Techstrong TV March 20, 2026
AI Bug Bounty Reality: Kara Sprague, CEO of HackerOne, explains how AI-generated code has flooded organizations with vulnerabilities—shifting AppSec from discovery to validating exploitability and prioritizing real-world remediation.
Agentic Business Transformation: Bryan Goode of Microsoft and Mitch Ashley outline how platforms like Microsoft Dynamics 365, Copilot Studio and Microsoft Power Platform are enabling AI-driven systems of action across the enterprise.
Shimmy Says – AI in Practice: Alan Shimel shares how Techstrong Group is operationalizing agentic AI across publishing, content workflows and internal operations—moving from experimentation to production.
Securing the Agentic Identity Explosion: Sanjay Ramnath of 1Password details a shift from static authentication to continuous governance with a unified access model designed for human and machine identities.
AI Infrastructure Arms Race: Tom Hollingsworth and Dave Graham break down major developments including innovations from Amazon Web Services, NVIDIA, Dell Technologies, Nutanix, CrowdStrike and Zscaler, as Jensen Huang forecasts a $1T AI market.
Unified Data Orchestration with Hammerspace: Chad Smith of Hammerspace demonstrates how enterprises can dynamically orchestrate data across cloud and on-prem environments—ensuring AI workloads always have access to the right data at the right time.
Transcript
Hi, everyone. Welcome back here to Techstrong TV. I am really happy to have this next guest on.
I don't think she's been on Techstrong TV before, unless I'm mistaken. But look, I've been doing a-- Techstrong TV for a long time. Let me introduce you to Cara Sprague.
Cara is the CEO of HackerOne. Cara, welcome to Techstrong TV. Thanks for having me, Alan.
Great to be here. You've not been on before, correct? Or with me anyway.
I don't believe so. At least not in this role. Nope.
Okay. Well, that's important. Well, and that's a great segue.
I wanted to ask you, you know, you weren't born the CEO at HackerOne. Give, give our audience a sense of your journey, Cara. It's a-- You know, it's a great story, and I'm sure people want to hear it.
Sure. Um, well, I am an engineer, by heart and by training. Um, and, you know, this was back in the early 2000s.
And at that point, when I started taking on engineering roles and, and realizing that a lot of the work, was very individual, it felt like I worked on the same thing for a very long time. Um, and wasn't-- I was missing the big picture. I decided to go back to school and broaden my horizons a bit, and that ended up taking me into management consulting for thirteen years, where I worked in, the tech practice.
So I got exposure to a whole bunch of technology companies, B2B, B2C, up and down the stack. Uh, it was a great overall view on the industry. And ultimately, I made the decision to move into a company, F5, i- as a- Sure ...
executive there in the product organization. And I, I, spent seven years there learning how to take, you know, translate what happens in consulting, which oftentimes, you know, goes only so far into the strategy and, and really, learn how to drive it and operationalize those strategies. And then last, November of twenty twenty-four is when I made the move over to HackerOne as CEO.
Love it. So look, F5 is a company we've covered. My, my good friend Lori MacVetty, I'm sure you probably know Lori if you were there- Yes, yes ...
seven years. Um, Lori's still there writing up a storm. I just saw something she wrote on LinkedIn this week, and I was gonna reach out to her and ask her if she wants to come on here and talk about it.
You know, I've been reading Lori MacVetty, and Don, her husband, used to write for us here at Techstrong. But I've been reading the MacVettys, I'm ashamed to tell you, like, since the nineties, early nineties- ... something like that.
A long time. Um, what-- So I, I get the whole engineer to, to business, you know, m- moving to the business side of the house, then doing the kind of the business consulting thing and, and all of that, the F5 piece. And of course, everyone wants to be a CEO.
Or I don't know. I don't know if everyone wants to be a CEO, actually. I, I think that's my generation's bias, right?
That's a, a dream job. Maybe today, people, not everyone wants to be the CEO. But Cara, what, what got your juices going, so to speak, about coming in as the CEO of HackerOne?
Well, HackerOne, you know, it's an organization that's been around for over a decade, and it is the pioneer in a space called, bug bounty. And, and that's where organizations, and I'm talking about, like, companies, they set up programs so that the independent security researcher ecosystem can then submit vulnerabilities in a safe way. Mm-hmm.
And in some cases, as in the case of bug bounty, get paid for that. Um, and that model was in- incredibly intriguing to me when I, when I first learned about the company, because if you've been in cybersecurity for a while, and, you know, I started getting into cybersecurity when I was a consultant and then did more of it, even more at F5 as the company was enhancing its portfolio in, in security. Um, what you find is that the c- the industry has been plagued by some very long-term, challenges.
So number one is, we keep creating a lot of insecure stuff. Uh, you know, every time we, we, we make new applications and put them out there, those applications often have a lot of vulnerabilities that are being shipped with them. And we know, especially in this age of AI, with more AI generating more code, that the code that's getting released is even more insecure.
And so that backlog of vulnerabilities only continues to grow. Um, we know that there's a talent shortage, and there's just not enough people, with the skill set and the desire to be in cybersecurity. I think, you know, some estimates are that that talent shortage is in the millions of people.
And so when you look at an organization like HackerOne, the whole premise is how do you scale out, through a platform and through the ecosystem of independent security researchers to really bring companies the kind of talent and expertise they need to identify those vulnerabilities and make their applications and their technology safer before it can be exploited by a criminal? That just really spoke to me. And I would say in the time since when I, since I joined the company, I'm even more excited, because now we're seeing all of these new developments out there.
Um, you know, there's still, AI is en- enabling us to write, applications and develop technologies faster than ever. Um, we've got these new developments like, Claude Code Security, and, I think OpenAI has one of their own, which are, are promising to say we, we can stop shipping insecure code. And so there's even this li- this, this vision that maybe someday the code that we write and, and produce will no longer have vulnerabilities in it.
And we still have- One could hope. That's at least, that's at least, you know, the, the very rosy view of it. Uh-huh.
And, and there's still this mountain of technology that's already out there and deployed that people are using. It's, it's running our critical infrastructure, it's running, you know, our core citizen, services, it's running the business cores. Uh, but there's still fundamental, vulnerabilities and exposures within that code base, that we still need to address.
Agreed. Agreed. You know, look, as I said, I've been in the, in the security industry twenty-five plus years.
Mm. Technology almost thirty-five. " And I was here when the whole bug bounty concept, you know, Katie Moussouris and- Mm-hmm ...
and some of the other folks came about, and what a great thing that was, right? Because now you had this army crowd- literally crowdsourced of vulnerability researchers who can , you know, whether they were fuzzing or whatever, they, they would help you find your vulnerabilities. And it was...
You know what? Yeah, there were these, you know, there were a few big million-dollar vulnerabilities if you wanna call them, but the average vulnerability we were finding was a couple of hundred bucks, and it was well worth a couple of hundred bucks to find that vulnerability and, and, and close that one off, right? Of course, you mentioned the AI word, and it's had a-- it's already had a profound impact, especially on the bug, bug bounty program, right?
Because I, I wrote an article about this just last week. Actually, it might have just come out today actually, now that I think about it. But the, the, the arithmetic has changed.
Where we used to pay the money to find maybe bugs- Mm-hmm ... what we're finding now is with AI, AI finds a lot-- Forget whether AI creates bugs when it's coding. I, I agree with you, it'll get better.
But it's finding so many bugs in our existing code and in our new AI code that the, the value is no longer in finding potential bugs. The value is in evaluating those potential bugs, finding out if they are in fact real bugs, and then-- or vulnerability, vulnerabilities, let's not, you know, use the right term. And then finding out are they exploitable, are they reachable, are they, you know, how, what, you know, how critical severity-wise are we doing these things?
And that focus change, that arithmetic change is something that I'm sure like at HackerOne, Kari, you guys gotta be seeing firsthand already, right? It, it's not- Yes ... just enough to find a potential bug.
We gotta take it all the way through. I'm wondering how that... You know, what you guys-- 'cause you're, you're in the front lines on this.
I, I just report on it. Well, we're seeing, we're seeing very much the same thing that you are describing. Um, so you know, average bounties today are a couple of thousand and, you know, HackerOne in the last year paid out over eighty million dollars in bounties.
So the amount of bugs that this, this approach is, is-- and vulnerabilities that this approach is uncovering continues to grow. Uh, but to your point, right, we're at an inflection point in the cybersecurity industry where we now have attack surfaces growing very, very fast as companies rush to, implement new AI-driven capabilities, and, and deploy technology faster than ever before. But at the same time, the cost to run an attack or the cost to find a vulnerability has come way, way down because of the capabilities that AI enables for, for cyber criminals as well as for, for ethical hackers.
Um, and that means to exactly what you're saying, the focus can no longer just be on discovery. Um, we need to look for solutions that enable co- companies to move from discovery all the way through the cycle to remediation, and actually prove that there's actually a fix that has been implemented and that it sticks. Um, and that's one of the th-- really exciting things I think there is about, you know, these, these offerings that, that provide adversarial thinking, which is, which is what a lot of what HackerOne brings to, to companies, is we offer them a view of the vulnerabilities that are truly exploitable, because these are things that have been identified on an external, attack surface and, things that have actually been validated, to be of a certain severity level and truly, a risk to the company.
And what we find, in those programs is that those are oftentimes the things that companies wanna prioritize for their development teams to focus on first. Because rather than focus on, you know, the laundry list of, theoretical, exposures or vulnerabilities that might come out of a more deterministic scanner, what you want to do is, is find those things that an external adversary is actually able to detect and exploit, in your technology, and make sure that you close that gap first, and that's exactly what we offer. Absolutely.
Absolutely. And, and I think that's an important piece of it, right? Too many...
You can't blame them. I'm not blaming anyone. But too many f- people, like you mentioned eighty million dollars.
Mm-hmm. A lot of people, they just get fixated on the number, right? And, and they don't understand the real, the, the full mission.
Yes, the mission is to facilitate- Mm ... researchers getting compensated for, for bugs and vulnerabilities they find. ButYou know, and, and if that's all you're interested in, great.
Eight-eighty million is the number you should know. But there's more to that mission, right- Yes ... that goes beyond paying out the bounty.
Precisely. I want to- Yep. Yep.
A-and I think that's an important... You know, people out there need, need to pick that out. Um, but Kara, I, I t-- I-- we were talking off camera.
I told you I spent all weekend automating stuff with agentic AI. Now, was it... You know, I've been using, generative AI for, since it burst on the scene, right?
But- Mm-hmm ... I, I can't help but think over the last three weeks, four weeks, this, this thing with ClawBot, right? Mm-hmm.
OpenClaw, whatever you wanna call it. OpenClaw. The-- it's like an-another era has kicked, right?
We're seeing a whole different kind of wave, if you will. Um, I wonder, are, are you feeling and seeing that too? Like, so we're moving from purely generative to agentic AI.
So, you know, you didn't need an agent in Claude Code to write code. But now not only is Claude Code writing that code, it's deploying that code for you. It's hosting, it's setting up the hosting of it and everything else, right?
And, and then as you said, the, the latest, ChatGPT is Codex or whatever it's called. It, it's not terrible either. Um, though developers seem to be forming around Claude for, for various reasons.
But, do you see this-- Have you seen this switch flip as well? Are you, you know... Absolutely.
Um, yeah. So absolutely, I see this, and I, I, I have been also using this in my, both my, my personal and my, my own specific professional, workflows. Um, the agentic AI has been a game changer.
Uh, we see this with our customers. Um, so, you know, we, we were very proud to evolve our, GenAI offering high, into a team of agents, last year. And what we're seeing from our customers in terms of what they're reporting is that some of the agentic workflows are saving our customers up to seventy-five percent of the time that they used to spend on, incoming reports.
Um, and again, for, for overworked security teams, that is a massive, massive time, saver for them and a huge amount of- It's a miracle. I mean, it's, it's, it's game changing. Um, and then equally, you know, for, for those CISOs that, have been struggling to get coverage across their attack surface area because, you know, it's, it's, it's time intensive and expensive to be doing pen testing, for example, or periodic pen testing, which many, many organizations in the past have, have applied to only to a fraction of their overall, attack surface on a, on a very irregular basis.
What we're now seeing, with agents is that agents can now test continuously across those entire attack surfaces. And so you get the proposition of a lot more continuous testing and a lot more breadth of coverage. Um, so it's, it's actually really exciting in terms of the ability now that we have to do, much more, robust, cybersecurity and, find more of those issues.
