Techstrong TV March 6, 2026
Post-Quantum Cryptography Becomes a Board-Level Priority: Qrypt CTO Denis Mandich warns that the threat of “Harvest Now, Decrypt Later” attacks and the potential to forge code-signing keys means organizations must begin migrating to post-quantum cryptography well before a projected 2029 deadline.
AI as an Advisor in the Mainframe Era: Anthony DiStauro of BMC Software explains how organizations can prepare legacy environments for AI by integrating institutional knowledge, real-time data and governance frameworks to ensure trustworthy adoption.
Taming the Technical Debt Snowball: Ron Browning, CEO of Dyna Software, warns that rapid development and “vibe coding” in platforms like ServiceNow can accelerate technical debt unless organizations enforce strict governance and prioritize configuration over customization.
Patterns of Success in Operationalizing AI: Microsoft executive Michelle Lancaster outlines how enterprises are successfully scaling AI initiatives through apps, agents and chat interfaces that deliver measurable business outcomes.
Modernizing Brownfield Data Centers Without Downtime: Nokia IT leader Ahmed Abutaleb explains how the company migrated legacy environments into a modern architecture built on Nokia SR Linux and Nokia Event‑Driven Automation while maintaining uninterrupted application services.
Security Beyond AI Models in 2026: A Tech Field Day podcast discussion highlights how identity security, browser protection and governance for non-human identities are becoming just as critical as securing AI systems themselves.
Inside the Bell Labs Reliability Model: Experts explain how operational discipline, automation and AI-driven monitoring—developed through Nokia Bell Labs—can push data center networks beyond five-nines availability.
AI in Overdrive: Chips, Networks and Robots: The Tech Field Day News Rundown analyzes major industry shifts including NVIDIA investing $4B in optical networking leaders Lumentum and Coherent Corp., Accenture acquiring Ookla, and Google integrating robotics firm Intrinsic to accelerate the next phase of AI infrastructure and automation.
Transcript
Hey, everyone. Welcome back here to Techstrong tv. Our next guest is Dennis Manic Mandich.
Dennis is one of the Secur Quantum Security 25 winners from our first, uh, list of the top 25 leaders in quantum security. First of all, Dennis, congratulations for making the list well deserved. And secondly, welcome to Tech Trunk TV For having me and putting me on the list.
That was a lot of fun to get that. You know, I, I gotta be honest, I was only one of, I think about five judges and, um, no one of us made, you know, a decision. It was done collectively.
But what was interesting is, you know, the, the way the process worked is first we went through our own list, then we shared that list with the other judges and the overlap from judge to judge to judge if, if I tell you, I think there were five or six names at the end that we maybe didn't make everyone's list, so to speak. And so it, it wasn't as hard as I thought it was gonna be with that amount of judges it, which I guess it, it shows, you know, that, well, it shows one or two things, either there wasn't really a lot of people to choose from or, you know, the people that we picked really have set themselves apart as, as leaders here. Dennis, why don't, and that's a great segue.
Why don't we, if you don't mind, tell people how a little bit of your journey, a little bit of how you came to be a, a leader here in quantum security? Well, I'll start with kind of the middle, which is that the reason why your list is probably small is 'cause it's a small industry. There's a small number of people who can get into Quantum at all.
And my, my background is in, I'm a physicist by background, but I spent 20 years in the intelligence community. And one of the things I saw in a couple of my last positions was the scale of IP theft by China from the US and the tools were available in the intelligence community. They were even available in some of the biggest companies, but they just didn't use them and they weren't really gonna be very helpful in the quantum era.
And so back in 20 16, 20 17, we helped stand up the Quantum Economic Development Consortium, which is the national industry organization that we have today with only a couple of dozen companies now it's, you know, over 200 companies in the space, but that's still not huge compared to, you know, computer, uh, science, computer development, quantum computing, and so on. So we really helped stand up the industry. So we're pioneers in this space, especially on the security side of it, which is probably why I ended up on the list, because there aren't that many people that do what we do.
Most people are just worried that, Hey, Q day's coming, can we just update our algorithms, update TLS and so on? And that's just not gonna do it. That's where really Crip comes in.
Absolutely. Uh, you know, and the the other thing though that we have seen as a result of going through this exercise, Dennis, is that I can't tell you when Q Day's gonna be here. I'm not even sure I'll be able to tell you Q Day's here when Q Day's here.
It may be a little while after Q Day where I can look back and say, yep, you know, Q Day is here already, but it's no longer the five to 10 years out that we've been talking about for the last, I don't know, 15 years or maybe more. It's, it's sooner, you know, it's much closer on the horizon. Where, where if we don't start taking, or maybe this is, uh, I'll ask you, should we be taking prudent steps now?
Yeah. As you said, we won't know when Q Day is. If it happens in China, we're gonna experience a deep seek type moment where they'll surprise us.
The difference here is that China, since this is very broad implications for intelligence collection and optimization, operationalization of all the data that they're sitting on already, they won't tell anyone. They'll sit on that as long as possible to protect their sources and methods. That's much higher priority than any money that they could make out of it, or any data that they could exploit for diplomatic or military purposes.
Those sources and methods are more important than intelligence collection. Absolutely. Very possible.
At Q Day, like you said, already happened, and they've outspent the entire us, all of our industries combined. We have entire facilities in China dedicated to winning the quantum race at all costs. They're gonna graduate tens of thousands of physicists to do that.
And we're, we're behind in this race, and this is one we really can't afford to lose. Sounds like a rosy picture. You know, it's, it was a tough news weekend, Dennis.
Go easy on us. I don't have good News in this space. Yeah, I mean, but but that being said, so look, I'm a, I'm a believer in global progress and, you know, I think we're past the, the, the juncture where something pioneered in one country stays in that country, right.
I, I think, I think in sharing information is probably the greatest thing the internet has done. Whether, whether you put up a firewall or, or what have you. Information wants to be free at some level and somehow it makes itself out there.
Um, talk to us a little bit, you know, so your background as you mentioned physicist and and intelligence, and talk to us kinda how you came up with the, you didn't wake up one day and say, God darn it, I want to co-found a company. No, No one does. Um, and I've done a few of them myself, believe me.
But tell us kind of the, the origination story, if you will, for crypt. The always, um, in these interviews, I quote General Alexander, who's the head of the NSAA little more than 10 years ago, and he came out and said it, look, this is the greatest transfer of wealth from one country to another in the form of IP theft. And we don't know if we survive this as the world's global economic superpower, but you can only give up so much of your industry to another country before you become second.
And I, my position is I three kids, I don't want them to have to work for Huawei one day. And so I felt that we had to bring something to market that would really solve this problem that, you know, the intelligence community enjoys extraordinary, powerful cybersecurity tools, encryption technologies that are not public, obviously. And we want to bring something like that to industry that would really solve this problem once and for all.
I don't think people realize that the cryptography that we've been using and that we're about to upgrade is 1970s technology. It was made for telecom networks and infrastructure when a handful of copper wires and switches connected people, not the world we live in today. And that's really what we wanted to do.
We wanted to bring something that even if this next generation of algorithms completely fails, which is likely we're told to be crypto agile, they'll likely be replaced in the future. That's no consolation for anyone whose data has been harvested and will be exploited at some point. So we need to solve the architectural piece of changing the way we do business in cryptography.
And that's where it really crip comes in. So you, you, you wet my list. So there, where do we, so what exact, how, how exactly is Crip doing this?
How's it helping us? So in, in the past, we always bundled the encryption keys and the data together in the same channel. So you've probably heard Harvest now and decrypt later.
Yep. On of Q Day. Well, that's been going on for generations.
Not has nothing to do with quantum meters. And the fact that you can do that at all to capture that data in an encrypted state and exploit it when a flaw is found in the way the libraries were implemented, the way we generated keys, the random numbers used for those systems, and then it's all packaged together to be able to decrypt in the future. At any point, when someone at Black Hat reveals a vulnerability that they discovered, that's not a good situation to be in when we have many other tools available to eliminate that mechanism entirely.
So if you think about public key infrastructure, the way we send every H-T-T-P-S session, every, uh, email, every text message that we do that is based on that older technology. And all we do fundamentally is distribute encryption keys in that channel. And what crypto does is eliminate the key distribution mechanism and we replace it with simultaneously generating keys at the end points.
So the keys are never in the channel and they're not correlated with the data. So even if somehow you're able to break any of those channels, it doesn't help you with decryption. So we eliminate the harvest now, decrypt later problem, even if these next generation of algorithms fail.
That's high level how we do it. Excellent, excellent. Um, Dennis, you mentioned before, who knows when Q Day comms, did it come your advice for people out here who are grappling, wondering, I mean, obviously use Cry, right?
But beyond that, you know, what, what, what's your best advice for folks? I think it's, it's collectively, you know, we're all in this together, and especially in your company, this isn't the CISOs problem or the CIO's problem, it's the entire company's problem. It could be an existential threat for many of these companies.
So treat it as a transition that we absolutely have to do. That's table stakes. But start looking at cybersecurity in general.
The, you know, where are the crown jewels of my company and how to protect that as a board level decision. It's the C-suite and the company, it's responsible and the board should force that on their own companies. But broader, the US government has already said, look, if by 2030, in some cases, 2035, if you have not at least transitioned to post quantum cryptography, you can't do business with the US government.
They're a Fortune Zero company. So it's incumbent on people using these tools and people building them to get on board with this. If I'm buying, you know, Microsoft Office or Zoom, I'm gonna demand that they tell me what their roadmap is for post quantum cryptography and what other security protocols will you implement to make me and my communications more secure.
'cause I shouldn't trust anybody else anymore. Agreed. You know, Dennis, one of the things I've heard from companies and talking about this is, well, you know, we already have quantum proof algorithms for our certificates.
Our RSA kind of encryption. It'll be, it'll be okay as long as we upgrade to these post quantum algorithms and and so forth. You know, this is like Y 2K, we're going to get all spun up about nothing.
What do you say to those people? Well, I mean, even this just told us, look, we don't know if these algorithms are secure at all saying that they're quantum secure, quantum safe. We don't know that that's true because we Haven't had a quantum computer to write on yet.
Now we might not even need one because of the two finalists that were in the NIST competition for standardization. The other stronger one was broken by laptop, computer by discovery from math that was in a paper in the 1970s and eighties. Oh geez.
So unfortunately, the Pqc album that were transitioned, there's no proof that they're secure at all. We're just hoping that, and since no one's broken them yet, that they will endure for some period of time before AI figures out how to do it. Or even a bigger quantum meter comes online.
That's a, a much deeper issue, which goes back to the heart of harvest now and decrypt later, which is we do not know if any public key infrastructure system can be made secure. So that's where cryp comes in, is really eliminate that entire model and change the architecture of the system so we don't have to rely just on a little bit of math and a handful of cryptographers who put it together to get security at all. Agreed.
Agreed. Well, you know, with everything else going on in the world, there's one more thing we could throw on the, on the pile. I'm gonna put you on the spot.
Last question. Okay. When do you think this gets real?
That we gotta do this? Like now? Yeah.
Fortunately, uh, it's coming before 2030, if we're to believe the head of IPM and Google. Yeah. They've already this, it's, it's not theoretical.
This is coming faster than anyone ever thought. Uh, like you said in the beginning, you know, in the nineties we thought we had 20 years, you know, the timeline keeps shrinking every year as the increase in speed of developments grows, that timeline gets shorter and shorter. So it's gonna take a few years to get this done, so at least we can focus on our high priority data and finish that before 2029.
Sure. The cat videos and stuff, all that stuff can wait. But the really important stuff that's existential threats to our businesses has to be done now.
And again, it's not, you know, flipping a switch or upgrading library. It's a lot more complicated than that. We've never done this before.
The last transition was decades ago when the internet was tiny. We didn't have, the cloud didn't exist. We're, we're in a much different world Now.
That's extremely complex. It's extremely interlocked with other systems that we don't even know about. You know, ai now we need to get on this right now.
If we're gonna finish by 2029 for our most important stuff, the other stuff's gonna take 10 years. Hmm. You know what, we, I don't think we mentioned from people wanting to get more information on Crypt.
Where do they go? com. com.
Don't use autocorrect 'cause it'll do C-R-Y-P-T Yeah. Dot com. Unfortunately.
Uh, so I miss a lot of emails because people don't realize that's happening in their email address. But, uh, we're available on the, on the internet where a lot of the big conferences we'll be at RSA and so on. You can come meet with us there and we're happy to help you.
We'll be there as well. Hey, Dennis, congratulations on making the Quantum Security 25 list. You know, kudos to you and thanks for coming on here and talking with us today.
Appreciate it. Thanks for having me, and thanks for the reward. Nice meeting you too.
Nice meeting you. Uh, we'll be at broadcast Ali all week on the RSA. If you want to stop by Dennis Manic, co-founder, CTO Crypt here on Textron tv.
We're gonna take a break. We'll be back. Hi and welcome.
Welcome to our conversation about AI readiness in the mainframe environment. My name is Mitch Ashley, and I lead the software lifecycle engineering practice with the RUM Group. Today I'm joined by Anthony Desaro.
Anthony is Senior director of architecture for AI with BMC software. Welcome, Anthony. Mitch, thanks for having me.
You bet. Great to have you. Now, this is a three part series.
Our first part is talking about AI readiness, and the series is, uh, sponsored by BMC software. We appreciate the folks at BMC, uh, putting this on and putting this together. So, Anthony, let, let's jump right in.
So, we hear a lot about organizations needing to be AI ready, especially for the mainframe environment. Mm-hmm. At the earliest stage, what does AI readiness really mean?
Yeah, Mitch, this question, I can't tell you how many times I get this, whether it's I'm speaking at a conference or customer visit, this always comes up, you know, how do we get going? How do we, we get started with that, and it's so foundational into a successful journey with ai, but yet it's a step that you'd be surprised how many organ organizations just kind of ignore or are not even aware there is a readiness, uh, you know, playbook that, that, that they should be, uh, following. So it all boils down to, uh, from an organization perspective, you know, how do we roll in AI technology?
How do we use AI technology safely within our organization? How do we put guardrails around AI for, uh, you know, for protection against data? Uh, for example, you know, uh, from a, from a legal perspective, you know, uh, what policies and governance that we need to have in place.
Uh, we bring AI into our organization and there's all kinds of challenges around that. But at the end of the day, you know, that's one part of the organization's gotta deal with that. And then it comes down to the individual, you know, groups and, uh, departments within an organization on how they want to utilize ai.
So the first really good step in that journey is looking at AI as an advisor. Mitch, really look at it as like you would bring in a human into your organization, you know, based on their experiences and, and their background to have a dialogue exchange with them about whatever challenges that you may have. And you're gonna lean on that person for their insights and guidance based on their experiences.
Ai, that's a great first step with AI image. Look at AI as an advisor. It's there to explain, it's there to guide, it's there to recommend, et cetera.
