history are doomed to repeat it.
2024 in 20, the last half of 2023 has certainly seen some churn, upheaval, tumbled within the DevOps DevSecOps space. Um, if I had to ask each of you, what were your, what were your big stories or big trends in 2024 that we think we should look ahead to going into 2025? What would you say they were?
Sabrina, you are the newcomer here, so I wanted to give you first, first dibs. What do you think were the big 2024 trends in stories that we need to learn from in order to look ahead? I think, you know, obviously the big topic, what everyone's talking about is ai.
And I think over 20, 24 people were trying to figure out how to roll it out. What does it mean, what does it change? Everyone thought they needed it, but they didn't really know what to do with it.
And I think there was a lot of experiments, a lot of be spent, um, and a lot of lessons learned. I think what I, I'm excited about mostly is as you come to the close of the year and agents become something that's more of a reality, you really see the opportunity to apply AI to improve how people work, right? And I think that it took us a whole year to get here, um, and to really start to believe that it was possible.
But, you know, we are seeing people look at not just how to develop code, but also how do you operate the systems that you're building. And, you know, having worked in production engineering for so long and, and AI for, you know, even longer, um, I think that to see this reality is really exciting and really trying to get people to really embrace it is, I think what we have to look forward to next year Panel. What do you think?
Wow. I mean, a, I I think myself personally, it's, I'm starting to see glimmers of hope. Um, as a security person.
I'm a pessimist and paranoid. Um, so, you know, there are gaps there that I, that I, I wanna see better AI in the world of the actual supply chain as opposed to just the developer experience. Mm-hmm.
But I'm seeing now some of those coding agents helping developers and getting to a point where I can start to trust them. Um, but there's still a long way to go. And I think also from the perspective of regulations, I think we're just starting to see inklings.
Europe is scary because they put teeth under regulations. Uh, I, I'll be blunt, I think we need to do that in the US as well. Um, 'cause there's accountability across the board.
But I, I'll pass it over to Nick. F Fred, I don't wanna hold the mic, but Nick, for your perspective. No, I, I can, you know, I think you're right on the AI side, I think one of the things also we've seen is that we've seen people now unifying on singular platforms and getting away from point solutions.
And I think it was one of the things that we actually talked about last year, Alan, yeah. Uh, was this was gonna happen, that people are actually starting to unify on platforms and they're, they're getting away from, from, from grabbing all these point solutions. And I think that was something we actually saw.
And, and to good measure, right? We saw people actually gaining a lot of value, gaining velocity, adding security into this, because now it is one, one platform versus, you know, having to bolt and spending the time, you know, bolting together and writing the glue code versus actually being part of a platform. Kobe, that's check marks one, right?
Yeah, exactly. That's check marks one. We, uh, I fully agree, uh, we saw a lot of consolidation, meaning, uh, people are kind of, do not want to run point solution, have multiple vendors, uh, get themselves and their, uh, developers and users, uh, and security people, uh, confused with, with all them.
They want to, they want to consolidate. So we saw that we actually, this was one of the, uh, main objectives of Check Mark one, have a one stop shop for application security testing. We also connected it with a runtime in order to provide runtime insights.
That's actually changing the way security is done on, on the left hand side in, in the pipeline, because you can give, uh, you can give runtime. You, you can, you can provide runtime context and then give more actionability and confidence in the results, uh, because, you know, it's, it's running in, in right time. Uh, I also agree with Sabrina, like, ai, like 2024 was the year of, uh, okay, what do we do with ai?
And, and I think that it's, uh, I think that that, that, you know, a lot of our customers kind of came to us and say, okay, we know that we needed ai. What, what do we do with it? So we kind of, uh, we kind of, uh, put in place, uh, um, a strategy of, uh, protect, um, and we're protecting the code, uh, mainly on, on the developers and side.