But to your point, finding the issues is not the only problem, right? Um, you need to complement the discovery with a platform that can actually facilitate getting those issues remediated, which is where all of the validation and the prioritization has to come in, and the integration into developer workflows. Um, and so that's, that's actually, you know, the, the vision that I'm, I'm very excited about that, that we are working on, is how do you bring an entire, end-to-end view, together, so that regardless of the different discovery mechanisms that might be out there in the market finding vulnerabilities, and there's gonna be a lot of vulnerabilities discovered over the next twelve to eighteen months, how do we make sure that you put those into something that makes sure that you're optimizing the, the risk that you're reducing, by, by prioritizing appropriately what your developers are focused on?
And, and this is something HackerOne is bringing to market? Yes. Yes.
Available now, available soon, coming soon? What's, what's the status? Uh, it-- we have it available...
It's available now, and it's continuing to get better every, every month, every quarter. So- As everything is, it seems, right? Yeah.
Yeah. It's, it's crazy. Um, how do people sign up for that, Kara?
They can, well, they can reach out to HackerOne. You can contact us through our website. You can reach out to me directly, kara@hackerone.
Um, but, you know, this is, this is exciting, and, and what I'm, I'm looking forward to, I, I really see a huge amount of potential, as we move into this agentic era, uh- Mm-hmm ... to truly take the burden off of cybersecurity teams and to really actually, I think there is a path for us to finally start, having technology that is more inherently secure, which should be exciting for everybody. From your mouth to God's ears, right, as they say.
Um, Kara, you know, but there are people out here who worry about their jobs. Yeah. I don't know a nicer way of saying it, so I'm just gonna be blunt, which is my style.
They're worried, is this AI gonna take their job? Yeah. Is this AI gonna just automate finding vulnerabilities, remediating vulnerabilities, documenting vulnerability?
You know, where do I fit in? Where's the human-- I'm a human. Where, where, you know, what do I do?
Am I, am I gonna be as valuable? Am I gonna, you know... Is the security industry gonna have a place for me?
Do I have a place in it? And, you know, as you said right in the beginning, it's still an industry where we have, at the very least, tens of thousands of openings probably, right? If not hundreds or millions.
Um-And, and if history is any guide, as these new waves of innovation and technology come out, it doesn't make security smaller, right? I, it's none of these things always. So I'm wondering what, what do you say to those people out there, Kara, who are worried?
I would say, first I, I think that, that concern, is, is a familiar feeling for, for anybody who's lived through, you know, these massive generational shifts in technology. Um, you know, we saw this, when the industrial era, era came. We saw this through the various evolutions of computers from mainframes into personal computers, and then into the internet era.
And AI is bringing a, a fresh wave of, of disruption to the way that that work gets done. And yes, there are some new things about AI, that are different from, from previous generations. Um, but if history is our guide, to what...
To the point you made exactly, Alan, this sh- this will expand the opportunity set. This expands tremendously what, an individual is capable of doing. Um, and this should create more, opportunity for us to, to bring real outcomes to life at an individual level.
And so the, the amount of empowerment that an individual has at this point with these tools is astounding. Um, and that's very, very exciting. And, and yes, there is change in, in what we do on a day-to-day basis, and how we get our work done, and how we drive impact.
Um, but that change buys us the opportunity to have much, much more impact than ever before. Agreed. You know, we mentioned the website, we mentioned the website, but I don't think we ever did the URL, Kara.
Oh. com? com.
Then that's one spelled out, O-N-E. com. Got it.
Kara, we're about out of time. I wanna thank you. I wanna invite you back because this, as we were talking about, this changes almost day to day right now, if not week to week, certainly month to month.
Yeah. I'd love to hear what, continue hearing what you're seeing, not just from your customers who pay you, right- Yeah ... for the HackerOne services, but from the research community that you're so intertwined with as well.
And because it, you know, I, I think they, they're mirror images of each other in some ways, but there's gonna be some... They'll each be figuring out their place in this new reality that we're finding ourselves in. Happy to.
Happy to. It's a, a- I love it ... as, as you're, as you said, it's a very fast-moving space.
And, uh- Yes ... a lot of, a lot of very fascinating things are happening every day. Absolutely.
You know, I was here for the whole internet thing, and then of course the cloud, and, you know, I rode the dotcom up, the dotcom down. I did the cloud. I did, you know, venture backed startups, then here in media for 10, 12 years.
I don't think anything has moved this fast, right? This gives internet time a whole new, whole new meaning. Um, Kara, thanks for coming on here.
Continued success at HackerOne. Do come back and keep us posted, okay? Thank you.
Thank you. Kara Sprague, CEO, HackerOne, here on Techstrong TV. We're gonna take a break.
We'll be back in just a bit. Hey everyone, it's Alan Schimmel, founder, CEO here at Techstrong. And welcome to our continuing series on, AI, agentic AI, the future here with, the Microsoft team and our Futurum analyst team, as well as Techstrong.
In this next episode, though, we're gonna be joined by Mitchell Ashley, of Futurum, who leads the software development life cycle and building segment at Futurum. And Mitchell is talking with Brian Good, whose official titles is corporate vice president at agents marketing. But Brian is really here talking about agent apps and chat, and it, it's a, you know, obviously a very hot topic as we move to an agentic AI workflow based, basis.
So let's join Mitchell and Brian here with me, and it's great to have them both. My name is Mitch Ashley, and I'm VP and practice lead of the software life cycle engineering practice at Futurum Research. And, and Mitch, my name is Brian Good.
Uh, I lead the business applications and agents team, here at Microsoft. Well, let, let's start here. 2025 is described as kind of an inflection point for AI adoption.
What do you think are the most significant changes that, you've seen in organizations as they're using AI and agents in their businesses this year? Well, I absolutely agree. 2025 is really an inflection point, and we'll sometimes describe it as the year that the frontier firm was born.
And you might have heard us talk about the frontier firm before. It's this idea of companies that are putting AI really at the heart of their business, and it's enabling them to do things like reinvent the way they engage with customers, or transform their business processes inside their company, and beyond. And it's really the year these frontier firms are sort of rising up in a time when I think we can learn a lot from these early adopters in understanding how they're deploying AI, how they're being successful, and then figure out how we can take those insights and bring them to, to our own businesses.
That's where you can have outsized impact As AI transforms those functions, what do you see as the new patterns of work that's enabled by Copilot and agents as customers start leveraging the technology for productivity or innovation? I'll tell you what, I have studied these frontier firms as they, as they come up, and there's really three patterns that I see across these frontier firms. The first is really enabling, employee productivity.
So they give every employee, an AI assistant like Microsoft 365 Copilot, and it helps them, those employees be more productive. The second pattern that I see is, really these frontier firms deploying AI to automate existing business processes. So for example, they already have a way of handling expense reports, but they can use AI to speed that up and reduce costs and, and that certainly results in some benefits to the customer.
The third pattern is really where a customer like starts from the beginning, let's say from first principles, and they reimagine a function altogether. They'll reimagine what it means to engage with a customer who has a, a, an issue with their product, and they'll put agents at the heart of that. Most companies can only take on one or two of these functional transformation projects at, at any given time because it's a big lift.
Again, it's reimagining a function from first principles. It's not just taking existing processes and, and applying AI to them. How far along do you think most organizations are in their adoption cycle for generative AI?
Well, I think we're still in early innings. Uh, that-- there's no doubt about that. Um, you know, customers are starting to deploy AI in different functions as we talked about, but certainly they haven't, in most cases, fully realized kind of the transformation that AI can have across their organization, so it's still very early innings.
But I'd say we see very promising signs and, and green shoots, of that, of that adoption and success. Uh, again, the key really here is to start function by function, think about a particular function, think about peeling it back to the business processes you need to go focus on. That's where you can have outsized impact.
How do you define agentic business applications, and why are they critical for organizations? Yeah. Well, I do have a vision that there's, the application of old is really transformed with AI, and we call that new type of application the agentic business application.
And the agentic biz app includes the assistant for the human to start to use. It includes pre-built business process agents that basically take the drudgery out of work, and then it's built on a data foundation. And so instead of being limited just to the data that, you know, maybe is in the CRM system or the ERP system, it joins that with data from other lines of business systems and even productivity data so that you have a rich set of data that you can build agents on top of, and you can empower your humans to get better decisions from.
And so this idea that brings all those together, the assistant, the agent, the application, I call the agentic biz app, and I think it's a really big idea. Let's talk about why you're optimistic about the future of agentic business applications. I have a lot of optimism here because, number one, I see customers already deploying these applications, and, and really transforming their business.
So I already see people starting to get great benefit from it. But at a more human level, the thing that gets me excited is, like if you think about every one of our jobs, like there's a lot of stuff that we end up having to do that really isn't adding joy to our lives. Uh, you know, me doing an expense report or, you know, filling out a CRM, system, you know, with an update from a customer call, those aren't the things that, that make us, unique.
Those aren't the things that bring joy. Those aren't really even things that add business value collectively. But if we can delegate those things to AI and agents, I think we'll enable ourselves to actually go do far bigger things and really take our ambition to the next level, and so I am absolutely excited for what the future holds.
I'd love to hear about how you see the role of AI agents evolving just over the next few years, especially as organizations start to redesign core business processes, drive outcomes for efficiency. How, how do you see this taking shape? Yeah, great question.
You know, I'd-- I, I would say that we really believe there's a spectrum, of, of agents. You know, there will be very simple agents that someone will use that might just be grounded on a particular knowledge source and help you, you know, understand, you know, what, what might happen from that, from that knowledge source. Then there'll be task-based agents, and then there'll also be more sophisticated, fully autonomous agents as well.
And this more autonomous agent is where you can unlock a lot of business value. These are agents that, you know, aren't called by a, by a human. They're just running independently.
They're triggered based on different actions, and they can really automate business processes, in some cases from start to finish. So we believe there's this spectrum of agents, and today I'd say most agentic use cases start with those more simple kind of knowledge agents. Uh, but increasingly, we're seeing customers bring in these task-based agents and autonomous agents, to automate, things, end-to-end.
How about the C-suite leaders? How should they be thinking about investing in agentic technologies for long-term value? Well, every C-suite leader I talk to today is already in on AI.
Like every one of them recognizes that it's a competitive advantage if they can move quickly, and if they don't move quickly, they recognize it could be a, a disruptive force in their industry. Uh, but let's face it, AI, it's transforming businesses, it's transforming functions, it's, it's gonna reshape entire industries. And every C-suite leader I talk to recognizes that and wants on board.
What they're looking for though is a partner. They're looking for the tech, of course, they wanna make sure they've got the right tech, but they're also looking for a partner to help them shape this in their business, and that's where Microsoft, I think, comes into play. Uh, you know, we're not a large scale model maker, but we do take the best of the models and bring them into the workplace, so that companies can use them.
You were talking about AI being a disruptive technology, probably because it seems that it really can and will affect every part of our work, our lives, et cetera. Certainly, it's affecting how we create software with new concept like agents and agentic AI. Curious about your thoughts.
Share with us, how does Microsoft view what the transformation is going to be like with AI really having an impact and a big benefit to businesses? Yeah. Many industry, pundits will say that this move to AI agents is gonna, lead to the rise of, uh more consumption-like models or outcome-based pricing, and I think they're right.
I... That's definitely a direction that I see the world shifting as well. Um, the only thing I would, balance that with is that many customers are still, you know, most comfortable buying things on a, a per user or pre, per seat basis.
And so, the approach I'm taking is, you know, how do I enable customers to buy offerings that they're comfortable with, and that's typically like a per user or some type of per tenant type of, type of license, while giving them the flexibility to, to grow and shift into more consumption models as they, as their business changes. And so, we are at an inflection point, just as we said, and I think one of the things that will change is the business model over time. Talk some more about agentic, when you think about agents operating on their own or more autonomously, and why are, why is that an important thing that organizations are looking to move to?
Yeah. It really comes down to business priorities. Like every business leader I talk to wants to find ways to grow their top-line revenue, or they're looking for ways to automate, things that, that they're doing so that they can save money or redirect folks to, focus on more important activities.
And, you know, autonomous agents really fit that bill. You know, imagine in the sales context, you can have an autonomous agent, you know, going through marketing leads and qualifying them before handing them off to a human seller. That's work that wouldn't have gotten done in the past or would've been done by a human seller, and have been relatively low value, not something they, they really enjoyed a-about their job.