It's there to provide knowledge and insights that you may otherwise miss or not know how to surface. So from that perspective, that is a safe AI journey to start moving your organization to. But then the other side of that is the skills of your staff itself.
When you bring AI into an organization, you wanna make sure that your SA staff is skilled in AI usage. You want to make sure your staff is skilled and understand on where they should be applying AI within the organization. So there's some education and training that need to be done for your staff.
There's guidelines, uh, uh, and policies that you need to be putting in place, guardrails that you need to be putting in place. And that's all very, very, um, very focused on individual organizations and what that means. But that's the first step, um, to get that, those foundational aspects of AI in place.
That's a really good point about having that kind of direction you want to take with AI versus it's so accessible. We can use it, try it out, but how are we gonna focus and leverage it for the organization. And you mentioned the concept of AI as an advisor, using that as your first entree into ai.
Talk about how that is different than maybe automation, autonomous ai, agent ai, all the terms that we hear about, uh, doing things with ai. Yeah, so what, you know, when you do hear about, uh, autonomous AI and agents that's all around actionability and the AI take, you know, perceiving a situation, making a decision, and taking it in action, jumping into the deep end of the pool when it comes to AI in that regard, that, that, that's concerning to a lot of, a lot, a lot of folks. So when we talk about the advise the advisor part of that, the advisor takes no action, right?
Again, the advisor is there just to guide you, nurture you, and move you along. But it's up to you, the human to actually take those actions. It's up to the team who's using AI to infuse AI with the right pieces of information to get the right types of guidance that they want from that AI system.
But that AI system is benign, right? That again, the AI system is not going to take any actions on or your, your behalf. It's all back to you.
And what you want to get out of that, that AI system. So if you're a developer, I'm gonna use AI as an advisor to maybe gimme code, recommendations, code, explain, um, maybe to do a best practices analysis on my code, et cetera. That's, that, that's really good.
Maybe from the AI ops space, Mitch, we're gonna use AI as an advisor to oversee my, my dashboard and maybe surface insights to me out of that dashboard that I would otherwise miss. But there's no actionability to it in that regard. It's just providing the insights and information so that that is, that is a part that fits very naturally into the advisor part of it opposed to the autonomy part of ai.
It's good you mentioned that. 'cause it is a much more comfortable way to kind of enter into the AI space and start to use it, but you don't have to jump right into automation and agents and, you know, doing more of the, you know, advanced things. If you wanna think of it that way.
You'll build trust, you'll learn about AI by using it. And we, and we've done that ourselves, right? You know, look over the last 18 months, whoever your chat provider of choice may be.
But that's how we, we all got into the game of ai. When, when, when, when, uh, you know, chat GPT was released as an example. We all went out there and, and started having conversation with AI at that point, whether it was professionally or personally, that experience was an advisor type experience.
You know, we sent it a bunch of questions and we got responses back and we had a conversation and a dialogue with it, but nothing happened. There was no actionability to it. So that was all of our entries into the AI world.
And for organizations, for enterprises, that's a great first step also in the, in the start of their AI journey To that point, there are plenty of ways to engage with a AI and query, use it as a tool, but what do you need to have in place to be an effective advisor role in, in the environment we're talking about? Yeah. So one of the things that we've learned in our journey with AI so far, and I think as an industry, we've all learned just bringing a large language model into the organization, not enough, right?
It's like it's, that's just, that's the bare minimum entry that you could do. But the problem with just bringing a large language model into your organization is it doesn't have any context. Those large language models were trained on huge corpus of information.
They were targeting the masses of users, where once you get into an organization and you bring AI into an or into an organization, you're, you're in a particular domain. You're in a particular realm. So now how do you, how do you utilize this large language model that's general purpose for specific domain that you may be in?
Well, the way you do that, and what we've learned o over the past, you know, 12 to 18 months, is you have to augment that large language model. You have to augment it with realtime product data or whatever data, uh, realtime data that your, your organization is playing in. You also have to augment the language model with additional knowledge, whether that's workflow, knowledge, processes knowledge, best practices, knowledge.
It's, it's your enterprise knowledge, whatever that means to you and your organization, you want to infuse that into your AI system. So then you have the large language model with your enterprise knowledge, with your real time data access, uh, knowledge. It's a combination of all three of those that brings relevance to AI with an organization because it brings relevant context into your organization and the AI perspective.
And when we're using AI advisors, and I agree with you very much about the point of, you know, contextualizing it with information about your organization. Where do you see the fastest value that can be delivered by using, uh, AI advisor in the mainframe teams today? It's definitely in the DevOps space by far that it, it's the DevOps community that has really opened their arms and embraced ai.
And the mainframe environment is no different, whether, you know, from the cloud environment to a distributed environment in that realm, the developers have accepted AI in the mainframe space. There's a, you see a lot of interest, a lot of adoption AI in the, uh, mainframe space. So that is, to me, has progressed us as an industry in the a those working in the AI space, the work that the development com community has done over the past year, 18 months has really accelerated our journey, uh, with ai.
Now, you also starting to see other areas starting to get really interested in that. The AI ops space, as an example, is getting, getting a lot of traction now when it comes to, uh, to ai. And we're heavily looking into that within our portfolio, in our AI ops, uh, part of it.
But it's the knowledge capture that is what's gonna play the biggest game here, why we're in this massive transition within the mainframe community. We have a lot of folks heading out towards retirement on the tail end of their careers. How do we capture that knowledge and how do we infuse that into our AI system so that next generation coming in has that experience?
They can lean on that they otherwise would not have that person they would go to, you know, Bob, Bob is not here anymore. But if we were able to capture Bob's knowledge in some way, shape, or form, and put that and infuse that into the AI system so that next generation can lean on the AI system and get access to the information that Bob had, that is game changer in our mainframe space. It's really, it's not only helps get that next generation up to speed, Mitch, but here, he, I I just had a conversation yesterday with someone about this AI on the mainframe is making the mainframe and that next generation outta colleges and universities we're in the conversation.
Just like the cloud space in the distributed space when it comes to AI and technology advancements in general, that is really cool. It very much is a sense of excitement in the mainframe environment, particularly with ai. And I, and, and you have a really good point about that knowledge loss, you know, as folks retire, move on, whatever it might be.
So the next generation of people work in a mainframe, have got that information contextually available to them in ai. I can't think of a better application of ai. Yeah, absolutely.
And we hear that from our customers. Our customers are like, you know, we got decades worth of white papers. We got years and years worth of, uh, video recordings, training material, et cetera.
How do we capture that? How do we, how do we get that into an AI system? And that's something with B-M-C-A-E, uh, assistant that we, we, we took very, very serious, right?
So it's like, well, how do we do this? How do we allow our customers to capture this knowledge that they have and get it infused into B-M-C-M-E assistant and we're delivering to our customers a tool that makes that really easy to do, uh, where they can, uh, manage documents, they can manage videos and build out their own knowledge base that B-M-C-M-E assistant would be totally aware of. Now, when we ship our solution, we have the large language model.
We have an a e knowledge base that we ship, the customer can build their knowledge base, and then we have access to all of our product data. So we got all this information that's available to BMC AMY Assistant, that goes back to what we talked about before about what's relevant context to a customer. Yeah.
We can't talk about AI without talking about trust. And I've heard you discuss the importance of explainability. Talk more about, love to hear your thoughts about why that's so important.
Oh, Yeah, yeah, yeah. So with, with ai, of course, you know, trust always comes up in the conversation from the very beginning when we all started working with generative ai, that was the, you know, everybody was talking about trust in that regard. It's multiple ways to answer this.
You know, we have some responsibility in the solutions that, um, that we provide our customers. We gotta give the customers insights into what our AI system is doing. We have to connect our AI system into their workflows and processes around auditing, logging, tracing, et cetera, observability in their organization.
So how do we do that? So as an architect, from the very beginning, foundational, we have to be able to capture everything that is happening through our, uh, our AI system through BMC Amy Assistant. From a user typing a prompt to us formulating a response, not only did it has to be auditable, but as much insight as we can provide on why we came about a response has to be clearly articulated.
And some of that is clearly articulated back in the product experience. So when we give a response back, we may cite in that response where we, why we came to this conclusion and what pieces of information led us to the, to this conclusion. But it also has to be totally, uh, traceable and auditable behind the curtain so that the administrators of the AI system have full optics into everything that is happening in that system.
It cannot be treated as a closed door system. So it, it, it's the optic optics into the AI system. It's the auditability, traceability, logging, everything has to be done.
So if you go into the system, Mitch, and you are working with BMC Amy Assistant day in and day out, the system administrator has, you know, full trans full transparency into all the things that you've done with the AI system. And when, and, and customers have asked us for that from the very beginning, we started working with our customers in this journey that was foremost right at the top of the list. They need to understand what's happening in the system and why.
And we've done that. That's foundational for us. That was something we had to put in at the lowest level of the architecture.
That's not an afterthought. If, if, if you go with that approach is an afterthought, you'll miss things. It has to be done at the ground level of the system.
Yeah. That explainability of transparency is fundamental, that that builds that experience that you start to build that trust with very much so. And it's that trust that's gonna lead us to the, to, to the next part of the AI journey beyond the advisor where you look at AI as a true partner in your daily journey.
You look at AI agents and agentic AI as a digital workforce doing work, and, but we gotta take those steps and build that trust. Speaking of taking those steps for organizations that maybe just starting out, thinking about AI readiness, what do you think are the smartest first steps to take? We went through this journey ourselves.
So, so we have a pretty wide and deep portfolio, which we with done our BMC Amy, uh, product area. So we had to go through this exercise. Where do we find true immediate value that we can deliver to our customers?
The AI journey was new for us too. We had to be very careful, very systematic on how we approached it. So the, the way we approached it was, let's just start looking at the low risk, but high value returns that we can give our customers with our AI infusion within our products, within our portfolio.
And we've been very, very successful at that. But one of the key things, even though it's, you know, it may be a, a low risk, high reward type, um, AI enhancement, we want to be able to also capture and measure that. You have to be able to measure and capture that to make sure you're truly getting your return on your AI investment.
This model worked very well. I, I I, I, I spoke to other architects about this model. I spoke to customers about this model, and this is a really good entry point model.
Start small. Don't try to drink the ocean, as they say. Start small.
Identify those low risk impacts. You don't want anything that's gonna disrupt your business, uh, on a day to day. But then just start taking those steps.
And before you know it, when your organization gets more and more comfortable with ai, you start building the trust with ai and you start to get a good feel of what you can and cannot do with ai. Before you know it, you're starting to take on bigger and bigger and bigger challenges with AI and be, when you look in the mirror, you'll see yourself progressing pretty far pretty quickly with AI when you start that way. Those are some great insights and very sage advice, I think.
Anthony, thanks for joining us today. Thanks for being part of this. Thank you.
We really appreciate the BMC software team for sponsoring this kind of event where we can share this information, share some of our experiences, and bring up some of these important questions. So this concludes our first segment that we're doing in this three part series that covering AI readiness. In our second segment, we're gonna be talking about infusing intelligence with ai, using AI as a partner, using generative AI in the mainframe environment.
Thanks for joining us. We look forward to seeing you on our next segment. Hey guys, thanks for the throw.
We're here with Ron Brownie, who's the CEO of Dyna software, and we're having a little chat about technical debt specifically when it comes to ServiceNow, which is probably maybe now one of the most widely used IT service management platforms out there. Ron, welcome to show. Thanks.
Yeah, thanks for having me. Mike. Technical debt exists I think before and after we adopt ServiceNow.
So, uh, walk us through this a little bit. What kind of technical debt are people bringing with them into the environment in the first place that maybe they should just check that baggage at the door? Um, well, when you think about technical debt, um, a lot of things are occurring in terms of, um, legacy systems, legacy tools, business needs, and oftentimes just to accelerate or even meet business demand, when you're say implementing ServiceNow, really, really either poor configurations or poor thought out, um, designs get ported into ServiceNow or items that from a translation perspective don't make a lot of sense to either rebuild in a custom way as opposed to leveraging out of the box features and other elements.
Um, oftentimes what what, uh, we certainly encounter in here is customers having that whole drive for speed and also trying to meet with what's the business trying to do and basically getting pinched with, we've gotta just roll this out and pull it in. And from that point forward, that's where you start to get lots and lots of problems that start to snowball and sort of, sort of go forward from there. But, um, that, that's probably the, the easiest overview to, uh, to sort of explain this stuff coming in.
When, when you're just starting off, How much of that is a technical problem versus a cultural problem? 'cause I think what happens is a lot of people just wanna bring their existing workflows and port them onto ServiceNow, when in reality somebody at ServiceNow probably already thought this through and just build that feature into the platform, right? I think I would agree with you on, on the most part, there's, there's an element of, well, to be honest, there's sort of that front end components of governance when you're thinking about standing stuff up.
And one of pr one of the key principles to really start to instill in that type of a framework is the decision making around what moves in and, uh, and why is, is really the, the key element of it. So I would certainly agree with you from a, from a a people perspective, process perspective and why they're choosing to actually move stuff through is, is the ultimate culprit in terms of the, the initial onset of technical debt in that, that circumstance. Now, once I start running ServiceNow, I also seem to wind up generating some technical debt.
So what's the source of that and what can I do to kind of minimize that? Well, um, very similar situations where you've got driving business demand, um, you've got short turnaround times that start to create, um, creative approaches in terms of, of developing. Um, what I've seen in my past specifically is situations where the fastest path was the key path to get something done.
Um, ServiceNow is a unique platform where, and oftentimes there's maybe 10 different ways you could do something. And of those in terms of safety, and I'll explain safety in a second here, um, there's maybe only two to three that are really the, the best path to actually execute to do that. One of those typically being just configure as opposed to script or build or, or develop the safety sort of aspect is really thinking about what else is this related to?
So really good example, early days for me, um, I encountered a, a, a, a customer dealing with an implementation of, uh, HRSD, the human resources, um, um, application suite from ServiceNow. Um, and the issues with that, not being able to move forward and not realizing the actual interconnections to ITSM and the knowledge management component, um, and really not having the ability to recognize and understand there's linkages here as you're actually driving forward. So when really building out and developing and meeting some of that business demand understanding are you configuring or, or building in the right sort of path, and also what ServiceNow themselves doing that you need to pay attention to that might be related or could be related in the upcoming future.
Almost the same kind of question, but as part of the issue is I'm bringing a bias to that platform where maybe I think I need to build everything when I just need to configure it. And if I build it, then I gotta support it and maintain it. And that's where the technical then comes from A hundred percent.
And the, the cascading challenges, uh, from there, Mike are now you've got longer durations in in upgrades, you've got more complication in analyzing and understanding what's there when you're either introducing brand new product or features from ServiceNow. Plus when you're also building unique things for your business needs on ServiceNow. It's almost like a snowball effect.