We have integrations with, yeah, we, we have like integration with, uh, uh, with copilot and, and, and tools like that. We also have a tool of our own, which, which actually provide best security practices as, as code has been written. Remediation, okay?
We're talking about pipelines. We don't want to run the, uh, we don't want to run the pipelines 10 times until we get the, until we get it right. So Remedia, ai, remediation advice, and also secure lms, this is more of a 2025 thing.
Uh, you know, we see people going more and more into open source LLMs. I think that this is going to be the next big thing in 2025, and people will like to, to protect that. And a lot of supply chain, by the way, uh, we invested quite a lot of supply chain, uh, especially in malicious, okay.
Kind of the SCA part is, is kind of figured out, but the malicious part isn't, uh, isn't meaning let's say if I'm taking, actually, if you use an open source, you're actually taking code from stranger. How do I know that this stranger didn't put anything malicious in it? So kinda, we invest a lot of research in that, and, uh, we're trying to bring this value to, uh, um, to, to customers.
You know, what's interesting is, at least two of you up here, your companies are open source companies, right? And so you're not getting code, you know, is it, is it from strangers? Yes.
Is it from, it, it, it's not so much from strangers, but perhaps untrusted sources, right? Especially if you are maintaining a, a, a, a repo like Artifactory or something. But I wanted to return to AI for a second because that is the big, I think when, when people look back five years, 10 years from now, 2024 will be the year AI went big.
It, it dominates. But I think also when we look at 2024, it'll be the year that Gen AI went big gen ai, right? This whole, the idea of the co-pilot, and I think all of you have some sort of co-pilot type of functionality built into your products now or are coming out with them.
But I think when we look ahead to 2025, gen AI may not be the big AI story. I think, Sabrina, you mentioned it, AG agentic AI may wind up being the real story, not just for 2025, but going forward. And I totally agree with that.
Yeah, I totally that I think that's really the power. I think, you know, the press likes to talk about the code, the developing the code, the code aids, right? And I think, think that's true, right?
But ultimately, that's still up to the software engineer, whether they accept it or not. I think it's really the agents that are gonna unlock the power and really help us find the next opportunity. Free up your people so that they really thinking about the next innovation that we should have.
I have to say, I'm pretty surprised at how quickly AI has gotten into the DNA of not just tech companies, but the average user. They're very comfortable playing with it. I think that's surprising.
I do think with large LLMs really made it accessible. And so I think we'll see this accelerate a little bit more in, in how people learn how to commercialize it. But really, 2025 is gonna be about the agents and how people put it to use.
And I think to Paul's point, like the regulation is coming, right? Compliance is not getting easier. You can't staff fast enough today because one, this technology's really expensive.
Um, and so I really think this is what's going to unlock the power of what AI can do for companies and the users. If I could Go ahead, Paul, I was just gonna say the, the, I as a geek as a techie, um, agentic AI is really, really exciting for me because I've always won. I, I, I have a personal assistant, people know me.
I wear little gadget on my shirt. This is my personal assistant, it's an AI agent, right? But it's, I don't trust it.
But the thing that I get scared about is, um, I think we could see us repeating the same mistakes we did with ai, with Agent ai. This same acceleration path is coming along where people have false expectations around it, have these grandiose ideas, and the reality becomes, oh, actually we need better controls about, we can't trust it. I remember in one situation where I was doing automation and one particular customer shut down everything because they managed to do a self-inflicted denial of service.
Mm-hmm. The agent ai, letting it make decisions by itself scares me. Okay.
I'm, it, I'm paranoid, but I, I think I, I, you know, as you said at the beginning, Alan, if we don't learn from history, we're gonna make the same mistakes. I think we need to apply the same disciplines we talked about. Like, um, LLMs being weaponized, I'm marketing weaponizing, LLM sounds ho exciting, um, malicious.
Um, but, uh, from the perspective of we are now realizing that the data scientists are developers and are being targeted, and that the, the, the models, the ML secs model needs to align with the sort of the traditional SecOps. We also, and we are learning disciplines and stuff like that. And so I'm sure everybody in this call is saying, but I think we need to basically make sure we, we apply some discipline.