And so an AI agent can do that and add great value to the company, and again, help that company grow on the top line. for functional transformation. You know, as far as the toolkit goes, we really believe that there's three essential parts to it.
The first is we think every employee should have an AI assistant. In our case, that's Microsoft 365 Copilot. Uh, think of that as a productivity tool to help every employee work, get through their workday, and get more done.
It can be quite transformative. That next step up is where agents come into the picture, and I describe agents as really being for every business process or workflow in an organization, and we have a, a toolkit that enables customers to build their own agents. It starts with Copilot Studio, but even extends into our Azure capabilities with our Azure AI Foundry product.
So agents pair very nicely with that Copilot that I described first. And then the final step is where the system of record becomes the system of action, and we'll sometimes call this the agentic business application, where you take a CRM system, and you add agents and an assistant to it to really transform. Those three are the essential ingredients or building blocks for AI transformation, in a frontier firm or any business at this point.
That's a great term. Can you share some examples of how Microsoft customers are already seeing measurable impact from adopting agentic business applications? Yeah.
One example I, I think I can give is Lifetime. Uh, they're a great customer of ours, based here in the United States. They've used us as part of their finance and supply chain operations, and they've, deployed agents to basically speed up how they handle and process e-commerce orders.
In fact, I think it saved them ninety-five percent, in terms of their order, e-commerce order efficiency by deploying, AI agents and agentic business applications to solve that problem. So I think that's a great example. We also have, another great example, from Europe, a large utility named Eneco, who deployed a multi-language, AI agent, for their customers to help them scale and address customer questions.
Uh, it's a pretty cool solution, saves them time, and again, helps them scale up. Uh, it's a, it's a really exciting time in the world of agents. You know, you talked about the C-suite and kind of the three phases in this adoption curve as we adopt AI.
Uh, what, what kind of recommendations do you have of, like, how to get started? Well, maybe near some of the near-term activities. Well-You know, as I said earlier, I think AI is gonna transform every company, every function, every industry, and that opportunity is so vast, sometimes it's hard to know where to get started.
And I've got two bits of advice really there to, to anybody that, that is, is pondering that question. Uh, the first thing is, again, start with a function. Pick a function that you wanna go after, and then peel it like an onion.
You know, go look at the next layer, which are the business processes in that function that you can apply, a copilot or agents to, to really transform. The other thing, though, is like don't get into analysis paralysis. Just pick a business process.
Just go pick a business process to get started with, and as you learn from applying AI to that business process, whatever it is, whatever your thorniest business process is, go apply AI to it. You are gonna learn. Your organization's gonna learn.
Your culture will adapt, and then it will flow from there. So the opportunity is so vast, don't let that keep you from getting started. You gotta get started.
Start simple, pick one thing, and go from there. So as we move to an agentic business environment, let's talk about the people. How do you see the role of human creativity, judgment, leadership?
How is that gonna evolve? Yeah, well, that's an excellent question, and one of the things that we'll often talk about is how AI and frontier firms is gonna transform the way we work. It's gonna change, the org chart into more of a work chart.
Uh, we sometimes talk about, a frontier firms taking on the Hollywood model, where individuals will swarm around a problem, like focus on a problem, and then disband, uh you know, when the-- w- you know, once they've got a solution. And so it's absolutely gonna change the way we work with others inside the workplace. It also I think is gonna give rise to a new idea that we call an agent boss, and you can imagine just as a people manager today might take work and delegate it to different humans on their team, you know, resolve conflicts and sort of manage performance, every one of us in the future is gonna do that, but not just with humans, but also with agents.
So imagine taking a business problem, breaking it up into pieces, delegating it to agents or a-gents, on your team, resolving conflicts that might come up, applying human judgment. Uh, it's gonna be an absolutely transformational moment, and I'm really excited about it. I, I really believe that, you know, there is still a huge opportunity for humans with human ambition to go do great work amplified by AI.
Talk a little bit about how you see the d-difference in, in the working together between applications, assistants, agents, the different technologies. Well, that's an excellent question, and, you know, we really have this complete toolkit that spans everything from the assistant to the agent to the application. And I think those three things work together in a symbiotic way.
As an example, you can imagine that I might go to my assistant and, you know, ask a simple question, my AI assistant, like Microsoft 365 Copilot, and ask a question about, you know, summarize the emails or help me respond to the emails I've got, or I might use an agent to update a CRM record after I meet with a customer. But I'm still gonna wanna go to an application really that's a purpose-built experience for me if I want a more specialized or fine-tuned experience. So those three things really work together.
Talk a little bit about the industries or maybe the business functions that you expect to see reshaped first by agentic AI transformation. Yeah, there are three or four, I'd say, functions in particular that are, I'd say, you know, ground zero for, functional, transformation with AI and agents. Certainly, customer service and customer experience is one that is, absolutely being reshaped and say a very early adopter of AI, no doubt about it.
Another where I'm seeing a lot of early AI adoption, is in sales, and it's just because w- just as we talked about, there's a big opportunity to use AI to basically increase capacity for that organization to grow top-line revenue, so the business impact there is undeniable. But I also see it in places like finance and supply chain, where you can use AI to shorten the time it takes to-- from an order to actually being able to ship it, that order. We're seeing people use AI to improve accounts, payable and accounts receivable, so we're seeing some pretty, interesting impacts there.
Let's talk a little bit more about the frontier firms. You know, they're not just adopting technology, they're also changing the way they're do-doing business around AI agents and copilot capabilities. Can you talk about, you know, what they're doing to invest and support the short-term ROI that they're looking to get for long-term innovation?
The most successful frontier firms are doing actually is taking a functional approach. And so certainly they'll think about their entire company, but they'll really take an approach that's function by function. They'll think about their sales function as an example, and then they'll peel back the onion a little bit and un-understand which processes inside their sales department they can automate, using AI agents as an example.
They'll look at which, things their salespeople need help with, where you could pair up an assistant like Copilot to help them throughout their workday. And they'll even look at how they can bring agents in to really augment business capacity, maybe to grow top-line revenue or take out costs. But starting function by function has really been the recipe that these, frontier firms, are using to see success.
As an example, in our sales organization, by deploying Copilot and agents, uh-We've been able to improve revenue per seller, in some cases by almost ten percent in some organizations. And, you know, if you think about that, giving a seller ten percent more capacity is like giving them an additional month, in a year, without actually having them spend any extra hours through the work week. And so there's some pretty remarkable results.
That's just sales. We've been able to do the same in customer service and our finance department and our IT department. Our legal team has been able to reduce costs by five percent, by deploying AI and agents, within their, within their functions.
How do we ensure trust and transparency as agentic systems become more and more autonomous? Yeah. Well, there's two things that we want to do to help with trust and transparency.
The first is we have a rigorous set of principles on, responsible AI. So for any AI that, Microsoft deploys, we adhere to a, an important set of guidelines, and that's really table stakes. So that's the first piece, responsible AI and our focus there.
The second thing that I think is important is we now have an opportunity to start to quantify the value and the impact that many agents will have, and we often will call that, in the industry we'll call that evals or benchmarks. And increasingly, I think we have an opportunity to help our customers understand how agents are being effective in their workplace using these evals and benchmarks on real world problems. So, for example, we, a typical, workflow will be a sales leader doing sales research to try to understand, like, how they might wanna organize accounts or territories or, you know, reshape planning as they think about the year ahead.
We recently released a new benchmark, that we call the Sales Research Bench, and it shows how agents can actually help sales leaders in that very specific job, and it's quantified. Uh, and so I think you'll start to see more of that. And between following responsible AI standards and then using quantitative measures like evals and benchmarks to understand efficacy, I think we're really on the cusp of helping customers know how they can deploy AI in a safe way for real business results.
Well, thank you, Brian, for sharing with us your insights into kind of look into the future, what's happening with agentic business applications. Thank you very much. You know, it's really amazing the pace at which AI has been adopted and continues to evolve.
The technology evolves on a near daily basis. But at the same time, organizations have to figure out how they're gonna implement their AI strategies and what the business outcomes that they're most important to their business. I think it's very fascinating how Microsoft has approached the market, both from the standpoint of addressing the individual and their productivity, but also thinking about new workflows, new models of business, but doing that with not a set of tools, but a set of capabilities that provide integration with data, process, workflow and agentic AI.
No one knows for sure what the future holds and what an agentic business might really, really look like. But in situations like today, when we remove constraints of what we can do with technology thanks to AI, that's where the possibilities are created, you know, using tools like Copilot, using applications like Dynamics 365. And we'll, we'll see what end users as well as technologists bring to bear in their ideas and how they reshape businesses for today and tomorrow.
I don't about you, but I'm super excited about the future that we're creating together, thanks to working with technology companies and with end users like yourself. " Hey everyone, welcome to this week's Shimmy Says. You know, this one's gonna be a little different.
I say that every week, but this one really is a little different. You know, we're living in heady times, and you know that moment when you realize that, you know, the flip, the switch is flipped, something big just changed things, and we're never going back to where we were before? Over here at Techstrong, we had that moment this week.
I'm gonna tell you more abou-about it, but it involved an AI agent, a WordPress, and one very stubborn editor. Sounds like a joke. They didn't all walk into a bar at the same time.
But, you know, there's so much talk about AI, AI, agentic AI. Of course, NVIDIA had GTC this week, and Jensen Huang was up there talking all about how, you know, this is gonna add a trillion dollars in revenue. " We've got other people saying, "It could be amazing.
" Well, that, that's what I wanna talk to you about today, but I'm not gonna talk about what I've read or what I've heard, what other people are saying. I wanna get real this week. I'm gonna tell you exactly what our experience here at Techstrong has been.
You know, I, I call it Techstrong eating our own AI agentic dog food, and it's really a peek behind the curtains how one small tech media company has, you know, adopted or at least tried to adopt agentic AI and what our experience has been and how it's changed things. And I, I, I hope it'll serve as a, a real point of information for you, not hype. So let's, let's really talk about what's going on with AI, right?
As I said before, not the press releases or the slides or the, the profits of LinkedIn, you know, telling you we're all going to be replaced by lunchtime next Tuesday. Well, I'll be at RSA next Tuesday. I wanna tell you what happens, as I said before, in a real company, when a real company like Techstrong deploys this stuff inside our business.
You know, it's funny, we've been covering AI at Techstrong since it burst on the scene two and a half or so years ago. But we've gone from covering AI to running on AI, and, and that's very different, right? Talking about it, writing about it's great.
Eating that dog food, that's another story. So let me, let me get into it here, right? So when ChatGPT first burst on the screen, I guess it was late twenty twenty-three, we did what every tech media company did.
We wrote stories, we interviewed vendors, we debated the implication, we tested it out. And what do I mean by tested out? You know what I mean.
The parlor tricks, the magic stuff, right? Write me a poem. Take this article in the style of Shakespeare.
Summarize that article. Explain, explain quantum computing to me like I was a five-year-old. You know, and for people who hadn't seen the AI kind of parlor tricks before, it was magical.
It-- You got, like, all kinds of oohs and aahs. But for those of us, especially in security tech in general, but security more importantly, we were very impressed, but cautious. Look, it hallucinated.
It made stuff up. It lied. It deleted stuff.
There was all kinds of security. And, and around the wrapper of it, no matter how bad it screwed things up, it always sounded so confident. Even when it was wrong, it sounded confident.
" So internally here at Techstrong, we thought it was really cool, but it wasn't ready for prime time. We were not about to let a machine publish under, under our brand without human oversight. We told our writers, "No AI.
It's your reputation on the line. " But let me tell you what else is real. Sometime last year, September, October, certainly by November, it got real.
All of the models got so much better. Not just clever, but they became useful, consistent, capable of doing real work. And I'm gonna tell you what else happened too at the same time that kind of flipped the switch.
Humans, especially us here at Techstrong, we got better at using them. We learned one-shot prompts, two-shot prompts. How do you-- You don't take-- You know, you don't take what it first gives you.
How do you stop prompting from being guesswork and make it a skill? We learned how to steer the gen AI models, how to structure requests, how to get the output that matched your voice. And you know what?
As I said, sometime around November, December, man, we weren't playing around anymore with AI. We were collaborating with it. And that, that was a huge change for us.
Now yeah, there's a lot of AI slop out there, and we tried not to let that get through the filters, but there's tons of AI slop out there. It's low-quality garbage that's flooding the internet. It's low-quality bug reports that are flooding open source projects.