Um, one of the best, uh, sort of analogies for what technical debt turns into, uh, that was ever shared with me was really about a loan where you've got compounding interest as you're going forward. And if you're not actually dealing with that and paying attention to it, it's eventually gonna get extremely costly. And that's one of the big challenges a lot of customers are facing these days is situations where even ServiceNow themselves are doing analysis to understand how much tech debt is on a platform.
And the recommendation starting to come back. You just need to replatform, meaning just get rid of the whole thing and start fresh because it's become way too complicated and way too difficult to support and introduce some of those new features. To that end, you cannot go anywhere near ServiceNow these days without somebody leaping out to tell you about some new AI agent that can do this, that and the other.
Will these AI agents help us reduce the technical debt or might they actually increase the technical debt? That is, uh, an awesome question, Mike. So my, I'll call, I'll say my current perspective, it's a double-edged sword.
Um, there's a lot of things where it can accelerate stuff like development. Um, you probably heard the term vibe coding and other stuff these days. There's a lot of things that can accelerate certain pieces.
The big worries I have is of what gets built and pushed out, are the proper mechanisms in place to validate one, is it actually good code two, is it secure? All those different elements. Missing component always for me is what's this related to what ServiceNow is doing?
'cause what I've found in the past is not so much what I'm doing, but what ServiceNow is doing themselves. And when those come into conflict, I'm guaranteed to have some form of problem or challenge that's gonna limit me in in the future. On the plus though, you do have a lot of different things that are coming out where it is accelerating either usage, um, in terms of end user and and elements there, certain pieces where if it's done in the right way, um, accelerating different aspects of development.
Um, but my future that I hope we really see is something where you've got very, very specific boundaries that some of these AI agents are working within, uh, both in terms of context of the target instance or the target customer and what they've configured uniquely for themselves. And also, um, making sure that you're sort of staying inside the rails of what is sort of safe to actually go and configure. I can't say that there's a whole ton of stuff out there in that vein yet, but I think that's the direction where stuff is starting to lead to as people are getting more normalized with using it to basically develop and configure and seeing some of those sort of challenges.
I wa I was mentioning just a second ago, Are people kind of conscious of technical debt or is it just something that kind of adds up over time and then they wake up and they go, holy moly, this stuff is gonna collapse out of its own weight because I didn't pay attention to all this stuff. So maybe do we need, I don't know, flags in the system that's somewhere that says, you know, here's your technical debt rating. I, you know, it's a great, it's a great question and, and um, things that I've really seen is, um, it's not so much that people are unaware as it's going forward.
Um, it is for sure a snowball effect. Uh, oftentimes the root reason is, you know, here's something that, that got developed, that got built, um, maybe something that gets scanned after the fact, meaning the code is already done and uh, they're about to promote it, then they find an issue and then they start to identify, do we need to pull this out or do we push it in and put something basically to fix it after the fact? And oftentimes the business pressures are, we're just gonna have to push this in, effectively broken, get enough value out of it while we circle back and fix it.
And that all starts to eventually build up. And the big challenge ends up being usually platform owners recognize this is becoming unwieldy to try to move forward. And it's everything from the total duration in terms of upgrades, plus moving through new enhancements or installing new things, um, and the also ever-growing cost of supporting it.
And that creates a situation where people are that own the platform are, are reluctant to add more things on. So business value and ROI sometimes gets deflated or stifled. Um, also then, uh, uh, creating a situation where they're looking at this mountain and to be honest, to go to business to say, I need half a million dollars to remediate this stuff.
Very difficult conversation to have to get interest because perspective on that side of the fence usually is one, why does that even exist? This is your problem, but two, how does this even help my business? And making that connection, that reducing the technical debt actually helps the business oftentimes is very, very difficult to actually achieve.
Then you basically got stuck with a, with a project that's hard to actually get off the ground, and then you just see nothing but accumulation, you know, as you go forward. And I think that's part of the reason why ServiceNow starts to identify you're, you're gonna have to replatform and, and, and, uh, you know, start fresh. Now, does this issue get more challenging when, I mean, historically ServiceNow has been an ITSM platform, but we're seeing it extended into all kinds of different use cases because, well, I can have a single platform and it's more cost effective, but a lot of the people who are running those other workflows outside the IT department don't even know what technical debt is.
So, or are we gonna see more of it because we're gonna have more, shall we say, non-professionals building application environments that for different workflows and they won't even think about technic technical debt till it's way too late. I, I think you're bang on there and, and just to link it back to, to your question about AI and, and where that's going, that's one of those big risks that I see. You know, the, the ultimate goal from a an enterprise use perspective would be get the ability to create closer to the actual, um, end user or the business side.
But everything you just said now becomes the major risk is what is actually being built. Is it considerate, I mean at the root of it with architectural principles and other elements, is it considerate of what's it gonna be interconnected to and what could it affect upstream, downstream that then affects everybody else? So it definitely is a bigger risk as you go.
What I was saying earlier about, um, you know, having some, some aspects of, of uh, um, uh, visibility and understanding and awareness and creating some governance around that, that becomes the key thing to actually start to solve, you know, those types of challenges. Nothing I'm gonna say is a hundred percent ever gonna be bulletproof. Things change, things happen, but without something like that, it becomes very difficult to manage business expectations and speed while keeping a stable platform.
Of course, everywhere you go these days, people are talking about, well, AI and is this gonna eliminate the need for this IT person or that IT person? But, um, much of what you just described seems like it still requires some sort of human in the middle of this thing. So our IT professionals listening to this conversation and basically having a good chuckle about, I don't see that happening.
I, I think it's true. And you know, I even in early days when, when, when at my company we were really investigating, we're all, can we, can we leverage ai? What, what does this mean from what our customer's potential is?
The way I'd always look at it is that this is enhancing development, not replacing it. Um, even when you get into things like really complicated architecture integration, more of that systems level of how is this all gonna fit together? And I'm meeting more peripheral to even just ServiceNow itself, it's gonna be very hard to find something that's gonna understand all the bits and pieces.
So you're always gonna need that level of oversight. The other thing that I always worry about too is that to get that skillset and capability in terms of our workforce, what does that mean in terms of the future and the gap that might be created if a lot of those junior roles that we're gaining the experience to get to that level I just described start to disappear or get replaced by ai, it's a, it's an interesting conundrum sort of down that path, but to your point, I don't think this eliminates the need for, you know, really smart and really capable developers. What's your best advice then to IT leaders about how to have this conversation with the business side?
Because to your early point it's a little difficult and from their perspective, maybe even a little esoteric. So how do I kind of get folks outside of the traditional IT leadership to wrap their heads around this? Um, uh, the way that I've seen it best done, to be honest, is making those connections to cost and business impact.
And there could be situations where the recognition in terms of how quickly or how how slow it takes before they're actually affected might come into play, but really making those connections that if we're not setting things up in a certain way and structuring things to basically protect what you are using, we're gonna end up ever increasing cost and it's gonna translate to your needs being slowed down, um, you know, consistently over time more and more and more. And how fast do you think businesses are moving these days or wanna move on these ServiceNow platforms because, um, just because we can do something doesn't mean we should or do, but, um, it almost seems like, I think the proverb of something is to the effect that, you know, if you want to go fast, go alone, but if you wanna go far, go with the many and is this an opportunity to do the right thing with the many? It's a good question.
Um, you know, and I think over the last say six years or so, I've seen a bit of peak in valley in terms of enterprise use. And if I go back maybe about four years ago, I saw very substantial increase in terms of organization, shared service use. So I'm thinking things like, obviously IT facilities, hr, like something where your actual, um, stakeholders in terms of employees would be affected and you could create more of a common experience that would be there.
I saw some sort of slowdown in terms of that and, and a little bit more shaping towards it and more IT function, security, those types of areas. But in the last few years, two or so, I've seen a lot more increase where the idea of enterprise usage and more importantly, overall service delivery and actually getting further than just employee and into customer space or citizen space depending on, um, what sector you're sitting in. Um, that's starting to increase and we're seeing a lot more large scale enterprise organizations really looking at ServiceNow as a foundational component to enable better service delivery and things that are actually affecting customers and actually affecting the way they generate revenue.
Well, let me ask you this, 'cause you mentioned security and we are starting to see IT teams take more responsibility for at least security operations, you know, the management of the firewalls, whatever it may be. Um, but I can't help but wonder if the way IT teams are organized should change in the age of ai because we built a lot of those roles and responsibilities around the various silos that existed and maybe we're taking the silos down, so maybe we should reorganize the teams. What do you think?
Well think, thinking back to some of my operation days that the, the reorganization probably creates some different turmoils, but I think to your point, the reshaping though, because there is a lot of shared responsibility that that really starts to come around when you're thinking about who's using AI and for what and what it's actually gonna be affecting. Um, there's definitely security components that need to come into play, but I think there's also gonna be, um, a little bit more visibility and a push on ownership in terms of those users and let's just call it business areas that are trying to adopt to make sure that this is actually meeting and, uh, um, security requirements and being able to be more of a responsible and safe usage. I am seeing a lot more organizations standing up responsible AI tied with security where a lot of the questions are diving into not just, you know, what's the technical aspects of the ai, but what's the business use and the why, what's it related to data, all these different types of elements.
So I think we will see something that becomes a shared responsibility. I, I'm reluctant to say, I think it'll really reshape organizations and that's only just my, my own personal opinion on seeing how difficult that sometimes is. But it's a great question.
So what is that one thing you do see IT teams doing in the ServiceNow environments that just makes you shake your head a little bit and go, folks, maybe we wanna be a little bit smarter than that. Whew, that's a great question. Um, you know, I I, the, the, the way I probably answer that is, is paying more attention to some of the basics.
And oftentimes what I'll see is some, some ServiceNow customers getting themselves into challenges by sort of ignoring some of the basics in terms of code reviews, in terms of creating some of those structures of control that help make sure the right things happen. And there's two things that on that note, there's for sure process and sort of individual involvement in terms of being able to have those right checkpoints. There's also leveraging tool sets that can help to automate those to make it more simple.
And my belief is that a lot of times those get ignored just because of how difficult it is to capture everything and make sure you're, you're, you're seeing things. The worst stuff that I've typically seen is environment drift, where it's just the easiest thing to control. ServiceNow is built in mechanisms, but how they shape delivery, they start to just ignore and drift that changes in controlled environments, those types of things.
So my gut would be right at just ignoring some of the basics as as, as crazy as it sounds and surprising. All right, folks, while you're heard it here, hey, even in the age of ai, there's no substitute for mastering the fundamentals because if you don't, you're gonna pay for it later. Anyway, Ron, thanks for being on the show.
Yeah, thanks so much, Mike. All right, and back to you guys in the studio. Hey everyone, it's Alan Shimmel from Techstrong.
Again, welcome to our next session in our recent Futurum Techstrong sessions with our friends at Microsoft. Today's session is patterns of Success and IT features Michelle Lancaster, general manager and partner for GLO and Global Leader for business strategy and AI Business Solutions at Microsoft and fus own Mitch Ashley software development life cycles. Michelle is gonna unpack the patterns of success emerging from the most transformative customer engagements Microsoft has seen in this particular session.
You're gonna see how organizations are successfully operationalizing AI through apps, agents, and chat to drive measurable outcomes. It's not science fiction, it's not vaporware. These are real live engagements that are with real outcomes and real metrics to look at.
You can expect a strategic overview of what is really working, why it matters, what's not working, and why that matters. And you can use these insights to drive and scale business impact with intelligent apps. Let's go to Michelle and Mitchell now.
I hope you enjoy this session. Thanks, Alan. My name is Mitch Ashley and I am VP and practice lead of the software lifecycle engineering practice at the Futurum Group.
And I'm Michelle Lancaster. I lead business strategy and our go-to market team for Microsoft's AI business solutions team. Michelle, I'm really excited to talk to you about this.
The market is really energized around tic business applications, AI agents, all of this. What's your experience about how customers are approaching and and reaching out to go after this to start to energize their businesses with these technologies? We've seen in the past six months or so, a lot of the hype cycles start to turn into the tricycle.
And that is not a three legged instrument here. It's really how do we go from thinking about AI and applications as something that people want to dabble in, into something that is the future of their business. We're starting to see apps and agents and co-pilot come together, starting to see the power of taking automated applications powered with agents and humans and running copilot over top of it as their overall UX system.
We're starting to see people go from individual productivity to things like, how can I change the way my business operates? And we're starting to see some really impressive results in terms of not just time savings, but real dollars saved as well across many industries. Yeah, I'd love to hear some about the organizational patterns that are coming about that are helping enterprises, uh, successfully coordinate multi-agent orchestration across business functions to help 'em deliver an impact.
It's a big question. Maybe we'll try to take it bit by bit. Multi-agent orchestration is at the forefront of where real transformation starts to happen.
Having individual agents improve efficiency is one thing. Um, multi-agent orchestration can actually drive that business transformation. That orchestration layer brings us back into the heart of what I think the Microsoft value proposition is, which is not just the agents and the automation intelligence, but back to the core of security and governance.
So you need to make sure that we have governance in place, we have rules in place, we have the group identities in place, and we've cleanly defined those. It turns out that's also the secret sauce of the organizations starting to move forward, finding the right use case and them starting with the foundation of security and a clear understanding what the KPI is for that use case. Sounds relatively simple, but it is really the ticket to success of people going from lodging, individual agents, seeing full scale business process transformation.
You know, Michelle, it seems like we're kinda moving beyond the technology as the variance are really how we approach implementing ai, whether it's as a productivity aid or marketing agents to do workforce or even autonomous type agents. Can you talk a little bit about that progression and how uh, companies are approaching it? Yes.
We really see this as a concept that we've called the Frontier Firm. We see that evolution through three different stages. It really starts with humans using agents as assistant.
Think of copilot, where you can summarize a team note or be reminded of the most important email in your box. Really a individual worker aid around productivity. And we see lots of people experimenting in this space.
We move into that second phase, which is humans working directly with agents. So more of an autonomous agent that is able to run a process but is human led. The human is directing it to do work, seeing the recipients of that work and then continuing to move forward.
People have started using researcher or analysts to summarize things, um, ahead of a, a meeting though that agent's really taking on that research work for you and delivering the final product with that prompt. What's really exciting is the number of companies we see shifting into the third stage of this, which is autonomous agents working with other agents and working with humans. Some of the places we start to see that advancement happening is in industries like manufacturing, where there are fairly complex processes where you are able to have multiple different types of agents working together to solve a problem.
One of our customers has taken a look at supply chain management. They have an agent that's keeping track of the inventory inside all of their workplaces, um, and in the places where they need to ship products, they have a reasoning agent going over top of that and saying, based on these numbers, based on what we're seeing in the predictive workflows, where do we need to up, uh, increase or decrease the amount of changes? How do we then communicate that to the agent who does order fulfillment?