We don't set false expectations. And I don't know whether people agree with that, but I am a little bit concerned that I have high expectations, but I'm cautious. Others might read that magazine and go, oh, let's do this.
And we lose control. I have a, I have a fun take on it a little bit. And, and by the way, like this comes from, you know, when Harness came out to the market, actually in 2018, it came out as the first software platform using AI to actually remove the worst part of people's jobs.
And it wasn't about taking the best part, we didn't go after coding because that's what people loved. We went out after all of the things they hate doing. So babysitting, deployments, waiting for tests to run, all of those things.
And so what's interesting though is, you know, a lot of people talk about agentic AI actually mirroring human behavior. And I actually think this is, is actually opposite. I think we are actually going to mirror agentic behavior.
What we're gonna do is we're gonna empower people to do what they love. I know that's the weird one, right? But the reality is each one of these agents dives down and does something specific, right?
But if we're focused out on what we hate doing, right? And all the things that, that, that, that are the things that we put off till tomorrow, let Theis do that and now spend our time focusing on what we love. When you get someone who's locked in doing what they're passionate about and not having to focus on writing a terraform or a groovy or like working on all the extra pieces, let them do what they're phenomenal at.
Now we're actually empowering our people, and it actually brings harmony amongst all this, as opposed to like having it be combatant. So I think it's, it's a huge future. It's a huge opportunity.
Um, and I'm really excited about what we're, what we're seeing in the agent AI space as well. I think that the main challenge with ent, AI will be to manage all these agents. Yeah.
Yep. You know, you'll, you know, you will have, like, you know, you'll have an LLNI dunno, tens, hundreds of agents. You know, each developer will put in what, what, what each one of them do.
And, uh, what, what do we, the sequence of, of, of, of what, of what they're doing. I think that this Is the, well, you're just thinking about one developer to many agents, or one, each developer has their own agents. So you have many developers.
One happens when one developer has 10 different agents, right? Mark Benioff, uh, spoke, I think it was just yesterday or last earlier this week. Well, by the time people watch, this was a few weeks ago, you know, and he said, we're all gonna have all of these virtual employees, he calls them that will, you know, we may have thousands of them that are out there doing tasks for us.
Some, some agents will be one trick ponies, right? They'll do one thing, they'll do it pretty well, but they only do one thing. Other agents will be more general agents that are kind of alter egos for our digital presence.
Other agents will be managing agents, you know, agent managers of other, I mean, the, and I imagine to yourself just to troubleshoot an issue that comes from a customer. Yeah. I, that was between all the, okay, what, what kind of, what, what the hell is going on here?
But I mean, this is, this is a, this is the world. We could be looking at it, and we need to, we need to put some order, some order in here, right. To, to, otherwise it's gonna run amok.
I don't any, I think Kobe Okay, sorry, Sabrina, go ahead. Please Talk. Yeah, I think Kobe makes a really good point, right?
If you really wanna think about, um, unlocking the power, you should also think about the management of all of these things coordinating together and who's gonna create the controller for this, right? And to Paul's point, like you still need the oversight, right? Automation has, you know, I've been automating production systems for a long time, and I can tell you, like, you can shoot yourself in the foot just as well as an agent could.
That's not, that's not new really. I think it's just a new way to look at it. Um, but I think that Kobe's highlighting a really big important thing for people to think about as they start creating these agents and automating them, is you do need to figure out how do you coordinate all these things together.
Um, I I, I agree. I it's gonna be interesting. And I'm not even touching on the security implications of having agents running all over the place.
This is why, this why I talked about control, not even secure. Yeah. It, it, it, it is.
But on the other hand, I mean the, the, the things that it opens up the, the possibilities, right? Are pretty exciting when you, when you really think about it. And then, you know, and Benioff, and, and granted, he's a great marketer, right?
