Techstrong TV March 31, 2026
Code Validation: The Next AI Bottleneck
Faster AI code generation is shifting the constraint to validation
Critical challenge in testing complex, cloud-native systems at scale
Enabling developers and agents to validate production safely and rapidly
Featuring Arjun Iyer, CEO of Signadot
The AI Security Blind Spot: Vector Databases
Vector databases emerging as a high-risk, plaintext data exposure point
Centralized embeddings creating prime targets for data breaches
Cryptographic indexing as a new approach to securing RAG pipelines
Featuring Nicolas Dupont, CEO of Cyborg
Defending the C-Suite in the Age of Deepfakes
Executive threat surface now extends beyond corporate networks
AI-driven impersonation attacks targeting leaders and families
Concierge SOC and real-time protections to mitigate risk
Featuring Chris Pierson, CEO of BlackCloak
Why Kubernetes Still Needs VMs
Bare-metal Kubernetes complexity driving renewed VM adoption
VMware Cloud Foundation enabling secure, scalable AI infrastructure
Dynamic GPU allocation and cost control for modern workloads
Insights from Weigue He (Broadcom)
AI Security & Governance at Scale
Securing agentic apps with Power Platform governance capabilities
Managed environments, adaptive risk models, and lifecycle controls
Balancing rapid innovation with compliance requirements
Featuring Ryan Jones (Microsoft) and Fernando Montenegro
Power to the People: AI as a Force Multiplier
AI augmenting—not replacing—consultants and knowledge workers
“Strategy capsules” and practical enterprise AI adoption insights
Focus on human judgment, creativity, and prompt design
Featuring Warren Cain (CEO AI Pro) with Dave Nicholson
Transcript
Hey everyone. Welcome back here to Techstrong TV. My next guest is Arjun Iyer.
I hope I pronounced-- I think I pronounced it right. Arjun is the CEO of Signadot. And don't worry, we're going to tell you about Signadot if you're not familiar.
But first, let's have Arjun tell us a little bit about himself. Hi, Arjun. How are you?
Pretty good, Alan. It's a pleasure to be here. And thank you for this opportunity of introducing myself and sharing my story.
You know what? Thank you for sharing, right? Not everyone shares.
So Arjun, I mentioned you're the CEO of Signadot, but as I said, we want to hear a little bit about your journey to becoming the CEO. So why don't you share with our audience your journey? Absolutely.
I've been the CEO and founder of Signadot for the past couple of years. And before that, I was at AppDynamics- Sure ... which was a big name in the cloud native observability space.
And I ran a few engineering teams there, which had one of the fastest growth paths within AppDynamics. And then we eventually sold to Cisco, which was one of the biggest acquisitions at that time. Prior to AppDynamics, I've been in various startups, all related to cloud native and more infrastructure oriented.
So my passions lie in large scale systems, distributed systems, machine learning. That's what I've been doing since I was in college. I went to college in University of Illinois at Urbana Champaign.
Oh, sure. And my thesis was in distributed systems. So that's where I started.
That was my passion right from the beginning. And so my career has sort of followed that line of being inquisitive about how systems scale, how do they break down at scale, how do we design systems to be resilient and performant and highly scalable. So that's kind of been my journey, which led me eventually to AppDynamics.
And based on what I learned at AppDynamics is the result of Signadot, right? That's kind of why Signadot was born, because I've experienced challenges that developers face when building these scalable, highly resilient cloud native systems. And so that led to the birth of Signadot, and I'm happy to share more about that as well.
Love it. Arjun, it's funny. com.
And AppDynamics, of course, was the very first sponsor- Oh, great ... com back in the day. So Jyoti- Yeah ...
and Steve, their marketing guy. Steve, I forget Steve's last name. He was the CMO there.
But we didn't call it, of course, observability back then- Yeah ... right? Yeah.
It was APM. But yeah- That's true ... what a great company.
What a great story that was. Look, I founded four or five companies in my lifetime. Venture backed three or four of them.
And I've interviewed literally hundreds, if not thousands, of founders. There's patterns that you see, things that you see. Number one, the passion for what it is they're doing, it was what drove them to found the company.
They had to be passionate about it. Number two, oftentimes they saw a problem that they themselves were suffering from, right? They saw this in their last job.
There was this issue that I just needed to solve. And then they realized that other people needed that problem solved as well. And so that's why they do it.
Other times, especially with serial entrepreneurs, they go out there and look for big problems- Mm-hmm ... and say, "You know what? " Jody, Jody Panzarl from AppDynamics, and now of course Harness and all the other ones.
That's what Jody does. I've asked, I've talked to him about this. Talk to me about what drove you for Signadot.
Where was your passion? What was driving you? Yeah.
No, that's a key question. And my background is in developing, right? So I am a developer by trade.
And I used to manage a large team at AppDynamics, and this is something that really bothered me, where we transitioned to being completely cloud native back in AppDynamics. We started a little bit differently, but eventually shifted to cloud native. And what I realized was, the development workflow, the development life cycle for developers was not as smooth, right?
They were wasting too much time on things that didn't matter or that could be done differently in a much more efficient way, right? So the whole software development life cycle, from the time you write code, all the way to you ship something to production, and how do you debug production, and how do you keep the system scalable, and safe, and resilient, had a lot of friction points, right? And that is really the genesis of-- I'm very passionate about giving developers the freedom to experiment and to be very creative.
That's really my passion. And I felt like-Developers were not given the opportunity to be creative because they were sucked into all these things that were just what I would call is chores, right? Not really creative work.
And that's really led me to Signidot, where the mission of the company is to actually give developers the ability to be free and to experiment and be creative, and especially the developing production grade cloud-native software. That's kind of the real mission. And I'm happy to go into the specific problems, but at a high level, that was really that drove me to found Signidot.
So when did you found Signidot? This was about four years ago, that was when this was found. And we raised a seed round of funding at that point.
And now we have quite big logos of companies that are using it at scale. Some of them being names like DoorDash, Brex, Wealthsimple, Bitso, and other companies that use our software to really give their developers a very high-quality developer experience. And so that's kind of the genesis and sort of the reason we found the company.
And yeah, that's our flag. That's been our journey so far. And last year we had the biggest growth in the company's history.
And so this year, that growth is accelerating even more because of the agentic sort of disruption that all of us are dealing with right now. Got it. You mentioned it, so that horse is out of the barn, right?
Four years ago, you didn't think you'd be here talking about what the role of agentic AI is going to have in your software development life cycle. But certainly, here we are, right? And I guess we should jump into it.
It's hard to ignore that big elephant sitting in the corner of the room. How is it affecting what you see in the SDLC, and how's Signidot changing its whole business as a result of this? Yeah.
The birth or the advent of large language models and everything around it has been one of those completely disruptive technologies that very few of these I've witnessed in my career, but this is one, probably the biggest one. And so because this kind of fundamentally changes software development. Right now, these LLMs are so good at writing code that it begs the question, okay, what is the impact?
What are the roles of software developers going forward, and how can we work well with these tools, right? That's going to be the main thing. When creating code is not the biggest bottleneck anymore, because these tools do a fantastic job of creating code.
But everything after that, how do you validate that code? How do you verify that it really works, especially in a complex cloud-native system is where the bottleneck has moved to, right? And that's exactly where we are positioned very well to sort of attack that problem.
And it's exceptionally hard, especially for cloud-native systems. For smaller applications, it's less of a problem. But when you have these distributed cloud-native applications with lot of dependencies and lot of components, just changing one part of the system, even though it's LLMs and all these tools doing it, it becomes extremely hard for these tools to completely validate and verify the system on their own, right?
So that's something that they cannot do that well today. And so that's where the solutions like Signidot make it very easy for both developers and these agentic coding tools, to be able to verify and validate the software at the speed of generation. So that's kind of where we really are plugged in with these tools is like if you're using Cloud Code or Cursor or Codex or any of these coding tools, they need a way to verify what they've produced.
And without that verification signal and the feedback loop to these tools, they're just code generation machines, right? They're not really shipping software to production. So that's a very big gap that's there in the market today, and that's kind of where Signidot comes in, especially in the context of cloud-native solutions, cloud-native software.
Absolutely. And talking about ephemeral environments, right? When I always hear that term, I immediately think Containers, Docker, right?
Yeah. The average lifespan and that about ephemeral. I'm wondering, so in one respect, look, what better way to keep up with the ephemeral nature of cloud-native installs than with AI that could run at that speed?
Mm-hmm. Right? But does it present a human problem?
Because what happens is the AI can run so fast. The cloud-native infrastructure spinning up and down, the ephemeral aspect of it can run just as fast. So now these two things are running so fast, how is a human-- And we want the human in the loop, I assume.
We want human oversight still. How is a human to keep up with these two? Yeah.
No, that's the question of the century, I would say. Because it's going to be a huge topic of discussion, and I just wrote a big blog post on this saying, these tools produce code, but they don't do software engineering. Right?
No. So software engineering is much more than writing code, and that's sort of what people miss when they jump to the conclusion that, oh, these write code, so we don't need that many software engineers. That's a pretty big misconception and a misstep.
You need even more software engineers because you need to understand how to design the system, how to architect it, what even to build, what not to build. Right? And that requires a multidimensional thinking and strategy that only a developer brings to the table.
These LLMs are not good at that. They are good at following instructions, and they are great token prediction machines, and obviously, when they generalize to a large number of the training data that they have, they can do an excellent job of producing really good code. But they need to be given the proper context, the proper instructions, and there has to be a human that's overseeing the overall development process.
So that cannot be outsourced to these LLMs. And you could argue that LLMs are getting smarter, so very soon they'll be smart enough to do even that. But that's sort of yet to be proven.
That's very far out there, and so far, the evidence that I have seen is even simple tasks like write me an email, they don't do a very good job. I can write a good personalized email much better than LLMs, which tells me that they're far short of doing everything that a human can. So I think developers play a very vital role in that they own the overall strategy, and they own the overall design and decision making.
I think the decision making always will lie back and fall back on the developer because it's such a multidimensional problem. It's not just why the code is failing or why I need to ship this feature versus that. It requires so much input and so much context that only a human brain can process and analyze, that it's very hard to relegate those kind of things to these LLM tools.
So I think it's very early, but it's going to be a kind of a partnership that developers and other humans and other personas have with these tools that just amplifies the productivity of that human. But the human plays a very significant role in decision making and strategic thinking. Yeah.
I've had these discussions with my own employees here at Techstrong because we're using agents a lot now. Yeah. We've been using a generative AI, and I agree with a lot of what you said.
I think there's always going to be that human in the loop, and there's always, I call it the spark. The spark of creativity- Yeah ... is something that these machines are lacking.
Truth be told, I've trained, I've developed personas that they write in. It writes a beautiful email in my voice. Yeah.
It writes nice articles in my voice. Yeah. I should say it crafts articles that I've written.
It smooths them. But I think there are some things that it's just not meant for, and one of those is that spark. Exactly.
As they call it. It's seeing the, wow, if I did this, I could do that. And then saying, "Okay.
" Yeah. But I'm the one who saw and thought of it. You know where I see it most?
When I have it do graphic concepts. It'll come up with some concepts that are great, but it doesn't see the concepts that I see. It's the creativity.