But there's a part that we don't acknowledge, and that is that AI has dramatically increased the output. It's cre-- It's increased the output of content. It's increased the output of code.
It increases the output of everything we point it towards. We're just publishing a lot more content. We're making a lot more code.
We're doing a lot more things. And not all of it's bad. Most of it's really good, and that's a good thing.
It's a good thing for us, quite frankly, because the amount of AI-related content out there has forced us to widen our aperture to cover all this stuff. It's insane the amount of news coming out that we gotta keep up with. So without leveraging AI and some of these tools, we couldn't keep up with it.
And that was fine up until a couple of weeks ago. With the launch of OpenClaw, another switch flipped, and this might be a bigger switch in the long run, and that's agentic AI, right? Up until that point, agentic AI was a tougher sell, let's face it.
You know what? Up until that point, my attitude is, you know, agents s****d. They did.
They were hard to use, didn't do what they promised. I just didn't see it ready for prime time. Look, what they say they claimed to do sounded incredible.
Autonomous agents and software that could do tasks for you, not just prac-- chat. But they did. They, they s****d.
So we spent some time babysitting them more than they sa-- You know, the time they sa-- that you spent babysitting was more time than they saved you, and it wasn't good. It's just easier to do the work yourself. But it's part of our charter here at Techstrong, right?
It's news. We covered it. We told you about it.
But internally, I couldn't sell that. It was like, you know, selling ice to Eskimos. I couldn't get that out the door.
But as I said, OpenClaw came in, I guess maybe a month and a half ago now, and that really was the oh, God moment. Suddenly, these agents became usable, accessible, dangerous, but in the best possible way. " It re-energized people.
And that's the thing I've seen. You know-The people who are in on this agents thing, they have like a look in their eye, like they're almost manic because they-- it-- the, the, the promise of what it does and what they're doing with it has them like... It's, it's almost like a, an endorphin kinda or a caffeine kinda hit.
So for us here at Textstrong though, it really started with me pushing one of our producers to try it. He was a smart guy, somewhat security aware, not easily impressed, jaded even. He resisted.
I, I get it. Giving an autonomous system access to your machine should make you a little nervous. But I pushed him.
" And eventually he got-- he went out, he did it. He put a Mac Mini. We got him a Mac Mini.
He installed it, and that one machine here triggered a tsunami. Within days, we had the next team member getting their own Mac Mini and setting their own agent setup, their own instance setup. Before you know it, more Mac Minis starts popping up all over the place.
Before you know it, you can't buy Mac Minis. They're hard to get. We experimented, this is pure open source, learning how to lock them down, how to manage permissions, what APIs you're gonna need, what could it do, what could it not do, how to connect them to the tools that we're already using.
Do we need MCP servers? And then the magic moment happened, another magic moment. These agents, they started talking back.
They started doing real work. They were reading transcripts, watching videos, pushing buttons, drafting posts, editing content, publishing articles, scheduling the updates for us, summarizing the meetings. And I'm not talking about demos or toys.
I'm talking about real production work here. Our newsletter's being published like this. Our content is being posted.
Here's the key point though. This didn't mean that no-- everyone stopped working, sat back, and let their agents do their job. No one got laid off.
People just stopped doing these roto tasks, this mind-numbing stuff that used to eat their entire days. The copy-paste workflows, you know what I'm talking about, right? Formatting, uploading, cross-posting, admin-- pure administrative overhead kinda stuff.
The work that makes you busy, but not valuable. And the agents, that's the first thing they ate, that busy work. But then came yet another wave.
And the, and just to show you the timeline, all these waves came in the last two and a half weeks. We all started reading about Perplexity and this Perplexity Computer. Truth be told, we wanted the Perplexity Computer personal that runs on its Mac Mini, but that's not available yet.
So we shelled out two hundred bucks a month and started giving people their own Perplexity Computer accounts, those who didn't already have OpenClaw on Mac Mini set up. " And I hear it, but I say to you, compared to what? Compared to the fully loaded monthly cost of an employee, like if I hired a coworker?
Compared to outsourcing it to somewhere in who knows where in this war-ridden world? Compared to lost productivity of people doing mind-numbing work? Two hundred dollars starts looking like lunch money to me.
Forget lunch money. Two hundred dollars a month isn't gonna buy me lunch all month. It's m- looking more like coffee money.
So I made a deal with my team, and I encourage every CEO and executive out here to make this deal. Anybody who wants it, we'll pay for your Perplexity Computer for a month. But in return, this is what I asked of my employees.
Give me a weekly report. What did it do for you? What, what task are it doing?
How much time did it save? What changed in your day or as a result? As a result of it doing those tasks, what other kind of work were you able to do that you haven't been able to maybe do as well before?
We'll look at the three weeks, three and a half weeks of you using that, and at the end of the month, let's decide together, is it worth the two hundred dollars a day? For some, it may be worth three, four hundred because they're gonna use a lot of credits. And I thought, look, half are gonna use it, and half probably it won't work out.
But I gotta tell you, it's only been about a week, and the results are already ridiculous. As I mentioned before, we've automated our newsletter production. Our video descriptions get generated.
Social posts are queuing up. Articles moving through our publishing editorial process so much faster. Whole web pages, forget it.
Websites designed and deployed being done. We got something for next week in RSA that you're gonna love on Security Boulevard. Meeting agendas are being summarized before the meetings even start.
And we're just warming up. This is just a week. How sales is using it, marketing, operations, video, editorial.
We're looking at learning events, the webinars, our internal ops. Everything is being rewritten, rethought, redone in, in lightning speed right now. We're looking at stuff we haven't questioned in years.
You know, some accounts that haven't been changed since twenty-thirteen. And you know what? We're looking and saying, "They're optional.
" Our whole sorta Zap system of how we integrate stuff, is it something we're gonna use going forward? I don't know. Personally, myself, I'm using my agentTo triage my email, manage my, the chaos that is my calendars.
I'm streamlining the workflows that used to drain hours out of my day every day. Now they're all going on in the background. When I check my, my email at six, six thirty in the morning, I have everything all taken care of here.
But let me, let me stop here for a second. I know what a lot of you are saying. "Shimmy, this is great.
" No, absolutely not. I didn't-- we didn't lay anyone off. We didn't fire no one.
Let me be crystal clear here. This really isn't about layoffs. It's about leverage.
It's leveraging good employees to ten-x themselves. Because a lesson I've learned in my career is you give smart people tools that multiply their output and then just stand back and watch what happens. Instead of grinding through ten hours of routine work, they spend those hours on strategy, creativity, problem-solving, thinking of new and better ways of getting stuff done.
That's the stuff humans are good at, and it's actually gonna be the stuff we continue being good at. There is a flip side. I'm going to acknowledge it.
Not everyone is thrilled. Some people are uneasy. Some people are skeptical.
Some people are just so stuck in their ways they don't want to accept new things. They just don't want to learn something new. They're very happy in their little routines that they live in, and I get that too.
Change is scary for people, especially if you've been doing the same thing over and over for a while, right? Especially when it feels like the ground under your feet is shifting and it, it's all you can do to just stay up without falling down. But I'm gonna be really honest with you here as a CEO founder of a company multi-time.
If your job can be dramatically enhanced by these tools and you refuse to use them, you're making yourself very much less valuable, very much an optional person or an optional part of the organization. Not necessarily because the company wants fewer people or less salaries. I mean, there are some companies that'll do that, but it's because the world outside the company is moving just as fast as we are here at Techstrong.
You can't freeze time by ignoring it, wishing it away, or closing your eyes. Let me tell you about my favorite moment so far with this whole experiment. We've got a young editor here.
He's been here... He's worked here forty-five years with us. I called him and told him I wanted him to use this, and he told me flat out there was no way that AI could publish directly to WordPress.
He's tried it. It doesn't work. It'll never replace him.
Forget about it. Too complicated, too many formatting issues, not feasible. We debated in a healthy argument, and I say that it was a argument.
I don't know how healthy it was, but we banged heads and, you know, I said, "Well, just do me a favor. Try this anyway. Do me the...
" He looked at me up. " And that's when I knew how big this was. That's when I knew this was real.
That's when I knew this is gonna stick. In tech, we always talk about eating your own dog food, using your own product before asking customers to trust it. What we're doing here goes beyond that.
We're not just eating this dog food. Our people are howling at the moon because once you see what's possible, you can't unsee it. You start looking at every process, every task, every meeting, and you're asking the same question of it.
Is this something I should be doing? Is this a job for a human, or can I get the agent to do it? Again, not in a dystopian let's cut jobs way, but in a practical way.
Humans should be doing work that's worthy of humans. So my friends, here's the deal. If Techstrong is any indication of what's going on out there, these next, these next few months are gonna be wild.
Entire job descriptions will shift. Entire ways of doing business will disappear and reappear. New roles will appear.
Old workflows will disappear. Companies that adapt are going to accelerate through this and, and really take off. But companies that hesitate are gonna feel like they're standing still while everyone else is moving at warp speed.
And this is the thing. This isn't hidden. It's not theoretical.
It's not ten years away. " It's sitting on your desk right now. Right now, you can get started, and every day you don't get started is a day you're wasting.
So here's my advice to you, especially if you're in leadership. Stop debating whether this is real. It's real.
It's not perfect, but it's real. Stop waiting for permission. Stop assuming someone else is gonna figure it out first and you could piggyback it.
Start experimenting right now. Start learning right now. Break things, build things.
Push the tools they, they... until they fail, and then learn why and fix them. Because the people who master this early, they're not just gonna be a little bit ahead.
They're gonna look like they were teleported into the future and you're riding a horse because the future doesn't always arrive with fireworks. Don't miss the knock of opportunity here. Embrace AI, embrace agentic AI.
We're doing it, and I-I'm really, really happy we are. I'm Shimi, and that's what Shimi says. I'll see you next week.
I'll be live at RSA for Shimi Says. Shimi says, Shimi says, Shimi, Shimi, Shimi says. Ask me almost anything.
Is AWS partnering with a three-headed dog? Cisco gets a ten that they really didn't want. Dell digs into AI at GTC.
CrowdStrike does too. Nutanix is also doing stuff with AI. Zscaler goes for global compliance, and we're going to listen to the king of AI getting even bigger in this week's episode of The Tech Field Day Rundown.
Hello, everyone. Welcome to The Tech Field Day Rundown for March the eighteenth. We're very glad that you all survived St.
Patrick's Day to join us here on National Oatmeal Cookie Day. And, I'm-- I have a hot take. Uh, oatmeal cookies are actually not that bad.
I think that what most people hate is the raisins that are in them. But joining me is someone who is the best cookie ingredient around, a new co-host, Mr. Dave Graham.
Dave, it's good to meet you. Yeah, likewise. Great to be here, Tom.
Well, we're very happy that you could join us on National Sloppy Joe Day if oatmeal cookies are not your thing. Uh, but what is not sloppy is all of the great news that we have because it is all about all of the cool stuff that's going on in the industry, but also NVIDIA GTC, which is, you know, eating up all of the oxygen in the room. And we're gonna have several stories talking about that, but also some other fun stuff.
So make sure that you are seat belted in. Amazon Web Services and Cerebras Systems announced a new collaboration to speed up AI inferencing in the cloud. The architecture combines AWS Trainium processors with Cerebras' Wafer-Scale AI systems and will be delivered through Amazon Bedrock.
By splitting inference workloads across specialized processors, the companies aim to dramatically improve response speed for demanding AI applications such as coding assistance and real-time AI services. Dave, I guess my question here is we've seen a lot of talk about what Cerebras can do to accelerate all of this stuff. Do you think that Amazon is going to be offering this as kind of a, basic solution offering, or is this gonna cost you if you wanna go with what Cerebras has to offer?
Little column A, little column B, you know, potentially little column C. I mean, it's about time for Cerebras to be adopted into something that's a little bit more mainstream than just their own cloud or some, you know, hypo, Neocloud and regions that we shall not mention at, at the current date and time. So yeah, that was very exciting, and ent-entrée into Bedrock means that they're gonna have a pretty good cadre of folks that they can draw from that will be able to kind of tap into their services, and we'll, we'll see what the outset is.
I mean, it may be a little bit spendy on the ins-- on the in-- onset of this, but as, you know, as users scale up, you know, it's a possibility it's gonna drive some revenue down. So I'm pretty stoked about that for, for them, and we'll see what happens. All right.