Give the man credit where credit's due. He is one of the best in terms of marketing. But when he refers to these agents, he interchangeably uses the word robot.
Is an agent a robot? And is, is a robot something that does physical task or is it also just a digital robot? Right?
And, um, and, and once we start marrying AI to robots, what, what does that mean for our, the way of life, right? Um, I mean, it's, it it's a brave new world in many ways, right? That, that this, And in some sense, you know, bots are kind of the same concept of agents.
Okay. Kind of. I did.
That's what he's getting at. Yeah, We did, we we did have it. Like we did have these software bots, but I, I, I think that, that the kind of the options are, are kind of the, the, the limit is the sky right now because be, be because of the, uh, gen ai, which is behind it.
Uh, Everyone could be. I, I think you're gonna see an actually, an interesting turn. I think you're gonna see people overuse LLMs and overuse agents where they're gonna use these massively expensive things that, that, that do very basic tasks.
It's back to the times when like people's, you know, like using this mass amount of ai when in actuality you could just be doing math, right? So instead of doing creative, uh, AI doing math, You do automation. Well, point up is a bunch of wallies just fat, colorful people on chairs.
And, you know, the ai, we can't do math without a calculator, right? I I, yeah, I, I I think people actually have to focus and realize, like, do we automate this? Do we do predictive modeling?
Do we use generative modeling? Like, and actually using the right tool for the job. 'cause I think right now, people are just throwing everything at, at Gen AI right now and, and calling it good.
But in reality, that could be two lines of job or two lines of go instead of a massive LLM. And I think that's, that's some of the challenges. Well, well, you remind me of, uh, uh, I've met, uh, one of the DevOps leaders a few weeks ago and told me, you know, my job is to watch as much Netflix as I can, meaning the automation of DevOps should, should, should do everything.
So, uh, what what you said about the, uh, agent AI reminded me of that. Absolutely. So, I, I think, Nick, you said at the beginning, we should be using it for the, I, I like to say I want people to use to start using their brain, stop doing the boring stuff, right?
Yeah. Um, I think it's really fun that we're all saying the same thing, which is we need control. We need to set our expectations and roll these things out.
I remember when I was on a manufacturing plant, there was this one robot, physical robot, and it could make seven different models of car, brands of car without changing anything. It was so well-defined, but it still needed people at the end to just do the tweaks, to do the things like that. That was God, 15 years ago, right?
I think we got the same thing with this stuff. And I think I, I'm kind of reassured that we're all talking the same thing, which is we need to have oversight. We need set our expectations, because otherwise it will run rampant.
But the trouble is we will see people that are, um, like, um, setting their expectations the wrong way, you know? Well, I, I think that's the story. That will be the story in 2025, right?
E experimentation in excess in, in experimenting with this stuff. But you know what? Just like in the real world, AI is sucking up our conversation here.
We have do have a couple of other things we need to talk about. One of them, I wanted a big, you know, I think a big emergence in 2024 was sort of the, the legitimate legitimatizing of the platform engineering space, right? And in many ways, I think platform engineering, first of all, it's not replacing DevOps, right?
Yeah. DevOps isn't going anywhere. But platform engineering is a response to DevOps, I think, where DevOps wanted to bust down the silos and have us all working together.
That was kind of the original intent, right? And what it, one of the outgrowths of that though, is that we just started shifting everything left. Give it on the developer, put it on the developer, put it on the developer.
As I mentioned earlier, things we put on the developer was security. I think we found out that they care about security, but they're not security people, but they wanna develop secure code. Another thing we put on them is build your own platform.
They don't wanna necessarily build their own platform. You know what, maybe having a silo for platform builders is a good thing, as long as they communicate with all of the other stakeholders, developers, testers, security, SRE right? All the, the traditional disciplines in there.