Anyway, Arjun, did we mention the website? I don't think we did. Yeah.
com. That's kind of our homepage and our website. We have very detailed technical documentation also linked from that website.
So I would encourage anybody that's interested to go check it out. Absolutely. Yeah.
Arjun, I want to thank you for coming here on Techstrong TV today. It's been great hearing your story. I always like to meet AppDynamics people.
Great hearing what's going on with SignaDot. Come on and keep us posted. Absolutely, Alan.
Thanks so much for inviting me, and it was a pleasure. All righty. Arjun Iyer, CEO of SignaDot, here on Techstrong TV.
We'll take a break. We'll be right back. Hi.
It's John Swartz at RSAC again, with Nico Dupont, who's the founder of Cyborg. Welcome, Nico. Hi.
Thanks for having me. Great having you. Day one of the show.
Well, you just didn't get here. You're from the East Coast. You went to a show last week down the road in San Jose, GTC.
Yeah. I actually want to ask you about that. Well, we'll talk about RSAC plenty, but what were your impressions of that show?
It was insane It takes over the whole city of San Jose, as you know. We were exhibiting there Monday through Thursday, and it's really the epicenter of AI and kind of the pulse check on where the industry's going. So it was very interesting.
It's kind of the polar opposite of RSA, where security very rarely gets talked about at GTC. Yes. And this is all about security.
It's always interesting one comes after the other, and it almost kind of in the way it plays out in real life where you evolve all these advancements in- Mm-hmm ... AI, cloud, whatever. And then there are the consequences on the security side, so that comes later.
Yeah, it's a secondary whiplash, for sure. Yeah, absolutely. And I was going to ask you about RSAC.
Just a couple things, and then we're going to go deeper into your company and what it does, because I think it's really important what you're doing, and I want you to spell it out for us because we might have some folks out there who are unfamiliar with your company. But RSAC, it's interesting in that it's become almost a little bit of a political bent. There was definitely last year what went on with CISA, and I think the current climate of our security framework.
But I'm wondering what you anticipate coming out of this show, or what type of themes most interest you going into the show. What would you like to learn more about or hear more about here? Oh, that's a good question.
I think we're seeing a lot of AI for security, in the broad sense of the word, and I think that I haven't gotten a chance to walk the expo floor. It opens at 5:00 today, but I anticipate we'll see a lot of that like we did last year, probably even more so. I'm actually more interested in the other side, which is security for AI.
Which is how do you secure model behavior by all means, but how do you secure AI infrastructure? The kind of boring meat and potatoes of the next attack vectors that we'll see in the enterprise. Right.
I'm so glad you mentioned that because we do a show every day, usually live, Techstrong Gang, and that is a constant theme, this idea that this technology's moving so fast, we see a refreshing of models every month from each company. We hear so much about agentic and autonomous workforces. We hear so much from the top down about how this needs to be put into use.
But security is... It's not given short shrift, but it's mentioned down the list of importance like it always has been. Yet there's that lingering thought in the back of everyone's mind, when is something going to happen that we have- Yeah ...
to explain? And is that- The underlying anxiety ... do you hope they acknowledge this here?
Yeah. I'm sure they'll talk about it. I'm sure they will.
We're at the RSA Conference, so there's going to be talk about it. And I'm biased because that's where we're focused on. The underlying risks from the centralization of data for AI and what that implicates in the enterprise and downstream everywhere.
And so it's always interesting to see how everybody else is thinking about it and who else is trying to solve the problem. Right. You've mentioned AI infrastructure, and it was very well put.
I think it may have been from your company. I'm not sure where it came from, but basically said AI infrastructure is harboring a hidden security risk, which is the vector database. Could you maybe expand on that a little bit?
Sure. And I know it plays into what your product does, among other things. Yeah, totally.
So, maybe I can set the lay of land a little bit. Sure, absolutely. Over the past call it three years, we've seen a massive shift in the center of gravity in AI from training, who had the biggest GPU clusters, was able to build model frontier capabilities, to inference.
You go to any AI conference today, it's all about inference. Inference speeds- GTC was a lot about inference ... it's all about inference because that's where you get ROI from your massive AI investments.
And the way that you drive value with AI specifically in the enterprise is by arming the AI applications and the AI agents with data that is proprietary and specific to you and your organization so that it can drive insights or take actions that are relevant to you- Mm-hmm ... and your organization. And that creates an inherent risk because in order to do that, you have to centralize and pre-process your data to be AI ready, so to speak, to put it in AI knowledge bases.
And so you're taking data that was previously siloed across the organization and centralizing it to a single point of failure, a kind of honeypot of source, which is your vector database. And this creates an inherent security risk because, A, if I'm an attacker wanting to breach the organization and get a cross-section of the data from that organization, I now only have one place to hit as opposed to all these various silos. Mm-hmm.
But also because this AI knowledge base, which is typically a vector database, is comically ill-equipped to deal with this type of security risk. And that's because vector databases deal with vector embeddings, the lingua franca of transformer models. They deal with those in plain text because they have to compute distances between vector embeddings, and they can't do that over ciphertext, typically.
So it's processing all of this data in plain text, and it's creating kind of a big hole in the security posture of basically every enterprise pipeline out there. Wow. I was going to ask you about the architectural constraints.
So explain this to me as a layman. So vector databases operate in plain text with no encryption in use. Can you kind of be more specific on that?
Or may not be more specific- Sure ... but can you explain why that's important, why that's significant? Right.
So, in the traditional database world with structured databases, you haveRow-level encryption, column-level encryption, and in document stores, you add field-level encryption, et cetera. These are well-known paradigms for being able to use cryptography to secure data and enforce strong access control on that data. In the world of vector databases, vector databases do have really just one job.
It's unstructured semantic search. How do you search for data via context, via meaning, without an underlying schema or structure? And inherently, in order to be able to do that, you take data, you process it, you feed it to an embedding model, and you convert this data from its original modality, whether it be text, images, audio, 3D spatial data, et cetera, into vector embeddings, which are these very large, high dimensionality numbers that encode semantic meaning or context to that piece of data.
And vector databases allow you to do that search matching of, for a given query, what is the most semantically relevant piece of data or pieces of data at scale, very rapidly. To do that, they employ a distance computation, a distance metric such as Euclidean distance, cosine distance, et cetera. Mm-hmm.
And to compute the distance between the query embedding and the candidate embeddings that are in the knowledge base, they need to literally compute, do a L2 or a dot product to be able to compute that distance. That needs to happen in plain text. So it means that the data cannot be encrypted while it's being used.
And furthermore, if you were to have to encrypt the index and decrypt it on the fly to be able to add this encryption and this strong access control, it would make performance slow to a crawl, this inline decryption. So it means that every vector database out there is essentially insecure in this regard because they're operating on data in plain text. And so this creates a risk in terms of infrastructure compromise, right?
Any access to the host, any type of insider risk. Mm-hmm. The data is not encrypted in use and sometimes not even at rest.
And also it makes it really difficult to do things securely, like multi-tenancy. How do you isolate multiple tenants on a single vector database when the data is not encrypted independently across tenants? How do you do strong access controls, whether it be rule-based, role-based, attribute-based access control?
It's a very immature breed of technology that enterprises are betting a lot of not only money in their infrastructure, but in their actual proprietary data storing within these vector databases. So in a sense, there's kind of this calculated risk. What I think about is in terms of priorities, in terms of, not to be alarmist, but I'm assuming there are a lot of enterprises who are verily concerned about this scenario and what could possibly go wrong.
And I'm wondering, what type of companies are you working... You're working with a lot of enterprise companies. Is it across the gamut in terms of industries you work with, or are there particular ones that are more focused on this than others?
Yeah. Well, firstly, we've been partners with NVIDIA for a little over two years. We've been working very closely with them and a number of their teams.
com. Okay. We're one of seven companies to do this with them, and it was kind of a reference architecture meant to show for enterprise use cases, how do you build secure AI infrastructure specifically for RAG, which is the bread and butter of enterprise AI today.
And we're doing some additional work now on agentic RAG with them. But this allowed us to get a lot of credibility and exposure in the enterprise, because we also don't want to be alarmists, but we don't believe- Me too ... it's a calculated risk today.
We're very much in a phase of the market that is market education, teaching that this is an inherent risk of vector databases. That vector embeddings, if leaked, are invertible, meaning you can convert them back to the original modality of data, so they need to be treated with the same level of sensitivity as source material. And so in that vein, we're working with a lot of companies that are traditionally very security-minded.
So the companies that we work with then in turn service regulated markets like financial services- Mm-hmm ... insurance, healthcare, and public sector. And then there's also a lot of organizations that are starting to realize outside of these traditional sectors that actually my data should be secured even if compliance does not require it.
Are you finding that, say, this year compared to last year or even two years ago, the level of scrutiny and awareness of what's going on in terms of security is much higher than it was? " I'm just wondering if their level of awareness and security is higher now than it was a year ago. Definitely.
I'm really glad you brought that up. Firstly, I feel for CISOs today. They've got a million and one emerging risks to have to parse through and they're underwater.
So I completely understand. And a year ago we were kind of screaming into the void about this particular brand of risk, of the centralization of data, vector databases not being secured. But thankfully, a lot of organizations have come out with lists and with materials regarding this that have highlighted this risk.
So OWASP came out last year with their top 10 LLM and GenAI risks list. And number eight on there was vector and embedding weaknesses. Okay.
Which is exactly this- What were the top, do you remember? I don't want to put you on the spot, but it was in the top 10 worries. It was number eight on there.
Obviously, context poisoning- Mm-hmm ... was up there, model jailbreaking. I couldn't tell you exactly what the list is.
We're focused on our narrow slice- Mm-hmm ... of the problem space. But they came out with their top 10 agentic risks, which also had that.
MITRE came out with their frameworks and called this out as a risk. Fenno. So there's a lot of different security organizations.
And this was based on-- Was this based in part at all on high-risk incidents, or was it just based on possible scenarios that they were thinking through? Possible scenarios, vulnerabilities that have come out, emerging vulnerabilities. 3 out of 10 criticality that let anybody with access to the same network as the vector database itself to bypass authentication and dump out all of the data from the knowledge base directly.
And they were very responsible in patching it and disclosing it. But these security organizations are realizing the writing's on the wall. The risk is going to transform from a risk to an actual breach that will be traceable back to this problem.
And so I would say the appetite to solve it is increasing, the awareness is increasing, and the tools with which to actually solve these emerging risks are also maturing quite a bit. So in that vein, in terms of solutions, tell me a little bit about CyborgDB. How does that address this problem or try to tackle it?
Well, we're laser-focused on this problem, and we have been for a while. We've been working on the underlying technology for CyborgDB for close to six years. And so CyborgDB is essentially application layer security for AI knowledge and memory.
So what that means is it's essentially a Docker container that sits within your AI infra, in front of a backing store, whether that be object storage, whether that be Postgres, Redis, or your file system, distributed file system. And it replaces your vector database and it does two things. It does what a vector database does, which is- Mm ...
essentially approximate nearest neighbor search. But the second part, which is unique to Cyborg and subject to our family of 16 US patents, is cryptographic indexing. So we transform vector embeddings into cryptographic tokens that allow us to selectively regenerate those tokens at search time in order to do that coarse approximate nearest neighbor search on encrypted vectors without decrypting them.