So critical vulnerability accepts, ac-accepts all of us, but affecting Cisc-Cisco C-Catalyst SD-WAN controllers could allow remote attackers to bypass authentication and gain administrative access. The flaw, tracked as CVE-2026-20127, pretty fancy there, carries a CVSS score of ten out of, I'm assuming, ten, and it may allow attackers to manipulate SD-WAN network configurations. Cisco has released patches and recommends organizations update immediately and review logs for suspicious access.
So Tom, in the compendium of CVEs doing bad things or highlighting bad things that have happened within the SD-WAN or let's say the networking security space, what is this one like? Well, I-- it got a ten point O from the, the folks over at the research facility, but I heard it got an eight point seven from the Russian judge, which is, par for the course. I-- look, we're, we're, we're dealing with more and more of these nine and above CVSS scores for a simple reason.
It's because the attackers are not just looking to breach systems. They're not looking for footholds anymore. They're looking to immediately manipulate the access that they get to do something with it, and that's because the, the dwell time on these, breaches is starting to shrink significantly.
And that is both a good and a bad thing, as you could probably tell. The good news about that is, is that when people get access, we're immediately detecting it and being able to shut down their access to laterally move through the systems and do all kinds of things that they're not supposed to. We like that.
The bad news is that means that the people who do find these vulnerabilities are immediately motivated to do the kinds of things like we're seeing here, where they can bypass authentication, and they were able to translate that into the ability to jump into the configuration and, and basically do things that they weren't supposed to do. And this is a problem because in a Cisco device, you really want the control plane and the data plane to be separated from each other, right? If I can get administrator access to the device and I can do all kinds of control plane stuff, woohoo, that's good because that means that I don't affect the data path.
So in the event that something were to happen, you know, maybe I can modify some configurations or do things that I weren't supposed to, but ultimately the device is still gonna be able to forward traffic, which is what it's supposed to do. But if I can get in and I can do this, configuration manipulation thing, that is a problem because now I'm affecting the data plane, and I can knock these things out, and I create denial of service without the need for doing massive packet generation. " You wanna make sure that you're up to date, and you also wanna make sure that your logs are, showing that people aren't actively exploiting this because that's the other thing too.
You can get this patch, but you know that if people were able to get in and do something with it, you now are gonna have to audit all of your configs, and you might find yourself a tempting target in the near future. So please patch what you can and make sure that, you know, you're, you're missing the triple axle on this, so your score goes all the way down. Got a good Olympics reference there.
I do my best. Uh, we're gonna jump into the first of our many stories about GTC this week. Dell Technologies announced new additions to its AI infrastructure portfolio during NVIDIA GTC, including a data orchestration engine designed to help organizations prepare and manage data for AI applications at scale.
The updates also support, NVIDIA's Blackwell GPUs and new AI frameworks aimed at simplifying how enterprises deploy AI across cloud, edge, and on-premises environments. Dave, what's Dell's in here to be a part of the bigger NVIDIA ecosystem? I mean, Dell has been, foaming at the mouth to be part of infrastructure, anything to do with AI.
I mean, this has been Jeff Clarke's kinda mantra for, I don't know, I'm an alma mater, you know, Dell's my alma mater, so looking back about it, he's been talking about this for a long time, right? So any of the introductions they do in this particular space are gonna be sh- trying to shift the energy away from bespoke, you know, bits and piece build type things to monolithic infrastructures that are encompass server, storage, networking, and compute, right? And then that soft squishy layer of software that sits on top of it.
So when you start to talk about these, you know, application layers or AI frameworks, right? This is a huge investment by Dell in terms of making the bits and pieces talk and work together in ways that are now above the stack. You know, Dell's always done hardware.
Dell knows how to do hardware. It's table stakes at this point. But I think that differentiation point for them is really focusing their energy on now software now defines the AI era in ways it never has.
And oh yeah, don't forget that little data piece that, you know, they spent a large quantity of dollars on when they bought EMC back in, you know, twenty sixteen, right? That's the legacy kinda paying it forward finally, in my opinion. So yeah, really exciting to see Dell kinda step into this space.
I think it's, I'm gonna keep on saying this, probably about d**n time that they get some, get some metal behind it and, you know, pun intended, I suppose, in that case. But yeah. So there we go.
Moving on to the, the joys of, more security software. So CrowdStrike is expanding its collaboration with NVIDIA to bring more AI agents into managed detection and response services. So they announced at NVIDIA GTC the partnership, which includes new agentic AI capabilities, integrates a secure by design AI blueprint into A- NVIDIA's Open Shell, and uses NVIDIA Nemotron models to accelerate cybersecurity investigations and improve detection accuracy.
This move highlights how security teams are increasingly using AI to defend against attackers while also working to secure the growing number of AI agents deployed inside modern enterprises. As long as those modern enterprises don't resemble a, you know, an airline that we know has affected them in the past. So Tom, again, hot take here.
AI as actors, AI as middleware, AI as, you know, something you're gonna have to protect and enable, right? So what's CrowdStrike doing here that's, that's kinda moving the, moving the dial a bit? I think CrowdStrike is really trying to, tell their customers that they are integrated into what NVIDIA is offering so that their customers don't try to jump to the next thing.
So one of the things you talked about was Open Shell, which is NVIDIA's big announcement that they're gonna try to offer solutions that will prevent things from like Open Claw from being able to operate in your network with full autonomy. You know, we're, we're not just building guardrails now, we're putting up fe- lobster fences everywhere. And I think that the important thing that people need to understand is that this is going to happen.
Whether you want it to or not, people are installing Open Claw, and they are working with it, and they're working on the successors. And it's funny to me that there has been a huge run on Mac Minis over the last three months because people's methodology for creating these guardrails right now is to have it running on its own machine so that it is effectively air-gapped from the rest of what you want it to touch. Because as we've seen and as we've reported on a number of occasions over the last ninety days, this thing really does kind of act on its own, and it, it has, agency, and it has motivation to go out and do things, and you really have to give it these limitations.
And we talked about one of them last week with Chris Grundemann, this iron curtain idea that it, it can slam shut to prevent things from getting in the way. " And that-- but that's not the only thing, right? Like, that is probably the, the one thing that people at home will recognize.
But for enterprise users of CrowdStrike, you know, they're gonna be leveraging all of these new inputs to help, detect attackers more quickly, and also the fact that attackers are gonna start using AI to leverage, new, attack vectors and things like that, 'cause we've already seen that right from Claw, Claude, being able to scan and do a whole bunch of other stuff. We covered that on Security Boulevard a few weeks ago. Uh, I just think it's fascinating that now, there's this arms race in AI, inside of security to leverage it, to beat it being used to attack you.
And I don't know how that's ultimately going to shake out. But, you know, time will tell. Hey, look, it's another story about GTC.
This time we're gonna be talking about Nutanix because guess what? They have new capabilities for securely running AI agents within their enterprise AI platform. Built with support from NVIDIA tools and models, the platform allows organizations to deploy and manage AI agents across on-premises, hybrid, and self-managed cloud environments while also maintaining stronger control over security, networking, and infrastructure costs.
I gotta ask you, Dave, what value are people getting from running all of this on Nutanix? I, I, I think you're seeing the same theme that, you know, we saw with Dell and we see with, pretty much everybody in this space is gonna be announcing some way to orchestrate or manage or deploy or yes, you know, when it comes to AI and agents or models or, or whatever. Uh, the interesting thing that Nutanix brings to the table, which I think in this day and age where we haven't really talked about hyperconverged infrastructures for a long, long time, right?
It's kind of gone the way of the dodo bird relative to marketing and intent. But, you know, Nutanix has just been quietly plugging right along and, you know, selling, selling sleds, man. Like, they, they've been doing a really good job with this, is they have invested so much in their software ecosystem around...
You know, hardware is table stakes these days. No one, no one really is... To be fair, the innovation that's coming within the compute cycles is really rather, rather limited.
It's, it, it, it's operating in epochs and cycles. But where you're seeing that is the folks that sit, sat down and they developed the software ecosystem, that container AHV, right, that, you know, Nutanix threw themselves at as an alternative way back in, you know, way back in the day to the Broadcom, VMware takeover, you know, that kind of rolling forward. They spent so much time in that, they've, kind of almost accidentally, but maybe on purpose, laid the foundation for this incredible infrastructure now that enables them to do things.
Like it's tightly coupled, it's very, it's flexible, it's, you know, all these things you just mentioned, you know, OpenClaw. Like again, there's variations of OpenClaw now that run in cont- you know, that you can isolate and put in containers, right? You can propagate that out.
I think Ironclaw maybe is, one of those. Uh, Nanoclaw, I think is another one. But anyway, any of these kind of permutations, right?
So the idea behind this is, hey, listen, and Nutanix is, has been playing the game for decade plus at this point, and they're continuing that kind of rolling forward plan. They've developed all, they have a great platform, they have great software. The hardware's great, you know, no, no complaints there.
So I think this is, again, just another turn of the cycle for Nutanix that's hopefully gonna pay off really, really well for them. I mean, they're the, they're the dark horse that not a lot of folks talk about, but they, they've just been quietly winning in the backend, so hands off to them. All right.
You know, it, it's not a name that's... Uh, I have a lot of friends that actually work for this next company, and it's, a-again, you know, it's, it's out there. It's not a table, you know, tabletop name, but Zscaler's been doing some interesting stuff.
They hired a really good friend of mine who's in the research space now, and, they're expanding their data sovereignty capabilities as a consequence, and going into this zero trust exchange platform to help enterprises meet and grow against regulatory requirements. So the updates that they've introduced include regional controls, local encrypted traffic inspection, enhanced compliance features designed to keep sensitive data within national boundaries while maintaining global cloud security performance. Now, there are a lot of buzzwords in that particular story, but in this day and age where geopolitics, dare I say it, are a very large concern, data sovereignty, you know, dare I say OPSEC being kind of something you wanna make sure is clean, Zscaler's kinda rising to the charge there.
So how is Zscaler de-differentiating themselves against, you know, some of our other compatriots in this particular security space like CrowdStrike and Cisco et al.? It's the trust but verify model, and that only matters to you when an auditor shows up at your front door with a bunch of papers that you are going to then have to justify, because that is one of the key things that you have to worry about with data sovereignty. And, kids, when you hear the word data sovereignty, you should hear it with a German accent, because that is what most of these data sovereignty features are designed to do.
Um, I, I jokingly told somebody the other day, if I wanna know the opinion of how a piece of security software works, I'm gonna call my German friends because, oh my God, those guys are very serious about this. Data sovereignty is becoming the new security buzzword for these kinds of SD-WAN and SASE providers. " Well, how do you know that it didn't?
Because when you have a lot of these automated systems that are in place that are trying to make sure, oh, well, I'm using the cheapest transit leaks over here, well, I can do that through path selection influence, right? Like, I can make the paths between, my data center in Reston and, and some other places a lot cheaper overnight so that the data does traverse through those locations, and depending on how the rules for data sovereignty are set up, if it traversed through my data center, I get to scan it on the way through and on the way out, right? I know that sounds really, really suspicious, but do you remember a point when YouTube melted down about 10 years ago because somebody made a mistake in BGP and forced the global internet traffic through Pakistan?
Do you think that was an accident? 'Cause it, it wasn't an accident. Uh, that's also why it's important to do things like encryption and stuff like that, because even if those links accidently, they accidentally traverse in an area where it's not, you wanna make sure that the, the data is protected as it transits through those links.
But again, it comes back to the data sovereignty pieces are not just making sure that the data is going where it's supposed to, it's the verification steps to show that it stayed where it was supposed to, that it never left these boundaries. Because one of the things that we see a lot with a lot of the EU, structures that are in place to make sure that data is staying where it's supposed to, and it's not being exposed to places that could cause harm, is that their fines have real teeth. Like, this isn't the thing of like, you know, if you've ever heard it in the US, if the only, punishment for a crime is a fine, then it's legal for a fee.
Um, in the EU, EU, especially with things like GDPR, yeah, if you screw that up, you get fined like 5% of your total, like, revenue for the year for every infractionThat is painful on purpose. So for organizations, again, read that in a German, accent, that wanna make sure that the data stays within the borders of a sovereign nation, Germany, this gives those auditors proof that it never left, and that's really what most people are wanting. " All right.
We n- have a story we need to take a closer look at. I'm, I'm gonna give you three guesses, and the first two don't count, because at GTC 2026, everyone's favorite jacket salesman, Jensen Huang, projected one trillion dollars in orders for Blackwell and Vera Rubin AI systems through 2027. Hey, wait, that's next year.
