Techstrong TV March 17, 2026
AI Industrial Revolution: Samuel Pasquier of Cisco explores how industrial AI and machine vision are transforming factories and critical infrastructure—and why securing autonomous systems is now a top priority amid a growing skills gap.
Agentic Automation in Practice: Tiffany Treacy of Microsoft and Keith Kirkpatrick break down how apps, agents and chat are converging—highlighting multi-agent orchestration, human-in-the-loop governance and inclusive, AI-driven productivity.
The Rise of the “Born in AI” Partner: Alex Smith from The Futurum Group explains how AI is reshaping the IT channel—shifting from hourly billing to outcome-based services and giving rise to “Frontier Partners” built on LLMs and agentic workflows.
The Quantum Threat – A New Y2K: Rebecca Krauthamer, CEO of QuSecure, outlines the urgency of quantum-safe encryption and the risks of “harvest now, decrypt later” attacks threatening today’s data.
AI Regulation Ahead of RSAC: Tom Hollingsworth, Mitch Ashley and Fernando Montenegro discuss why cybersecurity leaders are calling for enforceable AI regulations—not just ethical guidelines.
Preserving Knowledge with the Internet Archive: Joy Chesbrough highlights the mission of the Internet Archive, founded by Brewster Kahle, to provide open, global access to millions of digital resources and preserve cultural and technical history.
Transcript
Hey everyone, welcome back here to Techstrong TV. I'm happy to introduce you to my next guest on today's show. His name is Samuel Pasquier, and I, I had it good and I spoke and forgot it.
Samuel, pronounce your name for us again so we get it right. Samuel Pasquier. Pasquier.
I wish I could say it as well as you could. Don't stress about it. I just...
I'll, I'll never be able to. I'll never be able to. Rolling the Rs, the whole thing, it just doesn't work for me.
But Samuel, it's great to have you here on Techstrong TV. Samuel is the, by the way, is the VP of Product Management for Industrial IoT Networking over at Cisco, and we're gonna dive into what exactly industrial IoT networking means. But first, let's, let's find out a little bit more about Samuel.
Samuel, give us kind of your career path, if you don't mind. Give people a little sense of who they're talk-- who they're listening to. Sure.
So Sa-thank you so much. Thank you for having me here. Uh, so I'm Samuel Pasquier, and my past is, you know, I, I grew up, I was born in US, believe it or not, but I grew up in France, so that's the French accent.
Um- Mm. I... So my study in France, I studied, software engineering, and I moved to the Bay Area in California to work as a software engineer, and I was lucky enough to work on Catalyst sixty-five hundred.
For any- Mm-hmm. -of the audience that have been in networking for a few years, Catalyst sixty-five hundred was a, a big, uh- Workhorse. Yeah, exactly.
So I worked for many years on this platform, and then I made the move between engineering to product management. You know, you never want to change too many variable, so I kept the product, but I changed role. I became the product manager for this product, sixty-five hundred, which was amazing because I knew a lot about the technical aspect of the product, so it helped me to build trust with my audience, with the customer.
And then the, I would say the rest is history. You know, I went from sixty-five hundred, became a manager, led the launch of the sixty-eight hundred, then moved to, Catalyst 2K, 3K, you know, the access, switching platform at Cisco. And ten years ago, I moved to, this thing is called industrial networking, which I always thought was really interesting.
And you see, it's been ten years, I'm here and, in industrial networking, and I love it. Love, love, love, love it. What a great story.
Yeah, the sixty-five hundred, you know, brings back a lot of memories. It was a, it was a, it was the backbone in many ways of a lot of networks. Exactly.
Exactly. A lot of going on. Samuel, when we talk about industrial IoT, and you even say that so much nicer than me with your accent, but industrial IoT networking, what exactly are we talking about?
Yeah. So maybe le-let's, you know, le-let's go through a story lesson. You know, I know you've been familiar with Cisco, like a lot of the audience.
Cisco has been building network for forty years. What people may not know is Cisco has been building industrial network for twenty years. So it's pretty much building, networking equipment to go into a manufacturing environment, can go into a, a utility network, substation, connecting the grid, or even all the way to, I would say more heavy industry, oil and gas, mining, those kind of things.
So what we do in industrial networking is really build the connectivity and security that you need to connect those machine that are outside the office space, you know, outside of the nice climatized, room that we are. It's outside, it's where it's dirty, where it's, and where you have different type of constraints in terms of networking, need and redundancy need. That's what we do, and we do that leveraging the Cisco, DNA, I would say, and the Cisco, knowledge and know-how, to bring that to the industrial network.
Very cool. Um, you know, f-for those of you out there who maybe have not worked or dealt a lot with the, industrial IoT world, you know, you focused on the norm-- the regular IT world, it's a big world, IoT. There's l-- you know, not, not to sound like Carl Sagan, but there's billions and billions of IoT devices that are out there in the world, and more coming on every day and, and every single one of them has a unique IP.
They need a unique certificate for security or a unique ID. Um, and they're doing beyond mission critical, life or death kind of functions. And, and, you know, this is-- it's ni-- I remember a friend of mine was the IT director for a hospital, and he said the unique thing about running technology at a hospital is you had three networks.
You had the normal IT network that we all work on, right? With computers and laptops and printers and, and so forth, servers. Then you had the medical device network, the ins-- the intravenous pumps, the heart monitors, the, the dialysis, the CAT scans, the MRI, the stuff that makes modern medicine, right?
It's all networked, it's all connected, and it's a beyond mission critical, it's life and death. And then you had a network for the doctors, 'cause they don't follow any rules and they're a security risk anyway, and we had to keep them on their kind of their separate network, so they don't mess up everything else. But, you know, i-in a lot of places, industrial IoT isAs I said, life and death, mission critical, and even bigger in some ways than, than just, you know, traditional IT.
So- Yeah. And you know what I, what I would say to echo to what you're saying is when you look into the industrial world, you look into factory, you look at utilities, you, you look at all those, those place, there's more and more, connected device connected to an IP network, like you mentioned. And those device needs to talk, need to exchange with an increased amount of data.
And the truth is, a lot of those devices have been connecting for many years, but it's been done, in a very organic way. And now with security being top of mind for a lot of people, you, you mentioned hospital, but the same in a factory, you know, that put some very interesting challenge, for people who have to manage this kind of infrastructure. Absolutely.
Absolutely. Samuel, if you don't mind, we-we're gonna come back and... com- Yeah ...
that they could go to, to find more information there. But I want you to turn over to a recent report that Cisco put out. It's Cisco's twenty twenty-six State of Industrial AI report.
And, like, you know, like everywhere else, AI is moving from pilot into production. But as we said before, these, these are potential life and death situations, right? And you know, where we can't have cyber instances or downtime or safety failures.
Talk to us maybe a little bit about the rationale behind the report, and then maybe we could dive into some of the key findings. Yeah, sure. So to give some context, like I mentioned, we've been, helping to build industrial network for twenty years.
And, you know, when we saw AI coming on the market and we, we were-- first, we were wondering, you know, what's going on in industrial network and what the trends. So two years ago, we did a report for State of Industrial Network. And two years ago, when we, we asked a thousand, people that are dealing with industrial network, they told us that AI will be the biggest impacted trend for them in industrial in the next five years.
So we are done two years. We thought like, "Okay, let's focus on state of industrial AI. What are the use case?
What are people doing? " Try to demystify that a little bit and really try to understand when we talk about impact on industrial network, what does it mean? What are the change?
What are people doing, and so on. So that's a little bit why we decided to do this report, to really talk, to ask practitioner, people who do and build and operate industrial network every day, "What do you see? W-what are the use case?
What, what's going on with AI? Where are you using AI? " And so on.
So that's really, why we decided to do this report and try to get insight. And being a product manager, obviously, I want to make sure that we are investing in the right direction to build the future of industrial network, right? So that was really the intent behind this report, and we found a lot of very interesting information, and that's why we published it, right?
Excellent. Excellent. Um, a-and you know, I, I-- look, just from my own experience with I-AI, i-it's gotta be a very different picture this year from last year, right?
'Cause we've made so much, we've made so much progress. Well, some would say progress, some would say not. But we, you know, we've certainly learned a lot about how, how AI can help us, what the things that it could do now, what are the things we're learning to use it for, et cetera.
Mm-hmm. With these kinds of reports, Samuel, I always like to ask, you know, what are the... Give me the top three things.
Mm. The three key findings from this year's report. Yeah.
So maybe, you know, we should, try to put some color on what does it mean AI in industrial maybe first, and, and I can explain you what the finding because when we talk about AI in industrial, you know, we-- people may have a view of what is AI in the IT world or what is AI in your personal life, you know, we play with w-with students on. In industrial world, we really see, I would say, three things happening. One is, the explosion of machine vision.
So a machine using camera to see the world, right? And that change a lot because you go from a world where you sensor to a world where you have machinal eyes, and you can do things. So that puts constraint on the network.
The second thing that we see is, you know, everyone is talking about physical AI, and the reality is you have robots, human doing or not, doesn't really matter, that are getting smarter and smarter to do things and are moving. So there is a concept of, you know, the mobility of those machine, of those robots. How do they connect?
How do they get the information? And when you combine the two together, you have something that is even more powerful. Now you have robots that can move, that can be smart.
They have a view, they can see. And now the question is: Where do you process all this information? So you need to be able to connect to a place where you have unlimited CPU resources and memory to be able to process all this information to give back to the machine or the robots what to do.
So that's, in a very, very simple way, what we see in the industrial world. And out of the report, when we ask people what the big finding, is really three things. The number one is the infrastructure gap, right?
Uh, meaning, you want to have more and more cameraYou see, the beauty of that is you can save things to learn on the huge set of data, right? So you can have a deployment of using a camera for quality inspection on, let's say, your car manufacturer on one station on your car. That's really good.
Where it becomes very powerful, if you can do that to a thousand of car a day, can you cor-correlate a little bit of learning? Can you do learning from the volume of data? If you want to do that, you need to have the bandwidth, you need to have the storage, you need to be able to capture all this information.
Can be quality, can be, quality of the work, can be general assembly. Did I put the screw where I need to put the screw? Those kind of things.
The second things that comes to mind is, so you need to connect all of that. But like you said, you know, everything has an IP address now, which means your attack surface is increasing. And what you don't want is in industrial, it's not I don't want to lose control of my factory.
I don't want anyone to come and stop my factory. I may lose some data. I don't like it, but I may survive that.
Stopping the plant is a no, is a no-no, right? Or if you think about utility substation, you don't want to lose power, right? So the idea of security in that environment is super top of mind, and that has been for a few years, and it's just accelerating.
And with now the new threat that can come from AI, it's even more top of mind. And then the last thing is, okay, so you need to have people who understand the industrial environment. You need to connect to build capacity.
That I would say it's, it's okay, but you need to secure all of that at the same time. And then comes the problem of the skill gap. So I like to joke that, you know, you can always find the unicorn, someone that is very strong in industrial, understand the, the, the space, and understand networking and understand security.
But the truth is, you need scale. You need more people than you can really find with this skill set. So there's no other choice than having a collaboration between IT, the, the people who know networking and security, and more the operation team, the people who know the process, know industrial automation, know what needs to be done, and, what information to collect to be able to improve the quality.
So that's really the, the third point is really this collaboration between the IT team and the OT team. So to summarize, there is three, infrastructure readiness. Do I have the, the pipe and the connectivity that I need?
Do I have the security that I'm worried about security? And last is skills. I need people, right?
So that's really the, the three big finding, and we hear, really more and more, I would say, not concerned, but we can see it top of line for, for people who re-reply to this, report, right. I love it. 'Cause it's a good way of looking at this report.
You know, especially now with AI, so many things we see kind of challenge our previous norm, right? What used to... What we used to take for granted is not grant-- taken for granted anymore, and what we used to think of as, you know, dreams is reality.
What about anything in the report this year, Samuel, that made you think, "My God, I didn't see that coming," or, "I didn't see it coming that fast"? I would say it's the other way around, if I may. I, I, it's not, you know...
Look, in industrial, things move maybe a little bit slower than in the IT space, right? Which might be a good things, no? Mm-hmm.
Uh, you know, people go slowly. They want to make sure things are working. Uh, let's not be crazy.
Uh, so people are adopting technologies. They are a little bit more risk-averse, but they move with a lot of, I would say, inertia. You know, when they move, it moves.
They go, right? There is no way down. The thing that was sup- the most surprising for me is, look, I've been in ten years in this world being in an IT company working in industrial network, and maybe I've been biased to think like this IT-OT collaboration is very happening, and it's going on full swing.
I was a little bit surprised that it's not as, I would say, prevalent as what I thought. I thought it would be much higher in terms of percentage than what it is. I think people are moving, but when I step back, I think it's a lot about the culture change, right?
You need to have... And changing the, the people is very hard, right? And, and I think that's the thing.
So I've, I've personally observed some customer who are very, I would say leading edge. I, I can think about, one utility customer where they build, their team to handle their networking for the grid. Half of the team come from a service provider background, people who build very large-scale routing network, and half of the team come from electrician.
They put all of them together. They have twelve people. Let's go and build the, the network for the grid of the future, which is very interesting.
And you have some other customer who are a little bit more on the way back and kind of trying to fight it, but they cannot really fight it. I would say the writing is on the wall that you need to have those two team working, and I think that's where we are progressing. So I'm convinced, this, partnership will, will increase significantly, but it's not at the level I thought it would be.