That used to be a human being looking across multiple different kinds of spreadsheets, multiple different systems. The agents are there to work together to bring some of the complexity out, improve the efficiency, and then give that back with a human who's overseeing that work. And some of those gains there are really impressive.
You know, we've started to see things like 30% increases in order fulfillment and at a 40% decrease in the overall sort of stack housing costs of extra inventory sitting on the shelves for too long. And that's our aspiration is to make sure all companies are starting to work across that flow. You'll see productivity gains.
We will see, um, ongoing transformation. That true sort of transformation takes place when you have all three of those opportunities realized inside the firm. Yeah.
Let's turn a focus to kinda the guidance that we can offer folks about how to successfully implement AI and agentic applications. First, could you share maybe an example of a customer who measured a meaningful business outcome from their AI implementation? I might give you two.
Um, because the first one that always comes to mind for us is Microsoft. Our, our own best customers. We get tons and tons of calls from customers, from everything about Xbox logins to changing their Windows application to understanding why their surface laptop is not working.
Um, we're able to quickly sift through all of those issues, but the game changer has been the existing platform been built on a power app. How are we able to sort of assistance for those call center folks? We now have a set of agents that are able to classify exactly what type of issue it is, match it to the right human being.
They're provided the latest information on any of the common outages challenges that we're facing in that space. They're able to get on the phone fully confident that they know exactly what is going on with it. Has really helped the efficiency of folks in those call centers.
That assistive technology was able to take an average person going from about a hundred calls a day to 300 calls a day. That's a pretty big increase in what a human being is able to do. And that's because they're able to more easily dispatch and resolve those calls with, uh, a happy customer.
And that's the second thing which I get super excited about. Efficiency is what we should largely expect, um, from agents and ai. You don't always think of human satisfaction, um, in the space, but we should.
Our callers, they weren't waiting on the phone as long. They got more pertinent information. They were talking to somebody that was able to cut directly to the chase.
That is a really exciting sort of value. Flip to the other side, we have seen in that industrial iot space, large scale manufacturers operating heavy industry equipment. They have had sensors on them forever, but those sensors have typically fed into an application.
There's lots of data, there's very little insight. Introduce agents that can quickly make sense and build out the insights. And that customer in was able to take that existing infrastructure, the work that they had already built on power platform to automate processes and have agents go through to start to make the predictive maintenance decisions.
What they've seen is about a $50 million, um, cost savings just in the first factory they implemented alone. And they're also able to see quite a bit of, um, improvement in terms of efficiency in servicing those. No longer do you have a single person checking the spreadsheet or checking all of the sensors and able to precision, um, pinpoint.
That's sort of the, the next frontier of that is when we're able to start to take human intelligence on those systems, combine it with an agent that's able to reason over data and to make a recommendation that is then able to be followed. Yeah. We're talking about AI results, talking about the human element.
What about the cultural or team structural changes that are effective or essential for scaling ai? Uh, this is probably the most critical question, and that's an easy thing to say. What we've seen is, uh, largely learned through what Microsoft has gone through.
We know that for the culture to be in place, you have to create, you have to start with security and governance, really starting with understanding. You've got to make sure that people have a bit of psychological safety with the information being disclosed. You also build psychological safety with the fact that there is a future for humans in all of these work streams.
When we talk about the Frontier Firm, there's not an instance where there is not a human being involved in those processes. It becomes a question of how can you build trust in the data that's being provided? So you feel like it's assistive and additive.
There are also organizational protocols that are really important. That also goes back to security, um, and governance. But it also goes to some level of explainability.
We talk a lot about evaluations. We talk a lot about benchmarks. Um, that's not just to make the products better, it's also to really make sure that if you're trusting an agent to run a part of your business, you want to see some type of performance report the same way that you wanna see that from an individual employee.
Are they doing their job? Are they learning over time? And that's why we've put a lot of focus into things like, uh, agent Observability, the ability to run that through the governance center and Power Automate.
We've had this as part of the core of that product for a long time, something that we've built in throughout. So it really starts with, you know, trust from the individual trust in the process and then trust in making sure that you have, um, some, uh, level of observability into that process to continue to make it better. Michelle, let's talk about power platform and the role that it plays in simplifying multi-age agent orchestration across different modalities like chat apps, backend systems, and, and also how we interact with that because agents are a little, little different than how they have to be managed.
It's a great question. Um, it's one that I am really glad you asked because we are getting lots of questions about what is the future of power platform and apps and what is the future of agents? And the answer is they are better together.
Agent interacting with different applications inside the business, through the work that we've already done. Inside Power Platform tends to be the, the ticket to success. In fact, some of our biggest customers, we have seen Power Platform power users have become the fastest adopters of copilot studio and agents because that DNA is already there.
We have built the Maker platform, the ability for observability as well as the data feeds. And so that's really the, the fast pass towards ai. The organizations that have already taken the time to organize data, secure the data fi, figure out the right identities and have the right systems in place to manage across are gonna be the one the first.
Um, and certainly some of our biggest users have done this from oil and gas all the way to financial services, have used Power App and Power Platform as the jumping off point for their agents. And they started with those agents attached directly to those apps as really, uh, sort of the people that are at the forefront at that frontier firm curve. It's really intriguing.
The agent feed. Tell us more about that and how that works. Agent Feed is one of our secret weapons.
As AI adoption rolls out across the organization, what Agent Feed does is that it provides that level of observability into both the application and the agent interaction. So you're able to see agents, you're able to see the interaction of how that agent is interacting with all of your data sources as well as the interaction with the application. And that's super important because it is the way that we continue to have the human element.
We're making sure those agents are making the right decisions that they're picking from the right data sources and we're able to continue to make sure they are getting better at their jobs. That is something we feed back into all of the work inside our engineering teams. Part of both a continuous process loop's also something that the makers and the creators and the owners inside the business can take to make sure that we're working on the highest order problems, that they're finding the right solutions.
And moving really quickly, How does THETIC Automation reshape the way applications are designed, deployed, uh, even delivered, you know, built especially by end users Already? We've seen a great adoption of power platform, but it's still been a relatively IT driven, um, activity. We have lots of different types of makers, but when it comes to an application that is widely used through an organization that is still largely more in the, the technical space, the intersection of these two trends though really start to open up the door for everyone.
My background is a hundred percent in sales and marketing. I've built three agents that are now working with one of the power applications we have on our dashboard. It has really changed the, the ability for folks to think about a problem, identify sort of what the parameters of that problem would need to be, identify some data sources and move pretty quickly to get that done.
So in my case, we are going from, you know, multiple meetings where we have multiple different asks. Um, how do we synthesize those and how do an app is running and tracking our feedback. I no longer have to send a bunch of emails out to the field telling them that's what's happening.
The agents are collecting it, they're updating the information, the app is tracking and we've just given access to that. I am just one example. We see many of the organizations with which we're working right now of where you have someone who is able to identify a problem that's common to the rest of the organization, find a solution and get it out pretty quick.
And the beautiful thing about that interrelationship between power platform and that agent maker space is that it's not just someone, um, you know, off doing something that then gets stuck. But when you're using that defined identity group, you can go from a single maker to widespread, uh, adoption. And that's occurred that we see can everybody create and can everybody create a solution that is common to many and being used in a sort of exponential effect.
You know, you talked about end user builders creating applications. We've been doing that right with technology, uh, platforms that we've had up to this point. But you said something really interesting about going beyond what we're capable of doing today.
Building agents, you know, never imagining that that was something to do. Talk about what that, what that looks like, what that future, what's possible for, for the end users in a world where they don't have to go to it for everything. Yes, and I would be in big trouble if I cut my IT friends out.
But I think there is a place where in the right sort of culture dimensions, you've already defined the identity groups, you defined the problem and you've, I, uh, been been able to put the parameters around security. So really being very clear about which information sources to pull from that part is also something that used to be a, a pretty complex task requiring a lot of negotiation. When we do that.
Now in this environment, we're able to either rely on existing identity groups and security protocols that are native in power platform or we're able to really quickly give that direction to an agent by saying, please only pull from these types of things. So for example, if you're using researcher, you can say, please only pull from our internal work documents. As we think about widespread adoption, it is really shortening the curve to creation and then being able to demonstrate value.
That is the key crux IT professionals usually care about system access and the system I identity pieces. 'cause that's what makes sure that nothing crashes. They also care about usage.
You're making sure we start with security in mind and then we solve the most repeatable use case tends to be the thing that has, um, enabled makers to create and then it to love the stuff. You know, when we talk about builders, you, you might imagine starting completely from scratch, but we're really not. We have a lot of things in place that it has put in place and also that are built into kind of the fabric of the tools, the capabilities.
Talk about that a little bit, Michelle. Yeah. And uh, when I talk about identity management, I'd be remiss if I didn't talk about RA and the many things that we have built in, um, to that.
So when we think about defined identity, it's why starting with power platform is that shortcut. In many cases we've defined through RA what the IDs are. We have also defined group identities.
We define roles for what those different groups can access, what they cannot access, and at what time. And so it becomes very easy and it gives an extra level of trust. I'm really excited about the continuing investments that Microsoft is making here.
That core strength of what we've had in power platform is joined by things like purview Agent 365, that is that control plane for agents. This is a great time to be in technology, but be in business where we're able to le leverage ai. Thanks for sharing your insights.
You know, some of the learnings that you've had working with customers, even your own 'cause you're building agents, so we appreciate you sharing that with us. Thanks so much, Mitch. Appreciate it.
One of the things that's most interesting to me about AI is not only what we can do with it, but how it's changed about how we think we can solve problems and who can solve those problems. We've had citizen developers and tools for creating applications and business units and outside of it and situations where they still need to come to it to kinda get the harder parts done. And it seems like we're passing that we're moving past some of those barriers into a world where some of the constraints around what we can do with technology are being lifted or, or lessened and of a burden on the end users.
And that's when things change. That's when systems fundamentally change, uh, because you remove constraints and now what's possible is actually even increased the space of what you can do. It's really interesting to see how Microsoft has approached this of having an embedded base of customers that are using the, you know, the current generation, if you will, of technologies, but helping them move into the ENT future.
And it's not a jump off the deep end, it's a process to move through that, but also helping customers understand what you can do and who can do that and how to leverage those tools while at the same time, security, guardrails, governance, the things that you need from a corporate or an enterprise standpoint. Uh, not our our checkpoints at the end, but also built into the processes and tools that you have so you can start to leverage that as well. It's really exciting to think about the future of agents and what they can do as we move into the, the second and third phases that Michelle talked about around agents doing work for us and then working along, uh, agents.
I can't think of it as not just humans in the loop, but humans leading the loop of agents that are doing those that work for us. So it's an exciting future and I think we'll have a lot of opportunities to share experiences along the way on this journey. Now you, you've made some decisions architecturally product selection.
Um, you now have a real network. You not, you don't get to build a greenfield. Um, you know, we're just gonna build this fresh and new with no legacy.
You have the historic brownfield migration scenario here, so you had to take this very carefully. Why don't you talk us through what, what did those brownfield migrations look like knowing that, you know, you weren't directly on the ops team. I'm sure you had, uh, uh, a lot of involvement in designing the process and being sensitive to what could go wrong here.
Nokia is is a group of many companies that have merged into Nokia. Sure. Yep.
So, so, so that's why you find that those different companies are, are not, were not using the original Nokia rafter equipment. Sure. So you might be, they might be using other vendors because they were not related to us.
And I think you Had at least two different vendors in the legacy environment, correct? Yes, Yes. We, yes we do.
To non Nokia, two different non Nokia vendors. Yep. Two different non Nokia vendors, two different non Nokia vendors.
And, um, and so, so we have existing data centers with existing applications mm-hmm. And they're running and we, we needed to move them into this common modern data center architecture, you know, based on net ops and stuff like that. And, and based on IDA and Azure Linux.
So we had to migrate all these different data centers from their original equipment and original management platforms to, to Edda and Azure Linux. Mm-hmm. Without, without outages, without, without causing any outages.
So we had, we had to, to our data centers were at some time, and they are still in some cases interconnected to different vendors. Sure. At the same time.
So some, some of the servers in, in the, in our SR Linux in the, in the environment are actually on the same subnets, for example, on the same network as the servers in the other vendors, uh, environment. Sure. And they're talking with each other as if, as if they, they're, they're just as if they're together in one data center.
Excellent. And so, so, so we've developed this, it, of course the first time it was very, uh, interesting and challenging, but we think we mastered this to the extent now it's like become routine, you know, oh, we, there's another data center we have to migrate, therefore we, we connect our SR Linux e the data center to it, and we begin migrating. And then we go through a process where we build, you know, uh, a network across the two data centers and move servers one by one without, even the application team shouldn't really, I mean, we're not telling the, of course we tell them we're migrating, but we, we really tell them, we you shouldn't see any disruption.
You shouldn't, your application shouldn't be affected in the, so we move their service from one environment to other another without them actually seeing effect. So this is one kind of, of Brownfield, you know, where, and there's, there's another kind of brownfield, there's another kind of brownfield where we had to replace, you know, legacy legacy mm-hmm. Uh, uh, management platform from prior, uh, Nokia companies to, to, to, and we had to do this in one shot, in one shot because we thought, okay, why don't we have the opportunity we have, it was running SR Lin Sr Linux by itself, but what the management platform was complete was different.
Mm-hmm. So we took that and we actually, in one maintenance window, moved all the data center from one management platform, which actually required, you know, reconfiguring every single node in the data center Wow. To look for the new, and we did this with no hits as well, with no hits as well.
So it's really, of course, the digital twin here, the migration with the digital twin is very important. Why? Mm-hmm.
Because the digital twin enables you to look at specific, uh, now you need to go down to the node level, the, the CLI level, and make sure that every port, every subnet, every VLAN in, in what it was in the, you know, previous life mm-hmm. Is actually this gonna be, that has exactly the same configuration, eh, of course different different type of configuration. But the same, same members, same subnet, same everything in the new data center.
So the, the digital twin enabled us to make this comparison. And we did some automation of course, to, to compare them together. But the digital twin was very critical that because we couldn't make mistakes in any node and, uh, you know, every single node had to have the, the correct configuration, otherwise you get an outage.
Have you ever thought about, how did I get along, you know, for years or decades doing all this stuff without digital twin support. Um, it's one of these, you know, pieces of tooling that is just a game changer. It's fascinating to me.
I, I mean, you see, you're saying it's fascinating, but go to a, a common network engineer and Sure. I'll tell you, I'm confident with CLI, I like, I like C-L-I-I-I can understand. I, I know what I'm doing, you know, I'm mm-hmm.
I can see what I'm implementing, what I'm imp they're, they're not used to this idea of hiding the complexity, hiding the complexity from you or, or, or using modern techniques like, oh, let's, let's put it like a, like a software development cycle. So it actually wasn't, so, you know, you're thinking back now, we were thinking, oh, that's great. You know, how did we live without it?