And so we solve this whole platform engineering kinda concept rise. And I'm glad to see that in speaking to most of you, your companies are bracing platform engineering. It's no longer, uh, if us or them, it's, we're in it together.
Give, if you wouldn't mind let, well, Sabrina, we started with you last time. I'm gonna start with Nick this time. Let's talk about how do you guys view platform engineering, especially going forward here in 2025?
Sure. I think you, you made a good point. And then the way we actually referenced it, when we're talking about shift left, people started shifting, the workload left.
And that actually wasn't good. And what we actually want is we hire really smart people and wanna shift the information left, give them the information, give 'em those, uh, results. The security scans now, not when it's in production and they have to go, you know, get in a backlog, give them cost information now, right?
Make sure they understand what that change the infrastructure's gonna do now, not a month later when it gets into production. So it's about bringing that information at the right time. It's also about making it easy to do the right thing.
And it's about making it hard to do the wrong thing. And I know that sounds super basic, but it was easy to do the right thing. The cloud wouldn't exist 'cause we would've made VMs in our company, right?
So you make those easy paths to get people to production, make it extremely simple. But you put policies in place to make sure that everything that you're doing actually meets your security, your compliance, your regulatory rules. And as a platform, the goal here is actually to create harmony amongst all these teams.
Like, although the folks on this phone or on the, on this call, we actually integrate with, right? Because again, you have to, and what we do, what we don't wanna do is we don't want to have security being the team of, no, they should be the ones empowering us by writing the policy. We don't wanna be financed to be the ones of no.
And in cost, you know, coming back with a big stick and a carrot, empower them to write that, to make sure that you're, you're meeting your budgets, make sure the DevOps teams can write the pipelines, but we're all doing it in harmony. So now it's an actual platform to bring people together. If you're buying a tool that's a stick to use to beat a different department, it's the wrong tool.
It's not the platform that you need. You need something that brings harmony. That's, I know it might be like a little controversial.
Mm-hmm. And, and maybe a little hippie. No, I think it's genuine.
I think it Goes back to dev, that's DevOps, right? It's about working together. Not necessarily that we all, all of us become DevOps engineers or DevSecOps engineers, but it's about, we all have our thing that we do, but we work together.
So I I'm, I'm, I'm with you. Rest of the panel. What do, what do you guys gal think about, about that?
Uh, sorry, did you wanna Go ahead, Kobe? No, no, go ahead. So the, the thing for me is, is you're right, it is, um, bringing together the teams.
We have a lot of siloed, I've heard feedback that the data scientists don't trust infrastructure people to stand up the infrastructure in, in production. Partly because it's a brand new world. It's, it's in, it's not just standing up a server.
We have to have additional tools to see drifting, uh, compromises, new attack forms, et cetera, coming in. So the whole thing, we actually came with a term called every ops, because, you know, there's DevSecOps, DevOps, machine ops, ml ops, it just goes on and it's pretty, you've got SRE, there's all this stuff and everything, but it rarely, I, I like it because I spend a lot of time working with customers, getting them to overcome those barriers and unify them. So we talked about security.
I'm sorry, Nick. I convert developers into security people, right? Okay.
Bad. In fact, I already disrupted, we were cube gun and this poor guy is sitting there, uh, we're having a drink. And I said, you know, you're a security person.
And he went, and by the end of he says, I hate you, but you're right, because security is everybody's responsibility, but it's not the no thing. It's not the thing. It's about enabling and understanding the implications.
And we talk about streamlining that ability to create a, a, a, a visible view of everything that's going on, and understand, leveraging each other's expertise to create a pipeline that's streamlined, fast, secure, safe. I know, I'm I ideal, but that's what we want, isn't it? Yeah.
Right. Because that's what protect our big customer's businesses. But that model of everything, we gotta stop the silos.
And I think for a lot of the leaders, the CISOs and the, the CTOs, the CIOs, there's gonna be change. Right? Kobe, I saw you get a big smile on your face when Paul said that we've gotta convert them all into security people.