So that's the answer to your question. Absolutely. Um, but again, I think the, the, there's more in front of us to come, right?
And, and, and so it will. But you're right, it does... You know, there's the hype, and then there's the reality of these things, Samuel, right?
I don't know if it's gonna happen in, you know, in three years, five years, and who could look out beyond five years? And there's some of that in, in these... especially when we talk about things like IoT, right?
Though we have billions, literally, I forgot what the latest number was. Was it six or seven billion, or was it four billion IoT devices connected in the world today? They estimate something like that.
Uh, and I'm not tracking... I'm getting confused of what IoT stands for, but, but- Yeah ... it's a big number, more than I can, uh- Yeah, it's a big number ...
And, you know, and, and it's a hard number to kind of wrap your head around. I mean, it's, it's just... it, it's incredible.
But, you know, we'll, we'll have to see. So, and, and the... and i- it's not like, as you say, de- depends what IoT is.
It's not like all IoT moves at the same speed, right? Different areas of this different, different things. So we'll, we'll have to wait and see.
But, but- Anyway, Samuel, for people who want to download the report maybe and get their hands on it and dive in, what do you think is the best... where should we send them? Well, so w- we have a, a...
or maybe we'll post the, the link, after the video. Yes. com/go/ uh industrialuh networking.
I think we have a, we have quite a few link over there, and, w- the report will be available, and we'll post a link, with the video, so people can go and- We'll put the vid- we'll put the link in the show notes, but, you know, there's still good old Google, and if you Google Cisco's 2026 State of Industrial AI report, I bet you'll get it. You will find it faster as I'm trying to go and click you on the link. You remember that, yeah.
That's for sure. Well, sometimes, you know, you gotta st- well, the old school works best. Samuel, thank you so much for coming out here on Techstrong TV.
We appreciate it. Great report. Keep up the great work there at, Cisco, and come back and keep us informed, okay?
Thank you. Thank you very much. Thank you for hosting me, and I will be back.
Thank you. My pleasure. Thank you.
Samuel Pasquier, our VP Product Management, Industrial IoT Networking, Cisco, on the Cisco 2026 State of Industrial AI report here on Techstrong TV. We're gonna take a break. We'll be right back.
Hey, everyone. It's Alan Schimmel from Techstrong. Welcome to our next session in our dynamic series of conversations between the select thought leaders at Microsoft, as well as the a- some of the analysts from the Futurum Group.
In this session, we have Tiffani Tracy, VP of Product Management for the Power Platform at Microsoft, and, and as well as analyst from Futurum Group, Keith Kirkpatrick. The ses- this ti- this session is titled Agentic Automation. In this session, Tiffani is gonna lead us on a deep dive into the operational realities of agentic automation.
It's a world where apps, agents, and chat are converging to reshape enterprise execution. We hope you'll discover how AI empowers everyone, with a special focus on those who need accessibility and disability support. You're gonna learn how business users supervise autonomous agents that execute, escalate, assist, driving inclusive productivity.
Expect insights into multi-agent orchestration, human-in-the-loop governments, and chat-led transformation across support and product activation. So another great session. Here's Tiffani and Keith.
Thanks, Alan. I'm Keith Kirkpatrick, Research Director with the Futurum Group, covering enterprise software and digital workflows. Today, we're gonna be talking about agentic automation and how it is reshaping enterprise execution, where apps, agents, and chat functionalities are converging to assist across workflows, driving external engagement through the delivery of personalized, intelligent experiences, and streamlining interactions.
And hello, my name is Tiffani Tracy, and I'm the VP of Product Management for the Power Platform Core, which covers our Power Apps, Power Automate, Power Pages, RPA, and process mining. I've been with Microsoft for 25 years in a variety of product roles and looking forward to the conversation today. As we're both aware, we really can't get away from a discussion about today's technology without talking about agentic AI.
And I wanted to first start off by asking you about some of the ways in which agentic AI is changing the way customers are engaging with businesses on a day-to-day basis. Yeah, so I think it's great if we first start with the fact that agentic AI is going to change the way we work, right? We're moving much more into these human-led, agent-operated environments, and some of the big changes that come with that are we're gonna move much more from this very task-based focus to a more intent and goal-driven focus, and we're gonna move from working, like, in a particular app to really working across apps.
With that, we'll see this synergy of humans that are, you know, driving what we're gonna do. They're adding business intelligence, they're guiding. We're gonna have agents that really do a lot of the, the execution work.
We're gonna have intelligent apps where these agents and humans can dock in to manage everything, and we're still gonna have automations like we have today for very deterministic workflows. When we put all of that together, what we get from a customer experience is they're going to get much more personalized and contextually relevant experiences, much faster and with a lot less effort on their part. And in fact, in many cases, we see that customers or organizations were able to expand the audiences that they can actually serve with this technology.
So, like a simple example that that might be I'm on a flight, turns out I'm gonna miss my connecting flight. You know, today when I land, I might get a, a text message that I've missed my connecting flight, but you see very quickly I'll land, the airlines has already rebooked me with an agent. They're gonna let me know what my new flight is, and then if that doesn't work for me, they're gonna give me a human to escalate.
That's gonna change in these kind of customer experiences. Can you talk to me a little bit about how we're going to see all of this automation, intelligent automation be managed? So one of the powers of this agentic transformation is you begin to get intelligence on tap.
So you have these different agents that you can leverage for different business functions. A level one agent, I think most of us have probably experienced in this point, and that is AI is maybe we're asking it questions, or it's giving us a set of information. And then you have level two, where the human is actually directing the agent to conduct some sort of task, and then the business rules, dictate when the, the human will get involved, and it may be just giving the human information so they can make a better decision.
And then level three- Mm ... is where you see these agents actually taking action aligned to the business rules and the human being in the loop aligned to whatever business rules you set. So what you'll find is that the goal of how we're thinking about agentic AI is we want humans to continue to work in the way they do today.
We want them to have a personal assistant that transcends with them throughout their day, whether in their business data, their productivity data, whatever task they're doing. And then they will have intelligent apps that let them manage some of these autonomous agents, but those agents can dock into their personal assistant. They can dock into their agents.
So we really want the humans continue to work the way they do today, that this AI will sort of collaborate seamlessly with them, and that's why you see that using both intelligent apps and kind of copilot in this chat interface have their place depending on what the human's trying to accomplish. And so we want this all to kind of slot in more seamlessly versus thinking about it as, like, they, they have to change as much the way they work. Right.
That makes sense. But I guess one thing that I'm, I'm particularly curious about is as we move into this world where we have agents that work alongside of humans, and there are obviously gonna be agents that work sort of autonomously, obviously still with, you know, human in the loop to make sure they, that they're, that they don't go off the rails. How do you actually coordinate multiple AI agents across a platform to make sure that, you know, the agents do what they're supposed to do when they're supposed to do it?
Yeah, it's an excellent question. It, it's very inherent in, in the platform we're building a-a-across both Copilot Studio and Power Platform and, of course, some of the pieces in Azure. But it is very straightforward to design for a particular agent what its rules are, what it's allowed to do, what knowledge it has, what memory it has, what kind of guardrails it needs to follow.
Mm-hmm. And what we see as customers are moving to these level three agents is they're really thinking through their business processes and chunking those up into reusable components. So maybe, for instance, you, you interact to gather information from an external company, and you do that for several business processes.
You might build a dedicated agent that does that and, and gathers that information. That will have a set of business rules that you set for that agent. It will have a set of points where you escalate to a human or where the agent can actually take action.
And then that agent may talk to another agent. Again, you define what that communication is and the business rules. So it's very configurable to what your business policies are, what your risk tolerance is, depending on the, on the impact.
The other piece is it's quite straightforward to evolve those business rules. So maybe, for instance, you start with an agent that makes recommendations on approving insurance claims or approving purchase orders. Then maybe you say, wow, that's going really well.
If it's, you know, under such amount, one thousand dollars, the agent can auto-approve. If it's over that, the human still has to make that decision. And then you keep ratcheting that up as you build confidence in the, the agentic system you've created.
And those things are very straightforward to configure and continuing to evolve. Actually, how does Power Platform help to sort of manage that, that, as you're talking about multi-agent orchestration across different modalities, whether we're talking about chats, applications, and back-end systems? Because that seems like that's gonna be a core sort of, requirement as organizations, whether they're dealing with regulated industries or not.
Absolutely. So when you think about the Power Platform, one, we, we have a tremendous amount of line of business, large scale apps running on the platform today. And I think it's really important to note for those customers, we are going to bring AI to where they're working today and let them use AI to add even more value to the, the applications they have today.
Then we're introducing new tools, for building agents and some of these intelligent apps that will, will dock the agents in. All of that will still run on the Power Platform managed environments. So all of the governance that you're used to in the Power Platform will extend to this agentic transformation so that customers have confidence that they are running in a managed environment, that they have the ability to set the policies, to manage it, to audit it, to understand RAI, all of the different components they need.
But that will be within the, the core platform that they have come to, to trust in, in managed environments. Now, Tiffani, you just mentioned something that's really interesting, and, and you've been talking about it throughout our conversation, about the idea of human-in-the-loop governance. I'm curious, how do you actually embed that into agentic workflows without sort of slowing down automations or creating unnecessary bottlenecks?
So human-in-the-loop can be orchestrated at any milestone in the process that makes sense for that process or that business. This is one of the places that we think intelligent Power Apps is going to play a large role. So you can imagine that I might have, you know, a thousand automations or a thousand agents that are running, and I have this intelligent app that lets me go through and quickly approve, guide, change, whatever needs to happen to ensure that the human is guiding but not slowing down the process.
And I think this is one of the roles we see for intelligent apps as we go forward. What about, you know, the other thing I've heard about is the use of adaptive risk models and how that might help ensure that agents just remain compliant with any kind of regulatory or even indus- or even, business guidelines. Can you talk to me a little bit about that?
So for every agentic solution, the organization really needs to think through a concept we call evals. And those evals are what are letting you know that the quality, the functionality, the reliability is all within your guidelines. And so it depends on the agentic solution, but you're going to have metrics that tell you the functionality and the reliability.
It's gonna let you know the quality of the response. If it's a agent that's creating some sort of UX or interface, you're gonna have metrics that let you test if that is, is high quality and functional. Um, and then of course, you're going to have evals around responsible AI.
And so depending on the solution, one of the first things you want to do as you get started is define for the type of solution you have, what are the areas that will be key, and what are the metrics and tests you want to use? And then there'll be multiple ways to ensure that those metrics are on track. So we've heard a lot about agentic AI, but one of the things that I hear from talking with companies is that there's still a little bit of fuzziness or confusion around what sets a agentic AI apart from sort of the chatbots or assistants that we become, become accustomed to dealing with in our everyday lives.
There's a number of things. One is that an agent, if you give it to them, has memory, so they can remember previous conversations with you. They can remember previous context.
The second is that the agent can learn. You can continue to train it on knowledge, and it can continue to learn and help-- be more and more helpful as it goes along. It also has not just the initial, knowledge that you trained it on, but it has generative AI, which helps it to fill in the knowledge that you've given it.
So you can think it of it has all the power of the, the orchestration and the LLM, or the large language model, with your specific information on top to personalize it. All of those are things that chatbots could not do. Chatbots also cannot take action.
So chatbot was really-- it was a great at the time, but it's really more of like a Q&A with very curated answers. A-When we get to LLM, it has all of these richer capabilities. And so it's not only quicker to get the information back to the human, but it also can do more of that on its own because of the context, the shared memory, the knowledge, and the fact it can take actions.
Well, one of the things I think that agentic AI is really sort of building on is that chat modality, where you're able to use natural language to interact with it. Uh, d- do you see that as being sort of, you know, another sort of real selling point for using agentic AI? Because you are able to...
You know, anyone can interact with it. You don't need to have- you don't need to program, you don't need to remember specific terms or anything like that. Natural language interfaces are going to have a large role in agentic AI because as humans, that's an interface that we like, we enjoy, and has a much lower barrier for people to participate in.
So I think natural language and being able to, you know, type what you want an app to do or what you want an agent to do for you and be able to go create that will absolutely have a large role in that. Again, I think it will depend on the business solution. We also know that humans are more comfortable in sort of like a personal assistant, like a copilot realm, talking back and forth, because that's how they interact with their other coworkers.
And so we really want, as much as possible, to have the humans still work in the way that they're accustomed to working. So they might, you know, ping a coworker to ask a question. Now they might ping their, their personal assistant to ask that question.
There will be places where they'll actually go into an intelligent app because that's the best interface for them, and then they may continue to ask their personal assistant questions about that app, so they will be much quicker to learn about that app and what they're doing. But the natural language interface is definitely gonna play a key role because of the way it lowers the barrier and allows humans to continue to interact with the technology in a way that they're most comfortable. So it sounds like what you're describing is sort of an agent first or, or assistant first, approach to interacting with systems.
Is that kind of what we're, we're moving toward? I would kind of flip it around. I think it's a human first, a human-led.
I think the human is going to have a personal assistant, like Copilot, that transcends their day with them, understands their productivity context, their business context, you know, how they like to communicate, how they don't like to communicate. It's gonna be more kind of, I'll call it, connected with the human and their personality. And then I think there's gonna be a set of intelligent apps and agents that dock into those places.