The announcement highlights the explosive demand for agentic AI and ad- advanced GPU infrastructure, including new Groq 3 LPUs, upcoming Kyber Rack systems, and some freaky AI inferencing related to graphics cards that we're not gonna talk about. Uh, the focus on high performance inference and energy efficiency signals Nvidia's continuing dominance in the AI computing and next generation autonomous application space. Now, Dave, we all knew that this was going to be a big deal because Nvidia is the number one company in the world.
They are the leader by far, and it feels like they're just stepping on the gas pedal to accelerate away. But most of the comments that I have heard from people that are on the ground at GTC, including our very own Aleister Cook, said that it was a two-hour keynote that really could have been a one-hour keynote because it felt like an hour of it was just Nvidia telling you how awesome they were. So let's talk about this.
Can anybody catch Nvidia? Uh, I think it's, you know, Nvidia made some tactical decisions up front, again, I think similar to the Nutanix story, right? They made some tactical decisions up front to invest very, very heavily in that software ecosystem.
I mean, hardware became table stakes to them. They know the cycles that it takes to do good EDA and to get it out to foundry and get it back, right? So they invested very, very heavily in this software ecosystem.
They made it almost indispensable, right? You know, almost indistinguishable from their hardware product, right? And so that investment is paying them dividends.
People use it, use their hardware because their software is that good. Now, we're seeing some differentiation. There's certainly p- folks that are nipping at the heels.
I think the Groq thing is very interesting, and that's Groq with a Q, not Grok with a K, because, you know, read that in a German accent, pun intended. There's... And I...
That acquisition or that acqui-hire, if you will, it becomes interesting because this is acknowledgment that core silicon is not always gonna win. You know, the general purpose, the GP in GPU is general purpose. And, you know, there's this idea that some of these, you know, competitors, small or large, are out-thinking some of the fringing areas that we're starting to experiment with, right?
Everything is converging at SLMs now versus large language models. Small language models are starting to come up. We're starting to see those being embedded.
So I think there's this acknowledgment that Nvidia, yes, is the preoma- predominant player, the eight hundred pound g*****a that copped something from, you know, the register back in the day. Um, but there is opportunities, and there's always gonna be opportunities within the market. So yeah, whether it be a two-hour marketecture that could have been an hour type conversation or whatever, it's good to hear the optimism especially given, again, geopolitical concerns and compression and supply chain issues that are things that are going on right now.
Uh, but at the same time, I think there's enough white space between those lines to say, you know, Nvidia is leading today. They may be leading in through 2027. They may be leaving, leading into 2028.
But there's always opportunity, and there's, certainly folks like, you know, they sh- that shall not be named, that, will be able to take advantage of those particular things. I mean, your opinions on that, for sure. This is Nvidia's market to lose, but I don't think Nvidia is going to have to worry about someone coming up to take their market share.
I think they have bigger concerns, and this, this you can see from all the moves that they're making. This is less about whether or not an AMD or any other companies are gonna come up behind them and take anything, and more about how do I keep the, the money printer printing? Because think, this is something I mentioned to my friends, and this kinda cracked me up.
Do you remember when we were kids and everything was futuristic and robotic and awesome and, you know, autonomous this and that? And do you know what they call autonomous vehicles and robots now? It's physical AI.
No, it's not. It's robots. It's autonomous vehicles.
It's self-driving cars. Don't rebrand it to put your friggin' trademark all over it. Look, I get it.
You guys don't want the money printer to stop, because every trillion dollars that you make off of all of these things is another trillion dollars that you can use to, I don't know, fix the Wi-Fi at the Nvidia headquarters. Shout out to my friend John Kilpatrick. But more importantly, like, you g- th- this is the thing.
You've gotta start shoving your stuff into everything, because if you don't, people are gonna realize they don't need your stuff. Like, that's one of the problems that, that a lot of people are looking at right now is, what am I using AI for? Um, a lot of people are using AI for a lot of things, and, I have lived through this before, because I remember a time not so long ago, it was probably about ten years ago, when everything had to have a software-defined networking component.
We had to shove software-defined networking into everything, and it all had to run on eigh- X86 hardware because that's what DPDK was optimized for. And where are we now? Oh yeah, that's right.
Everything has a DPU that runs on ARM because it turns out you don't need all that heavyweight stuff. Now, a lot of the things that we built through software-defined networking are applicable now because we've abstracted what was important away from it. But yes, for those of you youngins who just got started in the field and are working on your prompt engineering skillsAll of this has happened before, and all of this really will happen again.
Do I think that Jensen is gonna sell a trillion dollars' worth of CPUs and GPUs and DPUs and IPUs and PUPUs? Yes. He's gonna sell all of it, and all of the RAM and all of the hard drives that are out there are gonna continue to be ridiculously expensive until something magical happens and someone invents the next big thing.
And I don't know what it's gonna be. It's quantum computers. Uh, we're gonna detect alien life.
Um Someone's gonna build a slightly faster cell phone that consumes a little less battery power. Whatever it is, when it happens, everyone is going to shift. You know why?
Because that is the pattern. Because it always happens. This is the hottest, exciting, best, newest thing.
Look, something shiny. Yoink, off we go. AI will persist in the way that it is, and Nvidia will be the only buggy whip manufacturer at that point, and they'll be happy.
You know why? Because IBM still sells mainframes, and they're really good at it, and nobody's breaking into the mainframe market right now because nobody wants to. Dave, thoughts?
Yeah. I mean, hard to argue with that passion there, Tom. Like ground-source passion and belief.
It's almost like you're a fundamentalist of the Nvidia church. Uh, that being said, you know, yeah, it, it... Again, it's, it's an opportunity that can be lost.
You know, it can be lost through spending too much time and looking in the rearview mirror and wondering what competitors are catching up to you. And so I think this is where Jensen, you know, we, we made the comparisons to VMware over the, over the decades, right? You know, you need the, you need the founder mentality.
You need the Diane Greens in there to start things up, and you need that kind of visionary. You need the Paul Maritz that's in there to stir some s**t up and do some interesting things, right? And then you need a business person that's in there that's executing to plan.
And whether you consider Pat Gelsinger that person or not, it's beside the point. He's a business guy. So I think you kinda have the same rotation going on, and Jensen's always been at the helm, but he surrounded himself with incredible people that are pushing the needle for him, right?
So like, you know, the acquisition of Mellanox, and these are calculated moves and pushing into it. Um, it's interesting to note the things, the areas where he hasn't spent a ton of money, specifically in storage space, which is, like, kind of an ironic thing because when you start to look at the storage market, when you start to look at what drives AI, when you start to look at what drives the need for silicon and all these things, you know, it's deriv-- it's driven by data. So they've spent a lot of time on making sure that the door's open, the window's open, the building's made, the air-- all the plumbing works and whatever, but they also have the data is people problem, right?
It's that, how are you gonna manage that influx? How are you gonna manage that, that inflow? And so, you know, their participation in LMD and all the other fun stuff they're doing with Dynamo and Nixle and that kind of thing, it's, it's great.
You know, and we have folks from VAST and Weka, and they made a huge amount of announcements on it. But it's the one niche in their portfolio that they haven't really filled with anything. They haven't acquired anything.
They haven't over-rotated. So I would, I would, I would say that trillion dollars is gonna be great. You can spend all the money in the world on that silicon, and you can do that, and again, they're gonna lead the market.
Again, to your point, it's theirs to lose. But they need to backfill some of these spots, and I'm, I'm looking for them to, you know, if I'm gonna prognosticate, and maybe it's again in the white space of what Jensen didn't say, I'm looking for them to try to fill that storage portfolio and fill it a little bit tighter and a little bit closer maybe within the next year. It's gonna be in software.
It's not gonna be in hardware because Jensen also understands the political pressure to keep supply chains going in one way or the other, whether it be sovereign US semiconductorism is in fabrication facilities or, you know, Asia concerns right now in terms of saber-rattling and whatnot. You know, Jensen's a smart, smart dude. He's gonna, he's gonna pay attention, and he's gonna surround himself with people that know where they can fill those, those buckets from.
So I don't know. So it's gonna be an interest- it's gonna be an interesting couple of years to see what he does. But, you know, at least in the short term, we got some predictability.
We got some, you know, there's some money that needs to be printed and some, AI-flation that's gonna probably occur as a, as a result of it. But yeah. One other thing that is predictable is all of the great stuff that we're doing here at Tech Field Day.
And guess what, kids? It's gonna be a busy month coming up because I'm gonna be really busy. Next week, I'm gonna be out in San Francisco for RSAC.
We're gonna be doing Tech Field Day Extra there Monday and Tuesday. We're gonna have live streaming video from companies like Veeam, Object First, and Commvault. com to check those out on the 23rd and the 24th.
And then I'm going to go home, do my laundry, and go back after Easter for t- the Networking Field Day experience number 40. We are officially in Roman numeral territory, folks. Uh, we have a very packed lineup.
com. Uh, we're gonna have lots of great presentations, new faces in the delegate panel. You're not gonna wanna miss that.
Week after that, Stephen Foskett is back on the road for Tech Field Day Experience at Qlik Connect. Uh, make sure you stay tuned because some of the videos that they're gonna be recording while they're on site will be published on our website. Uh, won't be any live streaming, but don't worry, you won't miss any of that fun action.
And then at the end of April, I'm gonna be back in Silicon Valley for Security Field Day, and we have, some fun presentations lined up. com. You're not gonna wanna miss that.
Uh, just like I am probably gonna miss home for quite a while. Uh, but the home for all of the things that Dave Graham is talking about, where can I find that, sir? So, you know, I work for a technical standards organization called ML Commons Association.
org. We have a... We're doing a presentation this week atGTC talking about what's coming next in the benchmarking for generative AI space.
So stay tuned to that. A couple of bits and pieces going on from there, but I'm around. You can find me on LinkedIn.
You can find me, on ML Commons and, you know, always in the community here at, Tech Field Day. Well, we thank you very much for joining us today, Dave, and we thank you all for watching the Tech Field Day Rundown. You can catch new episodes every Wednesday on YouTube or in your favorite podcast application of choice.
Rundown is also being streamed on Techstrong TV, and you can catch myself and many of our other fun folks on many Techstrong and Futurum Group programs like the Security Boulevard podcast and the Techstrong Gang. We're gonna be back next Wednesday. Well, I won't, but Al will be back next Wednesday with a new cohost to talk about all the IT news of the week that was.
Until then, for myself, for Dave Graham, and all the great people that help us out here at Tech Field Day, thank you very much, and go have an oatmeal cookie. Uh, my name is, Chad Smith. I'm the Field CTO of Alliances here at Hammerspace.
And today, I'm gonna give you a demonstration of Hammerspace running both on-prem and cloud, kind of a hybrid solution. Um, I decided on doing demos instead of slides today because, a lot of you have a lot of experience in hearing about Hammerspace, talking about it, but not actually seen it in action. So I went ahead and recorded a couple demos I'd like to share with you guys today.
So today, I'm gonna present you guys with four demos. Um, they're covering, various topics such as assimilation, global file systems, Tier Zero, as well as our, our S3 interface and metadata. So let's jump into w- the first demo.
So the first demo is really all about data in-place assimilation. We're gonna walk through the process to set it up storage assimilation, shares, storage systems, volumes, and mounts. We're gonna spend a little bit of time discussing Hammerspace sh- snapshot efficiencies tied to third-party storage and APIs.
Uh, we're gonna briefly discuss, multi-protocol access via SMB to an assimilated NFS server. And then finally, we'll conclude our first demo with what it takes to set up a global file system across sites. So let's jump into it.
We'll start this video, and I'm gonna pause it frequently to discuss some aspects of the solution. So out of the gate, what you're looking at right now is the Hammerspace UI. It actually runs on the Anvil server itself.
So as long as you point your browser to the Anvil's IP address, you're gonna get to the Hammerspace interface. This is a relatively fresh cluster, installed on an on-premise environment. And the only thing I'm gonna show you guys that I took the liberty of installing is I just attached it to Active Directory.
And the reason why I did that is 'cause we'll be using, SMB a-access throughout this demo. I wanted to make sure that cross-site, SMB access is, is set up correctly. So to start the actual, data in-place assimilation process, what I'm gonna do is I'm gonna create an empty share called Collections.
So within our UI, just gonna type in the name of it. Then I'm gonna go ahead and set a snapshot schedule on this as well. The reason why I'm doing this is 'cause we're gonna talk a little bit more about snapshots later on in this demo.