Yeah. You Know, we, we built a platform like in the first place to be kind of, to unite everyone, like security people, developers, uh, developers, et cetera. Um, kind of the, the use cases that we see now that, that kind of customers are interesting in is, uh, how to save DevOps people's time and also developers time providing them a new experience through the platform.
For example, uh, you know, there was a kind of a discussion if developers or security people, or not kind of, uh, through platform engineering, you can actually reach a situation, kind of that everything is being done automatically, uh, you know, automatically. And the developers is actually, uh, we just show him a, a Jira case and tell them, okay, you need to fix this, this, and this. Okay.
This is kind of a, a kind of, of a platform engineering together with, combined with, with a bit of, of ai. So kind of, it, it saves time. It, it also provide a different experience and it also eliminates mistakes.
So kind of the, these are the main three use case that, that, that we see now of kind of what kind of our customers and design partners want, want to use, uh, the platform engineering for. I think I agree with what everyone has said. I think I have a little bit of a different take.
So I think platform engineering has always been something that people would argue is a good thing. It was an ideal, but in reality it was an idealistic state, and it was never like a high enough priority to do because people were like, well, I'm gonna choose best in class and then I'll figure out how to integrate these things together. And, you know, so we'll delay that idealistic viewpoint.
I think maybe what's changed on why platform engineering is such a highlight right now is that there is so much regulation coming. Mm-hmm. And so all of these integration points that we have done for probably the last decade, because we wanted to choose best in class, and that ended up with many, many solutions that we then tried to tie together.
If you have to do something like GDPR, all these integration points are now a risk to your business. And I think as business leaders, that's why platform engineering is such a buzzword right now and why people recognize that. Like you need to have an already existing integrated platform.
So as we meet our requirements for the different regulations and all the compliance that we're being held accountable today, that maybe didn't exist five or 10 years ago, platform engineering helps you unlock that and actually reduces the risk for your business. And I think that's why it's so popular today, this collaboration. It's actually just an added benefit.
Much more so than the driver today. Sabrina would, would you say, so I've had some people say to me, the platform eng, the platform engineering team is actually an oversight team. It's almost like a platform architecture where they've got the full visibility across the whole thing, and they're guiding and being the focal point for getting the groups to work together.
Does that resonate or not with you? I think that's how, um, people defined platform engineering in the past, right? They plug all these things together.
You'd have your SRE team that SRE team would manage all of these different integrations, and then they were the oversights committee. I don't think that is sufficient going forward, right? I think that breaks down very quickly.
Um, I think that's very expensive way to do it. And true platforms reduce your cost of ownership, right? Yeah.
And I don't, I think that's something we didn't pay attention to for a long time. But in the current market with the current cost of technology, that line item is actually, uh, not as, you know, available today. As the businesses are growing and the market pressure is there, Does that mean that should be part of the office of the CTO or part of Dev, or, I don't know.
I'm trying to work out how it fits Where it fits. Yeah, I mean, I think that varies by company. Yeah.
Right, right. Yeah. In today's world where the CTO is often the CPO as well and vice versa, or the CIO is also the CISO, it, it really does vary.
com, our newest site, and we have a new show out there that actually check marks is sponsoring with, that's called the Platform Engineering Show. org, which has two to 200 to 300,000 members involved. So we're gonna be looking hard at platform engineering.
I think the other big story is it's not replacing DevOps, it's part of this whole continuum, right? Platform engineering enables DevOps, it enables DevSecOps, and then, and the only way it works is through open lines of communications with developers, with SREs, with DevOps teams, with security tips, right? And I, I think that's the important thing to remember, guys, we've got one more subject and not a lot of time to do it.
And so I want to get it up there. We, we touched a little bit on software supply chain and software supply chain security. So I, I gotta disagree.
We haven't solved the open source security issue. I, I, I think this is just like a, a snake that keeps coming up and biting us, us. Um, what makes you think 2025 will be any better?