Agents may dock into your apps, agents may dock into your personal assistant, depending on what they do. All that together will build kind of the new tapestry of how we work and how we move forward. But I think it's the human at the center with these technologies helping to make them more productive and giving them more time to s- think strategically, to be creative, and to think about what they can do next.
We, we know from all kinds of studies that 80% of, of people in organizations say they don't have enough time to do what they wanna do, to think about the things they wanna think. So we're thinking about how we empower that human and how they now have more time for those strategic creative things, and then this technology is, is really helping them along the way. Tiffany, one thing you mentioned is that AI should be for everyone, and I'm curious if you could talk a little bit about how agentic automation can help ensure that people with disability aren't just included, but actively empowered as they're working and using enterprise workflows.
Yeah, this is an area I feel extremely passionate about what we've seen so far with, particularly Copilot and, and some of the automations that have been done in, in Teams and some other places. So, you know, there's lots of different situations that, that people with disabilities face. Um, you may have someone who has hearing loss, and now with the transcript on a meeting, they can fill in where something wasn't quite clear to them.
You may have, someone who has ADHD who focusing on the meeting and the notes, they feel like they miss out on both fronts. I think, I think that's a human experience across the board. Now, with meeting notes and the transcription, like, you can stay 100% focused on the conversation, the meeting, and know the rest of that is going to be there for you.
You could flip this over to other environments like schools or education, where the concept of meeting notes can help students take notes in lectures, and they can have it all there, so they're focused on their learning in the moment. I mean, a lot of these, agentic AI pieces are gonna help humans be fully present in the moment and know all this other stuff is there for them to use later, but they're not having to multitask in the moment. And the, the numbers are showing, people see the real impact to that.
They feel like the quality of their work is better. They feel like they are more included. They feel like they have better performance, and they feel like the meaning of their work has actually gone up.
We're just seeing the beginning of all the impact that this is going to have for us. Tiffany, can you give me an example where agentic AI has provided an outsized impact above and beyond what you either might have expected or what we could have previously done? Yes.
We see many times that the spark for starting with AI is around efficiency or productivity, but what we're hearing from customers is they're seeing a number of other vectors of impact. Um, accessibility and inclusion has been a really strong one, which I'll talk about. Uh, being able to upskill and learn has been another one that's come up quite strongly.
In fact, EY, Ernst & Young, recently did a, a study where they interviewed over three hundred people who had been using Microsoft Copilot, asking them, how did it impact their work? All of these three hundred people identified as having a disability- Hmm ... and over seventy-five percent of them said they felt like Copilot had made them more productive at work.
They kind of laid that along three lines. One was removing barriers. Eighty-eight percent said they were doing better communications by using Copilot than they had in the past.
They also talked about feeling more included and feeling like the quality of their work had gone up. That was over eighty-five percent. And they also talked about feeling like they were getting more meaning out of their work because of their productivity and the quality.
So that is just a tremendous, like, additional benefit that we're seeing from AI, where organizations are able to ensure that every team member is bringing their best selves to work and doing the best role that they can, and I think we will just see more and more of this as we move forward. Because as Copilot and some of the other AI continues to learn even more and more and becomes more personalized, it can even help in other ways that will be very valuable for people. So Tiffany, I was wondering if you could share some examples about how agentic technology is being designed with accessibility in mind.
Yeah. So as you know, Microsoft's had a, a long history of thinking about accessibility features in our products, whether that's been sort of in Xbox and assistive controllers or Office a- and the many accessibility features we provide there. That same sort of mission is, is moving into agentic AI.
So we can think about what are the new f- accessibility features that maybe in the past weren't as feasible that now we can bring to the forefront. Some of them are already out. You think about Teams meetings, Teams transcripts.
You think about things like Copilot being able to ask questions a- across all of your graph data. As we move forward, we see even new opportunities. For example, the Teams team is thinking about how today in a Teams transcript, you have whatever has been said verbally, you know?
Might be another language, might be in English, might be in multiple languages, but it's what was spoken. In the future, what they wanna do is include what was signed in the meeting into the transcript so everybody has a complete transcript, whether that was spoken or whether that was signed, and that's just one example of the many type of agentic AI features that we feel like is now feasible that we're exploring. So I was wondering if you could tell me about how agentic automation has really streamlined very personal or sensitive, processes and procedures.
One of the areas that would be a, a great example of this might be human onboarding. So we each come to a new role or a, a, a new set of work with various, backgrounds, with strengths in places, things we know nothing about, and agentic AI can really personalize helping that human onboard in a way that they feel completely comfortable. They can ask many questions.
They can get access to many resources. They can get recommendations and guidance that will help them learn at a much quicker pace, but not something whereas in the past they would have had to share very broadly with their new team that they didn't understand a concept or they didn't have this experience or maybe it's very difficult in a, a large conference room to, to hear, the, the voices. And so agentic AI has the opportunity to really help speed up that onboarding, personalize that onboarding and do it in a way that is really taking the human into account and helping them do that in the best way possible, in a way that's sensitive to things and very positive and productive.
Thank you very much, Tiffany, for a great conversation and real insight into the world of agentic technology. Thank you, Keith. I really enjoyed our conversation today.
It's always fun to talk about the transformation that's ahead of us and how agentic AI is gonna help all of us move forward. Today, we heard a lot about agents, and I think some of the things that really resonated with me was the fact that ultimately, to have success, you need to start with humans, looking at processes and goals, and then bring in the technology. Now, of course, there's a need for platforms that can really provide an orchestrated agent experience across intelligent appsagents, and of course, all of the workflows that are integral to really driving real business benefits.
And ultimately, the other thing that really, really sort of, resonated for me is the ability of agent technology to improve the experience of people who may have disabilities, and to do it in a way that really takes into account how they're feeling, and not really kind of separating them from the rest of the employee base or other customers, but to do it in a way that's empathetic, and again, can really drive outcomes. Hey, guys. Thanks for the intro.
We're here with Alex Smith, who's vice president of Ecosystem Channels and Marketplaces for the Futurum Group, and there's a new report out about what's going on in the channel, and well, in the age of AI, you might be surprised to discover that there's a lot of change happening. Alex, welcome to the show. Hey, thanks for having me, Mike.
So, in general, I know you've been following this now for years and putting out multiple reports, but have you seen any fundamental changes in the mindset in the channel, and what are some of the highlights in the report? So Mike, the, I think the channel is a community that's always kind of facing adversity and always facing kind of the, the looming threat of, extinction, and, AI is, probably the latest, technology paradigm that is, you know, putting, a lot of, partners maybe at, well, surfacing that conversation again, let's, let's say. But, really, I think what's striking is that the partners, you know, from what we can see, are still showing, you know, pretty healthy growth, pretty healthy optimism, and especially around AI, you know, really showing a, a real surge of confidence in their ability to, navigate their business model in the, in the AI landscape, and that certainly was one of the data points that came out.
You know, 83% of partners who we surveyed, explained, or showed that they were confident about their business prospects in the, age of AI. So overall, I think, you know, lots of good optimism from the partner community. It seems like there's two ends of, of this...
Let me try that again. It seems like there's two ends to this thing. One is the selling motion around AI products and services, and the more we get into AI, the more challenging and complex that seems to be for the end customer.
So is that creating the opportunity for the partners? Because ultimately, it just comes down to who has the expertise. Yeah, exactly.
So, I think as you highlighted, from a portfolio side of things, any time there's a new, technology landing in the market, that is a new technology that, tech partners can bring to their customers, as part of their o-overall portfolio. And certainly, that is one of the, you know, when we look at AI software, one of the, or the technology that partners indicated is going to drive, growth for their business, that kind of came out overwhelmingly, on top. Um, but then, of course, there's all the other, associated underlying technologies that really support that.
Um, cloud infrastructure is still showing a lot of, strong growth. Um, cybersecurity, it's a technology that, you know, no matter what trend is happening in the landscape, it has cybersecurity, implications. So partners that are in the business of cybersecurity, will see more, opportunities, around cybersecurity as they're deploying, AI and AI software for their customers.
So it's not just the AI software itself that creates opportunities for partners, but it's all the underlying associated technologies, as well, and so that has a kind of a multiplier rippling effect for, across the portfolio. And then on the other end of it is how they use AI themselves internally to become more profitable, because I think a lot of the partners, as you well know, have always struggled with, you know, making sure that they're making enough money to sustain themselves, and that also requires a fair amount of expertise. And as you talk to those folks, you know, are they getting there?
Are they kind of still in the early stages of that? And kind of what are their hopes and dreams? Yeah, I think, I think that's a dynamic for every business, right?
Like, it's, it's... AI is one of those transformational technologies that, you know, really a-asks kind of two questions. One, you know, how are you as a company going to improve your portfolio of offerings that you have to the market on the back of AI?
Like, what are you providing that is underpinned by AI? And then two, you know, let's call it enterprise AI, how are you actually leveraging AI internally to improve your operational efficiency, your, your cost of doing business, et cetera? And, and so we see those dynamics play out likewise in the partner ecosystem.
Um, in fact, one of the areas, and we asked these questions, to get a pulse from partners, one of the biggest changes we saw compared to this time last year was the number of partners who are developing their own solutions on top of LLM, well, on, on top of these large language models, and I think that's something that all companies are experimenting with. How can they, you know, add a, a wrapper of their own IP, their own, use cases around these LLMs? And in, in terms of what we're seeing in the partner ecosystem, we definitely saw a big spike of that, more partners actually building on top of LLMs, you know, as, as the understanding and the knowledge base around this technology, um-...
matures a little bit compared to this time 12 months ago. Looking over the horizon, do you think partners might be a little concerned about, well, eventually the customer's gonna figure out that the cost of delivering services is dropping in the age of AI because I'll be able to, I don't know, update and automatically patch an application, for example, or I might be able to thwart some sort of security attack, at a much lower cost. And if that's the case, will there eventually be pressure on the pricing of the services?
And how does this play out in your mind? So Mike, I think that goes back to the opening remarks, right, of, you know, the, the partner ecosystem always under threat of, you know, being cannibalized by technology and, you know, evolving, you know, evolution of, of, technology, platforms. Um, but I, I would point to a couple of things.
I think you're right that the, the, kind of the question on services on human deployed kinda capital like, you know, hourly billing, for sure, those types of things are under scrutiny. And I think even if you look at some of the recent partner program, changes that we've seen in the market, where you're looking at-- whether you're looking at Salesforce or, Adobe, you know, all companies who are revamping their partner programs, and there's definitely an emphasis there of shifting some of the metrics, so to say, towards outcomes rather than billed hours. So I think there will be a dynamic there where partners need to evolve more towards, outcome type and deliverables versus, you know, a, a, a standard hourly billing type dynamic that has existed in the pro- professional services world for, for decades.
Um, the second point I would say is even the, the, the purveyors of, AI, companies like OpenAI, have, have really, shown an appetite for working with the partner ecosystem. Um, OpenAI just launched its, announced its, Frontier Alliances, and really framed in the market's mind, a ecosystem of partners who they saw as companies who are going to be at the front edge of helping enterprises deploy, AI at scale. " So I, I, I think, for, a, a, a few partners out there who really understand the technology, grasp it, there's gonna be a whole new realm of actually what we're calling frontier partners, companies who are really landing AI operationally inside of, you know, modern enterprises.
Do you think also, and I, I know we've been banging this drum for years, but the partners need to be more, business use case led, in that they're working with their customers to actually drive some sort of outcome that means something to the business. But have we finally come to the point now where, well, that's no longer an option, that's just a matter of survival? Uh, absolutely.
Yeah, I think that, increasingly, I mean, that's been a dial, as you, as you alluded to, that's been kind of being turned really for a number of years now. Um, you know, it's not just about deploying horizontal technologies en masse inside, inside companies. Like, that part of the market will gradually commoditize.
Those will be a role for, you know, the act of just simple reselling. But, you know, admittedly, it will kind of be a different part of the value chain. Whereas the actual, you know, deployment of technology to make it, really map towards the specific business outcomes that a customer has, that's the secret sauce that partners can, can bring, and being that kind of inter- interconnect between here's this whole kind of complex world of technology that exists out there, a growing, complex technology, world, and here's how it can map to, you know, my specific customer and the, the specific challenges that they have, the specific processes that they have, the specific industries that they play in.
Um, and partner is always going to be a, a, a strong interconnect there, just by virtue of being that, you know, kind of last mile, engagement between, the tech community and the, the end customers themselves. It also seems like the line between what services the partner builds and provides versus resells from somebody else is getting a little blurry, and maybe has been for a while now. But we've had this software as a service kind of motion and this whole as a service category.
Are we getting better at kinda sorting out, if I'm a partner, what should I go invest and build in versus what do I need to just kinda resell within my portfolio, but I, I don't need to build everything myself? Uh, I, I think that we actually might be getting more complicated there, unfortunately, and I think AI might supercharge that. Um, I noticed that, for example, one anecdote is, when, when Google Cloud launched, well, launched the, the agentic, category in its marketplace, you know, one of the big, contributors to that were, were the, the GSIs themselves.
Um, and, you know, I think that's one kinda corner where-Um, if anything, what, what agentic is doing is kind of bringing that world of product and services more closely together. When you think at the very core of what, you know, agentic does, it is that kind of almost, technologifying of, of, of professional services, of, of, of human capital, of human labor. So I, I think both the, the, the quote unquote traditional SaaS software companies are wanting to get into this space, but so are the traditional services companies.