But when we started, when we started, it was, there was, we got a lot of, you know, opposition. You know, sure. You guys are gonna mess up.
We've never done this before. This has not been done be before. Uh, it is gonna be disaster.
This is our factories, uh, uh, you know, our product lines don't do it. You know? Right.
'cause they're used to do it in a, in a certain way. And we, and architecture was completely, you know, revolution to what, to everything that it, what, what, what it was in, in the previous life. So, sure.
So thinking backwards, it makes sense, but when, when you are beginning, it was a lot of resistance, you know? Yeah, No, totally understood. And I think so many of us, you know, have been trained to, like, just like you said earlier in our conversation, I've gotta go get the equipment in the lab and test it in the lab before.
I'll believe that this before I'll trust putting this into production. And, uh, you know, this digital twin functionality in EA now brings you to that much higher level where I, I don't need to invest in that equipment in the lab. I don't need to go physically cable that up or make sure somebody's there to do it for me.
So Conference season is upon us, and RSAC is coming up soon. But what are the things that are gonna be discussed? And are they gonna include ai?
This week, a very challenging episode. We are gonna be talking about all things related to security that don't involve ai. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry.
This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and is often associated in association with one of our events. Tech Field Day is a part of the ING group, and this podcast is also published, our sister company's website, tech Strong tv. On this episode, we're gonna be discussing security.
But before we get to that, I wanna have a chance for our guest to introduce themselves so you know who you're listening to, starting with Drew. Hey, I'm Drew Connery Murray. I am with Packet Pushers.
Uh, we are a tech podcast outfit covering the IT industry. You can hear me co-hosting our Heavy Networking Network break and packet Protector podcasts. Hi, I'm Jack Poller.
I am CEO and principal analyst for Paradigm Technica. We are a cybersecurity industry analyst and research firm. And of course, I'm Tom Hollingsworth event lead here at Tech Field Day.
Let's jump into the premise for this episode. No doubt, you have been hearing a lot about security, especially for me, if you've tuned into our Security Boulevard podcast. But today I wanted to bring on a couple of my friends from the industry who are gonna be joining me at the RSAC conference this year to talk a little bit about some of the bigger trends in security.
And I, I gave him a challenge before we started with this, because I didn't wanna talk about AI stuff necessarily. 'cause I know that we, we talk about that a lot. So the premise for this episode is that security in 2026 is more than just ai.
So I'm gonna kind of throw this out here to you, gentlemen, because, you know, I know Jack, you live in the security world and Drew, you do a lot of security podcasts with our friend jj. Um, what are some of the trends that you're seeing in security that kind of stand out to you, that don't necessarily have to do directly with securing against prompt injection or dealing with rogue agents? Well, I think one of the important things to consider is we're really starting to see the implementation of Zero Trust.
And Zero Trust is all about identity. And I, and I hate to use this term, it's another one, like those forbid words, but, uh, uh, identity is the new perimeter. And really what we're seeing is a big shift from looking at place and time to be, uh, controlling how you access resources to identity, being controlling how you access resources.
And I think that trend is important because we're just moving so quickly with everything we're doing. Uh, the, and we've, you know, the cloud has sort of erased our concept of a boundary, uh, physical boundary location, boundary time boundary. So I think we need to rethink everything and move towards this.
Yeah. I'm seeing, um, that as well as, um, a kind of a renewed interest in sort of the endpoint. Uh, and in particular the browser.
A lot of activity around trying to secure the browser in various ways, either by delivering a custom secure browser or putting controls in so that you have some visibility into control over extensions and what people are up to in the browser and the endpoint in general. I think in part it's been driven by issues around things like, you know, malicious NPM packages, IDE extensions, browser extensions that start off looking like a useful tool. And then, you know, the, the malware creator lets them sort of get adopted and then flips the evil bit.
And, and suddenly your end point is compromised. NN never flip the evil bit unless you wanna be RFC evil bit compliant, which used to hang on my door by the way. It was great because I just like moved a little magnetic slider over to warn people if I was feeling evil that day.
Um, but you both, you both bring up really interesting points and, and I will small plug for everybody out there. Uh, we had both examples of both of those at our previous Security Field day event in the fall of 2025, uh, where we talked to one password, who had a really great example of, you know, talking about some of the identity based stuff that they're dealing with, but also from Square X, which is a secure browser company that actually was just recently acquired by Zscaler, uh, which I thought was a really interesting pickup for them as they kind of work through sass ESSC magic. Um, I wanna dive into that second topic.
First drew the, the idea behind the secure browser, because this is one of the things that a lot of people have been talking about for years. Uh, if anybody remembers the, the horror that was Internet Explorer for, with all of those browser helper objects and all of those ActiveX controls that were embedded into the browser, and oh my God, what are you doing? And, you know, hey, Netscape Navigator still works and it, it still has its own foibles, but like we've been fighting the browser wars for a long time and it looked like for, at least for the foreseeable future, chromium was gonna win out.
And then we started piling security pieces on top of it as we started kind of turning the browser less into a functional piece of software just designed as browse webpages and more into effectively a user portal. Uh, and, and we didn't just see that from companies that were building these objects in, if you look at things like ARC and Brave and, and other consumer-focused browsers, like they were doing all kinds of crazy stuff to, you know, provide additional functionality and stuff like that. But that never really carried into the enterprise until today where we're seeing, like most of the applications that we're using are web-based.
Like it's, it's whether or not they're using a web functionality like, uh, safari or a Chrome or they're, uh, just a, a rebuilt electron app. I mean, that's if for those of you out there who use Slack, guess what kids, that's basically a custom browser. Uh, but if you have something that can install itself into Electron, then you basically create a secure front end.
Do you see kind of also bring Jack's point in here, do you see that as a way to kind of control the identity crisis of we have, uh, a lot of users who are accessing all of these software pieces from all over the world and we need a way to basically kind of funnel them into a choke point and that becomes a browser that's running, uh, an extension that allows us to do security right there? Yeah, I guess I'll, my impression is that in the past that the primary risk from the browser was, uh, are your employees going to be shopping or looking at naughty sites, uh, you know, time wasting, uh, exposing you to either time wasting risks or some kind of liability from looking at things they shouldn't be looking at now, because the browser is essentially a, a productivity tool. It's your, um, gateway to a bunch of corporate apps with lots of sensitive data.
The attention now is, I think, uh, that that's driven the attention of executives who are like, oh yeah, this is a huge risk and we're actually seeing attackers exploit the browser, uh, as a way in. So that choke point used to be the firewall, now we're bringing it right down to the end point. Um, in, in terms of it is, I, I don't know that there's so much of an identity play in the browser, but it is definitely, we need to see what folks are running on the browser, what folks are doing in the browser.
And again, with and with encryption, you know, most traffic being encrypted now, the browser's kind of the only place you can really get deep visibility into that traffic, uh, as it leaves the enterprise. One, one of the interesting things is, you know, when browsers first came out, and I don't know, you know, 30 some odd years ago with Netscape Navigator, You're dating Yourself, having worked there at Netscape when it first came out, I can talk about this a little bit. We talked at that time about the browser being the universal user interface.
And for a very long time it was trending that way. It didn't make sense to develop your own full blown user interface, instead use the browser. And that eliminated a lot of development effort.
I think what we're seeing now is we're seeing to sort of see a trend starting very slowly to move away from that because there are certain things you just can't do in a browser that you need a specific user interface for. And there are a lot of things that are now happening that don't go over an HTTP or h TBS port. So instead of you're communicating on 4 43, you're seeing it where it's a private communication, API to API from one of those, you know, and I'm gonna say it Tom, an AI type environment, but not thinking about the AI part, just thinking about more the user, the user interaction is.
And I think it's, um, I think Drew, you said it early on, it's really more the endpoint and the endpoint is now becoming more in focus. And I think very soon we're gonna start realizing that it's not just the browser we have to worry about. There are so many other ways users are using the endpoints to communicate with, um, corporate and enterprise applications and services.
And more importantly, the endpoint is now when, when, you know, when we think about traditional endpoint security, we really think about it as, uh, your PC primarily in your, uh, your Apple laptop, your Mac, secondarily, uh, and I think now, um, the younger generations are starting to become very much mobile first and mobile dependent. And the endpoint security on mobile devices is still way, way, way, way behind where we're on, uh, desktop PCs and laptops. And I think we need that, that we're gonna very quickly have a problem there that we need to think about.
This is why people pay Jack the big bucks folks, is because he got to the point I was gonna bring up before I ever got there. I think that where we're at right now, especially when it comes to identity and security, is people like us. I'll just say that because we are over the age of 30 comfortably, uh, we have a very unique concept of what a, an endpoint is.
Like, I was literally telling somebody yesterday about when I was an intern at IBM and uh, I took a walk with somebody 'cause he, he was like, Hey, I wanna test this cool thing and I wanna check by email. I'm like, you can't, your desktop is back at your desk. He goes, no, I have this thing called a Blackberry and it runs over wireless ethernet.
And I'm like, cool. And today my kids, and you know, 'cause my son is 20 and now, you know, the, his generation, they're kind of coming into the workforce. They don't like laptops.
They, they wanna run off of tablets or phones. Like the whole idea of having a place where you go to do stuff or having a four pound slug of aluminum that you carry around with you is foreign to them. And that has changed the way that people do, um, their software, right?
Even on like a Mac or a Windows pc, it is an app, not a software program. So they're trying to provide the same user interface that you might see on a mobile tablet or a mobile phone. And that creates its own challenges.
Kind of, Jack, to your point, I think one of the reasons why people have moved away from using browsers as the the standard user portal in a way is because we've secured them too well because their sandbox now, they can't really affect anything else going on in the system because so many people have exploited it for so long. And so we're treating the endpoint as the identity piece, right? Because, you know, lover or hate them, apple really does a terrible job of creating multiple user identities on their mobile devices.
If I'm on a phone, it's my phone. If I'm on a tablet, it's my tablet. In fact, the only thing that Apple makes that is really good at transferring identities is the Apple tv because you can have different people logging into the Apple tv.
I think we might see that in the future as kind of like an enterprise level, um, thing for like, you know, like maybe like a host stand or like, um, you know, student identities checking in and out of an iPad. But by and large, like we know that if someone's on an iPad and it says like, Jack's iPad, that's Jack, right? So we can enforce Jack's security policy, but the design of the OS does not allow us to do that.
So we're in effect, we're kind of fighting our way uphill because iOS is like, oh no, you can't do that. Oh, you wanna run your own browser? Well, it's really safari under the hood.
And, and so people have been like challenged to come up with ways to prevent security incidents from a, an increasingly mobile workforce where I don't have visibility into that at all. Like an iPad might as well be an island. I think there's, there's another thing, and Drew, I'm really glad that you brought this topic up because there's another aspect to it, and you alluded to it with the browser and talking about browser plugins.
And that's very critical. 'cause one of the things we've seen with browser plugins is, uh, a developer will provide, you know, do some open source or free plugin and start, people start using it. And then either, as Tom mentioned, the developer will flip the evil switch or more likely somebody else overcomes, you know, takes over that development effort.
And they are the evil people who just sort of over, you know, come in and take over what's going on. So we have a browser extension problem, but as we move outta the browser and we start having custom applications, a lot of these applications are also plugin enabled. So they have the ability to add feature functionality to them from third parties.
And we don't, unlike Apple in the browser, in in the iOS environment, we don't have a walled garden in all of these plugins. So we again, have this ability for people to create what appear to be benign plugins that are really have the evil switch flipped under the hood in a really malicious underneath. And so the security landscape and the, the, the footprint becomes that much larger and our, our threat exposure becomes that much larger.
And it, I think, you know, there's a lot going on at RSA, but I'm not sure people are really focusing on this because I think we're too over rotated onto thinking about AI and what AI is gonna do for us. I will say, uh, I know recently Palo Alto Networks acquired a company called coi, uh, for I think $400 million. And that's, that's right in their wheelhouse, just starting to give you visibility into what kinds of extensions and packages are my employees downloading and using.
Um, it's sort of like the old back to like, you know, virus and malware lists, but for NPMs and, and extensions and so on. Yeah. And that's, that's one of the challenges that people are always gonna face, right?
Is you have to give attention to the squeakiest wheel in the room. And sometimes that is identity security and sometimes that's the identity of a software package running autonomously on your network, deleting all of your emails because you told it to, You didn't tell It not to, and how do you guard against it? Right?
Right. Or, and even when you're telling it not to, it's ignoring you just like a, a junior intern who doesn't know any better. Uh, and I, and I feel like some of the, the security pieces that we're starting to see are, and, and this is a great conversation we had on, on Security Boulevard, was you're trying to get the human out of the loop because the human is actually creating problems here.
Um, and I know like we had a really great presentation from Dave Meyer when he worked back at Brocade years and years ago at, at Networking Field Day, where he said, eventually the system will only be as robust as the number of people in it. You have to get people outta the loop. And now what we're starting to see is that the people in the loop who are constantly going back and checking up on the agents that are running, are creating problems.
And, and this was, uh, uh, something that Mitch Ashley from the Future Group brought up. He said, eventually what we're gonna have to do is we're, instead of asking the human for permission to do things, we're gonna have to have the agent do the thing and then tell the human later, Hey, I did all this stuff. You're okay with it.
Right? Because security is getting to the point where the time between vulnerability detection and exploitation has shrunk from weeks to days. And I'm gonna guess sometime in the next couple years, it's gonna shrink to hours for some of these vulnerabilities because you have something doing, uh, effectively multiplicative, um, exploit capability, right?
Where, oh, I found this. Let me go have dispatch like a thousand agents to go see where it's exploitable, you know, log onto show Dan. And all of a sudden I have like a whole bunch of stuff that I could figure out.
And, and like that's that the scalability problem is what we're gonna run into. Because unfortunately, humans don't scale Well, the the, you're right that humans don't scale. And, but the interesting thing there is talking about vulnerabilities is half of the puzzle, and I I I read about this last week, or maybe it was earlier this week, uh, in, in relation again to AI where we think about a, a lot of what we think about insecurity is either vulnerabilities or network access, and it's an attacker coming in from the outside.
However, when you actually look at what's going on in the world, half of half or more of a attacks are based on the identity and getting somebody access to somebody's identity. And that's, whether it's social engineering or stolen identities or the fact that they're, you know, the default password was never changed for you never set a password or your password is PA sswr D one, right? Or you have to do frequent password rotation.
So you just add a number and increment that all the time. So all of those issues relate to humans and human gullibility and the ability to manipulate humans. And no matter how much we try to take humans outta the loop, humans are involved.
This is a human oriented, businesses are all about people, not about the machines unless you're com building the machine, right? So how, how do we deal with social engineering and identity attacks? And if we ignore that part of the puzzle, we focus only on, you know, we can do all we want in the world on code security and, and evaluating code and network security and all these other aspects and endpoint security and eliminating malicious packages.