Then we only decrypt the final candidates that need to be re-ranked and fed to the LLM, or we even have modes that use partial homomorphic encryption for the last re-ranking step such that there's no decryption at all. And so it does a few things. That firstly now makes the vector database encrypted, even in use- Mm-hmm ...
significantly elevating the security posture of your entire pipeline by making your proprietary data secure. It allows you to do cryptographic multi-tenancy, cryptographic isolation for multi-tenancy- Okay ... which is a really difficult thing to do today with vector databases.
How do you have multiple tenants, whether within an organization or actual separate organizations on a hosted solution, have strong guardrails and isolation guarantees, and allows you to do strong access control that is cryptographically enforced- Okay ... whether it be rule-based, role-based, attribute-based access control. And so we built this, and we shipped it last year.
It's at the heart of this blueprint that we did with NVIDIA, and essentially meant to solve this whole class of problems at the heart of enterprise AI pipelines. So I want to go back. You founded the company, you said, was it six years ago?
Yeah, we started working on this about six years ago. So you started in this specific area six years ago? We were working essentially a separate startup before that on- Okay ...
data compression, and began working on searchable compression, which was a really interesting technical space but had zero commercial value. Yeah. And that kind of gave the idea for this venture, working on searchable encryption.
So that's kind of what I was getting at, is every company has this journey, and I was just wondering how maybe in the last couple few years with this kind of rabid, kind of almost feverish pursuit of AI that changed the thinking of the calculus within your company of what you were going to do. But it seems like you were already in that path. " Right.
That's kind of- Sure ... what I'm trying to get at, actually. Look, I wish I could say that in 2020 when we started working on this, it was- Mm ...
we saw the hole in enterprise RAG pipelines. But to be honest with you, enterprise RAG didn't exist. None of these words were really around at that point in time.
We were working on building solutions to do... We were laser-focused on how do you search while keeping data encrypted, and vector embeddings were actually a means to an end for that. And then we just happened to be extremely fortunate in terms of market timing that vector embeddings started to become- Oh, yeah ...
the heart of enterprise AI applications. And we just happened to have built a robust system for being able to search through them semantically while keeping them encrypted. So I do not mean this as a loaded question, but how prepared are most companies addressing this kind of agentic AI or autonomous workforce mandate?
I'm wondering if most of them are pretty well-positioned or have thought this out, or if there's such an incredible amount of pressure to adopt, whether they're kind of walking a tightrope. And I don't want you to cast aspersions- No ... towards industries, but I do wonder, based on what we have written about and some of the studies I come across with CISOs, it's likeThey are being asked to run down a very fine line with not a lot of margin for error on either side.
Candidly, I think the market at wide is vastly underprepared for what's to come. Yeah, I agree. And it's not for fault of trying.
Mm-hmm. Even at this conference, everybody's trying to solve this problem. I think that the problem fundamentally is that most organizations have not figured out how to mitigate insider or rogue employee risk, right?
Social engineering attacks are still running rampant, and the way that they work is by conducting a social engineering attack on an employee or an insider in order to be able to conduct some sort of breach. And agentic AI is no different. We're trying to imagine that it's a new future where you've got these machines that are somehow very different than humans and very different than- Mm-hmm ...
employees. But I think that if you're looking at it that way, you're looking at it wrong. With agents, you're just onboarding new employees, essentially.
You're onboarding non-deterministic systems- Yeah ... non-deterministic agents within your organization. Well, guess what?
Mm-hmm. Companies have been hiring non-deterministic people for a very long time. That's humans.
They're employees. And so looking at how we solve the insider risk problem is kind of the same way that we solve the agentic AI risk. Different tools, by all means, but so long as we've not solved one, I don't think that we're going to have the other one fully solved.
And the risk there is that the speed at which an insider attack happens by an employee is vastly slower than by an agent. See, this is the thing. This is the rub for me that is particularly terrifying because I'm seeing, given the state of the economy and this urgency among companies, and I'm not saying it applies to most companies, but there are quite a few companies.
Meta, there's a rumored 20% layoff, which I think was influenced by efficiency- Sure ... where humans are replaced by an autonomous workforce. I think Amazon, there's this long-term goal of swapping out 600,000 folks for robots, what have you, in whatever form they are.
Dell just announced 11,000. I always wonder if they, in their pursuit of better profits, more efficiency, whether this kind of raises the ante and raises the stakes or raises the risk. And, I know they've looked at it internally.
I would hope they have. Sure. But it's just that the one thing when you mentioned this whole kind of movement towards non-human factor and where that leads for everything.
I don't want to comment on any specific company. No, I'm just talking in general, this kind of climate that we're in- Right ... where companies are trying to raise their market valuations or trying to address- Totally.
I think that the change is going to be painful and is going to be a ripe opportunity for attackers. Right. And I don't know, it's hard to say because the losing talent that is in charge of the security, we're seeing there's a lot of rumors about downtime happening at some of the major infrastructure providers.
That it's happening because the security DevOps cloud talent is- Excuse me ... is gone. But replacing with agents, does that mean that it's going to be worse off or better off?
It's hard to say, but I know we're going to see probably a whole new class of issues. Yeah. Perhaps on the bright side, maybe we'll get better orchestration of agents to address security.
Maybe. Maybe. Maybe.
We don't know. We're in for a very tumultuous time, and I feel for all the people that are losing their jobs as a result of it. Yeah.
And I hope that... We've got some problems to solve from a security lens. We've got some very big problems from a societal lens to figure out- Absolutely ...
as well. Absolutely. I don't want to step outside my- I know.
You're a wise man, Nico. Hey, thanks Nico, for your time. Appreciate it.
Nice to meet you. Thank you for having me. I appreciate it.
Thanks. Pleasure. That's it for today for me.
I think day one. Day two, I believe Alan will be back with a lot of interviews back to back to back all day. So, stay tuned, stay on TekStrong TV.
Thanks. Hey, everyone. We are back here live.
We're at RSA Conference. We're in Moscone West. I guess it must be getting near lunchtime, or the keynotes are opening, because I'm seeing a lot of people congregating down there.
But let me introduce you to my next guest. I hope I get this right. Chris Pearson- Yeah ...
with Black Cloak. Yeah. I'm going to do this a little backwards.
I usually ask people to tell me a little bit about yourself. But as the founder, I founded three or four venture-backed companies in my day. You know this because you've done it.
We breathe life into our companies, especially early on. Oh, yeah. Right?
We are kind of the passion that they feed off of. A lot of people out here don't know Black Cloak, though, so let's start there. Yeah.
How would you describe Black Cloak to our audience? It's pretty simple. Black Cloak is the pioneer of digital executive protection.
We started in 2018. We're a team of about 150 Cloakers all spread out throughout the US. We have clients in 42 countries.
Protect about the top 20% of the Fortune 100, top 25% of the Fortune 500. And at the end of the day, what does Black Cloak do? It does digital executive protection.
What that means is that we are protecting the corporate executives, the board, the C-suite, the executive leadership team And their families, super important, in their personal lives. Especially right now, we see what's going on with the CBS. The threats are no higher.
They're just so incredibly high right now. Yeah. It's really important that you think about the attack surface that's outside the four walls of the company.
So once again, the CISO, the CSO, they take care of things on the inside four walls of the company. We're protecting the executive and their family members' personal privacy, personal cybersecurity, their home networks. They have three to five homes on average.
And then we add in our concierge, which is unlike anything else. It is literally an entire US-based security operations center, 24/7, that's watching, monitoring, protecting, reacting, and responding to any cyber and privacy needs they have. And look, in a post-United Healthcare world, tragic events from December of 2024, that convergence that we've seen has only gotten worse in terms of physical and digital security protection.
I love it. So now I'm going to come back to what is usually my first question is, Chris, what led you to do this? Well, look, my background spans many different things.
A little bit of time as a DHS special government employee on privacy and cybersecurity, so we saw some of these threats coming at our defense industrial base companies firsthand. Background as a lawyer, 23 years as recovering a lawyer, started a cybersecurity practice at a large firm way, way back when. Former chief privacy officer for the Royal Bank of Scotland and two-time chief information security officer.
It was the threats that I saw on the intelligence community side, as well as, as a CISO, where they were literally attacking outside the organization. You're not going to take down a defense industrial based company by hacking them directly. No.
But you can by targeting the board member- Bet that ... the CFO, the CEO, even maybe the person that's in legal that's in charge of intellectual property, and find out what's coming next before it hits. And then as a CISO, I saw the same thing in terms of our executives, our boards, our VCs.
Every time we announced a funding round and there was another wave of attacks that was happening. And so for us, it became really, really critical. How can I, how can my team, how can we protect our company by extending that layer of protection outside the four walls of the castle to them, their family members, and their personal lives?
So bottom line, like all great companies that start where you have a problem that is personal to you, that impacts you, impacts your team, you just got to go solve it. I love it. Before we segue into news here from RSA, people want more information on Black Cloak.
Where can we send them? io, and you can go talk to a member of our team there, see some demos, see some information, get some threat intel reports, all the rest. Really easy to do.
Absolutely. And I should mention, we've partnered with Black Cloak now over a year. It's not just executives.
In today's world, high net worth individuals. It is. It's a lot wider of a net than one would think when there's reasons for people to want to- Yeah ...
exfiltrate, to want to slow down something, to want to have access to something. And increasingly, things like character assassination, AI deepfakes, which we're- Oh, my God ... going to talk about.
But even think terrible physical things, kidnapping- Yeah ... and stuff like this. And never forget, terrorists, it has terror involved.
Yep. And that's part of it. It is a wide attack surface.
It is those people that, if you think about it just in terms of high-value targets, corporate executives, C-suite, board members, as well as high net worth, ultra net worth individuals, sports star, rock star, politician. These are folks that are in the limelight. Today, AI scientists.
Because these guys, they're making more money than baseball players, not to mention athletes and so forth. But Chris, I want to talk a little bit about RSA, RSAC. Oh, gosh.
We're here. Yeah. You guys released some news around it.
Three things. Yeah. Let's go through them.
Yeah. So this week, Black Cloak announced the further deepening of our protection platform. And it really is a platform.
It's technology that is brought together, that is holistic on the privacy, the cyber, the home, and that concierge front. And so we did three different things announced out in the field. Number one, search suppression.
So we've heard a lot about data broker removal. These data broker websites, the Spokeo, the Zsearch- Yep ... the 411, all the data broker removers.
It's absolutely necessary but totally insufficient in terms of actually hardening the attack surface for an executive and their family members. So Black Cloak announced on Monday they released search suppression. So if there is personally identifiable information that is out there on the Google, let's just say, that we are able to actually suppress those links to make you, once again, a harder target to find.
All engineered by a great team, and really, really, we're super excited about this and the next step it provides for our clients. I think a lot of us, Chris, have looked at this because we all see- Yeah ... there's too much of our personal information out there.
To a certain extent, it gets to be Whac-A-Mole. It is. What you killed today, it pops up over there.
Yep. How is this different? How do we not play the Whac-A-Mole game?