So yeah, I do think agentic brings these two, I don't wanna say disparate worlds, but you know, a more sep- more disparate worlds together in, in a way that, I, I think we really haven't seen, prior to it. So I think there will be some reframing of, like, what roles do, do partners play versus technology companies. But, I think what doesn't change is that last mile aspect and the fact that fundamentally technology companies are building products and solutions kind of more for wide mass adoption, and partners are, you know, gearing their offerings more towards very specific, client customer bases.
And so that's something that they could still bring to the table in many cases as a competitive advantage and, and, you know, a-a-an important role too, that they'll continue to have in the, in the ecosystem. Maybe I'm doing this too long, but every time there's a new inflection point in the technology, I always see the same thing play out, and I wonder if you're gonna see it here again. Um, there's a consolidation among the old guard, folks who don't wanna necessarily move on to the next phase and don't really wanna play with the business model and reinvent their business.
And then there emerges this whole other class of folks who are native to that technology, and maybe we'll see some AI native partners as well. But is that whole drama just playing out again? I think so.
I, I think, you know, anytime, you know, a new technology lands in the market, there's gonna be a new ecosystem of companies that are really building kind of very, you know, much around that new technology paradigm. I mean, in the same way that we saw kind of the born in the cloud partner, I think we will see the born in AI partner, a-and again, we're calling them the frontier partners. Um, but as we saw kinda play out in, with the born in the cloud partner, many of those will end up getting acquired by, partners of old, so to say.
Um, and you know, I think we'll see that kind of life cycle, play out again. So do I think that, you know, the, the big GSIs of the world will, you know, kind of disappear? No, certainly not.
But some will, you know, some will rise, some will strengthen through M&A activity and skills development. Um, some probably will, struggle to make the leap. And the same will be kind of, you know, can be said of each of the major, partner categories, whether you're talking VARs or, distributors, et cetera.
Um, so I think we'll see this, you know, interesting blend of new business models, new capabilities, M&A activity and consolidation, as the partner landscape kinda goes through a, you know, a, a typical reshuffling, um- As part- Yeah, you know, kinda story plays out again. Yeah. And, and as part of that, do you think the next generation partners might be more independent of the vendors than they have historically, where they're always kinda dependent upon, you know, in the old days, just reselling something that somebody else made?
But maybe this next generation of partners, you know, they're the ones who will create their channel programs and, and, and then decide if the vendors wanna be part of it. I don't-- I th- I think it will be more, the next generation of partners will be aligned to a different part of the technology ecosystem. So if you were a, a, a, a, a channel partner in the, l- the, the, the, the early part of the century, the, the kinds of technology companies who you would build your business around are probably gonna be very different from, the technology companies that you would build your business around if you were launching a partner today, you know, and just by virtue of some of them not existing.
But if you were building a, a AI first practice, it's almost certainly you're going to want to build your tech, and services platform around an OpenAI, an Anthropic, or even a, you know, a Google Cloud or, or, or what have you. So I, I, I think the, you know, AI as a technology paradigm has kind of moved the, the center of-- w- is gradually moving the center of the partner universe, so to say. Um, I, I, I think you could even kind of make that same kind of leap when we were talking again about moving into the born in the cloud era, right?
Um, there was a time not too long ago where, you know, there weren't that many partners out there who were building their business in and around AWS or Google Cloud. Now they have become very much, you know, top strategic, partners for, for most company, for most partners, i-in the ecosystem. A-and I think what's even more impressive when you have a company like Microsoft that has managed to navigate those transitions from, you know, from era to era and remain a top, you know, key strategic partner for the ecosystem.
Well, fast-forward 10 years, I think-The technology partners will be, you know, still reliant on their underlying vendor technology brands, but what brands it will be, you know, that, that, that kind of, that, that, that, lens moves gradually over time, I'd say. All right. Well, I know you just got the first half report for 2026 in the books, so I, I know there's no rest for the weary, though.
So what's the second half looking like? Ooh. Um, well, you know, I think the second half we're gonna have to see, you know, some of the, some of the let's call it, problems of old around, you know, I think co- going into, going into this year, some of the challenges the partners were e- expressing in terms of what they were, concerned about going into 2026 tend to be a little bit more inward facing around, like, their portfolio competitive- competitiveness, around their ability to, you know, dr- you know, to drive, to drive sales.
Whereas this time last year, a lot of the concerns were more external factors, the state of the economy, supply chain issues. Um, I almost wonder if, you know, as we kind of get into 2026, if some of those concerns, macro concerns, might start to rear their head again, whether you're looking at kind of the, the health of the global economy, whether you're looking at kind of, supply chain short- shortages that are impacting from the, you know, memory constraints and the rippling effects that that will have throughout the entire, technology stack. So I, I, I wonder if some of those, concerns and fear factors will start to, simmer up as we kind of get into the middle part of the year.
All right, folks. You heard it here. The times are a-changing in the channel one more time.
Hey, Alex, thanks for being on the show. Hey, thanks for having me, Mike. Talk again soon.
All right, and back to you guys in the studio. Hey, everyone. Welcome back here to Techstrong TV.
I am really thrilled to have my next guest on here. You know, she's actually one of the few people we have who live in South Florida, so the last time she was on she was nice enough to come up from Miami to our studio, and we did this in person. Unfortunately, she's not in Florida today.
She's up in New York, and, so we're doing it via Zoom. But let me introduce you to, Rebecca Krauthamer. If you...
Maybe you've saw or, or caught the last time Rebecca was on with us. Uh, Rebecca is the CEO and co-founder of QSecure, a, post-quantum security company. And she's here today as one of the winners of our initial Quantum Security 25 list that we did in partnership with our friends at DigiCert.
Rebecca was a worthy member of that list. I... You know, as a judge, I, I was looking for her name when the nominations came in, so I was happy to see her on there.
Rebecca, welcome back to Techstrong TV. It's great to have you on. Alan, it's great to be back, although I do wish I was down in Florida with you in the, in the sun, um- Well, I- ...
but New York will have to do today. I, I heard it was warm in New York today, or it was yesterday. Maybe it got cold?
I'm giving it a hard time. It's beautiful, sunny, clear, um- Yeah. I, I spoke- It was, like, 70 degrees.
Yeah. Yes. I spoke to my brother.
He... " We were up in Boston this weekend. It was really cold there visiting my, my older son.
Anyway, Rebecca, as I mentioned, you've been on the show before, but not everyone watching this saw that one. Give them a little bit of your story, if you don't mind. Sure.
So my background, I came, I came out of the AI space. So I got to study AI at Stanford when, like, deep learning was the, was the buzzword. You know, now it's, now it's LLMs.
Mm-hmm. I worked in that space for several years, and then I kinda joke in, like, 2015, 2016, I got bored with AI, and I wanted to see what was next. And so that's how I entered into the quantum world.
And so we, we worked in the quantum space, like, building applications for early quantum computers. Uh, and then in about 2020, we got an initial grant from the US Air Force, and they said, "Hey, quantum computing, it's gonna do these amazing things, and can you help us out with the security side? " And so that's what gave birth to QSecure, which is, as you mentioned, we solve that quantum threat.
Excellent. " We solve the- I, I, I, I guess first we gotta define the threat, right? Sure.
What, what do you think the biggest... I mean, I know, but maybe not everyone out here knows the biggest threat that quantum, you know, supposes that, it... or it presents to ourselves.
So the threat is... It, it's got a lot of buzzwords, but it's pretty simple. Uh, every time we send data somewhere or data gets sent over networks, and we want it to remain private, it's using encryption.
That encryption, we rely on basically one type of encryption for that, for, for our communications. That's the type of encryption that gets broken by a sufficiently powerful quantum computer. So that's a big bad, right?
It's coming, it's coming fast, but it's not here yet, so why do we care? And we care because of this idea of harvest now, decrypt later, or the idea that bad actors are sitting in, listening in on those, those transmissions, harvesting that encrypted data and stockpiling it for when that quantum computer comes online, because a lot of that data will still be relevant. So there are now mandates, across US government, across the world to make this transition to quantum-safe infrastructure.
And this is the thing that I find most business executives still don't know. A lot of them know that there's a big threat, but they don't understand that it is largely a solved problem. And in twenty twenty-four, NIST, the, the National Institute of Standards and Technology, eh, established, verified this new suite of algorithms that run on regular stuff, not on quantum computers, run on our regular devices, and these algorithms protect against quantum threats and classical threats.
So when I say it's a solved problem, that means that you can adopt and should adopt these algorithms today to protect secure communications, and you do not need a quantum computer to fight against that quantum threat. You just need to adopt those, those new encryption algorithms. Post-quantum algorithms.
Exactly. You know, to me-- so we, we've solved post-quental-- post-quantum algorithms. We've come out with post-quantum algorithms.
I think the problem we have though is that, you know, you could lead the horse to water, but you can't make him drink. And that, and that to me is gonna be the biggest issue, right? We can't get people off of, you know, Windows Ten or whatever the latest version of Windows they discontinued.
Um, right? How the heck are we gonna get them to move into post-quantum algorithms? Y-you know, it's, it, it-- that's the, that's the, the trillion-dollar question.
Um, we-- I was out in, on the Hill in DC, right? We were talking to some of the, the Senate offices. And there, there's a lot of room, a lot of air being taken up on the Hill by AI.
AGI, what are we gonna do about it? Are we gonna regulate it? How should we regulate it?
And these are big questions, right? These are things that people care about, but it's hard to find something definitive to say, "This is the path through. " On the other hand, when it comes to the quantum threat, it's this big thing that's coming into, it's econometric modeling, right?
One successful attack on one of the top five US banks could cost, cause cascading- Trillions ... financial failure. Trillions.
Two to three trillion dollars. Wow. So this big thing coming, this big, big problem, but again, clear path through that forest, right?
We have an answer. We have... And it's not, it's not typical that we have this big of an issue that we know how to solve, and yet, right, it's getting people to move because there's so much that in the cybersecurity world and beyond, there's so much that, that rightfully takes, takes up attention.
So how do we get people to move? I, I, we have government mandates now. The first timeline, the first part of that timeline falls into place at the end of twenty twenty-six.
There can be no new, technology acquisitions into national security that don't support post-quantum cryptography after the end of this year. But, you know, I, I think back to Y2K, and a lot of people think of Y2K as, a, a anticlimactic. Like, oh, was it overhyped?
Was it...? But the truth is, the reason that, that nothing devastating really happened is because collectively there was a deadline, and collectively across the world, somewhere between six hundred billion and one point one trillion dollars in today's, adjusted for inflation, it was spent to remediate. But they had the luxury of having that deadline, right?
And, and the reality with quantum is that we don't know, and we won't know when it comes online. Right. So we need those, those government timelines, but we need, we need more, and we need this to be not just a boardroom discussion pushing it down, but we need everybody who is consuming, digital services to also be putting pressure on organizations to adopt in a timely manner.
Because I know personally, I use a lot of services, and I want that data to be kept secret, not just for today, but for, right, the next several years. I mean, you know, th-this is kind of an old story in security. Nothing happened.
You did your job. Yep. Right?
Exactly. Yeah. And, and, and when something happens, well, the stuff hits the fan.
But here, here is the... You know, to me, the, the biggest stick we have with, with forcing people to adopt post-quantum, whether it's kicking and screaming or not, is expiring certificates, right? And I know Google's moved towards this.
They wanna get to, what is it, a forty, like some odd number. Was it forty-seven days or something like this of, of- Mm. It wasn't like- Let me get- ...
a thir- a month or thirty-one days. It was like forty-seven, every forty-seven days or something- Yeah ... the, the certificate expires.
And, you know, that's gonna force a lot of people who, when we're talking about digital certificates like that for your websites, your SSL certificates, your, you know, your encryption that way. But so much of our PKI infrastructure-Doesn't necessarily run on a certificate issued by a third party that, you know, they could become the enforcement. Um, I, I just don't, you know, I wor-- I honestly I worry about it because I know people procrastinate- Mm-hmm.
-by nature, right? Mm-hmm. And until there's literally a gun to their head- Right ...
they, they just don't, just don't do it. Um, let's talk about QSecure a little bit. How are you-- How, how's QSecure helping with that?
So, well, you know, you just-- you said so many things that are, that are true. And, and the procrastination is, is going to happen. It's inevitable.
It's something that we, we know people are gonna act at the last minute. The problem is, it's already the last minute, right? So what we do...
When we, when we started, and we got that initial engagement with the Air Force, we understood three things, I think, before, before a lot of people were talking about this, just because we were in there. We were embedded. We were thinking about solving for this migration.
So, one, the Air Force is a really good example of vast, often legacy infrastructure that is very hard to upgrade, a-and has taken huge investment to build out, right? So we can't ask people to rip and replace in the same way that, that past migrations have happened. So legacy, right?
Legacy compatibility. Um, two, the sprawl of li-this-- Everyone is still underestimating how big and how much effort needs to go into even just setting the groundwork to make this happen across all of that digital infrastructure. So the scope, right?
We need to help make the scope tractable. And three, this is not going to be the last migration. This is probably the biggest that we've ever seen.