Once the, share is created, I'm gonna go ahead and, and add a storage system. Gonna call it Images, and we're just gonna add a simple description of what it is. I'm gonna pause real fast and talk about our a-API interoperability, to third-party storage solutions.
Really the-- what makes it really efficient is that a Hammerspace file can live on multiple third-party storage platforms. But when it does live on a particular platform, we wanna take advantage of its, snapshotting and clone efficiencies, for its copy-on-write. Uh, so what we have is deep API integrations into that storage to allow us to gain that storage efficiency regardless of where it lives.
Chad, Jack Pauller with, Paradigm Technica. So a couple questions on that. You're talking about, when you say copy-on-write and third-party storage, are you talking about...
And you talked about a Hammerspace file. First, define what you mean by Hammerspace file versus the native files. Sure.
Yeah. So Hammerspace writes its files out in what's called a clone structured file system. Mm-hmm.
Okay? That file system itself is basically our structure that we understand, but the third-party storage system may not necessarily understand. Even though it may reside, let's say, on a, a PowerScale- Mm-hmm ...
it is our clone structured file system on it. Now, what we wanna do is we wanna get the efficiencies out of that third-party storage. Right.
Right? We wanna use its, sta- space efficiencies and copy-on-write. Okay.
So when you're talking about the, the, the copyright snapshots, clone efficiencies, you're talking about leveraging the third-party- Yes ... storage system's native capability. That's right.
Okay. Yes. But you gotta understand, our files can live on multiple storage systems.
Right. Each one will use its third-party integration to manage these, the storage efficiencies beneath the file system itself. Right.
And then when you're talking about Hammer space files- Mm-hmm ... that means that, if I understand you correctly, when a user is interfacing through the u- the, the Hammer space's global namespace- Yes ... that user can see the existing files, but if they say they're going to create a new file, right, it's going to be a Hammer space file that's then stored in some underlying storage that may be a third party.
Yes. Right? But it may ...
That, that new file isn't necessarily native to the or- the ... It wouldn't reside, let's say, on your PowerScale as a file native ... As a- Yes ...
side by side with the existing. Correct. Right?
Yes. Okay. That's correct.
Yeah. So, that's what we refer to as data placement simulation. Mm-hmm.
We're not gonna move the files or modify the files until it's re- it's a modification or a creation or whatever happens. After the initial assimilation- Mm-hmm ... then we'll change the, the file structure to a Hammer space specific structure.
You still go through our virtual file system to access the file- Right ... 'cause we're tracking all those changes. Mm-hmm.
You would never go back through your Isilon once you assimilate it. That's what I was going to go to next. Yes.
So, so once you start using Hammer space, you essentially lose the access to, through the native interface- Yes ... to that file. Yes.
Okay. Yes. Uh, we do have a process called de-assimilation, which puts everything back.
Gotcha. Mm. Thank you.
Mm-hmm. All right. Let's continue with the, demonstration here.
So I'm just showing all the various products that we support. In this particular demonstration now, I'm using a Manila, NFS server. Just adding the IP address of it.
Uh, we're scanning all the available volumes on our system. To us, a volume is a mount, right? So that's an interchangeable term with Hammer space.
But we do see a volume on the server called, Images that resides in the Mount Images directory on that server. Continue the presentation here. I'm just gonna select that volume.
Hit Next Steps. Now, it's important, I'm sl- I'm selecting the Assimilate button. I ha- I went through that pretty fast.
Let me go ahead and pause that again. But the Assimilate, the Assimilate button, allows us to use the existing storage. We're not gonna re-silver that share and use it for s- new, net new storage.
We're gonna use the existing storage that resides under all the files, the directories, and we're gonna go data in place assimilate that. That's, by checking that box, allows you to do that. And what would happen if you didn't check that box?
It would re-silver it. It would, it would clean it out, and it would just use it as a storage bucket, in essence. And delete all the data.
It would delete all the data. Okay. Yeah.
You're not assimilating. You're just using that space to put more files into it. I see.
Can I, can I jump in with that? That's, uh ... Maybe, maybe you're gonna cover it later, but- Mm-hmm ...
how does it work with ... By the way, Brett Walrent. Yeah.
Uh, this is also to Jack's question, I think you answered. Maybe I misunderstood it, but is it a bit ... Some of these flows almost seem like one-way flows.
No, they're bi-directional, for sure. Okay. A- and what I mean is, o- one-way streets in a sense.
Like, if you assimilate to Hammer space, you then need to tell everyone, "Stop writing directly- Yes ... " Is that ... Am I- Yeah, yeah.
And we have ... Because basically, what, what we're gonna do is you're gonna do a one-time remapping of your data. Happens once.
So you're going to your previous, PowerScale storage. Now you're basically gonna tell your, your users or you're gonna remap to a, a, another drive. Then you're gonna continue on.
Uh, and that's, that's your ... That, that is your, your outage window in theory is that one-time mapping over. Everything else, as data migrates and moves between multiple systems ...
I mean, a lot of people use Hammer space as a migration tool, right? I'm gonna go off a NetApp, and I'm gonna go to an Isilon. Yeah.
Well, I can now do this assimilation- Ah, I see ... and everything seamlessly moving behind the scenes, and the users don't know from one day to the next, is my data actually residing on NetApp, or is it residing on an Isilon? All happens kind of behind the scenes.
So it- Once you've added that virtualization layer- Mm-hmm ... of the namespace, that all just is part of the solution. So rather than it being an extended long outage- Yes ...
for the migration, what we're essentially saying is is you're gonna have a 30-second remap to a new drive, and then from then on, the migration's just happening transparently and- Exactly, yes. Okay. Interesting.
What about availability in those cases then? What kind of solutions do you have for that? Uh, we'll get to that.
Okay. But you're using the, durability and availability that's already existing in the Isilon- Yeah, sure ... or the, the NetApp.
Yeah, that's on the back end. Like- Yeah ... you can show the front end where you're presenting namespaces, right?
Yeah. So our, our namespace is all virtualized. Okay.
And it really depends on ... The devil's in the detail. It really depends on what protocol you're using.
2, that's all built into the metadata layer that's being presented by the Anvil servers. And we have this notion called a flex file, and a flex file hands out a layout-And that's the directions to where the file's at. And it really kind of gets into the minutiae or the, the details of the solution.
But any other protocol that you're using, NFS v3, SMB, CSI Driver, and S3, that goes directly to our DSX server. And then that handles any legacy, protocols, what we call legacy protocols, and then that's distributed across multiple DSXs with their own virtual IP for each one. So that is how you maintain your high durability across legacy protocols as well.
Okay. So I'm just walking through the rest of the add volumes installation wizard here. Okay.
And in a moment, we will see it show up. There it is. Now, what we're gonna do is we're gonna go back to that empty directory that we had previously created, and now what's happening behind the scenes is this data in-place assimilation process.
It's running in the background right now. It's walking the file system. It's collecting all the metadata itself.
It's not moving the data, it's just collecting the metadata. It does take a couple minutes to happen. This is running on a couple instances in the cloud, so it's not the fastest thing.
But as you can see, we're already discovering directories, right? We, we can go inside a directory, and lo and behold, you can actually now see the files, right? So there's all my files.
Uh, it's updating right now, and as you can see, just finished with 14th, 14K files it just discovered on this system. Right? What we're gonna do real fast is we're gonna go ahead and check it.
Can I have access to that? And the interesting thing to note, too, this is an NFS server accessing through SMB. So there's your bimodal multiprotocol access out of the box, NFS server connecting via SMB.
Right? And that's what we're gonna verify and check, can we have access to these files? So I'm quickly going into the directory.
I'm looking at one of the directories, and there's a file. That's a permissions issue from, an earlier lab. But now I can go into this one, click on the file, and there it is.
I can see the image. So now I can access this assimilated storage, from an SMB share. Now, the next thing I'm gonna do- I have a question- Yes ...
regarding permissions- Yeah ... that belavance. Uh, so I probably have permissions defined on the file system that exists- Yeah ...
on target storage. Yes. How is, how are those permissions assimilated by Hammerspace?
They are assimilated. Okay. I guess that's the que- That's my big thing ...
that, that, that, that's the SE answer ... mess with those permissions. Yeah, no.
All, everything gets, everything gets migrated over. You know, all your, all your, your, your file permissions gets carried over. Um, we have an RC2307 mapping that happens, that will map SMB permissions to NFS permissions.
And it just... I can't really go into too much details about it right now, but it just, rest assured that it does get migrated over. Going forward, as I start using Hammerspace- Mm-hmm ...
to manage that portion of my file system, do the permissions get written back to that storage device? So if, if someone- No ... wanted to make an end run around- Yes ...
Hammerspace to that Isilon- Yes ... would the- Well, they wouldn't even see the files because we're also laying our cone structured file system across the files. Every file becomes a UUID- Mm ...
and within that UUID becomes a payload of file that's in a chunked format. Okay. So even if they did directly- Yes ...
to the storage device and tried to enumerate files- Yes ... they wouldn't have permission- They would have a, a very difficult time trying to figure it out Okay. So really- Yes ...
at that point, the only way to get to the files is through- Yes ... Hammerspace interface, and that's what is- Yes. Yeah ...
enforcing permissions and access control. That's correct, yes. Awesome.
All right, thank you. But to be clear, that rewriting of the file into the new cone file system, that only happens when the file's changed. Modified or written or changed, yeah.
Well, because that's data in place assimilation. Now, you can set, you could set a, a read-only policy where you, keep your file in place, read, and then set an objective, which we haven't really talked about, but those are the rules for data movement, to put it in another location, in another volume. So our professional services team generally will make an as- a, a assimilated share read-only, and then with, on that same storage system, make a new mount where all the new data gets dropped into.
I see. Okay. So there's different ways that you can address this.
It really depends on the customer's use cases and situation. Okay. So the next thing I'm going to do righ- right now is I'm going to prepare this on-prem cluster for the cloud, and this is the beginning process of setting up the global file system between two sites.
The way that we do that is we use a bucket in the middle or an object storage in the middle to facilitate that transfer of the data. So in this next demo is just me walking through adding a s- another storage system, but this time we're gonna be connecting to, some S3 object storage in US West One in this example. This is a little bit of a laborious prod- process.
I, I do apologize. It, it does take a little bit of time. Uh, but just basically drop it in your access key and security keyUh, we'll give you, you'll give you visibility to all the available buckets, and then what we'll do is we'll pick a particular bucket to use as our, as our target.
Sorry to interrupt you again. Uh-huh. Um.
Go ahead. That screen gives me the willies. Is there any other o- option besides an access key, like a role?
Uh, yes, I believe there is, yes. Okay. Um- Access keys, no good.
Yep. Yeah, yeah. Why not?
You- I think we have, like, access tokens and stuff, I, I believe. Okay. For this demonstration, you're walking us through the user interface.
Yes. Makes sense. Can this all be done programmatically as well?
Yes. It can. Okay.
Yeah, yeah. So we have, uh... Let me pause this real fast.
We have, the HSCLI, and then we have the HSTK, which one is a command line utility, then the other one is a toolkit, a- and it can be a Python toolkit. Uh, and then ultimately, if you're really good, we have a REST, a REST interface as well. Okay.
How about a Terraform provider? Right. Oh, we have all that.
Yeah, so we'll, we'll get to cloud in a second. Okay. But we support every, every, every template imaginable.
Okay. So just continuing on here. Oops, I hope I, didn't mess anything up here.
Uh, so that actually concludes our first demo. So what did we do? We assimilated some, some third-party storage.
In this example, just a Linux server. And then we, made sure that it's accessible by SMB. And then we set up, an S3 bucket that can be an archive and DR disaster recovery bucket if you wish, but we're also using it as a means to replicate between sites.
Okay. So the second demo is we're gonna go ahead and deploy in cloud, and then we're gonna finish setting up the global file system. We're gonna quickly discuss, the Hammer space deployment options, and then we're going to, enable and finish the global file system between sites.
Uh, and then we're gonna understand the behavior of a default, global file system, system, excuse me, where on, out of the box it's a pool on demand, but we want to apply objectives to proactively keep files local at each site. Okay. So let's jump into the second demo.
All right, so what I'm showing right now is I'm showing, AWS, and that is a Terraform... not Terraform, the CloudFormation tool that's built into Marketplace. Um, so of the, of the major clouds, we support or we have Marketplace listings, and they're generally a BYOL or a metered offering.