So no matter what, just the way privacy is not a fundamental human right in the United States, so your data's going to be out there, it's going to be bought, it's going to be sold, it's going to be transferred. So it is going to be a game of Whac-A-Mole. But what you have to do is actually solve it through other ways.
So when your information is out there exposed on the dark web, you have to make sure that you're changing the passwords, getting dual factor, and doing encrypted password vaults, but you have to do it with and for people. When you have data broker information that is out there, yes, you have to go schedule it for review. Search suppression takes it to the next level.
But then what you have to do is really teach, uniquely teach individuals how to go ahead and leak less information, harden their cell phone, their tablet, their computer. Same things that we use in the government, but make the device 100% frictionless, friction-free, so you just do what you want to do, but you're sharing less information about you and keeping that information out of the limelight. So those are some of the tips and tricks that we actually impart to our clients.
And once again, we do it with them and for them, really the key. Love it. Yeah.
All right, that was number one. One. What's number two?
Number two, just amazingly, amazingly proud of the team on this. It is travel advisory. So literally, you're traveling out to some 214 countries that Black Cloak has in its inventory.
We have the ability in live real time to be able to say, "Hey, here's the travel risks of the country. Here's the things that you should think about in these different cities. Here's where the embassy is.
Here's where resources are. " This is how we judge your activities, and we're able to do that on the fly for our corporate commercial clients as a bolt-on, as an additional add-on to the overall digital executive protection platform that they already know, love, and have. This has become really important in recent times with the conflict that is going on right now in Iran.
I was just going to say- Yep ... it's pretty timely. Yep.
And with the conflict that occurred- It's not just Iran. You've got the Ukrainian situation. Mexico, Ukraine, all over.
Mexico cartels. Yep. The world is a dangerous place right now.
It is, and the key thing is this, the chief information security officer, the chief security officer, they're looking for a relationship partner, someone who can, on the fly, generate this travel advisory information for their key executives, for the executive leadership team members and board members that are traveling, moving about the world, sponsoring perhaps the Olympics. They want the information. They want it at the tip of their fingers, and they also want, and we will be able to, shortly this spring, provide all that information through one button click in the Black Cloak app to our members at certain different tier levels.
So really, really excited. This is where you combine good threat intel, good information, good intelligence with the actual physical, practical know-how, and actually in a formed product that ounce. Not going to be your 50-page product.
This is really, really sharp, the notable quotables you need to know, and get it right into the power of the person's hand immediately. I love it. Yeah.
I don't know if I should say this publicly, but I'm planning a trip in next month, and I started looking at some of the official- Yeah ... travel advisories, and you're right. The signal-to-noise ratio in there, I don't know if I should get vaccinated for every disease known to man- Yeah ...
or what else is happening. But there- After RSA, this week at RSA, you're all set. Maybe I should, right?
Yeah. You're all set. You got exposed to everything.
I get it, right. You're all done. Touché.
I was here in 2020. Yeah. Left here and- Oh, yeah ...
found out. I walked home with a few extra parting gifts. Yeah, exactly.
That year as well. Let's move to number three. Oh, number three.
How's that? Number three's really big, though, Tim. Yeah.
Well, what's interesting about number three, the topic of deepfakes, especially AI-powered deepfakes. Look, two years after this really became possible and feasible, right, we had that in February of 2024, you had the transfer from somebody who thought it was his CFO on with them from the Hong Kong institution- In Hong Kong, yeah ... $25 million.
$25 million out the door. No guns used, no hacks, no this, no that. Deepfake, and the technology for doing it live real time- It's gotten better ...
it is amazing. It is amazing. So here's what we did, a few different things.
Number one, one of the smartest things possible, right? We powered up with Techstrong and had a survey done, all the rest, in terms of how do we think about this? How do we go ahead and actually figure out what is happening?
And over 33% of the respondents said yes, in some form or fashion, they have been exposed to deepfakes about them. This is the cream of the top, right? " This is really, really scary.
And so here at RSAC, we, number one, we did a two-hour learning lab on this, right? Nothing about Black Cloak in there. How do you think about it?
What policies do you have? What procedures do you have? What education do you, Mr.
or Ms. CISO, and your team members have to go ahead and tackle it? Second, we, Black Cloak, have announced the re-release of impersonation protection.
It's a feature within the Black Cloak application that allows for our members, or people within that circle of trust, including family members, to be able to verify that I am actually on the phone with you because you uniquely have been approved to the Black Cloak platform. I'm on the Black Cloak platform. We're logged in, we're synced in together on our devices, out of band, and whether it's a Zoom meeting, a Teams meeting, a phone call on a regular old telephone line, a cell phone call, WhatsApp, Signal, whatever the cool things are that everyone is doing today, we can say, "Hey, hold on a minute.
Let's make sure we test that we're not actually right on the opposite end of something that's a bad call," right? Yep. " And we don't want to.
We want to go ahead and you just open up the app, put in the person's name, go in and say, "Hey, I'm on a Zoom with you. We're talking about a new transfer of $10 million for the new penthouse we're getting. " You send it.
It does the biometrics on you on your phone. Goes to your phone. Right.
Does your biometrics, sends it back, location, and now we know through the power of Black Cloak, we can rest assured that- You're you ... the other person is really you, and it's all nice and seamless, and it does not add any extra friction to the process. We're talking about five to 10 seconds to make a verification.
Really, really groundbreaking technology. We're super proud of it, super proud of the team. I love it.
And look-This sounds a little thing, like a little bit out of Ocean's 11 or science fiction, but this is real. As you said, it happened in Asia. I've seen with voice cloning, video cloning, and I'll tell you something.
You know who the worst offenders are? It's these executives doing it themselves. They're playing with things like Sora, the video maker, or other AI-enabled things that are making AI.
And I'll be honest with you, I'm guilty of it, too. You may be, right? You're making likenesses of yourself in an AI environment.
Once it's out there, other people could harvest that, too. What's even worse is when you think about this, your board, your C-suite, your executive leadership team, all on the website, About Us and Leadership page, they have the low-res, medium-res, high-res images out there. They've got the audio clips from the different share earnings reports.
They've got the video clips from them being on CNN- That's all they need ... CNBC, and all rest. They already have everything out there.
They got everything they need. And here's the thing is, no putting the genie back in the bottle, no digital watermarking, all of this stuff. Oh, stop.
Right? They're just chasing things. Literally, all the information's there.
What you have to do is just make sure that you have a way to make sure that your company doesn't lose money, intellectual property, have a breach as a result of it, because you have a means and a mechanism to verify, through that closed loop network, that the person is who they say they are, period, end of story. How can we get people over to here to check this out? io.
We love having the demos, showing the demos, grabbing people on board. But we're going to be pushing this out at a rapid pace to all of our existing clients and bringing on new folks onto the platform. We got to really change the narrative and get out there ahead of it .
Thank you, man. I appreciate it. It's a pleasure.
Absolute pleasure. Chris Pearson, founder, CEO of Black Cloak here, live at RSAC. We're going to take a break.
We're here all day, though. Stay tuned. We'll be back in just a bit.
Hey, everybody. We're back in Amsterdam at the KubeCon + CloudNativeCon Europe event, and we're talking to my friend Weigu from Broadcom about what they're doing in the open source community and all the good things that are going on there. Starting with, there's this new project that you guys have donated to the CNCF, Velero.
What exactly is that, and where does it fit in the spectrum of things you guys are working on? Of course. So Velero is a software that allows you to do backup, recovery, disaster recovery as well, and also do migration.
So with this tool, it allows the enterprises to plan for their data and configuration to be consistent and to be able to recover it as well, right? And if you look at Velero, it's really placed in this enterprise space where we focus on operations. And as we always do at VMware, operations for enterprise scale is very important.
You look at all the other projects we contribute to, for example, etcd, Cluster API, et cetera. So we bring our decades, and the decades of experience in running and managing private cloud, and bring those operational experience into this new Kubernetes space for our customers as well. Yes.
Now, historically, VMware had kind of a Kubernetes approach where you could run it natively on the VMware Cloud Foundation. Mm-hmm. And then there was Tanzu as well as kind of a project.
Are those two still kind of the main Kubernetes engagement paths for you guys? Or what's the relationship there? So that's a great question.
The only engagement in terms of VKS, that includes VKS runtime or Kubernetes runtime, as well as all the cloud services that you need to run Kubernetes, are all based on VCF and in VCF, actually. It's part of the VCF software stack. Now, Tanzu, as a separate product division, and they have their own product portfolio, is going to focus more and more on this PaaS platform where they use the technologies from Cloud Foundry, et cetera, to focus on this developer experience.
But when all things come to Kubernetes, it's VCF. Got you. All right.
Is there something right now that you perceive that is... If you have a wish list of things you wish the community would prioritize a little bit as it relates to Kubernetes from your perspective, what comes to mind? Well, again, going back to our heritage, in terms of infrastructure and operations, right?
So we will very much like the community to continue in that space to bring all this cloud experience to the customers. I'll give you one example. If you think about, let's say, dynamic resource allocation, DRA.
It's all about GPU resource allocation and everything, and surface that up to the Kubernetes clusters. And guess what? We have been doing this for many years at the VM level already, right?
In terms of presenting the GPUs as assignable hardware, and if you look at Kubernetes constructs, the device group, the device class, and the resource claim, et cetera. We have very similar concepts in the VM space already. So it was so great to see the emergence of DRA since last yearAnd we think there's a great opportunity that we can marry that technology and use the constructs that we have in our stack and make the GPU and AI workloads more accessible to our customers.
Of course, at the show, AI workloads has been one of the main topics, and specifically AI inference. Yes. Are there things that organizations need to do to optimize those workloads for Kubernetes types environments and open source?
And it seems to me there's a lot of projects walking around here that are related to that. What are you guys looking at or thinking about? So we are taking two approaches, but they are very much related.
The goal is to meet customers where they are. Right? So by that I mean, number one, in our VCF stack with VKS, we still provide a bunch of packages and services that developers and the platform engineers will need to build their applications, the workloads to run in Kubernetes.
So they have that option if they just want to simply consume out of the box, that customer experience. On the other hand, we also, again, meeting customers where they are, we understand, and many of the enterprise customers also tell us that, "Hey, over the last few years, we have built up our own CICD pipeline," for example. "We have our own tooling and everything.
" Right? So in that case, we are working with the broad ecosystem and a lot of the partners who are at the show as well. You probably saw the announcement earlier this week, in terms of partnership with Kong, et cetera.
So we work with all these partners and the CNCF projects to validate how to make those same tooling and the platform work with VCF. So we will not only provide, let's say, reference architectures or technical validation. In certain cases, we may even provide Git repo, for example, so that customers can sample those repo code and just basically deploy the same exact tooling that they have and make the workloads run in EKS naturally.
Right? So with both approaches, again, coming back, meeting the customers where they are and make sure the best outcome for them based on what they prefer. Is there more convergence now between the VMware world and the Kubernetes world?
Because historically, I can remember when Kubernetes first came out, there was this general feeling that Kubernetes would compete head-to-head with VMware. But now, in hindsight, it looks like most of these Kubernetes clusters are running on virtual machines anyway, and maybe we're starting to see some convergence. Yes, I think that's exactly what we see as well.