However, this is really a forcing function for us to think about encryption management differently, right? We can't-- As, as AI, as quantum comes faster and faster, the threats to encryption similarly, right? Um, it's gonna be under attack all the time.
So this is a catalyst moment for us to rethink how encrypted data security, right, is done. And so what we do is, is we've abstracted out the encryption from the asset itself, right? And so, solving for all of these three things, making, simplifying deployment.
We take it at a network level because this is where the quantum threat really is. It's, it's asymmetric encryption. Um, so we decided to solve it at the network level.
So we, we built a orchestration layer, a service mesh for managing and deploying encryption, so you can get up to date with your post-quantum cryptographic algorithms without, again, rewriting any code. Um, and then should anything change, should you need to change out a library, an algorithm, you can then push a button and make that rotation happen. Define your policies, whatever, whatever is within your organization's policy, that is, you can, you can just push a button instead of going through many years of a migration process.
So that's what, that's what we do in a nutshell. And, what I'll say, interestingly, is that we don't always get brought into organizations to carry out the post-quantum migration proper. Like you're saying, a lot of organizations need help with man-- cert management.
Um, or even just getting from, a lot of applications are stuck on TLS one dot two. You need to get onto one dot three to, to even start the migration process, right? So this idea of cryptographic debt and management is, is a really important one, and often what we see is the, the first step, the forcing function, even before post-quantum.
Got it. Rebecca, we're running low on time. I did wanna mention, as I started this with, you are on this inaugural list of the Quantum Security twenty-five, top twenty-five folks in quantum security.
Some really big names there. I don't know if you had a chance to look around at the rest of the list. I'm sure you probably know.
One of the things I've discovered in this exercise is that it's a small world and when it comes to quantum and quantum security, and a lot of these folks have worked together, know each other, you know, the whole thing. I would imagine for you there's a lot of familiar names on the list. Absolutely.
Yeah. I think there's only a, there's only a small few that I haven't actually met in person or worked with, but it's a, it's a, it's an honor. Um, it's an honor to be, be chosen by Dissert and by you, and obviously, Alan, you're a, you're a legend.
Um- I'm not a legend, please. You, you're gonna make it hard for my wife. Don't say that.
Um, but, but no, I, I will tell you, as one of the judges, you know, I, I actually used a little AI here and said, "Give me a weighting system- Mm-hmm ... " And, and, and it, it really helped to give at least the ones that I nomin-- like my list that I submitted for the nominees. I, you know, I-- It, it mixed it well and weighted well between, you know, pure researchers Mm-hmm Business leaders, you know, business leaders, executives, you know, call them evan-ev-ev-evangelists.
I mean, it, it, it, it gave me a good cross-section of the community, and that's what-- I mean, we didn't wanna make it all researchers. We didn't wanna make it all CEOs. Right.
We wanted a, a, a good mix of the people who are making it happen. So I, I was really happy with the way it turned out. It was interesting, you know, we had four judges.
We all submitted... I think when you took all four lists and, and, you know, did a diff- Mm-hmm ... twenty-two or something like that of the twenty-five were the same.
Wow. Wow. It was just- And I imagine there were- ...
the last three ... good amount of nominations. Oh, yeah.
There were, there were over a hundred, I think almost a hundred and fifty- Wow. Wow ... nominations in general.
But, like I said, I think we came up with the same twenty-two, and then we kinda went back and forth on the last three. I'm not gonna say who the last three were and who were the other twenty-two, but everyone on that list was deserving. Um, but, and none more than you, Rebecca, so congratulations on, on inclusion in the list.
We appreciate it. Uh- Well, thank you ... we appreciate you being in, you know, doing what you do.
And look, next year, you're coming back home, next time back here in the studio, okay? Back in studio. Done.
All right. Hey, enjoy New York. Again, congratulations.
Best of luck with QuSecure. We'll be in touch. We're out here- Thank you ...
though. Thank you. Rebecca Krauthamer, CEO, co-founder, QuSecure, here on Techstrong TV.
We're gonna take a break. We'll be back. Welcome to Security Boulevard, the cybersecurity podcast from the Futurum Group.
Each episode explores a variety of topics within cybersecurity and the technologies that drive it. com, the Security Boulevard YouTube channel, Techstrong TV, and all of your favorite podcast platforms. Let's meet today's hosts before we jump into our fun topic, starting with Fernando.
Fernando, it's good to see you again. Absolutely. Hi, everyone.
Uh, Fernando Montenegro. Uh, I'm, I'm eager to, to, to, to dive into the topic. We're-- as, as we're chatting, we're also preparing for the, the, the RSAC conference coming up, so, it's a good thing.
I just hope that the cold I have kind of weans off before, but I think we'll be fine. Yeah. You, you'll be fine.
Just, drink some tequila. That seems to be the, the, the general solution to- Oh, my God ... getting rid of whatever ails you.
Um, also joining me, of course, is Mitch Ashley. Mitch, it's good to see you as well. Thanks.
Great to be here. And tequila, by the way, just makes you not remember how bad you felt, so it's okay. So I didn't mean to make you cough there.
You are sounding better, Fernando, so far. For the record, this is water, okay? Just- Okay.
for the record. Okay. Good.
It's a family show. Um, good to be here, guys. Yes, and RSAC is on the doorstep, you know, right around the corner here, so that's top of mind, of course.
But there's also plenty going on in the world, in the world of security, so I imagine we'll have plenty to talk about. Oh, absolutely there is. So let's jump into the topic, and I, I get to finally say something I've been waiting years to say in my little Gen X heart.
Regulators, mount up. Uh, if, if you, remember what song that lyric's from, you should probably take some ibuprofen 'cause your back's hurting. Uh, but what I wanted to do today is talk a little bit about regulation around security, because we've seen a lot of things come up in the last couple of weeks that make me kind of wonder, how we should be approaching some of these, massive advances in technology and automation and things like that.
Uh, you know, look, we, we've, we've beaten the Claude bot thing to death at this point. Uh, yeah, I think we've referenced it, you know, a couple weeks ago. Uh, the head of, Meta's AI safety division had it delete all of her email, because, well, she didn't tell it to stop.
Actually, she did. She told it to stop, like, four times. " Uh, and then we have, people that are proponents of this AI and, and not just, folks like Sam Altman, but people like Marc Andreessen, who not only say we shouldn't regulate it, but that it should be illegal to even attempt to regulate those kinds of things.
But as a security person, I no longer believe in the goodness and faith of humanity. Uh, I know that everyone is evil and mean and needs to be told what to do. Uh, so you know, throw that one out there for everybody to leave a comment about.
Uh, but I, I kinda wanna throw this out to, to the two of you. Um, as we see these things get more and more complicated, as we see more and more inputs causing the decision-making, outputs to happen, should we have some kind of system in place that functions almost-- W- you know, we say guardrails, but it needs to be, like, an inviolate rule. Things like, oh, I don't know, you can't kill people.
Or convince keep people into killing people. Uh, w- right? Like, well, a-and this...
There's been a lot of articles that have come out recently about things around, like, it's called AI psychosis now. We'll probably come up with a DSM version of it later. But, like, the AI just goes right down this rabbit hole of feeding into whatever a person says that causes them to do it themselves sometimes.
Should there be a system in place and not just a, "Oh, we'll, we'll make sure that doesn't happen again," but, like, if something along those lines occurs, you know, kind of like Asimov's rules of robotics, like, no, under no circumstances can you cau- allow that to happen. Well see, we're kind of operating under the same similar but not regulation rules as the internet has been, which is if I'm a carrier, I'm an ISP, I'm just the network, right? What you do on top of this is your business.
I'm not responsible for whatever it is, illegal or not legal. Um, w-we've kind of taken the same approach, although albeit it's not through an act of Congress or regulation, which is we don't wanna, we don't wanna inhibit anything about AI, so let it be what it's gonna be, and then we'll deal with the fallout, with the problems that happen. Now, if it happens to be someone commits suicide or commits a crime or whatever because of psychosis, that the AI, you know, the AI did, it sounds like Son of Sam, but that's a whole 'nother issue.
The AI did it, told me to do it. Um, you know, we're in this mode of let's just let, let happen what's gonna happen, we'll-- and then we'll deal with the fallout. And I, while, you know, I think that's all good from a let businesses do whatever the heck they want, or individuals, there also are consequences to doing that, and there will be some very negative, and we've seen some already, consequences from it.
And it's, it's a safety issue, right? It's more than just a regulation issue. It's a safety issue.
And that's a lot of what happened with the kerfuffle with, Anthropic and, and the Defense Department of, you know, well, you aren't reg-regulating, but we're gonna kind of self-regulate ourselves with our EULA, with our use, what you can do with our technology, like we don't want you to blow things up with it. Um, there... But there's, that's, that's a different kind of self-regulation.
Yeah. I'm, I'm, uh... This is a deep, deep topic, and- ...
I, I can bring economics into it the very first second of the conversation in terms of externalities, right? When somebody makes a decision that doesn't take into account the whole cost of something, right, they are more, they will do more of it, right? So, this is not cybersecurity, this is not IT, this is economics, right?
The way that we resolve externalities is, amongst many other things, regulation, right? You bring the cost back into the, to somebody who is doing this as a way to minimize that. And I, as much as I agree that, like, I'm a, I'm a Gen X kid and, and I grew up under, I mean, South America, but like, like, Reagan, right?
And, and, the, the most dangerous words, right? Um, "I'm from the government, I'm here to help you," kind of stuff. But it's not quite like that, right?
I think that we have, as a society, deployed technology widely enough that we start hitting limits of what technology-- Uh, we start hitting societal limits. And it's funny you bring up Andreessen. I mean, he wrote the, he wrote back in 2001, "Software is eating the world," right?
Uh, 2011, I think. And he was right, right? Software did eat the world.
Here we are. But the, the, the consequence of that is, look, in a society, we need some guardrails, we need some limits, right? Because that's how societies function.
And here we are. So do we need regulation? Absolutely, we do, right?
Are we getting the right type of regulation? We're working towards it, but I'm a, I'm a, I'm a free market as much as the next guy, but we do need something. And, and the, the-- I think that there is so much going on that we are losing track.
So let, let's, let's split things apart, right? So the whole Anthropic and, and Department of Defense or Department of Wars, they now want to be called, is, is, is one thing, right? I would argue that the indiscriminate use of AI in other things, I mean, this is where, on, on, on civil society is something that we need to be more aware of what's going on and where we can use it, and where there are, I mean, 50 states in the US and probably 50 different regulations, or, or if not more, on the use of AI.
But the call to arms, I would say, for security practitioners is get familiar with what's going on and don't dismiss it, right? This is, I know we talk about cybersecurity, and I'm sorry for the rant, guys, but I know we talk about cybersecurity, but when I first came into this industry, it was called information security, right? And well, it was always broader than just, quote-unquote, "cyber," right?
Uh, we were chatting just before, the, the, we started the recording, like reminiscing about old certifications. I'm an old school CISSP, and I remember having to, like, there, there was a, there is a module on law regulation and ethics, right? It's here.
We should be aware of it. Sorry. Rant, rant over for now.
Oh, and don't worry, the law versus ethics episode will be coming eventually. Like, that, that one's penciled in on the calendar. That, that will happen.
But, but the reason why I think it's important that we have regulations is because the systems that we're building are learning from our behaviors, and that's creating a challenge, because what do you do when someone says, "Oh, well, that's the law. You have to follow it," and then they don't? Like, what are we teaching the, the, the learning systems of the law is really just a set of guidelines?
Because one of the things that you guys brought up was the, most people should be aware of this by now, Anthropic was a, provider of AI systems for the US federal government, specifically, the Department of something, whatever they wanna be called today. " Um, like you're re- you're relying on a company to self-police. That's like saying, "Oh, look, insider trading shouldn't be illegal because companies will just do what they're supposed to do," right?
They- they'll do the right thing. And if you look at the law, the right thing for them is to make as much money as possible and d**n the consequences. You know, and I'm sorry, to make the most money for their shareholders.
And see, that's where you're getting into the nuance of the law, right? And that's why regulation not only has to be explicit but specific, because when you let people have, creativity within regulation, that's where we start running into specific kinds of problems. Well, you never said that it had to be active.
You just said that I had to have a firewall. And it's like, well, what are, what are you trying to argue there? And so wh- when we, when...
And, and those are the kinds of things that the system will learn, and then eventually it will parrot back to us, what we've seen, because that-- Those are the stories of the earliest chatbots, right? You expose them to the internet for 20 minutes, and they turn into, not nice things, we'll put it that way. So- Well, Tom, I think, you know, there, there's different kind of regulations.
There are protective things like I was referring to Section 230, right? Right. The Communications Act that protects ISPs.
That- that's very pro. The, ISPs obviously, you know, who lobbied for that. It wasn't, it wasn't the consumer worrying about whatever.
Um, but there's also, you can't regulate yourself out of every edge condition, right? Especially, and I think that's the fear with AI, is we don't know enough about it that we should regulate it, but we don't know enough about it that we don't know what to regulate it. And you combine that with we're in an era of, I don't know what the right term of it, of it is, term of art is, sort of not trusting the expertise of people in this, in the, the domain that they're an expert in.
So if you're gonna write regulation, but you aren't gonna invite people to the table who either know AI really well but have less of a bias influenced by financial means or driven, also that not only know AI, but also know the security side of it as well. So it takes a combination of things to do it well. So, but we don't have that today.