So you really have your choice of how you wanna consume Hammer space in the cloud. Now, I won't bore you with all the details of the fields that you have to fill out in a, in a CFT, but what I will do is I'll assume that we're familiar with that and cut directly to it running. So here we are right now.
This is, this is a deployment running in AWS. It just stood up. I just...
All I'm doing is taking the IP address of the Anvil server, throwing it into our browser, and logging onto the system. See, we have the same dashboard. Uh, you can see that the site's slightly different right here.
So you can see the location is now in, is in San Francisco Bay Area, while the other one was in, Ohio, for example. Uh, so shows you it's a different cluster. And then all we're gonna do at this point is we're just gonna go configure that bucket, and it's the same bucket that we had configured in the on-premise cluster.
So you're accessing the same bucket. This is what facilitates our global file system between the two sites. Does take a little bit of time.
Does anybody have any questions while we're- I just have a- Uh-huh ... pretty, pretty basic, just a fundamental question. I suppose, the, the UI, the, is pretty nice, of course.
Um, I suppose you have a, a, at least one API to drive this if- Yeah. Oh, yeah ... necessary?
Yeah, yeah. This is all API-driven. Um- So- I'll...
We have- If I right-click Inspect, I'll just see the- Yeah ... API calls, or do you have a spec that can be downloaded and- Yeah, we have a spec. We have, we actually have, a HSTK, API toolkit that can be downloaded.
Then, of course, we have the HSCLI, which is, you know, scriptable, command line language too. Oh, that's... Yeah.
Now we're getting to the whole agents using CLI sort of- Yeah ... MCP service debate. Okay, thank you.
Yeah, yeah. There will be some announcements, in the next week about that, that very topic. Another, another question.
Sharla here. Um, you mentioned earlier, you know, what we were looking at was, I believe maybe 14,000 files, so I was just kind of curious, what about if it's like a really large data set? Yes.
Like, what's that timeline look like? Well, it's a formula, and it really is based on the amount of resources that are in the Anvil. Uh, the Anvil that we use in this demonstration is an Amazon EC2 instance that I'm running in a lab.
I think it's an M2, 2xl large, right? So it's not a representation of what a production environment would be. Yeah.
And it's, you know, it's more like a, you know, a million files per hour or something like that. What- what- whatever that- that is because that's the, our production environment. Right.
So it's gonna be far different than what I'm showing you in this demonstration. Okay. And then what about...
So, does the system, like, perform a full file system crawl, or can you ingest metadata, you know, lazily as files are accessed? It does it... It...
Well, it's really interesting, and that's a great point that you brought that up. Um, I didn't really go into the details of it, but if you can imagine a file system with a billion files in it, right? And it's a live file system.
As you're scanning it, you have users accessing it. Mm-hmm. " So you can go to a very specific sub-directory within your file system, and it will scan on demand and assimilate that and bring it in because a user is requesting access- Yeah ...
to that specific section within a file system. So we can, we can, pr- we'll- we'll scan, the directory, you know, parent, child, and sub-directory on down, or we can do it on demand. Okay.
Yeah, y- I just thinking in my head because I deal a lot with data migration- Sure ... and so our goal post is forever moving- ... as you're trying to get them migrated, so.
Yes. Yes. Yeah, and again, a lot of people, find, the intrinsic benefit of Hammer space is just for storage migrations, right?
It's an added benefit. That's something they get for free is this ability to make this seamless. Nice.
Okay. Oh, so let you guys know what's going on here. Um, so we created the bucket of the remote site, and now I'm gonna go log into my original on-premise cluster.
It is the owner of the collections share, and I'm going to give the remote site permissions to participate in a global file system. So that's what I'm doing real fast. Log back into the on-premise cluster.
I'm gonna go to the collections share. I'm gonna go in the Edit tab, and now this time I'm going to the File Systems tab and I'm adding a participant. Let me pause this real fast and tell you what's happening in the background.
When we share a bucket as a replication target, there's a reservations file that gets created. And inside that reservations file, any participating site will add its login credentials. It will add the name of the cluster and the IP address for it to connect to.
So when you have another cluster connecting, it's gonna have a list of all the participants already pre-populated. So all you have to do is select it because it's all in that file itself. It's an encrypted file.
But imagine having up to 16 sites participating at the same share at the same time. You wanna have that list pre-populated for you. That's exactly what we're showing right now, in the GUI.
So typing in the, the- the username and password of the remote cluster, testing the connection, then adding it to the global file system. So now the collections share is a global resource between sites. It's that simple.
So what we're gonna do now is we're gonna go back to the- the Anvil in the cloud, and we're gonna go look at the collections share, and we can actually see all the files available at the remote site. Just like that, they're all available. So now you can actually see them.
You can see all the metadata associated with it. Quick- Quick ... quick...
Oh, sorry. No, go ahead. It may be a silly question, but I'm going to ask it anyway- Sure ...
because I love doing it. Um- ... it would be kinda cool possibly for the audience to clarify, we keep hearing the term Anvil, like maybe- Oh, okay.
S- I do apologize. So Anvil is our metadata server. And then what we have is a DSX server, a data- data services node.
Um, and at a real high level, the Anvil server, it just, is just there to, collect and maintain the metadata about the server. 2. Uh, the DSX servers has several roles and functionalities.
2 it serves on the DSX. It also is the data mover. So when you set an objective to move data, it is the engine that move, physically moves the data from one storage platform to another behind the scenes and makes it all seamless.
It also, another role that it has, is responsible for, moving files to object storage. We call that the, the cloud mover. Okay.
Its job is to take files, chunk it, encrypt it, move it up to an ob- an, an object storage. And then on the other side, bring it back down, un-encrypt it, and then we typically will apply encryption, in- compression on it. So it's also de- decompressing the file and making it available on the DSX as well.
So those are the major roles of a DSX. 2Uh, does that answer your question? Yes.
Thank you. Okay. Thanks.
Okay. So just to kind of catch ourselves back up to speed here, boy, I'm really running out of time. Um, I'm going to, try to connect, to SMB in a remote site.
Oops, sorry. And just got a map to it. It's really important that we have Active Directory integration on both sites right now, so we-- they understand the SIDs and the layouts between sites.
dom. Uh, if you didn't, you wouldn't-- you would instantly get permissions issues, right? So we're gonna log in real fast.
We're gonna verify that it's working. And quickly, what I'm going to do is I'm going to pause this again and talk about why it's taking a while to load this file. Because all we did between the two sites right now is we just replicated the metadata, right?
So what this file is actually doing right now is it's going across all the way to the assimilated storage. It's grabbing that file, it's moving it across the DSX out to a bucket, back to a DSX, back to the SMB share. It's doing this on demand because we've set no policy on how to cache the data and where to cache the data.
So yes, it's gonna take a while to do because we're going across the wire each time to pull this file. Now, what we do behind the scenes is we'll cache this a, a, on, on the... in the RAM on the DSX for five minutes.
If the file isn't touched or not modified after a five-minute period, we'll, we'll evict that cache, and we'll move it back. And then if you touch it again ten minutes later, you gotta go through the whole process again. But we do have this concept called objectives, what we'll talk about later on, that removes that need to have the wait for the file to be pulled across each time.
All righty. So there's the file, and I believe that pretty much concludes the second demonstration. Okay.
So I'm gonna pause real fast, and I'm gonna start the second part of the, the demonstration now. Hello, everybody. My name is, Chad Smith.
I'm a cloud CTO at... She's... Hey, Chad Smith.
I'm a field CTO at Hammerspace. I'm responsible for alliances. It's been a long day already.
Um, I previously, showed two demos of Hammerspace, on-prem, assimilating some third-party storage, and then, setting up a global file system to transfer files to a second site that lives in the cloud. Now we're gonna continue that conversation and add on this new concept we like to talk about, which is called Tier Zero. So let me bring my...
bring it back up here. Make sure I just re-share my screen. I don't know what happened.
I do apologize. Hopefully, I can make this work. All right.
All right. And I'll put this in presentation mode. Uh, go jump to this slide.
That work? No, it did not work. I apologize, guys.
I don't know why this is... Share. All right.
Third time's a charm. All right, let me get to the next one here. Okay.
So this is where it gets exciting, right? Um, so what I like to describe Tier Zero as local performance with the utility of a file system. So we're gonna discuss Tier Zero installation dependencies on GPU nodes, how the NVMEs are mapped to the NFS mounts versus mounted shares on the client.
Uh, we're gonna set up Hammerspace storage, volumes, and this concept called volume groups and how high availability zones, ensure data protection in this model. We're gonna review, data placement policies that affect the creation, modification of files when a durability or availability objective is applied. 2 client-side mirroring works.
Okay, so before I jump into the demo, let's talk about what it takes to prepare the, the Tier Zero nodes, or this would be your AI nodes, your GPU nodes. This would be the, the use case. There is a little bit of installation that needs to be done on these nodes, but it's not like you're, you're a kernel-level driver you have to compile for.
It is really simple stuff. Uh, it can get complicated, depending on the environment, 'cause you got, you got NUMA zones, and you got all kinds of com-com-complexities on, on larger environments. But in this demo, we're just gonna, we're gonna keep it really simple.
And really when I mean simple, it's simple. Basically, you're creating a directory, which is gonna be a mount point. You're gonna drop an, an NVMe in it, and then you're gonna mount that NVMe to a share, and then you're going to then map your NV-- your Tier Zero client to that mount that we had created earlier called Collections on the Hammerspace system.
We're gonna tie each NVMe to a mount, and then we're going to, tie it all together by mounting my client to the Hammer space. And a little switcher-- Oh, and then also wanted to discuss too this notion of availability zones. So by definition, an availability zone is a fault-tolerant...
is a fault domain. And what we consider a fault domain in this use case is the instance itself and its underlying storage associated with it. And what we do is when we write out files using our client-side mirroring, which is a synchronous write across multiple zones, we want to ensure that we're not writing two mirrored copies to the same node.
By, by dictating what an AZ is, our product ensures that it's not being written to the same, the same node twice, right? Defeats the purpose of client-side mirroring if you're writing to the, the, the same drives on the same nodes, right? So that's what an AZ, avoids.
And of course, to make this all work, it's a place on. It's another objective that I'll get into in a little bit, and we're gonna assign it to the collections share. It'll be much clearer in a second, trust me.
All right, so another demo here. Just like before, when we assimilated that third-party storage, we basically walk through the same process. We're gonna take a storage system, and this time the storage system is an individual GPU node.
Um, and then what we're going to do is we're going to, assimilate it with, NFS other again, and we're just gonna type in its IP address. Same step as the previous one. Uh, we have lots of scripts that can automate this.
Imagine having a hundred GPU nodes. You don't wanna do this individually, so we have ways of streamlining this process. But we just discovered two volumes on this system, and what we're gonna do is we're gonna append the name with the availability zone that I mentioned earlier, right?
By just appending AZ one to it, we're telling Hammer space that this is an availability zone and these two volumes are, in that availability zone. I'm just changing the notification thresholds about the usable space and capacity. Um, you really don't have to worry about that too much with Tier Zero.
And then I'm just gonna skip to performance test for part of this, demonstration. I know they were not gonna get to it. So I just repeated the process for all five nodes.
And then you can see that all ten volumes are available as well. So the next thing I'm gonna do is I'm gonna create a volume group, and this volume group is gonna be all AZs. And a simple description.
Not so simple, actually. Let me see. Fast-forward this thing a little bit here.
All right. So I finished that. I created the volume group.
Now what I'm gonna do is I'm going to associate all volumes I've created with this volume group. What we are doing is we're creating a distribution map to map all the available volumes to this group. And then all we do to make this thing work is just assign this newly created volume group to the share itself.
So I go into the objectives. I'm gonna add an objective. We're gonna use one called a place on, and I'm going to place on this AZ and apply.
And then what's gonna happen is you're gonna see a flurry of activity. 'Cause what we're doing right now is we're moving all the data that was sitting on that assimilated storage all the way across to the, all of these, Tier Zero nodes now. So yes, go ahead.
Um, are you moving or copying or freezing and moving or? We are copying- Okay. -the, the data over.
Okay. Uh, but the concept of Hammer space, we don't ever like to use the word copies because from a physical standpoint, it's a copy, but from a metadata standpoint, it's a single instance of it. We call that instantiation.
Okay. So it ever only is a single metadata copy, but it can physically live at multiple spots. Okay.
Thank you. So yes, we are copying the data over.