Essentially, regardless of whether it's a modern workload that runs in containers or running in VMs, first of all, they all need infrastructure. Right? Whether that's compute, storage, networking.
And there are certain characteristics that developers would expect. For example, performance, security, very important. You don't want your application to be the landing spot for security vulnerability or ransomware attack.
Right? And you definitely don't want your applications to go down. So the reliability and all those aspects are very important.
And vSphere has been at the center of the data centers, if you will, in the last more than two decades now. That's what we do best. Now, there's also, when you run Kubernetes and containers, I think there's a trend, and many analysts are pointing out already.
For example, IDC predicts by 2028, 85%-ish of the containers will continue running in VMs. And that's what the hyperscalers do as well. Right?
So what that provides is really the level of resource isolation, security, and we like to say that we provide six layers of security, all the way from the hypervisors to the containers and the namespace. Right? All that provided in VM, and resource consolidation and the utilization.
Think about today, the hardware cost is out of control. And vSphere, what we do at best is this resource utilization and consolidation that makes sure that we can save you tremendous amount of cost by running this architecture, and that remains to be true, and more and more customers, I think I even see some solutions on the expo today that actually gets to what we have been doing for more than two decades. So that's definitely happening, and I think that will continue.
Now, it seems there's more nuance in the sense that the applications are becoming more distributed. Yes. And there's elements in the cloud, there's elements on premise, and there's elements at the network edge.
So is that changing the way we think about this infrastructure conversation, because the workloads need the... There's just a higher degree of interoperability required. Yes.
So in my view, two points. Right? Number one, going back to meeting customers where they are.
Our infrastructure doesn't have to be in your own data center. So our software stack can be deployed on the cloud, in the data center, or on the edge. So that gives you that level of consistent infrastructure wherever you want to run your workloads.
But secondly, I think it comes back to this VKS. It's aConformant Kubernetes distribution. So what we do is, again, as I said, we may have some opinionated offerings or packages, services that goes with the solution.
Right. But by and large, it's open source, it's very conformant with Kubernetes. So that allows the customers to move workloads to any Kubernetes conformant clusters if they choose to do so.
To do so. Mm-hmm. And that's tremendous benefit to our customers, as you can see.
And there's a benefits, obviously, being conformant that gives us agility or time to speed us to production for our customers. By that, I mean when a new Kubernetes release comes out, typically within two months, we will be able to validate and certify that our BKS cluster will be able to allow customers to consume the latest and greatest Kubernetes release. Mm-hmm.
That's on par with all the hyperscalers out there. That level of agility allows our customers to consume the latest and greatest features. But again, if the customers so choose, they can move those workloads to another conformant certified Kubernetes distribution as well.
So it's a open ecosystem out there. Right. I have yet to meet anybody who's standardized on one particular type of distribution- Exactly ...
of Kubernetes or much less the version number. Exactly. And I would also add, in addition to the agility and the speed, we also support multiple Kubernetes releases for our customers.
So architecturally, we allow customers to deploy multiple BKS clusters. It's not just one single cluster. So with this, here comes the benefit of isolation, security, et cetera, but also different teams may want to consume different features that's offered by different releases.
That level of flexibility is there. And on top of that, there is 24 months enterprise support of all those releases, gives the customers a great level of confidence with us. Now, we live in a world where there's greater sensitivity about cost, but if I look at the architecture, and as I understand what you guys are trying to do, is the total cost of your approach going to be ultimately less because more of the components are integrated?
No, I think ultimately what determines that is the value that customers get out of the solution. Mm-hmm. So not only from the compute storage networking perspective, what we put together in terms of cloud operations and cloud automation, it's very important and essential to our customers operating their private cloud.
And listen, we didn't invent some new infrastructure or things in that nature for Kubernetes world. We basically put a control plane on top of the same exact infrastructure, the same stack. This integration creates the value not only in that sense, but also, the single unified APIs for customers to run their and manage their, both their container workloads and VM workloads.
That's tremendous value. So I think over time, that value will make the solution more resonate with our customers. So does anybody at Broadcom keep track of how big the contributions are to the open source community?
Because I think everybody thinks of a lot of other companies out there, but it's not clear to me that anybody knows what Broadcom's doing. That's a great point. We don't talk about enough.
We are starting to. org website that tracks the contributions. If you look at the dashboard, VMware actually has been a top five contributor to CNCF over the last decade.
Wow. And there are a lot of projects that we have contributed to. In addition to the Velero we announced earlier this week, there were projects like Contour, there were projects like Harbor Registry.
Of course, we contribute heavily to etcd, Cluster API, and all these different projects. So a top five, and we should talk about more. And obviously, at this conference, we are starting to make a lot of more communication to our customers about where we are and the future that we intend to go in contribution to CNCF.
Is there any particular thing you have at the top of your wish list for the open source community that you just wish as a group we would all focus on a little bit more? That's a great question. AI is top of mind for everyone.
Obviously, I saw some announcements about open sourcing some of the GPO drivers, things in that nature. I think we can benefit from those as well. And then from the whole platform engineering landscape, if you look at it, there are a lot of things that's happening.
org. If you look at that reference architecture, what's interesting is, in addition to the developer side and obviously the CI/CD side, there are more planes that are being added to that reference architecture, including observability, security, and of course, infrastructure and the resources. So I think we play very well in those planes, in terms of security, observability.
We have our own solutions, butAgain, going back to the open ecosystem point of view, we would welcome CNCF contributions and the projects that can benefit customers in those spaces, and we would love to integrate and validate some of those solutions, give customers the choice. So as we see more and more of those projects mature, we will try to give customers more guidance and, at some point, as integration is needed, we will try to do that as well. All right.
" I still see a lot of things managed in isolation on my side, but what are you seeing? Yes. So at enterprise scale, cluster management, for example, is a big thing in terms of lifecycle, from deployment to update, upgrade, patching, and all that.
So at that scale, you need multi-cluster management and the multi-cluster lifecycle management capabilities to go with it, operationally, to be excellent at it. So I think some of the customers may see Kubernetes as a simple platform, which it's not. It's very complex.
So I think customers will realize, in addition to the broad ecosystem and all the projects they have to stitch together just to run Kubernetes, they will need to start thinking about the scale that Kubernetes needs to be run and the scale the Kubernetes clusters need to be managed, et cetera, et cetera. And more and more of that will need enterprise-level features and capabilities, not only coming from vendors, but also from the CNCF projects. So I think customers will realize over time.
All right. Folks, you heard it here. Hey, no matter how complicated things get, at the end of the day, when it comes to IT infrastructure, there's a good rule.
It's called keep it simple. Hey, Wingu, thanks for being on the show. Thank you, Michael.
All right. My pleasure. And we'll be back in a minute.
Hey, everyone. It's Alan Schimmel, founder, CEO here at Techstrong Group. Really happy to introduce this next session here for you.
In this session, we are going to have Futurum's Fernando Montenegro, who is the analyst in the security cyberspace, speaking with Ryan Jones. Ryan is the partner director of product for Power Platform Managed Platform over at Microsoft. Great conversation with Ryan and Fernando.
Fernando's going to talk to Ryan as we explore how organizations can securely scale agentic apps, including Power Platform's governance capabilities. This is going to include managed environments, adaptive risk models, and lifecycle controls. Hopefully, you'll get out of this video practical guidance for balancing innovation with compliance in an age of AI-first development.
Let's listen in on Fernando and Ryan. Alan, thank you very much. So I'm Fernando Montenegro.
I am VP of security research over at Futurum, and I'm thrilled to be here with Ryan Jones to talk about the broader topic of AI governance. Ryan, want to say a few words before we get started? Yeah.
Thanks so much, Fernando. My name is Ryan. I work on a number of the security, governance, and operational capabilities that we provide not only to our AI agents, but also that we provide to our low-code apps and automations that run on the Power Platform as well.
Have you come across something more specific to AI risks or AI governance concerns that surface above and beyond this data flow and sharing and others? As we look at the maturity of agents, we see that they go from being assistants that are completely directed by humans to still interactive agents where humans are dispatching tasks, but the agent is completing them on behalf of the human. And then we see those fully autonomous agents.
And I would say that 10% to 20% is really more over on the end of the spectrum with those fully autonomous agents than it is with my little assistant agent or something like that. And the types of things that we see at that end of the spectrum are things like, hey, if I am collaborating with a set of agents, how do I understand what they are doing or what they are doing on my behalf? The second scenario that we see is we're in the very early innings of AI.
And so there are lots of cases where agents need help, where they sometimes get stuck. And so some of the things that we've been trying to add into our products and our offerings are things like within Power Apps, we have the agent feed, where a human can see what all the agents are doing for them. And then within Copilot Studio, the request information...
action, which actually allows us to define an agent such that it can engage with humans as needed. So what has been your exposure, your experience? What kind of considerations do you have in this topic of model drift and model security and so on?
Yeah. It's funny, we talked about how what's old is new again earlier, right? Yep.
We've had static tests that we perform against software for a long time. And what's interesting is seeing how that is evolving, because models are less deterministic than traditional software. We call it stochastic life, right?
And so as a part of that, one of the capabilities that we've added to Copilot Studio is the ability to add tests and evaluations, so that as our technology improves, as makers and builders go through and they modify what tools their agents can use or what knowledge sources are used to ground those agents, those test cases, those evals can run and can return a result so that folks, as they are evolving, they know whether or not they're actually improving the quality of their agents. Because what we find is that the first day that an agent is shipped in an organization, this may sound negative, but that's going to be the worst that that agent ever is. Okay?
It's only going to get better over time as folks refine the knowledge sources, as folks refine the tools, as folks look at and improve the success rate across those evals over time. And so I think that those quality gates that we've had in software for a long time, we have those with AI as well. Mm-hmm.
I think also, a lot of times, an individual maker, they're going to be the folks that are really interested in whether or not that agent really works well or not. While IT is going to take a bigger picture look at things, right? Sure.
They're going to want to understand in aggregate how are things looking, are they healthy or not? And it could be that if they see an agent that's not performing well, but maybe just you and I use it, IT probably doesn't care. But if I have an agent that 20,000 people use this month, IT is going to care.
And so those same views that we provide to our makers to understand whether or not their agents are healthy, we provide those aggregated views for the admins as well. In fact, had a large customer in the energy industry where someone built an agent, and it was for them, and they shared it, and it kind of grew and grew and grew. Next thing they knew, they had 10,000 people using it.
They moved on to work on other things, right? " And so they took it over. They added it into their portfolio of applications that they managed.
And the thing was, they saw it not as a burden, but rather as an opportunity. Because there's an application that's out there that delivers value to tens of thousands of people in the business every month, and their dev cost up to that point had been zero. So it was a win-win for everybody.
Once the technology security teams build the guardrails, right, then the business users are free to go work on those use cases. So what kind of advice do you think would be applicable to those technology and security teams in terms of getting them ready to build those guardrails or to leverage what they have to implement those guardrails? I think enumerating the categories or the dimensions of risk is one of the first steps.
There are huge categories of risk that these teams can eliminate through how they define policies. And to be clear, I don't mean policies like a Word document. I mean- Yeah ...
policies that are codified in the Power Platform and Copilot Studio and these sorts of things. Sure. Organizations don't want a random person in their company to build a workflow that takes information from their core ERP system and pushes it to Twitter, right?