That's not an environment that we're working in, that we live in, at least not in the United States. Um, it's, it's more true, I think, in, in Europe, but it's not perfect there either. The, the, the fallback for that is either all the way back of, to your point, Fernando, let's just rely on what the companies wanna do, self-policing, right?
Which is, who knows why Anthropic decided they want to stand behind a couple of rules, and I have a, and I have some thoughts about it. But the, the middle ground or somewhat middle ground is the whole define your policy and then prove that you met it. That's what so much of certifications are about with companies, right?
So if you want to be certified for this trustworthy computing or trust, online trusting for websites, they don't tell you everything that you should do. They say, "Define what you think you should do, and then prove that you did that," so that the people who are doing business with you could say, "What's your policy, and are you, is that what you're doing? " So there, that's sort of the trust but verify.
Okay, if I'm willing to buy into what your, what your level of what you're, doing today and that I have some way of knowing that you've done it, then I can accept those terms, lack of a formal regulation. Yeah. I, I, I'm, I'm latching on to something that, sorry, that, that, that Tom mentioned about, shareholders and whatnot, right?
So this is, Milken Friedman and, and, and the, the, the theory of corporate governance, of shareholder primacy, right? That, it wasn't always like this, and there, I, I'm, I'm, I'm not going to, I don't know enough to argue both sides of the, the, the, the, the argument, but there is something to be said, people are questioning that now. Now, but the thing I wanted to bring this back to, to, to, to, to our audience is, is, is what role do you play in this?
Right? And the role that you play is absolutely critical because from a, as a cybersecurity professional, right, you are being looked upon to help navigate the fundamental question of, do we trust what we are building, right? And what does that trust entail, right?
And there are elements of that trust that are extremely technical in nature. Hey, are we preventing prompt injection? Are we, do we, do we have the proper level of data security so that RAG doesn't, doesn't find information or doesn't, doesn't spill information that's, that it's not supposed to, and so on.
But there is an element of governance, and there is an element of regulation as well that, again, I urge people to get familiar with, right? So, ISO 42001 on AI governance, how well do you understand it, right? How well does it sit in your environment?
And even if you're not going to go down the regula- the regulatory part, I think that you have a voice as a security, practitioner in how should we think about this inside of our organizations, right? Who is accountable, right, for AI failures, right? You should have a voice in that conversation.
And my perspective is that as sophisticated as it is, right, AI is tooling Right? Agentic AI is tooling at scale. Yes, there is a level of autonomy.
Yes, but ultimately that has, that, that accountability is still human, right? That accountability may be the chief AI officer who decided to deploy it. It may be the, the, the project manager or whatever.
It may be the CEO, but, but navigating that conversation and where regulation ties into that accountability is something we should all be doing. So let me give you an example of something that's not a regulation, but it might as well be, and, and the unintended, side effects that I can see happening from that. So, hopefully you guys are familiar with lockout/tagout on equipment where, engineers and contractors and people carry a little padlock with them, and they lo- use it to lock out a piece of equipment if they're working on it.
And the fact- Mm-hmm ... that if there's a lock on that equipment, you don't, you don't mess with the lock. It's not yours.
And, and there are stories, right, of people who have left locks on equipment for hours and left the site, and, like, you don't cut that lock off because you don't know what's going on. They've had to recall contractors to cut them off, because a- as people will tell you, that was written in blood a long time ago because people have died because you, you bypassed a lockout. We know that, right?
That's not a, that's not, like, a hard and fast regulation. I mean, OSHA might have one, but, but by and large, people know if there's a locked out piece of equipment, you don't touch it. So what happens if there's no regulation saying you absolutely can't do that, and you can convince someone, "Well, the, the line's down and it's a million dollars an hour if it, if it's not running, and the line's been down for an hour.
" What, what kind of calculus goes in there without a hard and fast regulation that says we don't do this? Because I... And, and Mitch, to your point, yes, I absolutely agree.
You're never gonna be able to solve every corner case. But what you have to have is a set of guiding principles. And, and, and I come back to Anthropic, at least they've tried, right?
They have enshrined things in the, the baseline of, you know, we're gonna do this for the good, we're gonna not hurt people. Like, like you would think that that should be assumed, right? But, you know, the-- like the movie "I, Robot" is literally a corner case in how to get around the three laws, right?
Like, like what happens when the robots just decide the best way to save humanity is to enslave them. But, but that's not the problem. The problem is, is that without explicit definitions, things become very murky.
Like, well, you never said that a... You know, a good example of this is kidnapping. Is it illegal to kidnap somebody?
Yeah, there-- it's a crime. What's kidnapping? Well, it's crossing state lines with somebody.
" Yeah. Like that, that's how, like, fine the regulation has to be. And so I feel like one of the things that, that we're, we're running into is that without good regulation, without explicit rules, writing it down, that's just inviting a disaster.
Because if you just expect people to, quote-unquote, "do the right thing" or listen to the experts, the people in Grafton, New Hampshire would love to talk to you as soon as they're not getting eaten by the bears that invaded the town five years ago. Because, oh, people should take their garbage out. Like, that's a societal norm.
Turns out that's not, 'cause under the right circumstances, people can be convinced to just not take their garbage out. Let me ask you, Tom, do you consider like NIST and ISO st- standards or whatever you wanna refer to them, do you consider that regulation when you use the term regulation? Because my, my belief is the, the chance we're gonna get anything useful out of the federal government in terms of regulation is, is next to zero, if it's even non-zero.
So I think the real, the real effort is around what ISO is doing, 'cause there are some efforts around AI management systems and risk management. I don't know all the numbers for it, but NIST has its own framework for AI. I think that's where we're gonna get the guidance and the- Yeah ...
kind of agreed upon rules of the road, right? They're not gonna come from federal laws, they're gonna come from that. At least that's my opinion.
I, I mean, the only way that that would be, be actually valid is if, the EU said that if you don't follow ISO, we're gonna fine you like 4% of your global revenue every year kind of thing. The, the-- to me, the difference in a regulation and a guideline is the enforcement policy, is like if, you know, if it's a guideline, you can do it if you really want to, but if it's a regulation, you have to do it, otherwise we punish you. Again, going back to the whole law versus ethics things.
Um, you know, regulations are laws, guidelines are ethics. And, and we come back to, well, who's gonna tell me to do that? I agree with you.
A- a- but to be honest with you, Mitch, as low as your opinion is of the, of the US federal government implementing regulations, my opinion of corporations regulating themselves is slightly lower than that. Because- I agree with that ... if it does not produce a profit for the shareholders, they're not going to do it, and we've seen that time and time again.
Like, all you gotta do is go read Upton Sinclair, and you'll know why we are where we are today. A- and, and I just, I feel like somebody who's not the company and not the shareholder needs to be the one making the, the, the call on that. It needs to be some kind of a neutral third party, and ISO's about as neutral as you're gonna get.
Yeah, the, so here's my argument to what you're saying, is that yes, I agree with the... Trust me. I know the financial motive of companies, startups or large corporations.
Don't disagree with that at all. That ultimately is even when you're following standards or certifications or whatever, that's where those compromise, that com- compromise line is drawn. But I don't think NIST and ISO are ethics.
I think they, what they are, are a shared set of agreements of how we're gonna do things, but the enforcement part of it you're saying is, is missing, it actually is there. It's sit-- there in a much different way. If the people, if people who are making financial decisions to buy things or work with companies, whatever agreements that they have for their companies to operate with other companies, whether they're vendors or partnersIf those things are part of what they require and they provide evidence of that, certifications, different things, that's how that elevates into the, "Yeah, you're not gonna go to jail if you don't follow it, but you might get sued or you might get whatever," right?
There could be some consequences to it. " That's not gonna happen, not in today's climate anyway. So, I...
And I'm gonna give Fernando a chance to, to respond to that. But I just wanna say that you hit on the third leg of that stool, which is not legal and not, like, self-reporting, but community enforcement. Right.
Yeah. And, and I'll-- Let's-- Let-- I'm gonna let Fernando respond to that before I jump into where I'm gonna pivot to on that. No, I, I, I, I...
We can, we can, we can move quickly. The, the point that was, that came to my mind is that what are we expecting to happen here? I do not want, uh...
We want to balance innovation with safety, period, right? And I think that I, I, I am a big proponent of, of things like NIST and, and ISO and, and, and IETF, right? In the context of these are agreements that we have made to make it possible.
Here we are talking, the three of us, remotely with our audience listening across the world, thanks in, in large part to the fact that everybody at some point in time, follows RFC 791 for, for IP, right? Um, and the very fact that we have... And, and, and I think that we're going to ha- And that we have, different enforcement mechanisms throughout, including a amorphous market-driven, mechanism of not buying your stuff.
In my past career, I was in sales engineering, right? And one of the things we used for, for, high-end network security equipment. Well, one of the things we had to prove was that, "Look, our product is, compatible with or follows this whole list of RFCs," right?
Because that is the quality, that is the quality hurdle that the buyers expected. Why did they expect the quality hurdle? Well, because they needed to put this piece of equipment into their large networks, and they didn't want the hassle of this not working.
This is fundamental, economics. It's information asymmetry, right? It's how do you validate the quality of something.
Again, Nobel Prize work that, that, from George Akerlof, "Market for Lemons," right? Paper is 1970. And this is about how do you evaluate the quality of something.
" And that's how a buyer makes a decision. That is a purely economic thing that in, in my view is separate than regulation, right? Regulation is about an external entity defining, "Look, you need to follow these criteria or there will be this level of punishment for it," or, or...
And the role that regulation plays is that none of us individually here have so much time on our hands to, a-and so much economic power to be arguing with our telco providers that, they should be giving a service that follows a standard. So we rely on the, on, on community to do that, right? It's a, uh...
So again, I go back to I'm a, I'm-- I understand the point about regulation to some extent, limiting innovation, but you know what? We absolutely need it. I don't want innovation when I am 50,000 feet up in the air and some...
And, and I don't want the, the, those engines on that airplane to be innovating at 50,000 feet. I want a very rigorous, regulatory process that certifies those engines time and time again until they can fly. And honestly, as much as I love free markets, and, and trust me, I do, we are at the point where we need to do the same thing for technology and cybersecurity.
It's that simple. It's amazing fa- how fast move fast and break things, changes when it's a motorcycle helmet or, you know, a car's safety system. You know, your seatbelt should not move fast and break things.
But- And, and, and it's amazing that we've gotten to this point with technology. It, it, it's a testament to the creativity and innovation that everybody did. But you know what?
At some, at, at, at certain point, it becomes enough of a societal risk that, yes, you know what, guys, and ladies, and others, let's calm down. Let's make sure that whatever we're doing here works where it's supposed to work. Generally comes from one of two things: either you have a massive disaster or you have a community that's willing to push so hard that it forces the people who are participating to reevaluate things.
And that's where I wanted to pivot to, is as you're listening to this episode on March 17th, thereabouts, we are just a week out from RSAC. And I think RSAC has had a huge impact on the way that we do things because the community of cybersecurity professionals is a very loud voice. And when they come back and say, "Don't do this thing Or there needs to be some kind of a system in here to, to prevent this from happening.
People listen because me, a-and this is the joke that I have on social media, right? " Uh, as someone once told me, this is not an airport, you do not have to announce your departure. Um, but if you can convince 50 people to do that, suddenly that company has a problem on their hands because it's become a bigger issue.
And that to me is the, the third leg of the stool, is the ability of a community to organize and say, "You know what? " And that's one of the things we saw last week, is when An-Anthropic announced they were gonna pull out of this deal with, the Department of Defense, they actually crashed Anthropic's servers because everybody went to download the, the app from the App Store. Likewise, when OpenAI announced that they were gonna step in to fulfill the contract, I think someone said that it was noticeable the number of uninstalls of OpenAI off of systems to the point where Sam Altman actually got an email about it.
And, and, and- So yeah. Memes and instructions about how to move from OpenAI to Anthropic. Uh, pivoting a little bit to, to RSAC, right?
Uh, it is a forum that, I mean, many of us have been going for many, many years. Uh, it, it undergoes its own changes, right? But it is so important that, that we, that we be able to have these conversations there and, and, and, and elsewhere.
So yes, I'm, I'm really looking forward to it. Sorry. You're kind of thinking about RSAC.
Yeah, you, Fernando, you and I have, you know, a, a calendar full of appointments, right? Of companies that we're meeting with. Tom, you've got, the Tech Field Day, the Tech Field Day event that you're, you're doing there and your own list of appointments.
As I'm kind of looking, I have two lists of RSAC whenever I go, "This is what I think I'm gonna hear about, and this is what I wish I would hear about," right? And sometimes they're the same thing. Sometimes they're sort of adjacent, and oftentimes they're a little far apart.
But yeah, certainly I think we're not only gonna hear about AI this year, I think we're gonna hear a lot more about agentic AI, this moving into more autonomous type of work, 'cause the capabilities are there and people are starting, starting to use it. It's not norm, it's not there, but I think security professionals want to think ahead. They don't like to be surprised and be...
You know, they're out of the mode of let's, let's build the moat and the wall and prevent it from happening and try to keep it out of our environment. They know that doesn't work. There may be a few places in the world where that, that can be possible, but I think that that's gonna be one theme.