But if the guy's gonna fall for, Hey, you've won a million dollars, give me your, you know, your username, your password, and your date, first date of birth and your mother's maiden name, you know, if you can't get past that, then we're still, we're, you know, we're leaving half of the landscape uncovered. And I, you know, that's, I think identity is gonna be the other part of the puzzle that that's gonna be a big thing in RSA. No, I, I agree.
And, and Maya culpa, I'm just gonna admit this to my entire listening public, I almost fell for a phishing attack the other day because it came from somebody that I recognized the email and I'm like, oh, maybe this is something they need me to take a look at. And as soon as I clicked on it, it wanted me to log in with my Google address, I was like, wait a minute. Something doesn't smell right here.
And then when I mentioned it to the person, you know what their response was? Who in the hell uses Zoom docs? Like, like that?
That was their exp And, and then of course I'm like, you know, you got a point. Nobody, nobody does that. And, and, and that's the problem we're running into is we have taught people the basics, right?
Like, you know, don't give out your, your PII on a phone call or don't just answer the emails that people send you, check all the links, but I check the links and they looked legitimate. It's just the, the, the way that we're, we're hitting a thing like, oh, I haven't logged into that system for 20 years. Like, like obviously I must reset my password to get in there.
Oh, oh wait, no, you're harvesting information now. And, and that's, I think that's where people are kind of figuring out, like you can't bust in through the front door, but you can come in through the smoking door if you're paying attention. And for those of you who are in your twenties, the smoking door used to be the unsecured door in the building where the smokers gotta go out and have a cigarette.
And, and there are tons and tons of stories about, uh, penetration testers who slipped in there 'cause they had a pack of cigarettes and nobody asked questions. Yeah, Jack, I think you're right to, to talk about identity as being one of the great unsolved problems. Uh, and it's just getting worse as we throw ag agentic AI in there.
But also social engineering, uh, has been an issue basically since the dawn of computing. And I don't see it going away. And in some ways, uh, you know, LLMs make it easy for maybe non-native language speakers who are attacking a specific country or user group to craft even better, more effective social engineering messages, Right?
And, and we have, we have developed ways to eliminate some of the risks with social engineering. So we've moved from password based authentication to Passwordless where you use, uh, uh, you know, two-factor authentication is still easy to be, uh, socially engineered. But when you use pass keys, Fido pass keys, it's a lot harder to break into.
There's no known compromise right now. It's very hard to social engineer it. It's very locked down.
Uh, you know, and yet most companies I deal with are still, you know, most enterprises, you look at most enterprises today, and they barely make MFA mandatory, let alone go to this new technology. And I don't understand, given the breadth of capabilities we have the number of vendors at RSA who are gonna be talking about this, what, why is it so hard to get people to put the very simplest lock and key? They'll spend a billion dollars on advanced, you know, zero day protections and endpoint protection and this, that and the other, and they still allow people to log in with basic password protection, which is, it's, it essentially meaningless, you know, and I don't understand, I, I wish there was some way at the RSA conference that that could be, you know, we could spend an entire year just saying, lock the front door.
You know, I maybe it's because there's not a great way for, uh, security companies to make money off of pass keys. Is is could be the issue. I'm being a little cynical, but I, that that could be part of it.
Oh, Drew, the Senate comes out again, boy, we haven't seen him in a while. No, I drew you bring up a really good point. A lot of it is driven by, by, uh, basically by investment potential, right?
Like, like I, it, it's the old, uh, the people who distrust, uh, doctors and pharmacists. 'cause they're like, well, why would I cure you when I can just sell you, uh, you know, a solution to your symptoms? Just don't, don't lump me into like anti-vax or anything, Tom.
No, no, no, no, no. I'm, I'm not, I'm definitely not. But I'm, what I'm saying is like, there's always gonna be this suspicion amongst people that I'm not gonna use the most secure thing because then it's a solved problem.
But I think that the issue that we're running into here is that there is so much reticence from the, the traditional security people to upset any apple cart. Like remember when NIST came out a couple years ago with the, the guidance that you shouldn't just change your password every like 60 days because it didn't really matter. It was actually better to keep the same password, just make sure it's, it's kind of strong because constant password changes cost people to wanna jot them down and stuff like that.
Do you remember the uproar in the community? Like there, it was very clear draw on the battle lines. It's like half of everybody is like, yeah, I guess that works because for the reasons they stated and the other group were like, oh my god, no.
If you, if your password's older than your underwear, then you, you have to get rid of it. And like, how can we still disagree on something like that? And, and don't get me wrong, I pass key everything I touch because it is to me the most secure form of providing that.
In fact, when something doesn't pop up and offer me a pass key, hello Salesforce, um, I get worried. And, and, and, and that kind of goes that hand in hand with things of like, I guess a password dialogue is comforting to people because they're like, oh, I can just tighten the password in. Or like, okay, who types their password in anymore?
They use a password manager. It's always hard to change, uh, people's workflows. Uh, you get resistance, you get pushback, and there may be systems in an enterprise that aren't able to support pass keys and then you're working with dual systems and that's a nightmare to manage.
Yeah, I think you're a hundred percent spot on, uh, that there is a lot of inertia involved and a it is, as you noted, it's, it's, you know, pass keys are very, very important, but not very, very profitable. And you know, as, as you know, I work with a lot of cybersecurity vendors and it's always easy to tout and talk about the shiny new toy, right? We've got this new thing and that new thing and you know, and we've been doing MFA for a decade now, and MFA is, you know, it's sort of passe now.
We don't talk about it. It's just sort of there, it's table stakes, but we also don't make it mandatory. And, you know, it's, it needs to be, these things need to be, you know, if if the new vendors on the block started with developing a sys their systems by never offering you the choice of passwords and only give you the choice of pass keys that would, we would be better off.
But even the brand new vendors who are cybersecurity vendors still build their SaaS apps with a username and password. And I just think that, you know, that to me, I wish that that was part of the RSA conversation in the community. You know, the, the theme of RSA this year is all about community and bringing people together and, and the, the attackers work as a community, right?
We have all these different cartels that are various groups of people that do things on the attacker side and they coordinate and they cooperate. And it would be really nice if on the vendor side and the defender side, we behaved much more as a real community and said, not only are these best practices that we advise you to do, we're gonna eat our own dog food and we're gonna force you to do it by not allowing you to register for this thing. Whatever this thing is, we're, we're going to eliminate this.
Here's our phase out plan over time to eliminate passwords from our application. So you better get used to it and get ready for it. We just talked about a couple weeks ago, I think on a packer protector episode about Windows mentioning that, hey, NTLM is eventually gonna go away, right?
And that's been an issue for decades, but because of legacy applications and legacy systems, they have to be very deliberate and very careful and finally getting rid of it. So yeah, it's absolutely just vendor, vendor. I, it's a great point, Jack and I really do wish vendors would eat their own dog food and start to push their customers and the market in that direction.
That would be really fantastic. We could record a whole episode about, uh, sun setting technologies. Like on the one hand you've got Windows who are like, Hey, listen, for real, before you know, 3000, we are gonna get rid of NTLM.
And on the other hand, you've got companies like Apple who are like, you don't need a floppy drive. And, and, and you, you're always kind of trying to find that comfortable balance of when do I start sunsetting technologies versus when do I just jump right out there and say it's gotta go? I, I think that the challenge though is that a lot of companies have used some traditional technologies to kind of solve security problems.
And when you sunset those technologies without a clear roadmap to, to basically give them an option to change what they're doing, it causes a lot of friction. It's like, oh yeah, well, you know, you didn't have a mechanism for us to be able to do that through the API back in the day. So like we, we routed it through an SMB one share, and you're like, why on earth would you do that?
Because you're like, well, in the early two thousands it's all we had. And so you, you just, you kind of have to build on things because again, it comes back to the whole, this is a solved problem and I don't need to work on it anymore until it's not a solved problem. Because instead of a better solution coming out, we're getting rid of the solution that you built.
And, and security people need to get much, much better at that. So all of my security friends who are out there do not get mad when people move your cheeks. Anybody who ever read that book is giggling right now.
Alright, so I'm gonna, I'm gonna turn this around and I'm gonna ask you guys, what, what do you think is your one big prediction for RSA? Like what, when, when we're recording the post RSA podcast and, and people are talking about, oh, did you see this? Oh, did you see that?
What is the one big thing coming out of it that you think is gonna kind of cha change the trajectory or, or further the trajectory of what we're seeing in 2026? Well, I'll, I'll say that the challenge I have with answering that question is right now, I don't think the vendors are in big picture mode I don't think they're focused on any one big thing that's gonna change the way we think about the industry. I think everybody right now is in shiny new toy moat is, is, come look at me, I've got this cool little thing.
And you know, we've really avoided the topic for a long time, but it's all gonna be about ai. And, and I, I made a challenge to myself last year, and I think it's gonna be even harder this year, which is to walk the conference expo hall, which is gonna have five, 600 vendors in it, and to find the few booths that don't actually have AI plastered all over the booth, right? And they're actually talking about, this is the very specific problem we're solving for you.
Not we're pasting AI on top of our product. And for me, that's really the key is now I'm all about AI and understanding impact of AI for security and how you secure ai. But still, there's a whole lot that happens without AI for a whole lot of enterprises and smaller companies that we need to be thinking about and securing, particularly around identities and the challenges, finding the, those technologies for me, I mean, maybe one good thing that could come out of this focus on AI given, you know, the rise of agentic AI with these, you know, sort of autonomous entities running around doing things, that's an identity and access management problem.
And if people think it's big enough, maybe that will help us get our arms around AI identity more broadly, uh, as an industry and a community and help drive some change. For my part, I think what we're gonna see is a lot of companies that are gonna start beating the drum of reduced time to vulnerability exploitation. Like, uh, they'll, they'll probably put AI all over it 'cause that's what sells right now.
But, but they're gonna, they're gonna start saying like, if, if something's been reported, just assume that it's already being actively breached. Don't, don't try to hope against hope. And, and maybe that's gonna solve some of our problems, right?
You know, like maybe the technical advisory board has to meet an extra day this month to approve the patches to go out. Or maybe we start trusting automated deployment systems to do that. But like, I mean, you know, drew, you and I both run weekly news podcasts and oh my God, if we actually just posted all of the vulnerabilities that we did, we could make a podcast out of that.
Which by the way, is, um, you know, uh, risky Business is a great podcast basically for that. If, if you, if you wanna go listen to Patrick Gray, but like, there are so many things that we have to deal with on a daily basis, and it's not like low level stuff. Like these are like, you know, CVSS like nine plus all the freaking time.
And I think that we gotta get better about detecting and remediating those things. And, and if that involves using non-human coworkers to do that, then great. But otherwise, I mean, you know, what can you do?
Alright, um, these two gentlemen do a lot of writing. They do a lot of content creation. I wanna give them an opportunity to tell everyone out there where you can find what they're doing.
So Jack, if people wanna check out some of the stuff you've been creating, Uh, you can find, uh, my content on my website at paradigm technica do com or LinkedIn and the usual social sites as well as I do write, uh, column for Security Boulevard. net. net.
You can find me on LinkedIn. And I'm also on Blue Sky at Drew CM And I produce a lot of security content, not only here at Tech Field Day, but also as part of the Security Boulevard podcast with my co-host Alan Shimmel, Fernando Montenegro, and Mitch Ashley. And don't forget that we at Tech Field Day are going to be at RAC for the first time this year, and we're gonna be getting great presentations from companies like Veeam Object First and Commvault.
If you head over to tech com, you can see more information about that. And I know we're gonna have some great content, both video, audio and written coming outta that. Thank you very much for listening to this episode of the Tech Field Day podcast.
If you enjoyed this discussion, please do us a favor, subscribe on YouTube or in your favorite podcast application. 'cause we don't want you to miss any of our episodes. If you do that, please consider leaving us a rating or review and possibly a comment so that we know you enjoy the content that you're seeing.
This podcast is brought to you by Tech Field Data Home for IT experts from across the enterprise, which is a part of the Future Group. For upcoming events and more episodes, you know what to do. Head over, detect the daycom slash podcast or check us out on Techstrong tv, including the Techstrong TV app that runs on iOS devices, set top boxes, and pretty much everywhere.
In fact, install it in your doctor's office 'cause we want them to check out our podcast too. Thanks for listening and we see you all next week. Hi, I am Mitch Ashley with the Futurum Group.
Today we're unpacking the Nokia Bell Labs recently developed model for data center fabric reliability. We'll look at how the fabric design plus operations, especially automation and AI ops, can move enterprises from a legacy PMO baseline to an FMO with Nokia's Sr. 1 nines availability and shrink downtime significantly.
And I'm Scott Roon with Al, it's the age of operations. You know, hardware still matters, but operations dominate outcomes, you know, day two and beyond. This Bell Lab's model includes significant detail, and today we'll zoom in on some key areas in operations.
We'll also talk on talk, touch on the significant financial impact as well. Um, you know, the model shows that reliability gains can result in real cost reduction and, uh, that should be no surprise to those of us who've been, you know, in the ops world for some time. Very good.
Well, the model treats configuration net ops is one of the main areas for improvement, including common cause failures. So what does it mean in practice, Scott? The, the model shows the most significant reduction in downtime measured in absolute terms, you know, minutes, um, eliminated per year is achieved during the config and provisioning phase, driven by decrease in confi related errors.
Errors. There are multiple key components and mechanisms in the Nokia solution at the heart of the model, first you have SR Linux, the operating system developed for modern data center operations. It facilitates efficient structured and language agnostic comms between system components, minimizing operational complexity and reducing the likelihood of user error.
Next, you've got features like ZTP zero touch provisioning, which are integral to EDA, that further eliminate manual intervention takes the human out of the loop for opportunities to inject errors, um, and contributing to that enhanced reliability for operational efficiency. And then there's ida's digital twin construct that provides like, for like environment, um, to design and validate network configs with correct intent inputs. This minimizes config and provisioning errors as in the configs generated in the digital twin directly mirror production that's not special configs in the twin, um, and then modified to push in production.
It's actually the same configurations reliability is further enforced and improved by it's built-in dry run validation routines prior to every config being pushed into the network, helping ensure accuracy and consistency before changes are put into the live network. Now you mentioned the term age of operations. So talk to us about why is ops a primary lever in this model?
At the simplest level, you know, once you stand up a data center fabric, most of the day-to-day work in net ops is around operations and monitoring. And with AI ops centering the room here, we have a day one killer app that drives the use for NetOps natural language processing. I can talk to the fabric to see what's going on.
We also benefit from increased programmatic access to the fabric. For example, SR Linux provides a single API for set get and streaming telemetry resulting in less operational complexity and minimizing, minimizing mis configs. 1 nines.