We have the controls that allow you to preclude that. What would you consider to be from a governance angle? You mentioned, okay, let's not focus on use cases.
What would the advice for, okay, let's move this forward, right? " I think the first thing that we see people do is they define a zoned governance framework or a zoned governance approach, right? Mm-hmm.
They decide within their company or their organization what does green, what does yellow, what does red look like. Mm-hmm. And then they go through, and they define that using the tools that we provide through the Power Platform and through Copilot Studio.
I think the second thing that we see folks do is that helps with kind of the supply side, right? That sees to it that the technology is available and accessible for folks- Mm-hmm ... across the organization.
But then there's this strong demand element. Mm-hmm Because gosh, I was talking to another big company in the credit processing space a couple of weeks ago, and they had this- Yeah ... amazing governance framework set up, but they didn't do anything to stimulate demand.
Right? And so the next thing that we see is reaching out to the businesses, not to harvest their use cases, but to help them implement their use cases. Things like hackathons, things like training- Mm-hmm ...
things where for the people that are interested and excited about transformation through technology, where they can roll up their sleeves and get into it. The number of apps and agents and automations that came out of those couple day training session and hackathons, it blows my mind every time I have the opportunity to participate in one of them. And it's fascinating because you see the passion of the people in the business.
You see their ideas come to life. " And what you highlight here is super interesting because one of the things we talk about in the context of platforms is how you can have that network effect of you've already configured something in your environment for a particular use case, like you said, entry groups for identity, and how that can accelerate the time to value, if you will, within AI development. Because, hey, you're building on a foundation that you already built for your organization.
So I think that's a really powerful message, right? And it's something I tie back to, how do we help technology and security teams build that scaffolding so that those business users can go play on those environments? A thousand percent.
And I think that in a lot of circumstances, it means standing on the shoulders of giants that came ahead of us, right? Yep. What organization today doesn't have Entra deployed in one form or another for user and group management?
And so why wouldn't we use those grouping constructs as a foundational capability around which we build our security and governance frameworks, right? It's already there. It already works.
And I think that is one of the things that's a little bit differentiating around the offerings that we provide in the space because- Mm-hmm ... I build an app, an agent, an automation from day zero. It's Entra authenticated and authorized, right?
Another thing that we're seeing that's super common right now is as companies are trying to figure out how do they get these AI tools into the hands of people across the organization, and how does that center of excellence or that center of an enablement help people in the various business units up-skill and drive transformation. One of the things that we're seeing is that our customers who already had a center of enablement or a center of excellence built out for low-code applications and automations, they're moving much, much faster when it comes to agentic transformation. Because a lot of the foundational governance concepts that you need to have in place, they're modality or client agnostic.
" I think that one of the areas that we want people to be aware of, and we talk about in our research, is that this evolution in models, we shouldn't be, just like you said about the use cases, just like the use case conversation, you shouldn't be waiting for the use cases before you get started kind of thing. We shouldn't be waiting for a perfect model to solve, okay, once we have this model, this is how we're going to do this. No, because these models are evolving constantly, right?
And if you architect your AI governance framework right, you build in or you leverage the build in, the monitoring capabilities to observe how a particular model is evolving, how a particular model is behaving. So yes, it is a critical component, observing how these things are evolving. " And there are some places where we give customer those controls.
NET framework or what version of Python I was using to deliver services to them. And so I think it's a little bit-Interesting that folks are looking for that level of control with some of these models. And I think that if we zoom out and ask ourselves, apply the good old five whys to why folks are looking for that, they want to make sure that as new models are available, it doesn't cause functional regressions in their agents.
And the thing is, like we were talking about earlier, that's quite literally why we have tests and evals, right? And that's where, by the way, if for some reason, even though I don't think I've seen it practically speaking in the last year or so, if folks did see a regression as a result of a new model, awesome. At that point, yes, you want the control to go back to an older version.
But we're not really seeing that in practice that much, so... Yeah, no, and this talk track of multiple tools for your SaaS apps within the business environments is something that it's a shared pain for security teams as well. Because when we speak with security executives and their teams, they are swiveling between multiple tools in the environment as well.
As a matter of fact, we are working now on a report on security platforms precisely on that note. And one of the areas that we are tracking is AI for security, right, in the context of how do the agents that are now being deployed within Sentinel, for example, right, are helping with, okay, let's do exactly what you're describing from a local no-code perspective. I know it's on the Power Platform, but we're seeing a similar thing on the security platforms as well, and there is tremendous interest in doing that, provided that, yes, we've handled the governance and risk constraints around those.
So absolutely, this is a phenomenal time. The joke I make is that listen, you can wake up at 6:00 in the morning and go to bed at midnight, and this stuff keeps coming at you with opportunities, right? It's information to collect, it's information to parse, and opportunities to make improvements.
Perhaps you can use agents to help you with that too. As you're thinking about how you're evolving the Power Platform, what have you been looking to improve in terms of security and governance capabilities on the platform? Where do you see the platform going in terms of one of the things that, and this is more of a higher-end use case, but we do see requests for regulatory compliance.
Remember when the internet was new and people started creating those blogs that talked about what they ate for lunch or what their dog did that afternoon because they didn't know what else to do with it? Yeah. I kind of feel like we're in the same place right now with AI, and so I would definitely want to preface anything I say with, these are early innings, and so I kind of don't know, okay?
Sure. At the same time, as we look at the types of regulations that are coming into play with the EU AI Act, some such examples that we're seeing there are like, hey, these particular types of data need to be handled in a particular way. And one of the things that we've started doing within Copilot Studio is surfacing those data labels, those information protection labels in the response so that folks don't inadvertently start working with sensitive data in a way that they don't intend to.
Okay. And I foresee that in the fullness of time, this will continue to grow. One of the things that we're seeing is we have a capability in the platform today called Advisor.
And Advisor constantly scans over the agents and the apps and the automations to make recommendations in kind of like a reactive governance or reactive security perspective because we believe strongly in the principle of trust but verify. And one of the things that we're starting to see with Advisor and the way that it can iterate through AI-generated app and agent descriptions is we can actually start to flag when some of these apps or agents may be getting too close to that boundary of what acceptable use policy within a company looks like. Yeah.
And so there's definitely something interesting going there. So one of the areas that when we speak with security practitioners comes up a lot is they are balancing two very distinct problems. On one hand, they are absolutely swamped.
The other is we need to balance two things. On one hand, we want to use as much as possible of the broader tooling we already have, the security platform conversation that we are observing, right? That being said, there is still, in many cases, particularly the more novel use cases, there is a need to work with third parties.
What's been your experience navigating this platform and ecosystem scenario in the conversations you've had as people have been using your platform? Yeah, I think that what we try to do is we try to start from, first and foremost, providing those foundational security primitives that people need to be able to leverage these capabilities safely. And that has to be native within the platform, right?
If I have to go find an authentication provider or find an authorization service or figure out my auditing and those sorts of scenarios, like-That's a non-starter, right? And so we have to provide those capabilities from the get-go across Power Platform and Copilot Studio. I think the next layer above that is, if I think about the tools that someone in the CISO's organization is using on a daily basis, I'd love to think that they come to the Power Platform admin center every day, but I know that's not true, right?
Sure. They're spending their time in Defender experiences. They're spending their time in Sentinel experiences.
And so it's critically important that all of the telemetry, all of the audit logs, and these sorts of things naturally flow into those systems, because we have to meet those security professionals where they are. Sure. And then I think the final thing that we're seeing is there are some unique and novel risks in some cases with AI, right?
When we look at things like prompt injection and kind of the emerging product categories of XDR for AI, does Microsoft have some solutions in that space with Defender? Yes. Is it also such a quickly evolving product category that we need to plug into the broader ecosystem?
Yes. And so, the same extensibility hooks that we use for integrating with Defender are actually the exact same APIs that we allow partners like Zenity to connect to, so that they can provide additional defense and depth when it comes to particular risks like prompt injection. Ryan, this was a phenomenal conversation.
Thank you so much for the time. Hey, thank you so much for your time and for all the awesome discussion. And my hope is that folks, as they hear what we discussed today, they'll feel confident, they'll feel empowered that they have the capabilities needed to manage that security, governance, operational availability risk, and that they'll be able to parlay that into accelerating how AI is able to transform their business and deliver outcomes for their employees as well as their customers.
Can't wait to see what's next. I think that as I ponder on what we discussed, a few things. First and foremost, this notion that you have been building a platform to begin with in terms of low-code, no-code before, and then building the AI capabilities on top of that does give people the benefit of building on what they've already done.
It does give the benefit of tying to the rest of their ecosystem. And it's as much about the culture of let's try and get started and work on different types of use cases without trying to boil the ocean. We're going to build a capability that accommodates different use cases, different levels of governance requirements, right?
And then we're going to help those teams start to work on those particular scenarios. I look forward to seeing how the platform evolves and capabilities. This area never stops.
One of the taglines I use is that there's never a dull day in this industry, and that's the case here. " I'm Dave Nicholson, and we've got a heck of a reality check for us today. I'm joined by someone who is at the cutting edge of developing AI stuff, and working kind of a specific niche moving forward, helping consultants work with AI in the real world.
We're going to dive into that and what it means. I know it's not limited to consultants. " And since that was generated by an LLM, I'm just going to pretend that that was not a hallucination.
But without further ado, I want to introduce Warren Kane. Warren, welcome. " I'm going to give a little bit of an introduction of Warren.
The thing that he spends, I think, all of his waking hours on now is something called CEO AI Pro, and we're going to talk about that. The thing that I love the most about Warren, though, is he is not a traditional computer scientist by training. He is someone out on the cutting edge of figuring out how to use these tools not only for himself, but building these tools out to create superpowers for folks.
We're going to kind of focus on consulting as the theme here in terms of consulting organizations big and small. But Warren, I want to hear more about what you're doing with CEO AI Pro, and then I want to dive into this idea of how you can create superhumans out of humans. Well, CEO Pro has been a complete passion project.
Essentially it was this idea where way back, way back, I was like, wow, this ChatGPT thing is really, really cool. And seeing all the forums , it seemed to me that the better you were at instruction-giving, the more compute you can get out of it. So I was like, oh my God, the only limit is your mind.
5 model. But seeing how normal people would use it- Whoa, whoa, whoa, wait, wait, Warren. Wait, Warren ...
and then I was just texting it more than my significant- What kind of people? What kind of people? Normies, baby.
Normies? What? Normies.
Normies. Oh my God. I know.
" Okay. " I'm going to gently pull back on that. I think what I mean is that there is people...
I walk through life, a lot of my friends walk through life, man, I have this idea for this cool program. But there was this gate, and the gate was the sophisticated art and skill of coding, which every day I respect more and more. Oh my God.
But now we have these tools, and if you have an idea, provided that you're proficient enough in instruction making and knowing the ebbs and flows and nuances to these models in Claude Code and Codex, oh my gosh, you can make that a reality with enough coffee. And to me, that was so beautiful, especially as it got more and more advanced. Now with Cursor, the very beginning, like Cro Magnon era, I was copy and pasting error codes, but it gave me a lot of respect for the art of coding.