And I think to that point, that's sort of on my what I expect to hear, what I would hope to hear. What I'd love to hear is, my own, my own belief is one of the models we have to change about security, that we're at this pivot point, is we have to get out of the scan and fix later mode. The, the idea we're gonna scan and have human, for whatever purpose, governance, security, incidents, et cetera, you name it, and non-security, whether it's DevOps, other things, the idea that we're gonna have humans in the loop reviewing everything is impossible.
It'll, it won't scale. It already doesn't scale today, and it won't scale with AI as velocity increases. So to me, I think the industry has to move to security vendors become fixers of problems, resolution of problems, not just identifiers of problems.
Doesn't mean they're gonna be, you know, the solution to everybody's problem, but if all you're gonna do is report more problems that humans have to intervene on, that's a failure mode. Now, you could argue, and I think this is a very viable approach, is yeah, y-you need to know about those things. I think you need to find them closer to the point of origin, but even so, you still have to have other places where you look for issues, that that can be funneled into other agents that then are fixers that do, that resolve those issues.
That's fine too. But when I see announcements by vendors of, "Yeah, we're now in, in the agent development process and reporting more issues," I kind of shake my head and like, "Yeah, that's not gonna go very well for you," at least I don't think in the long term. So that, that's sort of my two top of the list things that I'm thinking are gonna be topics and would I'd like to be the topic.
Yeah. I, I, I make the joke, right? I've, I've, I've said it sometimes I think Brazilian Portuguese, the letters A and I spell ai, and ai is the sound you make when something hurts.
" Right? Perfectly tracks. Like as a matter of fact, I think I used that joke in, in my report on the Futurum, my Futurum report for RSA Conference, RSAC Conference 2025.
But, I, yes, we'll absolutely see, agentic all over the place, right? " Yeah. Okay, fine.
We, we, we can have that conversation, right? And I, I like your, your model of having things you want to hear versus things you think you'll hear, right? I would like to, I would, I very much want to hear where agentic is working and not working and, and, and, I would like to hear, a lot more around, guardrails for reasoning, right?
Everybody here is talking, we're deploying agentic everywhere. We are, but the core of that, the, the agentic reasoning engine still seems to be LLMs, right? Still seems to be lock- Here is a very capable large language model.
Here is significant context around it. We moved from prompt engineering to context engineering, and now we're moving, further along the stack. We think that this model reasons over something and, and duck, right?
And, and I don't know, I'm, I'm, I'm, skeptical that that works outside of very controlled cases. The question be-be, can we define the, the cases well enough where this works? Perhaps it is code fixing.
Perhaps it is, it, it is SOC triage, right? But beyond that, we'll see. But the other thing is that, I very much want to see, that, that, that, that I love your point about fixes.
I think that there needs to be a broader conversation around things that are honestly outside the vendor's control. If I take a firewall and I configure an, allow any, any rule, right? And that allow any, any rule is the source of a breach, with all due respect, that's not the vendor's fault, right?
So, as much as we need secure by default, and oh, by God, we do, right? We also need, this level of, of assurances and, and oversight over configurations as well, right? If I choose to make somebody domain admin, is that really Microsoft's problem that somebody was a domain admin, or is it me who gave that permission to somebody because I didn't want to do something?
We go back to regulations, right? We go back to insurance, right? Who-- how are we going to hold anything people or how are we going to hold people accountable for, failures that result in cybersecurity related losses, right?
I would love to have more of that conversation at RSAC. I'll leave you with two thoughts. Um, if you're gonna be at RSAC, you should think now about what you feel like is the biggest problem, the biggest concern for you, and that's the thing you should ask everybody you talk to.
How are you going to address this? If you can't think of a good one, though, here's another trick that you can use. This is a journalist, trick.
Ask them what they think the biggest threat, biggest problem, biggest issue to solve is gonna be. Yeah, their answer's probably gonna be interesting, but I'm more curious as to the reasoning behind it. If they think that the biggest problem to solve is, is this gonna make me a trillion dollars, that's one way to look at it.
If they think that the problem is, is that eventually it will become sentient and wipe out all of y- life in the universe, that's a slightly different problem. A-and you should, you should kind of be interested in how both of those people approach that. And, and that should at least give you some fun topics of conversation.
Speaking of which, the two gentlemen who join me every week have some great stuff coming up, and I hope they can, tell you a little bit about it. Starting with you, Fernando, what have you got working on that people should, be checking out? Uh, so Tom, you and I are, are, we are, we are moving our way through a, a report on SASE, Secure Access Service Edge, because as I like to say, there is things that in cybersecurity outside of AI, right?
Mm-hmm. So that, that should be coming up in the, in the near future, right? And be-- and, and alongside that, we are, helping or we're looking at what is the, the, the, the basis that organizations need for this level of trust, right?
And sorry to bring it back to AI, but it, but it comes down to is do you trust your infrastructure? Do you trust your identities? Do you trust the data that you have?
So, so those kinds of, of topics are, are top of mind for me right now as I, as I'm putting some research together. How about you, Mitch? Well, several things.
One, I'm gonna be issuing a new analyst insight report, about agent control plane. And, in this case, I'm, like I did with Observability Native, I'm issuing a framework for that, just so we can kind of put the parts and pieces in the places where they are part of this discussion, because the thing that's elevated in our conversation around AI is accountability. It's not normally what we talk about in security.
Yes, yes, we do, but not in terms of... It's almost equated to governance, right? Accountability through governance, through security, through guardrails, et cetera.
Um, in, in, in the world, you know, to your example, Fernando, of, you know, is it the fault of Microsoft for allowing you to make someone a, a, root admin, or is it the fault of the person who did it? We're now in a world where that accountability has to apply to agents also, like who did it and why. So what was the intent?
What was the reasoning that led AI to do that? Were there guardrails or policies in this code or whatever mechanisms we have to keep those actions within some, within some, allowed lanes of operation? And then, of course, what happened, and do we know who that is?
And so there's a lot of discussion around agent control plane, and it's interestingly enough, it's not just one thing. Yes, Microsoft has and, and GitHub has, Agent HQ. Um, we have Agent Core from AWS.
There are elements of this in a bunch of different products. And just in the last couple of weeks, GitHub and Microsoft issued the new release of VS Code, Visual Studio Code, which is very-- the most popular IDE environment, where now some of those things, you could do them within the, within the, IDE, but now they're being automated, some of these control plane capabilities, the application of governance, the application of control as you're doing more and more agent work. So this is a big rising part ofNot only the operational capability of agents and agentic AI, but also the security, the governance, and operational capability.
So I think it's gonna be a big part of our conversation. I don't think it's g- elevated to an RSAC topic quite yet. Maybe in a year or two that will be the hot buzzword.
We'll see. I can't wait for that. Uh, I also can't wait for RSAC.
As, as Fernando and Mitch have mentioned, we're gonna be doing Tech Field Day there. com, that are gonna be presenting. Uh, and I'm also gonna be running around talking to some interesting companies while I'm there.
Uh, I'm probably also going to be running, so if you see me in the street, try to keep up. Uh, but we wanna thank you very much for listening to this episode of Security Boulevard podcast. If you enjoyed this conversation, do us a favor, subscribe on YouTube or in your favorite podcast application, 'cause we don't want you to miss any of our episodes.
And then do the thing where you click the thumbs up button, you give us a bunch of stars, and you leave a comment, positive comment, and that helps the show grow. com and the Futurum Group. com, the, s- Techstrong TV website, or the Techstrong TV app.
Uh, as previously mentioned, I am now trying to get it to run on my thermostat, which should be really interesting to see Mitch welcoming me to turn the temperature up. Um, we will be back with more great stuff, and you make sure to follow us on Security Boulevard, on social media and on LinkedIn by looking for SecurityBlvd. Uh, lots more content there.
We'll be back next week with another great episode. Until then, we'll see you soon. Um, hi, I'm Joy Chesebro.
I actually lead up all of our philanthropy, so this is gonna be an interesting talk for those of you, though I do work very often with many tech founders and, and many of the tech individuals who support our work. Um, so the Internet Archive, as you all know, has been around for almost thirty years. Um, so the Internet Archive was founded by Brewster Kahle, who himself was a technologist.
Um, so at the time when he began the Internet Archive, we were really just beginning to look at the web. It was the beginning, days of the internet. So for the archive, we became a, a, a nonprofit, a not-a-profit-seeking, organization, and that was on purpose.
Um, we-- Brewster didn't wanna be acquired. Um, you know, you're obviously have st- you know, stakeholders, and boards and other things, so he really wanted it to be open and free. We're open source.
We're an open source platform, and he really wanted to build it for the people. Um, he really believed that knowledge should be openly shared and should be accessible by everybody. So as you look, the Internet Archive is actually one of the top frequented websites in the world.
Um, we're I think in the top one fifty in the United States, and I think in the top five hundred in the whole world. So we have about two point two million people that come to our website every day, frequenting the, internet, looking for everything from books, magazines, obviously tech. You know, I love to, to read Byte.
Remember Aloha? Um, there's all kinds of different, tech, magazines as well. So I'm gonna go into detail about that a little later.
So obviously, the Wayback Machine, we're very noted for the Wayback Machine, especially over the last thirty years. Um, obviously recently, we have lots, you know, thousands of different journalists and news, you know, facilitated, stations and things like that that use us, when anything disappears. Obviously, we have a record of it on the web.
Nothing disappears on the web, as many may not know, especially a lot of our politicians. So, so everything, can be accessible, and a lot of times we do, when things disappear, we wanna see what it was like prior to that. So for instance, I'll give you an example.
We do an end of term crawl, at the end of every presidency when one walks away and a new one comes in. We capture our government websites. So it was very interesting in the last year and a half when our new administration went in and things started disappearing and things started changing.
So the Department of Education, the CDC, all of these incredible, web pages began to disappear. So thank goodness for the Wayback Machine. We were able to go into action, and we were able to capture what our government website looked like before.
So you can actually access that. The-- another example is during the Ukraine War when Russia went in, we, we worked with Stanford, and we went in with a lot of engineers, and we were able to capture a, a, a large majority of what was on the web. So again, culture disappearing.
We were able to help Ukraine, and we were able to digitize a number of their cultural artifacts online. So again, the Wayback Machine is super valuable. It's also great for people like me.
You know, you wanna go back in time. I wanna know what Google's website looked like in the 1990s. Um, so, and I think for marketing people and things like that, it's really important to kinda compare and begin to sort to launch different type of brand ideas, and it's good to see what things have been in the past.
So in a sense, I always say the web, the Wayback Machine is sort of like a time machine for the web. Um, we also run within the Wayback Machine, we have an Archive-It, and it's an earned income, option that we have. We work with thousands of partners, museums, universities, and cultural, cultural, agencies.
We do web archiving, we do text and data mining, and we do digital preservation through our arc- Archive-It program. Um, so a super, super important program that we run w- in, within the Internet ArchiveUm, we also, when you look at our mission, many of you may know our mission, it is to provide universal access to all knowledge. Yeah.
A lot of people refer to us as the Library of Alexandria. Um, of course, that was built in 48 BC, and we're a little bit up to more being modern, but we still feel that we are our age's library of inner- Library of Alexandria. So I'm gonna give you a little snapshot 'cause this is always interesting for me 'cause I love data, I love numbers.
I have to track all of this all the time. So we're already at about 250 petabytes of data, that's... You can imagine the servers we have and, and, and how we house that and how much that costs, 'cause I have to keep track of that.
Um, we have 113 million public media items on the Internet Archive, and we just celebrated this year, we had a huge celebration in October, we hit one trillion web pages on the Internet Archive. We are 10 times as large as our own US, Library of Congress. We're 10 times larger than that, as far as when you look at all the archive data we have.
And you can see the rest. I mean, we're already over 56 million texts in the collections. Um, to continue, we do television, movies.
A lot of people don't realize that. We- audio, old-time radio. We have software, images, incredible collections of photography.
Everything under the sun. I'm sure many of you are using it for a variety of reasons to access. And so I get to, to work with all of our supporters all over the world, and I hear all these incredible stories of how they're accessing and using the Internet Archive.
I mean, I've talked to huge genealogy groups, I've talked to huge tech groups, I've talked to people who love old, manuals to build cars. Sure. Yeah.
I mean, it's everything under the sun- Mm-hmm ... when you look at the individuals accessing our wide variety, this amazing library. Um, so the public loves us.
I have to work with the public. That's what I do. Um, you can see...
And I hear the stories. We get thousands and thousands of these, comments every day. " I think vanishing culture, we actually helped the, country of Aruba digitize a vast amount of their culture online, which I think is super important when you're looking at the world and how everything is starting to disapp- everything is on the web, right?
We all use the web. We do everything on the web. We have now chatbots, everything.
Well, it can take one second to disappear. Yahoo, you know, they wanted to delete vast amounts of information. " So I think knowledge in itself, we're in a digital knowledge world, and it's gonna be even more imperative for organizations like us to ensure that all of this incredible knowledge and information is saved into perpetuity for future generations.
Um, so I want to play something. This is... Oh, the sound.
No sound? Yeah. Okay.
Okay. This guy is on Instagram, okay? I love him.
He's always going to Internet Archive and showcasing some really cool collections. Um, and I'll have to give you his, his, URL or his, his tag in Instagram. Um, and it's kind of funny, kind of what he says because he goes into these obscure...