When all these features are combined from a network operating system architecture perspective, the event handling system in SR Linux and e DDA is capable of proactive predefined actions based on things like port saturation packet drops, looking at other network conditions to automatically trigger corrective actions and prevent network degradation and mitigate issues before they occur. So putting that all together, it sounds like what you're saying is tools operationalize the design. That's a really good summary of a very long description, Mitch.
Um, exactly. You know, design gives you redundancy, operations makes it reliable every day. The details matter for sure.
So planned work can still hurt, uh, availability. How does, how does the model address that and, and Sr. Linux in particular, and how do they handle ongoing maintenance such as upgrades, patches, the things that we commonly do?
We need to point out the fact that SR. Linux uses an unmodified Linux kernel. This is what the rest of the world is using for Linux that's gives you, uh, the ability to tap into a worldwide community of developers hammering away at it every day, identifying potential performance and security issues across many, many different application areas, not just networking.
In addition to that, EAP provides built-in capabilities to ensure network reliability during maintenance operations. You can use the platform to gracefully gain traffic, drain traffic from uh, a node and put nodes into maintenance mode. Um, preventing service disruptions, minimizing traffic, G loss, EA also centralized and stream centralizes and streamlines the upgrade process.
When a route router's locked and is ready to reboot, it significantly re reduces the actual maintenance window. EA also gives you group-based upgrades and stage promotion, um, to shrink maintenance windows. Reduce the time used for maintenance windows and limit that blast radius.
You can pick targeted nodes, you can automate pre and post checks, and you can roll forward only when you're a process gates get passed altogether. These features, um, result in enhanced reliability and minimize downtime. All the upgrade steps can be tested, um, with, um, the EA digital twin functionality in a like, to like environment, this is what gives you impact, um, and reduces, um, maintenance issues for far less annual downtime as you move from your present mode of operation to your future mode of operation.
Excellent. So who should people talk to at Nokia to see how this model and can apply to their environment, their data center network? Well, to learn more about the model SR Linux and Edda, contact your Nokia account team or your regional business center contacts and they'll work with you to work through the details.
Thank you, Scott. Appreciate, uh, you sharing us some interesting facts from this study. Thanks, Mitch.
NVIDIA's fiber diet, open claw law sha Microsoft plugs up their pipeline. Poor K chat, GPT Google does the robot iCloud use. Accenture looks at okla Qualcomm wows at MWC and more in this week's episode of the Tech Field Day rundown.
Hello everyone and welcome to the Tech Field Day rundown. Hey, we're almost to spring, uh, unless it's 85 degrees outside, in which case we're practically to summer. Uh, but another thing you need to keep in mind is that you have to be radically correct whenever you do all of the things since it's national grammar day.
And, uh, it's a day that's near and dear to my heart unless I end a sentence with a preposition and in which case I'm going to get yelled at, but not by my co-host, Mr. Alistair Cook. Al, welcome to the show once again.
Welcome Tom and I would never yell at you remotely. I would would've to be there with you in person for yelling, uh, particularly on National Suns Day. I personally don't have any sons, although I'm of course a son.
Um, but celebrating today all of the suns of the world. Yes, it's a National Suns Day on a Wednesday, but, uh, one thing that isn't gonna change no matter what day of the week it is, is all of the news that we're gonna be bringing to you because it has been a very busy week. And we're gonna start off with our friends over at Nvidia because they are doubling down on AI infrastructure.
With a $4 billion investment in two different companies, $2 billion each, two momentum and coherent. The move strengthens NVIDIA's position in advanced photonics, a critical technology for next generation AI supercomputing that uses light instead of electrical signals to move massive amounts of data. Everyone's favorite CEO and walking leather jacket, Jensen Wong called it part of the largest computing infrastructure build out in history as rivals like a MD and Meta ramp up their own AI investments.
Nvidia securing long-term access to optical capacity that is needed to power AI's facilities tomorrow. Al, I know there's been a lot of talk about using Fiber everywhere. Is Nvidia kind of doing an end run around people that don't realize they're gonna need it very soon?
I think that very much what NVIDIA's trying to do here. So they've thrown some money. I mean, $4 billion is a lot of money to you and I Tom, but to Nvidia it's, it's not really that big of an investment compared to the other money that they've spent.
So these investments are in a couple of, uh, silicon photonics companies and the investments are gonna help those companies with RD both Lumen and, um, sorry, luminum and Coherent have, uh, made commitments around more r and d and more r and d onshore in, in the United States, which of course suits the current political crime quite well. Uh, there's also some guaranteed availability of buying product. So in addition to giving these companies money or investing in these, these, uh, companies for their r and d work, there's also a commitment that Nvidia can buy, uh, billions of dollars worth of the silicon photonics that come outta these development works.
The aim with the silicon photonics, and it's been around for a while, I know I've, I've seen other vendors talking about silicon photonics for at least 10 or 15 years. Uh, the idea is to move away from using those electrical signals, uh, where the propagation and the, the cost and the particularly power that's required to move large amounts of data can be very limiting. Uh, move towards a, a scenario where we're using light being sent through fiber rather than, uh, electrical signal sent through copper.
I think this is a, a very significant element of protecting the future for Nvidia. Nvidia has had a very strong head start as being the, the most well-known brand for AI infrastructure as they were the most well-known brand for, uh, crypto beforehand. Uh, but we're seeing a lot of investment in alternatives to Nvidia.
We're seeing, um, investments. We saw meta investing $60 billion in a deal with a MD and Marvell. And so these are definitely, um, there's, there's a, a maturing in the market, seeing that Nvidia isn't necessarily the be all the all and I think this is a very much a protective move for Nvidia making sure that they get the first bite at whatever the next silicon photonics, uh, technology's gonna be around.
Of course, they have other companies working on silicon photonics that might wanna either take a cash injection or be ready to supply people who maybe aren't Nvidia in the future. So no guarantees that this will protect them forever. A new vulnerability called Claw Jacked allows malicious websites to silently hijack open clause locally hosted AI agents by exploiting trusted local host connections, attackers can brute force access, register ERO devices and take full control all without the user's interaction.
Now, there's a patch available, but the issue highlights a bigger concern. Powerful AI agents running with broad system access, very little oversight security experts say that organizations must govern AI agents like any other high privilege identity. So we've now got an even more powerful kind of non-human entity, Tom, We do.
And, uh, to quote, uh, Battlestar Galactica, all of this has happened before, and all of this will happen again because I was literally asked this weekend by someone who was probably, I don't know, 13 or 14 when they were talking about security. Why was it back in the day that web browsers could install all of this crap on your system? And, uh, for those of you who are old enough to remember a browser helper object, you know, the kind of special hell that you had to deal with to get rid of those things to avoid the 80,000 popups that just wouldn't ever end on your screen.
And eventually we had to do things like architecturally change the way that Internet Explorer worked by creating Chrome, mostly because Chrome doesn't suffer from a lot of those problems. Fast forward to today, what is the helper object that I'm corrupting? Oh, that would be the AI agent that I have silly given all of the privileges on my machine.
And I feel like this particular flavor of claw is gonna be the story that keeps on giving in 2026. I mean, we've talked about it so much already, but it feels like every week someone kicks over another rock and it just scuttles away with more problems like, oh, I don't know, letting it run with pretty much root access on your system. Again, something I talked about this week, uh, when I was teaching people about cybersecurity and I, I kind of half jokingly said, you know, there's no, uh, Linux antivirus because no one on Linux is dumb enough to run as root on a regular basis.
And then I said, you know, there actually are Linux viruses, but they're a lot less targeted because the system tends to be hardened. But, but what if I ran an agent on top of the system that did have root access at all times, or maybe it doesn't have root access to the system, it just has root access to my email and my bank accounts and all that other stuff. Boy, wouldn't that be a juicy, tempting thing to just crack open and and siphon as much as I could?
Yeah, yeah. It would like siphoning drawn butter on top of a lobster claws, for example, uh, or crab claws or, or whatever, uh, form of mollusk that you choose to eat. But the thing here is the experts are exactly right.
You cannot assume that every piece of software on your system runs with the same level of privileges. Ironically enough, one of the reasons why you don't have this problem with browsers causing these issues now is because effectively most of them are sandboxed. They don't have the ability to affect other things on the system.
Everything kind of lands in its own little playpen and it doesn't ever break out. It's just, in this particular case, someone found a way to call a function that was probably listening in the web browser anyway and then corrupt it. So, yeah, uh, here's a fun, fat kids, uh, you should secure software.
Who knew first principles and all that? Hmm. Okay.
Anyway, now I'm hungry for lobster. Uh, but before I get to my meal of lobster, I think we need to talk about a new a CM paper. And because Mark Russinovich and Scott Hanselman of Microsoft caution that generative AI could unintentionally weaken the software engineering talent pipeline, they argue that a agentic coating assistance amplify senior engineers while reducing opportunities for junior developers to gain critical experience by making mistakes.
The result may be a seniority based shift in hiring that narrows the traditional growth path from entry-level coder to technical leader, their proposed solution, a structured mentorship model where AI tools or configured to support learning, not just productivity, ensuring that the next generation of developers builds judgment and expertise that AI cannot replace. Al I was watching a video, uh, recently where someone said, basically, the reason why you end up making senior engineer is because you screw a whole bunch of things up as a junior engineer and with ai now you won't be making those mistakes, which means you never get the experience you need to become a senior. Did the, uh, folks over at Microsoft finally figured out that that might actually happen?
Well, I think both, um, mch Scott Hansel, my nine, they're very well respected in the community within the industry, and they're pointing out something that's, uh, I think reasonably well known in the industry. And it is that when you eliminate the value of junior roles and only have value in senior roles, you make it very hard for people to become senior. Uh, and that doesn't matter how, how that comes about.
In this case, it's coming about because AI tools are eliminating the junior roles. They're basically being able to make all of the mistakes that a junior engineer would make, uh, rather than the junior engineer getting to make those mistakes. I think one of the elements is that it's telling us that there isn't going to be the same path that there has always been to go from a junior developer to being a senior developer, but maybe there's still a different path because the use of an AI agent to write things is a different way of approaching software development.
And so the, the role of the junior engineer is going to be learning how to tell the AI agent to do its job well, and it still works the same way as you would've started with a developer as a a junior developer, you get to look after a small piece of code, or now you get to look after how you describe the function of that small piece of code to an AI agent. And so the role of the junior is shifting, but also the role of the senior is shifting. The senior engineer is still, uh, looking at more of a wider view architecture.
And this is the place where AI agents at the moment, coding agents tend to fall down as with architectural view rather than straight up coding. Now, absolutely in the article that, um, Scott and Mark wrote, they talk about some of the mistakes that an AI coding agent will do that absolutely mirror what a junior developer will do. They talk about adding an arbitrary pause in a piece of code to avoid a race condition when there should be proper coding to actually prevent the race condition rather than avoid it showing up in the tests.
So that kind of, um, view that a, a junior engineer might just attack the symptoms and produce lots of technical debt and that the senior engineer will attack the causal problem and prevent that accumulation of technical debt. Uh, the thing is that when we shift to AI generates most of our code, and we just describe what it should do, right? So this is some of the, the sort of design based driving of the AI agents.
We care less about a bunch of the things that we used to care about deeply. So one of the elements in here is they, they talk about the code base reimplementing the same functions multiple times with these AI agents. Uh, and that leads to messy code.
Well, when humans don't need to read the code, it doesn't matter so much if it's messy, maybe we just embrace the fact that AI generated code is the future and we teach junior engineers to prompt the AI to actually write the descriptions well and have them move outwards from smaller pieces. I think the approach that the authors of the paper, uh, mark and and Scott proposed, which is that, uh, companies invest in the future by accepting less productivity out of their junior developers than they might want. In fact, possibly, uh, these junior developers will slow down even the senior developers.
That's never gonna fly in business because all of these, uh, all of our companies are, are focused on what's the results for this quarter and this year they're not gonna invest in five to 10 years of developing a staff member, particularly with the employment patterns we see where staff are staying for 2, 3, 4 years at a company at most, and then moving to a new company. Where's the benefit to that first company and investing in making that, uh, that developer a better developer when they're going to move on before they even get to the point of returning on that investment. So I think yes, in an ideal world, we would've this practice where, uh, we're teaching junior developers to be better developers in the ways that we have in the past.
But the reality is we need to embrace the fact that being a developer is different now than it was before these AI generated coding tools turned up, uh, progressively, those tools will get better and will have less reliance on human judgment of, of the individual pieces of code. Researchers say that an attacker used AI chatbots, including both Anthropics, Claude and open AI's chat GPT to breach Mexican government networks and steal up to 150 gigabytes of sensitive data. According to FI findings highlighted in CrowdStrike's latest threat research and reported by Bloomberg, the hacker allegedly jail broke, clawed generated exploit scripts, network weaknesses and automated parts of the attack.
The incident underscores a growing trend. Cyber criminals are using AI tools to accelerate their attacks, expand their reach and target AI systems within the enterprise organization that provide a wonderful new attack service. Tom, should we be worried and turning off AI everywhere?
I don't know that we can at this point 'cause the toothpaste is out of that particular tube. And I love to see the intersection of two things that I was super worried about using AI to accelerate the way that you attack things and vulnerable nation states who are believing themselves wide open. Oh, look, I I got a bingo on my card.
It's, it's amazing how that works. This is the natural result of where we're at and we talked about it a number of times on the Security Boulevard podcast. AI in and of itself is not evil.
It's only as evil as the people who use it. And in this particular case, it took a little doing, although I I do think jailbreaking Claude to make it do evil things was, was rather, um, uh, a chef's kiss moment. Uh, you know, given that that Claude has purported to basically try to be the, the, I don't know, uh, altruistic one out there, um, but you know, with a little jailbreak magic, Claude will just go do what you want it to do and including footprinting your entire network and automating some attacks.
And how does it know it's not running a test or some other thing? This is only going to get worse. And that's when you consider that a lot of the other systems out there don't kind of have the guardrails in place to prevent this from happening.
Uh, and if you can develop a reliable jailbreak that will let you get out of the models guardrails, it's really only a matter of time before we start seeing this being employed against hardened targets. Yeah, let's be honest, getting some of the easy to attack ones is probably not going to be difficult right now. I'm sure there are already folks that are, uh, mopping up some of the, uh, the lesser secured governments out there.
But what happens when it becomes the Pentagon or Beijing or the Kremlin or you know, the UAE or Riyadh or some other place where it could cause real problems? Well, we can totally defend against that because we have the best cybersecurity out there, Uhhuh, and you have an attacker that doesn't eat, doesn't sleep, doesn't care, and it will not stop until it has completely invaded your network and stolen every secret that you've got. And then it's probably gonna ransom some of them for bitcoins and crash your entire infrastructure.