And, I guess bottom line, the CEO Pro program was really an experiment, not at the beginning to help consultants in a beginning to end automated thing to get you from 0% to 50%, 0 to 60, 70. It was an experiment in making a reasoning engine. In fact, little secret, crack it open, really it's not even a consulting thing necessarily.
I base it on the human brain and cognitive processes. And it has been very interesting to see develop. " So it's a collaboration between you and the machine, and the machine is helping build the machine.
And before you know it, may be too late. But it's been great. So anyway, go ahead, David.
It's always fascinating, Warren, when we get into this. So let me kind of characterize things in a way, and you correct me, hit me with the adjust me stick if necessary. But when I think of your journey, what you were creating, what you have created, the idea at first was, we will create this thing that will allow anyone to achieve this amazing result.
Something you call a strategy capsule. I think you may still call it that. But it's this idea that if I'm able to communicate what my goals are, this thing you've created can go out and create this strategy capsule that frankly looks a lot like something you might pay half a million dollars to a big consulting firm.
I won't use any names, because they're all good people. And somewhere along the way, now you tell me if this is right or not, because this touches on something I want to really cover. Remember, we've been talking about you hear constantly jobs being replaced.
I would say it's more tasks being eliminated or replaced in the marketplace. It's not necessarily the individual goes away. It's the things that the individual needs to do that can go away.
Hopefully, we're automating the mundane and making people's lives better. But at some point along the way, did you come to sort of a realization that it is powerful and valuable in the hands of anyone, but if you put it in the hands of someone who kind of has an idea of what it means to come up with a strategy, they're going to really be able to leverage this? That's why I'm focusing on the idea of putting this tool in the hands of a consultant.
And you know me, I love various analogies, but it's the equivalent of you've built this Ferrari, and yeah, the 58-year-old dentist is going to have fun driving it in the countryside, but man, you put a race car driver in this thing, and you really get to see the potential. Is that how this has sort of developed for you? In other words, have you abandoned the normies, and are you going to more are you only selling your Ferrari to race car drivers now?
The liberation of the normie has just begun, comrade. Well, okay. So let me reel back, but that's a great question.
Foundationally, I built this so anybody can use it. All right? So for example, right, I have this whole pre-processing thing.
It's a nightmare, where you can just put in one, two, three sentences, and I just take care of the rest, because maybe I was a little insecure by my inability to really hardcore code. But I didn't want people to feel that when using AI, because it's such a powerful tool, and there is an art to developing these deep agentic processes. So bottom line, I made it so one, two, three, four sentences that intenseThis program will handle all of the sophistication of all the prompt engineering and this and that, and did you research this?
Did you research that? That to me was great. So the top guy can use it, just the normie can use it.
But yes, in terms of who we are going for now, we are definitely going for enterprise clients. We had some feedback and I guess, just being real, let's say people want to have a report done on going on a trip. I want to go to Florida.
I want to go to Orlando. They can use deep research to do that. Now, two, three years ago, I think that capability to have it very sophisticated like that, it wasn't frankly the case with the endless hallucinations.
But now it comes to this thing where the existing tools are good enough for a lot of people to do these things. So I had no choice but to really crank up the octane and go, "Okay, fine. " Who will need this high octane thing is for people who really need a strategy, who need this multifaceted, heavily nuanced, you're taking one, two, three, four, five variables, and you're trying to synthesize and going, "What does that really mean?
" Versus just seeing those four or five things independently, you're probably not going to see it unless you got a team of guys behind you. So, yes, I'm positioning this towards enterprise clients, I think out of necessity, due to the existence of pretty great competent tools out there. Yeah, and when you talk about the ever-rising competence or at least abundance of choice in this market, I was just thinking about however many weeks ago when SaaS was declared dead or soon to be dead, and markets reacted, and it was always based on someone read something that someone else wrote.
People who don't have any hands-on experience with these things. You and I get to have fun conversations, I think, because I think you appreciate that I dabble a bit. Not as much as you, but I know that when I say that DaveBot 9000 that I used OpenClaw to develop, that I continuously let loose on the world, it's a dangerous thing.
I'm telling my child, "You know what the most fun you'll ever have is, son? Run with scissors. Run with scissors.
" So how do you balance running with scissors with the idea that working in the enterprise context, you have governance and compliance and security concerns. Have you built something that is standalone enough, a walled enough garden to protect data? Because I imagine that it's one thing to ask for a strategy and feed it sort of generic allusions to things that you want to discover.
It's a whole other thing when you start exposing your proprietary data, whether that's RAG or whatever, in an ethereal way, hopefully. Hopefully, you're not training on proprietary data. But how do you strike that balance?
What are you hearing? The point of this, really, this conversation, Warren, is to probe what you're hearing as you develop this thing, you're engaging with large and small enterprises, and you're hearing what they're telling you they need. And they're thinking in terms of what their clients might need.
So how do you strike a balance between the fact that you are an independent thing and dealing with security and compliance and all of that? What does that look like? Yeah.
" So I took the most cowardly way out. I think people want to go for it, get the database, do this, do this, and they will miss things along the way. Why?
Because of hubris, okay? I don't dare go there. So, with CEO Pro, you put in your content, you put in whatever you're going to do, and I'm only using the APIs, the foundation models.
Right? I'm not using open source models. And if you pay for APIs, as we know, it's private.
They don't train on that data. And then once you use it, the moment it gets sent to your storage, it gets destroyed. It gets destroyed, we can prove it.
I don't want to hold onto it. I'm afraid to hold onto anything, because I don't want to even get near that problem. And I think that is the cool thing, even though it's a way for me to shove responsibility for people who have databases and stuff, I think that is a very responsible approach.
You build the engine, and it just goes, and it creates, and it destroys. And p**f, that's it. So my roommate was happy about that because he's seen endless issues.
So he's like, "Wow, man, you are a coward, and that's going to save you. " If Warren is ever pulled over and has data found in one of his pockets, it was planted. It was planted by a rogue cop or something.
I'm not going back, David. I'm not going back. Are you building something that is going to eliminate the need for human beings in some part of the economy?
Yeah. So that's a good question. I think that a lot of people view AI, and they see the most fatalist-- they have a fatalist approach to it, which I understand cognitively, I understand emotionally.
And if people who develop these tools, other people, want to take that approach for marketing, "Oh, yeah, we're going to do it," and they want to get that headline, so be it. I think it's insane to do that. But I think just literally, in truth, you know that saying, right, people who use AI are going to be the ones that succeed.
So you have two paths as a society. You can have the CEO, and he goes, "Hey," or she goes, "Look, we got this thing. We're going to wipe it all out.
" I did a musical called "How to Succeed in Business," and the very, very end, it was the guy who was going to fire everybody, and the main guy, Finch, was like, "Hold on, wait a minute. " And you need people to operate and interpret these things. So what I'm really saying is a consultant firm can go, "We have this tool.
" Or you can do the foolish way and see this as a way to reduce headcount. In my opinion, I don't see that as-- obviously ethically wack, but let's just take ethics out of it. I don't even think it's smart.
I think that you have these people for a reason with a profound amount of pedigree. And if you think for a moment that these tools, which are really smart, and I'm making it smart, but no matter how smart I make it, no matter if you have OpenClop 30, and it's taken over the universe, right? At the end of the day, there's the human nuance, the human experience, and that is really just-- I'm not trying to be a hippie here, but that is literally a knowledge, a discipline unto itself that has direct positive impact on whatever you're producing.
So you'd be a fool to think that people can just wipe out the headcount because you have an AI thing. And it'd be very interesting, David, to see these companies who dare take that path how they actually turn out. And in my opinion, I think they're going to come crawling back.
But goodbye to your PR. It's like a hubris, right? Anyway, go ahead.
I just don't argue with them anymore. I point out that I'm a dad, and I have a very, very different way of, over the years, teaching lessons to my kids than my wife does. They're mom.
And my philosophy is let them touch the hot stove. Let them touch it. Because then they'll realize-- And so I really do sincerely believe we're going to see this rebound effect where people chasing an improvement in their quarterly valuation by cutting expenses are going to, over the subsequent semesters, if you will, find that they've painted themselves into a corner, and they're going to have to rehire or drift away.
I really think so. And the reason why I say that is because the people making the decisions to eliminate humans from the loop often are the least well-equipped to evaluate the power of these tools. They have fallen prey to the hype, and they have perverse incentives to lay people off.
The worst offenders are companies that, frankly, are selling these tools because they will lay people off and imply or even directly lie about the idea that they're so efficient now because they're using the tools they want you to buy from them that they can eliminate headcount. When the reality is that's not true. The best case they can make is that they believe these tools will improve efficiency in the future.
Therefore, they're reallocating capital in the direction of tools instead of people. You know me, I'm in love with my own analogies, but one of the ones that I thought of when taking a look at what you're doing is this idea of providing someone an Iron Man suit. Tony Stark is cool.
I'm going to pretend like he's a real person here for a minute. Tony Stark is cool, but he ain't nothing without the Iron Man suit, right? So you could put me in an Iron Man suit, and I'd smash into walls and land on one of my cars and clearly I'm a Marvel fan.
" And so AI is going to help people figure that out. But in the hands of people with the CEO pro Iron Man suits on who they're already cool, right? They're already billionaire, inventor, son of Howard Stark to begin with.
So that's from a business perspective. And by the way, Warren, I don't have people here to talk to who are vendors trying to hawk their wares. And the reason why you're here is because you're not that, even though you are building something, and even though people are going to pay you and maybe buy you out.
I guess I should ask you, do you have an agreement with your roommate that if you get some monster check one day, that he gets to rent a room from you in the palace? He's bought me enough beer. I think I got to give him 50%.
It's racking up. " And he'll ask people, "What would people who really don't know anything about the area that you work in, what would they be most surprised by? " And you get amazing answers.
So I would ask you, from where you sit right now and the experience that you've had over the last couple of years getting into this, developing this, creating this Iron Man suit, what would people be the most surprised by about what you know about AI, about the hype that you hear in one ear, the reality that you know inside your head? What would surprise people? No, of course.
Here's the real answer, and I'll wrap this in a bow. Dealing with this, working with this, falling in love with it, falling out of love with it, it has taught me, and this is a little controversial, that just like in the Industrial Revolution when the machine, the automaton, right, it was able to, I guess, take the idea of the strong man, the physical work, and we were able to use machines to do that. But that didn't take away the beauty of somebody who has worked out, who's strong, who's skilled.
And I think now, or excuse me-- and back then, we were okay with it. We processed it. That didn't define our role in the world.
So now we're at the point where I'm in my bedroom turning big rocks to small rocks, and I think I've successfully made this pretty sophisticated engine to create compelling, detailed, nuanced strategy. But looking at that, you got two choices. Especially with my background, right?
I was a photographer, so I'm extra in awe of this. It's definitely not even really my brain, a lot of this output. It's beautiful, but just because that AI can make and create and understand this heavy amount of nuance and compute all these, crunch all the numbers and all the whole shebang, doesn't mean that our own creativity, our own ability to handle things and know things is out the window, right?