He finds the most obscure collections, stuff I don't even know about. So it is a black hole. I mean, once you go down, he talks about it, it just leads to one thing, to the next, to the next.
You really need to get in there and really discover incredible, collections that we have digitized. Here's another person. Um, he talks about the Wayback Machine and all of the different things that we've been, you know, scanning, crawling, capturing, and the importance of the, the Wayback Machine.
So we have people all over the world like this, that I get to work with, supporters and just avid, you know, fan... It's like a fan base that we have in a way that are using the Internet Archive. I mean, newspaper articles, all k- you know, drama, television.
Um, each of us has a really, you know, interesting life, and we're very interested in specific things. So the Internet Archive, I think, is one of those places where you can find almost anything that you're interested in. I'm sorry this doesn't work, but it's kind of interesting.
We also ran a 24/7 scanning, online where we were scanning the books, and we thought, "This kind of seems... " We had thousands of people watch just a book being scanned online. I mean, I thought maybe this is what's happened to our society today.
We just want something mundane. We're so stressed out. The world is in a situation.
I just wanna watch a book being scanned. So we had thousands of people log in 24/7 watching. It was kind of like that thing where I was watching that eagle birth an egg, and I sat there all the time, every time, you know, at night, watching, waiting for that eagle, that small eagle to birth.
But this was even more popular. Um, so basically, when you're looking at the projects, the Wayback Machine, as many of you already probably know, you know, we're crawling the web and preserving all of these web pages. We're looking at making sure culture doesn't vanish, and we, we launched Democracy's Library.
Um, so yes, we do the end of term crawl, like I mentioned. It ended up archiving four million web pages, two million videos, and 300,000 data sets, all of which would've been lost through our government if we had not done this. Um, also Community Webs, I, I think this is a program that I, I really love because a lot of times there is people in positions of power or privilege.
Um, and a lot of times the voices of minorities, and the marginalized sometimes get downplayed. And honestly, the, the historical record isn't there for the reasons I've mentioned. So the modern digital world, it offers an opportunity, especially us in, at the Internet Archive, to change that, to change the narrative for those who, those voices who are sometimes not heard.
Um, so we do work, we give those voices, the silent majority a record of impact. So basically, the program works where we work with, libraries all over the United States, sometimes in rural areas. Um, like we, we digitize the Black diaspora, in America.
That was a project that we did. Um, we work with, you know, indigenous groups to make sure their voices are digitized online. LGBTQ, making sure that doesn't disappear.
Um, those voices are important. All of these different voices need to be heard, and they need to be part of our cultural heritage. So the Internet Archive and this program works very hard with partners all over the United States to ensure those voices are heard and seen on the web.
Another program, Open Library, someone had mentioned to me accessibility was really important for those with disabilities. That is an also important area for us. Um, we really work with Open Library.
Um, we have millions and millions of books, for those who, you know, I think it's called OCR, capabilities. Also, we have voi- you know, which is voice activated. We can, the type can, can get larger for those with, visual issues.
Um, so there's a lot of, on the back end built, to ensure those with disabilities have the opportunity to read a book, to hear a book. We have lots of e-books, through Open Library, that, millions of e-books that can also be accessible. Um, what was interesting, I didn't realize only 7% of published works are currently available in accessible formats.
I thought that was really sad. Um, so I do really, um... I'm super happy that the Internet Archive has made this part of one of our projects to ensure those with, disabilities are, are, are l- are, are, we, we cater to, to those, that group.
Um, the WayBack Machine and Automattic. So, WordPress, we have a great partnership. Um, I work very closely with WordPress and their foundation.
Um, so we, worked on the, corporate side. Automattic is a affiliate with WordPress, and we did a link, link fest- fixer, project. We do all these interesting projects, so maybe some of, like I said, our engineers and that could come in and talk more deeply about all of how they built these different projects with, with a variety of partners.
But basically link rot, we all- You know, 404s, you know. We, we really work hard. In fact, we did a partnership with Wikipedia.
We're turning all their links blue. So I used to go and click on it, we go to a 404. " So now we, we have millions of, of links that go to periodicals in the actual page.
So when you go to, Wikipedia, it comes to the Internet Archive. So we're partnering and helping them, the functionality, to be a, a better resource for people. Um, so this is another partnership, as you can read, with, with Automattic that we, we've formed.
Um, so I'm gonna get into philanthropy a little. Hope you enjoy this, but this is my passion. This is what I do.
This is what I been trained to do. This is what I get up every morning and I can't wait to do. Um, so love to hear about all of you because I know you have your own passions.
But, you know, it's, we're a purpose-driven nonprofit. Um, and we, we did this on purpose because it really... We wanted the Internet, Archive to last, and we really wanted to build something for the public.
We're a public service, and I think it's really important that we're structured as an independent nonprofit so that we can offer everything for free. We don't track anything. We don't have ads.
We don't monetize. We're really about the core value of privacy. Besides open source, we're very much about privacy for our patrons.
Um, we also, if you look at the big scope, I love going big and then small, and where does the Internet Archive fit? Um, I don't know if many of you know, but this is what the nonprofit sector contributes here in America. Over $592 billion goes into the nonprofit sector in America, and we are a small piece of that.
Our operating budget's 30 million, but the, the wealth of work and impact that we make is unbelievable. And the fact is that we utilize that money so efficiently. That's one thing Brewster is very conscious of, is making sure every single penny, every dollar, goes to building the Internet Archive.
" Um, and then they'll be... " So I think our brand is the WayBack Machine. Um, but we're about 14% of this market, of the 592.
It's education and cultural- Yeah ... you know, organizations. Conservation, it's only 3%, which tells you something.
It might be even less now. Um, but we do have one of the coolest collections. It's called the Biodiversity Heritage Library Collection on the Internet Archive.
Check it out. It's, it's really a fantab- a wonderful biodiversity if you're into that. 4 trillion.
Um, that's the kind of activity that goes on in the nonprofit sector. Um, so a little d- deeper dive, you can kind of see over the years, it's really fascinated me. Look at the data.
How are we trending? How are things growing? Why are they growing?
Inflation plays a big role. All of these things play a big role in how, you know, fundraising and the nonprofit, sector scales. So it...
There's, there's positive points, low points, obviously 2008, '9, all of that yellow, that was during the, bubble, the real estate bubble and collapse here from 2008 and 2... to 2010. That hit the nonprofit sector in a huge way.
Um, hopefully nothing like that happens with AI. There is no AI bubble. Um, we, we don't know.
Um- I'll assume that one between '99 and 2004 is the dot-com bubble. Yes. Yes.
Thank you. I was just gonna mention, yes, that is the dot-com bubble. Um, so you can see how all of this has a, a huge impact in giving.
Um, so philanthropy supports the mission here at the Internet Archive. I have a great team. Um, we work with, you know, millions and hundreds of...
I think it was over 200, almost 250,000 individuals my team and I worked with this past year. These are unique individuals who donate to the Internet Archive. Um, so we've been building that over the last number of years.
Um, we've scaled. We've, actually grown. I c- I came on about six years ago.
We've grown about 325% in revenue. Um, so my background mainly was working for very large institutions and globally as well as with universities and hospital systems and things like that. So, you know, I took a lot of those best practices and brought them into the Internet Archive, and I love, absolutely love the archive.
So these are the kind of four areas that philanthropy at the Internet Archive focuses on. We focus on database management, all of the information and data on everyone that comes in, is very secure. Um, there's a, a lot of anonymity, and we're...
Like I said, there's a lot of privacy built into that. Um, we also do all the fundraising and external communication. So if you wanna join our newsletter or wanna get inside and know what's going on, you can sign up, and my team, manages all of that.
Then we do a ton of A/B testing on all three of our sites, Open Library, Wayback Machine, and the Internet Archive. Those are our three main sites. Um, so we A/B test through my team all of the communication and all the messaging that comes and goes through that.
So there's a lot of analytics. I use a Metabase analytics, to kind of track mostly not the individuals, but the trends and how, philanthropy is being tracked within Metabase. And then, of course, we handle all of our events, partnerships, with the corporate sector, foundations, and all kinds of things.
So, we did... I launched crowdfunding recently, last year. It actually performed really well.
Um, the reason why crowdfunding performs well is because we had a l- really large base, so we were able to activate that base around specific cool projects, maybe like Link, Link Fixer or, you know, our trillionth, you know, website. Um, we kind of... I kind of play a little bit with campaigns, and then I really activate people who are passionate about it, and we did fantastic with our crowdfunding.
And we focus on the web we've built, so that was the campaign. Um, and then of course, we do all kinds of events. I love meeting everyone across the country.
Um, Brewster comes and speaks, and we really are just building our brand and building knowledge and understanding. I notice on, in the, on the East Coast, they're not as well, versed or, you know, understanding how the Internet Archive works versus here in the Bay. Mm.
Everybody kind of understands what we do. Um, again, I track all of our analytics and performance monitoring. Um, this is well tracked.
I'm really into making sure... You know, philanthropy is more of a science than it is an art. Um, it's very, very science-based.
Um, everything has trends. Everything, you know, every month, everything we're doing. We have a lot going on.
Um, we have eight to nine different, funding channels now. Um, when I started, I think there was one or two, and now there's nine. So we have earned income, you know, major corporate, estate planning, and we have, new funding, you know, token-based funding.
You know, when you're looking at, um... Well, now it's not doing it, but, you know, crypto, you know, the whole crypto, sector. Um, I launched a lot of these things at the Internet Archive.
Um, so we've been growing. Um, some of these numbers, as you can see on the philanthropic side, which one thing I wanted to spotlight was the average donation is a lot higher than most nonprofits in America. Oh.
And that is a testament to my team. Um, we've worked really hard over the years to build loyalty, and I think it's because the Internet Archive is a beloved tool and service to our country and, and really the world, and people see the value of what would happen if the Internet Archive or the Wayback Machine went away, so that our, our average rate is so high, our donation, because people don't want it to go away. They wanna make sure it's supported into perpetuity.
Um, this, you know, the great use of life is to spend it for something that will outlast it. Um, the Internet Archive will at last outlast me. It will outlast all of you in this room, and it should because it is a Library of Alexandria.
Um-And it should be given to future generations that are coming behind me, and we want to make sure it continues to digitize all of the world's, as much as we can, culture and history. Um, we're built on knowledge. Everything that we're all doing in this room, everything that I do, is built on knowledge.
And what I always think, I like dystopian thinking sometimes, what would the world be if knowledge was taken away? Um, I mean, we kind of have some examples of that in history, when knowledge was e- either controlled, or erased or changed, and so that's what we're up against, is why the value of the Internet Archive is so important, is because we are living in times where, certain regimes in certain areas have the ability to turn the lights off, or change the narrative, or culture can vanish. And then what do we have to prove?
And there's also the, the realm of misinformation. Um, what are the facts? How do we go to ensure that this is truth?
Um, we need a foundation, a library that we can go to, to fact check, to ensure that our culture stays stable and that we do know what truth is. And so that's one of the other things why the Internet Archive is so incredibly important. So that's the end of my presentation.
Um, the last thing I'll say is right now we're really, focusing on vanishing culture, and link rot, because the internet is fraught with link rot. And so that is also something that we're, we're putting a lot of, of energy around. A lot of our engineers and, those in the tech side are really building out to ensure that, we c- we tackle a lot of the link rot.
And, so that's, you know, something maybe later on you might wanna talk with some of them. It's very interesting, some of the, the infrastructure they're building around that. So are there any questions?
More like a statement. Yeah. Um, this was, like, for me, pure nostalgia.
So when I first got out of college, I did UX and UI design. This saved me a lot when, either, A, we goofed up on something as we were designing it live. We would use Wayback Machine.
Yeah. Yeah. " You go to their site and it's like, "Oh, this one's kind of c****y.
" I'm trying to remember what they did- Yeah ... for inspiration. WayBack Machine.
Awesome. That's a great... Yeah.
No, I hear the stories. So what... So, when you went back, where- did you do it with multiple, like, to see the iteration?
You go- Yeah ... go through the timeline? Yeah.
Do that. Because as, like, especially when I was doing web design for the front end, you're, you're literally trying to create something from a blank screen. Nothing.
Right? Yeah, sometimes. And so sometimes, yeah, or a lot of times you need inspiration, and there's just this one thing that caught your eye way back when, and of course their site has completely changed.
" Yeah. WayBack Machine. It's cool.
Yeah. Yeah, I mean, our UI is sort of... There's sort of a, a back and forth about our UI UI.
Um, and there's a reason why we don't want to make it too easy- ... to find, you know? But, what's great is you can.
You can see the iteration. Mm-hmm. " You know?
That. Yeah. A lot of the time was, like, with Google.
Um, but no, I, I like it. I think also, like, the UI, how it is for me, like, is I'm probably biased- Yeah ... but definitely nostalgic, where the UI is like, yo, I love this.
I still go there, like, every so often now still, and I'm always happy to see that it's still around, to be honest. Yeah. Mm-hmm.
It's, it's a b- it's our brand. Like, I don't think you're gonna come in and be this, this really smooth looking, like- You know? I, I do worry...
You know, we were trying to work out with chatbots, like, how, you know, the whole AI aspect of things. Um, that's a whole nother conversation, because a lot of organizations, as you've seen, there's lots of laws and things coming into play because these crawlers are going everywhere and grabbing all of these, the, the data. Um, and so yeah, you have to have some...
But that's great.