Or will it? Paul, we haven't started with you. Let's start with you on this one.
Wow, that's a hot one. So, uh, so I mean, securing the supply chain, I think it's, it's, it's be, it's, it's something that now that the executives are starting to realize, it's important that they're accountable for, they, you know, just like, um, a friend of mine was saying about Sarbanes Oxidative best to sign off, supposed service best to sign off on supply chains. It's gonna happen more and more.
But I think, I think we're still getting there. I think it's not, it's, it's, we still got a long way to go, I'm afraid to say, because, um, I'm still, we talked about streamlining, consolidation, getting, you know, that traceability, um, and that sort of thing for, for us to have a secure supply chain, we've gotta see everything as it traverses through, um, through its lifecycle of getting into production. Um, securing that and getting everybody, you know, a platform engineering, uh, and sorry, Sabrina, I think it's critical and I think it does need to be a focal point.
'cause it's gonna be the one place that can push that story together with the security team to get that going through. But in 2025, I'm hoping that we're gonna see some new tools, which will help with that consistency and that traceability. I think we still have a long way to go because I'm still working with customers and organizations who are still struggling of trying, just, just trying to consolidate their tool sets.
I spend a lot of time on streamlining exercises. So from that perspective, I, I'm hopeful I see progress. I don't see all the answers being ai, I'm afraid.
And in fact, in some conferences, I dunno if you've, it's almost like it's a groan. Oh, somebody's doing a presentation on ai. It's like not enough one, you know what I mean?
I, oh, I live it. Yes. But I think standardized processes, maturity, actually tying it to better metrics beyond developer velocity.
Um, I always thought talk about the ripple effect. When something goes right, it has a beautiful effect across the whole organization. When it goes wrong, it has a, a ripple effect that hurts everybody.
It's not just there, it's not social security, it's not just infrastructure ops or whatever. Everybody gets impacted. And I think I'm hoping, and yeah, and I'm gonna be pushing to get different metrics in place so people are actually understand the impact and the positive nature of supply chain beyond just getting product faster onto, into, into production radical, I'm sorry, fair panel.
I, I think that in 2025, uh, uh, we're also going to go further down, further down or up in the chain, and you go into the source and assess how trustable it is. Meaning like, is the repo that I am taking something from, how healthy that is, the contribu the contributors that are contributing to, to the open source that I'm trying to fetch how, kind of, how reliable they are. 'cause up until now, we kind of, uh, we mainly focused, okay, I'm taking a piece of something, a piece of software.
Uh, is that specific piece of software? Is that, uh, is that, uh, a healthy one or not? I think that we're now going to go kind of one step down in, in the chain and, and, and again, and assess how trustable the source and the contributors to that source, uh, are we, we act never a, I'm not supposed to mark it, but we have a solution that acts like a gateway between the public repos to stop the bad stuff coming in.
Um, the real challenge is getting the developers to say, go through this way, go through this way to the, to to get due to your repos. Supposed to go direct. Like, don't go home, install the package and then come back, sort of thing.
So there's a lot of, there's a lot of challenges about that enforcement and trying to explain to the developer what you're gonna save them time, uh, save them time And money and let them spend less time fixing bugs and more time Creative. I mean, there are still people downloading the wrong log four J, Right? Well, struts two and Equifax, this is a common, how do you stop them from downloading old vulnerable bug ridden bad components.
Sabrina, I saw you shaking your head though. I wanted to give you a chance. I mean, obviously, you know, we get hundreds of external contributions into GitLab.
It's amazing. People ask me a lot of questions about that. And you know, look, just because all of your contributors are internal does not mean you don't have risk, right?
It's just sort of like if you had a firewall versus not having a firewall. If you're behind the firewall, you're safe. That's not true.
That's never been true, right? We've learned the hard way that that's not true. I actually think sometimes the number of eyes who are on open source, right?