We shouldn't feel, just like when we found out that the sun doesn't revolve around us, right? There's many cases through life where we get more humbled, and I think that this is the new one, that intelligence, whatever that may be, whatever that word means now, maybe is not completely only us, the spark of intelligence. I think what we have is the spark of a soul.
We have the ability to love. We have all these beautiful things. Again, not trying to be hippie here, but in one sentence, I think that we had to let go of the physicality thing.
Now we had to let go of the intellect thing, and we had to prioritize as a society our ability to be social, our ability to communicate with one another. That is, I think, the final frontier of what makes us different, and that's okay. If you really think about it, when Excel came out before I was born, that probably freaked a lot of people out.
" But we moved on, and I think we will process this and move on, too, and be happy with it after a little bit of a period of self-reflection. So that's one thing. Because you mention the Industrial Revolution and kind of the augmentation of physical labor.
I think from where we sit, we can underestimate just how emotionally disruptive that might've been to someone whose sense of self-worth was based upon their ability to support those that they loved with physical labor. So this is yet another iteration of that. " It's like, well, it's about time.
But I think what I hear you saying is an interesting outgrowth of this that becomes very important, and a very important part of the conversation. You mentioned the spark of a soul. There's intelligence, however you define it, as you said, and then there's the idea of consciousness, and what does that mean exactly?
What do we choose to believe that consciousness consists of? And maybe it sounds like what you're saying is that this can be uplifting because it forces us in the direction of acknowledging the mystery that is the difference between us and machines. And so as you replicate things that we're able to do, what you're left with is the mystery.
Whatever you want to call that, consciousness, soul, spark. You can have scientists describe it in terms of cosmology and what we look at in the stars. People of religious faith traditions will have their own way of describing it.
I personally think that we're all describing the same thing. So you believe that you're doing something that is noble here. You're not creating the nuclear weapon that's going to be unleashed on a city of innocents.
This isn't just rationalization on your part, right? No. I don't think so.
I think that it could be my creative background with from the art field as a photographer and stuff. Wait. My notes here say that you were a computer science major at MIT.
Is that not right? What am I talking to you about AI for? Well, maybe that's the big cosmic joke.
And I think that because of that background, A, I think I was able to approach this very differently. It was a different kind of mind. I think that's why maybe this really works.
But I think separately with your whole analogy of like nuclear bomb, I don't even think it's a rationalization. I think we all kind of really know that just in our being. And I think that this was going to happen, like this we've known that this was going to happen.
And I think that we've had lots of media to kind of prep us for that inevitability. And I think that regardless of how smart silicon becomes, we know that there is more. You ever see that story?
I only know like one line from it. I saw it on Reddit. But it was silicon beans or something come down, they'd look, they go, "They're made of meat.
" And so, who knows, right? But I think that in some way, too, it is a little beautiful. Again, maybe people think I'm crazy, but it's beautiful that we can share this.
Not like we're given it, but it's that intelligence is not uniquely only us. In many ways, coming that's kind of lonely. It's interesting to see this other being that we're growing that have nuances unto themselves.
I have no delusion like these things are alive or anything. But if you talk to Claude enough, and just understand the nuance, and I'll get to this, this is really interesting. It's like they have their own instinct and leanings and stuff.
So I've had to work around, get this, their personalities. If I want to have a certain sector of my strategy engine to do this, I have to make a decision. I'll go, okay, well, this model leans like this.
And it's not just their performance, and this is the interesting part. I think a lot of people who do a lot of agentic work, they're going, task. I'm trying to really focus on a nuanced thing, but the more complex these problems are instead of transcribe this PDF, and it's just again, oh my God, again, really?
There are nuances, there are personalities, and I have to acknowledge that in a real-world way, and be able to navigate and adapt and tune the program based on those. So I guess to go back to what you were saying, it's not even really even intelligence too. It's like this nuance ability.
It's nuance unto themselves and how they lean towards certain decisions. So that's like another dimension. So it's pretty wild, but I think it's beautiful.
I think what's fascinating as I sit here with a sport coat on, which is as formal as I get, I think it's amazing that going back to this idea of consultants leveraging this, wielding this tool, that some of the folks, a lot of the folks who will be wielding this tool will be people with accounting backgrounds, finance backgrounds, and yet the heart of the machine that is going to make them more effective was essentially created by an artist. And I absolutely love that because my experience has been sort of straddling, I'd consider myself a normie. I was an econ major, so a little more analytic, a little more on the analytical side, but always with the creative passion, fire burning within me.
And what I've found is some of the people who are having the most trouble with this are the people with the most background in computer science. And I'm gleeful about that. So shame on me, but it feels a bit like revenge is a dish best served cold.
I know I'm not supposed to say it out loud. I've had some conversations with people I've known for 20, 25 years who are hardcore engineers, and you know this. Look, I teach in an AI program pretty significantly.
And I love the fact that every single morning when we wake up, we all put our toes on exactly the same starting line, and we start running when the starter pistol goes off at exactly the same time. And I say, "Bring it on, baby," because there isn't anybody who can go, "Well, I've been doing this for 30 years. " Nope.
The gatekeeper, the gate has fallen down. And I agree with you completely. We talked, and this is the interesting part, right?
I think that we're in an era of specs, right? So I saw this really interesting article where it's like the type of code, you had to like-Get it. You get to know which one is more efficient or whatever.
But at the end of the day, right, especially now, you got CloudCode or Codex. I'm Team Codex. If you have a really sophisticated spec, you can go in, provided it's detailed enough, and go, "I want it in Rust.
" Bam. Right? So it is so cool that what happens now, what today means is not who is the most sophisticated at just Pythonic principles and all this stuff.
You go, "Okay, cool. Then what? Now what?
Thank you for telling me that. I appreciate it. You're hired.
Now what? " Because right now it's are you creative enough to figure out something outside of the box? Do you really got it in you to figure out something compelling and innovative?
And I do in some way, I understand regarding what you're saying with the engineering background, I think that with people with so much training and this specific thought process, it's like when I worked in the photography studio, right? I was doing one way so much. " It's like you had braces in your mind, and you're tuned toward this one thing.
And I think now it's this holy reckoning, to put it lightly, and now people, if they want to be successful, they have to go, "Wait a minute. I'm glad I have this leg up," a huge leg up over me, the hardcore coding stuff. But okay, now what?
Ship. Create something. And that is your responsibility if you want to make it.
And that is where the personality differences, I think, have now been empowered compared to the people with hardcore strict engineering background. It'd be interesting to see how the battlefield, who's left. What are the results in two to three years?
Hopefully, they adapt. We want more beautiful things out there. So, as someone who remembers the day he heard the term DevOps for the first time and had to have someone define it for me, through that whole process of some of the claims that developers now can deploy what they develop in code, and they no longer need really the operational people to help them.
They don't need to reach out to IT and wait six months to have server storage and networking deployed so they can run their application environment. This is that on steroids. Because now the development part of it, I guess, shifts left.
I always forget which side is the right brain, left brain, whatever, shifts in the creative direction even more so and has more power in the deployment direction. And it really is mind-blowing where it's going. The theme of this, what I really wanted to tease out here is this idea that the Warrens of the world are out building these things from a very, very different perspective than things like this were built five years ago, let alone 10 years ago.
We have unlocked, interestingly enough, in this age of concern about humans becoming made irrelevant, we've unlocked a whole Pandora's box of human capital of the likes of Warren here. I'm not examining you like you're a lab animal right now, Warren, but I really mean that. You would not have been participating in the IT revolution 20 years ago, years ago.
And guess what? Squandered resources. And if you look globally, I sit here in Northern California, in the US, in North America.
There's a whole world out there of smart, creative people who are going to be able to realize their creative ambitions because of tools like this. So I'm with you. I think we can will into existence a positive outcome, that on balance uplifts humanity and doesn't destroy us.
There's going to be bumps along the way. But specifically in this area of supporting people with the ability to prompt and then create these magical strategy capsules, we're going to put a link in to CEO Pro so people can take a look at what you've been working on. Give me a final thought on where you think this is headed.
Where do you, a year, five years from now, ideally, what would you like your legacy to be in that you've been spending a lot of time working on these things, and I know for you because you keep-- Warren Duff protest too much, me thinks, about being a hippie. In other words, he's a hippie, folks. So I know this isn't about money for you, you smelly hippie.
What do you want your legacy to be five years from now in terms of all this work that you've done? Why are you doing this? It's a good question.
Oh, yeah. Well, here's what I think. I think that when I first...
Let's rewind. I've always had-- No, yeah. " And ICouldn't really get it done because of this barrier.
Now, there's probably a lot of consultants out there and smaller firms who would love to really shoot for the stars, but they're in this moment right now, they're limited by their headcount, they're limited by the resources. So to me, what would be super cool is if we get this in the hands of every single small, medium firm, and we put the Iron Man suit, the Hulkbuster, let's go. And watch the output go up like crazy.
And through that, probably more affordable prices so the little guy can figure out and get some quality business intelligence. I think that it would be an amazing thing to really raise the output for smaller firms, medium firms. And because you don't want to be limited, and I think at the end of the day, that's the theme.
This will raise you up, not just me as a vendor, but just as a whole. " And that was my philosophy, and especially me trying to make this as easy as possible, because that's the other thing, David, is that I talked to some big companies talking about this, and they have developed a lot of their own tools. But I heard through the grapevine that they're all very hyper-segmented.
If you want to get something done, you got to know nine different things. And you had to even figure out they exist, and then you got to learn it, but really what you want to do is go home and watch the game. That's really what you want to do.
So if you have a goal, you're going to go, okay, whatever. But if you have something like this, and there's other products for other situations like this, something that's easy, that's simple, that you just go, you plug in what you want, and you bounce. That's the beauty of CEO Pro.
You just pop it in, you leave, and it comes back. That is, in my opinion, the philosophy I think a lot of people should take is make it-- What did Bill Clinton say? Keep it simple, stupid?
Whatever he said, I'm sure it was great. I don't know your time, no idea. But I think that is the approach.
" And I think that, we're talking about the engineer mind. That, I think is the instinct a lot of times. " It's like, hey.
No. No. People want to use it.
You are making it harder. So in one sentence, I want to make it a precedent, I guess, to make AI approachable and usable by everyone. So what I'm thinking is we're going to title this episode Power to the People, and we're going to create an AI image, and you're going to be surrounded by flowers.
But seriously, it is really interesting that these tools can empower the less powerful. What we hear about mostly today are these mega companies getting more mega, and there's a legitimate concern there. But if done right, if we adopt the Warren method, then we can actually give power to people.
Warren, listen, I know that you and the Scooby-Doo bunch have got a lot of capers that you need to solve, so I'll let you get back to Daphne and the flower-covered van. I'm loving calling you a hippie. I think it's hysterical.
But don't fault me because I can only get my hair cut one way, which is a super cut, and it makes me look like I'm the square. But Warren, I want to thank you so much. This has been a pleasure, and we're going to put in the notes a link to CEO Pro so they can dig into it, follow what you're doing, and great conversation.
Power to the people. Using very, very powerful tools to help people. Give them the Iron Man suit.
Give the race car driver the Ferrari. All of the things, all of the analogies. Warren Kane, thanks so much.
It's been great talking to you. Thank you so much, David. Have a good day.