So who knows what might happen after that? Uh, we have to start putting guardrails in place, and we have to start anticipating the fact that the attackers have better weapons and they're going to be coming even harder than we've seen in the past. Google is folding its robotic subsidiary intrinsic back into its core business that's signaling a bold push into physical ai.
The move gives intrinsic direct access to Google's AI models like Gemini and the scale of Google Cloud while aligning more closely with Google DeepMind. CEO Sundar Phai has reportedly described the effort as Android for robotics, which feels like a tology, but it is aimed at creating a standardized software platform for industrial robots. Similar to how Android, the operating system unified smartphones as competition heats up with players like Amazon and Tesla investing every penny they can into physical AI robots.
Google is betting that AI powered automation could define the next era of manufacturing. But the question that I have is, are they going to be three laws compliant? Al Absolutely not, because they're not actually gonna be making that significant of a Judgment.
Kind of wish that that was the, uh, top level view of how things work. That's Asimov three laws of robotics about not killing humans. That's kind of nice to not kill humans.
Um, essentially what's going on here is intrinsic, uh, was was one of the alphabet companies. They were building a platform to democratize access to robotics, and of course, AI has to be added to everything. AI's been in robotics for a long time, particularly around the idea of doing, uh, image recognition components.
So, um, what we would've previously called, uh, the the sort of predictive AI or the, um, machine learning AI rather than the generative ai. Uh, and I think we'll see more of that kind of AI continuing to be used in robotics because it suits what robotics tools do. Uh, the ability to describe how you would like the robotic to interact with whatever component you're assembling or manufacturing, uh, will be useful.
I think that's the place where maybe large language model for that human described freeform description. Fundamentally, when the the robot is building something, we want it to follow a determined path. We want it to absolutely be handling the components that are in its face.
So hopefully more of the machine learning kind of behavior we'll see in the, the driving of these robots. The overall objective here for Google is that this intrinsic tool set is gonna become the most common tool set for building, uh, robotic paths, allowing more organizations to use robotic manufacturing. And yeah, the AI flows over it, but I think the, the real thing in here is this flow state, um, development environment for building the actual workflows that, uh, that your robots are gonna follow and your manufacturing processes in here.
I think it's pretty cool to aim to have a, a standardized simple way of doing this with a Google standardized simple way will be the winner. We'll see there's some previous, uh, history on that. This is probably why I sent up, was talking about the, uh, Android for robotics because Android has become one of the dominant, uh, platforms on smartphones.
So yeah, maybe this, this will work out to be one of the dominant platforms for building, uh, robotics and robotics paths. 2 billion. This organization will be folded into the connectivity division of the consulting firm.
Accenture announced that they will target LER services for end to end network intelligence for AI based transformations. Let's CLE tools, uh, I know a lot of people are, I haven't had to use EAU for quite a while, and a lot of companies are starting to ask what this means for the future because I can remember a time way, way, way, way, way, way back at wireless field day two in 2011 where EAU was the upstart going against companies like Fluke Network's, air Magnet, and then eventually Ekahau upset air magnet and became the dominant force. And now you're seeing other companies like homina and STOs and, and others that are creating tools to kind of take on the, the big giant, but here's where it gets a little bit interesting.
So I did some digging into, uh, you know, the wireless industry and started asking some very important questions about where the value would be in Accenture paying so much money for okla. And a curious thing happened, uh, for the last few months, maybe a little bit longer. Um, a lot of the designs that have been created, there's been an option to upload them back to Ekahau and, and make sure that you define that the things that you're uploading belong to Ekahau and they're not yours necessarily, right?
Like it's sometimes this feels like standard bullet boilerplate, but what would the value be in that? Well, I don't know if a large company that does consulting work wanted to, uh, acquire a lot of data about wireless installs real fast. Do you think that that could be valuable?
Because I think that could be really valuable. And another thing that has been kind of out there that maybe not everybody knows is an offering that Ola was putting together that would allow organizations to use OLA tools like Ekahau and Speed test to verify their connectivity. So like one of the things that we've seen, a lot of people will choose their hotels, for example, based on amenities, right?
Does it have a spa? Does it have a bar? Does it have good internet connectivity?
And how would you be able to test that? Well, in this case, Okla was offering a service that said, well, you can put a little plaque on the wall that says you were a five star Okla hotel, because we use speed test to verify that on a, you know, regular basis. And of course, you know, every so often you'd want to go back and and reverify that, right?
How much do you think that would be worth to a company like Hilton or Marriott or any other large hotel chain that's trying to use that as a differentiation piece, especially if they already worked with Accenture and Accenture could just roll the cost of that into the renewal of their contract next year. Do you think that they could possibly make up the difference in the acquisition cost of a large company like that? Yeah, yeah.
I absolutely think that they could. And I think that that's the value here is that Accenture bought okla with all of that rich data for all of these deployments to understand how people want to deploy the things that they're building, while also looking at how they can create services revenue to regenerate those costs and kind of basically make the system pay for itself is the only thing that makes sense to me. Uh, the big question now honestly is what's going to happen to a company like eca?
How, because I don't see an immediate synergy with that. Um, there's possibility that Okla could just kind of continue to use eau the way that they've been using it, that would make the most sense. There's also a possibility that they could spin cca how out and see if it could stand on its own or possibly see if someone wants to buy it.
I don't have a good answer for that because we're still early in this, but I promise you whatever the answer is, Accenture's only gonna do the thing that makes them the most potential revenue in the future. We're gonna be talking about Claude again because they experienced a widespread outage, but it wasn't because of errors, it was because of a surge in user demand tied to political tensions in Washington DC following a very public clash with the White House and Department of Defense, as well as criticism from President Donald Trump. Claude briefly topped app charts ahead of open AI's chat, GPT driving record signups and that spike strained login systems and consumer tools.
Though enterprise APIs remained operational probably because they weren't running on the same servers, services were restored within hours, but the disruption highlights the infrastructure challenges AI platforms face as they scale during moments of national controversy. Al, do you think Claude could provide code some better login servers for the consumer side of things? Well, I think you always make a decision around how much resource you provide to the people who aren't giving you money and how much resource you provide to people who are giving you money.
And that's a little differentiation in what, what went on here and the enterprise, uh, APIs, the ones that that, uh, philanthropics actually getting money for didn't go down. They scaled very fast and, uh, very well. Uh, yet the things that are, are not generating any revenue yet.
The free access to Claude was the thing that failed. And as, um, uh, you know, in terms of architectural design, I absolutely would, uh, design a system that didn't allow my free tier to scale infinitely when demand came up. I'd much rather have it fail than cost me vast amounts of money.
Whereas if I'm earning money from the use of the the resource, I'll let it scale as much as possible to get more income. So there's an element here around this is absolutely how system design works. So, uh, having a, a mass increase in, uh, the consumption of the clawed, uh, free addition is likely to cause, uh, an outage.
It's just a matter of how much of a scale of of mass effect. Uh, this is definitely one of those streisand effect kind of elements where, uh, the president stated that, uh, and Pete, his Secretary of Defense stated that, uh, there were all of the US Department of Defense Department of what you like, uh, is gonna move off using an and Claude tools moving to using open AI tools because Anthropic declined to roll back the protections against mass domestic, uh, surveillance, which as I understand it, is not permitted under the US Constitution by the government. Uh, as well as, uh, not turning off the protections against fully automated lethal weapons being built using anthropic tools.
Uh, so this was a sort of line that, that anthropic have made and said, we're not gonna allow this use case open. AI have said Yes, we'll allow this use case. And so the government loves open ai and as a result, lots of other people like philanthropic, uh, this kind of thing will roll back and forth.
It's, um, not overly surprising that people get very heated around which AI platform has what ethics. And it's a discussion that's not over yet. The discussion around the ethics of use of AI and what are acceptable uses is gonna continue to roll onwards.
Uh, and in terms of that outage that appears to be about four hours of outage, yeah, that's enough time to go back into that backend and say there's the scaling for the free tier. Let's increase that and allow more resources to roll out and eventually things become less, less overloaded. Of course, anthropics hoping that all of these free tier users will come in and decide that yes, this is worth something worth paying for and start giving them money.
Uh, I know locally here in New Zealand, uh, some of my, my local development, uh, colleagues use Claude code extensively for modern coding techniques where they describe the outcomes and say, Claude Code gone write my code. Same sorts of things I was talking about earlier in the, uh, Microsoft related story of, uh, junior engineer, senior engineer, right? The skills they're learning is to write that description.
So told code definitely very widely used in that more declarative desired state kind of description of how your code should work. Um, where was I going with that? I think I hit headed out on a random tangent and uh, I should climb back off my soapbox and move to the next story.
At Mobile World Congress 2026, Qualcomm laid out its vision for ai, native wireless networks, introducing its wifi eight portfolio and the Fast Connect 8,800 platform with multi gigabit speeds and improved performance in dense environments. The company also, its X 1 0 5, it's a 5G modem RF system, and it's designed to support 5G advanced and early six G development with built in AI for Sparta connectivity and efficiency. With a new global six G coalition and expanded infrastructure under its dragon wing brand.
Qualcomm is positioning wireless networks, not just out for faster speeds, but as an intelligent AI powered computing platform for the next decade. More AI for the future, Tom, Possibly, but here be dragons. And I'm not just talking about the branding that Qualcomm seems to use on all of their chips.
1, and this is something that I brought up, uh, back at CESI wrote in a blog on my own personal site, eh, wifi eight's not a thing. Uh, sorry guys. Uh, there it's pre-standard, it's not decided.
Uh, it's pre-standard wifi eight, which means a lot of the features that are in there right now probably are more or less baked, but not final. So I'd be a little weary about doing anything wide with this deployment. It seems like Qualcomm's kind of, you know, aiming this at development stuff because it includes wifi eight and six G, which are not the same thing for those people out there that are curious, it's just, it's faster.
It's, it's trying to make better decisions and do better things. And why would you want to do that? Well, it turns out that we are hungry for data right now.
We, we need all the datas everywhere, you know, fist full of datas even, uh, which was also a really excellent Star Trek next generation episode. But just like that, uh, you can never be sure if the data you're getting is good or bad until you get it back into the system and process it. And you need to get it from where it's at to where it wants to go.
And as we know, data has gravity and how do you overcome all that data? Gravity? Well, you send it as fast as possible.
And that's kind of what I'm looking at here, is they're using AI in this case a little bit of buzzwordy to engineer better wireless networks because one of the things that we're running into is no amount of spectrum is gonna reduce the noise. No amount of multi antenna operation is gonna make things go faster without some kind of overarching software to kind of guide these things. And so a lot of these tweaks are kind of designed almost like OS 10 Snow Leopard, which was designed to just make everything run a little bit better.
That's what, that's where we're looking at here. Seven was a big leap forward, wifi seven that is, and wifi eight is kind of be, you know, kind of doing some cleanup work behind the scenes. Uh, but by positioning this as, you know, an intelligent AI powered computing platform, what you're really saying is we're gonna turn all of those edge devices, whether they're phones or tablets or laptops or I don't know, headsets or whatever into data collectors for AI algorithms to crunch on.
And the faster we can get that data uploaded to wherever it lives in LLM land, the better off we're all going to be. Uh, cautious optimism. Uh, I'm glad to see that companies that are not just the usual suspects I'm looking at you real tech are the ones that are out there trying to push the envelope of wifi eight.
I will note that this week we finally got, uh, apple devices that were all across the board, wifi seven. Um, pretty sure that unless you went to the big box store recently, you're probably not even running a one dose or a wifi seven uh, AP at home. Uh, maybe we don't need to constantly be trying to buy the best and brightest.
Uh, I can still remember, uh, deploying an 8 0 2 point 11 n that's wifi four for you people. Uh, Belkin that was so pre-standard that I ended up having to throw it out eight months later when the boss suddenly wanted something different. So take it with a grain of salt, whether it's pre-standard wifi eight, pre-standard six G pre-standard ai.
We gotta have a little, little bit of standard around here folks. But, uh, one thing that you can count on that is so standard and so fun is all of the events that we do during Tech Field Day and next week we've got a big one coming up. Al Yes indeed it is Cloud Field day number 25.
It's the quarter century of Cloud Field Day, although I guess not quite a century in years. We're not quite that old with cloud. Uh, I'll be out in Santa Clara with my wonderful panel of delegates and presenting companies including, uh, hammer Space and VMware and Future and Research.
We'll also be representing that. Uh, my delegates will also be getting some other experiences along the way. It's gonna be an interesting and fun event for us.
Do follow along the hashtag CFD 25 on all your favorite social media and watch out for what's happening, particularly on the tech, uh, tech Field Day, LinkedIn, uh, profile. Keep a watch for us there. Personally, I'm staying in the Silicon Valley area and gonna the Nvidia GTC conference the following week.
Why am I expect to see a, a lot of our tech Field day sponsoring companies? I was surprised just how many will be there. Of course.
Uh, Tom, you are back in, in the, um, the left hand coast again in March as well. I am, I've got my uh, black hoodie and my black cat and my sunglasses all ready to go for the RSAC conference 'cause we're gonna be having Tech Field Day extra there. We've got great presentations coming up from Veeam Object first and Commvault schedules up on the website if you wanna tune in live, including on YouTube.
Did you know that we're streaming on YouTube now for all of our Tech Field day events? If you're not already subscribed to the Tech Field Day YouTube channel, you absolutely should. So you can get notified when we go live with great field day content and we are gonna be talking to a lot of great companies while we're out there, but we can't talk about what's going on because it's sensitive, compartmentalized information as we learn, if you take any kind of security test, which I'm sure there's gonna be some security tests there on site as well.
And then after I am done, uh, wiping all of my devices and tearing down the VPNs, I'm gonna be back out in Santa Clara for more Great field day action at Networking Field. Day number 40, we are officially over the hill. There's gonna be black streamers everywhere and we're gonna be talking about having to take extra ibuprofen, something like that.
Yeah, it's uh, over 15 years since the very first networking field day. And we're very excited to be, uh, coming at you with a big lineup of presenters, some old favorites, some new faces, uh, both on the presenting side, but also for the people who are around the table. com and learn more about who they are right now.
And we would love it if you would because we wanna show them some love. But we love that you are watching the Tech Field Day rundown. Every week, every Wednesday new episodes, find us on YouTube, subscribe to us on your favorite podcast application.
Don't forget that we're also streamed on Techstrong TV as well. And then we are all over the place with all the things that we do. The Tech Field Day podcast, the Security Boulevard podcast, uh, field day events, uh, coverage from a whole bunch of other stuff.
Wherever we are, you can catch us across Tech Field Day Techstrong and Future and Group Programs. We're gonna be back next Wednesday to talk about all the IT news in the week. That was probably some more stuff about Mobile World Congress and a few other things that broke along the way.
But until then, for myself, Tom Hollingsworth, for Alistair Cook, and everyone else here at Tech Field Day, thank you so much. We're wishing you and yours a great day.