And like checking for that and looking out for that is much more powerful than what you might get. Um, if you're all hidden internal, like having worked for a very large tech company for a long time, not all teams are the same. They don't all ha make the same assumptions.
So even when you're integrating inside your corporate walls, you have the same kind of risks. You need to be on the lookout for that. You can get malware into your system unknowingly.
What you, what you really need to have is like, you need to have policy controls, things that are enforced, that are automatically looking for that. So if your employee does do it, it's not like, Hey, you broke the rules. It's like, Hey, we just stopped what you did.
That cannot be integrated into the system we are watching for where this is going. And that's, again, back to the platform. Like the platform can enable those things for you because it all, your system is all plugged together.
You can look at everything at the same time. And I think that's how you wanna think about it. It's not open source or internal.
The risks are the same for the both. One has consequences, right? 'cause you, they're your employee, right?
You have, um, you can do something about it, whereas the other person can't do anything about it. But actually it's the same problem in the end. I think, uh, I think this falls in that same thing that I was saying earlier, which is make it hard to do the wrong thing.
And if you put in all that policy in place, like you said specifically, like that's, that's why we built open policy agent into harness. So you can prevent any one of these, right? Make sure that every piece of code is scanned.
Make sure that every piece of code doesn't hold that MIT license. Make sure that it goes through the appropriate measures to block things like a log four J, but also make sure that it has salsa attestation. So it's got a bill of materials.
You make sure you're there, but you actually know that it's the actual artifact you're using so you don't fall into like a SolarWinds attack. And so now the actual attack vector's grown from just the artifact or just the code. But now to your point, this is why the platform's so important.
This has to be from source code, from the build, from the deploy throughout all the systems. And it's not even just about validating it, finding it, checking it. You're going to have that zero day now how to remediate it.
So that platform should know what you deployed on, which infrastructure with which configuration and which secrets to get you back. Or more importantly, as you update those, uh, artifacts or you, you change those libraries to promote them out to production again. And so getting you remediated quickly so you don't struggle with those.
And I think this is truly where when we start automating all those things, and it gets us back to where we were. Like, if we start taking that burden off of people, uh, and actually focusing them on the areas, now each one of those teams can do what they're great at you. You empower it.
And what's really scary here, you know, the government is actually the first ones who did this. Well, there was an executive order that forced this that said, Hey, you have to have a bill of materials. You have to have an attestation that proves it.
And this is one of the first times we've seen our US government actually leapfrog and actually leave the, the, the public sector behind. And we've been working with those enterprise customers on that specific problem for years now. And what we're seeing this year, and I think as to get it back into predictions in 25, you're seeing now actually all these, you know, public companies catch up to, we need to have this secure.
We need not only for our own software, but to your point, even the people that are our vendors, uh, the people that are contributing. It actually, it, it builds trust amongst the entire community Agreed To Sabr, to Sabrina's point that, uh, in internal, you know, internal code is also, uh, not, not secure. Like we have a whole concept of what we call price packages.
Not open, not not only open source by meaning packages that were actually developed within, within the, uh, within the organization. And we treat, we treat them. Have We treated the same?
They're potentially malicious Open source packages. Yes, absolutely. Guys, we are at a time.
I wish we had, as I said in the beginning, twice as much, three times as much. We could talk about this all day. What a ma, an amazing, amazing panel.
Thank you all. Nick, Paul, Sabrina, Kobe, I, I honestly from the bottom of my heart, thank you so much. I hope you guys out here watching this have enjoyed this panel.
Um, all four of these companies and these folks are kind of frequent guests on Text Drunk tv, so watch for them throughout the year. Um, we have a lot more lined up here for you today on Predict 2025, including the winners of the DevOps Dozen awards we'll be announcing. So for on behalf of everyone and, and here at Techstrong, I'm Alan Shimel.
Thanks for joining us on this great panel. Stay tuned for a lot more here at Predict.